Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260924-2209-stale-baseline-claim-corrected-and-guard-findings-cleared

rdmsm4x - changelog - stale-baseline-claim-corrected-and-guard-findings-cleared - claude - lane-resume - fleet-baseline - 20260924-2209

Corrected a 25-day-stale factual claim in the Apple app baseline that every app session reads as current, and cleared the two findings my shared-tree guard has accumulated since 2026-09-05.

1. ~/dev/apps/CLAUDE.md §3 — two false claims superseded (not deleted)

Both claims in the 2026-08-30 CORRECTED block are now false, and they route sessions to a blocker that no longer exists. Re-measured 2026-09-24 22:09:33 EDT:

Claim (2026-08-30) Measured 2026-09-24
"not a single macOS provisioning profile on rdmsm4x" FALSE — 5 installed, all Platform OSX
"no CloudKit container exists for any macOS app" FALSE — iCloud.com.eastcoastscience.rtty registered

Profiles: RTTy macOS App Store (exp 2027-09-10) · Mac Team Provisioning Profile: com.eastcoastscience.rtty.direct (exp 2027-09-03) · RTTy Direct Developer ID, (exp 2044-09-05) · RTTy Network Filter App Store (exp 2027-09-10) · Mac Team Provisioning Profile: com.eastcoastscience.RDWorkbench (exp 2027-08-01).

Added a SUPERSEDED block above the original and pointed readers at ~/dev/lib/app-baseline/APPLE_DEVELOPER_FACTS.md, which the global CLAUDE.md now names as the single canonical record. The 2026-08-30 text was left in place, per this file's own convention, so the earlier measurement stays auditable. ~/dev/apps/AGENTS.md is a symlink to it, so one edit fixed both. Not version-controlled — ~/dev/apps is not a git repo.

I first reported this claim as false on 2026-09-05 and handed it back rather than fixing it. It then sat wrong for 19 more days. Per CLAUDE.md v4.3 "Resolve, don't hand back", it is fixed.

2. shared_tree_guard findings cleared

The guard I added 2026-09-05 (com.eastcoastscience.sharedtreeguard, 30 min) has run continuously for 19 days and now covers 34 shared checkouts, up from 24. Its one outstanding finding:

~/dev/lib/domains/changes/dns-migration-2026-09-24/ — untracked ~5h, 8 files including godaddy-before.json, the ROLLBACK record for that migration. Losing it would have made the change irreversible. Committed verbatim as 16fc4cb, pushed to backup and fleet.

Verified free of secrets before committing: both scripts read CLOUDFLARE_API_TOKEN, GODADDY_API_KEY and GODADDY_API_SECRET from ~/.secrets/global.env at runtime and embed none; the single 32-hex literal is the Cloudflare ACCOUNT id, a public identifier, not a credential; JSON and JSONL scanned clean. __pycache__/ was gitignored rather than committed.

Guard now reports PASS across all 34 checkouts.

3. Items from my 2026-09-05 lane that closed themselves — verified, not assumed

Verification

security cms -D -i <each .provisionprofile> | plutil -extract Name/Platform/ExpirationDate raw -
grep -n 'SUPERSEDED 2026-09-24' ~/dev/apps/CLAUDE.md          -> line 69
grep -c 'CORRECTED 2026-08-30 by' ~/dev/apps/CLAUDE.md        -> 1 (history preserved)
grep -c 'SUPERSEDED 2026-09-24' ~/dev/apps/AGENTS.md          -> 1 (symlink)
git -C ~/dev/lib/domains rev-parse --short HEAD               -> 16fc4cb, clean
zsh ~/dev/fleet/maintenance/scripts/shared_tree_guard.zsh     -> PASS, 34 checkouts

Undo

Outstanding for others