rdmsm4x-changelog-20260825-0155-replicantdb-overnight-cloudkit-ios-stability-fixes
Summary: Continuation of the replicantDB session (part 2 of 2 tonight). Landed CloudKit sync, an iOS companion app, three verified stability fixes, real Apple Development code signing, durable logging, and six independent reviews. Quarantined rooDB after harvesting its corpus profile. Changed machine state on rdmsm4x (firewall allow-lists, skills) and fleet state (rooDB daemons).
Session: Claude Code (Fable 5), rdmsm4x. Part 1 changelog:
…20260824-2245…. This part covers 2026-08-24 22:45 →
2026-08-25 01:55 EDT.
Scope
- rdmsm4x — all project work, firewall allow-lists, skill updates, rooDB quarantine.
- Fleet (rdmbair13m5, rdmbair15m5, rdmpw3275m) — rooDB daemon state re-verified paused. Absent on rdmpw3265m, jdmbair13m5. No other host state changed.
What changed
Project —
~/dev/apps/replicantDB (30 commits, tree clean)
- CloudKit sync merged.
CloudSyncKit(transport-neutral engine) +ReplicantDBSync(the synced slice: rules, user overrides, host digests, settings). Saves are compare-and-swap only — the API has no blind-overwrite path, so the documented CloudKit data-loss mistake is unrepresentable. The 750k-row bulk index deliberately does not sync. - iOS companion merged.
ios/xcodegen project, sharedReplicantDBSyncSchemaso both platforms compile one wire format. Bundle ID identical to macOS (preserves universal purchase).xcodebuildfor simulator succeeded with warnings-as-errors; ran on iPhone 17 Pro simulator. - Three stability defects fixed, each with tests:
- Concurrent-pass stampede — the daemon's flag guarded only
start/stop, so a pass outliving its 300 s interval stacked siblings on
one serial DB queue.
PassGateadmits exactly one. - Two copies of the app — enabling the daemon relaunched the app's own
binary via launchd, so app and agent were two writers to one SQLite
file.
SingleInstanceGuard(advisoryflock). - Unbounded memory — the Notes connector retained every note's full body until parsing finished.
- Concurrent-pass stampede — the daemon's flag guarded only
start/stop, so a pass outliving its 300 s interval stacked siblings on
one serial DB queue.
- False cryptography claim removed: the CLI announced BLAKE3 while only SHA-256 is implemented.
- Signing:
build.shnow signs withApple Development: Richard Doty (S65Q255HA8);TeamIdentifier=ZU2882L4HT, flags0x0(none). Designated requirement verified byte-identical across two rebuilds, so TCC grants (incl. Full Disk Access) persist across iteration. - Logging: lifecycle events promoted from
.info(memory-only in OSLog) to.notice. Root cause of the predecessor leaving zero log lines over seven days. - Six reviews + corpus profile under
docs/review/. - Status page published to
~/Desktop/replicantDB-status.htmland~/dataroo.net/wiki/replicantDB/index.html— self-contained, verified free of client names.
Machine state — rdmsm4x
- Application Firewall: allow-listed
dist/replicantDB.app,dist/replicantdb-cli,dist/replicantdb-mcpviasocketfilterfw --add+--unblockapp. Firewall left ENABLED — binaries allow-listed, control not weakened. Undo:socketfilterfw --remove <path>. - Skill
capturing-chat-images→ v2.0.0. Its v1 claim that pasted images "NEVER land on the filesystem" was wrong: Claude Code persists them as base64 in the session transcript. Added~/scripts/extract_chat_images.py(verified: recovered 21 unique images at exact dimensions). Snapshot archived to~/dev/concepts/llm-wiki/_assets/skill-archive/. - New skill
terminal-shell-envv1.0.0 — zsh/alias traps (the eza--iconsgreedy-value bug,nomatchaborting compound commands, U+202F screenshot filenames).
rooDB retirement — quarantined, NOT deleted
Per AUTHORITY.md rule 2.
~/dev/_quarantine/roodb-20260825/ holds
rooDB-full.bundle (git bundle verify: "records
a complete history", 6 refs) and an INGEST-MANIFEST.md.
Retained untouched: the working tree at
57a2416, and the live 750,677-row database
(PRAGMA integrity_check = ok) as a reference corpus.
Verification evidence
swift test→ 230 tests, 0 failures.swift build→ clean, 0 warnings.xcodebuild … 'generic/platform=iOS Simulator'→ BUILD SUCCEEDED (warnings-as-errors).codesign -dv dist/replicantDB.app→TeamIdentifier=ZU2882L4HT, flags0x0(none).- Signature stability: built twice, designated requirement diffed → identical.
- Corpus profile derived read-only (
PRAGMA query_only=ON) from the paused rooDB store. - rooDB daemons re-verified paused/absent on all six hosts; zero
roodbprocesses.
Outstanding owner actions (Rich)
- Add
~/dev/apps/replicantDB/dist/replicantDB.appto Full Disk Access — the pane was opened for him. Only manual step needed for indexing~/Library. - Create the CloudKit container
iCloud.com.eastcoastscience.replicantDBusing Apple ID[email protected], teamZU2882L4HT— steps indocs/CLOUDKIT-PLAN.md§7. Team-permanent, so deliberate. - Icon decision (candidates in
assets/icon-candidates/).
Known-open defects (not regressions from this session)
Two P0s remain and block publication/fleet install: employer client
names compiled into the product (fix delegated, in progress), and a
re-scan that erases classification badges including
USER_OVERRIDE. Full detail in the project's
ISSUES.md.
Not done
Nothing was pushed to any remote. No CloudKit container created. No index cycle run.