rdmbair15m5-changelog-20260830-1515-global-app-capability-standard
rdmbair15m5-changelog-20260830-1515-global-app-capability-standard
Defined and broadcast a production global app-capability standard,
prepared a tested isolated ecs0lib patch, and preserved
live canonical app repositories while giving every fleet host the same
adoption packet.
Scope
- Work host:
rdmbair15m5. - Canonical review/integration target:
rdmsm4x:/Users/richh/dev/lib/ecs0lib. - Knowledge notification targets: all agents/providers on all six fleet hosts.
- Source base inspected read-only: canonical
ecs0libcommite0ff5101dce072a50cf18f9b107ed37611207ca2. - No canonical app/library checkout, installed app, signing identity, entitlement, launch item, permission database, or fleet configuration was modified.
Local files changed
/Users/richh/Documents/Codex/2026-08-30/all-apps-going-forward-should-have/work/ecs0lib-global-app-capabilities/โ isolated clone and branchcodex/global-app-capabilities-20260830, commit1cf7301444450fa5655cc9fb9984fb6c7be80f18./Users/richh/Documents/Codex/2026-08-30/all-apps-going-forward-should-have/outputs/GLOBAL-APP-CAPABILITY-STANDARD-v1.md./Users/richh/Documents/Codex/2026-08-30/all-apps-going-forward-should-have/outputs/APP-ADOPTION-MATRIX-2026-08-30.md./Users/richh/Documents/Codex/2026-08-30/all-apps-going-forward-should-have/outputs/IMPLEMENTATION-RECEIPT-2026-08-30.md./Users/richh/Documents/Codex/2026-08-30/all-apps-going-forward-should-have/outputs/0001-Add-shared-global-app-capability-settings.patch./Users/richh/.agent-coordination/checkins/codex-rdmbair15m5-global-app-capabilities-20260830.json.- Fleet mail messages
20260830-151510-247FBD1A,20260830-151510-2661398B,20260830-151510-F206B5E4, and20260830-151510-B29F7F18.
Implementation summary
- Added a composable
ECS0AppSettingsproduct. - Added persistent runtime Dock-icon choice with default restoration and truthful temporary-Dock semantics.
- Added launch-at-login state/control using
SMAppService.mainApp. - Added notification authorization, setup, state refresh, and a test notification.
- Added menu-bar preference models.
- Replaced fabricated Local Network authorization and weak Full Disk
Access inference with explicit
unqueryablestate and evidence quality. - Added direct Accessibility, screen capture, and Location checks plus a guarded Location request lifecycle.
- Added a data-driven terminal color-profile catalog with
~/libthen~/dev/liblookup. - Corrected the shared Liquid Glass modifier so it does not cover glass with an opaque decorative fill and honors Reduce Transparency.
- Added a production adoption standard, capability gating, diagnostics/privacy/accessibility recommendations, and a 24-app adoption matrix.
Commands and verification
- Resolved host with
scutil --get ComputerName:rdmbair15m5. - Read fleet policy, project index, Liquid Glass/SwiftUI skills, peer mail, canonical library source, color-profile manifest, and app inventory.
- Contacted
agy@rdmbair15m5through the fleet bus for live owner/state evidence. - Baseline
swift test --sanitize=threadreproduced 113/113 passing after moving disposable build output outside File Provider metadata interference. - Final
swift test --sanitize=thread --scratch-path /tmp/ecs0lib-global-capabilities-tsan.lDguMv: 119 tests, 0 failures, no reported data races. - Final
swift build -c release --scratch-path /tmp/ecs0lib-global-capabilities-release.iuFxhz: passed. git diff --check: passed before commit.- Patch SHA-256:
34cca777f41adb30bbbcd940e6808ab2e5b364353d52e4855695153a88bddaaf. - Fleet broadcast message reached all six hosts with identical SHA-256
7c36db4f98984858f42ad53e6eb2710d7d2138b5efe375798d0487e5d144de4f.
Backups and undo
- The source of truth was not mutated; the isolated clone is the rollback boundary.
- To discard the reference implementation, delete or archive only the
isolated workspace directory after preserving this receipt. Do not touch
canonical
rdmsm4xsource. - Canonical integration should apply
0001-Add-shared-global-app-capability-settings.patchin a new isolated worktree from the verified base, review it, run complete tests, and revert the resulting integration commit if rejected. - Do not perform a bare
git push; current fleet guidance requires explicit remote/branch verification.
Outstanding owner actions
agy@rdmbair15m5has not yet replied to the live status request; its existing Tyrell/replicantDB icon directives were incorporated as peer evidence, not treated as completed implementation.claude@rdmsm4xor the assigned canonical owner must accept/review the patch in an isolated worktree and preserve the canonical checkout's unrelated dirty web/docs files.- The canonical fleet knowledge owner must integrate the standard into the managed source, run supported propagation, and verify Claude/Codex/agy context hashes on all six hosts.
- App owners must adopt in waves, beginning with current
ecs0libconsumers and reference implementations, and independently validate signed.appSettings, entitlements, permissions, icons, menu bar, accessibility, and rollback. - No app adoption, canary, or fleet rollout is claimed by this record.
No secrets, credentials, signed URLs, or provider authentication state are included.