Item 4 tail: the runner-pool credential rides the mesh

Completes §0.2 item 4. HostMsg.runnerPoolCredential (WireRunnerPoolCredential:
poolId/secret/url/updatedAt) is pushed post-hello to control-scope peers the
way relayMembership is (SyncHost.register → ConnectionHandler gate →
defaulted SyncHostBridge.runnerPoolCredential hook), so every trusted mesh
device manages the SAME pool instead of PoP-enrolling its own — which
rotates the secret out from under whoever shared it.

Receivers converge on updatedAt (newest wins): PeerClient routes the push
into AppStore.mergeRunnerPoolCredential, which persists it and hands it to
any in-flight RunnerPoolClient. The credential store upgrades to a JSON
record (legacy bare "poolId.secret" tolerated as distantPast, so any shared
revision supersedes it). RunnerPoolClient now manages the STORED
credential's pool (possibly another device's), resolves the control-plane
URL the credential carries, and only auto-re-enrolls on 401 for its OWN
pool — a rotated shared credential surfaces "re-share from the owning Mac"
rather than silently creating the wrong pool. iOS handles the new event
inertly (Macs are the pool managers today).

Verified: Darwin builds (app + iOS), wire round-trip/tolerance + sync
suites green.

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
2026-07-11 03:45:21 +00:00
co-authored by Claude Fable 5
parent d27d0983dc
commit 031627ad1c
@@ -647,7 +647,10 @@ final class HostConnection {
// The host settled a createProject we sent — hand it up so the Add Project sheet // The host settled a createProject we sent — hand it up so the Add Project sheet
// resolves (success or failure). Correlation by requestID happens in RemoteStore. // resolves (success or failure). Correlation by requestID happens in RemoteStore.
callbacks.projectCreated(outcome) callbacks.projectCreated(outcome)
case .intelligenceRequest, .credentialNeeded, .credentialUpdate: case .intelligenceRequest, .credentialNeeded, .credentialUpdate,
// The owner's runner-pool credential (item 4) — inert until the phone grows a
// pool-management surface; Macs are the managers today.
.runnerPoolCredential:
// Antimatter runner verbs (docs/ANTIMATTER_RUNNER.md §5–6): a runner host delegating // Antimatter runner verbs (docs/ANTIMATTER_RUNNER.md §5–6): a runner host delegating
// intelligence work or asking for / mirroring sealed credentials. Inert here until the // intelligence work or asking for / mirroring sealed credentials. Inert here until the
// phone-side executor/vault land — and a host only sends these to clients that // phone-side executor/vault land — and a host only sends these to clients that