-
Notifications
You must be signed in to change notification settings - Fork 0
Project Tracker
André Borchert edited this page Sep 18, 2026
·
436 revisions
Standard: Task table standard.
| ID | Task | Type | Area | Size | Status | Owner | Next step |
|---|---|---|---|---|---|---|---|
| B-133 | Keep a stolen task in the run queue of the CPU that owns it. | Bug | Scheduler | S | Open | here |
try_steal_from_cpu (kernel/sched/scheduler.c:346-381) sets assigned_cpu without moving the task out of its slot, so the stealing CPU's find_task_local never finds it; move the slot with the assignment — or search the queue by assignment — and assert a steal in the scheduler's own self-test. |
| C-02 | Keep network_stack.c state inside its module. |
Bug | Concurrency | S | Open | here | The socket map now returns a copy and no exported function returns a pointer into module state; add the test that dereferences a row after the guard is released and must fail, then re-run it under C-01's multi-core acceptance. |
| B-89 | Answer a CertificateRequest with a real client certificate when one is configured. | Improvement | WebTransport | S | Open | here | Send a CertificateVerify after the Certificate message; RFC 8446 section 4.4.2's empty Certificate is already what a client with no certificate sends and is conformant, so the change is only for a configured certificate. |
| OD-007 | Pin the official immutable Qwen 3.8 fixtures. | Investigation | Models | S | Open | here | Record the hashes and source revisions for the official Qwen 3.8 config, tokenizer, SafeTensors and parity corpus before any adapter work (B-143). |
| OD-010 | Define the opt-in approximate-mode contract. | Investigation | AI server | S | Open | here | Name the modes and define their quality reporting, telemetry and acceptance before any approximate mode ships. |
| B-85 | Encode and validate QUIC transport parameters instead of carrying them as opaque bytes. | Improvement | WebTransport | M | Open | here | Encode the client's own parameters and parse and check the server's against RFC 9000's rules; userspace/wt/ today requires only that the extension is present, so no flow-control limit, idle timeout or connection ID the peer set is known. |
| B-88 | Handle a HelloRetryRequest instead of refusing it by name. | Improvement | WebTransport | M | Open | here | Rewrite the transcript with the synthetic message_hash (RFC 8446 section 4.4.1), send a second ClientHello and refuse a second retry. |
| B-143 | Pin the immutable official Qwen config, tokenizer, SafeTensors and parity corpus. | Improvement | Models | M | Open | here | Record the hashes and source revisions for the official Qwen 3.8 package. |
| B-145 | Give the model package its own tokenizer. | Improvement | Models | M | Open | here | Make trusted tokenizer IDs match the package-owned tokenizer (B-144). |
| B-147 | Reach Python-reference parity for scalar embedding, RMSNorm and the first projection. | Improvement | Models | M | Open | here | Add the three scalar operators and diff every output against the Python reference. |
| B-150 | Make 32-step deterministic decode match the trusted continuation. | Improvement | Models | M | Open | here | Decode 32 steps and compare against the trusted continuation within the documented tolerance. |
| B-91 | Qualify the WebTransport module on RISC-V by running it, not just building it. | Investigation | WebTransport | M | Open | here | The module now compiles to RISC-V objects in compile-check's riscv64 userspace leg; close it with a booted guest that completes a handshake (make qemu-quic-handshake-gate, B-84). |
| B-139 | State the Qwen 3.8 support boundary and its completion gate. | Improvement | Models | M | Open | here | Pin an immutable official configuration before tokenizer, tensor, layer, prefill-logit, decode, session, backend and physical parity work (B-143). |
| B-140 | State the Kimi K3 text support boundary and its completion gate. | Improvement | Models | M | Open | here | Prove KDA/MLA/MoE/MXFP4/operator and target-token parity on a real checkpoint (B-155 to B-159). |
| B-141 | State the Kimi K3 multimodal support boundary and its completion gate. | Improvement | Models | M | Open | here | Stand up a separate official vision and multimodal golden acceptance (B-159). |
| B-84 | Drive a QUIC handshake from a socket inside the guest. | Improvement | WebTransport | L | Open | here | A guest opens a datagram socket, sends a real QUIC Initial, receives a ServerHello and completes a handshake; exit gate make qemu-quic-handshake-gate boots a guest that says so on the console. |
| B-86 | Build a QUIC connection runtime. | Improvement | WebTransport | L | Open | here | Add packet number spaces, CRYPTO stream reassembly, ACK and loss recovery, connection IDs, Retry and Version Negotiation; the TLS module is handed messages already reassembled and in order, and nothing does the reassembling today. |
| B-87 | Implement 0-RTT and the session-ticket store it needs. | Improvement | WebTransport | L | Open | here | Add the c e traffic and binder branches of the key schedule, a session-ticket store for the PSK and an early-data encryption level. |
| B-129 | Make the scheduler tick preempt a task on every architecture. | Improvement | Scheduler | L | Open | here | Each architecture fills the scheduler's frame from its own trap frame, calls the tick from its timer interrupt unless that CPU carries the network tick, and writes the frame back; RISC-V is landed and behaviourally tested, and x86-64 and AArch64 still name their missing half (B-132). |
| B-130 | Isolate mediated functions behind the RISC-V IOMMU. | Improvement | IOMMU | L | Open | here | Mediated functions share one identity-mapped table; give their buffers distinct mappings, prove one cannot reach another's memory, and repeat the proof on a second board; virtio-mmio stays unmediateable and is stated so in docs/RISCV-IOMMU.md. |
| B-132 | Make a user process a scheduled task on x86-64 and AArch64 too. | Improvement | Scheduler | L | Open | here | Port RISC-V's working dispatch to the other two ports, each with its own per-task kernel context (a per-task user_resume_rsp/TSS rsp0 record and floating-point area on x86-64, SP_EL1 loaded from the frame on AArch64), and settle the timer_mask_local() question. |
| E6 | Execute distributed work across the cluster data plane. | Improvement | Cluster | L | Open | here | Framing, sealing and peer state already cross a real network in make qemu-cluster-two-node-gate and -three-node-gate; the remaining piece is distributed execution, which waits on D-05. |
| D-05 | Run real local inference. | Improvement | AI server | L | Open | here | Prove real Qwen correctness, typed state, scheduling, cancellation, backpressure and metrics. |
| D-06 | Control an authenticated cluster across nodes. | Improvement | Cluster | L | Open | here | The QEMU-testable tranche is done (join, partition, recovery, ownership and quorum); the remaining piece is execution across nodes, which waits on D-05. |
| D-07 | Place and execute experts across the cluster. | Improvement | Cluster | L | Open | here | Hosted tests cover deterministic ownership, grouped routing, simulated node-loss rerouting and stable reduction; end-to-end distributed activation execution needs D-05 and D-06 first. |
| D-09 | Serve production inference. | Improvement | AI server | L | Open | here | Implement the authenticated API, streaming, cancellation, saturation, loss and long-lived tests. |
| B-144 | Stream SafeTensors, config and tokenizer imports. | Improvement | Models | L | Open | here | Reach bounded RSS and deterministic package output. |
| B-146 | Probe the official architecture and build an ordered, config-derived layer plan. | Improvement | Models | L | Open | here | Make unknown fields fail closed. |
| B-148 | Implement every configured operator through a complete layer. | Improvement | Models | L | Open | here | Cover attention, recurrent and convolution operators, position encoding, FFN, residual and norm/head, and gate on complete-layer and prefill-logit parity. |
| B-149 | Separate prefill and decode plans with real per-layer state. | Improvement | Models | L | Open | here | Prove state and reload continuity. |
| B-152 | Run a real model plan in a native, model-executing macOS process, with optional Metal. | Improvement | Models | L | Open | here | Run a real model plan end to end while CPU fallback remains authoritative. |
| B-154 | Add typed paged state, prefix COW, ragged batching and exact speculation. | Improvement | Models | L | Open | here | Make target-only and speculative deterministic outputs match. |
| B-155 | Build a separate kimi_k3 adapter from the immutable official config. |
Improvement | Models | L | Open | here | Make config and tensor roles reject unsupported fields. |
| B-156 | Implement K3's KDA, gated MLA, AttnRes, exact top-16 routing, shared experts, SiTU and MXFP4. | Improvement | Models | L | Open | here | Prove scalar operator, router and expert parity. |
| B-157 | Make K3 expert shards independently addressable with async residency and prefetch. | Improvement | Models | L | Open | here | Keep authoritative routing unchanged by prediction. |
| B-159 | Implement the K3 MoonViT-V2 multimodal pipeline. | Improvement | Models | L | Open | here | Cover separate golden image and text cases. |
| B-166 | Support Qwen 3.8. | Improvement | Models | L | Open | here | Roadmap target whose acceptance criteria are B-143 to B-154; work starts at B-143. |
| B-167 | Support Kimi K3 text. | Improvement | Models | L | Open | here | Interface only today; the acceptance criteria are B-155 to B-159, starting at B-155. |
| B-168 | Support Kimi K3 multimodal. | Improvement | Models | L | Open | here | Roadmap only; it needs a separate golden image and text suite (B-159). |
| V-06 | Capture the Virtualization.framework graphical console. | Improvement | Hypervisor | S | Blocked | operator | The display device is claimed and make vz-framebuffer-gate captures it through ScreenCaptureKit; grant Screen Recording permission to the terminal that runs the gate, then collect the evidence. |
| P-05 | Provide physical Apple NEON evidence. | Investigation | Hardware | S | Blocked | operator | Run the NEON canary on physical Apple silicon; QEMU cannot satisfy this physical gate. |
| B-142 | Verify the DeepSeek V4 Flash 0731 source before architecture work. | Improvement | Models | S | Blocked | maintainer | An authoritative, maintainer-approved immutable official source must exist before any architecture work (B-160). |
| B-160 | Verify the DeepSeek V4 Flash 0731 official source. | Improvement | Models | S | Blocked | maintainer | Record the maintainer-approved immutable official source; B-142 and B-169 wait on it. |
| OD-005 | Define SSH fleet limits, identity, audit retention, lockout and recovery. | Investigation | Network | S | Blocked | operator | Required before production SSH exposure; the operator must set the policy. |
| OD-008 | Pin the official Kimi and DeepSeek sources. | Investigation | Models | S | Blocked | upstream | Required before the corresponding adapters; the exact DeepSeek label is unresolved upstream. |
| V-02 | Deliver MSI-X for virtio on PCI. | Improvement | Hypervisor | M | Blocked | operator | Every PCI virtio device receives a distinct vector through QEMU's translation service and three defects are fixed; the remaining evidence is physical ARM PCIe, and Virtualization.framework has no ITS so its queues stay polled. |
| V-03 | Make the guest's IPv6 globally routable. | Improvement | Network | M | Blocked | upstream | Apple issues com.apple.vm.networking only with a provisioning profile and ad-hoc signing cannot provide it; with the entitlement a bridged Fusion guest autoconfigures a routable address (F-03). |
| V-04 | Qualify multiple vCPUs. | Investigation | Hypervisor | M | Blocked | operator | Boots come up 1/1, 4/4 and 8/8 with byte-identical smptest signatures across ten runs, and make vz-gate requires 4/4; the host has eight cores against a 128-256 core target and the platform offers no interrupt-affinity control. |
| C-01 | Hold shared kernel state correct under genuine parallelism. | Bug | Concurrency | M | Blocked | operator | The network stack, service records and CPU-AI runtime now take reentrant guards, the resolver shares the network guard and the pointer-holding counters became atomics; the remaining evidence is a sustained multi-core run on a machine with more cores than this one. |
| D1 | Prove the USB image on every architecture. | Investigation | Hardware | M | Blocked | operator |
make release-image-gate boots each shipped image as a disk across five environments and the installed-disk gate boots the partition layout twice, but write-usb.sh has never been run against a real device; write a stick per architecture and boot it. |
| D2 | Network-boot a blank machine and let it install itself. | Investigation | Network | M | Blocked | operator |
make qemu-netboot-gate runs DHCP/TFTP, a loader-only medium, an install onto a blank disk and a standalone boot to SSH; the remaining evidence is the same sequence on physical hardware. |
| D3 | Ship ready-to-run images per environment. | Investigation | Release | M | Blocked | operator |
make vm-package-gate boots all five VM kits out of their archives and make boot-media-gate boots all three shipped netboot binaries; the remaining evidence is physical media (D1). |
| E1 | Install XAIOS onto a blank disk from a running XAIOS. | Improvement | Storage | M | Blocked | operator | The installer partitions, formats the EFI System Partition and copies loader, kernel, initfs and entropy seed across, and make qemu-installed-disk-gate boots the result; the remaining run is on physical media (D1). |
| E3 | Prove NUMA placement on both nodes. | Investigation | NUMA | M | Blocked | operator | The self-test now asserts placement inside node 1's range and exactly one node per CPU through both lookups, held by make qemu-x86_64-numa-gate across two- and four-node machines; the remaining evidence is physical NUMA hardware. |
| E4 | Qualify multiqueue and RSS networking. | Improvement | Network | M | Blocked | operator | Per-queue state and round-robin polling are in, RSS is negotiated from the device's own config and make qemu-rss-steering-gate measures four pairs spreading [64, 62, 66, 64] against a one-bucket control; the gate needs Linux, root and a multiqueue tap, so it runs on the Intel host only, and virtio-mmio multiqueue is unexercised. |
| E5 | Take xaibootFS and xaiFS to scale. | Improvement | Storage | M | Blocked | operator | xaibootFS v6 records a file as extents, lifting a volume to 1 GiB and 1024 nodes, and the write path deliberately refuses above 256 KiB until it streams; the remaining evidence is scale on physical storage. |
| E7 | Measure storage throughput, caching and power-loss durability. | Investigation | Storage | M | Blocked | operator | Raising buffer_size to a mebibyte and reading each byte once changed the throughput by orders of magnitude, and make qemu-power-loss-gate replays QEMU's blklogwrites journal; the remaining evidence is physical storage, because emulator figures are not throughput evidence. |
| P-07 | Provide the SVE/SVE2 backend's physical evidence. | Improvement | SIMD | M | Blocked | operator |
make qemu-aarch64-sve2-gate executes the SVE2 canary and preserves per-task Z/P/FFR across scheduling and interrupts, and the packed SVE GEMV kernel is verified against the scalar reference; the remaining evidence is physical Apple silicon, since nothing here is performance evidence. |
| P-14 | Provide physical Intel/Xeon evidence. | Investigation | Hardware | M | Blocked | operator | Physical firmware, ISA, NUMA, storage, network, thermal and sustained-load gates remain and need the machines chosen by OD-002 and OD-003. |
| S-11P | Qualify physical production NVMe. | Investigation | Storage | M | Blocked | operator |
make qemu-qualification-readiness consolidates the QEMU NVMe and crash-recovery evidence; named physical devices must still pass queue scaling, interrupt affinity, FUA/flush/discard semantics, reset recovery, power-loss durability, sustained-load and performance gates. |
| S-12 | Establish the production xaiFS trust root and signing-key custody. | Investigation | Storage | M | Blocked | operator | Offline trusted-replica payload repair is implemented and QEMU/hosted-tested; production trust-root enrollment, private-key custody, replica authorization and rotation decisions need named operators and deployment credentials. |
| N-F3P | Qualify SSH and network security on physical hardware. | Investigation | Network | M | Blocked | operator |
make qemu-qualification-readiness consolidates the QEMU evidence; physical lossy-link, sustained-load, side-channel analysis and independent SSH/cryptography review remain open. |
| D-08 | Produce benchmark and diagnostic evidence on real machines. | Investigation | AI server | M | Blocked | operator | QEMU benchmark telemetry and a hashed qualification-readiness report exist; physical metadata-rich NUMA, bandwidth, PMU, thermal, storage, network and redacted support-bundle evidence remain. |
| D-10 | Qualify and clean up support. | Investigation | AI server | M | Blocked | operator | Documentation contracts and the consolidated make qemu-qualification-readiness gate exist; physical, model, cluster, thermal, PMU and durability qualifications remain. |
| B-163 | Enforce SRAT/SLIT/HMAT placement policy and local/remote byte telemetry. | Improvement | NUMA | M | Blocked | operator | The two-node x86_64 QEMU gate validates SRAT/SLIT/HMAT parsing, usable-memory intersection, deterministic preferred-node policy, node-local allocation and local/remote byte accounting; physical locality and performance qualification remain. |
| B-164 | Make NUMA/machine expert ownership stable and failure-aware. | Improvement | Cluster | M | Blocked | operator | Hosted tests validate deterministic owner selection, grouping, simulated owner failure and stable reduction; real NUMA/machine transport, remote activation execution and multi-QEMU exactness remain. |
| B-169 | Support DeepSeek V4 Flash 0731. | Improvement | Models | M | Blocked | maintainer | Roadmap only; it waits on an official immutable source being verified (B-160 and B-161). |
| OD-001 | Select the first physical Apple/ARM target and its firmware/storage/NIC boundary. | Investigation | Hardware | M | Blocked | operator | The operator must choose the machine before physical ARM support can be claimed (D4). |
| OD-002 | Select the representative AVX2 Intel desktop and hybrid-core/device baseline. | Investigation | Hardware | M | Blocked | operator | The operator must choose the machine before Intel desktop support can be claimed (P-14). |
| OD-003 | Select the Xeon generation, sockets/NUMA, memory, NIC and NVMe. | Investigation | Hardware | M | Blocked | operator | The operator must choose the machine before Xeon support can be claimed (P-14). |
| OD-004 | Provision the production update and xaiFS trust roots. | Investigation | Storage | M | Blocked | operator | Rotation, revocation, offline recovery and interrupted-activation rollback are implemented; private operator keys and defined custody and authorization procedures are required before untrusted deployment. |
| OD-006 | Define the supported NVMe/FUA/flush/discard/repair/power-loss contract. | Investigation | Storage | M | Blocked | operator | Required before physical persistent deployment (S-11P). |
| OD-009 | Select the expert-parallel interconnect and failure/ownership model. | Investigation | Cluster | M | Blocked | operator | Required before cluster inference (D-06 and D-07). |
| D4 | Qualify physical Apple/ARM, Intel desktop and Xeon machines. | Investigation | Hardware | L | Blocked | operator | Named hardware must pass firmware, device, durability, security and ISA-static gates; the machines are chosen by OD-001, OD-002 and OD-003 and no physical result is being waited on to close another row. |
| B-151 | Add physical AVX2 and tiled prefill/verification kernels. | Improvement | Models | L | Blocked | operator | Produce physical differential and performance artifacts on the chosen Intel machine. |
| B-153 | Add AVX-512/VNNI/AMX, SVE/SVE2, persistent worker gangs and NUMA autotuning. | Improvement | Models | L | Blocked | operator | Produce capability canaries, a scalar differential and physical evidence on the chosen machines. |
| B-158 | Run a real K3 text checkpoint. | Improvement | Models | L | Blocked | operator | Pass the tokenizer, operator, router, target-token and production-width physical gates. |
| B-161 | Build the DeepSeek adapter and parity suite. | Improvement | Models | L | Blocked | maintainer | Depends on the verified source (B-160). |
| B-162 | Support multi-terabyte sparse allocations and large pages. | Improvement | Models | L | Blocked | operator | Hosted packages represent sparse offsets above 100 GiB and both QEMU targets cover 2 MiB mappings, with x86_64 covering a 1 GiB leaf plus targeted SMP TLB invalidation; physical capacity and performance qualification remain. |
| B-165 | Dispatch real inference to AI Cells and secondary CPUs. | Improvement | Models | L | Blocked | operator | Real model work must execute on leased workers. |
| F-06 | Cover Fusion releases beyond 26H1. | Investigation | Hypervisor | M | Parked | operator | Parked: revive when a Fusion release other than 26H1, an x86_64 guest or physical Apple hardware has to be carried as a compatibility claim; nothing external blocks it. |
XAIOS is a freestanding Unix-like operating system. QEMU and VMware results are correctness evidence, not physical performance or production certification.