Skip to content

What to Expect

Honest assessment of Kunuleco's current state.


Current Alpha State

Kunuleco is functional but incomplete. The core architecture works. Many features are rough or missing.

Platform Support

Platform Status Notes
Linux x64 (Ubuntu 22.04+) Supported Primary development platform
Windows 10/11 x64 Supported Tested regularly
macOS Intel Experimental Builds, limited testing; Veilid is not available for macOS x86_64
macOS Apple Silicon Experimental Builds, minimal testing

Transport Status

Transport Status Issues
mDNS Working Requires same network segment. A sighting is only a hint, and the signed hello decides who the peer is
Veilid Working Installed and started by Urchin's setup; needs an accurate system clock
Tor Working Installed and started by Urchin's setup. Gives reachability, not location privacy
IPFS Impaired Stores the media you upload. The node reports it impaired for connections because peer discovery over IPFS does not work yet

What Works

Identity: - Create an identity with username and password, in the Urchin client - AIRO encrypted storage - A signed hello on every connection proves the peer's AID - Encrypted backup with export-identity and restore with import-identity

World: - Create and navigate rooms, zones and Halls - Create Capsules with capability access - Persist to SQLite - Restore on restart

Communication: - CapTP message exchange - Presences you can open or make invite-only with door - One-to-one messages with tell, kept in a history that survives restarts - Messages to offline friends wait in your outbox - Multi-transport failover


What's Incomplete

Capability validation: - Some Place methods ignore the capability they are given (registry CAP-04, open) - Security-sensitive operations may not be fully gated

Configuration: - The node reads only a few settings, from the installer's config.json and environment variables - Many settings are hardcoded - See Configuration

Identity: - There is no command to rotate a key yet - There is no password reset

Updates: - Updates are manual, from inside the client, with /check-updates and /update (everything) or /update client|kunuleco|veilid|tor|ipfs - /reinstall performs a clean reinstall when something is broken

Installer: - Windows/Linux: functional - macOS: builds but untested


Performance Expectations

No performance figures are published yet. Note what you see and include it in reports, for example how long a first join took and over which transport.

Startup time depends on the transports. Veilid and Tor can take a minute or more to become reachable after the node starts.


Stability Expectations

Will likely work: - Single-user, single-node operation - mDNS discovery on simple networks - Veilid connections once Veilid is running (@node_processes) - Basic CapTP messaging

May have issues: - Multiple rapid connections/disconnections - Network transitions (WiFi to ethernet) - Long-running sessions (>24h) - Corporate firewalls

Not yet reliable: - Capability delegation beyond a single grant - Recovery from partial transport failure - Handling of corrupted state


Known Limitations

Architectural

  1. One node, many accounts. The first account is the node's owner. Every later account needs a sponsor who holds the right to create accounts.
  2. Owner rights expire. The rights to create accounts and to run the node expire 90 days after they are granted unless the granter renews them with renew. The first owner's own grants do not expire.
  3. Offline messages wait. A tell to an offline friend waits in your outbox until they are back.
  4. No social recovery. Your safety net is an encrypted export made with export-identity.

Practical

  1. Desktop only. No mobile release yet.
  2. English only. No i18n yet.
  3. Minimal docs. You're reading what exists.
  4. Mixed versions. Both machines in a test must run the same release. A newer node can reach an older one over mDNS, but not the other way round.

Security Notes

Alpha software may have security issues.

  • Don't use for sensitive communications
  • Don't assume capability checks are complete
  • Tor gives reachability, not location privacy. A node reached over Tor sends its IPFS addresses in its hello
  • Live voice is not end-to-end encrypted
  • Choose a password you will remember, because nobody can reset it, and keep an export-identity backup

This is for testing, not production.


Changes to Expect

During alpha, expect:

  • Breaking changes. Data formats may change, requiring a fresh start
  • Missing features. Planned features not yet implemented
  • Bugs. Things will break
  • Rapid iteration. Fixes come quickly once reported

Next: Test Scenarios

Ready to start testing? See Test Scenarios.