rdmpw3275m-changelog-20260912-0120-tyrell-build20-canary-launch-and-automation
rdmpw3275m — Tyrell Build 20 canary launch and monitoring handoff
Build 20 was independently verified and launched only on the
designated rdmbair15m5 canary with a fresh rollback guard;
the local heartbeat was updated to supervise the runtime gates and the
already-complete local agy queue without starting duplicate work.
Scope
- Controller:
rdmpw3275m - Canonical read/build-artifact source:
rdmsm4x - Only installation target:
rdmbair15m5 - No fleet expansion and no Tyrell source edits from this controller.
Controller files changed
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build20-canary-20260912-96a5fc0/- Fresh Build 20 guard, exact signed daemon, policy, memory gate, and pinned lifecycle dependencies.
- Guard SHA-256:
52e53684d4436919dc02f9a9f25a2ebf6b8f1ed690cc866603bc78284caaf2da. - Policy SHA-256:
742c28971e73c62ea7a9d1158885fe2983230949a74a4125d1b70b3ea004c882.
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrelld-build18-recovery-20260910.json- Updated to the exact Build 20 runtime owner, hashes, canary PIDs, backup, and temporal gates.
/Users/richh/.codex/automations/finish-tyrell-build-16/automation.toml- Heartbeat remains active every 15 minutes under the name
Finish Tyrell Build20 canary + local agy work. - Prompt now pins the exact Build 20 artifacts, backup, rollback, guard, six-hour and 24-hour acceptance rules, and agy no-duplicate-resume rules.
- Heartbeat remains active every 15 minutes under the name
Commands and operational actions
- Ran the mandatory AgentKit preflight and fleet bus/check-in synchronization.
- Verified the
rdmsm4xSSH ED25519 fingerprint asSHA256:3D5x0tqX2D3EBA8UBJFr/JjZxNIpVjC3TLltySf0Erkbefore using canonical artifacts. - Independently recomputed Build 20 artifact hashes, architectures, signatures, designated requirements, Gatekeeper status, stapling status, notarization evidence, version/build, and test receipts.
- Created and verified a pre-migration SQLite online backup on
rdmbair15m5. - Staged a fresh guard, ran
canary_guard.py prepare, deployed the exact app with the pinnedredeploy_app_fleet.zsh, and startedcanary_guard.py runundernohup. - Ran the app-driven usage/chat canary probe and issued a fresh nonce-specific host receipt.
- Added exact launch evidence to
ISSUE-20260912-01,TASK-20260911-01, andISSUE-20260909-12; published the runtime handoff on the fleet bus. - Rechecked the local agy manifest, status file, process table, launch control, and pending canonical receipts. No agy process was started because every parent remains complete or closed and there is no provider quota error/reset evidence.
Verification evidence
- Build 20 source:
96a5fc012ff754d072aee04a47452fd84e69b2e0; PR 32 merge:cfcb32a03a1617c2054f17ad70dbb9293af89237. - Full test receipt: 553 XCTest cases with one skip and no failures; 662 Swift Testing cases; ten release script suites and eleven unchanged memory-gate tests passed.
- Candidate daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77. - Candidate app executable SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd. - Candidate canonical arm64 full CodeDirectory hash:
37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c. - App and daemon Apple notarization submissions were accepted; the installed app passed strict signature, staple, and Gatekeeper checks.
- Canary guard PID
86129; daemon PID86219, process startSat Sep 12 01:14:35 2026, stable release path, launchd runs1, never exited. - Both status ports and both authenticated permission routes returned HTTP 200; initial guard sample recorded 42 open-file rows and two TCP descriptors.
- Pre-migration backup SHA-256:
db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f;quick_check=ok, 152,805 file rows, nolast_seen_atcolumn. - Live post-launch database:
quick_check=ok, one additivelast_seen_atcolumn, 152,805 file rows. - App functional probe SHA-256:
e7e54259bd325fac54578f6e3a1d130fa113369f1bced5c84648fc293fe45049; canary receipt SHA-256:eaad5865d2420aaeef18821919e3d90157fa5b5e5a6c54f322de6b5564886287. - Local agy manifest and status remained byte-identical at SHA-256
7117f14cd805e77270cf60b8fc36be5746e33284e4e6245f82ae446d92970401andbfb8601ed8d976b46ce4237f545adcbdb1f9c5e71ad39e30aff91ef49b35d99f; exact agy process count remained zero.
Backups and rollback
- Exact Build 15 daemon rollback:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Exact Build 17 app rollback:
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Pre-migration database backup:
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.dbonrdmbair15m5. - Guard-owned recovery:
/Users/richh/.tyrell/build20-canary-20260912-96a5fc0/prior/onrdmbair15m5. - Do not restore the database backup over newer live data. Build 20's schema change is additive and the signed Build 15 rollback is compatible with it.
- On a guard failure, let the guard restore the exact Build 15 daemon
and Build 17 app. For deliberate rollback, first verify and stop only
guard PID
86129, then run the stage'scanary_guard.py rollback; never run rollback concurrently with the guard.
Outstanding acceptance work
- Short physical-footprint-v2 gate at about 01:54 EDT.
- Six-hour-after-warmup gate at about 07:24:36 EDT, including an unchanged inventory pass at or immediately before the fixed endpoint.
- 24-hour gate at about 01:14:36 EDT on September 13, followed by independent CPU review, a new fresh app probe/receipt, and controlled reboot stable-path proof.
- Fleet rollout remains unauthorized.
- Local agy execution remains complete or closed; canonical integration receipts remain pending and no quota retry is appropriate without an actual provider denial and reset boundary.