Tyrell chat authority, daemon release, and fleet app alignment
Tyrell now reconciles one friendly authority channel per canonical
project without deleting legacy chat history, records explicit recipient
delivery truthfully, runs the new signed daemon on rdmsm4x,
and runs the exact signed system app once on all six Macs; the physical
iPhone has the app installed but was absent from the final live process
list, and live CloudKit/chat acceptance remains explicitly pending.
Scope and ownership
- Acting host:
rdmsm4x. - Source worktree:
/Users/richh/dev/_worktrees/tyrell-release-20260828. - Branch:
codex/tyrell-release-20260828. - Implementation commit:
7662e97ddd1b698b52bb6727f06131ba0d33b954. - Release-documentation commits:
09a54e5, followed by the final device-state correction56a2c23. - Canonical main was not modified; it remained at
f64e8da7e963be0ec1b889a330a68441c70b0dcewith its pre-existing.DS_Storemodification preserved. - Fleet app scope:
rdmsm4x,rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Physical-device observation:
rdip17ponly; no device setting or credential was written.
Source files changed
/Users/richh/dev/_worktrees/tyrell-release-20260828/Sources/TyrellCore/ChatServerLogic.swift/Users/richh/dev/_worktrees/tyrell-release-20260828/Sources/TyrellCore/ChatStore.swift/Users/richh/dev/_worktrees/tyrell-release-20260828/Sources/TyrellCore/SQLiteStateStore+Chat.swift/Users/richh/dev/_worktrees/tyrell-release-20260828/Tests/TyrellCoreTests/ChatAuthorityTests.swift/Users/richh/dev/_worktrees/tyrell-release-20260828/Tests/TyrellCoreTests/ChatServerLogicTests.swift/Users/richh/dev/_worktrees/tyrell-release-20260828/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-release-20260828/ISSUES.md/Users/richh/.agent-coordination/checkins/codex-tyrell-release-20260828.json- This changelog file.
What changed
- Project-channel authority now accepts explicit project references
first and otherwise derives only from standardized direct project roots
below
dev/apps,dev/sites, ordev/localAI. - Migration, cache, linked-worktree, nested-repository, unsupported-domain, malformed, and counterfeit authority inputs fail closed.
- Reconciliation upgrades/restores canonical rows and archives retired
tyrell.filesproject rows without deleting conversations, memberships, messages, command results, or recipient receipts. - Explicit recipient delivery persists one pending row per intended recipient and changes to delivered only when a receipt with a timestamp is recorded. Broadcast audiences remain intentionally receipt-free.
- The exact universal daemon candidate was Apple Development signed
for Team
ZU2882L4HTfrom the existing Aqua user domain because the Codex Background launchd domain cannot unlock the login Keychain. No TCC, SIP, firewall, Keychain, or other security policy was weakened. - The formerly stale
rdmbair13m5home-directory app was preserved as rollback and replaced with the exact managed/Applications/Tyrell.app; the same signed candidate was revalidated idempotently on the other fleet Macs.
Commands and validation
- Ran the full Swift package test suite. Final runner groups were 162, 21, 68, and 48 passing tests: 299 total non-XCTest tests with zero failures.
- Ran all eight script contract suites covering app deployment
planning, operational entrypoints,
/Applicationsinstallation, bundle construction, app lifecycle, daemon release lifecycle, bounded collector scanning, and collector lifecycle. All passed. - Ran
git diff --check; it passed. - Built a universal release daemon with Xcode and verified both
x86_64andarm64slices. - Signed the exact candidate through the existing Aqua user session and verified its strict code signature, Team ID, and immutable executable hash.
- Executed
scripts/promote_tyrelld_release.zshwith its clone-database, endpoint, identity, SQLite, cutover, and rollback gates. - Queried the production database read-only in one transaction.
PRAGMA quick_checkreturnedok; the accepted catalog contains 894 conversations, 39 active current project channels, 854 preserved archived legacy project channels, one active domain channel, 2,675 memberships, five messages, 11 recipient rows, and zero orphan messages/memberships/receipts. Every active room has exactly one owner. - Verified port 43117 as the data/chat plane (
status=200,usage=200, unauthenticated bootstrap POST=401) and port 43118 as the intentionally GET-only control plane (status=200,usage=200, bootstrap POST=405). - Ran a synthetic explicit-recipient delivery contract canary. It moved one row from pending to delivered with a timestamp. This proves the shared-token API/database transition only; it is not evidence that Claude or a human read the message.
- Designated canary
rdmbair15m5ran the signed app itself through usage decode, authenticated chat send/page, and/who, then issued a nonce-bound mode-0600 receipt. - Executed the receipt-gated fleet installer and then independently
verified on all six Macs that
/Applications/Tyrell.apphas the exact expected executable SHA, bundle ID, Team ID, and exactly one running process. - Queried
rdip17pwithdevicectl: it is available/paired and Tyrell 0.1.0 build 3 is installed. PID16541was observed earlier, but the app was absent from the final live process list; itsLibrary/Preferencesdirectory contains zero files. - Re-read Tyrell usage/fleet tools. Advice was
proceed; authoritative worst buckets were Anthropic 7% and OpenAI 53%. Google remained activity-only and xAI remained installed but unauthenticated.
Artifact identities and acceptance evidence
- Daemon path:
/Users/richh/Library/Application Support/Tyrell/releases/7662e97/tyrelld - Daemon SHA-256:
1d02d26342cb410b666de135a19c90354428916b8dde51102552e479b8bbdfe4 - Accepted daemon PID at the release checkpoint:
84063. - App executable SHA-256:
d7e8ef984b9f5b62a626dcfdd03c73264d6fc429df2da6bdc8d5df9ddebbeacb - App canonical full CodeDirectory hash:
0462233fc093554e0d3e29903f4f9e2e2015fcf0b2e602d0095157e24c08fe08 - Canary nonce:
tyrell-release-20260829T024054Z-7662e97. - Canary receipt:
/Users/richh/.tyrell/canary-receipts/tyrell-release-20260829T024054Z-7662e97.json - Canary receipt SHA-256:
cc27241f8317c17b30a91df77600f10af46655ce9a252278aaa84909d8a13ffd - Only
rdmbair15m5has the fresh full app-driven receipt. The other five hosts have exact install/runtime evidence, not independent canary acceptance.
Backups and rollback
- Daemon pre-cutover rollback:
/Users/richh/Library/Application Support/Tyrell/backups/20260828-223449-daemon-7662e97 - Previous daemon release retained:
/Users/richh/Library/Application Support/Tyrell/releases/dff09ab/tyrelld - The stale
rdmbair13m5app was moved before replacement to:/Applications/.tyrell-rollbacks/20260828-225946-3a694e84e74c/Tyrell.app - Existing per-host managed app rollbacks were retained by the installer.
- Source rollback is the preserved isolated branch/worktree; canonical main was not changed.
To undo the daemon release, restore the prior LaunchAgent/release
from the recorded daemon backup through the same promoter lifecycle and
re-run status, usage, chat-auth, identity, process-uniqueness, and
SQLite gates. To undo a fleet app install, restore the host's retained
.tyrell-rollbacks bundle through
install_app_local.zsh, then verify the exact signature and
sole managed process. Do not copy mutable Git directories or delete the
release worktree until canonical integration and rollback acceptance are
separately recorded.
Outstanding actions
- Configure the physical
rdip17papp securely, then prove live private-CloudKit account/container read-write, authenticated chat bootstrap, explicit-recipient delivery, relaunch persistence, and rollback. Installed/running is not accepted as functional. - Diagnose stale per-host manifest timestamps separately from the now-complete signed app installation; stale data must remain labelled stale.
- Integrate the release branch into canonical main only through a separate owner review and verification gate; no push or main mutation occurred here.
- Apply the ReplicantDB
5a5703cdamped text/icon/chrome scaling pattern in a separate UI lane after the device/chat gate, with any deliberate Tyrell divergence recorded.
No credential value, fleet token, prompt, response body, memory body, provider database, or raw chat payload is included in this record.