Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260914-1648-tyrell-build23-notarized-candidate

Tyrell 0.2.0 Build23 — signed candidate, not installed

Build23 fixes a proven activity-event retention defect. It is ready for the coordinator's protected canary; it is not runtime accepted, integrated into main, or deployed. Build21 remains rejected and must not be reinstalled. The separate app-only Build22/PR36 lane is unchanged; its daemon must never deploy.

Owner: codex@rdmsm4x/01a08a70. Next owner: codex@rdmpw3275m/01a078a7. Existing high BUG ISSUE-20260912-01 remains open.

Source and behavior

Source 093d653493be92aed0fb39779f52d5eaef04230b on existing branch codex/tyrell-build21-memory-20260914 in /Users/richh/dev/_handoff/tyrell-build21-memory-20260914/apps/Tyrell. Only five source/test/version files changed: BUILD_NUMBER, Version.swift, ActivityEventBufferActor.swift, SQLiteStateStore.swift, ActivityEventBufferActorTests.swift.

SQLiteStateStore previously persisted every activity event and also appended it to an unpersisted queue with no production drain. The new committed-event path updates the bounded cache after successful SQLite commit without retaining that redundant queue entry. Direct actor writers keep their genuinely pending events. No pending data was trimmed; no schema or gate changed.

Reproducible validation

Signed artifact identity

Artifact SHA256
App executable 631d3a60eb57623d4a6afecba2e2085f8a8b2c132fac2c0f3803765566d5c732
Daemon 6afb7431fb4288875b6ba4ad591bce8a27156ebb3176546a4ac42ca5b6cd791c
App archive 41f0f16d55dfcb9db5b8a296da81fc4c27a9d3d7a0f5284ecdca4f2b86414fa4
Daemon notary archive 5ac13fc86087b83b66b585070d44141fa8c41b1c163a8c2f590b6c0d1a9e39d9

Both artifacts are universal x86_64/arm64, signed by Developer ID Application: east coast science, llc (ZU2882L4HT), with hardened runtime and trusted timestamps. App notarization 54188fda-19b1-4c58-b3bf-f1732a6da11c and daemon 226fedec-cd54-4a3a-8503-88320daf5679 are Accepted, issues null. App is stapled; strict signature, Gatekeeper and archive round-trip checks pass. App execution --version reports0.2.0(23). The bare daemon is notarized and cannot carry a stapled bundle ticket.

Candidate canonical arm64 CDHash bb1e0064230fc271d4374d08938cc388d488412273430b3e7ae0757829908208. Designated requirement hash remains 9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee.

What remains unproven

Build21's17.42→38.53MiB physical trajectory is not quantitatively attributed to this queue. Most growth is an18MiB step around the first inventory completion at27min, after the10min warm-up. Failure vmmap shows4.6MiB live allocation and22.4MiB fragmentation; a free-page count is not a retained object count. The async JSON replay plateaus and census standalone adds under1MiB on first call. Neither supports claiming a complete allocator cure.

The coordinator must retain the unchanged gate and rollback protections and capture allocation attribution around inventory completion. Candidate creation, notarization, canary acceptance, source integration and fleet deployment remain separate states. No installs, launchd changes, or main/Build22 edits occurred in this lane.

Preservation and next action

Frozen packet: /Users/richh/dev/_handoff/tyrell-build23-memory-20260914/frozen-handoff. It contains exact source archive, source patch, source metadata, artifacts, test/review/notary logs, diagnostics, visual fixture, and verified signed prior Build15 daemon/Build17 app rollback copies. MANIFEST.sha256 covers file contents; recursive_manifest.py additionally covers directory/symlink/mode metadata. Hash receipts are outside the frozen directory to avoid self-reference.

Start by checking all manifest entries and artifact-receipt.json. Prepare the coordinator-owned canary using the exact daemon hash and prior rollback identity. Do not reinstall Build21, deploy Build22's daemon, silently merge app UI changes, or reuse this candidate's acceptance label without a successful runtime gate.

Undo for local source: this is an isolated branch; no installed state needs rollback. Preserve the packet and return the worktree to the owner before any source reversal. Root PROJECTS.md changes affect only the Tyrell row, with separate full-file backups and single-row receipts; restore just that row if needed after checking intervening changes. Notes and archive records document the source and root-index changes. No credentials are included.

Final producer receipts

Frozen manifest file SHA256: 64885d1fcb969911b7fe4f58f9ade039e91036d88c11d1619806f37d4b65fb5a. Recursive summary: 96325d8939f9f62b59d2f999522caec69faf8c01d4819780d59a445e59c30766;92 files,472843528 bytes. Every file verified. Strict codesign checks also pass on the frozen candidate and rollback copies.

Documentation commit9bef4bb8655554193fe5c15568d4f27353e14ed6 is verified on backup/fleet; source093d653 remains the exact artifact source. Worktree clean; canonical main75e8ab6 remains clean and unchanged.

Root-index candidate milestone changed only the Tyrell row. Before SHA256 bff493174abf3e737949ab3306d702e6471a815ac543c0b8ef03da4661b153bd, after df8865e6689bc67f2543654de45dfa37768de483ff65dde33bf2f4039232fc88; backup /Users/richh/dev/_handoff/tyrell-build23-memory-20260914/PROJECTS.md.before-build23-candidate. Initial rejection/dispatch backup and receipt remain adjacent. Restore only the prior row, preserving later unrelated changes.

Two sequential Terra/high review jobs were used; budget advice was proceed before each. Exact spend was not measured. No user credential action is required. Coordinator owns protected runtime verification; no candidate is installed by this producer.

User-requested relay: full handoff delivered to claude@rdmsm4x mailbox as20260914-165126-E7395726; persisted body verified. Read acknowledgment not yet observed. Coordinator ownership remains unchanged.