TCC permissions (microphone) are currently only requested at the moment a voice-enabled experience is first streamed. This causes two bugs:
Backup binary TCC prompt: During self-update, the old binary is kept as .backup. If the backup binary is ever executed (e.g. rollback path, or prior test run), macOS treats it as a new identity and shows a separate TCC dialog. This dialog blocks the kiosk display and cannot be dismissed remotely (no Accessibility TCC). The requesting process can even be dead while the dialog persists.
Mid-stream prompts: If the mic permission has never been granted, the first mercator-talks stream triggers the TCC prompt mid-stream, overlaying the experience for the visitor.
On first launch (or after an update that changes the binary identity), hydraheadflatscreen should proactively trigger all TCC permissions it needs by briefly exercising them before the kiosk grid appears:
Additionally, the self-update flow should NOT execute the .backup binary under any circumstance - rollback should be a file copy operation, not a process launch.
.hydranode/bin/hydraheadflatscreen.backuptccutil reset Microphone and killing tccdinternal/cli/run.go: add startup TCC pre-flight that opens + closes an AudioQueue input.backup binary is never exec'd, only used as file-level rollbackMoved from the NimsForest tracker (issue #129), where it was misfiled. This is Hydra work: project hydraheadflatscreen. Original creation date 2026-05-15. Plan, comments and nim actions were carried across; their timestamps here are the migration time, and the original dates are noted inline.