rdmsm4x-changelog-20260901-1508-tyrell-worktree-integrity-containment
Tyrell worktree integrity containment
Installed a non-destructive integrity monitor and commit gate so a preserved-mtime stale copy cannot silently erase the only recoverable revision of in-flight Tyrell work.
Scope
- Host:
rdmsm4x - Canonical checkout monitored:
/Users/richh/dev/apps/Tyrell - Incident:
INCIDENT-20260901-04 - Portfolio follow-on:
EPIC-20260901-02 - No disputed Tyrell source file was restored, reverted, staged, or committed.
Changes
- Installed Homebrew
fswatch1.22.0 for event-driven filesystem observation. - Added
/Users/richh/bin/worktree_integrity_watch.zsh.- Content-addresses each observed dirty revision under
~/.agent-coordination/worktree-integrity/. - Detects content replacement whose modification time moves backwards.
- Captures candidate Claude, Codex, and agy processes whose current directory is inside the affected worktree.
- Never restores, checks out, stages, commits, or edits project content.
- Content-addresses each observed dirty revision under
- Added
/Users/richh/Library/LaunchAgents/com.eastcoastscience.worktree-integrity.tyrell.plist.- Runs the watcher in the GUI launchd domain.
- Watches canonical Tyrell through FSEvents with
.gitand.buildexcluded.
- Added the local shared Git hook
/Users/richh/dev/apps/Tyrell/.git/hooks/pre-commit.- Blocks direct commits from canonical
mainunless the integration override is explicit. - Blocks commits where a staged path also has a different unstaged revision unless an explicit reviewed override is used.
- Blocks direct commits from canonical
- Preserved the pre-containment dirty Tyrell state at
/Users/richh/.agent-coordination/snapshots/rdmsm4x/Tyrell/20260901-144708.
Verification
zsh -n /Users/richh/bin/worktree_integrity_watch.zshpassed.plutil -lintpassed for the LaunchAgent.- Disposable Git regression:
- established a committed baseline;
- observed a newer dirty revision;
- replaced it with an older preserved-mtime copy;
- watcher retained both content objects and emitted exactly one
criticalbackward-mtime event.
- Git-hook regression:
- canonical-main commit attempt blocked with rc 1;
- clean linked-worktree invocation passed with rc 0;
- staged-plus-unstaged same path blocked with rc 1;
- explicit reviewed override passed with rc 0.
- Live LaunchAgent evidence at 15:08 EDT:
- state
running; - PID 35898;
- runs 1;
- never exited;
fswatchchild observed.
- state
- Live monitor state:
- HEAD
2f4a1222979530d50598394d2b3dd66f2c43b3a4; - 12 current dirty content objects preserved;
- 0 new critical transitions after installation.
- HEAD
- Artifact SHA-256:
- watcher
b8fe6484847ab555879f1f0b2684f5180ae9fd18f3ea63aeb4e3202ea9a6e999 - LaunchAgent
34edf294123c8818f214fe8566561dc0535b05f0f54197edf650780d5462fbc0 - hook
2a20bf460d83c886f5a1dc282698012dfbb9e491f86b8c039e35e9015e68d3d5
- watcher
Coordination
- Asked
claude@rdmsm4xfor exact Tyrell dirty-path ownership and stale-copy attribution in messages20260901-144546-13FAEA57,20260901-145207-DBBA84D7, and20260901-150509-A082BD1A. - Relayed Rich's all-app priority in
20260901-150706-CFD9A502. - Relayed the follow-on ecs0lib integration, rebuild, package, launch,
and smoke-test directive in
20260901-150733-821E7036. - Claude's explicit Tyrell ownership response remains outstanding as of this record.
Rollback
- Stop the monitor with
launchctl bootout gui/501/com.eastcoastscience.worktree-integrity.tyrell. - Preserve the three installed files before removing them if rollback evidence is required.
- Removing the LaunchAgent, watcher, or hook does not modify any Tyrell source revision.
- Homebrew
fswatchmay remain installed; it is inert without a consumer.
Outstanding actions
- Reconcile Claude's ownership of the seven pre-existing dirty/untracked Tyrell paths.
- Restore or integrate the two historically reverted deployment scripts only after that ownership response.
- Roll the integrity mechanism out portfolio-wide only after each app's writer, worktree, dirty state, and recovery snapshot are recorded.
- Resume
FEAT-20260901-15from its clean isolated chat worktree after incident containment is accepted.