Skip to content

Prepare Keld for external contributors and open-source applications #167

Description

@0monish

Keld is a public pre-alpha desktop framework. This program makes current capabilities, contribution paths, ownership and security controls understandable and verifiable. It does not claim completed Electron/VS Code migration, independent adoption or a release that does not exist.

Acceptance

  • README: what works today → try it → evidence → public roadmap → target; every current claim agrees with the product-status ledger.
  • Reproducible current source-build demo, accurate platform/capability matrix and compatibility evidence links.
  • Public Issues triage, Discussions, Code of Conduct, maintainer identity, contributor guide and changelog.
  • A visible keld-maintainers team, valid CODEOWNERS, private vulnerability reporting and explicit pre-release support policy.
  • Main requires PRs, CI, an independent approval and appropriate CODEOWNER review; no force push/deletion.
  • CodeQL and dependency review are exercised with accurate language/metadata limits.
  • Public follow-ups expose unfinished task prerequisites, benchmark provenance, compatibility examples and release readiness.
  • Independent testers/contributors contribute voluntarily; their genuine public activity is preserved. No manufactured activity.
  • Release, tags, notes, automation, checksums and supply-chain metadata ship only when an actual runnable distributable meets acceptance.
  • A stranger can identify the project, current scope, setup, maintainers and contribution route within five minutes.

Applicant/founding maintainer: @0monish, confirmed by the project owner. GitHub Issues is the public entry point; maintainers may retain internal coordination without requiring private accounts from contributors.

Execution

This is dependency-ordered work, not a request to implement every future feature. Dedicated child issues will carry scope, ownership and actual evidence. No release or application-readiness claim until the open prerequisites are met.

Internal coordination

Maintainer execution: KEL-177. Public scope, progress and acceptance remain visible here; contributors do not need access to the internal board.

Current progress — 2026-09-15

Keld remains pre-alpha. Governance, public onboarding, security CI, startup cancellation and the stock native-Close lifecycle correction have landed. The remaining rows stay open where named; this is not a release, broad Electron-compatibility or application-readiness claim.

Work Current evidence Next completion check
Public participation and account protection Issues/labels and Discussions are live; maintainer team and contribution/security routes are public; private vulnerability reporting, Dependabot, secret scanning and push protection were configured during the foundation program Genuine independent contributor/tester activity, not maintainer/agent-generated participation
Governance and contribution policy PR #183 merged as 937b172; public maintainer, contribution-intake and security-reporting ownership is on main Keep public ownership, appeal and reporting paths current as maintainers change
README, quick-start, platform matrix, roadmap, changelog PR #172 merged as 99e2998; the source-build path and current/target distinctions are on main Land the current stale-evidence wording refresh, then run the genuine newcomer five-minute check
CodeQL and dependency review PR #173 merged as f48c7d8; CodeQL covers Rust, JavaScript/TypeScript and Actions and dependency review is part of admission Keep scanner/action pins and coverage honest; a green scan is not a product/release claim
Windows acceptance Physical Windows source-build/window/Ctrl-C evidence remains on #174; stock native Close/cleanup/relaunch is separately qualified on the Windows 11 x64 capture Complete remaining strict-profile/release-platform acceptance; do not generalize the captured source/device
Linux lifecycle and startup PR #184 merged as 9ad7993. Stock native Close issue #176 is closed after PR #228 merged as 9eb54fb; exact candidate e498770 passed two Ubuntu 26.04.1 GNOME Wayland native-Close/relaunch runs Run the still-unproved X11/non-Debian/other-architecture and release-packaging rows only on their actual systems
External evidence and release Genuine follow-ups #177–#181 remain open. The lifecycle-example blocker for #178 is now removed because #176 is complete Genuine newcomer test; bounded lifecycle example; measurable compatibility corpus; reproducible benchmark provenance; only then consider an actual dev-preview distributable

Main protection and the independent approval requirement remain enabled. Merge decisions follow current repository policy and exact evidence; this status update does not turn agent or CI work into genuine external participation.
No alpha tag, binary release, universal compatibility score, or independent adoption metric has been manufactured. VS Code migration remains a future stress workload, not a current demo.

Activity

  1. added
    foundationOpen-source foundation readiness and its evidence
    on Sep 7, 2026
  2. self-assigned this
    on Sep 7, 2026
  3. amishabenramani commented on Sep 7, 2026

    @amishabenramani
    Member

    Windows acceptance preflight for the published docs candidate 8981b670ce1e865e9bdd8a5c640cae4932a9063a (PR #172), based on main dcc4676af16146c887e03e5dcbdd824032c10055:

    • Real Windows 11 25H2 x64, build 26200.9168; installed WebView2 152.0.4191.66; Rust/Cargo 1.97.1; Bun 1.4.0 (1.4.0+34cbb9a40). New isolated worktree, unchanged candidate sources.
    • cargo fmt --all --check: exit 0. Docker client 29.7.2 cannot connect to its Linux engine (docker version: exit 1).
    • Build/create/doctor/dev, native window, supervised Bun, shutdown output, descendant/stage cleanup, relaunch, workspace Clippy, full tests and just ci are unrun. An existing endpoint security prerequisite must be resolved by the designated security workflow before artifact creation/execution. This run does not establish a new detection or a product defect.
    • Windows desktop qualification remains awaiting. Installed prerequisites and formatting are not desktop proof; this is agent-run evidence, not independent human adoption. No runtime/test/permission changes or release work.

    Next completion check: program coordinator assigns the existing security prerequisite to an operator and obtains its source/environment-specific clearance; then the Windows acceptance owner executes the published commands and independent window/process/cleanup observations, followed by unchanged required gates. The current docs' Windows implementation row must not be interpreted as a completed acceptance result for this candidate.

  4. 0monish commented on Sep 7, 2026

    @0monish
    MemberAuthor

    Linux acceptance of docs candidate #172 at 8981b670ce1e865e9bdd8a5c640cae4932a9063a is incomplete. This is an agent-run physical-desktop check, not independent human adoption or release qualification.

    • Environment: Ubuntu 26.04.1 x86_64, kernel 7.0.0-31-generic, local GNOME/Mutter 50.1 Wayland; GTK 3.24.52, WebKitGTK/JSC 2.52.6, Bubblewrap 0.11.1, Rust/Cargo 1.97.1, Bun 1.4.2+744846f84. NVIDIA RTX 3050 Laptop / driver 595.84 is inventory only; no general NVIDIA qualification.
    • Exact source build, create and doctor exit 0. First dev exits 1 because a group-writable checkout ancestor (0775) fails strict launcher validation. Narrowing only the new checkout to 0700 permits launch; this prerequisite needs clearer documentation.
    • AT-SPI independently identifies the host-owned native frame and WebKit document/heading. /proc executable hash identifies actual Bun; socket peers establish native Wayland. No screenshot pixels are claimed because GNOME denied the capture API.
    • Native Close fails: it removes the renderer but leaves CLI/host/Bun and stage alive beyond an additional 20-second pidfd bound. The stock template waits indefinitely after echo; the Linux window loop emits LastWindowClosed and waits for Bun Quit. The scaffold/lifecycle owner needs a regression using an untouched generated app and native Close, followed by identity/stage cleanup assertions. Docs must qualify normal-close wording pending that proof.
    • SIGINT cleans all observed identities/stages and forwards both expected echo lines. Fresh launch also produces a new frame/Bun/echo and cleans up on early SIGINT, but additionally emits KELD-CORE-037: ... primary recovery arm — owner ended before acknowledgment; cancellation owner must triage this separately.
    • Format, warning-denied workspace Clippy, rustdoc, cargo-deny, TypeScript (41/41), status/corpus and structural documentation checks pass. Exact workspace nextest gate exits 100: 547 passed, 1 failed, 2 skipped, 29 not run. Failure is the Linux fixture's required Bun 1.4.0 versus installed 1.4.2. Next qualification run needs the pinned Bun in an isolated tool path; the assertion was not relaxed or retried.
    • just ci initially exits 1 with Docker stopped. After user-directed Docker Desktop startup, its API works and the immutable Mermaid image pulls, but the unchanged render gate exits 1 because its /tmp output is unshared. No sharing expansion or substitute renderer. CI/render owner must qualify an output path compatible with Docker Desktop's existing boundary.

    X11, headless CI desktop acceptance, other distributions/architectures and packaging remain separate. No runtime/test fixes, permission widening, migration or release work. Exact logs, hashes and OS/branch handoffs are retained under KEL-183; coordination and scoped-owner assignment remain with KEL-177.

  5. 0monish commented on Sep 7, 2026

    @0monish
    MemberAuthor

    Follow-up to the Linux acceptance report: two scoped fixes are published and awaiting review/integration.

    • fix(ci): keep Mermaid output inside shared checkout #182 (9180f70bfca0cc6e5de17c7ba71139acf4c45304) fixes Docker Desktop rendering with private output inside the validated shared checkout and rejects target symlink escapes. No Docker sharing, container-user or isolation changes. Final local full gate: 577 workspace passes / 2 existing skips; nine pinned diagrams render; exact-head hosted CI required passes.
    • fix(core): order initial recovery admission before shutdown #184 (0c69842b3950d575926a827a2c0bb1ab12246585, stacked on fix(ci): keep Mermaid output inside shared checkout #182) fixes initial Ready/recovery admission racing accepted shutdown. It queues admission under the existing transition guard and releases that guard before acknowledgment; genuine owner errors remain visible. The final combined local gate passes: 580 workspace tests, 2 existing skips, TypeScript41/41, format, warning-denied Clippy, docs and dependency gates. Hosted Ubuntu/macOS/Windows tests and CI required also pass.

    On the exact #184 source, physical Ubuntu26.04.1 x86_64 GNOME Wayland early-frame interrupt and rendered-frame relaunch/interrupt both show the actual host/Bun session, expected echo, all observed process identities exited, nonce stages removed and no earlier core error. These Linux observations do not substitute for physical Mac/Windows proof. Issue-local official Bun1.4.0 was used; the global runtime remains unchanged. Original failures and mutation controls are retained.

    Normal native Close remains open in #176. It requires the shared TypeScript transport/adapter decision; no copied parser, second handshake or blanket host-kill workaround was added. #172 now accurately documents that gap and the checkout/Bun prerequisites. Next maintainer actions are review/integrate #182, rebase/retarget #184 with fresh exact-head checks and required OS evidence, and resolve the shared-transport prerequisite before stock-close regression and product acceptance. No migration, packaging, release or broader GPU/platform claim.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

foundationOpen-source foundation readiness and its evidence

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions