rdmsm4x - build - RTTy 524 Standard trust chain re-pinned 157-188 - claude - TASK-20260925-15 - RTTy - 2026-09-25 1933 EDT
HANDBACK — TASK-20260925-15 RTTy 524: register 8 Standard sources + re-pin the Standard trust chain
[2026-09-25 19:31:54 EDT · rdmsm4x] · claude@rdmsm4x/97f5c581 (headless, dispatched by grok@rdmsm4x/fleet-wd). Work ran from 19:28:25 to 19:32 EDT.
Status: DONE on
grok/524-standard-trust. Not merged to main or
grok/524-integrate. No version bump, no qa_release.sh or
build_and_run.sh, no App Store Connect, no notarize. The
522 freeze (TASK-20260925-01) still holds.
Where it is
- Worktree:
/Users/richh/dev/_scratch/rtty-524-standard-trust-20260925. Branchgrok/524-standard-trust, forked fromgrok/524-integratea5c3398. - One commit:
190a271eeab970e4d9afba8073d140e2e7f9d566, pushed tobackupwithout force.git ls-remote backupreturns the same SHA. Nothing was pushed to origin or fleet. - The commit touches the same 9 files as the pattern commit
9d6785d(+141 / −22), staged by explicit path. The worktree is clean afterwards.
What
was done (the procedure in
docs/release/RELEASE-PROCEDURE-RTTy.md §1, steps 1–8)
| Step | Result |
|---|---|
1–2 project.yml + StandardSources.txt |
3 RTTy files were added to both files at the same relative position:
Stores/ObservationStore+FriendlyVerdict.swift and
Stores/ObservationStore+UsageProfile.swift after
ObservationStore.swift, and
Views/UsageProfileSettingsSection.swift after
SettingsView.swift. StandardSources.txt went from 75 to
78 lines, and the project.yml app-target sequence diffs
identical to it. The 5 LatencyCore files were added to the project.yml
LatencyCore target in alphabetical position
(Profiles/CustomServiceProfileManager,
Profiles/DiscoveredProbeKey,
Profiles/UsageProfile,
Verdict/ApplicationCheckSummary,
Verdict/NetworkVerdict). LatencyCore is taken whole, so it
has no StandardSources.txt entry. |
| 3 xcodegen 2.46.0 | rc 0. The pbxproj gained 41 lines (4 references per file). No other file was touched: no Info.plist or scheme changes. |
| 4 pins | EXPECTED_COMPILER_INPUT_COUNT 149 →
157 and EXPECTED_BUILD_INPUT_COUNT 180 →
188, in both standard_project_graph.py and
standard_archive_validator.py, each with a ledger entry
that gives the source commit of every file (1481739, 390ad31, 656b44a,
e8c89d1, 8ecd722). standard_candidate_closure_test.py pins
changed to (79, 69, 1, 8) / 157. |
| 5 source policy | standard_source_policy.py --path <f> returned
rc 0 for all 8 files. As a negative control, a scratch
file containing Process() returned rc 1 ("Foundation
Process"). |
| 6 render-graph | Rendered into scratch and diffed. The only changes are the 8 files, the counts, and the hashes of project.yml, the pbxproj, StandardSources.txt and the template. The Release.xcconfig, scheme and workspace hashes are unchanged, so there is no version drift. The template pbxproj and graph were copied in. |
| 7 verifier bundle | standard_verifier_bundle.py render output was 4330
bytes and 26 entries. A second render and a third render were
byte-identical: a fixed point. Bundle sha256 is
9016178d3f7e404eaf264d3bce6ad2b587fdabfd246deee54410d5d8d312bb6d. |
Tests — rc and counts, not "green"
| Test | Before (a5c3398) | After (190a271) |
|---|---|---|
python3 Tests/ScriptTests/standard_source_reference_closure_test.py |
rc 1 (5 LatencyCore files missing) | rc 0: 78 allowlisted, 13 Direct-only, 69 LatencyCore registered |
python3 Tests/ScriptTests/standard_pbx_source_closure_test.py |
rc 1 | rc 0: every Standard PBX Sources phase matches its projection |
python3 Tests/ScriptTests/standard_candidate_closure_test.py
(materializes HEAD) |
rc 1 (got 76/69/1/8) | rc 0: 157 compiler inputs |
standard_frontend_input_closure_test.py,
standard_project_test.sh,
standard_archive_manifest_test.py,
standard_launch_capability_policy_test.py,
standard_source_policy_adversarial_test.py (67 caught / 9
controls), standard_source_policy_alias_test.py,
standard_snapshot_lifecycle_test.py,
standard_app_intents_metadata_test.py |
— | rc 0 (8 of 8) |
git diff --check |
— | clean |
Three tests fail both before and after this change. None was caused by it:
standard_trust_entry_policy_test.pyandarchive_standard_policy_test.shboth report "installed stable Python interpreter bytes differ from the trusted graph", with rc 1 on an export of the basea5c3398too. The graph pins the/usr/bin/python3real path from the Xcode 26.6 toolchain, and this host currently runs Xcode 27. This is environmental, and the release runbook's 26.6 swap (§0) is what satisfies it. This commit did not change the graph'stoolchainblock.mobile_pbx_source_closure_test.pyfails becauseApps/RTTyMobile/App/RTTyCloudKitRoundTripProbe.swiftis not in the reviewed Mobile entry points. That file was added by2cd3c60, which is already on main. This commit's diff against a5c3398 underApps/RTTyMobileis empty. It belongs to whoever owns the iOS debug probe, not to this ticket.
Not done (out of scope or release-time work)
- Launch-capability policy re-render (runbook §2). It
needs a 26.6 archive of the candidate. The 8 new files add SwiftUI
surfaces (the Settings section and the verdict), so expect new symbols.
Grep the delta for
Process|NSTask|posix_spawn|popen. This is a release-time step, done with the bump after the freeze lifts. - No Standard xcodebuild compile was run: no gate and no archive, per the hard rules. The closure tests prove registration and closure. They do not prove the Store target compiles under Xcode 26.6.
- Merging
grok/524-standard-trustintogrok/524-integrate/ main is the lead's job. It is a single commit on top of a5c3398, so it fast-forwards onto integrate.
Scratch left behind (tmp, not repo)
/private/tmp/rtty-524-stdtrust-render-193026 (the
rendered graph), /private/tmp/rtty-524-base-a5c3398 (the
base export used for the before/after runs),
/private/tmp/rtty-srcpol-negctl-39437 (the negative
control).