rdmsm4x-changelog-20260828-2111-xentropy-lifecycle-fleet
rdmsm4x XEntropy lifecycle, local runtime, and fleet skill rollout
Merged the reviewed XEntropy API Key Table and credential-lifecycle
work into canonical local main without discarding
concurrent documentation, installed and verified one local metadata-only
runtime, retained rollback evidence, and distributed the values-free
Codex usage skill to every currently reachable remote fleet Mac. This
matters because agents now have a reviewed request workflow while
credential values and real provider mutations remain outside unattended
agent surfaces.
Scope and lifecycle truth
- Canonical source/signing host:
rdmsm4x. - Source checkpoint: local
mainatc2ac06aafter merge9d818fd, preserved-documentation commita564815, and lifecycle-state commit28b0b06. - Remote repository: unchanged; local
mainis ahead and no push occurred. - Local runtime: signed app running from
~/Applications/XEntropy.app; metadata catalog and lifecycle stores healthy;local-cliKeychain pairing and any loopback listener remain disabled/pending. - Remote app/CLI installs: previously completed on all five remote Macs with foreground first launch and Keychain bootstrap still pending.
- Codex skill: validated locally and installed with exact hashes on
rdmbair15m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5; adoption requests were dispatched but are not acknowledgements.rdmbair13m5is offline and its skill install is held. - Claude skill: authoring request and follow-up were sent to
claude@rdmsm4x; no completion or adoption claim is made without its reply. - No live secret source was scanned, no secret value was printed or stored, no provider was contacted, and no credential was validated, created, rotated, revoked, copied, or revealed.
Files and local state changed
- Repository documentation:
/Users/richh/dev/apps/Xentropy/STATUS.md,ISSUES.md,SESSION-STATE.md, andCHANGELOG.md. - Canonical project index:
/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md. - Fleet writer check-in:
/Users/richh/.agent-coordination/checkins/codex-xentropy-lifecycle-20260828.json. - Local app and CLI:
/Users/richh/Applications/XEntropy.appand/Users/richh/.local/bin/xentropyctl. - Local app-owned stores:
/Users/richh/Library/Application Support/XEntropy/Catalog/credential-metadata-v1.sqlite3and/Users/richh/Library/Application Support/XEntropy/Lifecycle/credential-lifecycle-v1.sqlite3. - Local Codex skill:
/Users/richh/.codex/skills/xentropy-local/SKILL.mdand/Users/richh/.codex/skills/xentropy-local/agents/openai.yaml. - The same two skill files were installed under each reachable remote
host's
~/.codex/skills/xentropy-local/directory. - Remote Markdown records were installed under each reachable host's
~/dev/LLM/Claude/changelogs/; Apple Notes publication is pending their foreground sessions. - Recovery manifest:
/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/MANIFEST.md.
Commands and verification
- Revalidated repository identity, branch, dirty state, and retained stashes before and after integration.
- Synchronized with
claude@rdmsm4x; Claude reported no repository/runtime ownership and that the earlier process had ended before the local reinstall proceeded. - Ran
swift test --package-path app: 204/204 XCTest cases passed with 0 failures (33 app/UI, 126 core, 18 gateway, 27 CLI/transport). - Built
XEntropyandxentropyctl: both completed successfully. - Ran Git whitespace/diff checks and a staged high-risk secret-pattern count: clean, with zero high-risk patterns in the four committed state documents.
- Verified the installed app signature with strict deep code-signature validation.
- Verified the authoritative catalog and lifecycle stores are owner
richh, mode0600,PRAGMA integrity_check = ok, and have zeroforeign_key_checkrows. - Ran metadata-only
xentropyctl capabilitiesandcatalog snapshot; the snapshot reports schema 2 / projectionxentropy.catalog.v2, and reveal/redeem/validate/create/revoke/execute capabilities remain unavailable. - Validated the local skill with the official validator using
uvand PyYAML.SKILL.mdSHA-256 is6650fe0492ed2d519d7e4b06ae394eb2ab40218bac5e768fcafd367c76661b22;openai.yamlSHA-256 is6b835bf61bcf536e94f0b049df2c327a2b13f136e41e9fc4a77a46a1c4a66108. - For remote skill installs, verified pinned SSH host keys,
scutilhost identity, isolated staging, exact post-install hashes, and no pre-existing destination. Four installs passed;rdmbair13m5was confirmed offline in Tailscale and was not guessed successful.
Recovery and rollback
- Retained stashes:
82ffbcae14ddddb45b92d2ec4aabc4598d8ecc84and47f56816fd4eb33a4a0efa8df7acb18eaa423bde. - Pre-integration bundle:
/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/xentropy-pre-main-integration.bundle. - Integration bundle through
28b0b06:/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/xentropy-local-main-28b0b06.bundle. - Final local bundle through
c2ac06a:/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/xentropy-local-main-c2ac06a.bundle, SHA-2561406622921e2be4a83c6775bcc29a1ea3f3762fe499c827c026ce104a507de4d, mode0600;git bundle verifypassed. - Preinstall Application Support backup:
/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/xentropy-app-support-before-local-install.tar, SHA-256eb5f07bf6ce5c00be1dbe4ca46d2e7467c96f64bff6dc714a1e6c7d81a74e046. - Installer rollback directory:
/Users/richh/Library/Application Support/XEntropy/DeploymentRollback/20260828-205644-28b0b06fe57d7a55ec46dd88f24e66e8c66e7fe6. - A verification command initially used two incorrect store names.
sqlite3created two zero-byte files at those nonexistent paths. Their creation time and zero-byte size were verified, and only those two files were moved—not deleted—to/Users/richh/dev/_migration/conflicts/rdmsm4x-20260828-xentropy-lifecycle-merge/accidental-empty-sqlite-probes-20260828-2107/. The real app stores were not moved or modified by that correction. - To undo the source integration, verify a retained bundle and fetch into a disposable clone or isolated worktree; never apply either stash blindly over a newer checkout.
- To undo a skill install, move the host's
~/.codex/skills/xentropy-localto a retained quarantine directory. Do not delete it until adoption evidence is reconciled. - To undo the local app install, stop only this installed XEntropy process after checking ownership, then use the installer rollback directory and preinstall Application Support backup. Do not overwrite a newer store without a fresh values-free backup and integrity check.
Outstanding owner-attended actions
- Apple Notes publication is pending:
notes_changelog.zshrefused this Background audit session as designed. From Terminal.app in therdmsm4xdesktop session, runzsh ~/scripts/notes_changelog.zsh '/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260828-2111-xentropy-lifecycle-fleet.md'. - On
rdmsm4x, complete thelocal-cliKeychain bootstrap from a foreground Aqua session, then run one loopback-only caller canary. Do not place the bearer in argv, environment files, Notes, tasks, logs, or chat. - On each remote Mac, launch the installed app and complete the foreground bootstrap; publish that host's prepared changelog to its matching Apple Notes folder.
- Retry the
rdmbair13m5skill install only after the pinned host is online and identity-verified. - Collect explicit Codex and Claude received/reviewed/accepted/adopted acknowledgements; installed files and dispatched messages are not adoption evidence.
- Revoke the credential generation previously exposed in chat without recovering or importing its value. Any future chat-pasted credential is treated as compromised and produces only a values-free review request.
- Review unresolved candidates before correlation. Any real
.env, Notes, Keychain/Passwords, browser, or password-manager scan requires a fresh redacted root/exclusion/retention preview and exact approval. - Any real provider rotation remains an owner-attended provider-specific canary with exact tenant, scope, consumer map, rollback, canary validation, stop-before-revocation behavior, and post-revocation rejection evidence. A 72-hour due state or queue receipt never authorizes unattended provider mutation.