Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260902-0103-tyrell-build5-fleet-rollout-and-hub-daemon

rdmsm4x — Tyrell 0.2.0 build 5 rolled to all six hosts; hub daemon rolled to a1ed2fe

2026-09-02 00:03 → 2026-09-02 01:03:41 EDT · rdmsm4x · Claude Code (session tyrell-c5), unattended on Rich's instruction

Rich, 00:1x EDT: build 3 showed no consolidated settings pane, the app not named "Tyrell", spokes seeing only themselves, Full Disk Access "denied/unavailable" although granted, and the Location button opening the wrong Settings section. Then: "continue iterating through Tyrell.app re-building, re-deploying to fleet as you add/solve issues."

Result

Host Before After
rdmsm4x (hub) app build 3 (Aug 29); tyrelld 7662e97 (Aug 28) app build 5; tyrelld a1ed2fe (7662e97 retained)
rdmbair15m5 (canary) build 3 build 5 — probe PASS, receipt accepted
rdmbair13m5 · jdmbair13m5 · rdmpw3265m · rdmpw3275m build 3 build 5 (--execute-fleet: pending=none failed=none)

Measured from every spoke after rollout: app running, display name "Tyrell", local daemon reports 6 fleet rows, chat bootstrap on the hub HTTP 200 in 0.47–0.70 s (was ~9 s → chat_unavailable). Permission health run as the installed app on rdmsm4x and the canary: Full Disk Access granted, Location granted, Login Item granted.

What was actually wrong (each measured, not inferred)

  1. The user was looking at build 3. The fresh build sat in .build/, never installed.
  2. "Unavailable" — the daemon-identity resolver looked for an install.json nobody writes and a path inside the bundle; found nothing; every daemon-evaluated row read Unavailable while tyrelld ran. Now resolved from the LaunchAgent's ProgramArguments.
  3. Location "wrong section" — open(url) does not navigate an already-open System Settings window (4/4 stayed on the previous pane; 6/6 correct after quitting first). Fixed: quit, then open.
  4. "Spokes only see themselves" — the hub's old daemon answered chat bootstrap only after ~9 s (write lock free, CPU idle — the wait was in its request path); the canary probe's budget is 8 s. HEAD's daemon answers in 0.4–0.7 s — but would have answered 409 for everyone, because 7662e97 had archived 854 project rooms and HEAD treated each as a conflict. Fixed in a1ed2fe: archived = retired, skipped. Proven against a snapshot of the hub DB before the rollout.
  5. Name — "tyrell" was a deliberate 08-25 decision; reversed per Rich (DEC-20260902-01).

Commits

bf23ea8 build 4 (name, FDA probe, anchors, agent-permissions pane, headless dump) · a1ed2fe build 5 (retired channels, snapshot diagnostic) · 64e1f76 session state. Tests: 360 → 363, 0 failures. Bundle: universal2, Apple Development, DR unchanged 30c2c43e….

Tickets

Resolved: TASK-20260902-01, UI-20260902-01, ISSUE-20260902-02/-03/-04, UI-20260831-02, INCIDENT-20260901-04, ISSUE-20260831-20. Opened: FEAT-20260902-01 (periodic re-inventory — every host scans once at launch; the hub never self-scans, its row is 3 days stale), ISSUE-20260902-05 (daemon dies on EADDRINUSE during restart; KeepAlive recovers in ~30 s; install_service reports a false CRITICAL).

Not done tonight, deliberately

Spoke daemon rollout (deploy_fleet.zsh) — no spoke-side change landed; night-time remote builds add risk for no gain. HEAD's files-derived fallback created new project rooms on the hub on first bootstrap (324 provisioned) — recorded for the FEAT-20260831-03 owner rather than re-policied.

Undo

App: sudo zsh scripts/install_app_local.zsh --bundle /Applications/.tyrell-rollbacks/20260902-005939-e52fe90b472e/Tyrell.app … (per host, rollback dirs retained). Hub daemon: zsh scripts/install_service.zsh --server --binary "~/Library/Application Support/Tyrell/releases/7662e97/tyrelld".

No secrets recorded. Token values never printed (fingerprints only).