Start with the current capability and execution records. Older overview, audit and completion documents are dated evidence and can describe superseded implementations; a historical COMPLETE heading is not a current product claim.
| Need | Document |
|---|---|
| What the kernel can do and what is missing | Roadmap — all 25 kernel libraries, component capabilities, Linux gaps, trust boundaries and release conditions |
| Priorities, dependencies and implementation handoff | Current nextplan — full September 12 rollover; both KSA and older open queues |
| Execution paths and crate graph | Architecture; capability availability is governed by the roadmap |
| Run tests and read reports | CI/testing guide, quality gates, scripts |
| Audit acceptance vs release readiness | Security status |
| Supported VT-d/platform modes | VT-d matrix |
| Experimental livepatch limits | Livepatch support |
| Stress failure history and open profile contracts | Stress-v2 historical record |
| Recent changes | Commit history |
The kernel runs static Ring-3/musl programs and has substantial MM/process/VFS/ network/SMP/security infrastructure. KSA-001..020 are accepted within their rubrics, and the QEMU EDU slice is accepted. Physical VT-d, full KPTI, compiler retpoline and production livepatch remain unqualified or unsupported.
1.0-Preview is blocked. R186-4 admission closure, historical review lineage, all-six stress acceptance and strict profile/full-audit conditions remain; the recorded clean-audit streak is 0/3. The roadmap and nextplan keep current counts and evidence limits together.
- Readable architecture: composition, layering, boot, syscall and component paths.
- Current design records: item-specific invariants, decisions, current-source amendments and acceptance oracles.
- Local historical references:
docs/overview/architecture/ARCHITECTURE.md,docs/overview/02-architecture/subsystems/anddocs/design/. These are maintainer archives, outside the files distributed by a normal clone.
| Collection | Purpose |
|---|---|
| Audits | Dated original findings, including KSA-2026-09-06 |
| Fixes | Repair ledgers, source/evidence handoffs and scoped reviews |
| Review-fix | Independent verdicts and repair acceptance |
| Nextplan archive | Full rollovers and historical status addenda |
| Standalone security records | R188 and other standalone investigations |
| Remediation archive | Historical debt inventories |
Local docs/overview/testing/ archive |
Older test expansion/coverage design |
Local docs/overview/06-security/safety/ archive |
IRQ/locking and primitive migration references |
| Fuzz investigations | Historical crash triage and filesystem evidence |
The security status and source ledger summarize the September 11 software acceptance and September 12 QEMU device evidence, retaining the original record identities. Archive indexes can be public even when their underlying local audit artifacts are not distributed.
Use one current capability inventory (roadmap) and one complete dated nextplan. Keep README/README_zh summaries aligned with them. Preserve source/evidence links, rejected or deferred capability boundaries and every open plan item. Use meaningful component/test evidence rather than file counts or lifetime audit totals as a maturity score.
Documentation-only updates require link/reference and consistency checks. Remote synchronization applies at relevant validation/handoff boundaries under the local project contract; it is not a per-edit dual-write rule. Commit/push follows user authorization.
CONTRIBUTING · GOVERNANCE · SUPPORT · SECURITY · README