rdmsm4x-changelog-20260828-2056-tyrell-domain-chat-roster
Tyrell domain chat roster reconciliation
Added a server-owned reconciliation path so the canonical Tyrell default room includes observed fleet chat agents without accepting a client-supplied roster.
- Scope: source-only change on
rdmsm4x; no runtime database, daemon, CloudKit, credential, or fleet deployment mutation. - Worktree:
/Users/richh/dev/_worktrees/tyrell-domain-chat-20260828 - Base:
4ff610929976e0b322fcffbd37bfec3ef4a25044 - Commit:
9a373ad92f4311a7e3e685ed91783e6b49d4d534 - Files changed:
Sources/TyrellCore/ChatStore.swiftSources/TyrellCore/ChatServerLogic.swiftSources/TyrellCore/SQLiteStateStore+Chat.swiftTests/TyrellCoreTests/ChatAuthorityTests.swiftTests/TyrellCoreTests/ChatServerLogicTests.swift
- Behavior: authenticated bootstrap reconciles
domain:tyrell.local:generalfrom server-held accepted manifest and latest census evidence. It derivesclaude@hostname,codex@hostname, andagy@hostnameonly for observed interactive agent families; it does not treat Ollama as a chat identity. - Safety: callers cannot submit roster identities or roles; existing roles and the first owner remain unchanged; bans are respected; direct, group, and project channels are untouched; reconciliation is idempotent.
- Verification:
swift test --filter 'domainRosterReconcilesOnlyManifestCensusAgentsAndPreservesFirstOwner|bootstrapHandlerReconcilesTheDefaultRoomFromTrustedFleetCensus'swift testgit diff --check
- Rollback: do not integrate commit
9a373ad92f4311a7e3e685ed91783e6b49d4d534, or revert it from the release integration branch. - Outstanding: the present roster evidence remains shared-token fleet/census evidence; signed per-agent device identity and presence remain a future hardening item.