rdmsm4x - implementation - Tyrell and ReplicantDB defaults - codex - FEAT20260927 25 - Tyrell ReplicantDB - 20260927-1557
Local source defaults and focused safety tests were committed on isolated task branches. Automatic XEntropy broker integration remains for the collector owner.
FEAT-20260927-25 — permissive defaults implementation handback
Started 2026-09-27 15:34:17 EDT; handback finalized 2026-09-27 15:57:44 EDT on rdmsm4x.
Source/test work committed locally; requirement 3 (automatic XEntropy broker integration) remains incomplete. No merge, push, signing or deployment. Both task worktrees are clean.
Scope and state
Implementation is confined to two isolated
codex/permissive-defaults-20260927 branches:
- Tyrell:
/Users/richh/dev/_worktrees/tyrell-defaults-20260927, base85b5ddaaf68d338ab9a91849091660d5c4f5262a. - ReplicantDB:
/Users/richh/dev/_worktrees/replicantdb-defaults-20260927, baseff76a0028471b3251d4b89d18867c1a74801470f. Created a companion linked worktree; canonical source was clean before work.
No merge, push, deployment, signing, main checkout edit, installed preference mutation, live home scan, real browser access, or credential-value collection was performed. Existing explicit choices remain effective; these are source defaults, not a forced migration of saved settings.
Money, deletion and messages sent as Rich require explicit
approval and must never auto-perform. Browser-cookie reading stays
off. The queue enforces this before ambient modes and
remembered allowlists. For these requests, even an older UI action
requesting permanent consent is normalized to one-time consent. Generic
fileChange includes deletion and generic MCP/command calls
can spend or send: requests whose effects cannot be proved safe require
a fresh decision, including in fullAccess. Tests cover
purchase/send MCP calls, deletion, destructive shell variants, command
substitution, and allowlist reuse. This policy does not claim to police
independent applications or a caller that mislabels an operation as a
file read.
Implemented behavior
- Tyrell inventory and worktree observation default to
~/; task/offload working-directory fallbacks also use~/. Explicit configured roots still win, including an explicitly empty list. Database, store, registry and provider-specific source locations remain purpose-specific, rather than being moved to the home root. - ReplicantDB scan/watch roots default to home; consolidation's
initial target is
~/. The UI no longer claims that scanning/watch activity is restricted to~/dev. - A fresh approval queue automatically approves classified safe
requests and records
policy_default_autoin SQLite, without entering the pending queue. Opting out at actor construction still works. Expired requests cannot be resurrected by automatic policy or allowlists. - Boot resume's standing-consent default, hub election, Google activity meter, ReplicantDB peer offload, and Finder tagging on explicit taxonomy edits are on by default. Google activity remains activity-only, never a fabricated percentage. An isolated test daemon retains election off unless its explicit test flag enables it.
- Expanded home scope keeps secret/auth/browser files ineligible for Tyrell hashing/transfer. ReplicantDB's Library exclusion is enforced at traversal and direct-root admission, separately from its database purge list. Existing Library rows are preserved.
Credential collection: precise limitation and next action
The checked-out base has no Tyrell credential-collection
opt-in/grant switch in
scripts/usage_collector.zsh, ECSQuotaKit's
vendor collector, or provider detection. The thin wrapper invokes the
quota reader unconditionally; provider discovery already auto-registers
detected sign-ins. The new fixture contract runs the wrapper with an
empty environment and a harmless fake quota executable, proving there is
no prerequisite grant flag without running any credential reader.
However, automatic XEntropy broker collection is not
completed or live-verified here. The base contains a manual
XEntropyImporter that calls secrets get-value
and stores a key through ProviderSecretSink; it is not a
values-free broker reference interface. Making that import automatic
would both overlap the explicitly reserved credential area and introduce
secret reads/persistence into this run. No new credential gate has been
added and none of XEntropy's own authentication or lock boundaries has
been bypassed.
Exact next action: the tyrell-usage-contract owner must
expose/identify its broker-backed collector integration and
default-allow contract, then apply the same absent-setting-is-enabled
policy at that integration point with injected broker metadata fixtures.
Verify zero Tyrell grant prompts and zero cookie access. Keep broker
authentication and unavailable/locked/error states truthful. The lead
should reconcile this handback with that owner's collector tests before
calling requirement 3 complete. No inspection, checkout, merge or
modification of codex/usage-contract-20260927 was
performed.
Coordination and merge considerations
The parent FEAT lease remains with
tyrell@rdmsm4x/tyr0926; the implementation slice was
accepted by ticket comment under the explicit assignment. Preflight
reported 275 aging HIGH messages; no lease was stolen or force-claimed.
No subagents were spawned and no external counterpart was dispatched.
Worktree source changes were authorized directly by the user despite the
general delegated-worker handoff-only convention.
All existing Sources/TyrellCore/Providers/*,
Sources/TyrellCore/Credentials/*,
Sources/tyrelld/FleetUsage.swift,
scripts/usage_collector.zsh, and shared ECSQuotaKit sources
were left unchanged. New
Tests/ScriptTests/permissive_usage_defaults_test.zsh
exercises only the existing wrapper. The shared
SettingsView.swift change is one default literal in Resume;
if the credential work also touches that large file, preserve both
hunks. SESSION-STATE.md gets an additive task checkpoint.
No collector/usage-contract redesign is included.
Validation
ReplicantDB commit:
5606b7da5b3e48711d334380b1dc05c9f0255145 (9 intentional
files, clean task worktree).
ulimit -Sn 65536; nice -n 10 swift test --jobs 6 passed
1,561 XCTest tests, 0 failures, 233.575 s, exit 0
(replicantdb-full-final.log, matching .rc).
Its complete staged diff passed
gitleaks stdin --redact --no-banner, exit 0.
./build.sh was intentionally not run because it signs;
SwiftPM test compilation built the relevant targets.
Tyrell commit: 23dbe856d31aee56f62b77da0b9f12b63e6d3fe8
(24 intentional files, clean task worktree). Both commits carry the
installed Agent: trailer. Raw logs are in this handoff
directory.
| command | result | evidence |
|---|---|---|
Tyrell:
ulimit -Sn 65536; nice -n 10 swift test --jobs 6 |
exit 0; 649 XCTest reported, 5 skipped, 0 failures; 1,533 Swift Testing passed | tyrell-verified.log,
tyrell-verified.rc |
Tyrell: same limits,
swift test --jobs 6 --filter 'TyrellPermissionTableContractTests|PermissiveDefaultsTests|ApprovalRelayTests' |
exit 0; 5 XCTest + 18 Swift Testing passed, 0 failures | tyrell-final-focused.log, matching
.rc |
ReplicantDB:
ulimit -Sn 65536; nice -n 10 swift test --jobs 6 |
exit 0; 1,561 XCTest passed, 0 failures, 233.575 s | replicantdb-full-final.log, matching
.rc |
zsh Tests/ScriptTests/permissive_usage_defaults_test.zsh |
exit 0; no opt-in flags, fake reader invoked; missing-reader control returns 2 | collector-defaults-final.log, matching
.rc |
git diff --cached --check in each worktree |
exit 0 | reviewed explicit staged paths before each commit |
gitleaks stdin --redact --no-banner on each full staged
diff |
exit 0, no findings | tyrell-gitleaks-final.log,
replicantdb-gitleaks-final.log |
The five Tyrell skips are intentional: one unavailable launchd
descriptor-table probe, one opt-in real-Keychain test, and three opt-in
live-fleet endpoint probes. No opt-in was enabled. The full run reports
2,182 tests including those five skips (2,177 passed); ReplicantDB
reports no skips. The final focused run also recompiles and validates
the final permission-description wording after the full-suite build.
Shared sibling dependency identities at validation are retained in
shared-dependency-heads.tsv (33 app/dependency pairs). No
shared dependency or manifest was changed. Initial failed runs are
retained, not overwritten. Initial errors were stale test expectations
for changed defaults and a test incorrectly treating pending-only
rehydration as approved-history reload; the final test instead opens a
second SQLite connection.
No-prompt evidence from the passing focused approval test:
NO_PROMPT_PROOF approved=1 pending=0 supervisor_resolve_calls=0 durable_decider=policy_default_auto
The test submits a harmless file-read request to the real
ApprovalQueueActor, checks the pending route is empty,
checks its audit record, then reads the persisted decision through a
second SQLite connection. It does not invoke resolve, show
UI, attach a PTY, execute a command, or contact a provider. Full proof
is Tests/TyrellCoreTests/PermissiveDefaultsTests.swift.
The ReplicantDB home fixture contains an ordinary Documents file and a harmless cookie-named file under Library. A real indexer and temporary database must index the ordinary file, never call extraction for the Library fixture, reject a direct Library root, and preserve a previously indexed Library row. No production database is opened by the new tests.
Settings audit
Audit covers configuration models, persisted application settings,
approval/resume policy, provider settings, scanner/watcher defaults,
governor and shared quota/event-layer behavior.
tyrell-settings-inventory.txt and
replicantdb-settings-inventory.txt retain source search
results. Runtime state (loading, selected, streaming, cooling down,
released, incomplete, mock mode), capability facts and operation
arguments are not feature defaults and must not be changed to true.
Shared-library settings were inspected read-only; no shared library was
edited.
| setting | old default | new default | why |
|---|---|---|---|
| Tyrell inventory roots | Nine dev/agent/Documents roots | ~/ |
Home is the default inventory scope; explicit roots win |
| Tyrell observer worktree roots | ~/dev, ~/.tyrell/worktrees |
Home | Observe projects throughout the selected account's home |
| Tyrell task working directory | ~/dev |
~/ |
Coherent fallback folder |
| Tyrell fleet offload cwd | ~/dev |
~/ |
Coherent fallback folder |
| Tyrell rescan interval / minimum | 3600 s / 300 s | Unchanged | Bounded recurring home scans |
| Tyrell default master / project masters / fleet hosts / chat owner | Derived or explicit configuration | Unchanged | Host identities are topology, not folders or off feature gates |
| Tyrell DB/store/config/token paths | Application Support / TyrellStore / .tyrell |
Unchanged | Data storage destinations are not scan roots |
| Tyrell approval queue auto-approval | Allowlist only | On for classified safe requests | Goal-driven default with durable no-prompt decision |
| Approval timeout | 300 s | Unchanged | Expired actions must not execute |
| Protected/ambiguous operation approval | fullAccess and allowlists could bypass |
Fresh explicit approval | Money, deletion and Rich-sent messages never auto-perform; broad legacy kinds cannot distinguish safe effects |
| Explicit per-request approval flag | Not consulted | Honored | Producer can require a fresh decision on otherwise safe requests |
Tyrell resume alwaysAutoApprove core/UI |
false | true | Enable standing consent default; do not remove collision/pruning checks |
| Resume mode / cap / trigger | autoTopN / 3 / rebootOnly | Unchanged | Automatic resumption already enabled and bounded |
| Resume includeNonClaude | true | true | All supported harnesses included |
| Resume stale claim / live session threshold | 48 h / 300 s | Unchanged | Avoid duplicate live work |
| Hub election enabled | absent → false | absent → true | Enable discovery/failover; preserve explicit false and initial hub pin |
| Hub Bonjour / pin / seeds / advertise / host class | Bonjour on when enabled; others derived | Unchanged | Working discovery defaults; explicit topology remains honored |
| Isolated daemon election | off unless test flag | Unchanged | Safety exception: tests cannot start an unintended fleet election |
| Provider enabled switches | absent → true | Unchanged | Providers already enabled |
| Provider discovery/registration | Auto-detect existing sign-ins | Unchanged | No Tyrell grant gate found in this base |
| Usage collector invocation | Unconditional | Unchanged, fixture-proven | No opt-in or grant flags needed |
| XEntropy automatic broker collection | No automatic broker integration in base | Unchanged; incomplete | Reserved concurrent area; exact follow-up above |
| XEntropy compromised offers | Not selected | Unchanged | Safety exception: compromised material is not selected automatically |
| Browser-cookie reading | Off / not implemented for sign-in | Off | Explicit user exception; no cookie reading performed |
| Real Keychain tests | Off unless opt-in | Off | Test safety exception; real credential stores must not be touched |
| macOS privacy grants / login service status | Read from OS | Unchanged | Measured authorization state is not a false feature default; no TCC or account changes in this source task |
| Credential biometrics default | false | false | No additional Tyrell prompt gate; existing OS permissions remain real |
| Chat enableBroadcast / offerFiles | true / true | Unchanged | Features available; sending still requires an explicit send action |
| All notification categories | true | true | Attention features work by default |
| Menu-bar Google activity meter | false | true | Enable its display; retain activity-only evidence semantics |
| Other menu-bar meters / automatic cycling | true / true | Unchanged | Already functional |
| Pinned menu-bar meter | none | none | Automatic cycling remains active |
| Operations canary / parallel deploy / APFS checkpoint / FD checks | true | true | Existing functionality and protections remain enabled |
| Operations dryRun | false | false | Already permissive; this task performs no deploy |
| Operations strategy / canary timeout / sysmon interval / task threshold | canary / 15 s / 5 s / 10 | Unchanged | Preserve bounded operational defaults |
| Observer branch overlap / FSEvents | true / true | Unchanged | Observation already active |
| Transcript pressure/battery pause / bounded reads / cloud guard | Enabled | Unchanged | Safety/resource exceptions; no secret-bearing transcript migration |
| UI appearance / color profile / workspace / zoom / settings destination | System/current palette/last workspace/standard/general | Unchanged | Presentation choices do not disable features |
| First-run completed / chat-first-open timestamp | false / 0 | Unchanged | Lifecycle evidence, not a feature gate |
| Development-bundle launch override | false | false | Safety exception: installed-origin protection stays intact |
| ReplicantDB rootScanDirectories / daemon watcher roots | ~/dev |
Home | Shared config drives scanning and FSEvents |
| ReplicantDB consolidation default target / first preset | ~/Documents/Consolidated |
~/ |
Coherent default folder; no consolidation executed |
| Other consolidation target presets | Desktop/Archive; Downloads/Cleaned | Unchanged | Optional named destination presets remain useful |
| Collision policy | renameWithSuffix | Unchanged | Preserve both files by default |
| APFS copy-on-write / checksum verification | true / true | Unchanged | Enabled functionality and integrity protection |
| Cleanup source after transfer | false | false | Explicit deletion exception; never enable automatic removal |
| LAN Bonjour discovery | true | true | Already enabled |
| Peer AI offloading | false | true | Enable configured local/peer feature |
| Peer timeout / preferred AI engine / endpoint | 10 s / mlx / loopback 11434 | Unchanged | Bounded local defaults; no paid endpoint configured |
| LAN credential/privacy guardrail | Hard-locked true | Unchanged | Never export sensitive credential content |
| iCloud / Dropbox / Google Drive / OneDrive / Box / Proton / pCloud | true each | true each | Already enabled for supported local provider data |
| Cloud stub guard | true | true | Safety exception: never hydrate placeholders while indexing |
| External volume indexing | true in application default; false member initializer | true in both initializers | Coherent existing external-volume functionality |
| Backup / Time Machine auto-discovery | false | false | Safety exception: whole-machine backups can contain other accounts and credential/browser stores; broad safe admission is not proved here |
| Latest-only backup snapshots | true | true | Resource protection, useful duplicate results |
| Sparse-bundle band protection | Hard-locked true | Unchanged | Do not descend into raw image bands |
| Strict exact-match dedup | true | true | Safety exception: similarity must never justify automatic deletion |
| Variation detection | true | true | Already enabled alongside safe exact-match policy |
| Perceptual distance / minimum dimension | 10 / 128 | Unchanged | Detection thresholds do not disable the feature |
| GPS privacy | Hard-locked true | Unchanged | No raw location coordinates stored |
| WAL / auto integrity checks | true / true | Unchanged | Already enabled |
| Database busy timeout / footprint | 5000 ms / 3072 MB | Unchanged | Avoid lock stalls and runaway memory |
| Concurrent workers / thermal throttling / indexOnBattery / idleOnly | 4 / true / true / false | Unchanged | Indexing already active with resource protections |
| Governor enabled / honor fleet directives | true / true | Unchanged | Keep fleet resource arbitration effective |
| Governor thresholds / quiet hours / AC cap | Existing bounded thresholds / unset / unset | Unchanged | Resource policy, no disabled feature needing activation |
| Finder tags on explicit taxonomy edits | false | true | Complete the selected tagging feature; saved false still wins |
| ReplicantDB attention notifications | true each | true each | Service, permission and maintenance notifications already enabled |
| ReplicantDB chart/chip/background palettes / appearance / font scale | automatic / auto / automatic / system / 1.0 | Unchanged | Presentation defaults |
| ReplicantDB workbench / duplicate view / purpose view | corpusAtlas / list / cards | Unchanged | Presentation choices |
| Library scan exclusion | Outside default roots; Caches excluded | Explicit scan-only Library boundary | Retain recorded scope, prevent browser/auth reads, never purge historical rows |
| Tyrell secret exclusions | env/keychain/token/private-key patterns | Expanded auth/browser/config/key patterns | Home scope must not make auth or cookies transferable/hashable |
| ReplicantDB denied-path purge list | Existing credential and employer exclusions | Unchanged | Changing scan scope is not authorization to delete indexed user data |
| Drift baseline refresh / force / mock / runtime status fields | false | false | Commands and measured state, not disabled feature defaults |
Limits and review requirements
- This is source/test acceptance only. Canary, installed rendering, runtime migration, fleet rollout, full-home performance and broker credential collection are not claimed.
- The broad legacy file-change/MCP effects remain conservative because they lack typed non-destructive semantics. A future producer contract can distinguish safe edits from deletion and paid/outbound operations; do not restore blanket fullAccess/allowlist bypasses.
- Library remains excluded from content scanning despite the new home root. Existing historical rows remain untouched. Backup auto-discovery remains off until credential/cookie-safe admission can be proved.
- No saved explicit off setting is silently flipped. The old resume consent field is a configuration/UI preference; the no-prompt proof is the real approval queue, not a claim that the boot engine arbitrates all ambiguous resumes.
- Rollback is to retain these task branches/worktrees and have the lead omit or forward-revert their explicit commits after integration. No deployed state needs rollback.
Files changed, from committed objects
Tyrell — 24 files
SESSION-STATE.md
Sources/TyrellAppSupport/SettingsSupport/TyrellPermissionTable.swift
Sources/TyrellBarSupport/MeterModels.swift
Sources/TyrellCore/Approvals/ApprovalModels.swift
Sources/TyrellCore/Approvals/ApprovalQueueActor.swift
Sources/TyrellCore/ExclusionRules.swift
Sources/TyrellCore/Hub/HubRoleResolver.swift
Sources/TyrellCore/Mesh/FleetOffloadGovernor.swift
Sources/TyrellCore/Planning/TaskDAGScheduler.swift
Sources/TyrellCore/Resume/BootResumeEngine.swift
Sources/TyrellCore/Telemetry/FleetObserver.swift
Sources/TyrellCore/TyrellConfig.swift
Sources/tyrell-app/SettingsView.swift
Sources/tyrelld/HubRuntime.swift
Tests/ScriptTests/permissive_usage_defaults_test.zsh
Tests/TyrellBarSupportTests/MeterModelsTests.swift
Tests/TyrellBarSupportTests/MeterSettingsStoreTests.swift
Tests/TyrellCoreTests/ApprovalQueueAdversarialTests.swift
Tests/TyrellCoreTests/ApprovalQueueTests.swift
Tests/TyrellCoreTests/ApprovalRelayTests.swift
Tests/TyrellCoreTests/HubElectionSimulationTests.swift
Tests/TyrellCoreTests/M2_Challenger2_EmpiricalTests.swift
Tests/TyrellCoreTests/PermissiveDefaultsTests.swift
Tests/TyrellCoreTests/SessionHoldOrchestratorTests.swift
ReplicantDB — 9 files
SESSION-STATE.md
Sources/ReplicantDBCore/Config.swift
Sources/ReplicantDBCore/FileIndexer.swift
Sources/ReplicantDBCore/ReplicantDBPermissions.swift
Sources/ReplicantDBCore/ReplicantDBSettings.swift
Sources/replicantDB/ReplicantDBApp.swift
Tests/ReplicantDBTests/PermissiveDefaultsTests.swift
Tests/ReplicantDBTests/SettingsViewChallenger1StressTests.swift
Tests/ReplicantDBTests/SettingsViewTests.swift
Durable output and final authority boundary
Apple Notes publication is PENDING, because
launchctl managername returned Background. The
fleet-notes-publish skill explicitly says to retain the
file copy and report Notes pending in a headless session; no AppleEvent
or interactive account access was attempted. File copies are retained in
both ~/dev/LLM/Claude/changelogs/ (fleet core canonical
record) and ~/dev/LLM/Codex/changelogs/ (skill
requirement), with a seven-field title.
The Tyrell parent ticket is not resolved or released: its lead owns the lease and must reconcile the broker integration gap. No native account/task/session stores were copied. No credential, cookie or auth values were read for this task. No source/recovery worktree was removed. Money, deletion and Rich-sent messages still require explicit approval; browser-cookie reading remains off.