rdmsm4x-changelog-20260902-1936-tyrell-build13-cloudkit-ios-source-integration
Tyrell Build 13 guarded CloudKit and iOS source integration
Completed and independently reviewed the next source-only Tyrell milestone: a fail-closed ECSCloudKit transport for sanitized master snapshots plus truthful iOS sender acknowledgement states. This matters because the product can now progress toward private CloudKit remote visibility without either leaking fleet evidence or claiming recipient delivery that has not occurred.
Scope
- Host:
rdmsm4x - Project: Tyrell, Production mode
- Ticket:
FEAT-20260902-26(resolved as a source-integration milestone) - Isolated worktree:
/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 - Branch:
codex/tyrell-build13-cloudkit-transport-20260902 - Exact base:
e7b8dff538e1709ff9819097a3090f5496c1c73d - Final clean checkpoint:
75459efa8b0f28db4271ce1ae57339c2052f9ef6 - Tested source HEAD:
02bc5403fb9056b180149e986bf82505dd23ae35 - Accepted live fleet remains Tyrell
0.2.0 (11); Build 13 was not signed, installed, launched, or deployed.
Files and source units changed
/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/Sources/TyrellCloudProjection//Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/Tests/TyrellCloudProjectionTests//Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/ios/TyrellMobile/ChatView.swift/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/ios/TyrellMobileTests//Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902/ISSUES.md/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-20260902.md/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-independent-audit-20260902.md/Users/richh/dev/_handoff/tyrell-build13-combined-package-02bc540-20260902.log/Users/richh/dev/_handoff/tyrell-build13-combined-ios-02bc540-20260902.log/Users/richh/dev/_handoff/tyrell-build13-combined-02bc540-20260902.xcresult/Users/richh/dev/issues/resolved/FEAT-20260902-26-tyrell-build-13-guarded-cloudkit-publish.md
Delivered behavior
- Added a guarded master-snapshot publisher that accepts only the
closed, provenance-stamped
TyrellClusterEvidenceSourcemodel and emits the exact sanitizedTyrellClusterSnapshotallowlist. - Enforced gate order: master role, explicit write authorization, exact Tyrell entitlement, available iCloud account, validated projection, exact private custom zone, then save.
- Made CloudKit writes disabled by default. The public production initializer fixes the exact Tyrell container, real entitlement probe, and real ECSCloudKit private database; dependency injection remains internal to tests.
- Hardened direct saves so a foreign zone, noncanonical type/name, or unsanitized fields are rejected before database construction.
- Added truthful iOS sender state: a matching conversation ID and
immutable client nonce means only
Accepted by Tyrell; recipient status unknown; a proven terminal rejection saysFailed โ not queued; ambiguous network/timeout/malformed acknowledgements make no acceptance or delivery claim. - Never render
Deliveredbecause no recipient-receipt protocol is implemented yet.
Commands and verification evidence
- Ran the full Swift package suite without parallel test execution: 242 XCTest + 389 Swift Testing = 631/631 passed, zero failures.
- Built the
TyrellCloudProjectionrelease product successfully. - Regenerated the ignored iOS Xcode project with XcodeGen 2.46.0.
- Ran the complete iOS simulator suite on a disposable iPhone 17 Pro
Max / iOS 27 simulator: 49/49 passed,
TEST SUCCEEDED; then shut down and deleted that simulator. - Independently audited the public API boundary and hardened the two initially identified risks. The focused post-hardening suite passed 17/17.
- Re-read Git state after the documentation checkpoint: final worktree
clean at
75459efa8b0f28db4271ce1ae57339c2052f9ef6. - Package log SHA-256:
ef7808ff8f9abdc2ae9f807392c1f688ce451cfaefe2213910b390986e41cfb8 - iOS log SHA-256:
feae92b12abc7c69bb3b184bc886eef5b8389cc8c913905702bcef620dc8bba5 - Independent audit SHA-256:
62f8e040148296db5b57b995b6119c0d794030cec4a38c622df47c7662d4980b - Integration handoff SHA-256:
9c6d3479725d4b4aa00138cea6324342ccb35967625a717d2ee3ea0a541805ba
Safety and non-actions
- No canonical Tyrell or ecs0lib checkout was edited.
- No production CloudKit read/write, zone/schema mutation, account change, credential access, APNs action, signing, physical-device install, service restart, daemon replacement, canary, or fleet deployment occurred.
- No prompts, responses, memory bodies, provider databases, credentials, or secret values were stored in source, logs, tickets, or this record.
Backups and rollback
- Source is isolated on the branch and worktree above; discard the isolated branch for complete rollback.
- For a commit-level rollback, revert
02bc5403fb9056b180149e986bf82505dd23ae35,e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c, and7e0c34cb4c24317f242c966d09d20e372abf6e30in reverse order. - The accepted Build 11 fleet does not need rollback because it was untouched.
Outstanding owner actions and next gates
- Production CloudKit still requires separately authorized
signing/provisioning, exact entitlement and account verification,
private zone/schema validation, one known sanitized fixture write, iOS
reader confirmation, designated
rdmbair15m5canary, and rollback proof. - Build 14 is implementing a private, durable, device-local FIFO outbox with reconnect retry and nonce deduplication.
- Shared persistence, networking, and logging candidates remain isolated until the ecs0lib owner explicitly publishes them and Tyrell proves behavior, privacy, and concurrency compatibility before runtime replacement.