Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260912-0100-tyrell-build20-notarized-candidate

Tyrell Build 20 — notarized candidate, runtime acceptance pending

September 12, 2026; rdmsm4x; owner codex@rdmsm4x/01a08a70; ISSUE-20260912-01. Coordinator: codex@rdmpw3275m/01a078a7.

Build 20 fixes a reproduced source of hourly inventory allocation churn. It is signed, notarized and staged on the canonical Mac. No Build 20 installation or fleet rollout has occurred. The prior Build 19 rejection remains final; no gate was relaxed.

Exact candidate

Item Receipt
Version Tyrell 0.2.0 (20), verified by execution
Artifact source 96a5fc012ff754d072aee04a47452fd84e69b2e0
Source integration PR32, cfcb32a03a1617c2054f17ad70dbb9293af89237
Daemon SHA-256 71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77
App executable SHA-256 423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd
Combined app CDHash 37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c
Designated requirement SHA-256 9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee, unchanged
App archive SHA-256 d0cf01bc8369a05a8520a934444447bd892a4a012780c4575cc9aa9d1123cc5c
Daemon archive SHA-256 f4ec3ca32fab18126b2421a19c7c838e0f5d44a4d1d44e45f12a93550fd91beb
Signer Developer ID Application: east coast science, llc (ZU2882L4HT)
Architectures x86_64 and arm64; all five declared executable products verified
App notarization f7d4f24c-8320-4eaa-bf21-916f2f4382d2 — Accepted, issues null
Daemon notarization c17e7e4f-493e-47d2-8165-f913ae95ee15 — Accepted, issues null

Artifacts are under /Users/richh/dev/_handoff/tyrell-build20-memory-20260912/artifacts/: Tyrell.app, Tyrell-build20.zip, tyrelld, tyrelld-notary.zip. Runtime and secure timestamp checks passed. The app is stapled and Gatekeeper reports Notarized Developer ID. The archived app was extracted again, its signature verified and its executable hash compared to the original. A bare daemon cannot be stapled.

The pinned Aqua build command was zsh /Users/richh/dev/_handoff/tyrell-build20-memory-20260912/build-release-aqua.zsh; it returned zero at 00:57:47 EDT. Its prerequisite checks pinned the source, clean trees, successful full-suite exit and accepted review snapshot. No artifact was rebuilt from a later documentation commit.

Reproduced cause and correction

Every unchanged hourly inventory upsert advanced updated_at. That invalidated the sync fingerprint and turned unchanged metadata into nearly a full delta. Sync also read the complete corpus before it knew whether any blobs were missing. The SQLite adapter retained copied Rows alongside the FileRecords it returned. These are demonstrated sources of allocation churn, consistent with the canary's allocator evidence; a new runtime trial must establish the residual physical footprint.

The patch separates observation time (last_seen_at) from content-change time (updated_at). It uses null-safe comparisons for all serialized fields and retains scan pruning through MAX(last_seen_at, updated_at). The additive column preserves reads and writes by the signed Build 15 rollback binary; migration and simulated old-writer behavior are tested. No user database was modified during this development task.

Accepted metadata deltas now avoid a whole-corpus lookup. Required full snapshots transform SQLite rows as the statement advances, retaining only the requested FileRecords. Failed steps throw rather than returning partial success; statements finalize on all paths.

Independent review caught a related reconciliation trap: a stable fingerprint could skip the existing six-hour full-push deadline. The final candidate checks that deadline before both idle and held-upload shortcuts. Controlled-clock tests cover pre-deadline idle, exactly one due full, rediscovery of server-lost blobs and post-full idle, with and without held uploads. The full reconciliation is preserved.

Changed source files: Sources/TyrellCore/SQLiteStateStore.swift, SyncEngine.swift, TyrellSQLite.swift; regressions in Tests/TyrellCoreTests/StateStoreTests.swift, SyncEngineTests.swift, SQLiteMappedReadTests.swift; version in BUILD_NUMBER and Sources/TyrellCore/Version.swift. Sixteen ECS library checkouts remained unchanged and clean. No library or release-gate source changed.

Validation

Failed Build 19 and current containment

Independent recomputation confirms361 post-warmup samples over21602.749 seconds:638.095535 MiB physical at the endpoint,1.498985 MiB/min endpoint growth and0.501300 MiB/min regression. One PID69804 and process start; maximum sample gap60.095 seconds. Pass7 completed38 roots and29 bundle plans near the fixed endpoint. Allocator evidence includes382025728 dirty Malloc Large bytes and279412736 dirty Malloc Small bytes, with512.3 MiB fragmentation at88 percent. Full original evidence hashes are in build19-evidence-sha256.txt; no predecessor failure was reclassified.

At00:54 the canary independently remained on exact signed Build15 daemon dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0, PID40001 started00:28:25, and Build17 app executable 8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. Both43117/43118 status planes returned200. Preserve those exact rollback artifacts for the next trial.

Next canary and rollback requirements

Use a fresh Build20 stage and nonce on designated rdmbair15m5; never reuse the rejected Build19 stage or receipt. Before launch, bind the new guard to the exact hashes above, pin install/rollback dependencies and preserve the exact signed15 daemon and17 app. The prior guard has completed rollback and must not be restarted as a Build20 monitor.

Keep physical-footprint-v2 unchanged:300 MiB short/six-hour endpoint budget,400 MiB at24 hours, regression and endpoint growth at most0.20 MiB/min; mandatory raw RSS and physical data, same PID AND process start, bounded sample gaps, exact executable path/hash. Require a complete inventory pass overlapping or immediately preceding the fixed six-hour endpoint, plus unchanged-repeat evidence. Preserve all existing24-hour,CPU,descriptor/socket,status/permission,app-functional,reboot stable-path,signature and rollback gates. No fleet expansion from source tests, notarization or a short trial alone.

The schema change is additive; old-binary compatibility was tested. Before first installation, retain a consistent database backup under the established local backup procedure. Do not remove the added column during rollback. There is no Build20 runtime to undo yet; a source undo would be a new reviewed revert commit, not history rewriting. Existing candidate, predecessor and recovery copies are retained.

Continuity

Existing isolated source worktree: /Users/richh/dev/_handoff/tyrell-build18-release-20260911/apps/Tyrell, branch codex/tyrell-inventory-memory-20260912. ISSUE-20260912-01 stays open for canary acceptance. Parent TASK-20260911-01 remains with the coordinator. Local changes and this receipt are published to the rdmsm4x Apple Notes folder and the per-host Markdown archive. Root PROJECTS.md/archive update is delegated to the coordinator to avoid a second root-doc writer.

Preflight recorded a historical unacked-message backlog; the current exact rejection was read/acked and claim checks found no writer collision. The moved topology audit was located under fleet/dev-fleet-reconciliation; canonical and canary were verified, with two other spokes unreachable. Check-in and fleet bus milestones were published. No source writer was spawned; the existing reviewer wrote reports only.

Test-count correction: the earlier progress receipt counted an 80-case E2E sub-suite separately. Named top-level bundles prove553 XCTest cases (358+11+184), including one skip, plus662 Swift Testing cases. The full-suite exit remains0; no test was lost or rerun for this reporting correction.