rdmsm4x-changelog-20260824-1510 — fleet bare-hostname LAN resolution, DHCP reservations, private-MAC fix, UDM work
[2026-08-24 ~14:55–15:10 EDT · rdmsm4x · claude@rdmsm4x session
dev-ab] Scope: all six fleet Macs +
the UDM Beast (192.168.1.1). Requested by Rich in-session. Apple
Notes copy: PENDING — notes_changelog.zsh is failing fleet-wide
(600s ceiling vs 7.8GB store, open issue E2). This file is the durable
record until that ships.
Summary
ping <bare hostname> now resolves to the
192.168.0.0/23 LAN address on every fleet Mac; the duplicate-IP client
mess was root-caused to macOS Private Wi-Fi Address rotation and fixed
at both ends (Mac-side setting + UDM reservations for hardware MACs).
Private Relay complaints are NOT caused by the UDM (verified: no
ad-block config, ssl_inspection off) — almost certainly the eero on
starlink18a.
Changes
- /etc/hosts on ALL SIX hosts — appended managed
block
# BEGIN/END fleet-lan-hosts 20260824: rdmsm4x 192.168.0.29 · rdmbair13m5 192.168.1.177 · rdmbair15m5 192.168.1.170 · rdmpw3265m 192.168.1.53 · rdmpw3275m 192.168.1.65 · jdmbair13m5 192.168.1.159. Backup per host:/etc/hosts.bak-fleetlan-20260824. Undo: restore backup or delete the block. - Private Wi-Fi Address → off for SSIDs
18aandstarlink18aon rdmsm4x, rdmbair13m5, rdmbair15m5 (jdmbair13m5 already off since 08-23; Intel towers' Wi-Fi lives on the eero). Edited/Library/Preferences/com.apple.wifi.known-networks.plist(backup.bak-20260824alongside). Trap discovered: a plainpkill airportdlets airportd flush stale cache over the edit — rdmsm4x reverted once; re-applied inside apkill -9sandwich, verified persisted. Takes effect at next Wi-Fi join/reboot: interfaces will present HARDWARE MACs. - UDM: 6 DHCP fixed-IP reservations written via mongo
(port 27117, db ace, db.user use_fixedip/fixed_ip/network_id=default
68a0ea9484190d535116a0e5), matching the table in (1) — wired MACs for
the three wired hosts, hardware Wi-Fi MACs for the three Airs. All 6
verified persisted post-restart (
systemctl restart unifiran, ~70s). Backup of the six pre-change client docs: UDM/root/udm-fixedip-backup-20260824.log+ scratchpad copy. Undo: unset use_fixedip/fixed_ip on those docs, restart unifi. - No UDM change for hostname resolution was needed — its dnsmasq already resolves bare names; the fix was client-side (/etc/hosts beats the tailnet search-domain race).
Root causes found
- Duplicate IPs = Private Wi-Fi Address rotation: rdmsm4x had appeared as 5 client identities, rdmbair15m5 as 4, rdmbair13m5 as 2 (current ones hostname "Mac"); plus historical wired-and-wifi-both-on-18a joins on all three wired hosts.
- Bare names were resolving to 100.x TAILNET IPs of STALE dead nodes (e.g. rdmsm4x → 100.97.225.81) via MagicDNS search domain — worse than not resolving.
- Private Relay: UDM exonerated (no ad-block lists anywhere in db.setting; ssl_inspection state "off"; doh=own-upstream only; IPS lists are threat categories, no ad/tracking lists). Remaining suspect: eero Secure ad-blocking on starlink18a (out of SSH reach — eero app fix).
Notes / follow-ups
- Legacy reservation spotted: 88:66:5a:19:b6:ba (rdmpw3265m Wi-Fi) → 192.168.1.109 for the 18a SSID — dormant while that radio sits on starlink18a; harmless; left in place.
- Old rotating-MAC client entries remain in UniFi as UI clutter; safe one-off cleanup, offered to Rich, NOT executed.
- ROTATE the UDM root/SSH password — supplied in chat this session AND echoed back inside the mgmt settings doc (with an API token) into the transcript. Stored meanwhile at ~/.secrets/udm.env (600). After rotation update that file and Settings→System→Advanced SSH.
- Verification: wired hosts sit on their reserved IPs now; the Airs prove theirs at next reboot (hardware MAC + reservation + matching /etc/hosts pin). Independent subagent verification report: ~/dev/fleet/_review/network/VERIFICATION-fleet-lan-dhcp-20260824.md
Addendum 15:35 EDT — gateway-wide DHCP/DNS review (Rich's request) + verification results
Reviewed all 187 known clients on the UDM (both
LANs). Base was healthy: 66 reservations, ZERO duplicate-IP conflicts,
gateway DNS resolving reserved+leased hostnames bare and as
<host>.dataroo.net (both LANs carry
domain_name=dataroo.net). static_dns collection empty
(unused).
7 new reservations added (at current IPs, zero
disruption; backup appended to UDM
/root/udm-fixedip-backup-20260824.log; total now 73): HP
printer #2 .1.14 · unaspro818a ports
.1.5/.1.2 · rdpi5b eth .1.21 +
wlan .1.22 · Philips Hue Bridge
.0.198 · iAquaLink pool .1.220.
Controller restarted again; DNS re-verified after.
Cloudflare ruling recorded:
<host>.ts.dataroo.net records already exist in the
dataroo.net zone (verified against live nodes); LAN
<host>.dataroo.net records exist for the six Macs;
printers/IoT stay UDM-only (public LAN records add nothing without a
subnet router); NO 18a.dataroo.net sub-zone (would compete
with the UDM's flat scheme).
Independent verification (sonnet subagent, 25
checks):
fleet/_review/network/VERIFICATION-fleet-lan-dhcp-20260824.md.
Highlights: reservations propagated into 4 provisioned UDM config files;
jdmbair13m5 already reconnected on hardware MAC holding its
reserved IP (live proof of the whole chain). Two fails, both
now dispositioned:
- rdmpw3275m resolved bare names to STALE tailnet IPs even via
getaddrinfo with a correct hosts file — mDNSResponder wedged;
killall -HUPinsufficient,killall -9fixed it (verified all names → LAN after). Trap recorded. - rdmsm4x plist edit for Private Wi-Fi Address reverts within ~45 s even with SIGKILL sandwich (airportd re-syncs from a canonical store elsewhere on macOS 27 when Wi-Fi is active) — the two Airs' edits verified durable, this one host needs the Settings UI (30 s, Rich).
Judgment calls made (NOT reserved, deliberately): HomePods/Apple TVs (~15, DHCP is fine), Miele appliance, Withings sensor, laptops (rdx1g9l, L-6DFVSW3), towers' 2nd NICs (.0.65/.0.253 — replug = duplicate risk, Rich's call), eero devices (not UDM clients), WAN-side gear. Rotating private-MAC ghost entries (~20, incl. seven at .1.177) left to age out. Needs naming by Rich (reserved, DNS-invisible, unknown purpose): .0.220 Google · .1.24 LG (253d stale — prune?) · .1.110 Moxa · .1.162/.1.163 Microchip · .1.204-206 ARRIS ×3 (33d stale — prune?) · .1.242 APC UPS. Oddity: null-MAC ghost client doc ("Officially Xerox" OUI) at .1.110.