rdmpw3275m-changelog-20260916-2343-tyrell-build26-r2-protected-canary-launch
rdmpw3275m-changelog-20260916-2343-tyrell-build26-r2-protected-canary-launch
Launched a distinct, zero-clock Tyrell Build 26 post-deploy R2 on
rdmbair15m5 after a fresh AC/open preflight; Build 26 is
now online on all six fleet Macs under a fail-closed canary guard while
the short, same-process six-hour, and fixed 24-hour gates remain
pending.
Scope
- Control and evidence authoring host:
rdmpw3275m. - Canary changed:
rdmbair15m5only. - Canonical evidence destination:
rdmsm4x. - The other five Build 26 hosts were observed read-only and were not restarted or modified.
- No Tyrell source file, Git ref, release branch, or predecessor evidence packet was changed.
- All local AGY conversations remain terminal or safely contained and were not resumed. The separate ramdisk one-writer reconciliation remains owner-controlled.
Why this changed
Build 26 post-deploy R1 was already closed as
environmental-inconclusive-before-short-gate after the
canary lid closed and the guard restored exact Build 17/15. At
2026-09-16 23:24:53 EDT, the canary owner reported the lid open on AC
with the rollback baseline untouched. R2 therefore started from a new
stage and a new deployment nonce, with no R1 sample or elapsed time
reused.
Changes
rdmbair15m5
- Created fresh live stage:
/Users/richh/.tyrell/build26-postdeploy-r2-20260916-233028-40145fd- static manifest SHA-256
56f8380506676086e33bdd853c1f2022d2a3b27c77b0c2a863fbd0a6bbe05ebd - zero dynamic gate files before preparation
- Captured an exact rollback snapshot in the R2 stage from the verified Build 17 app and Build 15 daemon.
- Installed and relaunched exact Build 26 app executable SHA-256
75d41b417c393fb71ee9483836dcf1397236f207a2919faeabb3e74e9c1e9d2c. - Retained the newly displaced Build 17 app at
/Applications/.tyrell-rollbacks/20260916-233309-2c5ca2a674fe/Tyrell.app. - Ran a fresh nonce-specific Build 26 app probe and acceptance receipt
using nonce
tyrell-b26-r2-20260917T033028Z-40145fd:- probe SHA-256
5e91140482b4bc5a9872627743d20aa471161dcd3925387d685bf716f388036f - receipt SHA-256
1aa1954b56bfc305bb4242b3f4cf3a32bcdcc1903398111297391d1da8170b41
- probe SHA-256
- Launched the pinned guard at 2026-09-16 23:33:54 EDT:
- guard PID
33224 - diagnostic allocation sidecar PID
33295 - guard-owned
caffeinatePID33296 - candidate daemon PID
33599 - daemon process start
Wed Sep 16 23:33:53 2026 - managed daemon target
/Users/richh/Library/Application Support/Tyrell/releases/daemon-a4f43d83eb69/tyrelld
- guard PID
- The guard disabled normal boot-time loading for the already-running unaccepted candidate, armed the persistent reboot/guard-loss recovery sentinel, and retained exact rollback inputs.
- Froze launch evidence at
/Users/richh/.tyrell/verification/tyrell-build26-r2-launch-evidence-20260916-2336.
rdmsm4x
- Copied and independently verified the frozen 68-file R2 launch
packet at
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-r2-launch-evidence-20260916-2336. MANIFEST.sha256SHA-256:0582c7a8ad7f7dffe9547ccadda0ecbd88be773bec2d74c084bf671b467c0397.- Every file listed in the manifest revalidated on the canonical host.
rdmpw3275m
coordination state
- Updated heartbeat automation
/Users/richh/.codex/automations/finish-tyrell-build-16/automation.tomlthrough the Codex automation API; SHA-256c95e135028ee447253aa53f3296577dee7d80d93080e22a0c8afa3af0cfc3d9a. - Updated check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-canary-20260915.json; pre-changelog coordination checkpoint SHA-2569746af1031d3178eca4fe44bef7fc113dc55a1898849ca9e6df16b6467b6e7b8. - Synced that pre-changelog coordination checkpoint exactly to all six Macs; the later final check-in additionally records this changelog and its Apple Notes verification.
- Sent launch and independent-review notices in fleet messages
20260916-234210-632874BAand20260916-234211-E61CF6C7. - Independent canary-owner verification arrived in messages
20260916-234454-C48A51E4and20260916-234509-7D9EFB40; it reproduced exact Build 26 app/daemon identity, all four live process IDs, AC/open state, both HTTP 200 JSON status planes,soakingstate,physical-footprint-v2, and an armed interlock with no discrepancy.
Commands and procedures run
- Read-only six-host process, artifact, LaunchAgent, API, role, and SQLite identity checks.
- Fresh canary power, lid, residual-process, recovery-agent, stable-path, candidate-signature, and Gatekeeper checks.
- Pinned guard validation:
- allocation-attribution self-test
- launcher identity-pin test
- nine reboot/guard-loss interlock regression cases
- 30 live libproc samples with zero
lsofcalls - disposable launchd disable/re-enable integration test
canary_guard.py preflight,prepare,rollback-preflight, andlaunch-preflight.- Signed app installation through the pinned
install_app_local.zshhelper. - App-driven usage/chat probe and nonce-specific receipt generation.
- Guard launch through
launch_guard_power_protected.zsh. - Frozen evidence creation, content manifest generation, transfer to
the canonical handoff directory, and canonical
shasum -cvalidation. - Check-in synchronization through
/Users/richh/dev/fleet/maintenance/scripts/fleet_checkin_sync.zshonrdmsm4x.
Verification evidence
- Fresh baseline before mutation: exact Build 17 app and Build 15
daemon; one
Tyrell, onetyrellbar, and onetyrelld; managed LaunchAgent path; ports 43117 and 43118 HTTP 200 valid JSON with client role; live databasePRAGMA quick_check=ok; AC power; open clamshell; no active guard, sidecar, recovery plist, or canarycaffeinateprocess. - R2 launch verification: exact Build 26 app and daemon; one
app/bar/daemon; both status planes HTTP 200 valid JSON; database
quick_check=ok; AC/open; recovery interlock armed; normal service disabled only for the already-loaded candidate PID. - Frozen launch packet: four samples through 180.673 seconds, same PID/start/path, physical footprint 32,326,928 bytes at the frozen latest sample, 26 descriptors, two TCP descriptors, inventory pass 1 complete, and no status or permission-plane error.
- Subsequent live observation through 360.681 seconds retained daemon
PID
33599, physical footprint 48,317,712 bytes, 26 descriptors, two TCP descriptors, AC/open, and both APIs healthy. - Startup peaks before the ten-minute warm-up remain diagnostic and are not acceptance verdicts.
- At 23:44:54 EDT,
claude@rdmbair15m5independently reproduced exact Build 26 app/daemon identity, live guard/sidecar/caffeinate/daemon PIDs33224/33295/33296/33599, AC/open state, both HTTP 200 JSON status planes,soakingstate,physical-footprint-v2, and an armed interlock with no discrepancy. - Six-host pre-changelog coordination checkpoint SHA-256 matched
exactly:
9746af1031d3178eca4fe44bef7fc113dc55a1898849ca9e6df16b6467b6e7b8.
Rollback and recovery
- The guard owns automatic rollback on product, identity, power, lid, reboot-boundary, guard-loss, or stale-heartbeat failure.
- Exact app rollback is inside the R2 stage and retained at
/Applications/.tyrell-rollbacks/20260916-233309-2c5ca2a674fe/Tyrell.app. - Exact daemon rollback remains
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld, SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Pinned compatible database backup remains
/Users/richh/Library/Application Support/Tyrell/backups/20260916-213016-40145fd/tyrell.db, SHA-256da19f5c4a7d227ca9acd55a7a78637e9151da315191c3bd2c3ba6fbad994cff2. - If a bounded operator rollback is required, use the stage's
documented
canary_guard.py rollbackentry point with$(brew --prefix)/bin/python3.14; do not kill the guard or candidate manually.
Outstanding gates and owner actions
- Short gate target: approximately 2026-09-17 00:13:54 EDT.
- Same-process six-hour gate target: 2026-09-17 05:43:54 EDT.
- Fixed 24-hour gate target: 2026-09-17 23:33:54 EDT.
- Each gate requires frozen evidence and independent verification. R1 remains immutable and contributes no elapsed time.
ISSUE-20260912-01,ISSUE-20260909-12, andISSUE-20260914-15remain open until their exact criteria are met.- Do not merge the Build 26 release branch into
mainor resolveISSUE-20260915-18from soak evidence;mainremains ancestry-incomplete for future cuts. - The separate ramdisk divergence remains preserved for canonical-owner reconciliation; no Tyrell heartbeat may mutate it or resume the terminal AGY conversations.