GenesisCode Feature Matrix (Audit Date: 2026-08-11)
Scope: capability maturity for AI-agent autonomy, semantic selfhost closure, and production runtime trust.
This is a generated status view, not release evidence. The canonical source is docs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.json. Product and deployment qualification is reported in this document’s generated product/target section and docs/spec/PRODUCT_TARGET_MATRIX_v0.1.json; foundation maturity never implies a child target.
Maturity legend: - L0 specified - L1 implemented/reachable - L2 verified on the named reference host - L3 reproducible on the supported host matrix - L4 product-proven under declared SLOs - L5 release-attested with immutable evidence
Selfhost legend: H0 routed, H1 GenesisCode implementation, H2 GenesisCode production authority, H3 reproducible bootstrap fixpoint, H4 independently conformant, N/A deliberately outside selfhost closure. Capability-row selfhost labels are non-authoritative traceability summaries. Exact per-decision status, including decisions below H0, is derived from docs/spec/SEMANTIC_OWNERSHIP_LEDGER_v0.1.json in docs/status/SELFHOST_AUTHORITY_v0.1.md.
Supported Host Scope
| Platform ID | Host | Tier |
|---|---|---|
macos-arm64 |
macOS arm64 | 1 |
linux-x86_64 |
Linux x86_64 | 1 |
linux-arm64 |
Linux arm64 | 2 |
windows-x86_64 |
Windows x86_64 | 2 |
Capability Maturity
| ID | Capability | Class | Overall | macOS arm64 | Linux x86_64 | Linux arm64 | Windows x86_64 | Selfhost | Owner |
|---|---|---|---|---|---|---|---|---|---|
CAP-KERNEL-DETERMINISM |
Pure deterministic kernel separated from effects | foundation | L1 | L1 | L1 | L0 | L0 | N/A | kernel-runtime |
CAP-COREFORM-IDENTITY |
Canonical CoreForm IR + stable content hash identity | foundation | L1 | L1 | L1 | L0 | L0 | H0 | coreform |
CAP-SEALED-PROTOCOL |
Sealed unforgeable UNHANDLED/EFFECT/ERROR protocol |
foundation | L1 | L1 | L1 | L0 | L0 | N/A | kernel-runtime |
CAP-DENY-DEFAULT-POLICY |
Deny-by-default capability policy runtime | foundation | L1 | L1 | L1 | L0 | L0 | H0 | effect-runtime |
CAP-EFFECT-REPLAY |
Deterministic effect logs + replay checker | foundation | L1 | L1 | L1 | L0 | L0 | H0 | effect-runtime |
CAP-SEMANTIC-VCS |
Built-in semantic VCS (commit/patch/refs/merge3) |
foundation | L1 | L1 | L1 | L0 | L0 | H0 | vcs-patches |
CAP-PACKAGE-MANAGER |
Built-in package/project manager (pkg/gcpm) |
foundation | L1 | L1 | L1 | L0 | L0 | H0 | package-registry |
CAP-ARTIFACT-GC |
Reachability-based artifact GC (refs + locks + pins) |
foundation | L1 | L1 | L1 | L0 | L0 | H0 | package-registry |
CAP-EVIDENCE-GATED-PUBLISH |
Obligation/evidence/attestation-gated publish + ref updates | foundation | L1 | L1 | L1 | L0 | L0 | H0 | obligations-registry |
CAP-RUNTIME-SURFACES |
Native + WASI + wasm-host runtime surfaces | aggregate foundation | L1 | L1 | L1 | L0 | L0 | H0 | runtime-platforms |
CAP-SELFHOST-FRONTEND |
Selfhost frontend default in production CLIs | foundation | L1 | L1 | L1 | L0 | L0 | H0 | selfhost-toolchain |
CAP-SELFHOST-CUTOVER |
Full selfhost cutover profile + readiness scorecard | foundation | L1 | L1 | L1 | L0 | L0 | H0 | selfhost-toolchain |
CAP-STRICT-NO-FALLBACK |
Strict no-production Rust semantic fallback guard | foundation | L1 | L1 | L1 | L0 | L0 | H0 | selfhost-toolchain |
CAP-AGENT-JSON-CONTRACTS |
CLI + GCPM JSON schema contracts for agent automation | foundation | L1 | L1 | L1 | L0 | L0 | H0 | agent-interface |
CAP-AGENT-SKILL-PACK |
Agent index + skill-pack conformance contracts | foundation | L1 | L1 | L1 | L0 | L0 | N/A | agent-authoring |
CAP-DOMAIN-STARTERS |
Domain starter registry for agent workflows | aggregate foundation | L1 | L1 | L1 | L0 | L0 | N/A | agent-authoring |
CAP-AGENT-WORKLOAD-PARITY |
Agent generative workload parity gates (native vs WASI) | foundation | L1 | L1 | L1 | L0 | L0 | N/A | agent-evaluation |
CAP-AGENT-WORKSPACE-PERF |
Large-workspace agent iteration perf lane | foundation | L1 | L1 | L1 | L0 | L0 | N/A | agent-evaluation |
CAP-CONCURRENCY-REPLAY |
Concurrency/task replay stress lane | foundation | L1 | L1 | L1 | L0 | L0 | H0 | effect-runtime |
CAP-GPU-COMPUTE |
GPU compute capability independent of graphics surface | aggregate foundation | L1 | L1 | L1 | L0 | L0 | N/A | graphics-compute |
CAP-GRAPHICS-RUNTIME |
Graphics/window/input/audio capability families | aggregate foundation | L1 | L1 | L1 | L0 | L0 | N/A | graphics-compute |
CAP-BROWSER-XR |
Browser + XR runtime families | aggregate foundation | L1 | L1 | L1 | L0 | L0 | N/A | runtime-platforms |
CAP-PLUGIN-FFI |
Host plugin + FFI schemas/contracts | foundation | L1 | L1 | L1 | L0 | L0 | H0 | effect-runtime |
CAP-HOST-BRIDGE |
First-party bridge for network/process/db/crypto/plugin/ffi | foundation | L1 | L1 | L1 | L0 | L0 | H0 | effect-runtime |
CAP-STAGE2-WASM-VALIDATION |
Stage2 CoreForm->WASM translation-validation | foundation | L1 | L1 | L1 | L0 | L0 | H0 | wasm-optimizer |
CAP-DEPLOYMENT-PIPELINE |
Deployment target pipeline in core toolchain | aggregate foundation | L1 | L1 | L1 | L0 | L0 | H0 | package-registry |
CAP-ASSURANCE-PROFILES |
Assurance profile packs + standards crosswalk | foundation | L1 | L1 | L1 | L0 | L0 | N/A | assurance |
CAP-TOOL-QUALIFICATION |
Tool qualification lineage + evidence closures | foundation | L1 | L1 | L1 | L0 | L0 | H0 | assurance |
CAP-MODULAR-BOUNDARIES |
AI-first modular decomposition + boundary guards | foundation | L1 | L1 | L1 | L0 | L0 | N/A | architecture |
Release Claim Eligibility
A capability is eligible for an unqualified v1 release claim only at L5 on every required tier-1 platform. Lower levels must be described with their platform and evidence limitations.
| ID | Capability | Overall | Tier-1 Maturity | Immutable Evidence | Eligible |
|---|---|---|---|---|---|
CAP-KERNEL-DETERMINISM |
Pure deterministic kernel separated from effects | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-COREFORM-IDENTITY |
Canonical CoreForm IR + stable content hash identity | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-SEALED-PROTOCOL |
Sealed unforgeable UNHANDLED/EFFECT/ERROR protocol |
L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-DENY-DEFAULT-POLICY |
Deny-by-default capability policy runtime | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-EFFECT-REPLAY |
Deterministic effect logs + replay checker | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-SEMANTIC-VCS |
Built-in semantic VCS (commit/patch/refs/merge3) |
L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-PACKAGE-MANAGER |
Built-in package/project manager (pkg/gcpm) |
L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-ARTIFACT-GC |
Reachability-based artifact GC (refs + locks + pins) |
L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-EVIDENCE-GATED-PUBLISH |
Obligation/evidence/attestation-gated publish + ref updates | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-RUNTIME-SURFACES |
Native + WASI + wasm-host runtime surfaces | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-SELFHOST-FRONTEND |
Selfhost frontend default in production CLIs | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-SELFHOST-CUTOVER |
Full selfhost cutover profile + readiness scorecard | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-STRICT-NO-FALLBACK |
Strict no-production Rust semantic fallback guard | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-AGENT-JSON-CONTRACTS |
CLI + GCPM JSON schema contracts for agent automation | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-AGENT-SKILL-PACK |
Agent index + skill-pack conformance contracts | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-DOMAIN-STARTERS |
Domain starter registry for agent workflows | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-AGENT-WORKLOAD-PARITY |
Agent generative workload parity gates (native vs WASI) | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-AGENT-WORKSPACE-PERF |
Large-workspace agent iteration perf lane | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-CONCURRENCY-REPLAY |
Concurrency/task replay stress lane | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-GPU-COMPUTE |
GPU compute capability independent of graphics surface | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-GRAPHICS-RUNTIME |
Graphics/window/input/audio capability families | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-BROWSER-XR |
Browser + XR runtime families | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-PLUGIN-FFI |
Host plugin + FFI schemas/contracts | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-HOST-BRIDGE |
First-party bridge for network/process/db/crypto/plugin/ffi | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-STAGE2-WASM-VALIDATION |
Stage2 CoreForm->WASM translation-validation | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-DEPLOYMENT-PIPELINE |
Deployment target pipeline in core toolchain | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-ASSURANCE-PROFILES |
Assurance profile packs + standards crosswalk | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-TOOL-QUALIFICATION |
Tool qualification lineage + evidence closures | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
CAP-MODULAR-BOUNDARIES |
AI-first modular decomposition + boundary guards | L1 | macOS arm64=L1, Linux x86_64=L1 | none | no |
Authorized unqualified claims: - None. No capability currently carries immutable L5 release evidence.
Known GenesisCode gaps
R1.3.c: Generate and verify the pinned MCP agent interface from canonical CLI schemas. Affected claims:CAP-AGENT-JSON-CONTRACTSR1.4.c: Build deterministic generation, repair, refactor, and deployment task benchmarks. Affected claims:CAP-AGENT-WORKLOAD-PARITYR1.5.a: Generate the authoring skill from canonical language and capability inputs. Affected claims:CAP-AGENT-SKILL-PACKR1.5.f: Validate skill distribution, offline use, token budgets, and multi-agent compatibility. Affected claims:CAP-AGENT-SKILL-PACKR2.3.e: Meet explicit incremental large-workspace agent-loop SLOs. Affected claims:CAP-AGENT-WORKSPACE-PERFR3.2.a: Audit existing stage2/Wasm coverage and eliminate undeclared fallback. Affected claims:CAP-RUNTIME-SURFACES,CAP-STAGE2-WASM-VALIDATIONR3.2.b: Validate source-to-Wasm translation and embedded artifact identity. Affected claims:CAP-STAGE2-WASM-VALIDATIONR4.1.c: Maintain a semantic-ownership ledger for every production decision. Affected claims:CAP-STRICT-NO-FALLBACKR4.1.e: Enforce selfhost and stage0 dependency boundaries structurally. Affected claims:CAP-STRICT-NO-FALLBACKR4.2.a: Make frontend and canonicalization GenesisCode-produced with independent identity verification. Affected claims:CAP-COREFORM-IDENTITY,CAP-SELFHOST-FRONTENDR4.2.c: Make semantic patch and refactor behavior GenesisCode-authoritative. Affected claims:CAP-SEMANTIC-VCSR4.2.d: Make obligation and policy decision logic GenesisCode-authoritative. Affected claims:CAP-DENY-DEFAULT-POLICY,CAP-EVIDENCE-GATED-PUBLISHR4.2.e: Make package, registry, and VCS logic GenesisCode-authoritative. Affected claims:CAP-SEMANTIC-VCS,CAP-PACKAGE-MANAGER,CAP-ARTIFACT-GCR4.2.g: Make CLI and agent orchestration selfhost-authoritative without hidden Rust semantics. Affected claims:CAP-SELFHOST-FRONTENDR4.3.a: Split oversized host crates and meet source concentration budgets. Affected claims:CAP-MODULAR-BOUNDARIESR4.3.b: Generate repetitive host, Prelude, capability, MCP, codec, and parity bindings from one schema. Affected claims:CAP-MODULAR-BOUNDARIESR4.4.c: Prove cross-host bootstrap fixpoint on the tier-1 host matrix. Affected claims:CAP-SELFHOST-CUTOVERR5.2.a: Audit and reconcile deterministic concurrency specifications and runtime behavior. Affected claims:CAP-CONCURRENCY-REPLAYR5.2.e: Differentially explore and replay bounded schedules across tiers and hosts. Affected claims:CAP-CONCURRENCY-REPLAYR5.5.a: Adopt and pin the WebAssembly Component Model/WIT extension boundary. Affected claims:CAP-PLUGIN-FFIR5.5.c: Sandbox extension memory, CPU, calls, effects, cancellation, and lifecycle. Affected claims:CAP-PLUGIN-FFIR6.1.a: Freeze and migrate deterministic package manifest and lock schemas. Affected claims:CAP-PACKAGE-MANAGERR6.2.d: Enforce package evidence policy at registry acceptance. Affected claims:CAP-EVIDENCE-GATED-PUBLISHR6.3.a: Define the supported v1 build target profiles. Affected claims:CAP-RUNTIME-SURFACESR6.3.b: Implement the selfhosted genesis build graph and evidence outputs. Affected claims:CAP-DEPLOYMENT-PIPELINER6.3.c: Make target artifacts reproducible across independent builders. Affected claims:CAP-DEPLOYMENT-PIPELINER7.1.a: Classify and own the complete layered verification suite. Affected claims:CAP-ASSURANCE-PROFILESR7.1.e: Use mutation testing to demonstrate trust-check sensitivity. Affected claims:CAP-TOOL-QUALIFICATIONR7.2.a: Mechanize the pure core semantics and determinism theorem. Affected claims:CAP-KERNEL-DETERMINISMR7.2.b: Prove seal unforgeability and protected-boundary behavior. Affected claims:CAP-SEALED-PROTOCOLR7.2.c: Model and prove deterministic complete effect dispatch and replay checking. Affected claims:CAP-EFFECT-REPLAYR7.2.f: Verify or independently cross-check canonical codec assumptions. Affected claims:CAP-COREFORM-IDENTITYR7.3.a: Threat-model every kernel, effect, bridge, package, build, and release boundary. Affected claims:CAP-DENY-DEFAULT-POLICY,CAP-ASSURANCE-PROFILESR7.3.b: Sandbox host execution with hard cancellation, least privilege, and bounded IPC. Affected claims:CAP-HOST-BRIDGER8.2.a: Prove the pure library and CLI agent archetype end to end. Affected claims:CAP-AGENT-WORKLOAD-PARITYR8.2.e: Prove the browser application agent archetype and its sandboxed effects. Affected claims:CAP-BROWSER-XRR8.2.h: Prove the GPU or numeric agent archetype with deterministic backend evidence. Affected claims:CAP-GPU-COMPUTER8.3.a: Ship and maintain at least five evidence-backed flagship programs. Affected claims:CAP-DOMAIN-STARTERS,CAP-GRAPHICS-RUNTIMER9.2.c: Publish and independently mirror immutable E4 release attestations. Affected claims:CAP-TOOL-QUALIFICATIONR5.6.a: Define the deterministic shared application architecture and lifecycle. Affected claims:TARGET-APPLICATION-UIR5.6.b: Build the typed presentation and style intermediate representation. Affected claims:TARGET-APPLICATION-UIR5.6.c: Implement the complete static, interactive, SSR, and PWA web product stack. Affected claims:TARGET-WEB-STATIC,TARGET-WEB-INTERACTIVE-SSR-PWAR5.6.d: Implement accessible cross-target widgets and input semantics. Affected claims:TARGET-APPLICATION-UI,TARGET-DESKTOP-MACOS,TARGET-DESKTOP-LINUX,TARGET-DESKTOP-WINDOWS,TARGET-IOS,TARGET-ANDROIDR5.6.e: Make UI rendering efficient, incremental, validated, and inspectable. Affected claims:TARGET-WEB-INTERACTIVE-SSR-PWAR5.6.f: Ship one product-grade cross-target UI testing API. Affected claims:TARGET-APPLICATION-UI,TARGET-WEB-INTERACTIVE-SSR-PWAR5.7.a: Complete typed service routing, middleware, security, and protocol construction. Affected claims:TARGET-SERVICE-DATAR5.7.b: Complete durable typed data, query, transaction, and migration APIs. Affected claims:TARGET-SERVICE-DATAR5.7.c: Add production queues, jobs, cache, storage, and coordination primitives. Affected claims:TARGET-SERVICE-DATAR5.7.d: Unify capability-scoped observability and operations. Affected claims:TARGET-SERVICE-DATAR5.7.e: Build first-party data, numeric, tensor, and local ML libraries. Affected claims:TARGET-DATA-MLR5.8.a: Define the deterministic game and simulation core. Affected claims:TARGET-GAMES-MEDIAR5.8.b: Complete real 2D and 3D runtime systems. Affected claims:TARGET-GAMES-MEDIAR5.8.c: Make shaders and the asset pipeline Genesis-authored. Affected claims:TARGET-GAMES-MEDIAR5.8.d: Add production audio and creative timeline systems. Affected claims:TARGET-GAMES-MEDIAR5.8.f: Ship Genesis-native game and media editing and debugging workflows. Affected claims:TARGET-GAMES-MEDIAR5.9.a: Define Embedded Linux and constrained MCU profiles separately. Affected claims:TARGET-EMBEDDED-LINUX,TARGET-MCU-LANGUAGE-AOTR5.9.b: Implement closed-world static flash, RAM, stack, timing, and resource verification. Affected claims:TARGET-MCU-LANGUAGE-AOTR5.9.c: Specify real-time, interrupt, reset, watchdog, and power semantics. Affected claims:TARGET-MCU-LANGUAGE-AOTR5.9.d: Define capability-safe typed board and peripheral HAL APIs. Affected claims:TARGET-EMBEDDED-LINUX,TARGET-BOARD-HAL-FAMILIESR5.9.e: Build self-hostable IoT and robotics packages. Affected claims:TARGET-BOARD-HAL-FAMILIESR5.9.f: Preserve and validate semantic identity across constrained compilation. Affected claims:TARGET-MCU-LANGUAGE-AOTR6.3.f: Require target-native executable entrypoints and authentic runtime workloads. Affected claims:TARGET-DESKTOP-MACOS,TARGET-DESKTOP-LINUX,TARGET-DESKTOP-WINDOWS,TARGET-IOS,TARGET-ANDROIDR6.3.g: Make all generated foreign glue disposable, reproducible, and non-authoritative. Affected claims:TARGET-DESKTOP-MACOS,TARGET-DESKTOP-LINUX,TARGET-DESKTOP-WINDOWS,TARGET-IOS,TARGET-ANDROIDR6.5.a: Ship the incremental Genesis web compiler and development server. Affected claims:TARGET-WEB-STATIC,TARGET-WEB-INTERACTIVE-SSR-PWAR6.5.b: Produce standards-valid deployable static, SSR, edge, and PWA artifacts. Affected claims:TARGET-WEB-STATIC,TARGET-WEB-INTERACTIVE-SSR-PWAR6.5.c: Prove supported behavior in real browser engines and mobile viewports. Affected claims:TARGET-WEB-STATIC,TARGET-WEB-INTERACTIVE-SSR-PWAR6.5.d: Ship and maintain a complete self-hosted full-stack reference product. Affected claims:TARGET-SERVICE-DATAR6.6.a: Build signed and installable real macOS, Windows, and Linux applications. Affected claims:TARGET-DESKTOP-MACOS,TARGET-DESKTOP-LINUX,TARGET-DESKTOP-WINDOWSR6.6.b: Build complete executable iOS and Android applications. Affected claims:TARGET-IOS,TARGET-ANDROIDR6.6.c: Automate simulator, emulator, and physical mobile and desktop qualification. Affected claims:TARGET-DESKTOP-MACOS,TARGET-DESKTOP-LINUX,TARGET-DESKTOP-WINDOWS,TARGET-IOS,TARGET-ANDROIDR6.6.d: Prove shared product reuse without hiding target-specific work. Affected claims:TARGET-IOS,TARGET-ANDROIDR6.7.a: Promote reproducible Raspberry Pi-class Embedded Linux delivery. Affected claims:TARGET-EMBEDDED-LINUXR6.7.b: Implement the closed-world MCU AOT, link, firmware, and evidence pipeline. Affected claims:TARGET-MCU-LANGUAGE-AOTR6.7.c: Establish qualified RP2040, RISC-V ESP32, Xtensa ESP32, and Arduino-compatible board families. Affected claims:TARGET-BOARD-HAL-FAMILIESR6.7.d: Build deterministic board simulation and physical hardware-in-the-loop infrastructure. Affected claims:TARGET-DEVICE-FLASH-DEBUG-OTA,TARGET-HARDWARE-IN-THE-LOOPR6.7.e: Complete authorized device discovery, flash, debug, provisioning, crash, and OTA lifecycle. Affected claims:TARGET-DEVICE-FLASH-DEBUG-OTAR6.7.f: Ship maintained Embedded Linux and physical MCU hardware products. Affected claims:TARGET-EMBEDDED-LINUX,TARGET-BOARD-HAL-FAMILIES,TARGET-DEVICE-FLASH-DEBUG-OTA,TARGET-HARDWARE-IN-THE-LOOPR8.2.m: Prove a nontrivial cross-target game under real frame and resource budgets. Affected claims:TARGET-GAMES-MEDIAR8.2.n: Prove a creative media tool with deterministic transforms and real preview/export. Affected claims:TARGET-GAMES-MEDIAR8.2.o: Prove a Raspberry Pi-class Embedded Linux product on real hardware. Affected claims:TARGET-EMBEDDED-LINUXR8.2.p: Prove RP2040 and ESP32-class constrained firmware on physical boards. Affected claims:TARGET-MCU-LANGUAGE-AOT,TARGET-HARDWARE-IN-THE-LOOPR8.2.q: Prove an end-to-end IoT or robotics system with hardware-in-the-loop. Affected claims:TARGET-BOARD-HAL-FAMILIES,TARGET-HARDWARE-IN-THE-LOOPR8.2.r: Prove a reproducible Genesis-native data science and local ML system. Affected claims:TARGET-DATA-ML- Active
upgrade_plan.mdP0/P1 defects: none. Roadmap maturity gaps above remain open and are not erased by an empty defect queue.
Product and Target Qualification
This matrix is the authority for product and target support. Foundation capability rows, host-operation reachability, archive suffixes, descriptors, empty exports, headless plans, synthetic launchers, and simulator-only runs do not raise a product target’s maturity.
Release states are mechanically tied to maturity: L0 unsupported, L1-L3 experimental, L4 candidate, and L5 qualified. Release eligibility additionally requires L5 on every required scope plus immutable E3/E4 evidence.
Qualification Summary
| ID | Product / target | Family | Profile | Overall | Release state | Scope maturity | Eligible | Owner |
|---|---|---|---|---|---|---|---|---|
TARGET-APPLICATION-UI |
Cross-target application and UI architecture | application-ui | application-ui-shared |
L0 | unsupported | browser-evergreen=L0 (browser; required)desktop-tier1=L0 (host; required)mobile-ios-android=L0 (device; required) |
no | application-platform |
TARGET-WEB-STATIC |
Static website output | web | web-static |
L0 | unsupported | standards-static-host=L0 (runtime; required)browser-evergreen=L0 (browser; required) |
no | web-platform |
TARGET-WEB-INTERACTIVE-SSR-PWA |
Interactive, SSR, and PWA web application | web | web-interactive-ssr-pwa |
L0 | unsupported | chromium-current=L0 (browser; required)firefox-current=L0 (browser; required)webkit-current=L0 (browser; required)linux-ssr-runtime=L0 (runtime; required) |
no | web-platform |
TARGET-SERVICE-DATA |
Self-hosted service and data platform | service-data | service-data-selfhosted |
L0 | unsupported | linux-x86-64-service=L0 (host; required)linux-arm64-service=L0 (host; required)wasi-component-service=L0 (runtime; optional) |
no | service-platform |
TARGET-DESKTOP-MACOS |
Installable macOS desktop application | desktop | desktop-macos-arm64 |
L0 | unsupported | macos-arm64=L0 (host; required) |
no | native-app-platform |
TARGET-DESKTOP-LINUX |
Installable Linux desktop application | desktop | desktop-linux |
L0 | unsupported | linux-x86-64=L0 (host; required)linux-arm64=L0 (host; optional) |
no | native-app-platform |
TARGET-DESKTOP-WINDOWS |
Installable Windows desktop application | desktop | desktop-windows-x86-64 |
L0 | unsupported | windows-x86-64=L0 (host; required) |
no | native-app-platform |
TARGET-IOS |
Installable iOS application | mobile | mobile-ios |
L0 | unsupported | ios-simulator-arm64=L0 (simulator; required)ios-device-arm64=L0 (device; required) |
no | native-app-platform |
TARGET-ANDROID |
Installable Android application | mobile | mobile-android |
L0 | unsupported | android-emulator-x86-64=L0 (simulator; required)android-device-arm64=L0 (device; required) |
no | native-app-platform |
TARGET-GAMES-MEDIA |
Cross-target games and creative media runtime | games-media | games-media-cross-target |
L0 | unsupported | browser-game=L0 (browser; required)desktop-game=L0 (host; required)mobile-game=L0 (device; required) |
no | interactive-runtime |
TARGET-DATA-ML |
Data science and local machine-learning platform | data-ml | data-ml-local |
L0 | unsupported | macos-arm64-cpu-gpu=L0 (host; required)linux-x86-64-cpu-gpu=L0 (host; required) |
no | data-ml-platform |
TARGET-EMBEDDED-LINUX |
Embedded Linux and Raspberry Pi-class application | embedded-linux | embedded-linux-arm64 |
L0 | unsupported | raspberry-pi-5=L0 (device; required)linux-riscv64-sbc=L0 (device; optional) |
no | embedded-platform |
TARGET-MCU-LANGUAGE-AOT |
Constrained MCU language profile and AOT backend | microcontroller | mcu-closed-world-aot |
L0 | unsupported | armv6m-thumb=L0 (runtime; required)riscv32imc=L0 (runtime; required)xtensa-esp32=L0 (runtime; required)avr8=L0 (runtime; required) |
no | embedded-platform |
TARGET-BOARD-HAL-FAMILIES |
Representative board and capability-safe HAL families | microcontroller | board-hal-families-v1 |
L0 | unsupported | rp2040-pico=L0 (board; required)esp32-c3=L0 (board; required)esp32-xtensa=L0 (board; required)arduino-uno-r3=L0 (board; required) |
no | embedded-platform |
TARGET-DEVICE-FLASH-DEBUG-OTA |
Device discovery, flashing, debugging, and OTA lifecycle | device-lifecycle | device-flash-debug-ota |
L0 | unsupported | rp2040-debug-probe=L0 (board; required)esp32-secure-ota=L0 (board; required)arduino-serial-bootloader=L0 (board; required) |
no | embedded-tooling |
TARGET-HARDWARE-IN-THE-LOOP |
Physical hardware-in-the-loop qualification | hardware-assurance | hardware-in-the-loop-v1 |
L0 | unsupported | isolated-device-lab=L0 (lab; required)board-simulator=L0 (simulator; required) |
no | embedded-assurance |
Predicates and Evidence
TARGET-APPLICATION-UI: Cross-target application and UI architecture
- Authentic artifact: The same state/update/view application executes accessible interactions and scoped effects in real browser, desktop, iOS, and Android runtimes.
- One-language source: Deleting every generated platform root and rebuilding from .gc, Genesis manifests, policies, tests, and assets reproduces all target projects without foreign-source edits.
- Related foundations, not inherited support:
CAP-GRAPHICS-RUNTIME,CAP-RUNTIME-SURFACES,CAP-EFFECT-REPLAY - Current evidence:
E1:target-application-ui/ledger-classification - Open gaps:
R5.6.a,R5.6.b,R5.6.d,R5.6.f - Limitations: No normative cross-target application, presentation, accessibility, widget, or UI test contract exists; current graphics and browser operations are foundation plumbing only.
TARGET-WEB-STATIC: Static website output
- Authentic artifact: The emitted directory serves standards-valid HTML, CSS, assets, routes, metadata, CSP and integrity data and passes real-browser navigation, accessibility, and offline checks.
- One-language source: The deployable site is regenerated from GenesisCode views, routes, styles, tests, manifests, and assets with no authored HTML, CSS, JavaScript, Node configuration, or hosting YAML.
- Related foundations, not inherited support:
CAP-DEPLOYMENT-PIPELINE,CAP-BROWSER-XR,CAP-DOMAIN-STARTERS - Current evidence:
E1:target-web-static/ledger-classification - Open gaps:
R5.6.c,R6.5.a,R6.5.b,R6.5.c - Limitations: The current web target is a CoreForm package and synthetic launcher, not a deployable website, so aggregate deployment reachability grants no web support.
TARGET-WEB-INTERACTIVE-SSR-PWA: Interactive, SSR, and PWA web application
- Authentic artifact: A real browser and SSR process execute routing, hydration, forms, workers, storage, WebSocket, offline service-worker, update, rollback, and scoped network effects under declared budgets.
- One-language source: All client, server, style, route, worker, service-worker, schema, and deployment behavior is authored in GenesisCode inputs; generated HTML, CSS, JavaScript, and runtime configuration are disposable.
- Related foundations, not inherited support:
CAP-DEPLOYMENT-PIPELINE,CAP-BROWSER-XR,CAP-EFFECT-REPLAY,CAP-STAGE2-WASM-VALIDATION - Current evidence:
E1:target-web-interactive/ledger-classification - Open gaps:
R5.6.c,R5.6.e,R5.6.f,R6.5.a,R6.5.b,R6.5.c - Limitations: No web component/style/router/SSR/hydration/PWA compiler exists, and the current edge Wasm export performs no application work.
TARGET-SERVICE-DATA: Self-hosted service and data platform
- Authentic artifact: A deployed process handles real protocol traffic, authentication, persistence, migrations, jobs, observability, backup, restore, graceful drain, update, rollback, and injected faults.
- One-language source: Routes, middleware, schemas, queries, migrations, jobs, policies, observability, deployment, and tests are GenesisCode-owned inputs with no handwritten Python, shell, SQL migration, or YAML requirement.
- Related foundations, not inherited support:
CAP-DEPLOYMENT-PIPELINE,CAP-HOST-BRIDGE,CAP-PLUGIN-FFI,CAP-PACKAGE-MANAGER - Current evidence:
E1:target-service-data/ledger-classification - Open gaps:
R5.7.a,R5.7.b,R5.7.c,R5.7.d,R6.5.d - Limitations: Individual network and database effects exist, but there is no cohesive typed service, durable data, operations, or authentic service artifact platform.
TARGET-DESKTOP-MACOS: Installable macOS desktop application
- Authentic artifact: A signed app package installs, launches a native window, performs accessible input and one scoped host effect, captures crashes, updates, rolls back, and uninstalls on macOS arm64.
- One-language source: Application logic, lifecycle, UI, permissions, assets, tests, and packaging declarations are GenesisCode inputs; generated Xcode, plist, entitlement, and signing plans are never edited.
- Related foundations, not inherited support:
CAP-GRAPHICS-RUNTIME,CAP-DEPLOYMENT-PIPELINE,CAP-RUNTIME-SURFACES - Current evidence:
E1:target-desktop-macos/ledger-classification - Open gaps:
R5.6.d,R6.3.f,R6.3.g,R6.6.a,R6.6.c - Limitations: The desktop target emits a descriptor-style package and launcher rather than a signed native macOS application.
TARGET-DESKTOP-LINUX: Installable Linux desktop application
- Authentic artifact: A native package installs, launches a real accessible window, performs one scoped host effect, records resource and crash evidence, updates, rolls back, and uninstalls on supported Linux hosts.
- One-language source: Application, UI, desktop integration, assets, tests, and packaging are GenesisCode inputs; generated desktop files, unit manifests, and native adapters are disposable and unedited.
- Related foundations, not inherited support:
CAP-GRAPHICS-RUNTIME,CAP-DEPLOYMENT-PIPELINE,CAP-RUNTIME-SURFACES - Current evidence:
E1:target-desktop-linux/ledger-classification - Open gaps:
R5.6.d,R6.3.f,R6.3.g,R6.6.a,R6.6.c - Limitations: No installable Linux desktop runtime, package integration, lifecycle, accessibility, update, or interaction evidence exists.
TARGET-DESKTOP-WINDOWS: Installable Windows desktop application
- Authentic artifact: A signed Windows package installs, launches a real accessible window, performs one scoped host effect, captures crashes, updates, rolls back, and uninstalls on Windows x86-64.
- One-language source: Application, UI, Windows integration, assets, tests, installer, and signing declarations are GenesisCode inputs; generated project and installer sources are disposable and unedited.
- Related foundations, not inherited support:
CAP-GRAPHICS-RUNTIME,CAP-DEPLOYMENT-PIPELINE,CAP-RUNTIME-SURFACES - Current evidence:
E1:target-desktop-windows/ledger-classification - Open gaps:
R5.6.d,R6.3.f,R6.3.g,R6.6.a,R6.6.c - Limitations: No installable Windows desktop runtime, package integration, lifecycle, accessibility, update, or interaction evidence exists.
TARGET-IOS: Installable iOS application
- Authentic artifact: A valid signed IPA containing executable Genesis application code installs and passes launch, lifecycle, accessibility, permission, storage, network, process-death, upgrade, and rollback workloads on simulator and device.
- One-language source: The Xcode project, Swift/Objective-C adapters, plist, entitlements, resources, and signing plan regenerate from GenesisCode-owned application inputs and are never manually patched.
- Related foundations, not inherited support:
CAP-DEPLOYMENT-PIPELINE,CAP-RUNTIME-SURFACES,CAP-GRAPHICS-RUNTIME - Current evidence:
E1:target-ios/ledger-classification - Open gaps:
R5.6.d,R6.3.f,R6.3.g,R6.6.b,R6.6.c,R6.6.d - Limitations: The current IPA is a deterministic metadata/source archive without an executable app runtime and therefore provides no iOS product support.
TARGET-ANDROID: Installable Android application
- Authentic artifact: A valid signed AAB/APK containing executable Genesis application code installs and passes launch, lifecycle, accessibility, permission, storage, network, process-death, upgrade, and rollback workloads on emulator and device.
- One-language source: The Gradle project, Kotlin/Java adapters, XML resources, manifest, permissions, and signing plan regenerate from GenesisCode-owned application inputs and are never manually patched.
- Related foundations, not inherited support:
CAP-DEPLOYMENT-PIPELINE,CAP-RUNTIME-SURFACES,CAP-GRAPHICS-RUNTIME - Current evidence:
E1:target-android/ledger-classification - Open gaps:
R5.6.d,R6.3.f,R6.3.g,R6.6.b,R6.6.c,R6.6.d - Limitations: The current AAB declares android:hasCode=false and contains only metadata and Genesis source, so it provides no Android product support.
TARGET-GAMES-MEDIA: Cross-target games and creative media runtime
- Authentic artifact: A nontrivial game or media tool runs real frame, audio, input, asset, save/replay, and device-loss workloads under declared frame-time, memory, startup, and artifact budgets on every required scope.
- One-language source: Simulation, scenes, UI, shaders, audio, assets, networking, tooling, tests, and packaging are GenesisCode inputs; generated shaders and target adapters are disposable outputs.
- Related foundations, not inherited support:
CAP-GRAPHICS-RUNTIME,CAP-GPU-COMPUTE,CAP-BROWSER-XR,CAP-DEPLOYMENT-PIPELINE - Current evidence:
E1:target-games-media/ledger-classification - Open gaps:
R5.8.a,R5.8.b,R5.8.c,R5.8.d,R5.8.f,R8.2.m,R8.2.n - Limitations: Current graphics support is deterministic headless planning and resource codecs, not a production UI, game, shader, physics, asset, audio, or creative runtime.
TARGET-DATA-ML: Data science and local machine-learning platform
- Authentic artifact: A reproducible dataset-to-analysis-or-model pipeline executes typed table/tensor/statistics workloads, checkpoints, evaluation, local inference, and resource accounting on CPU and a qualified GPU backend.
- One-language source: Datasets, transforms, analyses, model pipelines, evaluation, services, UI, and tests are GenesisCode inputs with no Python notebook, Python package, or foreign orchestration script required.
- Related foundations, not inherited support:
CAP-GPU-COMPUTE,CAP-PACKAGE-MANAGER,CAP-EFFECT-REPLAY - Current evidence:
E1:target-data-ml/ledger-classification - Open gaps:
R5.7.e,R8.2.r - Limitations: GPU dispatch foundations exist, but typed arrays, tensors, dataframes, statistics, model adapters, datasets, and end-to-end local ML workflows are absent.
TARGET-EMBEDDED-LINUX: Embedded Linux and Raspberry Pi-class application
- Authentic artifact: A reproducible image or package boots on the named board, runs a Genesis service or UI, accesses real GPIO/I2C/SPI/UART under policy, survives power/network loss, and updates and rolls back.
- One-language source: Device application, service/UI, peripheral policy, system integration, deployment, tests, and update plan are GenesisCode inputs; generated units, udev, device-tree overlays, and scripts are unedited.
- Related foundations, not inherited support:
CAP-RUNTIME-SURFACES,CAP-DEPLOYMENT-PIPELINE,CAP-HOST-BRIDGE - Current evidence:
E1:target-embedded-linux/ledger-classification - Open gaps:
R5.9.a,R5.9.d,R6.7.a,R6.7.f,R8.2.o - Limitations: Linux arm64 is listed as a host tier but no Raspberry Pi image/package, peripheral capability, remote lifecycle, power-loss, or physical-device evidence exists.
TARGET-MCU-LANGUAGE-AOT: Constrained MCU language profile and AOT backend
- Authentic artifact: Closed-world compilation emits linked firmware that boots and executes the normative embedded subset on every required architecture with validated semantics and measured flash, RAM, stack, timing, reset, and fault behavior.
- One-language source: Firmware, static resource declarations, interrupts, tasks, peripherals, tests, startup intent, and memory policy are GenesisCode inputs; generated C/Rust, startup, vector, and linker sources are disposable.
- Related foundations, not inherited support:
CAP-COREFORM-IDENTITY,CAP-STAGE2-WASM-VALIDATION,CAP-RUNTIME-SURFACES - Current evidence:
E1:target-mcu-aot/ledger-classification - Open gaps:
R5.9.a,R5.9.b,R5.9.c,R5.9.f,R6.7.b,R8.2.p - Limitations: No no-OS language subset, static resource verifier, interrupt contract, MCU code generator, startup/linker pipeline, or semantic validation exists.
TARGET-BOARD-HAL-FAMILIES: Representative board and capability-safe HAL families
- Authentic artifact: Signed BSP/HAL packages compile, flash, and exercise typed GPIO, timers, serial, and at least one bus or radio peripheral on each named physical board with pin-conflict and unavailable-peripheral negative tests.
- One-language source: Board manifests, pin/peripheral ownership, firmware, tests, and resource policy are GenesisCode inputs; vendor bindings and register adapters are audited package internals rather than application source.
- Related foundations, not inherited support:
CAP-PACKAGE-MANAGER,CAP-EVIDENCE-GATED-PUBLISH,CAP-HOST-BRIDGE - Current evidence:
E1:target-board-hal/ledger-classification - Open gaps:
R5.9.d,R5.9.e,R6.7.c,R6.7.f,R8.2.q - Limitations: No board manifests, BSP/HAL registry, peripheral ownership checker, board conformance kit, or physical board implementation exists.
TARGET-DEVICE-FLASH-DEBUG-OTA: Device discovery, flashing, debugging, and OTA lifecycle
- Authentic artifact: Genesis tooling discovers only authorized devices, flashes and verifies exact firmware, opens bounded serial/debug sessions, captures crashes, and performs interrupted-update recovery and signed rollback on supported boards.
- One-language source: Flash, debug, provisioning, crash, OTA, rollback, and recovery intents are Genesis manifests and policies; users do not author shell scripts, OpenOCD files, vendor CLI wrappers, or updater code.
- Related foundations, not inherited support:
CAP-HOST-BRIDGE,CAP-DEPLOYMENT-PIPELINE,CAP-DENY-DEFAULT-POLICY - Current evidence:
E1:target-device-lifecycle/ledger-classification - Open gaps:
R6.7.d,R6.7.e,R6.7.f - Limitations: The repository has no Genesis device command, authorized discovery, flasher, debugger, provisioning, crash capture, OTA, rollback, or brick-recovery implementation.
TARGET-HARDWARE-IN-THE-LOOP: Physical hardware-in-the-loop qualification
- Authentic artifact: Ordinary CI runs deterministic peripheral simulation while an isolated rig repeatedly flashes, power-cycles, measures, injects peripheral/network/power faults, and retains signed serial/debug/resource evidence from named boards.
- One-language source: Device tests, digital twins, fault plans, expected traces, resource budgets, and qualification policy are GenesisCode inputs; lab-control internals remain isolated infrastructure rather than application authority.
- Related foundations, not inherited support:
CAP-ASSURANCE-PROFILES,CAP-TOOL-QUALIFICATION,CAP-HOST-BRIDGE - Current evidence:
E1:target-hil/ledger-classification - Open gaps:
R6.7.d,R6.7.f,R8.2.p,R8.2.q - Limitations: No board simulator contract, isolated physical rig, power/peripheral fault injection, timing/power measurement, or signed hardware witness exists.
Aggregate Claim Boundary
The following capability claims are aggregate foundations and cannot imply support for any row above:
CAP-RUNTIME-SURFACESCAP-DOMAIN-STARTERSCAP-GPU-COMPUTECAP-GRAPHICS-RUNTIMECAP-BROWSER-XRCAP-DEPLOYMENT-PIPELINE
Primary evidence paths:
ROADMAP.mddocs/spec/AGENT_AUTHORING_BUNDLE_v0.1.mddocs/spec/CAPABILITY_COVERAGE_AUDIT_v0.1.jsondocs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.jsondocs/spec/CAPABILITY_EVIDENCE_LEDGER_v0.1.schema.jsondocs/spec/PRODUCT_TARGET_MATRIX_v0.1.jsondocs/spec/SEALS_DISPATCH_REPLAY.mddocs/spec/SELF_HOST_BOUNDARY.mdupgrade_plan.md
Interpretation
- A path or gate mapping establishes traceability; it does not by itself raise maturity.
- Mutable
.genesis/perf/reports are E0 local observations and cannot establish L5. - Overall maturity cannot exceed the weakest required tier-1 platform.
- Selfhost levels describe semantic authority, not the existence of a
.gcwrapper. - Aggregate foundation claims report shared plumbing only. They cannot authorize any product or target listed in the product/target matrix.
upgrade_plan.mdis the active P0/P1 defect queue;ROADMAP.mdcontains strategic maturity gaps.