rdmsm4x — Tyrell Round 2 release
Tyrell Round 2 was integrated to local canonical main,
promoted as a signed private master runtime, accepted on the designated
app canary, and deployed to every reachable app target. The result
matters because Tyrell now has a cohesive Signal Glass fleet/usage
interface, production chat authority and native clients, explicit
evidence semantics, and fail-closed application lifecycle controls
without overstating the two offline hosts or any later-phase research as
shipped behavior.
Scope and lifecycle truth
- Host performing source integration, signing, master promotion, and
release coordination:
rdmsm4x. - Canonical project:
/Users/richh/dev/apps/tyrell. - Integrated local branch:
main. - Final local source commit:
42e9287a7d79548b7b41f61f3f9c3ce1099c731b. - Integration range:
53494a9755de0deadc70fa4faae506c894ae54a0..42e9287a7d79548b7b41f61f3f9c3ce1099c731b. - Source state: integrated locally; no remote push is claimed.
- App state: privately Apple Development-signed and accepted on designated canary; not notarized and not a public-distribution artifact.
- Master daemon state: signed release promoted and live on
rdmsm4x. - App rollout state: 4 of 6 hosts installed/running; 2 offline hosts explicitly pending.
- ECS0 state: a release-accurate integration packet is committed; no ECS0 source, generated page, authentication boundary, or deployment was changed.
- replicantDB state: a sanitized pointer-only reuse packet was dispatched; no receipt, acceptance, source integration, runtime change, or cross-project mutation is inferred.
Product work integrated
- Heatmap-first Signal Glass Observatory with dark/light modes and Blade Runner-like translucent evidence chips.
- Fifteen selectable chart styles with distinct tested geometry, including heatmaps, multi-lane heatmaps, lines, bars, areas, opposing/overlay/stacked/stepped modes, impulses, dots, dual traces, and peak envelopes.
- Evidence-aware provider and usage surfaces that preserve vendor-authoritative, proxy-observed, estimated, activity-only, stale, missing, and unavailable states instead of presenting unknown data as zero.
- Provider discovery and settings for frontier, local, memory, proxy, and custom OpenAI-compatible lanes, with credentials represented only as logical write-only Keychain configuration.
- Native macOS chat interface and iOS remote visibility/chat client.
- Transport-neutral chat domain supporting private-domain,
project-channel, direct, and group conversations; canonical
agent@hostnameidentity; first-owner rules; owner/moderator/member projection; promotion/demotion; invite, kick, ban, unban, block, unblock, topic, who, broadcast, op, and deop commands. - Server-side chat acknowledgements, idempotency, role enforcement, project-channel stability, participant-scoped reads, and explicit shared-domain-token limitations.
- Truthful macOS permission-health reporting and user-controlled Settings affordances.
- App lifecycle controls for exact signed identity, one managed copy, stale-copy retirement, rollback, designated-canary acceptance, receipt binding, and pinned-SSH fleet rollout.
- Research/design records for Apple on-device intelligence, MLX/Core
AI, Apple networking, a future least-privileged
tyrell-chatd, secure attachments/E2EE evaluation, and replicantDB reuse. These remain future work, not shipped runtime claims.
Key source and documentation paths
/Users/richh/dev/apps/tyrell/Sources/TyrellAppSupport//Users/richh/dev/apps/tyrell/Sources/TyrellCore//Users/richh/dev/apps/tyrell/Sources/TyrellRemoteSupport//Users/richh/dev/apps/tyrell/Sources/TyrellRemoteTransport//Users/richh/dev/apps/tyrell/Sources/tyrell-app//Users/richh/dev/apps/tyrell/Sources/tyrelld//Users/richh/dev/apps/tyrell/iOS//Users/richh/dev/apps/tyrell/Tests//Users/richh/dev/apps/tyrell/scripts//Users/richh/dev/apps/tyrell/design/screenshots/signal-glass//Users/richh/dev/apps/tyrell/docs/research//Users/richh/dev/apps/tyrell/docs/status/2026-08-28-tyrell-phase2-dashboard-integration-packet.md/Users/richh/dev/apps/tyrell/SESSION-STATE.md/Users/richh/dev/apps/tyrell/ISSUES.md/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md
The canonical checkout's pre-existing
/Users/richh/dev/apps/tyrell/.DS_Store modification was
preserved and not staged, rewritten, or reverted.
Exact signed artifacts
Tyrell.app
- Managed install:
/Users/richh/Applications/Tyrell.app. - Executable SHA-256:
7c0d6db1e3b1fbb96a9208986ec87beadec2d873e7c0cf619fe6e120462bb857. - Architectures:
x86_64 arm64. - Canonical arm64 full CodeDirectory hash:
4d30006c2d68403d827639f56115bbe1ad7bca875f3e8cc2e50ad2759d2c600d. - x86_64 full CodeDirectory hash:
7c684f93eec4ebc8bdea2a17b095d41422d106049ece264bcb5cf497ab77b8a1. - Bundle identifier:
com.eastcoastscience.Tyrell. - Team identifier:
ZU2882L4HT. - Hardened runtime present.
codesign --verify --deep --strictpassed.spctl --assessrejects this private development build because it is not notarized; public/notarized distribution is not claimed.
tyrelld master runtime
- Release source identity:
a264a467bc681eb40e52004416020582b0928267. - Installed release:
/Users/richh/Library/Application Support/Tyrell/releases/a264a46/tyrelld. - SHA-256:
ec3f05896ed5949abd7946698d28cdc93eec1225d9110eee958a255b05fa1e84. - Architectures:
x86_64 arm64. - Signed by Team
ZU2882L4HT. - Live LaunchAgent PID at final verification:
18511.
Production backup and rollback
- Pre-cutover backup:
/Users/richh/Library/Application Support/Tyrell/backups/20260828-145405-round2-942140e. - Database backup is mode
600and passed SQLitePRAGMA quick_check. - Previous managed local app rollback:
/Users/richh/Applications/.tyrell-rollbacks/20260828-151152-732f3e67baab/Tyrell.app. - Each successfully installed fleet host received its own pre-replacement rollback copy through the lifecycle script.
- Rollback source: reinstall the retained app copy for the affected host and restore only the corresponding Tyrell database backup if a data rollback is explicitly required. Do not replace unrelated host data.
Designated-canary acceptance
- Required canary:
rdmbair15m5; no substitute was used. - Exact candidate installed and launched as one managed app process.
- Canary PID at acceptance/final fleet evidence:
4791. - Nonce:
round2-942140e-20260828-145745. - App-driven probe verified current fleet usage and an authenticated
chat send/page/
/whoround trip. - Probe artifact SHA-256:
5ed94be15213e32cfc70fd541393a64926465494a69a4441b810e26abfc8a7c1. - Host-originated receipt:
/Users/richh/.tyrell/canary-receipts/round2-942140e-20260828-145745.jsononrdmbair15m5. - Receipt mode:
600. - Receipt SHA-256:
3ec9485740964cc60de95a496c7477674c5cd23db909d7c0c99f104175b3469a.
Reachable-fleet rollout
rdmsm4x: exact managed candidate running once at/Users/richh/Applications/Tyrell.app, PID73578at final verification.rdmbair15m5: exact managed candidate running once, designated canary accepted, PID4791at recorded fleet verification.rdmpw3275m: exact managed candidate running once, PID41607at recorded fleet verification; current fleet usage returned200.jdmbair13m5: exact managed candidate running once, PID15636at recorded fleet verification; current fleet usage returned200.rdmbair13m5: offline during rollout and explicitly pending; no deployment or acceptance inferred.rdmpw3265m: offline during rollout and explicitly pending; no deployment or acceptance inferred.- Final app coverage: 4/6. The rollout script returned a truthful partial-failure state rather than hiding offline targets.
The stale local repository-build app process at PID
37508 was verified by exact path, executable hash, and
signing identity before it was terminated. The managed app remained
running and the rollback copy was retained. No unknown-owner process was
killed.
Only the master daemon was promoted. Client-daemon and TyrellBar fleet rollout remain separate pending states.
Final verification evidence
swift test: 249 tests passed (140 TyrellCore/transport, 65 TyrellBarSupport, 44 TyrellAppSupport).Tests/ScriptTests/*.zsh: all four release-script suites passed.- iOS: 17 tests passed earlier against the unchanged release
candidate; result bundle
/Users/richh/Library/Developer/Xcode/DerivedData/TyrellMobile-cwbmfnmuwmvxbufedmfqqzriseyd/Logs/Test/Test-TyrellMobile-2026.08.28_14-09-30--0400.xcresult. - Signal Glass: all 38 files passed
SHA256SUMS, including 30 graph-style dark/light targets. - Gitleaks 8.30.1: 52 commits, approximately 1.18 MB scanned over the integration range, 0 findings; redacted JSON report written temporarily outside the project.
git diff --check: passed.- Round-2 writer worktree: clean at
42e9287a7d79548b7b41f61f3f9c3ce1099c731b. - Canonical
main: same commit; only the preserved pre-existing.DS_Storemodification remains. - Runtime
GET /api/status:200on both43117and43118. - Authenticated
GET /api/fleet/usage:200. - Unauthenticated chat conversation request:
401. - Local token-file mode:
600; no token value was logged or copied. - Production
/Users/richh/Library/Application Support/Tyrell/tyrell.db: SQLitequick_check=ok. - Independent release review: GO after the live release-gate fixes.
- Independent Intel/Apple Silicon retry review: GO after canonicalizing receipt identity to the arm64 CodeDirectory hash while retaining full universal-binary SHA, Team ID, bundle ID, hardened runtime, and dual-architecture gates.
- Dedicated simulator
TyrellRound2Testswith UDIDB300F3ED-1475-4C1C-8F3D-989693C7C40Cwas verified shutdown, deleted, and verified absent. No other simulator was removed.
Primary commands run
swift testzsh Tests/ScriptTests/<each-suite>.zshshasum -a 256 -c design/screenshots/signal-glass/SHA256SUMSgitleaks git --redact --log-opts=<integration-range>codesign --verify --deep --strict <Tyrell.app>codesign -dv --arch arm64 --verbose=4 <Tyrell.app>lipo -archs <app-executable-or-daemon>shasum -a 256 <app-executable-or-daemon>- Local HTTP status, authenticated fleet-usage, and unauthenticated chat-boundary probes without printing credential material.
sqlite3 <production-db> 'PRAGMA quick_check;'xcrun simctl shutdown <dedicated-test-UDID>andxcrun simctl delete <dedicated-test-UDID>.- Fast-forward-only integration of the verified Round-2 branch into
local canonical
main.
replicantDB reuse handoff
- Artifact:
/Users/richh/dev/_handoffs/tyrell-082826-round2/agent8-replicantdb-interoperability-summary.md. - SHA-256:
1cfcd490d73e6f365c0dcea4a9555fb8a6921f7f33429b75b9a8bae862265752. - Fleet-bus pointer:
20260828-131455-17F6B8DB. - Boundary: Tyrell remains authoritative for fleet evidence and chat. replicantDB remains authoritative for file intelligence, mutation policy, local corpus truth, and transfer intent.
- Reuse candidates: typed operations and receipts, command catalog, transport/discovery seams, transfer planning, idempotency, validation/rollback rules, and guarded on-device intelligence contracts.
- No reply was recorded before release closure; state is
dispatched, notreceived,accepted, orintegrated.
Outstanding owner actions and next gates
- Bring
rdmbair13m5andrdmpw3265monline and resume only those targets. If receipt freshness has expired, issue a fresh designated-canary receipt before retrying. - Complete a separately evidenced TyrellBar rollout and client-daemon rollout.
- Supply a real proxy-observed LiteLLM ingestion feed with provenance and explicit budget authority before enabling LiteLLM spend or quota reporting.
- Resolve the current ECS0 page/generator owner, integrate the committed packet in that owner's worktree, validate generated output, and publish only through the authorized ECS0 lane.
- Notarize only when producing a separately approved public/distribution release.
- Treat Bonjour/local neighbor discovery, multi-path transfer,
file-byte transfer, signed-device identity,
tyrell-chatd, secure attachments, E2EE/MLS, and guarded Core AI/MLX remediation as future gated implementation—not current runtime behavior. - Obtain an explicit replicantDB owner receipt before treating the Agent 8 reuse packet as accepted or integrated.
Undo guidance
- Source: because canonical
mainwas advanced only by fast-forward and no remote push occurred, create a named rollback branch at42e9287a7d79548b7b41f61f3f9c3ce1099c731bbefore any requested source reversal; do not discard the preserved.DS_Storechange. - Master daemon: use the retained pre-cutover backup/release pointer
and the project installer to restore the preceding signed release, then
re-run both status probes and SQLite
quick_check. - App on one host: stop only the exact managed Tyrell executable,
restore that host's timestamped
.tyrell-rollbacksbundle, verify SHA/signature/bundle/Team identity, and relaunch exactly once. - Fleet: roll back only hosts that accepted the candidate; leave the two offline/pending hosts untouched.
- Data: restore a database backup only with an explicit data-rollback decision; the source/app rollback does not require destroying current operational records.
No credential values, provider payloads, prompts, responses, memory bodies, private database contents, or secret-bearing URLs are included in this record.