rdmsm4x-changelog-20260902-2327-tyrell-build16-ios-lifecycle-correction
rdmsm4x-changelog-20260902-2327-tyrell-build16-ios-lifecycle-correction
Corrected and fully verified Tyrell Build 16's iOS lifecycle coordinator so reachability is owned only by the active scene, configuration follow-ups cannot be lost, and caller cancellation reaches child refresh work; the isolated source lane is ready for independent rereview but not integration or deployment.
Scope
- Host:
rdmsm4x - Project: Tyrell, Production mode
- Ticket:
FEAT-20260902-33(source work resolved) - Independent rereview:
SEC-20260902-04(pending) - Isolated worktree:
/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902 - Branch:
codex/tyrell-build16-ios-lifecycle-20260902 - Reviewed base:
3b0dedf8e0dfdce19a69952929f339f3e94dc136 - Corrected source commit:
a991b308e492d5001dd235e1e11724089651ee52 - Final documentation/branch HEAD:
117b4a89ef7b9fbe62f857c18bb03fd465b2d0d5 - No canonical checkout, shared library, service, device, installed app, preferences, production data, credentials, or fleet source was changed.
Files changed
/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/ios/Sources/MobileLifecycleRefresh.swift/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/ios/Sources/MobileStores.swift/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/ios/Sources/TyrellMobileApp.swift/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/ios/Tests/TyrellMobileTests.swift/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build16-ios-lifecycle-20260902/ISSUES.md/Users/richh/dev/_handoff/tyrell-build16-ios-lifecycle-resumed-20260902.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-tyrell-build16-ios-lifecycle-20260902.json- Ticket/check-in/Notes records only outside the isolated source tree.
What changed
- Replaced app-lifetime implicit reachability monitoring with an explicit active-scene lifecycle controller.
- Monitoring start/stop/restart is idempotent; stop and teardown clear
callbacks, invalidate generations, cancel callback tasks, and cancel the
active
NWPathMonitor. - Both inactive and background scene phases stop monitoring; foreground restarts it once while retaining cache-first initial launch and online-edge recovery.
- Coordinator task ownership is now released inside its worker, eliminating the completion boundary that could strand a configuration follow-up.
- The initiating request explicitly propagates cancellation to its child refresh task and restores hold-down eligibility on cancellation.
- Added deterministic lifetime, teardown, 2,000-iteration completion-boundary, and cancellation tests.
- Narrowed one reconfiguration test fixture to an explicitly unavailable CloudKit test service, preventing unintended default CloudKit access during source-only simulator tests.
Commands and verification
- Focused iOS tests ran with
xcodebuildagainst coordinator, reachability-lifetime, and cache/store test classes: 21/21 passed, including 2,000/2,000 exact follow-up iterations. Log SHA-256:1f969c264a38fe242b0abf4859735760049ae8d71db6cd67370faaa5d177aeb8. - Fixture regression: 1/1 passed. Log SHA-256:
f73fb713801d7ee6fefc2d89d5ac66af2510b9f52b0315ae902aa95e7bd785c6. - Full suite on fresh disposable iOS 27 simulator: 72/72 passed, zero
failures. Simulator
E792081F-1495-4F5A-A28D-4203D2D8C1FEwas shut down/deleted and absence verified. Log SHA-256:03536b9cb3dea64d509d60b0e19b5fc86aa3f1fbc216dfccc13b216daed8c33c. - Full package command
swift test --no-parallel -j 4: 646/646 passed, comprising 242 XCTest and 404 Swift Testing tests. Log SHA-256:1f6cd6adf73f2968bc51a97e554e8dcc437dc00dc3171fdf5250934ef1131f83. - Unsigned iOS simulator Release build passed. Log SHA-256:
0775cffc58729cb56d9b7cd9ed0e23c1fb746070f736546aa579f8efecdab8ca. swift build -c release --product TyrellCloudProjectionpassed. Log SHA-256:9f5c4233f1ee9026994bf9a8b950b5939ce8b80ffd106a3766ca21039685053b.swift build -c release --product tyrell-apppassed. Log SHA-256:d940582f0b913818c42fbf35e857d7973be98e600d0233adc6ee4dd8475722fa.git diff --checkpassed; direct store-refresh calls remain centralized; Build 15 cache and Build 14 outbox invariant files are byte-identical to base.- Durable handoff SHA-256:
93ffeb422a3600e70a78e81ba0e4cebfcb3c60d4739112c857ac060cab3b95cd.
Boundaries and outstanding actions
- No production CloudKit write, APNs action, real credential use,
physical-device action, signing, app installation, runtime launch,
merge, push, canary, fleet rollout, deployment, canonical edit,
preferences mutation, or
ecs0libedit occurred. - Existing compiler warnings outside this iOS slice remain unchanged.
- Actual
NWPathMonitortiming and device background behavior remain runtime/device acceptance work. - The earlier request to assess
117b4a89ef7b9fbe62f857c18bb03fd465b2d0d5was superseded by the second NO-GO and correction recorded below.
Undo
No external/runtime state requires rollback. Leave branch
codex/tyrell-build16-ios-lifecycle-20260902 unmerged to
reject the source lane. Reviewed Build 15 remains
3b0dedf8e0dfdce19a69952929f339f3e94dc136. Preserve the
worktree and evidence until rereview and integration disposition are
recorded.
Addendum โ second independent NO-GO correction
- A second independent rereview returned NO-GO in
/Users/richh/dev/_handoff/tyrell-build16-ios-lifecycle-rereview-20260902.md, SHA-256f5ede24fa078235b3691dcfb9c8f2df9e9b28bbf19b7fdc6c4456da8150ec57e. - Finding: cancellation of an older lifecycle caller cleared a separately queued configuration refresh, which could leave rebuilt Fleet and Chat stores unrefreshed.
- Corrected production source:
848df64dc2d71dfecdfab0e4c53acb70881795b1; a one-line test-helper accessor follow-up produced final branch HEAD8d50910affa97ac65265ada38f69fe9b99d2e3b1, tree5d6ab039a579675031fed9ea9a8f6101548806b9. - Changed only
ios/Sources/MobileLifecycleRefresh.swiftandios/Tests/TyrellMobileTests.swift, committed explicitly with the required provenance trailer. - The coordinator now retains the pending new-store obligation across old-caller cancellation and transfers it to at most one internally owned recovery task. The recovery retries after any intervening cancelled/coalesced request and returns to idle after exactly one required new-store refresh.
- Added a deterministic combined cancellation/configuration test specifying one canceled old-store request, one new-store refresh, no old-store follow-up, no duplicate refresh, and final idle.
- Current validation is intentionally parse/static only:
swiftc -frontend -parse,git diff --check, refresh-centralization inspection, and byte-identity checks for Build 15 cache and Build 14 outbox invariants passed. - No focused Xcode/Swift test, simulator, full-package test, or
Release build was run for final HEAD
8d50910a, because the portfolio serialization hold has not been authoritatively released. Earlier 21/21, 72/72, 646/646, and Release evidence predates this latest patch and is not claimed as its validation. FEAT-20260902-33was reopened and reclaimed. Another independent rereview was requested underSEC-20260902-04. No integration, runtime, device, CloudKit, APNs, signing, deployment, canonical, preferences, fleet, orecs0libaction occurred.