History

A curated record of Lispex v1 from the first deterministic runtime through Exact Images, verified bytecode, Native Topaz AOT, and the four-route court.

How to reason about it

  • The initial v1 line established the deterministic reader, hygienic normalizer, trampoline evaluator, numeric profile, control model, standard-library floor, WASM build, and Playground before the first consolidated v1.2 tag.
  • v1.2 grew a second checked execution line around canonical Core, Meaning Graph, decision galleries, differential receipts, offline verification, replay, and mutation-tested evidence boundaries.
  • v1.3 turned that foundation into Lispex Vouch and Bridge workflows; v1.4 refreshed the shared native, npm, WASM, Playground, and download surface.
  • v1.5 published the bounded Lispex-in-Lispex and Lispex-in-Topaz execution lines, then built the first typed Vouch authentication, re-execution, and local-gate boundaries.
  • v1.6 assembled portable, exact-source-authorized Vouch tooling; v1.7 made every authority-bearing use bind a consumer-supplied source and input request.
  • v1.8.0 added byte-exact Lispex Images without letting image bytes mint authority. v1.8.1 rebuilt the Modern documentation as a beginner learning system, v1.8.2 separated normative profile membership from backend support, later checkpoints completed LIL's capability denominator, v1.8.14 added canonical resolved Core IR inspection, v1.8.15 added verified Native bytecode and the explicit Rust VM, v1.8.16 bound optional compiled VM agreement to request-bound Vouch, v1.8.17 added deterministic source formatting and editor integration, v1.8.18 admitted the exact installed Topaz 5.11 VM for explicit bytecode execution and Rust/Topaz comparison, v1.8.19 added a complete-profile Native Lispex-to-Topaz AOT route, and v1.8.20 joined the four explicit routes in one non-authoritative court.
  • v1.9.0 publishes that complete v1.8.x line as one portable-execution product without changing the language profile or the default Rust tree route.
  • Language, package, and artifact-contract versions are related but do not advance in lockstep.
  • The runtime profile owns evaluation behavior, while the named CSK and Vouch contracts own their artifact schemas. A matching package number alone does not establish artifact compatibility.

Meaningful v1 milestones

VersionMain changeBoundary
v1.9.0publishes the beginner learning system, LIL 205/205 convergence, canonical Core IR, verified bytecode and Rust VM, request-bound compiled Vouch, source formatting, and the explicit exact Topaz VM/AOT plus four-route court as one coherent productkeeps lispex-profile-1.5, Rust tree as reference/default, route-specific support and resource differences, zero fallback, and typed Vouch nonpromotion. It does not claim whole-profile proof or independent witnessing, change F7 defaults, or invent npm/browser/Playground compiled routes
v1.8.20adds Native compare-routes: one source/input frontend derivation, exact matching AOT admission, explicit tree/Rust VM/Topaz VM/AOT execution, and a no-clobber lispex.route-comparison/v1 receipt with semantic and comparable-resource mismatch axes. It repairs AOT primitive-call charging and structured resource faults, and deterministically finalizes macOS executables by recording exact strip/sign tool identities and rebinding the Topaz artifactpreserves every route and default independently, reports unavailable tree counters and genuine resource-diagnostic differences instead of normalizing them away, performs no retry, and grants no new backend-family, equivalence, Vouch-evidence, or gate claim. npm explicitly refuses the command; public WASM, browser, and Playground expose no substitute
v1.8.19adds complete-profile Lispex-to-Topaz AOT on Native macOS ARM64: deterministic readable Topaz and source maps, exact installed Topaz/Rust build-tool admission, and strict source-free product build, inspect, validate, and run with canonical full-width u64 resources, diagnostics, warnings, and five visible zero fallback counterspreserves lispex-profile-1.5, the Rust tree and VM recovery routes, the separate Topaz VM, npm/WASM/browser/Playground behavior, and every Vouch typed-authority boundary. The correctness-first AOT product is execution material, not a family receipt, equivalence proof, producer trust statement, or gate input
v1.8.18adds the explicit macOS ARM64 Native bytecode run --engine topaz --topaz-vm route for the exact installed Topaz 5.11 lispex-topaz-vm/v1 product and compare-vms receipts over one verified bytecode artifact; optimized Native builds also retain every Core IR and bytecode compilation operationRust remains the default. Lispex strictly binds product, request, result, bytecode/input identities, canonical full-width u64 resources, and zero fallback; failure never retries another engine. Topaz transport and comparison are diagnostic only, cannot enter Vouch or mint authority, and do not prove independent whole-language equivalence. npm, public WASM, Playground, other targets, and AOT expose no Topaz VM route
v1.8.17adds deterministic Native lispex fmt, quiet --check, safe --write, and VS Code/Open VSX Format Document integration while preserving comments, pragmas, tokens, and original literal spellingsformatting validates before output or replacement and changes atmosphere only; it does not execute, alter lispex-profile-1.5, canonicalize literal values, create evidence, or fall back to npm/WASM/Playground. Marketplace publication and production release remain separately authorized operations
v1.8.16adds canonical lispex.vouch-compiled-artifact/v1, Native vouch compiled build/inspect/validate, opt-in vouch verify --reexecute --compiled-artifact, and a compiled local gate requiring exact source derivation plus matching current tree/Meaning and verified Rust VM transcriptsthe consumer still supplies exact source and input, authentication and current tree/Meaning remain prerequisites, and no fallback exists. General bytecode, containers, hashes, reports, VM output, and compiler provenance cannot mint evidence or authority. The VM is the same Rust lineage, not an independent witness; npm, public WASM, and Playground expose no compiled Vouch surface
v1.8.15adds canonical binary lispex.bytecode/v1, strict pre-execution lispex.bytecode-verifier/v1, complete-profile lispex-rust-vm/v1, Native bytecode build/inspect/validate/run, explicit source --engine vm, and exact no-clobber tree/VM comparison reportstree remains the reference and default; requested VM work never falls back. Tree and VM share Rust values and primitive leaves, so comparison is same-lineage evidence rather than an independent backend or proof. npm, public WASM, and Playground provide no bytecode/VM surface, and bytecode, verifier output, VM results, or comparison reports cannot enter or grant Vouch authority
v1.8.14adds canonical complete-profile lispex.core-ir/v1 with stable 205-row primitive IDs, resolved lexical/global cells, exact closure captures and tail positions, source anchors, Canonical Core audit projection, and Native core-ir build, validate, and inspect commandsCore IR is non-executing integrity-only material from the same Rust lineage: it does not replace Meaning Graph, authenticate provenance, bind a request, prove independent agreement, or grant Vouch authority; npm, public WASM, and Playground expose no Core IR reader or facade
v1.8.13implements %, list-first, and list-rest in LIL with their exact W330/W331 compatibility warnings, raising current capability coverage from 202/205 to 205/205warnings occur only when the genuine deprecated primitive runs, stay ordered and deduplicated once per source call site, survive a later delegated error, and remain separate from stdout, values, and diagnostics; complete capability coverage does not claim whole-language equivalence, change Rust semantics or LIT, rewrite the historical receipt, alter Vouch authority, or grant production-release authority
v1.8.12implements display, write, newline, and println in LIL through a bounded private effect sink, raising current support from 198/205 to 202/205explicit output and top-level auto-print retain exact stdout order while completed root values use a separate typed projection; rendering, zero-value returns, partial output, and arity match the current profile with no host stdout or Rust fallback. Deprecated warning aliases, Rust or language-semantic changes, LIT changes, historical-receipt rewrites, Vouch authority changes, and production-release authority remain outside
v1.8.11implements all 12 remaining collection higher-order rows in LIL through explicit guest-machine continuation frames, raising current support from 186/205 to 198/205 and guest-calling coverage from 6/18 to 18/18callback order, strict boolean short-circuiting, single/discard value contexts, string character results, vector snapshots, errors, and one-shot escapes stay inside LIL with zero host callback or Rust fallback; output rows, deprecated aliases, Rust or language-semantic changes, LIT changes, historical-receipt rewrites, Vouch authority changes, and production-release authority remain outside
v1.8.10implements nine exact-intermediate division rows and gcd/lcm folds in LIL, and admits exact-integer expt plus two-value exact-integer-sqrt through the recorded numeric kernel, raising current support from 173/205 to 186/205floor/truncate signs, exactness contagion, domain faults, and multiple values match the existing profile; deprecated %, guest-calling rows, output rows, Rust or language-semantic changes, LIT changes, historical-receipt rewrites, Vouch authority changes, and production-release authority remain outside
v1.8.9admits exactness-preserving floor, ceiling, round, truncate, exact/inexact conversion, and integer parity through the recorded numeric host kernel, and implements mixed-tower min/max folds in LIL, raising current support from 161/205 to 173/205round remains half-to-even and exact recovers the finite binary value; the numeric-kernel lineage stays explicit, with no % or integer-division family, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.8admits 18 character/string case predicates, conversions, and case-insensitive ordering operations through LIL's explicitly recorded Unicode host kernel, raising current support from 143/205 to 161/205host-kernel lineage remains explicit; no full Unicode CaseFolding upgrade, locale collation, normalization, hidden fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.7implements list copying, lookup and shared-tail navigation, deterministic list/string constructors, and character-indexed string/vector conversion inside LIL, raising current support from 135/205 to 143/205no warning-bearing deprecated aliases, new host delegation or fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.6implements case-sensitive character and string ordering chains inside LIL using Unicode scalar and lexicographic order, raising current support from 127/205 to 135/205no locale collation, normalization, case folding, new host delegation or fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.5implements three finite-real tower predicates, structural !=, memv, assoc, assq, and assv inside LIL, raising current support from 119/205 to 127/205no new host delegation or fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.4implements abs, square, three sign/zero predicates, boolean=?, and symbol=? by composition inside LIL, raising current support from 112/205 to 119/205no new host delegation or fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.3implements all 27 previously missing composed pair accessors from caar through cddddr inside the Lispex-written LIL kernel, raising current LIL coverage from 85/205 to 112/205no host fallback, Rust or language-semantic change, LIT change, historical-receipt rewrite, Vouch authority change, or production-release authority
v1.8.2records all 205 current capabilities as normatively profile-required, separately classifies host-only and future-profile decisions, and gives every one of the 179 historical pair divergences one machine-checked primary reasonno language semantics, Rust/LIL/LIT support count, historical receipt byte, Vouch authority, image behavior, or production release boundary changes; classification does not mean acceptance or repair
v1.8.1rebuilds the Modern documentation as a four-step beginner course, Syntax at a Glance, ten globally numbered groups, and 53 production-final English, Korean, and Russian surfaces; Downloads adds exact version verification, command recovery, and official VS Code and Open VSX guidancedocumentation and product presentation only; Classic is byte-preserved, while lispex-profile-1.5, Rust/LIL/LIT capabilities, the image format, Vouch schemas, and typed authority remain unchanged
v1.8.0publishes exact Lispex Images as one same-Rust product across Native, npm, Node/browser WASM, and the local Playground, then lets a fully proved image supply the exact source bytes to the existing Request-Bound Vouch journeyimages preserve exact public source bytes and integrity commitments; they do not provide secrecy, signatures, provenance, independent witnessing, trust, freshness, request choice, decision correctness, or execution authority
v1.7.3lets a fully proved Lispex Image supply the exact source bytes for Native Vouch identity, policy, issue, inspect, authentication, re-execution, and gate, plus npm identity, policy, and authenticated verify; the maintained refund-window flow now uses image ingress end to endthe image chooses only a source representation; consumer-owned source/input binding and the existing typed authority chain remain mandatory, while PNG/ZIP, inspection JSON, bundles, and reports cannot mint authority
v1.7.2extends the one Rust image core to the npm CLI, Node/browser WASM, and a fully local Playground workflow with create/open, proved page navigation, exact recovery, download, and separate explicit run; cross-surface single/multipage bytes match the fixed C1 goldenssame-core byte parity is deployment parity, not an independent witness; local previews, inspection JSON, recovered source, and downloads are not Vouch evidence or authority
v1.7.1introduces canonical Lispex Images in Native: exact source-to-PNG/ZIP encoding, public commitment inspection, byte-for-byte decoding, and explicit execution only after full canonical proofimage canonicality is integrity, not secrecy, signature, provenance, trust, request binding, Vouch evidence, or execution authority; npm, public WASM, and Playground do not yet expose image operations
v1.7.0publishes Request-Bound Vouch as one consumer-owned journey: derive exact identities, create and check policy, issue a bundle, authenticate it against an optional external source/input request on Native or npm, then re-execute and gate only that live request on Nativeunpinned bundle verification remains authentication-only; request equality is not freshness, replay prevention, identity, provenance, policy correctness, or external-action authority
v1.6.4makes the verification-only npm Vouch WASM regenerate to the same tracked bytes from clean, dirty, or relocated source checkouts and keeps the standalone export-surface audit runnable from a clean checkoutthe fixed non-attesting build placeholder and virtual source path are not Git provenance or a reproducible-build claim for Native, browser WASM, or other platforms
v1.6.3Native bundle re-execution and gate require matching external source/input and pass only live request-bound evidence through re-execution to the grant; the localized documentation refresh adds the /v1.6 public-minor route namespace, Downloads, numbered current/Classic navigation, aligned document surfaces, concise browser titles, balanced responsive hero copy, a Korean 리스펙스 wordmark, and one readable locale-aware display-label system for landing eyebrows, form/data folios, results, pagers, and menu categoriesunpinned bundle verify remains authentication-only; request equality is not freshness, intent, or external-action authority
v1.6.2Native/npm pinned bundle verify authenticates first and then compares separately supplied exact source/input bytesexact request equality is not freshness, replay prevention, human intent, or external-action authority
v1.6.1Native/npm vouch key-id, engine-id, and input-id close public identity derivation beside source-id through shared Rustidentity is not provenance, trust, input validation, authentication, evidence, or execution authority
v1.6.0aggregates portable bundle v0, key-local exact-source policy v1, shared-Rust source-id and policy tooling, and raw/bundle authentication into one consumer-owned Vouch workflowsemantic profile and artifact schemas stay frozen; only Native issues, re-executes, or gates
v1.5.8Native/npm vouch policy create/check composes and validates canonical consumer trust policy v1 through shared Rustvalid configuration is not trust selection, authentication, evidence, re-execution, a decision grant, or external authority
v1.5.7Native/npm vouch source-id --source derives the exact bounded-byte source identity through the shared Rust corederivation is not source approval, policy generation, artifact trust, authentication, or evidence
v1.5.6trust policy v1 rejects a fully valid signed rule unless its exact source identity is allowed by the selected keyv0 remains source-unconstrained; no input/request approval, freshness, replay prevention, or transferable authority
v1.5.5bounded canonical envelope/source/input bundle with Native emission/consumption and npm authentication-only consumptiontrust/profile/decision remain external; WASM and Playground do not expose Vouch authentication
v1.5.4npm vouch verify authenticates signed Native envelopes and exact source/input/profile through a verification-only build of the shared Rust core, matching Native v0 report bytes and C-VN-06 outcomessame-core packaging parity, not an independent witness; npm cannot issue, re-execute, gate, expose live evidence, or promote a serialized report; public WASM and Playground do not export authentication
v1.5.3Native vouch gate --require-decision requires authentication, current complete-transcript agreement, and an exact decision match before returning a local grantNative-only local process result; serialized reports, Bridge, and authentication-only evidence cannot grant; no freshness, replay-prevention, identity, policy-correctness, deployment, or external-action authorization claim
v1.5.2namespaced Vouch workflow, maintained refund-window flow, LIL 85/205 capability boundary, and native vouch verify --reexecute with separate authentication and current-execution agreementre-execution is native-only and same-Rust-lineage; no historical-execution, freshness, independent-witness, authorization, policy-correctness, or whole-language-equivalence claim
v1.5.1native Vouch issuance: qualifying checked decisions can be constructed and signed as DSSE envelopes, then authenticated against a consumer-supplied trust policynative release binaries only; a valid signature authorizes a key for exact checked bytes but does not prove human identity, time, honest deployment, policy correctness, or broader semantic equivalence
v1.5.0bounded LIL and LIT execution lines, 84-of-205 capability ledgers, a three-family joint receipt, and coordinated native/npm/WASM/Playground distribution59 of 144 cases agree across all three families; 179 pair divergences remain disclosed; no whole-language or LIT source-independence claim
v1.4.0runtime and distribution refresh: apply and multiple-value paths in the checked evaluator, bounded receipt fuel, native/npm/WASM/Playground alignment, and pinned native downloadsprevious public release; native and WASM remain the same Rust lineage
v1.3.11canonical Bridge read-side acceptance, closed-world nested checks, linked artifact and optional context checksnative canonical-reader hardening remained deferred
v1.3.10adversarial artifact-class checks and explicit authenticity non-goalsno signing, issuer binding, timestamping, or non-repudiation
v1.3.9twelve-case welfare-style replay evaluation corpusworked evaluation artifact, not a legal or policy model
v1.3.8Vouch Bridge report shape, offline checker, and external-engine examplechecker does not run or prove the external engine
v1.3.1-v1.3.7closed the usable Vouch loop: native receipt generation, release-build engine identity, offline verify, versioned replay corpus, and an explicit authenticity boundaryVouch records declared execution and byte bindings; it does not add signing or issuer trust
v1.3.0checked-profile decision receipts, offline verify, replay, and release gatesbounded checked profile, not a whole-language correctness claim
v1.2.15-v1.2.19external Scheme-oracle ledger, authored semantic vectors, strict artifact readers, tamper fixtures, and mutation drillshardening and measured evidence; not proof of complete Scheme compatibility
v1.2.14expanded the checked decision profile and gallery with search, rounding, any/all traversal, strict faults, and clearer replay ergonomicsprofile execution, not the whole Lispex language surface
v1.2.9-v1.2.13checked-profile boundary, intrinsic binding, control/arithmetic gallery, closures and traversals, host-input binding, npm offline verify, and replay UXlanded as one consolidated baseline; intermediate numbers were contract milestones rather than separate tags
v1.2.2-v1.2.8versioned canonical Core, execution receipt, conformance manifest, Meaning Graph and lowering, separate Meaning Environment evaluator, and differential receipt contracta checked subset and artifact line alongside the reference interpreter, not a replacement for it
v1.2.0first consolidated v1 tag; added recoverable raise, guard, and with-exception-handler semantics while shipping native, Node/WASM, Playground, and download pathsrecoverable handlers use the pinned Lispex control model, not host exceptions
Initial v1 implementation line (2026-06-28/29)deterministic reader, hygienic normalizer, trampoline evaluator, exact integer/rational plus finite-real profile, pinned rendering, one-shot upward call/cc, dynamic-wind, multiple values, proper-tail apply, broad R7RS-shaped procedures, WASM, and Playgroundnot a v1.0 or v1.1 release; these are dated implementation commits later consolidated into v1.2

A common mistake

The repository has no v1.0 or v1.1 release tags. “Initial v1 implementation line” is therefore a dated implementation milestone, not an invented release.

Current boundaries

  • Backend claims remain bounded to their named capability rows, host routes, corpora, and receipts.
  • The chronology omits prose-only edits, CI churn, hash refreshes, review mechanics, and release rehearsals unless they changed a user-facing capability or a substantive verification boundary.
  • Historical receipt and Bridge changes do not imply new language semantics unless a release explicitly says so.

Keep going

Continue with the introduction for a practical entrance or History for the exact release-by-release record.

Introduction · History