rdmpw3275m-changelog-20260917-0039-tyrell-build26-r3-envelope-launch
Tyrell Build 26 post-deploy R3 is now soaking on
rdmbair15m5 under the fail-closed physical-footprint-v2.1
envelope, which permits the closed clamshell only while AC power, the
exact guard-owned PreventSystemSleep assertion, and bounded
60-second sample continuity are all independently verified.
Scope and reason
- Coordinator and evidence host:
rdmpw3275m. - Canary runtime host:
rdmbair15m5. - Canonical evidence destination:
rdmsm4x. - R2 automatically and cleanly restored the exact Build 17 app and Build 15 daemon at approximately 00:02 EDT after the lid closed. Its 28 samples ended before the short gate, so R2 is environmental-inconclusive and contributes no time to R3.
- Two lid-only aborts produced no product-defect signal.
DEC-20260917-01chose option A: measure the actual safety properties—AC power, a guard-owned system-sleep assertion, and sample continuity—rather than treating lid position itself as the acceptance property. - The original offline defect remains fixed under resolved
ISSUE-20260905-23: the managed LaunchAgent targets a retained hash-addressed release through~/Library/Application Support/Tyrell/bin/tyrelld, not mutable SwiftPM.buildoutput.
Files and state changed
Local coordinator sources were created or updated under:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/canary_guard.py/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/launch_guard_power_protected.zsh/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/policy.json/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/test_launcher_identity_pins.py/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/test_power_envelope_v21.py/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/r3_prepare_and_validate.zsh/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/r3_status.zsh/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/freeze_r3_launch_evidence.zsh/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-envelope-v21-20260917/STATIC-MANIFEST.sha256
The fresh canary stage is
/Users/richh/.tyrell/build26-postdeploy-r3-20260917-002550-40145fd.
R1 and R2 stages were preserved and never reused. The R3 static manifest
contains 25 pinned entries and has SHA-256
17bc3a6d224c31936d3a118b6dbb292edf64411e6f6a81db5b5cf73ce222a6da.
Runtime changes on rdmbair15m5:
/Applications/Tyrell.appis exact Build 26 executable SHA-25675d41b417c393fb71ee9483836dcf1397236f207a2919faeabb3e74e9c1e9d2c.~/Library/Application Support/Tyrell/bin/tyrelldresolves to exact Build 26 daemon SHA-256a4f43d83eb69113ed05d22b8f0b8521e09f71cd3475857e21d89e2572efea6e4.- Guard PID
83629, assertion PID83701, and daemon PID83826launched with every R3 acceptance clock at zero. - The normal daemon LaunchAgent is disabled only as the reboot interlock for the already-loaded candidate. The persistent recovery sentinel is armed and will restore the exact predecessor if the guard, assertion, AC envelope, sample continuity, boot identity, candidate identity, or health checks fail.
- Fresh app deployment nonce:
tyrell-b26-r3-20260917T042550Z-40145fd.
Commands and validation
The work used pinned SSH to the canary,
shasum -a 256 -c, the stage's focused Python tests,
zsh -n, the disposable launchd-disable test, a real
caffeinate/pmset assertion test, exact app
lifecycle scripts, a fresh app usage/chat probe and receipt,
sqlite3 -readonly ... PRAGMA quick_check, both localhost
status APIs, launchctl print,
pmset -g assertions, ps, and the stage's
deterministic recursive-manifest tool.
Verified results:
- Static file hashes matched on the canary before mutation.
- Power-envelope unit tests: 5/5 passed.
- Reboot-interlock unit tests: 9/9 passed.
- Launcher identity pins and shell syntax passed.
- Disposable launchd disable/enable integration passed without touching Tyrell's production service.
- Libproc guard probe: 30/30 iterations, zero
lsofcalls, exact Build 15 baseline path, descriptors 27, TCP 2. - Allocation attribution self-test passed.
- One early combined diagnostic batch observed a transient assertion-discovery failure; the subsequent direct diagnostic passed, ten consecutive real assertion tests passed, the fail-closed preparation script passed its own required assertion test, and the live guard has verified the exact assertion continuously. The failed diagnostic did not launch or accept a candidate.
- Fresh Build 26 app probe passed decoded fleet usage plus
authenticated chat message/page/command; probe SHA-256
e43be99157ef9828735c13bffa01965a7ea28caba645a1eff5235e483b322bdb. - Fresh canary receipt passed; receipt SHA-256
baff556b1698b1b07382cec27e36a9c86a8d130d9532ea1a84c0aaaed288352d. - R3 launch state is
soaking; the reboot interlock is armed; one app, one bar, and one daemon are live; both status APIs are HTTP 200 valid JSON; live databasequick_checkisok. - The first two live samples used the same daemon PID, landed
60.050558 seconds apart, saw AC plus closed clamshell plus exact
assertion PID
83701, and returned HTTP 200 on both status planes. The second sample completed inventory pass 1. - The early 444,466,784-byte physical-footprint sample is inside the documented ten-minute diagnostic warm-up and is not a gate verdict.
DEC-20260917-01is resolved with option A. An independent Claude read-only check on the canary reproduced the live R3 identities, power/assertion envelope, API health, and soaking state.
Frozen evidence and backups
- Canary snapshot:
/Users/richh/.tyrell/verification/tyrell-build26-r3-launch-evidence-20260917-0037. - Coordinator snapshot:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r3-launch-evidence-20260917-0037. - Canonical snapshot:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-r3-launch-evidence-20260917-0037onrdmsm4x. - All three copies verify against
SNAPSHOT-MANIFEST.sha256SHA-256dac41742effcc467d1f5ab276de4eef1b9ee9412066364773343a5baff4a6af3. - Snapshot contents: 76 files, 17 directories, zero symlinks,
155,751,393 bytes; deterministic recursive digest
cbd0c2b152dbdcf527c8b23f9f6f55bbfd5d9c0d45ae53a839e3f213318272b4. - Exact rollback payload is retained inside the active stage under
prior/: Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e, Build 15 daemon SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, prior LaunchAgent plist, and pinned compatible database backup/Users/richh/Library/Application Support/Tyrell/backups/20260916-213016-40145fd9/tyrell.db.
Undo and outstanding gates
Safe rollback command on the canary is:
PYTHONDONTWRITEBYTECODE=1 /opt/homebrew/bin/python3.14 /Users/richh/.tyrell/build26-postdeploy-r3-20260917-002550-40145fd/canary_guard.py rollback
The guard normally performs this automatically. A successful rollback restores the exact Build 17 app and Build 15 daemon, re-enables normal launchd loading, removes the active recovery marker/plist, verifies both APIs, and records the terminal state. Do not delete R1, R2, R3, rollback, receipt, or evidence directories while monitoring remains active.
Outstanding acceptance gates are intentionally not claimed: the short
gate is expected after approximately 01:15 EDT, the same-process
six-hour gate after approximately 06:45 EDT, and the fixed 24-hour gate
after approximately 00:35 EDT on 2026-09-18. Fleet promotion is already
complete under DEC-20260916-04; final acceptance,
controlled-reboot proof, ticket closeout, release-branch integration,
and automation deletion remain gated on their own explicit evidence.
Local AGY work remains terminal or safely contained. No provider quota failure or reset boundary occurred, so no AGY conversation was resumed and none should be resumed by the Tyrell monitor.