Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260821-0440-fleet-doctor-and-normalization

rdmbair15m5-changelog-20260821-0440-fleet-doctor-and-normalization

Summary: Consolidated record of the Claude-doctor and fleet-normalization work performed by rdmbair15m5 on 2026-08-20 and 2026-08-21 — always-loaded context cut ~52% on this host, a plugin hook that had failed silently at every session start for two weeks fixed, ~/CLAUDE.md retired fleet-wide after its non-derivable facts were migrated and guard-verified, and orchestration handed off cleanly to rdmsm4x. Prepared for Apple Notes filing under rule 26.


1. Scope

Mutated on this host ~/.claude/settings.json (enabledPlugins, skillOverrides), ~/.claude/CLAUDE.md (append-only block), ~/CLAUDE.md (retired), hooks/run-hook.cmd (mode only), ~/.agent-coordination/checkins/
Mutated fleet-wide from this host ~/CLAUDE.md promoted then retired on all 5; doctor block appended per host
Never touched ~/dev_update.zsh (read/execute only), permissions.defaultMode, any peer-owned marker block, RTTy/LogTTY artifacts, sudo

2. What changed

Context reduction (this host): always-loaded total ~21,322 → ~10,232 est. tokens (−52%). 17 plugins disabled (enabledPlugins: false) and 7 skills disabled (skillOverrides: "off") — every one had 0 lifetime uses and 0 transcript hits across a 21-day / 24-transcript window. Kept superpowers (232 uses), hookify (1,941), learning-output-style (229), explanatory-output-style (229), ralph-loop (39).

hooks/run-hook.cmd exec bit. Shipped mode 644 by the superpowers plugin, so hooks.json invoking it directly failed every SessionStart with exit 126 / Permission denied — silently, 10 occurrences in transcripts, most recent 2026-08-20T21:41Z. chmod +x applied; re-run as hooks.json invokes it returns exit 0 and 3,414 bytes of additionalContext.

~/CLAUDE.md retired on all 5 hosts (owner-approved). Content was 100% duplicated (fleet-dev-update v2.5 and claude-doctor-baseline v1, byte-identical copies in ~/.claude/CLAUDE.md) or stale 08-15 version tables already wrong within 5 days. Three non-derivable facts were migrated into the doctor block first, and a guard verified all five required strings were present before any deletion:

  1. rdmbair15m5 has 0 valid code-signing identities (team ZU2882L4HT).
  2. env -u DEVELOPER_DIR xcode-select -p is the only truthful read of the active Xcode.
  3. The host-label warning — relative labels name the generating host.

Latent footgun fixed. The mac_fleet_library_updates_081526 block in ~/.claude/CLAUDE.md had a BEGIN marker with no matching END. Any idempotent strip-and-reappend keyed on that pair would have deleted everything to EOF. END marker added.

Orchestration handed off. rdmsm4x claimed sole-orchestrator role at 08:28Z; this host acknowledged, stood down from fleet-wide mutation at 08:40Z with nothing in flight, and published the hand-off as a check-in.

3. Commands run

security find-identity -v -p codesigning
chmod +x ~/.claude/plugins/cache/claude-plugins-official/superpowers/6.1.1/hooks/run-hook.cmd
grep -n "claude-doctor-baseline v1\|fleet-dev-update v2.5" ~/.claude/CLAUDE.md
shasum -a256 ~/dev_update.zsh
brew doctor                                  # under dev_update.zsh's exact PATH (line 179)
tailscale status --self=true
ssh -n -o BatchMode=yes [email protected] '...'      # read-only probes
zsh fleet_checkin_sync.zsh                   # peer mode, union-only

4. Verification evidence

5. Correction filed against the pending "sbin" issue

The orchestrator reported that rdmbair15m5 "still WARNs because it has a genuine Homebrew's "sbin" was not found in your PATH finding" and was preparing to file that as a new fleet-wide OPEN issue. That does not reproduce on this host as dev_update.zsh actually runs it.

This is the same false-positive class already documented for npm doctor: a doctor check comparing against the invoking shell's PATH, not against any persistent defect. Recommendation: do not file the fleet-wide OPEN issue on this host's evidence, and do not "fix" it by editing PATH.

6. Backups and undo

Change Undo
Plugin/skill disables flip enabledPlugins entry back to true, drop its skillOverrides key, or use /plugin
~/CLAUDE.md retirement cp ~/.claude/backups/doctor-clean-20260820-183004/CLAUDE.md ~/CLAUDE.md (remotes: ~/.claude/backups/CLAUDE.md.retired-20260820)
Settings + memory files ~/.claude/backups/doctor-20260820-175709/ (pre-change snapshot, all 5 hosts)
Check-in records delete the JSON; the sync script is union-only and never deletes a peer's record

Caveat: chmod +x on a plugin-cache file does not survive a plugin re-extract. After any superpowers update, re-check run-hook.cmd or every SessionStart fails silently with exit 126.

7. Outstanding owner actions

  1. Rotate the UDM root password found in cleartext in a transcript on rdmpw3275m. Transcripts are never retroactively sanitized. Referenced by name and location only — no value recorded here.
  2. Sign in through Xcode on rdmbair15m5 — 0 valid code-signing identities, re-verified today.
  3. Apple Notes filing of this record is PENDING, not skipped. This session's launchctl managername is Background, so AppleEvents to Notes are dead and notes_changelog.zsh would hang on -1712 and report a false failure. Needs a run from Terminal.app in the desktop session on this host, or filing from rdmsm4x on this host's behalf.

No secrets recorded. Credentials referenced by name and location only.


8. End-to-end validation of the v2.8 filter (added 04:55 EDT)

The orchestrator had tested the v2.8 filter's logic but not the shipped code path in a run. Closed here, on this host, with a real before/after — no mutating run required.

Before — v2.7, real run, dry_run=0, ~/scripts/dev_update_20260821_042522.log:

"warnings": ["brew doctor found issues \u2014 review below"],
"issues": []

A WARN banner with an empty issues list — the spurious output v2.8 exists to remove.

After — v2.8, --dry-run, ~/scripts/dev_update_latest.json @ 04:40:56 EDT:

  ✓ brew doctor: only the macOS 27.0 Tier-2 support notice — benign, no action
"warnings": [], "issues": []

The INFO line prints as designed, green ✓ rather than a yellow warn banner.

Why the dry run is valid evidence here: the Homebrew doctor block carries no DRY gate — brew doctor is read-only, so it executes identically in both modes. This is the shipped code path executing for real, not a simulation of it. The one thing still unobserved is the same block inside a full mutating run; nothing in the block's control flow depends on that, but it is stated rather than assumed.

Method note: an earlier measurement in this session recorded exit 0 for brew doctor. That was head's exit status from brew doctor | head -20, not brew's — zsh reports the last command in a pipeline. True exit is 1. Corrected in section 5. It does not change any conclusion, because the filter branches on doctor_left, not on the exit code.