Skip to content

FlipDeck Mission Control: Mac engine + app, BLE protocol, new Flipper client - #71

Merged
mohabbis merged 5 commits into
masterfrom
claude/flipdeck-takeover-yv3bv3
Sep 24, 2026
Merged

mohabbis merged 5 commits into
masterfrom
claude/flipdeck-takeover-yv3bv3

Conversation

@mohabbis

Copy link
Copy Markdown
Owner

Moves FlipDeck from a USB keystroke deck to Mission Control. The Mac watches the dev environment and the Flipper Zero shows it over Bluetooth LE, and can request a small allowlist of actions. Phase 1 of the plan in ARCHITECTURE.md. The audit behind the keep/remove decisions is in docs/AUDIT.md.

What's in it

Mac (mac/, Swift package)

  • FlipDeckCore has no platform dependencies and builds and tests on Linux:
    • project discovery with Git state (porcelain v2)
    • dev-server detection (ps, lsof listeners, cwd → project)
    • Claude Code and Codex agent providers
    • Vercel integration (.vercel/project.json link, Keychain token)
    • a state-diff event engine with a baseline on first observation
    • a persistent activity log and deterministic notification rules
    • an action allowlist that re-validates targets against live state (PID start time, known URLs only)
    • the FDP/1 session
  • FlipDeckMacPlatform: CoreBluetooth transport with credit-based flow control, Keychain, Mach/IOKit metrics, NSWorkspace effects, notifications.
  • FlipDeckApp: SwiftUI with Overview, Projects, Agents, Services, Activity, Flipper and Settings. It shows empty states rather than placeholder data.
  • flipdeck-headless: runs the engine without the UI and can print the exact frames a Flipper would receive.

Protocol (docs/protocol.md)

  • Line-based frames with CRC-16, at most 240 bytes each.
  • Snapshots are staged and committed atomically; heartbeats and staleness detection keep the link honest.
  • Alerts and action requests are idempotent.
  • Protocol-version handshake; the Mac retries HELLO until the Flipper answers.
  • Golden vectors in docs/protocol-vectors.txt, checked by the Swift and C suites.

Flipper (src/, application.fam)

  • New client; the old keystroke app is removed.
  • Uses its own BLE profile. The BT service takes over the stock serial profile for RPC on every connect (bt.c), so the stock profile can't be reused. Pairing keys are kept separate from the phone app's.
  • Row-based screens: Home, Mac, Projects, Deploys, Services, Agents, Activity, Attention, alert overlay, and a confirm dialog.

Verification

  • Swift core: 71 tests passing on Linux (Swift 6.1). They include:
    • real git repos
    • real listening sockets and processes
    • an end-to-end engine run
    • InteropTests, which drives the Swift session against the Flipper's actual C state machine over pipes
  • C protocol/state: 153 checks under ASan/UBSan (make -C src/tests/host run).
  • Flipper app:
    • scripts/check_flipper_sdk.sh type-checks it against current flipperzero-firmware headers with the firmware's -Werror flags; all 118 external symbols are exported to apps.
    • A full uFBT build passes APPCHK against Momentum's SDK zip (mntm-011).
  • Not verified:
    • The macOS-only Swift code (SwiftUI, CoreBluetooth, Keychain, IOKit) hasn't been compiled, because I had no macOS toolchain.
    • Nothing has run on real hardware or over real Bluetooth.

⚠️ Needs a maintainer: CI workflows

This session's token lacks GitHub's workflow scope, so the intended workflows are in ci/ and need copying into .github/workflows/ (see ci/README.md). They add macOS build and tests, Linux Swift tests, and a uFBT build on every PR. Until then, the existing flipper-host job runs the new C tests, and nothing in CI compiles the Swift code.

Not changed

web/, desktop_helper/ and sd_card/ belong to the old keystroke product and are marked legacy. Vercel still deploys web/, so removing them is your call. After merge, the existing build-fap.yml will build the new app and commit it into web/public/; ci/build-fap.yml replaces that with an artifact upload.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq


Generated by Claude Code

Pivot foundation: a platform-independent Swift core that discovers projects,
reads Git state, detects dev servers and coding agents from ps/lsof, tracks
Vercel deployments, derives normalized events, routes them through
deterministic notification rules, and speaks FDP/1 to a Flipper over any
byte-stream transport.

- docs/AUDIT.md: pre-pivot audit (keep/refactor/remove decisions)
- ARCHITECTURE.md: target architecture and phased plan
- docs/protocol.md + protocol-vectors.txt: wire protocol and golden vectors
- mac/: SwiftPM package; FlipDeckCore builds and tests on Linux (69 tests,
  incl. real git repos, real listening sockets, end-to-end engine run)
- flipdeck-headless: runs the engine without UI for debugging

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq
- BLESerialTransport: CoreBluetooth client for the Flipper serial GATT
  service with credit-based flow control, pairing, and auto-reconnect
- KeychainSecretStore, MacMachineMetrics (Mach/sysctl/IOKit/Network),
  MacSystemEffects (NSWorkspace), MacUserNotifier, OSLogSink
- SwiftUI app: Overview, Projects, Agents, Services, Activity, Flipper,
  Settings; empty states instead of placeholder data
- scripts/build-app.sh + Info.plist to produce a signed FlipDeck.app
- Session: retry HELLO until HI; alerts flush pending snapshots first
- InteropTests: the Swift session against the Flipper's C state machine
- Stricter frame decoding (4 hex CRC digits, 1-7 letter types) with new
  golden vectors

macOS-only files are wrapped in #if os(macOS); they are compiled by the
macOS CI job proposed in ci/test.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq
…lient

The pre-pivot USB-HID keystroke app is removed (it could not exit and never
switched USB into HID mode; see docs/AUDIT.md). It remains in history at
26b96bb. The new app keeps the same appid and layout so existing CI builds
and tests it unchanged.

- fd_proto: FDP/1 framing, CRC-16, stream reassembly (host-tested)
- fd_state: staged snapshots with atomic commit, heartbeats, staleness,
  alert de-duplication, action requests with timeouts (host-tested)
- fd_ble: own BLE profile around the exported serial service, since the
  BT service hijacks the stock serial profile for RPC; separate bonding
  keys; restores the default profile on exit
- fd_ui: row-based screens (Home, Mac, Projects, Project, Deploys,
  Services, Agents, Activity, Attention, alert overlay, confirm dialog)
- scripts/check_flipper_sdk.sh: type-checks against real firmware headers
  with firmware -Werror flags and verifies every symbol is exported

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq
README, CLAUDE.md, CONTRIBUTING and ARCHITECTURE now describe FlipDeck
Mission Control. Docs that only described the removed keystroke app are
deleted; web-installer docs move to docs/legacy/. ci/ holds workflows for
.github/workflows/ that this session could not push (no workflow scope).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq
@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
flipdeck Ready Ready Preview Sep 24, 2026 4:58am UTC

Request Review

Binding(get:set:) inferred a non-optional SidebarItem, so the setter's
optional unwrap wouldn't type-check on macOS. Also move enum pattern
matches out of view builders into computed properties.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PMkHPu93LjX5phcrk37APq
@mohabbis
mohabbis marked this pull request as ready for review September 24, 2026 12:57
Copilot AI lite review requested due to automatic review settings September 24, 2026 12:57
@mohabbis
mohabbis merged commit add9185 into master Sep 24, 2026
5 checks passed
@mohabbis
mohabbis deleted the claude/flipdeck-takeover-yv3bv3 branch September 24, 2026 12:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T12:58:56.425404Z 1b147b7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

This branch was successfully deployed

1 active deployment
Preview — 1b147b7f Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants