Commit Graph
557 Commits
Author SHA1 Message Date
abkslmandClaude Opus 4.8 77ca4d1d67 Wrap long permission request text in approval UIs
The macOS ApprovalBar put the title and action buttons on one row, so a
long file-path title got truncated. Stack title above the buttons so it
wraps to as many lines as needed. Bump the iOS card's input summary cap
from 3 to 8 lines. Both made text-selectable.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-13 21:25:57 -07:00
abkslmandClaude Opus 4.8 9d4999bb74 Sandbox: host build/run mode (host_exec tool)
Adds a per-project "Allow host build/run" sandbox capability that lets a
containerized agent request to build and run executables on the host
machine, escaping the Linux sandbox — e.g. compiling and running a macOS
binary the container can't.

- New `host_exec` MCP tool on the approval server, advertised only when the
  session opts in. Pre-allowed via --allowedTools so the call reaches our
  handler directly rather than Claude's permission path: the handler is the
  sole gate, so `auto` mode can never auto-approve it.
- Every host command surfaces an explicit approval (risk .hostExec) and runs
  on the host via /bin/zsh -lc in the session worktree only after approval.
  An explicit "Allow for Session" choice grants the rest of the session;
  auto-approve never sets that — only a deliberate user choice does.
- ProjectSandbox.allowHostExec (off by default) with tolerant decoding so
  rows persisted before the field default to false instead of dropping the
  whole sandbox config.
- Threaded allowHostExec through RunSpec/ResumeSpec/SessionController; Mac
  Project Settings toggle; Mac ApprovalBar "Allow for Session" button; iOS
  risk styling/biometric gate for .hostExec.
- Tests: host_exec advertised/served only when registered + refused
  otherwise; allowHostExec round-trip and legacy-JSON default-to-false.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-13 16:52:01 -07:00
abkslm 644851e179 Merge mobile control-scope parity + design language into main
iPhone client gains full control-scope parity with the Mac (start chats, manage
to-dos, manage/integrate sessions), the desktop design language (teal palette,
status colors, cards), and Home/Projects/To-Dos surfaces. Fixes archived chats
leaking into Needs You. See nucleic-m4-state.

# Conflicts:
#	ios/NucleicRemote/NucleicRemote.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved
2026-06-13 02:24:43 -07:00
abkslm 5277583456 NucleicRemote: set development team for device signing + resolve SwiftTerm pins
Adds DEVELOPMENT_TEAM (3XPAYVD6BP) so the app signs to a physical iPhone, and
records the resolved SwiftTerm / swift-argument-parser package pins. Generated by
opening the project in Xcode.
2026-06-13 02:23:45 -07:00
abkslmandClaude Opus 4.8 a70b21cd3e M4+: mirror the desktop design language onto mobile (Home/Projects/To-Dos/Sessions)
Design system: Palette (teal accent + the Mac's categorical status colors, status→color
refined by turn disposition), StatusStyle glyphs/labels, a card surface modifier, app-wide
teal tint.

Fixes the reported bug: Sessions now hides archived chats and uses disposition to split
NEEDS YOU from DONE (a finished-the-work turn no longer shows as needing you). Rows gain
status dots, favorite star, approval-count badge, diffstat; swipe to favorite/archive/delete.

New surfaces, full control-scope parity with the Mac:
- Home: greeting + day-streak flame, GitHub-style activity grid, stat cards, quick to-dos,
  and a start-chat composer (project picker + Auto).
- Projects: per-project session counts → project detail with a scoped composer.
- To-dos: capture, group by project, complete/dispatch/delete.
- Session detail: a control menu (rename, favorite, interrupt, integrate merge/squash/rebase,
  archive, delete).

RemoteStore handles the dashboard event + exposes all control intents; claims control scope.
A NUCLEIC_DEMO/NUCLEIC_TAB env seam seeds mock state for offline UI preview.

iOS app builds for the iOS 27 simulator; Home + Sessions verified rendering via screenshots.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-13 02:20:53 -07:00
abkslmandClaude Opus 4.8 c907333df2 M4: make device testing work — LAN IP in QR + automatic iOS signing
- LANAddress.primaryIPv4() (getifaddrs, prefers en*) embedded in the pairing QR via
  beginPairing, so the phone dials the Mac directly instead of relying on Bonjour
  discovery (much more robust on real networks; Bonjour stays a fallback).
- iOS project switches from CODE_SIGNING_ALLOWED=NO to CODE_SIGN_STYLE=Automatic so
  it signs to a physical device once a team is selected in Xcode (simulator still
  builds without a team).

174 tests green; macOS + iOS-simulator builds clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-13 01:22:12 -07:00
abkslmandClaude Opus 4.8 6f24b42004 M4: NucleicRemote iPhone app — SwiftUI client over the shared protocol
A real iOS Xcode app (ios/NucleicRemote) linking the NucleicProtocol SwiftPM
library as a local package. Builds for the iOS 27 simulator and launches to the
pairing screen.

- Transport: NWFrameChannel (NWConnection) + LANDiscovery (Bonjour _nucleic._tcp).
- Engine: drives NucleicProtocol.SyncClient (Noise XXpsk0 pair / IK reconnect,
  hello/welcome, HostMsg→Event stream).
- State: RemoteStore (ObservableObject) — the single on-device projection of host
  state; IdentityStore persists the device identity (Keychain) + pinned host.
- UI (UX_IOS): attention-first SessionsView, SessionDetailView (transcript/diff +
  status-driven action area / composer), ApprovalCardView with Face ID gate on
  high-risk approvals + allow-always menu, PairingScannerView (AVFoundation QR),
  SettingsView, connection chip. Same status glyphs/semantics as the Mac.

Add-iPhone QR display + server start live on the macOS side (follow-up); push /
Live Activity are M5 (needs the relay). gitignore keeps this .xcodeproj despite
the blanket *.xcodeproj rule.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-13 01:12:55 -07:00