Product Roadmap

The current direction keeps the Rust semantics stable while improving learnability, exact-source transport, request-bound evidence, and honestly bounded backend observations.

The stable center

Lispex is a small deterministic language for decision rules. Rust is the execution reference and supports all 205 tracked primitive capability rows. Exact Lispex Images reversibly carry the original source bytes, while Request-Bound Vouch can authenticate a declared context and—only on Native, with an external exact request—re-execute and reach a local decision gate. That Native path can explicitly add an exact source-derived compiled artifact and require the verified Rust VM to agree without dropping the tree/Meaning check.

The hosted interpreters keep explicit boundaries. Lispex-in-Lispex supports all 205 primitive rows in the current capability denominator; Lispex-in-Topaz supports 84 of 205. Unsupported LIT rows fail closed instead of borrowing behavior from the host. Complete LIL capability coverage is not a claim of whole-language equivalence.

How to read the direction

DirectionWhy it mattersA real completion signalNot promised
Learnabilitya capable language is useless if a new reader cannot write a first rulerunnable lessons, exact results, natural English/Korean/Russian, and tested navigationa large language, classroom platform, or hidden tutorial state
Deterministic product ergonomicsthe same semantics should be easy to install, inspect, and automateexact local products, stable diagnostics, and task-first Native/npm/WASM/Playground guidanceidentical resource ceilings on every surface
Exact-source workflowsreviewed source should survive visual transport byte for bytecanonical proof, exact recovery, explicit execution, and clear corruption failuressecrecy, signature, provenance, or authority from image appearance
Request-bound evidenceauthentication must not silently become permissionconsumer-owned source/input binding before Native re-execution and gatefreshness, replay prevention, policy correctness, or permission for an external action
Bounded backend growthanother implementation is useful only when its supported surface is measurablean explicit capability row, negative control, provenance, and receiptsilent fallback or a whole-language equivalence claim
Research evidencecomparisons should disclose their denominator and assumptionsnamed corpora, runners, observations, mismatches, and not-comparable casesproof by test count or a release-date commitment

Ordered portable-execution direction

The architectural outcomes are deliberately ordered. The stable profile now has complete LIL capability coverage, and Native can lower the complete normalized Core to canonical Core IR with resolved cells, explicit tail positions, primitive IDs, source anchors, cost identity, and one strict JSON byte representation. The public commands build, validate, and inspect that artifact without executing it or granting authority.

Native now compiles strict Core IR to canonical lispex.bytecode/v1, rejects malformed structure before execution, and runs the verified artifact in the explicit-control lispex-rust-vm/v1. The source route can select --engine vm; tree remains the default and VM never falls back. The focused tree/VM comparison records exact intermediate identities and semantic axes, while honestly labelling both routes as the same Rust lineage.

Vouch-bound compiled execution is now the bounded result of this sequence. Only lispex.vouch-compiled-artifact/v1, re-derived from the consumer's exact source after authentication and request binding, can add current verified Rust VM agreement to the existing tree/Meaning chain. Ordinary bytecode, compiler provenance, artifacts, and reports cannot promote themselves into authority.

Native now also admits the exact separately installed Topaz 5.11 lispex-topaz-vm/v1 product on macOS ARM64. The explicit Topaz bytecode route and compare-vms bind the provider product, request, result, exact bytecode and input identities, full-width u64 resources, and zero fallback. Rust remains the default, the Topaz transport is excluded from every Vouch constructor, and the comparison is bounded evidence rather than a proof of independent equivalence.

Native macOS ARM64 now also has the explicit correctness-first Lispex-to-Topaz AOT route. It emits readable Topaz and a source map from the verified static control graph, consumes only the exact installed Topaz 5.11 compiler, and installs a source-free product whose source, Core IR, bytecode, generated bundle, artifact, executable, resources, and zero fallbacks remain bound. It is execution material outside Vouch, not a new backend family or an equivalence proof. Native can now derive one request and issue a no-clobber diagnostic receipt across tree, Rust VM, exact Topaz VM, and the matching AOT product. Semantic and comparable-resource axes, lineage, and every fallback remain visible; the receipt grants no authority and does not turn four routes into four independent witnesses.

This closes the current portable AOT foundation. The next ready direction is a stable multi-route product: reduce operational friction around explicit products and receipts without changing defaults, hiding lineage, weakening exact-tool admission, or admitting Topaz into Vouch. It is ready for a future explicit checkpoint, not activated or assigned a version. Python, browser, direct WASM, optimization, and cross-compilation likewise remain evidence-gated directions rather than promised versions or dates.

What does not move casually

Language semantics do not change just to make a tutorial, backend, or artifact easier to implement. A genuine semantic change must update the runtime specification, Rust implementation, tests, receipts, and public explanation together. Exact Images remain a source representation—not a new datum or compiler—and Vouch artifacts remain evidence—not transferable authority.

Current boundaries

  • Roadmap directions are not assigned versions, dates, or staffing promises.
  • Rust, LIL, and LIT are separately labelled execution families; generated or packaged variants do not become independent witnesses.
  • The historical three-family receipt records 59 agreements across its 144 checked cases. That denominator must not be enlarged in prose.
  • A future backend or mechanized model closes only the surface and assumptions it explicitly names.

Keep going

Read Philosophy for the decisions behind these limits. Use History when you want the exact chronology of shipped capabilities.

Philosophy · History