rdmsm4x-changelog-20260903-0717-tyrell-build13-successor-daemon-and-ios-qa
Tyrell Build 13 successor daemon, fleet cleanup, and iOS QA
Tyrell now has one exact accepted Build 13 macOS app and daemon on every fleet Mac, recoverable archives for old app copies, a substantially faster agent-bus chat bootstrap, and a tested iOS correction that keeps Fleet and Chat usable when a private CloudKit read stalls.
Scope
- Source and signing host:
rdmsm4x. - App and daemon runtime verification:
rdmsm4x,rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Mandatory canary:
rdmbair15m5before the remaining five-host daemon promotion. - Canonical mutable worktree:
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902on branchcodex/tyrell-build18-chat-catalog-20260902. - Tested implementation commits:
1aee989,ec784ca,34b66bc, and3a29d9a; documentation checkpoint69e78c389ca70e30fdab89811a55dec075e97bf8.
Changes
- Deployed the already accepted signed universal2 Build 13
/Applications/Tyrell.appto all six Macs, with exact main executable SHA-25636b5ee65416d571e3fc68a986367742fa2346efada8e779439a1018e16c2f95aand Team IDZU2882L4HT. - Archived 80 verified old macOS app bundles as non-launchable,
checksummed
Tyrell.app.disabledobjects. Each host retains one exact Build 11 app rollback. Current desktop inventory is one/Applications/Tyrell.appper Mac. Source-worktree, iOS/simulator, daemon, data, CloudKit, credential, MCP, and TCC artifacts were excluded. - Built and signed the Build 13 daemon, then installed it with a new
dry-run-first, immutable-release, dual-port, process-cardinality,
rollback-protected transaction. Exact daemon SHA-256 is
ea8c1de11ff324b35b270a43876e51f89f055873bef1fe027f7db9d0d5c7cd52; CDHash is28c5566b622f16483df5286838741c9b89ea18bf; Team ID isZU2882L4HT; architectures arex86_64 arm64. - Optimized the production chat bootstrap from 18.8 seconds to
approximately 0.06โ0.07 seconds warm by replacing a host-wide ledger
scan with a stable indexed range query. Agent-bus channels now group by
normalized topic and recipient scope, directed traffic stays
audience-isolated, header-only messages remain visible as
[No message body], and active rooms sort above empty project rooms. - Added a 12-second iOS CloudKit read boundary. Timeout preserves
accepted cached evidence as retained, explicitly reports
refresh-timeout, and cannot be overwritten by a late platform result. Simulator QA proved the loading state clears and Fleet-to-Chat navigation works. The current dark palette now supplies matching system navigation and tab contrast. - Replaced the base-schema migration's expected failing
duplicate-column statements with explicit column inspection and included
repos.bundle_hashin fresh schema creation. This source-only correction will remove the cosmetic startup warnings after the next signed daemon promotion; it did not touch the live production database or currently accepted daemon. - Updated
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/SESSION-STATE.mdand/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902/ISSUES.mdwith exact lifecycle boundaries and evidence. - Replaced only the stale Tyrell row in the canonical iCloud
PROJECTS.mdregistry with the current source/deployment/acceptance boundaries. The pre-edit registry is preserved byte-for-byte at/Users/richh/dev/_handoff/projects-md-backups/PROJECTS.md.pre-tyrell-build13-20260903-0725.sha-f9022f0c; its SHA-256 isf9022f0cee61ef55894cbd67de3353b1a37b55599268c3aa3542ed078ccc10e3. The updated registry SHA-256 is14ee79985fa1e36e10c121f619a392c0a738871055910f9c4be5affec31c9a54. - Refreshed
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-tyrell-build17-integration-20260902.jsonwith the current clean source HEAD, exact app/daemon hashes, test evidence, rollback paths, and remaining gates.
Commands and verification
- Built and signed universal2 release products on
rdmsm4x; verified strict signature, Team ID, CDHash, architectures, executable bytes, and build identity before canary deployment. - Installed the daemon first on
rdmbair15m5, verified both API ports and exactly one launchd-owned process, then promoted the identical artifact to the other five hosts with host-local rollback receipts. - Rechecked all six installed daemon paths and SHA-256 values over
authenticated fleet SSH. Observed one exact process per host with PIDs
81654,32661,66532,30460,93409, and28030in the host order listed above. - Queried the live status, fleet, usage, and authenticated chat
surfaces. All six fleet rows were classified live. Usage was
vendor-authoritative and advised
holdbecause OpenAI's vendor-reported seven-day bucket was 78% used. Unauthenticated chat access returned 401 and sender impersonation returned 403. - Ran
PRAGMA quick_checkagainst the live database:ok. Observed 2,081,317 file rows, 1,077 repository rows, 3,033 chat conversations, and 3,481 chat messages. - Ran the complete Swift gate: 242 XCTest plus 433 Swift Testing,
675/675, zero failures. Log
/private/tmp/tyrell-build14-full-swift-20260903.log, SHA-25612bc694d9b5c64f0f88cdfc31a9ea8f9c4db1dc8626a6a0bac22f3ded6c6dc99. - Ran all ten release/lifecycle script contracts: 10/10 passed. Log
/private/tmp/tyrell-script-contracts-build14-20260903.log, SHA-2567790b013e186ca9f35448cd95bafa288d22d7c0f7e667354b25debda53f493a0. - Ran the exact-head iPhone 17 Pro simulator suite: 76/76, zero
failures. Log
/Users/richh/Library/Developer/XcodeBuildMCP/workspaces/Tyrell-849b79905b71/logs/test_sim_2026-09-03T11-13-30-614Z_pid11294_ad97e05a.log, SHA-256f57ff3ae10196684cbcc89b65214d85d5b498ca8e98416e076bd04942831ff5b. - Ran a copied-production-ledger bootstrap gate before daemon promotion and verified the original production database was not mutated by that test.
Backups and rollback
- App archives and manifests:
~/.tyrell/archives/obsolete-apps/build13-36b5ee65416d-prior-a2eecac9759f-<host>/plus the explicit supplemental reconciliation archives documented in Tyrell issue #69. They are recoverable and deliberately non-launchable. - Each host retains one accepted Build 11 app rollback with executable
SHA-256
a2eecac9759f115b8137c1d7246c06db53f62e86a8441064ca8c445d91293fd9. - Daemon receipts:
~/.tyrell/canary-receipts/tyrelld-b13-ea8c1de11ff3-<host>.jsonand local fleet receipt~/.tyrell/deploy-receipts/20260903-064105-b13-ea8c1de11ff3-rdmsm4x.json. - Local daemon rollback:
~/Library/Application Support/Tyrell/rollbacks/20260903-064105-b13-ea8c1de11ff3; each remote receipt names its host-local timestamped equivalent and retains the prior accepted Build 8 bytes. - Source rollback is additive and non-destructive: revert
3a29d9a,34b66bc,ec784ca, and1aee989individually from a clean successor branch if a reviewed regression requires it. Do not rewrite published history or delete the accepted rollback artifacts.
Outstanding owner actions and boundaries
- Production CloudKit writes remain disabled. The first sanitized private-zone write, CloudKit reader acceptance, and APNs behavior require a separate owner-controlled gate.
rdip17pandrdip17airphysical-device install/notification acceptance remain pending; simulator success is not a device deployment claim.- The schema-warning correction is source-green but not in the accepted Build 13 daemon. Promote it only in the next signed, canary-first release.
- Continue ecs0lib networking/logging replacements only where behavior, privacy, authentication, timeout, and severity equivalence are proven. Existing guarded fallbacks remain intentional where the shared contract is not yet sufficient.
- This Codex session runs under a Background launch context, so Apple
Notes publication must be performed by an Aqua desktop-session owner
using
zsh ~/scripts/notes_changelog.zshwith this file. The file archive is complete; the Notes copy is pending until that helper reports success. - Aqua publication request was sent to
claude@rdmsm4xas fleet message20260903-072043-D3CDE489. This is a request, not proof that the Note exists.