rdmpw3275m-changelog-20260914-1545-tyrell-build21-r1-canary-launch
Tyrell Build 21 R1 was installed only on the designated canary under a fail-closed rollback guard after Build 20 failed its unchanged memory gate; the new build is healthy in early soak but is not accepted or fleet-released.
Tyrell Build 21 R1 designated-canary launch
Scope and outcome
- Coordinator host:
rdmpw3275m(codex@rdmpw3275m/01a078a7). - Canonical development host:
rdmsm4x; source producercodex@rdmsm4x/01a08a70completed and returned the isolated source/artifact lane before launch. - Designated canary:
rdmbair15m5only. No other fleet host was installed, restarted, or expanded. - Build 20 remains rejected after R11 failed the unchanged
physical-footprint-v2short gate at +1.511723 MiB/min endpoint growth and +1.887622 MiB/min regression growth versus +0.20. Its exact signed Build 15 daemon and Build 17 app rollback passed. - Existing high-severity bug
ISSUE-20260912-01was extended; no duplicate bug was filed. - Build 21 source
be3e664f20afc0e7bb3de9c2fa057fee01b15674bounds pending-upload selection to requested missing hashes and one eligible path per hash. Independent review accepted it. The exact full suite passed 553 XCTest cases with one skip and 664 Swift Testing cases with zero failures. - Exact signed/notarized Build 21 daemon SHA-256:
b9d85e48ff2e6d75ee58235537a61d0f204c9fb01cc726e054324b01b9a3d158. - Exact signed/notarized Build 21 app executable SHA-256:
dbc4bc187fba6089da185f566213d0ab8fdb44d929f59346d5d0135478c466a1. - Apple submissions
c7b00c6d-f2e9-4791-bf7a-4d0afbe93a18and127df84f-0e1e-42a2-9804-6e0fa8b4fb72are Accepted; app staple and Gatekeeper verification passed.
State changed
- Installed and launched exact Build 21 R1 only on
rdmbair15m5from/Users/richh/.tyrell/build21-canary-r1-20260914-be3e664at 2026-09-14 15:33:52 EDT. - Daemon PID/start/path at launch:
61143;Mon Sep 14 15:33:50 2026;/Users/richh/Library/Application Support/Tyrell/releases/daemon-b9d85e48ff2e/tyrelld. - Guard PID
60887and caffeinate PID60971hold both system-sleep assertions. Guard SHA-256 is323e385286f79914cbf2858704f12c08fe8e5b528eb3ba7976f7b6a86cb7d69f; policy SHA-256 is2674761f053232c0a2518163931ff487d8c54affe1da19336b3c241e1518bc94. - Candidate automatic loading is disabled while unaccepted. Persistent
recovery label
com.eastcoastscience.tyrell-canary-recoveryis loaded with exact identity pins, a 180-second heartbeat limit, and an armed reboot interlock. - Created immutable local launch snapshot
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build21-r1-launch-20260914-1533and copied it byte-identically to canonical/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/canary-r1-launch-20260914-1533. - Launch snapshot contains 85 files, 29 directories, zero symlinks,
and 224792287 bytes.
MANIFEST.sha256file hash is3c97bdf7b2b0829d86babd776f9d113b3207466a3d2c447d6a3e55210d373b3b; recursive summary hash isd3490d0d1722ae9ec98bb0e8db75fdd29da1ad5282a284a9b98278adcb3644bb. Local-to-canonical rsync dry-run was empty. - Updated the owned coordination check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrelld-build18-recovery-20260910.jsonand propagated it with the canonical fleet check-in synchronizer. Matching local/canonical/canary SHA-256:2b4b2297a54d2fadc54f09d87d1b2629f0ed094488b4a63c305d8c2af1ea35e4. - Updated the
finish-tyrell-build-16heartbeat through the Codex automation API. Automation configuration SHA-256:07770db09d3519b4a42c00d1f3fc93a67ceb80f04b54556a8534e7d996b371c7. - Appended exact launch milestone comments to
/Users/richh/dev/issues/open/ISSUE-20260912-01-tyrell-build-19-hourly-inventory-allocat.md,/Users/richh/dev/issues/open/TASK-20260911-01-independently-integrate-and-canary-signe.md, and/Users/richh/dev/issues/open/ISSUE-20260914-10-build-20-canary-guard-dies-across-reboot.mdonrdmsm4x. All three remain in progress.
Commands and verification
- Used the canonical signed Build 21 producer packet at
/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/frozen-handoff; its manifest SHA-256 isd7f811463a11fc48ff6a7b736aea2e61a1e0b2c5fea02bf3e294a12c1669f748. - Ran the stage dependency, unit, launchd-disable interlock, live libproc, app dry-run, rollback-preflight, final-launch-preflight, install, app functional probe, app receipt, database, endpoint, signature, notarization, and power/interlock checks. The frozen stage retains the raw outputs.
- The live read-only power/interlock verifier passed AC power, open clamshell, guard/caffeinate parentage, both sleep assertions, loaded recovery sentinel, disabled candidate autostart, exact boot identity, and a fresh heartbeat.
- The frozen first five one-minute samples span 240.048137 seconds
with maximum gap 60.036472 seconds; all identify daemon PID
61143, the same process start, and the same hash-addressed executable path. Descriptor rows stay 26..27, TCP descriptors remain exactly two, and every status and permissions probe is HTTP 200 valid JSON. Physical footprint is 259589440 -> 18203944 bytes, maximum 259589440 bytes. This is early-soak health only, not a memory-gate pass. - Live SQLite
quick_check=ok; both direct status endpoints are HTTP 200 valid JSON. Nonce app probe SHA-256a97e6f36635940c842c6cec4b9a417928e8e4f6dfc585cb0c6a71bf078cc3ffd; app receipt SHA-256fab07fc13fc8277a2afc680562c91b9fd2a7c15759d7239c7b84745be2aa0ef6. - Ran
/Users/richh/dev/fleet/maintenance/scripts/fleet_checkin_sync.zshonrdmsm4x, then independently verified the check-in hash on local, canonical, and canary hosts.
Backups and recovery
- Fresh preflight database backup on
rdmbair15m5:/Users/richh/Library/Application Support/Tyrell/backups/20260914-1525-build21-r1-preflight-be3e664/tyrell.db, SHA-256c2c5cfc0f32311d8c2c255d2fe32b60e122cd0c6840c0862a2c7ca06a808e5d6;quick_check=ok, 153412 rows, one additivelast_seen_atcolumn. Do not restore it over a healthy additive live database. - Exact rollback daemon is signed Build 15 SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Exact rollback app is Build 17 executable SHA-256
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e, retained at/Applications/.tyrell-rollbacks/20260914-153342-2c5ca2a674fe/Tyrell.appon the canary. - Bounded operator rollback, if required, is:
ssh -o BatchMode=yes [email protected] '/opt/homebrew/bin/python3.14 /Users/richh/.tyrell/build21-canary-r1-20260914-be3e664/canary_guard.py rollback'. The guard also invokes the same serialized exact rollback automatically on a gate, identity, endpoint, power, guard-loss, or reboot-interlock failure.
Outstanding gates and owner actions
- Build 21 R1 is
SOAKING_NOT_ACCEPTED. No causal claim is made from the source fix alone. - Short gate is no earlier than about 16:13:52 EDT; six-hour gate about 21:43:52 EDT; fixed 24-hour gate no earlier than 2026-09-15 15:33:52 EDT.
- Still required: independent gate recomputations, at least two
complete inventory passes with an unchanged repeat and endpoint overlap,
CPU review, a fresh app probe, controlled reboot proof for
ISSUE-20260914-10, source integration, and fleet rollout validation. - Do not relaunch Build 20, intentionally reboot before memory/app/CPU prerequisites pass, merge draft PR 35, expand the fleet, or claim release acceptance until every unchanged gate passes.
- The recurring heartbeat remains active to monitor these boundaries and the separate local AGY receipt lane.