rdmsm4x-changelog-20260826-1620-rtty-build44-flows-fleet
Session 2026-08-26 ~15:05–16:20 EDT · rdmsm4x
RTTy 0.3.822 build 44 deployed to 5 of 6 fleet Macs, carrying working per-application flow visibility with per-endpoint attribution, plus the Mac App Store content-filter foundation and a repaired Standard target.
The defect this release exists to fix
Build 42's application-flows band was dead on every fleet
host. The shipping runner passed
-J bytes_in,bytes_out, which makes nettop emit a four-field
row with counters at indices 2/3, but NettopCSVParser
required six fields and read 4/5. Every live sample failed to parse, so
the band read "Collecting application flows…" forever — while every unit
test stayed green, because the fixtures were captured from the wide
-x layout the runner never used.
Fixed by making the parser layout-aware, and closed for good by the
test that could actually have caught it: an opt-in live integration test
(RTTY_LIVE_NETWORK_TESTS=1) that runs the real shipping
runner against real nettop and asserts the output parses. Unit fixtures
cannot catch a flag change that alters column layout; only exercising
the two together can.
New functionality
- Per-endpoint attribution. Each process row expands
to the remote endpoints it is talking to — protocol, remote
address:port, rates, totals. Dropping
-Pmakes nettop nest connection rows under their owning process, so both views come from the SAME sample: no extra invocation, no added CPU, no entitlement. - Two parser defects found and fixed, both the same shape: a
connection descriptor can satisfy the process-identity rule (IPv6 ports
are dot-separated; so are IPv4 addresses in unsupported-protocol rows).
Reading either as a process does not merely drop that row — it REPLACES
the owning process, so every row beneath it is attributed to a phantom
app. Any row containing
<->is now disqualified from being read as a process.
Fleet state
| Host | Build | Flows verified |
|---|---|---|
| rdmsm4x | 44 | 66 processes · 141 endpoints (screenshot) |
| rdmbair13m5 | 44 | 40 processes · 162 endpoints |
| rdmbair15m5 | 44 | 44 processes · 127 endpoints |
| rdmpw3275m | 44 | 46 processes · 130 endpoints (macOS 26.7, Intel) |
| jdmbair13m5 | 44 | 28 processes · 79 endpoints |
| rdmpw3265m | 42 — NOT deployed | host unreachable at 16:11 EDT |
Verified per host by running the exact shipping nettop invocation and parsing it the way the app does. Every host — both macOS 27.0 and the Intel 26.7 machine — emits the same narrow layout, so the fix holds fleet-wide across two OS versions.
Rollback: each host keeps
/Applications/RTTy.app.backup-build42-20260826T2014*.
Restore = quit RTTy, sudo mv the backup back, relaunch.
App Store (Standard) channel — foundation only, not shipped
- Packaging correction. BUILD-43-PLAN W3 and the
flow-visibility research both specified a system extension with
content-filter-provider-systemextension. That is the Developer ID form; the App Store uses the unsuffixedcontent-filter-providerpackaged as an.appex. Built as specified it would have failed submission with "Unsatisfied entitlements". Corrected in both documents. Appex packaging also avoids the macOS 26.3sysextdactivation bug the research called its biggest operational risk. - Standard had not compiled since 2026-08-24 (ISSUES
RTTY-B44-001). Five files were reachable from Standard sources but
missing from
project.yml.qa_release.shbuilds Direct only, so every gate was green while the App Store product could not build. Repaired; boundary now asserted instandard_project_test.sh, andstringsfinds zeronettopin the Standard binary or the appex. - Identity: Standard →
com.eastcoastscience.RTTy. Direct deliberately keepsnet.dataroo.RTTy, so the fleet needed no TCC or Keychain re-grant.
Evidence
- Tests 750 passed / 0 failed / 5 skipped (opt-in live), up from 723. Both live nettop tests run explicitly and pass.
- Direct: universal (x86_64 + arm64), team ZU2882L4HT,
gitDirty: false, commit5739b77. - Standard:
BUILD SUCCEEDEDwith the appex embedded atContents/PlugIns/RTTyNetworkFilter.appex. - Archive sha256
268626516200fa5f…, executable sha256e36368e2ac58bec5….
Outstanding
- rdmpw3265m needs build 44 when it comes back up.
- Blocked on Rich: App IDs
com.eastcoastscience.RTTyand.NetworkFilterwith the Network Extensions capability, App Groupgroup.com.eastcoastscience.RTTy, and profiles for both. Nothing filter-related can be signed or run until these exist. - Standard host UI (flows band fed by the filter, per-app block
toggle) and
NEFilterManageractivation are not written. - Accessibility TCC grant on rdmsm4x still gates qa gates 5–7.