Public release roadmap

Two kernels. Two release lanes.

JefeRust 1.1 has shipped with the bounded JefeOS 1.1-compatible Xylem authority and recovery path. JefeOS 1.2 is advancing a separate reliability and cross-vessel failover program.

Status snapshot: September 1, 2026

How to read this roadmap: implemented features and releasable evidence are different states. A lane normally ships only when its mandatory gates pass against one exact source revision and its published artifacts. Any release-owner exception stays visible as a waiver and never becomes a fabricated PASS. Dates are deliberately not promised before the evidence exists.
Released · 1.1.0

JefeRust 1.1

The Rust kernel retains its complete 1.0 foundation and adds the deliberately bounded Xylem contract deployed by JefeOS 1.1.

Feature baseline

  • 55 of 55 frozen JefeOS 1.0 benchmark feature lines are implemented and the final blocking accept interruption parity defect is closed.
  • Full NTFS write parity landed, including allocation growth, fragmented runs, directory-index growth and shrink, and $MFT growth.
  • Bounded Xylem parity landed: local supervision, exact grant verification, two fixed durable authority floors, fail-closed admission, stateless singleton lifecycle, and real-panic recovery.
  • Real workload proof exists: the JefeRust Discord bot was observed running the 1.1.0 SMP0 image over its native networking and Linux-compatibility stack.
  • Graphics boundary: an experimental in-kernel framebuffer/window-manager implementation is compiled into 1.0, but a functional GUI was not a 1.0 goal and was not exercised by the 1.0 runtime gates.

Release decision and evidence

  • No confirmed release-relevant HIGH defect remained at the exact release commit.
  • A clean, pinned build produced the published SMP0 and SMP1 artifacts from 80e07d9b7468038e2e288e91f7efb2e1a0611d31.
  • Independent QEMU, Hyper-V parity, host accounting, Xylem S5/S6/S9, correctness, and security gates passed against the exact release.
  • The final verifier accounted for 17 PASS, 0 FAIL, and 2 NOT-RUN gates with zero confirmed HIGH release blockers.
  • The release is qualified. Operational validation observed the exact-product bot for 8,527 seconds with 30/30 READY samples and no product failure.
Not claimed by JefeRust 1.1: resource fencing, authenticated membership, quorum or partition safety, a stable service front door, fleet observability, stateful failover, consensus, generalized placement, or a supported functional GUI. Read the release evidence and download the exact images.
1.2 development

JefeOS 1.2

The C++ kernel's next release is centered on trustworthy recovery, exact evidence, and surviving a whole-vessel failure.

Target progress

  • OpenStack-managed guest: proven in the nested-KVM lab. The image was uploaded through Glance, launched by Nova, and operated through Horizon using the conservative BIOS + IDE + E1000 profile. Its ISO 9660 config-drive applied hostname and SSH keys, then networking came up through DHCP.
  • Cross-vessel failover: foundations landed. Membership, failure detection, and a failover primitive exist; fencing, workload binding, and real panic-to-peer proof remain.
  • Diagnostic accuracy: active. Reboot-reason tracking is complete; exact build identity and the broader measured-vs-hypothesis audit remain.
  • Bot stability: acceptance active. The residual Node/libuv strand is measured outside the kernel wake path, but the exact release candidate must still pass the clean stability soak.

Mandatory release proof

  • No confirmed release-relevant HIGH defects.
  • One-command, machine-readable evidence from a clean pinned build.
  • Independent QEMU and Hyper-V boot/regression proof with exact artifact identity.
  • A four-hour production-equivalent bot soak with zero organic harvests, plus separate deterministic Xylem recovery proof.
  • Honest accounting, immutable provenance, current public claims, and enforced warning floors.
Release rule

Evidence closes a lane—not a percentage.

Both releases use the same discipline: a clean source revision, reproducible artifacts, exact build identity, independent runtime proof, fail-closed test accounting, and immutable checksums. A green-looking stale artifact, skipped suite, transport failure, or recovered organic crash does not count as a pass.

After 1.2

JefeOS 1.3

Make clean CI, cross-kernel conformance, warning reduction, Tier-5 workload truth, and self-service lab tooling the normal development loop.

Major boundary

JefeOS 2.0

Supported-default SMP, JSL-2 native containers, production-facing security contracts, stable external interfaces, justified density work, and a functional userspace GUI proven through interactive runtime gates.

Major boundary

JefeRust 2.0

Advance beyond the bounded 1.1 Xylem contract and deliver the same functional GUI boundary: stable userspace display/input interfaces, a compositor and application surfaces, keyboard and mouse interaction, and automated plus interactive runtime proof.

North star

Xylem

Continue from membership and local supervision toward fenced cross-vessel recovery, replicated service placement, and eventually stateful cells.