The stable center
Lispex is a small deterministic language for decision rules. Rust is the execution reference and supports all 205 tracked primitive capability rows. Exact Lispex Images reversibly carry the original source bytes, while Request-Bound Vouch can authenticate a declared context and—only on Native, with an external exact request—re-execute and reach a local decision gate. That Native path can explicitly add an exact source-derived compiled artifact and require the verified Rust VM to agree without dropping the tree/Meaning check.
The hosted interpreters keep explicit boundaries. Lispex-in-Lispex supports all 205 primitive rows in the current capability denominator; Lispex-in-Topaz supports 84 of 205. Unsupported LIT rows fail closed instead of borrowing behavior from the host. Complete LIL capability coverage is not a claim of whole-language equivalence.
How to read the direction
| Direction | Why it matters | A real completion signal | Not promised |
|---|---|---|---|
| Learnability | a capable language is useless if a new reader cannot write a first rule | runnable lessons, exact results, natural English/Korean/Russian, and tested navigation | a large language, classroom platform, or hidden tutorial state |
| Deterministic product ergonomics | the same semantics should be easy to install, inspect, and automate | exact local products, stable diagnostics, and task-first Native/npm/WASM/Playground guidance | identical resource ceilings on every surface |
| Exact-source workflows | reviewed source should survive visual transport byte for byte | canonical proof, exact recovery, explicit execution, and clear corruption failures | secrecy, signature, provenance, or authority from image appearance |
| Request-bound evidence | authentication must not silently become permission | consumer-owned source/input binding before Native re-execution and gate | freshness, replay prevention, policy correctness, or permission for an external action |
| Bounded backend growth | another implementation is useful only when its supported surface is measurable | an explicit capability row, negative control, provenance, and receipt | silent fallback or a whole-language equivalence claim |
| Research evidence | comparisons should disclose their denominator and assumptions | named corpora, runners, observations, mismatches, and not-comparable cases | proof by test count or a release-date commitment |
Ordered portable-execution direction
The architectural outcomes are deliberately ordered. The stable profile now has complete LIL capability coverage, and Native can lower the complete normalized Core to canonical Core IR with resolved cells, explicit tail positions, primitive IDs, source anchors, cost identity, and one strict JSON byte representation. The public commands build, validate, and inspect that artifact without executing it or granting authority.
Native now compiles strict Core IR to canonical lispex.bytecode/v1, rejects
malformed structure before execution, and runs the verified artifact in the
explicit-control lispex-rust-vm/v1. The source route can select
--engine vm; tree remains the default and VM never falls back. The focused
tree/VM comparison records exact intermediate identities and semantic axes,
while honestly labelling both routes as the same Rust lineage.
Vouch-bound compiled execution is now the bounded result of this sequence.
Only lispex.vouch-compiled-artifact/v1, re-derived from the consumer's exact
source after authentication and request binding, can add current verified Rust
VM agreement to the existing tree/Meaning chain. Ordinary bytecode, compiler
provenance, artifacts, and reports cannot promote themselves into authority.
Native now also admits the exact separately installed Topaz 5.11
lispex-topaz-vm/v1 product on macOS ARM64. The explicit Topaz bytecode route
and compare-vms bind the provider product, request, result, exact bytecode and
input identities, full-width u64 resources, and zero fallback. Rust remains
the default, the Topaz transport is excluded from every Vouch constructor, and
the comparison is bounded evidence rather than a proof of independent
equivalence.
Native macOS ARM64 now also has the explicit correctness-first Lispex-to-Topaz AOT route. It emits readable Topaz and a source map from the verified static control graph, consumes only the exact installed Topaz 5.11 compiler, and installs a source-free product whose source, Core IR, bytecode, generated bundle, artifact, executable, resources, and zero fallbacks remain bound. It is execution material outside Vouch, not a new backend family or an equivalence proof. Native can now derive one request and issue a no-clobber diagnostic receipt across tree, Rust VM, exact Topaz VM, and the matching AOT product. Semantic and comparable-resource axes, lineage, and every fallback remain visible; the receipt grants no authority and does not turn four routes into four independent witnesses.
This closes the current portable AOT foundation. The next ready direction is a stable multi-route product: reduce operational friction around explicit products and receipts without changing defaults, hiding lineage, weakening exact-tool admission, or admitting Topaz into Vouch. It is ready for a future explicit checkpoint, not activated or assigned a version. Python, browser, direct WASM, optimization, and cross-compilation likewise remain evidence-gated directions rather than promised versions or dates.
What does not move casually
Language semantics do not change just to make a tutorial, backend, or artifact easier to implement. A genuine semantic change must update the runtime specification, Rust implementation, tests, receipts, and public explanation together. Exact Images remain a source representation—not a new datum or compiler—and Vouch artifacts remain evidence—not transferable authority.
Current boundaries
- Roadmap directions are not assigned versions, dates, or staffing promises.
- Rust, LIL, and LIT are separately labelled execution families; generated or packaged variants do not become independent witnesses.
- The historical three-family receipt records 59 agreements across its 144 checked cases. That denominator must not be enlarged in prose.
- A future backend or mechanized model closes only the surface and assumptions it explicitly names.
Keep going
Read Philosophy for the decisions behind these limits. Use History when you want the exact chronology of shipped capabilities.