This roadmap shows dependencies and product boundaries, not promised dates.
Now
- This manual describes Topaz 5.18.1 /
topaz-5.18. Its installed self-hosted compiler remains the default for supported current-language routes. - The installed
topaz lispex embed runcommand evaluates one bounded Lispex request through an exact component built into the Topaz binary. It has finite limits, explicit refusal, and no selector, discovery, download, callback, import, or fallback path. - The Rust compiler remains an explicit comparison, recovery, and compatibility path. Self-hosted by default does not mean that the Rust recovery chain has disappeared.
- Compiler, runtime, npm package, artifacts, documentation, and Playground continue to identify the same product. Existing native, Python, browser, HTTP, local-data, and binary-media application paths remain supported.
- Unsupported compiler selections fail instead of silently switching engines. Full platform and differential campaigns remain release-candidate work; ordinary changes use targeted checks.
- The installed native
topazexecutable includes the local stdio MCP server and its fresh no-capability worker attopaz mcp serve.
Next priorities
- Target 5.18 with bounded decision applications on every native target. The maintained package now declares exact Lispex rules, prepares each rule once, evaluates many inputs, stores and freshly replays unauthenticated consumer evidence, and reaches its semantic, aggregate, and deadline boundaries. It has also passed the normal npm installation path and run as a relocated native product after its source and compiler were removed. The exact 5.18 candidate source is now activated. The same source-free court must still pass on every supported native target before a public language profile can be selected. Python and Web remain explicit refusals rather than hidden fallbacks. The next gate binds the exact candidate commit through Topaz-owned containment and the fixed H1 ceremony, followed by I1-L, H1, and I1-C. Ordinary provider repository movement is not an input and does not pause Topaz development. Only an explicit owner-authorized versioned H2B offer opens optional intake review.
- Target 5.19 with complete-profile applications. The separate import-free complete-profile evaluator and its evidence have arrived and passed private intake and are retained privately, but they are not yet executable or admitted as a Topaz product. The next train adds exact native, Python, Raw Web, Worker, and managed-Web hosts for both profiles. The restricted decision profile remains the fixed default and is never widened in place.
- Target 5.20 only after exhaustive whole-compiler refactoring. After complete integration ships, every then-current part of the compiler written in Topaz enters repeated whole-tree audit and refactor waves. The train has no patch ceiling and continues beyond ninety-nine patch checkpoints if necessary. Candidate work cannot begin while any finding is actionable, deferred, unknown, unreviewed, or retained without owner adjudication, a concrete invariant, and an exact regression guard. Every accepted semantic change must close its specification, profile, implementation, evidence, and documentation surfaces. Topaz 5.20 becomes eligible only after two consecutive zero-finding audits over identical compiler bytes.
- Preserve release evidence. Every later release issues fresh admission and revocation records, keeps reused results visibly marked as reused, and periodically exercises the preserved recovery path.
Evidence boundaries
Primitive capability counts are not a denominator for whole-language conformance. Special forms, control behavior, values, failures, transcripts, diagnostics, resources, the host boundary, and receipts are tracked separately.
The installed bounded evaluator proves only its documented command, component, profile, inputs, limits, outputs, and supported platforms. It does not prove whole-language Lispex equivalence or add an independent semantic witness. LIT remains useful same-lineage regression and integration evidence and is still not a Topaz backend.
Product integration, Lispex semantic scope, and Topaz target support are tracked separately. A first-class native application does not by itself close the full Lispex profile, generated Python, browser, or MCP execution rows. Completed self-hosting and application milestones remain available in History.
Research
- Expand differential and fuzzing tools that find places where code generators misunderstand the language.
- Consider model checking or mechanized proofs only where there is a concrete artifact and a useful way to reproduce the result.
- Revisit direct WebAssembly compilation only if a measured product blocker justifies it. Keep broad optimizer work, async syntax, recoverable faults, grapheme APIs, user-defined templates, general host FFI, and new syntax outside the current plan.