rdmsm4x-changelog-20260902-1506-tyrell-build9-integrated-source-gates
Tyrell Build 9 integrated source gates
Integrated and independently revalidated the Build 9 iOS private-snapshot, sanitized publisher, and shared-persistence slices while keeping the accepted Build 8 fleet runtime unchanged.
Scope and identity
- Host:
rdmsm4x - Project: Tyrell, production mode
- Integration worktree:
/Users/richh/dev/_worktrees/tyrell-build9-integrated-20260902 - Branch:
codex/tyrell-build9-integrated-20260902 - Clean checkpoint:
42f1ee9574b4ccd077edf1d3414c42450ae3f91e - Umbrella ticket:
FEAT-20260902-03 - Canonical dirty checkout and accepted Build 8 worktree were not edited.
Integrated changes
- Added one shared
TyrellCloudProjectioncontract used by the iOS reader and the master-side publisher. - Added a master-only sanitized snapshot publisher behind an injectable fake transport. This build intentionally contains no production CloudKit adapter.
- Enforced the exact record and nested-node allowlists, deterministic identity and ordering, bounded payloads, freshness/provenance evidence, and fail-closed role, entitlement, and account behavior.
- Added the iOS CloudKit state card to Fleet and Chat, including checking, live, awaiting-first-snapshot, retained-offline, and unavailable states plus cache, freshness, provenance, revision, last pull, and last attempt.
- Replaced Tyrell's duplicate SQLite value/row representation with
ECS0Persistence.DatabaseValueandDatabaseRowin the production compatibility path. - Integrated the shared-logging privacy gate and networking equivalence map. No unsafe logging or networking runtime replacement was made.
- Defined explicit source, CloudKit, iOS, macOS canary, fleet, and rollback acceptance gates.
Verification
- Complete Swift package run: 235 XCTest cases across four bundles plus 386 Swift Testing cases, 621 distinct tests, zero failures, exit 0.
- Raw package output:
/Users/richh/dev/_handoff/tyrell-build9-final-swift-test-20260902-1500.log, SHA-256126c0feef3a8aa35a32677f839e529842eeb399e25c91d0e6723a4f45d093f50. - Complete iPhone 17 Pro simulator run: 28 tests, zero failures, exit 0.
- Raw iOS output:
/Users/richh/dev/_handoff/tyrell-build9-final-ios-test-20260902-1505.log, SHA-2568d6eb0cf3866909428a64a5ae6bfd0e6ca60233eb899e55f8aa99fb7d65862c0. - Release builds of
TyrellCloudProjectionandtyrelld: passed. git diff --check: passed; final worktree clean.- The earlier 570 shorthand was corrected: the shared helper counted
only the largest 184-case XCTest bundle and omitted the 30-, 10-, and
11-case bundles. Evidence and regression requirements were added to
FEAT-20260901-25.
External-state boundary
- No production CloudKit container, account, zone, schema, record, or file asset was read or written by the publisher lane.
- No physical iPhone signing, installation, launch, device mutation, or notification acceptance is claimed.
- No Build 9 app signing, macOS canary, daemon rollout, or fleet deployment occurred.
- Tyrell 0.2.0 build 8 remains the accepted installed runtime on the six-Mac fleet.
Rollback
- Source-only rollback: revert the Build 9 integration commits or
branch again from accepted Build 8 checkpoint
835345e850c909583283e21c39d1494e067668d0. - The shared-persistence change requires no schema/data rollback because it changes in-memory binding/row representation only.
- Runtime rollback is not required for Build 9 because no Build 9 runtime was deployed. Existing signed Build 8 app and immutable Build 8 daemon rollback artifacts remain in place.
Next work
- Implement the privacy-safe typed logging API and authenticated injectable HTTP client in isolated ecs0lib owner lanes before any further Tyrell replacement.
- Repair the agentkit multi-bundle counter with the retained Build 9 log as a regression fixture.
- A real private CloudKit write,
rdip17pphysical-device canary, Build 9 signing,rdmbair15m5macOS canary, and fleet rollout remain separate acceptance gates.