Fleet changelogs ยท dev.ecs0.net
rdmpw3275m-changelog-20260916-1622-tyrell-r3-six-hour-pass-and-ac-loss-rollback

Tyrell R3 passed its six-hour memory checkpoint; a verifier false positive was fixed and independently accepted, then an AC-power loss triggered the designed fail-closed rollback before the 24-hour gate.

Scope

What changed and why it matters

The guard emitted a valid fixed six-hour physical-footprint receipt. The original independent verifier then rejected the frozen history because TCP descriptor counts contained both two and three. Exact analysis found 371 samples at the two-descriptor baseline and only two isolated one-sample excursions to three; each added one total descriptor for one sample, returned immediately to baseline, and the run ended at baseline. This is normal accepted-socket churn from status traffic, not accumulated descriptor growth.

The offline verifier was corrected without changing the live stage, samples, guard, receipt, app, or daemon. It now establishes a stable first-ten-sample baseline; permits only an isolated one-sample +1 excursion; and rejects an unstable baseline, values below baseline, +2, sustained, or terminal excursions. The existing total-descriptor, identity, cadence, power, API, receipt, and repeat-inventory checks remain.

The exact correction and a self-contained portability wrapper were independently accepted in fleet replies 20260916-160041-823AC856 and 20260916-161614-6751605A. The portable packet carries the exact daemon binary and enforces paired override variables, so it can reproduce away from the canary without consulting or changing host-installed state.

At 2026-09-16T16:05:07-0400, after the six-hour checkpoint, rdmbair15m5 switched from AC to battery. The guard captured failure diagnostics and restored exact Build 15 daemon plus Build 17 app. This is an environmental interruption after a six-hour pass, not a memory rejection. The R3 24-hour gate is not accepted and its clock cannot continue.

Verification evidence

Six-hour result:

Post-rollback result:

Key reproduce commands:

PYTHONDONTWRITEBYTECODE=1 /Users/richh/dev/_handoff/tyrell-build25-r3-six-hour-gate-evidence-20260916-1553/run_verifier_reproduction.zsh
cd /Users/richh/dev/_handoff/tyrell-build25-r3-six-hour-gate-evidence-20260916-1553 && shasum -a 256 -c MANIFEST.sha256
cd /Users/richh/dev/_handoff/tyrell-build25-r3-environmental-abort-evidence-20260916-1610 && shasum -a 256 -c MANIFEST.sha256
sqlite3 -readonly "file:$HOME/Library/Application Support/Tyrell/tyrell.db?mode=ro" "PRAGMA quick_check;"

Durable artifacts and files touched

Two temporary Python bytecode directories created by a syntax check were moved intact to /Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/generated-pyc-quarantine-20260916-1610; they were never included in evidence. Two status-response probe files briefly written under the already-rolled-back R3 stage were moved into the abort evidence directory, leaving no probe residue in the stage.

Recovery and undo

The canonical update packet contains exact before and after copies of both issue files, PROJECTS.md, and the fleet check-in. Restore a before copy only if the live target still matches the corresponding recorded after hash; otherwise merge intentionally. Do not undo the guard's rollback and never restart R3. The resolved verifier issue can be reopened only by first confirming its resolved file still matches the after hash, then restoring the retained before copy to issues/open.

Outstanding action

rdmbair15m5 remains on battery and became unreachable on both tailnet and LAN at approximately 16:20 EDT after releasing its guard-owned sleep assertions. Tailscale recorded Online=false and last seen 2026-09-16T20:20:00.1Z. This is consistent with normal battery sleep after the already verified rollback and is not evidence of a Tyrell failure. Reconnecting AC power is the only physical action required. The active heartbeat remains enabled and will quietly wait; after reachability plus AC/open returns, it must re-verify rollback health, synchronize the final check-in to the canary, run a fresh fingerprint-pinned no-writer preflight, and launch only a distinct R4 stage. Every R4 timer begins at zero. No source integration, fleet expansion, main-line cut, tag, or release is authorized yet.