rdmsm4x-changelog-20260925-1527-replicantdb-build44-fleet-release
rdmsm4x-changelog-20260925-1527-replicantdb-build44-fleet-release
ReplicantDB 1.20.0 (44) "Cartography" was tested, company Developer ID signed/notarized, deployed as identical app/CLI/MCP bytes to all six Macs, and all inventoried older executable/release products were archive-first consolidated with verified rollback coverage.
Scope
- Canonical source and signing host:
rdmsm4x. - Deployment/test hosts:
rdmsm4x,rdmpw3265m,rdmpw3275m,rdmbair13m5,rdmbair15m5, andjdmbair13m5. - Ticket:
TASK-20260925-12(resolved 2026-09-25 15:26 EDT). - Source branch:
codex/replicantdb-build44-release-20260925; isolated release worktree was integrated and then removed. - Frozen release source:
dbac491c9516891395e214832db5da2514c91cee, taggedv1.20.0-build44. - Integrated canonical
main:f07649866fc7be23e11df68132d81761b8253a1a, reproduced on both privatefleet/mainandbackup/main.
Source changes
- Reconciled the already-deployed Build 42/43 lineage to the next
monotonic identity,
1.20.0 (44) "Cartography", inSources/ReplicantDBCore/Version.swiftand the product/status documentation. - Fixed a deterministic full-suite hang in
Tests/ReplicantDBTests/FleetDirectiveAdversarialTests.swift: process-wide stdout was redirected to an undrained 16 KiB pipe, allowing concurrent XCTest output to block infflush. The helper now captures into a unique regular temporary file, restores stdout, reads the result, and removes the file. - Recorded the accepted Developer ID, hardened-runtime, timestamp,
notarization, staple, architecture, dependency, and
CloudKit-provisioning facts in
dist/ReplicantDB.build.json. - Added the durable release receipt
docs/RELEASE-1.20.0-BUILD44.mdand updatedCHANGELOG.md,ISSUES.md,PRD.md,README.md,SESSION-STATE.md,STATUS.md,docs/index.html,docs/status-generated.html, anddocs/status-page.html. - Added the 2026-09-25 ReplicantDB milestone to the canonical iCloud
PROJECTS.md.
Build and verification
swift testcompleted 1,468/1,468 tests, zero failures, in 238.577 seconds. Full log SHA-256:37fbea84284536042d343c0743c4363de0c704db8005a51297abd0102b0b1c2c.- Aqua-domain
ALLOW_UNPROVISIONED=1 ./build.shcompleted successfully. The expected unprovisioned state is explicit: production CloudKit entitlements/profile are absent andcloudKitProvisionedisfalse. - Developer ID:
Developer ID Application: east coast science, llc (ZU2882L4HT); certificate SHA-11C07FCD80C36EAD5D9E3B73F7ACCCA5368DC73FB. - App, CLI, and MCP all have hardened runtime, secure timestamps,
arm64 x86_64slices, Cascade Lake x86_64 optimization, and macOS 15.0 minimum OS. - App notarization
d3a94718-1a8c-4d7e-8046-11f13e2bbb8band tools notarizationb997659c-5894-4ec3-968a-6f7d2d85ed0bare Accepted withissues: null. codesign --verify --deep --strict,spctl --assess --type execute, andstapler validatepassed for the app. Bare CLI/MCP Mach-O files are signed/notarized but are not independently stapleable app bundles.- Accepted artifact hashes:
- app archive:
b4bb13d5db62af73cc0551a06f6cfaf2fa8e2fe139f56c4f40b377c2f50a8682 - app executable:
0c463d7b67e5e2225ada25579204aa36edc5fd70885ee015b3ad13d358a7195e - CLI:
fff168a721bb858d2f3ce53f6f711cd11d33e4e62f19a5a1a74346a7d8052381 - MCP:
7e571356cb4588ecbb1509f9b3bf6b5dc8f44f769829d1b199b41609cc4f3899 - designated requirement:
1e6a54940256e94329db9d3492a257c9584ce468e0038a13b02cbeb4fa4ff4b5, unchanged from Build 43 so the app/TCC identity remains stable.
- app archive:
Fleet deployment result
- The exact accepted hashes are installed at
/Applications/ReplicantDB.app,~/bin/replicantdb-cli, and~/bin/replicantdb-mcpon all six hosts. - Four previously running GUIs (
rdmsm4x,rdmpw3275m,rdmbair15m5,jdmbair13m5) were relaunched from the exact Build 44 executable path and remained running. - Two previously stopped GUIs (
rdmpw3265m,rdmbair13m5) were launched against isolated temporary SQLite paths for smoke testing and returned to stopped. - Each host retained its prior daemon state. Tyrell-owned helpers on
rdmbair15m5andjdmbair13m5retained the same command/PID/ownership contract and were neither booted out nor restarted. - The daemon plist SHA-256 remains
8c4d1b256e555e0773969f5706d44265ec715267266e3814e05f8a91018e63feon all six hosts. - No host produced a new ReplicantDB diagnostic report during rollout.
Older-version consolidation
- Reviewed manifests named 38 fleet executable/staging targets: 12 on
rdmpw3265m, 5 onrdmpw3275m, 6 onrdmsm4x, and 5 each onrdmbair13m5,rdmbair15m5, andjdmbair13m5. - For every host, the cleanup tool created a Build 43 rollback archive
and a superseded-executables archive, extracted each to private scratch,
compared each regular file byte-for-byte, and only then removed the
unpacked target. Every final
verifypass succeeded. - Build 43 rollback / superseded archive SHA-256 pairs:
rdmpw3265m:a9a8721950eab91becae04ab7482d553cabde11e94aec553d0e6c6fb230bd625/f357f8928c8efabb5fea75ee7ec369604593fc2887d8745bbf00d9a14f62b70brdmpw3275m:73c54db050305ec1ba9e7fe90a736b94f0fe17b1204fbd30db372ad8ba465bb7/54f990f281a101e055c43dcbdb4e389e859e9077dfcda642e2f92d4a33fab0a6rdmsm4x:f1b776ba878ca41b44216e8ca699cd3252e5b4f91f39e34c30bc6348e2b00faf/7c429c85a23c0b6ec1c16dfe17cdbfeeb858bcebcce521a735eb6357921d1482rdmbair13m5:ef088fab4d776136cebe37d2e983602b6cdd1f29ed43b1c59d30c2f55bbb7b74/314b03dad236fb3d180f9c127f0218a1ecde6633dd70bc1939552d80f5543a61rdmbair15m5:35183d6e3efa85e99d131d22518cb3ef57f1b956801dd2c989e2eb0bef1b676e/016a1f6426df15d30c4fe88aec366727836f3b17dc038cb75596dbe05b57330ejdmbair13m5:a370f49b7950acb2262ed986edb7f847682a750347bf21c33149ca807a33b514/211acfe18b61d6728f72c22bb68a95c50a8c8dcd78565b47be85d811c9360d37
- Old source-tree products were also archive-first consolidated: 36
paths on
rdmsm4x(40a3803b3cbaca6dbb2390c0a118d254fdcebad257b4f022ef8a853aa1af5df1), 7 paths onrdmbair15m5(6fb6b997e9d6d0faa44b0592176615d775eb43291e811111624165e2bedf9a4b), and a final five residual Build 38/42 archives onrdmsm4x(2d7ba13bcb2a682e0c86bce0a31feb6816621e456eb9473df118ff62fec4bf3f). - Final six-host censuses found exact Build 44 active products and no
unpacked superseded executable assets outside Cleanup Archives.
Canonical
dist/and the frozen candidate retain current Build 44 only. A filename-only match for the protected app-icon worktree snapshot was inspected; it contains no app, CLI, or MCP executable.
Files, evidence, and backup locations
- Checked-in receipt:
/Users/richh/dev/apps/replicantDB/docs/RELEASE-1.20.0-BUILD44.md. - Raw build/notary/rollout/census/cleanup evidence:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.20.0-build44-rollout-20260925/evidence/. - Frozen accepted candidate:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.20.0-build44-rollout-20260925/candidate/. - Per-host rollback and cleanup archives:
~/Library/Application Support/ReplicantDB Cleanup Archives/<rollout-run-id>/. - Canonical current products:
/Users/richh/dev/apps/replicantDB/dist/. - Coordination check-in:
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-replicantdb-build44-release-20260925.json. - Ticket receipt:
/Users/richh/dev/issues/resolved/TASK-20260925-12-replicantdb-1-20-0-build-44-reconcile-id.md.
Commands and operational mechanisms used
- Source gates:
swift test, targeted XCTest filtering,./build.sh,scripts/verify_build_contract.zsh,git diff --check, and JSON parsing. - Artifact gates:
codesign,lipo,vtool,spctl,stapler, andnotarytool info/login the logged-in Aqua session. - Fleet rollout:
replicantdb-host-rollout.zshphasespreflight,install, andverify, one host at a time, with exact caller-supplied SHA-256 values and rollback state capture. - Cleanup:
replicantdb-cleanup.zshandreplicantdb-source-artifact-cleanup.zshphasesdry-run,execute, andverify;replicantdb-artifact-census.zshfor the read-only final six-host census. - Integration:
git merge --ff-only, annotated source tagv1.20.0-build44, ordinary pushes to the privatefleetandbackupremotes, and remote-SHA rechecks.
Undo / rollback
- On an affected host, locate its rollout run under
~/Library/Application Support/ReplicantDB Cleanup Archives/and verifybuild43-rollback.tgzagainst the host-specific hash above. - Restore the Build 43 app/CLI/MCP from that verified archive to
/Applications/ReplicantDB.appand~/bin/, preserving the host's prior GUI state and daemon/Tyrell-helper ownership. - Validate signature, universal slices, version, executable hashes, exact launch path, and absence of new diagnostic reports.
- Source rollback is ordinary Git history:
v1.20.0-build44identifies the frozen release source andf076498identifies the integrated evidence tip. Do not rewrite published history; revert with a new commit if source rollback is required.
Safety boundary and outstanding owner action
- The release harness did not directly query or mutate the live database and did not run scan, OCR, classification, hashing, tagging, deduplication, consolidation, file moves, daemon installation, or CloudKit writes. Four existing GUIs were relaunched, so ordinary application behavior after relaunch is possible; unchanged database bytes are not claimed.
- Git source, peer worktrees, user files, live databases, permissions, TCC grants, authorization records, credentials, and agent/session stores were excluded from cleanup.
- Only owner/Apple action remaining for this release line: create/stage the matching ReplicantDB macOS provisioning profile/container entitlement before claiming production CloudKit or App Store/TestFlight readiness. Build 44 itself is complete for private fleet testing.