Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260927-0309-tyrell signing and FDA consolidation

HANDBACK — ISSUE-20260927-10

Work interval: 2026-09-27 02:34 EDT–2026-09-27 03:10:24 EDT; host rdmsm4x; codex/tyrsigfda. Owner of integration/rollout: claude@rdmsm4x/tyrlead1. Worker S owns service/UI files.

Worker delivery complete; overall ticket remains open for integration, the SMAppService decision, signing review and FDA owner actions.

Source delivered

Commit f8f97d179ce37a52cc04d9675b05f71c7522bba7 on codex/tyrell-sigfda-20260927, based on 75eac5f53bdb0d6cfbfb01109f142002d76ce9f3. Pushed only this branch to fleet and backup; working tree clean after commit. Agent trailer present. No merge, main push, install, signing, canary deploy or fleet rollout.

Installed-origin guards now protect SelfBootstrap, the production daemon entry point and installer; worktree bundle --install is refused. Development daemon tests require explicit scratch state/log/token paths, isolated mode and a separate port. Installer verifies the installed helper instead of modifying its signature. No entitlement changes.

 SESSION-STATE.md                                   | 20 ++++++++
 Sources/TyrellCore/Bootstrap/SelfBootstrap.swift   |  4 ++
 .../Bootstrap/TyrellInstallationOrigin.swift       | 55 ++++++++++++++++++++++
 Sources/tyrelld/Daemon.swift                       | 10 ++++
 .../tyrell_install_origin_contract_test.zsh        | 43 +++++++++++++++++
 .../tyrell_installation_origin_swift_test.zsh      | 52 ++++++++++++++++++++
 .../tyrelld_stable_install_contract_test.zsh       |  7 ++-
 docs/ops/2026-09-27-signing-fda-consolidation.md   | 53 +++++++++++++++++++++
 scripts/install_service.zsh                        | 43 ++++++++---------
 scripts/lib/tyrelld_lifecycle.zsh                  | 21 ++++++++-
 scripts/make_app_bundle.zsh                        |  8 +++-
 11 files changed, 288 insertions(+), 28 deletions(-)

Integration dependencies — do not adopt installer alone:

  1. worker-S-origin-guards.patch is proposal-only. Lead/Worker S must add guards to service controller mutation/lifecycle and app-login SMAppService adapters. No Worker S source was edited.
  2. lead-rollout-installed-helper.patch is proposal-only. Rollout must select the already-installed bundled helper and require candidate daemon bytes to match the candidate bundle. The installer must run from outside a linked worktree. Existing independently re-signed standalone daemon and bundle helper have different hashes: B43 standalone b4d96abd578a131b5fd56e566413678152a1297d04891ecb4d7ec65c40d25d9b; embedded helper 195da20b53564f1488add6602d62b17698cc8e8105154b1d86641195d3197128. Update the release daemon hash/source together.
  3. Full app/daemon build and signed canonical-path canary verification remain the lead's gates. The focused tests do not establish installed acceptance.

Tests and checks

Test Count/result
Shell installed-origin contracts 9 passed
Compiled Swift 6 origin/scratch policy 23 passed
Proposed service-controller guards 8 passed
Existing process restart contracts 23 passed
Stable-install contract script exit 0
Bundle contract script exit 0
Version contract script exit 0
Both proposal patches git apply --check exit 0
Swift/shell syntax, zero fleet identity, diff whitespace exit 0

Seven test scripts; 63 explicitly counted checks/cases. The proposal harness uses real controller/model/parser/policy code and stubs configuration dependencies; UI adapters were syntax-parsed, not fully typechecked. All builds/tests used nice -n 10. No tests wrote production stores. See individual *-test.log, bundle-contract.log, version-contract.log, zero-fleet-identity.log. Harness corrections and full validation limits are recorded in SOURCE-AUDIT.md.

Signing evidence

codesign-raw.json contains raw codesign -dv --verbose=4, codesign -d -r-, and strict verification for release cuts B42/B43 and installed counterparts. *-inventory.json records each host's installed bundle/helpers and running executable metadata.

Component B42 → B43 DR exact match Installed DR equals B43 Authority/team
Tyrell.app yes yes Developer ID / ZU2882L4HT
Contents/MacOS/Tyrell yes yes Developer ID / ZU2882L4HT
Contents/MacOS/tyrellbar yes yes Developer ID / ZU2882L4HT
LoginItems/TyrellBar.app yes yes Developer ID / ZU2882L4HT
Helpers/tyrelld yes yes Developer ID / ZU2882L4HT
Helpers/tyrell-mcp yes yes Developer ID / ZU2882L4HT
Helpers/ecsmem0d yes yes Developer ID / ZU2882L4HT
Helpers/replicantdb yes yes Developer ID / ZU2882L4HT
Standalone/stable tyrelld yes yes Developer ID / ZU2882L4HT

9/9 comparisons match, 27/27 strict signature verifications passed. No current installed component was ad-hoc or mismatched. There are 108 historical/development ad-hoc binary path entries in the inventory, individually labeled in MANIFEST.tsv. Full certificate authority strings are in SIGNING.md.

One canonical daemon and DEC

All six active jobs execute ~/Library/Application Support/Tyrell/bin/tyrelld, a real file; launchctl + PID + ps + root lsof and /health confirm Build 43 at 02:55–02:59 EDT. All six have the same standalone hash above, /health exit 0 and ok=true. Existing ReplicantDB jobs, including the one using Tyrell's embedded helper, were preserved.

The requested SMAppService daemon architecture is not implemented at this base or installed cuts. The helper is bundled, but the embedded LaunchAgents plist and SMAppService.agent registration are absent. Existing docs/ops/2026-09-27-service-mode-DEC.md chooses plain launchctl stable-path mode. Main-app login registration is a different facility. Headless operation is a separate daemon process.

No matching DEC ticket was found by the final SMAppService / 'tyrelld ships' searches at 03:03–03:04 EDT. Lead was asked on the bus; lead must reconcile/file it. This worker did not change Worker S files or migrate the daemon's TCC/BTM identity. See SOURCE-AUDIT.md for the source finding and Apple documentation link.

Stray inventory and archival

Host Binary paths Release binaries moved Dev aliases moved Stale FDA rows Canonical daemon FDA
jdmbair13m5 53 13 1 15 2
rdmbair13m5 60 14 1 9 2
rdmbair15m5 150 21 1 3 2
rdmpw3265m 58 14 1 12 0
rdmpw3275m 79 15 1 17 0
rdmsm4x 320 28 0 8 0

Total: 720 binary paths plus 27 agent plists; 105 old release binaries and five development symlinks moved, 110/110 post-move hashes/source-absence checks passed. Path counts include duplicates/aliases. Complete six-host manifests were published and byte-verified on all six hosts.

Central: MANIFEST.tsv. Per host: ~/dev/_archive/tyrelld-strays-20260927/<host>/MANIFEST.tsv, preserved intent/result MOVE-JOURNAL.tsv, and files/ retaining original path structure. Publication checksums: manifest-publication.jsonl.

No plist was classified as an obsolete loaded daemon, so no bootout was performed. Active worktree .build outputs, app bundles, handoff artifacts, current/recent rollback copies, existing archives, open files and canonical jobs remain untouched and listed. This is a conservative archive, not elimination of every historical copy.

Open exception: on jdmbair13m5, ~/Library/Application Support/Tyrell/releases/daemon-098e1b457bc4/tyrelld is mapped by /usr/sbin/spindump PID 1298 (fresh 03:03 EDT check); retained. Other ambiguous ownership/rollback cases remain marked retained in MANIFEST.tsv. Never restore over a newly created file; recheck live custody before restoring any recorded move.

FDA and Needs Rich

FDA-STALE.md contains one section per host and 64 stale-row manual-removal candidates. Only read-only sqlite3 queries were used. No tccutil reset or TCC writes. User DB was absent on four arm64 hosts; Intel user DB queries succeeded with zero matching rows. System DB was readable on all six.

Durability and coordination

Detailed committed audit: docs/ops/2026-09-27-signing-fda-consolidation.md; resumable SESSION-STATE.md updated. Raw evidence and proposed patches remain in this handoff directory. Start/milestone/handback bus notes and ticket comments record progress. No reroute was received in the milestone inbox reads.

File changelog archived under both fleet Claude and Codex changelog roots. Apple Notes publication remains PENDING: session is Background and the active directive prohibits GUI prompts until Rich returns (~10:00 EDT). No prompt was raised. Topology mismatches and old preflight mail were routed to ops; they did not authorize account/session migration.