Fleet changelogs · dev.ecs0.net
rdmsm4x - changelog - monitor repair and expense verification - codex ops - opsmid0927 - fleet RDExpense - 20260927-1127

rdmsm4x - changelog - monitor repair and expense verification - codex ops - opsmid0927 - fleet RDExpense - 20260927-1127

Host rdmsm4x. Work interval 2026-09-27 11:10:13–11:27:01 EDT.

Ops midday continuation — rdmsm4x

Started 2026-09-27 11:10:13 EDT. Checkpoint 2026-09-27 11:27:01 EDT. Executor: Codex for ops@rdmsm4x, exported AGENT_LLM/TICKET_AGENT=ops and AGENT_SESSION/TICKET_SESSION=opsmid0927 before ticket, bus and Git commands. The bus/Git trailer normalizes the session to opsmid09. No delegated agents.

Outcome

Both requested tickets are resolved for their repaired/scoped work. Remaining runtime coverage and explicitly deferred rename steps have separate linked tickets; this is not a claim that every fleet host or Apple registration is complete.

Ticket Delivered Commit on main, pushed to fleet and backup
ISSUE-20260926-16 Zero-byte monitor v1.2; 12 isolated regression tests; installed script matches tested source fleet 88388f663023b24a1837a0ae2af22217270997ce; scripts de2d6a074b80ddc5098aad258da0d56ecc8eb7b1
TASK-20260926-60 Verified already-integrated RDExpense rename; corrected stale build instructions and blocked handoff; completed CHAIN.md R0–R4/in-repo R8 scope RDReceipt/RDExpense 24f8594b33c776d24b322b0f97b49e2de2f34bc1

All three commits were made on named branches in linked worktrees under ~/dev/_worktrees/, fast-forward merged to their canonical main branches, and pushed non-force to both named remotes. All six pushes returned 0. Remote main readbacks matched. Agent trailers were installed by the normal hook.

1. Zero-byte monitor

Root cause: v1.0 treated four identical counts as a stuck task, despite Rich's scope change making stable counts healthy. It then returned success whenever its HALTED marker existed. The earlier ops v1.1 repair had already removed that rule; missing ops-zerobyte tmux did not mean the scheduled monitor was dead.

Live evidence before changes: com.eastcoastscience.zerobyte-monitor was loaded, nice 10, natural scheduled runs=1, last exit=1. Its September 27 09:00 pass finished 09:31:32 with 4/5 hosts observed, two rising findings, verdict blind. The HALTED marker was absent and its historical copy was already preserved in ~/archive/launchagents-20260926/zerobyte-HALTED-20260827.

Additional defects reproduced and fixed: failed SSH with stdout was accepted, malformed output could poison the baseline, unreachable-only runs returned 0, corrupt state/status-writer failures could return success, and the positive control used a duplicate implementation rather than the actual classifier.

v1.2 validates SSH status and exactly three nonnegative counts, preserves last-good baselines on failed scans, checks remote find pipeline errors, atomically replaces state, requires a timeout command, and propagates blind/broken outcomes as exit 2. HALTED remains exit 3; rising findings exit 1; full healthy coverage exits 0. SSH uses the documented tailnet names and remote scans run at nice 10. The report no longer equates a growing empty-file count with proven data loss.

Tests: before fix, 9 test methods produced 8 failing assertions including subtests. Final: 12 tests passed, 0 failures, plus zsh syntax validation. Coverage includes five stable runs, first/falling/rising counts, preserved HALTED, failed SSH with stdout, malformed output, corrupt state, failed status writer, failed find, invalid prior baseline, and a production-classifier mutation that must break the positive control. Tests use temporary HOME/state, fake SSH/bus, and the real status writer; no canonical store or user files are used.

Deployment: installed ~/scripts/zero_byte_monitor.zsh and fleet source both hash 46d5d1a38712a4ff3e497968cdfed4fc3205e37c5336d6b12eaf25ab8b4201d2. The scripts checkout was clean before deployment. Rollback copy is rollback/zero_byte_monitor.v1.1.zsh; restore that file between runs, or revert scripts commit de2d6a0 and fleet commit 88388f6 separately. No HALTED marker was removed in this run and no other session was killed.

Runtime acceptance boundary: launchd was kickstarted without -k at 11:19:52. New run count=2, PID=7085. At 11:21:23 it measured rdmsm4x as STABLE (93274 / 1 / 1175). At 11:25:00 rdmbair13m5 was also STABLE (663600 / 1 / 807). The full five-host v1.2 pass was still running at the checkpoint; the last-exit field still belongs to v1.1 and is not new success evidence. ISSUE-20260927-16 tracks the completed-pass readback, missing rdmpw3275m coverage from the prior run, and the +1 Documents findings on each Air. Counts alone do not establish loss. Do not interrupt the live scan to inspect its result.

Evidence: zerobyte-before-tests.log, zerobyte-after-tests.log, zerobyte-launchd-before.txt, zerobyte-launchd-after-start.txt, and zerobyte-launchd-current.txt. Re-run regression tests from canonical source: nice -n 10 /usr/bin/python3 ~/dev/fleet/ops/checks/test_zero_byte_monitor.py.

2. RDExpense

The original Codex read-only .git block was historical. Later agy work already merged inventory at 1690b75, renamed at 001f1ef, merged that at 748f3c8, and then merged the profile seam at 4a29c06. This run preserved all of that work and did not replay or roll back the rename. The canonical app checkout was clean.

The remaining in-repo documentation defect was real: AGENTS.md and CLAUDE.md had updated the decision sentence while retaining nonexistent package paths, old scheme names and executable commands. Those references are corrected. SESSION-STATE.md and ISSUES.md now carry the fresh evidence and accurate scope. The historical _handoff/rdexpense-rename-20260927/RESULT.md has an additive supersession note.

Fresh checks at code commit 4a29c06 (documentation-only final commit 24f8594):

Check Result
SwiftPM package build exit 0
CLI benchmark warmup exit 0
Test discovery 574 tests
Swift tests 573 passed = 565 Swift Testing + 8 XCTest; 0 failed
Excluded test 1: testKeychainManagerGetOrCreate, because it creates/deletes a Keychain item and user prohibited credentials
Xcode RDExpense-macOS BUILD SUCCEEDED; CODE_SIGNING_ALLOWED=NO
Xcode RDExpense-iOS, generic iOS Simulator BUILD SUCCEEDED; CODE_SIGNING_ALLOWED=NO
build.sh exit 0; unsigned RDExpense.app + rdexpense + rdexpense-mcp
Architectures all three have x86_64 and arm64
Parser/classifier fixtures 17/17 passed
Config seam guard positive control detected; no forbidden source matches
Storage/identity/artifact invariants 9/9 passed
rollback_rename.zsh --dry-run exit 0; tag present

Builds ran sequentially under the build-slot guard, nice 10; Swift/Xcode builds used four jobs where the entry point supports it. Tests used a temporary HOME and CFFIXED_USER_HOME. No signing/notarization, live vault opening, Apple portal access, credential reads, Concur submission or outbound human message was performed.

Preserved identifiers: app.rdreceipt.vault; master-encryption-key; rdReceipt vault and rdReceipt/ImageCache directories; com.eastcoastscience.rdreceipt.label xattr. New bundle ID verified as com.eastcoastscience.RDExpense. Both remote rollback tags peel to 1690b75bd8f3ce524bd1ac61a3a655a8f268a5bd. Backup exclusions still include both RDExpense/rdexpense and the old names.

Explicitly deferred, not completed: CHAIN.md instructs keeping current paths until steps 2–4 finish. R5 remote rename, R6 folder/worktree repair, and R7 external fleet records are preserved in TASK-20260927-44, dependent on FEAT-20260926-19 and REV-20260926-05. R9 Apple registration and R3 attended legacy-vault acceptance remain with FEAT-20260926-20. Resolution of TASK-60 is expressly the chain-authorized in-repo scope, not every original R1–R9 acceptance item.

Evidence: rdexpense-checks.tsv, nine check logs, rdexpense-test-list.log, rdexpense-invariants.json, rdexpense-remote-{fleet,backup}.txt, and rdexpense-rollback-dry-run.log. verify-rdexpense.zsh records exact commands.

Preservation and remaining records

Final artifact preservation

Generated package .build, dist, .ops-derived, and generated Xcode workspace shared data (4 paths) were moved intact into build-artifacts/ in this run directory. The RDExpense and scripts linked worktrees were then removed cleanly; their named branches remain. The verification script recreates its named RDExpense worktree if needed. Final source changes are documentation-only on top of the verified code. Ticket records were committed as 1b735dd with explicit paths, preserving all existing comments. Unrelated ticket-store changes were left unstaged.