rdmsm4x-changelog-20260831-1829-fleet-tcc-agent-privilege-verification
Session: claude@rdmsm4x (Opus 5) ·
Window: 2026-08-31 18:15:40 → 2026-08-31 18:29:17 EDT
EDT Scope: all six fleet Macs — rdmsm4x, rdmbair13m5,
rdmbair15m5, jdmbair13m5, rdmpw3265m, rdmpw3275m
Ticket: SEC-20260831-10 (follows SEC-20260831-08,
closed 18:17 by antigravity@rdmsm4x)
Independently re-measured TCC (Screen Recording / Full Disk Access /
Accessibility / Input Monitoring / PostEvent) for every installed
terminal app and AI agent app+CLI on all six hosts, established two
structural facts that change how the gap list should be read, and
deployed a per-host permission requester. No TCC grant was
changed — none can be: TCC.db is unwritable even by root
under SIP. 41 switches remain as human toggles.
Findings
sshdcan never obtain Screen Recording. Four attempts on rdmsm4x, macOS 27.0 (26A5421a), 18:20–18:23 EDT:CGRequestScreenCaptureAccess()and/usr/sbin/screencapture -x, each over plain ssh and again undersudo launchctl asuser 501(confirmedAqua). All failed withcould not create image from display, exit 1, no TCC row created, and zerotccdlines inlog stream— tccd is never consulted, because an sshd-descended process has no WindowServer connection. Apple also forbids MDM/PPPC from grantingkTCCServiceScreenCapture. This was Rich's headline ask; it is unclosable and should be struck from gap lists. Working alternative: a LaunchAgent in the Aqua session, granted once by hand, that the ssh job asks for captures.- The TCC subject is the responsible process, and it must be
measured.
sudo launchctl procinfo $$→responsible path = /Applications/Ghostty.app/…/ghosttyfor a shell inside this claude session;/usr/libexec/sshd-keygen-wrapperfor an ssh shell. Corroborated: theclaudebinary carries an explicit DENY for Full Disk Access, yet a protected read from inside this session succeeds. So ~90 "agent CLI not in the list" rows in the earlier matrix are not gaps. - 41 real switches remain, per host, listed in the
report. rdmpw3275m's
sshd → Accessibilityis an explicit DENY written at 18:14:59 by the prior run;tccutil reset Accessibility /usr/libexec/sshd-keygen-wrapperfails (No such bundle identifier, OSStatus −10814, rc 64) because tccutil cannot target a path-keyed client — hand toggle only. rdmbair15m5:/Applications/Grok Bot.appand/Applications/Raycast.appare empty directories, not bundles (created 2026-08-28 20:56). macOS still classifies them as Applications. Not deleted; flagged for reinstall ormvtoarchive/.
Files changed
| path | change |
|---|---|
~/dev/fleet/tcc-privileges/VERIFY-20260831-1830.md |
new — verification report, matrix, 41-item click list, deltas vs the 18:17 matrix |
~/dev/fleet/tcc-privileges/request_all.zsh |
new — fires every
requestable prompt for the current shell and relaunches Terminal.app +
Ghostty running the requester; refuses to run outside
Aqua |
~/dev/fleet/tcc-privileges/results/verify-20260831/ |
new — raw per-host dumps, inventories, matrix, click list |
~/.claude/skills/macos-permissions/references/macOSpermissions.md |
corrected §6: the prior text said
screencapture over ssh "returns wallpaper only"; it fails
with exit 1 and writes nothing, and the grant is unobtainable |
~/.claude/projects/-Users-richh-dev/memory/tcc-belongs-to-responsible-process.md |
corrected — responsibility is not
predictable; measure with launchctl procinfo |
~/.claude/projects/-Users-richh-dev/memory/sshd-cannot-get-screen-recording.md |
new |
~/dev/issues/open/SEC-20260831-10-*.md |
new ticket |
all 6 hosts:
~/dev/fleet/tcc-privileges/{tcc_probe,tcc_probe.c,tcc_dump.sh,request_privileges.zsh,request_all.zsh}
+ ~/scripts symlinks |
deployed |
FLEET-TCC-MATRIX.md, GAPS.md,
ISSUES.md, README.md and
SESSION-STATE.md in that directory were written by
antigravity@rdmsm4x minutes earlier and were left
untouched; the new report supersedes their state and records
the deltas rather than overwriting them.
Verification evidence
- All 6 hosts reached and measured live (
rdmbair15m5via Tailscale 100.74.59.4,jdmbair13m5via 100.86.185.90; both time out on their short hostnames). - SSH-context probe, all 6: Full Disk Access OK everywhere; Accessibility / Input Monitoring / PostEvent OK on 5 of 6 (rdmpw3275m MISS, cause = the explicit DENY above); Screen Recording MISS on all 6 (unobtainable, per finding 1).
log stream --predicate 'process == "tccd"'captured during the capture attempts: 0 lines.tccutilpath-client rejection reproduced on rdmpw3275m with the exact OSStatus.
How to undo
Nothing to undo — no permission, setting, or existing file was
modified except the two documentation corrections listed above (both
additive edits to text that was factually wrong). The deployed scripts
are read-only tools; remove with
rm ~/scripts/{tcc_probe,request_privileges.zsh,request_all.zsh}
and rm -rf ~/dev/fleet/tcc-privileges on a spoke host.
Outstanding owner actions (Rich)
- On each host, at the console:
~/scripts/request_all.zsh— fires every prompt that can be fired, then opens the three panes. - Flip the 41 switches listed per host in the report. Highest value first: rdmpw3275m → Accessibility → sshd-keygen-wrapper (explicit DENY, blocks remote UI automation on that host), then the terminals on rdmpw3265m / rdmpw3275m.
- Decide on the Aqua screenshot LaunchAgent (finding 1). Not built.
- Reinstall or archive the two empty
.appstubs on rdmbair15m5.