rdmsm4x - changelog - monitor repair and expense verification - codex ops - opsmid0927 - fleet RDExpense - 20260927-1127
Host rdmsm4x. Work interval 2026-09-27 11:10:13–11:27:01 EDT.
Ops midday continuation — rdmsm4x
Started 2026-09-27 11:10:13 EDT. Checkpoint 2026-09-27 11:27:01 EDT. Executor: Codex for ops@rdmsm4x, exported AGENT_LLM/TICKET_AGENT=ops and AGENT_SESSION/TICKET_SESSION=opsmid0927 before ticket, bus and Git commands. The bus/Git trailer normalizes the session to opsmid09. No delegated agents.
Outcome
Both requested tickets are resolved for their repaired/scoped work. Remaining runtime coverage and explicitly deferred rename steps have separate linked tickets; this is not a claim that every fleet host or Apple registration is complete.
| Ticket | Delivered | Commit on main, pushed to fleet and backup |
|---|---|---|
| ISSUE-20260926-16 | Zero-byte monitor v1.2; 12 isolated regression tests; installed script matches tested source | fleet 88388f663023b24a1837a0ae2af22217270997ce; scripts
de2d6a074b80ddc5098aad258da0d56ecc8eb7b1 |
| TASK-20260926-60 | Verified already-integrated RDExpense rename; corrected stale build instructions and blocked handoff; completed CHAIN.md R0–R4/in-repo R8 scope | RDReceipt/RDExpense
24f8594b33c776d24b322b0f97b49e2de2f34bc1 |
All three commits were made on named branches in linked worktrees
under ~/dev/_worktrees/, fast-forward merged to their
canonical main branches, and pushed non-force to both named remotes. All
six pushes returned 0. Remote main readbacks matched. Agent trailers
were installed by the normal hook.
1. Zero-byte monitor
Root cause: v1.0 treated four identical counts as a
stuck task, despite Rich's scope change making stable counts healthy. It
then returned success whenever its HALTED marker existed. The earlier
ops v1.1 repair had already removed that rule; missing
ops-zerobyte tmux did not mean the scheduled monitor was
dead.
Live evidence before changes:
com.eastcoastscience.zerobyte-monitor was loaded, nice 10,
natural scheduled runs=1, last exit=1. Its September 27 09:00 pass
finished 09:31:32 with 4/5 hosts observed, two rising findings, verdict
blind. The HALTED marker was absent and its historical copy
was already preserved in
~/archive/launchagents-20260926/zerobyte-HALTED-20260827.
Additional defects reproduced and fixed: failed SSH with stdout was accepted, malformed output could poison the baseline, unreachable-only runs returned 0, corrupt state/status-writer failures could return success, and the positive control used a duplicate implementation rather than the actual classifier.
v1.2 validates SSH status and exactly three nonnegative counts, preserves last-good baselines on failed scans, checks remote find pipeline errors, atomically replaces state, requires a timeout command, and propagates blind/broken outcomes as exit 2. HALTED remains exit 3; rising findings exit 1; full healthy coverage exits 0. SSH uses the documented tailnet names and remote scans run at nice 10. The report no longer equates a growing empty-file count with proven data loss.
Tests: before fix, 9 test methods produced 8 failing assertions including subtests. Final: 12 tests passed, 0 failures, plus zsh syntax validation. Coverage includes five stable runs, first/falling/rising counts, preserved HALTED, failed SSH with stdout, malformed output, corrupt state, failed status writer, failed find, invalid prior baseline, and a production-classifier mutation that must break the positive control. Tests use temporary HOME/state, fake SSH/bus, and the real status writer; no canonical store or user files are used.
Deployment: installed
~/scripts/zero_byte_monitor.zsh and fleet source both hash
46d5d1a38712a4ff3e497968cdfed4fc3205e37c5336d6b12eaf25ab8b4201d2.
The scripts checkout was clean before deployment. Rollback copy is
rollback/zero_byte_monitor.v1.1.zsh; restore that file
between runs, or revert scripts commit de2d6a0 and fleet commit 88388f6
separately. No HALTED marker was removed in this run and no other
session was killed.
Runtime acceptance boundary: launchd was kickstarted
without -k at 11:19:52. New run count=2, PID=7085. At
11:21:23 it measured rdmsm4x as STABLE (93274 / 1 / 1175). At 11:25:00
rdmbair13m5 was also STABLE (663600 / 1 / 807). The full five-host v1.2
pass was still running at the checkpoint; the last-exit field still
belongs to v1.1 and is not new success evidence.
ISSUE-20260927-16 tracks the completed-pass readback,
missing rdmpw3275m coverage from the prior run, and the +1 Documents
findings on each Air. Counts alone do not establish loss. Do not
interrupt the live scan to inspect its result.
Evidence: zerobyte-before-tests.log,
zerobyte-after-tests.log,
zerobyte-launchd-before.txt,
zerobyte-launchd-after-start.txt, and
zerobyte-launchd-current.txt. Re-run regression tests from
canonical source:
nice -n 10 /usr/bin/python3 ~/dev/fleet/ops/checks/test_zero_byte_monitor.py.
2. RDExpense
The original Codex read-only .git block was historical.
Later agy work already merged inventory at 1690b75, renamed
at 001f1ef, merged that at 748f3c8, and then
merged the profile seam at 4a29c06. This run preserved all
of that work and did not replay or roll back the rename. The canonical
app checkout was clean.
The remaining in-repo documentation defect was real: AGENTS.md and
CLAUDE.md had updated the decision sentence while retaining nonexistent
package paths, old scheme names and executable commands. Those
references are corrected. SESSION-STATE.md and ISSUES.md now carry the
fresh evidence and accurate scope. The historical
_handoff/rdexpense-rename-20260927/RESULT.md has an
additive supersession note.
Fresh checks at code commit 4a29c06 (documentation-only final commit 24f8594):
| Check | Result |
|---|---|
| SwiftPM package build | exit 0 |
| CLI benchmark warmup | exit 0 |
| Test discovery | 574 tests |
| Swift tests | 573 passed = 565 Swift Testing + 8 XCTest; 0 failed |
| Excluded test | 1: testKeychainManagerGetOrCreate, because it creates/deletes a Keychain item and user prohibited credentials |
| Xcode RDExpense-macOS | BUILD SUCCEEDED; CODE_SIGNING_ALLOWED=NO |
| Xcode RDExpense-iOS, generic iOS Simulator | BUILD SUCCEEDED; CODE_SIGNING_ALLOWED=NO |
| build.sh | exit 0; unsigned RDExpense.app + rdexpense + rdexpense-mcp |
| Architectures | all three have x86_64 and arm64 |
| Parser/classifier fixtures | 17/17 passed |
| Config seam guard | positive control detected; no forbidden source matches |
| Storage/identity/artifact invariants | 9/9 passed |
| rollback_rename.zsh --dry-run | exit 0; tag present |
Builds ran sequentially under the build-slot guard, nice 10; Swift/Xcode builds used four jobs where the entry point supports it. Tests used a temporary HOME and CFFIXED_USER_HOME. No signing/notarization, live vault opening, Apple portal access, credential reads, Concur submission or outbound human message was performed.
Preserved identifiers: app.rdreceipt.vault; master-encryption-key;
rdReceipt vault and rdReceipt/ImageCache directories;
com.eastcoastscience.rdreceipt.label xattr. New bundle ID verified as
com.eastcoastscience.RDExpense. Both remote rollback tags peel to
1690b75bd8f3ce524bd1ac61a3a655a8f268a5bd. Backup exclusions
still include both RDExpense/rdexpense and the old names.
Explicitly deferred, not completed: CHAIN.md
instructs keeping current paths until steps 2–4 finish. R5 remote
rename, R6 folder/worktree repair, and R7 external fleet records are
preserved in TASK-20260927-44, dependent on
FEAT-20260926-19 and REV-20260926-05. R9 Apple registration and R3
attended legacy-vault acceptance remain with
FEAT-20260926-20. Resolution of TASK-60 is expressly the
chain-authorized in-repo scope, not every original R1–R9 acceptance
item.
Evidence: rdexpense-checks.tsv, nine check logs,
rdexpense-test-list.log,
rdexpense-invariants.json,
rdexpense-remote-{fleet,backup}.txt, and
rdexpense-rollback-dry-run.log.
verify-rdexpense.zsh records exact commands.
Preservation and remaining records
- Fleet integration inventory recorded 259 dirty/untracked entries.
Every pre-existing regular-file hash in that inventory was unchanged
immediately after the merge. The inventory is
fleet-dirty-before.json. No unrelated dirty work was staged. - Requested
~/dev/FLEET.mdwas absent. GROKBOT.md points to~/.agent-coordination/FLEET.md; that canonical policy was read instead. - The old topology audit path was absent. The equivalent canonical
fleet script checked six hosts and returned three findings: rdmpw3265m
account-lane mismatch; jdmbair13m5 unclassified account lane and
unexpected durable project-root state. These account/state findings were
recorded in
topology-audit.log, not changed. - No money, irreversible user-data deletion, account migration, credentials, external human communication or termination of another session occurred.
- Notes publication: Background harness; file changelog retained. Apple Notes entry remains pending the documented Aqua-session requirement, not claimed published.
Final artifact preservation
Generated package .build, dist, .ops-derived, and generated Xcode
workspace shared data (4 paths) were moved intact into
build-artifacts/ in this run directory. The RDExpense and
scripts linked worktrees were then removed cleanly; their named branches
remain. The verification script recreates its named RDExpense worktree
if needed. Final source changes are documentation-only on top of the
verified code. Ticket records were committed as 1b735dd
with explicit paths, preserving all existing comments. Unrelated
ticket-store changes were left unstaged.