Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260909-1352-tyrell-build16-signed-fleet-deploy

rdmsm4x-changelog-20260909-1352-tyrell-build16-signed-fleet-deploy

Tyrell 0.2.0 Build 16 was signed with the Apple Development identity and deployed to 5 of 6 fleet Macs (CFBundleVersion 7 -> 16); this is the first signed release since the errSecInternalComponent signing wall, which is now resolved.

Scope

Hosts changed: rdmsm4x (hub), rdmbair15m5 (designated canary), rdmbair13m5, rdmpw3265m, rdmpw3275m. Host NOT changed: jdmbair13m5 — offline (ssh = Operation timed out), still on CFBundleVersion 7.

Artifact

Commands run (in order)

  1. zsh scripts/make_app_bundle.zsh — rc 0
  2. zsh scripts/redeploy_app_fleet.zsh --bundle … --candidate-hash … --candidate-cdhash … --dry-run — rc 0
  3. … --deployment-nonce build16-20260909-133057 --execute-canary — rc 0
  4. zsh scripts/run_tyrell_app_canary_probe.zsh --target rdmbair15m5 … — rc 0
  5. ssh rdmbair15m5 'zsh ~/.tyrell/app-staging/<cdhash>/issue_tyrell_app_canary_receipt.zsh …' — rc 0 (wraps accept_tyrell_app_canary.zsh; the fleet step only accepts a receipt fetched from the canary)
  6. … --execute-fleet — rc 0 (fleet_rollout=partial_pending pending_hosts=jdmbair13m5 failed_hosts=none)
  7. sudo -n /bin/zsh scripts/install_app_local.zsh --bundle … --expected-hash … --expected-cdhash … --target-user richh — rc 4, then rc 0 after the launch-health cause below
  8. zsh scripts/install_tyrellbar_agent.zsh — rc 0 (hub agent restored byte-identically)
  9. zsh scripts/deploy_fleet.zsh --hosts rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m — rc 3
  10. zsh scripts/deploy_fleet.zsh --hosts rdmbair15m5 — rc 0 (after syncing the missing transitive dep)
  11. zsh scripts/install_service.zsh --server (hub) — rc 0

Verification (read the installed Info.plist, never a changelog)

plutil -extract CFBundleVersion raw -o - /Applications/Tyrell.app/Contents/Info.plist = 16 on rdmsm4x, rdmbair15m5, rdmbair13m5, rdmpw3265m, rdmpw3275m; CFBundleShortVersionString = 0.2.0; lipo -archs = x86_64 arm64; codesign -dvvv Authority = Apple Development: Richard Doty (S65Q255HA8). On the two Intel hosts the default codesign -dvvv prints the x86_64 code directory (573b18c0…); codesign -dv --arch arm64 --verbose=4 returns the canonical ea496114… on both.

tyrelld: restarted from the new build on rdmsm4x (pid 14585, --server), rdmbair15m5 (pid 14865), rdmbair13m5 (pid 91969) — all answering /api/status. Unchanged on both Intel hosts (see below).

Backups / how to undo

Build 7 (cdhash ea537c7e5b93) is retained on every host: /Applications/.tyrell-rollbacks/20260909-133602-* (hub), -133132-* (rdmbair15m5), -133219-* (rdmpw3275m), -133256-* (rdmbair13m5), -133332-* (rdmpw3265m). To roll a host back, install that bundle with install_app_local.zsh. Nothing was deleted anywhere.

Problems found (filed in the repo's ISSUES.md)

Outstanding owner actions

  1. Decide the #71 fix (own bundle for the companion, or point the installer at the embedded login item).
  2. #73 needs a source change and therefore a new build before the Intel hosts get the current daemon.
  3. Re-run the rollout for jdmbair13m5 when it is reachable.
  4. rdmbair13m5 has no tyrellbar LaunchAgent at all (pre-existing), so it has no menubar; not changed here.

Commits: 573e991 (SESSION-STATE.md), e37482f (ISSUES.md) on main, pushed to backup and fleet. No secrets, tokens, or ~/.tyrell/token values appear in this record.