Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260903-0539-replicantdb-build36-fleet-rollout-cleanup

ReplicantDB 1.19.2 build 36 is deployed and launched on all six Macs, and archive-first cleanup leaves one unambiguous active app/CLI/MCP plus one verified recovery package per host.

Scope

Why this matters

Build 36 fixes an unbounded-resource mechanism: caller-side timeouts could return while synchronous Vision/ImageIO framework closures remained live, allowing subsequent files to dispatch more work. The release adds process-wide admission leases—four outer extraction workers and two Vision workers—and retains a timed-out worker's lease until it actually returns. Saturated timed-out capacity now fails closed rather than accumulating threads and IOSurface state.

The deployment also fulfills Rich's request to remove/archive prior app copies throughout the fleet. After a final from-scratch census, each host has exactly one active app, one canonical CLI, one canonical MCP, and one compressed recovery package; no other matching executable or installer copy remains in the searched operational, development, recovery, cloud, or release locations.

Exact source and files touched

Installed state changed

On all six hosts:

Commands and workflow

Verification evidence

Cleanup incident and repair

The first local cleanup stopped safely after archive creation when read-only signed-app contents prevented quarantine deletion. It resumed against the same archive only after verifying the preflight inode/mode/size/hash ledger and repaired permissions solely inside obsolete quarantine.

The first deep census then found three build-36 app bundles in private round-trip extraction directories left by shutil.rmtree(ignore_errors=True). Each path and app hash was validated against the already verified recovery archive, then the three temporary directories were removed. The verifier now makes its private extraction directories removable and fails if any residue remains. The read-only fixture and all eight existing safety fixtures pass. A brand-new full census then found no duplicate app copies.

Backups and rollback

Each host retains one safe-member-reviewed, fully extracted, inventory-backed rollback package:

Undo is manual and owner-reviewed: verify the local archive hash and embedded inventory, stop only owned ReplicantDB processes, extract to a new private temporary directory, and restore only explicit selected members to absent destinations. Never overwrite the active app, CLI, MCP, plist, live database, source checkout, or another agent's worktree. The installed build can also be replaced transactionally from a separately approved immutable artifact.

Outstanding owner/lead actions