← Documentation
Project homeEdit source
Start here · kofun source

Implemented status

The concise capability matrix. Active claims require an executable gate.

docs/MVP_IMPLEMENTED.md

Implemented status

CapabilityStatusGateClaim
.kofun source extensionimplementedtask repository-checksource-extension
Kofun-written compiler seedimplemented: nested-block and looping Int/Bool/Text/List[Text] Core with 15 typed profile builtinsbootstrap/stage1/check.shcompiler-seed
Reproducible bootstrapimplementedbootstrap/stage1/check.shreproducible-bootstrap
arithmetic Core validation/emissionimplementedtests/cli.sharithmetic-core
build/run/check/test CLICore onlytests/cli.shcli-commands
explicit skip reporting and coverageimplementedkofun testtest-skip-reporting
semantic compiler self-recompilethree-generation fixed point reached for the frozen profile: C2 == C3 and A2 == A3 byte for bytetask selfhost-fixed-pointself-recompile
diverse double compilationtwo unrelated host C compilers build Kofun compilers that emit byte-identical C; independent reproduction (B6) stays opentask selfhost-diverse-double-compilationdiverse-double-compilation
Stage 2 lexer, parser, and integer Core loweringcheckpoint implementedbootstrap/stage2/check.shstage2-core-lowering
Stage 2 semantic tooling outputbounded compiler-derived KSE projects one-way into canonical non-authoritative typed-sidecar v1 for explicit single-file kofun check; compiler/KIF/cache consumers remain forbiddentask stage2-events, task typed-sidecar-projectorstage2-typed-sidecar
compiled visibility interfacesbounded Stage 2 KIF v2: exact resolved flat-nominal function/payload refs and parameter labels; public/internal/private leak rejection; atomic public/internal filteringtask visibility-filtering, task visibility-api-leaks, task module-interface-artifactcompiled-visibility-interfaces
typed-sidecar documentation indexbounded KIF-filtered projection: canonical public and exact-package internal declaration views with explicit partial/stale trust and atomic publicationtask documentation-indexdocumentation-index
qualified module aliasesbounded same-package import a.b as local; local-only AliasBindingId preserves target identity, with no public/per-name/external aliases or bin/kofun routingtests/conformance/modules/import-aliases/run.sh, task import-aliasesmodule-aliases
C11 user-function callsbounded Int Core: recursion and forward callsbootstrap/stage2/check.shc11-function-calls
C11 bounded List[Int] values and mutable local writesbounded by-value 64-element locals and direct function carriers; standalone mutable-local element assignment with checked positive, negative, constant, and dynamic indicestask list-int-values, task list-int-signaturesc11-list-int-values
x86-64 native user-function callsbounded Int Core: six arguments, guarded returns, recursiontests/conformance/functionsnative-x86-64-function-calls
x86-64/AArch64 native Text-returning callsbounded compiler-shaped profile with parameters, locals, concatenation, forwarding, and direct callsbootstrap/native/check.shnative-text-returning-calls
AArch64 native user-function callssame bounded Int Core lowered to AArch64; executed under qemu-aarch64tests/conformance/functions, bootstrap/native/check.shnative-aarch64-function-calls
x86-64/AArch64 native Int64 valuesliteral magnitudes through INT64_MAX, backward-compatible deterministic encodings, and the complete signed range through checked expressionsbootstrap/native/check.shnative-int64-values
x86-64/AArch64 native integer division// and % use the specified floor semantics; / is not defined on Int and both targets refuse it with one diagnostic (#687); both guard zero and non-representable quotients with canonical per-operator R010 diagnosticstests/conformance/numeric, tests/conformance/functions, bootstrap/native/check.shnative-integer-division
exact Decimal arithmetic, explicit rounding, and binary64 FloatStage 2 C11 lowers native Decimal +, -, *, comparison/equality, checked /, all five signed rounding modes, rounded division with mandatory scale/mode, and exact display-scale format/parse; Float remains observably binary64; every other declared backend has an explicit unsupported capability row (#724)tests/conformance/decimal-arithmetic, tests/conformance/capabilities.tsv, tests/conformance/decimal/run.sh, stdlib/decimal/tests/verify.shdecimal-arithmetic-v1
self-host success corpus as a native binarythe driver's five-print corpus reaches a static ELF on both targets and matches the self-host C11 path exactlybootstrap/selfhost/native/check-native-corpus.shselfhost-native-corpus
x86-64/AArch64 constant-stack returned callsa return of a direct call branches instead of calling, so direct and mutual recursion in that position run in constant stack; proved by executing three million steps under a lowered stack limitbootstrap/native/check.sh, tests/conformance/functionsnative-constant-stack-returns
stable diagnosticscanonical registry plus executable family owners; Stage 2 retains 46/46 codes and 3 explicit span debtstests/diagnostics/, task diagnosticsstable-diagnostics
explicit public re-exportsbounded same-package pub import / pub from; non-widening ExportBindingId edges, 64-edge chains, 1,024 bindings/module and 65,536 edges/package, KIF export facts, and facade/canonical tooling pathstests/conformance/modules/re-exports/run.sh, task re-exportspublic-re-exports
deterministic compiler fuzzingversioned oracle/backend observations for arithmetic plus focused grammar, value-if, match-guard, match-value, and enum-match familiestests/fuzz/, task fuzzdeterministic-fuzzing
concrete enum matching with one Int payloadbounded Stage 2 C11 slice with constructor-set exhaustiveness; constructors and enum bindings cross ordinary function arguments and returns, C(name) exposes the payload to guards and arm bodies, and a binding catch-all may be re-matched. Wider payload types, more than one field, nested payload patterns, generics, and non-C11 backends stay outside ittests/conformance/syntax/issues_35_47/run.sh, tests/fuzz/enum_match.shenum-matching
nominal heterogeneous recordsbounded Stage 2 C11 mixed Text/capacity-64 List[Int]/Int records: labelled construction, declaration-order AggregateLayout, typed field reads, whole-record pass/return, and list-field copy semantics; no general lists, List[Text], nested aggregates, modules, generics, native lowering, or stable ABItask aggregate-bridge, task records, spec/records-v1.mdnominal-records
bounded benchmark report v1 model, Bytes codec, and comparisonbounded C11 Stage 2: 49 fields, 100 samples in 64+36 segments, canonical Bytes and explicit threshold comparison; no live runner, providers, filesystem publication, generic JSON, or other backendtask benchmark-reportbenchmark-report-v1
general parser/type checkeropenno active gategeneral-parser-type-checker
borrowed-List Copy/move ownership checknarrow Stage 2 checkpointbootstrap/stage2/check.shborrowed-list-ownership
bounded positional take and record-edit checkingcheckpoint for direct bare owning Bytes and Int/Bool records; BindingId-based E2S123 and by-value record-edit E2S181; no general CFG ownershiptask move-call-crossingspositional-move-crossings
bounded Bytes[65536] carrier and mutation on C11 Stage 2bounded C11 Stage 2 checkpoint over tracked fixtures; refuses read-to-edit crossing, wrapper aliases and private source results, and resolves same-name declarations and parenthesized BindingIds; includes bounded whole-file reads and a Text bridge of at most 255 bytes; excludes complete exit cleanuptask bounded-bytesbounded-bytes
bounded injected-Bytes time-zone transition producerbounded Stage 2/C11 checkpointtask tzdbbounded-tzdb-producer
bounded affine resource-handle protocolbounded Stage 2/C11 checkpointtask affine-resource-handleaffine-resource-handle
general ownership and law checkingopenno active general passgeneral-ownership-checking
ELF64/x86-64 native image writercheckpoint implementedbootstrap/native/check.shelf64-image-writer
Mach-O 64/x86-64 and AArch64 native image writerbounded deterministic image checkpoint with a declared libSystem runtime dependency; matching-host execution covered by the six-host evidence claim, not a macOS CLI/general runtimebootstrap/native/check.sh, bootstrap/native/check-macho64.shmacho64-image-writer
Mach-O 64 embedded ad-hoc signingbounded deterministic x86-64/AArch64 signed-image checkpoint; matching-host strict validation/execution covered separately; no notarization or certificate claimbootstrap/native/check.sh, bootstrap/native/check-macho64-signed.shmacho64-ad-hoc-signing
PE32+/x86-64 and AArch64 native image writerbounded deterministic no-import image checkpoint; matching-host execution covered by the six-host evidence claim, not a Windows CLI/general runtimebootstrap/native/check.sh, bootstrap/native/check-pe32plus.shpe32plus-image-writer
exact six native checkpoint images on matching hostsLinux, Windows, and macOS x86-64/AArch64 digest-bound execution; macOS also passes strict Apple signature validationtests/native-host-evidence/check.sh, .github/workflows/native-hosts.ymlnative-six-host-execution
wasm32 Int64 arithmetic Core + lazy browser hostexecutable checkpointbootstrap/wasm/check.sh, tests/conformance/numeric, examples/wasm-browserwasm32-arithmetic-core
wasm32 host ABI v1 bounded object arenaexecutable checkpointtask wasm-object-arenawasm32-hostabi1-object-arena
x86-64/AArch64 List[Int] Corecheckpoint implemented; AArch64 executes under qemubootstrap/native/check.sh, tests/conformance/listnative-list-int-core
x86-64/AArch64 UTF-8 Text Corecheckpoint implemented; AArch64 executes under qemubootstrap/native/check.sh, tests/conformance/textnative-utf8-text-core
general native loweringopenunified types/control flow and additional target profilesgeneral-native-lowering
C ABI extern / repr(C) profilebounded host-C implementationbootstrap/c_abi/check.shc-abi-profile
audited raw C bindings from the Clang ASTbounded stage-1 generator; raw and trusted, not safetests/interop/bindgen-c/check.shbindgen-c-stage1
vendored Rust crate through C ABI shimimplemented exampleexamples/rust-shim/check.shrust-crate-shim
Linux HTTP/1.1 epoll framework through C ABIbounded library implementationtests/http/check.shhttp-framework
Linux x86-64 native CLI application frameworkbounded direct-static implementationframework/cli/check.shcli-framework
Linux x86-64 syscall/stdlib APIKofun source contractstdlib/tests/verify.shsyscall-stdlib-api
syscall file round-trip executionimplementednative ELF success and errno failure gatessyscall-file-round-trip
stdio language serverbounded diagnostics, definitions, hover, completion, outline, references, highlights, ownership inlay hints, signature help, folding, selection ranges, semantic tokens, and rename for locals and parameterstests/lsp/check.shstdio-language-server
formatter and REPLopendesign onlyformatter-and-repl
checked Int64 contractimplemented for Corenumeric conformance corpuschecked-int64-contract

Historical prototypes do not count as active after their source is removed.

The Claim column is the stable identity of each row in release/claims.json, which binds it to a positive gate, a boundary that fails outside it, and a reproduction command. task release-claims fails if a row here gains, loses, or reworders a capability without the manifest following, so this table and the evidence cannot drift apart. Status text lives here and is mirrored into the manifest; do not restate it in the manifest by hand.