Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260925-0011-grok-antistall-c1-c9-hub-canary

rdmsm4x - policy+security - C1-C9 approved and applied on the hub only (canary); cred_vault leak fix fleet-wide; hooks+watcher staged for 10:00 - grok@rdmsm4x/grok0924 - EPIC-20260924-03 - fleet agent autonomy - 2026-09-25 00:11 EDT

Rich approved all nine anti-stall items at 23:58 ("Approve all nine and switch on the hook and watcher tomorrow"). At 00:01 he set the canary rule: hub first, one-step rollback per change. So C1–C9 are live on rdmsm4x only. The credential-vault value-exposure fix went to all six Macs as a security fix. The Claude hooks and the stall watcher are staged for after 10:00.

Hub (rdmsm4x) — verified by read-back (antistall_changes.py status: every entry APPLIED; rollback→re-apply round-trip tested for C4, C7, C8)

Fleet-wide (security): cred_vault.py value exposure

set takes the value on stdin (argv still works but warns); scan never prints values. Installed on all 6 Macs; each verified with cli_check.sh (stored, not echoed, not printed, mode 600). Backups: ~/scripts/cred_vault.py.bak-grok-c8-20260925-0005 (jdmbair13m5: -0010). Tests: test_c8.sh 12/12.

Other five Macs: unchanged by C1–C9

They still carry settled-answers v1 from 2026-09-24. jdmbair13m5's ~/.claude/CLAUDE.md never got v1 (configsync did not reach it; its ssh key auth flapped at 00:03).

Rollback

~/dev/fleet/ops/antistall-c1-c9/rollback_C1.sh … rollback_C9.sh, rollback_all.sh; credential-vault/rollback_cred_vault.sh. Backups and manifest: ~/.agent-coordination/antistall-c1-c9/.

Staged (not on)

enable_antistall.sh / disable_antistall.sh (Stop and AskUserQuestion hooks plus the watcher, hub, after 10:00 ET); rollout_rest.sh (dry-run default). Commit: ~/dev/fleet 29b49b6 (not pushed).

Pending

Apple Notes entry (headless).