Product Roadmaps

This page tracks seed product work without treating source presence as product readiness.

Stage Meaning
operational current clean seed source checks/builds and has executable gate evidence
foundation a bounded, tested substrate exists, but the complete product loop does not
active an explicitly named roadmap gate is being implemented
cross-link compilation/link evidence exists, but execution is not claimed
planned design or historical source exists without a current operational product

seed is pre-1.0. None of these labels is a general production-readiness claim.

Portfolio

Track Current stage Delivered evidence Roadmap / next boundary
Language and compiler operational, pre-1.0 LLVM compiler Gates 0-23; safe release profiles; ownership, linear resources, regions, structured tasks, packages, LSP, cross-module interfaces Continue hardening and target-specific evidence; macOS arm64 remains cross-link-only
CLI authoring foundation G08 closed: argument/flag classification, owned metadata, fallible help and completion rendering Interactive process execution and polished end-user framework lifecycle
TUI foundation G08 closed: input classification, cell surfaces, layout, widgets, deterministic snapshots Exact terminal owner, raw-mode restore, resize signals, PTY execution and application-level accessibility
Web foundation G12-G16 provide networking, protocol validators, owned OpenSSL TLS, bounded streaming HTTP/HTTPS GET clients, bounded-redirect absolute-URL fetch with same-origin Authorization and caller-bounded capped retry/backoff, routing/middleware policy, and application metadata; integrated runtime/facade remain archived IPv6/dual-stack, resolver-cancellation/cookie/cache composition, Retry-After/jitter policy, plus an owned server connection-to-response loop and shutdown drain
Public site internationalization production candidate An immutable five-locale artifact is active in /opt/dev/seed-site; the 210-page core matrix plus five localized diagrams, catalogs, documentation structure, metadata, internal links, anchors, subscription contract, responsive Playwright matrix, and rollback automation pass Promote the exact machine-policy artifact through G8 with human_reviewed=0, then collect post-deployment human language validation without relabeling the promoted artifact
Desktop / adaptive UI foundation UI0-UI4 plus the UI6 native-desktop slice close the headless core and shared Gallery contracts across Linux AArch64 and x86-64 X11/AT-SPI, Android API 37 ARM64, macOS ARM64 AppKit, and Windows x86-64 Win32/Wine; initial UI9 adds bounded UTF-8 clipboard interoperability and typed native dialogs, generation-checked multi-owner ABI-v1 Seed plugins, deterministic schema-1/2/3/4/5/6/7 bundles/discovery, semantic version constraints, fail-closed optional dependencies, bounded versioned numeric/UTF-8 capability negotiation, default-deny permission declarations and explicit graph-wide grant preflight, explicit-root transactional install/removal, bounded fail-closed ordered search, validated standard user/system roots, canonical archive installation/upgrade transport, caller-bounded eight-generation history with selected rollback/pruning/uninstall/recovery, artifact-authenticated explicit-URL HTTPS updates with explicit grants and permission-aware rollback, bounded schema-1/2 remote catalogs with highest-compatible newer-only selection plus detached Ed25519 freshness and sequence anti-rollback policy, canonical durable trust persistence, root-pinned signed trust-policy envelopes fetched over verified HTTPS with freshness and anti-rollback, bounded application-selected HTTPS Authorization confined to same-origin redirects, capped exponential retry/backoff for transient GET failures, and bounded simultaneous dependency activation on all three desktops UI5 Savana, Wayland, physical Windows and independent Windows assistive-client evidence, rich/mobile clipboard formats, desktop IME/platform views, conditional caching, Retry-After/jitter policy, authentication-scheme negotiation and credential acquisition/refresh, pinned authority-root provisioning/rotation, secure-clock/transparency policy, sandboxing, tooling and acceleration
Mobile Android operational slice; iOS simulator/device slices Android API 21/29/37 AVDs and initial API-35 physical device; iOS 26.5 simulator and initial signed iPhone XR; shared lifecycle/services, frame, input, semantics, and accessibility contracts Broader device matrices, IME/accessibility completeness, archive/export, store validation, release signing, and production hardening
Ridge DB completed bounded v0.3 local foundation v0.2 P0-P12 frozen, P13 explicitly waived; v0.3 V3-G0-G44-A and V3-G47-G57 complete (V3-G52 partial); alpha preview readiness gates V3-G44-B and V3-G46 pending; V3-G58-G60 planned; V3-G67 planned 2026-08-18 for disk space efficiency (footprint currently a multiple of PostgreSQL) v0.4 scoped 2026-08-18 as device↔cloud sync (offline-first edge peers with an authoritative cloud); implementation has not started; multi-master, sharding, and distributed SQL remain v0.5 or later
Ridge Admin operational professional preview built-in Local Ridge, loopback web security, local/native-SSH pgwire pools, catalog explorer, SQL workspaces, typed filters, atomic staged data editing, verified backup/offline restore, maintenance, signed packaging, and Chromium UX gates Linux arm64 execution, Windows service/package implementation, privileged macOS lifecycle, screen-reader audit, and long-duration release evidence
Game active foundation Declared P0-P7/P9 plus a primary desktop window and three bounded generational auxiliary native window/renderer owners with independent lifecycle, size/timing/refresh, fullscreen, negotiated VSync, isolated complete graphics/input surfaces with surface-owned textures/targets and cross-window rejection, independent refresh-adaptive pacing, and bounded CPU-side present-call telemetry; bounded IME pre-edit/candidate and clipboard state, 16-contact touch and eight-device pen snapshots, controller rumble, nearest/bilinear sampling, pivot-rotated/flipped sprites, owned render targets, explicit bounded layer/material-sorted ordinary/transformed-sprite batches, exact-order retained primitive/sprite/bitmap-glyph/viewport/target plus pre-tessellated path/compound-fill/styled-stroke command replay, deterministic paths with explicit/adaptive curves, fixed or tolerance-adaptive round width/cap/join styles, bounded dash styles, antialiased solid/dashed fringes, bounded compound even-odd/non-zero fills with holes, LF-multiline/width-wrapped Unicode text with ordered font fallback, ICU UAX #9 paragraph bidi with caller-selected automatic/LTR/RTL base direction, validated optional BCP-47 language and ISO 15924 script overrides, up to eight range-checked OpenType variation axes with atlas-instance isolation, and visual-run metrics, preserved color glyphs, caller-declared retained glyph atlases with reusable immediate/batched/retained quad layouts, and a typed shaped-text-to-gfx2d ownership adapter with bounded automatic atlas-page/exact-text/wrap/direction/language/script/variation LRU caching, PCM16/IMA ADPCM WAV, incremental Ogg Vorbis/Opus plus native FLAC and MP3, a bounded HTTP/HTTPS range source with safe codec ownership transfer, an adaptive PCM reservoir, structured background block decode, coherent portable interruption/classified-route monitoring, and retained owning-task output/session handlers provide a backend-neutral ABI and relocatable desktop packages plus reproducible ZIP/tar.gz, mounted read-only DMG, reproducible Linux x86-64 AppImage with externally validated signed zsync updates, reproducible direct-download Flatpak, and reproducible unsigned or caller-signed Windows x86-64 MSIX publication; contract v27 passes headless/macOS/Linux, the focused Windows MinGW/Wine ABI, and all three relocated packages, including typography contract v9; Seed Garden shares one deterministic model, a bounded Opus loop, and a decoded-once FLAC victory clip across Android, iOS, and native macOS/Linux/Windows, with 10,044-move stress, OpenSL ES, allocator-instrumented Android lifecycle evidence, Apple AudioQueue simulator callbacks, a complete unsigned iPhoneOS bundle, and bounded mobile metrics Add authored Garden content/audio, obtain physical Windows fullscreen/VSync/audio/input and trusted MSIX certificate/key/timestamp plus install/upgrade/uninstall evidence, physical multi-window/touch/pen/controller/rumble evidence, physical Android/iOS audio and interaction evidence, physical-device performance/thermal stress, compositor/GPU completion telemetry, physical audio interruption/route validation, higher-level HTTP/live-stream policy, Garden production Flatpak catalog/hosting inputs, owner-controlled AppImage release-key custody/HTTPS hosting, and signed/notarized distribution
ML / tensor foundation G18-G22 bounded tensor storage, datasets, metadata, tokenizer/config and orchestration contracts Numeric CPU kernels, autograd execution, model inference/training and measured correctness/performance
LLM metadata foundation bounded config, tokenizer/model compatibility, datasets, experiment and evaluation contracts Decoder execution, checkpoints, inference/training loop and reproducible model-quality evidence
SSH protocol foundation bounded crypto/protocol/config/auth packages check under current seed End-to-end owned transport, host-key verification, cancellation and interoperability matrix
Web automation operational bounded-redirect client foundation Absolute URL plus system IPv4 resolution, bounded redirects, and owned HTTP/HTTPS body streams with certificate/hostname verification IPv6/dual-stack, cookie/cache/resolver-cancellation composition, crawl loop, robots/rate policy and browser automation
Savana OS migration roadmap seed provides freestanding x86-64/AArch64/RISC-V64 compiler boot foundations First LLVM-built Savana x86-64 boot/console gate; historical v0.1 is migration evidence only
WebAssembly object-level / planned runtime wasm32-WASI/object target rows exist Hosted services, browser bindings and execution evidence

In the desktop row, “conditional caching” refers to HTTP validator revalidation plus cache expiry, eviction, quota, and encryption policy. The bounded exact-URL offline plugin cache documented below is complete.

Language and compiler

The clean compiler under seed/compiler/llvm is the repository launcher and semantic authority. Gates 0-23 are closed for their recorded scopes. Linux x86-64 is the primary executed target; Windows x86-64 passes under required Wine and macOS x86-64 passes natively on Intel. macOS arm64 is implementation/link/ABI complete but has no native execution claim.

Evidence: seed/compiler/llvm/ROADMAP.md, seed/compiler/llvm/tests/GATE*_BASELINE.md, and Current Status.

CLI and TUI

Grove G08 closed a safe portable authoring foundation. It intentionally did not claim interactive terminal or child-process execution: those require exact owners that restore terminal state, wait for children and handle cancellation on every exit.

Evidence: seed/compiler/llvm/tests/GROVE_G08_BASELINE.md.

Web

The current web work is a collection of operational lower layers, not a production framework. Request/response validation, routing rules, middleware policy, networking and buffers exist. G12 now owns OpenSSL 3 server/client contexts with mandatory client certificate and hostname/IP verification. G14 owns bounded HTTP/1.1 and HTTPS GET bodies with partial I/O, content-length/chunked/close framing, typed deadlines, and exact transport cleanup. std-url supplies complete borrowed absolute-URL components and std-http-fetch composes bounded absolute or relative redirects through the host system's IPv4 resolver into HTTP or verified HTTPS, rejecting TLS downgrade. An authenticated path accepts a bounded application-supplied Authorization value only over HTTPS and retains it only across same-origin redirects. IPv6/dual-stack selection, bounded resolver cancellation, cookies, decompression, cache policy, authentication-scheme negotiation and credential lifecycle, and pooling remain higher-level work. The integrated web, web_core runtime and web_runtime facade remain archived until the server connection-to-response loop, cancellation, and shutdown drain are closed end to end.

Evidence: Grove G12 baseline, Grove G14 baseline, the G13 and G16 baselines, and Web Stack.

Public site internationalization

The public site currently serves English-only landing, subscription, and documentation pages from the custom seed-site server. The source tree is under /opt/seed-lang/seed-site, the production artifact is under /opt/prod/seed-site, and /opt/dev/seed-site does not yet exist. English keeps the existing unprefixed URLs; Spanish, Brazilian Portuguese, French, and Italian use /es, /pt-br, /fr, and /it. Locale tags remain BCP 47 values (en, es, pt-BR, fr, and it) even when URL segments are lowercase.

Gate Closure evidence
SITE-I18N-G0 — reproducible development baseline /opt/dev/seed-site is created from a clean, recorded source revision; its binary, static files, documentation tree, configuration schema, and content manifest are reproducible; the English route and form smoke matrix passes there without changing production
SITE-I18N-G1 — locale and route contract One route resolver preserves the current English URLs, serves the four prefixed locale trees, redirects /en/... permanently to the equivalent unprefixed URL, separates query strings before matching, emits the exact Content-Language, and passes home, subscription, documentation, static-asset, API, missing-page, and traversal-rejection cases for every locale
SITE-I18N-G2 — templates and message catalogs Landing, subscription, documentation shell, navigation, footer, form states, countdown units, metadata, and server-visible errors have stable catalog keys; the subscription API returns locale-neutral error codes; the build rejects missing, extra, duplicate, or placeholder-incompatible messages; rendered English retains content parity except for intentional routing and discovery changes
SITE-I18N-G3 — five-locale public pages Home and subscription pages have source-current machine translations for es, pt-BR, fr, and it, canonical English copy, a shared technical glossary, locale-preserving navigation, and an accessible language selector; localized form success, duplicate, invalid-input, server, and network states pass desktop and mobile layout checks; the release manifest discloses whether human language review occurred
SITE-I18N-G4 — localized documentation foundation Locale-specific Markdown roots, localized documentation navigation, per-page titles/descriptions, stable explicit heading IDs, and locale-aware internal-link rewriting pass for the introduction, overview, current status, product roadmaps, Ridge DB overview, and Ridge DB quickstart in all five locales; code, commands, identifiers, and product names remain canonical
SITE-I18N-G5 — complete documentation coverage All 40 public documents have source-current machine translations in the four added locales; every translation records its English source revision, provider, schema, and review state; missing or stale translations cannot publish under the machine policy; a full link crawl finds no accidental cross-locale navigation, .md route leaks, broken anchors, or English prose presented under a localized canonical URL
SITE-I18N-G6 — discovery and sharing Every published page has self-canonical URL, exact lang, complete available-locale hreflang plus x-default, localized title/description/Open Graph metadata, and consistent clean URLs; robots.txt and the generated sitemap enumerate only valid canonical pages and pass duplicate/missing-alternate checks
SITE-I18N-G7 — ancillary public assets The Ridge runtime diagram extracts translatable controls, accessibility labels, statuses, and narrative copy from its data model and passes keyboard/screen-reader smoke checks in all five locales; llms.txt, downloadable archives, and other language-neutral or canonical-English assets have an explicit publication policy instead of silent localized duplication
SITE-I18N-G8 — staged release and production promotion The exact candidate artifact passes the 210-page core route matrix (home, subscription, and 40 documents across five locales), localized subscription integration, sitemap crawl, metadata assertions, missing/stale-translation policy, responsive screenshots, and rollback rehearsal in development; that same immutable artifact is then promoted atomically to production with recorded hashes and a verified rollback target

The gates close in order. The default policy requires human technical review, but an owner-authorized machine policy may close G3-G5 through complete, source-current translations plus the automated content, route, accessibility, responsive, and interaction matrix. Such a release must record translation_policy=machine and human_reviewed=0; human language validation is post-deployment and does not retroactively change that provenance.

Desktop, adaptive UI and game

The Adaptive UI track has a live Linux X11/AT-SPI backend and the shared Android Gallery. Its reusable grove-ui-platform contract now also runs one native Gallery source through headless Linux/macOS, X11 plus a live independently queried AT-SPI registry on Linux x86-64, AppKit/NSAccessibility on macOS ARM64, and Win32/GDI/UI Automation on Windows x86-64 under required Wine. The native desktop gates cover a platform view, pointer and semantic actions, adaptive styles, resize, and exact close failure propagation; Wayland, physical Windows, and independent Windows assistive-client evidence remain open. The initial UI9 grove-ui-native-bridge slice now provides contract version 2 with a 4096-byte valid UTF-8 clipboard plus bounded typed information/warning/error dialogs and platform-neutral OK/Cancel/Yes/No responses. Independent X11, AppKit, and Win32 processes exchange clipboard text with Seed in both directions; native X11 modal windows, NSAlert, and MessageBoxW execute all four response classes; headless and all three desktop debug/release gates pass. Rich formats, Wayland/mobile adapters, file dialogs, platform views, inspector/profiler tooling, and hot reload remain open. The companion grove-ui-plugin slice loads an explicit Seed-authored ABI-v1 dynamic library on native macOS/Linux and Windows/Wine through host contract 4. It validates the complete entry table and bounded identifier, retains up to sixteen distinct generation-checked owners, rejects duplicates, overflow, stale handles and ABI v2, accepts bounded semantic-versioned capability catalogs with legacy fallback, classifies numeric and bounded UTF-8 capabilities through a complete optional signature group, rejects partial catalog/signature groups, and unloads/reopens independently in debug and release. The raw loader remains policy-free; package-layer grants and trust do not sandbox native code. Sandboxing, crash isolation, and platform-view capabilities remain open. The companion grove-ui-plugin-package provides a schema-1/2/3/4/5/6/7 directory bundle and deterministic resolution by identifier in one caller-selected root. Schema 2 adds at most eight ordered dependency identifiers while schema 1 remains dependency-free. Schema 3 adds strict semantic versions and exact, caret, or tilde requirements. Schema 4 adds explicit boolean optional edges. Schema 5 adds a bounded exact/caret/tilde capability requirement set checked against the loaded binary catalog. Schema 6 requires numeric or UTF-8 signatures and checks them against the exact binary. Schema 7 adds bounded unique permission declarations, introspection, default denial, and explicit grant-aware open before native loading. Canonical JSON, dependency/version/optional/capability-policy validation, and manifest/request/binary coherence pass an identical positive and negative corpus on macOS/Linux and Windows/Wine debug/release. Package host contract 3 streams a domain-separated SHA-256 digest over the exact bounded manifest and binary, retains a private read-only POSIX snapshot or a replacement-denying Windows handle, and loads that exact resource. Seed provides opt-in Ed25519 verification and verified-open APIs; independent fixtures reject manifest and binary tampering, attempt source replacement after verification, and prove stable execution in every desktop debug/release row. grove-ui-plugin-trust supplies bounded application-owned publisher/key/signature records, one active and one overlap key per publisher, explicit rotation/revocation, and package/repository trusted-open APIs. Missing, revoked, or mismatching records fail before native open. grove-ui-plugin-trust-store durably retains the complete bounded trust policy and up to eight minimum catalog sequences in one canonical 64-KiB document. Its native macOS/Linux and Windows/Wine debug/release gates cover private atomic replacement, stale-part recovery, key rotation/revocation round-trips, corruption rejection, and monotonic anti-rollback state. grove-ui-plugin-trust-bundle verifies a canonical root-pinned Ed25519 schema-1 policy envelope with bounded authority metadata, freshness, validity, and sequence anti-rollback. grove-ui-plugin-trust-distribution fetches the envelope only through verified HTTPS. The composed macOS/Linux/Windows debug/release gates apply sequence 7 and then sequence 8 atomically, retain sequence 8 across invalid-signature, wrong-authority, expiry, replay, HTTP, status, and oversize failures, and leave no part-file debris. Authenticated delivery follows the shared HTTPS-only, same-origin credential policy. Its bounded exact-URL raw-envelope cache fallback runs only after transient fetch failures, repeats root-pinned signature/freshness/validity/sequence verification, and stores only application-verified envelopes. Pinned authority-root provisioning/rotation, secure-clock and transparency/timestamp policy, conditional HTTP revalidation, cache expiry/eviction/quota/encryption, Retry-After/jitter policy, authentication-scheme negotiation and credential acquisition/refresh, and sandboxing remain open. Envelope GETs use three total attempts with capped 100/200 ms exponential backoff for transport failures and the shared transient status set. The companion grove-ui-plugin-store provides transactional new installation and removal inside that explicit-root model. It copies into private staging, has Seed validate and execute the exact staged copy, publishes without replacement, and hides removal behind an atomic tombstone. The three desktop debug/release gates cover collision, invalid-manifest abort, execution, removal, and reinstallation. The companion grove-ui-plugin-repository searches up to eight caller-ordered roots, falls through only on absence, and fails closed on invalid higher-priority packages. Two binaries sharing one ID prove shadowing, reversed precedence, fallback, bounds, invocation, and close on the three desktop debug/release gates. grove-ui-plugin-roots supplies validated platform-standard user and system paths plus bounded absolute process-local overrides. The same gates cover real defaults, exact overrides, user shadowing, system fallback, invalid-path rejection, invocation, and close. grove-ui-plugin-archive host contract 3 provides strict two-entry schema-1 stored and schema-2 raw-DEFLATE ZIP transports plus a canonical schema-3 raw-LZ4 envelope, CRC and compressed/uncompressed size validation, fixed path-free extraction into a private owned root, exact Seed package execution, and transactional installation/upgrade handoff. Its dependency-free bounded decoders cover stored/fixed/dynamic DEFLATE and overlapping LZ4 matches. Native macOS/Linux and Windows/Wine debug/release gates reject corruption, traversal, invalid/trailing/excess-block DEFLATE streams, unsupported or mixed methods, extra entries, oversized manifests, and invalid extracted packages while proving schema-1 compatibility, upgrade/rollback, and cleanup. Transparency/timestamp policy, sandboxing, and hot reload remain open. grove-ui-plugin-generations host contract 3 retains a caller-selected one to eight prior validated bundles behind the unchanged active path. Upgrade and selected tentative rollback candidates execute through Seed before commit; fixed pending/swap names, durable per-slot rotation progress, and an OS-owned lock recover deterministic interrupted states. Generation-aware uninstall removes the active bundle and every retained entry and completes recorded interrupted removal. Native macOS/Linux and Windows/Wine debug/release gates prove the eight-entry bound, selected rollback, pruning, invalid-stage and corrupted-rollback abort, interrupted rotation, normal/interrupted uninstall, and stale cleanup. grove-ui-plugin-update composes bounded HTTP/HTTPS download, canonical archive extraction, caller-selected Ed25519 credentials, explicit permission grants, and retained generation publication. Trust and grant preflight precede the first native load, and one per-package OS file lock protects a synced private part file. Native macOS/Linux and Windows/Wine debug/release gates prove invalid-signature, wrong-grant, and oversize abort without active or history mutation, then publish a valid permissioned update, retain the prior generation, and execute bidirectional permission-aware rollback. grove-ui-plugin-catalog parses up to 32 bounded schema-1/2 release records and selects the highest compatible version strictly newer than the installed package. Schema 2 verifies a domain-separated detached Ed25519 signature and application-selected publisher/key, issue/expiry, clock-tolerance, maximum-validity, and monotonic-sequence policy. The composed update path owns transport and binds the selected version to the signed package before native loading. Native macOS/Linux and Windows/Wine cover already-current/no-match behavior plus duplicate, publisher, version-mismatch, invalid-signature, premature, expired, and rollback rejection. Authenticated variants cover both catalog and archive requests under the shared HTTPS-only, same-origin credential policy. Both GETs use three total attempts with capped 100/200 ms exponential backoff for transport failures and the shared transient status set. grove-ui-plugin-remote-cache retains bounded exact-URL raw catalog and archive entries in one explicit root; transient fallback repeats catalog signature/freshness/sequence plus archive, package, version, trust, and permission checks before native loading or publication. Conditional HTTP revalidation, cache expiry/eviction/quota/encryption, Retry-After/jitter policy, authentication-scheme negotiation and credential acquisition/refresh, grant selection, and pinned authority-root provisioning/rotation remain higher layers. grove-ui-plugin-dependencies resolves schema-2/3/4/5/6/7 graphs through the ordered fail-closed repository. It returns deterministic dependency-first postorder, emits shared nodes once, and rejects missing, cyclic, too-deep, or oversized graphs. Native macOS/Linux and Windows/Wine debug/release gates validate four distinct Seed binaries split across two roots plus the negative corpus, then retain all four owners simultaneously and invoke each indexed transform capability before reverse close. The graph enforces exact/caret/tilde requirements, skips and counts absent optional packages, and rejects present invalid or incompatible optional packages. Its schema-7 row negotiates and invokes numeric and bounded UTF-8 secondary capabilities, exposes one unique permission union, denies ordinary activation, and preflights explicit grants before native loading. Its trusted variants preflight all four package signatures, accept one rotation-overlap key, reject revoked keys and cryptographic mismatches, and activate only after the whole graph passes. Live forced-process/power-loss update evidence remains open. The Game track now has a versioned backend-neutral boundary, an owned window loop with idempotent fullscreen/VSync control, keyboard/mouse/text/touch/pen/controller snapshots, shapes, bounded IME pre-edit/candidate state, typed controller power telemetry, RGB LED feedback, cached controller touchpads and sensors, and dual-motor controller rumble with explicit stop, owned RGBA textures with nearest/bilinear sampling, pivot-rotated/flipped sprites, owned offscreen render targets with feedback rejection, transparent consecutive-sprite/glyph batching, and explicit bounded ordinary/transformed-sprite batches sorted by layer/material with stable same-material order and allocation-free submission. Exact-order retained buffers replay clear, primitive, viewport, render-target, and ordinary/transformed-sprite commands plus paths, compound fills, styled solid/dashed strokes, antialiased meshes, and atomic bitmap-glyph runs across frames without new allocation after whole-stream portable validation. Their caller-bounded mesh and glyph arenas are cleared and reused with the command owner. The track also includes bounded single-contour linear/quadratic/cubic paths with deterministic simple-concave fill and portable width/cap/join stroke styles plus solid/dashed antialias fringes through per-vertex colors, a strict headless host, clipped camera viewports, versioned asset manifests, safe bounded asset reads, a root-scoped capacity-bounded LRU byte cache with observable hit/miss/eviction/reload behavior and synchronous exact-content development refresh, plus bounded root-scoped polling and native-event watchers for creation/change/replacement/removal hints. The native watcher uses kqueue on Apple platforms and inotify on Linux/Android, performs exact per-path classification after a wakeup, and transparently retains polling on unsupported targets or backend failure. Structured background jobs copy borrowed inputs before spawning, preserve the same safe-root and byte bounds, and return owned raw/image/WAV/SBF results through non-blocking poll, blocking wait, or safe discard. Applying completed results to live caches remains explicit. An independent typed LRU arena for decoded image RGBA, sound PCM, and bitmap-font RGBA, pinned bounded PNG/JPEG plus dependency-free PPM-to-RGBA and SBF bitmap-font decoding, measured ASCII text, plus bounded HarfBuzz and FreeType TTF/OTF Unicode shaping/rasterization. SDL3 execution passes on macOS ARM64 and Linux x86-64; a focused Windows x86-64 backend ABI gate passes under required MinGW/Wine/Xvfb at contract v27. The complete relocated Linux, macOS, and Windows packages rebuild and execute the contract-v27 application. Contract v20, which adds owned IME candidate snapshots to eight-device pen snapshots, 16-contact touch, refresh-adaptive pacing, IME pre-edit/clipboard state, controller power, and controller rumble without exposing SDL. Contract v21 adds aligned per-vertex RGBA triangles used by the bounded antialiased-stroke tessellator. Contract v22 adds completed-present count and last/average/maximum CPU-side native present-call duration. Contract v23 adds negotiated adaptive VSync with explicit standard fallback. Contract v24 adds three bounded generation-checked auxiliary native windows with independent lifecycle, size/timing/refresh, fullscreen, negotiated VSync, and clear/present frames. Contract v25 adds opaque surface-selected full gfx2d routing, isolated renderer/resource contexts, and cross-window texture/target rejection. Contract v26 routes window-bearing input snapshots; contract v27 adds independent precise/adaptive pacing and CPU-side presentation telemetry. Contract v28 adds bounded RGB LED feedback, two four-finger touchpads, and six explicitly enabled accelerometer/gyroscope variants; a virtual SDL3 gamepad proves exact fixed-point snapshots and callbacks. Contract v29 routes renderer reset/loss events by window, publishes a monotonic graphics generation plus target/device counters and lost state for every surface, and generation-invalidates textures and targets after device reset/loss. A synthetic SDL fixture proves stale-handle rejection, replacement generation, and lost-device shutdown. Controllers and clipboard remain process-global. Deterministic headless and macOS ARM64 SDL3 pass v29; preceding v27 evidence covers complete Linux, focused Windows/Wine, and all relocated package matrices. Shared owned PCM streams now include a bounded owned output-device snapshot, an abstract default route on every backend, SDL3 physical-output names and preferred formats, explicit opening by ephemeral snapshot index, and an owned monitor with SDL3 playback-device events, exact post-event snapshot comparison, and portable polling fallback for list/name/format/default changes. Headless, Android OpenSL ES, and Apple AudioQueue currently expose only the default route. Contract v5 adds owned non-blocking PCM16 mono/stereo capture from SDL3's default recording route; headless, Android, and Apple explicitly report it unavailable. It also adds an allocation-free coherent session monitor: SDL3 playback events, Android audio focus/device callbacks, and Apple AVAudioSession notifications report interruption and classified route transitions through one portable API. Seed Garden arbitrates that state independently from lifecycle and player-selected pause. Integer-only 8–192 kHz PCM16 WAV resampling plus 48 kHz IMA ADPCM decoding, codec-neutral memory/file/seekable-or-live-callback Ogg Vorbis, Ogg Opus, native FLAC, and MP3 decode, and shared incremental 8–192 kHz compressed-stream normalization to 48 kHz including direct unknown-duration 48 kHz streams, a bounded adaptive PCM reservoir, and exclusive-ownership structured background block decode with one reusable PCM workspace, plus a bounded frame-driven game mixer cover sound effects, looping compressed music, channels, volume groups, typed bounded linear stereo panning, relative 3D distance attenuation with typed listener orientation, Doppler playback and live channel updates for sound voices, bounded persistent two-tap HRTF elevation filtering, frame-exact bounded master/sound/music fades, pause/resume, and exact cleanup. Portable fixed-step timing, timers/statistics, backend-neutral precise frame pacing, millihertz refresh queries, and stable-divisor adaptive caps, plus vectors, collision, transforms, deterministic random, and a shared color contract also pass. A relocatable Linux directory and ad-hoc signed macOS application bundle plus a Windows portable directory contain SDL3, the required Seed code, manifests, and assets. The independent seed-game-assets CLI deeply validates packaged manifests and PNG/JPEG/PPM/SBF/TTF/OTF/WAV/Ogg Vorbis/Opus/native FLAC/MP3 payloads without a window or SDL, and deterministically converts accepted WAV input to compact mono/stereo IMA ADPCM, PNG/JPEG/PPM images to RGBA8 PNG, SBF glyph atlases to PNG, and shaped/wrapped TTF/OTF text to PNG. It packs bounded decoded images into a deterministic alpha-preserving shelf atlas with composable stable sorting, transparent trimming, and clockwise tall-sprite rotation. It also imports exact 16x6 PNG/JPEG/PPM bitmap sheets into canonical runtime-validated SBF documents. Versioned seed-atlas 2/3/4 maps have a bounded public runtime parser, and the CLI authors bounded ordered sparse seed-tilemap 1, compact binary dense seed-tilemap 2, sparse binary chunked seed-tilemap 3, and origin-aware chunked seed-tilemap 4 documents consumed by matching runtime parsers; a bounded single-layer Tiled CSV importer and a 1..16-layer, 1..16-tileset finite orthogonal Tiled JSON importer produce the same dense format. Bounded infinite JSON and TMX importers preserve negative coordinates and canonicalize fixed-size chunks into v4. The TMX paths accept finite layers or infinite chunks with uncompressed CSV. JSON and TMX tilesets are strictly ordered and align the atlas to Tiled's global GID space. Both import paths can resolve named external TSX files relative to the map and derive the atlas size from bounded tile counts. The portable RGBA8 encoder uses a two-pass exact-bit selector between fixed and complete active-alphabet dynamic Huffman DEFLATE, with a deterministic 32 KiB latest-match window and matches up to 258 bytes. Explicit fixed/dynamic block checks and decoder round trips keep the output portable without a platform image encoder. grove-game-test v9 adds deterministic goldens, property corpus, integer and structured byte-buffer shrinking, four-controller replay, allocation-free versioned SGTR trace capture/playback, and atomic semantic complete-frame trace shrinking into caller-owned storage. grove-game-debug v1 aggregates bounded frame/update/draw/ audio counters and produces deterministic printable-ASCII overlay text. An independent bounded seed-objectmap 1/2/3/4 runtime now validates canonical object layers, signed-thousandth rectangle/point/ellipse/polygon/polyline/tile geometry, vertices, UTF-8 metadata, and typed map/layer/object properties; v2 adds acyclic group hierarchy, layer IDs, cell/millipixel offsets, opacity, and layer visibility, v3 adds object visibility, and v4 adds bounded Tiled text content/font/color, pixel size, wrap/style/kerning flags, and alignment; older versions remain compatible. The JSON and TMX importers now author equivalent nested group/object-layer hierarchies in bounded parent-before-child pre-order with parent links, kinds, layer IDs, cell/millipixel offsets, opacity, visibility, empty layers, scalar properties, exact decimals, deterministic ID sorting, failure-before-output, and byte-identical seed-objectmap 4 results, including hidden and text objects. Bounded non-tile JSON/TMX templates now inherit geometry, metadata, and scalar properties with deterministic instance and same-name-property overrides. Nested class-valued properties use class:<propertytype> and bounded canonical JSON, producing byte-identical JSON/TMX object maps. External-TSX tile templates normalize relative paths, validate local tile indices, and remap into the map's global GID space. Cross-serialization and nested templates remain active. Dynamic-Huffman optimization, Tiled object/group/property/ collision-object import, graphical editors, and richer structure-aware shrinkers remain tooling work. Seed Garden now consumes this foundation through a deterministic headless rules/progression model and a native desktop adapter. Its relocatable macOS, Linux, and Windows packages execute the same model used by Android. The desktop adapter persists a versioned checksummed progress payload through sync + atomic rename, restores timed attempts across restart, and quarantines corrupt/incompatible files before clean recovery. Mobile and desktop block retries when no attempt remains; the desktop result overlay presents all 15 levels with unlocked best scores, stars, and the next minimum-score-gated level. It also mixes a 96-byte mono IMA ADPCM WAV move effect, a file-streamed 4,464-byte Opus music loop, and a 24,808-byte native FLAC victory effect decoded once into a retained PCM16 clip, and pauses the mixer with the game. The Linux directory additionally publishes as a reproducible direct-download Flatpak targeting Freedesktop Platform 25.08. The installed application has only IPC, Wayland/fallback-X11, PulseAudio, and DRI permissions, with no network or host-filesystem access. The completed bundle installs and executes under the sandbox, retains the GLIBC_2.34 ceiling, and leaves its runtime as a separately resolved dependency. The generic signed Flatpak repository gate passes AppStream discovery and a static-delta update; Garden-specific catalog licensing/content, key custody, and hosting, plus a trusted MSIX certificate, key, timestamp policy, physical install, and release signing, remain distribution work. Windows x86-64 MSIX now passes reproducible unsigned publication and reproducible caller-supplied embedded signing, official-SDK unpack validation, independent signature and subject validation, tamper rejection, and exact-payload Wine execution. The signed gates deliberately use disposable certificates rather than defining a production publisher. The AppImage publisher also has a reproducible signed-update mode with an explicit full OpenPGP fingerprint, GPG home, release timestamp, HTTPS zsync location, and external signature validation. Its generic gate rejects a tampered image, verifies HTTP byte ranges, and uses the official updater for an exact signed 1.0.0-to-2.0.0 delta. The Garden product gate preserves GLIBC_2.34, reproduces both AppImage and zsync bytes, validates the signature, and executes the signed image. Those gates deliberately use disposable keys and a non-release location; owner-controlled release-key custody and a real HTTPS range endpoint remain distribution inputs. Authored production content/audio, physical Android/iOS audio evidence, and physical-device performance/thermal stress remain explicit product work. The Android adapter now retains that mixer in an Activity-generation context, keeps the compact Opus and FLAC sources compressed in memory, and queues decoded PCM through a bounded OpenSL ES backend. An API-35 ARM64 AVD proves an active 48 kHz stereo track, scoring-move playback, and pause/resume across both the game overlay and Activity background/foreground; physical speaker quality and latency are not claimed. A clean API-37 ARM64 gate adds eight alternating portrait/landscape recreations with all 64 tile semantics, reduced-motion scoring, audio teardown, and bounded startup/frame/PSS metrics. Its dedicated allocator row runs two symmetric eight-rotation lifecycle workloads under guarded bionic malloc_debug; both measured libmemunreachable scans report zero bytes and zero allocations. The iOS 26.5 ARM64 simulator builds the same mobile Garden source and assets. Its reusable application context and atomic private-file persistence survive continuous frames; XCUITest covers 67 stable semantic nodes, pause/resume, rotation, background/foreground, termination, and relaunch. The iOS audio backend uses fixed bounded Apple AudioQueue buffers; the gate requires one active stream with advancing callbacks and also emits an iPhoneOS-identified Garden object plus a complete unsigned application bundle with validated flat assets. This is simulator audio-processing and device packaging evidence, not physical execution, speaker-route, latency, or signing evidence. This is a reusable native foundation, not a shipped game runtime: HTTP retry/authentication/cache/playlist/live-chunk policy above the completed bounded range/callback/background-decode/reservoir layers, capture and physical enumeration beyond SDL3, physical interruption/route validation beyond the completed coherent monitors and retained owning-task handlers, physical Windows/iOS evidence, distribution signing/notarization/installers, and broader mobile adapters remain open.

Evidence: UI4 baseline, UI6 baseline, UI9 native bridge baseline, UI9 plugin baseline, UI9 plugin package baseline, UI9 plugin store baseline, UI9 plugin repository baseline, UI9 plugin roots baseline, UI9 plugin archive baseline, UI9 plugin generations baseline, UI9 plugin update baseline, UI9 plugin catalog baseline, UI9 plugin trust-store baseline, UI9 plugin trust-distribution baseline, UI9 plugin dependencies baseline, Game P1 baseline, Game P2 baseline, Game P3 baseline, Game P4 baseline, Game P5 baseline, Game audio stream baseline, Game Opus baseline, Game FLAC baseline, Game MP3 baseline, Game P6 baseline, Game P7 baseline, Game P8 Linux baseline, Game P8 macOS baseline, Game P8 Windows baseline, Game P8 AppImage baseline, Game P8 AppImage update baseline, Game P8 Flatpak baseline, Game P8 MSIX baseline, Game P8 signed MSIX baseline, Game P9 baseline, Game test baseline, Game text baseline, Seed Garden portability baseline, and the Game roadmap.

Mobile

Android and iOS are active mobile tracks at explicitly scoped evidence levels. Android packages arm64-v8a and x86-64 through Gradle/Kotlin/CMake/JNI and passes API 21/29/37 AVD plus an initial API-35 physical-device slice. iOS passes the 26.5 ARM64 simulator and an initial signed iPhone XR slice through the Swift/UIKit host. Shared lifecycle/services, bounded input, frame, semantics, rotation, and accessibility contracts are covered; broader hardware, full IME/accessibility matrices, archive/export, store validation, and production release remain open.

See Android Applications.

Ridge DB

Ridge is the most advanced application track. The v0.2 line froze P0-P12 and waived P13 rather than reporting a failed matrix as passing. The bounded v0.3 local foundation completed V3-G0-G44-A, with V3-G47-G57 also complete (V3-G52 partial). v0.4 is scoped as device↔cloud sync for offline-first applications (mobile apps, POS terminals) against an authoritative cloud, reusing the embedded/server engine on both sides. Multi-master replication, failover, sharding, and distributed SQL remain deferred to v0.5 or later.

Evidence: Ridge Database, grove/apps/ridge/CAPABILITIES.md, grove/apps/ridge/ROADMAP.md, and grove/apps/ridge/V3_CONTRACT.md.

Ridge Admin

grove/apps/ridge-admin is a Ridge-native browser administration application, not a PostgreSQL compatibility claim. The 0.2.0+contract.3 professional preview owns a loopback-only HTTP boundary, launch/session/CSRF/CSP policy, the built-in Local Ridge profile, secret-free saved profiles, four local or native SSH direct-tcpip pgwire connections, versioned Ridge introspection, SQL workspaces, deterministic data paging, up to four typed parameterized filters, conflict-aware drafts, atomic save/import of up to 10,000 staged changes, server-spooled bounded CSV export, integrity/vacuum operations, verified operator-rooted backup, and non-overwriting offline restore.

Evidence and current release blockers are in grove/apps/ridge-admin/SPEC.md, README.md, RELEASE.md, and the machine-readable runners under grove/apps/ridge-admin/tests/.

ML and LLM

The clean Grove conversion retained bounded, ownership-safe tensor storage, shape/dataset/model metadata, tokenizer/configuration and experiment contracts. It explicitly archived numeric CPU/CUDA kernels, full graph/model execution and LLM runner behavior that lacked safe current owners. The next stage is executable numeric correctness before performance or model-quality claims.

Evidence: Grove G18-G22 baselines.

Savana OS

Savana's historical v0.1 tree is not an operational current kernel. The active roadmap starts by porting a minimal x86-64 boot/console path to the clean LLVM compiler, then builds explicit KAL/HAL/backend contracts. AArch64 and RISC-V64 Savana boots remain future gates even though the compiler itself has freestanding boot fixtures for those architectures.

Evidence: savana/ROADMAP.md.

Status discipline