The task list behind the roadmap. Each item has a stable ID, a completion gate and a record of the evidence behind it. Updated 2026-09-12. No launch dates are promised.
Resume here: Work after the base API goal is the consolidated handoff of outstanding validation, deferred features and product decisions, each with a clear completion gate. Use it for current remaining work. The sections below keep earlier slices under their original IDs.
How to read it. [x] means implemented and checked within the stated scope; [ ] means pending or partly implemented, as the entry says. Scope matters: a fixture, a browser preview, a native build, a user confirmation and a live-host run are different kinds of evidence, and each entry names the ones it has. For BASE-11, the kernel roadmap and the eight-area acceptance audit take precedence over older notes here; superseded checkpoints live in the kernel history.
-
WIN-HOST-04 — Windows mapped-file behavior assessed for release. Closed-file rename/delete are fixed and verified through the Windows host. Native Windows sharing refusals remain respected. Simultaneous readers/writers and open-file rename remain accepted SFTP server/protocol limitations by user decision; no remote helper, custom server, or lock-bypassing workaround will ship. See Windows behavior and evidence. Re-test if upstream changes; do not claim that upgrades guarantee full parity. ACL-preserving staged editor saves remain a separate limitation with the existing confirmation.
-
WIN-HOST-01 — Reliable existing-file saves. Windows uses explicitly confirmed in-place saves, preserving the existing file's security descriptor. A single read/write handle avoids Windows sharing failures while rechecking contents. Live overwrite, larger Unicode text, stale revision rejection and empty saves passed; unconfirmed saves left the original intact.
-
WIN-HOST-02 — Binary transfer interoperability. Split SFTP writes into 16 KiB requests without changing logical transfer limits. Account for Windows' synthetic FSTAT permissions while checking full path and handle revisions independently. Live normal upload, download, copy, cancellation cleanup and stale-source rejection passed on a 2 MiB fixture.
-
WIN-HOST-03 — Desktop acceptance. Verify the repaired Drives view, native clipboard/folder round trips, WinFSP and cross-drive behavior on Windows OpenSSH. Clock timeout handling now allows bounded Windows startup, retains fresh samples and retries failures sooner; prolonged contention still needs observation.
See Windows-host live results for passed checks, exact remaining gaps and the repeatable disposable probe.
| Area | Done | In progress | Not started |
|---|---|---|---|
| M1 · Extensible base | BASE-01 to BASE-11 | ||
| M2 · Everyday workspace | CORE-00, CORE-01a, CORE-05a, CORE-07, CORE-08, CORE-09a, CORE-10a, CORE-10b (themes) | CORE-01b, CORE-02, CORE-03, CORE-04, CORE-05, CORE-06, CORE-09b, CORE-10b (host settings), UX-01 | |
| File clipboard | CORE-05b, CORE-05d, CORE-05e | CORE-05c | |
| M3 · Remote providers | HOST-02 | HOST-01, HOST-03, HOST-04 | |
| M4 · External extensions | EXT-01, EXT-02, EXT-04, EXT-05 | EXT-03 | |
| Connection adapters | LINK-01 to LINK-04 | ||
| M5 · Optional AI assistant | AI-00, AI-02, AI-03 | AI-01 | |
| M6 · Distribution and community | SHIP-00, SHIP-01, COMM-00 | SHIP-02, COMM-01 | SHIP-03, SHIP-04 |
"In progress" covers entries marked partly implemented or partly validated, and items with delivered parts. The post-goal handoff adds the POST, BRIDGE and later items.
Prioritize a dependable working desktop over adding protocols or more bundled apps. Delivered: terminal containment/actions, saved host CRUD, independent host workspaces, Files context actions/clipboard, multiple app instances, existing-file text editing with unsaved guards, and persistent desktop/app preferences. Save As, explicit reconnect, provider-owned navigation, regular-file transfers and provider-defined host settings are also implemented. Next: remaining native integration and failure-handling gates. Core completion work records the earlier stopped overnight goal. Keep the composite-adapter architecture as a constraint rather than building every adapter now.
-
BASE-11 — System API and runtime extension core (Windows). Shared dialogs/services, runtime app/adapter packages, independent source replacement, SDKs/schemas, standard-service starters and AI development skills are delivered. The acceptance audit maps all eight areas to runtime evidence and final clean-source verification: 258 frontend tests, 186 Rust tests, SDK checks, Clippy and the Windows build. No new API families are required. Additional native platforms, protocols and advanced clipboard features are separate follow-ups.
-
BASE-01 — Versioned bundled app registration. Validate unique IDs, API version, scope, capabilities and layout. Derive initial apps from manifests. Gate: an app with a new ID can open without shell edits; invalid manifests fail clearly. Unit coverage and Host details provide the proof.
-
BASE-02 — Window lifecycle. Keep minimized apps mounted; close unmounts them; dock reopens closed apps; maintain full focus order. Preserve toolbar/dock work area. Gate: three-app focus/minimize/close tests, browser walkthrough, frontend build. Files/Terminal now support multiple instances with unique identities and independent lifecycle.
-
BASE-03 — App render failure containment. Catch rendering/lifecycle failures per app and offer reopen; host replacement resets host app boundaries. Gate: a deliberately failing development fixture leaves sibling windows usable. Async/event failures remain the app's responsibility; this is not a sandbox.
-
BASE-04 — Testable provider selection. Connection-neutral CommandProbe/ProbeContext/HostInfo, ordered selection, total deadline and a bounded per-attempt cache preserve available services without exec. Tests cover recognized, unknown, no-exec, failed inspection, timed-out and overlapping probes; a fresh attempt never inherits cached results. The authorized Linux SSH/SFTP/PTY regression passed. See device detection. Additional production providers and composite sessions remain separate gates.
-
BASE-05 — Session-bound app services (Windows base). Public app calls retain the accepted workspace/provider generation; grants, capabilities and disposal are enforced by the broker and native services. Composite routing cannot redirect stale work. Bundled code remains trusted; installed UI uses the separate Windows extension boundary. See app services and the acceptance audit.
-
BASE-06 — Generic filesystem navigation. File services return named roots, optional home/parent and opaque locations. Files and Editor no longer parse separators or assume Unix roots; Save As uses provider metadata. Unix/drive/opaque fixture checks and live Linux regression passed; see docs/filesystem-contract.md. This completes the navigation contract, not production Windows/appliance support. Provider selection and composite bindings remain separate.
-
BASE-07 — Contributor starters and contract harness. Independent app/custom/Files/console/settings adapter starters, public SDKs, shared schema/package validation and clean-project build/install fixtures are delivered by BASE-11. See app SDK, adapter SDK and AI skills.
-
BASE-08 — Connection-neutral service contracts. Files/text/actions/transfers, console, settings, discovery and namespaced custom services are separate from SSH/Tauri. Adapters advertise only supported operations. Versioned process dispatch and typed connector configuration permit other transports without changing desktop apps. See adapter process contract.
-
BASE-09 — Composite workspace bindings (Windows base). Explicit source roles/generations, independent source replacement, retained lifetimes and secret-free profiles are implemented. Mixed-source, partial failure, stale callback and preserved editor/console work fixtures pass. See workspace bindings and connection UI validation.
-
BASE-10 — Capability status and partial UI (base contract). Per-service/operation availability, source identity and permission discovery drive controls; unsupported actions leave useful services accessible. Console-only, files-only, custom-only and partial-disconnect fixtures pass, with accepted rebinding and compact layouts. More device-specific status reporting belongs to the respective adapters. See service availability.
The Windows base contracts above are closed by BASE-11. Choose subsequent product work explicitly; do not expand the core milestone to cover every transport or platform.
-
CORE-05a — Multi-selection and reviewed batch deletion. Pointer/keyboard range/toggle/select-all, per-window selection, copying multiple names/paths, and sequential revision-checked deletion of up to 100 items. Review captures exact entries and the original connection; progress/results distinguish completed, unconfirmed and unattempted items. Stops on first failure, cancellation or connection loss; no automatic retry/rollback. Two-window browser checks and unit checks passed. See batch actions. Native batch deletion and multi-item Cut remain follow-ups. Multi-file/folder Copy/Paste and transfers are delivered by CORE-05b/05d/05e.
-
CORE-01a — Saved host CRUD. Create, edit and remove named SSH profiles beside imported SSH config entries. Versioned connector-tagged JSON in the native app data directory; atomic replacement and cross-process locking. No passwords/passphrases. Gate: persistence/concurrency/corruption tests and dialog fixture create/edit/reopen/remove checks. Save is explicit; connecting alone does not save a host.
-
CORE-01b — Profile polish (partly implemented). Searchable host picker groups saved profiles and imported SSH entries, with endpoint details, natural sorting, keyboard selection and empty-state handling. The 80-profile fixture passed search, saved-copy removal and desktop/narrow-layout checks; see host profiles. Custom groups, optional history, import/export, provider preferences and adapter migrations remain. Credential vault remains a separate decision.
-
CORE-00 — Terminal containment and actions. Separate terminal viewport from footer, coalesce resize/fit and clip without scrolling the outer wrapper. Context menu provides copy/paste/select-all/clear scrollback/new shell; Escape/arrows and Shift+F10 supported. Native text clipboard plugin; no clipboard monitoring. Gate: varied-height fixture, menu/focus/clipboard fake tests and native build. Windows native copy into an editor draft and Unicode comment paste into the terminal passed; the pasted input was cleared without execution.
-
CORE-02 — Host trust and authentication UX (partly implemented). Snapshot-based known_hosts checks support wildcard/negated/hashed names, aliases/ports, revocation precedence and explicit unknown-versus-mismatch classification. New hosts now have cancelable, expiring fingerprint review, atomic app-owned persistence and exact-key verification on reconnect. Native registry/store tests, real loopback SSH checks and synthetic UI/bridge checks pass. See SSH host trust. Trusted-host management, certificates, SSH agent, keyboard-interactive and a native enrollment walkthrough remain; no silent trust downgrade.
-
CORE-03 — App instances and close behavior (partly implemented). Files/Terminal/Editor instances have unique IDs, independent state, cascade placement, titlebar creation and dock switching. Browser guards and native dirty-editor quit/cancel walkthroughs passed. The native Rust service/pump/registry probe verified two real PTYs with independent state/dimensions and survival after one closes. Windows GUI second-terminal open/close and terminal-to-editor clipboard checks passed; native Unicode terminal paste also passed; broader interrupted-session walkthroughs remain.
-
CORE-09a — Existing-file text editing. Open regular UTF-8 files up to 256 KiB, edit with undo/redo/find/wrap/clipboard, preserve CRLF, and save through optional TextFileService. Atomic SFTP replacement preserves basic UID/GID/mode; revision checks detect content/permission changes. Browser draft/conflict/loss checks and a live disposable-directory probe passed. Extended metadata and distributed compare-and-swap are not guaranteed; see docs/text-editor.md.
-
CORE-09b — Editor completion (partly implemented). Save As/new files work with no-clobber creation, collision draft retention, canonical location/revision adoption and subsequent normal Save. Open editors now follow confirmed file/folder rename/move results, retaining independent buffers, undo and conflict revisions; browser, unit and live disposable SFTP checks passed. Native dirty-editor app-close validation passed in the earlier Windows walkthrough. Save As replacement now uses explicit destination review and revision checks; unit and browser checks cover conflicts, permission errors, late results and sibling drafts. The native Save As replacement happy path now passes with exact Unicode readback and cleanup. Native relocation/failure walkthroughs and optional draft recovery remain. Keep conflict/uncertain-outcome handling and unsaved guards.
-
CORE-10a — Persistent app preferences. Desktop wallpaper/clock/motion, terminal font/cursor/scrollback, editor font/wrap/indent/gutter, Files visibility/sort/density, and selected-host connection settings entry points. Versioned local storage with validation, failure feedback and deliberate reset. Unit and browser persistence/draft/shell-continuity checks passed; see docs/settings.md.
-
CORE-10b — Installable themes and appearance. Data-only theme packages, coordinated Canvas light/dark variants, local/GitHub installation, wallpaper photos, interface scale, toolbar/dock sizes and recovery. See theme milestone and authoring guide.
-
CORE-10b — Host settings and native integration (partly implemented). Provider-owned settings fields and Linux static hostname/timezone operations now include read-only reasons, proposals, review/apply, preconditions and verified readback. Controlled mutation tests, live read-only inspection and desktop/tablet UI checks passed; see docs/remote-settings.md. Actual mutations on a disposable systemd host, unprivileged authorization, broader native preference/quit/clipboard walkthroughs and additional device schemas remain. Saved connection configuration stays separate from remote device settings.
-
CORE-04 — Transfers (partly implemented). Native pickers, queues, bounded streaming, progress/cancellation, no-clobber publication and temporary cleanup are implemented. Automated ownership/cancel/failure checks, browser interactions, live binary probes and an 8 MiB Windows dialog round trip passed. Real unprivileged upload/download refusal and subsequent recovery now pass; see permission validation. Physical-network interruption and larger/slow-link performance remain gates. Recursive transfers are delivered by CORE-05d/05e; resume and overwrite refinements remain. Requires BASE-05/06.
-
CORE-05 — File changes (partly implemented). New folder, non-overwriting rename, files/links/empty-folder deletion and text creation/editing have explicit UI actions and metadata/revision checks. Browser and disposable live-host tests passed, including real unprivileged permission denial, unchanged data and subsequent allowed operations. Browser folder/editor failure recovery passed. Move to folder supports files, symlinks and nonempty folders with destination browsing, no replacement, stale checks and session isolation. Open editors and Files folders/history/previews follow provider-owned mappings after confirmed moves/renames; delayed reads cannot restore old paths. Browser and disposable live probes passed, including real unprivileged move refusal/recovery. Workspace-scoped Cut/Paste now shares one pending item across Files windows, with revision checks, cancellation and reconnect isolation; 54 frontend tests and browser collision/opaque/close-source checks passed. See file clipboard. Native Ctrl+X and Paste here across Files windows now pass with source/destination readback and cleanup. Regular-file Copy to folder now uses the transfer queue with no replacement, progress and cancellation; browser and disposable live-host checks passed. See transfers. Native Copy to folder now passes progress/completion, busy guards, collision refusal and exact binary readback/cleanup; see native file workflows. Directory and remote clipboard copying are delivered by CORE-05b/05d/05e. Recursive deletion, native cancellation/editor relocation and interrupted-operation gates remain. No writes to arbitrary test-host data.
-
CORE-06 — Connection recovery (partly implemented). Deliberate Disconnect now retains windows/drafts; Close workspace separately confirms discard. Delayed/failed teardown, reconnect/save and retained terminal-output browser checks pass; native disconnect retained all windows. Native dirty-draft reconnect still needs a walkthrough after an accessibility text-entry failure. Explicit reconnect preserves workspace windows, Files paths and editor drafts using new session bindings and fresh shells. Cancelable native attempts, late-result cleanup and accessible drafts after capability loss are implemented. Browser slow/late/loss fixtures, workspace state tests and native SSH-handshake cancellation passed; see docs/connection-recovery.md. Physical-network loss, cancellation across all authentication/provider phases and broader slow-link walkthroughs remain. No preview fallback.
-
CORE-07 — Multiple host workspaces. Native session registry and top-bar switcher preserve independent Files/Terminal/window state. Disconnect closes only the selected workspace; terminal IPC verifies session ownership. App service handles capture session identity and reject stale results. Gate passed with two live protocol fixtures: independent input/navigation, switching without shell restart, failed connection preservation, and closing one while the other keeps working. Native registry and session-binding tests cover ownership, stale generations and late cleanup. Two real devices have not been tested simultaneously; layouts remain in-memory.
-
CORE-08 — Files actions and shared menus. Shared keyboard menu supports open/preview, folder in a new window, parent/back/refresh, copy name/path/text and clipboard-path navigation. Files, terminal, titlebar, dock and desktop use shared menu styling. Browser fixture verified selected-path copy, new-folder-window isolation, clipboard navigation, and dock keyboard creation/minimize/restore. Native folder-path copy into an editor draft passed. Native selected-file path/full-preview text copy and clipboard-folder navigation now pass; selected-substring copying remains a native follow-up. See native file workflows. Upload/download and remote changes follow CORE-04/05.
-
UX-01 — Desktop polish (partly implemented). Visible window menus, keyboard move/resize and cancellation, titlebar F6 cycling, left/right tiling, restore and viewport bounds passed browser desktop/tablet checks. See window controls. Native right tiling, F6, Shift+F10 and keyboard move/cancel passed. Native keyboard resize and acceptance passed too. Drag-to-edge previews, touch resize handles and persisted layouts remain. Preserve the approved visual direction.
- CORE-05b — Regular-file clipboard transfers. Multi-file remote Copy/Paste, multi-file Download through one folder picker, Windows virtual-file streaming to Explorer, and Explorer file Paste into the upload queue. New local Copy replaces stale remote selections. Remote Cut synchronizes the clipboard; cross-device pastes retain sources. See behavior and verification.
- CORE-05d — Folder transfers. Recursive remote Copy/Paste, folder Download and Upload picker, and Windows Explorer folder clipboard in both directions. Includes empty folders, aggregate progress, cancellation and no-merge destination checks. Interrupted folders retain completed items with an explicit message. Device providers opt into
files.folders. See folder behavior and evidence. - CORE-05e — Scalable folder discovery. Removed the 1,024-entry and 64-depth caps. Iterative paged provider cursors feed a disk-backed metadata catalog; local source files open only when transferred. Queue discovery and Explorer preparation expose progress/cancellation. Indexed clipboard streams reuse the catalog. Scale fixtures cover 50,000 entries, 512 levels, 10,000 Windows descriptors and cancellation of a stalled cursor. Filesystem/native format constraints remain; restart/resume and crash-time scratch cleanup are follow-ups.
- CORE-05c — Expanded clipboard semantics. Cross-host copy, cross-device moves with verified deletion, multi-item Cut, native macOS/Linux file clipboard adapters, foreign virtual-file inputs and clipboard exchange between separate desktop processes remain. Physical-network interruption, native incoming Ctrl+V and Cut interoperability are separate validation follow-ups. See POST-01/02 and POST-11 through POST-14 in the current handoff.
- HOST-01 — Linux variants and Raspberry Pi OS. Fixtures and live checks for Ubuntu/Debian, Alpine/BusyBox and Raspberry Pi OS. Gate: missing utilities, unprivileged users and disabled SFTP degrade honestly. Raspberry Pi hardware alone is not a provider.
- HOST-02 — macOS over SSH (partly validated). The user confirmed Windows-client browsing and a live shell on the Mac. Darwin/BSD-specific detection, writes/transfers, shell negotiation and failure/lifecycle acceptance remain. This is separate from the now-confirmed native Mac launch/layout/Settings fix. See Mac validation.
- HOST-03 — Windows OpenSSH. Detect configured default shell, support PowerShell/cmd differences and drive paths without POSIX assumptions. Gate: native host tests for listing, preview, PTY and session lifecycle. Requires BASE-04/06 and an authorized Windows SSH endpoint.
- HOST-04 — First appliance provider. Start with one chosen RouterOS/MikroTik version or another requested device; document exact SSH exec/shell/file capabilities. Gate: terminal-only devices remain useful and unavailable apps explain why. No mandatory SFTP, uname, POSIX shell or custom agent. Device/version and fixture access remain to be selected.
- EXT-01 — Package contract (version 1). Version negotiation, namespaced identity, manifest/schema validation, declared permissions and lifecycle are shared with the SDK tools. Incompatible packages fail review. Future API/data migrations remain version-specific work. See runtime apps.
- EXT-02 — Windows UI isolation and broker. Owner-bound isolated frames, guarded native IPC, operation grants, cancellation, ownership and stale/foreign request refusal are tested in native fixtures. Installed UI remains gated on unverified native platforms. Trusted native adapters are not sandboxed by these UI grants.
- EXT-03 — Package distribution follow-ups. Reviewed install/update/disable/remove, content integrity, retained generations and cleanup are delivered by BASE-11. Publisher authentication, explicit rollback tooling, signing and marketplace distribution remain separate work. See runtime apps.
- EXT-04 — Provider packaging. Reviewed native process adapters use a versioned protocol and immutable executable generations. They run with user OS permissions and are explicitly presented as trusted native code, not sandboxed UI or safe dynamic libraries. See adapter packages.
- EXT-05 — Connector packaging. Independent adapter SDK/schema/generator, typed configuration, optional standard/custom services and runtime installation are implemented. Adding a connector does not edit desktop apps or silently grant its privileges to isolated UI apps; native-code trust is reviewed separately. Actual device protocols still need representative tests.
Scope is flexibility now, not implementing every protocol now. Pick the first real adapter from an actual device need after BASE-08/09; each task is independently shippable and requires authorized test access.
- LINK-01 — Serial console. Device selection, baud/framing/flow control, exclusive ownership, reconnect and byte I/O. Gate: real loopback/device tests, unplug/replug and resource release. No automatic Linux detection writes into the console; resizing is optional.
- LINK-02 — Telnet console. Correct protocol negotiation and console behavior, explicit connection/trust presentation, cleanup and timeout tests. Gate: supported device fixture plus authorized real target. No automatic fallback from failed SSH.
- LINK-03 — FTP file services. Listing/read/transfer support with server path conventions and explicit connection security properties. Gate: disposable server tests for partial support, encoding, cancellation and listing variants; Files app remains protocol-neutral. Prove composition with a separate console leg.
- LINK-04 — One structured device API. Select one documented target, implement typed capabilities and connector-specific credentials. Gate: useful operation without terminal/exec/SFTP and partial-failure fixtures. Do not invent a universal vendor API.
- AI-00 — WispCrew reuse assessment. Inspect local source, runtime dependencies, tool defaults and approval interfaces; record findings and integration choices in docs/ai-integration.md. No WispCrew source copied, changed, or executed.
- AI-01 — Optional WispCrew runtime integration. Compare companion connection with portable extraction if later agent features justify it; measure startup/size and platform costs. The first assistant already uses an independent bounded app-side engine and needs no Node sidecar or WispCrew runtime.
- AI-02 — Assistant app. Independent public Canvas Assistant package with explicit model setup, Responses/compatible Chat Completions, streaming, cancellation, local conversation history/host context and selected text/image attachments. Files/Terminal remain independent. See goal evidence.
- AI-03 — Host tools and approvals. Discovery/files, reviewed text writes and console input with retained bindings/revisions, cancellation and budgets. Native Windows model/tool tests and deterministic rejection/conflict tests passed. No hidden local filesystem or exec defaults; see goal evidence.
- SHIP-00 — Private source repository. Initialized local Git on main and created
techartdev/ShellCanvas, verified PRIVATE. Source includes architecture, backlog and fixtures; build output, dependencies and local credentials are excluded. No hosted workflows are added. Update 2026-09-11: the repository is now public (see POST-24), and hosted workflows followed under POST-23. - SHIP-01 — Local verification and releases.
npm run verifyruns formatting, frontend build/tests, locked Rust tests and Clippy, with fail-fast reports and working-tree fingerprints;--nativeadds the current platform debug build. Full Windows verification, runner failure-path tests and invalid-option refusal passed. See the verification guide and release checklist. Reports explicitly exclude manual/live-host/cross-platform claims. Public publication, hosted CI and the release matrix remain separate decisions. Update: publication and hosted CI were decided under POST-23; the release matrix continues as SHIP-02. - SHIP-02 — Desktop release matrix. Optimized Windows, macOS and Linux packages; startup/package size measurements; accessibility, key storage and platform prerequisites documented. Signing/update strategy follows verified builds.
- SHIP-03 — Tablet feasibility. Tauri Android/iOS spikes covering SSH lifecycle, key import, terminal IME, external keyboard and touch window management. Gate: actual device tests; browser responsiveness is insufficient. Phone refinement follows tablet proof.
- SHIP-04 — Web gateway design. Authenticated gateway, per-user host access, credential policy and private-network routing. Gate: threat model and deployment prototype before offering hosted access. Commercial terms remain open.
- COMM-00 — Product name. User selected ShellCanvas; app title, package/crate names, application identity and documentation updated. Workspace folder stays in its existing location.
- COMM-01 — Community launch. Maintain contribution templates, the supported-system matrix, SDK examples and release notes. Domain/trademark checks and paid-tier planning remain separate work.
Earlier slice-by-slice evidence, kept for reference. Current status lives in the entries above and in the handoff.
-
Permission slice: the actual SFTP adapter running as an unprivileged account on an authorized Linux test host denied private reads/downloads and forbidden create/save/rename/delete/upload, preserving original files without temporary leftovers. The same services then completed allowed editing and binary transfers. Exact disposable-file/directory cleanup and disconnect passed. Browser folder/editor refusal retained input/drafts and a later retry succeeded; all-target Clippy passed. See permission validation.
-
Terminal service slice: 32 Rust tests and Clippy passed, including an all-targets check of the live probe. Neutral runtime fixtures verify blocked-write cancellation, concurrent output, fixed-size consoles, byte preservation and failures. A live two-console probe on an authorized Linux test host passed independent state, different dimensions, one-console close, surviving-console input, stale/cross-session refusal and disconnect. No remote files were changed.
-
Provider-selection completion: 29 Rust tests and Clippy passed. Cached probes share concurrent success/failure results, enforce entry/command/output bounds and do not survive an inspection attempt. Ordered failure fallback, unknown-system identity/capability preservation and deadline tests passed. The read-only authorized-host regression passed known-host authentication, Linux inspection, SFTP locations/preview, PTY input/resize and disconnect.
-
Windows clipboard/quit walkthrough: Unicode and multiline text copied and pasted between independent editor drafts. Canceling native app quit preserved both; confirmed discard closed the process. Dusk persisted across a full restart, then the original Fjord setting was restored. No remote writes were made. Editor titlebars and dock menus now share stable instance numbering, including document titles; browser labels were checked with two editor windows.
-
Remote settings slice: 37 frontend tests, 24 Rust tests and Clippy passed. Provider fixtures cover validation, readonly/partial access, concurrent changes and verified/uncertain outcomes. Browser hostname/timezone review, apply, close guards, conflict retention and desktop/tablet layout checks passed. The authorized read-only Linux probe discovered both fields and 497 timezone choices; no remote settings were changed. Real mutation and unprivileged authorization checks remain pending a disposable systemd environment.
-
Transfer slice: 36 frontend tests, 18 Rust tests and Clippy passed; the standard embedded-assets Windows debug build succeeded. Browser failure/cancel/panel checks passed. The authorized live SFTP probe verified 8 MiB + 7 bytes and negative cases; Windows Open/Save dialogs completed an 8 MiB round trip with matching SHA-256. All generated remote test files/directories were cleaned. Physical-network interruption and unprivileged permission behavior remain unverified.
-
M0: owner-authorized Linux transport/SFTP/PTY probe and user-tested native Files/Terminal. Only the tested target is confirmed.
-
M1 app slice: 10 frontend tests passed; browser walkthrough verified three mounted minimized apps, Files navigation surviving minimize, close removing the instance, reopen resetting it, and maximize filling the 1162px work area from toolbar bottom (44px) to dock top (774px). The failure fixture recovered while its sibling counter retained state. Native SSH transport is unchanged; additional OS/device support and external extensions remain pending.
-
Windows debug executable rebuilt successfully with the app slice; native UI and remote SSH flows were not re-exercised in this slice.
-
Rust workspace tests passed (2 core tests; no new Rust changes).
-
Connection-neutral probe slice: 6 Rust tests and clippy passed; 11 frontend tests passed. Console-only UI fixture disables Files with a reason while Terminal and Host details remain available. The owner-authorized read-only Linux SSH/SFTP/PTY regression passed. These fixtures do not establish serial/Telnet/FTP/API support or complete composite-session support.
-
ShellCanvas name applied and Windows debug build produced at
target/debug/shellcanvas.exe; browser title and desktop branding verified. Workspace directory remains unchanged. -
Multi-host slice: 16 frontend tests, 10 Rust tests and Clippy passed. Two synthetic hosts in the real desktop retained independent paths, terminal text and input routing across switches; a failed connect preserved both, and disconnecting one left the other usable. The xterm viewport background now covers spare pixels below full text rows. Windows debug build passed; two real devices together remain unverified.