Fleet update, GitHub consolidation, domain refresh — rdmsm4x
Session: 2026-08-23 01:18 → 02:03 EDT · host
rdmsm4x (master agent host) · agent claude One
line: Updated Claude Code fleet-wide, fixed a dead binary on
jdmbair13m5, put every ~/dev/agy and
~/dev/apps project into a private GitHub repo, preserved
both LogTTY histories without merging, and refreshed the domain
portfolio.
Scope
All six hosts: rdmsm4x, rdmbair13m5, rdmbair15m5, rdmpw3265m, rdmpw3275m, jdmbair13m5.
1. claude-code@latest → 2.1.241 (all six)
Before: 2.1.240 on rdmsm4x/rdmbair13m5/rdmbair15m5/jdmbair13m5,
2.1.238 on the two Intel hosts. Command:
brew update && brew upgrade --cask claude-code@latest --greedy
per host. Verified with claude --version on each
afterwards.
REGRESSION FOUND AND FIXED — jdmbair13m5. The
upgraded cask binary was written mode 644:
/opt/homebrew/Caskroom/claude-code@latest/2.1.241/claude →
zsh: permission denied (exit 126) for any new launch.
Running processes survived because they held the old inode, so this
would have surfaced only on the next start. Fix: chmod +x
on that path; now reports 2.1.241. Same signature as the
superpowers hook bug already in CLAUDE.md.
Recommend adding a post-upgrade exec-bit assertion to
dev_update.zsh. Undo:
brew uninstall --cask claude-code@latest && brew install --cask claude-code@latest.
2. Agent bus
jdmbair13m5 held 45 mail files vs 47 elsewhere. Ran
agent_msg.zsh sync; all six then at 51, and 52 after a
broadcast. Proved delivery with a send→sync→verify round-trip on all
six. Note: sync reported "rdmbair15m5 unreachable" while
that host's count was correct — the host is saturated (peer reported
load 310), not down. A failed poll is not a down host.
3. GitHub consolidation — 51 new private repos
Per Rich: every project dir gets its own private repo.
~/dev/agy/*→ 35 repos,rdmsm4x-agy-<name>~/dev/apps/*→ 28 repos pushed (14 reused existing remotes),rdmsm4x-apps-<name>- Totals now: 196 repos, all PRIVATE, zero unpushed
commits, and no
.env/.p12/.p8/id_rsatracked in any repo (verified withgit ls-files). - A shared
.gitignoreexcludes.build/,venv/,node_modules/,DerivedData/,__pycache__/,*.p12/.pem/.p8,id_rsa*,.env*. Applied before the first commit, andgit rm -r --cached .run so nothing previously tracked stayed tracked. - Commit identity forced to
[email protected]; the account rejects pushes carrying the private gmail address.
DataRoo: remote had diverged (remote 4 commits /
local 2). NOT force-pushed. Local work went to branch
rdmsm4x-consolidation-20260823. Needs a human
reconcile.
4. LogTTY — preserved, NOT merged
Independently verified the ref-shadowing reported by
claude@rdmbair15m5: loose .git/refs/heads/main = 3d3c908 (1
commit) shadows packed-refs main = f2c385c (80 commits); roots 3d3c908
vs 2cac42f are disjoint; 63 local refs; no remote configured. Excluded
LogTTY from the bulk sync because of this — the script would have
published the masked 1-commit state.
- Bundle taken first:
~/dev/_backups/LogTTY-rdmsm4x-allrefs-20260823-0155.bundle(154 MB,git bundle verify= complete history). - Pushed missing branch NAME
work/live-feed-ui(commit already on remote). - Second history preserved as its own repo
richhdoty/rdmsm4x-apps-logtty-build18. 3d3c908 itself was rejected for email privacy, so a re-authored commit80a5420dover the byte-identical tree (5f25b6fb, 3,821 files) was pushed instead; the original object survives in the bundle. - Local checkout left EXACTLY as found: loose main 3d3c908, packed main f2c385c, 61 untracked build files. No merge, no reset, no force, no unmasking.
5. Domain portfolio refreshed
zsh ~/dev/lib/domains/refresh_domains.zsh → 439 domains,
359 Cloudflare zones. 372 ACTIVE; 61 renewals inside 90 days, 22
within 5 days; zero active domains have auto-renew off. No
adds, removals or status changes vs the 2026-08-22 21:36 pull. Backup:
~/dev/lib/domains/domains.json.bak-20260823-0128.
6. Credentials
- Captured the exposed ToshLLM llama-server API key (found in argv on
rdmpw3275m, bound 0.0.0.0:11435) into
~/.secrets/global.envas TOSHLLM_API_KEY. Value never printed, never passed on a command line. Backup of the prior file alongside it. - Wrote a reusable helper
~/scripts/save_credential.zsh(reads the value from stdin only). - iCloud Keychain sync NOT achieved.
SecItemAddwithkSecAttrSynchronizablereturns OSStatus -34018 (errSecMissingEntitlement) from an unsigned CLI tool. Needs a signed helper with the keychain-sharing entitlement; rdmsm4x is the only host with a signing identity. - Apple Notes master credentials table NOT rebuilt —
the permission classifier blocked the script that aggregates all
credential values into one document. Left for Rich to authorise. The
existing note was backed up first to
~/.secrets/notes-backups/(mode 600).
7. Correction issued to the fleet
The broadcast verdict "4 of 5 agy projects have no source" is
wrong fleet-wide. The source is on rdmsm4x; the auditor
measured rdmbair15m5's empty copies. Measured here: bookmarkscope
35/106, passwordscope 70/74, sqlitescope 46/88, eostty 67/134,
darwinsysctl 21/34, rdreceipt 39/122 (Sources/Tests .swift counts).
Reproduced: cd ~/dev/agy/sqlitescope && swift test
→ 185 tests in 19 suites passed. Lesson recorded on the
bus: reproduce steps must name the HOST.
Outstanding owner actions
- Rotate TOSHLLM_API_KEY and rebind llama-server off 0.0.0.0 — it is LAN and tailnet reachable.
- agy sessions on rdmsm4x (ttys002, ttys003) could not be
resumed. This session is
launchctl managername = Backgroundover SSH with no tty and cannot send AppleEvents to Terminal.app. Needs a GUI session on rdmsm4x. - Decide the LogTTY merge
(
consolidate/live-stream-20260823→ main). - Reconcile DataRoo's diverged branch.
- Authorise (or decline) the Apple Notes credential table rebuild.
- Nothing on
~/dev/agyhad ANY git history before tonight — now all 35 are backed up remotely.
No secrets in this record
Key NAMES and LOCATIONS only. No values in this file, in Notes, or in any commit.