rdmsm4x-changelog-20260902-2020-tyrell-build14-integrated-outbox
Tyrell Build 14 completed a source-only durable iOS chat-outbox integration with secure atomic persistence, deterministic recovery, guarded reconnect retry, and truthful master-acceptance status; the live six-Mac Build 11 runtime was deliberately unchanged.
Scope
- Host performing source work:
rdmsm4x - Project worktree:
/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902 - Branch:
codex/tyrell-build14-integrated-20260902 - Ticket:
FEAT-20260902-29 - Exact source code checkpoint:
55d9d4568b8abc355effb4409da5d0caf009afc4 - Final documentation checkpoint:
8270ed192956b6228fe075bda21c637acf724766 - No canonical Tyrell, canonical ecs0lib, production CloudKit/APNs, installed app, daemon, service, credential, signing state, physical device, canary, or fleet runtime was changed.
Files changed
/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/Sources/TyrellAppSupport/ChatOutboxStore.swift/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/Tests/TyrellAppSupportTests/ChatTransportTests.swift/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/Tests/TyrellCoreTests/ChatServerLogicTests.swift/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/ios/Sources/MobileStores.swift/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/ios/Tests/TyrellMobileTests.swift/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build14-integrated-20260902/ISSUES.md/Users/richh/dev/_handoff/tyrell-build14-integrated-20260902.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-tyrell-build14-integration-20260902.json- Local ticket lifecycle records for
FEAT-20260902-29and its generated private dashboard pages.
What changed
- Outbox replacement files are opened at mode 0600 before writing, synced, and atomically renamed; their directory is enforced at 0700.
- Monotonic append sequence preserves equal-time FIFO; legacy format-v1 snapshots without the sequence field upgrade in persisted array order.
- Successful bootstrap bypasses persisted delay only when connectivity transitions from unknown/offline to online; repeated refreshes honor backoff.
- The existing SQLite chat master has a regression proving that a retry after the commit/lost-ack crash window returns the original envelope for the immutable conversation/nonce and creates no duplicate.
- Sender status remains queued, failed-not-queued, or
accepted-by-Tyrell with recipient status unknown. No recipient
DeliveredorReadstate is fabricated.
Commands and validation
- Ran focused Swift package tests for outbox ordering, migration, permissions, retry policy, and server idempotency.
- Ran
swift test --no-parallel -j 4: 242 XCTest plus 391 Swift Testing tests, 633/633 passed. - Ran the complete generated iOS project on a disposable iOS 27 iPhone 17 Pro simulator: 53/53 passed; the simulator was deleted.
- Ran release builds for
TyrellCloudProjectionandtyrell-app; both passed. - Ran
git diff --checkand explicit-path staging before commits. - Independent report conditionally accepted the source boundary.
Evidence
- Full package log SHA-256:
18fe806932f02e3183926cdfd9dacff36c128fd20410932bfeb7cf61ed1bbc92 - Full iOS log SHA-256:
92e714fd7c2c90857c7599803df7d151499e4a01abb08f3112c1d6b08cfa3d13 - Release cloud-projection log SHA-256:
4afd70aa3b7bad5bd37bd5829594ebe580d1d0a0cb6428b12f769fb012aebc8e - Release app log SHA-256:
9806243803d2dac316373ae1d92cfeec7c55ef004db2a25ada0f0397baee0a80 - Independent audit SHA-256:
0c4e4be98e3f9a2e8e23cc855641ef77f9cd3eb48e8329638b9b70cdb251aae6 - Full handoff SHA-256:
e4ec01b3156b436d0d2883fff3c7e36368c63f26c3637038ca24b4fef1e954c4
Backup and undo
No live state changed, so no runtime restore is required. Preserve
the Build 14 branch and handoff. To undo source in a new isolated
worktree, start from Build 13 checkpoint
75459efa8b0f28db4271ce1ae57339c2052f9ef6, or revert
55d9d4568b8abc355effb4409da5d0caf009afc4 followed by
dac86cace5326e7c12baa5ce780391aa4a6003a4.
Outstanding owner actions and next work
- Build 15 iOS should add cache-first offline/read continuity with explicit retained/stale/offline evidence.
- Device installation, notification display, APNs, production CloudKit, signing, canary, fleet rollout, and runtime longevity remain separate gates.
- The outbox remains plaintext; fault-injected filesystem and real process-kill crash-window tests remain resilience work.
- Shared persistence and networking must wait for owner-published canonical ecs0lib APIs; shared logging remains blocked on a typed private audit contract.