Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260903-2146-fleet-repo-consolidation-sync-and-p0-fixes

rdmsm4x-changelog-20260903-2146-fleet-repo-consolidation-sync-and-p0-fixes

Session: claude@rdmsm4x (ecs0lib-6b) · Window: 2026-09-03 21:10 → 21:46 EDT · Host: rdmsm4x

Swept all 144 git repos under ~/dev: resolved two real divergences, archived the one duplicate working copy, cleaned nine dirty trees, unblocked and verified ecs0lib's four-platform gate, fixed two P0-class bugs, and synced every repo to its GitHub/fleet remotes. 22 commits across 14 repos.


Scope

Goal from Rich: every repo under ~/dev clean and consolidated on rdmsm4x, GitHub copies synced, conflicts resolved, apps rebuilt, bug list reduced. All actions pre-approved.

What changed

Sync and conflict resolution

Consolidation

Bugs fixed

ecs0lib four-platform gate: RED since 09-02 → GREEN

Builds

Repos cleaned (dirty → clean)

Repo Before Action
ai/LLM 4,166 mod / 56,561 untracked Ignored vendored LiteLLM (1.6 GB, 56k files) + per-run telemetry; untracked 309 tracked-but-ignored files; checkpointed Claude/ChatGPT archives. 60,727 → 105
fleet 85 / 733 Committed 36 MB of audit, overnight-health, tooling and TCC records — this repo exists to hold them
scripts 157 / 127 Committed the library; ignored zsh history backups, logs, pycache
sites/dev.ecs0.net 201 / 177 Published 187 generated ticket pages; merged PRs #3/#4 from origin
concepts/icloud-cleanup 37 / 38 Untracked a committed virtualenv; committed 16 uncommitted scanners; gitignored token.pickle (a Google OAuth token) rather than committing it
arista/arcedb 1 / 82 Closed a 2026-08-14 OPEN decision: gitignored 623 MB of archive/data artifacts, wrote DATA.md recording where the data lives, restored html/images.zip
docs, data, todo small Committed

Tickets

Owner actions required

  1. SEC-20260903-10 — rotate a credential. The dev.ecs0.net build refused to publish apps/dataROO/web-app/artifact/index.html, reporting credential-shaped content. That file is tracked in git since the initial commit and the blob is on the GitHub backup remote (confirmed by git merge-base --is-ancestor). No value was printed to any transcript or written to any file. Rotation is the fix; history rewriting does not invalidate an exposed key. The repo also has an origin-SHARED-DO-NOT-PUSH remote whose audience should be checked.
  2. ISSUE-20260903-41 — decide whether to gate ecs0lib changes on a consumer build sweep, make the existing ECS0LibraryManifest contract load-bearing, or adopt deprecate-then-remove.

Deliberately not touched

Mistake made and disclosed

git add -A scripts/ in sites/dev.ecs0.net swept another session's in-flight build_site.py change (+31/−1, a verify_published_site() function, mtime 21:12) into a commit about the wiki. The content is preserved and pushed — nothing lost, and the function works: it ran during the later site build and its HTTP probes returned 200. The defect is attribution: 7b80c42's message does not mention it. This is exactly the path-scoping rule I was applying elsewhere in the same session, and lib-44 had explicitly avoided touching that file for this reason. Every subsequent commit was path-scoped and mtime-checked first.

Verification

No secrets

No credential value was printed, logged, or committed. token.pickle and the dataROO finding were handled by exclusion and by a ticket recording shape and location only.