Tyrell Build 8 fleet release
Tyrell 0.2.0 (8) was accepted on the designated canary and deployed unchanged to all six Macs, together with the immutable Build 8 daemon; stale remote manifest evidence was refreshed so the fleet heatmap has current source data.
Scope
- Source/signing host:
rdmsm4x - App hosts:
rdmsm4x,rdmbair15m5,rdmpw3275m,rdmbair13m5,jdmbair13m5,rdmpw3265m - Source worktree:
/Users/richh/dev/_worktrees/tyrell-build8-integrated-20260902 - Release source commit:
609ef4e391d24f180b74ca105b4ae5b78fd39c01 - Release checkpoint commit:
835345e
Source files and product behavior
The Build 8 commits changed Tyrell app, bar, daemon, chat, activity, settings, glass appearance, shared-library disclosure, deployment tests, and the associated regression suites. The release checkpoint updated:
/Users/richh/dev/_worktrees/tyrell-build8-integrated-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build8-integrated-20260902/ISSUES.md
Build 8 includes authenticated remote heatmap/activity reads,
in-window Settings/About, multiple simultaneously enabled menu-bar
meters including the original colored bars, recency-sorted chat,
recipient-scoped read-only agent-bus rooms with chips, a durable
truthful chat outbox, liquid-glass intensity profiles, and real runtime
use of ECS0AppKit.SingleInstanceGuard.
Commands and operations
- Ran the complete Swift package suite and all five app deployment/lifecycle contract scripts before release; all exited zero.
- Built and signed the universal app with the project release tooling.
- Installed the hub daemon with
scripts/install_service.zsh --serverfrom the immutableb8-609ef4erelease directory. - Enabled Tailscale split-DNS acceptance on the five spoke Macs so the enrolled tailnet HTTPS endpoint resolves; no public exposure was created.
- Planned and executed the app deployment with
plan_app_deployment.zshandredeploy_app_fleet.zshusing nonceb8-20260902-1405-609ef4e. - Ran the staged app-driven canary probe and issued the nonce-specific
receipt on
rdmbair15m5. - Installed the same accepted app locally on
rdmsm4xwithinstall_app_local.zsh. - Staged and installed the Build 8 daemon, CLI, and MCP executable in
the immutable
b8-609ef4erelease directory on each spoke without rewriting its scratch repository. - Ran a bounded
tyrell syncon all five spokes and a self-sync on the hub.
Verification evidence
- App version:
Tyrell 0.2.0 (8) - Executable SHA-256 on all six hosts:
9f50f9fb5ff5eae7a96623b19002d04b64e9b1138e7205c534b2bb80bf091bca - arm64 CDHash:
8f4dcff092840b870e01f90df1692e24c1d09c2c8485d913e2fc1472b167110d - x86_64 CDHash:
9f2bed58d70bf0a5d822bc1ceb0a8122544169c8 - Team:
ZU2882L4HT; architectures:x86_64 arm64; strict deep signature verification passed. - Exactly one
/Applications/Tyrell.appprocess ran on every host. - Canary probe passed fleet-usage decode and authenticated chat
send/page/command. Receipt SHA-256:
5ea5aba675a3f5c7de2b3502abb2326fc3c11b5ce71ddf068eee308d26459495. - Each host resolved and reached
https://rdmsm4x-1.kangaroo-kitefin.ts.net:8443; status returned HTTP 200. - Unauthenticated remote activity returned HTTP 401; authenticated activity and chat returned HTTP 200.
- Each daemon ran exactly once from
/Users/richh/Library/Application Support/Tyrell/releases/b8-609ef4e/tyrelldand answered local status HTTP 200. - Final fleet sample: all remote manifest rows were seconds old rather than hours or days; the hub self-row was also current.
Rollback
- App: restore the host's immediate predecessor from
/Applications/.tyrell-rollbacks/20260902-14*/Tyrell.appthrough the signed lifecycle installer. - Hub daemon: reinstall
/Users/richh/Library/Application Support/Tyrell/releases/5c8f1b1/tyrelldin server mode. - Spoke daemon: repoint the LaunchAgent to the preserved
/Users/richh/dev/apps/Tyrell/.build/release/tyrelldartifact. - DNS preference:
tailscale set --accept-dns=falserestores the prior host preference if the secure endpoint is rolled back.
Outstanding owner actions
- Integrate and gate the next-build iOS read-only CloudKit snapshot client; a sanitized master publisher and first private-zone write remain separate approval/acceptance events.
- Continue behavior-proven shared runtime migration for persistence, networking, and logging. Do not treat a package import as adoption.
- Historic chat in CloudKit remains a future, separately designed privacy/retention schema.