Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260911-1549-tyrell-build18-review-rejected

Build 18 independent review — REJECT 9a0fe66

2026-09-11 15:49 EDT · codex@rdmsm4x/01a08a70 · TASK-20260911-01. Delegated by codex@rdmpw3275m/01a078a7; anycast 20260911-153559-5C88425C taken. Related: ISSUE-20260911-01, ISSUE-20260909-12. Their leases remain with the coordinator.

Verdict

REJECT exact candidate 9a0fe66f8fb7a3d8251d3340efc6467255bb7265 for integration/signing/deployment. One reproduced P1 preservation defect blocks acceptance. No production source, binary, LaunchAgent, cloud schema, credentials, or release tags were changed.

Reproduced defect

Sources/TyrellCore/RepoBundler.swift:144 merges plans for independent Git stores solely because their destination matches. Destination is remote-derived repository key plus checked-out HEAD digest; neither represents clone-local unpublished branches/tags.

The regression constructs two independent clones with identical remote and HEAD, adds a private branch commit to the second clone, then checks out the original HEAD there. Distinct sourceKey values and equal HEADs are asserted. The candidate returns one plan, selects the first clone, and its actual git bundle list-heads omits the private commit. Both preservation assertions fail. ClientLoop subsequently assigns that one bundle hash to both roots. The legacyRepoRoots pruning path can also remove per-root legacy bundles without proving their unique refs are present in the replacement. No real data was used.

A repair must preserve distinct Git stores unless complete bundled ref/object coverage is proven equivalent, invalidate snapshots when relevant refs change without changing HEAD, and make pruning conditional on coverage, not merely a readable replacement file. Keep linked-worktree coalescing and unchanged-pass hash reuse, but do not equate HEAD with complete --all history. An independent source owner should repair the candidate before release validation resumes; this review branch contains a deliberately failing regression.

Reproduction

From this review branch on rdmsm4x:

swift test --filter independentClonesWithSameHeadMustPreservePrivateRefs

Expected with defective source: exit 1, one test, two issues:

The test is appended to Tests/TyrellCoreTests/RepoBundlePassTests.swift and creates/removes only its synthetic temporary fixture. It performs no network Git operations.

Validation before adding the regression

Exact 9a0fe66 in isolated worktree, Xcode 27.0 build 27A5252f:

swift test --filter TyrellCoreTests

Exit 0: XCTest 358 tests, one skipped, zero failures (62.801 s); Swift Testing 468 tests in 34 suites passed (1.479 s). This is the full selected TyrellCore target, not a full all-target app release run. Debug build completed; universal release build not attempted after the preservation defect was proven.

Three independent script contracts each exit 0:

zsh Tests/ScriptTests/agent_permission_cache_contract_test.zsh
zsh Tests/ScriptTests/tyrelld_stable_install_contract_test.zsh
zsh Tests/ScriptTests/version_single_source_contract_test.zsh

Raw local logs: /Users/richh/dev/_handoff/tyrell-build18-release-20260911/core-tests.log and clone-regression.log. Summary extracts are adjacent to this report.

Execution, topology, and live containment

Shell works on rdmsm4x. Canonical main and fetched backup/main and fleet/main remain 53c0d8c17a4858fda4c182678e0baa823e603f77, clean before review. Worktree: /Users/richh/dev/_handoff/tyrell-build18-release-20260911/apps/Tyrell. Branch: codex/tyrell-build18-release-20260911. Relative lib dependency layout uses a symlink to canonical /Users/richh/dev/lib; no shared library was edited.

The instructed Documents/Codex topology script is absent; its relocated fleet copy ran: /Users/richh/dev/fleet/dev-fleet-reconciliation/scripts/audit_codex_fleet_topology_v1.0.zsh. Exit 1: rdmpw3265m account-lane mismatch; jdmbair13m5 account lane unclassified and durable project-root state mismatch. All six canonical SSH checks passed; hub/canary identities passed. These findings were reported, not repaired by moving account data.

At 15:48 EDT the hub and rdmbair15m5 stable daemon paths both hashed exactly: dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. Both symlinks target Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld. Canary PID 1020; /api/status returned HTTP 200 on ports 43117 and 43118. This is a baseline spot check, not a new canary acceptance or a memory soak.

Remaining release work

After a reviewed fix: exact final candidate full tests, universal app and daemon build, company Developer ID/runtime/timestamp signing, notarization/stapling as applicable, rollback-protected canary with complete and repeated inventory, concurrent permission requests, both status planes, descriptors/sockets and long same-PID CPU/physical-footprint soak. Only accepted exact artifacts may expand. None of these release stages ran here.

This shell reports launchctl managername=Background. Production signing/installation must use the authorized hub GUI/Terminal execution lane. Apple Notes publication is pending; the mandatory Markdown archive is durable. No secret values are in these records.

Local changes and undo

Created isolated review worktree, test, review evidence, coordination checkin, and subtask. Published review branch preserves the failing test. No live daemon or user data changed. To undo local workspace after retaining review evidence, remove only this named linked worktree through git worktree remove; no reset of canonical main or shared library is needed.