Fleet changelogs · dev.ecs0.net
rdmpw3275m-changelog-20260916-2201-tyrell-build26-release

Tyrell Build 26 fleet release and post-deploy soak

Tyrell 0.2.0 Build 26 was built from clean, lineage-complete source, fully tested, Developer ID signed and notarized, deployed with retained rollback to all six Macs, and independently verified online. The original tyrelld Offline incident is now closed as a stable-runtime-path defect. The first guarded post-deploy memory run ended safely before its short gate when the laptop lid closed: the canary restored exact Build 17/15, while Build 26 remains online on the other five hosts and under active monitoring.

Scope

Why tyrelld was Offline

The original outage was not an unexplained daemon crash. The per-user LaunchAgent referenced the mutable SwiftPM alias /Users/richh/dev/apps/Tyrell/.build/release/tyrelld. SwiftPM had rewritten that alias to .build/out/Products/Release, whose target later disappeared. After reboot, launchd could not spawn the executable and recorded exit 78 (EX_CONFIG); loopback ports 43117 and 43118 were therefore silent, so Tyrell.app correctly displayed Offline. Tailscale was also down during the original incident, but that was secondary because the app's local loopback health checks already failed.

The durable fix originated in commit 869503a: install a verified universal daemon into a retained hash-addressed release under ~/Library/Application Support/Tyrell/releases/, then atomically point the stable ~/Library/Application Support/Tyrell/bin/tyrelld link and LaunchAgent at it. Build 26 carries and exercises that lifecycle on all six hosts. Existing ISSUE-20260905-23 was the correct bug record, so no duplicate was filed; it was resolved after fresh six-host verification.

Build and artifact evidence

The first Aqua release wrapper correctly built, signed, and notarized both artifacts but then exited because it attempted to parse JSON with PlistBuddy. That evidence-only finalization defect was corrected to use a JSON parser. The accepted artifacts were not rebuilt or overwritten; the corrected finalizer revalidated source, dependencies, identities, signatures, notarization, and packaging. The original failed wrapper is retained as build-release-aqua.failed-v1.zsh; the corrected wrapper and finalizer remain beside it in the canonical release packet.

Deployment and verification

Minor operator-side orchestration errors were caught before causing product-state loss and are retained rather than hidden: an invalid hash validator in the first canary daemon attempt; a local quoting error after the hub daemon had already deployed; a verifier pipeline exit 141 caused by pipefail plus early awk; and a JSON-summary quoting error in the first warm-up evidence formatter. Each corrected rerun passed. No failed attempt changed the accepted artifacts or bypassed rollback.

Post-deploy soak R1

The exact fleet-deployed Build 26 daemon began a fresh protected soak on rdmbair15m5 at 2026-09-16 21:46:14 EDT:

No short, six-hour, or 24-hour Build 26 memory acceptance is claimed in this record. Build 26 remains installed and online on rdmsm4x, rdmpw3275m, rdmbair13m5, rdmpw3265m, and jdmbair13m5; only rdmbair15m5 is back on Build 17/15. The active Codex automation finish-tyrell-build-16 remains active at a 15-minute cadence. While the laptop lid is closed it monitors the five Build 26 hosts, including consecutive rdmpw3275m observations through inventory completion. It may start only a distinct R2 after a fresh fingerprint-pinned AC/open preflight, with a new stage and every gate clock at zero. Automation TOML SHA-256 after this correction: 55452836876d31cc9e62bed04a227163f303079c52d61dd80f015bedaa26fc34.

Bounded fleet footprint diagnostic

Two read-only fleet samples approximately 92 seconds apart found physical footprints of: rdmsm4x 196→196 MB; rdmbair15m5 106→106 MB; rdmpw3275m 631→631 MB; rdmbair13m5 33→33 MB; rdmpw3265m 132→131 MB; and jdmbair13m5 44→44 MB. All exact Build 26 PIDs remained continuous and their APIs remained healthy.

The 631 MB Intel observation is above the later canary ceiling, but it was flat across the bounded pair while a direct process sample placed the active thread inside ClientLoop.autoInventory / TyrellScanner.scan; the status plane still exposed an incomplete 22,348/256,402 inventory, and the mount-independent libproc probe found only 27 descriptors and two TCP descriptors. This is not evidence of the prior pipe leak and is not yet a memory-gate verdict. Existing memory ticket ISSUE-20260912-01 was updated; no duplicate bug or fleet rollback was triggered. The required follow-up is consecutive sampling through inventory completion and escalation only for sustained growth, post-inventory above-bound footprint, identity/endpoint failure, or an authoritative guard verdict.

The reusable read-only sampler is /Users/richh/dev/_handoff/tyrell-build26-release-20260916/sample-build26-fleet-footprint.zsh, SHA-256 e8fab8c8938601b48af7824a18e5dde525f50f8befc92d30d82e9f05bb48bcff. Sample logs: fleet-footprint-sample-a.jsonl SHA-256 ed32e1ef07e04a21cdd36fc3be5e84eb26ffa01984116c5fe375c84e97256c82; fleet-footprint-sample-b.jsonl SHA-256 e4542ad8050619145f9ac2d3dc4e1e661093b54b968d6745ad0e97bda9b1a2ff.

Files and records changed

Undo and recovery

The deployment harness retained the exact previous Build 17 app and Build 15 daemon on every host, plus a pre-deploy database backup that independently passed quick_check. The canary guard automatically restores those exact identities on a guard, identity, power, lid, or product failure. For another host, use the retained host-specific rollback paths and receipts in the canonical release evidence; verify app/daemon hashes, one process each, both status planes, database integrity, and launchd autoload after rollback. Do not restore or overwrite a live database unless integrity or migration evidence specifically requires it.

A laptop power or lid event is an environmental canary interruption and does not by itself authorize fleet rollback. A reproducible product or identity failure on the exact Build 26 artifacts requires a coordinator classification and then rollback using the retained per-host payloads.

Outstanding work

Durable-record receipt