rdmsm4x-changelog-20260903-0814-tyrell-build14-heartbeat-fleet
Tyrell Build 14 quiet-host heartbeat fleet release
Tyrell's fleet evidence now stays fresh when a healthy client has no
changed files; the exact signed Build 14 daemon is accepted on all six
Macs while the separately accepted Build 13 GUI remains the sole
installed Tyrell.app on each host.
Scope and reason
- Source/signing host:
rdmsm4x. - Mandatory canary:
rdmbair15m5. - Fleet expansion:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Reason: unchanged manifests were suppressed for the six-hour full-push interval, so healthy quiet clients appeared aging or stale even while their signed daemons were running.
Source and files changed
- Worktree:
/Users/richh/dev/_worktrees/tyrell-build18-chat-catalog-20260902. - Branch:
codex/tyrell-build18-chat-catalog-20260902. - Implementation commit:
de6cf7a504b72138b1e464382c7e0e7f5a62a983. - Final checkpoint commit:
56842ab9b349fd5de92a584b66dbabccf06be458. - The implementation changes the client/server heartbeat and database
receipt paths plus focused regression tests.
SESSION-STATE.mdandISSUES.mdrecord the production acceptance boundary. - Durable release report:
/Users/richh/dev/_handoff/tyrell-build14-heartbeat-signing-20260903/REPORT.md. - Project registry: Tyrell row only in
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. - Pre-edit project-registry backup:
/Users/richh/dev/_handoff/projects-md-backups/PROJECTS.md.pre-tyrell-build14-20260903-0815.sha-5c7cfde6.
What changed
- A bounded empty-delta heartbeat is sent after five minutes when inventory remains unchanged.
- The server advances only receipt/census state for an empty heartbeat. It does not invent file rows or materialize the CAS hash set.
- Heartbeats are handled outside non-empty per-host manifest coalescing so they cannot replace pending file evidence.
- Quiet-client checks use the stored file count rather than loading every indexed file row every 30 seconds.
- The already-tested base-schema startup correction is included in this daemon, eliminating the expected duplicate-column warning path without manually changing the live database.
Build, signing, and commands
- Ran the focused heartbeat test filter, then the complete
swift testsuite with pipefail-preserved exit status. - Ran all ten
Tests/ScriptTests/*_contract_test.zshrelease and lifecycle contracts without a masking pipeline. - Built Release executables separately for arm64 and x86_64, combined
them with
lipo, verifiedlipo -archs, and signed the final file namedtyrelldin the authorized Aqua session. - Verified the exact candidate with
codesign --verify --strict --deep,codesign -d, SHA-256, Identifier, TeamIdentifier, and native per-architecture CDHash. - Installed through
scripts/install_daemon_release_local.zshfirst onrdmbair15m5, thenrdmsm4x, then the four remaining clients. Each transaction preserved the prior daemon/plist and emitted a host-local receipt. - Ran
/Users/richh/dev/_handoff/tyrell-build14-heartbeat-signing-20260903/verify_build14_host.zshon every host after expansion. - Queried the live status/usage endpoints, production SQLite
PRAGMA quick_check, launchd bindings, listener ports, process counts, application inventory, and post-release unified logs.
Verification evidence
- Accepted universal2 daemon SHA-256:
bab002d10d1fc0302ab1404656a8e7785ad0175a3a60b9c5ccef79676bfa1273. - Installed path on every host:
~/Library/Application Support/Tyrell/releases/b14-bab002d10d1f/tyrelld. - Signature: Identifier
tyrelld, Team IDZU2882L4HT; architecturesx86_64 arm64. - Full Swift gate: 242 XCTest + 435 Swift Testing = 677/677, zero
failures. Log
/private/tmp/tyrell-build14-heartbeat-full-20260903.log, SHA-256eff8d126e3ed16e83e2d914724ed0fc41f236495dffd916cec4cd36aceebed43. - Script-contract gate: 10/10. Log
/private/tmp/tyrell-build14-heartbeat-script-contracts-20260903.log, SHA-256c44721d9433cf9aa7b3365dbbb42b902549274f97cd2ce3f51ad6bc32d54b917. - Canary proof:
rdmbair15m5retained exactly 352,118 files and 135,355,893,103 bytes whilelastManifestAtadvanced by about 293 seconds and freshness reset to 16 seconds. - Six-host verifier: pass on every host for exact bytes, signature,
launchd path, one daemon process, ports 43117/43118, API identity, one
exact GUI process, and absence of
~/Applications/Tyrell.app. Log SHA-25655575e54dd95c37f0994dd6b6a0201b7a3d0aac2cbac5f145462bedddda51081. - Fleet snapshot: all six rows
live, ages 7โ260 seconds. Snapshot SHA-256f643af034097e167d68b06a839d9eb9b38abf2e021c0cacf4b6b000d843d3b9c. - Production database:
PRAGMA quick_check=ok; post-release log window contained no current daemon error or duplicate-column event.
Deployment receipts and rollback
rdmbair15m5:~/.tyrell/deploy-receipts/20260903-075539-b14-bab002d10d1f-rdmbair15m5.json.rdmsm4x:~/.tyrell/deploy-receipts/20260903-075711-b14-bab002d10d1f-rdmsm4x.json.rdmbair13m5:~/.tyrell/deploy-receipts/20260903-080235-b14-bab002d10d1f-rdmbair13m5.json.rdmpw3265m:~/.tyrell/deploy-receipts/20260903-080235-b14-bab002d10d1f-rdmpw3265m.json.rdmpw3275m:~/.tyrell/deploy-receipts/20260903-080235-b14-bab002d10d1f-rdmpw3275m.json.jdmbair13m5:~/.tyrell/deploy-receipts/20260903-080234-b14-bab002d10d1f-jdmbair13m5.json.- Each receipt is
accepted, with rollback statusnot_required, and names a host-local timestamped rollback directory containing the exact signed Build 13 daemon plus prior plist. - Local rollback example:
/Users/richh/Library/Application Support/Tyrell/rollbacks/20260903-075711-b14-bab002d10d1f. - Undo: on the affected host, use its receipt's
rollback_pathand the rollback-protected installer to restore the retained Build 13tyrelldand plist, then independently recheck exact signature/hash, launchd path, one process, both ports, and API identity. Do not delete the Build 14 release or receipt until rollback acceptance is proven.
App-copy cleanup and exclusions
- The preceding Build 13 transaction archived 80 verified old macOS
app bundles as checksummed, non-launchable
Tyrell.app.disabledobjects and retained one Build 11 GUI rollback per host. - This release reverified exactly one
/Applications/Tyrell.appand no~/Applications/Tyrell.appon every host. The GUI remains exact Build 13 SHA-25636b5ee65416d571e3fc68a986367742fa2346efada8e779439a1018e16c2f95a. - Source/build worktrees, iOS/simulator products, daemon releases/rollbacks, databases, CloudKit, credentials, MCP state, and TCC records were deliberately excluded from app-copy cleanup.
- No production CloudKit write, physical-device install, credential/provider route, TCC grant, app-bundle replacement, public exposure, or manual database edit occurred.
Outstanding work
- The umbrella feature remains open for the owner-gated first
sanitized private CloudKit write, physical
rdip17p/rdip17airacceptance, and behavior-proven ecs0lib networking/logging migrations. - The usage plane was fresh and advised
holdbecause authoritative OpenAI seven-day usage reached 81%; no new worker context was opened. - Apple Notes publication must be performed and read back from an Aqua desktop session; the Markdown record above is the canonical file copy until that evidence exists.