rdmsm4x-changelog-20260914-2116-tyrell-build24-signed-correctness-candidate
Tyrell Build24 event-identity correctness producer
Objective and ownership
ISSUE-20260914-15: preserve distinct relayed activity events whose colon-delimited field boundaries collide. Producer codex@rdmsm4x/01a08a70 explicitly claimed this issue before writes in the existing isolated worktree /Users/richh/dev/_handoff/tyrell-build21-memory-20260914/apps/Tyrell, branch codex/tyrell-build21-memory-20260914. Coordinator codex@rdmpw3275m/01a078a7 retains ISSUE-20260912-01. Production mode.
Source3834d4522aad647411385a244d882c80194af3c1 descends from reviewed093d653 via documentation-only42c429f. No app-only Build22/PR36 code was absorbed. Main and the Build22 worktree were clean at preserved75e8ab6 and1af256d respectively.
Material correction
mergeFleetEvents formerly created
timestamp:host:kind:detail strings. A kind
custom:scan with detail file collided with
kind custom and detail scan:file, losing a
valid event. A private Hashable EventKey retains the four fields
separately and preserves the previous textual timestamp semantics with
String(event.ts), including signed zero. Merge ordering, retention
capacity, and genuine pending writes are unchanged.
Changed exactly four paths: BUILD_NUMBER, generated Sources/TyrellCore/Version.swift, Sources/TyrellCore/Activity/ActivityEventBufferActor.swift, Tests/TyrellCoreTests/ActivityEventBufferActorTests.swift. No library/pin/gate edits. All18inspected dependency repositories were clean and unchanged from Build23 before testing.
Verification
- Real production-seam red: unchanged093d653 actor compiled, then mergeFleetEventsPreservesCollidingFieldBoundaries failed one test with8assertion issues (exit1); both incoming-only and existing-cache cases, kind/detail and host/kind boundaries. This was not a compile-error surrogate.
- Green:11actor tests pass. New tests cover collision survival, exact duplicate suppression across repeated relays,100-entry newest-first capacity from150events, preservation of a genuine pending write, and otherwise-identical signed-zero timestamps across existing/incoming sets.
- Final
swift testexit0:553XCTest tests reported,2environment skips,0failures;669SwiftTesting tests (22+490+65+92),0failures. Full logSHA256 b61e73bee9c76fcfdc48717c07cf9f008c19ca2e7b30f91682b6b888fb7e62a6. Test receipt names skips and commands. Initial full suite also passed but was rerun after requested test-only revision; initial evidence retained separately. - Independent source review: Terra/high ACCEPT exact patch8e24e7e04e33c8bab38bc66d1c5d45d69adc5f46d5cccceeaf7219dba0a10258. Prior REVISE requested the signed-zero regression only and is preserved. Two sequential bounded review workers total, both budget advice proceed; no other delegation, exact spend not measured. -15unchanged source/release/memory contract checks passed. CI token fixture stalled in HomebrewBash heredoc_write; captured stack, terminated own blocked child, reran identical script under systemBash with exit0. No real credentials in that hermetic fixture and no script edit. Initialrc1 and passing rerun retained; do not count initialrun as pass.
- Live fleet-state deployment planner and standalone live service stress harnesses are not producer-source checks and were not executed. Actual app/canary/reboot/integration/rollout gates remain coordinator work. No gate weakening or synthetic receipt accepted as deployment authority.
Reproduce source tests from the worktree using
swift test; source-only contracts using run-contracts.py
plus the four commands and environment correction recorded in
contract-scope.json. Source archive and exact path hashes are under
source/.
Release and rollback boundaries
Build24 is warranted by ISSUE-20260914-15 correctness. The subsequent unchanged memory gates validate the cumulative daemon; no claim is made that structured event keys cured allocator behavior. Build23R1's prior AC interruption is environmental and supplies no memory rejection or successor-causality evidence.
Production source is pinned during universal build and signing. Artifact/signature/notarization receipts and final hashes are recorded separately once verified. Only build artifacts are produced: no install, candidate app/daemon execution (including --version), launchd change, main merge, Build22 change, database write, or coordinator canary operation. Bundle version is read from Info.plist, not reported as runtime launch proof. Existing test suites execute their test harnesses; this is not a candidate application launch.
Rollback payloads are exact retained15daemon (dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0) and17app executable(8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e). No rollback logic, schema, designated requirement or configuration transition is introduced by this key fix. Prior artifacts remain intact.
Next owner is codex@rdmpw3275m/01a078a7 for independent artifact/preflight verification and fresh designated-canary acceptance. This packet grants no runtime acceptance or fleet rollout. Leave the producer candidate unapplied to undo local preparation; preserve source and evidence.
Verified producer completion
Both Apple submissions Accepted with issues=null; universal app/daemon/bar each x86_64+arm64; company DeveloperID hardened runtime and secure timestamp verified. App notarization 1775ea77-4073-459e-a650-cad729cf7157; standalone daemon c9ea750b-2a10-4bf0-83f3-a80dcaf60876. App stapled, Gatekeeper NotarizedDeveloperID, deep strict signature and archive roundtrip match. Bare daemon is notarized but not a staplable bundle.
- source_commit:
3834d4522aad647411385a244d882c80194af3c1 - app_executable_sha256:
9298390eeb542cb4f99e380a4fb0f105c334c8099ce427e3e24b0f68762dbafb - daemon_sha256:
220f6eac4298ca32faf866d0edc6308924482d2980730368faf12bb355fce949 - app_archive_sha256:
864d1a748129afe82693e3f858214d8af6628e1df48126c208040ac947ed1e12 - daemon_archive_sha256:
fc86afd6abd24d2eb47993c409e5c285b5002a25bf935f47910686e43c9a60c0 - app_cdhash:
628876e9c8135249d256be0a348e83236a92a2f731e48b389e34ff11cbb68289 - designated_requirement_sha256:
9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee
All18dependencies and contract hashes unchanged after build. Main75e8ab6 and queued Build22 1af256d unchanged/clean. No candidate execution or installed-state delta. Original Build23 frozen packet and interrupted-run evidence were not modified. Final machine-readable artifact-receipt.json binds source, reviews, tests, signatures, architecture and notarization.
Closeout records
Docs commit 0ff4ea3b1238acbd53d25353851084825df75d7b records completion in the isolated SESSION-STATE.md and ISSUES.md; production source remains3834d45. Frozen manifest f79e52f0c05acb5efb6e565d8c86c0f1053e0f80bbfdbb73d424a6bf5fe9c456; recursive a04f1c543d75b5661e32e85996eca515a5aaa8fc91f6472bd860c4a902dac882. Exact commands and output are retained in the packet. Local-state scope is own worktree, build/evidence packet, own check-in, ticket notes and per-host Notes/file archive. No runtime undo is needed; leave candidate unapplied. Coordinator receives final claim and can update root PROJECTS release status from the receipt.