Skip to main content

GenesisCode Feature Matrix (Audit Date: 2026-08-11)

Scope: capability maturity for AI-agent autonomy, semantic selfhost closure, and production runtime trust.

This is a generated status view, not release evidence. The canonical source is docs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.json. Product and deployment qualification is reported in this document’s generated product/target section and docs/spec/PRODUCT_TARGET_MATRIX_v0.1.json; foundation maturity never implies a child target.

Maturity legend: - L0 specified - L1 implemented/reachable - L2 verified on the named reference host - L3 reproducible on the supported host matrix - L4 product-proven under declared SLOs - L5 release-attested with immutable evidence

Selfhost legend: H0 routed, H1 GenesisCode implementation, H2 GenesisCode production authority, H3 reproducible bootstrap fixpoint, H4 independently conformant, N/A deliberately outside selfhost closure. Capability-row selfhost labels are non-authoritative traceability summaries. Exact per-decision status, including decisions below H0, is derived from docs/spec/SEMANTIC_OWNERSHIP_LEDGER_v0.1.json in docs/status/SELFHOST_AUTHORITY_v0.1.md.

Supported Host Scope

Platform ID Host Tier
macos-arm64 macOS arm64 1
linux-x86_64 Linux x86_64 1
linux-arm64 Linux arm64 2
windows-x86_64 Windows x86_64 2

Capability Maturity

ID Capability Class Overall macOS arm64 Linux x86_64 Linux arm64 Windows x86_64 Selfhost Owner
CAP-KERNEL-DETERMINISM Pure deterministic kernel separated from effects foundation L1 L1 L1 L0 L0 N/A kernel-runtime
CAP-COREFORM-IDENTITY Canonical CoreForm IR + stable content hash identity foundation L1 L1 L1 L0 L0 H0 coreform
CAP-SEALED-PROTOCOL Sealed unforgeable UNHANDLED/EFFECT/ERROR protocol foundation L1 L1 L1 L0 L0 N/A kernel-runtime
CAP-DENY-DEFAULT-POLICY Deny-by-default capability policy runtime foundation L1 L1 L1 L0 L0 H0 effect-runtime
CAP-EFFECT-REPLAY Deterministic effect logs + replay checker foundation L1 L1 L1 L0 L0 H0 effect-runtime
CAP-SEMANTIC-VCS Built-in semantic VCS (commit/patch/refs/merge3) foundation L1 L1 L1 L0 L0 H0 vcs-patches
CAP-PACKAGE-MANAGER Built-in package/project manager (pkg/gcpm) foundation L1 L1 L1 L0 L0 H0 package-registry
CAP-ARTIFACT-GC Reachability-based artifact GC (refs + locks + pins) foundation L1 L1 L1 L0 L0 H0 package-registry
CAP-EVIDENCE-GATED-PUBLISH Obligation/evidence/attestation-gated publish + ref updates foundation L1 L1 L1 L0 L0 H0 obligations-registry
CAP-RUNTIME-SURFACES Native + WASI + wasm-host runtime surfaces aggregate foundation L1 L1 L1 L0 L0 H0 runtime-platforms
CAP-SELFHOST-FRONTEND Selfhost frontend default in production CLIs foundation L1 L1 L1 L0 L0 H0 selfhost-toolchain
CAP-SELFHOST-CUTOVER Full selfhost cutover profile + readiness scorecard foundation L1 L1 L1 L0 L0 H0 selfhost-toolchain
CAP-STRICT-NO-FALLBACK Strict no-production Rust semantic fallback guard foundation L1 L1 L1 L0 L0 H0 selfhost-toolchain
CAP-AGENT-JSON-CONTRACTS CLI + GCPM JSON schema contracts for agent automation foundation L1 L1 L1 L0 L0 H0 agent-interface
CAP-AGENT-SKILL-PACK Agent index + skill-pack conformance contracts foundation L1 L1 L1 L0 L0 N/A agent-authoring
CAP-DOMAIN-STARTERS Domain starter registry for agent workflows aggregate foundation L1 L1 L1 L0 L0 N/A agent-authoring
CAP-AGENT-WORKLOAD-PARITY Agent generative workload parity gates (native vs WASI) foundation L1 L1 L1 L0 L0 N/A agent-evaluation
CAP-AGENT-WORKSPACE-PERF Large-workspace agent iteration perf lane foundation L1 L1 L1 L0 L0 N/A agent-evaluation
CAP-CONCURRENCY-REPLAY Concurrency/task replay stress lane foundation L1 L1 L1 L0 L0 H0 effect-runtime
CAP-GPU-COMPUTE GPU compute capability independent of graphics surface aggregate foundation L1 L1 L1 L0 L0 N/A graphics-compute
CAP-GRAPHICS-RUNTIME Graphics/window/input/audio capability families aggregate foundation L1 L1 L1 L0 L0 N/A graphics-compute
CAP-BROWSER-XR Browser + XR runtime families aggregate foundation L1 L1 L1 L0 L0 N/A runtime-platforms
CAP-PLUGIN-FFI Host plugin + FFI schemas/contracts foundation L1 L1 L1 L0 L0 H0 effect-runtime
CAP-HOST-BRIDGE First-party bridge for network/process/db/crypto/plugin/ffi foundation L1 L1 L1 L0 L0 H0 effect-runtime
CAP-STAGE2-WASM-VALIDATION Stage2 CoreForm->WASM translation-validation foundation L1 L1 L1 L0 L0 H0 wasm-optimizer
CAP-DEPLOYMENT-PIPELINE Deployment target pipeline in core toolchain aggregate foundation L1 L1 L1 L0 L0 H0 package-registry
CAP-ASSURANCE-PROFILES Assurance profile packs + standards crosswalk foundation L1 L1 L1 L0 L0 N/A assurance
CAP-TOOL-QUALIFICATION Tool qualification lineage + evidence closures foundation L1 L1 L1 L0 L0 H0 assurance
CAP-MODULAR-BOUNDARIES AI-first modular decomposition + boundary guards foundation L1 L1 L1 L0 L0 N/A architecture

Release Claim Eligibility

A capability is eligible for an unqualified v1 release claim only at L5 on every required tier-1 platform. Lower levels must be described with their platform and evidence limitations.

ID Capability Overall Tier-1 Maturity Immutable Evidence Eligible
CAP-KERNEL-DETERMINISM Pure deterministic kernel separated from effects L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-COREFORM-IDENTITY Canonical CoreForm IR + stable content hash identity L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-SEALED-PROTOCOL Sealed unforgeable UNHANDLED/EFFECT/ERROR protocol L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-DENY-DEFAULT-POLICY Deny-by-default capability policy runtime L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-EFFECT-REPLAY Deterministic effect logs + replay checker L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-SEMANTIC-VCS Built-in semantic VCS (commit/patch/refs/merge3) L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-PACKAGE-MANAGER Built-in package/project manager (pkg/gcpm) L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-ARTIFACT-GC Reachability-based artifact GC (refs + locks + pins) L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-EVIDENCE-GATED-PUBLISH Obligation/evidence/attestation-gated publish + ref updates L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-RUNTIME-SURFACES Native + WASI + wasm-host runtime surfaces L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-SELFHOST-FRONTEND Selfhost frontend default in production CLIs L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-SELFHOST-CUTOVER Full selfhost cutover profile + readiness scorecard L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-STRICT-NO-FALLBACK Strict no-production Rust semantic fallback guard L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-AGENT-JSON-CONTRACTS CLI + GCPM JSON schema contracts for agent automation L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-AGENT-SKILL-PACK Agent index + skill-pack conformance contracts L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-DOMAIN-STARTERS Domain starter registry for agent workflows L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-AGENT-WORKLOAD-PARITY Agent generative workload parity gates (native vs WASI) L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-AGENT-WORKSPACE-PERF Large-workspace agent iteration perf lane L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-CONCURRENCY-REPLAY Concurrency/task replay stress lane L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-GPU-COMPUTE GPU compute capability independent of graphics surface L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-GRAPHICS-RUNTIME Graphics/window/input/audio capability families L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-BROWSER-XR Browser + XR runtime families L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-PLUGIN-FFI Host plugin + FFI schemas/contracts L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-HOST-BRIDGE First-party bridge for network/process/db/crypto/plugin/ffi L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-STAGE2-WASM-VALIDATION Stage2 CoreForm->WASM translation-validation L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-DEPLOYMENT-PIPELINE Deployment target pipeline in core toolchain L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-ASSURANCE-PROFILES Assurance profile packs + standards crosswalk L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-TOOL-QUALIFICATION Tool qualification lineage + evidence closures L1 macOS arm64=L1, Linux x86_64=L1 none no
CAP-MODULAR-BOUNDARIES AI-first modular decomposition + boundary guards L1 macOS arm64=L1, Linux x86_64=L1 none no

Authorized unqualified claims: - None. No capability currently carries immutable L5 release evidence.

Known GenesisCode gaps

  • R1.3.c: Generate and verify the pinned MCP agent interface from canonical CLI schemas. Affected claims: CAP-AGENT-JSON-CONTRACTS
  • R1.4.c: Build deterministic generation, repair, refactor, and deployment task benchmarks. Affected claims: CAP-AGENT-WORKLOAD-PARITY
  • R1.5.a: Generate the authoring skill from canonical language and capability inputs. Affected claims: CAP-AGENT-SKILL-PACK
  • R1.5.f: Validate skill distribution, offline use, token budgets, and multi-agent compatibility. Affected claims: CAP-AGENT-SKILL-PACK
  • R2.3.e: Meet explicit incremental large-workspace agent-loop SLOs. Affected claims: CAP-AGENT-WORKSPACE-PERF
  • R3.2.a: Audit existing stage2/Wasm coverage and eliminate undeclared fallback. Affected claims: CAP-RUNTIME-SURFACES, CAP-STAGE2-WASM-VALIDATION
  • R3.2.b: Validate source-to-Wasm translation and embedded artifact identity. Affected claims: CAP-STAGE2-WASM-VALIDATION
  • R4.1.c: Maintain a semantic-ownership ledger for every production decision. Affected claims: CAP-STRICT-NO-FALLBACK
  • R4.1.e: Enforce selfhost and stage0 dependency boundaries structurally. Affected claims: CAP-STRICT-NO-FALLBACK
  • R4.2.a: Make frontend and canonicalization GenesisCode-produced with independent identity verification. Affected claims: CAP-COREFORM-IDENTITY, CAP-SELFHOST-FRONTEND
  • R4.2.c: Make semantic patch and refactor behavior GenesisCode-authoritative. Affected claims: CAP-SEMANTIC-VCS
  • R4.2.d: Make obligation and policy decision logic GenesisCode-authoritative. Affected claims: CAP-DENY-DEFAULT-POLICY, CAP-EVIDENCE-GATED-PUBLISH
  • R4.2.e: Make package, registry, and VCS logic GenesisCode-authoritative. Affected claims: CAP-SEMANTIC-VCS, CAP-PACKAGE-MANAGER, CAP-ARTIFACT-GC
  • R4.2.g: Make CLI and agent orchestration selfhost-authoritative without hidden Rust semantics. Affected claims: CAP-SELFHOST-FRONTEND
  • R4.3.a: Split oversized host crates and meet source concentration budgets. Affected claims: CAP-MODULAR-BOUNDARIES
  • R4.3.b: Generate repetitive host, Prelude, capability, MCP, codec, and parity bindings from one schema. Affected claims: CAP-MODULAR-BOUNDARIES
  • R4.4.c: Prove cross-host bootstrap fixpoint on the tier-1 host matrix. Affected claims: CAP-SELFHOST-CUTOVER
  • R5.2.a: Audit and reconcile deterministic concurrency specifications and runtime behavior. Affected claims: CAP-CONCURRENCY-REPLAY
  • R5.2.e: Differentially explore and replay bounded schedules across tiers and hosts. Affected claims: CAP-CONCURRENCY-REPLAY
  • R5.5.a: Adopt and pin the WebAssembly Component Model/WIT extension boundary. Affected claims: CAP-PLUGIN-FFI
  • R5.5.c: Sandbox extension memory, CPU, calls, effects, cancellation, and lifecycle. Affected claims: CAP-PLUGIN-FFI
  • R6.1.a: Freeze and migrate deterministic package manifest and lock schemas. Affected claims: CAP-PACKAGE-MANAGER
  • R6.2.d: Enforce package evidence policy at registry acceptance. Affected claims: CAP-EVIDENCE-GATED-PUBLISH
  • R6.3.a: Define the supported v1 build target profiles. Affected claims: CAP-RUNTIME-SURFACES
  • R6.3.b: Implement the selfhosted genesis build graph and evidence outputs. Affected claims: CAP-DEPLOYMENT-PIPELINE
  • R6.3.c: Make target artifacts reproducible across independent builders. Affected claims: CAP-DEPLOYMENT-PIPELINE
  • R7.1.a: Classify and own the complete layered verification suite. Affected claims: CAP-ASSURANCE-PROFILES
  • R7.1.e: Use mutation testing to demonstrate trust-check sensitivity. Affected claims: CAP-TOOL-QUALIFICATION
  • R7.2.a: Mechanize the pure core semantics and determinism theorem. Affected claims: CAP-KERNEL-DETERMINISM
  • R7.2.b: Prove seal unforgeability and protected-boundary behavior. Affected claims: CAP-SEALED-PROTOCOL
  • R7.2.c: Model and prove deterministic complete effect dispatch and replay checking. Affected claims: CAP-EFFECT-REPLAY
  • R7.2.f: Verify or independently cross-check canonical codec assumptions. Affected claims: CAP-COREFORM-IDENTITY
  • R7.3.a: Threat-model every kernel, effect, bridge, package, build, and release boundary. Affected claims: CAP-DENY-DEFAULT-POLICY, CAP-ASSURANCE-PROFILES
  • R7.3.b: Sandbox host execution with hard cancellation, least privilege, and bounded IPC. Affected claims: CAP-HOST-BRIDGE
  • R8.2.a: Prove the pure library and CLI agent archetype end to end. Affected claims: CAP-AGENT-WORKLOAD-PARITY
  • R8.2.e: Prove the browser application agent archetype and its sandboxed effects. Affected claims: CAP-BROWSER-XR
  • R8.2.h: Prove the GPU or numeric agent archetype with deterministic backend evidence. Affected claims: CAP-GPU-COMPUTE
  • R8.3.a: Ship and maintain at least five evidence-backed flagship programs. Affected claims: CAP-DOMAIN-STARTERS, CAP-GRAPHICS-RUNTIME
  • R9.2.c: Publish and independently mirror immutable E4 release attestations. Affected claims: CAP-TOOL-QUALIFICATION
  • R5.6.a: Define the deterministic shared application architecture and lifecycle. Affected claims: TARGET-APPLICATION-UI
  • R5.6.b: Build the typed presentation and style intermediate representation. Affected claims: TARGET-APPLICATION-UI
  • R5.6.c: Implement the complete static, interactive, SSR, and PWA web product stack. Affected claims: TARGET-WEB-STATIC, TARGET-WEB-INTERACTIVE-SSR-PWA
  • R5.6.d: Implement accessible cross-target widgets and input semantics. Affected claims: TARGET-APPLICATION-UI, TARGET-DESKTOP-MACOS, TARGET-DESKTOP-LINUX, TARGET-DESKTOP-WINDOWS, TARGET-IOS, TARGET-ANDROID
  • R5.6.e: Make UI rendering efficient, incremental, validated, and inspectable. Affected claims: TARGET-WEB-INTERACTIVE-SSR-PWA
  • R5.6.f: Ship one product-grade cross-target UI testing API. Affected claims: TARGET-APPLICATION-UI, TARGET-WEB-INTERACTIVE-SSR-PWA
  • R5.7.a: Complete typed service routing, middleware, security, and protocol construction. Affected claims: TARGET-SERVICE-DATA
  • R5.7.b: Complete durable typed data, query, transaction, and migration APIs. Affected claims: TARGET-SERVICE-DATA
  • R5.7.c: Add production queues, jobs, cache, storage, and coordination primitives. Affected claims: TARGET-SERVICE-DATA
  • R5.7.d: Unify capability-scoped observability and operations. Affected claims: TARGET-SERVICE-DATA
  • R5.7.e: Build first-party data, numeric, tensor, and local ML libraries. Affected claims: TARGET-DATA-ML
  • R5.8.a: Define the deterministic game and simulation core. Affected claims: TARGET-GAMES-MEDIA
  • R5.8.b: Complete real 2D and 3D runtime systems. Affected claims: TARGET-GAMES-MEDIA
  • R5.8.c: Make shaders and the asset pipeline Genesis-authored. Affected claims: TARGET-GAMES-MEDIA
  • R5.8.d: Add production audio and creative timeline systems. Affected claims: TARGET-GAMES-MEDIA
  • R5.8.f: Ship Genesis-native game and media editing and debugging workflows. Affected claims: TARGET-GAMES-MEDIA
  • R5.9.a: Define Embedded Linux and constrained MCU profiles separately. Affected claims: TARGET-EMBEDDED-LINUX, TARGET-MCU-LANGUAGE-AOT
  • R5.9.b: Implement closed-world static flash, RAM, stack, timing, and resource verification. Affected claims: TARGET-MCU-LANGUAGE-AOT
  • R5.9.c: Specify real-time, interrupt, reset, watchdog, and power semantics. Affected claims: TARGET-MCU-LANGUAGE-AOT
  • R5.9.d: Define capability-safe typed board and peripheral HAL APIs. Affected claims: TARGET-EMBEDDED-LINUX, TARGET-BOARD-HAL-FAMILIES
  • R5.9.e: Build self-hostable IoT and robotics packages. Affected claims: TARGET-BOARD-HAL-FAMILIES
  • R5.9.f: Preserve and validate semantic identity across constrained compilation. Affected claims: TARGET-MCU-LANGUAGE-AOT
  • R6.3.f: Require target-native executable entrypoints and authentic runtime workloads. Affected claims: TARGET-DESKTOP-MACOS, TARGET-DESKTOP-LINUX, TARGET-DESKTOP-WINDOWS, TARGET-IOS, TARGET-ANDROID
  • R6.3.g: Make all generated foreign glue disposable, reproducible, and non-authoritative. Affected claims: TARGET-DESKTOP-MACOS, TARGET-DESKTOP-LINUX, TARGET-DESKTOP-WINDOWS, TARGET-IOS, TARGET-ANDROID
  • R6.5.a: Ship the incremental Genesis web compiler and development server. Affected claims: TARGET-WEB-STATIC, TARGET-WEB-INTERACTIVE-SSR-PWA
  • R6.5.b: Produce standards-valid deployable static, SSR, edge, and PWA artifacts. Affected claims: TARGET-WEB-STATIC, TARGET-WEB-INTERACTIVE-SSR-PWA
  • R6.5.c: Prove supported behavior in real browser engines and mobile viewports. Affected claims: TARGET-WEB-STATIC, TARGET-WEB-INTERACTIVE-SSR-PWA
  • R6.5.d: Ship and maintain a complete self-hosted full-stack reference product. Affected claims: TARGET-SERVICE-DATA
  • R6.6.a: Build signed and installable real macOS, Windows, and Linux applications. Affected claims: TARGET-DESKTOP-MACOS, TARGET-DESKTOP-LINUX, TARGET-DESKTOP-WINDOWS
  • R6.6.b: Build complete executable iOS and Android applications. Affected claims: TARGET-IOS, TARGET-ANDROID
  • R6.6.c: Automate simulator, emulator, and physical mobile and desktop qualification. Affected claims: TARGET-DESKTOP-MACOS, TARGET-DESKTOP-LINUX, TARGET-DESKTOP-WINDOWS, TARGET-IOS, TARGET-ANDROID
  • R6.6.d: Prove shared product reuse without hiding target-specific work. Affected claims: TARGET-IOS, TARGET-ANDROID
  • R6.7.a: Promote reproducible Raspberry Pi-class Embedded Linux delivery. Affected claims: TARGET-EMBEDDED-LINUX
  • R6.7.b: Implement the closed-world MCU AOT, link, firmware, and evidence pipeline. Affected claims: TARGET-MCU-LANGUAGE-AOT
  • R6.7.c: Establish qualified RP2040, RISC-V ESP32, Xtensa ESP32, and Arduino-compatible board families. Affected claims: TARGET-BOARD-HAL-FAMILIES
  • R6.7.d: Build deterministic board simulation and physical hardware-in-the-loop infrastructure. Affected claims: TARGET-DEVICE-FLASH-DEBUG-OTA, TARGET-HARDWARE-IN-THE-LOOP
  • R6.7.e: Complete authorized device discovery, flash, debug, provisioning, crash, and OTA lifecycle. Affected claims: TARGET-DEVICE-FLASH-DEBUG-OTA
  • R6.7.f: Ship maintained Embedded Linux and physical MCU hardware products. Affected claims: TARGET-EMBEDDED-LINUX, TARGET-BOARD-HAL-FAMILIES, TARGET-DEVICE-FLASH-DEBUG-OTA, TARGET-HARDWARE-IN-THE-LOOP
  • R8.2.m: Prove a nontrivial cross-target game under real frame and resource budgets. Affected claims: TARGET-GAMES-MEDIA
  • R8.2.n: Prove a creative media tool with deterministic transforms and real preview/export. Affected claims: TARGET-GAMES-MEDIA
  • R8.2.o: Prove a Raspberry Pi-class Embedded Linux product on real hardware. Affected claims: TARGET-EMBEDDED-LINUX
  • R8.2.p: Prove RP2040 and ESP32-class constrained firmware on physical boards. Affected claims: TARGET-MCU-LANGUAGE-AOT, TARGET-HARDWARE-IN-THE-LOOP
  • R8.2.q: Prove an end-to-end IoT or robotics system with hardware-in-the-loop. Affected claims: TARGET-BOARD-HAL-FAMILIES, TARGET-HARDWARE-IN-THE-LOOP
  • R8.2.r: Prove a reproducible Genesis-native data science and local ML system. Affected claims: TARGET-DATA-ML
  • Active upgrade_plan.md P0/P1 defects: none. Roadmap maturity gaps above remain open and are not erased by an empty defect queue.

Product and Target Qualification

This matrix is the authority for product and target support. Foundation capability rows, host-operation reachability, archive suffixes, descriptors, empty exports, headless plans, synthetic launchers, and simulator-only runs do not raise a product target’s maturity.

Release states are mechanically tied to maturity: L0 unsupported, L1-L3 experimental, L4 candidate, and L5 qualified. Release eligibility additionally requires L5 on every required scope plus immutable E3/E4 evidence.

Qualification Summary

ID Product / target Family Profile Overall Release state Scope maturity Eligible Owner
TARGET-APPLICATION-UI Cross-target application and UI architecture application-ui application-ui-shared L0 unsupported browser-evergreen=L0 (browser; required)
desktop-tier1=L0 (host; required)
mobile-ios-android=L0 (device; required)
no application-platform
TARGET-WEB-STATIC Static website output web web-static L0 unsupported standards-static-host=L0 (runtime; required)
browser-evergreen=L0 (browser; required)
no web-platform
TARGET-WEB-INTERACTIVE-SSR-PWA Interactive, SSR, and PWA web application web web-interactive-ssr-pwa L0 unsupported chromium-current=L0 (browser; required)
firefox-current=L0 (browser; required)
webkit-current=L0 (browser; required)
linux-ssr-runtime=L0 (runtime; required)
no web-platform
TARGET-SERVICE-DATA Self-hosted service and data platform service-data service-data-selfhosted L0 unsupported linux-x86-64-service=L0 (host; required)
linux-arm64-service=L0 (host; required)
wasi-component-service=L0 (runtime; optional)
no service-platform
TARGET-DESKTOP-MACOS Installable macOS desktop application desktop desktop-macos-arm64 L0 unsupported macos-arm64=L0 (host; required) no native-app-platform
TARGET-DESKTOP-LINUX Installable Linux desktop application desktop desktop-linux L0 unsupported linux-x86-64=L0 (host; required)
linux-arm64=L0 (host; optional)
no native-app-platform
TARGET-DESKTOP-WINDOWS Installable Windows desktop application desktop desktop-windows-x86-64 L0 unsupported windows-x86-64=L0 (host; required) no native-app-platform
TARGET-IOS Installable iOS application mobile mobile-ios L0 unsupported ios-simulator-arm64=L0 (simulator; required)
ios-device-arm64=L0 (device; required)
no native-app-platform
TARGET-ANDROID Installable Android application mobile mobile-android L0 unsupported android-emulator-x86-64=L0 (simulator; required)
android-device-arm64=L0 (device; required)
no native-app-platform
TARGET-GAMES-MEDIA Cross-target games and creative media runtime games-media games-media-cross-target L0 unsupported browser-game=L0 (browser; required)
desktop-game=L0 (host; required)
mobile-game=L0 (device; required)
no interactive-runtime
TARGET-DATA-ML Data science and local machine-learning platform data-ml data-ml-local L0 unsupported macos-arm64-cpu-gpu=L0 (host; required)
linux-x86-64-cpu-gpu=L0 (host; required)
no data-ml-platform
TARGET-EMBEDDED-LINUX Embedded Linux and Raspberry Pi-class application embedded-linux embedded-linux-arm64 L0 unsupported raspberry-pi-5=L0 (device; required)
linux-riscv64-sbc=L0 (device; optional)
no embedded-platform
TARGET-MCU-LANGUAGE-AOT Constrained MCU language profile and AOT backend microcontroller mcu-closed-world-aot L0 unsupported armv6m-thumb=L0 (runtime; required)
riscv32imc=L0 (runtime; required)
xtensa-esp32=L0 (runtime; required)
avr8=L0 (runtime; required)
no embedded-platform
TARGET-BOARD-HAL-FAMILIES Representative board and capability-safe HAL families microcontroller board-hal-families-v1 L0 unsupported rp2040-pico=L0 (board; required)
esp32-c3=L0 (board; required)
esp32-xtensa=L0 (board; required)
arduino-uno-r3=L0 (board; required)
no embedded-platform
TARGET-DEVICE-FLASH-DEBUG-OTA Device discovery, flashing, debugging, and OTA lifecycle device-lifecycle device-flash-debug-ota L0 unsupported rp2040-debug-probe=L0 (board; required)
esp32-secure-ota=L0 (board; required)
arduino-serial-bootloader=L0 (board; required)
no embedded-tooling
TARGET-HARDWARE-IN-THE-LOOP Physical hardware-in-the-loop qualification hardware-assurance hardware-in-the-loop-v1 L0 unsupported isolated-device-lab=L0 (lab; required)
board-simulator=L0 (simulator; required)
no embedded-assurance

Predicates and Evidence

TARGET-APPLICATION-UI: Cross-target application and UI architecture

  • Authentic artifact: The same state/update/view application executes accessible interactions and scoped effects in real browser, desktop, iOS, and Android runtimes.
  • One-language source: Deleting every generated platform root and rebuilding from .gc, Genesis manifests, policies, tests, and assets reproduces all target projects without foreign-source edits.
  • Related foundations, not inherited support: CAP-GRAPHICS-RUNTIME, CAP-RUNTIME-SURFACES, CAP-EFFECT-REPLAY
  • Current evidence: E1:target-application-ui/ledger-classification
  • Open gaps: R5.6.a, R5.6.b, R5.6.d, R5.6.f
  • Limitations: No normative cross-target application, presentation, accessibility, widget, or UI test contract exists; current graphics and browser operations are foundation plumbing only.

TARGET-WEB-STATIC: Static website output

  • Authentic artifact: The emitted directory serves standards-valid HTML, CSS, assets, routes, metadata, CSP and integrity data and passes real-browser navigation, accessibility, and offline checks.
  • One-language source: The deployable site is regenerated from GenesisCode views, routes, styles, tests, manifests, and assets with no authored HTML, CSS, JavaScript, Node configuration, or hosting YAML.
  • Related foundations, not inherited support: CAP-DEPLOYMENT-PIPELINE, CAP-BROWSER-XR, CAP-DOMAIN-STARTERS
  • Current evidence: E1:target-web-static/ledger-classification
  • Open gaps: R5.6.c, R6.5.a, R6.5.b, R6.5.c
  • Limitations: The current web target is a CoreForm package and synthetic launcher, not a deployable website, so aggregate deployment reachability grants no web support.

TARGET-WEB-INTERACTIVE-SSR-PWA: Interactive, SSR, and PWA web application

  • Authentic artifact: A real browser and SSR process execute routing, hydration, forms, workers, storage, WebSocket, offline service-worker, update, rollback, and scoped network effects under declared budgets.
  • One-language source: All client, server, style, route, worker, service-worker, schema, and deployment behavior is authored in GenesisCode inputs; generated HTML, CSS, JavaScript, and runtime configuration are disposable.
  • Related foundations, not inherited support: CAP-DEPLOYMENT-PIPELINE, CAP-BROWSER-XR, CAP-EFFECT-REPLAY, CAP-STAGE2-WASM-VALIDATION
  • Current evidence: E1:target-web-interactive/ledger-classification
  • Open gaps: R5.6.c, R5.6.e, R5.6.f, R6.5.a, R6.5.b, R6.5.c
  • Limitations: No web component/style/router/SSR/hydration/PWA compiler exists, and the current edge Wasm export performs no application work.

TARGET-SERVICE-DATA: Self-hosted service and data platform

  • Authentic artifact: A deployed process handles real protocol traffic, authentication, persistence, migrations, jobs, observability, backup, restore, graceful drain, update, rollback, and injected faults.
  • One-language source: Routes, middleware, schemas, queries, migrations, jobs, policies, observability, deployment, and tests are GenesisCode-owned inputs with no handwritten Python, shell, SQL migration, or YAML requirement.
  • Related foundations, not inherited support: CAP-DEPLOYMENT-PIPELINE, CAP-HOST-BRIDGE, CAP-PLUGIN-FFI, CAP-PACKAGE-MANAGER
  • Current evidence: E1:target-service-data/ledger-classification
  • Open gaps: R5.7.a, R5.7.b, R5.7.c, R5.7.d, R6.5.d
  • Limitations: Individual network and database effects exist, but there is no cohesive typed service, durable data, operations, or authentic service artifact platform.

TARGET-DESKTOP-MACOS: Installable macOS desktop application

  • Authentic artifact: A signed app package installs, launches a native window, performs accessible input and one scoped host effect, captures crashes, updates, rolls back, and uninstalls on macOS arm64.
  • One-language source: Application logic, lifecycle, UI, permissions, assets, tests, and packaging declarations are GenesisCode inputs; generated Xcode, plist, entitlement, and signing plans are never edited.
  • Related foundations, not inherited support: CAP-GRAPHICS-RUNTIME, CAP-DEPLOYMENT-PIPELINE, CAP-RUNTIME-SURFACES
  • Current evidence: E1:target-desktop-macos/ledger-classification
  • Open gaps: R5.6.d, R6.3.f, R6.3.g, R6.6.a, R6.6.c
  • Limitations: The desktop target emits a descriptor-style package and launcher rather than a signed native macOS application.

TARGET-DESKTOP-LINUX: Installable Linux desktop application

  • Authentic artifact: A native package installs, launches a real accessible window, performs one scoped host effect, records resource and crash evidence, updates, rolls back, and uninstalls on supported Linux hosts.
  • One-language source: Application, UI, desktop integration, assets, tests, and packaging are GenesisCode inputs; generated desktop files, unit manifests, and native adapters are disposable and unedited.
  • Related foundations, not inherited support: CAP-GRAPHICS-RUNTIME, CAP-DEPLOYMENT-PIPELINE, CAP-RUNTIME-SURFACES
  • Current evidence: E1:target-desktop-linux/ledger-classification
  • Open gaps: R5.6.d, R6.3.f, R6.3.g, R6.6.a, R6.6.c
  • Limitations: No installable Linux desktop runtime, package integration, lifecycle, accessibility, update, or interaction evidence exists.

TARGET-DESKTOP-WINDOWS: Installable Windows desktop application

  • Authentic artifact: A signed Windows package installs, launches a real accessible window, performs one scoped host effect, captures crashes, updates, rolls back, and uninstalls on Windows x86-64.
  • One-language source: Application, UI, Windows integration, assets, tests, installer, and signing declarations are GenesisCode inputs; generated project and installer sources are disposable and unedited.
  • Related foundations, not inherited support: CAP-GRAPHICS-RUNTIME, CAP-DEPLOYMENT-PIPELINE, CAP-RUNTIME-SURFACES
  • Current evidence: E1:target-desktop-windows/ledger-classification
  • Open gaps: R5.6.d, R6.3.f, R6.3.g, R6.6.a, R6.6.c
  • Limitations: No installable Windows desktop runtime, package integration, lifecycle, accessibility, update, or interaction evidence exists.

TARGET-IOS: Installable iOS application

  • Authentic artifact: A valid signed IPA containing executable Genesis application code installs and passes launch, lifecycle, accessibility, permission, storage, network, process-death, upgrade, and rollback workloads on simulator and device.
  • One-language source: The Xcode project, Swift/Objective-C adapters, plist, entitlements, resources, and signing plan regenerate from GenesisCode-owned application inputs and are never manually patched.
  • Related foundations, not inherited support: CAP-DEPLOYMENT-PIPELINE, CAP-RUNTIME-SURFACES, CAP-GRAPHICS-RUNTIME
  • Current evidence: E1:target-ios/ledger-classification
  • Open gaps: R5.6.d, R6.3.f, R6.3.g, R6.6.b, R6.6.c, R6.6.d
  • Limitations: The current IPA is a deterministic metadata/source archive without an executable app runtime and therefore provides no iOS product support.

TARGET-ANDROID: Installable Android application

  • Authentic artifact: A valid signed AAB/APK containing executable Genesis application code installs and passes launch, lifecycle, accessibility, permission, storage, network, process-death, upgrade, and rollback workloads on emulator and device.
  • One-language source: The Gradle project, Kotlin/Java adapters, XML resources, manifest, permissions, and signing plan regenerate from GenesisCode-owned application inputs and are never manually patched.
  • Related foundations, not inherited support: CAP-DEPLOYMENT-PIPELINE, CAP-RUNTIME-SURFACES, CAP-GRAPHICS-RUNTIME
  • Current evidence: E1:target-android/ledger-classification
  • Open gaps: R5.6.d, R6.3.f, R6.3.g, R6.6.b, R6.6.c, R6.6.d
  • Limitations: The current AAB declares android:hasCode=false and contains only metadata and Genesis source, so it provides no Android product support.

TARGET-GAMES-MEDIA: Cross-target games and creative media runtime

  • Authentic artifact: A nontrivial game or media tool runs real frame, audio, input, asset, save/replay, and device-loss workloads under declared frame-time, memory, startup, and artifact budgets on every required scope.
  • One-language source: Simulation, scenes, UI, shaders, audio, assets, networking, tooling, tests, and packaging are GenesisCode inputs; generated shaders and target adapters are disposable outputs.
  • Related foundations, not inherited support: CAP-GRAPHICS-RUNTIME, CAP-GPU-COMPUTE, CAP-BROWSER-XR, CAP-DEPLOYMENT-PIPELINE
  • Current evidence: E1:target-games-media/ledger-classification
  • Open gaps: R5.8.a, R5.8.b, R5.8.c, R5.8.d, R5.8.f, R8.2.m, R8.2.n
  • Limitations: Current graphics support is deterministic headless planning and resource codecs, not a production UI, game, shader, physics, asset, audio, or creative runtime.

TARGET-DATA-ML: Data science and local machine-learning platform

  • Authentic artifact: A reproducible dataset-to-analysis-or-model pipeline executes typed table/tensor/statistics workloads, checkpoints, evaluation, local inference, and resource accounting on CPU and a qualified GPU backend.
  • One-language source: Datasets, transforms, analyses, model pipelines, evaluation, services, UI, and tests are GenesisCode inputs with no Python notebook, Python package, or foreign orchestration script required.
  • Related foundations, not inherited support: CAP-GPU-COMPUTE, CAP-PACKAGE-MANAGER, CAP-EFFECT-REPLAY
  • Current evidence: E1:target-data-ml/ledger-classification
  • Open gaps: R5.7.e, R8.2.r
  • Limitations: GPU dispatch foundations exist, but typed arrays, tensors, dataframes, statistics, model adapters, datasets, and end-to-end local ML workflows are absent.

TARGET-EMBEDDED-LINUX: Embedded Linux and Raspberry Pi-class application

  • Authentic artifact: A reproducible image or package boots on the named board, runs a Genesis service or UI, accesses real GPIO/I2C/SPI/UART under policy, survives power/network loss, and updates and rolls back.
  • One-language source: Device application, service/UI, peripheral policy, system integration, deployment, tests, and update plan are GenesisCode inputs; generated units, udev, device-tree overlays, and scripts are unedited.
  • Related foundations, not inherited support: CAP-RUNTIME-SURFACES, CAP-DEPLOYMENT-PIPELINE, CAP-HOST-BRIDGE
  • Current evidence: E1:target-embedded-linux/ledger-classification
  • Open gaps: R5.9.a, R5.9.d, R6.7.a, R6.7.f, R8.2.o
  • Limitations: Linux arm64 is listed as a host tier but no Raspberry Pi image/package, peripheral capability, remote lifecycle, power-loss, or physical-device evidence exists.

TARGET-MCU-LANGUAGE-AOT: Constrained MCU language profile and AOT backend

  • Authentic artifact: Closed-world compilation emits linked firmware that boots and executes the normative embedded subset on every required architecture with validated semantics and measured flash, RAM, stack, timing, reset, and fault behavior.
  • One-language source: Firmware, static resource declarations, interrupts, tasks, peripherals, tests, startup intent, and memory policy are GenesisCode inputs; generated C/Rust, startup, vector, and linker sources are disposable.
  • Related foundations, not inherited support: CAP-COREFORM-IDENTITY, CAP-STAGE2-WASM-VALIDATION, CAP-RUNTIME-SURFACES
  • Current evidence: E1:target-mcu-aot/ledger-classification
  • Open gaps: R5.9.a, R5.9.b, R5.9.c, R5.9.f, R6.7.b, R8.2.p
  • Limitations: No no-OS language subset, static resource verifier, interrupt contract, MCU code generator, startup/linker pipeline, or semantic validation exists.

TARGET-BOARD-HAL-FAMILIES: Representative board and capability-safe HAL families

  • Authentic artifact: Signed BSP/HAL packages compile, flash, and exercise typed GPIO, timers, serial, and at least one bus or radio peripheral on each named physical board with pin-conflict and unavailable-peripheral negative tests.
  • One-language source: Board manifests, pin/peripheral ownership, firmware, tests, and resource policy are GenesisCode inputs; vendor bindings and register adapters are audited package internals rather than application source.
  • Related foundations, not inherited support: CAP-PACKAGE-MANAGER, CAP-EVIDENCE-GATED-PUBLISH, CAP-HOST-BRIDGE
  • Current evidence: E1:target-board-hal/ledger-classification
  • Open gaps: R5.9.d, R5.9.e, R6.7.c, R6.7.f, R8.2.q
  • Limitations: No board manifests, BSP/HAL registry, peripheral ownership checker, board conformance kit, or physical board implementation exists.

TARGET-DEVICE-FLASH-DEBUG-OTA: Device discovery, flashing, debugging, and OTA lifecycle

  • Authentic artifact: Genesis tooling discovers only authorized devices, flashes and verifies exact firmware, opens bounded serial/debug sessions, captures crashes, and performs interrupted-update recovery and signed rollback on supported boards.
  • One-language source: Flash, debug, provisioning, crash, OTA, rollback, and recovery intents are Genesis manifests and policies; users do not author shell scripts, OpenOCD files, vendor CLI wrappers, or updater code.
  • Related foundations, not inherited support: CAP-HOST-BRIDGE, CAP-DEPLOYMENT-PIPELINE, CAP-DENY-DEFAULT-POLICY
  • Current evidence: E1:target-device-lifecycle/ledger-classification
  • Open gaps: R6.7.d, R6.7.e, R6.7.f
  • Limitations: The repository has no Genesis device command, authorized discovery, flasher, debugger, provisioning, crash capture, OTA, rollback, or brick-recovery implementation.

TARGET-HARDWARE-IN-THE-LOOP: Physical hardware-in-the-loop qualification

  • Authentic artifact: Ordinary CI runs deterministic peripheral simulation while an isolated rig repeatedly flashes, power-cycles, measures, injects peripheral/network/power faults, and retains signed serial/debug/resource evidence from named boards.
  • One-language source: Device tests, digital twins, fault plans, expected traces, resource budgets, and qualification policy are GenesisCode inputs; lab-control internals remain isolated infrastructure rather than application authority.
  • Related foundations, not inherited support: CAP-ASSURANCE-PROFILES, CAP-TOOL-QUALIFICATION, CAP-HOST-BRIDGE
  • Current evidence: E1:target-hil/ledger-classification
  • Open gaps: R6.7.d, R6.7.f, R8.2.p, R8.2.q
  • Limitations: No board simulator contract, isolated physical rig, power/peripheral fault injection, timing/power measurement, or signed hardware witness exists.

Aggregate Claim Boundary

The following capability claims are aggregate foundations and cannot imply support for any row above:

  • CAP-RUNTIME-SURFACES
  • CAP-DOMAIN-STARTERS
  • CAP-GPU-COMPUTE
  • CAP-GRAPHICS-RUNTIME
  • CAP-BROWSER-XR
  • CAP-DEPLOYMENT-PIPELINE

Primary evidence paths:

  • ROADMAP.md
  • docs/spec/AGENT_AUTHORING_BUNDLE_v0.1.md
  • docs/spec/CAPABILITY_COVERAGE_AUDIT_v0.1.json
  • docs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.json
  • docs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.schema.json
  • docs/spec/PRODUCT_TARGET_MATRIX_v0.1.json
  • docs/spec/SEALS_DISPATCH_REPLAY.md
  • docs/spec/SELF_HOST_BOUNDARY.md
  • upgrade_plan.md

Interpretation

  • A path or gate mapping establishes traceability; it does not by itself raise maturity.
  • Mutable .genesis/perf/ reports are E0 local observations and cannot establish L5.
  • Overall maturity cannot exceed the weakest required tier-1 platform.
  • Selfhost levels describe semantic authority, not the existence of a .gc wrapper.
  • Aggregate foundation claims report shared plumbing only. They cannot authorize any product or target listed in the product/target matrix.
  • upgrade_plan.md is the active P0/P1 defect queue; ROADMAP.md contains strategic maturity gaps.