rdmsm4x-changelog-20260902-2202-tyrell-build15-menu-bar-launcher-review-correction
Tyrell Build 15 menu-bar launcher independent-review correction
Corrected both independent-review findings in the isolated Build 15 source lane: Settings now has one serialized launchd owner for every menu-bar transition, and both Settings and shell rollback visibly distinguish verified restoration from incomplete restoration.
Scope
- Host changed:
rdmsm4xsource and documentation only. - Worktree:
/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902 - Branch:
codex/tyrell-build15-menubar-launch-20260902 - Exact base:
8270ed192956b6228fe075bda21c637acf724766 - Initial reviewed SHA:
8c0e9402ecc687b80395eb7fa651fbee82dcbfbc - Correction SHA:
5c42446d16dac7c50c62efae8e8915ef47f17be4 - Ticket:
ISSUE-20260902-19 - No installed app, preference, LaunchAgent, process, service, canary, fleet runtime, canonical checkout, CloudKit, or ecs0lib state was changed.
Files changed in the correction commit
/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/Sources/TyrellAppSupport/TyrellAppLaunchPolicy.swift/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/Sources/tyrell-app/SettingsView.swift/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/Tests/TyrellAppSupportTests/TyrellAppLaunchPolicyTests.swift/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/Tests/ScriptTests/tyrellbar_agent_install_contract_test.zsh/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/Tests/ScriptTests/tyrellbar_agent_rollback_fault_test.zsh/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/scripts/install_tyrellbar_agent.zsh/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/scripts/lib/tyrellbar_agent_transaction.zsh/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/scripts/redeploy_app_fleet.zsh/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build15-menubar-launch-20260902/ISSUES.md- Updated handoff:
/Users/richh/dev/_handoff/tyrell-build15-menubar-launch-20260902.md
What changed
- Removed the direct
Process.runcompanion path from Settings. - Added a serialized whole-transition gate so Show, Hide, enable-at-login, and disable-at-login cannot interleave.
- Every starting transition converges to zero, bootstraps one persistent or transient launchd job, and proves exactly one fixed installed-bundle process owned by that job. Stopping transitions prove zero.
- Installed-bundle validation happens before Settings state capture or mutation.
- Settings rollback compares exact prior plist bytes and prior loaded-program identity. An unproven restore is shown as incomplete and retains the recovery backup.
- The shell installer uses a testable transaction library that performs the same exact byte and launchd program checks, returns a distinct incomplete-rollback status, and retains the backup path.
- Added injected copy, bootstrap, and wrong-program rollback failures plus Show-then-enable single-process sequencing coverage.
- Preserved fixed
/Applications/Tyrell.app/Contents/MacOS/tyrellbaridentity, signature/Team-ID/universal gates, explicit preferences, fixed-meter defaults, dynamic/operational meters, and alert behavior.
Verification
- Focused transition tests: 6/6 passed.
- Complete Swift package: 242 XCTest + 405 Swift Testing = 647/647,
zero failures. Log
/tmp/tyrell-build15-review-correction-swift-test.log, SHA-25622043c79894227d024b5ae6f609303a8f2bc903b550de548afc4ae0942e4ac31. - All eight shell regression scripts passed. Log
/tmp/tyrell-build15-review-correction-script-tests.log, SHA-256548a3e5f18322d6a737922e2938d855e7b500afed76a3214d79d7e527d15a19f. - Full shell syntax and Git whitespace checks passed.
- Read-only installer dry-run and plist lint passed. Read-only deployment planning selected only the designated canary; it did not execute.
- Universal release builds passed:
tyrellbarandtyrell-appboth reportx86_64 arm64. - Local non-release artifact hashes:
tyrellbar91abfa2922c7c53b7212eb20ca65f8831e9cbce3d1e37336193d736cd996da81;tyrell-appa18cbcaeef0996269132e0834071182192ff5f82774a96ede4ce787a03b8a0a9. - Worktree is clean at correction SHA
5c42446d16dac7c50c62efae8e8915ef47f17be4.
Rollback
In a clean integration lane, reverse the source range
8270ed192956b6228fe075bda21c637acf724766..5c42446d16dac7c50c62efae8e8915ef47f17be4;
do not reset a shared checkout. The runtime installer keeps an exact
prior-plist backup, verifies restored bytes and loaded program after a
candidate failure, and retains the backup with a visible incomplete
status if restoration cannot be proven.
Outstanding owner actions
- Independent source rereview is required before acceptance.
- Parent approval is required before any
rdmbair15m5runtime canary. - Fleet rollout remains not started.