Tyrell Build 20 — notarized candidate, runtime acceptance pending
September 12, 2026; rdmsm4x; owner codex@rdmsm4x/01a08a70; ISSUE-20260912-01. Coordinator: codex@rdmpw3275m/01a078a7.
Build 20 fixes a reproduced source of hourly inventory allocation churn. It is signed, notarized and staged on the canonical Mac. No Build 20 installation or fleet rollout has occurred. The prior Build 19 rejection remains final; no gate was relaxed.
Exact candidate
| Item | Receipt |
|---|---|
| Version | Tyrell 0.2.0 (20), verified by execution |
| Artifact source | 96a5fc012ff754d072aee04a47452fd84e69b2e0 |
| Source integration | PR32, cfcb32a03a1617c2054f17ad70dbb9293af89237 |
| Daemon SHA-256 | 71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77 |
| App executable SHA-256 | 423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd |
| Combined app CDHash | 37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c |
| Designated requirement SHA-256 | 9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee, unchanged |
| App archive SHA-256 | d0cf01bc8369a05a8520a934444447bd892a4a012780c4575cc9aa9d1123cc5c |
| Daemon archive SHA-256 | f4ec3ca32fab18126b2421a19c7c838e0f5d44a4d1d44e45f12a93550fd91beb |
| Signer | Developer ID Application: east coast science, llc (ZU2882L4HT) |
| Architectures | x86_64 and arm64; all five declared executable products verified |
| App notarization | f7d4f24c-8320-4eaa-bf21-916f2f4382d2 — Accepted, issues null |
| Daemon notarization | c17e7e4f-493e-47d2-8165-f913ae95ee15 — Accepted, issues null |
Artifacts are under
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/artifacts/:
Tyrell.app, Tyrell-build20.zip,
tyrelld, tyrelld-notary.zip. Runtime and
secure timestamp checks passed. The app is stapled and Gatekeeper
reports Notarized Developer ID. The archived app was extracted again,
its signature verified and its executable hash compared to the original.
A bare daemon cannot be stapled.
The pinned Aqua build command was
zsh /Users/richh/dev/_handoff/tyrell-build20-memory-20260912/build-release-aqua.zsh;
it returned zero at 00:57:47 EDT. Its prerequisite checks pinned the
source, clean trees, successful full-suite exit and accepted review
snapshot. No artifact was rebuilt from a later documentation commit.
Reproduced cause and correction
Every unchanged hourly inventory upsert advanced
updated_at. That invalidated the sync fingerprint and
turned unchanged metadata into nearly a full delta. Sync also read the
complete corpus before it knew whether any blobs were missing. The
SQLite adapter retained copied Rows alongside the FileRecords it
returned. These are demonstrated sources of allocation churn, consistent
with the canary's allocator evidence; a new runtime trial must establish
the residual physical footprint.
The patch separates observation time (last_seen_at) from
content-change time (updated_at). It uses null-safe
comparisons for all serialized fields and retains scan pruning through
MAX(last_seen_at, updated_at). The additive column
preserves reads and writes by the signed Build 15 rollback binary;
migration and simulated old-writer behavior are tested. No user database
was modified during this development task.
Accepted metadata deltas now avoid a whole-corpus lookup. Required full snapshots transform SQLite rows as the statement advances, retaining only the requested FileRecords. Failed steps throw rather than returning partial success; statements finalize on all paths.
Independent review caught a related reconciliation trap: a stable fingerprint could skip the existing six-hour full-push deadline. The final candidate checks that deadline before both idle and held-upload shortcuts. Controlled-clock tests cover pre-deadline idle, exactly one due full, rediscovery of server-lost blobs and post-full idle, with and without held uploads. The full reconciliation is preserved.
Changed source files:
Sources/TyrellCore/SQLiteStateStore.swift,
SyncEngine.swift, TyrellSQLite.swift;
regressions in Tests/TyrellCoreTests/StateStoreTests.swift,
SyncEngineTests.swift,
SQLiteMappedReadTests.swift; version in
BUILD_NUMBER and
Sources/TyrellCore/Version.swift. Sixteen ECS library
checkouts remained unchanged and clean. No library or release-gate
source changed.
Validation
- Seven actual unchanged inventory upserts failed eight assertions against the prior implementation, then passed after correction. A separate accepted-metadata-delta test failed the full-read assertion before its fix.
- Final focused validation: 28 tests passed. Coverage includes all payload fields and nil transitions, observed-versus-vanished pruning, additive migration, old-writer compatibility, held-blob retry, periodic reconciliation, row-by-row decoding and statement cleanup.
- Full Apple Swift 6.4
swift testat96a5fc0: exit 0. XCTest bundles: 358 Core cases (one skipped), 11 App Support cases and 184 E2E cases, zero failures. Swift Testing:22,483,65 and92 tests, all passed. Full log SHA-256:872459c3691d16bc87a41c2c16de2f40e6d76df7142476707c4f5e757f2529de. - Ten selected release script suites and eleven unchanged
physical-footprint gate tests passed. Commands and individual logs are
retained in this directory;
script-results.jsonrecords exit codes. - The first full-suite attempt failed only because its pre-existing
Providers PNG prerequisite was absent. The actual existing Tyrell
fixture renderer produced the required2640x1640 PNG in Aqua; it was
inspected and retained here. The full rerun passed with no test skip or
substitute image. The earlier log is preserved as
full-suite-missing-fixture.log. - Independent review is retained in
INDEPENDENT-REVIEW.md, including the rejection of the first candidate and acceptance of96a5fc0 after correction and full-suite verification. No claim of runtime acceptance is implied.
Failed Build 19 and current containment
Independent recomputation confirms361 post-warmup samples
over21602.749 seconds:638.095535 MiB physical at the endpoint,1.498985
MiB/min endpoint growth and0.501300 MiB/min regression. One PID69804 and
process start; maximum sample gap60.095 seconds. Pass7 completed38 roots
and29 bundle plans near the fixed endpoint. Allocator evidence
includes382025728 dirty Malloc Large bytes and279412736 dirty Malloc
Small bytes, with512.3 MiB fragmentation at88 percent. Full original
evidence hashes are in build19-evidence-sha256.txt; no
predecessor failure was reclassified.
At00:54 the canary independently remained on exact signed Build15
daemon
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0,
PID40001 started00:28:25, and Build17 app executable
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e.
Both43117/43118 status planes returned200. Preserve those exact rollback
artifacts for the next trial.
Next canary and rollback requirements
Use a fresh Build20 stage and nonce on designated rdmbair15m5; never reuse the rejected Build19 stage or receipt. Before launch, bind the new guard to the exact hashes above, pin install/rollback dependencies and preserve the exact signed15 daemon and17 app. The prior guard has completed rollback and must not be restarted as a Build20 monitor.
Keep physical-footprint-v2 unchanged:300 MiB short/six-hour endpoint budget,400 MiB at24 hours, regression and endpoint growth at most0.20 MiB/min; mandatory raw RSS and physical data, same PID AND process start, bounded sample gaps, exact executable path/hash. Require a complete inventory pass overlapping or immediately preceding the fixed six-hour endpoint, plus unchanged-repeat evidence. Preserve all existing24-hour,CPU,descriptor/socket,status/permission,app-functional,reboot stable-path,signature and rollback gates. No fleet expansion from source tests, notarization or a short trial alone.
The schema change is additive; old-binary compatibility was tested. Before first installation, retain a consistent database backup under the established local backup procedure. Do not remove the added column during rollback. There is no Build20 runtime to undo yet; a source undo would be a new reviewed revert commit, not history rewriting. Existing candidate, predecessor and recovery copies are retained.
Continuity
Existing isolated source worktree:
/Users/richh/dev/_handoff/tyrell-build18-release-20260911/apps/Tyrell,
branch codex/tyrell-inventory-memory-20260912.
ISSUE-20260912-01 stays open for canary acceptance. Parent
TASK-20260911-01 remains with the coordinator. Local changes and this
receipt are published to the rdmsm4x Apple Notes folder and the per-host
Markdown archive. Root PROJECTS.md/archive update is delegated to the
coordinator to avoid a second root-doc writer.
Preflight recorded a historical unacked-message backlog; the current exact rejection was read/acked and claim checks found no writer collision. The moved topology audit was located under fleet/dev-fleet-reconciliation; canonical and canary were verified, with two other spokes unreachable. Check-in and fleet bus milestones were published. No source writer was spawned; the existing reviewer wrote reports only.
Test-count correction: the earlier progress receipt counted an 80-case E2E sub-suite separately. Named top-level bundles prove553 XCTest cases (358+11+184), including one skip, plus662 Swift Testing cases. The full-suite exit remains0; no test was lost or rerun for this reporting correction.