rdmsm4x changelog — Tyrell Build 13 CloudKit transport independent audit
Completed a read-only independent audit of Tyrell Build 13 CloudKit
transport commit 7e0c34cb4c24317f242c966d09d20e372abf6e30,
confirming source-level guard ordering and sanitized projection behavior
while keeping production CloudKit publication unwired and
unperformed.
Scope
- Host:
rdmsm4x - Worktree inspected:
/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 - Requested commit:
7e0c34cb4c24317f242c966d09d20e372abf6e30 - Parent:
e7b8dff538e1709ff9819097a3090f5496c1c73d - Read-only source files inspected:
Sources/TyrellCloudProjection/ClusterSnapshotPublisher.swift,Sources/TyrellCloudProjection/ECSCloudKitSnapshotTransport.swift,ClusterSnapshotContract.swift, and the two focused test files. - Shared dependency inspected:
/Users/richh/dev/lib/ECSCloudKitentitlement probe, private-database adapter, and sync database protocol. - No repository/worktree source edit, merge, publication, signing, deployment, credential access, CloudKit state change, service change, or live network mutation.
Verification
- Focused transport test:
swift test --package-path /Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 --scratch-path /tmp/tyrell-build13-cloudkit-audit-20260902/swiftpm --filter ECSCloudKitSnapshotTransportTests→ 5 tests, 0 failures. - Focused publisher test:
swift test --package-path /Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 --scratch-path /tmp/tyrell-build13-cloudkit-audit-20260902/swiftpm --filter ClusterSnapshotPublisherTests→ 11 tests, 0 failures. - Focused log:
/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-focused-rerun-20260902.log - Focused log SHA-256:
b425690365d76e092fb12a60cb97a09f3a3a86032a56a2d46a7526fcc0e705c - Candidate handoff:
/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-independent-audit-20260902.md - Candidate handoff SHA-256:
30d8da347fe3ab31aab1ee580ed764d060431b3d7bc7544e85829670a0a5e5f2 - Exact candidate file hashes are recorded in the handoff.
Findings and decision
- Source-only verdict: accept as a guarded candidate for review/integration.
- Production verdict: no-adopt/no-publish until explicit owner integration, transport-level boundary decision, signing/provisioning/account/zone evidence, controlled sanitized fixture write, reader verification, and rollback evidence.
- Verified order: master role → explicit write authorization → exact Tyrell container entitlement → account status → typed projection/codec validation → exact Tyrell custom zone save.
- Verified private boundary: default
CloudKitSyncDatabaseselectscontainer.privateCloudDatabase; entitlement probe checks CloudKit service and exact container before database construction. - Verified sanitized output: exact 11-field allowlist, exact nested node keys, bounded identifiers/nodes/payload, path rejection, deterministic identity, and no sensitive source fields.
- No runtime wiring: new publisher/transport symbols occur only in source/tests/docs; no Tyrell executable, daemon, or iOS target instantiates them.
- Material risk: direct public transport save accepts arbitrary
SyncRecordandSyncZoneIDafter authorization; publisher-level exact record/zone validation does not protect a direct transport caller. - Secondary risk: public injectable entitlement probe/database factory can bypass the default checks if misused; constrain or document before production wiring.
- Test-quality gap: fake tests use counts and a failed-zone no-early-save check rather than a complete event-order recorder; default production factory and signed entitlement path remain untested by design.
Concurrent-state note
The target branch was clean at the requested commit when the audit
began. A concurrent agent subsequently advanced the same branch/worktree
to e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c; this audit did
not make that change and does not use that later state as evidence.
Backup and undo
The audit packet and focused log are retained under
/Users/richh/dev/_handoff. SwiftPM scratch output is under
/tmp/tyrell-build13-cloudkit-audit-20260902. No source
rollback is required because no source was changed. Removing only these
audit artifacts is the reversible undo for the local audit record.
Outstanding owner action
The integration owner must decide whether to tighten the direct transport seam, explicitly accept the source candidate, and separately authorize production signing/provisioning and a controlled private-zone fixture write. Keep the master runtime unwired until those gates pass.