rdmsm4x-changelog-20260831-1640-carta-mcp-disable-and-codex-reboot-resume
rdmsm4x-changelog-20260831-1640-carta-mcp-disable-and-codex-reboot-resume
Disabled all Carta Cowork-derived Codex plugins across the six-Mac fleet and armed this exact Codex session for a safe one-shot resume after the next reboot and Aqua login.
Scope
- Hosts:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m,jdmbair13m5. - Plugins:
carta-cap-table@claude-cowork,carta-crm@claude-cowork,carta-investors@claude-cowork. - Session: Codex
01a0597b-8ae6-7472-9d8d-ab8ddea6b98ein/Users/richh/dev. - Ticket:
TASK-20260831-14.
Files changed
- Every host:
/Users/richh/.codex/config.toml— three explicitenabled = falseplugin sections. - Every host:
/Users/richh/Library/Application Support/CartaFleetDisable/backups/20260831-1624/— private mode-0600 original config plus manifest. rdmsm4x:/Users/richh/scripts/resume_codex_on_login_v1.0.zsh.rdmsm4x:/Users/richh/Library/Application Support/CodexResume/carta-fleet-disable/PINNED-SESSION.rdmsm4x:/Users/richh/Library/LaunchAgents/com.eastcoastscience.codex-resume-carta-fleet-disable.plist.rdmsm4x:/Users/richh/dev/_handoff/carta-fleet-disable/apply_carta_plugin_disable_v1.0.py.rdmsm4x:/Users/richh/dev/_handoff/carta-fleet-disable/probe_carta_integrations_v1.0.zsh.rdmsm4x:/Users/richh/dev/_handoff/carta-fleet-disable/SESSION-HANDOFF.md.rdmsm4x:/Users/richh/dev/SESSION-STATE.md.rdmsm4x:/Users/richh/.agent-coordination/SESSION-STATE.md.rdmsm4x:/Users/richh/.agent-coordination/checkins/codex-carta-fleet-disable-20260831.json.- Canonical iCloud
PROJECTS.mdmilestone index. - Ticket records under
/Users/richh/dev/issues/.
No Carta plugin cache, credential, OAuth state, cookie, auth database, native history, or other agent's resume artifact was deleted or modified.
Commands and actions
- Resolved host identity with
scutil --get ComputerName. - Read the mandatory fleet coordination and continuity records.
- Opened and claimed
TASK-20260831-14, then broadcast a one-writer start notice. - Ran the values-free Carta probe locally and over direct SSH on each named host.
- Ran
apply_carta_plugin_disable_v1.0.py --dry-runon 6/6, applied first tordmsm4xas canary, then expanded to the five peers. - Re-ran dry-run, native plugin listing, process/config probes, and checksum/mode validation on 6/6.
- Validated the resume script with
zsh -nand the LaunchAgent withplutil -lint. - Ran
FORCE_TEST=1 DRY_RUN=1 resume_codex_on_login_v1.0.zsh carta-fleet-disable. - Loaded and kicked the Aqua LaunchAgent through
launchctl bootstrapandlaunchctl kickstart.
Verification evidence
- All three Carta plugin states are
falsein each of six live Codex configs. rdmsm4x: all three native listings areinstalled, disabled.rdmbair15m5: Carta CRM native listing isinstalled, disabled.- Other hosts: plugin caches absent, with explicit false config retained against later refresh.
- Six hosts report zero Carta processes and no checked Claude Code/Desktop or Antigravity Carta registration.
- Six second dry runs report
changed=false. - Six backup hashes reproduce each manifest's
sha256_before; six live hashes reproducedsha256_afterduring the immediate post-apply proof; backup modes are0600. A final 16:50 EDT observation still showed Carta false 18/18 and zero Carta processes, but full-file hashes onrdmsm4xandrdmbair13m5had changed because only the unrelated[email protected]key was later added. The other four hashes were stable. - Resume dry run resolved the exact rollout, cwd, and Codex binary without opening Terminal.
- LaunchAgent reports two runs, last exit code
0, idle; log confirms the same-boot guard prevented duplicate session launch.
Backup and undo
- Carta config backup/manifest: each host's
~/Library/Application Support/CartaFleetDisable/backups/20260831-1624/. - Restore the original config on the owning host with the staged
transformer
--rollbackand that host's manifest. - Stop future session auto-resume without deleting evidence with:
launchctl bootout gui/$(id -u)/com.eastcoastscience.codex-resume-carta-fleet-disable. - Full rollback and proof commands are in
/Users/richh/dev/_handoff/carta-fleet-disable/SESSION-HANDOFF.md.
Outstanding owner/runtime actions
- After the next reboot and GUI login, verify the Terminal tab,
RESUMED-BOOT, andresume.log. - Re-run the six-host Carta probe after reboot to prove persistent disabled state.
- The current Codex session may retain Carta tools already loaded in memory until it ends; no active session was terminated to force a reload.
- Apple Notes is confirmed pending: the background attempt exited
3. Aqua-side execution and exact-title readback were dispatched toclaude@rdmsm4xin message20260831-164802-DF9DF6CB; delivery is not completion. - A general Codex machine-state snapshot is due. The
Codex-state-backupskill's recorded script/Users/richh/dev/_ops/backup/claude_state_backup.zshis absent and a bounded search found no promoted copy. The six changed configs still have their separate checksum-valid host-local backups described above.