Completes Phase 5 of the multi-device mesh / session-transfer program (docs/MESH_TRANSFER.md) except the two-Mac memory-carry spike. All additive + capability-gated; SyncProtocol stays v1. - Moved-session visibility: additive SessionSummary.movedTo (MovedDestination), decode-defaulted. A moved session no longer silently vanishes — the source keeps a read-only "Moved to <Mac>" tombstone under Archived (name resolved live from paired Macs), surfaced on relaunch without rebuilding a runnable controller, and sent on the wire so phones see it too. - Relaunch recovery driven from launch (+ on every peer reconnect, single-flight): AppStore.recoverInterruptedTransfers clears abandoned pre-tombstone locks, discards orphaned inbound staging, and re-drives a tombstoned commit via SessionTransferCoordinator.recoverTombstoned (bounded, idempotent; a dest that lost staging leaves the lock, never revives the source). - Bulk "Hand off active sessions…": transferableSessions + moveSessionsToPeer (sequential, rollup error) behind a "Hand off…" button → HandoffSheet checklist in RemoteAccessView. - Arrived-from provenance (mirror of moved-to): GRDB v24 arrived_from_device_id/arrived_at; the importer stamps them at staging; additive SessionSummary.arrivedFrom (ArrivedFrom); a subtle "Arrived from <Mac>" marker on the sidebar (live name) + iOS row (host-baked name). - Stranded-arrival "Activate anyway": the importer persists the staged Session to the staging dir at .ready, so a destination that relaunches before commit can recoverableInboundTransfers() and activateRecoveredTransfer()/clearInboundStaging(). AppStore surfaces pendingArrivedTransfers with activate/discard, shown in a new "Interrupted arrivals" section. (A .ready lock with no manifest is now cleared as unrecoverable.) Tests: +6 core, +2 protocol across WireMessageTests, SessionTransferTests, AppStoreTests, AppStoreSyncBridgeTests. Full package builds; Swift suites green. iOS NucleicRemote edits reviewed but not compiled here (separate Xcode target). Co-Authored-By: Claude Opus 4.8 <[email protected]>
NucleicRemote (iPhone client)
The thin iOS remote client for Nucleic (PLAN milestone M4). It's a pure projection of the
Mac host over LAN: monitor sessions, read transcripts/diffs, answer approvals, and send
follow-up input — scope approve. No local git or CLI; the Mac is the single authority
(see docs/UX_IOS.md and docs/SYNC_PROTOCOL.md).
Architecture
All wire/crypto logic is shared with the Mac via the NucleicProtocol SwiftPM library
(this Xcode project links it as a local package at ../..):
- Transport —
NWFrameChannel(NWConnection) +LANDiscovery(Bonjour_nucleic._tcp). - Engine —
NucleicProtocol.SyncClientruns the Noise handshake (XXpsk0 to pair, IK to reconnect), exchanges hello/welcome, and turnsHostMsgs into aSyncClient.Eventstream. - State —
RemoteStore(ObservableObject) is the single on-device UI state, a pure projection of the host. Identity + pinned host live inIdentityStore(Keychain + UserDefaults). - UI — SwiftUI:
SessionsView(attention-first list),SessionDetailView(transcript/diff + status-driven action area),ApprovalCardView(Face ID gate on high-risk),PairingScannerView(QR),SettingsView.
Build & run
# Resolves the local NucleicProtocol package automatically.
xcodebuild -project ios/NucleicRemote/NucleicRemote.xcodeproj \
-scheme NucleicRemote \
-destination 'platform=iOS Simulator,name=iPhone 17 Pro' build
Or open NucleicRemote.xcodeproj in Xcode and run. To pair, start the sync server on the Mac
(Nucleic ▸ Settings ▸ Add iPhone shows the QR), then scan it. On a real device, both must be
on the same Wi‑Fi.
Status
The full pair → list → subscribe → approve → reconnect path is implemented and the protocol/
server side is covered by tests in Tests/NucleicProtocolTests and Tests/NucleicCoreTests.
Push notifications / Live Activity (UX_IOS §5.1/§5.3) are the M5 follow-up (needs the relay).