Fleet changelogs · dev.ecs0.net
rdmsm4x - reference - claude-code-fleet-baseline-doctor-findings-20260820 - claude - memory-trim - fleet - 20260823-0254

Claude Code fleet baseline & doctor findings — point-in-time report, 2026-08-20

Extracted verbatim from ~/.claude/CLAUDE.md on 2026-08-23 02:54 EDT during a /doctor pass. It was a dated diagnostic report, not operating guidance, and several claims had gone stale: it stated 2.1.237 on five hosts (actual: 2.1.241 on six as of 2026-08-23), "rdmbair15m5 has 22 plugins" (rdmsm4x has 6), and that rdmbair15m5's signing identity exists nowhere — which was corrected on 2026-08-22: rdmsm4x holds the identity and key.

The durable rules from it were kept in CLAUDE.md in condensed form. Full original below.


Claude Code fleet baseline & doctor findings (v1, 08-20-26)

Read this before trusting any host label in this file

This file is generated on ONE host and propagated verbatim to all five Macs. Relative labels ("Local Host", "Report Origin") name the generating host, never the machine you are reading on. Resolve the current host first, always:

scutil --get ComputerName

An earlier fleet copy propagated ### Node: rdmbair13m5 (Local Host) to all five hosts, which reads as a false claim on the other four. Prefer explicit hostnames over relative labels when editing this file.

Install & update channel — installMethod is always null here

All five hosts run Claude Code from a Homebrew cask, never npm and never the native installer. Consequences:

Settings: which keys are fleet-synced and which are per-host

Fleet-synced baseline, identical on all five and verified 2026-08-20: remoteControlAtStartup: true · crossSessionInbound: "accept" · inputNeededNotifEnabled: true · agentPushNotifEnabled: true · model: "opus[1m]" · verbose: true · askUserQuestionTimeout/dialogExpiry: "60s". These take effect at session start; a running session cannot be enrolled retroactively, so ListAgents will not show peers that started before the keys landed.

Per-host by design, never force-synced by a script: theme · editorMode · enabledPlugins · skillOverrides · hooks · statusLine · worktree · permissions.defaultMode.

permissions.defaultMode is bypassPermissions fleet-wide, and that is INTENDED

Confirmed by the owner 2026-08-20. Do not "correct" it to auto, plan, or default.

A live Claude Code session writes its own mode back to ~/.claude/settings.json, so this key cannot be managed by an external script while sessions are running. Claude runs on all five hosts continuously, so any scripted change is re-asserted by the local session within minutes — observed repeatedly on 2026-08-20: a fleet-wide set to auto was reverted to bypassPermissions on all five without any sync job involved. Symptoms that mislead:

Practical rule: read defaultMode as an observation, never as a setting you own. To change it for real, change it in the running session (or restart the session), not in the file. This is why the fleet policy lists it as per-host-by-design and never force-synced.

Extensions are NOT fleet-wide

Only rdmbair15m5 has plugins (22 enabled), an MCP server (rdworkbench, tools deferred), and a populated ~/.claude/skills (11). The other four hosts have zero plugins. Never assume a plugin fault found on one host exists elsewhere.

Plugin hooks can ship without the exec bit — exit 126

A plugin whose hooks.json invokes a wrapper directly needs that wrapper executable. superpowers shipped hooks/run-hook.cmd mode 644, so every session start failed with exit 126 / Permission denied — silently, for weeks. Only the directly-invoked wrapper needs +x; scripts it launches via exec bash "$SCRIPT_DIR/$NAME" do not.

chmod +x ~/.claude/plugins/cache/<marketplace>/<plugin>/<version>/hooks/run-hook.cmd

A plugin update re-extracts and may drop the bit again. Also note /Users/rich is a symlink to /Users/richh, so a /Users/rich/... path in a hook error is not the bug.

Transcripts are plaintext on disk — treat them as a secrets surface

~/.claude/projects/**/*.jsonl stores every tool call verbatim, including commands that embed credentials. A UDM root password was found in cleartext in a transcript on rdmpw3275m (2026-08-20). Per CLAUDE.md §3 secrets never belong in a command line: read them from ~/.secrets/global.env or Keychain at runtime instead. Rotate anything already captured; the transcript is not retroactively sanitized.

Diagnostics that are cheap and worth re-running

Host-specific facts that live nowhere else (migrated from ~/CLAUDE.md, 2026-08-20)

rdmbair15m5 — code signing is broken and unrecoverable locally. security find-identity -v -p codesigning returns 0 valid identities (re-verified 2026-08-20). Team ZU2882L4HT (east coast science, llc) and three com.eastcoastscience.RDWorkbench provisioning profiles are cached and valid to Aug 2027, but no certificate or private key exists on disk and none is backed up — no .p12, no App Store Connect .p8. Simulator work is unaffected; device runs, notarization, and App Store submission are blocked until someone signs in through Xcode. Do not assume a build failure here is a code problem.

xcode-select -p can lie. Read the active developer directory as env -u DEVELOPER_DIR xcode-select -p — a DEVELOPER_DIR in the environment silently overrides what plain xcode-select -p prints, which is how the fleet report got the wrong Xcode recorded on 2026-08-15.