rdmsm4x - fix - collector Keychain reads round two - codex - TASK2026092763 - rdmodelrouter - 20260927 1629
Round 2 fixes
2026-09-27 16:23:55 EDT → 2026-09-27 16:29:33 EDT · rdmsm4x. Builder codex@rdmsm4x/rmrcollectors2; TASK-20260927-63 reopened and claimed for this repair. Starting HEAD 5179dff4a222ece55491786df0acd49ae82da655, clean branch rmr/own-collectors-20260927. Both Required fixes in VERIFY-2.md are implemented and live-verified. Commit only; no merge/push.
Changes
- Replaced UsageCredentials' SecItemCopyMatching query with the
existing UsageCommandRunner:
security find-generic-password -s <service> [-a <account>] -w. Claude uses serviceClaude Code-credentials; OpenRouter uses servicerdmodelrouter, accountOPENROUTER_API_KEY. - Pipe-only stdout, discarded stderr, null stdin, a five-second security-process timeout and discarded output on failure. Other official usage commands retain their 40-second bound.
- Claude prefers a valid Keychain entry and falls back to its saved file on missing, malformed, empty or expired Keychain data. Expired file data still fails. Source labels distinguish both.
- No credential refresh or write, cookies, proxy, listener, paid inference or default-policy change.
- Private-PATH fake-security tests check exact argument boundaries including the spaced service, stdout pipe, stderr exclusion, Keychain priority, read-only fallback, expired-file rejection, missing/empty/failed OpenRouter reads and timeout rejection of partial stdout.
Validation
| Check | Result | Evidence in this handoff folder |
|---|---|---|
| Default swift test | 114 tests / 15 suites / 0 failures; rc 0 | tests-round2-final.log |
| RMR_DISABLE_QUOTA_KIT=1 | 114 / 15 / 0; rc 0 | tests-noquota-round2.log |
| Universal app and CLI rebuild | rc 0; x86_64 + arm64, Intel minos 26.7; plist OK | build-status-app-round2.log |
| Fresh release CLI, Tyrell hidden | rc 0; 3.02 seconds | live-round2.log, quota-no-tyrell-round2.json |
| Credential preservation | 5 files identical SHA-256/mtime/size; both Keychain mdat unchanged | credential-state-round2-before.json / after.json |
| Secret scan including native Keychain values | 44 values only in memory; 138 files, 445 reachable objects; 0 findings; both controls passed | secret-scan-native-round2.log |
| Broader env/bundle/transcript scan | 66 values only in memory; 142 files, 274 reachable blobs, 1 transcript; 0 findings; controls passed | secret-scan-round2.log |
| Whitespace | git diff --check rc 0 | branch diff |
Live observation 16:28:53 EDT, with RDMODELROUTER_USAGE pointing to empty-tyrell-round2/usage.json. The sanitized usage cache was preserved as usage-cache-before-confirmed-round2.json and moved out of the cache location before the run, proving a fresh collection rather than cached fallback.
| Provider/account | Own-reader result |
|---|---|
| Claude | 5h 7%; 7d 51%; direct Keychain, fresh |
| OpenRouter key | USD 0.000004571 used / USD 100 limit; direct Keychain, fresh |
| OpenRouter credits | USD 0.000004571 used / USD 50 total credits; direct Keychain, fresh |
| Codex iCloud | 7d 63%; pro; official app-server |
| Codex Gmail | Not signed in; local home absent |
| agy | Gemini 7d 35.16%, 5h 25.26%; third-party 7d 20.29%, 5h 0% |
| Copilot | 0.20%, 34 / 20000 billing units; individual_max |
| Hermes | Plus, 32 credits remaining; UI balance-display advisory remains |
| Grok Build | Explicitly unmeasured: vendor creditUsagePercent absent |
| Grok Bot | Explicitly unmeasured: no verified weekly export |
All Claude/OpenRouter rows say own reader and direct Keychain (XEntropy binary missing); no Tyrell fallback supplied these measurements. XEntropy ordering remains unchanged.
First live attempt: the CLI also produced correct own-reader numbers, but the preservation assertion failed because ~/.hermes/auth.json changed SHA-256 and mtime during the wider interval that included waiting on SwiftPM. The writer was not identified; this is not claimed as an unchanged interval. The four other files and both Keychain entries were unchanged. All first-run evidence is preserved with -first suffixes. The immediate fresh release run above passed all seven preservation checks. The Hermes reader still only reads its file and performs a GET; no refresh/write was added.
Screenshot app-window-build.png (1320 x 1480) captured and visually inspected from rebuilt development app PID 55902, window 4459. Claude displays 51% Fresh with the own-reader Keychain source; the app still says Degraded for the existing missing/unmeasured accounts. OpenRouter lies below this viewport; its two own-reader rows are proved by the CLI JSON. The exact development process was terminated. No installed app was replaced, no login item was registered, and no signing/deployment occurred.
Files changed: UsageCredentials.swift, UsageTransport.swift, IndependentUsageTests.swift, docs/USAGE-CONTRACT.md, SESSION-STATE.md, ISSUES.md and this BUILD-RESULT.md. Preflight reported historical HIGH mail; the no-outbound task scope was retained. Parent claims were preserved. No workers or cross-account changes. Remaining VERIFY-2 advisories are outside Required fixes: Hermes presentation, absent Grok field, absent XEntropy binary.
Apple Notes PENDING: Background session; fleet-notes-publish requires durable file copies rather than a GUI workaround. Copies in ~/dev/LLM/Claude/changelogs and ~/dev/LLM/Codex/changelogs. Resume: independently verify this committed Round 2 repair; lead owns merge/push/integration. Undo by reverting the repair commit; credential stores and installed artifacts were not modified.
Round 2 final commit receipt — 2026-09-27 16:31:47 EDT · rdmsm4x
Committed a32a5df7e3f731087d0406441d150052fd21c106 on rmr/own-collectors-20260927. Seven explicit files, Agent trailer present, worktree clean. No merge or push. Postcommit scans: 66 known values / 145 files / 281 reachable blobs / current transcript, and native-Keychain-inclusive 44 known values / 145 files / 460 reachable objects: zero findings, exact and pattern positive controls passed. Changelog copies included. Apple Notes helper refused Background (no Aqua); file copies retained, Notes pending. TASK-20260927-63 builder repair complete; independent re-verification/integration remains with lead.