Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260830-2158-fleet-universal2-intel-cloudkit-and-ticket-leases

rdmsm4x — universal2 fleet-wide, Intel closed, CloudKit consolidated, ticket leases shipped

2026-08-30 20:35–21:58 EDT · rdmsm4x · session replicantdb-a1 (docs / verification / coordination)

One-line summary: replicantDB went from 1.10.1 to 1.16.1 on all six hosts across five releases; every app in the family now builds universal2 and runs on both Intel Mac Pros; CloudKit became a shared library with a settled container convention; and the ticket engine gained work-claim leases so tonight's three-writer collision has a real fix rather than a broadcast.

Supersedes rdmsm4x-changelog-20260830-1254-replicantdb-daemon-release-sequence-and-pcc-privacy-gate.md, which covered to 12:54.

Scope and roles

Four Claude sessions were live in overlapping trees. Negotiated split: replicantdb-ca owned Sources/, Tests/, dist/, build.sh and git history; an unidentified session owned the ECSCloudKit extraction; dev-bf owned fleet distribution and ~/dev intake; this session owned docs, verification and coordination. No file had two writers. Nothing pushed to any remote.

replicantDB — five releases to six hosts

Release What
1.14.1 (26) bounded ALL per-file extraction
1.15.1 (28) live indexing progress; Location + Local Network probes; appearance triad
1.16.0 (29) OCR circuit breaker — shipped, then found inert
1.16.1 (30) breaker counted a streak; changed to a per-run budget a success does not restore
1.16.2 CloudKit container derived from the bundle ID (not deployed)

6 of 6 on 1.16.1 (30), verified by execution — app plist, CLI self-report, and a pipelined MCP handshake with the JSON parsed — by two sessions with independent probes. lipo = x86_64 arm64 everywhere. No TCC grant moved.

Universal2 and Intel — closed

CloudKit — one engine, per-app containers

Rich: "we are using cloudkit from the global shared library." ~/dev/lib/ECSCloudKit is the family engine. Convention settled and recorded (DEC-20260830-02, apps/CLAUDE.md §4): the app owns its identifier (containers are team-permanent and unrenameable, so a library bump must never change one); containers are per-app, because CloudKit schema changes are additive-only and one-way; form is iCloud. + bundle ID exactly, including case.

Measured drift — 7× iCloud.net.dataroo.RTTy on a dropped domain, 2× the malformed iCloud.LogTTY.projection.chartStyle, and an iCloud.example.other placeholder. ECSCloudKit validates none of them.

Ticketing — leases, atomic dequeue, plan queues

claim / heartbeat / release / claims / mine / next / handoff / plan / unplan / queue / status, plus decision and spike types. A lease, not a lock — a lock an agent can die holding is the wedged-daemon bug in social form. rdmsm4x is the single claim authority; an unreachable authority fails closed. next claims atomically, so two agents cannot select the same item. Verified by running it: refusal at exit 3 naming the holder, recorded steals, four concurrent next calls returning four distinct tickets.

ecs0lib — importable on all four platforms

Ingested one commit stranded on rdmbair13m5 (7 modules/~700 lines → 8/~1490), then platform-gated: 36 real builds across macOS/iOS/tvOS/visionOS, all succeeding, 127 tests.

Instrument limitations found — the day's most reusable artifact

Four tools answered a question nobody asked while appearing to answer the one asked, and in three the wrong answer was REASSURING:

  1. swift build --triple <platform> — silently ignores the triple; printed Build complete! while compiling a module that imports Cocoa, emitting no iOS product.
  2. xcodebuild -scheme X build without -destination — builds host-arch only even with ARCHS set correctly, and reports BUILD SUCCEEDED.
  3. An os_log query returning zero — the positive control showed it returns zero for any predicate from that subsystem.
  4. A designated requirement is constant across versions — it encodes identifier and certificate, not content. Right for "will TCC grants survive?", worthless for "is this the right build?".

A tool that fails loudly costs an hour; a tool that succeeds falsely costs the belief that you checked. Defence in every case: read the artifact, not the recipe.

Two shared-mutable-state incidents, same shape, different altitude

Fleet ingest — five hosts scanned read-only

Genuinely unpromoted: obsidian_fleet_sync and fleet-agent-registry (rdmbair15m5), unipak_roo and a changelog (rdmpw3275m), an Apple Notes investigation archive (rdmpw3265m). ~60 GB on rdmpw3275m needs a decision rather than a copy. rdmpw3265m holds the only evidence Tyrell builds on Intel — it vanishes when that host is cleaned.

Outstanding owner actions for Rich

  1. LogTTY's bundle identifier — the only remaining decision; the container follows from it. Lowercase logTTY is the intended name (4d564f1); the fleet runs the pre-rename capital form. Going lowercase costs a one-time TCC/Keychain reset on five hosts and a helper re-registration.
  2. The ECSCloudKit owner has not identified themselves, and its Package.swift rewire is still uncommitted in a shared tree.
  3. A file on rdmbair15m5's Desktop named as a GCP OAuth client secret — path recorded, contents never read.
  4. rdmbair15m5 rebooted twice; the sshd log for its lockout window was never captured, so the original cause is unknown and could recur.

Not done

Nothing pushed to any git remote (D-26 stands). No /Applications bundle deleted on any host. 1.16.2 not deployed. The ECSCloudKit validating type not written — it belongs to the library owner.