Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260831-1934-claude-code-2.1.252-fleet-rollout-and-syspolicyd-wedge

rdmsm4x-changelog-20260831-1934-claude-code-2.1.252-fleet-rollout-and-syspolicyd-wedge

Window: 2026-08-31 18:46:32 – 19:34:51 EDT (~48 min) · Lead: claude@rdmsm4x session dev-94 [785f8b]

One-line summary: brought all six Macs to Claude Code 2.1.252, deployed the missing claude_code_update auto-update job to the four hosts that never had it, and cleared a wedged syspolicyd on jdmbair13m5 that was deadlocking every exec of the claude binary.

Scope

All six fleet hosts: rdmsm4x, rdmbair15m5, rdmbair13m5, jdmbair13m5, rdmpw3265m, rdmpw3275m.

What changed

1. Claude Code upgraded on rdmsm4x

2. Auto-update mechanism deployed to 4 hosts (the real gap)

The version numbers looked fine fleet-wide, but the mechanism keeping them current existed on only 2 of 6 hosts. rdmbair15m5, rdmbair13m5, jdmbair13m5 and rdmpw3275m had neither ~/scripts/claude_code_update.zsh nor the launchd job — they were current by coincidence, with nothing to keep them current.

Deployed to those four, byte-identical to the rdmsm4x copy:

Left alone: rdmsm4x and rdmpw3265m already had v1.1 at the same sha.

3. jdmbair13m5 — wedged syspolicyd (the actual incident)

Symptom: claude --version hung indefinitely (>7 min, rc=124 at every timeout). Binary was mode 755, byte-identical (sha256 b661c6a094fcc32656bf7c0071c5b45b, 197,220,928 bytes) to two hosts where it ran fine.

Ruled out by measurement, not assumption:

Root cause, from spindump:

AppleSystemPolicy::procNotifyExecComplete
  AppleSystemPolicy::waitForEvaluation
    ASPEvaluationManager::waitOnEvaluation
      lck_mtx_sleep   (indefinite)

The AppleSystemPolicy kernel extension blocks exec until syspolicyd returns a Gatekeeper verdict. syspolicyd (pid 532) had stopped servicing its evaluation queue, so the kernel slept forever. The tell that misleads: syspolicyd showed 0.0% CPU and the syspolicy/AMFI log was silent — it looked healthy precisely because it was wedged. An idle security daemon is not evidence of an idle security path.

Fix: sudo killall syspolicyd (launchd respawned it as pid 45627). claude --version returned 2.1.252 rc=0 immediately after. No reboot needed.

Verification (end state, all six)

Every host re-measured after the work — version by actually running the binary, exit code captured separately rather than through a pipe:

Host claude rc mode script job last run log
rdmsm4x 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252
rdmbair15m5 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252
rdmbair13m5 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252
jdmbair13m5 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252
rdmpw3265m 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252
rdmpw3275m 2.1.252 0 755 v1.1 9a586985faf9 loaded exit=0 UNCHANGED 2.1.252

Outstanding / owner actions

How to undo

No secrets were read or written.