rdmsm4x — LogTTY read-only do-not-ship audit
Time: 2026-08-30 21:43–21:50 EDT
Host: rdmsm4x
Project: /Users/richh/dev/apps/LogTTY
(Production)
Source task: Codex coordinator
01a05576-551e-7502-af54-bd854b1e56aa
Outcome
Resumed LogTTY only as a read-only diagnostic lane. The do-not-ship
gate remains active. No source, branch, worktree, index, build
directory, dist/ artifact, installed app, process, or
project continuity document was modified. No build, signing,
installation, deployment, cleanup, reset, merge, commit, or live-session
termination occurred.
The terminal job-notification defect remains resolved. The current
LogTTY repository and loose dist/logTTY.app are not safe
inputs for a release build or deployment.
Owner and repository evidence
- Canonical root:
/Users/richh/dev/apps/LogTTY. - Branch / HEAD:
mainat23f9a899c7d9024908cde31ad86c5254a63bd401. - Dirty inventory before and after audit: 36 tracked modifications, 10 untracked entries, 0 staged files; diff stat 464 insertions / 1,415 deletions.
- Live owner evidence: Claude PID
85556, commandclaude --resume 0da93685-c63b-48c3-ae45-8ad9674bf79c, held this repository as CWD throughout the audit. - The stale
.agent_session.locknames Claude andSTRICT_READ_ONLY, but its PID is dead and its TTL expired. It is supporting provenance, not the current lease. The live process plus the 21:41 coordinator directive are the current gate. - Explicit release request sent to Claude as bus message
20260830-214521-758540BB; no reply or isolated path release arrived before closeout.
Artifact provenance
Loose app — explicitly not shippable
dist/logTTY.app, modified 2026-08-30 14:51 EDT:
- product/bundle identity:
LogTTY/com.eastcoastscience.LogTTY(uppercase identity) - version/build:
0.1.1/18 - embedded source: archived commit
3d3c908414aefefa47c197abcbb4ad01ee207b35f - embedded
gitDirty=true - ad-hoc signature /
TeamIdentifier=not set
The current dirty worktree matches that rollback direction:
BUILD_NUMBER is changed from HEAD's 21 to 18; the build
script rolls lowercase logTTY back to uppercase
LogTTY, removes current migration safeguards, and removes
helper build/validation paths.
Signed ZIPs — coherent historical candidates, not released artifacts
dist/logTTY-0.1.1-20.zip, SHA-25606a5bc3c5919b1d5a068673d806a20fcb441f3f747004142cda9882b09a932ae: embeds clean commitfa5de9c7942d80ef853eb22089f2962de6c6c9e0, correct lowercase identity, build 20, helper, universalx86_64 arm64, teamZU2882L4HT, strict codesign verification PASS.dist/logTTY-0.1.1-21.zip, SHA-25651d3e1bdec95e03b1b6e0056811098b52876b63f899d7233000906428096689e: embeds clean current HEAD23f9a899c7d9024908cde31ad86c5254a63bd401, correct lowercase identity, build 21, helper, universalx86_64 arm64, teamZU2882L4HT, strict codesign verification PASS.
These signatures and embedded source pointers do not prove current install/runtime/helper/data integrity/canary/fleet deployment. No Build 20/21 release-evidence manifest exists in the current repository. Therefore neither ZIP is approved to ship from this lane.
Isolated clean-source validation
Exported clean HEAD via git archive into
/var/folders/sj/4w2t0nk174z6ngr3qqt6c1tw0000gn/T/logtty-head23f9a899-test.akCmF0O8O2
and ran the complete suite there, never touching the canonical
.build directory:
SWIFT_TEST_EXIT=0
11 + 27 + 93 + 70 + 37 = 238 tests passed
This proves package tests for clean commit 23f9a899; it
does not prove the ZIP's runtime or release lifecycle state.
Real loaded PTY validation
Launched interactive zsh with the actual ~/.zshrc,
telemetry state unset before startup, and session ID
CODEXPTY2148. Observed:
_SESSION_LOGGER_ACTIVE=1_session_preexecand_session_precmdregistered- commands and exit codes
0, 1, 0, 0, 0recorded jobsempty- 0
[N] done ... nc -ucompletion notices
Generated telemetry proof:
/Users/richh/.local/state/terminal-sessions/rdmsm4x_tty_session_agy_CODEXPTY2148_20260830-214702-20260830-214705.log.
Local coordination state changed
- Created and completed
/Users/richh/.agent-coordination/checkins/codex-logtty-readonly-gate-audit-20260830-2147.json. - Sent bus request
/Users/richh/.agent-coordination/mail/20260830-214521-758540BB__from-codex-rdmsm4x__to-claude-rdmsm4x__logtty-readonly-audit-request-isolated-release-20260830.md. - Temporary artifact extraction retained at
/var/folders/sj/4w2t0nk174z6ngr3qqt6c1tw0000gn/T/logtty-artifact-audit.ji9JCGlkkH. - The first Swift wrapper used zsh's read-only special variable
statusafter tests completed; it exited 1 after the test runner. The already-built suite was rerun with--skip-buildand a non-special variable, producing the authoritative exit 0 / 238-test result above.
Gate and next action
Do not ship the loose app. Do not rebuild from the dirty canonical tree. Do not treat signed ZIP presence as runtime/deployment acceptance. Claude must first identify the owner and preserve or reconcile the unknown dirty rollback, then explicitly release an isolated worktree/path. Only after that should a release lead regenerate a clean manifest, install a rollback-protected local candidate, prove helper/runtime/data integrity, canary it, and make per-host deployment decisions.
Undo
No project changes require rollback. The check-in and bus message are append-only coordination records. Temporary audit directories are disposable but were intentionally left intact rather than deleted from this session.