Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260901-1615-fleet-hardening-audit-mechanical-controls

rdmsm4x — fleet hardening audit: four documentary controls made mechanical

When: 2026-09-01 15:47:05 → 16:15:49 EDT (~29 min) · Host: rdmsm4x · By: claude@rdmsm4x

One-line summary: audited 1,014 documents, 2,362 bus messages and 44 re-verified tickets to establish the fleet's complete recurring-failure state, converted four memory-only controls into enforced ones with 36 self-test assertions, found three live unreported defects, and filed 10 tickets. No secret value appears in this record.

Scope

All six hosts' shared state was read; only rdmsm4x was written. No app source under ~/dev/apps was modified. permissions.defaultMode was not touched in any file.

Files changed

Path Change Backup / recovery
~/dev/lib/agentkit/lib/integrity.zsh NEW commit 14c9fab; git revert 14c9fab
~/dev/lib/agentkit/tests/test_integrity.zsh NEW, 23 assertions same commit
~/dev/lib/agentkit/README.md +1 section same commit
~/dev/lib/app-baseline/VERIFICATION_AND_EVIDENCE.md 174 → 239 lines commit 1e16c65; git revert 1e16c65
~/.claude/skills/terminal-shell-env/SKILL.md 110 → 152 lines not a git repo; prior copy in this session's transcript
~/dev/_ops/ecs0lib-audit-20260901/ 4 new documents additive only

Snapshot taken before any edit, via the fleet's own tool: worktree_snapshot.zsh save ~/dev/issues/bin/ticket ~/dev/lib/app-baseline/VERIFICATION_AND_EVIDENCE.md → ~/.agent-coordination/snapshots/rdmsm4x/issues/20260901-155951

Verification evidence

$ zsh ~/dev/lib/agentkit/tests/test_agentkit.zsh    -> PASS=13 FAIL=0  rc=0
$ zsh ~/dev/lib/agentkit/tests/test_integrity.zsh   -> PASS=23 FAIL=0  rc=0
$ git -C ~/dev/lib/agentkit     status --porcelain  -> (empty)
$ git -C ~/dev/lib/app-baseline status --porcelain  -> (empty)

Live acceptance, not just fixtures:

$ agentkit_tool_exists worktree_snapshot.zsh
  EXISTS   worktree_snapshot.zsh -> /Users/richh/bin/worktree_snapshot.zsh
$ agentkit_doc_cli_conformance ~/.claude/skills/fleet-ticketing/SKILL.md ~/dev/issues/bin/ticket ticket
  DRIFTED  8 documented but NOT implemented: claims handoff mine next plan queue status unplan   rc=1
$ agentkit_provenance_check ~/dev/apps/Tyrell   -> 1 suspect   rc=1
$ agentkit_provenance_check ~/dev/lib/ecs0lib   -> 0           rc=0
$ agentkit_provenance_check ~/dev/issues        -> 0 of 38 modified files   rc=0

The 1/0/0 spread is the evidence the check discriminates rather than firing on everything.

The three live defects found

  1. Third occurrence of the Tyrell silent revert, uncommitted. Sources/TyrellAppSupport/PermissionHealth.swift working-tree blob 8c72803a37f6 equals the 2026-08-29 revision at commit 9dc001c; HEAD holds 37f1c853967a from today 11:48 (9b513b8). Reported to codex@rdmsm4x, who owns Tyrell. Not touched.
  2. bin/ticket has no concept of closed/ — 48 real tickets invisible to every query and their IDs reissuable. grep -n "CLOSED_DIR\|closed" bin/ticket -> rc=1, no matches (positive control: RESOLVED_DIR -> 3 matches).
  3. An unidentified rsync rewrote LogTTY's git loose refs on rdmbair15m5, making the repo report 1 commit while 80 sat intact. Both candidates ruled out on 2026-08-23; never found; the investigation's own words: "still armed and unexplained." Zero hits in any documentation.

Four errors of my own, corrected before shipping

  1. Declared worktree_snapshot.zsh absent. It exists and is on $PATH. I validated the search shape and not the search space.
  2. agentkit_provenance_check v0 returned 61 false positives comparing mtime to commit time.
  3. agentkit_doc_cli_conformance v0 reported English prose as missing subcommands.
  4. Copied a bus report's claim that (( x = 0 )) exits 0. It exits 1, in zsh and bash.

Tickets filed

INCIDENT-20260901-07 (critical, ticket CLI lost next) · -08 (closed/ blind spot) · -09 (LogTTY rsync) · -10 (Apple Notes cold-start duplicate) · REV-20260901-03 (Tyrell fleet identity in 19 files) · DEC-20260901-01 (distribution target — needs Rich) · FEAT-20260901-43 (tyrell-cli) · FEAT-20260901-44 (fleet-config repo) · TASK-20260901-06 (watcher coverage 1/64) · TASK-20260901-07 (this work). Comments on INCIDENT-20260901-04 and FEAT-20260901-26.

Outstanding owner actions for Rich

  1. DEC-20260901-01 — Developer ID vs Mac App Store for Tyrell. Decide before first outside distribution; a bundle-ID change after release is a new app.
  2. INCIDENT-20260901-07 — restore the removed ticket surface or update the skill. Never neither.
  3. Credential rotation: ~/.secrets/global.env mtime is 2026-08-23 01:35, eight days before the rotation tickets were filed. Names and locations only; no values read or recorded.
  4. DEC-20260831-06 — the fleet-wide pre-commit hook, deferred earlier; the class has recurred three times since.