# Tether Readiness Matrix

> **Canonical snapshot: 2026-08-31.** All facts below are VERIFIED from source files in
> `/Users/hanifibozok/tether`. This file is the one-page truth for anyone asking "is Tether
> ready?" — it does not forecast. When a fact changes, update this file in the same turn.

---

## 1. Module Inventory

64 Python source modules in `src/`. Status reflects VERIFIED test coverage and
implementation state as of 2026-08-31.

### Core Engine (dispatch, offload, routing)

| Module | Class | Status |
|---|---|---|
| `tether_cli` | CLI entry point, `--auto` dispatch, `--status` rendering | VERIFIED (145+ affected tests pass) |
| `tether_offload` | Remote execution spine, host selection, fallback | VERIFIED (host-bound dispatch shipped) |
| `tether_route` | Command routing / shim decision | VERIFIED |
| `tether_offload` (shared) | — | — |
| `tether_boost` | Boost logic | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_boost_cli` | Boost CLI | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_boost_ollama` | Ollama boost adapter | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_shard` | Sharding logic | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_pipeline_depth` | Pipeline depth analysis | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_predictor` | Runtime prediction | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_testparse` | Test output parsing | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_specsafe` | Spec safety checks | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |

### Spec / Shell / Pool / Shim

| Module | Class | Status |
|---|---|---|
| `tether_spec` | Spec CLI | VERIFIED |
| `tether_shell` | Interactive REPL | VERIFIED |
| `tether_pool` | Pool management CLI | VERIFIED |
| `tether_shim` | Transparent shim layer | VERIFIED |
| `tether_init` | Onboarding / init | VERIFIED |
| `tether_surprise` | Borrow CLI | VERIFIED |
| `tether_adapter` | Adapter interface | VERIFIED |
| `tether_manifest_adapter` | Manifest adapter | VERIFIED |
| `tether_worker` | Worker logic | VERIFIED |
| `tether_action` | ActionSpec / ActionResult | VERIFIED |

### Broker / Admission / Campaign

| Module | Class | Status |
|---|---|---|
| `tether_broker` | Broker CLI | VERIFIED |
| `tether_admission` | Admission CLI | VERIFIED |
| `tether_resident_campaign` | Resident campaign CLI | VERIFIED |
| `tether_ffmpeg_crossover` | FFmpeg crossover CLI | VERIFIED |

### Warm Session / Runtime Stats / Shadow

| Module | Class | Status |
|---|---|---|
| `tether_warm_session` | Warm session management | VERIFIED |
| `tether_warm_cli` | Warm CLI | VERIFIED |
| `tether_broker_warm` | Warm broker | VERIFIED |
| `tether_warm_job` | Warm job management | VERIFIED |
| `tether_warm_doctor` | Warm doctor | VERIFIED |
| `tether_warm_request` | Warm request handling | VERIFIED |
| `tether_warm_attach` | Warm attach | VERIFIED |
| `tether_warm_census` | Warm census | VERIFIED |
| `tether_runtime_stats` | Runtime statistics | VERIFIED |
| `tether_shadow` | Shadow observer (host-bound p95 evidence) | VERIFIED (aa5b611, b052e7c) |

### Audit / Transport / Dispatch

| Module | Class | Status |
|---|---|---|
| `tether_d1_audit` | D1 audit | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_endpoint_dispatch` | Endpoint dispatch | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_egv_stream` | EGV stream | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_egv` | EGV logic | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_pta` | PTA | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_rlspe` | RLSPE | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_naita` | NAITA (proxy-detour fix) | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED (992234a) |
| `tether_ast_hash` | AST hashing | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_cstc` | CSTC | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_jail` | Jail logic | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_arm_b` | ARM-B | UNIT-VERIFIED / NOT PRODUCT-INTEGRATED |
| `tether_version` | Version info | VERIFIED |

### Fabric v1 (Tasks 1-8, all VERIFIED local)

| Module | Class | Status |
|---|---|---|
| `tether_fabric_receipts` | Strict signed HMAC-SHA256 receipt contracts | VERIFIED (Task 1, 36 tests) |
| `tether_fabric_store` | Private pairing keys, atomic receipt publication | VERIFIED (Task 2) |
| `tether_fabric_platform` | OS-neutral capacity probes (Darwin/Linux/Windows) | VERIFIED (Task 3) |
| `tether_fabric_node` | Peer identity/capacity/terminal execution envelope | VERIFIED (Task 4) |
| `tether_fabric_qualify` | Preregistered qualification campaign, never-regress gate | VERIFIED (Task 4) |
| `tether_fabric` | Receipt intersection, aggregate snapshot, usable_now | VERIFIED (Task 5, 36 tests incl. real Chromium DOM) |
| `tether_fabric_scheduler` | Deterministic scheduler, kill switch, fail-local | VERIFIED (Task 8, 24 core + 94 expanded) |
| `tether_fabric_cli` | `pair`/`ingest`/`qualify`/`status`/`revoke` CLI | VERIFIED (Task 5) |
| `tether_fabric_transport` | Signed exactly-once transport (paired-HMAC) | VERIFIED (Task 7, 55 transport/node tests) |

---

## 2. Goals (G1-G6)

| Goal | Rung NOW | Evidence | Next |
|---|---|---|---|
| **G1 — Never-Regress Auto Mode** | Per-class evidence table: every adopted class carries its own passing p95 record | VERIFIED: first `would_adopt: True` on real evidence (5f910bf); host-bound revocable dispatch shipped; exec-local measurement gap closed (Darwin `EVFILT_PROC`); 399 passed + 6 subtests | Never-regress holds across **classes**, not one key |
| **G2 — Measurement Honesty** | Every number a user/agent reads carries provenance inline (source, method, timestamp, sample count) | VERIFIED: stale snapshot killed (m1 456→58ms); shadow mirrors dispatcher rank; capacity age explicit, authority fails closed; shadow 52 passed + 2 subtests; 94 passed + 2 subtests | Machine-readable consumers reject missing/malformed provenance by schema/version |
| **G3 — Borrowed Capacity That Earns** | Sync-bytes term in the gate math | PARTIAL: legacy `mac-studio-2` adopted-auto shows real 1.40x parallel-width win; signed Fabric Task10 real journey is still INCONCLUSIVE pending execution-receipt return | Gate predicts observed total within stated error bar on all three sweep classes; says "I don't know" when it cannot |
| **G4 — Evidence Discipline** | Hold it: RED before GREEN, blast radius before commit, real stdout/exit codes pasted, worker output = CLAIM until reproduced | VERIFIED: RED-first house standard; class-not-instance sweeps; green full-suite baselines; silent-rc0 killer root-caused and guarded | Mechanical pre-commit gate refuses src change whose touched-file tests did not run |
| **G5 — Platform Quality** | Every readable surface tells truth: `--status`, `doctor`, warm-doctor show real state with reasons | PARTIAL: `doctor` = `NOT_READY` (0/14 shims, `ready_for_activation: false`) — honest, not broken | `doctor` reaches READY on legitimately passed gates (real shim, real interception, promoted adapter, bit-exact crossover, seamless fallback) |
| **G6 — Continuity** | Tick is ON, SCOPE-FENCED, carries goals, fires in production | VERIFIED: SessionStart=command hook, Stop=agent hook; GATE 0 scope fence proven 5/5; head 5,582 chars, full tick 7,685 bytes; check-head cap enforced by construction | — |

---

## 3. Fabric Tasks 1-10

| Task | Description | Status | Evidence |
|---|---|---|---|
| 1 | Strict Signed Fabric Receipt Contracts | VERIFIED | 36 tests pass; HMAC-SHA256 round-trip, tamper, expiry, type-confusion |
| 2 | Private Pairing and Receipt Store | VERIFIED | Atomic publication, mode 0600, revocation |
| 3 | OS-Neutral Node Identity and Capacity Agent | VERIFIED | Darwin/Linux/Windows probes, unsupported-resource labeling |
| 4 | Qualification Campaign and Never-Regress Receipt | VERIFIED | Preregistered campaign, equivalence/fallback gate |
| 5 | Receipt Intersection, Fabric Snapshot, CLI/API, Web Evidence | VERIFIED | 36 tests incl. real Chromium DOM-vs-collector; Tasks 1-5: 316 passed |
| 6 | Native macOS Menu-Bar and Settings Surface | VERIFIED | 9 Swift + 5 bundle/process + 321 Fabric Python regressions; repeatable SHA `cc741652…105a75` |
| 7 | Signed Node Terminal Execution and Post-Side-Effect | VERIFIED | 55 transport/node + 250 load-gated; exactly-once CLI smoke; no real peer proof yet |
| 8 | Fabric Scheduler and `tether --auto` Integration | VERIFIED | Core 24, expanded 94, full Fabric Tasks 1-8: 364 PASS; scheduler 81% branch/store 82% |
| 9 | Packaging, Checkout Commands, Full Local Regression | GREEN | Clean wheel 14/14; current-byte full suite 3942P/8s/1xf/412 subtests rc=0; wrappers `bin/tether-fabric` and `bin/tether-fabric-node` live |
| 10 | Real Simultaneous Mac Acceptance + Cross-Platform Parity | MAC PASS / WINDOWS+LINUX BLOCKED | Generation `20260901T081436Z`: n=3 signed exact-output auto-win, p95 17.121s vs local 28.230s, shared native receipt state, telemetry, expiry fallback, visual evidence, zero residue. No authorized real Windows/Linux hosts yet. |

---

## 4. UI Surfaces

| Surface | Exists? | Works? | Missing |
|---|---|---|---|
| **CLI** (`bin/tether`) | YES | YES — VERIFIED end-to-end | Per-class evidence table (G1 NEXT) |
| **Status Dashboard** (`status-dashboard/`) | YES | YES — `index.html`, `app.js`, `styles.css`, `collect.py`, `favicon.svg`, evidence panel | — |
| **Native macOS App** (`apps/TetherStatus/`) | YES | BUILT — SwiftUI menu-bar + Settings; repeatable executable SHA verified | Manual visual acceptance not yet performed; not notarized |
| **Landing Page** (`web/landing/`) | YES | FINISH (U5) — no "demo"; baked feed snapshot (host `hbozok-US/tether-updates`, `stable.json` sha unknown / HTTP 404); Mac local-unsigned / Linux archive / Windows not yet | Consumer installer and signed public envelope still absent |
| **Login Page** (`web/login/`) | NO | RETIRED (U5) — PEER_ID form only printed a command; Tether has no accounts; real create/import lives in the Mac app | Do not add a fake login |
| **Onboarding / pairing steps** (`web/onboarding/`) | YES | FINISH (U5) — the Mac app's three PairingStep strings, one JSON source (`design/copy/pairing-steps.json`); no JSON-paste wizard | This page does not create invites |
| **Doctor** (`bin/tether doctor`) | YES | HONEST — `NOT_READY`, fail-closed, 0/14 shims | All 14 gates must legitimately pass before READY |
| **Installer** | NO | N/A | No installer exists (by design — checkout-based) |
| **Billing** | NO | N/A | No billing system (by design) |
| **Telemetry** | NO | N/A | No telemetry (by design) |
| **HK Deployment** | NO | N/A | No HK deploy (by design) |

---

## 5. Market Readiness Gates

| Gate | Criteria | Current State | Blockers |
|---|---|---|---|
| **ENGINEERING PREVIEW** | Owned-hardware preview; surfaces truthful; CLI + dashboard live | READY FOR CONTROLLED MAC PREVIEW | Checkout or local-unsigned only; not a consumer installer; doctor honestly remains NOT_READY |
| **ALPHA** | Real peer journey proven: connect → capacity → auto-win → disconnect-fallback, zero residue; per-class never-regress | MAC TECHNICAL GATE PASSED / USER ALPHA NOT READY | First Mac workload class passed; installer/updater, support diagnostics, and Windows/Linux parity remain open. Web pairing copy matches the Mac app; there is no account surface. |
| **BETA** | Cross-platform parity (Windows, Linux, server); installer or seamless onboarding; production hardening | NOT READY | No Windows/Linux peer proof; no consumer installer; account auth is intentionally absent (local `tether-fabric pair` only) |
| **GA** | `doctor` = READY; all 14 gates passed legitimately; notarized native app; HK deploy option; billing/telemetry decided | NOT READY | 0/14 doctor gates; native app not notarized; no HK deploy; billing/telemetry explicitly absent |

---

## 6. Prior Commitments

| Commitment | Status | Evidence |
|---|---|---|
| Fabric Tasks 1-8 VERIFIED local | DONE | 364 tests pass; compile, diff, static security clean |
| Task 9 packaging GREEN | DONE | Clean wheel 14/14; full suite 3942P/8s/1xf/412 subtests rc=0 |
| Task 10 simultaneous Mac acceptance | DONE FOR FIRST MAC CLASS | Generation `20260901T081436Z` passed all preregistered telemetry, receipt, performance, fallback, visual, and cleanup gates |
| `doctor` stays NOT_READY | HELD | 0/14 shims/interception/promotion; `ready_for_activation: false` |
| No installer, no billing, no telemetry, no HK deploy | HELD (by design) | Confirmed absent |
| HAN-FIRST prompt authority | IMPLEMENTED | Exact latest prompt persisted with UTC; stale heads not trusted |
| Sole-head crash takeover | IN EFFECT | All predecessor Tether windows/managers/workers closed/dead/non-authoritative |
| Reuse-before-invent law | ACTIVE | Top-50 ledger per category required before substantial implementation |
| Full-suite baseline | VERIFIED GREEN | 3495 passed / 8 skipped / 1 xfailed / 38 warnings / 410 subtests in 802.86s (log `/tmp/tether-fullsuite-hostsel-1787903171.log`, tree `6b57ed5`) |
| Fabric Tasks 1-8 full suite | VERIFIED GREEN | 3927 passed / 8 skipped / 1 xfailed / rc=0 |

---

*This matrix is a snapshot, not a forecast. Update it when facts change — never when hopes do.*
