rdmsm4x-changelog-20260902-1349-tyrell-build8-bus-security
Tyrell Build 8 bus and activity security
Completed the bounded Build 8 agent-bus and activity endpoint security remediation in an isolated linked worktree. This matters because private fleet-bus messages are now visibility-scoped, imported evidence is immutable to Tyrell clients, common secret formats fail closed, and remote activity reads require the existing fleet token.
Scope
- Host:
rdmsm4x - Project: Tyrell
- Runtime/deployment: none; no daemon, app, fleet-bus file, or installed artifact was changed.
- Ticket:
SEC-20260902-01 - Branch:
codex/tyrell-build8-bus-security-20260902 - Base:
4f950e76e4e122394722dc4999c7fad8b517de35 - Commit:
252d4e05b11befd4e4542c12ab10836640741304
Files changed
/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellBarSupport/UsagePolling.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellCore/AgentBusChatImport.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellCore/ChatServerLogic.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellCore/ChatStore.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellCore/SQLiteStateStore+Chat.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/TyrellCore/ServerLogic.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/tyrell-app/AppStatusFeed.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/tyrellbar/StatusFeed.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/tyrelld/ControlServer.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Sources/tyrelld/Daemon.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Tests/TyrellBarSupportTests/UsageEndpointPolicyTests.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Tests/TyrellCoreTests/AgentBusChatImportTests.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Tests/TyrellCoreTests/ChatAuthorityTests.swift/Users/richh/dev/_worktrees/tyrell-build8-bus-security-20260902/Tests/TyrellCoreTests/ServerLogicTests.swift- Handoff:
/Users/richh/dev/_handoff/tyrell-build8-bus-activity-security.md
Commands and verification
swift test --filter AgentBusChatImportTests: exit 0, 7 tests passed.swift test --filter ServerLogicTests: exit 0, 17 tests passed.swift test --filter UsageEndpointPolicyTests: exit 0, 8 tests passed.swift test: exit 0, 605 tests passed, zero failures.swift build --product tyrelld: exit 0.git diff --check: exit 0.- Worktree was clean after commit.
- Xcode 27 emitted the existing duplicate UniversalHID warnings; verification remained green.
Backup and undo
- The original canonical/lead worktree was not edited.
- Undo before integration: delete or retain the isolated branch/worktree; no runtime rollback is needed.
- Undo after integration: revert commit
252d4e05b11befd4e4542c12ab10836640741304through the owning integration worktree, then rerun the full suite.
Outstanding owner actions
- Lead owner must review and cherry-pick
252d4e05b11befd4e4542c12ab10836640741304. - Combined release-candidate regression and the designated canary/fleet release gates remain separate and were not performed here.
- Any pre-release database that previously ran the recipient-blind bus projection should be quarantined or rebuilt before canary rather than accepted as security evidence.