rdmpw3275m-changelog-20260916-2104-tyrell-build25-r4-environmental-abort
Tyrell R4 failed closed on a transient canary AC-power loss before its six-hour gate; exact Build 15/17 rollback, APIs, database, evidence promotion, and canonical registry updates were independently verified, so R4 is environmental-inconclusive rather than a product failure.
Tyrell Build 25 app / Build 24 daemon R4 environmental abort
Scope
- Coordinator and evidence capture:
rdmpw3275m. - Protected canary and automatic rollback:
rdmbair15m5. - Canonical evidence and project/issue registries:
rdmsm4x. - Local AGY conversation
79bad69b-cf45-4f90-b76e-157012ec740bwas already complete and was not resumed.
What changed
- At
2026-09-16T20:48:58-0400, R4's guard detected thatrdmbair15m5had left its required AC-power envelope. - The guard captured failure footprint/vmmap evidence, stopped the exact candidate, restored the signed Build 15 daemon and Build 17 app, re-enabled normal daemon autoload, disarmed/unloaded the recovery interlock, and exited.
- R4 was sealed as
environmental-inconclusive-after-short-pass. Its prior short receipt remains evidence for R4 only; its six-hour and 24-hour clocks are void and must never be continued. - No new product bug was filed: the external power-envelope failure
and fail-closed rollback behaved as designed. Existing
ISSUE-20260914-15remains in progress for the release gates. - Canonical
/Users/richh/dev/PROJECTS.mdand/Users/richh/dev/issues/open/ISSUE-20260914-15-tyrell-mergefleetevents-colon-concatenat.mdwere updated by a two-file compare-and-swap. No Tyrell source tree, Git ref, artifact, tag, build, fleet install, or release state changed.
Exact evidence
- Candidate daemon: PID
15449, startWed Sep 16 17:15:45 2026, SHA-256220f6eac4298ca32faf866d0edc6308924482d2980730368faf12bb355fce949. - Guard: PID
15146; candidate and guard were absent after rollback. - Full R4 history: 213 samples; maximum gap
60.09921717643738seconds; exact PID/start/path and recorded AC/open envelope throughout; descriptor range 25-30; TCP counts exactly[2]; zero status or permission failures; four inventory passes. - Final candidate sample: elapsed
12722.773263216019seconds, physical footprint52888800bytes, RSS285824KiB diagnostic, 26 descriptors, two TCP descriptors. - Restored daemon: PID
64356, one instance, SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, CDHash4344fbe498540b7f8e5a6f46edd7588ec9ed8495. - Restored app: Build
17, one app plus one TyrellBar, executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Both
43117and43118status APIs returned HTTP 200 with valid JSON andhost=rdmbair15m5; read-only databasePRAGMA quick_checkreturnedok. - Recovery LaunchAgent lookup returned
113(absent); stable daemon autoload is enabled.
Evidence locations and hashes
- Coordinator:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build25-r4-environmental-abort-evidence-20260916-2055. - Canary:
/Users/richh/.tyrell/verification/tyrell-build25-r4-environmental-abort-evidence-20260916-2055. - Canonical:
/Users/richh/dev/_handoff/tyrell-build25-r4-environmental-abort-evidence-20260916-2055. - All three copies: 22 files, one nested directory, zero symlinks,
622774 bytes;
MANIFEST.sha256file SHA-256e1c3eef9436f7fa09ad9ca4ed986c3838bacac2d85941045f40590a8f0c31923; deterministic recursive SHA-2565a476d9f76259c83b6a6ae6181bc235cacbfed57ff46ddc3817abf118d6ce1d6. - Canonical registry recovery packet:
/Users/richh/dev/_handoff/tyrell-build25-r4-abort-registry-update-20260916-2101; manifest file SHA-256666bf2bcdbc6627eeb2ced74f316bd903a7d6d400e04ceb42710a10c213885ff; deterministic recursive SHA-256fa82275c122f5a1dd8b81865761e51ba361d789219620d58785791b7eb08b6df. - Registry hashes: PROJECTS
668037c29eb9dec27586655e444f59c3c9aa6ade3ad8b9b3c3c752e668201c83to74ee39e2ca1513c302aadd976a808e3f493fd9d5cde1ac38941e832f9739b47e; issue600382ee48a757a10b9bdb4a414bcd7fa75b57ba6ecdb810e6f2e36567e8b1c3to4a8fc9c20272f5b118a2369523ce5857c33ea81d660d122faaec5164da80d288.
Commands and verification
- Fingerprint-pinned SSH probes verified the canary key
SHA256:HDXZpExLTrlJconcMTpEfnH+t9xRbzygqdpKMmyF5KUand canonical keySHA256:3D5x0tqX2D3EBA8UBJFr/JjZxNIpVjC3TLltySf0Erkbefore reliance. pmset,ioreg,ps,lsof,shasum,codesign,launchctl,curl,jq, andsqlite3 -readonlyindependently verified the rollback state.scpcopied the bounded stage evidence; source/destination SHA-256 lists matched exactly.shasum -a 256 -c MANIFEST.sha256passed for every payload on coordinator, canary, and canonical copies; all JSON/JSONL parsed; deterministic recursive hashes matched.- The canonical registry compare-and-swap required both live
before-hashes, no open file handles, exact staged after-hashes, and
final owner/mode
richh:staff 0644.
Recovery and next step
- No runtime undo is appropriate: the canary is already on the verified stable Build 15 daemon plus Build 17 app.
- Preserve R4 and all evidence copies immutably. Do not reuse R4's nonce, PID, clocks, or receipts for a successor.
- To undo the documentation-only registry update, require both live files to match the recorded after-hashes and use the retained before copies with another compare-and-swap; otherwise merge intentionally.
- A distinct R5 may launch only after at least two fresh fingerprint-pinned AC/open observations separated by a stable interval, exact stable rollback/API/database preflight, absence of candidate/guard/recovery residue, and no competing runtime writer. Every R5 gate starts from zero.
- Build 26 cutting, integration, fleet expansion, tagging, and release remain unauthorized.