rdmsm4x-changelog-20260903-2125-lib-root-repo-fleet-deploy-and-102gb-cache-reclaim
Put ~/dev/lib's five root documents under git,
recorded the missing test baseline, deployed the docs to four spokes,
archived verified-redundant spoke copies, and reclaimed 102.6 GB of
build cache — plus read-only credential and application inventories
across the fleet.
- When: 2026-09-03, 20:50:13 → 21:25 EDT (~35 minutes)
- Host:
rdmsm4x(canonical dev root). Four spokes written;jdmbair13m5unreachable. - Agent:
claude@rdmsm4x, session9b884bd7/lib-44 - Tickets:
INC-20260903-01,INC-20260903-02,TASK-20260903-33,TASK-20260903-34 - Budget posture at start:
usage_status→hold(OpenAI weekly 100%, vendor-authoritative; Anthropic 48.7%). Branched onadvice, not the percentage: no delegation, no codex, no agy, no subagents. All work inline.
1. Why
Rich approved git init on the lib domain root — the five
root documents had no version history at all while every meaningful
subdirectory had its own repo, and the CLAUDE.md rewritten
earlier the same day existed on disk in exactly one copy. Scope was then
widened across four further messages to a fleet-wide deploy, build
verification, stale-copy cleanup, a credential-store inventory, and an
application/build cleanup.
2. What changed
~/dev/lib
is now a git repo — five documents only
.gitignore opens with /* and re-includes
CLAUDE.md, README.md, index.html,
SESSION-STATE.md, LIBRARY-CANDIDATES.md and
itself by name. Git never descends into a subdirectory, which matters
because nine of them are their own repos and
arista/ alone is 5.4 GB. It is an inclusion list and
documented as one.
Verified: git status --short lists exactly six paths and
zero directories; --ignored accounts for all 14 remaining
root entries; git count-objects = 8 objects, 36 KiB.
This falsified two statements in CLAUDE.md itself, both
corrected in the same commit: it said "~/dev/lib itself is
not a git repo", and the directory map counted seven
subrepos and called apple-notes-api-key-inventory
unversioned. It is nine, and that directory is a repo.
Test baseline recorded — the gap the previous session flagged
Measured 2026-09-03 20:53 EDT, every suite rc=0:
| Package | Harness | Count | Failures |
|---|---|---|---|
ecs0lib |
XCTest
(ECS0LibTests.xctest) |
308 | 0 |
ecs0lib |
swift-testing (4 suites) | 12 | 0 |
ECSCloudKit |
XCTest | 22 | 0 |
agentkit |
test_agentkit.zsh |
13 | 0 |
agentkit |
test_integrity.zsh |
25 | 0 |
Each confirmed two independent ways — the harness summary line and a
recount of individual result lines. Session ecs0lib-6b
independently measured the same 308+12 at 20:07 EDT.
agentkit's README claimed 23 for
test_integrity; it is 25. Corrected in both files.
Fleet deploy — the spokes had none of these documents
No spoke had any of the five root documents. Agents
working lib on four hosts had no domain-level guidance at
all. Deployed additively (rsync, never
--delete) and verified by re-hashing on each host:
byte-identical on all four. Redeployed after the later edits; matched
again.
Stale spoke copies archived (Rich chose move-not-delete)
Verified redundant before moving —
ecs0lib 8805372 is a clean ancestor 9 commits behind
canonical; ECSCloudKit 93b9f70 is canonical HEAD;
app-baseline ad67745 is 1 behind; every
agentkit plain copy byte-identical to canonical HEAD~1.
| Host | Archived into
~/dev/archive/lib-stale-20260903/ |
Size |
|---|---|---|
rdmbair13m5 |
ecs0lib
ECSCloudKit app-baseline
agentkit |
2.8 MB |
rdmpw3275m |
ecs0lib
ECSCloudKit agentkit |
160 MB |
rdmbair15m5 |
agentkit |
40 KB |
rdmpw3265m |
agentkit |
40 KB |
Held back deliberately: t3code on
rdmbair15m5 (2 uncommitted changes), ECSMemory on
rdmpw3275m (unique + actively written), xcode-config
everywhere (deliberately distributed).
102.6 GB of build cache reclaimed on rdmsm4x
101 .build directories under _worktrees and
_handoff. Validated before deletion: every path ends in
/.build under those two trees (0 failures), every parent
still holds
Package.swift/Sources/.git (0
missing), nothing modified within 3 hours.
removed=101 failed=0; 0 remain; 135 of 140 worktrees retain
sources and the other 5 are container directories whose children all
retain theirs.
Snapshotted first: the newest built products living
inside those caches were copied to
~/dev/archive/build-products-20260903/ — Tyrell
build 15 (ahead of the installed build 7) and ScanRoo
build 1, 63 MB total.
~/dev/apps/Tyrell/.build was excluded: its mtime moved
to 21:05, mid-session. Something is building Tyrell.
Four-platform build gate — run and passed, for the first time
Once the licence was accepted, the gate documented in
lib/CLAUDE.md (which had never actually been executed) was
run for both shared packages:
| Platform | ecs0lib triple |
ECSCloudKit triple |
SDK |
|---|---|---|---|
| macOS | arm64-apple-macos15.0 |
arm64-apple-macos14.0 |
MacOSX27.0 |
| iOS | arm64-apple-ios18.0 |
arm64-apple-ios17.0 |
iPhoneOS27.0 |
| tvOS | arm64-apple-tvos18.0 |
arm64-apple-tvos17.0 |
AppleTVOS27.0 |
| visionOS | arm64-apple-xros2.0 |
arm64-apple-xros1.0 |
XROS27.0 |
Eight builds, all rc=0, all with real compilation
(110–134 Swift compile tasks for ecs0lib, 15–30 for
ECSCloudKit). The differing floors are correct and
deliberate.
A ninth trap, found here: the first iOS leg reported
BUILD SUCCEEDED from a 99-line log with zero
SwiftCompile tasks — an incremental no-op,
indistinguishable from a real pass by exit code. The clean rebuild
produced 1,847 lines and 134 tasks. Count compile tasks or pass
clean; rc=0 is not evidence that a platform
compiles. Same defect class as swift build silently
ignoring --triple.
Pending PRs — all 7 merged, 0 open
Seven were open across Rich's repos; all seven are merged. The first
per-repo sweep reported zero and was wrong — the repos
holding them are not checked out under the paths scanned. Caught only by
a positive control (--state all on ecs0lib returned 4). The
final zero was re-confirmed the same way.
The cvedb pair was a content migration, so the destination merged first, source second — the 712-line design file was never absent from both repos. Verified after: 36 KB in the destination, source reduced to a 1,187-byte signpost.
Two I declined and then merged, because the objections did not survive inspection:
eastcoastsicence#1— I said merging would put deploy/TestFlight automation live. It would not: both areworkflow_dispatch, and the author wrote why — "Manual trigger so the first deploy is deliberate rather than a surprise from a merge." The.tar.gzI refused unexamined is 1,206 bytes, checksummed, documented as blocking nothing. The missing secret gates the deploy, not the merge.rdmsm4x-dev-apps-replicantdb#3— its gate is an owner release; Rich is the owner and instructed integration. Signing and canary gate deployment, not the merge. Nothing was built or installed.
My error, corrected publicly: the dev#3
merge message claimed docs-only. It contains three scripts my own
pre-merge check had printed and I read past. Corrected in a PR
comment.
The dev-ecs0-net P0 is diagnosed, not fixed.
json.dumps() output interpolated straight into the single
inline <script>; json.dumps does not
escape <, so a harvested literal
</script> closes the tag and the router never starts.
Not applied — 403 dirty paths in that repo and another session had the
file open with uncommitted changes 21 minutes earlier.
Fleet re-deploy — what shipped, and what did not
Shipped: the five lib root documents
(three times as they changed) and
agentkit, which had been archived off the
spokes earlier with nothing put back. Verified by running the suites
on each host — 13 + 25 passing on all four, both
Intel machines included — not by checksum.
No application binary was built, installed or shipped,
because the premise did not hold: the fleet is already uniform.
Every reachable host carries identical versions — AINetNode 1.0.0/1,
LogTTY 0.1.1/19, ReplicantDB 1.19.3/37, RTTy 0.3.826/48, Tyrell 0.2.0/7,
updateRoo 1.0.0/1 — all x86_64 arm64, all signed Apple
Development: Richard Doty (ZU2882L4HT), all passing
codesign --verify --deep --strict. There is no drift to
correct. All five are uniformly one build behind artifacts that have not
been released, and promoting those is a release decision.
One real defect found: rooDB.app is
ad-hoc signed (Signature=adhoc,
TeamIdentifier=not set) on all three hosts carrying it —
the documented cause of a TCC re-prompt every launch.
ISSUE-20260903-42.
A probe that lied, worth keeping:
codesign -dv does not print
Authority= lines, so a properly signed app looks unsigned.
It made all six apps read as UNSIGNED in the first pass. Use
-dvvv, or --verify --deep --strict and check
the exit code.
Two
findings from session ecs0lib-6b, verified before
recording
- The Xcode licence is accepted on rdmsm4x. Two sessions accepted it independently inside 30 minutes, each acting on a note the other had already made stale. Now recorded as state.
- A green gate does not mean the consumers are green.
23 consumers built: 22 rc=0, one real break.
LogTTYfailed onrxBytes→receiveQueueOccupancyBytes— names that read as synonyms and are not (cumulative transferred vs. queued right now). A mechanical rename compiles and reports queue depth as a traffic total.ISSUE-20260903-41; fixed inLogTTY0fb7222. - Correcting my own numbers: I reported 110–134 compile tasks; only the iOS figure was a clean build. Clean is 134 per platform; the lower figures were incremental and not comparable — the same trap documented above, hit while documenting it.
3. Verification evidence
| Claim | Check | Result |
|---|---|---|
| Root repo scope | git ls-files /
status --ignored / count-objects |
6 paths, 14 ignored, 8 objects 36 KiB |
| Docs deployed | re-shasum on each spoke |
byte-identical ×4, twice |
| Archived copies redundant | merge-base --is-ancestor,
shasum per file |
9 behind / identical / 1 behind / byte-identical |
| Cache list safe | path-shape + parent-source assertions | 0 failures, 0 missing |
| Sources survived | .git/Package.swift/Sources
per worktree |
135/140 + 5 containers OK |
| Untouched caches intact | ls -d apps/Tyrell/.build lib/ecs0lib/.build |
both present (positive control) |
xcodebuild broken |
real build invocation |
rc=69, licence not agreed |
| Credential survey | mdfind + bounded
find, both counts printed |
probes live, not blind |
4. Traps hit — all caught, all worth keeping
- I parsed my own grep output as test output. The
background log held only
tail -40plus my own count lines, so "Executed 18 / 308 tests" were my echoes, not the harness. Fixed by capturing the full log and counting from it. ecs0libruns two harnesses in oneswift test. Tailing shows "Test run with 12 tests" and silently drops the 308.xcodebuild -versionreturns 0 while every build returns 69. The obvious health probe reports a healthy toolchain.set -e+(( n++ ))aborts on the first success — post-increment returns the old value 0, a false status. The archive script moved one directory per host and stopped silently.- An empty
gh pr listsweep looked like "no open PRs". A positive control (--state allon ecs0lib → 4 PRs) proved the probe worked and the repo list was wrong. There are 7 open PRs. ~/**/*.kdbxwalked the whole home directory and timed out at 2 minutes. Replaced with Spotlight plus a boundedfind, printing both probe counts.- My own omission: I showed Rich a candidate list
that left out
agentkiton rdmpw3275m, an item I had already verified byte-identical. Archived after, and disclosed. - The deletion job "failed" with exit 1 — but the deletion succeeded. The failure was my verification line using a zsh glob qualifier in a non-zsh shell, so the destructive half ran and the check did not. Re-ran the check separately.
5. Backups / how to undo
- Spoke copies: one
mvper directory out of~/dev/archive/lib-stale-20260903/. Nothing deleted. - Build products:
~/dev/archive/build-products-20260903/(Tyrell build 15, ScanRoo). - Build caches: deleted, not archived — moving them would free nothing, which was the point. 100% regenerable; every source tree verified intact first. Cost is one slow rebuild each.
- Commits:
git -C ~/dev/lib revert fd1f0eb 1e98858 592fa21;git -C ~/dev/lib/agentkit revert HEAD. - Deletion list preserved at
<scratchpad>/build-cache-delete.listfor audit.
6. Outstanding owner actions — all three need Rich
— RESOLVED at 21:06 bysudo xcodebuild -licenseagy@rdmsm4x, two minutes afterINC-20260903-02was filed. Re-tested rather than trusting the resolution:xcodebuildreturns rc=0 where it returned 69. The four-platform gate was then run for the first time and passed for both packages — see §2.jdmbair13m5SSH key (INC-20260903-01). Refusesrichhpublickey from rdmsm4x, a regression against the 2026-08-23 both-ways verification inFLEET.md. It was excluded from every part of this session's fleet work.- Keychain inventory needs a keyboard. Rich asked for
a contents inventory of the four orphan
login_renamed_{1..4}.keychain-dbon rdmpw3265m. Impossible over SSH —securityreturns rc=36 "User interaction is not allowed" for every keychain on that host, including the live one. Nothing was unlocked or read. Partial answer without unlocking: those four are not in the keychain search list, so nothing consults them.
Also for a lead, not for cleanup automation:
ECSMemoryon rdmpw3275m is unpromoted, unique and live (TASK-20260903-33).- Installed apps are older than what has been built —
/Applications/Tyrell.appbuild 7 vs build 15,ReplicantDB37 vs 38,LogTTY19 vs 21. Nothing was installed; promoting a build is an app-lead decision, not a cleanup side effect. - PR #4 on
dev-ecs0-netsays one thing and does another — body claims "adds the datedISSUES.mdentry only", diff is ≥100 files includingscripts/,config/,tests/,.gitignoreand 86 assets.MERGEABLE/CLEAN, so it would merge quietly. Not merged; it is explicitly agy's to resolve. ~/.secrets/global.envdiverges 6/5/2/2/2 across hosts (TASK-20260903-34).
7. Secrets
None written, and none read. The credential survey
collected paths, sizes, modification dates and file permissions only. No
keychain was unlocked, no vault opened, no value read, printed or
copied. xcode-config/ holds team IDs and signing identities
— identifiers, not secrets.