rdmpw3275m-changelog-20260914-1348-tyrell-build20-r11-reboot-safe-canary
rdmpw3275m changelog — Tyrell Build 20 R11 reboot-safe canary
Replaced the reboot-vulnerable R10 canary harness with a tested
fail-closed R11 harness, restored the accepted baseline before
re-launch, filed the defect, launched exact Build 20 only on
rdmbair15m5, and preserved reproducible evidence without
authorizing fleet expansion.
Scope
- Coordinator and evidence host:
rdmpw3275m. - Canonical evidence and issue host:
rdmsm4x. - Only runtime-mutated product host: designated canary
rdmbair15m5. - Tyrell is Production. No other fleet host was installed, restarted, or promoted.
- AGY Track B remained unchanged and no AGY process was started by this work.
Incident and containment
- R10 was healthy through 91 samples and 5,401.528 seconds when
rdmbair15m5entered a gracefulsessionlogoutd-initiated shutdown at 2026-09-14 12:55:53 EDT. - Exact Build 20 automatically relaunched after boot from the durable
hash-addressed stable path, proving path durability. The transient
Python guard and its
caffeinateprocess did not return; stale state continued to identify the pre-reboot PID. This was a fail-closed harness defect, not a Build 20 crash or product rejection. - The complete interrupted stage and a 2,029,620-byte shutdown-stall
report were preserved locally under
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build20-r10-reboot-interruption-20260914-1256and checksum-matched canonically under/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r10-reboot-rollback-20260914-1256onrdmsm4x. - A bounded rollback restored exact Build 15 daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0and Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. Both status APIs returned HTTP 200, SQLitequick_checkreturnedok, the additivelast_seen_atcolumn was retained, and no guard/recovery process or plist remained before R11 preparation.
Files and records changed
- Created and validated the R11 harness at
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-r11-reboot-safe-harness-20260914. - Created the clean local package at
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build20-r11-stage-20260914. - Created the frozen launch evidence at
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build20-r11-launch-20260914-1339. - Copied and checksum-verified the launch evidence to
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r11-launch-20260914-1339onrdmsm4x. - Updated
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrelld-build18-recovery-20260910.jsonwith the R11 ownership, paths, process identities, and gates; synchronized it to the canonical hub. - Updated only line 26, the existing Tyrell row, in
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. Before SHA-256 was612553edfa462aef508a8fa6d25c49034845f33b74eee096ab00b52233ac26f4; after SHA-256 wasc5124fba1345ea8028666bd4e52777a9c7f88a3ebc80d0b9581365c2013819fb. The exact before-copy is retained in the R11 launch evidence. - Filed and claimed
/Users/richh/dev/issues/open/ISSUE-20260914-10-build-20-canary-guard-dies-across-reboot.mdonrdmsm4x; appended root-cause, fix, test, launch, and evidence details. It remainsin-progresspending controlled reboot or equivalent end-to-end acceptance.
R11 changes
canary_guard.pyv1.6, SHA-2565bb4acf57abcc9c2738009c0396e54f4dcc447d5704cd9f57ccdcf699d02f120, now records the boot session and guard PID; writes an atomic heartbeat; disables normal candidate auto-load while the canary is unaccepted; installs a persistent user LaunchAgent recovery sentinel; serializes rollback; and rolls back on a boot mismatch, dead guard, missing/corrupt heartbeat, or heartbeat age greater than 180 seconds.- Recovery pins the exact guard, policy, and candidate daemon identities. Any drift keeps the candidate LaunchAgent disabled and refuses ambiguous recovery.
policy.jsonSHA-256 isd0feaa188de5486952863a347ec6b09d5cbf2408e1a3d7bb7972a83976c415be.launch_guard_power_protected.zshv1.6 SHA-256 ise88b70f2cb50bcda6675d6843bcd737d58d792f490a580b9afbf14016f64901d.verify_guard_power_protected.zshv1.2 SHA-256 is2eaad8bbe353dc33e8ca962ec7e01f416db082686011e8f953d9139a67d0048f; it validates power and lid state, exact guard/caffeinate ownership, state/marker/heartbeat/interlock identities, heartbeat freshness, disabled normal auto-load, and loaded recovery sentinel.
Commands and verification
- Used
shasum -a 256,codesign --verify --strict,codesign --verify --deep --strict,lipo -archs,zsh -n, Pythonpy_compile,jq,plutil -lint,sqlite3 -readonly,launchctl print,launchctl print-disabled,pmset,ioreg,ps,pgrep,rsync -a --checksum, and checksum dry runs. - Nine deterministic reboot-interlock tests passed locally and on
rdmbair15m5. - A disposable real-launchd test passed locally and on the canary: disable preserved a live PID; after bootout/bootstrap the disabled job stayed stopped; enable restored normal launch.
- The canary live-baseline libproc test completed 30 full measurements
with zero
lsofcalls, 27 descriptors, two TCP descriptors, and maximum duration 0.059 seconds. - Two bounded functional recovery tests on the canary restored the exact accepted daemon/app baseline from simulated prior-boot active state; one included final guard/policy/daemon identity pinning.
- Fresh stage dependencies, pre-Build20 database backup, rollback
payload, signatures, Team identity, hardened runtime, and universal
x86_64 arm64architectures passed before runtime mutation. - The signed Build 20 app was installed at
/Applications/Tyrell.app, accepted, and launched exactly once; its executable SHA-256 is423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd. - R11 started at 2026-09-14 13:39:52 EDT. Exact Build 20 daemon
SHA-256
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77ran as PID 55457; guard PID was 55257 and guard-ownedcaffeinatePID was 55320. - The normal daemon job was loaded and running but
launchctl print-disabledshowed it disabled for future starts. Recovery labelcom.eastcoastscience.tyrell-canary-recoverywas loaded from/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrell-canary-recovery.plist. - Three recovery-sentinel executions, about 60 seconds apart, returned
decision=monitor,boot_matches=true,candidate_active=true, andservice_disabled=true. - The third complete sample at elapsed 120.737 seconds had 18,187,464 physical bytes, 26 descriptors, two TCP descriptors, both status APIs HTTP 200/valid JSON, and 16 of 16 concurrent permission probes HTTP 200/valid JSON.
- Final launch-evidence root manifest SHA-256 is
c810b5d74834aee5475193ebaddd0a2d3d882409e357b41d49283b7c93dfd4aafor 80 files, 33 directories, zero symlinks, and 275,373,062 bytes. The frozen stage and harness identities are independently recorded in the receipt; canonical and local manifests matched.
Backups and undo
- Interrupted R10 evidence and shutdown report are retained locally and canonically at the paths above.
- The R11 stage contains a complete prevalidated
prior/snapshot plusprior.jsonfor exact Build 15 daemon, its LaunchAgent plist, and exact Build 17 app. - The app installer retained a verified system-app rollback at
/Applications/.tyrell-rollbacks/20260914-133906-2c5ca2a674fe/Tyrell.apponrdmbair15m5. - To undo the R11 canary, invoke
/opt/homebrew/bin/python3.14 /Users/richh/.tyrell/build20-canary-r11-20260914-96a5fc0/canary_guard.py rollbackonrdmbair15m5. The rollback is identity-checked and lock-serialized; it restores Build 15/17, re-enables the normal daemon job, unloads/removes the recovery sentinel, retains the additive database migration, and verifies daemon health.
Outstanding gates
- R11 is launched but remains
SOAKING_NOT_ACCEPTED. - Short gate is due near 2026-09-14 14:19:52 EDT; six-hour-after-warmup gate near 19:49:52 EDT; fixed 24-hour gate near 2026-09-15 13:39:52 EDT.
- Inventory-repeat, CPU, app, and controlled-reboot acceptance remain separate requirements.
- No fleet expansion, deployment, or release acceptance is authorized by this launch.
- The canary-host Apple Notes changelog must be created from an Aqua GUI agent; SSH cannot perform that AppleEvent operation.