Fleet changelogs · dev.ecs0.net
rdmbair15m5-20260820-1838-claude-config-cleanup-and-fleet-normalization

rdmbair15m5-20260820-1838-claude-config-cleanup-and-fleet-normalization

Cut always-loaded Claude context ~52% on this host, fixed a plugin hook that had failed silently at every session start for two weeks, and normalized Claude config + ~/CLAUDE.md across all five Macs.


1. Context reduction (rdmbair15m5)

Component Before After Δ
~/.claude/CLAUDE.md ~7,918 ~8,178 +260 (absorbed migrated facts)
~/CLAUDE.md ~4,677 retired −4,677
MEMORY.md ~842 ~842 —
Plugin agent listing (27 → 6) ~3,928 ~811¹ −3,117
Plugin skill listing (34 → 17) ~2,799 ¹ −2,799
User skill listing (11 → 4) ~1,158 ~400 −758
Always-loaded total ~21,322 ~10,232 −11,090 est. tok (−52%)

¹ Enabled plugins' skills + agents measured together after cleanup. All figures est. (chars ÷ 4).

Plugins disabled (17) — ~/.claude/settings.json, enabledPlugins: false

frontend-design, agent-sdk-dev, claude-code-setup, claude-md-management, code-review, code-modernization, commit-commands, code-simplifier, cwc-makers, feature-dev, math-olympiad, mcp-server-dev, playground, plugin-dev, pr-review-toolkit, skill-creator (all @claude-plugins-official) + andrej-karpathy-skills@karpathy-skills. All had 0 lifetime uses and 0 transcript hits across a 21-day / 24-transcript window.

Kept: superpowers (232 uses), hookify (1,941), learning-output-style (229), explanatory-output-style (229), ralph-loop (39).

Skills disabled (7) — skillOverrides: "off"

agents-sdk, durable-objects, sandbox-sdk, turnstile-spin, web-perf, cloudflare-one-migrations, cloudflare-email-service. Kept: cloudflare, wrangler, workers-best-practices, cloudflare-one — also zero-use, but active Cloudflare DNS/cert work is on record.

Undo: flip any enabledPlugins entry back to true / drop its skillOverrides key, or use /plugin.


2. ~/CLAUDE.md retired on all five hosts

Its content was 100% duplicated or stale:

~/.claude/CLAUDE.md loads in every project; ~/CLAUDE.md loaded only under ~. The global file strictly dominates, so retiring the local one loses nothing anywhere.

Three non-derivable facts were migrated into the doctor block first, then a guard verified all five required strings were present before any deletion:

  1. rdmbair15m5 has 0 valid code-signing identities (security find-identity -v -p codesigning). Team ZU2882L4HT + three com.eastcoastscience.RDWorkbench profiles are cached and valid to Aug 2027, but no cert/private key exists locally and none is backed up. Simulator work is fine; device runs, notarization, and App Store submission are blocked until an Xcode sign-in.
  2. xcode-select -p can lie — read ground truth as env -u DEVELOPER_DIR xcode-select -p.
  3. The host-label warning (relative labels name the generating host).

Undo: cp ~/.claude/backups/doctor-clean-20260820-183004/CLAUDE.md ~/CLAUDE.md


3. Broken plugin hook — silent for two weeks

superpowers ships hooks/run-hook.cmd mode 644, and its hooks.json invokes that wrapper directly, so every SessionStart failed with exit 126 / Permission denied — 10 recorded failures, most recent 2026-08-20T21:41:31Z. Nothing surfaced at normal verbosity.

chmod +x ~/.claude/plugins/cache/claude-plugins-official/superpowers/6.1.1/hooks/run-hook.cmd

Verified by invoking it exactly as hooks.json does: exit 0, 3,414 bytes of additionalContext that had been dropped. Zero failures since.


4. Fleet config normalization (all 5 hosts)

rdmbair15m5 rdmbair13m5 rdmpw3265m rdmpw3275m rdmsm4x
Claude Code 2.1.237 2.1.237 2.1.237 2.1.237 2.1.237
Cask @latest @latest @latest @latest @latest
defaultMode bypassPermissions ✅ ✅ ✅ ✅
~/.claude/CLAUDE.md identical ✅ ✅ ✅ ✅
~/CLAUDE.md retired ✅ ✅ ✅ ✅

permissions.defaultMode — do not script it

bypassPermissions is intended (owner-confirmed). A live Claude session writes its own mode back to ~/.claude/settings.json, and Claude runs continuously on every host, so any scripted fleet change is re-asserted within minutes. Observed: a fleet-wide set to auto reverted on all five without any sync job; on the next pass every host reported "already bypassPermissions".

Misleading symptoms that are not a rogue agent: the value changing on untouched hosts; one host flipping between two reads seconds apart (rdmsm4x did); the change appearing fleet-wide and simultaneous. Read defaultMode as an observation of live session state, never as owned config.


5. dev_update.zsh fleet run

Verified byte-identical first (sha256 2dd7fab797371a42, v2.6) to avoid racing the shared-write file, then launched on all five under nohup caffeinate.


6. Latent footgun fixed

~/.claude/CLAUDE.md had <!-- BEGIN mac_fleet_library_updates_081526 --> with no matching END. Any idempotent strip-and-reappend keyed on that marker pair would have deleted everything to EOF. END marker added; all four pairs now balance.

This actually bit during the session: an awk block-extract ran to EOF and mis-measured the block as 10,877 chars (real size ~700). A truncated ~/CLAUDE.md was briefly propagated as a result and was rebuilt from backups within minutes.


7. Health checks with no findings


8. Outstanding / owner action

  1. Rotate the UDM root password found in cleartext inside a transcript on rdmpw3275m. ~/.claude/projects/**/*.jsonl stores tool calls verbatim and is a plaintext secrets surface; transcripts are not retroactively sanitized. Per CLAUDE.md §3, read secrets from ~/.secrets/global.env or Keychain at runtime instead of embedding them in a command line.
  2. rdmbair13m5: run mas upgrade interactively (2 pending App Store updates).

9. Files touched

File Hosts Change
~/.claude/settings.json rdmbair15m5 +17 enabledPlugins:false, +7 skillOverrides:"off"
~/CLAUDE.md all 5 deleted (backed up)
~/.claude/CLAUDE.md all 5 doctor block + migrated facts; END marker fix
~/.agent-coordination/checkins/claude-code-doctor-fleet.json all 5 check-in published + updated
superpowers/6.1.1/hooks/run-hook.cmd rdmbair15m5 mode 644 → 755
~/.claude/projects/-Users-richh/memory/*.md rdmbair15m5 +4 memories, indexed in MEMORY.md