ReplicantDB 1.19.2 build 36 is deployed and launched on all six Macs, and archive-first cleanup leaves one unambiguous active app/CLI/MCP plus one verified recovery package per host.
Scope
- Acting host:
rdmsm4xin its logged-in Aqua session for signing/build; fleet operations were coordinated from the same host. - Target hosts:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Production data boundary: live ReplicantDB databases were queried read-only for row counts only. No scan, OCR request, classification, hashing, tagging, deduplication, file move, CloudKit operation, or database write was run.
Why this matters
Build 36 fixes an unbounded-resource mechanism: caller-side timeouts could return while synchronous Vision/ImageIO framework closures remained live, allowing subsequent files to dispatch more work. The release adds process-wide admission leases—four outer extraction workers and two Vision workers—and retains a timed-out worker's lease until it actually returns. Saturated timed-out capacity now fails closed rather than accumulating threads and IOSurface state.
The deployment also fulfills Rich's request to remove/archive prior app copies throughout the fleet. After a final from-scratch census, each host has exactly one active app, one canonical CLI, one canonical MCP, and one compressed recovery package; no other matching executable or installer copy remains in the searched operational, development, recovery, cloud, or release locations.
Exact source and files touched
- Canonical source root
/Users/richh/dev/apps/replicantDBwas preserved as a dirty non-writer. - Isolated worktree:
/Users/richh/dev/_handoff/codex-out/replicantdb-memory-bounds-20260902 - Branch:
codex/replicantdb-memory-bounds-20260902 - Implementation commit:
f23141de054aff1f0164031740493cfcc7e02e4a - Build-source commit:
eb69701e0424c2cc29e02d2a2f3f25b5d948702a - Dependency-receipt commit:
e9a845ec71ff01859247d70708eaa760c4d8475a - Release/handoff commit:
6ae1df13e93b62169b7eec57db3ded3b1fa71859 - First memory-observation documentation commit:
ee94d6cc4b84c3ce37f7a85a7530cd718406d41e - Four-minute follow-up documentation / final branch HEAD:
9a175eeacfca88bec9c4bf1f873e1f20e9864af6 - Source files from the implementation chain include:
Sources/ReplicantDBCore/BoundedWorkerAdmission.swiftSources/ReplicantDBCore/Connectors/DocumentExtractor.swiftSources/ReplicantDBCore/VisionOCRExtractor.swift- associated bounded-admission, extraction-bound, and Vision timeout tests
Sources/ReplicantDBCore/Version.swiftCHANGELOG.md,ISSUES.md, andSESSION-STATE.md
- Metadata-only evidence snapshot:
/Users/richh/dev/_handoff/codex-out/replicantdb-memory-bounds-20260902/dist-snapshots/1.19.2-build36/ - Rollout tools and evidence:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.2-build36-rollout-20260903/This includes the final cleanup/discovery/inventory tools plus the read-onlycapture-replicantdb-daemon-memory.zshandcapture-fleet-daemon-memory.zshobservation tools. - Coordination check-in:
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-replicantdb-memory-bounds-20260902.json - Canonical project index updated:
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md
Installed state changed
On all six hosts:
/Applications/ReplicantDB.appwas transactionally replaced with 1.19.2 (36)./Users/richh/bin/replicantdb-cliand/Users/richh/bin/replicantdb-mcpwere replaced with the exact release binaries.- Prior rollout/staging/rollback/build copies named in exact manifests were archived and removed.
- One recovery package and evidence directory was created beneath
/Users/richh/Library/Application Support/ReplicantDB Cleanup Archives/replicantdb-1.19.2-build36-20260903-044445/. - Existing daemon policy was preserved: loaded on
rdmsm4x,rdmbair13m5,rdmpw3265m, andrdmpw3275m; unloaded onrdmbair15m5andjdmbair13m5. - TCC was not reset or modified because build numbers share the same bundle/code designated requirement; resetting a purported old-build authorization would revoke build 36 too.
Commands and workflow
- Ran the exact versioned complete Swift suite and independently counted results.
- Ran unchanged
./build.shthrough a one-shot Aqua-domain launchd job after a direct/background signing attempt reproducederrSecInternalComponent; a pinned-identity Aqua signing probe first passed strict validation. Both one-shot jobs were removed after completion. - Ran immutable archive safety, signature, Team, architecture, minimum-OS, CLI, MCP, App Intents, and extraction validation.
- Staged and installed the same bytes with
stage-replicantdb-host.zshandreplicantdb-host-rollout.zsh, canary first and then the remainder of the fleet. - Ran independent per-host verification plus read-only database probes.
- Ran
discover-replicantdb-copies.zsh, generated exact per-host manifests, and executedreplicantdb-consolidate-copies.zshin preflight, execute, and verify phases. - Ran the isolated cleanup safety suite; final result is 9/9 with zero real paths touched.
- Reran the six-host exhaustive discovery from scratch after verifier residue remediation and captured a separate six-host active inventory.
- Captured all six daemon-policy states and the four loaded daemons' PID/age/CPU/RSS/physical footprint/IOSurface/work-count state without restarting them.
- Ran the prescribed topology audit from a byte-identical recovery copy because its canonical path was absent; all six hosts were reachable, but the audit reported stale account/topology expectations and no fleet identity setting was changed.
Verification evidence
- Source tests: 1,100/1,100, 0 failures, exit 0, 83.481 seconds; log
SHA-256
394d830b2de72c3dbb9a99aeb3601eaa7bb484d133ab03dd48dbb352f6b14b21. - App executable SHA-256:
c64d4b9493dacfe466687eff8e73505b9c8f7f286015fbf4fdf922749e5d3adf. - CLI SHA-256:
add761396e650c1a421c14d4038b16d22bb0e62d4a076c73bc8e7c439380648d. - MCP SHA-256:
af54210824218eb07166c4d42567f82e72aa722ece39448a130bc5b7814b029f. - All three: strict Team
ZU2882L4HTsigned, exactx86_64 arm64, macOS 15.0 minimum on both slices. - Executed CLI:
ReplicantDB 1.19.2 (36) "Contained"; parsed MCP initialization:name=replicantdb version=1.19.2. - Final discovery: pass on 6/6. Ledger SHA-256
b26ed4afd8372f1e18f72d0e9d659255306550b243645456edd41d7496e4894e. - Final active inventory: pass on 6/6. Ledger SHA-256
3f9434af8ec88cc48b918b25f10cbe82d9ed33784f9217a22fecb3eeac35f416. - At 35–41 minutes on the original PIDs, the three worker hosts were
active at 78.5–209.5% CPU. Current/peak physical footprint and IOSurface
regions were 294/1,445 MB and 49 on
rdmbair13m5, 232/384 MB and 61 onrdmpw3265m, and 201/455 MB and 103 onrdmpw3275m. The Air returning far below its own peak is useful evidence, but the peak remains material and this is not accepted as the long-duration window. Raw ledger SHA-25626b56c1e8f1f9f1ad90f3d0a970103699bcbdddbd88dcfb109f2de982c6b62ac. - Four minutes later the same four loaded daemon PIDs remained alive,
worker CPU was 94.4–203.5%, and no process established a new
physical-footprint peak. This is a second active point, not a claimed
plateau. Follow-up ledger SHA-256
05a78b8347f42abdd270b08a16b46c0646d5c83ea95d2a8dec24335e719cf738. - Full rollout receipt:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.2-build36-rollout-20260903/evidence/REPLICANTDB-1.19.2-BUILD36-FLEET-ROLLOUT-20260903.mdwith SHA-25601e018f93da523168b9ab7faca0128f62197c2c3f95f3280e0a506469241a56c.
Cleanup incident and repair
The first local cleanup stopped safely after archive creation when read-only signed-app contents prevented quarantine deletion. It resumed against the same archive only after verifying the preflight inode/mode/size/hash ledger and repaired permissions solely inside obsolete quarantine.
The first deep census then found three build-36 app bundles in
private round-trip extraction directories left by
shutil.rmtree(ignore_errors=True). Each path and app hash
was validated against the already verified recovery archive, then the
three temporary directories were removed. The verifier now makes its
private extraction directories removable and fails if any residue
remains. The read-only fixture and all eight existing safety fixtures
pass. A brand-new full census then found no duplicate app copies.
Backups and rollback
Each host retains one safe-member-reviewed, fully extracted, inventory-backed rollback package:
rdmsm4x:3854e22af87044e73d4f83505f9f466337f512b1d3eb1b2fef93a410f8f2e336rdmbair13m5:4dc54f665ba0423e2144b189f5337b8c58a7c1a9f7a80dc22899236adc51505erdmbair15m5:1adf0a5d67cab2cdc6fab0be372699a924cdfacaf8514b3a844b47124ca54ce4rdmpw3265m:5541c1668599ac0d426573e3d179238d05e23c1db1cc7376be3993751b74dbfardmpw3275m:34e75c99af3fff9e176b2e20565925dc13ff20a08f5f70fd0535b9f21ca1c6d2jdmbair13m5:5b33df3358f37bad9cc7a48c285ea3fcab8a9fb081ec0e42a2781ec89f57e295
Undo is manual and owner-reviewed: verify the local archive hash and embedded inventory, stop only owned ReplicantDB processes, extract to a new private temporary directory, and restore only explicit selected members to absent destinations. Never overwrite the active app, CLI, MCP, plist, live database, source checkout, or another agent's worktree. The installed build can also be replaced transactionally from a separately approved immutable artifact.
Outstanding owner/lead actions
claude@rdmsm4xshould review and integrate the isolated commit chain; canonicalmainwas not merged or pushed.- Keep
ISSUE-20260901-26open until a comparable long-duration, workload-normalized memory curve passes. Early roughly 100-second build-36 samples are favorable but not acceptance. - Provide a matching ReplicantDB macOS provisioning profile and run a real CloudKit round trip if CloudKit is to be enabled.
- Resolve the macOS 27 reentrant
NSTableViewdelegate warning. - Refresh the fleet topology audit's stale account/JDM expectations separately; no account or fleet identity was changed during this work.