The problems foreseen before building, ranked. Difficulty 1–5 (effort + unknowns); Risk = how much else breaks if it goes wrong. Problems actually hit while building are logged in the Problem Log as P-nnn; what is being worked on next is the Roadmap; the current state per area is Status.

Two id spaces

Until 2026-10-01 these rows were numbered P-01 … P-35, which collided with the Problem Log’s P-032 … P-035 (P-32 “git” here, P-032 “release-build observability” there). The ranking now uses R-nn everywhere in the vault; the log keeps P-nnn.

Status, as of Milestone 17 (2026-09-29): ✅ done · ◐ partly done (what is missing is said) · ○ open.

#ProblemDiffRiskState
R-01Core graph model + Source trait + query IR3very high◐ Node/Edge/Source/Query exist and every source uses them; not built: GraphView (query + watermark), node/edge properties, Source::subscribe (changes_since long-poll instead), the lifting rules in sources::lift — Graph-Native Model
R-02Folder source (native) + explorer panel2low✅ watched since Milestone 16
R-03JS interop protocol (eval + channel) on all webviews3medium✅ web, WebKitGTK, Android WebView (P-047 rules)
R-04Code editor with CodeMirror behind CodeEditorBackend3medium✅ splices since spec 018
R-05Extension API + static registry; built-ins as extensions3high◐ Extension trait (panels, commands, settings, flow libraries), tiers, permissions. Not built: moonkale.toml, activation events, when clauses, contribution points beyond panels/commands — and ui still hard-codes the catalogue (Extension Catalogue critique)
R-06tree-sitter index + wiki-link extraction3medium◐ native tree-sitter (arborium), wiki-links, Rust/Julia/Python symbols (Julia/Python only since the #16 fix, 2026-10-02); other languages, calls and references open
R-07Graph view v1: wgpu 2D, WebGL2/WebGPU, CPU layout, pick/popup4high✅
R-08SQLite + DuckDB sources + table editor3low✅ read-only
R-09Markdown editor: source mode, links, backlinks, local graph2low✅
R-10Remote source via api (web/mobile parity)3medium✅ token auth (M7), TLS (M11)
R-11Milkdown WYSIWYG behind RichTextBackend3medium✅
R-12Typst preview2low✅ no packages
R-13Terminal: PTY + xterm view + links2low✅ plus a Rust twin (M12)
R-14LSP client + local spawning3medium✅ full-document didChange still (issue #19)
R-15Graph DB sources: Ladybug, Falkor2low◐ LadybugDB (Linux only since M17, P-144); FalkorDB not started
R-16Cross-source edges + consistency4high○ needs projects (Projects and Sources)
R-17LLM gateway: providers, tool surface, policy, audit3medium✅ Claude Code, Anthropic, OpenAI-compatible, Ollama, mock
R-18Embeddings + hybrid search3medium✅ BM25 + brute-force cosine, in memory
R-19Postgres/Supabase, Turso sources2low◐ Turso embedded (M17, read-only); Postgres not started
R-20Remote LSP + remote terminal on api (security)4high◐ one token per server; the audit found gaps (Audit 2026-09-23); no accounts
R-21Stack-trace / AST → graph2low◐ traces; ASTs not
R-22GPU compute layouts; 100k+; desktop surface (P-001 Graph surface in desktop webview)5very high◐ Barnes–Hut on the CPU reaches 100k; surface plan A in use; GPU compute and the coarse tier (Case Selector) open
R-23wasmtime extension runtime + WIT world + permissions UI4high◐ JSON ABI v1 over core modules (ADR-0013 JSON ABI before components); no WIT, no UI contributions, no fuel limits (issue #4)
R-24Flow editor + Lux.jl codegen3medium◐ editor + codegen (M6); running the model with errors on blocks open
R-25Mobile: file access, collapsed shell, touch4medium◐ Android build, phone shell, gestures, touch drag; Storage Access Framework open (spec 028)
R-26TypeDB, HelixDB sources3medium◐ HelixDB embedded (M17, read-only, P-145); TypeDB not started
R-273D graph3low✅ planes per kind, orbit camera
R-28Browser-side WASM extensions5very high✅ Worker + SharedArrayBuffer, JSON ABI
R-29Rust-native backends (terminal → code → rich text)5research◐ terminal (M12) and code (M14) as opt-in twins; rich text none
R-30Collaborative editing (CRDT over the op stream)5research○
R-31Structured Typst / Excalidraw-in-flow4research○
R-32Git integration: status/diff, commit/log, history as a graph3medium✅ through the git CLI (not gix); no push/pull
R-33Entity log: events, fold, snapshots, checkpoints ↔ commits4high✅ JSONL per folder, compaction (M9); issue #17 open
R-34Presence: awareness, hub, desktop + web3medium✅ rooms, cursor lines, desktop hub client (M9)
R-35Windows / macOS / iOS builds3medium◐ CI builds Windows and macOS packages; a friend tests macOS; no iOS
R-36One store for internal state (settings, layout, history, sessions, index) instead of a dozen files, ready to sync4very high○ candidates in Milestone 17; comparison pending — Internal State, ADR-0014 One store for internal state
R-37The core as a library: ui without extension or driver dependencies, Workspace split into services, a server contribution point, reusable crates (graph renderer, core)4high○ planned — Milestone 18 - Library Refactor
R-38Security findings of the external audit (issues #1–#5, #7–#10, #18, #20)3high○ — Audit 2026-09-23, Security
R-39CI that runs the tests (none did until 2026-10-01)2high◐ ci.yml: fmt, layering rules, tests, clippy, wasm check, six browser suites; macOS/Windows/Android not tested in CI — Milestone 18 - Implementation Log
R-40Projects: several sources saved as a project, selector, sync4medium○ desired behaviour in Projects and Sources
R-41Writes to databases (OLTP) — every database source is read-only3medium○ announced after Milestone 17

Reading the table

  • What is left of the original top risks: R-01 (the model’s missing half), R-05 (the extension API’s missing half), R-16, R-20 and R-22. R-36 and R-37 are new and have the widest blast radius — every crate touches the state and the Workspace.
  • R-37 and R-39 come before new features: they are what makes the rest cheap to change. R-38 comes before any server is exposed beyond a trusted network.
  • Anything marked research has no committed date.