52e1e8288b
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2.8 KiB
2.8 KiB
BroV — guide for AI coding agents
BroV is a personal, never-published fork of Coucou (github.com/Louis-CFM/coucou, MIT, imported at 83708fe). Native macOS app in NotchBuddy/: an animated character in the MacBook notch that shows Claude Code sessions, lets the user approve/answer from the notch, and chats — with the user's own claude CLI as its brain (no API key).
Where things are
NotchBuddy/Sources/App/— Mac app code.NotchBuddy/Sources/CoucouKit/— shared models, the character engine (BotEngine.swift), pills (PillCatalog.swift).NotchBuddy/Sources/App/ClaudeCodeCLI.swift— runsclaude -p … --output-format stream-json --resume <id>for the chat.NotchBuddy/Resources/sounds/— WAV sounds.NotchBuddy/project.yml— XcodeGen project (never edit the.xcodeprojby hand; it is git-ignored and regenerated).
Build
bash scripts/build.sh # xcodegen + xcodebuild, installs ~/Applications/BroV.app, relaunches
bash scripts/render-brov.sh # character in every state → /tmp/brov-states.png
DerivedData must stay outside ~/Documents (iCloud adds Finder attributes and codesign fails).
Rules
- Personal use only: never publish to GitHub or any public place. The original Coucou name, Mochi character and icon are not used in BroV.
- Swift 6, SwiftUI + AppKit. One dependency: SwiftTerm (term.macOS tabs). The character is 11 Memoji images (
Resources/memoji) moved byBotEngineat 30 fps. - Secrets live in the Keychain or the root-only network core folder, never in git.
- Never block Claude Code: if the app doesn't answer, the hook exits immediately.
- Never overwrite
~/.claude/settings.json: dated backup, merge, write only after the user confirms. - Never approve a Claude Code permission without an explicit click.
- When spawning
claude, stripCLAUDECODEfrom the environment and close stdin. - Pill IDs are stable contract values: never rename an existing pill ID.
Network core (globe 🌐 in the header)
- mihomo runs as root: LaunchDaemon
local.maksar.brov.netd, binary + config + keys + API secret in/Library/Application Support/BroV/(root, 0700). Nothing user-writable is read by root. - BroV never sees the config or the API secret: it talks to the narrow root helper
scripts/netcore/netctl.py(LaunchDaemonlocal.maksar.brov.netctl, socket/var/run/brov-netctl.sock, only the installing user) — commands: state, select, delay, tun, add_key, remove_key. scripts/netcore/gen.pybuilds the config (Amnezia keys → providerkeys/amnezia.yaml, WireGuard clients, VLESS subscription). Install/update:sudo sh scripts/netcore/install.sh(verifies the mihomo SHA256, migrates keys). Never commit keys, configs or the guide (~/.brov-secrets).- Reloading the whole core config drops every connection (including this chat); group switches and provider reloads don't.