rdmsm4x-changelog-20260828-2031-tyrell-applications-deploy-hardening
rdmsm4x Tyrell Applications deployment hardening — 2026-08-28 20:31 EDT
Prepared an isolated, source-only migration from the legacy per-user
Tyrell.app location to /Applications/Tyrell.app, so a lead
can perform a signed, canary-first, rollback-protected release without
recreating the legacy path.
Scope
- Host:
rdmsm4x; project mode: Production. - Source worktree:
/Users/richh/dev/_worktrees/tyrell-applications-deploy-20260828. - Initial commit:
303ccf6bfe900066412d7c19ea17afed922bf9a0. - Rollback recovery follow-up:
9ed4140445519e10dca6f9e6b59e896484ff9b59. - Fleet scope: six Tyrell app hosts; no remote mutation was performed.
Files and behavior changed
- Moved the managed deployment contract to
/Applications/Tyrell.app, with system staging and rollback directories under/Applications. - Added root-gated, target-user-aware, identity-verified and dry-run-capable app promotion; it stops only exact managed processes and launches exactly one accepted system app.
- Added acceptance-gated legacy cleanup and verified stale managed rollback pruning while retaining the immediate rollback. On first migration the verified legacy app is moved into the managed rollback path only after candidate acceptance, so it is never deleted as the last known-good app.
- Added guarded recovery for post-promotion verification, candidate launch, and exact-one-process failures: restore and relaunch the verified prior system app when available, otherwise relaunch the still-present verified legacy app.
- Hardened the pinned fleet updater with all five remote host pins,
canary ordering,
sudo -nauthorization gating, and explicit pending state. - Updated canary acceptance/probe and menu-bar app resolution to prefer the system app; added/updated regression contracts.
- Durable deployment inventory and exact lead-owned rollout/rollback
procedure:
.handoff/applications-deploy-20260828.mdin the worktree.
Verification
- All four lifecycle script contracts passed.
- Full
swift testpassed after build (existing compiler warnings only). zsh -npassed for the modified lifecycle, fleet, acceptance, and canary scripts;git diff --checkpassed before commit.- Read-only pinned SSH inventory matched expected ED25519 fingerprints
on all six hosts. Every host had the signed universal legacy app at
~/Applications/Tyrell.app; none had/Applications/Tyrell.app.
Runtime and rollback
- No installed bundle, process, LaunchAgent, service, TCC setting, signing identity, remote filesystem, or deployment was changed.
- The lead must build/sign from an authorized Aqua session, run the
dry-run, execute
rdmbair15m5canary first, obtain its fresh receipt, then advance other reachable/authorized hosts. Hosts that are offline or lack required authorization remain pending. - The installer prints the immediate verified rollback path. First migrations retain a verified legacy copy under that managed path after acceptance; failed candidate launch/acceptance leaves the legacy copy available for recovery. Do not use development or unknown-owner home-directory bundles as rollback material.
Apple Notes
Apple Notes publication is pending: this Codex session is not an Aqua
desktop session and notes_changelog.zsh intentionally
refuses background/SSH execution. The Markdown archive above is complete
and ready for publication from Terminal.app on rdmsm4x.