rdmsm4x-changelog-20260903-0528-tyrell-build13-fleet-app-cleanup
Tyrell Build 13 fleet app acceptance and stale-copy archival
Build 13 is now the one accepted macOS Tyrell app on all six fleet Macs, and verified older installed/distribution bundles were moved into recoverable, non-launchable archives so Launch Services and runtime ownership are unambiguous.
Scope
- Source/signing host:
rdmsm4x. - Designated canary:
rdmbair15m5. - Fleet acceptance:
rdmsm4x,rdmbair15m5,rdmbair13m5,jdmbair13m5,rdmpw3265m, andrdmpw3275m. - Canonical source worktree:
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902. - Cleanup implementation HEAD:
c21452e434caea0e3e7b0cb7eb31d9b6784d4df9. - Documentation checkpoint HEAD:
161aef6edb3b76ddc7911c4111d9e9dafee575d4.
Source files changed
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/scripts/archive_stale_app_copies_local.zsh/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/scripts/lib/tyrell_app_lifecycle.zsh/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/scripts/lib/tyrellbar_agent_transaction.zsh/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/scripts/lib/tyrell_stale_app_archive_transaction.zsh/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/Tests/ScriptTests/stale_app_archive_contract_test.zsh/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/SESSION-STATE.md/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/ISSUES.md
Runtime changes
- Installed the same signed
/Applications/Tyrell.appBuild 13 artifact on all six Macs. - Accepted executable SHA-256:
36b5ee65416d571e3fc68a986367742fa2346efada8e779439a1018e16c2f95a. - Accepted canonical arm64 CodeDirectory SHA-256:
ec6e20caaecc96cd7974a640ac2f3e1499a8baf21567186d3d08d48ac4bea5e7. - Team ID:
ZU2882L4HT; main and nested helper are universalx86_64 arm64and strictly signed. - Archived 77 verified old deployment/staging/rollback copies through
stable host-local transactions: 7/23/10/13/11/13 on
rdmsm4x/rdmbair15m5/rdmbair13m5/jdmbair13m5/rdmpw3265m/rdmpw3275m. - Archived three additional exact-path macOS artifacts: a duplicate
signed Build 11 handoff plus one legacy local
distapp onrdmsm4x, and one legacy scratchdistapp onrdmbair15m5. - Kept exactly one designated signed Build 11 rollback per host.
Accepted rollback executable SHA-256:
a2eecac9759f115b8137c1d7246c06db53f62e86a8441064ca8c445d91293fd9; canonical CodeDirectory SHA-256:acded1ef4f2e58a67dac722dfafa2e0745576987f6013794a97d74e0b5f7a9d0. - Left all six
tyrelldservices on their separately accepted Build 8 release. No daemon replacement is claimed.
Verification evidence
- Full source gate: 669/669 tests, zero failures.
- iOS gate: 73/73 tests, zero failures.
- All nine release-script contract suites passed.
- Mandatory
rdmbair15m5nonce-bound canary receipt SHA-256:76400488b00ecf567a3b438e851d6b8f29cf86af4dc8a4e85aa9b79f0969c052; probe SHA-256:d26ebb7a8051ae4576c7fb08b4eff453555065dc0c60a30dd9eebc1cb8b8813c. - Every host independently re-ran the cleanup
--verifygate and proved the exact current app, exactly one main GUI, exactly one launchd-owned nested helper, correct-host status, and a nonemptysession_5husage bucket. - Independent review v6:
/Users/richh/dev/_handoff/tyrell-build13-stale-app-archive-rereview-v6-20260903.md, SHA-2562e16ae260138cf933db90253a65a8420de8c39976fa541767311602515e0dcd0. - Canonical supplemental archive:
/Users/richh/.tyrell/archives/obsolete-apps/post-build13-fleet-reconciliation-36b5ee65416d-rdmsm4x/; identity/tree/completion SHA-256 values are6dbe0216fb90714b6dc631756f8d8c2b1ca2185c47bc72a5c44d38d5a41dcb0f,4417a17a493838a023eafab68f21f75396a3563e73f0e24d4fddd8bf38af20d6, and89442aeba29e1e4e36374308ff9630a11d683ec8acbb1ee97b6fc216992762a8. - Canary supplemental archive:
/Users/richh/.tyrell/archives/obsolete-apps/post-build13-fleet-reconciliation-36b5ee65416d-rdmbair15m5/; identity/tree/completion SHA-256 values are0b74775c85bcec5ac399625a4dafb4075085647060b6d0be1ef2ee62e9dc2427,c270cbd546825d3ea3564caa4417a862ea3dfb1f439b7097d8b541bbb453e03c, and591101bd0864697d44b5318f6a24c57bca765dbdeb8f6bf3f11ca449868e7dee. - Final desktop inventory showed only
/Applications/Tyrell.appas a registered/process-owning macOS bundle on every host. Active build products remain unregistered and are not release installations.
Commands and operating actions
- Re-ran the signed app lifecycle and stale-copy verification gates on each host over the tailnet.
- Inspected exact process executable paths, launchd jobs, bundle metadata, universal architecture, signatures, Launch Services records, status API, usage API, archive receipts, and retained rollback identities.
- Used same-volume atomic renames into
Tyrell.app.disableddestinations; no stale app was hard-deleted. - Updated Tyrell tickets
TASK-20260831-30,FEAT-20260902-03, andFEAT-20260831-03, plus the fleet coordination bus.
Exclusions and permission truth
- No iPhone or simulator product, active source/worktree, daemon release, MCP process, database, CloudKit record, credential, provider data, or TCC record was deleted or changed by the archive.
- Removing an app copy does not erase Full Disk Access, Location, Local Network, or other TCC history. Permission state must continue to be reported for the exact responsible signed process using a real capability probe.
Rollback and recovery
- Per host, restore only the designated exact Build 11 bundle recorded
by that host's transaction under
/Users/richh/.tyrell/archives/obsolete-apps/build13-36b5ee65416d-prior-a2eecac9759f-<host>/; re-register it and re-run the exact lifecycle gate. - Supplemental archives retain original-path and archive-path mappings
plus complete before/after manifests. To recover one, first stop only a
process proven to execute that archived bundle, require the original
path to be absent, atomically rename
Tyrell.app.disabledback to its recorded source path, re-register that exact path, and reverify its recorded identity. - A failed preflight containing no app data was moved recoverably to
/Users/richh/.Trash/post-build13-fleet-reconciliation-36b5ee65416d-rdmsm4x-failed-preflight-20260903.
Outstanding work
- Promote the successor daemon only after behavior-proven ecs0lib
persistence/networking/logging integration and the mandatory
rdmbair15m5canary. - Complete the tested iOS CloudKit client and sanitized master snapshot publisher while production CloudKit writes remain owner-gated and disabled.
- Continue permission/UI QA using responsible-process capability probes; do not infer TCC state from app-copy cleanup.