Fleet changelogs · dev.ecs0.net
rdmsm4x - implementation - Tyrell and ReplicantDB defaults - codex - FEAT20260927 25 - Tyrell ReplicantDB - 20260927-1557

rdmsm4x - implementation - Tyrell and ReplicantDB defaults - codex - FEAT20260927 25 - Tyrell ReplicantDB - 20260927-1557

Local source defaults and focused safety tests were committed on isolated task branches. Automatic XEntropy broker integration remains for the collector owner.

FEAT-20260927-25 — permissive defaults implementation handback

Started 2026-09-27 15:34:17 EDT; handback finalized 2026-09-27 15:57:44 EDT on rdmsm4x.

Source/test work committed locally; requirement 3 (automatic XEntropy broker integration) remains incomplete. No merge, push, signing or deployment. Both task worktrees are clean.

Scope and state

Implementation is confined to two isolated codex/permissive-defaults-20260927 branches:

No merge, push, deployment, signing, main checkout edit, installed preference mutation, live home scan, real browser access, or credential-value collection was performed. Existing explicit choices remain effective; these are source defaults, not a forced migration of saved settings.

Money, deletion and messages sent as Rich require explicit approval and must never auto-perform. Browser-cookie reading stays off. The queue enforces this before ambient modes and remembered allowlists. For these requests, even an older UI action requesting permanent consent is normalized to one-time consent. Generic fileChange includes deletion and generic MCP/command calls can spend or send: requests whose effects cannot be proved safe require a fresh decision, including in fullAccess. Tests cover purchase/send MCP calls, deletion, destructive shell variants, command substitution, and allowlist reuse. This policy does not claim to police independent applications or a caller that mislabels an operation as a file read.

Implemented behavior

Credential collection: precise limitation and next action

The checked-out base has no Tyrell credential-collection opt-in/grant switch in scripts/usage_collector.zsh, ECSQuotaKit's vendor collector, or provider detection. The thin wrapper invokes the quota reader unconditionally; provider discovery already auto-registers detected sign-ins. The new fixture contract runs the wrapper with an empty environment and a harmless fake quota executable, proving there is no prerequisite grant flag without running any credential reader.

However, automatic XEntropy broker collection is not completed or live-verified here. The base contains a manual XEntropyImporter that calls secrets get-value and stores a key through ProviderSecretSink; it is not a values-free broker reference interface. Making that import automatic would both overlap the explicitly reserved credential area and introduce secret reads/persistence into this run. No new credential gate has been added and none of XEntropy's own authentication or lock boundaries has been bypassed.

Exact next action: the tyrell-usage-contract owner must expose/identify its broker-backed collector integration and default-allow contract, then apply the same absent-setting-is-enabled policy at that integration point with injected broker metadata fixtures. Verify zero Tyrell grant prompts and zero cookie access. Keep broker authentication and unavailable/locked/error states truthful. The lead should reconcile this handback with that owner's collector tests before calling requirement 3 complete. No inspection, checkout, merge or modification of codex/usage-contract-20260927 was performed.

Coordination and merge considerations

The parent FEAT lease remains with tyrell@rdmsm4x/tyr0926; the implementation slice was accepted by ticket comment under the explicit assignment. Preflight reported 275 aging HIGH messages; no lease was stolen or force-claimed. No subagents were spawned and no external counterpart was dispatched. Worktree source changes were authorized directly by the user despite the general delegated-worker handoff-only convention.

All existing Sources/TyrellCore/Providers/*, Sources/TyrellCore/Credentials/*, Sources/tyrelld/FleetUsage.swift, scripts/usage_collector.zsh, and shared ECSQuotaKit sources were left unchanged. New Tests/ScriptTests/permissive_usage_defaults_test.zsh exercises only the existing wrapper. The shared SettingsView.swift change is one default literal in Resume; if the credential work also touches that large file, preserve both hunks. SESSION-STATE.md gets an additive task checkpoint. No collector/usage-contract redesign is included.

Validation

ReplicantDB commit: 5606b7da5b3e48711d334380b1dc05c9f0255145 (9 intentional files, clean task worktree). ulimit -Sn 65536; nice -n 10 swift test --jobs 6 passed 1,561 XCTest tests, 0 failures, 233.575 s, exit 0 (replicantdb-full-final.log, matching .rc). Its complete staged diff passed gitleaks stdin --redact --no-banner, exit 0. ./build.sh was intentionally not run because it signs; SwiftPM test compilation built the relevant targets.

Tyrell commit: 23dbe856d31aee56f62b77da0b9f12b63e6d3fe8 (24 intentional files, clean task worktree). Both commits carry the installed Agent: trailer. Raw logs are in this handoff directory.

command result evidence
Tyrell: ulimit -Sn 65536; nice -n 10 swift test --jobs 6 exit 0; 649 XCTest reported, 5 skipped, 0 failures; 1,533 Swift Testing passed tyrell-verified.log, tyrell-verified.rc
Tyrell: same limits, swift test --jobs 6 --filter 'TyrellPermissionTableContractTests|PermissiveDefaultsTests|ApprovalRelayTests' exit 0; 5 XCTest + 18 Swift Testing passed, 0 failures tyrell-final-focused.log, matching .rc
ReplicantDB: ulimit -Sn 65536; nice -n 10 swift test --jobs 6 exit 0; 1,561 XCTest passed, 0 failures, 233.575 s replicantdb-full-final.log, matching .rc
zsh Tests/ScriptTests/permissive_usage_defaults_test.zsh exit 0; no opt-in flags, fake reader invoked; missing-reader control returns 2 collector-defaults-final.log, matching .rc
git diff --cached --check in each worktree exit 0 reviewed explicit staged paths before each commit
gitleaks stdin --redact --no-banner on each full staged diff exit 0, no findings tyrell-gitleaks-final.log, replicantdb-gitleaks-final.log

The five Tyrell skips are intentional: one unavailable launchd descriptor-table probe, one opt-in real-Keychain test, and three opt-in live-fleet endpoint probes. No opt-in was enabled. The full run reports 2,182 tests including those five skips (2,177 passed); ReplicantDB reports no skips. The final focused run also recompiles and validates the final permission-description wording after the full-suite build. Shared sibling dependency identities at validation are retained in shared-dependency-heads.tsv (33 app/dependency pairs). No shared dependency or manifest was changed. Initial failed runs are retained, not overwritten. Initial errors were stale test expectations for changed defaults and a test incorrectly treating pending-only rehydration as approved-history reload; the final test instead opens a second SQLite connection.

No-prompt evidence from the passing focused approval test:

NO_PROMPT_PROOF approved=1 pending=0 supervisor_resolve_calls=0 durable_decider=policy_default_auto

The test submits a harmless file-read request to the real ApprovalQueueActor, checks the pending route is empty, checks its audit record, then reads the persisted decision through a second SQLite connection. It does not invoke resolve, show UI, attach a PTY, execute a command, or contact a provider. Full proof is Tests/TyrellCoreTests/PermissiveDefaultsTests.swift.

The ReplicantDB home fixture contains an ordinary Documents file and a harmless cookie-named file under Library. A real indexer and temporary database must index the ordinary file, never call extraction for the Library fixture, reject a direct Library root, and preserve a previously indexed Library row. No production database is opened by the new tests.

Settings audit

Audit covers configuration models, persisted application settings, approval/resume policy, provider settings, scanner/watcher defaults, governor and shared quota/event-layer behavior. tyrell-settings-inventory.txt and replicantdb-settings-inventory.txt retain source search results. Runtime state (loading, selected, streaming, cooling down, released, incomplete, mock mode), capability facts and operation arguments are not feature defaults and must not be changed to true. Shared-library settings were inspected read-only; no shared library was edited.

setting old default new default why
Tyrell inventory roots Nine dev/agent/Documents roots ~/ Home is the default inventory scope; explicit roots win
Tyrell observer worktree roots ~/dev, ~/.tyrell/worktrees Home Observe projects throughout the selected account's home
Tyrell task working directory ~/dev ~/ Coherent fallback folder
Tyrell fleet offload cwd ~/dev ~/ Coherent fallback folder
Tyrell rescan interval / minimum 3600 s / 300 s Unchanged Bounded recurring home scans
Tyrell default master / project masters / fleet hosts / chat owner Derived or explicit configuration Unchanged Host identities are topology, not folders or off feature gates
Tyrell DB/store/config/token paths Application Support / TyrellStore / .tyrell Unchanged Data storage destinations are not scan roots
Tyrell approval queue auto-approval Allowlist only On for classified safe requests Goal-driven default with durable no-prompt decision
Approval timeout 300 s Unchanged Expired actions must not execute
Protected/ambiguous operation approval fullAccess and allowlists could bypass Fresh explicit approval Money, deletion and Rich-sent messages never auto-perform; broad legacy kinds cannot distinguish safe effects
Explicit per-request approval flag Not consulted Honored Producer can require a fresh decision on otherwise safe requests
Tyrell resume alwaysAutoApprove core/UI false true Enable standing consent default; do not remove collision/pruning checks
Resume mode / cap / trigger autoTopN / 3 / rebootOnly Unchanged Automatic resumption already enabled and bounded
Resume includeNonClaude true true All supported harnesses included
Resume stale claim / live session threshold 48 h / 300 s Unchanged Avoid duplicate live work
Hub election enabled absent → false absent → true Enable discovery/failover; preserve explicit false and initial hub pin
Hub Bonjour / pin / seeds / advertise / host class Bonjour on when enabled; others derived Unchanged Working discovery defaults; explicit topology remains honored
Isolated daemon election off unless test flag Unchanged Safety exception: tests cannot start an unintended fleet election
Provider enabled switches absent → true Unchanged Providers already enabled
Provider discovery/registration Auto-detect existing sign-ins Unchanged No Tyrell grant gate found in this base
Usage collector invocation Unconditional Unchanged, fixture-proven No opt-in or grant flags needed
XEntropy automatic broker collection No automatic broker integration in base Unchanged; incomplete Reserved concurrent area; exact follow-up above
XEntropy compromised offers Not selected Unchanged Safety exception: compromised material is not selected automatically
Browser-cookie reading Off / not implemented for sign-in Off Explicit user exception; no cookie reading performed
Real Keychain tests Off unless opt-in Off Test safety exception; real credential stores must not be touched
macOS privacy grants / login service status Read from OS Unchanged Measured authorization state is not a false feature default; no TCC or account changes in this source task
Credential biometrics default false false No additional Tyrell prompt gate; existing OS permissions remain real
Chat enableBroadcast / offerFiles true / true Unchanged Features available; sending still requires an explicit send action
All notification categories true true Attention features work by default
Menu-bar Google activity meter false true Enable its display; retain activity-only evidence semantics
Other menu-bar meters / automatic cycling true / true Unchanged Already functional
Pinned menu-bar meter none none Automatic cycling remains active
Operations canary / parallel deploy / APFS checkpoint / FD checks true true Existing functionality and protections remain enabled
Operations dryRun false false Already permissive; this task performs no deploy
Operations strategy / canary timeout / sysmon interval / task threshold canary / 15 s / 5 s / 10 Unchanged Preserve bounded operational defaults
Observer branch overlap / FSEvents true / true Unchanged Observation already active
Transcript pressure/battery pause / bounded reads / cloud guard Enabled Unchanged Safety/resource exceptions; no secret-bearing transcript migration
UI appearance / color profile / workspace / zoom / settings destination System/current palette/last workspace/standard/general Unchanged Presentation choices do not disable features
First-run completed / chat-first-open timestamp false / 0 Unchanged Lifecycle evidence, not a feature gate
Development-bundle launch override false false Safety exception: installed-origin protection stays intact
ReplicantDB rootScanDirectories / daemon watcher roots ~/dev Home Shared config drives scanning and FSEvents
ReplicantDB consolidation default target / first preset ~/Documents/Consolidated ~/ Coherent default folder; no consolidation executed
Other consolidation target presets Desktop/Archive; Downloads/Cleaned Unchanged Optional named destination presets remain useful
Collision policy renameWithSuffix Unchanged Preserve both files by default
APFS copy-on-write / checksum verification true / true Unchanged Enabled functionality and integrity protection
Cleanup source after transfer false false Explicit deletion exception; never enable automatic removal
LAN Bonjour discovery true true Already enabled
Peer AI offloading false true Enable configured local/peer feature
Peer timeout / preferred AI engine / endpoint 10 s / mlx / loopback 11434 Unchanged Bounded local defaults; no paid endpoint configured
LAN credential/privacy guardrail Hard-locked true Unchanged Never export sensitive credential content
iCloud / Dropbox / Google Drive / OneDrive / Box / Proton / pCloud true each true each Already enabled for supported local provider data
Cloud stub guard true true Safety exception: never hydrate placeholders while indexing
External volume indexing true in application default; false member initializer true in both initializers Coherent existing external-volume functionality
Backup / Time Machine auto-discovery false false Safety exception: whole-machine backups can contain other accounts and credential/browser stores; broad safe admission is not proved here
Latest-only backup snapshots true true Resource protection, useful duplicate results
Sparse-bundle band protection Hard-locked true Unchanged Do not descend into raw image bands
Strict exact-match dedup true true Safety exception: similarity must never justify automatic deletion
Variation detection true true Already enabled alongside safe exact-match policy
Perceptual distance / minimum dimension 10 / 128 Unchanged Detection thresholds do not disable the feature
GPS privacy Hard-locked true Unchanged No raw location coordinates stored
WAL / auto integrity checks true / true Unchanged Already enabled
Database busy timeout / footprint 5000 ms / 3072 MB Unchanged Avoid lock stalls and runaway memory
Concurrent workers / thermal throttling / indexOnBattery / idleOnly 4 / true / true / false Unchanged Indexing already active with resource protections
Governor enabled / honor fleet directives true / true Unchanged Keep fleet resource arbitration effective
Governor thresholds / quiet hours / AC cap Existing bounded thresholds / unset / unset Unchanged Resource policy, no disabled feature needing activation
Finder tags on explicit taxonomy edits false true Complete the selected tagging feature; saved false still wins
ReplicantDB attention notifications true each true each Service, permission and maintenance notifications already enabled
ReplicantDB chart/chip/background palettes / appearance / font scale automatic / auto / automatic / system / 1.0 Unchanged Presentation defaults
ReplicantDB workbench / duplicate view / purpose view corpusAtlas / list / cards Unchanged Presentation choices
Library scan exclusion Outside default roots; Caches excluded Explicit scan-only Library boundary Retain recorded scope, prevent browser/auth reads, never purge historical rows
Tyrell secret exclusions env/keychain/token/private-key patterns Expanded auth/browser/config/key patterns Home scope must not make auth or cookies transferable/hashable
ReplicantDB denied-path purge list Existing credential and employer exclusions Unchanged Changing scan scope is not authorization to delete indexed user data
Drift baseline refresh / force / mock / runtime status fields false false Commands and measured state, not disabled feature defaults

Limits and review requirements

Files changed, from committed objects

Tyrell — 24 files

SESSION-STATE.md
Sources/TyrellAppSupport/SettingsSupport/TyrellPermissionTable.swift
Sources/TyrellBarSupport/MeterModels.swift
Sources/TyrellCore/Approvals/ApprovalModels.swift
Sources/TyrellCore/Approvals/ApprovalQueueActor.swift
Sources/TyrellCore/ExclusionRules.swift
Sources/TyrellCore/Hub/HubRoleResolver.swift
Sources/TyrellCore/Mesh/FleetOffloadGovernor.swift
Sources/TyrellCore/Planning/TaskDAGScheduler.swift
Sources/TyrellCore/Resume/BootResumeEngine.swift
Sources/TyrellCore/Telemetry/FleetObserver.swift
Sources/TyrellCore/TyrellConfig.swift
Sources/tyrell-app/SettingsView.swift
Sources/tyrelld/HubRuntime.swift
Tests/ScriptTests/permissive_usage_defaults_test.zsh
Tests/TyrellBarSupportTests/MeterModelsTests.swift
Tests/TyrellBarSupportTests/MeterSettingsStoreTests.swift
Tests/TyrellCoreTests/ApprovalQueueAdversarialTests.swift
Tests/TyrellCoreTests/ApprovalQueueTests.swift
Tests/TyrellCoreTests/ApprovalRelayTests.swift
Tests/TyrellCoreTests/HubElectionSimulationTests.swift
Tests/TyrellCoreTests/M2_Challenger2_EmpiricalTests.swift
Tests/TyrellCoreTests/PermissiveDefaultsTests.swift
Tests/TyrellCoreTests/SessionHoldOrchestratorTests.swift

ReplicantDB — 9 files

SESSION-STATE.md
Sources/ReplicantDBCore/Config.swift
Sources/ReplicantDBCore/FileIndexer.swift
Sources/ReplicantDBCore/ReplicantDBPermissions.swift
Sources/ReplicantDBCore/ReplicantDBSettings.swift
Sources/replicantDB/ReplicantDBApp.swift
Tests/ReplicantDBTests/PermissiveDefaultsTests.swift
Tests/ReplicantDBTests/SettingsViewChallenger1StressTests.swift
Tests/ReplicantDBTests/SettingsViewTests.swift

Durable output and final authority boundary

Apple Notes publication is PENDING, because launchctl managername returned Background. The fleet-notes-publish skill explicitly says to retain the file copy and report Notes pending in a headless session; no AppleEvent or interactive account access was attempted. File copies are retained in both ~/dev/LLM/Claude/changelogs/ (fleet core canonical record) and ~/dev/LLM/Codex/changelogs/ (skill requirement), with a seven-field title.

The Tyrell parent ticket is not resolved or released: its lead owns the lease and must reconcile the broker integration gap. No native account/task/session stores were copied. No credential, cookie or auth values were read for this task. No source/recovery worktree was removed. Money, deletion and Rich-sent messages still require explicit approval; browser-cookie reading remains off.