HANDBACK — ISSUE-20260927-10
Work interval: 2026-09-27 02:34 EDT–2026-09-27 03:10:24 EDT; host rdmsm4x; codex/tyrsigfda. Owner of integration/rollout: claude@rdmsm4x/tyrlead1. Worker S owns service/UI files.
Worker delivery complete; overall ticket remains open for integration, the SMAppService decision, signing review and FDA owner actions.
Source delivered
Commit f8f97d179ce37a52cc04d9675b05f71c7522bba7 on
codex/tyrell-sigfda-20260927, based on
75eac5f53bdb0d6cfbfb01109f142002d76ce9f3. Pushed only this
branch to fleet and backup; working tree clean
after commit. Agent trailer present. No merge, main push, install,
signing, canary deploy or fleet rollout.
Installed-origin guards now protect SelfBootstrap, the production daemon entry point and installer; worktree bundle --install is refused. Development daemon tests require explicit scratch state/log/token paths, isolated mode and a separate port. Installer verifies the installed helper instead of modifying its signature. No entitlement changes.
SESSION-STATE.md | 20 ++++++++
Sources/TyrellCore/Bootstrap/SelfBootstrap.swift | 4 ++
.../Bootstrap/TyrellInstallationOrigin.swift | 55 ++++++++++++++++++++++
Sources/tyrelld/Daemon.swift | 10 ++++
.../tyrell_install_origin_contract_test.zsh | 43 +++++++++++++++++
.../tyrell_installation_origin_swift_test.zsh | 52 ++++++++++++++++++++
.../tyrelld_stable_install_contract_test.zsh | 7 ++-
docs/ops/2026-09-27-signing-fda-consolidation.md | 53 +++++++++++++++++++++
scripts/install_service.zsh | 43 ++++++++---------
scripts/lib/tyrelld_lifecycle.zsh | 21 ++++++++-
scripts/make_app_bundle.zsh | 8 +++-
11 files changed, 288 insertions(+), 28 deletions(-)
Integration dependencies — do not adopt installer alone:
worker-S-origin-guards.patchis proposal-only. Lead/Worker S must add guards to service controller mutation/lifecycle and app-login SMAppService adapters. No Worker S source was edited.lead-rollout-installed-helper.patchis proposal-only. Rollout must select the already-installed bundled helper and require candidate daemon bytes to match the candidate bundle. The installer must run from outside a linked worktree. Existing independently re-signed standalone daemon and bundle helper have different hashes: B43 standaloneb4d96abd578a131b5fd56e566413678152a1297d04891ecb4d7ec65c40d25d9b; embedded helper195da20b53564f1488add6602d62b17698cc8e8105154b1d86641195d3197128. Update the release daemon hash/source together.- Full app/daemon build and signed canonical-path canary verification remain the lead's gates. The focused tests do not establish installed acceptance.
Tests and checks
| Test | Count/result |
|---|---|
| Shell installed-origin contracts | 9 passed |
| Compiled Swift 6 origin/scratch policy | 23 passed |
| Proposed service-controller guards | 8 passed |
| Existing process restart contracts | 23 passed |
| Stable-install contract script | exit 0 |
| Bundle contract script | exit 0 |
| Version contract script | exit 0 |
| Both proposal patches | git apply --check exit 0 |
| Swift/shell syntax, zero fleet identity, diff whitespace | exit 0 |
Seven test scripts; 63 explicitly counted
checks/cases. The proposal harness uses real
controller/model/parser/policy code and stubs configuration
dependencies; UI adapters were syntax-parsed, not fully typechecked. All
builds/tests used nice -n 10. No tests wrote production stores. See
individual *-test.log, bundle-contract.log,
version-contract.log, zero-fleet-identity.log.
Harness corrections and full validation limits are recorded in
SOURCE-AUDIT.md.
Signing evidence
codesign-raw.json contains raw
codesign -dv --verbose=4, codesign -d -r-, and
strict verification for release cuts B42/B43 and installed counterparts.
*-inventory.json records each host's installed
bundle/helpers and running executable metadata.
| Component | B42 → B43 DR exact match | Installed DR equals B43 | Authority/team |
|---|---|---|---|
| Tyrell.app | yes | yes | Developer ID / ZU2882L4HT |
| Contents/MacOS/Tyrell | yes | yes | Developer ID / ZU2882L4HT |
| Contents/MacOS/tyrellbar | yes | yes | Developer ID / ZU2882L4HT |
| LoginItems/TyrellBar.app | yes | yes | Developer ID / ZU2882L4HT |
| Helpers/tyrelld | yes | yes | Developer ID / ZU2882L4HT |
| Helpers/tyrell-mcp | yes | yes | Developer ID / ZU2882L4HT |
| Helpers/ecsmem0d | yes | yes | Developer ID / ZU2882L4HT |
| Helpers/replicantdb | yes | yes | Developer ID / ZU2882L4HT |
| Standalone/stable tyrelld | yes | yes | Developer ID / ZU2882L4HT |
9/9 comparisons match, 27/27 strict signature verifications passed.
No current installed component was ad-hoc or mismatched. There are 108
historical/development ad-hoc binary path entries in the inventory,
individually labeled in MANIFEST.tsv. Full certificate authority strings
are in SIGNING.md.
One canonical daemon and DEC
All six active jobs execute
~/Library/Application Support/Tyrell/bin/tyrelld, a real
file; launchctl + PID + ps + root
lsof and /health confirm Build 43 at
02:55–02:59 EDT. All six have the same standalone hash above,
/health exit 0 and ok=true. Existing
ReplicantDB jobs, including the one using Tyrell's embedded helper, were
preserved.
The requested SMAppService daemon architecture is not
implemented at this base or installed cuts. The helper is
bundled, but the embedded LaunchAgents plist and SMAppService.agent
registration are absent. Existing
docs/ops/2026-09-27-service-mode-DEC.md chooses plain
launchctl stable-path mode. Main-app login registration is a different
facility. Headless operation is a separate daemon process.
No matching DEC ticket was found by the final SMAppService / 'tyrelld
ships' searches at 03:03–03:04 EDT. Lead was asked on the bus; lead must
reconcile/file it. This worker did not change Worker S files or migrate
the daemon's TCC/BTM identity. See SOURCE-AUDIT.md for the
source finding and Apple documentation link.
Stray inventory and archival
| Host | Binary paths | Release binaries moved | Dev aliases moved | Stale FDA rows | Canonical daemon FDA |
|---|---|---|---|---|---|
| jdmbair13m5 | 53 | 13 | 1 | 15 | 2 |
| rdmbair13m5 | 60 | 14 | 1 | 9 | 2 |
| rdmbair15m5 | 150 | 21 | 1 | 3 | 2 |
| rdmpw3265m | 58 | 14 | 1 | 12 | 0 |
| rdmpw3275m | 79 | 15 | 1 | 17 | 0 |
| rdmsm4x | 320 | 28 | 0 | 8 | 0 |
Total: 720 binary paths plus 27 agent plists; 105 old release binaries and five development symlinks moved, 110/110 post-move hashes/source-absence checks passed. Path counts include duplicates/aliases. Complete six-host manifests were published and byte-verified on all six hosts.
Central: MANIFEST.tsv. Per host:
~/dev/_archive/tyrelld-strays-20260927/<host>/MANIFEST.tsv,
preserved intent/result MOVE-JOURNAL.tsv, and
files/ retaining original path structure. Publication
checksums: manifest-publication.jsonl.
No plist was classified as an obsolete loaded daemon, so no bootout was performed. Active worktree .build outputs, app bundles, handoff artifacts, current/recent rollback copies, existing archives, open files and canonical jobs remain untouched and listed. This is a conservative archive, not elimination of every historical copy.
Open exception: on jdmbair13m5,
~/Library/Application Support/Tyrell/releases/daemon-098e1b457bc4/tyrelld
is mapped by /usr/sbin/spindump PID 1298 (fresh 03:03 EDT
check); retained. Other ambiguous ownership/rollback cases remain marked
retained in MANIFEST.tsv. Never restore over a newly created file;
recheck live custody before restoring any recorded move.
FDA and Needs Rich
FDA-STALE.md contains one section per host and
64 stale-row manual-removal candidates. Only read-only
sqlite3 queries were used. No tccutil reset or TCC writes. User DB was
absent on four arm64 hosts; Intel user DB queries succeeded with zero
matching rows. System DB was readable on all six.
- Rich: review installer signing-behavior diff (verification replaces re-signing) before release adoption. Entitlements and designated-requirement rules did not change.
- Rich: review/remove stale FDA entries using the minus button; preserve canonical app/daemon rows. Canonical daemon auth_value=0 on hub and both Intel hosts may need a deliberate grant if desired; three Airs have auth_value=2. These are DB observations, not fresh functional access tests.
- Lead: reconcile/file the SMAppService DEC and integrate the paired proposals, full-build and canary gates. Existing delegated ticket lease remains intact; not resolved or released by this worker.
Durability and coordination
Detailed committed audit:
docs/ops/2026-09-27-signing-fda-consolidation.md; resumable
SESSION-STATE.md updated. Raw evidence and proposed patches
remain in this handoff directory. Start/milestone/handback bus notes and
ticket comments record progress. No reroute was received in the
milestone inbox reads.
File changelog archived under both fleet Claude and Codex changelog roots. Apple Notes publication remains PENDING: session is Background and the active directive prohibits GUI prompts until Rich returns (~10:00 EDT). No prompt was raised. Topology mismatches and old preflight mail were routed to ops; they did not authorize account/session migration.