rdmsm4x-changelog-20260909-1352-tyrell-build16-signed-fleet-deploy
Tyrell 0.2.0 Build 16 was signed with the Apple Development identity
and deployed to 5 of 6 fleet Macs (CFBundleVersion 7 -> 16); this is
the first signed release since the errSecInternalComponent
signing wall, which is now resolved.
Scope
Hosts changed: rdmsm4x (hub), rdmbair15m5 (designated canary),
rdmbair13m5, rdmpw3265m, rdmpw3275m. Host NOT changed: jdmbair13m5 —
offline (ssh = Operation timed out), still on
CFBundleVersion 7.
Artifact
- Built from
/Users/richh/dev/apps/Tyrellatdd78ed4(clean tree; no source changed). - VERSION 0.2.0, BUILD_NUMBER 16.
- sha256
3150151bbefd1f4e76820df647208775f19709b595895b8ee0dbbf074a3be5c8 - cdhash (arm64 slice)
ea496114ae594d0eb87eb169d7259b139c481d48037789b13a73b3cc3a2090e8 - designated-requirement hash
7467a4ae84b198c35fa624c55939276f7ad2989f7dab4e102a71af6f2d7e33dc— unchanged, so app-scoped TCC grants survive. - Signer
Apple Development: Richard Doty (S65Q255HA8), TeamZU2882L4HT, hardened runtime. - universal2 verified on the artifact:
lipo -archs=x86_64 arm64forContents/MacOS/Tyrell,Contents/MacOS/tyrellbar, and the embeddedLoginItems/TyrellBar.app.
Commands run (in order)
zsh scripts/make_app_bundle.zsh— rc 0zsh scripts/redeploy_app_fleet.zsh --bundle … --candidate-hash … --candidate-cdhash … --dry-run— rc 0… --deployment-nonce build16-20260909-133057 --execute-canary— rc 0zsh scripts/run_tyrell_app_canary_probe.zsh --target rdmbair15m5 …— rc 0ssh rdmbair15m5 'zsh ~/.tyrell/app-staging/<cdhash>/issue_tyrell_app_canary_receipt.zsh …'— rc 0 (wrapsaccept_tyrell_app_canary.zsh; the fleet step only accepts a receipt fetched from the canary)… --execute-fleet— rc 0 (fleet_rollout=partial_pending pending_hosts=jdmbair13m5 failed_hosts=none)sudo -n /bin/zsh scripts/install_app_local.zsh --bundle … --expected-hash … --expected-cdhash … --target-user richh— rc 4, then rc 0 after the launch-health cause belowzsh scripts/install_tyrellbar_agent.zsh— rc 0 (hub agent restored byte-identically)zsh scripts/deploy_fleet.zsh --hosts rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m— rc 3zsh scripts/deploy_fleet.zsh --hosts rdmbair15m5— rc 0 (after syncing the missing transitive dep)zsh scripts/install_service.zsh --server(hub) — rc 0
Verification (read the installed Info.plist, never a changelog)
plutil -extract CFBundleVersion raw -o - /Applications/Tyrell.app/Contents/Info.plist
= 16 on rdmsm4x, rdmbair15m5, rdmbair13m5, rdmpw3265m,
rdmpw3275m; CFBundleShortVersionString = 0.2.0;
lipo -archs = x86_64 arm64;
codesign -dvvv Authority =
Apple Development: Richard Doty (S65Q255HA8). On the two
Intel hosts the default codesign -dvvv prints the x86_64
code directory (573b18c0…);
codesign -dv --arch arm64 --verbose=4 returns the canonical
ea496114… on both.
tyrelld: restarted from the new build on rdmsm4x (pid 14585,
--server), rdmbair15m5 (pid 14865), rdmbair13m5 (pid 91969)
— all answering /api/status. Unchanged on both Intel hosts
(see below).
Backups / how to undo
Build 7 (cdhash ea537c7e5b93) is retained on every host:
/Applications/.tyrell-rollbacks/20260909-133602-* (hub),
-133132-* (rdmbair15m5), -133219-*
(rdmpw3275m), -133256-* (rdmbair13m5),
-133332-* (rdmpw3265m). To roll a host back, install that
bundle with install_app_local.zsh. Nothing was deleted
anywhere.
Problems found (filed in the repo's ISSUES.md)
- #54 RESOLVED — the signing wall was a stale
fleet-signingkeychain shadowing the login keychain, not a locked keychain or anasuser/Aqua session problem. No keychain command was run by this session. - #71 —
tyrellbarrunning fromContents/MacOS/tyrellbarregisters with Launch Services ascom.eastcoastscience.Tyrellitself; withLSMultipleInstancesProhibited,open /Applications/Tyrell.appactivates it instead of launching the app, so the installer's launch-health gate cannot pass. The gate failed closed and rolled back correctly. Worked around by stopping tyrellbar, re-running the unchanged installer, restoring the agent. - #72 —
deploy_fleet.zshsyncs only DIRECT.package(path:)deps;ECSProcessis transitive and was missing on rdmbair15m5. Rsynced with the script's own flags, then re-ran the script unchanged. - #73 —
Sources/tyrell/Tyrell.swift:445fails to type-check on both Intel Mac Pros;tyrelldbuilds but the batch fails, soinstall_servicewas correctly skipped and both Intel hosts still run their pre-release daemons. - #74 — jdmbair13m5 offline; needs a fresh nonce and receipt when it returns.
Outstanding owner actions
- Decide the
#71fix (own bundle for the companion, or point the installer at the embedded login item). #73needs a source change and therefore a new build before the Intel hosts get the current daemon.- Re-run the rollout for jdmbair13m5 when it is reachable.
rdmbair13m5has no tyrellbar LaunchAgent at all (pre-existing), so it has no menubar; not changed here.
Commits: 573e991 (SESSION-STATE.md),
e37482f (ISSUES.md) on main, pushed to
backup and fleet. No secrets, tokens, or
~/.tyrell/token values appear in this record.