Commit Graph
71 Commits
Author SHA1 Message Date
abkslmandnucleic 0404147164 nvrsion: Add: Fix truncation of “Run now” button text in New idea composer, add model selector support for Claude Fable 5, refactor Project Workflow Enhancement, add Wait Button Logic, update iOS remote to match Chat Message Queue Display, block sandboxed/controlled agents from running git commands via mcp__nucleic__host_exec using container-level shims, add chat icon animation to bounce when chat is blocked for >60 seconds, add “Cmd+Shift+N” shortcut to open a floating chat composer over the window, remove “Run now” button from “New idea” composer, and shield Git command execution by scanning inside ‘-c’ strings.
Nucleic-Promote: 1
Co-authored-by: Nucleic <[email protected]>
2026-07-01 19:01:20 -07:00
abkslmandnucleic 911a426e0f Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:52:26 -07:00
abkslmandnucleic bddb019f2d Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:51:35 -07:00
abkslmandnucleic a28ed3f1b4 Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:51:22 -07:00
abkslmandnucleic e39bbaa2b3 Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:46:25 -07:00
abkslmandnucleic 119d53ebf1 Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:44:28 -07:00
abkslmandnucleic 45dbe9ea71 Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:44:04 -07:00
abkslmandnucleic f5babebaad Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:43:57 -07:00
abkslmandnucleic d93fd4077b Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:43:51 -07:00
abkslmandnucleic ae0c064972 Redirect Configuration
Nucleic-Session: D73FB6C0-C262-4297-A577-B37D0F149DCB
Co-authored-by: Nucleic <[email protected]>
2026-06-28 19:43:32 -07:00
abkslmandnucleic ca6a45b44d Version Communication Enhancement
Nucleic-Session: 1367F61F-9C84-4D8B-9ECC-01DEE9DF01E4
Co-authored-by: Nucleic <[email protected]>
2026-06-27 22:24:37 -07:00
abkslmandnucleic cae771d84b Commit Message Revision
Nucleic-Session: 37EA5099-12C5-4C33-AD88-798A5464D107
Co-authored-by: Nucleic <[email protected]>
2026-06-27 21:49:22 -07:00
abkslmandnucleic f10d2a6e26 Commit Message Revision
Nucleic-Session: 37EA5099-12C5-4C33-AD88-798A5464D107
Co-authored-by: Nucleic <[email protected]>
2026-06-27 21:49:13 -07:00
abkslmandnucleic b74100dba8 Commit Message Revision
Nucleic-Session: 37EA5099-12C5-4C33-AD88-798A5464D107
Co-authored-by: Nucleic <[email protected]>
2026-06-27 21:49:00 -07:00
abkslmandnucleic 0ae143c680 Version Promotion Logic
Nucleic-Session: C8D4A2E8-50AB-4F8B-ABFB-78AF4BAFE643
Co-authored-by: Nucleic <[email protected]>
2026-06-27 19:13:44 -07:00
abkslmandnucleic c31d77c02f Version Promotion Logic
Nucleic-Session: C8D4A2E8-50AB-4F8B-ABFB-78AF4BAFE643
Co-authored-by: Nucleic <[email protected]>
2026-06-27 19:13:35 -07:00
abkslmandnucleic a0f6e0c984 Session Command Conflict Detection
Nucleic-Session: 7B641658-B34C-4780-86B5-A4038C3749DE
Co-authored-by: Nucleic <[email protected]>
2026-06-27 17:56:30 -07:00
abkslmandnucleic b1cca25ecc Session Command Conflict Detection
Nucleic-Session: 7B641658-B34C-4780-86B5-A4038C3749DE
Co-authored-by: Nucleic <[email protected]>
2026-06-27 17:56:21 -07:00
abkslmandnucleic 5af826deb4 Session Command Conflict Detection
Nucleic-Session: 7B641658-B34C-4780-86B5-A4038C3749DE
Co-authored-by: Nucleic <[email protected]>
2026-06-27 17:39:11 -07:00
abkslm c834c23c67 Promote Chat Session Notification
Nucleic-Session: 68E3C84F-A081-45F2-9B94-0D49D06A0F51
2026-06-27 14:52:33 -07:00
abkslm 279ea38c04 Promote Chat Session Notification
Nucleic-Session: 68E3C84F-A081-45F2-9B94-0D49D06A0F51
2026-06-27 14:52:11 -07:00
abkslm 4bca5be90f Promote Chat Session Notification
Nucleic-Session: 68E3C84F-A081-45F2-9B94-0D49D06A0F51
2026-06-27 14:52:05 -07:00
abkslm 3040e74ef3 Promote Chat Session Notification
Nucleic-Session: 68E3C84F-A081-45F2-9B94-0D49D06A0F51
2026-06-27 14:51:50 -07:00
abkslm 8ef09b3318 Promote Chat Session Notification
Nucleic-Session: 68E3C84F-A081-45F2-9B94-0D49D06A0F51
2026-06-27 14:51:38 -07:00
Nucleic 4e09389984 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:26:39 -07:00
Nucleic aea3e24dd8 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:26:19 -07:00
Nucleic 6586fdd6c7 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:26:10 -07:00
Nucleic 45f8732ce6 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:26:04 -07:00
Nucleic 4de0362387 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:57 -07:00
Nucleic fe4e128307 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:53 -07:00
Nucleic 3002e51903 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:48 -07:00
Nucleic 217403ce39 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:43 -07:00
Nucleic 721930770c Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:36 -07:00
Nucleic 94a81256a6 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:28 -07:00
Nucleic 172a1c0296 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:12 -07:00
Nucleic b727e93b85 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:25:06 -07:00
Nucleic 5b09cfb3f6 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:24:55 -07:00
Nucleic 509868ec92 Adjust DAI Metrics File
Nucleic-Session: E357FC5A-6454-41EE-9AA8-139CDB6779DA
2026-06-27 14:24:50 -07:00
NucleicandClaude Opus 4.8 0a967beb19 nucleic-edge: rename relay/push KV bindings to NUCLEIC_RELAY_TOKENS / NUCLEIC_PUSH_TOKENS
Use the NUCLEIC_-prefixed binding names consistently across wrangler.jsonc, the
worker code (env.ts/index.ts/room.ts), and docs (README, CLOUD_INFRA), so the
declared KV bindings match what the Worker reads at runtime.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-27 13:47:33 -07:00
NucleicandClaude Opus 4.8 b50cb60190 Promote nvrsion trunk → dev
Squash-merge nucleic/trunk into dev (234 commits of accumulated nvrsion work).

Resolved two auto-generated-file conflicts:
- cloud/nucleic-edge/wrangler.jsonc: kept dev's real KV namespace ids and the
  xyz.blakeslee.nucleic.remote APNS topic, with binding names corrected to
  RELAY_TOKENS/PUSH_TOKENS to match the worker code on both branches.
- Package.resolved: took trunk's newer dependency pins.

Nucleic-Promote: 1
Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-27 13:43:32 -07:00
NucleicandClaude Opus 4.8 fc6b420990 Signing: rebrand bundle IDs to xyz.blakeslee.* and correct the Team ID
Desktop channels → xyz.blakeslee.nucleic.desktop.{dev,beta,rc,release} (the stable channel keyword is unchanged; only its bundle-id suffix is "release"). iOS remote → xyz.blakeslee.nucleic.remote, including its Keychain account namespaces, the scanner log subsystem, and the coupled APNS topic.

Correct the Apple Developer Team ID to L7UDTQ6F5W across the Xcode project, ExportOptions, the APNS config + tests, and the signing/cloud docs.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-26 16:52:14 -07:00
Nucleic e03d96b38a nvrsion: promote trunk to dev
Nucleic-Promote: 1
2026-06-26 16:18:02 -07:00
NucleicandClaude Opus 4.8 4197c3c0cc nvrsion: Control-tab setting, wrapping fix, and free mode toggling
- Add an app-wide nvrsion toggle to Settings -> Control (nvrsionByDefault), which seeds
  new Nucleic Control projects with nvrsion on; mirrors controlByDefault/sandboxByDefault.
- Clean up the per-project card copy (title 'nvrsion'; new description) and fix Project
  Settings descriptions truncating, by giving each Toggle label .fixedSize so it wraps.
- Make a session's versioning mode fixed at creation (isNvrsionSession = 'its working dir
  is the trunk') instead of re-derived from the project's current toggle. lockDomain and the
  land/re-ground path key off that, so existing chats keep their mode after a flip and the two
  models never mix. Removes the flip-safety guard, which wrongly blocked the toggle whenever an
  idle ('complete', awaitingInput) chat existed.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-25 22:41:44 -07:00
NucleicandClaude Opus 4.8 174da0301e Add nvrsion: per-file shared-trunk versioning for multi-agent orchestration
An opt-in (Beta, Nucleic-Control-only) versioning mode where a project's agent
sessions share one nucleic/trunk checkout, lock individual files per-edit, land each
completed edit into the trunk immediately, and release fast — instead of holding a
session-long lock until a big merge. Conflicts are structurally impossible within the
trunk (serialized per-file writes + forced re-ground), so 'merge' collapses to 'commit'.

- Phase A: ProjectNvrsion config, migration v20-nvrsion, nvrsionActive gate, Beta toggle
- Phase B: NvrsionTrunk actor (ensureTrunk/land/regroundOnGrant), shared-trunk topology
  (no per-session worktree), per-edit host-mediated path-scoped commit + release
- Phase C: NvrsionReleaseGovernor keep-warm idle eviction, launch crash-recovery,
  flip-safety guard
- Phase D: pre-land validation hook, trunk->base squash promotion + 'Promote trunk' UI

Design and rationale: docs/NVRSION.md. Full suite green (585 tests).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-25 21:32:09 -07:00
NucleicandClaude Opus 4.8 47aabd623f docs: vsock control plane is now the default (image v4)
Reflect the promotion in VSOCK_CONTROL_PLANE.md: the control plane rides the vsock-relayed socket by
default as of sandbox image v4, legacy gateway-TCP is the fallback behind an explicit off switch.
Also documents the Grok-install fix (relocated to /opt/grok) and the now-bounded MCP_TIMEOUT.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-25 18:02:22 -07:00
NucleicandClaude Opus 4.8 d5dd09e2a5 Codex exec: control-container exec + interceptor (observe/release)
CodexExecBackend now execs codex exec inside its control container (stdio over vsock) on the vsock control-plane path, with the git/gh/command interceptor wired to the shared per-container server (observe/release -> conflictCoordinator). --ask-for-approval never means no interactive acquire seam, so it joins the lock system on observe/release only. resume() now carries the container through. Gated on the control socket; default behavior unchanged.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 21:53:17 -07:00
NucleicandClaude Opus 4.8 9b85bcdf73 Codex: join the lock/arbitration system in its control container
CodexAppServerBackend now joins conflict locks, like Claude/Grok.

Acquire: an item/fileChange/requestApproval arbitrates on the edited paths before the patch applies (deny on deferred/cancelled/re-ground, ahead of the always-rule cache so an 'always allow' can't slip a conflicting edit past). The approval carries only the item id, so paths are captured from the fileChange item lifecycle (CodexAppServerDecoder.fileChangeItemPaths).

Release/observe: the same shared per-container server + git/gh/command interceptor wiring as Grok. Codex's approvals stay native (no MCP), so only the report routes register.

Gated on the vsock control socket, so default behavior is unchanged. CodexExecBackend (unattended, no interactive approval seam) is left unchanged.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 21:43:00 -07:00
NucleicandClaude Opus 4.8 29678ce618 Grok: wire the git/gh/command interceptor in its control container
GrokACPBackend resolves the shared per-container approval server, starts it on the relayed control socket, registers the git/gh/command report handlers (-> conflictCoordinator: locks + autoship), and injects CommandInterceptor.hookEnv. Grok's approvals stay native ACP (no MCP), so only the report routes register. Gated on the vsock control socket like the exec path, so default behavior is unchanged. Brings Grok control containers to parity with Claude (isolation + git observation). Refreshes the stale host-only comments + docs.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 21:26:53 -07:00
NucleicandClaude Opus 4.8 47bf548e13 Nucleic Control: install + auth-seed Codex and Grok in the sandbox image
Codex via npm (@openai/codex); Grok via the official x.ai installer, symlinked onto the global PATH with a grok --version build check that fails loudly if the arm64 binary didn't land.

containerSpec() now seeds auth per backend: both store auth as plain files (no Keychain), so seedAgentHome copies the host's ~/.codex / ~/.grok into the per-session writable home (the agent's $HOME), where the CLIs find $HOME/.codex / $HOME/.grok automatically. API-key users are covered by forwarding OPENAI_API_KEY / XAI_API_KEY / GROK_CODE_XAI_API_KEY.

Completes the binaries + auth for the gated Grok/Codex control-container exec path. See docs/VSOCK_CONTROL_PLANE.md.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 21:18:18 -07:00
NucleicandClaude Opus 4.8 f93579e6b6 Nucleic Control: vsock control plane for containers (gated, off)
Run a Nucleic Control container's approval + interceptor channel over a vsock-relayed unix socket instead of TCP/HTTP on the VM gateway, so macOS raises no incoming-connection / local-network prompts.

- MCPApprovalServer: real AF_UNIX listener + transport-agnostic ByteConn (host UDS transport).
- ContainerEngine: relay the host control socket into the guest (UnixSocketConfiguration.into); init launches an in-guest loopback bridge (control-bridge.js) forwarding 127.0.0.1:9099 -> the relayed socket.
- ApprovalServerRegistry: one token-multiplexed approval server per shared control container.
- ClaudeCodeBackend: serve UDS-only (no IP listener) + point mcpConfig/interceptor env at the bridge; CommandInterceptor.hookEnv centralizes the interceptor wiring.
- GrokACPBackend / CodexAppServerBackend: exec inside the shared control container (stdio over vsock) for per-family isolation.

All gated behind ContainerServiceSettings.vsockControlPlaneEnabled (default off); legacy gateway-TCP path unchanged. Needs the sandbox image to ship control-bridge.js (and, for Grok/Codex, their CLIs + auth) before flipping the flag. See docs/VSOCK_CONTROL_PLANE.md.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
2026-06-24 21:00:02 -07:00