jdmbair13m5-changelog-20260923-1944-automation-closeout
jdmbair13m5-changelog-20260923-1944-automation-closeout
Close-out of session 453a8d57 (claude@jdmbair13m5), 2026-09-23 09:52:57 → 19:44:13 EDT. Detail and correction: jdmbair13m5-changelog-20260923-1027-automation-toggles-reset-and-notes-migration.
Final state (measured)
- Automation:
tccutil list -s AppleEvents→ com.eastcoastscience.ECSToolHost ×3, com.apple.Terminal ×2, /usr/libexec/sshd-keygen-wrapper ×3. ECSToolHost Notes/Finder/System Events were re-approved by Rich at 10:33 via a herdr pane (claude@rdmbair15m5). - Lost by the 10:18:53 global reset and not recoverable by prompt on 27.2: 8 sshd-keygen-wrapper + 1 /bin/zsh grants. Recovery needs an MDM PPPC profile; claude@rdmbair15m5 raised this with Rich.
- Notes: all 44 local changelogs are in [email protected] → Fleet Changelogs/llmlog.
- ECSToolHost: build 2 reverted (0d7ff80); ECSTH-20260923-04 closed invalid (85110e4); fleet stays on build 1.
- ISSUE-20260923-02 (TyrellBar/Tyrell/rtty.direct entitlement): correction comment added; the premise is disproven for the responsible-process case.
- Rule: never run
tccutil reset. Canonical text is in FLEET.md §7 (fleet/maintenance 9186ba5); the macos-permissions skill points to it. - Test of the hourly com.rdm.claude-notes-autopublish job (/bin/zsh, platform binary): this changelog was left for that job to publish. Result: see the addendum below.
Addendum — 2026-09-23 19:44:51 EDT
- The autopublish test PASSED. At 19:44:35 the job (launchd → /bin/zsh, tccd AUTHREQ_SUBJECT=/bin/zsh) published this changelog. The note exists in Fleet Changelogs/llmlog (count 1). So the hourly Notes auto-publish on this host is NOT broken by the reset; the prediction that it would be refused was wrong. The MDM PPPC item applies only to the sshd-keygen-wrapper grants, if any SSH-driven Automation is still needed.