Tyrell
field-population audit — sessions=0 was false and the hub
was never idle
Read-only audit of every Tyrell surface (CLI, MCP, HTTP) for fields
that return empty, zero, null or stale, classified against
CLAUDE.md §7. From Rich's "make sure all fields in Tyrell
are populating", relayed by the Tyrell cloud oversight thread.
- Session: 2026-09-08 14:15 – 14:32 EDT,
claude@rdmsm4x - Scope: rdmsm4x, rdmbair15m5, rdmbair13m5, rdmpw3265m, rdmpw3275m; jdmbair13m5 not reached
- Mode: read-only measurement + documentation
commits. Nothing signed, installed, deployed or restarted; no
keychain;
ISSUES.md#54 not run; no defect fixed — each is named withfile:line.
Headline
The sessions=0 reading that the previous pass flagged
was not the hub being idle. 38 processes with
claude in the executable name were alive on it.
Three independent failures stack, and the CLI is structurally unable to
report any of them because an unknown subcommand exits 0.
The acceptance metric's "≥ 10 agent sessions" precondition was
met while the instrument recorded the opposite — which
means the 13:10 checkpoint's own caveat ("not yet a trustworthy pass")
rested on a false zero.
Issues filed — #59 to #64
| # | Class | Finding | Location |
|---|---|---|---|
| 59 | b | sessions= can only ever be 0 on every host;
tyrell not on PATH (exit 127), no deployed
binary has the subcommand, and unknown subcommands exit 0 |
Tyrell.swift:829-830,
probe_tyrelld_rss_slope.zsh:236 |
| 60 | b | Fleet census undercounts on all 5 hosts; rdmbair13m5 reports 0 against 32 matching executables | AgentCensusSampler.swift:34-36 (fixed in source,
deployed nowhere) |
| 61 | c | AgentCensus.sampledAt exists and is discarded, so a
101.7-min-old census is served like a 0.8-min-old one |
ServerLogic.swift:142 |
| 62 | b | mbps is Double? but a literal
0 is written; a live 97% transfer reports
0.0 MB/s, 0/0 files |
Daemon.swift:489 +
MobileDashboard.swift:97 |
| 63 | b | Missing census family renders 0; claude
and codex both render as the letter c |
Tyrell.swift:559 |
| 64 | — | Six host reboots across five Macs in under six hours; blocks the 6–12 h leak re-measurement | — |
Class (a) correctly empty · (b) empty/failed rendered as a number · (c) stale presented as current.
What passes
usage_status and agent-permissions are
fully §7-compliant and should be the template for the rest:
used_pct: null (never 0) on 7 of 11 buckets,
authoritative/approximate tags,
superseded_by, stale_seconds,
informational_reason for an unrecognised vendor window, and
a prose reason on every .unqueryable TCC store.
fleet_status
filesSeen/filesExpected correct.
tyrell status renders an entirely absent census and an
absent lastManifestAt as —, correctly.
Recorded against myself
My first ground-truth probe used pgrep -c -f claude.
-c is not a pgrep flag on
macOS; the command failed with a usage error and my
|| echo 0 fallback manufactured a plausible zero on all
five hosts. I nearly filed "the census reports 0 and reality is 0, so it
is fine." The audited defect, committed by the auditor, inside the
audit. Corrected by re-measuring with pgrep -f … | wc -l
and then, properly, with ps -axo comm= to match what
proc_name actually sees.
A collision resolved before writing
ISSUES.md held 35 lines of complete, verified,
uncommitted work from another session (mtime 13:43:47)
investigating Rich's "usage shows unavailable" report. Its
#57 collided with the CAS issue that reached the mirror
first. Preserved three ways — worktree_snapshot.zsh →
~/.agent-coordination/snapshots/rdmsm4x/Tyrell/20260908-141657,
a sha-verified copy, and a patch — then landed verbatim as
#58, renumbered only, in 24daffc. Not my
measurement; the entry says so. The authoring session should confirm the
renumber.
Files touched
| File | Change |
|---|---|
~/dev/apps/Tyrell/ISSUES.md |
rescued entry as #58; new entries #59–#64 |
~/dev/apps/Tyrell/SESSION-STATE.md |
new top checkpoint (audit table, +123 lines) |
No source file, script or config was modified. No spoke host was written to.
Git operations
| Ref | Before | After |
|---|---|---|
local / backup/main / fleet/main |
f81bb23 / 2fe8c6f /
f81bb23 |
8d7cbab (all three) |
Two fast-forwards from the mirror during the pass (it moved twice
while I worked), then commits 24daffc (rescued #58) and
8d7cbab (audit). Both via
TYRELL_CANONICAL_INTEGRATION=1 — documentation only; the
canonical checkout's integrity gate blocks direct commits on
main.
Verification evidence
SESSION-STATE.md2452 → 2575 lines,##headings 86 → 87, zero prior headings lost.ISSUES.md950 → 1099 lines, distinct issue numbers 43 → 49, zero prior numbers lost, exactly #59–#64 added. Both checked withcommagainstgit show HEAD:<file>.- Post-push
git rev-parseon local,backup/mainandfleet/mainall return8d7cbab.
Outstanding owner actions
ISSUES.md#54 (signing) remains Rich's call and was not run.- #64 blocks the 6–12 h leak re-measurement — the window does not exist until the reboots stop. Cause not investigated; it is a fleet-stability item, not a Tyrell defect.
- jdmbair13m5 still unreachable, and its failure mode
changed — accept-then-reset last pass,
Operation timed outnow. It is alive and publishing to the fleet (last manifest 12:37:39). No credential was touched. - #59 should be fixed before any further leak measurement is
trusted, since it invalidates the
sessions=field on every probe line the fleet has stored.
No secrets, credentials, tokens or signed URLs appear in this record.