First step of Phase 3 (iOS multi-host), per docs/MESH_TRANSFER.md. Converts IdentityStore from a single `nucleic.pairedHost` slot to a `nucleic.pairedHosts` registry (ordered [PairedHost], keyed by fingerprint = hostID), with a one-time migration of the legacy single value on first read (then the old key is removed) so an upgrade keeps its Mac. New registry API — pairedHosts(), pairedHost(id:), upsertPairedHost(_:), removePairedHost(id:) — for the coming RemoteStore multiplexer. A single-host bridge keeps every current caller unchanged and behavior identical: loadPairedHost() returns the active (most-recently-paired) host, savePairedHost upserts + makes active, clearPairedHost removes the active. RemoteStore is untouched and still holds one connection. Settings gains a "Paired Macs" list (the visible artifact): each registered Mac with its fingerprint, an "Active" marker, and a per-host remove (removing the active one unpairs the live connection; removing another just forgets it) — this also gives a removal path now that pairing a new Mac keeps the old one in the registry instead of overwriting it. Verified with an iOS Simulator build (BUILD SUCCEEDED). Remaining Phase 3: the RemoteStore [HostID: HostConnection] multiplexer (simultaneous connections, (hostID, sessionID) keying), host-qualified notifications/Live Activity, host switcher UI, demo N-hosts, and the two-Mac tailnet spike. Co-Authored-By: Claude Opus 4.8 <[email protected]>
NucleicRemote (iPhone client)
The thin iOS remote client for Nucleic (PLAN milestone M4). It's a pure projection of the
Mac host over LAN: monitor sessions, read transcripts/diffs, answer approvals, and send
follow-up input — scope approve. No local git or CLI; the Mac is the single authority
(see docs/UX_IOS.md and docs/SYNC_PROTOCOL.md).
Architecture
All wire/crypto logic is shared with the Mac via the NucleicProtocol SwiftPM library
(this Xcode project links it as a local package at ../..):
- Transport —
NWFrameChannel(NWConnection) +LANDiscovery(Bonjour_nucleic._tcp). - Engine —
NucleicProtocol.SyncClientruns the Noise handshake (XXpsk0 to pair, IK to reconnect), exchanges hello/welcome, and turnsHostMsgs into aSyncClient.Eventstream. - State —
RemoteStore(ObservableObject) is the single on-device UI state, a pure projection of the host. Identity + pinned host live inIdentityStore(Keychain + UserDefaults). - UI — SwiftUI:
SessionsView(attention-first list),SessionDetailView(transcript/diff + status-driven action area),ApprovalCardView(Face ID gate on high-risk),PairingScannerView(QR),SettingsView.
Build & run
# Resolves the local NucleicProtocol package automatically.
xcodebuild -project ios/NucleicRemote/NucleicRemote.xcodeproj \
-scheme NucleicRemote \
-destination 'platform=iOS Simulator,name=iPhone 17 Pro' build
Or open NucleicRemote.xcodeproj in Xcode and run. To pair, start the sync server on the Mac
(Nucleic ▸ Settings ▸ Add iPhone shows the QR), then scan it. On a real device, both must be
on the same Wi‑Fi.
Status
The full pair → list → subscribe → approve → reconnect path is implemented and the protocol/
server side is covered by tests in Tests/NucleicProtocolTests and Tests/NucleicCoreTests.
Push notifications / Live Activity (UX_IOS §5.1/§5.3) are the M5 follow-up (needs the relay).