rdmpw3275m-changelog-20260917-0205-tyrell-build26-r3-rejection-r4-launch
rdmpw3275m-changelog-20260917-0205-tyrell-build26-r3-rejection-r4-launch
Tyrell Build 26 post-deploy R3 was correctly rejected by the unchanged physical-footprint-v2.1 short gate and automatically restored the exact stable Build 17 app plus Build 15 daemon; the finding is now tracked by ISSUE-20260917-01. A distinct R4 was then launched on rdmbair15m5 from the verified rollback baseline with every acceptance clock reset to zero, unchanged policy, fail-closed rollback protection, and immutable launch evidence on the canary, coordinator, and canonical host.
Scope
- Coordinator and diagnostics: rdmpw3275m.
- Designated rollback-protected canary: rdmbair15m5.
- Canonical evidence and ticket authority: rdmsm4x.
- The five non-canary Build 26 installations were inspected read-only and were not changed.
- Local AGY sessions were inspected read-only. All tracked work remains terminal or safely contained; no AGY session was resumed or killed.
R3 rejection and bug record
- R3 stage:
/Users/richh/.tyrell/build26-postdeploy-r3-20260917-002550-40145fdon rdmbair15m5. - The fail-closed guard rejected R3 with reason
physical footprint growth exceeds policy limitand restored exact Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05eplus Build 15 daemon SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Independent deterministic recomputation used 31 contiguous post-warmup samples over 1800.3401568 seconds: physical footprint 33.9076 MiB to 40.9232 MiB, endpoint growth 0.233809982 MiB/min and least-squares slope 0.277428714 MiB/min against the unchanged 0.20 bound.
- The final ten minutes were flat at 0.008678 MiB/min endpoint growth and 0.010036 MiB/min slope. vmmap and footprint agreed, while live allocation count and allocated malloc decreased. This weakens an ongoing-leak interpretation for the R3 short window but does not invalidate the gate rejection.
- Stable rollback verification passed: one app, one menu-bar helper,
one stable-path daemon, no guard/sidecar/assertion, recovery service
absent, normal service enabled, both APIs HTTP 200 with valid JSON, and
database
PRAGMA quick_check=ok. - Existing high-severity ticket
ISSUE-20260917-01was claimed, moved to in-progress, enriched with the independent evidence, and linked to allocator issueISSUE-20260912-01. A separate comment onISSUE-20260912-01records the rdmpw3275m large-corpus observation without claiming common causality. - Frozen failure evidence:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-r3-short-gate-failure-20260917-0123; snapshot manifest SHA-256d77873604981b0ff3270cad5c190413a48b6f4f4ef1511362f777bbef7f2158f; recursive SHA-256ef6424ebaa1742249dada09e689433c5efd95420a110ba31cd499cd3af7b45f8. - Canonical diagnosis packet:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-r3-short-gate-diagnosis-20260917; recursive SHA-25685447d6dd690d52194ca635232b88c6344701e6ed53f16f926d2aa88197f8042, 9 files, 2 directories, 243,973 bytes.
R4 preparation and launch
- Local packet:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r4-launch-20260917-014653. - Canary stage:
/Users/richh/.tyrell/build26-postdeploy-r4-20260917-014653-40145fd. - Deployment nonce:
tyrell-b26-r4-20260917T054653Z-40145fd. - Source packet and remote copy matched recursive SHA-256
cb765ef7ffe3febe7f624e991066ab7794ffd38d7e4ff4ee45415427434cc0e2, 25 files, 3 directories, 31,937,993 bytes before runtime state was created. - The first preparation attempt exited before any snapshot or install
because the canary Claude harness temporarily owned an unrelated
five-minute
caffeinateprocess. The process owner was contacted; it expired naturally. No peer process was killed and no Tyrell state changed in that failed attempt. - The successful preparation passed 5 power-envelope tests, 9 reboot-interlock tests, 30 libproc iterations with zero lsof calls, launcher identity pins, zsh syntax, allocation attribution self-test, disposable launchd-disable integration, a real assertion self-test, exact Build 17/15 rollback preparation, database backup validation, and candidate launch preflight.
- Exact signed Build 26 app probe SHA-256:
adaf025e12e5cfc4a3ce55b20914b485177fd136b9ad0c1da47862a89f3d908c. - Nonce-specific app receipt SHA-256:
b5aa8a628aefe22f67bca445f5c1de3ce647d341b46b4589dede3ff937e27415. - Unchanged policy SHA-256:
5300fa4f488150a20ec9604af914efe46822087f921906c18eca748c0e6a5da9. - R4 started at epoch 1789624673.448512, 2026-09-17 01:57:53 EDT.
Exact process identity: guard PID 78016, diagnostic sidecar PID 78090,
guard-owned
caffeinateassertion PID 78091, candidate daemon PID 78205, daemon process start Thu Sep 17 01:57:52 2026. - The reboot/guard-loss interlock is armed, recovery sentinel loaded,
and the normal daemon LaunchAgent disabled only for the already loaded
candidate. App executable SHA-256 is
75d41b417c393fb71ee9483836dcf1397236f207a2919faeabb3e74e9c1e9d2c; daemon SHA-256 isa4f43d83eb69113ed05d22b8f0b8521e09f71cd3475857e21d89e2572efea6e4. - The first two samples retained one PID and process-start identity with a 60.061155-second gap, AC power, closed clamshell permitted by the exact verified assertion, both status APIs HTTP 200 valid JSON, and inventory pass 1 completed by sample 2. At 02:01:54 EDT, sample 5 remained healthy at elapsed 240.770788 seconds, 25,560,336 physical bytes, 26 descriptors, TCP 2.
Immutable R4 evidence
- Canary:
/Users/richh/.tyrell/verification/tyrell-build26-r4-launch-evidence-20260917-014653. - Coordinator:
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build26-r4-launch-evidence-20260917-014653. - Canonical:
/Users/richh/dev/_handoff/tyrell-build26-release-20260916/postdeploy-r4-launch-evidence-20260917-014653. SNAPSHOT-MANIFEST.sha256file SHA-256:97589280e3752b4d9a0bc83b03d08d89af90c9e47ed3ed356aab33fe6724b9df.- All three copies independently matched recursive SHA-256
88f6d3d76a7395a93ca2de96828b9f1c66985eddb582e207a6df743f5e300188, 68 files, 17 directories, zero symlinks, 155,728,622 bytes. shasum -a 256 -c SNAPSHOT-MANIFEST.sha256passed on the coordinator copy.
Commands and durable coordination
- Prepared R4 with
/bin/zsh /Users/richh/.tyrell/build26-postdeploy-r4-20260917-014653-40145fd/r4_prepare_and_validate.zsh. - Launched the protected guard with
launch_guard_power_protected.zshunder redirectednohup; the launcher became the exact Python guard and created its own directly boundcaffeinatechild. - Verified runtime with
r4_status.zsh, exact process ancestry, launchd state, hashes, both HTTP planes, database quick check, power assertion, interlock state, and sample continuity. - Froze launch evidence with
freeze_r4_launch_evidence.zshpinned to guard 78016, daemon 78205, and assertion 78091. - Used the
ticketCLI for claim, comments, and the relationship betweenISSUE-20260917-01andISSUE-20260912-01. - Updated heartbeat automation
finish-tyrell-build-16; automation TOML SHA-256f6851134a096e54474d0de89221858f3a23165d5e6f92cfa98190c957794bfe9. - Updated coordinator check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-tyrell-build25-canary-20260915.json, synchronized it from the canonical hub, and verified identical content on all six hosts. The check-in is intentionally updated again at later gates, so this changelog does not pin its mutable publication hash. - Coordination messages: launch handoff
20260917-015840-4F286891; temporary assertion-window request20260917-015212-D3165697; owner reply20260917-015318-3E57FF3D.
Recovery and undo
- Do not kill the R4 guard, assertion, sidecar, or daemon individually. The fail-closed guard owns rollback sequencing and verifies the complete snapshot before touching the live service.
- On a verified operator-directed rollback, run pinned Homebrew Python
3.14 against the active stage:
/opt/homebrew/bin/python3.14 /Users/richh/.tyrell/build26-postdeploy-r4-20260917-014653-40145fd/canary_guard.py rollbackon rdmbair15m5. This restores the exact retained Build 17 app and Build 15 stable daemon, re-enables the normal service, disarms the recovery interlock, and retains the compatible live database. - If identity or rollback-preflight checks fail, stop and preserve state. Never overwrite an unknown stable artifact or bypass the recovery sentinel.
Outstanding gates
- Short gate not before 2026-09-17 02:37:53 EDT.
- Same-process six-hour gate not before 2026-09-17 08:07:53 EDT.
- Fixed 24-hour gate not before 2026-09-18 01:57:53 EDT.
- All source, fleet, CPU, fresh-app, controlled-reboot, integration, and release criteria remain bounded by their existing acceptance rules. R4 launch is not a final release acceptance.
- Fleet rollback was not triggered. The five non-canary hosts remain on exact Build 26 and healthy; the separate rdmpw3275m large-corpus signal remains under evidence collection.
- AGY PIDs 18899 and 65024 are idle CLI prompts, not active work. There was no provider quota failure or reset boundary; no AGY resume is eligible.