Tyrell headless-version diagnostic recovery
A read-only fleet version check exposed a Tyrell lifecycle defect:
invoking the installed GUI executable with --version
initialized AppKit and launched a second GUI process on five remote
Macs. The exact diagnostic process trees were stopped, the accepted
Build 8 runtime topology was restored, and an isolated Build 11 source
fix was opened so future headless checks exit before AppKit or
instance-lock initialization.
Scope
- Operator host:
rdmsm4x. - Runtime hosts checked:
rdmsm4x,rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Live artifact changed: none.
- Source worktree changed by this recovery: none. The follow-on fix is
isolated under
/Users/richh/dev/_worktrees/tyrell-build11-headless-version-guard-20260902and tracked separately asISSUE-20260902-15. - No canonical Tyrell checkout, database, preference, credential, permission, launch agent, daemon release, or installed application bundle was edited.
Incident and bounded remediation
The installed Tyrell GUI executable was invoked remotely with
--version, expecting a bounded headless result. Instead, it
initialized the SwiftUI/AppKit application lifecycle and launched these
exact transient process trees at approximately 17:15 EDT:
rdmbair15m5: child8818, diagnostic-shell parent8810.rdmbair13m5: child45267, parent45259.rdmpw3265m: child54967, parent54953.rdmpw3275m: child24604, parent24590.jdmbair13m5: child33329, parent33321.
Only those newly created diagnostic trees were terminated.
Pre-existing Tyrell GUI and daemon processes were preserved.
rdmsm4x had its accepted Build 8 daemon but no GUI before
the diagnostic; the local GUI was restored once with
open -a /Applications/Tyrell.app, resulting in GUI PID
24625 and daemon PID 15196.
Verification evidence
A new safe verification used only process inventory and SHA-256
reads; it did not execute the installed Tyrell binary. At 17:23 EDT all
six hosts had exactly one Tyrell GUI and one tyrelld
process:
rdmsm4x: daemon15196, GUI24625.rdmbair15m5: daemon1029, GUI1177.rdmbair13m5: daemon1032, GUI1122.rdmpw3265m: daemon97534, GUI92901.rdmpw3275m: daemon38354, GUI32398.jdmbair13m5: daemon959, GUI1055.
Every installed GUI executable independently hashed to the accepted
Build 8 SHA-256
9f50f9fb5ff5eae7a96623b19002d04b64e9b1138e7205c534b2bb80bf091bca.
The accepted Build 8 daemon release path remains
~/Library/Application Support/Tyrell/releases/b8-609ef4e/tyrelld.
Commands and safeguards
- Read-only inventory used
pgrepandshasum -a 256, locally and over bounded batch-mode SSH. - Cleanup targeted only the exact transient PIDs listed above.
- No installed-binary
--versionprobe will be repeated until the Build 11 lifecycle fix is integrated, tested, signed, canaried, and deployed. - The Build 11 regression gate must prove that
--versionand permission-health JSON exit beforeNSApplication/SwiftUI startup and create no instance-lock or background process.
Rollback
No artifact or persistent configuration changed, so no runtime rollback is required. If the isolated Build 11 lifecycle change fails its gates, discard or revert only that isolated branch and keep Build 8 live. The safe fleet verification remains process inventory plus artifact hash until a corrected release is deployed.
Outstanding action
Finish ISSUE-20260902-15, integrate its clean source
commit into the combined Build 11 worktree, run lifecycle subprocess
tests plus the full package/iOS/release matrix, then perform the normal
build/sign/designated-canary/fleet rollout sequence. Apple Notes
publication of this changelog should occur after the currently active
Notes write finishes.