User-authorized overnight goal, started 2026-09-08. Work stopped at the user's request after the editor clipboard checkpoint below, pending discussion. This list does not replace the wider backlog or claim the base is complete.
Historical record: later work completed the Windows BASE-11 milestone and the Mac startup/layout follow-up. Use the post-goal handoff for current remaining work; unchecked or pending statements below describe their recorded checkpoint, not today's completion status.
- Files menus and clipboard: contextual open/preview/navigation, explicit copy name/path/text, clipboard path navigation, keyboard access and clear error feedback. Browser fixtures use fake clipboard contents; OS clipboard checks remain separate.
- Multiple app instances: separate terminal channels and Files navigation, unique instance identities, minimize/close isolation, dock instance switching, window and desktop menus. Switching hosts preserves all their instances.
- Text editor: open remote UTF-8 text, edit and save through provider services, conflict detection, bounded file size, loading/error states, undo/search/wrap, and unsaved-change handling for window/workspace closure. No silent overwrite after remote changes.
- Settings: persisted interface preferences, terminal/editor/file preferences, and usable host profile/settings entry points. Remote administrative changes must use provider-supported operations with explicit UI actions; do not invent universal shell commands for arbitrary devices.
- Everyday files: upload/download, progress/cancellation, new folders, rename and deliberate deletion with failure/overwrite handling. Validate writes only in a designated disposable test directory.
- Integration quality: workspace/window keyboard use, consistent menus, empty/error states, reconnect behavior, native build and relevant tests. Keep the approved visual direction and a bounded dependency footprint.
Additional protocols are optional until these core workflows work well. Connection-neutral service boundaries remain required; implement another protocol only when it proves the design and can be tested. AI, monetization, external-extension trust/runtime, credential-vault policy and other discussion-dependent decisions remain deferred.
Post-goal development resumed at the user's request with Files multi-selection and reviewed batch deletion. This does not restart the overnight goal. See batch actions and CORE-05a in the backlog for behavior, validation and remaining native checks.
The next requested increment adds multi-file Copy/Paste/download and Windows clipboard synchronization for regular-file transfers in both directions. Native Explorer-to-host uploads and Explorer virtual-file downloads were verified with exact generated-file hashes. See current clipboard behavior, validation and remaining limits.
-
Editor Cut/Paste now rejects stale asynchronous edits after document replacement, intervening edits/undo, Save, or a newer clipboard action. Stale failures are suppressed and caret restoration does not steal focus. The controlled browser fixture passed normal Cut/Paste/undo, CRLF normalization, identical-document replacement, edit/undo, Save, refusal and late failure after replacement/unmount. All 72 frontend tests and the standard Windows debug build passed. See editor validation. Native delayed-clipboard failure injection remains unverified.
-
Files now exposes sort headers and a checked Sort and view… context menu using existing persistent preferences. Browser checks passed keyboard/pointer sorting, selection retention, unknown-date placement, two-window synchronization without extra provider reads, compact rows/right tiling and fresh-page persistence. Small floating windows now adapt independently, keeping the location field and name/size columns usable; the menu still sorts by the hidden Modified column. Shared menus support labeled radio groups and checkbox states. See settings. These are local view controls; no remote data is changed.
-
npm run verifynow provides a fail-fast local check sequence and per-run JSON report;--nativeadds the current platform's debug build. The full Windows run passed runner failure tests, 72 frontend tests, 56 Rust tests, formatting, Clippy and the desktop build, with an unchanged source fingerprint during the run. Invalid options failed without starting checks. See verification and release checklist. This completes the local verification entry point, not the remaining native/network/platform gates. -
Native Copy to folder… now passes success/progress/busy guards, source preservation, destination browsing and collision refusal through the Windows UI. Independent SSH readback matched both 8,388,674-byte binaries before/after collision; exact cleanup and normal process exit passed. The walkthrough also fixed long folder headings consuming file-list space. See native file workflows. Native cancellation and physical-network interruption remain unverified.
-
Files now offers capability-gated Copy to folder… for one regular file, with provider-owned destinations, no replacement, progress and cancellation. Browser checks passed cancel, success, collision and separate source/destination windows; the live disposable SFTP probe passed exact binary/source readback, collision/stale refusal and cleanup. All 72 frontend tests, 56 Rust tests, Clippy and the standard Windows build passed. Terminal fixtures at 500px and 260px still show no black strip/footer overlap. See transfers. Native GUI copy, interrupted publication, directory copies and remote Copy/Paste remain open.
-
Deliberate Disconnect now preserves the workspace, while Close workspace separately confirms removal of unsaved work. Delayed cleanup disables reconnect/close controls; failures retain drafts. Browser checks passed delayed/failing cleanup, draft retention, reconnect and subsequent save, plus disabled new-window controls and preserved terminal output. All 70 frontend tests and the Windows build passed. Native disconnect retained Files/Terminal/Editor windows and exited normally; unreliable native text-entry focus prevented the dirty-draft portion. See connection recovery.
-
Per-capability snapshots now reach native connect/poll, stable frontend service handles, launcher/window controls and Host details. Browser checks passed file loss with surviving console input, file recovery, console loss with surviving folder navigation, and source/status display. All 70 frontend tests, 54 Rust tests, Clippy and the Windows build passed. See service availability. Native push events, independent-leg reconnect and richer provider state reporting remain.
-
Native service bindings now route every production role through an explicit connection source and workspace lifetime. Shared connection leases close on last workspace release; late reads/handles are rejected or cleaned up and late writes report uncertainty. Mixed files/console and shared-owner fixtures passed, along with all 53 Rust tests, Clippy and the live bound SFTP/two-console probe. See workspace bindings. Per-binding UI/status, service generations and independent-leg reconnect remain.
-
Connection-neutral identity and lifecycle now drive the native workspace's health/disconnect path. One shared resource coordinates cancellation-safe, bounded, once-only teardown and retains failures. Workspace IDs and established connection instances are separate. All 46 Rust tests, 65 frontend tests, all-target Clippy and the live two-console lifecycle probe passed. See connection lifecycle. Mixed-adapter routing, per-binding status/generations and last-workspace leases remain before the composition gate is complete.
-
Windows native file walkthrough passed selected-file path copying, full-preview text copying through the OS clipboard, clipboard-folder navigation in Files 2, shared Cut/Paste across windows, and Save As replacement. Readback proved no write during review, exact Unicode replacement, and correct moved contents/source absence. The native app exited normally and exact disposable-directory cleanup passed. See native file workflows. Native editor relocation, selected-substring copying and physical-network interruption remain separate checks.
-
Editor Save As now supports explicit replacement review with canonical destination/revision capture, safe new-name creation, draft and undo retention, fresh review after conflict, and late-result suppression on connection loss. All 65 frontend tests, browser opaque-path, permission/conflict/disconnect and two-editor checks, and the standard Windows debug build passed. Native replacement UI verification and optional draft recovery remain; see editor behavior.
-
Files text Copy now handles native edit events as well as keydown shortcuts. Preview Copy uses its own selection or full text; editable controls keep native behavior. Browser checks passed exact opaque paths, selected/full preview text, second-window clipboard navigation and clipboard refusal/recovery; 60 frontend tests and the standard Windows debug build passed. The terminal fixture was rechecked at 500px and 260px: unused row pixels match the terminal background and remain above the footer. The existing terminal fix required no further source change.
-
Bundled apps now declare required and optional services, and the generic window supplies a stable app-scoped handle. Undeclared calls reject before reaching the provider; optional services do not become launch requirements. App transfer-ticket ownership and workspace clipboard sharing are checked. Sixty frontend tests, a custom-app rejection fixture and bundled editor/terminal/Files/settings walkthroughs passed. See app service declarations. This is trusted-module enforcement; native extension isolation and composite policy remain open.
-
Workspace-scoped Cut/Paste now moves one item between Files windows through the existing no-replacement move service. Shared indicators, keyboard/native edit events, cancellation, revision retention, source-window closure, opaque tokens and collision retry passed browser checks; 54 frontend tests and the normal Windows build passed. Disconnect/late-result isolation and relocation/deletion invalidation have unit coverage. Native GUI Cut/Paste and remote copy remain open; see file clipboard.
-
Files windows now follow confirmed workspace relocations through their current folder, Back history, places, selections and previews. Mapping happens before refresh, pending reads cannot restore old paths, typed addresses/filters survive background refresh, and failed Back remains retryable. Two-window/delayed-read/opaque-preview browser checks and 47 frontend tests passed; see Files navigation. Native GUI navigation and clipboard walkthroughs remain separate.
-
Open editors now follow provider-supplied rename/move mappings, including files inside moved folders, while preserving independent buffers, undo history and conflict revisions. Browser file/folder/opaque-ID checks, 45 frontend tests, 42 Rust tests, Clippy and live disposable SFTP mapping/save/cleanup probes passed. Failed/late moves do not retarget drafts. A native GUI relocation walkthrough remains open; see editor behavior.
-
New-host fingerprint review now binds an expiring, one-use decision to the native connection attempt and exact endpoint/key. Approval saves atomically in the app-owned trust store; the authenticated reconnect also pins the exact reviewed key in memory. Changed/revoked/malformed keys remain blocked. Native store/attempt tests, real loopback pre-auth checks, synthetic browser flows and asynchronous bridge tests pass (43 frontend and 41 Rust tests). Native enrollment walkthrough, trust management, agent and keyboard-interactive authentication remain open. See SSH host trust.
-
Files now has a capability-gated Move to folder… dialog with provider-owned navigation, destination review, no replacement and stale-session safeguards. Browser collision/denial/retry/two-window/opaque-location checks and live disposable file/folder/symlink moves passed. Real unprivileged move refusal/recovery and exact cleanup passed too. See file actions. Cross-host copy/move and interrupted-move integration remain separate work.
-
Windows native terminal checks passed copy through the OS clipboard into an editor draft, opening and closing a second terminal, right tiling, F6 focus cycling, Shift+F10 menus and keyboard move/cancel. Floating/tiled native windows and compact/large browser fixtures showed no black strip or footer overlap. Follow-up native checks passed folder-path copy into an editor, Unicode terminal paste without command execution, and keyboard resizing. Selected-file/text clipboard, clipboard navigation and interrupted-network checks remain; see terminal services and window controls.
-
Real unprivileged SFTP permission refusal and recovery now pass for reads, file actions, editor saves and transfers. Original files and temporary cleanup were checked; browser folder/editor failures retained their inputs and recovered on retry. See permission validation.
-
Connections now has a searchable, keyboard-accessible host picker with separate saved/imported groups and endpoint details. The 80-profile fixture passed search, navigation, no-match handling, saved-copy removal and narrow-layout checks without submitting a connection. Native profile persistence and reconnect semantics are unchanged; see host profiles.
-
Native terminal opening and pumping now use transport-independent console traits, with independent read/write progress and explicit per-console cancellation. Tests cover blocked input, optional resize, byte preservation and cleanup; the live two-console Linux probe passed independent state/dimensions and survival after closing one. See terminal services. This does not add another production protocol or replace the pending GUI walkthrough.
-
Provider selection now has bounded per-attempt shared probes and connection-neutral inspection contracts. Recognized/unknown/failed/no-exec/timed-out fixtures, concurrent cache checks, 29 Rust tests, Clippy and a read-only Linux SSH/SFTP/PTY regression passed. This completes BASE-04; composite bindings and further connection-neutral lifecycle/terminal contracts remain open. See device detection.
-
Window menus now expose keyboard move/resize and left/right tiling. Titlebars support F6 cycling and Shift+F10 menus. Browser geometry, cancellation, restore, edge bounds and desktop/tablet transition checks passed; see window controls. Native keyboard move/cancel and resize/accept checks also passed; layout persistence remains separate.
-
Host details now renders provider-defined remote settings with individual availability, proposals, review/apply and conflict/uncertain-outcome handling. Linux hostname/timezone commands have controlled tests; live read-only inspection and desktop/tablet UI checks passed. Actual systemd mutations still require a disposable host. See remote settings.
-
Regular-file upload/download now has native pickers, a bounded streaming broker, per-window queues, progress, cancellation and no-clobber publication. Automated cleanup/ownership/late-outcome checks, browser queue interactions, live SFTP and permission probes, and an 8 MiB Windows native dialog round trip passed. See transfers. Resume, recursive transfers and physical-network interruption checks remain.
-
Files and Editor now consume provider-owned names, parents, home and roots without parsing paths. File contracts were extracted from the SSH implementation. Drive/opaque UI fixtures and a read-only Linux regression passed; see filesystem contracts. This prepares transfers and future providers; it does not add a production connector.
-
Files keyboard menu copied the exact selected path using the fake clipboard and opened a folder in an independent second Files window. Clipboard-path navigation changed only that second window.
-
Two Terminal windows accepted separate input; closing the second left the first usable with its own buffer. Window element order remains stable while stacking changes, avoiding lost clicks on focus.
-
Desktop, dock, window titlebar and Files share the same menu component. Dock/window menus expose creation and existing instances; Files also exposes a touch-accessible actions button.
-
Editor now opens/saves existing remote text, with undo/redo, find, wrapping, clipboard and unsaved-close guards. Browser conflict/loss checks retain drafts; the live disposable-file probe passed save/readback, basic metadata, conflicts, bounds and cleanup. See editor behavior and limits.
-
Desktop, terminal, editor and Files preferences now persist and apply across open windows. Host entries open the selected connection settings. Browser persistence, reset, draft preservation and shell continuity checks passed; see settings behavior.
-
Files now creates folders, renames items and deliberately deletes files/links/empty folders. Editor Save As creates a new file without overwriting an existing name. Browser checks passed including refresh across two Files windows; a disposable live-host probe verified creation, rename, stale checks, symlink isolation and cleanup. See file-action behavior and limits.
-
Explicit reconnect now preserves app instances, folder paths and editor drafts, while starting new shells. Slow attempts can be canceled and late results are disconnected; unsupported capabilities preserve accessible local work. Browser, workspace and native handshake-cancellation checks passed; see connection recovery.
-
Windows native walkthrough passed Unicode/multiline clipboard copy and paste between independent editor drafts, canceled app quit preserving both drafts, and confirmed discard-and-quit. The Dusk preference survived a full process restart; the original Fjord preference was restored afterward. No remote files or administrative settings were changed in this walkthrough.
-
Broader file operations/recursive deletion and final integration audit remain open. Remote settings writes/authorization on a disposable systemd host, physical-network interruption and interrupted-operation outcomes still need walkthroughs. The goal is not complete at this checkpoint.