Tyrell R3 passed its six-hour memory checkpoint; a verifier false positive was fixed and independently accepted, then an AC-power loss triggered the designed fail-closed rollback before the 24-hour gate.
Scope
- Coordinator host:
rdmpw3275m - Canonical host:
rdmsm4x - Canary host:
rdmbair15m5 - Product/run: exact Build 25 Tyrell app plus Build 24
tyrelld, R3 stage/Users/richh/.tyrell/build25-canary-r3-20260916-4818529 - Parent ticket:
ISSUE-20260914-15remains in progress - Verifier bug:
ISSUE-20260916-21resolved - Local AGY lane: already completed and verified; no continuation was sent
What changed and why it matters
The guard emitted a valid fixed six-hour physical-footprint receipt. The original independent verifier then rejected the frozen history because TCP descriptor counts contained both two and three. Exact analysis found 371 samples at the two-descriptor baseline and only two isolated one-sample excursions to three; each added one total descriptor for one sample, returned immediately to baseline, and the run ended at baseline. This is normal accepted-socket churn from status traffic, not accumulated descriptor growth.
The offline verifier was corrected without changing the live stage,
samples, guard, receipt, app, or daemon. It now establishes a stable
first-ten-sample baseline; permits only an isolated one-sample
+1 excursion; and rejects an unstable baseline, values
below baseline, +2, sustained, or terminal excursions. The
existing total-descriptor, identity, cadence, power, API, receipt, and
repeat-inventory checks remain.
The exact correction and a self-contained portability wrapper were
independently accepted in fleet replies
20260916-160041-823AC856 and
20260916-161614-6751605A. The portable packet carries the
exact daemon binary and enforces paired override variables, so it can
reproduce away from the canary without consulting or changing
host-installed state.
At 2026-09-16T16:05:07-0400, after the six-hour
checkpoint, rdmbair15m5 switched from AC to battery. The
guard captured failure diagnostics and restored exact Build 15 daemon
plus Build 17 app. This is an environmental interruption after a
six-hour pass, not a memory rejection. The R3 24-hour gate is not
accepted and its clock cannot continue.
Verification evidence
Six-hour result:
- 361 gate samples across 21,602.815850257874 seconds
- physical end 34.89183807373047 MiB
- physical delta 0.030464905646741192 MiB/min
- least-squares physical slope 0.08433926645703439 MiB/min against the 0.2 bound
- descriptor range 26โ29
- TCP baseline 2, maximum 3, two isolated one-sample excursions
- saved guard receipt matched
- seven corrected regression cases passed; original policy failed the real isolated-excursion case as expected
Post-rollback result:
- candidate, guard, and guard-bound caffeinate process counts: zero
- stable daemon, Tyrell app, and tyrellbar process counts: one each
- stable daemon PID
14804, SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, CDHash4344fbe498540b7f8e5a6f46edd7588ec9ed8495 - app Build 17, executable SHA-256
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e - both status APIs HTTP 200 with valid JSON and the correct host
- read-only database
PRAGMA quick_check:ok - recovery LaunchAgent absent with result
113; stable daemon autoload enabled
Key reproduce commands:
PYTHONDONTWRITEBYTECODE=1 /Users/richh/dev/_handoff/tyrell-build25-r3-six-hour-gate-evidence-20260916-1553/run_verifier_reproduction.zsh
cd /Users/richh/dev/_handoff/tyrell-build25-r3-six-hour-gate-evidence-20260916-1553 && shasum -a 256 -c MANIFEST.sha256
cd /Users/richh/dev/_handoff/tyrell-build25-r3-environmental-abort-evidence-20260916-1610 && shasum -a 256 -c MANIFEST.sha256
sqlite3 -readonly "file:$HOME/Library/Application Support/Tyrell/tyrell.db?mode=ro" "PRAGMA quick_check;"Durable artifacts and files touched
- Six-hour evidence:
/Users/richh/dev/_handoff/tyrell-build25-r3-six-hour-gate-evidence-20260916-1553- deterministic recursive SHA-256
f0a5a302b1168f1bc37b5122932e82202f252faf8307d6a7adf00048c03c7f0b - MANIFEST file SHA-256
7b32e98510e1ada0814ff61f3f717203cc5efa06bcd86e79df86e213511560b4
- deterministic recursive SHA-256
- Abort evidence:
/Users/richh/dev/_handoff/tyrell-build25-r3-environmental-abort-evidence-20260916-1610- deterministic recursive SHA-256
2a419bf2c8aedba6935a02e0b55f9a6ba3e2716506bb5a54671c2fb36064b543 - MANIFEST file SHA-256
dca67958d11e4b21271230661013a9ea4ea4095fa62291ae915eab0b83564765
- deterministic recursive SHA-256
- Canonical update/recovery packet:
/Users/richh/dev/_handoff/tyrell-six-hour-canonical-update-20260916-1608- deterministic recursive SHA-256
831f7e3ae32b13d3516beb37c656ac698495e3caf7b97a1e62f6ea2237906b02 - MANIFEST file SHA-256
5639fd1774866525c349ded451dbe4fdd97054f14ac6420572e78ef4101894af
- deterministic recursive SHA-256
- Updated parent issue:
/Users/richh/dev/issues/open/ISSUE-20260914-15-tyrell-mergefleetevents-colon-concatenat.md - Resolved verifier issue:
/Users/richh/dev/issues/resolved/ISSUE-20260916-21-six-hour-canary-verifier-rejects-bounded.md - Updated registry:
/Users/richh/dev/PROJECTS.md - Updated fleet check-in:
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-canary-20260915.json - Updated active automation:
/Users/richh/.codex/automations/finish-tyrell-build-16/automation.toml, final SHA-2566f370cf81762d8a59bb11bd7bf915ce7185b0d2b17ca70460eb98ed39ecd792f
Two temporary Python bytecode directories created by a syntax check
were moved intact to
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/generated-pyc-quarantine-20260916-1610;
they were never included in evidence. Two status-response probe files
briefly written under the already-rolled-back R3 stage were moved into
the abort evidence directory, leaving no probe residue in the stage.
Recovery and undo
The canonical update packet contains exact before and after copies of
both issue files, PROJECTS.md, and the fleet check-in.
Restore a before copy only if the live target still matches the
corresponding recorded after hash; otherwise merge intentionally. Do not
undo the guard's rollback and never restart R3. The resolved verifier
issue can be reopened only by first confirming its resolved file still
matches the after hash, then restoring the retained before copy to
issues/open.
Outstanding action
rdmbair15m5 remains on battery and became unreachable on
both tailnet and LAN at approximately 16:20 EDT after releasing its
guard-owned sleep assertions. Tailscale recorded
Online=false and last seen
2026-09-16T20:20:00.1Z. This is consistent with normal
battery sleep after the already verified rollback and is not evidence of
a Tyrell failure. Reconnecting AC power is the only physical action
required. The active heartbeat remains enabled and will quietly wait;
after reachability plus AC/open returns, it must re-verify rollback
health, synchronize the final check-in to the canary, run a fresh
fingerprint-pinned no-writer preflight, and launch only a distinct R4
stage. Every R4 timer begins at zero. No source integration, fleet
expansion, main-line cut, tag, or release is authorized yet.