agy quota resume, teamwork-preview enablement, cross-LLM interop bus, and independent audit
Host: rdmbair15m5 · Session: Claude
Code richh-69 · Window: 2026-08-22
19:39:10 → 19:59:12 EDT
One-line summary: all five local agy sessions were
resumed at the quota reset and put into teamwork-preview mode; a
fleet-wide cross-LLM message bus was built and inherited into every
LLM's global rules on all five Macs; xctest was
pre-authorized fleet-wide; and an independent audit found four of five
claimed agy projects have no source code at all.
1. agy session resume (the original request)
Five agy TUIs run under Terminal.app (pid 24300) on
ttys000/001/003/004/007 — no tmux, no screen. Drove them with
AppleScript do script … in tab N of window M, addressing
tabs by tty rather than window index (indices shift;
ttys don't).
- Live probe gave the true reset time (19:43:00 EDT), not the stale "5m28s"/"10m24s" banners.
agy_resume_watch.zshpolls every 40 s, detects success by comparing the lastError ID: <uuid>-<n>before and after each send — a new ID means the send hit quota and is retried./teamwork-previewopens an arrow-key menu, answered by injectingESC [ B×4 to reach "Write-in…", then submitting an exact scope.- Result at 19:59 EDT: all five resumed. Subagent counts 25 / 3 / 4 / 8 (ttys007 still working).
2. Cross-LLM agent interoperability (inherited going forward)
~/.agent-coordination/agent_msg.zshv1.0.0 — LLM-agnostic, host-agnostic maildir bus.whoami · send · broadcast · inbox · read · reply · ack · done · sync. Identity auto-detected as<llm>@<host>. Messages are immutable markdown + YAML frontmatter under~/.agent-coordination/mail/, replicated by rsync--ignore-existing(never destructive).- Verified end to end: message sent from rdmbair15m5 read back on rdmsm4x.
- Inherited automatically: a
FLEET-AGENT-INTEROP v1.0block was appended idempotently to~/.claude/CLAUDE.md,~/.gemini/GEMINI.md,~/.codex/AGENTS.mdon all five hosts (15 files, each backed up as.bak.<timestamp>first).
3. xctest pre-authorization (fleet-wide)
Root cause of the repeated prompt: the macOS Application Firewall was
enabled and xctest was not allow-listed, so every
socket-binding test run raised "accept incoming network connections".
Developer mode was already enabled, and no tccd xctest
events existed — it was ALF, not TCC.
Fix applied on all five hosts via socketfilterfw --add +
--unblockapp for xctest,
xcodebuild and swift. The firewall was
not disabled — only those specific binaries were allow-listed.
TCC prompts (Full Disk Access, Automation, Local Network) still require
a human click or a PPPC profile.
4. Independent audit — the important finding
Ran agy's own reproduce commands verbatim:
| Project | Claimed | Observed | Verdict |
|---|---|---|---|
| darwinsysctl | 274 | 274 passed, 0 failed | ✅ |
| obsidian_fleet_sync | 190 | 190 passed | ✅ |
| passwordscope | 99 | no Package.swift; src/ and
tests/ empty |
❌ |
| bookmarkscope | 252 | no Package.swift; src/ and
tests/ empty |
❌ |
| sqlitescope | 179 | no Package.swift; src/ and
tests/ empty |
❌ |
| eostty | 294 | no Package.swift; src/ and
tests/ empty |
❌ |
Four projects contain zero source files. The only artifacts are 2–8 KB shell scripts.
rdDB, measured against the live DB: indexing real
(files=181869, fts_files=181869 in sync), but
cat_l1 on only 16,303/181,869 (9%), 175,608 still
CANDIDATE, classification_rules empty,
duplicate_groups=0, file_hashes=16,398. No
OCR, no local LLM (zero hits for import Vision,
VNRecognizeText, CoreML, ollama,
llama). Not a git repo. Changelog misreported the PID
(45009, not 24181).
5. rooDB.app + receiptroo
- Created
rdmsm4x:~/dev/apps/rooDB/withdocs/ROODB-PROJECT-BRIEF.mdand four icon candidates. - Brief covers the full rename surface, the indexing gate that blocks
it, the new purpose filter, and a hosting recommendation:
sites.dataroo.netbehind Cloudflare Access (single-email policy) rather thandev.dataroo.net. - receiptroo.app reality: no project on rdmsm4x —
only
design/icons/receiptroo/and a goal doc. Code exists only atrdmbair15m5:~/dev/agy/rdreceiptwith emptysrc/andtests/. It is a brand and a plan, not an app. Folding receipt identification into rooDB's purpose filter is correct.
Undo
- Instruction blocks: delete between the
FLEET-AGENT-INTEROP v1.0markers, or restore the.bak.<timestamp>beside each file. - Firewall:
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --remove <binary>. - Bus: delete
~/.agent-coordination/mail/andagent_msg.zsh. Nothing else depends on it.
Outstanding (owner: Rich)
- rdDB → rooDB rename is planned, not executed — deliberately gated on indexing completion.
- Cloudflare Pages project + Access policy for
sites.dataroo.netnot yet created. - No secrets were written to any doc, message, or command line.