rdmbair15m5-changelog-20260831-1827-fleet-desktop-control-permissions-and-security-repair
Fleet desktop-control permissions and security repair
Audited Codex, Claude, and terminal-app desktop-control permissions across six Macs; removed the only stale RDWorkbench MCP catalog object; verified Codex Computer Use locally; staged a durable permission-request policy; and restored Apple-default taskport authorization rules after a concurrent fleet script broadened them.
Scope
- Hosts:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m,jdmbair13m5. - Local state mutation attempt: removed one stale
rdworkbenchobject from the Codex sidebar MCP catalog. The running Codex desktop app later rewrote that inert zero-tool cache object; the authoritative MCP registration remains absent. - Fleet security mutation: restored
system.privilege.taskport,system.privilege.taskport.debug, andsystem.privilege.taskport.safefrom each host's sealed/System/Library/Security/authorization.plistafter an overlapping script set all three to unconditionalallow. - No TCC database was written, copied, reset, or replaced. No SIP, TCC, firewall, Gatekeeper, or Tailscale control was disabled.
Exact files touched
/Users/richh/.codex/.codex-global-state.jsononrdmbair15m5: removed only the stale sidebar catalog entry whose server name wasrdworkbench./Users/richh/.agent-coordination/checkins/codex-rdmbair15m5-desktop-control-permissions-20260831.json./Users/richh/dev/_handoff/desktop-control-permissions/audit_gui_control_permissions_v1.0.py./Users/richh/dev/_handoff/desktop-control-permissions/FLEET-COMPUTER-USE-PERMISSIONS-POLICY-v1.md./Users/richh/dev/_handoff/desktop-control-permissions/FLEET-DESKTOP-CONTROL-REMEDIATION-20260831.md./Users/richh/dev/_handoff/desktop-control-permissions/request_computer_use_permissions_v1.0.zsh./Users/richh/dev/_handoff/desktop-control-permissions/restore_taskport_authorization_defaults_v1.0.zsh.- Each host received a checksummed taskport before-state/default
backup under
~/.agent-coordination/backups/taskport-authorization-restore-20260831-*.
An overlapping peer created
~/scripts/fleet_tcc_manager.zsh on all six hosts. This
record did not delete or edit that evidence file; no scheduled or
LaunchAgent reference to it was found. A high-priority stop/review
notice was sent to the canonical owner.
Principal commands and actions
- Read-only
codesign,profiles, TCC SQLite, application inventory,sw_vers, and CLI MCP-list probes across all hosts. codex mcp listandclaude mcp listwere checked without printing secret-bearing server detail.- Codex global state was atomically filtered with
jq, re-parsed, and re-queried. - The permission helper compiled against Apple
ApplicationServices/CoreGraphics and ran in silent
--checkmode. - Codex Computer Use used its embedded
@oai/skyruntime to capture Finder state and make a harmless single-click selection. - Each host's taskport rules were restored using
security authorizationdb writewith payloads extracted from that host's sealed Apple system policy; every Apple-defined field was verified.
Verification evidence
- Active RDWorkbench CLI MCP registration: none found on reachable
Codex/Claude CLIs; on
jdmbair13m5neither CLI is installed. The local running Codex desktop session rewrote one inert sidebar catalog object withserver=rdworkbench,tools=[], andpluginId=null. This is a UI cache, not a callable MCP server, and it requires a normal Codex quit/reopen boundary for durable cleanup. - RDWorkbench project/history references were preserved because they are not active MCP servers.
rdmbair15m5Apple Terminal preflight: Accessibilitytrue; Screen Capturetrue; exit0.- Codex Computer Use: Finder screenshot present; accessibility tree
present; selecting the
Tyrell-designfolder returned a fresh(selected)accessibility diff. - Taskport restoration: six of six hosts returned class
user, group_developerfortaskportand.debug;.safereturned classallow; all restore scripts exited0. - Claude Desktop has recorded Accessibility, Screen Recording, and Full Disk Access allows on all six hosts. Remaining gaps are per-host Codex Computer Use and terminal-app identities documented in the remediation matrix.
Backups and undo
- Codex state backup:
/Users/richh/.codex/backups/rdworkbench-mcp-removal-20260831-181149/.codex-global-state.json. Undo only while Codex is not rewriting state: restore that file atomically, then validate JSON. - Taskport before-state backups are under each host's
~/.agent-coordination/backups/taskport-authorization-restore-20260831-*directory withSHA256SUMS. Restoring the broadenedallowrules is not recommended; the backup exists for provenance and emergency rollback only.
Outstanding owner and canonical-lane actions
- Canonical
rdmsm4xowner must integrate the stagedfleet-computer-use-permissionsblock into both iCloud canonicalAGENTS.mdandCLAUDE.md, then run the canonical sync and verify all hosts. - After this live Codex task is safely checkpointed, quit/reopen Codex
and clear/recheck the inert
rdworkbenchsidebar cache. Do not terminate a live session merely to race an Electron state save. - Remaining Screen Recording/Accessibility gaps require the owner to approve the exact signed app in its logged-in Aqua session, followed by a same-app screenshot and harmless-control canary.
- Claude sessions must run their own responsible-app canary; Codex controlling Claude would not prove Claude's TCC identity.
- Remote-host Apple Notes entries for the fleet security restoration
remain pending because SSH is a Background session and cannot send Aqua
AppleEvents. This
rdmbair15m5record is the local durable Notes/file record.
2026-08-31 19:21 EDT future-memory, ticket, and canonical relay addendum
- Rich explicitly requested that the complete result be saved for
future use, tracked by ticket, and relayed to
codex@rdmsm4x. - Added memory-ingestion note:
/Users/richh/.codex/memories/extensions/ad_hoc/notes/20260831-1921-fleet-computer-use-and-rdworkbench-retirement.md. - Confirmed the canonical issueRoo ticket already existed, avoiding a
duplicate:
TASK-20260831-17, high priority, production fleet task. - Appended the verified outcome and remaining gates to the ticket,
then transferred its live claim from
codex@rdmbair15m5/roottocodex@rdmsm4x. Ticket status remainsin-progress; resolution requires canonical policy integration, local Aqua approvals/canaries, remote Notes receipts, and the post-checkpoint Codex sidebar-cache recheck. - Added receiver handoff:
/Users/richh/dev/_handoff/desktop-control-permissions/HANDOFF-TO-CODEX-RDMSM4X-20260831.md. - Relayed eight immutable messages to
codex@rdmsm4x: canonical handoff, policy block, remediation matrix, read-only auditor, Aqua-only request helper, taskport restore tool, full changelog, and RDWorkbench retirement changelog.