rdmsm4x-changelog-20260925-0012-grok-cursor-suite-verified-and-dev-update-v214
Summary: Grok/Cursor AI suite checked on all six
Macs (already installed everywhere via official Homebrew casks; Cursor
brought current on two hosts) and added to Brewfile.fleet. dev_update
v2.14 ships an AI-tools phase, bounded/quoted --fleet,
per-host fleet logs, a fleet coordinator lock and a --help
fix. Deployed to rdmsm4x, rdmpw3265m and rdmpw3275m. The three MacBook
Airs are held back: Rich asked for no installs there until they reboot,
and they hadn't rebooted by 00:12.
Agent: grok@rdmsm4x/grok0924 · Tickets: TASK-20260924-20 (suite), REV-20260924-01 (dev_update) · Requested by Rich 2026-09-24 22:49 EDT
Part A: Grok / Cursor suite
Official tools (verified from vendor sources)
| Tool | Cask | Binary / bundle | Source |
|---|---|---|---|
| Grok Build (xAI coding agent CLI) | grok-build |
grok (also links agent) |
https://x.ai/cli · https://docs.x.ai/build/overview · https://github.com/xai-org/grok-build |
| Grok Bot desktop app | grok-bot |
/Applications/Grok Bot.app |
https://x.ai/bot · https://docs.x.ai/grok-bot/get-started |
| Cursor editor | cursor |
/Applications/Cursor.app, cursor |
https://cursor.com |
| Cursor CLI | cursor-cli |
cursor-agent |
https://cursor.com/docs/cli/installation |
Not a real macOS tool: a native Grok chat app for
Mac. xAI lists web (grok.com), iOS and Android only. The App
Store "Grok" app (id 6670324846) is for iPhone and iPad. No separate
"Grok CLI" exists apart from Grok Build (grok). No
unofficial packages were installed. Cask download URLs are checked
against the vendors: grok-build pulls from x.ai/cli, and cursor,
cursor-cli and grok-bot pull from downloads.cursor.com.
Per host, measured 2026-09-24 22:5x–23:1x EDT
| Host | Arch | grok-build | cursor-cli | Cursor.app | Grok Bot.app | Change made |
|---|---|---|---|---|---|---|
| rdmsm4x | arm64 | 1.0.41 | 2026.09.23-86fc751 | 3.22.7 | 0.58.0 | none (stale ~/.grok/bin grok 1.0.13 + ~/.local/bin cursor-agent 2026.08.11 are shadowed; reported) |
| rdmbair15m5 | arm64 | 1.0.41 | 2026.09.23-86fc751 | 3.21.18 -> 3.22.7 | 0.58.0 | brew upgrade --cask cursor (app not running) |
| rdmbair13m5 | arm64 | 1.0.41 | 2026.09.23-86fc751 | 3.22.7 | 0.58.0 | none |
| jdmbair13m5 | arm64 | 1.0.41 | 2026.09.23-86fc751 | 3.22.7 | 0.58.0 | none (richh only) |
| rdmpw3265m | x86_64 | 1.0.41 | 2026.09.23-86fc751 | 3.22.7 | 0.58.0 | none |
| rdmpw3275m | x86_64 | 1.0.41 | 2026.09.23-86fc751 | 3.21.18 -> 3.22.7 | 0.58.0 | brew upgrade --cask cursor (app not running; codesign
-v OK) |
Manifest
~/dev/scripts/Brewfile.fleet: addedcursor,cursor-cli,grok-bot,grok-build(commit 01cf850, pushed). BackupBrewfile.fleet.bak-grok-20260924-2309.- The fleet installer that already enforces these is
~/dev/fleet/maintenance/scripts/fleet_github_tools.zshv1.1, documented in~/.agent-coordination/FLEET.md"GitHub tooling baseline". I added one bullet there (backupFLEET.md.bak-grok-20260924-2316).
Owner actions (Rich)
- Sign-ins (from
fleet_agent_signin.zsh --status23:16): grok is signed in only on rdmbair15m5, and cursor-agent only on rdmsm4x. Runzsh ~/dev/fleet/maintenance/scripts/fleet_agent_signin.zshon rdmsm4x when you're ready to click. It coversgrok login --device-authandcursor-agent login, and cursor-agent needs each Mac's GUI session. - First launch (Gatekeeper approval bit not set yet): Cursor.app on rdmsm4x, rdmbair13m5, jdmbair13m5, rdmpw3265m and rdmpw3275m. Grok Bot.app on rdmsm4x, rdmbair13m5 and jdmbair13m5. Open each one at the console, click Open, then sign in (Cursor account / Grok Bot account).
Part
B: dev_update v2.14 (~/dev/scripts/dev_update_v2.14.zsh;
aliases
dev_update/devupdate/updatedev/fleet_update/fleet_upgrade.zsh)
Commit fe8c7af (pushed to backup/main). Rollback =
ln -sfn dev_update_v2.13.zsh <alias> for each of the
5 aliases (v2.13 is untouched in git). Backup copy
dev_update_v2.13.zsh.bak-grok-20260924-2310.
Changes (orchestrator only; embedded payload dev_update.zsh 2.24 is
byte-identical, and --verify-embedded passes):
- AI TOOLS phase (
phase_ai_tools,--no-ai-tools). It reports the 4 casks plus the grok and cursor-agent versions, and names who ownsagent. It flags stale ~/.grok/bin and ~/.local/bin copies. An outdated Cursor or Grok Bot app cask gets upgraded (bounded to 900s) only when the app isn't running, auto-fix is on, and it isn't a dry run. Phase 2's default--greedy-latestskips these auto_updates casks, so an app nobody opens drifts: Cursor was 3.21.18 on 2 hosts. Missing tools produce a WARN with the install command and are never installed. --fleet/--hostsbounded: each host runs under a wall-clock cap (--fleet-host-timeout, default 6h,timeout -k 5) and times out as TIMEOUT. Reachability is probed in at most 15s (.ts.dataroo.net, then .local, then the alias). An unreachable host shows as UNREACHABLE in seconds.- Quoting bug fixed: pass-through args used to be spliced into the remote shell string unquoted. They are now quoted for both shell layers.
- Fleet coordinator lock
(
~/.local/state/fleet_update/fleet-lock, pid-checked, stale lock reclaimed). - Full per-host output goes to
~/Library/Logs/fleet_update/fleet-<ts>/<host>.log. Before, all but 6 lines were thrown away. - Display bugs fixed: fleet WARN/HIGH/FAIL lines
showed only the host name, because th_* print one argument. A
localredeclared inside the loop echoedout=<previous host output>. - The local fleet leg now re-runs the original file with the pin variables cleared. It no longer runs this run's pinned copy, which the child's EXIT trap then deleted.
--helpprinted "command not found: random": the unquoted heredoc had backticks. Fixed. Deliberately not changed: noset -euo pipefail, because the file checks every exit code explicitly and errexit would abort its intentional non-zero probes. It does no git writes anywhere; the bumblebee scan is read-only, so dirty or claimed repos are never touched. Exit codes 0/10/20/30 and all flags are unchanged.
Test evidence (rdmsm4x, load 90–160)
zsh -n: OK.-V:dev_update v2.14 (… payload sha 12ab4d67711c).--verify-embedded: materialise + sha + syntax OK. Unknown option: rc 2.- Full dry run
-n --plain --no-sudofinished all 7 phases, payload exit 0 in 1m30s (log /tmp/grok0924-du214-dry.log). It surfaced a quoting bug in the new phase (casks reported missing). Fixed, then re-tested with-n --no-dev-update: 4 PASS, stale copies flagged, apps "current", rc 10 (the stale-copy warnings). - Fleet:
--hosts rdmsm4x,rdmpw3265m,nosuchhost -n --no-dev-updategave local WARN, remote WARN, nosuchhost UNREACHABLE, per-host logs written, lock released, rc 30.--fleet-host-timeout 3gave TIMEOUT, rc 30, and no orphan process on the remote. A pre-held live lock was refused as intended. - No real (non-dry) run: that is left to the 03:07 nightly
fleet_dev_update.zsh, which gates each host on a dry run first.
Deployment
The hub pushed dev_update_v2.14.zsh (sha256
4b240347cf5e…) out to each spoke's ~/dev/scripts with scp
(atomic tmp+mv) and repointed the 5 alias symlinks. Nothing was rsynced
onto rdmsm4x.
- Done: rdmsm4x (canonical), rdmpw3265m, rdmpw3275m.
~/dev_update.zsh -Vreports v2.14 and the sha matches on each. - Pending: rdmbair15m5, rdmbair13m5, jdmbair13m5.
They still run v2.13, which is consistent and safe. Held per Rich's
22:54 instruction (wait for the Air reboot); still not rebooted at
00:09. To finish, run this from rdmsm4x after they reboot:
cd ~/dev/scripts; for h in rdmbair15m5 rdmbair13m5 jdmbair13m5; do scp -q dev_update_v2.14.zsh $h:dev/scripts/dev_update_v2.14.zsh.tmp && ssh -n $h 'cd ~/dev/scripts && chmod 755 dev_update_v2.14.zsh.tmp && mv -f dev_update_v2.14.zsh.tmp dev_update_v2.14.zsh && zsh -n dev_update_v2.14.zsh && for n in dev_update.zsh devupdate.zsh updatedev.zsh fleet_update.zsh fleet_upgrade.zsh; do [ -L $n ] && ln -sfn dev_update_v2.14.zsh $n; done; ~/dev_update.zsh -V'; done - Apple Notes entry: pending. notes_changelog.zsh
refuses to run from ssh (not an Aqua session). To add it, run
zsh ~/scripts/notes_changelog.zsh ~/dev/LLM/Claude/changelogs/<this file>in the rdmsm4x GUI Terminal.