Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260831-1829-fleet-tcc-agent-privilege-verification

rdmsm4x-changelog-20260831-1829-fleet-tcc-agent-privilege-verification

Session: claude@rdmsm4x (Opus 5) · Window: 2026-08-31 18:15:40 → 2026-08-31 18:29:17 EDT EDT Scope: all six fleet Macs — rdmsm4x, rdmbair13m5, rdmbair15m5, jdmbair13m5, rdmpw3265m, rdmpw3275m Ticket: SEC-20260831-10 (follows SEC-20260831-08, closed 18:17 by antigravity@rdmsm4x)

Independently re-measured TCC (Screen Recording / Full Disk Access / Accessibility / Input Monitoring / PostEvent) for every installed terminal app and AI agent app+CLI on all six hosts, established two structural facts that change how the gap list should be read, and deployed a per-host permission requester. No TCC grant was changed — none can be: TCC.db is unwritable even by root under SIP. 41 switches remain as human toggles.

Findings

  1. sshd can never obtain Screen Recording. Four attempts on rdmsm4x, macOS 27.0 (26A5421a), 18:20–18:23 EDT: CGRequestScreenCaptureAccess() and /usr/sbin/screencapture -x, each over plain ssh and again under sudo launchctl asuser 501 (confirmed Aqua). All failed with could not create image from display, exit 1, no TCC row created, and zero tccd lines in log stream — tccd is never consulted, because an sshd-descended process has no WindowServer connection. Apple also forbids MDM/PPPC from granting kTCCServiceScreenCapture. This was Rich's headline ask; it is unclosable and should be struck from gap lists. Working alternative: a LaunchAgent in the Aqua session, granted once by hand, that the ssh job asks for captures.
  2. The TCC subject is the responsible process, and it must be measured. sudo launchctl procinfo $$ → responsible path = /Applications/Ghostty.app/…/ghostty for a shell inside this claude session; /usr/libexec/sshd-keygen-wrapper for an ssh shell. Corroborated: the claude binary carries an explicit DENY for Full Disk Access, yet a protected read from inside this session succeeds. So ~90 "agent CLI not in the list" rows in the earlier matrix are not gaps.
  3. 41 real switches remain, per host, listed in the report. rdmpw3275m's sshd → Accessibility is an explicit DENY written at 18:14:59 by the prior run; tccutil reset Accessibility /usr/libexec/sshd-keygen-wrapper fails (No such bundle identifier, OSStatus −10814, rc 64) because tccutil cannot target a path-keyed client — hand toggle only.
  4. rdmbair15m5:/Applications/Grok Bot.app and /Applications/Raycast.app are empty directories, not bundles (created 2026-08-28 20:56). macOS still classifies them as Applications. Not deleted; flagged for reinstall or mv to archive/.

Files changed

path change
~/dev/fleet/tcc-privileges/VERIFY-20260831-1830.md new — verification report, matrix, 41-item click list, deltas vs the 18:17 matrix
~/dev/fleet/tcc-privileges/request_all.zsh new — fires every requestable prompt for the current shell and relaunches Terminal.app + Ghostty running the requester; refuses to run outside Aqua
~/dev/fleet/tcc-privileges/results/verify-20260831/ new — raw per-host dumps, inventories, matrix, click list
~/.claude/skills/macos-permissions/references/macOSpermissions.md corrected §6: the prior text said screencapture over ssh "returns wallpaper only"; it fails with exit 1 and writes nothing, and the grant is unobtainable
~/.claude/projects/-Users-richh-dev/memory/tcc-belongs-to-responsible-process.md corrected — responsibility is not predictable; measure with launchctl procinfo
~/.claude/projects/-Users-richh-dev/memory/sshd-cannot-get-screen-recording.md new
~/dev/issues/open/SEC-20260831-10-*.md new ticket
all 6 hosts: ~/dev/fleet/tcc-privileges/{tcc_probe,tcc_probe.c,tcc_dump.sh,request_privileges.zsh,request_all.zsh} + ~/scripts symlinks deployed

FLEET-TCC-MATRIX.md, GAPS.md, ISSUES.md, README.md and SESSION-STATE.md in that directory were written by antigravity@rdmsm4x minutes earlier and were left untouched; the new report supersedes their state and records the deltas rather than overwriting them.

Verification evidence

How to undo

Nothing to undo — no permission, setting, or existing file was modified except the two documentation corrections listed above (both additive edits to text that was factually wrong). The deployed scripts are read-only tools; remove with rm ~/scripts/{tcc_probe,request_privileges.zsh,request_all.zsh} and rm -rf ~/dev/fleet/tcc-privileges on a spoke host.

Outstanding owner actions (Rich)

  1. On each host, at the console: ~/scripts/request_all.zsh — fires every prompt that can be fired, then opens the three panes.
  2. Flip the 41 switches listed per host in the report. Highest value first: rdmpw3275m → Accessibility → sshd-keygen-wrapper (explicit DENY, blocks remote UI automation on that host), then the terminals on rdmpw3265m / rdmpw3275m.
  3. Decide on the Aqua screenshot LaunchAgent (finding 1). Not built.
  4. Reinstall or archive the two empty .app stubs on rdmbair15m5.