Gummy OS v1 — Calm Workspace
Gummy OS v1 — Calm Workspace
Gummy OS v1 is production complete at https://www.mygum.my/.
Shipped product
- Human-owned, local-first Gummy Box for projects, sources, results, history, imports, backups, and connections.
- Visual Composer with durable goal-first return journeys; Composer remains proposal-only and cannot execute work.
- Governed Productions and Master Control, with Make Production as the only Production-wide execution transition.
- Explicit Human, Actor, Agent, Mold, Lease, Grant, and runtime-principal separation.
- Calm Workspace, Living Collaboration, Command Center, saved workspace groups, and phone/desktop return journeys.
- Places, Returns, Receipts, immutable evidence, bounded imports, recovery, and rollback records.
- Provider-neutral runtime foundations without converting optional infrastructure into a shipped live capability.
Source and verification
- Accepted Phase 16.5 candidate:
ac9c5f61d5979531df7c5f9559bddb131a620613 - Phase 16.5 merge:
1bdd08a2c983b154a577fcf4e21e01034033bb53via PR #46 - Release-blocking phone correction: PR #48, preserving the accepted candidate in history
- Exact tagged and production-verified main:
7dace7c5fa472eec441e763e65e0b668f78286ca - GitHub Actions: candidate
30491169101,30491169166; final PR30503360593; final main30503641130; final cross-browser30503661570 - 204/204 Node tests
- 68/70 Chromium browser cases, with two explicit live-bridge skips
- 9/9 deep return journeys across Chromium, Firefox, and WebKit
- Zero automated accessibility violations across desktop, tablet, phone, Night, Day, and reduced motion
- Security gate: 404 source files scanned, zero source maps, zero server-only markers in the browser bundle
- 381 dependency packages audited, zero vulnerabilities
- Complete product-preservation, schema, fixture, brand, persistence, recovery, quarantine, migration, and bundle gates
Production attestation
- Vercel deployment:
dpl_4pkiVBNwjG16VaBmN6xu2Dkj2hC7 - Deployment URL:
https://gummy-cyakchmt3-mygummy.vercel.app - Source SHA:
7dace7c5fa472eec441e763e65e0b668f78286ca - READY:
2026-07-30T00:45:59.117Z - Canonical alias observed on the final source:
2026-07-30T00:46:41Z - Canonical URL: https://www.mygum.my/
- Apex policy: permanent redirect to the canonical host while preserving path and query
- Production endpoint, desktop, 390 px phone, and 320 px phone journeys passed
- Post-smoke Vercel inspection found no runtime errors and no warning/error/fatal logs
Truthful live-provider boundary
Live Google Agent Platform, Google runtime principals, Agent Identity, Memory Bank projection, provider telemetry ingestion, live MCP hosts/servers, MCP App execution, specialist live adapters, and background provider execution are not enabled or claimed in v1. Credentials for that optional work are absent. No active product capability depends on it.
Managed Box, Google Drive authority, hosted Gummy Rooms, social federation, enterprise habitat, billing, and marketplace remain outside v1. Exported .gummybox files are integrity-hashed but not encrypted or signed. Performance evidence is automated lab evidence rather than field Core Web Vitals.
Rollback identity
The documented clean rollback baseline is merged Calm Workspace main 1bdd08a2c983b154a577fcf4e21e01034033bb53 in Vercel deployment dpl_GWshoouUf6HqwmjWy75i8eMo6bzc. Rollback does not delete or rewrite Local Gummy Box data, accepted results, Returns, or Receipts. The immediately preceding release-record deployment dpl_9TErVFEScvFJrcctKFbjVRPDUS9Q at a219daa22e4ca2aea4fa56b2cfed3cda9b9da1fb is also retained.
Pick a candy. Make a world.