# 0017: The product graduates on published GPUI, behind an accessibility adapter, and Floem is frozen Status: accepted. Supersedes the provisional direction in `UI_SPIKE_SCORECARD.md`. Until now the product was `spikes/gpui-shell`: a cargo workspace of its own, listed in the root manifest's `exclude`, so it inherited neither `unsafe_code = "forbid"` nor `clippy pedantic`, and `./scripts/ci.sh` never compiled it. Every test written into it silently never ran. That is the reason this record exists before any feature work: the sidebar, settings, and devices pages are all substantial new code, and writing them into an unlinted directory would mean writing them twice. ## The GPUI dependency The product ships on published `gpui 0.2.2` from crates.io, not on a Zed git revision. The scorecard's provisional direction was "GPUI-first using current Zed GPUI behind a narrow Lumbridge UI adapter", and that is being inverted here, so the cost is stated plainly: **published 0.2.2 has no AccessKit dependency.** There is no `Role`, no `aria_label`. Every pane and every sidebar row ships screen-reader-silent, and `UX_VERTICAL_SLICE.md`'s hard gate — "the accessibility tree names each pane, selected state, execution target, and waiting state" — is knowingly unmet. It is chosen anyway because a git dependency on an unpinned upstream, plus an MSRV move from 1.94 to 1.97.1 across every crate in the workspace, is a large standing cost to carry for a capability we can stage. The mitigation is a narrow `a11y` adapter trait, introduced now while there are few call sites: it no-ops on 0.2.2 and calls real roles and labels on a git revision. The migration is then a swap rather than a rewrite. `spikes/gpui-accessibility-probe` (Zed revision `ce48461e`, toolchain 1.97.1) is retained, not deleted, as the standing proof that the semantics compile with stable IDs and roles. Reversing this decision means changing one dependency line and one adapter implementation. The scorecard's `pending` row for GPUI's dependency-license closure stops being a spike question the moment 746 lockfile packages enter the root workspace: it becomes the product's license closure. `deny.toml` and `cargo deny check licenses` land in the same change, and the result is pasted into that row. ## Floem `spikes/floem-shell` is **frozen**. It is no longer described as a comparable candidate, and `ARCHITECTURE.md`'s "UI decision gate" and `TESTING.md`'s "identical GPUI/Floem action replay" line are corrected to match. Comparability was already gone and already conceded — the scorecard records that "the Floem shell still renders the static footer fixtures, so the two candidates are no longer comparable on that strip", which the usage ledger work caused. It also records Floem failing the accessibility gate outright, with no AccessKit at its pinned revision. Keeping true parity would mean theming it alongside every visual change forever, which is a recurring cost for a candidate that has already lost on a hard gate. Freezing rather than deleting keeps the evidence trail: if the GPUI bet ever needs revisiting, the comparison exists at the revision where it was made. What freezing does not license is leaving falsehoods on screen — its fabricated footer quota and its fixture worktree list naming a developer's machines were deleted in the same pass as the GPUI shell's. ## The default theme and accent The UI accent stays cool blue. `BRAND.md` scopes Ember (`#FF6B35`) to the application icon and warns against low-contrast orange behind the mark; `UX_VERTICAL_SLICE.md` commits the UI to one cool-blue action accent. Ember is offered as a user-selectable accent rather than made the default, so neither document needs amending.