rdmsm4x-changelog-20260829-0454-tyrell-macos-build3-release
rdmsm4x-changelog-20260829-0454-tyrell-macos-build3-release
Tyrell 0.2.0 (3) restored truthful Full Disk Access detection, added Location and Local Network onboarding, preserved TCC identity across reinstalls, passed its designated canary, and was deployed to every fleet Mac with a currently authenticated management path.
Scope
- Source/signing host:
rdmsm4x. - Canonical project:
/Users/richh/dev/apps/tyrell. - Isolated release worktree:
/Users/richh/dev/_worktrees/tyrell-macos-visible-release-20260829. - Deployment targets:
rdmsm4x, designated canaryrdmbair15m5,rdmpw3275m,jdmbair13m5,rdmpw3265m, and pendingrdmbair13m5. - No credentials, prompts, responses, provider databases, or private message bodies were copied or recorded.
- No remote Git push, public release, notarization claim, daemon/database migration, or security-policy weakening occurred.
Source and files changed
- Canonical
mainfast-forwarded from9f97dda661baf6bf508c6710e76a8ff3350f010ftoeff529380e8c173ada39eaaad244264078a7031c. - Release implementation commits run from
9684c75throughfbd1ed8; release-state documentation commit iseff5293. - Product and support files changed:
Sources/TyrellAppSupport/AppCanaryProbe.swiftSources/TyrellAppSupport/PermissionHealth.swiftSources/TyrellAppSupport/WorkspaceTemplate.swiftSources/TyrellBarSupport/AppNavigationSignal.swiftSources/TyrellCore/Version.swiftSources/tyrell-app/MacPermissionHealthStore.swiftSources/tyrell-app/MainShell.swiftSources/tyrell-app/PermissionOnboardingCoordinator.swiftSources/tyrell-app/SettingsView.swiftSources/tyrell-app/TyrellAppMain.swiftPackage.swift
- Release and lifecycle files changed:
script/build_and_run_app.shscripts/accept_tyrell_app_canary.zshscripts/install_app_local.zshscripts/lib/tyrell_app_lifecycle.zshscripts/make_app_bundle.zshscripts/plan_app_deployment.zshscripts/redeploy_app_fleet.zshscripts/run_tyrell_app_canary_probe.zsh
- Test and durable state files changed:
Tests/ScriptTests/app_deployment_plan_contract_test.zshTests/ScriptTests/app_operational_entrypoints_contract_test.zshTests/ScriptTests/applications_deploy_contract_test.zshTests/ScriptTests/make_app_bundle_contract_test.zshTests/ScriptTests/tyrell_app_lifecycle_contract_test.zshTests/TyrellAppSupportTests/AppCanaryProbeTests.swiftTests/TyrellAppSupportTests/PermissionHealthTests.swiftTests/TyrellAppSupportTests/WorkspaceTemplateTests.swiftTests/TyrellBarSupportTests/AppNavigationSignalTests.swiftTests/TyrellCoreTests/VersionTests.swiftSESSION-STATE.mdISSUES.md.handoff/applications-deploy-20260828.md
- Fleet project index updated at
~/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. - Coordination record updated at
~/.agent-coordination/checkins/codex-rdmsm4x-tyrell-macos-visible-release-20260829.json.
Functional changes
- Full Disk Access now performs a read-only protected-folder probe from the signed Tyrell app process. Permission failures map to denied, readable candidates map to granted, and missing or inconclusive candidates remain unknown.
- The app reports the exact executable identity being tested and does
not imply that app-process Full Disk Access proves access for a
separately launched
tyrelldprocess. - Core Location authorization is queryable and requestable. A normal first launch requests access only while state is not determined.
- The app declares its Local Network purpose and
_tyrell._tcpBonjour service and starts a bounded network browser on first normal launch to trigger the system request. Because macOS exposes no public Local Network status API, the UI remainsUnknown / unqueryableuntil an actual operation supplies evidence. - The installer compares candidate and installed designated
requirements before stopping or replacing an app, fails closed on
identity drift, preserves the current bundle as rollback, removes only
exact stale Tyrell processes, and requires exactly one accepted
/Applications/Tyrell.appprocess. - Workspace template selection and updated 0.2.0 (3) visible versioning are included.
- Canary usage validation now permits an unreachable host to retain an explicitly aged, provenance-bearing snapshot without being incorrectly classified as missing.
Build and identity evidence
- App version/build:
0.2.0 (3). - Universal executable architectures:
arm64andx86_64. - Executable SHA-256:
f92d93bda5162f32a12c809231d551e2b3fa5ee28eac6b55b68d03a0764ce1b8. - arm64 full CodeDirectory SHA-256:
e52fe90b472ea3a5a9c7b11c36b22b751882e92ed7664aa20fd93e1fd72e7ee1. - Bundle identifier:
com.eastcoastscience.Tyrell. - Team identifier:
ZU2882L4HT. - Hardened runtime: enabled.
- Designated-requirement SHA-256:
7467a4ae84b198c35fa624c55939276f7ad2989f7dab4e102a71af6f2d7e33dc, exact match to the preceding signed install.
Commands and verification
swift test: 149 core/transport, 65 TyrellBarSupport, and 51 TyrellAppSupport tests passed; 265 total.- Five script contract suites passed: deployment planning, operational
entrypoints,
/Applicationsdeployment, app bundle, and lifecycle/canary receipt. - Release build, shell syntax,
git diff --check, universal architecture, signature, bundle/team/runtime, designated requirement, endpoint, and process-count gates passed. - Local runtime verification:
- exactly one
/Applications/Tyrell.app/Contents/MacOS/Tyrellprocess; http://127.0.0.1:43117/api/statusreturned HTTP 200;http://127.0.0.1:43118/api/statusreturned HTTP 200;- Settings reported Full Disk Access
Grantedfrom the app-process probe.
- exactly one
- Designated canary nonce:
tyrell-0203-canary-20260829-0446-fbd1ed8. - Canary probe:
/Users/richh/.tyrell/canary-probes/tyrell-0203-canary-20260829-0446-fbd1ed8.json, SHA-256d2769ece019e7f309a103bc65888f11b0e6efe4835c24aac513267448298c604. - Accepted canary receipt:
/Users/richh/.tyrell/canary-receipts/tyrell-0203-canary-20260829-0446-fbd1ed8.json, SHA-256ace76f19afb4daff748b1caeb4b6fad91a64fc32103fa2299865c2baca40b724. - The accepted canary decoded current fleet usage and completed
authenticated chat bootstrap/send/page plus
/whofrom the app. scripts/redeploy_app_fleet.zshrevalidated and installed the exact artifact using pinned host identities and the authenticated canary receipt. Final state:partial_pending,pending_hosts=rdmbair13m5,failed_hosts=none.rdmsm4x,rdmbair15m5,rdmpw3275m,jdmbair13m5, andrdmpw3265meach have the exact version, executable and CodeDirectory hashes, preserved designated requirement, one managed process, and both local endpoints returning HTTP 200.
Backup and rollback
- Local pre-release rollback bundle:
/Applications/.tyrell-rollbacks/20260829-044405-eff12320b7ff/Tyrell.app. - The fleet installer retains the current verified rollback per target and removes only older exact managed rollback copies according to its lifecycle contract.
- Source rollback is the pre-release main commit
9f97dda661baf6bf508c6710e76a8ff3350f010f; the isolated release branch and worktree remain preserved. - To undo on a host, stop only the exact managed Tyrell process,
restore that host's retained
/Applications/.tyrell-rollbacks/.../Tyrell.appto/Applications/Tyrell.app, validate signature/designated requirement, and launch exactly one process. Do not copy TCC databases or weaken TCC/SIP/firewall policy.
Outstanding owner actions
rdmbair13m5remains pending because its pinned tailnet route was unavailable and its LAN route rejected the authenticated management identity. Retry only when the authenticated path returns; no user action is required unless that host remains locked/offline.- Location remained not determined on rdmsm4x at acceptance time. macOS may show the standard consent prompt on a normal app launch; the app does not infer approval.
- Local Network remains truthfully unqueryable until a network operation supplies evidence.
- App-process Full Disk Access does not prove standalone daemon Full Disk Access; daemon protected-root health remains a separate future operational signal.
- Remote Git publication, notarization/public distribution, full
CloudKit/iOS rollout, LiteLLM ingestion, and
rdmbair13m5acceptance remain separate milestones.