rdmsm4x-changelog-20260914-1518-tyrell-build21-notarized-candidate
Tyrell Build 21 — notarized candidate, not installed
Build 21 removes a reproducible full-inventory allocation on pending upload retries. It is not a proven cure for R11 and has not passed runtime or fleet acceptance. No installed app, daemon, database, or canary was changed by this lane.
Source and ownership
- Ticket: ISSUE-20260912-01; producer codex@rdmsm4x/01a08a70.
- Coordinator: codex@rdmpw3275m/01a078a7, source task 01a078a7-f1fc-77f1-9114-949dab68f922.
- Artifact source:
be3e664f20afc0e7bb3de9c2fa057fee01b15674. - Branch:
codex/tyrell-build21-memory-20260914; worktree:/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/apps/Tyrell. - Draft PR: https://github.com/richhdoty/rdmsm4x-dev-apps-tyrell/pull/35.
- Source branch published and queried on backup and fleet. Canonical main remains 75e8ab6; no merge performed.
Proven change and limits
The baseline test required a full read on every pending retry. Strengthening it to require successful retry without another full read failed on baseline 75e8ab6, then passed after this patch. SQLite now selects only requested missing hashes, one non-secret/non-aggregate representative per hash, preserving the first eligible path and eligible-record count. Batches of 400 avoid bind limits. Tests cover host isolation, duplicate paths, exclusions, absent hashes, and 805 requested hashes across three batches. Initial and six-hour full reconciliation remain unchanged. No schema migration, shared-library change, or memory-policy change was made.
Frozen R11 MANIFEST SHA-256
0eeae8ca9627eabfaa14c9f1f4141fd96b1db2d1e444bd1e24406eeed89c1dcd
and README SHA-256
d9570bbec553f042a82153f4a98156c4a282f59da2b94099758d2b822b874c64
match the handoff; every listed file verifies. Independent recomputation
confirms approximately +1.512 MiB/min endpoint and +1.888 MiB/min
regression growth. The sample time span is 1800.305197
seconds; the README uses elapsed span 1800.306823 seconds,
a 1.6 ms difference that does not alter rejection.
There are no allocation stacks or sync-cycle logs in the frozen packet. A retrospective log query returned only its header, not evidence that sync was idle. R11's 21-minute jump therefore remains unattributed. Independent review also found no obvious unbounded retention in the observation loop. Keep the existing physical-footprint-v2 policy unchanged; Build 20 remains rejected.
Validation
swift test on Apple Swift 6.4 at the exact artifact
source returned 0:
- XCTest: 553 cases (Core 358, AppSupport 11, E2E 184), one skipped, zero failures.
- Swift Testing: 664 cases (22 + 485 + 65 + 92), zero failures.
- Full log SHA-256:
b3967fd8a58637a15ea0cb33df0d636ea6d689e63136577da1a6bf1339c97390. - Red regression log SHA-256:
49d4119c013be93436b98d189f45dfb7b3618926ff3adfd5931933cc14315064; exit 1, one expected assertion failure. - Green focused log SHA-256:
c89c81b16a2fbdc963efed131d51aa178e19aa391bcf51223a563541241f918a; exit 0, two tests. - Ten release-script suites plus eleven unchanged memory-policy tests
passed; run
python3 /Users/richh/dev/_handoff/tyrell-build21-memory-20260914/run-contracts.pyand read script-results.json. - Independent Terra review: ACCEPT source only. Report SHA-256
e3e1fb0fcc60f4898ff2ac93069322c459174182dec5d839e52dbf18ad5b2d8a. Reviewed five-file diff hash a85db194bc6fd704f4c0c6147bf941fb46d44afd1befa1823774f32584e6d24a matches committed code. - All 16 shared-library heads and clean states are unchanged before/after validation and packaging.
The existing Providers PNG prerequisite was regenerated using the current app's own visual-fixture renderer in Aqua (capture-provider-fixture.zsh, exit 0). The slow existing provider-reactivity test was sampled and was parsing telemetry, not hung. The pre-existing concurrency warning at MCPMain.swift:279 remains; this candidate is not warning-free. The first packaging preflight exited 2 because memory-policy tests generated an untracked Python cache; that owned cache was moved to this evidence root and the unchanged wrapper reran from a clean tree.
Artifact identity
- Version/build: 0.2.0 / 21; app and daemon contain x86_64 and arm64.
- Signer: Developer ID Application: east coast science, llc (ZU2882L4HT); hardened runtime and secure timestamps.
- App executable SHA-256:
dbc4bc187fba6089da185f566213d0ab8fdb44d929f59346d5d0135478c466a1. - Daemon SHA-256:
b9d85e48ff2e6d75ee58235537a61d0f204c9fb01cc726e054324b01b9a3d158. - App candidate CDHash:
b9a4625b31448f9143343528ecfc1027dbe83cb35925bdc28cfbb4826e2ebc61. - Designated requirement hash:
9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee(unchanged). - App submission:
c7b00c6d-f2e9-4791-bf7a-4d0afbe93a18— Accepted, issues null, stapled, Gatekeeper accepted. - Daemon submission:
127df84f-0e1e-42a2-9804-6e0fa8b4fb72— Accepted, issues null. A bare daemon cannot be stapled. - App archive:
/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/artifacts/Tyrell-build21.zip; SHA-256fce961cea049d3c25c22efbba13dcddadab93bd73921db9d380219138ed2edc5. - Daemon archive:
/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/artifacts/tyrelld-notary.zip; SHA-25693cc48bc2a99987e7bb613768ee2b2d3fc4c36cc0285050a85bf869e5aa27759.
Build/sign/notarization ran in the authorized rdmsm4x Aqua session. build-release-aqua.exit and artifact-verification.exit are both 0. The final app archive was extracted separately, signature/staple/Gatekeeper checked again, executable compared byte-for-byte, and version verified by execution. Scripts, logs, submission receipts and artifact-receipt.json are retained beside this file.
Next boundary and rollback
Return the existing bug to the coordinator for preflight; do not install automatically. No acceptance clocks have started for Build 21. Use a new stage, nonce and designated-canary receipt for rdmbair15m5, with the current reboot-safe recovery guard. Preserve all short, six-hour, 24-hour, CPU, descriptor/socket, API, functional-app, reboot, signature and exact-hash gates. The six-hour window needs inventory activity near its fixed endpoint. Capture phase-attributed sync/inventory logs; if allocation-stack capture changes overhead, keep it in a separate diagnostic run.
The frozen rollback material remains at
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r11-short-gate-failure-rollback-20260914-1419/stage/prior/:
daemon, Tyrell.app and daemon.plist. Both signatures and hashes
reverified:
- Build 15 daemon: dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0.
- Build 17 app executable: 8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e.
These are verified rollback copies, not a fresh claim about a running host. Coordinator must recheck the live baseline and take a consistent database backup before any install. This patch adds no schema change. Undo the source proposal by closing the unmerged PR; keep its branch and artifacts as evidence.
Topology audit reached all six hosts but returned 1: rdmpw3265m account-lane mismatch, plus jdmbair13m5 account classification and durable-root discrepancies. Nothing was repaired or reconfigured. These are coordinator pre-install findings, not authorization to alter accounts. No action is required from Rich for this source handoff.
Build21 frozen delivery receipt
Complete frozen packet:
/Users/richh/dev/_handoff/tyrell-build21-memory-20260914/frozen-handoff.
- 90 files covered recursively, 473186846 bytes; manifest excludes only itself.
- MANIFEST.sha256 SHA-256:
d7f811463a11fc48ff6a7b736aea2e61a1e0b2c5fea02bf3e294a12c1669f748. - handoff-receipt.json SHA-256:
aca7e311d1eaf8a4b10091b37f60a374c85edf8afed9b4cc9a7e05e785b10dab. - Packet includes exact source archive at be3e664, signed/notarized app and daemon, both archives, both signed rollback artifacts, raw test/build/notary/review evidence and machine-readable artifact/handoff receipts.
- Run
shasum -a 256 -c MANIFEST.sha256inside the packet. Independent verification passes all90 entries, all4artifact digests and strict signatures of bothcandidate andbothrollback artifacts. - Producer-owned redundant roundtrip and Python cache directories removed after validation evidence was saved. Signed archives, rawlogs and source worktree remain preserved.
- Existing bug ownership already returned to codex@rdmpw3275m/01a078a7 until2026-09-15T17:18:59-04:00 for protected canary preflight only. No installation, main integration, R11causalclaim or runtimeacceptance.