rdmpw3275m-changelog-20260914-1440-tyrell-build20-r11-short-gate-rejection
rdmpw3275m changelog — Tyrell Build 20 R11 short-gate rejection
Tyrell Build 20 was rejected by a real physical-footprint growth failure on the designated canary; the automatic fail-closed rollback restored the exact accepted Build 15 daemon and Build 17 app, and canonical Build 21-or-later remediation is now required.
Scope
- Coordinator and evidence host:
rdmpw3275m - Designated canary and runtime rollback host:
rdmbair15m5 - Canonical evidence and source-owner host:
rdmsm4x - Source project was not edited by this monitor.
- No fleet rollout occurred. Build 20 must not be relaunched on any host.
Runtime result
- Candidate source:
96a5fc012ff754d072aee04a47452fd84e69b2e0 - Candidate daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77 - Candidate app executable SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd - Candidate identity: PID
55457, startMon Sep 14 13:39:51 2026, unchanged across all 41 samples - Gate window: 31 post-warmup samples over
1800.306823seconds - Physical footprint:
58.454315 MiBto103.813690 MiB - Endpoint growth:
+1.511723 MiB/min; least-squares growth:+1.887622 MiB/min; policy maximum:+0.200000 MiB/min - Window maximum:
133.407440 MiB - Health stayed good throughout: AC/open, 26 descriptors, two TCP descriptors, both status endpoints and all permission probes HTTP 200 with valid JSON, no HTTP 503.
- Failure capture: allocator fragmentation
84.9 MiB / 95%; SQLite Page Cache charged0 B.
Recovery verification
- R11 recorded
state=rolled_backand reasonphysical footprint growth exceeds policy limitat epoch1789410002.211183. - Exact accepted daemon restored: Build 15 SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Exact accepted app restored: Build 17 executable SHA-256
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Normal daemon LaunchAgent was enabled/running as PID
94015, one run, never exited; libproc resolved the exact hash-addressed rollback target. - Both direct status endpoints returned HTTP 200 valid JSON.
- Live database passed
PRAGMA quick_check, retained one additivelast_seen_atcolumn, and contained153533rows; it was not overwritten by the pre-migration backup. - One app and one TyrellBar were running. Guard and caffeinate counts were zero. Recovery LaunchAgent was unloaded, its plist was absent, and the active-canary marker was absent.
- Strict daemon and deep app signature checks passed. Time Machine remained active during verification.
Files and records changed
- Complete frozen local evidence:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build20-r11-short-gate-failure-rollback-20260914-1419 - Complete canonical evidence:
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r11-short-gate-failure-rollback-20260914-1419onrdmsm4x - Incident README SHA-256:
d9570bbec553f042a82153f4a98156c4a282f59da2b94099758d2b822b874c64 - Frozen runtime-stage manifest SHA-256:
3070f10a51f6d5217c1744f370ac572d11d3bf30b77fba55715af55598932a50 - Project index updated atomically:
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md, SHA-256c5124fba1345ea8028666bd4e52777a9c7f88a3ebc80d0b9581365c2013819fbto7042388fec4334e552134f45edc757fe68cac49e36e3b7fbaf6c0f8df649f8a6; local and canonical copies matched. - Project-index rollback copy:
PROJECTS.md.before-r11-rejectionin the local evidence root. - Coordination check-in updated:
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrelld-build18-recovery-20260910.json, SHA-25681d20060249befbac9462ee6e6d5686eb675d74fbeb7534ebd8d89553a29ab6b; canonical sync verified. - Existing high allocator bug
ISSUE-20260912-01, harness bugISSUE-20260914-10, and release taskTASK-20260911-01received append-only evidence comments. No duplicate bug was filed. - Canonical Build 21 remediation handoff: detail message
20260914-143705-D7701E35; high-priority correction20260914-143727-E0380F84; hub receipt verified.
Commands run
The following command classes were executed with bounded SSH and no secret values:
ssh -o BatchMode=yes [email protected] <state, launchctl, libproc, codesign, curl, sqlite3, pgrep, pmset checks>
rsync -a <rdmbair15m5 R11 stage>/ <local frozen stage>/
rsync -naci <rdmbair15m5 R11 stage>/ <local frozen stage>/
python3 <independent samples.jsonl identity, continuity, gate, and trajectory analysis>
shasum -a 256 <incident payloads and manifests>
rsync -a --delete-after <local evidence>/ [email protected]:<canonical evidence>/
rsync -naci --delete-after <local evidence>/ [email protected]:<canonical evidence>/
ticket comment ISSUE-20260912-01 <R11 evidence>
ticket comment ISSUE-20260914-10 <sentinel result>
ticket comment TASK-20260911-01 <release block>
~/.agent-coordination/agent_msg.zsh send <canonical Build21 handoff>
~/.agent-coordination/agent_msg.zsh sync
ssh [email protected] /Users/richh/dev/fleet/maintenance/scripts/fleet_checkin_sync.zsh
Undo and recovery
- Do not undo the runtime rollback by relaunching Build 20. The accepted operational state is the exact Build 15 daemon plus Build 17 app.
- If the project-index text itself must be reverted, first verify that
its current SHA-256 is still
7042388fec4334e552134f45edc757fe68cac49e36e3b7fbaf6c0f8df649f8a6, then restore only from the checksummedPROJECTS.md.before-r11-rejectioncopy; do not overwrite later concurrent edits. - Ticket comments and fleet messages are immutable audit records and should not be deleted.
- The original database backup remains at
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.dbonrdmbair15m5, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f. It must not replace the healthy additive live database merely to undo this canary.
Outstanding owner actions
- Canonical owner must acknowledge the high-priority handoff, fix allocator retention in a distinct isolated worktree, independently review and run the full test suite, then build/sign/notarize a separately identified Build 21 or later.
- A future candidate must repeat the guarded short, six-hour, fixed 24-hour, inventory, CPU, descriptor/socket, fresh-app, and controlled-reboot gates from zero before any expansion.
ISSUE-20260914-10remains open until the persistent recovery sentinel is proven across a controlled reboot while a future candidate is actively soaking.- Local AGY work was separately inspected and remains complete/pending canonical receipt; no provider quota reset or eligible local resume was observed during this closeout.