rdmpw3275m-changelog-20260916-0955-tyrell-build25-r3-protected-canary-launch
rdmpw3275m changelog — Tyrell Build 25 R3 protected canary launch
Launched the exact notarized Tyrell Build 25 app plus signed Build 24
daemon as a new rollback-protected R3 canary on rdmbair15m5
after the owner opened the lid on AC power. R3 is only
SOAKING; no memory, reboot, fleet, integration, or release
acceptance is claimed.
Scope and ownership
- Coordinator host and identity:
codex@rdmpw3275m/01a078a7-f1fc-77f1-9114-949dab68f922. - Canonical source, issue, registry, and evidence host:
rdmsm4x. - Sole runtime canary:
rdmbair15m5. - Primary bug:
ISSUE-20260914-15, stillin-progresswhile canary and release gates remain open. - R2 remains immutable and
INCONCLUSIVE_ENVIRONMENTAL_INTERRUPTION; this R3 launch uses a distinct stage and restarts every acceptance clock. - The already completed AGY RTTy parent PID
5069, conversation79bad69b-cf45-4f90-b76e-157012ec740b, was not resumed again.
Changes made
- Repeated the SSH host-key fingerprint check and independently
verified
rdmbair15m5on AC withAppleClamshellState=No, exact Build 17 app, exact Build 15 daemon PID56164, valid JSON from both status planes, and no active recovery agent. - Published and synchronized the R3 ownership/check-in before runtime mutation.
- Transferred the exact immutable R2 packet into the new stage
/Users/richh/.tyrell/build25-canary-r3-20260916-4818529and reproduced its recursive SHA-25648185292affe41197c4b612824b3bda2a01bdc668fc3671720dfdef208272a80across 33 files, three directories, zero symlinks, and 67,205,503 bytes. - Cleanly extracted the app outside FileProvider storage. Verified
strict/deep code signing, Gatekeeper, stapler, universal2 architecture,
app build and identity, daemon identity, JSON/Python/zsh syntax,
launcher identity pins, allocation self-test, nine reboot-interlock
tests, 30 live no-
lsoflibproc probes, and a disposable launchd disable/enable interlock. - Snapshotted the exact Build 15 daemon/plist, Build 17 app, and pinned database backup into the R3 rollback payload. Both rollback preflight and launch preflight passed.
- Ran the app installer dry-run, installed Build 25, restarted the verified menu-bar agent, completed the authenticated nonce usage/chat probe, and issued the nonce-specific receipt.
- Launched the Build 24 daemon through the fail-closed guard. Verified active sleep assertions, an armed persistent reboot/guard-loss interlock, the exact PID/start/path/hash, both JSON status planes, and live database integrity.
- Froze and promoted initial launch evidence to
/Users/richh/dev/_handoff/tyrell-build25-r3-launch-evidence-20260916-0943. - Updated canonical
/Users/richh/dev/PROJECTS.mdby compare-and-swap, appended the launch milestone toISSUE-20260914-15, refreshed the fleet check-in, and updated heartbeat automationfinish-tyrell-build-16to monitor R3 rather than the cleared lid-open blocker.
Exact identities and evidence
- Build 25 app executable SHA-256:
d7bb71eba28f812b53f787e1d2020add0d6b99aa258b396a1a0c7f2adeab8de7. - Build 25 arm64 full CodeDirectory SHA-256:
2b3336065acd6998f83797a2a31614d3ab7350ce36dd4250febb92aacb29dac8. - Build 24 daemon SHA-256:
220f6eac4298ca32faf866d0edc6308924482d2980730368faf12bb355fce949. - Daemon PID
20671, process startWed Sep 16 09:40:52 2026; guard PID20320; allocation sidecar PID20432; guard-owned caffeinate PID20433; app PID19201; menu-bar PID17656. - Deployment nonce:
tyrell-b25d24-r3-20260916T134011Z-4818529. - App probe SHA-256:
742fa367eab3f7ba40d5566727b08e9af1e2937ec2bea6bbb06e4c7a9266a517. - App receipt SHA-256:
4d8b895743387177c3f32dab2d7d5f0fb971fad4c5b260a9f98ad42c1fcd8f2c. - Authoritative prepare-verification log SHA-256:
4e4d05ab2403bc1a13ebeba990f2df187239af7679ed408acc5cf76995209d16. - Authoritative independent launch-verification log SHA-256:
355debe9f4b59e094c7cf567c0f5371486fac7fe715d5470d822a589ce61d801. - Frozen evidence
MANIFEST.sha256SHA-256:1b0e422a50467113afdff9ffe02f74696815855611f2ac3353614ea015f7c60d. - Frozen evidence deterministic recursive SHA-256:
291bf9d1ee53fe99b6abad98bb7a9d14e7bf8f00b53a0a75d0b13cc49027ec0bacross 56 files, one nested directory, zero symlinks, and 180,990 bytes. - Registry compare-and-swap packet:
/Users/richh/dev/_handoff/tyrell-build25-r3-registry-update-20260916-0952; before SHA-256e9c610693af3f556fab029524da514e5915084fac7693a4037c3792e336e145b; after SHA-2565cdded38f04d4ea54bab756df7c630af57ab457166253930376f90e512462167; final owner/moderichh:staff 0644. - Updated automation TOML SHA-256:
f3597c7c09d745d10aa432647a291b78ff38056b54461a87f5c62f0611e94876.
Verification evidence
- The initial guard verification and the later independent verifier each passed AC/open, one exact guard, one guard-owned caffeinate, both sleep assertions, armed identity-pinned recovery interlock, disabled normal candidate auto-load, loaded recovery sentinel, and a fresh heartbeat.
- Both authenticated status planes returned HTTP 200 and valid JSON.
The live SQLite database returned
quick_check=ok, onelast_seen_atcolumn, and a positive row count. - At 540.94 seconds, before the ten-minute baseline, the same daemon PID reported 25,052,360 physical bytes, 145,712 KiB RSS diagnostic, 26 descriptor rows, two TCP descriptors, one completed inventory pass, and valid AC/open state. Startup peaks and all pre-baseline values are diagnostic only.
- The canonical issue comment explicitly keeps the issue in progress and distinguishes launch from acceptance.
- The canonical registry update and all retained evidence rehashed successfully after transfer.
Retained non-authoritative attempts
r3-artifact-harness-prepare.logstopped before preparation because the coordinator added an over-broad check that rejectedcom.apple.provenance. The prior successful R2 extraction carried the same OS provenance attribute; quarantine was absent. The separate attempt-2 log is authoritative and passed the established gate.r3-independent-launch-verification.logcontains a coordinator SQLite command-quoting error and is non-authoritative. The separate attempt-2 log executed the read-only query correctly and endedverification=passedwithdatabase_quick_check=ok.- No new product bug was filed for either operator-side attempt. The
existing product bug
ISSUE-20260914-15remains the correct ticket.
Backups and rollback
- Exact automatic rollback is retained inside the live R3 stage: Build
15 daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e, and pinned database backup SHA-256f042ddb7f32ea2fb3b1c48813daae27cc6c343cc7cc3bd934fd0ecbeacc354a6. - The app installer retained
/Applications/.tyrell-rollbacks/20260916-094006-2c5ca2a674fe/Tyrell.appon the canary. - The guard and persistent sentinel fail closed to the exact rollback on power-envelope, heartbeat, process-identity, reboot, or acceptance failure. Do not manually replace the live database with the older backup.
- To undo only the PROJECTS registry update, restore the retained
before-copy only if the live registry still has exact after SHA-256
5cdded38f04d4ea54bab756df7c630af57ab457166253930376f90e512462167; otherwise merge intentionally.
Outstanding gates and owner action
- Keep
rdmbair15m5connected to AC with its lid open. Closing the lid or leaving AC is a fail-closed rollback condition. - Still required: ten-minute warm-up baseline, 30-minute post-warm-up short gate, same-process six-hour gate, fixed 24-hour gate, unchanged repeat inventory, CPU review, fresh app probe, controlled active-candidate reboot proof, integration, rollback-protected fleet rollout, and release acceptance.
ISSUE-20260915-18still forbids cutting a release from currentmain, which lacks the Build 21–24 daemon lineage.- No fleet expansion, merge, tag, distribution, or release is authorized by this launch record.