rdmsm4x-changelog-20260905-1653-devupdate-cask-greedy-latest-switch
rdmsm4x-changelog-20260905-1653-devupdate-cask-greedy-latest-switch
Revised all fleet maintenance and update scripts to use
brew upgrade --greedy-latest by default instead of full
--greedy, preventing automated wipes of
auto_updates true application bundles (such as Google
Chrome), preserving macOS Notification Center and TCC permissions; added
--greedy override flags to dev_update.zsh.
Scope
- Hosts affected: rdmsm4x (and fleet-wide via centralized update tooling in ~/bin and ~/dev/scripts)
- Tooling: Homebrew Cask update pipelines across
dev_update.zsh,fleet_update.zsh,fleet-dev-update.zsh,mac_fleet_library_updates.zsh,macos-update.sh,omnibus_maintenance.sh, andfleet-modernize.zsh.
Rationale
- When Homebrew Cask upgrades an app marked
auto_updates trueusing--greedy, it unlinks and replaces the entire.appbundle from the downloaded DMG. - This creates a new filesystem inode, invalidates LaunchServices
registration tokens, and forces macOS
usernotificationsdand TCC to treat the app as an unverified/fresh installation, causing persistent prompts to re-authorize notifications on Google Chrome and other apps. - Switching to
--greedy-latestensures unversioned casks (version :latest) are still upgraded, while casks managing their own delta updates (Chrome, 1Password, Slack) update gracefully in-place via their native mechanisms without dropping system authorizations.
Exact Changes Made
/Users/richh/dev/scripts/dev_update_v1.96.zsh(symlinked via~/dev_update.zshand/Users/richh/dev/scripts/devupdate.zsh):- Added
--greedyand--greedy-latestflags to top-level CLI argument parsing (FU_DU_PASS) and usage documentation. - In the embedded
dev_update.zshpayload:- Set default
CASK_GREEDY=0(--greedy-latest). - Added CLI flag parsing for
--greedy(CASK_GREEDY=1) and--greedy-latest(CASK_GREEDY=0). - Dynamically selects
brew outdated --cask $cask_greedy_flagandbrew upgrade --cask $cask_greedy_flag. - Recalculated payload SHA256
(
28467549c5c5cbb1a44237921cf68c0a24fb962b2fcec1df14e885e7226154a7) and verified payload materialization via--verify-embedded.
- Set default
- Added
/Users/richh/bin/fleet_update.zsh:- Added flag parsing defaulting
GREEDY_FLAG="--greedy-latest". - Allows explicit
--greedyargument override if requested. - Updated step invocation to
run "brew upgrade $GREEDY_FLAG" brew upgrade "$GREEDY_FLAG".
- Added flag parsing defaulting
/Users/richh/bin/fleet-dev-update.zsh:- Added flag parsing defaulting
GREEDY_FLAG="--greedy-latest"with--greedyoverride. - Updated step invocation to
step "brew upgrade ($GREEDY_FLAG)" brew upgrade "$GREEDY_FLAG".
- Added flag parsing defaulting
/Users/richh/dev/scripts/mac_fleet_library_updates.zsh:- Updated line 128 to
run_step "Homebrew Upgrade (Greedy-Latest)" "brew upgrade --greedy-latest" 180.
- Updated line 128 to
/Users/richh/dev/scripts/macos-update.sh:- Updated line 423 to
step "Upgrade unversioned casks (brew upgrade --greedy-latest)" brew upgrade --greedy-latest.
- Updated line 423 to
/Users/richh/dev/scripts/omnibus_maintenance.sh:- Updated line 92 to
brew upgrade --greedy-latest 2>&1 | tee -a "${LOG_FILE}".
- Updated line 92 to
/Users/richh/dev/scripts/fleet-modernize.zsh:- Updated line 370 to
DEP_CASKS="$(brew outdated --cask --greedy-latest 2>/dev/null | wc -l | tr -d ' ')".
- Updated line 370 to
Verification Evidence
zsh -nandbash -nsyntax checks passed across all modified scripts./Users/richh/dev/scripts/dev_update_v1.96.zsh --verify-embeddedverified clean payload materialization and sha256 integrity./Users/richh/dev_update.zsh --helpconfirms new--greedyand--greedy-latestflags appear in usage.
How to Undo / Override
- To run a one-off full greedy upgrade: run
dev_update.zsh --greedyorfleet_update.zsh --greedy. - To revert defaults: git checkout
/Users/richh/dev/scripts/or restore from/Users/richh/dev/scripts/dev_update_v1.96.zsh.bak-20260905-pre-greedy-latest.