Tyrell Build 26 fleet release and post-deploy soak
Tyrell 0.2.0 Build 26 was built from clean, lineage-complete source,
fully tested, Developer ID signed and notarized, deployed with retained
rollback to all six Macs, and independently verified online. The
original tyrelld Offline incident is now closed as a
stable-runtime-path defect; a fresh guarded post-deploy memory soak
remains active and has not yet reached any acceptance gate.
Scope
- Coordinator and evidence host:
rdmpw3275m - Canonical source/signing host:
rdmsm4x - Designated canary:
rdmbair15m5 - Additional deployment targets:
rdmbair13m5,rdmpw3265m,jdmbair13m5 - Owner decision:
DEC-20260916-04— deploy the latest Build 26 to the fleet and soak the deployed build, superseding another pre-deploy 24-hour laptop-canary attempt for this release - Source worktree:
/Users/richh/dev/_worktrees/tyrell-build26-cut-20260916 - Source branch and HEAD:
claude/tyrell-build26-cut-20260916at40145fd912afe8b32ae7ee64c24950303a49eb7a - Source tree:
fbf1bdb43396db16e070101d9db707fb17fd9fb0
Why tyrelld was
Offline
The original outage was not an unexplained daemon crash. The per-user
LaunchAgent referenced the mutable SwiftPM alias
/Users/richh/dev/apps/Tyrell/.build/release/tyrelld.
SwiftPM had rewritten that alias to
.build/out/Products/Release, whose target later
disappeared. After reboot, launchd could not spawn the executable and
recorded exit 78 (EX_CONFIG); loopback ports 43117 and
43118 were therefore silent, so Tyrell.app correctly displayed Offline.
Tailscale was also down during the original incident, but that was
secondary because the app's local loopback health checks already
failed.
The durable fix originated in commit 869503a: install a
verified universal daemon into a retained hash-addressed release under
~/Library/Application Support/Tyrell/releases/, then
atomically point the stable
~/Library/Application Support/Tyrell/bin/tyrelld link and
LaunchAgent at it. Build 26 carries and exercises that lifecycle on all
six hosts. Existing ISSUE-20260905-23 was the correct bug
record, so no duplicate was filed; it was resolved after fresh six-host
verification.
Build and artifact evidence
- Full
swift testexited 0. Swift Testing summaries total 727 cases with zero failures; XCTest reported zero failures. Raw log:/Users/richh/dev/_handoff/tyrell-build26-release-20260916/swift-test.log, SHA-256515c86665c2e90cc53bc0644b3c5a73041ae22a7d913dcecf39e371b3c213d87. - App executable SHA-256:
75d41b417c393fb71ee9483836dcf1397236f207a2919faeabb3e74e9c1e9d2c. - App arm64 full CodeDirectory SHA-256:
5e230723fa522635d852dccb15bfebe64833daa26f8a9c0fbb8ab95c8ebb4031. - Designated-requirement SHA-256:
9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee. - Daemon SHA-256:
a4f43d83eb69113ed05d22b8f0b8521e09f71cd3475857e21d89e2572efea6e4. - App notarization submission:
b1552b90-42c3-44ff-a352-f48480d3860f. - Daemon notarization submission:
321c684b-41e4-48db-9f49-67d63c618e38. - Both executables are universal2, Developer ID signed by Team
ZU2882L4HT, and hardened-runtime enabled. The app is stapled and Gatekeeper accepted. - Independent artifact verifier exited 0; log SHA-256
4c67b59e304c47d8dc1965ee562926ebbb10d451f832508da64d5913a8e98529.
The first Aqua release wrapper correctly built, signed, and notarized
both artifacts but then exited because it attempted to parse JSON with
PlistBuddy. That evidence-only finalization defect was corrected to use
a JSON parser. The accepted artifacts were not rebuilt or overwritten;
the corrected finalizer revalidated source, dependencies, identities,
signatures, notarization, and packaging. The original failed wrapper is
retained as build-release-aqua.failed-v1.zsh; the corrected
wrapper and finalizer remain beside it in the canonical release
packet.
Deployment and verification
- Deployment nonce:
tyrell-b26-20260916T212700Z-40145fd. - Canary app probe SHA-256:
f87dd46ad5f5aef554c8a3fa8bf6c47f765638969d0ed11acb0c1433aa0c2105. - Canary receipt SHA-256:
ba947cb9156503f0970cdabe2beb8ef477a3f7327755decf598df6316113fa71. - The exact app and daemon were installed on all six hosts.
rdmsm4xruns the server role; the other five run clients. - Fresh independent verification on every host found exactly one
Tyrell app, one TyrellBar, and one
tyrelld; exact app and daemon hashes; correct roles; both/api/statusplanes at HTTP 200 with valid JSON; live databasequick_check=ok; retained Build 17 app and Build 15 daemon rollback; and a coherent Build 26 pre-deploy database backup. - Stable-runtime re-verification exited 0 on all six hosts: every
LaunchAgent uses
/Users/richh/Library/Application Support/Tyrell/bin/tyrelld, resolving toreleases/daemon-a4f43d83eb69/tyrelld; no.buildruntime remains. Log SHA-256:0afd4081f6a94b25c57f6a2905cf34299188defaf0a2557f11f3c603f90c24a2. - Canonical release evidence:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916.
Minor operator-side orchestration errors were caught before causing
product-state loss and are retained rather than hidden: an invalid hash
validator in the first canary daemon attempt; a local quoting error
after the hub daemon had already deployed; a verifier pipeline exit 141
caused by pipefail plus early awk; and a
JSON-summary quoting error in the first warm-up evidence formatter. Each
corrected rerun passed. No failed attempt changed the accepted artifacts
or bypassed rollback.
Post-deploy soak
The exact fleet-deployed Build 26 daemon began a fresh protected soak
on rdmbair15m5 at 2026-09-16 21:46:14 EDT:
- Guard PID
71421; allocation sidecar PID71841; guard-owned caffeinate PID71845; daemon PID72820. - Live stage:
/Users/richh/.tyrell/build26-postdeploy-soak-20260916-40145fd. - Persistent reboot/guard-loss interlock is armed. Normal daemon autoload is deliberately disabled while the already-loaded guarded process runs.
- Exact Build 17 app and Build 15 daemon rollback passed preflight and remain retained.
- The frozen launch snapshot contains 11 valid samples through 601.022871 seconds. Every sample has one PID/start/path, AC power, open clamshell, valid HTTP 200 status planes, descriptors 25–27, and exactly two TCP descriptors.
- Physical footprint began at 277,562,664 bytes, reached a diagnostic first-inventory warm-up maximum of 486,786,656 bytes, and fell to 110,495,064 bytes (105.376 MiB) at the first post-warm-up sample. This is neither a pass nor a failure; the 300 MiB ceiling is evaluated over the protected measurement windows after warm-up.
- Frozen launch/warm-up packet:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-soak-launch-evidence-20260916-2157; manifest SHA-256f9c8dcf84e71bc5bd0aaf4847168cecbaee50ca9673c46a1e5bcd77266e0dfc6. - Short gate is expected at about 2026-09-16 22:26:15 EDT; same-process six-hour gate not before 2026-09-17 03:56:15 EDT; fixed 24-hour gate not before 2026-09-17 21:46:15 EDT.
No short, six-hour, or 24-hour Build 26 memory acceptance is claimed
in this record. The active Codex automation
finish-tyrell-build-16 was renamed to
Monitor Tyrell Build 26 post-deploy soak, remains active at
a 15-minute cadence, and now pins these exact identities and gate times.
Its TOML SHA-256 after update is
a7d744f85a10aab2d397ab268e8bf22aac699d40cafb3e02e2bd8889820c12d6.
Files and records changed
- Installed
/Applications/Tyrell.appon all six hosts with exact Build 26 app identity. - Installed retained daemon release
~/Library/Application Support/Tyrell/releases/daemon-a4f43d83eb69/tyrelldon all six hosts and repointed the stablebin/tyrelldlink. - Updated per-host LaunchAgent runtime state through the guarded installer; did not weaken firewall, SIP, TCC, or Tailscale policy.
- Created coherent per-host pre-deploy database backups and retained predecessor app/daemon releases.
- Resolved canonical ticket
ISSUE-20260905-23; commented precise deployment/soak boundaries onISSUE-20260914-15andISSUE-20260912-01. - Updated canonical
/Users/richh/dev/PROJECTS.mdby compare-and-swap from SHA-25674ee39e2ca1513c302aadd976a808e3f493fd9d5cde1ac38941e832f9739b47eto14606da2d9c15334427ca120701f52da11d48878345e059ce319d4f333ad907b. - Updated fleet check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-canary-20260915.json, SHA-256869bc0ed7cafc2b37efe9522bcaea09b01ca612f94767dcdcc5f20ed94fc2885. - Updated automation
/Users/richh/.codex/automations/finish-tyrell-build-16/automation.toml, SHA-256a7d744f85a10aab2d397ab268e8bf22aac699d40cafb3e02e2bd8889820c12d6. - Coordination milestone: fleet message
20260916-220001-62E38515. - AGY work is complete at RTTy commit
c723b4f2b74f131272c832e134354b6e0a184a0e; the original parent is gone and must not be resumed again.
Undo and recovery
The deployment harness retained the exact previous Build 17 app and
Build 15 daemon on every host, plus a pre-deploy database backup that
independently passed quick_check. The canary guard
automatically restores those exact identities on a guard, identity,
power, lid, or product failure. For another host, use the retained
host-specific rollback paths and receipts in the canonical release
evidence; verify app/daemon hashes, one process each, both status
planes, database integrity, and launchd autoload after rollback. Do not
restore or overwrite a live database unless integrity or migration
evidence specifically requires it.
A laptop power or lid event is an environmental canary interruption and does not by itself authorize fleet rollback. A reproducible product or identity failure on the exact Build 26 artifacts requires a coordinator classification and then rollback using the retained per-host payloads.
Outstanding work
- Let the unchanged guard reach and independently verify the short, six-hour, and fixed 24-hour gates.
- Keep
ISSUE-20260912-01,ISSUE-20260909-12, andISSUE-20260914-15open until their actual criteria are met. - Do not merge or cut a future release from current
mainwhileISSUE-20260915-18remains open; Build 26 was cut from the approved lineage-complete base. - Delete the monitor automation only after legitimate Build 26 completion or definitive rollback closeout.