rdmsm4x-changelog-20260828-1218-tyrell-secure-chat-research
Tyrell secure chat protocol and daemon boundary research
Completed and committed a documentation-only, primary-source security architecture decision for Tyrell chat; it matters because the current shared-token/server-readable design is now distinguished from cryptographic device identity and E2EE, with a staged path to a separately isolated chat service.
Scope
- Host:
rdmsm4x - Production project: Tyrell
- Worktree:
/Users/richh/dev/_worktrees/tyrell-phase2-secure-chat - Branch:
codex/tyrell-phase2-secure-chat - Commit:
cb31e73cb79ead2663146d209b5c6ef3313ae0ca - Lifecycle: local research committed; canonical integration, source implementation, deployment, canary acceptance, and fleet rollout were not performed.
Files changed
/Users/richh/dev/_worktrees/tyrell-phase2-secure-chat/docs/research/2026-08-28-secure-chat-protocol-and-daemon-boundary.md/Users/richh/dev/_worktrees/tyrell-phase2-secure-chat/.handoff/phase2-secure-chat-report.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-tyrell-phase2-secure-chat-20260828.jsonrecords the bounded ownership lane; it is updated separately from the Git commit.
Decision recorded
- Extract chat into a least-privileged
tyrell-chatdprocess with a separate listener, persistence, secrets, logs, resource limits, release, health, and rollback boundary. - Keep attachment bytes in a separately privileged, ciphertext-only transfer boundary.
- Target MLS 1.0 behind protocol-neutral application interfaces, gated on library, Apple-platform, interoperability, state lifecycle, and external security validation.
- Preserve TLS 1.3 over the tailnet as defense in depth.
- Keep
shared_domain_token_assertiontruthfully labeled as domain access, not cryptographic agent identity.
Commands and verification
- Confirmed host, exact worktree, branch, HEAD, dirty state, coordination policy, fleet topology guidance, project mode, and active check-ins.
- Inspected current Tyrell chat models, policy, store, routes, daemon/listener, transport, endpoint resolver, file-offer interfaces, and relevant tests.
- Reviewed and spot-checked official IETF, Signal, Matrix, IRCv3, Tailscale, NIST, Apple, and OpenMLS sources.
- Ran required-heading and subject-term checks with
rg; all required sections and requested security subjects were present. - Ran
git diff --cached --check; no whitespace errors remained. - Ran staged
gitleakswith redaction; it scanned approximately 76.58 KB and reported no leaks. - Checked duplicate headings, conflict markers, internal web-reference IDs, and suspicious credential assignments; all checks were clear.
- Committed exactly two documentation artifacts: 791 insertions, no product-source changes.
- Re-read the commit summary and confirmed the linked worktree was clean after commit.
No product build or runtime test was run because this lane changed documentation only.
Backups and recovery
- The original source base remains commit
83f287d72f60692d8abad83db17da8cd31ffd546. - The research is isolated in a linked worktree and one local commit; no runtime data or service was changed, so no data backup was necessary.
- To undo after integration, use a normal revert of
cb31e73cb79ead2663146d209b5c6ef3313ae0ca; do not rewrite shared history.
Outstanding owner actions
- Review and accept or revise the open choices for history recovery, abuse-report verifiability versus deniability, device credentials, encrypted attachments, sandboxing, and implementation library.
- Integrate the local research commit if accepted and update the canonical project index.
- Authorize a separately owned implementation plan, beginning with truthful Day-1 containment and a non-production MLS/library spike.
- Preserve local, designated
rdmbair15m5canary, and fleet rollout as separate acceptance states.