Skip to content

feat: add explicit app permission and service status controls (#34) - #48

Draft
bigduu wants to merge 1 commit into
masterfrom
nova/feat/34-permission-status
Draft

bigduu wants to merge 1 commit into
masterfrom
nova/feat/34-permission-status

Conversation

@bigduu

@bigduu bigduu commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Nova currently requests Screen Recording permission at startup and offers no menu for checking its service or permissions. This change gives the independent macOS Nova.app a native status menu with separate service, Accessibility and Screen Recording states. Startup and Refresh Status only check permissions; each request and settings link requires the corresponding explicit menu action.

The service reports Ready after its existing listeners bind, preserves a visible Failed state, and distinguishes a duplicate launch from failure. Quit releases the owned listener before the dedicated app process exits, including when a native worker is still blocked. The existing connector, running-application discovery and capture-helper recovery remain the underlying implementations.

Closes #34.

Test Plan

  • 141 named safe tests passed: 125 library, 3 CLI, 2 app-service, 1 app-status, 8 managed MCP and 2 DevTools launcher tests. Environment-dependent tests remain ignored.
  • Separate process fixtures passed for Quit with a still-blocked native worker and for the resident AppKit application-discovery loop.
  • macOS and aarch64 Windows all-targets Clippy with warnings denied, formatting, full locked/all-features metadata and diff checks passed.
  • One initial run of the pre-existing singleton test observed the interval between bind and chmod. Its binding code is unchanged; the targeted rerun and complete affected safe suite passed. The focused follow-up is recorded separately in [nova] test: synchronize app-service readiness before socket-mode assertion #49 (Triaged, unclaimed).
  • An isolated packaged preview completed MCP initialize, 35-tool discovery, ping and application inspection with Accessibility ungranted. The installed Bodhi process remained running throughout.
  • Independent exact-head code review approved b5f8c706f5069ee15fa58f6e1e56a4736350bcdf; all six CI checks passed in run 34012774464.
  • The final universal arm64/x86_64 candidate is installed at /Applications/Nova.app, signed with the existing local certificate and unchanged designated requirement. Its reviewed source/tree and binary hash are recorded in the local install receipt; the prior app backup is retained. This remains a local candidate, not a production release.
  • Installed MCP initialize, 35-tool discovery, ping and inspection pass. Accessibility remains ungranted; the original Bodhi main process is still running with its original launch time.
  • Pending before merge: real menu interaction, actual permission transition and Refresh in this installed candidate while Bodhi stays open, plus focused menu screenshots. The user has been asked for the specific Accessibility grant; no permission change is inferred from the broader implementation request. This PR remains draft until these acceptance gates are complete.

Screenshots

Focused menu screenshots will be added after live GUI verification. The final reviewed universal candidate is installed; the isolated preview was stopped. The available Computer Use adapter times out on this windowless menu-bar application. User-assisted menu interaction and the explicit Accessibility grant are pending. No desktop permission has been requested, reset or changed during implementation.

@bigduu bigduu added the review:needed Waiting for review label Sep 6, 2026
@bigduu

bigduu commented Sep 6, 2026

Copy link
Copy Markdown
Owner Author

Independent code review completed by bodhi_nova_boundary for exact head b5f8c706f5069ee15fa58f6e1e56a4736350bcdf, tree b64cbeb5bd216bb391357f069232712400247f92, against current master 7f97daa14528600ef26df870e5a98ee37d51952d.

No blocking code findings introduced by this diff. The review covered all 15 files, passive permission checks and selected-only requests, status ownership, both listener bind boundaries, AppKit target/menu lifetime, Quit listener cleanup and terminating-runtime boundary, unchanged connectors/capture recovery, and macOS/Windows dependency guards. Local evidence includes 141 safe named tests plus the Quit and resident-AppKit process fixtures, strict macOS/Windows Clippy, formatting and locked all-features metadata.

The initial singleton test observation is the existing bind-before-chmod test race, with unchanged production binding code and protected parent directory. Targeted and complete safe reruns passed; this adjacent test issue is not added to #34.

This is code approval only. The PR remains draft and must not merge until real packaged-menu interaction, permission transition plus Refresh while Bodhi stays open, final universal app verification, and every CI check pass. No GUI acceptance or permission grant is inferred from automated tests or the windowless application's Computer Use timeout.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review:agent Agent review complete; human final review may proceed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[nova] feat: add explicit app permission and service status controls

1 participant