rdmpw3265m-changelog-20260903-2319-fleetupdater0903-standalone-rollout
FleetUpdater0903 standalone rollout
Created and verified a single self-contained fleet updater on
rdmpw3265m; this matters because the normal updater,
Footlights UI library, and development updater can now be transferred
and validated as one checksum-protected executable without relying on
neighboring source files.
Scope
- Runtime target on this host:
rdmpw3265m:/Users/richh/dev/scripts/fleetUpdater0903.zsh - Fleet scope:
rdmsm4x,rdmbair15m5,rdmbair13m5,jdmbair13m5,rdmpw3265m, andrdmpw3275m - Canonical development and distribution host:
rdmsm4x - Ticket:
TASK-20260903-38 - Mode: Production fleet operations
What changed
- Installed
/Users/richh/dev/scripts/fleetUpdater0903.zshwith mode0755. - Installed SHA-256:
b79d091e62fe89cc512d04f7e5eb2693f171d1625d1a33a410e0c8d4b7b48233. - Embedded the reviewed Footlights source payload unchanged, preserving in-process UI behavior.
- Embedded a reviewed
devupdate.zshpayload and continued to execute it as a child process so its globals, traps, and exits cannot corrupt the parent updater. - Replaced the embedded dev updater's one bare
lsinvocation with/bin/lsand resolved Homebrew paths through macOSpath_helperplusbrew --prefixto comply with fleet command-path and prefix rules. - Added atomically allocated
mktemppaths for the pinned executable and embedded payload directory, mode restrictions, SHA-256 checks before use, cleanup traps, and--verify-embedded.
Reviewed source inputs
- Canonical
/Users/richh/dev/scripts/fleet_update.zsh: SHA-256dab7c22c55bd278be5a584836143341289ccd76bbdb4431e717322ce430b4463 - Canonical
/Users/richh/dev/scripts/footlights.zsh: SHA-2561bdace7ce540672c29ae8719efb7ea891eab837451b8d0b8e3c087411f9b6fa1 - Canonical
/Users/richh/dev/scripts/devupdate.zsh: SHA-256ddcc82cd425ac2a6606048b8b1844f0da2299b9dc2f4ff2754d93929a272bb03 - Embedded reviewed
devupdate.zshafter the command-path and dynamic-prefix patches: SHA-2568675188d150e2a32323f4f7fb3b732a2470c3f9e8f24d37d6a5b0ec8dc980e23
Commands and evidence
- Original-source baseline:
zsh -non all three inputs andzsh -f fleet_update.zsh --self-test --plain; passed. - Standalone verifier:
zsh /Users/richh/dev/_handoff/codex-out/fleetUpdater0903-20260903/verify_fleetUpdater0903.zsh /Users/richh/dev/_handoff/codex-out/fleetUpdater0903-20260903/fleetUpdater0903.zsh; passed syntax, ASCII-only source, decoded payload checksums, mode, and runtime embedded verification. - Secret scan: canonical
gitleaks detect --no-git --redact=100 --max-decode-depth 5; exit0, reportgitleaks-final.jsoncontains an empty result list. A synthetic GitLab token positive control returned exit1as expected. - Identity preflight: resolved every computer name and compared its Ed25519 SSH host-key fingerprint before writing; six of six passed.
- Distribution: canonical
rollout_fleetUpdater0903.zshused the shared agentkit host list and checksum-verifying push; six of six targets reported the exact installed SHA, mode755, syntax exit0, and embedded verification exit0. - Full host workflow: canonical
selftest_fleetUpdater0903.zsh; six of six reportedselftest_rc=0,all_clear=1,log_fresh=1,temp_residue=0, and runner exit0. - This host's full run log:
/Users/richh/Library/Logs/fleet_update/fleet_update-20260903-231558.log. - Independent peer review:
Inline standards/spec review completed; its two findings were fixed in v1.2.1. External review receipts were requested from existing Claude and agy peers in bus threads 20260903-231417-A390D31B and 20260903-231417-73AD1384; no reply had arrived when this durable record was filed. The fleet budget gate returned conserve, so no new review worker was spawned..
Supporting records
- Canonical handoff:
/Users/richh/dev/_handoff/codex-out/fleetUpdater0903-20260903/ - Shared project index:
~/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md - Check-in:
~/.agent-coordination/checkins/codex-jdmbair13m5-fleetupdater0903-20260903.json - Ticket history:
rdmsm4x:/Users/richh/dev/issues/underTASK-20260903-38
Backup and rollback
- The target filename was absent on all six Macs before the initial rollout, so no pre-existing user file was overwritten.
- Before v1.2.1 replaced the first standalone build, v1.2.0 was
retained on this host at
/Users/richh/dev/scripts/.fleetUpdater0903-backups/20260903-231440/fleetUpdater0903.zshwith SHA-256acea7da956da97356ffdeff2b60218372b56ee2772538ea8ddee2b1ea00b242f. - The canonical handoff retains the installed artifact, verifier, rollout evidence, v1.2.0, and a recoverable superseded pre-ownership-guard candidate.
- To undo on this host without destroying evidence, move
/Users/richh/dev/scripts/fleetUpdater0903.zshinto a timestamped archive outside the active scripts path. Do not delete the canonical handoff until fleet validation and rollback retention are explicitly closed.
Outstanding actions
- No owner action is required for the standalone updater.
- The topology audit still reports pre-existing account/project-lane
drift on
rdmpw3265mandjdmbair13m5; it remains tracked separately asISSUE-20260903-08. No Codex authentication, session, task, rollout, approval, cookie, or enrollment store was copied or changed during this work.