rdmsm4x changelog — Tyrell Build 14 independent audit
Completed a read-only independent audit of the pinned Tyrell Build 14 iOS durable outbox source slice; the packet records a conditional client-source adoption verdict and blocks release/runtime claims until the retry/crash gaps are explicitly handled.
Scope
- Host:
rdmsm4x. - Project: Tyrell, Production mode.
- Candidate inspected:
/Users/richh/dev/_worktrees/tyrell-build14-ios-durable-outbox-20260902at89d309c0c96e37c653ec1331a2fc2390ff016ab1, parente0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c. - No source, candidate worktree, server, CloudKit, APNs, credential, signing, deployment, or physical-device state was modified.
Exact files created outside the repository
/Users/richh/dev/_handoff/tyrell-build14-ios-durable-outbox-independent-audit-20260902.md/Users/richh/dev/_handoff/tyrell-build14-ios-durable-outbox-focused-rerun-20260902.log/Users/richh/dev/_handoff/tyrell-build14-ios-durable-outbox-package-focused-rerun-20260902.log- This changelog file.
Commands and evidence
git -C /Users/richh/dev/_worktrees/tyrell-build14-ios-durable-outbox-20260902 status --short --branchremained clean.git diff --check e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c 89d309c0c96e37c653ec1331a2fc2390ff016ab1exited 0.- Focused iOS simulator xcodebuild run: 6/6 selected tests passed,
exit 0. Log SHA-256:
9e801527422b44e3514b586e680204129f4fff8e184eb2407830e7333409dd91. - Corrected focused package run from the exact candidate root: 3/3
outbox tests passed, exit 0. Log SHA-256:
c5588e7efa2569fc0934624e499226c85eca4733a8fd337a65c80c500a302882. - Independent packet SHA-256:
7269ff2782cb33684d076844d1009aa40562dbe7a248413e824e113a97131922. - Verdict: conditional adopt as client-only source; not
release/runtime acceptance. The queue is device-local plaintext with
final mode 0700/0600 protections, FIFO/head backoff, nonce tuple
deduplication, truthful terminal/ambiguous state, and no false
Delivered. Total retry count is unbounded, manual/bootstrap fast path can bypass persisted delay on each call, and crash-after-server-commit behavior is at-least-once relying on server idempotency; these are explicit owner gates.
Backup / undo
No repository or system state requires rollback. The audit packet and logs are additive handoff evidence; retain them for provenance. If the owner withdraws the audit record, preserve the files as historical evidence rather than deleting candidate source.
Outstanding owner action
Owner must integrate only the exact commit onto a clean hardened successor, decide the retry/fast-path/plaintext/tie/ownership contract, add a local fake-server crash-window test proving one server record for a retried nonce, regenerate the ignored iOS project, and rerun the integrated package/iOS gates. No live service or CloudKit/APNs action is implied.