Files
nucleic-remote-ios/NucleicRemote
abkslmandClaude Fable 5 031627ad1c Item 4 tail: the runner-pool credential rides the mesh
Completes §0.2 item 4. HostMsg.runnerPoolCredential (WireRunnerPoolCredential:
poolId/secret/url/updatedAt) is pushed post-hello to control-scope peers the
way relayMembership is (SyncHost.register → ConnectionHandler gate →
defaulted SyncHostBridge.runnerPoolCredential hook), so every trusted mesh
device manages the SAME pool instead of PoP-enrolling its own — which
rotates the secret out from under whoever shared it.

Receivers converge on updatedAt (newest wins): PeerClient routes the push
into AppStore.mergeRunnerPoolCredential, which persists it and hands it to
any in-flight RunnerPoolClient. The credential store upgrades to a JSON
record (legacy bare "poolId.secret" tolerated as distantPast, so any shared
revision supersedes it). RunnerPoolClient now manages the STORED
credential's pool (possibly another device's), resolves the control-plane
URL the credential carries, and only auto-re-enrolls on 401 for its OWN
pool — a rotated shared credential surfaces "re-share from the owning Mac"
rather than silently creating the wrong pool. iOS handles the new event
inertly (Macs are the pool managers today).

Verified: Darwin builds (app + iOS), wire round-trip/tolerance + sync
suites green.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-07-11 03:45:21 +00:00
..
2026-06-27 15:24:50 -07:00
2026-07-06 17:17:16 -07:00
2026-07-04 23:31:40 -07:00

NucleicRemote (iPhone client)

The thin iOS remote client for Nucleic (PLAN milestone M4). It's a pure projection of the Mac host over LAN: monitor sessions, read transcripts/diffs, answer approvals, and send follow-up input — scope approve. No local git or CLI; the Mac is the single authority (see docs/UX_IOS.md and docs/SYNC_PROTOCOL.md).

Architecture

All wire/crypto logic is shared with the Mac via the NucleicProtocol SwiftPM library (this Xcode project links it as a local package at ../..):

  • Transport — NWFrameChannel (NWConnection) + LANDiscovery (Bonjour _nucleic._tcp).
  • Engine — NucleicProtocol.SyncClient runs the Noise handshake (XXpsk0 to pair, IK to reconnect), exchanges hello/welcome, and turns HostMsgs into a SyncClient.Event stream.
  • State — RemoteStore (ObservableObject) is the single on-device UI state, a pure projection of the host. Identity + pinned host live in IdentityStore (Keychain + UserDefaults).
  • UI — SwiftUI: SessionsView (attention-first list), SessionDetailView (transcript/diff + status-driven action area), ApprovalCardView (approve/deny, high-risk answered in-app), PairingScannerView (QR), SettingsView.

Build & run

# Resolves the local NucleicProtocol package automatically.
xcodebuild -project ios/NucleicRemote/NucleicRemote.xcodeproj \
  -scheme NucleicRemote \
  -destination 'platform=iOS Simulator,name=iPhone 17 Pro' build

Or open NucleicRemote.xcodeproj in Xcode and run. To pair, start the sync server on the Mac (Nucleic ▸ Settings ▸ Add iPhone shows the QR), then scan it. On a real device, both must be on the same Wi‑Fi.

Status

The full pair → list → subscribe → approve → reconnect path is implemented and the protocol/ server side is covered by tests in Tests/NucleicProtocolTests and Tests/NucleicCoreTests. Push notifications / Live Activity (UX_IOS §5.1/§5.3) are the M5 follow-up (needs the relay).