XEntropy owner access, discovery, import preview, and fleet deployment
Completed the working local credential-tooling increment and deployed it to every reachable fleet Mac. XEntropy now combines owner-visible API-key values with local CLI, authenticated loopback JSON API, Stateless MCP 2026-07-28, values-free filesystem discovery, lifecycle locks/coalescing/hold-down, and a password-manager export preview workbench.
Scope
- Controller and canonical source:
rdmsm4x:/Users/richh/dev/apps/Xentropy - Installed and verified:
rdmsm4x,rdmbair15m5,rdmpw3275m,jdmbair13m5,rdmpw3265m - Pending because Tailscale reports offline:
rdmbair13m5 - No public listener, provider create/rotate/revoke operation, cross-host credential copy, LiteLLM route mutation, or source push occurred.
Source checkpoints
081d62443cc18083101f77530a9f758efa4d5e25— host-local authenticated owner access through UI, CLI, JSON API, and Stateless MCP.cee31167ba5562f32400edd0dd3c8ef2f6f59640— filesystem discovery UI and password-manager/browser preview workbench.26bf44f— CLI discovery persists the same app-owned host-local index.0c29777b8fa007be76f3cf65bcebb36653f98d21— skip dataless cloud placeholders without materializing them.b55175c315ff245c86ee036db40f3a43e29a0bba— grant exactlysecret.readto Claude/Codex gateway profiles while keeping LiteLLM metadata-only; includes a regression test that failed before the fix.d8fb6e6ba2b3d166c9824103f39a715e402d6cae— exact installed deployment commit.4ccf9b4a4accafee679800f14e638b03ee809fcb— final repository documentation checkpoint.
origin/main was not pushed.
Files and product areas changed
- SwiftUI owner-access table/templates, Sources workspace, discovery
table, manager-import matrix, detail views, and command explorer under
app/Sources/XEntropy/. - Local authority, credential discovery, parser, lifecycle
lock/request/coalescing/hold-down, catalog, CLI, API, MCP, loopback
server, and deployment support under
app/Sources/XEntropyCore/,app/Sources/XEntropyCLI/, andapp/Sources/XEntropyGateway/. - Regression and negative boundary coverage under
app/Tests/. - Architecture, lifecycle runbook, session state, and issues under
docs/,SESSION-STATE.md, andISSUES.md. - Native Codex skill at
~/.codex/skills/xentropy-local/. - Portfolio status at the canonical iCloud
PROJECTS.md.
Verification
swift test --package-path app: 232/232 XCTest cases passed: 46 app/UI, 131 core, 19 gateway, and 36 CLI/transport.swift build --package-path app --product XEntropy: passed.swift build --package-path app --product xentropyctl: passed.git diff --check: passed.- Production provider-key/private-key marker scan: zero files.
- Installed local CLI owner-value canary: nonempty value, value not emitted in validation output.
- Installed local Codex-profile JSON API canary: nonempty value, value not emitted in validation output.
- Installed local Codex-profile Stateless MCP canary: nonempty value, value not emitted in validation output.
- The first API canary found the Claude/Codex profile scope defect as
HTTP 403. A failing test reproduced it before
b55175c; the corrected build passed the full suite and real installed API/MCP canaries.
Discovery canaries
Only aggregate coverage counts were printed; matched values were never printed, stored in the portable catalog, logged, messaged, or copied between hosts.
| Host | Scanned files | Unresolved observations | Dataless skips | File failures | State |
|---|---|---|---|---|---|
| rdmsm4x | 27,700 | 5,000 | 1,492 | 0 | complete with two explicit truncation indicators |
| rdmbair15m5 | 2,920 | 5,000 | 0 | 0 | candidate cap reached |
| rdmpw3275m | 2,942 | 5,000 | 0 | 0 | candidate cap reached |
| jdmbair13m5 | 118 | 1,404 | 3,023 | 62 | partial coverage reported explicitly |
| rdmpw3265m | 2,990 | 5,000 | 1 | 7 | partial coverage and candidate cap reported explicitly |
The discovery index directory/file modes are
0700/0600. Password-manager support is
currently a bounded, security-scoped, user-selected CSV/JSON preview for
15 documented managers/browser stores; it is not yet an authority
import.
Fleet deployment and rollback
Final app/CLI build d8fb6e6 is installed and running on
the five reachable hosts. Real Codex-profile API and MCP value canaries
passed on rdmsm4x, rdmbair15m5,
rdmpw3275m, and rdmpw3265m.
jdmbair13m5 correctly reported that its local authority is
unconfigured; no credential was copied there.
rdmsm4x:~/Library/Application Support/XEntropy/DeploymentRollback/20260829-054538-d8fb6e6ba2b3d166c9824103f39a715e402d6caerdmbair15m5:~/Library/Application Support/XEntropy/DeploymentRollback/20260829-054646-d8fb6e6ba2b3d166c9824103f39a715e402d6caerdmpw3275m:~/Library/Application Support/XEntropy/DeploymentRollback/20260829-054812-d8fb6e6ba2b3d166c9824103f39a715e402d6caejdmbair13m5:~/Library/Application Support/XEntropy/DeploymentRollback/20260829-054901-d8fb6e6ba2b3d166c9824103f39a715e402d6caerdmpw3265m:~/Library/Application Support/XEntropy/DeploymentRollback/20260829-055019-d8fb6e6ba2b3d166c9824103f39a715e402d6cae
To undo on one host, stop only its installed
XEntropy.app process, restore the app and CLI from that
host's named rollback directory, and relaunch. Do not restore or copy
another host's Application Support authority.
Skills and agent handoff
- Codex skill:
~/.codex/skills/xentropy-local/SKILL.md - Codex skill SHA-256:
1b4c9014fd731dcb1775a1c558b27ca37b9e0877d917057e63cedb3a23961c2c - Codex prompt SHA-256:
1d329a412f6e80a76a8e2a005e4fb9b8334340fcb9edd9d159e697a32e635936 - The same hashes were verified on
rdmbair15m5,rdmpw3275m,jdmbair13m5, andrdmpw3265m. - Claude requests dispatched:
20260829-054005-6C6468CFand corrected-scope follow-up20260829-055211-FDF7832C. - Claude receipt, native skill path/hash, and fleet adoption remain pending; dispatched is not accepted or integrated.
Outstanding work
- Bring
rdmbair13m5online, then run the same exact install, discovery canary, local-authority canary if configured, and skill hash verification. - Correlate the unresolved discovery candidates before promoting any logical credential or version.
- Implement approved local authority imports for explicitly selected manager exports; do not scrape manager databases, browser profiles, Notes, Keychain, or Passwords.
- Implement provider-specific rotation adapters with create/store/update/canary/rollback/revoke/rejection evidence. Existing locks, duplicate coalescing, 60-second per-key mutation hold-down, and completion-or-72-hour eligibility are lifecycle controls, not proof of a provider mutation.
- Revoke the chat-exposed OpenRouter generation and securely store a replacement before use.
- Publish remote-host Notes changelogs from each host's Aqua session; SSH installation correctly left those Notes entries pending while preserving the Markdown file copies.