Fleet changelogs · dev.ecs0.net
jdmbair13m5-changelog-20260904-0345-fleet-tcc-rtty-location-repair

jdmbair13m5-changelog-20260904-0345-fleet-tcc-rtty-location-repair

Repaired reverting Location Services permissions for RTTy (com.eastcoastscience.rtty.direct) by purging stale colliding registrations, setting authorization in CoreLocation daemon clients.plist, and built/deployed fleetwide diagnostic and repair tool mac_fleet_TCC_repair_check.zsh with Gemini-style Footlights status bar (1-10 dense lines) across all 6 Mac fleet hosts.

Scope

Root Cause Analysis: Reverting Location Switch

  1. In macOS System Settings, toggling Location Services on for RTTy immediately reverted to off.
  2. Under /var/db/locationd/clients.plist, locationd maintained stale client keys mapped to /Applications/RTTy.app using the legacy bundle identifier net.dataroo.RTTy (with requirement identifier "net.dataroo.RTTy").
  3. The active RTTy binary is codesigned with bundle identifier com.eastcoastscience.rtty.direct and designated requirement identifier "com.eastcoastscience.rtty.direct" and anchor apple generic and certificate leaf[subject.CN] = "Apple Development: Richard Doty (S65Q255HA8)".
  4. When System Settings issued an XPC request to mutate authorization, locationd detected duplicate executable paths and a requirement mismatch against the registered client token, denying the mutation.
  5. In addition, locationd caches clients.plist in memory and flushes dirty memory to disk unless frozen (killall -STOP locationd) prior to editing and force-restarted (killall -9 locationd).

Exact Files Touched

Commands Run

# Built and tested mac_fleet_TCC_repair_check.zsh
/Users/richh/dev/scripts/mac_fleet_TCC_repair_check.zsh -l 5 --fleet --audit-only
/Users/richh/dev/scripts/mac_fleet_TCC_repair_check.zsh -l 5 --fleet --repair
/Users/richh/dev/scripts/mac_fleet_TCC_repair_check.zsh -l 5 --fleet --audit-only --verbose

# Distributed to rdmsm4x project and scripts across fleet
scp /Users/richh/dev/scripts/mac_fleet_TCC_repair_check.zsh [email protected]:/Users/richh/dev/apps/RDmacTCCfix/
scp /Users/richh/dev/scripts/mac_fleet_TCC_repair_check.zsh [email protected]:/Users/richh/dev/scripts/

Verification Evidence

[03:42:45] ● PASS  [jdmbair13m5] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]
[03:42:46] ● PASS  [rdmsm4x] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]
[03:42:46] ● PASS  [rdmbair13m5] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]
[03:42:47] ● PASS  [rdmbair15m5] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]
[03:42:47] ● PASS  [rdmpw3265m] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]
[03:42:48] ● PASS  [rdmpw3275m] Location Services: com.eastcoastscience.rtty.direct (/Applications/RTTy.app) -> Status: [CHECKED]

Active RTTy process on jdmbair13m5 (PID 76293) connected to locationd with RegistrationComplete: 1, newAuthContext: RegResult:0(0) (Authorized).

Backup Locations

How to Undo

To revert to the prior state on any host: sudo cp -f /var/db/locationd/clients.plist.bak.<timestamp> /var/db/locationd/clients.plist && sudo killall -9 locationd

Outstanding Owner Actions

None required. All fleet hosts now have com.eastcoastscience.rtty.direct authorized for Location Services, and mac_fleet_TCC_repair_check.zsh is installed fleetwide.