rdmbair15m5-changelog-20260822-2330-xcode-266-fleet-and-signing-diagnosis
Session: 2026-08-22 22:33 -> 2026-08-22 23:30:28
EDT Ran on: rdmbair15m5 · changed
state on: rdmsm4x
Installed Xcode 26.6 on rdmsm4x, corrected a wrong recorded diagnosis about fleet code signing, and delivered a script to distribute the signing identity. No signing change has been applied yet - that step requires Rich at rdmsm4x's keyboard.
1. Code signing - the recorded diagnosis was WRONG
~/CLAUDE.md states rdmbair15m5's signing is "broken and
unrecoverable locally... no certificate or private key exists on disk
and none is backed up."
rdmsm4x holds a fully valid East Coast Science identity:
CN = Apple Development: Richard Doty (S65Q255HA8)
OU = ZU2882L4HT O = east coast science, llc
valid 2026-08-05 -> 2027-08-05, private key present
2 provisioning profiles, both ZU2882L4HT, valid to Aug 2027
So the situation is recoverable: rdmsm4x has the key; the other four Macs have zero identities. The certificate was issued on rdmsm4x 2026-08-05 and never existed elsewhere - certificates do not sync via iCloud. This is NOT Xcode forgetting a sign-in.
~/CLAUDE.md should be corrected. It
currently sends any agent down a dead end.
Two traps worth recording
ssh -ndefeatsssh host 'bash -s' < script.sh.-nredirects stdin from /dev/null, silently discarding the piped script. Four healthy hosts returned nothing.-nis forwhile readloops only; afor h in ...loop does not consume stdin.- An ssh session is a
Backgroundsession, notAqua. The login keychain releases certificates there (public data - this is how remote verification works) but never a private key.sudo launchctl asuser $(stat -f %u /dev/console)reaches the unlocked GUI keychain, but a key export still blocks on an invisible dialog and hangs until killed. Certificate reads verify remotely; key exports do not.
2. Xcode 26.6 installed on rdmsm4x
26.6 (17F113) is the latest non-beta; 27.0 exists only as Beta 5. Before this session rdmsm4x had no non-beta Xcode at all - only two identical copies of Xcode-27-beta5.
mas install 497799835 stalled at 2242
MB after ~35 min: storedownloadd at 0.0% CPU, no open
network connections, holding the partial .pkg read-only, zero byte
growth over 45 s. Stopped it and removed the 2.2 GB partial.
Installed by copying from rdmbair15m5 instead - same version, same arch, and Xcode 26.6 is only ~3.5 GB (modern Xcode fetches SDKs on demand):
tar -c --mac-metadata -f - -C /Applications Xcode.app \
| ssh -o Compression=no [email protected] 'sudo -n tar -x --mac-metadata -p -f - -C /Applications'
macOS ships openrsync (protocol 29), which rejects
--info=progress2 / --no-inc-recursive;
tar --mac-metadata is the portable path for a signed
bundle. Transfer took 5m44s at ~37 MB/s.
Verified on rdmsm4x after the copy:
codesign --verify-> valid on disk, satisfies its Designated Requirement, exit 0spctl -a -t exec-> accepted, source=Mac App Storexcodebuild -version-> Xcode 26.6, Build 17F113-checkFirstLaunchStatus-> OK, no components needed- license already accepted
(
IDEXcodeVersionForAgreedToGMLicense = 26.6) - all 10 platforms present; 0 AppleDouble artifacts; no quarantine xattr
3. Fleet state at 2026-08-22 23:30:28 EDT
| Host | macOS | Xcode non-beta | Selected | Signing identity |
|---|---|---|---|---|
| rdmsm4x | 27.0 | 26.6 | Xcode-beta.app | YES |
| rdmbair13m5 | 27.0 | 26.6 | Xcode-beta.app | none |
| rdmbair15m5 | 27.0 | 26.6 | Xcode-beta.app | none |
| rdmpw3265m | 26.7 | 26.6 | Xcode.app | none (asleep at check time) |
| rdmpw3275m | 26.7 | 26.6 | Xcode.app | none |
rdmbair13m5.local now resolves
IPv6-only, so plain .local ssh fails;
reach it at Tailscale 100.75.186.59 (node
rdmbair13m5-1). Node rdmbair13m5 has been
offline 1d.
4. Files created
| Path | What |
|---|---|
rdmsm4x:~/scripts/fix_fleet_signing.sh |
distributes the signing identity to the fleet |
rdmsm4x:/Applications/Xcode.app |
Xcode 26.6 (17F113), verified |
rdmsm4x:~/scripts/logs/xcode-mas-install-*.log |
the stalled mas attempt |
5. Anthropic billing findings (read-only; nothing changed)
Single account [email protected], Claude Max
20x, stripe_subscription,
hasExtraUsageEnabled: true - overage
billing is ON and unbounded.
API-equivalent value consumed, mostly since 2026-08-07: rdmsm4x $5,429.65 · rdmpw3275m $774.21 · rdmbair15m5 $580.45 · rdmpw3265m $97.87 - $6,882.18 total, vs $43,893.20 with caching off. Cache reads are 97% of input.
This is value consumed at API rates, not the invoice - Max covers usage to the plan limits, and only the spill past them bills. The actual invoice is only visible at console.anthropic.com. Fable 5 ($10/$50 per MTok, 2x Opus) accounts for ~$2,044.
6. Outstanding owner actions
- Run
bash ~/scripts/fix_fleet_signing.shfrom Terminal.app on rdmsm4x's desktop (not over ssh - it refuses, by design). One Allow click + login password. - Decide the active toolchain. Three Apple Silicon
Macs still select Xcode-beta 27.0. For building/validating that is
probably backwards, but
xcode-select -schanges which SDK builds link against, so it was NOT changed without confirmation. - rdmsm4x carries two identical Xcode-27-beta5 copies (~20 GB wasted) - not removed.
- Correct
~/CLAUDE.md's rdmbair15m5 signing section (see item 1). - Consider turning off Anthropic extra usage if the bill should be bounded rather than monitored.
- Apple Notes entry PENDING - this session ran
headless over ssh;
~/scripts/notes_changelog.zshrefuses outside an Aqua session. Run it from Terminal.app on rdmbair15m5.
7. Secrets
None written. The probe passphrase visible in an early process listing belonged to a throwaway export that produced no file. The delivered script keeps its passphrase out of argv and off disk entirely.