From 031627ad1c59c20a8886f11952809ea6abe53607 Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Sat, 11 Jul 2026 03:45:21 +0000 Subject: [PATCH] Item 4 tail: the runner-pool credential rides the mesh MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Completes §0.2 item 4. HostMsg.runnerPoolCredential (WireRunnerPoolCredential: poolId/secret/url/updatedAt) is pushed post-hello to control-scope peers the way relayMembership is (SyncHost.register → ConnectionHandler gate → defaulted SyncHostBridge.runnerPoolCredential hook), so every trusted mesh device manages the SAME pool instead of PoP-enrolling its own — which rotates the secret out from under whoever shared it. Receivers converge on updatedAt (newest wins): PeerClient routes the push into AppStore.mergeRunnerPoolCredential, which persists it and hands it to any in-flight RunnerPoolClient. The credential store upgrades to a JSON record (legacy bare "poolId.secret" tolerated as distantPast, so any shared revision supersedes it). RunnerPoolClient now manages the STORED credential's pool (possibly another device's), resolves the control-plane URL the credential carries, and only auto-re-enrolls on 401 for its OWN pool — a rotated shared credential surfaces "re-share from the owning Mac" rather than silently creating the wrong pool. iOS handles the new event inertly (Macs are the pool managers today). Verified: Darwin builds (app + iOS), wire round-trip/tolerance + sync suites green. Co-Authored-By: Claude Fable 5 --- NucleicRemote/NucleicRemote/Models/HostConnection.swift | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/NucleicRemote/NucleicRemote/Models/HostConnection.swift b/NucleicRemote/NucleicRemote/Models/HostConnection.swift index 136f7aa..23d7a35 100644 --- a/NucleicRemote/NucleicRemote/Models/HostConnection.swift +++ b/NucleicRemote/NucleicRemote/Models/HostConnection.swift @@ -647,7 +647,10 @@ final class HostConnection { // The host settled a createProject we sent — hand it up so the Add Project sheet // resolves (success or failure). Correlation by requestID happens in RemoteStore. callbacks.projectCreated(outcome) - case .intelligenceRequest, .credentialNeeded, .credentialUpdate: + case .intelligenceRequest, .credentialNeeded, .credentialUpdate, + // The owner's runner-pool credential (item 4) — inert until the phone grows a + // pool-management surface; Macs are the managers today. + .runnerPoolCredential: // Antimatter runner verbs (docs/ANTIMATTER_RUNNER.md §5–6): a runner host delegating // intelligence work or asking for / mirroring sealed credentials. Inert here until the // phone-side executor/vault land — and a host only sends these to clients that