rdmsm4x-changelog-20260828-0408-tyrell-signal-glass-chat-release
rdmsm4x-changelog-20260828-0408-tyrell-signal-glass-chat-release
Shipped Tyrell's Signal Glass application and Day-1 local fleet chat
to the canonical master runtime with a verified rdmbair15m5
app canary, while preserving canonical source integration and broader
fleet rollout as separate pending states.
Scope and why it matters
- Host changed:
rdmsm4xonly for source, runtime binary, LaunchAgent, project registry, coordination record, and release evidence. - Read-only canary verification:
rdmbair15m5; no file, app, daemon, credential, or configuration was changed there. - No deployment claimed for
rdmbair13m5,rdmpw3265m,rdmpw3275m, orjdmbair13m5.rdmpw3265mremains unreachable. - Product result: a consistent native Signal Glass shell with a heatmap-first Observatory, selectable usage/traffic views, direct/group/channel agent chat, IRC moderation, provider discovery and write-only Keychain credential configuration, native Settings, and eight dark/light target screenshots.
- Architecture result: chat domain and UI remain protocol-neutral
behind
ChatTransport,PeerDiscovery, andChatFileTransfer; the Day-1 master adapter is authenticated HTTP+JSON. File offers are metadata-only and never represented as completed byte transfer. - Evidence result: vendor-authoritative, estimated, proxy-observed, activity-only, stale, partial, missing, and unavailable readings remain distinct. LiteLLM remains unavailable without real proxy-observed ingestion and explicit limit authority.
Source chronology and ownership
- Canonical source root preserved:
/Users/richh/dev/apps/tyrell. - Canonical
mainpreserved at53494a9755de0deadc70fa4faae506c894ae54a0; its pre-existing.DS_Storeremains unrelated and untouched. - One-writer worktree:
/Users/richh/dev/_worktrees/tyrell-signal-glass-chat-20260827. - Branch:
codex/tyrell-signal-glass-chat-20260827. - Eighteen-commit branch range:
972f7cb..52f09af. - Final implementation commit:
f14115c9fd56358967f4938aad3d7d951d7627d9. - Lifecycle-record branch HEAD:
52f09af4924a19d27466f56ba7756a19ac1a30e6. - Canonical integration is pending; local deployment does not imply merge, push, or source acceptance.
Exact tracked files changed
ISSUES.mdPackage.swiftSESSION-STATE.mdSources/TyrellAppSupport/ChatEndpointResolver.swiftSources/TyrellAppSupport/ChatTransport.swiftSources/TyrellAppSupport/ObservatoryModels.swiftSources/TyrellAppSupport/ProviderCatalog.swiftSources/TyrellAppSupport/ShellNavigation.swiftSources/TyrellCore/BlockingWorkExecutor.swiftSources/TyrellCore/BoundedBlockingWorkExecutor.swiftSources/TyrellCore/ChatCommands.swiftSources/TyrellCore/ChatModels.swiftSources/TyrellCore/ChatPolicy.swiftSources/TyrellCore/ChatServerLogic.swiftSources/TyrellCore/ChatStore.swiftSources/TyrellCore/ManifestAdmissionGate.swiftSources/TyrellCore/SQLiteStateStore+Chat.swiftSources/TyrellCore/SQLiteStateStore.swiftSources/TyrellCore/ServerLogic.swiftSources/TyrellCore/UsageAggregate.swiftSources/tyrell-app/AppStatusFeed.swiftSources/tyrell-app/ChatViewModel.swiftSources/tyrell-app/CredentialStore.swiftSources/tyrell-app/FleetChatView.swiftSources/tyrell-app/MainShell.swiftSources/tyrell-app/ObservatoryView.swiftSources/tyrell-app/ProvidersView.swiftSources/tyrell-app/SettingsView.swiftSources/tyrell-app/ShellSidebar.swiftSources/tyrell-app/SignalGlassComponents.swiftSources/tyrell-app/SignalGlassTheme.swiftSources/tyrell-app/SupportingDestinations.swiftSources/tyrell-app/TyrellAppMain.swiftSources/tyrell-app/VisualFixtureCapture.swiftSources/tyrell-app/VisualFixtures.swiftSources/tyrell-app/WindowSceneBridge.swiftSources/tyrelld/ChatRoutes.swiftSources/tyrelld/ControlServer.swiftSources/tyrelld/Daemon.swiftSources/tyrelld/FleetUsage.swiftSupport/com.eastcoastscience.tyrelld.plist.templateTests/ScriptTests/make_app_bundle_contract_test.zshTests/TyrellAppSupportTests/ChatTransportTests.swiftTests/TyrellAppSupportTests/ObservatoryModelsTests.swiftTests/TyrellAppSupportTests/ProviderCatalogTests.swiftTests/TyrellAppSupportTests/ShellNavigationTests.swiftTests/TyrellCoreTests/BlockingWorkExecutorTests.swiftTests/TyrellCoreTests/ChatCommandParserTests.swiftTests/TyrellCoreTests/ChatModelsTests.swiftTests/TyrellCoreTests/ChatPolicyTests.swiftTests/TyrellCoreTests/ChatServerLogicTests.swiftTests/TyrellCoreTests/ChatStoreTests.swiftTests/TyrellCoreTests/LaunchAgentTemplateTests.swiftTests/TyrellCoreTests/ManifestAdmissionGateTests.swiftTests/TyrellCoreTests/ServerLogicTests.swiftTests/TyrellCoreTests/StateStoreTests.swiftTests/TyrellCoreTests/UsageAggregateTests.swiftdesign/screenshots/signal-glass/README.mddesign/screenshots/signal-glass/SHA256SUMSdesign/screenshots/signal-glass/chat-dark.pngdesign/screenshots/signal-glass/chat-light.pngdesign/screenshots/signal-glass/observatory-dark.pngdesign/screenshots/signal-glass/observatory-light.pngdesign/screenshots/signal-glass/providers-dark.pngdesign/screenshots/signal-glass/providers-light.pngdesign/screenshots/signal-glass/settings-dark.pngdesign/screenshots/signal-glass/settings-light.pngdocs/superpowers/plans/2026-08-27-tyrell-signal-glass-chat.mddocs/superpowers/specs/2026-08-27-tyrell-signal-glass-chat-design.mdscript/build_and_run_app.shscripts/make_app_bundle.zsh
Exact non-repository state changed
- Staged signed runtime:
/Users/richh/Library/Application Support/Tyrell/releases/4748525/tyrelld. - Live LaunchAgent plist:
/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plist. - Fresh rollback snapshot:
/Users/richh/Library/Application Support/Tyrell/backups/20260828-034545-signal-glass-4748525/. - Project registry row:
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. - Coordination record:
/Users/richh/.agent-coordination/checkins/codex-tyrell-signal-glass-chat-20260827.md. - This changelog:
/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260828-0408-tyrell-signal-glass-chat-release.md. - Ignored worktree evidence under
.build/: signed builds, clone-gate logs, live-cutover guards/logs, soak evidence, samples, and values-free canary-check scripts.
Runtime release and rollback evidence
- Live service:
gui/501/com.eastcoastscience.tyrelld, PID95229at verification time. - Live executable:
/Users/richh/Library/Application Support/Tyrell/releases/4748525/tyrelld. - Executable architectures:
x86_64 arm64. - Team identifier:
ZU2882L4HT. - Executable SHA-256:
5e4bffa76ab6ba5d2f2c9746bef1cb880e98955d3e0ea62505a1be329a43409f. - LaunchAgent:
ProcessType=Interactive, plist mode0444. This is required because Tyrell.app synchronously depends on the local HTTP service; Adaptive XPC transactions cannot elevate an HTTP-only transport. - Database backup
PRAGMA quick_check:ok. - Database rows at backup and promotion: 1,194,209 files; 93,969 CAS-index entries.
- Earlier
ad6e7d0stabilization failure rolled back. One staging copy accidentally lost execute bits and was rejected by launchd asEX_CONFIG; its bytes/signature were unchanged, mode was corrected, and that attempt remained failed. A Background-classified candidate remained inxpcproxywithout executing; the guarded attempt rolled back. The Interactive-classified attempt reached readiness on attempt 2 and passed 20/20 stabilization rounds.
Commands and validation performed
swift test --filter daemonLaunchAgentProcessTypewas observed failing withBackground, then passing after the template changed toInteractive.swift testpassed 119 TyrellCore + 62 TyrellBarSupport + 18 TyrellAppSupport tests, 199 total.zsh Tests/ScriptTests/make_app_bundle_contract_test.zshpassed the signed-app failure contract.- Universal release products were built and signed from an Aqua
Terminal session;
codesign --verify --strictand Team-identifier checks passed. - Production clone gate: SQLite
.backupto a private temporary DB, real read-only CAS, ports 43227/43228, 129 rounds, 645 endpoint checks, zero failures, stable file/CAS counts,quick_check=ok. - Guarded live cutover: exact plist-array replacement, complete bootout wait, bootstrap retry, token read at runtime, readiness, 20 consecutive all-endpoint rounds, exact hash/team/mode/process-type checks, automatic rollback on every failure path.
- Live soak: 75 seconds, 67 rounds, 402 status/usage/fleet-usage/chat
checks, zero failures, stable PID, unauthenticated chat
401, authenticated chat200, valid fleet-usage JSON,quick_check=ok. - Canary: SSH read-only check from
rdmbair15m5; signed Tyrell.app PID88323, executable SHA-25680612111df9ae29415608f0e1e118bbef407ed139056ae7e00e5c39292585668, TeamZU2882L4HT; master status200, unauthenticated chat401, authenticated chat200. shasum -a 256 -c design/screenshots/signal-glass/SHA256SUMSpassed all eight screenshots.git diff --checkpassed.- Gitleaks scanned the 18-commit Tyrell range with zero findings. The
exact changed lifecycle/registry files also scanned with zero findings.
A brute-force ignored-worktree scan reported 13 redacted patterns, all
isolated to SwiftPM
.buildcache content: upstream SQLite/compiler-state patterns and GRDB's test.pfxfixture; none is tracked Tyrell source or release evidence. - Final read-only Claude review dispatched as fleet-bus message
20260828-040007-D41C9970; no receipt or acceptance is inferred until a reply arrives.
How to undo
- From the logged-in Aqua session, boot out
gui/501/com.eastcoastscience.tyrelldand wait untillaunchctl printconfirms the job is absent. - Restore
/Users/richh/Library/Application Support/Tyrell/backups/20260828-034545-signal-glass-4748525/com.eastcoastscience.tyrelld.plistto/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plist, preserving its metadata and restoring mode0444. - Bootstrap that restored plist into
gui/501, retrying only after a complete bootout, then verify both ports and the chat401boundary. The restored plist points to the prior signed276d054release. - The live database did not require migration rollback; chat tables
are additive. If database rollback is explicitly required, preserve the
current database first and restore the consistent
tyrell.dbfrom the same backup directory only while the daemon is fully stopped. - Source rollback is simply to leave canonical
mainunchanged and retire the isolated branch/worktree after owner review; no force push, history rewrite, or destructive checkout is needed.
Outstanding owner actions and next features
- Review and integrate the isolated candidate into canonical
main; final Claude review is pending. - Run and separately record the TyrellBar-specific
rdmbair15m5canary and broader fleet rollout. Do not countrdmpw3265muntil it is reachable and verified. - Implement Bonjour/mDNS neighbor discovery, selectable future transports/relays, and file-byte transfer through the shipped protocol seams.
- Connect LiteLLM only through sanitized, provenance-stamped proxy-observed events; do not ingest credentials, prompt/response bodies, provider databases, or Tyrell's private ledger into unrelated projects.
- Continue the separately owned unified local/cloud session inventory and historical private-chat retire-versus-redesign decision.