rdmsm4x-changelog-20260828-1239-tyrell-macos-permission-health
Tyrell macOS permission health
Implemented source-only, identity-aware macOS permission health reporting so Settings distinguishes truthful evidence states and offers only supported, least-privilege controls.
Scope
- Host:
rdmsm4x - Project worktree:
/Users/richh/dev/_worktrees/tyrell-phase2-macos-health - Branch:
codex/tyrell-phase2-macos-health - Commit:
83639bbc7f84791850620b111bedbfc376ce11e9 - Deployment, release signing, installation, canary, fleet rollout, services, and system permission state were not changed.
Files changed
.handoff/phase2-macos-health-report.mdPackage.swiftSources/TyrellAppSupport/PermissionHealth.swiftSources/tyrell-app/MacPermissionHealthStore.swiftSources/tyrell-app/SettingsView.swiftTests/TyrellAppSupportTests/PermissionHealthTests.swiftdesign/screenshots/signal-glass/settings-dark.pngdesign/screenshots/signal-glass/settings-light.png
What changed
- Added a portable capability catalog and the exact evidence states
not-required,not-determined,denied,restricted,granted,unavailable,manual-only, andstale. - Reports whether the Tyrell app or
tyrelldwas evaluated, with executable basename, bundle/signing identity, Team ID when available, and signature class; private paths are discarded. - Replaced the old current-process Full Disk Access directory guess with truthful daemon-scoped manual validation.
- Added narrow System Settings routes, refresh-after-return behavior,
and
SMAppServiceregistration/removal only for the optional main-app login item. - Marked Automation, Accessibility, and Screen Recording as not required and avoided unnecessary prompts.
- Added deterministic dark/light visual fixtures and nine focused tests.
Commands and verification
swift test: 231 tests passed, 0 failures (135 TyrellCore, 62 TyrellBarSupport, 34 TyrellAppSupport).swift build -c release --product tyrell-app: passed.bash script/build_and_run_app.sh capture settings dark: passed; 1960 x 1456.bash script/build_and_run_app.sh capture settings light: passed; 1960 x 1456.- Both fixtures were visually inspected at source resolution; visible rows, status pills, identity fields, purpose text, and controls were legible in both appearances.
- Post-commit
swift test --filter PermissionHealthTests: 9 passed, 0 failures. - Post-commit
swift build --product tyrell-app: passed. git diff --cached --check: passed before commit.- Count-only staged scan: 0 gitleaks findings, 0 conflict-marker matches, 0 absolute user-path matches in product source.
- Expected pre-existing warnings remain for
ChatPresentation.swiftand two unrelated TyrellCore source diagnostics.
Backup and undo
- Git commit
83639bbc7f84791850620b111bedbfc376ce11e9is the complete source rollback boundary. - Revert that commit after integration if rollback is required. No runtime or system rollback is needed because this lane did not alter permissions, services, signing, installation, or fleet state.
Outstanding owner actions
- Integrate the commit through the accountable Tyrell lead.
- Before canary acceptance, verify final responsible-code association and purpose-string packaging for Local Network privacy, stable release identities, the displayed prompt identity, a real signed-daemon LAN peer exchange, a protected-root daemon scan when Full Disk Access is desired, and login-item behavior across sign-out/sign-in.
- Keep source integration, deployment, prompt appearance, user decision, functional validation, canary acceptance, and fleet rollout as separate states.