Verified development truth

D5 Alpha Runtime Foundation

KINGAI OS separates source existence, CI verification, VM/hardware validation, published artifacts and production readiness. A later state is never inferred from an earlier one.

Source: 0.1.0-dev · Stage: D5 Alpha Runtime Foundation / Pre-Alpha · Facts updated: 2026-08-14

Verified runtime foundation
Verified

Identity + Policy + Approval

Unix peer identity, Agent Registry, fail-closed capability policy and target-bound one-time Approval are implemented and covered by current core tests.

Verified

Task Graph + Scheduler

Persistent tasks, dependency validation, step lifecycle, approval waits, failure propagation and automatic task completion exist in the D5 source line.

Verified

Constrained ExecD

A separate privileged broker exists with capability-specific handlers. The current native privileged capability is deliberately narrow rather than a generic root shell.

Verified

M0–M6 Memory foundation

Layered memory metadata, local persistence, search, expiry and controlled promotion foundations are implemented in source and unit tests.

Verified

Model + Adapter foundations

Provider-neutral routing, provider registry/health and a replaceable runtime adapter contract are implemented; production provider and external-runtime integrations remain future release work.

Verified

Core CI + CodeQL

The merged D5 main commit has passed Foundation CI and CodeQL. These verify software foundations, not production signing or hardware certification.

Platform engineering
Preview

Server

A public amd64 Developer Preview exists. Newer D5 source capabilities may be ahead of that published image.

Engineering

Desktop

Personal-computer edition with Plasma 6 core, three experiences, live/installer validation tracks and Agent Center foundations.

Engineering

IoT / Edge

Generic amd64/arm64 image pipelines exist; board-specific support still requires validated Device Packs on real hardware.

Engineering

Container

Docker/OCI profile, non-root runtime, persistent state pattern and CI image/runtime smoke path exist. Official production publication is still gated.

Verified system foundations
Verified

Installer / boot VM paths

Server/Desktop build and VM tracks cover install, live boot and BIOS/UEFI engineering paths.

Verified

A/B update + Recovery

Dedicated VM paths exercise staging, health confirmation, rollback and recovery workflows.

Verified

TUF client + Secure Boot VM

Client-side trust behavior and VM Secure Boot validation exist, but they are not equivalent to production key custody.

Protected production gates
Protected

Production TUF & signing

Threshold-key operations, offline key custody and final production Secure Boot signing are intentionally not claimed ready.

Protected

Hardware certification

Raspberry Pi, Jetson and industrial Device Packs require real board boot validation before being listed as supported.

Protected

Stable 1.0

Release governance, final vulnerability/legal review, artifact delivery, signing and lifecycle commitments must pass before Stable.

Status is evidence, not marketing.

The detailed ledger and machine-readable release gates live in the public source repository.

Open source status →