rdmsm4x changelog — RDReceipt resume + cross-project handoff filing
Session: RDReceipt — resume build work
Host: rdmsm4x Span:
2026-08-24 22:04 EDT → 2026-08-26 19:00 EDT (resumed
after a two-day gap) Model: Fable 5 for planning;
downgraded to Opus 5 by Rich at the resume point, per his own
model/spend policy — planning done, execution does not need the top
tier.
What Rich decided
Three things that had been blocking RDReceipt were settled by him this session, not by an agent:
- The project is
RDReceipt, permanently. His personal expense app, not App Store distributed, may carry personal-only features.receiptROObecomes a later fork — productized, personal features stripped, App Store version. The all-capsrdRECEIPTspelling is retired ("these all caps are bugging me now"). He renamed the folder himself; case-insensitive APFS meant every recorded path still resolved and nothing broke. - v1 is a deliberate hybrid — the launchable app
shell from
Apps/ReceiptRooover the tested engine and SQLCipher vault fromPackages/rdRECEIPT. Worth recording precisely: this is the one moveCLAUDE.mdand the consolidation packet said not to make speculatively. He was shown the trade (bundle-with-no-tests vs 505-tests-with-no-bundle) and chose the merge, so the instruction is discharged, not violated. - Push to a private remote — approved explicitly.
Driving goal stated plainly: his expenses, soon. That now orders the whole work plan.
What changed on disk
RDReceipt — the repo is no longer one disk deep
github.com/richhdoty/RDReceipt created private
and pushed at 18:56 EDT. This closes what
ISSUES.md called its highest-severity item: every other
sibling had a remote and this one did not, while also holding
_provenance/ — the only surviving lineage for two
agy repos deleted on 2026-08-23.
Verified after the push rather than assumed:
visibility PRIVATE, 473 files on origin/main,
0 files from data/real-corpus/ (Rich's
actual financial documents, gitignored, stayed local). Before pushing,
tracked content was checked by inspection, not pattern-matching: the
five benchmark receipt images are synthetic (fictional
merchants, 555 numbers, per their README), and the macOS screenshot was
opened and read.
One thing found by opening that screenshot, worth Rich
knowing:
docs/evidence/screenshots/receiptroo-macos.png shows three
ingested filenames from ~/dev/arista/bny/reports — BNY and
Virtu work documents. Filenames only, no figures, no contents, and the
repo is private, so it was pushed as-is. Scrub it before that
repo is ever shared or made public.
A claim this repo was making about itself, corrected
STATUS.md cited "real files ingested, 3 rows in
SQLite with real SHA-256 hashes" as the evidence that ingest works.
Opening the screenshot behind that claim shows the three rows are
work documents, not receipts, with every
merchant / date / amount cell empty.
The pipeline is behaving correctly — the classifier never gates the
parser, and an admitted unknown beats a confident wrong total — but the
evidence proves walk + hash + store and nothing about
parsing. STATUS.md now says exactly that. This is
the same class of defect §10 of the apps baseline exists to catch, found
in this project's own file.
Commits
b44802a— record the decisions, correct the ingest evidence, reorder the Next list around the actual goal.mainpushed to the new remote.CLAUDE.md,STATUS.md,ISSUES.mdall updated;~/dev/PROJECTS.mdrow rewritten.
Verification actually run
swift buildfrom the renamed root →Build complete! (7.29 sec)— the rename did not break path-dependent builds.git worktree repairrun after the folder rename.- Full
swift test(505 tests) launched with the documented cold-start warm-up first; result recorded in the session, not asserted here in advance.
Cross-project contexts filed for handoff
Rich asked that context belonging to other efforts be filed
with those projects so it is picked up automatically on their next run.
The fleet already has the mechanism — ~/dev/todo/items/
with an hourly scanner that relays into each owning project's
ISSUES.md, plus the standing rule that any agent reads
ISSUES.md on session start. Both were used rather than
inventing a channel.
| Project | What was filed |
|---|---|
apps/RTTy |
ISSUES.md created — RTTy was the only
app in the family without one. Its main ref is
masked (loose ce09657 ≠ packed
aad1465), still true 2 days after the off-host alert, and
documented nowhere. Plus the iCloud.net.dataroo.RTTy
container rooted in a drop-list domain. |
apps/logTTY |
Same masked condition (8b54756 ≠ 3d3c908).
It is intentional — SESSION-STATE.md calls it a
preservation checkout — but only prose says so, and
offhost_watch.zsh cannot read prose, so it keeps firing as
a fleet incident. Needs a machine-visible marker. |
apps/scanROO |
It now has a dependent it did not know about:
RDReceipt plans to copy its proven device-signing configuration
verbatim. Also the unexamined capture-layer overlap, and
app.scanroo.ScanRoo still unreconciled after
shipping to both phones. |
apps/rooDB |
Its absorbed receipt classifier has produced 0 of
627,660 purpose rows by its own P0 measurement,
while the app it absorbed from has measured accuracy on real
documents. |
apps/devSORT |
Its named-but-unbuilt perceptual/semantic dedup layer now has a second consumer. devSORT's own worked example of what byte-hashing misses was a re-photographed receipt — that case is now a live requirement. |
apps/rdLLM |
RDLLM-15: RDReceipt is a confirmed consumer of local batch
inference, with the workload, three ranked backends, and the constraint
that any HTTP backend needs a tested localhost-only
allowlist carved into ZeroNetworkTrap. |
sites/dev.dataroo.net |
Two items: the generator publishes no PRD section and no
portfolio-prds.html, which the baseline requires
for every product; and the live page asserts "installed on both
iPhones" as verified-with-evidence while the repo
says never. |
fleet |
The masked-refs item, and the 1Password agentic-autofill
transport failure — four transport_error results,
no prompt ever shown to Rich, which blocks every agent browser sign-in
fleet-wide. |
Four of these were confirmed relayed by the scanner during the
session (status: new → relayed), which is the
mechanism proving itself rather than being taken on trust.
Verified, not assumed
- The shared baseline's CloudKit error is fixed.
~/dev/apps/CLAUDE.md§4 no longer claims hash-as-record-name gives free dedup; it carries a dated CORRECTED block. RDReceipt'sISSUES.mditem is marked RESOLVED because the file was read, not because a prior session said so. - The masked-ref condition still holds on both repos — re-derived from the ref files at 18:52 EDT, not carried forward from the 2026-08-24 alert text.
Left open, deliberately
- Whether receipt contents may leave the machine via the
planned MCP server. Rich asked for an MCP server (route 1) plus
local batch inference (route 2). Route 2 keeps the zero-network
guarantee; route 1 breaks it — any tool result carrying receipt text
enters a cloud model's context, and
ZeroNetworkTrapenforces the opposite at runtime with passing tests. His direction implies yes, but he did not rule on it, so it is recorded as open, with the fork boundary proposed as the clean place for the line. - SAP Concur recon, blocked at the sign-in wall by the 1Password transport failure. Three questions remain — chiefly whether a verified receipt-forwarding email exists, which would give a zero-code integration path. Concur's own extraction is out of scope permanently: Rich rates it "garbage", so RDReceipt's parser does the extraction in every branch.
Next
STATUS.md now carries the ordered plan. First item is
the CSV/XLSX expense export, chosen because it is the
one deliverable that survives every Concur transport outcome and is the
shortest path to expenses being done.