Governed Capability Portfolio Roadmap
Status: canonical roadmap adoption authority and capability delivery standard.
This document governs how AncientOS capability work enters and leaves the active portfolio. The master portfolio view is the operator-facing summary. The Architecture and Capability Posture Taxonomy defines lifecycle and posture vocabulary.
AncientOS completed its numbered-era sequence through Era 8. No numbered era is active and Era 9 is not adopted. A capability appears here as a candidate only for analysis; it becomes authoritative work only after an explicit operator adoption decision is recorded.
Portfolio lifecycle
The canonical lifecycle states are:
candidate: identified option, not authorized work;proposed: complete adoption packet awaiting operator decision;adopted: explicitly selected for implementation, not yet started;in_progress: adopted implementation has begun;blocked: adopted work cannot progress for named reasons;complete: acceptance criteria and required validation are satisfied;deferred: intentionally inactive until stated conditions change;rejected: explicitly declined; reconsideration needs a new proposal;historical: retained provenance outside the current portfolio.
Portfolio state is not implementation readiness, runtime health, or execution authority. Those remain independent dimensions in the canonical taxonomy.
Current portfolio
| Lifecycle state | Items |
|---|---|
proposed |
None |
adopted |
Keeper exact-task completion lifecycle consolidation |
in_progress |
None |
blocked |
None |
complete |
Broad capability-backed read-only cognition (bounded source coverage; see C1) |
candidate |
qBittorrent pause/resume; read-only service diagnostics; the optional and prerequisite-bound inference follow-ons enumerated in the completed inference section |
deferred |
governed experiential confidence/reinforcement; container restart; Compose deploy/recreate; Git update; package/system update; broad delete; general scheduler; autonomous remediation; general shell executor; the routing, monitoring, persistent-default, and model-lifecycle inference items enumerated in the completed inference section |
Candidate order is not priority. No candidate is an implied next capability.
Program sequence — 2026-09-07
Reconciled against clean main at d914f2a, the September 7 Media milestone,
recent implementation reports, runtime composition, current source and deployed
surfaces. This is the current program view inside the existing adoption authority,
not a second backlog or a new governance system. Recommendations do not silently
adopt work. The exact-task Keeper adoption remains valid.
Recommended next objective: Keeper exact-task completion lifecycle consolidation.
NOW — foundational convergence
- Broad compositional read-only cognition (C1, complete): the shared runtime discovers principal-authorized Rubick operation contracts, executes a finite observational batch, and preserves Oracle source provenance and uncertainty in Kernel Records. Plex inventory no longer requires generic inference. Registered sources span media, notifications, governance, work, runtime and project state. Optional model interpretation remains dependent on inference availability; individual peer diagnostics and live device control readiness are not implied. See the implemented architecture for effect policy, authorization, bounds and deployed-surface limitations. Completion does not grant authority to execute recommendations.
- Program truth (C2): this reconciliation repairs the stale Media lifecycle, missing Keeper adoption in runtime metadata and obsolete next-step state. Observational roadmap ownership no longer requires a progression word: current state questions resolved to AncientOS also reach Oracle evidence. Maintain canonical-document/runtime agreement; evidence reconciliation is a release obligation, not an autonomous backlog writer. Runtime synthesis now consumes the canonical recommended objective without granting adoption.
- Security and validation hygiene (S1, V1): close authenticated chat's missing session-bound CSRF check and repair report-archive test discovery. Preserve existing Lich/identity authority. Finish deterministic test-fixture hygiene where baseline failures demonstrate it is necessary.
NEXT — bounded convergence after NOW
- C3: Keeper exact-task completion, already adopted: reuse durable exact-action proposal/approval/evidence/receipt primitives and test restart/uncertainty. Existing conversational task completion is not proof of the adopted canonical lifecycle. No new task backend, bulk completion or task mutation is implied.
- C4: Lich presentation parity: connect existing controls and simple scoped confirmation to normal proposal rendering, hide opaque identifiers by default, preserve exact binding and high-risk recent-authentication requirements.
- C5: observer/delivery host independence: move only the existing typed pulse hosting contract out of Discord when separately scoped; use shared Io and outcome-return primitives. Do not create a workflow engine or a second outbox.
- A1: cold-device playback truth: distinguish command dispatch, app/profile barrier and observed playback. Never report “playing” solely from dispatch. This can be a narrow App fix alongside Core convergence, not a reopened Media program or authorization to actuate a room during maintenance.
PRODUCT TRACKS
- Rotes (P1): design corpus ingested; documentation reconciliation complete.
The source authority inventory preserves the
Conceptual Specification Draft 1, Ontology and Effect Semantics Draft 1, and
the authoritative reconstructed collectibility/curation/provenance addendum,
plus supplied architecture context. The addendum records its replacement
adoption and is not a verbatim recovery of the unavailable original.
The reconciliation and decision ledger
separates settled intent, recommendations, unresolved choices and direct
implementation evidence. Universal semantics fit Core conceptual architecture;
Apps may specialize domain cognition without redefining them. Chen remains
Core. The first bounded informational exchange
is implemented in
79dc3628b5e1627c7e9aec29bc6f903c9c1b6ca7; the historical map's implementation and retrieval absences no longer describe current state. Project-corpus reads and narrow establishment have deployed evidence, without claiming complete broad planning. Next recommended Rote slice: governed read-only inspection of one received informational Rote with provenance and restrictions. Global discovery and effectful forms remain deferred. This recommendation does not grant implementation authority or displace the separately adopted Keeper slice. - Apps (P2): Media Manager, Home Automation, Naga Siren, X Feed, Meeting Intelligence and the read-only Prophet boundary retain independent domain ownership. Prioritize an explicit operator outcome per App; do not make all Apps prerequisites for Core or Rotes. No speculative Android product is implied.
ARCHITECTURE / MIGRATION
- M1: identity and repository migration: AncientOS is the system; Luna is the
configurable interface. Preserve
discord-luna, module names, Compose service identities, environment aliases, URLs, bind paths and data locations where they have consumers. First inventory consumer contracts and backups/restore; then separately approve remote rename, checkout relocation, compatibility changes and deployment validation. No blind global rename or storage move. - M2: Core/App extraction: retain Chen, runtime, routing, governance, Keeper, Rubick, Oracle, LifeVault and shared observation/return contracts in Core. Extract App-owned policy/adapters only after consumer and state boundaries are proven. Reconcile Naga's two histories and deployed availability before moving it. Existing X Feed/ops histories should be preserved. A container, integration or hero name alone does not justify a repository.
- M3: legacy reliability seams: database migration exception visibility, old Keeper stores/audit references, provider launch parity and duplicate host mount authority need isolated contracts and validation before deletion.
BOUNDED FOLLOW-UPS — reconciled recovered register
“Open” means current evidence supports the issue, not permission to execute. “Verify” means historical evidence is insufficient to claim current closure. Owner is Core, App, ops or integration; priority follows the sequence above.
| ID | Item and disposition | Type / owner | Evidence, dependency and completion boundary |
|---|---|---|---|
| C1 | Complete: bounded compositional inquiry ownership | Architecture/correctness / Core | runtime/compositional_inspection.py, Rubick reviewed operations and Oracle composition; multiple authorized sources precede generic fallback. Optional synthesis can be unavailable without erasing observations. |
| C2 | Reconciled: roadmap lifecycle/next objective | Correctness / Core | architecture/roadmap_state.py and this document now agree; contradiction still fails closed. Does not automatically reconcile all external project state. |
| C3 | Open: exact-task completion | Adopted capability / Core Keeper | 2026-08-25 adoption; current keeper/execution.py completion lane is not the durable adopted contract. Depends on stable platform, benefits from C4. |
| C4 | Open: Lich normal presentation | UX / Core + transports | Web Inbox, Discord LichApprovalActionView, scoped confirmation already exist; runtime/pipeline.py still renders opaque approval commands. Keep policy reauthentication. |
| C5 | Open: observer host independence | Architecture / Core wiring | bot.py hosts Clockwerk/Io/Chen pulses; shared io_tethers.py exists. Decouple hosting, not domain policy or approval. |
| C6 | Open: asynchronous Web/Terminal conversational return | Integration / Core transports | notifications/web_push.py shared outcome-return methods; durable rows and Push shared, Web polling is not proactive conversation delivery. Depends on C5 only for liveness, not a new store. |
| C7 | Open: Web conversation scoping | Correctness / Core transport | Shared Web channel and authenticated principal are distinct concepts; define browser/conversation continuity before widening delivery. |
| S1 | Repaired: authenticated chat CSRF omission | Security / Web ingress | Chat now checks existing session-bound header before runtime; Lich/settings already checked it. Anonymous read-only requests remain unprivileged. |
| S2 | Open: high-risk Web reauthentication ceremony | Security UX / Core identity | Existing separate-secret endpoint and recent-auth checks; do not weaken to ordinary yes/no. Need threat-model and browser acceptance, not a second approval system. |
| S3 | Open: preference-write telemetry | Observability / Core | Name preferences can persist while generic metadata says mutation_occurred=false; distinguish preference persistence from operational mutation without granting authority. |
| S4 | Resolved in Media: canonical Web principal mismatch | Correctness / Core/App seam | 62fb131, chen_media_watch_loop tests; invalid/revoked/mismatched contexts still refuse. Do not generalize this to every legacy path. |
| V1 | Repaired: pytest report-archive collection | Validation infrastructure | pytest.ini excludes disposable report copies only; app/services/tests remain discoverable. Reports are evidence, not executable suite inputs. |
| V2 | Repaired: date-sensitive dormancy tests | Test infrastructure / Core tests | September reports name two fixed-date fixtures. Use controlled evaluation time; do not alter production aging policy. |
| V3 | Repaired: repository byte-budget fixture | Test infrastructure / Core tests | Old assertion depends on growing live source contents; use fixed temporary source. Preserve production budget and chunk contract. |
| A1 | Open: cold Apple TV/profile barrier and truthful outcome | Bug / Media + device integration | Operator observed profile screen despite “playing” notification; awake/profile-selected Plex works. Require observed session or explicit unverified/intervention result. |
| Source inspection also found a concrete weak assumption: Earthshaker accepts a | |||
| matching Plex session with missing player state as playing. This is a bounded | |||
| follow-up lead, not proof of the cause of the reported cold-device event. | |||
| A2 | Open: exact-episode playback rating key | Bug / Media | media_manager/governed_watch.py uses show-level lookup in a path; movie acceptance cannot establish episode parity. Depends on verified episode identity. |
| A3 | Open: clarification claim crash recovery | Reliability / Media | Durable claim can be stranded after claim before proposal; review idempotent recovery and uncertainty, not blind replay. |
| A4 | Open: retained post-copy staging payload | Ops hygiene / Media | /media/plex/downloads/complete/... preserved intentionally; exact files, Plex verification, retention and separately governed cleanup required. Never blanket delete. |
| A5 | Open: catalog eligibility vs peer viability | Integration / Media providers | Bitmagnet/qBittorrent Search/Prowlarr discovery does not prove live peers; trackerless metadata stalls remain possible. Report separate evidence dimensions. |
| A6 | Verify: naturally eligible continuation replay | Acceptance / Media | One-shot replay guard repaired in d914f2a; prior live window confounded by containment. Next naturally eligible approved objective, no manufactured acquisition. |
| A7 | Verify: fresh post-atomic-claim Pixel return | Acceptance / notification integration | Real Pixel delivery preceded final race fix; 019d900 adds conditional claim. Await normal authorized outcome; no test notification sent here. |
| A8 | Resolved: wrong-series/latest-episode routing and provider-year gate | Bug / Media | September 6/7 title/clarification fixes and 68cff41, defd37f, 62fb131; retain regression coverage, not active reimplementation. |
| A9 | Resolved: unsafe SQLite-file flock interaction | Correctness / Media persistence | September 7 download-status report and 62fb131 move coordination off database inode; previous integrity check passed. No DB reset needed. |
| A10 | Open: spaced episode-range exclusion | Bug / Media policy | acquisition_discovery._parse_episode_coordinates recognizes compact ranges but can treat S01E01 - E03 or S01E01 to E03 as one episode. Bound hardening before claiming exhaustive exact-episode selection. |
| A11 | Verify: late Plex readiness recovery | Integration / Media | Earlier promotion reports lack a verify-only continuation after bounded failure; completion-v2 supersedes some lifecycle gaps but not proof for every legacy promotion row. No automatic retry authorization. |
| C8 | Open: unresolvable Discord-origin starvation | Reliability / Core transport | bot.deliver_origin_notifications skips malformed/missing channels before disposition; oldest bounded page may starve newer records. Resolve or record bounded failure through shared outbox. |
| V4 | Open: test default-store isolation | Test infrastructure / Core | Historical tests can use default stores; use disposable paths consistently before claiming zero developer-test data effects. Report directories are not governed evidence. |
| I6 | Verify: Prowlarr/Usenet and third-party Search hardening | Integration / Media | Multi-provider code is delivered; Prowlarr deployment/indexers and typed Usenet execution are not implied. Native Search plugin upstream timeout/redirect/read bounds need separate provider review. |
| W5 | Verify: physical device logout/revocation and exact-review click acceptance | Acceptance / Web identity | Controlled deployed API denial exists; later physical Push evidence supersedes missing-enrollment reports, but not every device ceremony. Do not revoke the user's working device merely to test. |
| W1 | Removed: retired NeoHabit card and endpoint | Hygiene / Web | No deployed NeoHabit container; both featured card and static endpoint removed. |
| W2 | Already delivered: qBittorrent WebUI link | UX / Web integration | launcher/services.js, /api/tui/qbittorrent-webui; configuration-backed redirect is not provider health. |
| W3 | Open: launcher shortcut vs capability readiness | Truth / Web | Most service links remain configured static shortcuts, explicit status probes exist; do not label all configured endpoints healthy. Remove dead placeholders instead of inventing live feeds. |
| W4 | Already delivered: enrollment/current-device Push and cookie continuity | UX / Core notifications | Durable sessions, Inbox subscription status, device replacement and fan-out exist; A7 is narrower remaining acceptance. |
| I1 | Open: inference deadline and configuration drift | Integration / inference | Live Web fallback reproduced a roughly 30-second inference_service_error; runtime-status showed local mode and a reachable service. Inventory on 2026-09-07 reports Qwen2.5 and llama.cpp Qwen ready, configured Mistral missing, Ollama Qwen3.8 degraded, xAI unobserved. No model install/selector change; C1 does not repair inference reliability. |
| I2 | Open: compatibility configuration/reporting consumers | Debt / inference | Compose fast/mid/heavy fields remain consumed; do not delete role names just because local/frontier mode exists. Current self-inspection implementation already distinguishes configuration and observation. |
| I3 | Already delivered: model registry/selection and runtime self-inspection | Capability / Core inference | dd6ddcc and completed inference contract; unknown is honest. Optional providers/benchmarks are separate decisions. |
| I4 | Open: Naga/provider readiness across launch paths | Packaging / App + Core integration | Prior audit found host package versus container gap; executable visibility is not authorization. Verify each actual launcher before claiming availability. |
| I5 | Open: Rubick setting observation gaps | Observability / Core integrations | September settings audit distinguishes desired/deployed/observed; many non-model keys have no process observer. Add adapters only for operator value; unknown values are not inherently bugs. |
| O1 | Resolved: qBittorrent/Gluetun namespace recurrence repair | Ops / external deployment | 0f86e74, guarded namespace/paused-state reconciliation and separate supervisor; no generic Docker authority. Current host containers inspected. |
| O2 | Resolved: old torrent cleanup approvals/blockers | Historical ops residue | September 5 exact cleanup reports supersede earlier waiting-authority reports. Preserve receipts and retained files; do not replay approvals. |
| O3 | Open: duplicate /host_bin mount authority |
Security/ops decision | Compose declares RO and RW for same target; effective access is RW. Settling intended lane authority precedes change. |
| O4 | Open: migration exception suppression | Reliability / Core persistence | app/db.py and migration runner historical catch paths; need existing-DB/cold-start and observable failure contract. No schema mutation here. |
| O5 | Open: obsolete cleanup script safety | Hygiene / developer tooling | scripts/cleanup_bak_files.py can delete after archive failure; review consumers, then retire rather than automate unsafe cleanup. Never run it as archaeology. |
| O6 | Open: old Keeper local store/audit references | Architecture / Core | task_store.py, keeper_audit; retain SQL/CSV evidence until consumers/retention decision established. No shadow backend expansion. |
| O7 | Open: legacy context injection signature mismatch | Bug / legacy Discord path | Identity report found one-argument call versus two-argument inject_luna_context; neutral fallback masks it. Fix only with real affected transport acceptance. |
| O8 | Open: host Terminal preference-write permissions | Ops / LifeVault adapter | Host reads container-created preferences; writes need explicit ownership policy. No chmod/chown inferred. |
| O9 | Deferred: trivial compatibility-helper simplification | Low-value debt / Core | _is_relative_to can eventually use supported Python API; does not block product progression. Delete only with consumers/tests known. |
| D1 | Delivered: development authorization/plan binding and commit integration | Core governance | d82c02c, 03c99e0, September 1 finalization lineage supersedes earlier blocked reports; deeper continuation parity remains an acceptance question, not new commit authority. |
| D3 | Deferred: broader project-authority envelope | Architecture / Core governance | September 1 target architecture is broader than delivered bounded development authorization; checkpoint/amendment/revocation and cross-domain effect semantics need separate adoption. |
| D2 | Verify: cross-transport development continuation acceptance | Core integration | Historical implementation report deferred deeper continuation/change attribution; later commit integration closes only its own scope. Reuse exact authorization records; no automatic commit/push. |
| L1 | Open/conditional: ordinary LifeVault retrieval and universal Zeus linkage | Core integration | Foundation durable memory/evidence exists; coverage is not universal across legacy domains. Scope one real consumer before adding stores or global hooks. |
| P1 | First bounded informational exchange implemented; received-Rote inspection next recommended | Rote domain over Core primitives | Current capability, preserved sources; public discovery and effectful forms deferred. |
| P2 | Deferred: App extraction/product expansion | Product/architecture | See boundary model and September 4 audit; no App must exist for Core identity to survive. |
| R1 | Research: Obscura vs SearXNG | Search integration | Operator interest in h4ckf0r0day/obscura; SearXNG already deployed. No installation, credentials or new exposure authorized. |
RESEARCH / EXPERIMENTS
R1 is ready for a bounded read-only comparative study after Core inquiry convergence. Establish the problem not served by SearXNG, overlap and unique capabilities, privacy/retention and trust implications, maintenance cost and whether a second search surface is justified. Default classification: search integration, not a new Core component or App. Expose both only if evidence supports independent operator value. No upstream functionality is asserted here; the study has not been performed and nothing was installed.
Inference benchmarks, extra providers, experiential reinforcement, networked identity and speculative automation are not maintenance prerequisites. Preserve the existing explicit inference/experience deferral gates below.
DONE / SUPERSEDED and subtractive decisions
Retire “finish Chen watch loop” as a broad active objective; preserve its bounded exceptions. Do not rebuild notification/outcome stores, Lich approvals, Io, canonical-principal identity, qBittorrent linking, model self-inspection or Media provider routing already delivered. Earlier blocked authorization reports are historical when later exact work completed; they do not create fresh backlog. Remove NeoHabit presentation. Exclude disposable report copies from test discovery without deleting reports. Keep unknown capability posture explicit instead of creating adapters merely to fill a dashboard. Retain compatibility paths until consumer evidence supports migration; a name mismatch alone is not a defect.
First-principles review: pipeline ordering and stale hand-maintained adoption metadata reflect historical growth. A second router, registry, scheduler or approval store would increase the ownership problem. Simplify by using the existing intent boundary, bounded provider contracts and single authorities. Do not automate roadmap mutation to compensate for unreconciled release records. Do not optimize model selection to answer questions already owned by evidence. DELETE > SIMPLIFY > OPTIMIZE > AUTOMATE remains the sequencing rule.
Dependency graph and release gates
Arrows are sequencing recommendations unless an adopted contract says otherwise. Rote conceptual requirements are now attributed to the preserved sources and separated from implemented dependencies in the reconciliation. The first exchange has bounded verified-instance mechanisms; broader network and identity mechanisms remain deferred. No graph edge authorizes implementation or mutation. For each implementation slice: focused/full tests, architecture/static/hooks/docs, diff review, Compose rebuild/health and actual affected-surface acceptance. Never substitute mocked providers for live device/notification acceptance.
Completed portfolio
Platform foundation
AncientOS Platform v1 Alpha provides the shared transport-neutral runtime, Runtime Composition, durable Kernel Records, restart-safe explanation, Governed Proposals, durable Lich approvals, bounded execution, Zeus evidence and receipts, rollback or compensation records, and transport parity.
This foundation is complete for the current alpha contract. It is not a claim of production readiness or universal capability coverage.
Oracle Operational Ergonomics
Historical program: Era 7. Portfolio state: complete.
Oracle supplies operator-facing inspection, action queue, governed proposal preflight, simplified proposal intake, explicit apply vocabulary, and proposal audit over existing governed services. Oracle remains advisory and does not own approval, execution, evidence, receipts, memory, or a second proposal lifecycle.
Completion commits:
0dba71eAdd Oracle governed proposal preflighte7c6ae6Fix governed action precondition race6c31539Add unified Oracle action queue8be8ee0Add Oracle governed proposal audit9263433Add simplified Oracle proposal intake08edff2Add explicit Oracle governed apply vocabulary
Spectre terminal observation
Portfolio state: complete for terminal observation v1.
Spectre ingests explicit spectre-shell terminal records, applies deterministic
redaction, supports explicit process-bounded conversation binding, and supplies
read-only evidence for Oracle interpretation. It does not intercept SSH,
capture hidden screens, execute commands, approve work, or certify success.
Completion commits:
0384b82Add Spectre terminal observation capabilityb6477dfFix Spectre pre-commit hygiene
First governed capability portfolio
Historical program: Era 8. Portfolio state: complete.
| Capability | Operator outcome | Authority and persistence | Evidence boundary |
|---|---|---|---|
governed_configuration_value_edit |
Inspect and change one registered non-secret scalar | Lich-bound proposal; bounded executor; durable Zeus evidence, receipts, and exact rollback | Shared-runtime smoke tested in a disposable workspace |
governed_atomic_file_rename |
Rename one registered regular file without overwrite | Lich-bound proposal; no-replace executor; metadata-only Zeus evidence and exact reverse receipt | Shared-runtime and filesystem integration tested |
governed_home_assistant_light_set_state |
Inspect and set one registered light.* entity on or off |
Lich-bound proposal; bounded provider; token-free Zeus evidence; reconciled or uncertain receipt; separate compensation | Fake provider only; not credentialed or live-provider validated |
| governed capability discovery | List and inspect the portfolio from Rubick | Oracle read-only rendering; no second registry or authority | Shared-runtime tested |
Completion commits:
cdc31efAdopt governed capability portfolio as Era 88b06de0Add governed configuration value edits319d0e3Add governed atomic file rename97cf673Add governed Home Assistant light state124e896Add Oracle capability portfolio discovery288a861Add Era 8 portfolio runtime acceptanceee65fb7Complete Era 8 governed capability portfolio
Governed experiential-learning foundation
Portfolio state: complete for the current advisory foundation.
AncientOS can persist independently certified experiential assertions through the governed LifeVault promotion lifecycle, derive deterministic scoped snapshots, attach an exact snapshot to LegionCommander plans after the deterministic task graph is complete, and retain the snapshot identity and evidence provenance for replay. Supported certification evidence is currently limited to exact governed-action receipts and deterministic pytest receipts with exact file-content subject binding and the shared 90-day evidence freshness policy.
LegionCommander is the only experiential consumer. Experience is advisory and
cannot influence intent or semantic routing, Rubick readiness or
authority_mode, Lich approval, mutation or pending-action authorization, or
executor selection. Durable promotion authorizes only persistence of the
advisory assertion; it does not approve the action described by that assertion.
Completion commit:
775d0feAdd governed experiential learning foundation
The following remain intentionally absent from the completed contract:
- confidence or reinforcement scoring, frequency-based ranking, and adaptive strategy weighting;
- automatic promotion or automatic contradiction adjudication;
- advisory consumers other than LegionCommander;
- learned routing, capability readiness, authority, or approval;
- automatic cross-domain experiential transfer;
- aggregate validation-suite receipts and generalized artifact/tree subject binding;
- arbitrary model-authored durable experiential knowledge; and
- generalized self-optimization.
These limits are architectural boundaries, not incomplete acceptance criteria for the completed foundation.
Governed Inference Registry and Model Selection
Portfolio state: complete for the current production boundary.
The operator explicitly authorized Slices 1–5B and the completion pass. The implemented boundary comprises canonical provider-independent model identity, configuration composition, deterministic aliases, discovery/reachability/ readiness evidence with freshness, bounded Ollama and authenticated OpenAI-compatible observation, canonical inventory and Oracle projection, read-only model questions, request and session selection, bounded restoration, reset to configured routing, targeted readiness verification, provider-name disambiguation, exact-target local/xAI invocation, and shared natural-language semantics across transports.
Live acceptance on 2026-08-21 established the local llama.cpp Qwen 3.8 target
and the configured xAI grok-4.3 target through luna-inference. The same
Qwen GGUF remains discovered but not ready through Ollama. OpenAI has a
provider and adapter contract but no deployed outbound key/model target;
LUNA_OPENAI_API_KEY remains only the inbound AncientOS API guard. Completion
evidence is recorded in the initiative implementation, tests, deployed
acceptance record, and repository history.
The completed capability changes cognition only. It does not change Rubick,
Lich, Zeus, executor, mutation, external-contact, tool, or pending-action
authority. Explicit selection has no fallback. Existing fast/mid/heavy,
LUNA_MODEL_MODE, and luna-local:preferred values remain compatibility
configuration when no explicit selection exists.
Remaining inference work is intentionally inactive:
| Item | Classification | Reconsideration condition |
|---|---|---|
| Governed persistent default mutation | deferred, prerequisite-bound |
Define an exact registry-ID-to-role/model-mode mutation contract, Lich approval, restart convergence, Zeus evidence, rollback, and unambiguous intent; do not edit environment files from ordinary conversation |
| Cost-aware routing and local-first/frontier fallback | deferred |
Adopt explicit cost/egress budgets and fallback semantics; preserve no fallback for explicit selection |
| Automatic capability-aware routing | deferred |
Demonstrate a bounded role/capability policy and replay evidence without granting models routing authority |
| LegionCommander-selected inference | deferred |
Adopt an advisory-only planning contract with deterministic policy ownership outside the model |
| Model quality and latency benchmarking | candidate, optional |
Define representative, privacy-safe datasets, metrics, repeatability, and cost bounds |
| Proactive/background readiness monitoring | deferred, scheduler-bound |
Adopt a narrow cancelable monitor with bounded paid probes, persistence, and no health-triggered switching |
| Further inventory latency optimization | candidate, optional |
Current five-minute cache, target verification, and provider-scoped reads prove insufficient under measured operator workload |
| Provider-role readiness unification | candidate, prerequisite-bound |
Define reconciliation between static role/provider posture and concrete target evidence without inflating readiness |
| Additional frontier providers | candidate, provider-bound |
Supply a concrete credential/configuration boundary, bounded adapter, egress policy, and live acceptance |
| Multimodal or vision selection | candidate, optional |
Define canonical modality requirements, transport artifacts, provider capability evidence, and privacy policy |
| Long-context policy | candidate, optional |
Establish per-role context budgets, truncation/retrieval rules, and provider-specific evidence |
| Model download, removal, and lifecycle management | deferred, mutation-bound |
Adopt typed storage/identity, capacity, provenance, approval, rollback or non-reversibility, and runtime convergence contracts |
| Automatic model updates | deferred |
Supply artifact trust, compatibility, rollback, and explicit scheduling governance |
| Session identity cleanup | candidate, compatibility-bound |
Replace historical default_session_key()/discord: labeling only with migration and transport parity evidence |
| Deeper selection history | candidate, optional |
Demonstrate operator need beyond the bounded two-prior-state restoration contract |
| Default Ollama availability repair | candidate, operational |
Choose an intended fast target or grant suitable acceleration/resources; current luna-local:preferred resolves to a CPU-loaded 15.4 GiB Qwen3.6 model plus 3.9 GiB KV cache whose runner terminates |
| Remote data-egress policy enhancement | candidate, policy-bound |
Decide per-target/provider disclosure, content classes, retention assumptions, and whether explicit selection is sufficient authorization |
| Usage and cost accounting | candidate, policy-bound |
Define provider usage normalization, privacy-safe persistence, budgets, and operator reporting |
| Per-model observability and metrics | candidate, optional |
Define bounded labels, latency/error/token metrics, retention, and cardinality limits without prompt/output capture |
These classifications close the initiative without adopting optional routing, monitoring, lifecycle, or policy work. A future session must explicitly adopt one bounded item before implementation.
Media Manager read-only episode inventory and acquisition discovery
Portfolio state: complete for the current read-only slices.
Episode inventory resolves an explicit TV series through TVmaze and Plex,
compares canonical aired-order episodes within an explicit latest-episode,
latest-season, or whole-series scope, and returns bounded missing, duplicate,
unmatched, wrong-library, ambiguity, and Plex-ahead observations. Acquisition
discovery consumes one uniquely resolved aired episode, checks Plex first, and
normalizes, filters, deduplicates, and ranks bounded provider observations into
an advisory recommendation under media_preference_v1.
Neither slice creates an executable proposal, invokes Lich, starts acquisition, contacts a candidate locator, controls a downloader, mutates the filesystem, refreshes Plex, schedules monitoring, or gains approval or execution authority. The deployed Bitmagnet candidate adapter remains unavailable until a bounded normalized observation contract exists; the synthetic provider is explicit acceptance-only.
Future provider adapters, quality/version policy changes, duplicate handling workflows, automated missing-episode workflows, scheduled monitoring, approval-gated acquisition, download-client integration, filesystem placement, and Plex refresh are not active capabilities. Each requires separate adoption and its applicable evidence, governance, execution, receipt, rollback or non-reversibility, and deployed acceptance boundary.
Completed Media vertical slice
Portfolio state: complete for the demonstrated governed objective lifecycle.
The 2026-08-25 watch-loop plan is historical lineage; subsequent operator work
extended its provider and playback scope. Commits 62fb131, 019d900, and
d914f2a establish the current boundary: natural objective, canonical principal,
entity resolution and bounded clarification, exact Lich approval, separate
execution, completion observation, Plex verification and qBittorrent cleanup,
durable outcome return, current-device Push, named-room playback and observation.
A real Pixel notification and awake Living Room playback were observed during
that milestone. Playback replay was repaired to make it a one-shot objective.
These are historical acceptance facts, not fresh live acceptance in this audit.
Do not reopen the milestone as an unfinished general acquisition program. Cold-device/profile barriers, exact-episode playback identity, observer hosting, clarification crash recovery, retained copies and fresh post-repair replay/Push acceptance are bounded follow-ups in the recovered register below. Completion is not universal device readiness, peer viability, or universal transport parity.
Candidate analysis
Candidates are retained because repository evidence shows plausible bounded operator outcomes. They are not adopted and have no mandatory order.
qBittorrent pause/resume
- Outcome: pause or resume one exact observed torrent.
- Reuse: read-only qBittorrent adapter, Chen provider experience, governed proposal and receipt lifecycle.
- Missing adoption evidence: exact hash identity, fixed operations, provider configuration, durable lifecycle integration, reconciliation, compensation, and transport acceptance.
- Authority boundary: any mutation remains separately Lich-gated.
Read-only service diagnostics
- Outcome: explain one service degradation from bounded evidence without remediation.
- Reuse: Beastmaster inspection, Oracle synthesis, Runtime Composition.
- Missing adoption evidence: exact target class, freshness, redaction, provider identity, route, and deterministic unavailable behavior.
- Boundary: read-only diagnosis must not grow an execution or repair path.
Deferred analysis
Deferred items are intentionally outside the active portfolio:
- container restart and Compose deploy/recreate because Docker authority, convergence, and reversal are unresolved;
- Git update because remote trust, signatures, dirty state, divergence, and recovery are unresolved;
- package/system update because root authority, reboot impact, network trust, and downgrade evidence are unresolved;
- broad delete because retention and irreversibility are unresolved;
- general scheduling because unattended durable execution and cancellation semantics are absent;
- autonomous remediation because explicit human governance remains doctrine;
- general shell execution because typed bounded capabilities are safer and more inspectable.
Reconsideration requires a new evidence-backed adoption proposal. Deferred items do not become candidates automatically when another capability completes.
Governed experiential confidence and reinforcement
Portfolio state: deferred. This is future architecture work, not an
implemented capability, an adopted implementation slice, or a Rubick
capability. The completed foundation intentionally has no confidence score,
reinforcement score, frequency ranking, or adaptive strategy weight.
Before reconsideration, a dedicated planning and review pass must define:
- the independent evidence that may justify a state change; model self-assessment cannot reinforce its own advice;
- the exact reinforcement unit (for example a scoped experience, strategy, planning heuristic, evidence relationship, or capability-specific advisory preference) without assuming one in advance;
- explicit domain, actor, subsystem, capability, and problem-class scope, with no implicit cross-domain transfer;
- deduplication by underlying evidence identity and treatment of correlated receipts from the same execution or validation chain as non-independent;
- failure, contradiction, and explicit supersession semantics that preserve historical evidence rather than producing simplistic score oscillation;
- whether evidence freshness makes a derived posture stale and whether any decay model is justified; automatic decay is not approved;
- an immutable replay projection containing the exact ranking inputs and state supplied to historical cognition;
- deterministic inputs, ordering, bounds, and tie-breaking for any advisory ranking;
- whether automatic evidence-derived updates and operator-authored judgments are durable mutations, and the governance required for each;
- an explanation contract that answers why one experience ranked above another using evidence and provenance rather than opaque learned state.
Any design must preserve the authority firewall: confidence or reinforcement
cannot grant authority, reduce Lich requirements, change authority_mode, make
a capability ready, select an unauthorized executor, alter deterministic
semantic routing, approve mutation, or authorize pending-action continuation.
Its first consumer, if separately adopted, must remain inside an established
post-boundary advisory path. LegionCommander is the only current experiential
consumer; no additional consumer is approved by this roadmap.
The prohibited feedback loop is explicit: experience may advise cognition, but cognition selecting a strategy and declaring itself successful cannot increase experiential posture without independent certification.
Recommended reconsideration sequence, with each step requiring its own bounded decision where applicable:
- accumulate and validate real certified experiences under the completed foundation;
- add missing evidence or exact subject-binding adapters only when stable repository contracts justify them;
- perform the confidence/reinforcement architecture planning and governance review described above;
- consider one bounded deterministic advisory-ranking implementation; and
- review any additional advisory consumer separately.
This sequence is not an adopted queue and does not authorize implementation.
Adoption contract
An adoption proposal must contain:
- stable capability ID and one bounded operator outcome;
- explicit scope, targets, operations, and non-goals;
- implementation, integration, and operator-route evidence;
- dependency and provider configuration requirements;
- authority classes and the exact Lich boundary for mutation;
- Zeus evidence, receipt, and outcome-reconciliation requirements;
- persistence and restart behavior;
- rollback, compensation, or explicit non-reversibility;
- security, privacy, identity, and blast-radius analysis;
- fixture, local, credentialed integration, and live-provider validation expectations;
- focused, transport, package-isolation, documentation, and full repository validation;
- explicit operator decision metadata.
Oracle and Rubick may assemble advisory evidence for this packet. They cannot
change its lifecycle state. The operator records adopted, deferred, or
rejected.
Adoption is not mutation approval. An adopted capability can remain default-disabled, and every live action can remain Lich-gated.
Delivery standard
Read-only capability
A read-only capability must demonstrate:
- bounded evidence and stable identity;
- provider configuration and request-time readiness without unsafe probes;
- deterministic failure for missing, stale, malformed, or unauthorized evidence;
- transport-neutral Runtime Kernel routing;
- Runtime Composition and Kernel Record linkage;
- operator-friendly and diagnostic rendering;
- no write-capable method reachable from the read path;
- focused, integration, transport, and repository-wide validation.
Governed mutation capability
A mutation capability must additionally demonstrate:
- deterministic durable proposal construction;
- exact action, target, scope, actor, hash, and expiry binding;
- durable Lich approval separated from execution;
- request-time freshness and precondition validation;
- bounded typed execution with no general command path;
- durable Zeus before/after evidence and receipts;
- reconciliation for external outcomes;
- exact rollback, compensation, or explicit non-reversibility;
- restart-safe continuation and explanation;
- default-disabled configuration and explicit allowlists;
- fixture and local acceptance plus honest external validation posture.
Platform extension gate
Capabilities should consume existing platform primitives. A shared platform extension requires either:
- at least two independent capability consumers; or
- a demonstrated correctness, security, compatibility, or truthful observability need.
The proposal must document consumers, failure semantics, persistence or migration impact, compatibility, and validation boundaries. Capability-local parsing, policy, allowlists, providers, evidence normalization, execution, and rollback should remain outside shared runtime layers.
Do not introduce a general executor, scheduler, registry, named subsystem, protocol, persistence hierarchy, or transport-specific business rule merely to anticipate candidate work.
Decision record
| Decision | State | Evidence |
|---|---|---|
| Adopt Era 7 Oracle Operational Ergonomics | historical decision; program complete |
Era 7 completion commits and Oracle tests |
| Adopt first Governed Capability Portfolio as Era 8 | historical decision; program complete |
cdc31ef through ee65fb7 |
| Adopt Era 9 | No decision; not adopted | No canonical adoption record exists |
| Defer Chen operator watch loop | deferred by operator on 2026-08-25 |
Preserved dirty implementation; reconsideration conditions in deferred analysis |
| Adopt Chen operator watch loop | Historical adoption on 2026-08-25; completed through subsequent Media milestone | Exact implementation contract; completion gaps preserved |
| Adopt Keeper exact-task completion lifecycle consolidation | adopted by operator on 2026-08-25; implementation not started |
Bounded adoption contract |
| Complete Media objective vertical slice | complete, reconciled 2026-09-07 |
62fb131, 019d900, d914f2a; bounded live limitations retained |
| Reconcile AncientOS program | Authorized bounded catch-up, 2026-09-07 | Operator program-reconciliation instruction; no new product adoption or runtime mutation authority |
| Adopt another capability | No decision | Keeper exact-task completion remains adopted; the next Core recommendation is advisory |
Future decisions must be added here or in a linked canonical decision record, then reflected in architecture metadata and the master portfolio view. Editing a candidate description alone is not adoption.
Historical relationship
The completed Era 8 contract proved configuration edit, atomic rename, Home Assistant light state, and capability discovery. Earlier detailed rankings, recommended sequences, and implementation prompts were planning inputs for that completed program. They are preserved by Git history and must not be replayed as the current queue.
Root era plans and other proposals are historical unless
docs/documentation_status.md explicitly classifies them as canonical.