nvrsion: Add instant away-recall logic to SyncHost.swift; fix live activity crash; adjust host_exec tool to allow read-only tools except “.env” files; fix iOS build errors by adding RemoteStore and IntentError imports.

Nucleic-Promote: 1
Co-authored-by: Nucleic <[email protected]>
This commit is contained in:
2026-07-06 17:20:09 -07:00
co-authored by Nucleic
parent c78f570373
commit 15ecf479fc
2 changed files with 13 additions and 5 deletions
@@ -1,5 +1,5 @@
import AppIntents
#if canImport(NucleicProtocol)
#if NUCLEIC_APP
import NucleicProtocol
#endif
@@ -7,12 +7,18 @@ import NucleicProtocol
/// "resolve from the lock screen without unlocking" path (docs/APP_INTENTS_OPPORTUNITIES §4.1).
///
/// It lives in the **Shared** group so both the app and the widget extension can reference it in
/// `Button(intent:)`. The widget extension links no `NucleicProtocol`, so this intent carries plain
/// `String` ids and compiles its real work only into the app (`#if canImport(NucleicProtocol)`).
/// That's sound because iOS runs a widget/Live-Activity button's intent in the **app's background
/// `Button(intent:)`. It carries plain `String` ids and compiles its real work only into the app,
/// gated on `#if NUCLEIC_APP` (a custom compilation condition set on the app target only). That's
/// sound because iOS runs a widget/Live-Activity button's intent in the **app's background
/// process** — where `RemoteStore` owns the live E2EE channel — never in the extension. The
/// extension-side copy exists solely to satisfy the `Button(intent:)` type reference.
///
/// NB: the guard is `#if NUCLEIC_APP`, *not* `#if canImport(NucleicProtocol)`. `canImport` tests
/// module findability, not linkage — and because the app builds `NucleicProtocol` into the shared
/// DerivedData products dir, it's findable from the widget extension too. So `canImport` is `true`
/// in the extension, which would compile this branch there and fail on the app-only `RemoteStore`
/// / `IntentError` types. `NUCLEIC_APP` tracks target membership, which is what we actually mean.
///
/// Not discoverable in Shortcuts/Spotlight: it's button-only, driven by ids embedded at render time
/// (a human uses `AnswerApprovalIntent` for the spoken/Shortcuts path).
struct ApproveFromActivityIntent: AppIntent {
@@ -39,7 +45,7 @@ struct ApproveFromActivityIntent: AppIntent {
@MainActor
func perform() async throws -> some IntentResult {
#if canImport(NucleicProtocol)
#if NUCLEIC_APP
let store = RemoteStore.shared
// §3.3 — a high-risk allow is never resolved inline; route to the app's biometric-gated card.
// (Surfaces shouldn't render an inline Allow for high-risk in the first place; this is the