rdmsm4x-changelog-20260902-2346-xentropy-vnext-legacy-retirement-prep
rdmsm4x-changelog-20260902-2346-xentropy-vnext-legacy-retirement-prep
Prepared a values-free, release-gated fleet retirement plan so the next verified XEntropy deployment can archive competing app copies and old rollbacks without losing source, catalogs, credentials, or recovery evidence.
Scope
- Controller and source host:
rdmsm4x - Read-only inventory targets:
rdmsm4x,rdmbair15m5,rdmpw3275m,rdmbair13m5,jdmbair13m5,rdmpw3265m - Isolated worktree:
/Users/richh/dev/_worktrees/xentropy-legacy-cleanup-vnext-20260902 - Branch/commit:
codex/xentropy-legacy-cleanup-vnextat9c317b5e74e7701a50cb719b125a947213ce5901 - Tracking:
TASK-20260902-13
Files changed in the XEntropy checkpoint
CHANGELOG.mdISSUES.mdSESSION-STATE.mdapp/Tests/XEntropyCLITests/FleetInstallerContractTests.swiftapp/Tests/XEntropyCLITests/LegacyRetirementScriptTests.swiftdocs/reviews/2026-09-02-xentropy-fleet-legacy-inventory.mddocs/runbooks/xentropy-vnext-deployment-recovery.mddocs/superpowers/plans/2026-09-02-next-revision-legacy-retirement.mddocs/superpowers/specs/2026-09-02-next-revision-legacy-retirement-design.mdscripts/inventory_xentropy_legacy_locations_v1.0.zshscripts/install_xentropy_local_instance_v1.0.zshscripts/retire_xentropy_legacy_copies_v1.0.zshscripts/retire_xentropy_legacy_fleet_v1.0.zshscripts/verify_xentropy_fleet_canary_v1.0.zsh
Coordination state also changed by creating/claiming
TASK-20260902-13, adding
~/.agent-coordination/checkins/codex-xentropy-legacy-cleanup-vnext-20260902.json,
and sending values-free owner/review messages to Claude, agy, and Codex
peers.
Commands and checks
- Verified canonical and isolated Git identities/status.
- Ran the pinned read-only fleet inventory with
zsh scripts/inventory_xentropy_legacy_locations_v1.0.zsh --all. - Ran syntax checks for all five install/verify/inventory/retirement scripts.
- Ran focused installer/retirement tests: 23 tests, 0 failures.
- Ran full
swift test --package-path app: 272 tests, 0 failures (53 app/UI, 19 gateway, 141 core, 59 CLI). - Built
XEntropyandxentropyctl: both passed. - Ran
git diff --checkand targeted values-boundary pattern counts: clean.
Evidence
- All six hosts authenticated through pinned Tailscale SSH identities.
- All six expose both an invalid, versionless
/Applications/XEntropy.appand an older Team-unset per-user app. No installed file or process was changed. - Inventory recorded 54 rollback generations (544,072 KiB), 76 Spotlight bundle-ID results including source/recovery evidence, and eight unopened local-auth records per host.
- A second values-free read-only probe classified every generation: each host has exactly one earliest manifest-only missing/missing generation and every later generation has matched full app/CLI state.
- Claude independently reproduced the 266-case predecessor checkpoint
and found two canary blockers: a controller-only verifier guard defect
and frozen plans that could not apply when they included manifest-only
generations. Commit
9c317b5closes both with behavioral tests, explicit child-shell fail-fast semantics, matched missing/missing archival, mismatched-state refusal, retry-safe partial-move undo, and retirement rollback independent of vNext health. Immutable re-review is pending. - The installer now selects
tyrell-lightexplicitly and sends remote launches through the logged-in GUI bootstrap domain. The two-layer recovery runbook distinguishes retirement rollback from exact previous-deployment restore. - The retirement verifier now counts every archived rollback in the
frozen manifest and rejects any active app/CLI entry name in retained or
archived generations.
.retiredremoves normal discovery/active-path ambiguity but is not represented as secure erasure. - Catalogs, auth contents, Keychain, TCC, provider state, and credential stores were not queried or mutated.
Recovery and undo
- The XEntropy work is an isolated commit and has not been merged into
canonical
main. Undo by abandoning the linked worktree/branch only after the ticket and peer review no longer need it; do not reset the dirty canonical checkout. - No fleet deployment or cleanup occurred, so no host rollback is required.
- Future retirement uses per-host digest-bound manifests, reversible
archive moves,
.retiredapp/CLI names, and an exact rollback command. The tool is implemented and remains gated on immutable re-review and same-host vNext proof.
Outstanding actions
- Preserve the 11 dirty canonical AppIcon paths, now confirmed as
unowned fleet generator output tracked separately by
TASK-20260902-14. - Obtain focused Claude re-review of immutable correction
9c317b5against prior finding delivery20260903-011305-BFEF46CB. - Canary the exact signed vNext artifact on
rdmbair15m5before any legacy move, then process the other five hosts one at a time. - Apple Notes publication is pending because this session runs under
the
Backgroundlaunchd manager rather than an Aqua desktop session.