Product Roadmaps
This page tracks seed product work without treating source presence as product readiness.
| Stage | Meaning |
|---|---|
| operational | current clean seed source checks/builds and has executable gate evidence |
| foundation | a bounded, tested substrate exists, but the complete product loop does not |
| active | an explicitly named roadmap gate is being implemented |
| cross-link | compilation/link evidence exists, but execution is not claimed |
| planned | design or historical source exists without a current operational product |
seed is pre-1.0. None of these labels is a general production-readiness claim.
Portfolio
| Track | Current stage | Delivered evidence | Roadmap / next boundary |
|---|---|---|---|
| Language and compiler | operational, pre-1.0 | LLVM compiler Gates 0-23; safe release profiles; ownership, linear resources, regions, structured tasks, packages, LSP, cross-module interfaces | Continue hardening and target-specific evidence; macOS arm64 remains cross-link-only |
| CLI authoring | foundation | G08 closed: argument/flag classification, owned metadata, fallible help and completion rendering | Interactive process execution and polished end-user framework lifecycle |
| TUI | foundation | G08 closed: input classification, cell surfaces, layout, widgets, deterministic snapshots | Exact terminal owner, raw-mode restore, resize signals, PTY execution and application-level accessibility |
| Web | foundation | G12-G16 provide networking, protocol validators, owned OpenSSL TLS, bounded streaming HTTP/HTTPS GET clients, bounded-redirect absolute-URL fetch with same-origin Authorization and caller-bounded capped retry/backoff, routing/middleware policy, and application metadata; integrated runtime/facade remain archived | IPv6/dual-stack, resolver-cancellation/cookie/cache composition, Retry-After/jitter policy, plus an owned server connection-to-response loop and shutdown drain |
| Public site internationalization | production candidate | An immutable five-locale artifact is active in /opt/dev/seed-site; the 210-page core matrix plus five localized diagrams, catalogs, documentation structure, metadata, internal links, anchors, subscription contract, responsive Playwright matrix, and rollback automation pass |
Promote the exact machine-policy artifact through G8 with human_reviewed=0, then collect post-deployment human language validation without relabeling the promoted artifact |
| Desktop / adaptive UI | foundation | UI0-UI4 plus the UI6 native-desktop slice close the headless core and shared Gallery contracts across Linux AArch64 and x86-64 X11/AT-SPI, Android API 37 ARM64, macOS ARM64 AppKit, and Windows x86-64 Win32/Wine; initial UI9 adds bounded UTF-8 clipboard interoperability and typed native dialogs, generation-checked multi-owner ABI-v1 Seed plugins, deterministic schema-1/2/3/4/5/6/7 bundles/discovery, semantic version constraints, fail-closed optional dependencies, bounded versioned numeric/UTF-8 capability negotiation, default-deny permission declarations and explicit graph-wide grant preflight, explicit-root transactional install/removal, bounded fail-closed ordered search, validated standard user/system roots, canonical archive installation/upgrade transport, caller-bounded eight-generation history with selected rollback/pruning/uninstall/recovery, artifact-authenticated explicit-URL HTTPS updates with explicit grants and permission-aware rollback, bounded schema-1/2 remote catalogs with highest-compatible newer-only selection plus detached Ed25519 freshness and sequence anti-rollback policy, canonical durable trust persistence, root-pinned signed trust-policy envelopes fetched over verified HTTPS with freshness and anti-rollback, bounded application-selected HTTPS Authorization confined to same-origin redirects, capped exponential retry/backoff for transient GET failures, and bounded simultaneous dependency activation on all three desktops | UI5 Savana, Wayland, physical Windows and independent Windows assistive-client evidence, rich/mobile clipboard formats, desktop IME/platform views, conditional caching, Retry-After/jitter policy, authentication-scheme negotiation and credential acquisition/refresh, pinned authority-root provisioning/rotation, secure-clock/transparency policy, sandboxing, tooling and acceleration |
| Mobile | Android operational slice; iOS simulator/device slices | Android API 21/29/37 AVDs and initial API-35 physical device; iOS 26.5 simulator and initial signed iPhone XR; shared lifecycle/services, frame, input, semantics, and accessibility contracts | Broader device matrices, IME/accessibility completeness, archive/export, store validation, release signing, and production hardening |
| Ridge DB | completed bounded v0.3 local foundation | v0.2 P0-P12 frozen, P13 explicitly waived; v0.3 V3-G0-G44-A and V3-G47-G57 complete (V3-G52 partial); alpha preview readiness gates V3-G44-B and V3-G46 pending; V3-G58-G60 planned; V3-G67 planned 2026-08-18 for disk space efficiency (footprint currently a multiple of PostgreSQL) | v0.4 scoped 2026-08-18 as device↔cloud sync (offline-first edge peers with an authoritative cloud); implementation has not started; multi-master, sharding, and distributed SQL remain v0.5 or later |
| Ridge Admin | operational professional preview | built-in Local Ridge, loopback web security, local/native-SSH pgwire pools, catalog explorer, SQL workspaces, typed filters, atomic staged data editing, verified backup/offline restore, maintenance, signed packaging, and Chromium UX gates | Linux arm64 execution, Windows service/package implementation, privileged macOS lifecycle, screen-reader audit, and long-duration release evidence |
| Game | active foundation | Declared P0-P7/P9 plus a primary desktop window and three bounded generational auxiliary native window/renderer owners with independent lifecycle, size/timing/refresh, fullscreen, negotiated VSync, isolated complete graphics/input surfaces with surface-owned textures/targets and cross-window rejection, independent refresh-adaptive pacing, and bounded CPU-side present-call telemetry; bounded IME pre-edit/candidate and clipboard state, 16-contact touch and eight-device pen snapshots, controller rumble, nearest/bilinear sampling, pivot-rotated/flipped sprites, owned render targets, explicit bounded layer/material-sorted ordinary/transformed-sprite batches, exact-order retained primitive/sprite/bitmap-glyph/viewport/target plus pre-tessellated path/compound-fill/styled-stroke command replay, deterministic paths with explicit/adaptive curves, fixed or tolerance-adaptive round width/cap/join styles, bounded dash styles, antialiased solid/dashed fringes, bounded compound even-odd/non-zero fills with holes, LF-multiline/width-wrapped Unicode text with ordered font fallback, ICU UAX #9 paragraph bidi with caller-selected automatic/LTR/RTL base direction, validated optional BCP-47 language and ISO 15924 script overrides, up to eight range-checked OpenType variation axes with atlas-instance isolation, and visual-run metrics, preserved color glyphs, caller-declared retained glyph atlases with reusable immediate/batched/retained quad layouts, and a typed shaped-text-to-gfx2d ownership adapter with bounded automatic atlas-page/exact-text/wrap/direction/language/script/variation LRU caching, PCM16/IMA ADPCM WAV, incremental Ogg Vorbis/Opus plus native FLAC and MP3, a bounded HTTP/HTTPS range source with safe codec ownership transfer, an adaptive PCM reservoir, structured background block decode, coherent portable interruption/classified-route monitoring, and retained owning-task output/session handlers provide a backend-neutral ABI and relocatable desktop packages plus reproducible ZIP/tar.gz, mounted read-only DMG, reproducible Linux x86-64 AppImage with externally validated signed zsync updates, reproducible direct-download Flatpak, and reproducible unsigned or caller-signed Windows x86-64 MSIX publication; contract v27 passes headless/macOS/Linux, the focused Windows MinGW/Wine ABI, and all three relocated packages, including typography contract v9; Seed Garden shares one deterministic model, a bounded Opus loop, and a decoded-once FLAC victory clip across Android, iOS, and native macOS/Linux/Windows, with 10,044-move stress, OpenSL ES, allocator-instrumented Android lifecycle evidence, Apple AudioQueue simulator callbacks, a complete unsigned iPhoneOS bundle, and bounded mobile metrics |
Add authored Garden content/audio, obtain physical Windows fullscreen/VSync/audio/input and trusted MSIX certificate/key/timestamp plus install/upgrade/uninstall evidence, physical multi-window/touch/pen/controller/rumble evidence, physical Android/iOS audio and interaction evidence, physical-device performance/thermal stress, compositor/GPU completion telemetry, physical audio interruption/route validation, higher-level HTTP/live-stream policy, Garden production Flatpak catalog/hosting inputs, owner-controlled AppImage release-key custody/HTTPS hosting, and signed/notarized distribution |
| ML / tensor | foundation | G18-G22 bounded tensor storage, datasets, metadata, tokenizer/config and orchestration contracts | Numeric CPU kernels, autograd execution, model inference/training and measured correctness/performance |
| LLM | metadata foundation | bounded config, tokenizer/model compatibility, datasets, experiment and evaluation contracts | Decoder execution, checkpoints, inference/training loop and reproducible model-quality evidence |
| SSH | protocol foundation | bounded crypto/protocol/config/auth packages check under current seed | End-to-end owned transport, host-key verification, cancellation and interoperability matrix |
| Web automation | operational bounded-redirect client foundation | Absolute URL plus system IPv4 resolution, bounded redirects, and owned HTTP/HTTPS body streams with certificate/hostname verification | IPv6/dual-stack, cookie/cache/resolver-cancellation composition, crawl loop, robots/rate policy and browser automation |
| Savana OS | migration roadmap | seed provides freestanding x86-64/AArch64/RISC-V64 compiler boot foundations | First LLVM-built Savana x86-64 boot/console gate; historical v0.1 is migration evidence only |
| WebAssembly | object-level / planned runtime | wasm32-WASI/object target rows exist | Hosted services, browser bindings and execution evidence |
In the desktop row, “conditional caching” refers to HTTP validator revalidation plus cache expiry, eviction, quota, and encryption policy. The bounded exact-URL offline plugin cache documented below is complete.
Language and compiler
The clean compiler under seed/compiler/llvm is the repository launcher and
semantic authority. Gates 0-23 are closed for their recorded scopes. Linux
x86-64 is the primary executed target; Windows x86-64 passes under required
Wine and macOS x86-64 passes natively on Intel. macOS arm64 is
implementation/link/ABI complete but has no native execution claim.
Evidence: seed/compiler/llvm/ROADMAP.md,
seed/compiler/llvm/tests/GATE*_BASELINE.md, and
Current Status.
CLI and TUI
Grove G08 closed a safe portable authoring foundation. It intentionally did not claim interactive terminal or child-process execution: those require exact owners that restore terminal state, wait for children and handle cancellation on every exit.
Evidence: seed/compiler/llvm/tests/GROVE_G08_BASELINE.md.
Web
The current web work is a collection of operational lower layers, not a
production framework. Request/response validation, routing rules, middleware
policy, networking and buffers exist. G12 now owns OpenSSL 3 server/client
contexts with mandatory client certificate and hostname/IP verification. G14
owns bounded HTTP/1.1 and HTTPS GET bodies with partial I/O,
content-length/chunked/close framing, typed deadlines, and exact transport
cleanup. std-url supplies complete borrowed absolute-URL components and
std-http-fetch composes bounded absolute or relative redirects through the
host system's IPv4 resolver into HTTP or verified HTTPS, rejecting TLS
downgrade. An authenticated path accepts a bounded application-supplied
Authorization value only over HTTPS and retains it only across same-origin
redirects. IPv6/dual-stack selection, bounded resolver cancellation, cookies,
decompression, cache policy, authentication-scheme negotiation and credential
lifecycle, and pooling remain higher-level work. The
integrated web, web_core runtime and
web_runtime facade remain archived until the server
connection-to-response loop, cancellation, and shutdown drain are closed end
to end.
Evidence: Grove G12 baseline, Grove G14 baseline, the G13 and G16 baselines, and Web Stack.
Public site internationalization
The public site currently serves English-only landing, subscription, and
documentation pages from the custom seed-site server. The source tree is
under /opt/seed-lang/seed-site, the production artifact is under
/opt/prod/seed-site, and /opt/dev/seed-site does not yet exist. English
keeps the existing unprefixed URLs; Spanish, Brazilian Portuguese, French, and
Italian use /es, /pt-br, /fr, and /it. Locale tags remain BCP 47
values (en, es, pt-BR, fr, and it) even when URL segments are
lowercase.
| Gate | Closure evidence |
|---|---|
| SITE-I18N-G0 — reproducible development baseline | /opt/dev/seed-site is created from a clean, recorded source revision; its binary, static files, documentation tree, configuration schema, and content manifest are reproducible; the English route and form smoke matrix passes there without changing production |
| SITE-I18N-G1 — locale and route contract | One route resolver preserves the current English URLs, serves the four prefixed locale trees, redirects /en/... permanently to the equivalent unprefixed URL, separates query strings before matching, emits the exact Content-Language, and passes home, subscription, documentation, static-asset, API, missing-page, and traversal-rejection cases for every locale |
| SITE-I18N-G2 — templates and message catalogs | Landing, subscription, documentation shell, navigation, footer, form states, countdown units, metadata, and server-visible errors have stable catalog keys; the subscription API returns locale-neutral error codes; the build rejects missing, extra, duplicate, or placeholder-incompatible messages; rendered English retains content parity except for intentional routing and discovery changes |
| SITE-I18N-G3 — five-locale public pages | Home and subscription pages have source-current machine translations for es, pt-BR, fr, and it, canonical English copy, a shared technical glossary, locale-preserving navigation, and an accessible language selector; localized form success, duplicate, invalid-input, server, and network states pass desktop and mobile layout checks; the release manifest discloses whether human language review occurred |
| SITE-I18N-G4 — localized documentation foundation | Locale-specific Markdown roots, localized documentation navigation, per-page titles/descriptions, stable explicit heading IDs, and locale-aware internal-link rewriting pass for the introduction, overview, current status, product roadmaps, Ridge DB overview, and Ridge DB quickstart in all five locales; code, commands, identifiers, and product names remain canonical |
| SITE-I18N-G5 — complete documentation coverage | All 40 public documents have source-current machine translations in the four added locales; every translation records its English source revision, provider, schema, and review state; missing or stale translations cannot publish under the machine policy; a full link crawl finds no accidental cross-locale navigation, .md route leaks, broken anchors, or English prose presented under a localized canonical URL |
| SITE-I18N-G6 — discovery and sharing | Every published page has self-canonical URL, exact lang, complete available-locale hreflang plus x-default, localized title/description/Open Graph metadata, and consistent clean URLs; robots.txt and the generated sitemap enumerate only valid canonical pages and pass duplicate/missing-alternate checks |
| SITE-I18N-G7 — ancillary public assets | The Ridge runtime diagram extracts translatable controls, accessibility labels, statuses, and narrative copy from its data model and passes keyboard/screen-reader smoke checks in all five locales; llms.txt, downloadable archives, and other language-neutral or canonical-English assets have an explicit publication policy instead of silent localized duplication |
| SITE-I18N-G8 — staged release and production promotion | The exact candidate artifact passes the 210-page core route matrix (home, subscription, and 40 documents across five locales), localized subscription integration, sitemap crawl, metadata assertions, missing/stale-translation policy, responsive screenshots, and rollback rehearsal in development; that same immutable artifact is then promoted atomically to production with recorded hashes and a verified rollback target |
The gates close in order. The default policy requires human technical review,
but an owner-authorized machine policy may close G3-G5 through complete,
source-current translations plus the automated content, route, accessibility,
responsive, and interaction matrix. Such a release must record
translation_policy=machine and human_reviewed=0; human language validation
is post-deployment and does not retroactively change that provenance.
Desktop, adaptive UI and game
The Adaptive UI track has a live Linux X11/AT-SPI backend and the shared
Android Gallery. Its reusable grove-ui-platform contract now also runs one
native Gallery source through headless Linux/macOS, X11 plus a live
independently queried AT-SPI registry on Linux x86-64,
AppKit/NSAccessibility on macOS ARM64, and Win32/GDI/UI Automation on Windows
x86-64 under required Wine. The native desktop gates cover a platform view,
pointer and semantic actions, adaptive styles, resize, and exact close failure
propagation; Wayland, physical Windows, and independent Windows
assistive-client evidence remain open.
The initial UI9 grove-ui-native-bridge slice now provides contract version 2
with a 4096-byte valid UTF-8 clipboard plus bounded typed
information/warning/error dialogs and platform-neutral OK/Cancel/Yes/No
responses. Independent X11, AppKit, and Win32 processes exchange clipboard
text with Seed in both directions; native X11 modal windows, NSAlert, and
MessageBoxW execute all four response classes; headless and all three
desktop debug/release gates pass. Rich formats, Wayland/mobile adapters, file
dialogs, platform views,
inspector/profiler tooling, and hot reload remain open.
The companion grove-ui-plugin slice loads an explicit Seed-authored ABI-v1
dynamic library on native macOS/Linux and Windows/Wine through host contract
4. It validates the complete entry table and bounded identifier, retains up to
sixteen distinct generation-checked owners, rejects duplicates, overflow,
stale handles and ABI v2, accepts bounded semantic-versioned capability
catalogs with legacy fallback, classifies numeric and bounded UTF-8
capabilities through a complete optional signature group, rejects partial
catalog/signature groups, and unloads/reopens independently in debug and
release. The raw loader remains policy-free; package-layer grants and trust do
not sandbox native code. Sandboxing, crash isolation, and platform-view
capabilities remain open.
The companion grove-ui-plugin-package provides a
schema-1/2/3/4/5/6/7 directory bundle
and deterministic resolution by identifier in one caller-selected root.
Schema 2 adds at most eight ordered dependency identifiers while schema 1
remains dependency-free. Schema 3 adds strict semantic versions and exact,
caret, or tilde requirements. Schema 4 adds explicit boolean optional edges.
Schema 5 adds a bounded exact/caret/tilde capability requirement set checked
against the loaded binary catalog. Schema 6 requires numeric or UTF-8
signatures and checks them against the exact binary. Schema 7 adds bounded
unique permission declarations, introspection, default denial, and explicit
grant-aware open before native loading. Canonical JSON,
dependency/version/optional/capability-policy validation, and
manifest/request/binary coherence pass an identical positive and negative
corpus on macOS/Linux and Windows/Wine debug/release. Package host contract 3
streams a domain-separated SHA-256 digest over the exact bounded manifest and
binary, retains a private read-only POSIX snapshot or a replacement-denying
Windows handle, and loads that exact resource. Seed provides opt-in Ed25519
verification and verified-open APIs; independent fixtures reject manifest and
binary tampering, attempt source replacement after verification, and prove
stable execution in every desktop debug/release row.
grove-ui-plugin-trust supplies bounded application-owned
publisher/key/signature records, one active and one overlap key per publisher,
explicit rotation/revocation, and package/repository trusted-open APIs. Missing,
revoked, or mismatching records fail before native open.
grove-ui-plugin-trust-store durably retains the complete bounded trust policy
and up to eight minimum catalog sequences in one canonical 64-KiB document.
Its native macOS/Linux and Windows/Wine debug/release gates cover private
atomic replacement, stale-part recovery, key rotation/revocation round-trips,
corruption rejection, and monotonic anti-rollback state.
grove-ui-plugin-trust-bundle verifies a canonical root-pinned Ed25519
schema-1 policy envelope with bounded authority metadata, freshness, validity,
and sequence anti-rollback. grove-ui-plugin-trust-distribution fetches the
envelope only through verified HTTPS. The composed macOS/Linux/Windows
debug/release gates apply sequence 7 and then sequence 8 atomically, retain
sequence 8 across invalid-signature, wrong-authority, expiry, replay, HTTP,
status, and oversize failures, and leave no part-file debris. Authenticated
delivery follows the shared HTTPS-only, same-origin credential policy. Its
bounded exact-URL raw-envelope cache fallback runs only after transient fetch
failures, repeats root-pinned signature/freshness/validity/sequence
verification, and stores only application-verified envelopes. Pinned
authority-root provisioning/rotation, secure-clock and
transparency/timestamp policy, conditional HTTP revalidation, cache
expiry/eviction/quota/encryption, Retry-After/jitter
policy, authentication-scheme negotiation and credential
acquisition/refresh, and sandboxing remain open. Envelope GETs use three total
attempts with capped 100/200 ms exponential backoff for transport failures
and the shared transient status set.
The companion grove-ui-plugin-store provides transactional new installation
and removal inside that explicit-root model. It copies into private staging,
has Seed validate and execute the exact staged copy, publishes without
replacement, and hides removal behind an atomic tombstone. The three desktop
debug/release gates cover collision, invalid-manifest abort, execution,
removal, and reinstallation. The companion
grove-ui-plugin-repository searches up to eight caller-ordered roots,
falls through only on absence, and fails closed on invalid higher-priority
packages. Two binaries sharing one ID prove shadowing, reversed precedence,
fallback, bounds, invocation, and close on the three desktop debug/release
gates. grove-ui-plugin-roots supplies validated platform-standard user and
system paths plus bounded absolute process-local overrides. The same gates
cover real defaults, exact overrides, user shadowing, system fallback,
invalid-path rejection, invocation, and close. grove-ui-plugin-archive host
contract 3 provides strict two-entry schema-1 stored and schema-2 raw-DEFLATE
ZIP transports plus a canonical schema-3 raw-LZ4 envelope, CRC and
compressed/uncompressed size validation, fixed path-free extraction into a
private owned root, exact Seed package execution, and transactional
installation/upgrade handoff. Its dependency-free bounded decoders cover
stored/fixed/dynamic DEFLATE and overlapping LZ4 matches. Native
macOS/Linux and Windows/Wine debug/release gates reject corruption, traversal,
invalid/trailing/excess-block DEFLATE streams, unsupported or mixed methods,
extra entries, oversized manifests, and invalid extracted packages while
proving schema-1 compatibility, upgrade/rollback, and cleanup.
Transparency/timestamp policy, sandboxing, and hot reload remain open.
grove-ui-plugin-generations host contract 3 retains a caller-selected one to
eight prior validated bundles behind the unchanged active path. Upgrade and
selected tentative rollback candidates execute through Seed before commit;
fixed pending/swap names, durable per-slot rotation progress, and an OS-owned
lock recover deterministic interrupted states. Generation-aware uninstall
removes the active bundle and every retained entry and completes recorded
interrupted removal. Native macOS/Linux and Windows/Wine debug/release gates
prove the eight-entry bound, selected rollback, pruning, invalid-stage and
corrupted-rollback abort, interrupted rotation, normal/interrupted uninstall,
and stale cleanup.
grove-ui-plugin-update composes bounded HTTP/HTTPS download, canonical
archive extraction, caller-selected Ed25519 credentials, explicit permission
grants, and retained generation publication. Trust and grant preflight precede
the first native load, and one per-package OS file lock protects a synced
private part file. Native macOS/Linux and Windows/Wine debug/release gates
prove invalid-signature, wrong-grant, and oversize abort without active or
history mutation, then publish a valid permissioned update, retain the prior
generation, and execute bidirectional permission-aware rollback.
grove-ui-plugin-catalog parses up to 32 bounded schema-1/2 release records
and selects the highest compatible version strictly newer than the installed
package. Schema 2 verifies a domain-separated detached Ed25519 signature and
application-selected publisher/key, issue/expiry, clock-tolerance,
maximum-validity, and monotonic-sequence policy. The composed update path owns
transport and binds the selected version to the signed package before native
loading. Native macOS/Linux and Windows/Wine cover already-current/no-match
behavior plus duplicate, publisher, version-mismatch, invalid-signature,
premature, expired, and rollback rejection. Authenticated variants cover both
catalog and archive requests under the shared HTTPS-only, same-origin
credential policy. Both GETs use three total attempts with capped 100/200 ms
exponential backoff for transport failures and the shared transient status
set. grove-ui-plugin-remote-cache retains bounded exact-URL raw catalog and
archive entries in one explicit root; transient fallback repeats catalog
signature/freshness/sequence plus archive, package, version, trust, and
permission checks before native loading or publication. Conditional HTTP
revalidation, cache expiry/eviction/quota/encryption, Retry-After/jitter policy,
authentication-scheme negotiation and credential acquisition/refresh, grant
selection, and pinned authority-root provisioning/rotation remain higher
layers.
grove-ui-plugin-dependencies resolves schema-2/3/4/5/6/7 graphs through the
ordered
fail-closed repository. It returns deterministic dependency-first postorder,
emits shared nodes once, and rejects missing, cyclic, too-deep, or oversized
graphs. Native macOS/Linux and Windows/Wine debug/release gates validate four
distinct Seed binaries split across two roots plus the negative corpus, then
retain all four owners simultaneously and invoke each indexed transform
capability before reverse close. The graph enforces exact/caret/tilde
requirements, skips and counts absent optional packages, and rejects present
invalid or incompatible optional packages. Its schema-7 row negotiates and
invokes numeric and bounded UTF-8 secondary capabilities, exposes one unique
permission union, denies ordinary activation, and preflights explicit grants
before native loading. Its trusted variants preflight all four package
signatures, accept one rotation-overlap key, reject revoked keys and
cryptographic mismatches, and activate only after the whole graph passes.
Live forced-process/power-loss update evidence remains open. The Game track
now has a versioned
backend-neutral boundary, an owned window loop with idempotent
fullscreen/VSync control, keyboard/mouse/text/touch/pen/controller snapshots,
shapes, bounded IME pre-edit/candidate state, typed controller power telemetry,
RGB LED feedback, cached controller touchpads and sensors, and dual-motor
controller rumble with explicit stop,
owned RGBA textures with nearest/bilinear sampling, pivot-rotated/flipped
sprites, owned offscreen render targets with feedback rejection, transparent
consecutive-sprite/glyph batching, and explicit bounded
ordinary/transformed-sprite batches sorted by layer/material with stable
same-material order and
allocation-free submission. Exact-order retained buffers replay clear,
primitive, viewport, render-target, and ordinary/transformed-sprite commands
plus paths, compound fills, styled solid/dashed strokes, antialiased meshes,
and atomic bitmap-glyph runs across frames without new allocation after
whole-stream portable validation. Their caller-bounded mesh and glyph arenas
are cleared and reused with the command owner.
The track also includes bounded single-contour
linear/quadratic/cubic paths with deterministic simple-concave fill and
portable width/cap/join stroke styles plus solid/dashed antialias fringes
through per-vertex colors, a strict
headless host, clipped camera viewports, versioned asset manifests, safe
bounded asset reads, a root-scoped capacity-bounded LRU byte cache with
observable hit/miss/eviction/reload behavior and synchronous exact-content
development refresh, plus bounded root-scoped polling and native-event
watchers for creation/change/replacement/removal hints. The native watcher
uses kqueue on Apple platforms and inotify on Linux/Android, performs
exact per-path classification after a wakeup, and transparently retains
polling on unsupported targets or backend failure. Structured background jobs
copy borrowed inputs before spawning, preserve the same safe-root and byte
bounds, and return owned raw/image/WAV/SBF results through non-blocking poll,
blocking wait, or safe discard. Applying completed results to live caches
remains explicit. An independent typed LRU arena for decoded image RGBA, sound
PCM, and bitmap-font RGBA, pinned bounded PNG/JPEG plus dependency-free PPM-to-RGBA
and SBF bitmap-font decoding, measured ASCII text, plus bounded HarfBuzz and
FreeType TTF/OTF Unicode shaping/rasterization. SDL3 execution passes on
macOS ARM64 and Linux x86-64; a focused Windows x86-64 backend ABI gate passes
under required MinGW/Wine/Xvfb at contract v27. The complete relocated Linux,
macOS, and Windows packages rebuild and execute the contract-v27 application.
Contract v20, which adds
owned IME candidate snapshots to eight-device pen snapshots, 16-contact touch,
refresh-adaptive pacing, IME
pre-edit/clipboard state, controller power, and controller rumble without
exposing SDL. Contract v21 adds aligned per-vertex RGBA triangles used by the
bounded antialiased-stroke tessellator. Contract v22 adds completed-present
count and last/average/maximum CPU-side native present-call duration.
Contract v23 adds negotiated adaptive VSync with explicit standard fallback.
Contract v24 adds three bounded generation-checked auxiliary native windows
with independent lifecycle, size/timing/refresh, fullscreen, negotiated VSync,
and clear/present frames. Contract v25 adds opaque surface-selected full
gfx2d routing, isolated renderer/resource contexts, and cross-window
texture/target rejection. Contract v26 routes window-bearing input snapshots;
contract v27 adds independent precise/adaptive pacing and CPU-side
presentation telemetry. Contract v28 adds bounded RGB LED feedback, two
four-finger touchpads, and six explicitly enabled accelerometer/gyroscope
variants; a virtual SDL3 gamepad proves exact fixed-point snapshots and
callbacks. Contract v29 routes renderer reset/loss events by window, publishes
a monotonic graphics generation plus target/device counters and lost state for
every surface, and generation-invalidates textures and targets after device
reset/loss. A synthetic SDL fixture proves stale-handle rejection, replacement
generation, and lost-device shutdown. Controllers and clipboard remain
process-global. Deterministic headless and macOS ARM64 SDL3 pass v29; preceding
v27 evidence covers complete Linux, focused Windows/Wine, and all relocated
package matrices.
Shared owned PCM streams now include a bounded owned output-device snapshot,
an abstract default route on every backend, SDL3 physical-output names and
preferred formats, explicit opening by ephemeral snapshot index, and an owned
monitor with SDL3 playback-device events, exact post-event snapshot comparison,
and portable polling fallback for list/name/format/default changes. Headless,
Android OpenSL ES, and Apple AudioQueue currently expose only the default
route. Contract v5 adds owned
non-blocking PCM16 mono/stereo capture from SDL3's default recording route;
headless, Android, and Apple explicitly report it unavailable. It also adds an
allocation-free coherent session monitor: SDL3 playback events, Android audio
focus/device callbacks, and Apple AVAudioSession notifications report
interruption and classified route transitions through one portable API. Seed
Garden arbitrates that state independently from lifecycle and player-selected
pause. Integer-only
8–192 kHz PCM16 WAV resampling plus 48 kHz IMA ADPCM decoding, codec-neutral
memory/file/seekable-or-live-callback Ogg Vorbis, Ogg Opus, native FLAC, and
MP3 decode, and shared
incremental 8–192 kHz compressed-stream normalization to 48 kHz including
direct unknown-duration 48 kHz streams, a bounded adaptive PCM reservoir, and
exclusive-ownership structured background block decode with one reusable PCM
workspace, plus a bounded frame-driven game mixer
cover sound effects, looping compressed music,
channels, volume groups, typed bounded linear stereo panning, relative 3D
distance attenuation with typed listener orientation, Doppler playback and
live channel updates for sound voices, bounded persistent two-tap HRTF
elevation filtering, frame-exact bounded master/sound/music fades,
pause/resume, and exact cleanup.
Portable fixed-step timing, timers/statistics, backend-neutral precise frame
pacing, millihertz refresh queries, and stable-divisor adaptive caps, plus
vectors, collision, transforms, deterministic random, and a
shared color contract also pass. A relocatable Linux directory and ad-hoc
signed macOS application bundle plus a Windows portable directory contain
SDL3, the required Seed code, manifests, and assets. The independent
seed-game-assets CLI deeply validates packaged
manifests and PNG/JPEG/PPM/SBF/TTF/OTF/WAV/Ogg Vorbis/Opus/native FLAC/MP3
payloads without a
window or SDL, and deterministically converts accepted WAV input to compact
mono/stereo IMA ADPCM, PNG/JPEG/PPM images to RGBA8 PNG, SBF glyph atlases to
PNG, and shaped/wrapped TTF/OTF text to PNG. It packs bounded decoded images
into a deterministic alpha-preserving shelf atlas with composable stable
sorting, transparent trimming, and clockwise tall-sprite rotation.
It also imports exact 16x6 PNG/JPEG/PPM bitmap sheets into canonical
runtime-validated SBF documents.
Versioned seed-atlas 2/3/4 maps have a bounded public runtime parser, and
the CLI authors bounded ordered sparse seed-tilemap 1, compact binary dense
seed-tilemap 2, sparse binary chunked seed-tilemap 3, and origin-aware
chunked seed-tilemap 4 documents
consumed by matching runtime parsers; a bounded single-layer Tiled CSV importer
and a 1..16-layer, 1..16-tileset finite orthogonal Tiled JSON importer produce
the same dense format. Bounded infinite JSON and TMX importers preserve
negative coordinates and canonicalize fixed-size chunks into v4. The TMX
paths accept finite layers or infinite chunks with uncompressed CSV. JSON and
TMX tilesets are strictly ordered
and align the atlas to Tiled's global GID space. Both import paths can resolve
named external TSX files relative to the map and derive the atlas size from
bounded tile counts. The
portable RGBA8 encoder uses a two-pass exact-bit selector between fixed and
complete active-alphabet dynamic Huffman DEFLATE, with a deterministic 32 KiB
latest-match window and matches up to 258 bytes. Explicit fixed/dynamic block
checks and decoder round trips keep the output portable without a platform
image encoder.
grove-game-test v9 adds deterministic goldens, property corpus, integer and
structured byte-buffer shrinking, four-controller replay, allocation-free
versioned SGTR trace capture/playback, and atomic semantic complete-frame
trace shrinking into caller-owned storage. grove-game-debug v1 aggregates
bounded frame/update/draw/
audio counters and produces deterministic printable-ASCII overlay text.
An independent bounded seed-objectmap 1/2/3/4 runtime now validates
canonical
object layers, signed-thousandth rectangle/point/ellipse/polygon/polyline/tile
geometry, vertices, UTF-8 metadata, and typed map/layer/object properties;
v2 adds acyclic group hierarchy, layer IDs, cell/millipixel offsets, opacity,
and layer visibility, v3 adds object visibility, and v4 adds bounded Tiled
text content/font/color, pixel size, wrap/style/kerning flags, and alignment;
older versions remain compatible.
The JSON and TMX importers now author equivalent nested group/object-layer
hierarchies in bounded parent-before-child pre-order with parent links, kinds,
layer IDs, cell/millipixel offsets, opacity, visibility, empty layers, scalar
properties, exact decimals, deterministic ID sorting, failure-before-output,
and byte-identical seed-objectmap 4 results, including hidden and text
objects. Bounded non-tile JSON/TMX templates now inherit geometry, metadata,
and scalar properties with deterministic instance and same-name-property
overrides. Nested class-valued properties use class:<propertytype> and
bounded canonical JSON, producing byte-identical JSON/TMX object maps.
External-TSX tile templates normalize relative paths, validate local tile
indices, and remap into the map's global GID space. Cross-serialization and
nested templates remain active.
Dynamic-Huffman optimization, Tiled object/group/property/
collision-object import, graphical editors, and richer structure-aware
shrinkers remain tooling work.
Seed Garden now consumes this foundation through a deterministic headless
rules/progression model and a native desktop adapter. Its relocatable macOS,
Linux, and Windows packages execute the same model used by Android. The
desktop adapter persists a versioned checksummed progress payload through
sync + atomic rename, restores timed attempts across restart, and quarantines
corrupt/incompatible files before clean recovery. Mobile and desktop block
retries when no attempt remains; the desktop result overlay presents all 15
levels with unlocked best scores, stars, and the next minimum-score-gated
level. It also mixes a 96-byte mono IMA ADPCM WAV move effect, a file-streamed
4,464-byte Opus music loop, and a 24,808-byte native FLAC victory effect
decoded once into a retained PCM16 clip, and pauses the mixer with the game.
The Linux directory additionally publishes as a reproducible direct-download
Flatpak targeting Freedesktop Platform 25.08. The installed application has
only IPC, Wayland/fallback-X11, PulseAudio, and DRI permissions, with no
network or host-filesystem access. The completed bundle installs and executes
under the sandbox, retains the GLIBC_2.34 ceiling, and leaves its runtime as
a separately resolved dependency. The generic signed Flatpak repository gate
passes AppStream discovery and a static-delta update; Garden-specific catalog
licensing/content, key custody, and hosting, plus a trusted MSIX certificate,
key, timestamp policy, physical install, and release signing, remain
distribution work. Windows x86-64 MSIX now passes reproducible unsigned
publication and reproducible caller-supplied embedded signing, official-SDK
unpack validation, independent signature and subject validation, tamper
rejection, and exact-payload Wine execution. The signed gates deliberately use
disposable certificates rather than defining a production publisher.
The AppImage publisher also has a reproducible signed-update mode with an
explicit full OpenPGP fingerprint, GPG home, release timestamp, HTTPS zsync
location, and external signature validation. Its generic gate rejects a
tampered image, verifies HTTP byte ranges, and uses the official updater for
an exact signed 1.0.0-to-2.0.0 delta. The Garden product gate preserves
GLIBC_2.34, reproduces both AppImage and zsync bytes, validates the signature,
and executes the signed image. Those gates deliberately use disposable keys
and a non-release location; owner-controlled release-key custody and a real
HTTPS range endpoint remain distribution inputs.
Authored production content/audio, physical Android/iOS audio evidence, and
physical-device performance/thermal stress remain explicit product work. The
Android adapter now retains that mixer in an Activity-generation context,
keeps the compact Opus and FLAC sources compressed in memory, and queues
decoded PCM through a bounded OpenSL ES backend. An
API-35 ARM64 AVD proves an active
48 kHz stereo track, scoring-move playback, and pause/resume across both the
game overlay and Activity background/foreground; physical speaker quality and
latency are not claimed. A clean API-37 ARM64 gate adds eight alternating
portrait/landscape recreations with all 64 tile semantics, reduced-motion
scoring, audio teardown, and bounded startup/frame/PSS metrics. Its dedicated
allocator row runs two symmetric eight-rotation lifecycle workloads under
guarded bionic malloc_debug; both measured libmemunreachable scans report
zero bytes and zero allocations.
The iOS 26.5 ARM64 simulator builds the same mobile Garden source and assets.
Its reusable application context and atomic private-file persistence survive
continuous frames; XCUITest covers 67 stable semantic nodes, pause/resume,
rotation, background/foreground, termination, and relaunch. The iOS audio
backend uses fixed bounded Apple AudioQueue buffers; the gate requires one
active stream with advancing callbacks and also emits an iPhoneOS-identified
Garden object plus a complete unsigned application bundle with validated flat
assets. This is simulator audio-processing and device packaging evidence, not
physical execution, speaker-route, latency, or signing evidence.
This is a reusable native foundation, not a shipped game runtime:
HTTP retry/authentication/cache/playlist/live-chunk policy above the completed
bounded range/callback/background-decode/reservoir layers, capture and physical
enumeration beyond SDL3, physical interruption/route validation beyond the
completed coherent monitors and retained owning-task handlers,
physical Windows/iOS evidence,
distribution signing/notarization/installers, and broader mobile adapters
remain open.
Evidence: UI4 baseline, UI6 baseline, UI9 native bridge baseline, UI9 plugin baseline, UI9 plugin package baseline, UI9 plugin store baseline, UI9 plugin repository baseline, UI9 plugin roots baseline, UI9 plugin archive baseline, UI9 plugin generations baseline, UI9 plugin update baseline, UI9 plugin catalog baseline, UI9 plugin trust-store baseline, UI9 plugin trust-distribution baseline, UI9 plugin dependencies baseline, Game P1 baseline, Game P2 baseline, Game P3 baseline, Game P4 baseline, Game P5 baseline, Game audio stream baseline, Game Opus baseline, Game FLAC baseline, Game MP3 baseline, Game P6 baseline, Game P7 baseline, Game P8 Linux baseline, Game P8 macOS baseline, Game P8 Windows baseline, Game P8 AppImage baseline, Game P8 AppImage update baseline, Game P8 Flatpak baseline, Game P8 MSIX baseline, Game P8 signed MSIX baseline, Game P9 baseline, Game test baseline, Game text baseline, Seed Garden portability baseline, and the Game roadmap.
Mobile
Android and iOS are active mobile tracks at explicitly scoped evidence levels. Android packages arm64-v8a and x86-64 through Gradle/Kotlin/CMake/JNI and passes API 21/29/37 AVD plus an initial API-35 physical-device slice. iOS passes the 26.5 ARM64 simulator and an initial signed iPhone XR slice through the Swift/UIKit host. Shared lifecycle/services, bounded input, frame, semantics, rotation, and accessibility contracts are covered; broader hardware, full IME/accessibility matrices, archive/export, store validation, and production release remain open.
See Android Applications.
Ridge DB
Ridge is the most advanced application track. The v0.2 line froze P0-P12 and waived P13 rather than reporting a failed matrix as passing. The bounded v0.3 local foundation completed V3-G0-G44-A, with V3-G47-G57 also complete (V3-G52 partial). v0.4 is scoped as device↔cloud sync for offline-first applications (mobile apps, POS terminals) against an authoritative cloud, reusing the embedded/server engine on both sides. Multi-master replication, failover, sharding, and distributed SQL remain deferred to v0.5 or later.
Evidence: Ridge Database, grove/apps/ridge/CAPABILITIES.md,
grove/apps/ridge/ROADMAP.md, and grove/apps/ridge/V3_CONTRACT.md.
Ridge Admin
grove/apps/ridge-admin is a Ridge-native browser administration application,
not a PostgreSQL compatibility claim. The 0.2.0+contract.3 professional
preview owns a loopback-only HTTP boundary, launch/session/CSRF/CSP policy,
the built-in Local Ridge profile, secret-free saved profiles, four local or
native SSH direct-tcpip pgwire connections, versioned Ridge introspection,
SQL workspaces, deterministic data paging, up to four typed parameterized
filters, conflict-aware drafts, atomic save/import of up to 10,000 staged
changes, server-spooled bounded CSV export, integrity/vacuum operations,
verified operator-rooted backup, and non-overwriting offline restore.
Evidence and current release blockers are in
grove/apps/ridge-admin/SPEC.md, README.md, RELEASE.md, and the
machine-readable runners under grove/apps/ridge-admin/tests/.
ML and LLM
The clean Grove conversion retained bounded, ownership-safe tensor storage, shape/dataset/model metadata, tokenizer/configuration and experiment contracts. It explicitly archived numeric CPU/CUDA kernels, full graph/model execution and LLM runner behavior that lacked safe current owners. The next stage is executable numeric correctness before performance or model-quality claims.
Evidence: Grove G18-G22 baselines.
Savana OS
Savana's historical v0.1 tree is not an operational current kernel. The active roadmap starts by porting a minimal x86-64 boot/console path to the clean LLVM compiler, then builds explicit KAL/HAL/backend contracts. AArch64 and RISC-V64 Savana boots remain future gates even though the compiler itself has freestanding boot fixtures for those architectures.
Evidence: savana/ROADMAP.md.
Status discipline
- A checked directory is not automatically a complete product.
- A cross-compiled artifact is not an execution claim.
- A benchmark is evidence for its named workload and host only.
- “Production” is reserved for a future release policy with compatibility, security, deployment and support criteria.
- Each track advances only when its roadmap records executable closure evidence.