ReplicantDB 1.19.1 build 35 fleet rollout and old-copy consolidation
ReplicantDB 1.19.1 (35) “Measured” was deployed and launched on all six fleet Macs, then 476 reviewed prior executable, staging, rollback, and historical-archive targets were consolidated into one inventory-backed package per host so the active application, CLI, and MCP locations are unambiguous.
Scope and reason
- Acting host:
rdmsm4x; user:richh; local GUI session context used for signed build and app launch. - Target hosts:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - Production project:
/Users/richh/dev/apps/replicantDB. - Source writer was isolated at
/Users/richh/dev/_handoff/codex-out/replicantdb-memory-bounds-20260902, branchcodex/replicantdb-memory-bounds-20260902. - Deployed source commit:
9a1e37ccd3ed6c0573d0cacf875889b23d0248c1. - Continuity commit after rollout:
c447569054d0182b0b57db2df79a363276e7c42a. - Metadata-only executable-distribution hardening commit:
3edaf5218a9966e077d3b6906c9a23b4345dd7cc. - Reason: ship the measured duplicate-statistics memory-bound repair for fleet testing and satisfy Rich's explicit request to archive/remove older ReplicantDB application, CLI, MCP, staging, cache, and rollback copies after the replacement passed canary acceptance.
Application and configuration changes
- Installed and launched
/Applications/ReplicantDB.app1.19.1 build 35 on all six hosts. - Installed the exact build-35
~/bin/replicantdb-cliand~/bin/replicantdb-mcpon all six hosts. - Preserved existing daemon state. The daemon remains loaded on
rdmsm4x,rdmbair13m5,rdmpw3265m, andrdmpw3275m; it remains unloaded onrdmbair15m5andjdmbair13m5. - Migrated ReplicantDB MCP command paths in
~/.codex/config.tomland~/.claude.jsonon all six hosts from the removed source-tree distribution path to the canonical~/bin/replicantdb-mcp. - Per-host configuration backups are under
~/.agent-coordination/backups/replicantdb-1.19.1-build35-20260903-003346-replicantdb-mcp-config/. - No TCC row was reset or rewritten. The active and older builds use the retained bundle/code identity, so resetting an “old” authorization would also revoke build 35.
Old-copy cleanup
- Cleanup run ID:
replicantdb-1.19.1-build35-20260903-003346. - The reviewed first-pass manifests are in
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.1-build35-rollout-20260903/manifests/. - The archive-first cleanup removed 344 exact reviewed targets. One canary Google Drive target disappeared before preflight, so the execution manifest correctly narrowed from 112 discovery candidates to 111 paths rather than guessing or broadening.
- Another reconciliation task subsequently created an old CLI/MCP pair
in a FileProvider-synchronized evidence packet. The pair propagated to
all six Macs. A separate tested two-phase workflow validated and
prepared every host's package before any removal, then made all 14
manifested late paths absent. Twelve were removed locally; two had
already disappeared on
rdmsm4xthrough synchronized deletion. - The first two follow-up censuses used a filename-oriented archive
filter. A source-integration review caught the blind spot: generic
archive names such as
1.19.0-build34.tgzand olderrdDB/rooDBZIPs could survive below ReplicantDB-named directories. The corrected full-path classifier found 80 additional paths onrdmsm4xand 38 onrdmbair15m5; the other four hosts had none. A hash-pinned, exact-manifest tool passed 10/10 isolated destructive-safety tests, prepared and read back both replacement packages before either deletion, content-deduplicated those 118 paths into eight and seven payloads respectively, then removed 80/80 and 38/38 with no drift or unexpected absence. - Total manifest-controlled cleanup: 476 reviewed targets — 344 initial application/binary/staging/rollback paths, 14 late reconciliation binaries, and 118 historical archives. Every removed payload is represented in its host's one retained package with source-path and SHA-256 metadata.
- The derived binary payloads were removed from both reconciliation
trees, while their source metadata was preserved.
EXECUTABLES-CONSOLIDATED.mdrecords disposition, and the repaired parent checksum sets pass at 323/323 and 1,066/1,066 entries:/Users/richh/Documents/Codex/2026-09-03/com/work/reconciliation-packets-20260903-0155/Users/richh/dev/_migration/conflicts/rdmbair15m5-20260903
- The isolated source branch is hardened at
3edaf52: tracked historical ZIP/TGZ/app/CLI/MCP payloads were retired, generated release payloads are ignored, andartifacts/plus the build-35 snapshot retain metadata and checksums rather than executable bodies. The dirty canonical checkout still contains the corresponding user-authorized deletions plus unrelated peer/user work; none of that canonical state was staged, committed, reset, or overwritten. Lead integration should take the isolated commit chain rather than restore the retired binaries.
One retained rollback package per host
All packages live under
~/Library/Application Support/ReplicantDB Cleanup Archives/replicantdb-1.19.1-build35-20260903-003346/
on their respective hosts.
| Host | Final package SHA-256 |
|---|---|
rdmsm4x |
3fa22a4e87277e81eb973c3930753015676ebd60ce42b06a30a450473a07a8c7 |
rdmbair13m5 |
018dfbfaf30a02ca411a4b66a9a8cca2db9e63e09f69858dc697472074d279d6 |
rdmbair15m5 |
77542e7e9154d41b977dd417eb6b2c37864fc6cf0c67403f49a773f81c31c9e6 |
rdmpw3265m |
d9ca8fe80bc8ed52b8ae029651342ff1eaee18bd43a96ed19d53103c5c1567ae |
rdmpw3275m |
94ffa4e1be803c36748868007120131856a7915a95808a6c228174ffdb08d02c |
jdmbair13m5 |
41722e8051fada52a2dca0bdfe11af534edc610eb995ef6568f3ed54c201c412 |
Commands and verification evidence
swift test: 1,095/1,095 tests, zero failures, exit 0. Accepted full-run log SHA-256:9e45719c1f6ce9752793ed154168b86d945ac2938ac05d27b553ea4620fe545d../build.sh: completed for the versioned source tree.- Exact artifact hashes:
- app executable:
3751650cfde840402a683de6f9a42ac218155a0ac259f7ac87d8abe8e66867a0 - CLI:
2fcd322292818d31ff592032f26eae49a9a8076831149a178bc551fdfe676ebf - MCP:
2d1c988f87a38f34b2791ab748af7c77c11a8b452f58076dd8e91107e6baf536 - immutable application archive:
d01755ae99d8fb92efb32efa56f5177e2c9e4483f117d4f61c456e50d1d51e31
- app executable:
- Transactional staging/install tools validated the immutable source, old-state backup, exact replacement, GUI launch, CLI execution, parsed two-message MCP initialization, daemon state, and rollback readiness.
replicantdb-consolidate-copies.zshran manifest-bound preflight/execute/verify, then the final verify re-extracted the complete package and compared every inventory record.replicantdb-extend-cleanup-archive.zshpassed syntax checks and 8/8 private-root fixtures, including unsafe path/hash/archive rejection, four-path source-host handling, inventory reuse, and FileProvider disappearance after prepare. Production actions ran in the globalprepare,remove,verifyorder.replicantdb-archive-historical-releases.zsh(SHA-256738491e7180120083fd16541116e0e8424311bd3179de25ce6a573e94b5c3c15) passed 10/10 fixtures covering exact-manifest and hash enforcement, link/path/archive-member rejection, active-artifact exclusion, content deduplication, package readback, prepare-before-delete, quarantine, atomic replacement, and the one-package invariant.- The final exhaustive discovery scanned explicit application, executable, development, migration, rollback, cache, cloud-storage, Documents/Codex, Spotlight, LaunchServices-adjacent, mounted-image, launch-agent, launchd, shell-resolution, and Background Items surfaces.
- Final census on every host: one
/Applications/ReplicantDB.app; two regular single-link canonical~/binexecutables; one rollback.tgz; no other matching executable/installer copy, symlink, hard link, mounted image, noncanonical launch agent, or Background Items record. - Strict
codesign --verify, Team identity,lipo -archs,xcrun vtool -show-build, actual CLI, parsed MCP initialization, Swift/AppKit LaunchServices lookup, exact GUI PID, daemon target, andsqlite3 -readonlyplusPRAGMA query_only=ONprobes passed on all six hosts. - Read-only final row counts:
rdmsm4x2,086,336;rdmbair13m5585,681;rdmbair15m53,875,125;rdmpw3265m1,209,515;rdmpw3275m4,407,433;jdmbair13m50. - The source-host seven-minute comparison improved from a 1,968 MB physical-footprint peak for the old 1.19.0 GUI to about 60 MB for build 35 against the same live corpus. This accepts the identified duplicate-hydration fix for fleet testing, not long-duration memory behavior.
- Full receipt:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.1-build35-rollout-20260903/evidence/REPLICANTDB-1.19.1-BUILD35-FLEET-ROLLOUT-20260903.md. - Final discovery ledger:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.1-build35-rollout-20260903/evidence/copy-discovery-post-cleanup/SHA256SUMS. - Final verification ledger:
/Users/richh/dev/_handoff/codex-out/replicantdb-1.19.1-build35-rollout-20260903/evidence/final-verification/SHA256SUMS.
Data and process boundaries
- No scan, OCR request, classification, hash request, tagging, deduplication, file move, watched-folder registration, CloudKit operation, or live-database write was issued.
- Live databases were queried read-only only. No indexed path/content was copied into this record.
- At the 04:04 EDT process recapture, three already-open tasks on
rdmsm4xand one onrdmbair15m5still held the deleted old MCP inode; ten of the 14 previously observed children had already ended naturally. Their filesystem path is absent; all current Codex and Claude configuration points to the build-35 binary. Parent agent tasks were deliberately not killed, so the remaining inherited child processes will end with their owning tasks. - The FileXen recovery concept was retained as historical product research only. No stale worktree or conflicting transfer-engine/credential/IoT scope was merged.
Undo and rollback
Do not restore automatically. On the affected host, first verify the
package SHA-256 above, stop only ReplicantDB processes owned by the
restoration, and extract the package into a new private temporary
directory. Read its metadata/inventory.json and
metadata/RESTORE.md; restore only an explicitly approved
exact target whose destination is absent. Never overwrite the active
app, canonical CLI/MCP, live database, source checkout, another agent's
worktree, or current configuration. Re-register an approved restored app
individually and then re-run exact artifact, signature, LaunchServices,
GUI/daemon-state, and read-only database probes. Configuration rollback
copies are in the per-host backup directory named above.
Outstanding owner/lead actions
- The designated ReplicantDB lead should review and integrate isolated
branch
codex/replicantdb-memory-bounds-20260902through3edaf52; canonicalmainwas not merged or pushed, but its dirty checkout contains the cleanup-driven tracked-distribution deletions beside unrelated preserved work. - Keep
ISSUE-20260901-26open until a comparable long-duration, workload-normalized memory window passes without restart masking. - Address the separate abandoned Vision/IOSurface worker risk and
macOS 27 reentrant
NSTableViewdelegate warning. - Obtain a matching ReplicantDB macOS provisioning profile and prove a real CloudKit round trip before enabling restricted CloudKit entitlements.
- Developer-signed private fleet testing is complete; Developer ID notarization, public distribution, and any production release remain separate gates.
Apple Notes publication
- The Aqua-session publication attempt begun at 03:58 EDT exited 1 after the Notes store remained unresponsive for the helper's full 600-second guard. No Apple Notes success is claimed, and no duplicate retry was started during this handoff. This Markdown file remains the durable archive copy.
- Retry from an interactive
rdmsm4xTerminal session after Notes responds:zsh /Users/richh/scripts/notes_changelog.zsh /Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260903-0257-replicantdb-1-19-1-build35-fleet-rollout-cleanup.md.