rdmsm4x-changelog-20260902-2115-tyrell-build15-evidence-api-review-correction
Tyrell Build 15 evidence API independent-review correction
Corrected the three independent-review findings in the isolated Build 15 source candidate, making usage output allowlisted, future observations non-actionable, and mobile unavailable numerics visibly unknown.
Scope
- Host:
rdmsm4x - Project: Tyrell, Production mode
- Ticket:
FEAT-20260902-32 - Isolated worktree:
/Users/richh/dev/_worktrees/tyrell-build15-evidence-api-20260902 - Branch:
codex/tyrell-build15-evidence-api-20260902 - Exact base:
8270ed192956b6228fe075bda21c637acf724766 - Correction/final HEAD:
c373e8559c3af40e1a8c580e91f8921f4b33fc52 - No other fleet host, canonical checkout, ecs0lib tree, installed app, or service was changed.
Changes
- Replaced arbitrary original usage-document forwarding with a closed,
type-checked root/bucket/vendor/host/unreachable wire allowlist shared
by MCP
usage_statusand daemon/api/usage. - Added synthetic regressions proving secret/account/fingerprint/credit/balance/cost/token/note/future keys and nested values are absent while required safe evidence remains.
- Added one 300-second future-clock-skew policy. Later observations are unavailable, carry no authority, and return unknown advice.
- Extracted the exact mobile dashboard numeric JavaScript into a
testable contract: missing, null, undefined, non-finite, and negative
values show
โ; observed zero remains zero. - Appended
SESSION-STATE.mdandISSUES.md; retained the earlier NO-GO lifecycle and recorded that independent re-review is still required.
Verification
- Focused correction tests: 17/17 passed.
- Full package: 242 XCTest + 404 Swift Testing = 646/646 passed.
- Release builds:
tyrelld,tyrell-app, andtyrell-mcppassed. - Values-free release MCP initialize/tools-list handshake passed; it
did not call
usage_statusor read private usage data. - Exact base-to-HEAD
git diff --checkpassed. - Full test log SHA-256:
b476b3a955144046923638105710838d9772b9fe38c82d6672891010c9da8743. - Handoff:
/Users/richh/dev/_handoff/tyrell-build15-evidence-api-20260902.md. - Handoff SHA-256:
eb68191d22ebfdaf6293dd45b615005493b70a4dd69fd7afa71780f11a25a8d5.
Safety and non-claims
- No daemon/app was launched and no live endpoint, real database, CloudKit container, credential, token, provider database, or private usage/body content was read or changed.
- No merge, push, signing, packaging, install, canary, deployment, or fleet rollout occurred.
- The live accepted fleet remains Build 11. The corrected source remains pending independent re-review and owner integration.
Undo
Before integration, retain this evidence and remove only the isolated
worktree/branch if the candidate is rejected. If integrated later,
recoverably revert correction commit c373e855 first,
continuity commit bb7a361 second, and implementation commit
70fd479 third, then rerun the same package/release gates.
Runtime rollback remains the accepted Build 11 artifact because this
work changed no runtime.