rdmsm4x-changelog-20260903-0309-tyrell-build13-stale-app-archive-rereview
Independent release review blocked Tyrell Build 13 stale-copy archival from canary execution until destructive-scope and recovery defects are corrected.
Scope
- Host:
rdmsm4x - Reviewed worktree:
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902 - Reviewed only
scripts/archive_stale_app_copies_local.zshandTests/ScriptTests/stale_app_archive_contract_test.zsh. - No project source, app copy, LaunchServices state, process, API, deployment, or runtime state was changed.
Files created
/Users/richh/dev/_handoff/tyrell-build13-stale-app-archive-rereview-20260903.md/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260903-0309-tyrell-build13-stale-app-archive-rereview.md
Frozen evidence
- HEAD:
bf4453d68767bd5e236ba86df5b71e26b57ff64c - Synthetic no-index patch SHA-256:
3b1243a40538400be61956c882a0428ed06035502957601e19445c291cc9c197 - Archive script SHA-256:
2d6bcdb13c1eef893dfeb22d3120133900ae7206b22812cb66aa536dc802d071 - Contract test SHA-256:
50cf76a7f80a95eac64d922c4f720ca695a126e32470753490d493a6aef6ef5a - Review report SHA-256:
991a385dcb9c35e8ed7e7ec57af549c786dbce09aae5bd278b04b0d8f81e4695 - Syntax, static contract, and no-index whitespace checks passed.
- A read-only path construction probe confirmed an unsanitized bundle-version value can escape the per-run archive root.
Verdict and blockers
- NO-GO for canary execution.
- P1: untrusted bundle metadata controls root-owned destination components.
- P1: failure after moving a candidate does not guarantee file and LaunchServices restoration.
- P1: manifest acceptance classes use executable hash without complete bundle identity.
- P1: unknown-owner
/Users/Sharedcontent can be moved. - P1: post-mutation API/helper verification and executable fault tests are absent.
- P1: a successful run is not idempotently verifiable because the
retained prior becomes
.app.disabledand a second dry-run cannot discover it. - P1: partial archives have no automatic resume/verify interface and may require manual root recovery.
Backup and undo
- No product backup or rollback is applicable because the review performed no product/runtime mutation.
- Remove only the two review-record files listed above if these records were created in error.
Outstanding owner action
- Correct every P1, freeze a new revision, and rerun executable
disposable-root success/fault/idempotence/resume tests before any
rdmbair15m5archive execution.