Tyrell Build 18 canary handoff — 2026-09-11 17:00 EDT
Owner: codex@rdmsm4x/01a08a70. Coordinator: codex@rdmpw3275m/01a078a7. Tickets: TASK-20260911-01; parent ISSUE-20260911-01 / ISSUE-20260909-12; installer ISSUE-20260911-11.
Current state
Source accepted, app and daemon signed and notarized; designated canary installed, runtime acceptance pending. No fleet expansion is authorized by this receipt. Build18 daemon PID94501 on rdmbair15m5 started 16:58:50 EDT. The guarded six-hour observation after ten-minute warm-up cannot pass before 2026-09-11T23:08:50.929977-04:00. A failed monitor check automatically restores the retained signed Build15 daemon and Build17 app. Other hosts were not deployed by this release task.
Source and verification
PR26 merged at 2f0fe26f591199b3a556e9c7124cc34b74fdd9bb (artifact source). Review accepted bd4ae6e plus test-only stdout capture repair667791. Independent clone history, linked-worktree pseudo-refs, and incomplete inventory pruning failures were reproduced before fixes. At accepted source: swift test --filter TyrellCoreTests exited0; XCTest358 with1skip and0failures; Swift Testing472 in34suites passed. Ten selected release script suites passed. This is not a claim that every Swift test target was run. CI Swift build remains blocked by the separate missing ECS_LIBS_TOKEN preflight.
PR27 merged at b2e45d04cb4154321a79f672fc841f702a60bf01 (installer source only). It lets exact /usr/libexec/xpcproxy use the existing bounded readiness retry; other unexpected executables still fail immediately, stuck proxy fails closed. Reproduction failed before fix,16 contract cases plus5 negative controls passed after. The signed artifacts were not rebuilt or re-signed for this script-only change.
Artifacts
Version0.2.0 / Build18, x86_64 arm64, Developer ID Application: east coast science, llc (ZU2882L4HT), hardened runtime and secure timestamp.
- App executable SHA256:08b2dca07d10c82e2a65161f5b61682aa305d4ad0fb279d3c1ccb47a00a305f5
- Combined app CDHash:643a2e342a6327469f53c5ae7126461a5b7197eb11855dc66cc8e75d75467dea
- Daemon SHA256:c4f17a2ec720f2be75099569990a13eed7bcef45d1e737cce8c1e72334176464
- App notarization:89a4dce9-5a4f-4aaf-85f5-f843da03ee63 Accepted; staple and Gatekeeper passed.
- Daemon notarization:6fc11aee-df99-4b0a-95fe-a79920de8717 Accepted; issues null. Bare executable cannot be stapled.
- Retained exact Build15 daemon:dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0.
Immutable artifacts: /Users/richh/dev/_handoff/tyrell-build18-release-20260911/artifacts. Build ran in rdmsm4x Aqua Terminal; build-release-aqua.exit=0. All16 library checkout identities were preserved in dependencies-before.json.
Canary transactions and live evidence
First app install failed on transient xpcproxy; installer and guard restored signed predecessors. First state receipt: rdmbair15m5:~/.tyrell/build18-canary-20260911-2f0fe26/state.json. Daemon18 was not installed in that attempt.
Retry2 app installer passed, exact companion executable verified. Guard then installed daemon18. Live stage: rdmbair15m5:/Users/richh/.tyrell/build18-canary-20260911-2f0fe26-retry2. Read state.json, latest.json, samples.jsonl, inventory.log, guard.log and daemon-install.log there. Monitor process launched as94369; managed daemon94501. Guard source and policy are retained here alongside this report; they never promote the fleet.
Initial sample: RSS710656KiB, physical463193504bytes, CPU116.4%,43lsof rows,2TCP descriptors. Both status endpoints43117/43118 returned200;16 concurrent permission calls all200. These are startup measurements, not accepted steady state. Guard enforces same PID/artifact, endpoint health, memory slope and bounds, descriptor stability, complete inventory plus unchanged repeat. CPU is recorded; no independent numerical CPU threshold is encoded, so coordinator must review sustained CPU before acceptance. Reboot stable-path proof and24h memory follow-up are outstanding.
App functional probe passed authenticated fleet usage/chat send/page/command and restored foreground app. Probe nonce build18-20260911-2f0fe26-retry2-functional; evidence SHA2566ef3fea3af7d611cb7b06ab462d6143e1106b6f98017cc6f32ba82680b252f1f. This probe does not authorize fleet rollout. A fresh full probe/receipt is required after long-runtime gates because receipts expire.
Undo and next action
For a deliberate early stop, coordinate ownership first, terminate only monitor PID94369 after verifying its command points at this stage, then run on canary: python3 /Users/richh/.tyrell/build18-canary-20260911-2f0fe26-retry2/canary_guard.py rollback. Never run rollback concurrently with the live guard. Guard itself rolls back on failed checks. Prior signed app and daemon/plist copies are in stage/prior; retained original daemon target is in prior.json. Preserve both attempts and all rollback copies.
Next owner reads latest state and PID continuity; investigate any rollback reason, do not resubmit notarization or rebuild accepted artifacts unnecessarily. If six-hour checks pass, independently validate metrics/inventory/CPU, reboot continuity as coordinated, run fresh app canary and issue receipt. Only then consider fleet expansion. No release tag or full runtime acceptance claimed here.
Local records: build-release-aqua.log, core-bd4ae6e.log, xpcproxy-red.log, xpcproxy-green.log, deploy-canary-aqua.log, deploy-canary-retry2-aqua.log, canary-functional.log. No credential values persisted. Keychain profile named ecs-notary only.