rdmsm4x-changelog-20260922-1911-fleet-remainder-ci-repair
Fleet remainder and GitHub Actions reconciliation
Captured 2026-09-22 on rdmsm4x. Owner: codex@rdmsm4x/01a0cb33; TASK-20260922-06.
Scope and outcome
Read-only inventory reached rdmbair13m5 (25 repository roots), rdmpw3265m (33), rdmpw3275m (35), and jdmbair13m5 (19): 112 discovered roots plus their listed worktrees. Scanned project areas were apps, lib, sites, fleet, scripts, _ops and agy, bounded to three discovery levels and excluding generated/archive trees. This is a repository/source census, not a whole-disk backup audit.
All 87 distinct branch tips outside canonical main are already reachable from refs in the matching rdmsm4x repositories. There is no newly unique spoke-only Git tip in that inventory. This does NOT mean every historical branch should be merged: preserved/checkpoint refs and the broader 253-branch review remain with the existing TASK-20260916-04 owner. Git status/stash inventory found no dirty work in valid checked repositories, but no-HEAD directories require separate file checks.
Those file checks found two empty Intel t3code/tokenbar roots and one
meaningful firmwaredb.app website source tree without a Git HEAD. Its 38
non-generated source files were preserved with provenance and SHA-256
manifest under
/Users/richh/dev/_migration/conflicts/rdmpw3275m-20260922-firmware-site;
30 match canonical and eight differ or are absent. Local .wrangler
state, node_modules, credentials and .git were excluded. The original
dangling commit fc6c9a9f6c93e24bf24cd1ad66f6ac7ad35da0a8
was subsequently recovered; all 38 files match its tree. That history is
bundled and published as
preserve/rdmpw3275m-firmware-site-20260922 to fleet and
GitHub after a zero-finding history scan. A curated acceptance excludes
the fabricated version mapping and unverified aliases; the original
commit is preserved rather than blindly merged.
Accepted source
| Project | Accepted canonical commit | Validation / publication |
|---|---|---|
| lib/xcode-config | 07ca14c1dd63f70ae2dd3a7b9a7b4478d710574d | ZIP integrity, plist/text structure and secret scan passed; private fleet head verified. No device registration performed. |
| apps/RDnamed | 8e0b14248d7ccde345c92da1787d7e93b6bb9001 | Seven unit tests, four CLI acceptance cases; GUI compiled. Fleet and owned GitHub heads verified. Export refuses missing address mappings; simulation explicit. |
| apps/firmwaredb | f6d20e57bb87f3b15738c33cd40b87aea0019154 | 207 tests, unsigned build, diff check and incoming history secret scan pass. Fleet + GitHub heads verified. Misleading Google live mode corrected to fixture-preview-only. |
| lib/t3code | 13b9b294597631b6295684f8029bedf83650cfb2 | actionlint passes; fleet + owned GitHub heads verified; actual new run uses supported hosted labels. GitHub billing blocks execution. |
| sites/firmwaredb.app | 426a8d0481a79e3be37d4a9afc1ed74683b4ecd7 | Clean npm ci, 67 tests / 10 files, TypeScript build and history secret scan pass. Fleet + GitHub exact SHA verified. Curated source; no deployment. |
FleetContainers ca48d09 is already patch-equivalent to canonical 058f5a3; reapplying it would revert newer continuity content. Retained as provenance. Earlier games/library and other peer publication receipts were independently read back: 28/28 receipt checks matched expected remote heads (some aliases repeat the same target).
Exact changed paths are in changed-files.json. No production signing, notarization, app installation, site deployment, device registration, Google account data access or database mutation was performed.
GitHub failures
Read-only census: 398 active owned repositories, five with Actions run history, no API census errors. A fresh owned-repository open-PR search returns zero open PRs. Local branch integration debt is separate from open PR count.
- Runner routing fixed: owned T3 mirror referenced upstream Blacksmith runner labels, leaving work queued. Its CI now chooses ubuntu-24.04 and macos-26 for richhdoty/t3code while preserving upstream labels elsewhere. No test jobs were removed. Workflow syntax validated with actionlint. Run https://github.com/richhdoty/t3code/actions/runs/35794967570 selected the intended labels, then all nine jobs were refused before steps for billing. Full application test suite was not rerun for this YAML-only repair.
- Account billing is unresolved: Tyrell and TokenBar also have jobs refused before steps with GitHub's payment/spending-limit annotation. The exact cause (payment problem versus usage/budget) cannot be read with current CLI scopes; browsers are signed out. The user has been asked to sign in. No plan, spending limit, payment information or OAuth scope changed. ISSUE-20260918-01 tracks the billing block. Existing ECS_LIBS_TOKEN is present; an old missing-secret ticket premise was updated, but its capability cannot be proved until jobs run.
- Deployment credentials are absent: richhdoty/eastcoastsicence and richhdoty/rdmsm4x-dev-sites-eastcoastscience.com fail Check credentials because CLOUDFLARE_API_TOKEN is absent from both repository and production-environment secret lists. Canonical project content identifies the deployment as routed.info. No suitable scoped token was found by key-name lookup; broad global and unrelated DDNS credentials were not substituted. ISSUE-20260922-07 records the scoped credential/authoritative deployment repository gate. No public deployment was triggered.
Disabled inherited upstream-only publisher workflows: T3 Release (363798870), T3 Deploy T3 Connect relay (363798841), TokenBar Update install count (363799096). These were unrelated to testing the owned mirrors; CI remains enabled. Before/after state is in publisher-workflow-state.json. Six superseded queued T3 runs were cancelled, not running production deploys.
Subscription conclusion: an upgrade is not yet justified. GitHub's annotation supports a billing restriction, not a diagnosis of the current plan. Payment/budget inspection comes first; a plan upgrade would not repair missing deployment tokens or unregistered runner labels. See official product billing guidance: https://docs.github.com/en/billing/concepts/product-billing/github-actions and locked account troubleshooting: https://docs.github.com/en/billing/how-tos/troubleshooting/locked-account .
Preservation and undo
Original spokes retained. Worktrees and recovery source retained.
Pre-integration refs: refs/reconcile/remainder-20260922/before
(xcode-config, RDnamed, firmwaredb); refs/reconcile/ci-20260922/before
(t3code). Restore behavior with reviewed revert commits; do not reset
shared main or force-push. Disabled workflows can be restored with
gh api --method PUT repos/OWNER/REPO/actions/workflows/ID/enable;
original states are recorded. Cancellation of superseded runs is not
reversible, but their run history remains and a fresh workflow run can
be dispatched deliberately after billing is fixed.
Homebrew installed actionlint 1.7.12 and shellcheck 0.11.0 for validation. One existing Luna worker handled bounded source inventory/review/tests; no additional agent fan-out, paid services or model subscriptions. Budget advice was proceed before delegation.
Durable record
Apple Notes entry in rdmsm4x folder: rdmsm4x-changelog-20260922-1911-fleet-remainder-ci-repair (verified title and body in native UI). File archive is saved under /Users/richh/dev/LLM/Claude/changelogs/ with the same title. Final website acceptance and peer verification are recorded below.
Broader canonical sweep — independently checked publication
Peer TASK-20260916-04 published 21 repositories; all 50 configured main-ref receipt checks match on independent readback. Evidence: peer-combined-publication-check.json. Peer reports Tyrell integration and rdKIPP builds completed; this task verified their publication, not rerun their tests.
Four backup content-scan gates remain under that owner: fleet, maintenance, _ops and eastcoastscience.net. No scanner bypass or history rewrite was used. XEntropy's three pending feature tips were rejected by independent review for overly broad OTP access and simulated/no-op transports reporting success; ISSUE-20260922-08 records the exact boundaries and tests required before acceptance. These branches are preserved, not merged. No live exposure was inferred from a source finding.
Corrected completion records and acceptance boundaries
FEAT-20260905-35 and its parent EPIC-20260905-04 reopened because live Google ingestion was never implemented. The native UI now states that accurately. ISSUE-20260922-09 tracks pre-existing mixed OS-version/build CVE comparison semantics in the website; the newly recovered arithmetic mapper is rejected. Synthetic acceptance catalogue/CVE rows remain isolated test fixtures. This source intake does not certify live advisory accuracy or release readiness. PROJECTS.md was updated with accepted milestones and RDnamed’s stale zero-code row corrected; its preimage is preserved in PROJECTS-before.md.
Final website acceptance — 2026-09-22 19:23 EDT
Accepted 426a8d0481a79e3be37d4a9afc1ed74683b4ecd7 after
source review, clean install, all 67 tests and build. Both owned remote
main heads match canonical; the canonical tree is clean. Source changes
preserve parser repairs and multi-field identifier lookup; no guessed
OS/build mapping or unsupported hard-coded model aliases were accepted.
Version comparison code, package.json ranges and production migrations
are unchanged. Sample CVE rows reside only under
test/fixtures/acceptance_catalog.sql. The lockfile is repaired, with
clean-install evidence captured on Node v26.9.0 / npm 11.19.1. See
firmware-site-integration.json and firmware-site-validation.log.
Accepted source is published; CI remains blocked externally. TASK-20260922-06 remains blocked for billing and scoped deployment credentials, with the source portion completed. Owner sign-in is required for billing inspection; no subscription upgrade is recommended solely from the observed failures. No automated retries or spend changes were enabled.
Exact project files touched
t3code
- .github/workflows/ci.yml
xcode-config
- ISSUES.md
- SESSION-STATE.md
- device_registration/Apple_dev_account_Multiple-Upload-Samples.zip
- device_registration/eastcoastscience-register-devices.deviceids
- device_registration/eastcoastscience-register-devices.txt
RDnamed
- ISSUES.md
- SESSION-STATE.md
- STATUS.md
- Sources/RDnamedApp/RDnamedApp.swift
- Sources/RDnamedKit/Exporters.swift
- Sources/rdnamed/main.swift
- Tests/RDnamedKitTests/RDnamedKitTests.swift
- Tests/cli_acceptance_test.sh
- docs/test_portal.html
firmwaredb
- ISSUES.md
- Package.swift
- SESSION-STATE.md
- Sources/FirmwareDBKit/CLI/Commands/DumpCommand.swift
- Sources/FirmwareDBKit/CSV/InventoryCSVEngine.swift
- Sources/FirmwareDBKit/Client/EdgeSyncService.swift
- Sources/FirmwareDBKit/Compliance/ComplianceEvaluator.swift
- Sources/FirmwareDBKit/Engines/CSVInventoryEngine.swift
- Sources/FirmwareDBKit/Hardware/IORegistryObject.swift
- Sources/FirmwareDBKit/Hardware/SystemProfilerParser.swift
- Sources/FirmwareDBKit/Harvesters/BluetoothTraceHarvester.swift
- Sources/FirmwareDBKit/Harvesters/DeviceDeduplicator.swift
- Sources/FirmwareDBKit/Harvesters/GmailReceiptHarvester.swift
- Sources/FirmwareDBKit/Harvesters/GoogleDriveHarvester.swift
- Sources/FirmwareDBKit/Harvesters/GoogleOAuthFramework.swift
- Sources/FirmwareDBKit/Harvesters/GooglePhotosHarvester.swift
- Sources/FirmwareDBKit/Harvesters/LocalTraceHarvesterProtocol.swift
- Sources/FirmwareDBKit/Harvesters/MobileSyncBackupHarvester.swift
- Sources/FirmwareDBKit/Harvesters/MockGoogleCloudServicesClient.swift
- Sources/FirmwareDBKit/Harvesters/PhotosEXIFHarvester.swift
- Sources/FirmwareDBKit/Harvesters/USBThunderboltHarvester.swift
- Sources/firmwaredb-app/AppState.swift
- Sources/firmwaredb-app/Components/CategoryOverviewCard.swift
- Sources/firmwaredb-app/Components/ComplianceBadgeView.swift
- Sources/firmwaredb-app/Components/SubsystemAccordionItem.swift
- Sources/firmwaredb-app/FirmwareDBApp.entitlements
- Sources/firmwaredb-app/FirmwareDBApp.swift
- Sources/firmwaredb-app/Models/InventoryGroup.swift
- Sources/firmwaredb-app/Navigation/AppSidebarView.swift
- Sources/firmwaredb-app/Navigation/DeviceContentListView.swift
- Sources/firmwaredb-app/Navigation/MultiplatformRootView.swift
- Sources/firmwaredb-app/Services/EdgeSyncService.swift
- Sources/firmwaredb-app/Views/CSVImportModalView.swift
- Sources/firmwaredb-app/Views/CloudIntegrationsView.swift
- Sources/firmwaredb-app/Views/ComplianceExportModalView.swift
- Sources/firmwaredb-app/Views/DeviceDetailInspectorView.swift
- Sources/firmwaredb-app/Views/FleetAuditView.swift
- Sources/firmwaredb-app/Views/GoogleSettingsView.swift
- TEST_READY.md
- Tests/FirmwareDBKitTests/BluetoothHarvesterTests.swift
- Tests/FirmwareDBKitTests/CSVEngineTests.swift
- Tests/FirmwareDBKitTests/ChallengerStressTests.swift
- Tests/FirmwareDBKitTests/ComplianceEvaluatorTests.swift
- Tests/FirmwareDBKitTests/DeviceDeduplicationTests.swift
- Tests/FirmwareDBKitTests/E2EAcceptanceTests.swift
- Tests/FirmwareDBKitTests/EdgeSyncServiceTests.swift
- Tests/FirmwareDBKitTests/GoogleConnectorTests.swift
- Tests/FirmwareDBKitTests/M2AdversarialStressTests.swift
- Tests/FirmwareDBKitTests/M2Iteration2AdversarialTests.swift
- Tests/FirmwareDBKitTests/M4AdversarialStressTests.swift
- Tests/FirmwareDBKitTests/MobileSyncHarvesterTests.swift
- Tests/FirmwareDBKitTests/PhotosEXIFHarvesterTests.swift
- Tests/FirmwareDBKitTests/USBThunderboltHarvesterTests.swift
- Tests/M4Challenger2StressSuite.swift
sites/firmwaredb.app
- ISSUES.md
- SESSION-STATE.md
- package-lock.json
- src/services/audit-engine.ts
- src/services/db.ts
- src/utils/csv-parser.ts
- test/fixtures/acceptance_catalog.sql
- test/helpers/test-db.ts
- test/integration/empirical-challenge.test.ts
- test/integration/enterprise-fleet-challenge.test.ts
Final Notes acceptance appendix saved and verified in rdmsm4x folder at 19:25 EDT.
Final recheck: RDnamed has a new untracked HANDOFF.md after clean acceptance; preserved, not staged or removed. The five accepted commit IDs still match publication receipts.