rdmpw3275m-changelog-20260915-2234-tyrell-build25-r2-protected-canary-launch
rdmpw3275m changelog — Tyrell Build 25 R2 protected canary launch
Launched the exact Tyrell Build 25 app plus Build 24 daemon as a
rollback-protected rdmbair15m5 canary after clearing
runtime ownership and repairing a fail-closed launcher identity pin; the
candidate is only SOAKING, not release-accepted.
Scope and ownership
- Coordinator:
codex@rdmpw3275m/01a078a7-f1fc-77f1-9114-949dab68f922onrdmpw3275m. - Canonical development and evidence host:
rdmsm4x. - Sole runtime canary:
rdmbair15m5. - Primary ticket:
ISSUE-20260914-15; launcher defect: resolvedISSUE-20260915-16. - Both original runtime-freeze threads returned direct acknowledgments after the pending Tyrell-open action was denied. No other source or runtime owner remains authorized to mutate the canary during this protected run.
Changes made
- Preserved the original R1 packet unchanged after detecting that its
launcher pinned stale policy SHA-256
86d27633fe0d5031066b5c18f70255c757e640b1f3c82ec1f2f327d8b28be70finstead of the actual policy SHA-256898df45dfc761123845bd835daf7b3f069d2d1796e3d2bc95bb5820143146d67. - Filed
ISSUE-20260915-16, built the separate immutable R2 packet, added a launcher dependency-pin regression test, re-ran the packet and fail-closed harness tests, and resolved that bug only after a successful protected launch. - Installed and launched exact notarized Tyrell Build 25 on
rdmbair15m5, ran the authenticated nonce probe, then launched the exact signed/notarized Build 24 daemon under the guard, power assertion, allocation sidecar, and persistent reboot/guard-loss interlock. - Updated canonical
/Users/richh/dev/PROJECTS.mdfrom inert R1-preflight state to R2SOAKINGstate. The exact before and after copies are retained under the frozen launch-evidence packet. - Updated
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-canary-20260915.jsonto record the live stage, PIDs, exact identities, evidence, and still-open gates. - Sent high-priority correction
20260915-223353-DE3419E9to the existing local AGY RAM-disk lane and the canonical Claude lane because its Victory Audit overstatesSESSION-STATE.mdsynchronization. No duplicate AGY process was launched.
Exact artifacts and identities
- R1 packet, preserved:
/Users/richh/dev/_handoff/tyrell-build25-app-build24-daemon-r1-launch-20260915-codex- PREP receipt:
89ccfaea99fdb432e31f2d242f38690ee27665aa5f96211ed0710e7842a6f610 - Recursive content:
1da36af3068bf82567b6b22a0852895b6334778c7aad63b9b6f34fec3bd4d54d
- PREP receipt:
- R2 packet:
/Users/richh/dev/_handoff/tyrell-build25-app-build24-daemon-r2-launch-20260915-codex- PREP receipt:
33d7e5eb84f02d47d0f3d769313cdad7bb1370cb4412c0da89b6b334fcc312c5 - Launcher:
d422044cc123ed4f7a95f0ded738ef08d433db8c91fc90f9d77d58a3b72c7dcc - Launcher identity test:
01498c95a408f90ad3313ccfdb364aec049895f49957a3041e71035aac620d7b - Recursive content:
48185292affe41197c4b612824b3bda2a01bdc668fc3671720dfdef208272a80across 33 files, three nested directories, and zero symbolic links.
- PREP receipt:
- Live canary stage:
/Users/richh/.tyrell/build25-canary-r2-20260915-4818529 - Build 25 app executable SHA-256:
d7bb71eba28f812b53f787e1d2020add0d6b99aa258b396a1a0c7f2adeab8de7 - Build 25 arm64 full CodeDirectory SHA-256:
2b3336065acd6998f83797a2a31614d3ab7350ce36dd4250febb92aacb29dac8 - Build 24 daemon SHA-256:
220f6eac4298ca32faf866d0edc6308924482d2980730368faf12bb355fce949 - Launch time:
2026-09-15 22:20:59 EDT - Live launch PIDs at verification: daemon
85673, app80663, menu bar79053, guard84738, allocation sidecar85115, guard-owned caffeinate85116. - Frozen initial evidence:
/Users/richh/dev/_handoff/tyrell-build25-r2-launch-evidence-20260915-2223- Recursive SHA-256:
5f65da6458c6534b66efa230952557b5772841d4c9bf29b8cfb8187e5f69cb95 - Independent launch-verification log SHA-256:
691edbb05d91ca4ec709942ae6e4faccc676fa4ae07c1f87d86dcfb7d7c7ff88
- Recursive SHA-256:
- Canonical registry:
- Before SHA-256:
ff9ed31f3c5e792c61854aa5019d0783a39e4d6b27542b890920c33cd695538f - After SHA-256:
4f2749e6a88f1f8ae3b1324c8e62171c026787e3ffbd29ece687534daecf5d34 - Recovery copies:
/Users/richh/dev/_handoff/tyrell-build25-r2-launch-evidence-20260915-2223/registry/PROJECTS.before.mdandPROJECTS.after.md.
- Before SHA-256:
Commands and validation
Representative reproducible commands used during the change:
python3 test_launcher_identity_pins.py
python3 test_reboot_interlock.py
python3 test_libproc_guard.py
zsh test_launchd_disable_interlock.zsh
zsh scripts/install_app_local.zsh
zsh scripts/run_tyrell_app_canary_probe.zsh
zsh scripts/issue_tyrell_app_canary_receipt.zsh
zsh launch_guard_power_protected.zsh
zsh verify_guard_power_protected.zsh
shasum -a 256 /Users/richh/dev/PROJECTS.mdVerified results:
- R2 JSON, Python, and zsh syntax passed; launcher identity pins
passed; allocation self-test passed; nine reboot-interlock tests passed;
30 live libproc iterations made zero
lsofcalls; descriptor-churn and disposable launchd interlock tests passed. - Clean app extraction passed strict/deep codesign, Gatekeeper,
stapler, universal2, Team ID
ZU2882L4HT, build25, executable SHA, full CodeDirectory SHA, and designated-requirement checks. Forbidden quarantine and FileProvider attributes were absent. - The app launched exactly once, the menu bar restarted, and the
authenticated nonce chat/page/command probe passed. Probe SHA-256 is
1a4cb2526fd441e9c5b76df6d4ccabf64f2e8c1eea538f10f4059c235cb60630; acceptance receipt SHA-256 is5285332a4b8c1b644a21145a66b50a5e25b7778d7060fc47acb65c79c0fec661. - The daemon launched from its stable hash-addressed release, both
authenticated status planes returned valid JSON, the live database
reported
quick_check=okwith onelast_seen_atcolumn, and the recovery LaunchAgent remained loaded while normal daemon auto-load was intentionally disabled. - Latest independent guard check reported AC power, open clamshell,
active system-sleep assertions, armed identity-pinned reboot interlock,
and fresh heartbeat. The state remained
soaking.
Backups and rollback
- Exact pre-canary rollback is retained in the live stage: Build 15
daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e, and database backup SHA-256f042ddb7f32ea2fb3b1c48813daae27cc6c343cc7cc3bd934fd0ecbeacc354a6(quick_check=ok, 153,929 rows, onelast_seen_atcolumn, mode0600). - The app installer also retained
/Applications/.tyrell-rollbacks/20260915-221916-2c5ca2a674fe/Tyrell.appon the canary. - The guard and persistent recovery sentinel automatically fail closed to the exact Build 15/17 snapshots on a policy, power, heartbeat, process-identity, reboot, or acceptance failure. Do not manually overwrite the live database with the older backup.
- To undo only the registry update, restore
PROJECTS.before.mdonly after confirming the live registry still has exact after SHA-2564f2749e6a88f1f8ae3b1324c8e62171c026787e3ffbd29ece687534daecf5d34; otherwise merge intentionally rather than overwriting concurrent work.
Outstanding gates and actions
- This candidate is only
SOAKING. Startup and warm-up memory values are diagnostic and do not pass or fail the steady-state policy. - Still required: ten-minute warm-up, 30-minute post-warm-up short memory gate, six-hour same-process gate, fixed 24-hour gate, repeated inventory, CPU, fresh-app, controlled reboot, integration, rollback-protected fleet rollout, and release acceptance.
- No fleet expansion, integration, merge, tag, or release is authorized by this record.
- The existing AGY RAM-disk parent remains alive and active. Its
canonical commit/audit is not accepted as complete until
SESSION-STATE.mdis corrected, committed, promoted, re-audited, and acknowledged without duplicating the process. Actual provider quota exhaustion remains the only quota-resume trigger.