Native SwiftUI companion for an authoritative Serve host. This target is deliberately source-only: it expects the sibling ../apple-shared shared client for discovery, TLS/HostId validation, pairing, Keychain storage, bootstrap, replay, reconnect, and idempotent commands.
The observations below are historical source checks, not 0.8.0 candidate verification or native-app release qualification.
- The sibling package now compiles:
swift buildinapps/apple-shared->Build complete!. - This target still does not build.
apps/macos/Package.swiftnames the shared package's only real product (OctetServe), excludesSources/OctetMacOS/Resources/Info.plistfrom the executable target (scripts/build-app.shinstalls it intoContents/Info.plist; SwiftPM forbids Info.plist as a resource), and the three source files that referenced the absent module importOctetServeinstead.swift buildthen reports exactly three errors, all inSources/OctetMacOS/MacOSClientFactory.swiftand all caused by one missing surface:cannot find type 'ServeClient' in scope,cannot find 'ServeClientConfiguration' in scope, andcannot find 'ServeClient' in scope. - Missing primitive (nothing was invented here): a shared client module that exports the API this
target consumes —
ServeClient,ServeClientConfiguration,ServeClientError,ServeConnectionState,ServeBootstrap,ServeCommands/ServeCommand/ServeCommandResultandServeEvent(transport, TLS/HostId validation, pairing, Keychain credential storage, replay, reconnect, idempotent commands). None of those names is declared anywhere in this tree (apps/apple-shared/Sources/OctetServeholds wire DTOs only:Identifiers,JSON,RuntimeModels,WireEnums,WireModels). The alternative is to rewire this target onto the app-owned boundary idiom thatapps/iosuses (ServeClientBoundary+ a closure factory), which is a redesign rather than a missing file. - Still hardware/qualification-gated and not claimed: Xcode app build, code signing, notarization, DMG/install/update, a live Serve host, LAN discovery, pairing, and sleep/wake reconnect.
Package.swift expects the sibling package at apps/apple-shared (the app path is apps/macos, so the relative package path is ../apple-shared) and its OctetServe product. The source-required client types listed above are absent; no HTTP, WebSocket, QR, TLS, or credential implementation belongs in this target.
- LAN discovery and manual host inspection, fingerprint-word confirmation, one-time ticket pairing, approval polling, cancellation, revocation, and host-identity-change handling.
- Inventory bootstrap followed by session snapshots and live host events; streamed assistant/tool output, progress, source/output references, approvals, user-input requests, interrupt, steer, and follow-up controls.
- PR status and links are rendered from host-authoritative session state.
- Sleep/wake and reconnect preserve selected session and drafts. Ambiguous mutations are reconciled by command ID and are never submitted a second time by the UI.
- Passive notifications contain only a session/event route. Clicking one revalidates authority and cursor state before opening a session.
- SwiftUI accessibility labels, keyboard commands, focus-safe background updates, and native menu/window behavior.
The scripts under scripts/ are authored but intentionally not run in this source-only delivery:
build-app.shassembles a versioned unsigned.appfrom a release SwiftPM build and requiresCONFIRM_BUILD=OCTET_BUILDbefore replacing an existing output.sign-app.shsigns with an explicitly supplied Developer ID identity and entitlements; it refuses an absent identity.notarize-app.shsubmits a Developer ID-signed app through an explicit notarytool keychain profile, staples and validates it, and replaces it only withCONFIRM_NOTARIZE=OCTET_NOTARIZE.make-dmg.shrequires a Developer ID signature, valid stapled notarization ticket, and passing Gatekeeper assessment before copying the app into a distributable DMG. Runnotarize-app.shbeforemake-dmg.sh; replacing an existing DMG requiresCONFIRM_DMG=OCTET_DMG.install.shverifies the bundle identity/signature and installs a locally supplied, already signed app withCONFIRM_INSTALL=OCTET_INSTALL.update.shverifies a local artifact's SHA-256, signature, bundle identity, and numericCFBundleVersion, and installs it only if newer than the installed app withCONFIRM_UPDATE=OCTET_UPDATE. Equal versions and downgrades are refused; there is no downgrade operation.remove.shrequires an explicit confirmation before deleting only the installed app; shared pairing credentials remain owned by the shared Serve client package.
Replacement operations stage beside the installed app and retain a rollback copy until the new app has been moved into place. No script removes quarantine metadata.
This source-only target has no signed, notarized, installed, or live-tested release artifact.