rdmsm4x — Tyrell agent permission audit (EPIC-20260831-03)
Session: 2026-08-31 20:53 → 21:10 EDT (rdmsm4x,
macOS 27.0, arm64) Project:
~/dev/apps/tyrell · Follows:
SEC-20260831-09 /
~/dev/fleet/tcc-privileges
Built the agent-permission audit into Tyrell and filed the epic that tracks the rest. Tyrell now answers a question nothing on the fleet could answer: do the agent CLIs, terminal apps and sshd on this Mac actually hold Screen Recording, Full Disk Access and Accessibility — and is each grant still attached to the binary running right now.
Tickets filed
| Ticket | State |
|---|---|
EPIC-20260831-03 — agent permission audit |
open (parent) |
FEAT-20260831-09 — pure model, parsing, orphan
detection |
resolved |
FEAT-20260831-10 — read-only collector, live-binary
resolution |
resolved |
FEAT-20260831-11 — CLI subcommand + MCP tool |
in progress (MCP done, CLI blocked) |
UI-20260831-02 — app panel |
open |
FEAT-20260831-12 — fleet aggregation |
open |
FEAT-20260831-13 — alert on upgrade-orphaned
grants |
open |
ISSUE-20260831-20 — another session's SQLITE_BUSY
regression, routed not absorbed |
open |
Files
changed — all in ~/dev/apps/tyrell, none committed (see
"Why nothing was committed")
Sources/TyrellCore/AgentPermissionAudit.swift— new, pure/platform-freeSources/TyrellCore/AgentPermissionCollector.swift— new, read-only TCC reads via raw SQLite3Tests/TyrellCoreTests/AgentPermissionAuditTests.swift— new, 15 testsSources/tyrell-mcp/MCPMain.swift—agent_permissionsMCP toolPackage.swift— one line: the two new files added toTyrellRemoteSupport'sexclude:
Verification
swift build→ exit 0.swift test --filter AgentPermission→ 15 tests, 0 failures.- MCP
tools/listreturnsagent_permissions. - Called from the agent CLI (no Full Disk Access): system store
readable: false, reasonauthorization denied, 0 findings — not "nothing granted". - Called over
ssh(sshd holds Full Disk Access): read 151 real rows and emitted, from live data, the exact incident from earlier today: "claude: Accessibility, Full Disk Access, Screen Recording were granted to /opt/homebrew/Caskroom/claude-code@latest/2.1.251/claude, which no longer exists. The current executable is .../2.1.252/claude and holds none of them. Re-grant, then relaunch."
Why nothing was committed
Another session (7b602c9b, active) is mid-migration off
GRDB onto TyrellSQLite.swift + ecs0lib,
holding uncommitted changes to Package.swift,
SQLiteStateStore*.swift, StoreRefs.swift,
Sources/tyrell/Tyrell.swift (627 lines),
ChatRoutes.swift, Daemon.swift and
ChatAuthorityTests.swift. My one-line
Package.swift change lands in the same diff
hunk as their GRDB dependency removal: committing it would
sweep their whole migration into my commit, and committing the sources
without it would leave HEAD unbuildable. Left in the
working tree with the handoff written into Tyrell's
SESSION-STATE.md §5.
For the same reason there is no tyrell agent-permissions
subcommand yet — registering one means editing Tyrell.swift
while it is being rewritten. The MCP tool gives agents the same answer
with no collision.
Notable
Package.swiftchanged on disk between my read and my write (TyrellSQLite.swiftwas added to the exclude list in that gap). Re-reading immediately before writing preserved it. A whole-file write-back from the earlier read would have silently reverted their work.swift testhas one pre-existing failure that is not mine:ChatAuthorityTests.concurrentProjectProvisionCreatesOneChannelAndExactlyOneOwner,database is locked.TyrellSQLite.swiftdeclaresbusyModeat lines 27 and 32 but never callssqlite3_busy_timeout— exactly what GRDB'sbusyModewas configured for. Filed asISSUE-20260831-20and left to its owner.
Undo
Remove the three new files, revert the one exclude: line
in Package.swift and the agent_permissions
additions in MCPMain.swift. Nothing is committed,
installed, signed or deployed. No secrets read or written; every TCC
access was read-only.