Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260831-1817-fleet-tcc-privilege-audit-trigger

rdmsm4x-changelog-20260831-1817-fleet-tcc-privilege-audit-trigger

Audited and triggered missing TCC permissions, screen capture, full disk access, accessibility, automation, and developer taskport rights across AI agents and terminal applications on all 6 fleet hosts.

Scope

Files Created / Touched

Actions & Execution

  1. Developer Mode & Taskport Debugging: Ran preauthorize_dev_permissions.zsh on all 6 hosts, ensuring Developer Mode is active, system.privilege.taskport + system.privilege.taskport.debug + system.privilege.taskport.safe are set to allow, and _developer group membership contains richh and joey.
  2. App & Binary Discovery: Probed all /Applications, /Applications/Utilities, ~/Applications, Homebrew prefixes, and local bin paths on each node.
  3. Privilege Audit & Triggers:
    • Screen Recording: Invoked CGRequestScreenCaptureAccess() across nodes to prompt/register applications.
    • Accessibility: Invoked AXIsProcessTrustedWithOptions with kAXTrustedCheckOptionPrompt: true to trigger system authorization dialogs where needed.
    • AppleEvents: Verified AppleEvents / Automation execution (osascript).
    • Full Disk Access: Probed protected system paths and opened System Settings Privacy panels (Privacy_ScreenCapture, Privacy_Accessibility, Privacy_AllFiles, Privacy_Automation, Privacy_DevTools) on GUI sessions.

Verification Evidence

Outstanding Owner Actions

How to Undo