rdmsm4x-changelog-20260902-1455-tyrell-build9-cloudkit-publisher
rdmsm4x-changelog-20260902-1455-tyrell-build9-cloudkit-publisher
Implemented and verified a source-only, master-gated sanitized Tyrell cluster snapshot publisher so the accepted iOS reader can share one closed evidence contract without authorizing or performing a production CloudKit write.
Scope
- Host:
rdmsm4x - Project: Tyrell, production mode
- Ticket:
FEAT-20260902-04 - Isolated worktree:
/Users/richh/dev/_worktrees/tyrell-build9-cloudkit-publisher-20260902 - Branch:
codex/tyrell-build9-cloudkit-publisher-20260902 - Base:
701788f2d368cba49224c70735f0d67f2d3c3293 - Commit:
6d394b496315db06d0ec744132a5ab831b1d99db
Files changed
Package.swiftSources/TyrellCloudProjection/ClusterSnapshotContract.swiftSources/TyrellCloudProjection/ClusterSnapshotPublisher.swiftTests/TyrellCloudProjectionTests/ClusterSnapshotPublisherTests.swiftios/Sources/MobileCloudSnapshot.swiftios/project.ymldocs/architecture/2026-09-02-ios-cloudkit-next-build-gates.mdSESSION-STATE.md/Users/richh/dev/_handoff/tyrell-build9-cloudkit-publisher.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-tyrell-build9-cloudkit-publisher-20260902.json
Changes
- Added a shared
TyrellCloudProjectioncontract and a master-only publisher behind an injectable transport protocol. - Added exact top-level and nested allowlist validation, bounded identifiers/node count/payload, deterministic record identity and node serialization, explicit provenance and freshness-derived evidence.
- Added fail-closed role, entitlement and CloudKit account gates and non-sensitive failure reason codes.
- Kept credentials, prompts, responses, memory bodies, provider databases, raw chat, file content and sensitive paths outside the typed source model and runtime contract.
- Reused the shared contract from the iOS reader, removing its duplicate schema and codec.
- Added no production transport adapter; automated tests use only an in-memory fake.
Verification commands and evidence
swift test --filter ClusterSnapshotPublisherTests: exit 0; 10 tests, 0 failures.swift test: exit 0; package XCTest bundles reported 235 tests, 0 failures.swift build -c release --target TyrellCloudProjection: exit 0.xcodegen generate --spec project.ymland the Tyrell Mobile iPhone 17 Pro simulator test: 22 tests, 0 failures,TEST SUCCEEDED.git diff --check: exit 0 before commit.- Repository state after commit: clean.
The developer frameworks emitted pre-existing duplicate
UniversalHID warnings during package tests. The iOS error
fixtures emitted expected loopback connection-refused messages. Neither
caused a test failure. No CloudKit container, account, zone, schema,
record, file-asset, signing, installation, runtime launch, canary or
deployment operation was performed.
Handoff and rollback
- Handoff:
/Users/richh/dev/_handoff/tyrell-build9-cloudkit-publisher.md - Integration requires re-observing the Build 9 integration worktree
and cherry-picking
6d394b496315db06d0ec744132a5ab831b1d99db. - Before integration, rollback is omission of that cherry-pick.
- After source integration and before deployment, use
git revert 6d394b496315db06d0ec744132a5ab831b1d99dband rerun package and iOS tests. - There is no CloudKit data rollback because this lane performed no remote write.
Outstanding owner/release gates
- Production transport adapter and retention/pruning design.
- Explicit Apple Developer provisioning and first private-zone fixture authorization.
- Signed
rdip17pdevice canary and independentrdip17airrepeat. - Runtime integration and deployment acceptance.