Files
nucleic-remote-ios/NucleicRemote
abkslmandClaude Opus 4.8 9d4999bb74 Sandbox: host build/run mode (host_exec tool)
Adds a per-project "Allow host build/run" sandbox capability that lets a
containerized agent request to build and run executables on the host
machine, escaping the Linux sandbox — e.g. compiling and running a macOS
binary the container can't.

- New `host_exec` MCP tool on the approval server, advertised only when the
  session opts in. Pre-allowed via --allowedTools so the call reaches our
  handler directly rather than Claude's permission path: the handler is the
  sole gate, so `auto` mode can never auto-approve it.
- Every host command surfaces an explicit approval (risk .hostExec) and runs
  on the host via /bin/zsh -lc in the session worktree only after approval.
  An explicit "Allow for Session" choice grants the rest of the session;
  auto-approve never sets that — only a deliberate user choice does.
- ProjectSandbox.allowHostExec (off by default) with tolerant decoding so
  rows persisted before the field default to false instead of dropping the
  whole sandbox config.
- Threaded allowHostExec through RunSpec/ResumeSpec/SessionController; Mac
  Project Settings toggle; Mac ApprovalBar "Allow for Session" button; iOS
  risk styling/biometric gate for .hostExec.
- Tests: host_exec advertised/served only when registered + refused
  otherwise; allowHostExec round-trip and legacy-JSON default-to-false.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-06-13 16:52:01 -07:00
..

NucleicRemote (iPhone client)

The thin iOS remote client for Nucleic (PLAN milestone M4). It's a pure projection of the Mac host over LAN: monitor sessions, read transcripts/diffs, answer approvals, and send follow-up input — scope approve. No local git or CLI; the Mac is the single authority (see docs/UX_IOS.md and docs/SYNC_PROTOCOL.md).

Architecture

All wire/crypto logic is shared with the Mac via the NucleicProtocol SwiftPM library (this Xcode project links it as a local package at ../..):

  • Transport — NWFrameChannel (NWConnection) + LANDiscovery (Bonjour _nucleic._tcp).
  • Engine — NucleicProtocol.SyncClient runs the Noise handshake (XXpsk0 to pair, IK to reconnect), exchanges hello/welcome, and turns HostMsgs into a SyncClient.Event stream.
  • State — RemoteStore (ObservableObject) is the single on-device UI state, a pure projection of the host. Identity + pinned host live in IdentityStore (Keychain + UserDefaults).
  • UI — SwiftUI: SessionsView (attention-first list), SessionDetailView (transcript/diff + status-driven action area), ApprovalCardView (Face ID gate on high-risk), PairingScannerView (QR), SettingsView.

Build & run

# Resolves the local NucleicProtocol package automatically.
xcodebuild -project ios/NucleicRemote/NucleicRemote.xcodeproj \
  -scheme NucleicRemote \
  -destination 'platform=iOS Simulator,name=iPhone 17 Pro' build

Or open NucleicRemote.xcodeproj in Xcode and run. To pair, start the sync server on the Mac (Nucleic ▸ Settings ▸ Add iPhone shows the QR), then scan it. On a real device, both must be on the same Wi‑Fi.

Status

The full pair → list → subscribe → approve → reconnect path is implemented and the protocol/ server side is covered by tests in Tests/NucleicProtocolTests and Tests/NucleicCoreTests. Push notifications / Live Activity (UX_IOS §5.1/§5.3) are the M5 follow-up (needs the relay).