Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260909-1416-signing-fixed-tyrell16-replicantdb40-fleet-deploy

rdmsm4x-changelog-20260909-1416-signing-fixed-tyrell16-replicantdb40-fleet-deploy

Signing wall removed (fleet-signing keychain shadowed the login keychain) and releases signed + deployed fleet-wide: Tyrell 0.2.0 (16) on 5 hosts, ReplicantDB 1.19.5 (40) on 6 hosts, RTTy 502 tagged. Written 2026-09-09 14:16:28 EDT by claude@rdmsm4x (Fable 5.1) session_01L5FqUPjVWGsMbP4UhAqAa6; execution by two Opus 5 workers, evidence in each app's SESSION-STATE.md.

Signing wall fixed — 2026-09-09 13:28:48 EDT · rdmsm4x (DEC-20260909-02)

Rich: "please go ahead and fix the signing and sign releases and deploy them to the fleet." Cause (measured): ~/Library/Keychains/fleet-signing.keychain-db was FIRST in the user keychain search list and LOCKED; its password no longer matches FLEET_SIGNING_P12_PASSWORD (file rebuilt 2026-09-05 00:58, rollout script is 09-01). It holds a copy of the same "Apple Development: Richard Doty (S65Q255HA8)" identity as the login keychain, so every codesign resolved the identity to the locked copy → SecurityAgent prompt → errSecInternalComponent. The login keychain copy is unlocked (no-timeout) and works. That is Tyrell ISSUES #54's wall; the "asuser is not Aqua" hypothesis was wrong — it failed from a real Aqua session too. Fix (reversible): security list-keychains -d user -s login.keychain-db fleet-signing.keychain-db (login first). Verified: codesign --options runtime on a scratch binary rc=0, Authority=Apple Development, flags=runtime. Nothing deleted; fleet-signing keychain left in place, still locked. Spokes: all four reachable spokes show the same search order (fleet-signing first) and fail codesign the same way over ssh. Not changed — the hub signs everything the fleet installs. If a spoke ever needs to sign locally, apply the same one-line reorder there, or re-run fleet_signing_rollout.zsh install with the CURRENT secret. Fleet release map at 2026-09-09 13:28:48 EDT: Tyrell app CFBundleVersion 7 on all 5 reachable hosts, repo at Build 16 → rolling out (Opus worker, canary rdmbair15m5). replicantDB 38 on hub/rdmbair15m5/rdmbair13m5/rdmpw3275m, 39 on rdmpw3265m (canary), daemon unloaded on all hosts; HEAD has moved past the staged 39 (telemetry + hardened runtime + compile fix) → next is Build 40 from HEAD. RTTy Build 502: signed, hardened runtime, universal2, installed on all 5 reachable hosts — CURRENT, no deploy needed (audit's "no build since build41" is a missing git tag, not a missing build). jdmbair13m5 offline for everything.

Releases signed and deployed — 2026-09-09 14:16:28 EDT · rdmsm4x (follow-through on DEC-20260909-02)

App Before After Hosts Evidence
Tyrell.app CFBundleVersion 7 everywhere 16 (0.2.0), universal2, Apple Development + hardened runtime, DR hash 7467a4ae… preserved rdmsm4x, rdmbair15m5 (canary, receipt build16-20260909-133057), rdmbair13m5, rdmpw3265m, rdmpw3275m Tyrell SESSION-STATE.md 13:30–13:58; commits e37482f, 978368e (#73 Intel header fix), f2771fe
tyrelld stale on both Intel hosts rebuilt from f2771fe, restarted 13:55:52 / 13:57:05, /api/status 200 all 5 reachable deploy_fleet.zsh rc=0 both runs
tyrellbar on rdmbair13m5 absent (ISSUE-20260831-17) installed from the Build 16 bundle, running rdmbair13m5 install_tyrellbar_agent.zsh rc=0
ReplicantDB 38 ×4, 39 on rdmpw3265m, 37 on jdmbair13m5 1.19.5 (40) "Restraint" — first hardened-runtime ReplicantDB ever; 1213 tests 0 failures; C1–C8 all PASS all six hosts (jdmbair13m5 reached via .local) replicantDB commits d61acf7…1a4ac47, tag v1.19.5-build40 at 5ca2e30; build.sh hardened-runtime assertion fixed (grep anchored at ^ never matched)
RTTy 502 everywhere, already signed/hardened/universal unchanged; tagged v0.3.827-build502 at 3f33fc7 5 reachable audit's "no build" was a missing tag

Undo