rdmpw3275m-changelog-20260915-1540-tyrell-build25-combined-canary-prep
rdmpw3275m-changelog-20260915-1540-tyrell-build25-combined-canary-prep
Prepared and canonically promoted an inert, fail-closed Tyrell canary packet pairing the newer Build 25 app with the Build 24 daemon, without touching the designated canary runtime.
Scope
- Authoring and verification host:
rdmpw3275m. - Canonical evidence destination:
rdmsm4x:/Users/richh/dev/_handoff/tyrell-build25-app-build24-daemon-r1-launch-20260915-codex. - Designated canary
rdmbair15m5was inspected read-only only. No candidate files were transferred there; no app or daemon was installed or launched; no guard, recovery agent, or interlock was armed. - Ticket:
ISSUE-20260914-15.
Files and state changed
- Created local packet
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build25-app-build24-daemon-r1-launch-20260915-codexand promoted an exact copy to the canonical path above. - Updated packet metadata files
policy.json,PREP-RECEIPT.json, andREADME-PREP.mdfor Build 25 app sourcef97f4cea5fe16cb66fe69929f670fce40a11d450and Build 24 daemon source3834d4522aad647411385a244d882c80194af3c1. - Added
Tyrell-build25.zip,artifact-verification.log,harness-self-tests.log, and the deliberate negative-control logharness-self-tests-attempt1-wrong-pid.log. - Reused the Build 24 daemon and guard harness byte-for-byte. The older Build 24 packet remains intact and immutable as a fallback.
- Created check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-combined-prep-20260915.jsonand synchronized it fleet-wide. - Updated heartbeat automation
finish-tyrell-build-16to monitor the Build 25 app plus Build 24 daemon candidate and retain the existing AGY track. - Appended the decision and verification evidence to
ISSUE-20260914-15; replied on fleet-bus thread20260915-141048-8F70D70Bwith messages20260915-142255-9023DA9Band20260915-153811-EB016E52.
Commands and checks run
- Copied the proven Build 24 guard packet with
rsync -awhile excluding its app ZIP, then copied the notarized Build 25 ZIP fromrdmsm4xwithscp. - Extracted the ZIP to a fresh
/tmpdirectory usingditto -x -k --noextattr --noqtn. - Ran
codesign --verify --deep --strict,spctl --assess,xcrun stapler validate, Mach-O architecture inspection, exact SHA-256 checks, and the packet's app-lifecycle hash, CodeDirectory, and designated-requirement functions. - Ran JSON validation, Python and zsh syntax checks,
allocation-attribution self-test, all nine reboot-interlock tests, 30
libproc iterations with zero
lsofcalls, and the disposable launchd disable/re-enable interlock test. - Deliberately supplied a non-tyrelld PID once; the guard rejected it
with
managed PID changed. Re-ran against the exact local baseline tyrelld and passed. - Compared the new packet recursively with the Build 24 packet. Differences were limited to the three metadata files, replacement app ZIP, and three verification logs; all guard, lifecycle, installer, measurement, interlock, and daemon files remained byte-identical.
- Before the canonical write, synchronized coordination state and
pinned the SSH endpoints: local fingerprint
SHA256:KT0oBLNDsMiiEDefde+diV7ETKIobGbK6ylpx52PXkU; canonical fingerprintSHA256:3D5x0tqX2D3EBA8UBJFr/JjZxNIpVjC3TLltySf0Erk. - Promoted into a newly created canonical directory and re-read all critical hashes plus the recursive manifest remotely.
Verification evidence
- Combined packet state:
inert_waiting_for_runtime_owner_acknowledgment. PREP-RECEIPT.json:89ccfaea99fdb432e31f2d242f38690ee27665aa5f96211ed0710e7842a6f610.policy.json:898df45dfc761123845bd835daf7b3f069d2d1796e3d2bc95bb5820143146d67.- Recursive packet manifest:
1da36af3068bf82567b6b22a0852895b6334778c7aad63b9b6f34fec3bd4d54d, 30 files, 3 directories, 0 symlinks, 67,196,291 bytes. Local and canonical values match. - Build 25 ZIP:
0c4a9f87f7b0f812a77ceffa6fc959b601bf948faaed3ac732cbad242a4514cc. - Build 25 app executable:
d7bb71eba28f812b53f787e1d2020add0d6b99aa258b396a1a0c7f2adeab8de7. - Build 25 arm64 full CodeDirectory:
2b3336065acd6998f83797a2a31614d3ab7350ce36dd4250febb92aacb29dac8. - Build 25 designated-requirement SHA-256:
9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee. - Exact Build 24 daemon:
220f6eac4298ca32faf866d0edc6308924482d2980730368faf12bb355fce949. - Artifact-verification log:
21bc23c43ff97de21236b0dc0f1110491fc82d3a1d0870710a7f11baccb749c4. - Passing harness log:
bb2698fbb2821e31ad882fb452f80edc14087c9d454cc01c8e715f42adfb8d0c. - Wrong-PID negative-control log:
a19967126c6202e282d1fb28b0f14bf4f8437cd34fbc7c421c2959d0eb7d5909. - At the post-preparation read-only canary check, AC power and open
lid were stable; exact known-good Build 15 daemon PID 24582 and Build 17
app hash remained present; both APIs returned HTTP 200 with valid host
identity; live database quick-check returned
ok; no candidate stage, guard, helper, or recovery plist existed.
Recovery and undo
- No runtime rollback is needed because no canary mutation occurred.
- The prior Build 24 packet remains at
/Users/richh/dev/_handoff/tyrell-build24-r1-launch-20260914and its local mirror, unchanged. - To abandon this preparation, mark the new packet superseded in the ticket and automation, retain it as immutable evidence, and continue from the prior packet. Do not delete evidence or alter the canary baseline.
- Existing canary database backup remains
/Users/richh/Library/Application Support/Tyrell/backups/20260914-2144-build24-r1-preflight-3834d45/tyrell.db, SHA-256f042ddb7f32ea2fb3b1c48813daae27cc6c343cc7cc3bd934fd0ecbeacc354a6.
Outstanding actions
- Await explicit acknowledgments to both runtime-freeze requests
20260914-212614-8BFD1B72and20260914-213416-818FC7BDfromclaude@rdmbair15m5/dev-a7. Silence, process absence, or an expired claim is not acknowledgment. - Await read-only acceptance or discrepancies for the combined packet
on thread
20260915-141048-8F70D70B. - After the freeze gate clears, perform the full two-reading power/lid preflight, exact baseline/backup checks, transfer-and-rehash, clean extraction, canary-local verification, dry runs, fail-closed preparation, nonce app probe, guarded launch, and all fresh memory gates from time zero.
- AGY supervision remains unchanged: no eligible unfinished parent or verified quota-reset event exists; definitive canonical receipts are still pending.