Tyrell Build 13 final release rereview
Completed a final independent, read-only release rereview of the amended Build 13 diff and issued a NO-GO because the new already-candidate recovery can still report verified after a suppressed failed process termination, and the prior non-running menu-bar state is not restored exactly.
Scope
- Host:
rdmsm4x - Reviewed worktree:
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902 - Base HEAD:
42277bcf045b3e9d6b93ac2ab98355db08c89d56 - Frozen diff SHA-256:
61498aaa6aafa9132d45c49105217cf858378964e7beb463bb607d272b5d82db - Review:
/Users/richh/dev/_handoff/tyrell-build13-release-rereview-v2-20260903.md - Review SHA-256:
e8d8200d72ce3633ad785e122a0d6468c4b101c25fd8df25c3a84ef3176356eb
Files changed by this review
/Users/richh/dev/_handoff/tyrell-build13-release-rereview-v2-20260903.md/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260903-0146-tyrell-build13-final-release-rereview.md
No Tyrell source, installed runtime, LaunchAgent, TCC state, or deployment state was edited.
Verification
- Five release scripts passed zsh syntax validation.
- Eight focused executable script contracts passed; the headless contract passed on an isolated rerun after an initial shared-SwiftPM output-contamination failure.
git diff --checkpassed.- Frozen diff SHA-256 was revalidated after testing.
- Lead evidence reports 669/669 full Swift tests passed.
Result
- NO-GO for Build 13 canary/fleet deployment.
- The prior idempotent disposition, accepted executable+CDHash pair, explicit restore return handling, and pre-mutation helper identity blockers are closed.
- A suppressed candidate termination can still yield false
rollback=verifiedin the already-candidate/no-prior-GUI case. - A previously non-running menu-bar job is accepted as exactly restored without proving that it has no PID or process.
Rollback
This review changed documentation only. Removing the two files listed above reverses the local documentation change; no product/runtime rollback is needed.
Outstanding action
Enforce exact foreground and menu-bar recovery postconditions, add fault-injection coverage for failed candidate TERM and prior non-running LaunchAgent state, then repeat the bounded release review before building the signed canary artifact.