Files
T

7.1 KiB

ADDED Requirements

Requirement: P3D-001 Apple Silicon platform baseline

The client SHALL target Apple Silicon with macOS 26 primary, macOS 15/14 supported, and a non-release macOS 27 compatibility lane when its SDK/runtime exists.

Scenario: Supported platform matrix

  • WHEN the frozen candidate is qualified
  • THEN exact native evidence exists for macOS 26, 15, and 14, while Intel is not claimed

Requirement: P3D-002 isolated SwiftUI state

The shell SHALL use SwiftUI with structured concurrency and isolated authentication, resource, broker, stream, and settings state.

Scenario: Concurrent state update

  • WHEN control and stream events arrive concurrently
  • THEN owning actors serialize mutation and views receive immutable main-actor projections

Requirement: P3D-003 no former C++ core

The implementation SHALL NOT restore the superseded C++ core packaging design.

Scenario: Core dependency audit

  • WHEN the native client dependency graph is inspected
  • THEN no VerseVDI C++ streaming core or wrapper is linked

Requirement: P3D-004 stable C ABI

The C ABI SHALL use sized versioned tables and define pointer ownership, lifetime, callback thread, cancellation, error, reentrancy, and destroy behavior.

Scenario: Older caller table

  • WHEN a caller supplies a supported older structure size
  • THEN the core reads only available fields and returns a deterministic compatibility result

Requirement: P3D-005 Rust core

The platform-neutral streaming core SHALL be Rust, not the superseded C++ implementation.

Scenario: Core artifact inspection

  • WHEN the XCFramework artifact is inventoried
  • THEN its exported VerseVDI surface is the reviewed C ABI backed by the pinned Rust core

Requirement: P3D-006 Swift platform ownership

Swift SHALL own HTTPS/WebSocket control, Keychain, navigation, accessibility, Apple decode/render/audio/input objects, signing, and update integration.

Scenario: Platform operation routing

  • WHEN a platform credential, window, decoder, audio device, or input operation occurs
  • THEN it is owned by Swift/AppKit/Apple frameworks and not by the Rust core

Requirement: P3D-007 narrow credential storage

Refresh credentials and device private keys SHALL use the narrowest practical Keychain accessibility; access tokens and gateway grants SHALL remain memory-only.

Scenario: Relaunch storage audit

  • WHEN the app terminates and relaunches
  • THEN no access token or gateway grant is recoverable from persistent client storage

Requirement: P3D-008 authenticated device enrollment

First use SHALL authenticate before device-key generation/registration and SHALL complete server challenge proof before launch authority.

Scenario: Unauthenticated enrollment attempt

  • WHEN device enrollment is requested without a current authenticated user session
  • THEN no key is registered and no launch authority is issued

Requirement: P3D-009 no active LDAP mode

The Phase 3D client SHALL NOT expose an active LDAP login mode before Phase 6.

Scenario: Login surface inspection

  • WHEN the Phase 3D login UI and control requests are exercised
  • THEN only local login is offered and no LDAP request is made

Requirement: P3D-010 authorized resources only

The UI SHALL show only assigned desktops and entitled pools, including unavailable assignment, awaiting_desktop, and capacity queue state.

Scenario: Cross-subject cached resource

  • WHEN stale local data references another subject's resource
  • THEN reconciliation removes or withholds it and no action is available

Requirement: P3D-011 idempotent broker reconciliation

The client SHALL request/cancel idempotently, apply events by sequence, resync gaps through REST, and reconcile current authority after relaunch.

Scenario: Event sequence gap

  • WHEN the next event sequence is not contiguous
  • THEN incremental application stops and REST reconciliation completes before further action

Requirement: P3D-012 gateway-only manifest

The client SHALL accept only a gateway-only manifest matching authenticated server, device, session, audience, expiry, and supported tunnel range.

Scenario: Wrong manifest context

  • WHEN any manifest binding or required tunnel capability is wrong
  • THEN the core rejects it before opening a media/input session

Requirement: P3D-013 forbidden provider details

The client SHALL reject and safely report any manifest containing a provider/VM endpoint or credential-like field.

Scenario: Provider field injection

  • WHEN a manifest contains a provider address or credential-shaped field
  • THEN launch fails closed and diagnostics contain no injected value

Requirement: P3D-020 callback isolation

Core callbacks SHALL transfer bounded immutable values to their owning actor and SHALL NOT mutate SwiftUI state directly.

Scenario: Callback storm

  • WHEN callbacks arrive rapidly from a non-main core thread
  • THEN bounded bridge delivery preserves order/ownership without direct view-state mutation

Requirement: P3D-025 fake-core-first candidate

The client SHALL pass fake-core UI behavior before real-core fixture integration and SHALL freeze a platform-qualified candidate before owner live Apollo acceptance.

Scenario: Live provider unavailable

  • WHEN deterministic implementation gates pass without owner Apollo access
  • THEN the candidate can reach engineering review with live interoperability recorded deferred-owner-e2e

Requirement: P3D-026 XCFramework packaging

The Rust core SHALL be packaged as a static library within an XCFramework behind one stable C ABI and thin Swift wrapper.

Scenario: Unsafe-call audit

  • WHEN Swift source is inspected
  • THEN only the designated bridge owns direct C ABI pointer and callback translation

Requirement: P3D-027 core responsibility boundary

The Rust core SHALL own tunnel negotiation, cryptography, reconstruction, encoded delivery, input encoding, policy updates, statistics, and core errors without owning product authorization or Apple UI/media devices.

Scenario: Responsibility audit

  • WHEN the core dependency/module graph is inspected
  • THEN no SwiftUI, Apple decoder/renderer/audio device, or product-auth implementation is linked into it

Requirement: P3D-030 registered media dispatch

Core and client SHALL dispatch framing, reconstruction, decode, and render from registered negotiated identifiers and SHALL fail stably on unsupported/stale combinations.

Scenario: Unsupported profile combination

  • WHEN framing and media identifiers have no supported explicit intersection
  • THEN the session fails before decoder allocation without guessing, fallback, or transcode

Requirement: P3D-031 local authentication lifecycle

The MVP SHALL support local login, rotating refresh, logout, device-revocation response, and generic anti-enumeration errors.

Scenario: Refresh-family revocation

  • WHEN the Server reports refresh reuse or device revocation
  • THEN local authority and active input/stream state are cleared and generic reauthentication is shown