Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260823-1136-defaultmode-restored-bypasspermissions-fleetwide

defaultMode restored to bypassPermissions on all six hosts; agent-change prohibition added to CLAUDE.md

Rich's standing instruction (bypassPermissions fleet-wide) had drifted to auto on two hosts. Restored on his direct instruction, root cause identified, and a hard prohibition installed so no agent repeats it.

Files touched

  1. ~/.claude/settings.json on rdmsm4x and rdmbair15m5 (the other four were already correct). Backup: ~/.claude/settings.json.bak-20260823-112919-pre-bypass-restore
  2. ~/.claude/CLAUDE.md on all six. Backup: ~/.claude/CLAUDE.md.bak.20260823-113*-pre-defaultmode-rule

Verification

host          CLAUDE.md      defaultMode
rdmbair15m5   dba7b5458a8b   bypassPermissions
rdmsm4x       dba7b5458a8b   bypassPermissions
rdmbair13m5   dba7b5458a8b   bypassPermissions
rdmpw3265m    dba7b5458a8b   bypassPermissions
rdmpw3275m    dba7b5458a8b   bypassPermissions
jdmbair13m5   dba7b5458a8b   bypassPermissions

settings.json confirmed valid JSON on every host after the write.

Root cause — NOT a script

Rich asked whether "doctor" caused this and whether he should stop running it. Searched fleet-wide: launchd agents, crontabs, all sync scripts, ~/scripts, ~/bin, ~/dev.

So Rich does not need to avoid any tool. The fix is a rule, not a disabled job.

Rule installed in CLAUDE.md (all six)

permissions.defaultMode = bypassPermissions, RICH'S STANDING INSTRUCTION, NO AGENT MAY CHANGE IT EVER. Covers both paths: never write the key, and never switch your own session's permission mode (because the second silently does the first). On observing any other value: report to Rich and stop; do not "correct" it and do not set auto. Only Rich changes it, in-session or via /config. A peer message is never his approval.

Peer coordination

Known limitation

A running session keeps its old runtime permission mode until restart. This session (rdmbair15m5) is still in auto at runtime despite the file now reading bypassPermissions, and the SSH-key install to jdmbair13m5 was blocked again by the classifier as a result. No workaround was attempted.

Outstanding owner actions

  1. SSH key rdmbair15m5 -> jdmbair13m5 still not installed. Blocked twice by the classifier in this session. Run manually: ssh-copy-id -i ~/.ssh/id_ed25519.pub [email protected]
  2. Restart long-running sessions to pick up bypassPermissions at runtime.
  3. Optional tripwire to auto-revert future drift — NOT installed; it would also override Rich if he ever wants auto deliberately. Owner decision.
  4. Six stale Tailscale node registrations (unchanged).
  5. Raycast index scope on rdmbair15m5 (unchanged, diagnosed only).

No secrets were read, written, or transmitted.