Fleet changelogs · dev.ecs0.net
rdmpw3275m-changelog-20260924-0210-xentropy-030-shipped-fleet-and-consolidation-prd

rdmpw3275m - changelog - XEntropy 0.3.0 shipped to six Macs plus consolidation PRD and audit tool - claude - FEAT-20260924-01 - Xentropy - 20260924-0210

Session: 2026-09-24 01:10:59 EDT to 2026-09-24 02:10 EDT (continuation of the 2026-09-23 14:41–17:50 session) Ran on: rdmpw3275m · Changed state on: all six Macs (XEntropy install), rdmsm4x (canonical repo, PROJECTS.md, project-docs JSON, dev.ecs0.net wiki, tickets), rdmpw3275m (audit outputs, discovery index)

XEntropy 0.3.0 (3) is installed, hash-verified and running on all six Macs. The blocker was the installer's codesign resolving to a locked duplicate identity over SSH; fixed by pinning the keychain. A consolidation/passkey-audit PRD (95 sources), six mock UI flows, a PRD index and a working owner audit script are merged on the fleet branch, and two pages are published for Rich.

Scope

Files created

Path What
apps/Xentropy/scripts/credential_audit.py, credential_audit.zsh, scripts/tests/test_credential_audit.py Owner credential/passkey audit tool, 23 tests
apps/Xentropy/docs/product/PRD-credential-consolidation-and-passkey-audit.md New PRD, 95 sources fetched 2026-09-24, UNVERIFIED list in §10
apps/Xentropy/docs/design/consolidation-flows.html Six mock screens, synthetic data
apps/Xentropy/docs/product/PRD-INDEX.md Every PRD with status and built-vs-pending
~/dev/data/project-docs/screenshots/Xentropy-observatory-030-20260924-0130.png (rdmsm4x) Observatory capture, values hidden
~/Library/Application Support/XEntropy/Audit/{credential-audit.sqlite3,credential-audit-report.html,credential-audit.csv} (rdmpw3275m, 0600) Values-free audit outputs
~/.claude/projects/-Users-richh-dev/memory/codesign-over-ssh-pin-keychain.md Memory: the codesign root cause
Published pages Ship status https://claude.ai/artifact/6TFBo9epkwX2a4SQVoVovB · Mock flows https://claude.ai/artifact/KjVRPhcqZGPv3e4a4ANKzj (private to Rich)

Files modified

Commands run

zsh scripts/install_xentropy_local_instance_v1.0.zsh --host rdmsm4x            # then the other five; jdmbair13m5 on retry
zsh scripts/verify_xentropy_fleet_canary_v1.0.zsh --all                        # two runs
~/.local/bin/xentropyctl discovery scan                                        # rdmpw3275m, 227 s
uv run --with pytest --with cryptography pytest -q scripts/tests               # 23 passed
python3 scripts/credential_audit.py scan --json ; audit --json                 # counts only
git merge --no-ff claude/xentropy-credential-audit-script ; claude/xentropy-consolidation-prd ; origin/main

Verification performed

How to undo

# Per host: the installer's rollback record (manifest-restorable)
ls ~/Library/Application\ Support/XEntropy/DeploymentRollback/     # pick the 20260924-* entry and follow docs/runbooks/xentropy-vnext-deployment-recovery.md
# rdmsm4x stale bundles: rename back
for d in $(find ~/dev -maxdepth 6 -name 'XEntropy.app-retired-20260924'); do mv "$d" "${d%-retired-20260924}"; done
# Docs: git revert 21b4f36 / a309b13 on the branch

Secrets