rdmsm4x-changelog-20260902-1405-tyrell-build8-release-audit
Read-only Tyrell Build 8 release audit
Created the handoff packet for the Build 8 candidate and its canary/fleet verification sequence. This gives the release owner exact identity checks, state transitions, acceptance evidence, stop conditions, and rollback paths without changing a live application.
Scope
- Host:
rdmsm4x. - Candidate source:
/Users/richh/dev/_worktrees/tyrell-build8-integrated-20260902at clean commit609ef4e391d24f180b74ca105b4ae5b78fd39c01. - Live observation target:
rdmbair15m5only, through strict known-host SSH.
Files touched
- Created
/Users/richh/dev/_handoff/tyrell-build8-release-audit.md. - Created this durable changelog record.
Verification evidence
- Candidate bundle reported
Tyrell 0.2.0 (8), executable SHA-2569f50f9fb5ff5eae7a96623b19002d04b64e9b1138e7205c534b2bb80bf091bca, arm64 full CodeDirectory hash8f4dcff092840b870e01f90df1692e24c1d09c2c8485d913e2fc1472b167110d, TeamZU2882L4HT, hardened runtime, andx86_64 arm64architecture. - Strict signature verification passed. Local Gatekeeper assessment returned rejected; the handoff records this as an owner release-policy gate because the deployment scripts do not assess it.
- Five bundle/deployment/lifecycle contract tests passed.
- The designated canary remains signed Build 7 with one managed foreground GUI process; neither local status endpoint answered during the audit, so Build 8 acceptance is pending a fresh post-install probe and receipt.
- Existing verified Build 6 rollback on the canary was observed at
/Applications/.tyrell-rollbacks/20260902-013750-39e8bc016588/Tyrell.app.
Commands run
- Git/worktree identity and cleanliness inspection.
- Bundle plist, SHA-256, strict signature, arm64 full CodeDirectory,
hardened-runtime, architecture, and
--versioninspection. - Direct execution of the five script contract tests.
- Strict known-host SSH inspection of canary bundle identity, GUI process, rollback, and status endpoints.
Change and rollback
No application, deployment, DNS, ticket, source, configuration, or fleet state was changed. The only work product is the audit packet above; removing that packet would revert the work-output file change. No backup was necessary because no existing file was overwritten.
Outstanding owner action
Resolve the intended Gatekeeper assessment/trust path, choose a fresh deployment nonce, and follow the packet's canary-first release procedure. Do not reuse historical Build 7 probe or receipt evidence.