Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260927-0118-rdmodelrouter-keys

rdmsm4x - feature - populate API keys in keychain and support CLI logins - agy - FEAT-20260927-10 - rdmodelrouter - 2026-09-27 01:18 EDT

[2026-09-27 01:18:00 EDT · rdmsm4x · agy@rdmsm4x/rmrkeys0927 · FEAT-20260927-10]

Summary

Completed Phase 3 delivery for rdmodelrouter in worktree ~/dev/_worktrees/rdmodelrouter-keys-20260927 (branch rmr/keys-logins-20260927, commit 5cf2830).

What Was Done

  1. VERIFY R1 Resolution:
    • Fixed post-cutover Codex tie-breaking logic in Dispatcher.swift so that verified accounts (selection.verified == true, e.g. icloud) take precedence over unverified placeholder accounts (gmail) when drain dates tie or reset dates are absent.
    • Added unit test postCutoverPrefersVerifiedAccountOverUnverified.
  2. Key Inventory (KEY-INVENTORY.md):
    • Scanned ~/dev, ~/.config, ~/.secrets, and ~ for .env-style API key configurations.
    • Identified 33 occurrences across 9 distinct keys/endpoints with zero cross-file value conflicts.
  3. Keychain Credential Storage:
    • Stored all 9 distinct provider keys/settings into the macOS login Keychain under service "rdmodelrouter", account "<VAR_NAME>".
    • Used native Security framework in-memory APIs (SecKeychainAddGenericPassword / SecItemCopyMatching) without exposing secret values on argv, shell history, or logs.
  4. Call-Time Key Resolver (KeyResolver.swift):
    • Implemented KeychainKeyResolver to resolve credentials at call time directly from Keychain and environment.
    • Non-secret status checks report presence, source, and 4-character masked fingerprints (KeyResolution). Never caches or writes keys to disk.
  5. Tyrell Architecture Proposal (TYRELL-PROPOSAL.md):
    • Inspected ~/.tyrell/ and ~/Library/Application Support/Tyrell/.
    • Drafted specification for Tyrell key-registry.json and cli-logins.json holding non-secret credential references and login statuses.
  6. Official CLI Service Logins (AccountStatusReader.swift):
    • Implemented rdmodelrouter accounts [--json] reporting official status for claude, codex, agy, and grok.
    • Implemented rdmodelrouter login <cli> [--account <id>] [--apply]: dry-run by default printing exact commands; isolates CODEX_HOME for secondary accounts (e.g. ~/.codex-gmail).
  7. StatusKit & StatusApp:
    • Extended RDModelRouterStatusKit and RDModelRouterStatusApp to render provider key presence and CLI login status.
  8. Verification & Testing:
    • Universal2 compilation verified for rdmodelrouter and RDModelRouterStatusApp (x86_64 + arm64, Intel minos 26.7).
    • Test suite passing: 69 tests across 10 suites, 0 failures.
    • NoSecretLiteralsTests scanner verified zero API keys committed to the repository.
    • Handoff documentation written to ~/dev/_handoff/rdmodelrouter-keys-20260927/RESULT.md.