rdmsm4x-changelog-20260902-2135-tyrell-build15-menu-bar-launcher-source
Completed the source-only Tyrell Build 15 menu-bar launcher correction so future app installs and upgrades use the installed system bundle instead of host-dependent developer products; no fleet runtime was changed.
Scope
- Work host:
rdmsm4x - Read-only observations: all six fleet Macs
- Source worktree only:
/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902 - Branch:
codex/tyrell-build15-menubar-launch-20260902 - Exact base:
8270ed192956b6228fe075bda21c637acf724766 - Final commit:
8c0e9402ecc687b80395eb7fa651fbee82dcbfbc - Ticket:
ISSUE-20260902-19 - No installed app, preference, LaunchAgent, process, service, canary, canonical checkout, or fleet deployment was changed.
Files changed
ISSUES.mdSESSION-STATE.mdSources/TyrellAppSupport/TyrellAppLaunchPolicy.swiftSources/TyrellBarSupport/MeterSettingsStore.swiftSources/tyrell-app/SettingsView.swiftTests/ScriptTests/tyrellbar_agent_install_contract_test.zshTests/TyrellAppSupportTests/TyrellAppLaunchPolicyTests.swiftTests/TyrellBarSupportTests/MeterSettingsStoreTests.swiftscripts/install_app_local.zshscripts/install_tyrellbar_agent.zshscripts/redeploy_app_fleet.zsh
What changed
- The one supported menu-bar runtime target is now
/Applications/Tyrell.app/Contents/MacOS/tyrellbar. - App promotion stages and invokes the user-agent installer after exact app acceptance and in the target user's GUI domain.
- The helper validates bundle identity, Team ID, signature, universal2 architecture, plist syntax, process ownership, exact loaded program, and one process. It preserves preferences and restores the previous agent on failure.
- Settings uses the same fixed contract, rejects stale developer-path agents as installed state, surfaces failures, and rolls back a failed bootstrap.
- Profiles without an explicit v2 fixed-meter preference default all eight current meters on. The semantically different v1 rotating-item preference is retained but ignored for fixed-meter enablement; explicit v2, cycle, and pin choices remain unchanged.
- Dynamic focus, operational meters, alert behavior, and status-item controller logic were not changed.
Root cause and fleet evidence
Build 11 installed a valid bundled companion on all hosts, but its
app promotion did not invoke or stage the existing helper, while
Settings generated a plist from a developer-tree binary path. Five hosts
therefore retained developer-tree targets. rdmpw3265m and
jdmbair13m5 currently lack those target files and report
launchd 78: EX_CONFIG; the installed bundled companion is
executable on both. rdmbair13m5 has no agent. Three hosts
run developer targets.
rdmbair15m5 currently runs PID 1059 from its developer
target and reports last exit code = (never exited). Its
process started at 16:29:07, contradicting the earlier audit's later
exit-78 observation. No mutation was made to force a canary failure.
Full table and timing evidence are in:
/Users/richh/dev/_handoff/tyrell-build15-menubar-launch-20260902.md.
Commands and verification
- Read the prior Build 11 runtime handoff and current project coordination state.
- Opened, claimed, and heartbeated
ISSUE-20260902-19; published a writer check-in before edits. - Used authenticated SSH plus
PlistBuddy, executable checks,launchctl print, exact-name process census,defaults read, and bounded launchd log queries on all six hosts; all fleet operations were read-only. swift test --filter TyrellBarLaunchAgentSpecTests: 4/4 passed.swift test --filter MeterSettingsStoreTests: 8/8 passed.swift test --skip-build: 242 XCTest + 399 Swift Testing = 641/641, zero failures. Log SHA-256:6ea10a8622d5dffbb160f5f3d93921e00b8d6162fb78d254043b1d3661f07330.- All seven
Tests/ScriptTests/*.zshcontracts passed. install_tyrellbar_agent.zsh --dry-runandinstall_app_local.zsh ... --dry-runpassed without mutation and reported the fixed target plus preserved preferences.zsh -npassed for the changed scripts and test.git diff --checkpassed; final worktree clean.- Universal release builds passed for
tyrellbarandtyrell-app;lipo -archsreportedx86_64 arm64for both.
Backups and rollback
- Source rollback: revert commit
8c0e9402ecc687b80395eb7fa651fbee82dcbfbcin a clean integration lane. - Runtime backup behavior is built into the new installer: it makes a byte-preserving prior-plist backup, and on failure boots out the candidate, restores the prior file, and re-bootstraps the prior job.
- Existing app promotion retains its verified bundle rollback and enters it when the menu-bar agent migration fails.
- No live backup was created because no installed or runtime state was changed.
Outstanding owner action
Review/integrate the source candidate. Before any runtime action,
explicitly approve the rdmbair15m5 canary. Canary
acceptance must prove installed artifact identity, exact plist target,
loaded launchd program, exactly one installed-path process, preference
preservation, and rollback. Fleet rollout remains separately
receipt-gated.