docs: §8 — app #1 universal clipboard spec (push-ahead, LWW, Option A + toast)

Banks the decided spec for the first app now that the networking is settled:
- identity = sign in with Apple/Google; sub → gossip topic → device list + key
- scope = proximity (push only to directly-reachable peers, never the relay) —
  Apple-esque, reuses prefer-direct/DirectSet as the proximity gate
- flow = push-ahead + last-writer-wins (NOT pull): copy pushes to nearby peers;
  paste just works because the content already arrived. No CRDT (Automerge is
  for app #2).
- agent design: Option A (proactive clipboard write on receive) chosen over B
  (paste-time substitution / hotkey); A is trivial and rides native Ctrl-V.
- mandatory awareness: a non-blocking toast on every remote clobber
  ("Copied from Patrick's iPhone · Photo"), which is also the exfiltration
  tripwire. Optional restore of the prior clipboard.
- the remaining hard part is OS clipboard integration, esp. background capture
  on mobile (iOS/Android restrict it); receiving+pasting is easy everywhere.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-22 00:54:41 -05:00
parent 6a96046a9c
commit 8797ac2670

View File

@@ -321,7 +321,61 @@ and crypto and getting it subtly wrong.
---
## 8. Roadmap
## 8. App #1 — the universal clipboard (the spec)
The first app on the substrate. Goal: **install, sign in once, never look at it
again** — and no walled gardens (works iPhone ⇄ Android ⇄ Windows ⇄ Mac ⇄ Linux,
unlike Apple's Apple-only Universal Clipboard).
**Identity = sign-in.** Sign in with Apple/Google → the `sub` is the account →
derives the gossip topic → you see your other devices (the Tailscale feeling).
That same high-entropy `sub` is also the crypto key (fixes §3's weak-key
problem). One move, three wins: identity, device list, key.
**Scope = proximity, not global.** Apple-esque: push only to **directly-reachable
peers** (same LAN / BLE), *not* relay-distant ones. This reuses the old
prefer-direct/`DirectSet` idea as a proximity gate, keeps content on the local
network (never touches the relay), and makes BLE the literal Handoff analog.
**The flow (push-ahead + last-writer-wins, NOT pull):**
```
iPhone clipboard COPY → push content to directly-reachable peers (scoped)
…moments later…
Windows agent: on RECEIVE → write to the local clipboard (Option A, below),
guarded by recency window + directly-reachable + remote-only
native Ctrl/Cmd-V → just works; the remote content is already there
```
Selection rule: most-recent-copy-anywhere wins (LWW by timestamp across
{local, received}); a recency window stops a stale phone clipboard ambushing a
paste. **No CRDT needed** — push events + LWW is enough; Automerge is for app #2's
shared state, not this.
**Agent design fork — chose A:**
- **A (proactive write, Apple-style, CHOSEN):** on receive, write straight to the
local clipboard → native paste works with zero interception. Trivial. Downside:
it clobbers the local clipboard.
- B (paste-time substitution): non-destructive but needs a dedicated hotkey /
keyboard hook / clipboard-manager role (no OS gives a background agent a "paste
event" to intercept). Deferred polish.
**Awareness is mandatory with A.** Because the write is silent, every remote
clobber fires a **non-blocking toast** (not a modal — a modal on every copy would
kill "never look at it again"): *"Copied from Patrick's iPhone · 📷 Photo"*.
Fires at receive (the clobber moment); only for remote copies; coalesce rapid
ones. Optional: stash the prior local clipboard for a one-click "restore". This
toast is also the **exfiltration tripwire** — nothing enters your clipboard
invisibly; with same-account scope + E2E, the trust model is sound.
**The hard part is no longer networking — it's OS clipboard integration.** iroh
makes the mesh trivial; the platform tax is: (1) **source-side capture on mobile**
— iOS/Android restrict *background* clipboard reads, so the iPhone capturing its
own copy while asleep is the constrained bit (desktop capture is fine); (2)
multi-modal payloads (text inline, audio/photo/data via `iroh-blobs`). Receiving
+ pasting is easy everywhere; capturing on mobile is where the effort goes.
---
## 9. Roadmap
**Near-term (ship the product):**
- [ ] Coordinated rebuild + reinstall of all clients so E2E actually activates
@@ -388,7 +442,7 @@ and crypto and getting it subtly wrong.
---
## 9. One-line summary
## 10. One-line summary
> **Peers with durable keypairs · E2E content · pluggable transports
> (LAN/RTC/QUIC/BT/LoRa) · supernodes volunteering signaling/relay/DHT/discovery