rdmsm4x - changelog - stale-baseline-claim-corrected-and-guard-findings-cleared - claude - lane-resume - fleet-baseline - 20260924-2209
Corrected a 25-day-stale factual claim in the Apple app baseline that every app session reads as current, and cleared the two findings my shared-tree guard has accumulated since 2026-09-05.
- Host: rdmsm4x · When: 2026-09-24 22:09:33 EDT · Agent: claude@rdmsm4x (session_01V624TifjnsJ7tsa2kxhmWi)
- Budget: Anthropic 7-day quota 93%, advice=hold. Worked inline, no subagent fan-out, finished rather than started. Did not touch TCC/FDA, xcode-select, or the herdr/ECSToolHost LaunchAgents per the 2026-09-24 22:04 broadcast.
1.
~/dev/apps/CLAUDE.md §3 — two false claims superseded (not
deleted)
Both claims in the 2026-08-30 CORRECTED block are now false, and they route sessions to a blocker that no longer exists. Re-measured 2026-09-24 22:09:33 EDT:
| Claim (2026-08-30) | Measured 2026-09-24 |
|---|---|
| "not a single macOS provisioning profile on rdmsm4x" | FALSE — 5 installed, all Platform OSX |
| "no CloudKit container exists for any macOS app" | FALSE —
iCloud.com.eastcoastscience.rtty registered |
Profiles: RTTy macOS App Store (exp 2027-09-10) · Mac Team Provisioning Profile: com.eastcoastscience.rtty.direct (exp 2027-09-03) · RTTy Direct Developer ID, (exp 2044-09-05) · RTTy Network Filter App Store (exp 2027-09-10) · Mac Team Provisioning Profile: com.eastcoastscience.RDWorkbench (exp 2027-08-01).
Added a SUPERSEDED block above the original and pointed readers at
~/dev/lib/app-baseline/APPLE_DEVELOPER_FACTS.md, which the
global CLAUDE.md now names as the single canonical record. The
2026-08-30 text was left in place, per this file's own convention, so
the earlier measurement stays auditable.
~/dev/apps/AGENTS.md is a symlink to it, so one edit fixed
both. Not version-controlled — ~/dev/apps is not a
git repo.
I first reported this claim as false on 2026-09-05 and handed it back rather than fixing it. It then sat wrong for 19 more days. Per CLAUDE.md v4.3 "Resolve, don't hand back", it is fixed.
2. shared_tree_guard findings cleared
The guard I added 2026-09-05 (com.eastcoastscience.sharedtreeguard, 30 min) has run continuously for 19 days and now covers 34 shared checkouts, up from 24. Its one outstanding finding:
~/dev/lib/domains/changes/dns-migration-2026-09-24/ —
untracked ~5h, 8 files including
godaddy-before.json, the ROLLBACK record for that
migration. Losing it would have made the change irreversible.
Committed verbatim as 16fc4cb, pushed to
backup and fleet.
Verified free of secrets before committing: both
scripts read CLOUDFLARE_API_TOKEN, GODADDY_API_KEY and
GODADDY_API_SECRET from ~/.secrets/global.env at runtime
and embed none; the single 32-hex literal is the Cloudflare ACCOUNT id,
a public identifier, not a credential; JSON and JSONL scanned clean.
__pycache__/ was gitignored rather than committed.
Guard now reports PASS across all 34 checkouts.
3. Items from my 2026-09-05 lane that closed themselves — verified, not assumed
ISSUE-20260905-21(stalestandard_candidate_closure_test.pycounts) — resolved by another lane.- The signing-identity dedupe I filed (
ISSUE-20260905-28) — fixed;script/resolve_codesign_identity.shnow exists andbuild_and_run.shcites it. t3codeandagentkitmirrors, which I flagged as missing — both now mirrored (t3code→fleet, agentkit→backup); the 71KB t3code analysis commit is no longer local-only.
Verification
security cms -D -i <each .provisionprofile> | plutil -extract Name/Platform/ExpirationDate raw -
grep -n 'SUPERSEDED 2026-09-24' ~/dev/apps/CLAUDE.md -> line 69
grep -c 'CORRECTED 2026-08-30 by' ~/dev/apps/CLAUDE.md -> 1 (history preserved)
grep -c 'SUPERSEDED 2026-09-24' ~/dev/apps/AGENTS.md -> 1 (symlink)
git -C ~/dev/lib/domains rev-parse --short HEAD -> 16fc4cb, clean
zsh ~/dev/fleet/maintenance/scripts/shared_tree_guard.zsh -> PASS, 34 checkouts
Undo
- Baseline: delete the SUPERSEDED blockquote at
~/dev/apps/CLAUDE.md:69; nothing else changed. - domains:
git -C ~/dev/lib/domains revert 16fc4cb(files return to untracked).
Outstanding for others
- Nothing blocked on Rich.
lib/domainscommit is another lane's work, preserved not altered — its owner should confirm the migration is complete.