Application shell #
The Octane/Kumo shell opens conversations at /conversations/<id>, with /
listing saved conversations, /tasks showing scheduled task summaries, and
/settings retaining the instructions and memory editors. /agents redirects to
/; removed starter pages return the normal 404. Messaging and task editing are
separate UI work, so the shell exposes no inactive chat composer or task actions.
ShellSessionProvider owns a native owner connection and conversation metadata
for navigation. It performs authenticated HTTP preflight before opening a native
AgentClient, waits for identity and list RPC, and only then reports Connected.
Offline events detach; reconnect and failed handshakes repeat authentication with
a three-second retry interval and bounded preflight, ready, and RPC waits.
Unauthorized responses stop automatic retries and clear navigation metadata.
Settings and the task overview retain independently scoped native owner clients.
The URL owns selection. Nothing private is written to browser storage or public SSR. A generic SSR navigation/content fallback remains around the published Kumo sidebar. Generation guards reject late connection/list results, and pending creation does not redirect a user who has since chosen another route. Closing a shell connection never cancels a durable conversation turn. Think remains the transcript authority; the shell stores no transcript or fabricated activity order. Metadata refreshes after creation, route changes, reconnect, and window focus.
The command palette stays mounted and uses Kumo results, search, focus, and click activation. The public pinned ARIA adapter retains a stale focusedNodeId after filtering. A shell-local compatibility boundary keeps the input's active descendant aligned with the native focused option and dispatches Enter through that option's ordinary click handler. This also preserves modifier activation and duplicate conversation names. Remove the boundary when a verified public upstream release fixes that behavior. Keyboard listeners and the scoped observer are disposed.
pnpm test:app-shell runs Chromium against the packaged production Worker with a
server-created owner cookie. It covers native create/list/rename and persistence,
deep links, private SSR, keyboard/pointer palette activation, focus return, mobile
navigation and 14px text, offline/auth recovery, bounded failed socket attempts,
native create-validation failure, and a delayed stale list response. Test-only
network interception introduces failures; successful data comes from the actual
native runtime. pnpm test:settings retains instructions/memory behavior coverage.
Run release builds and packaged browser tests sequentially to keep assets stable.