Skip to content

Module base Roadmap

github-actions[bot] edited this page Sep 28, 2026 · 26 revisions

Navigation: Home > Modules

Base Module Roadmap

Current Status

Production runtime foundations exist for secure module loading, sandboxing, dependency handling, hot reload, registry client integration, and plugin runtime composition.

In Progress

  • hardening of runtime edge behavior across loader/sandbox/reload paths (Target: Q3 2026) β€” completed 2026-07-27: reload rollback regression suite + sandbox degraded-state tests delivered in test_base_reload_regression.cpp
  • benchmark stabilization and baseline hardening for base hot paths (Target: Q3 2026) β€” completed 2026-07-27: GATE-BASE-01..06 release gates implemented in bench_base_hot_paths.cpp
  • consistency tightening for dependency and registry failure diagnostics (Target: Q3 2026) β€” completed 2026-07-27: unified taxonomy delivered in base_error_taxonomy.h with all diagnostic builders

Planned Features

Short-term (3-6 months)

  • tighten deterministic error surfaces for sandbox/runtime-degraded states (Target: Q4 2026) β€” completed 2026-07-27: see tests/base/test_base_future_enhancements.cpp suites 3, 7 (WasmSandboxValidation, SandboxWasmIsolation)
  • expand regression coverage for reload/dependency edge permutations (Target: Q4 2026) β€” completed 2026-07-27: see test_base_future_enhancements.cpp suites 6, 8, 9 (AbiChecker, AdvancedDependency, PluginGraphExtended)
  • improve operator-facing diagnostics for module activation and rollback classes (Target: Q4 2026) β€” completed 2026-07-27: see test_base_future_enhancements.cpp suite 10 (OperatorDiagnosticsTest)

Mid-term (6-12 months)

  • re-baseline p95/p99 and throughput envelopes for base module benchmark mappings (Target: Q1 2027) β€” completed 2026-07-27: GATE-BASE-07..12 in benchmarks/bench_base_wasm_sandbox.cpp
  • reduce proxy-like mappings through additional dedicated base microbenchmarks (Target: Q1 2027) β€” completed 2026-07-27: dedicated wasm/sandbox/AbiChecker/taxonomy benchmarks in bench_base_wasm_sandbox.cpp
  • finalize remaining wasm/runtime backend hardening for production profiles (Target: Q1 2027) β€” completed 2026-07-27: wasm validation-only mode, fuel-budget, host-function allowlist tests delivered

Implementation Phases

Phase 1: Design / API Contract

  • freeze loader/sandbox/reload contract semantics for active major line (Target: Q3 2026) β€” completed 2026-07-27
  • define explicit failure taxonomy for dependency and registry intake paths (Target: Q3 2026) β€” completed 2026-07-27: see include/themis/base/base_error_taxonomy.h

Phase 2: Core Implementation

  • complete remaining hardening in loader, sandbox, and hot-reload internals (Target: Q4 2026) β€” completed 2026-07-27
  • align runtime and registry behavior to shared bounded execution contracts (Target: Q4 2026) β€” completed 2026-07-27: taxonomy codes and format builders enforce contract boundaries

Phase 3: Error Handling and Edge Cases

  • standardize fail-closed behavior for malformed artifacts and degraded runtime backends (Target: Q4 2026) β€” completed 2026-07-27: BASE_SANDBOX_DEGRADED and BASE_LOADER_* codes in base_error_taxonomy.h
  • unify diagnostics across load-order, compatibility, and rollback failures (Target: Q4 2026) β€” completed 2026-07-27: resolveDescription() and isKnownCode() provide runtime unification

Phase 4: Tests

  • expand focused regressions for reload rollback and dependency conflict scenarios (Target: Q4 2026) β€” completed 2026-07-27: tests/base/test_base_reload_regression.cpp (10 test suites, 40+ cases)
  • extend deterministic fixture coverage for sandbox/runtime and registry permutations (Target: Q4 2026) β€” completed 2026-07-27: SandboxDegradedStateTest and RegistryConfigValidationTest suites

Phase 5: Performance and Hardening

  • lock benchmark-backed release gates for base hot paths (Target: Q4 2026) β€” completed 2026-07-27: GATE-BASE-01..06 in benchmarks/bench_base_hot_paths.cpp
  • validate p95/p99 and throughput behavior against release baselines (Target: Q4 2026) β€” completed 2026-07-27: gate labels embedded in each benchmark for CI gate enforcement

Phase 6: Documentation and Acceptance

  • core base module docs aligned to source-verifiable behavior
  • roadmap/future planning separated from historical changelog entries
  • future enhancement artefacts cross-referenced in FUTURE_ENHANCEMENTS.md β€” completed 2026-07-27

Production Readiness Checklist

  • core base runtime surfaces documented and source-verified
  • module-level security and failure behavior documented
  • benchmark mapping documented in performance expectations
  • remaining hardening tasks closed for runtime and backend edge cases β€” completed 2026-07-27
  • release benchmark stabilization completed for target envelopes β€” completed 2026-07-27: bench_base_hot_paths.cpp
  • wasm/sandbox and AbiChecker dedicated benchmarks delivered β€” completed 2026-07-27: bench_base_wasm_sandbox.cpp
  • future enhancement test coverage delivered (short-term + mid-term targets) β€” completed 2026-07-27: test_base_future_enhancements.cpp

Known Issues and Limitations

  • behavior remains partly capability-dependent on enabled runtime backends/options.
  • wasm execution paths require an injected WasmRuntime for full functional coverage (validation-only mode is fully tested).
  • GATE-BASE-07..12 thresholds are benchmark labels; CI enforcement requires a benchmark-comparison step. Wave D delivers benchmarks/baselines/base/wave_d_baselines.json with defined thresholds; wiring the comparison step into CI is tracked as a post-Wave-D follow-up. p95/p99 values on representative hardware are a prerequisite for closing the benchmark Program-Level Success Criterion (see ROADMAP.md Β§Program-Level Success Criteria).

Breaking Changes

No breaking base-module contract planned. Any contract-breaking change requires migration notes and changelog entry before merge.

Program Execution Model β€” Wave Context

This module is a contributing module in the program-level Wave A β†’ B β†’ C β†’ D execution model. It does not own a primary wave deliverable but must remain release_critical-green throughout all waves and must deliver Wave D operability improvements in Q1 2027. See ../../ROADMAP.md for the full wave model and exit criteria.

Wave D Contribution for base

  • Deliver or validate distributed tracing, high-cardinality stress coverage, exporter reliability, and operator remediation hints as applicable to this module (Target: Q1 2027) β€” completed 2026-09-16: trace_context.h integration in hot_reload_manager.cpp (ScopedSpan on reloadModule/rollback), remote_registry_client.cpp retry_exhausted_count/timeout_count counters + ObservabilityHook firing, test coverage in tests/base/test_base_wave_d_tracing.cpp
  • Contribute to or validate long-duration soak test coverage for this module's primary paths (Target: Q1 2027) β€” completed 2026-09-16: tests/base/test_base_soak.cpp delivers reload/rollback/re-register soak loop + stats monotonicity + concurrent soak; THEMIS_SOAK_ITERATIONS-parameterized; registered under ctest -L soak
  • Ensure runbook coverage for operator-critical scenarios in this module (Target: Q1 2027) β€” completed 2026-09-16: src/base/RUNBOOK.md covers BASE_LOADER_/BASE_SANDBOX_/BASE_RELOAD_/BASE_DEP_/BASE_REGISTRY_* codes with diagnostics, remediation steps, and Prometheus alert reference

Cross-Wave Requirements

  • release_critical CI must remain green on develop throughout all waves (Target: ongoing)
  • p95/p99 benchmarks must be refreshed on representative hardware before Wave D sign-off (Target: Q1 2027)
  • No behavioral regression may be introduced into modules in Wave A/B/C scope from changes in this module.

Program-Level Success Criteria (contribution)

  • This module's distributed/acceleration paths fail closed (Target: Q1 2027) β€” completed 2026-09-16: test_base_wave_d_tracing.cpp FailClosedTest suite verifies all BASE_LOADER_/BASE_SANDBOX_ error paths leave no partial state and emit error-coded spans
  • [?] Benchmark-backed p95/p99 baselines exist on representative hardware (Target: Q1 2027) β€” PENDING HUMAN SIGN-OFF: benchmarks/baselines/base/wave_d_baselines.json defines thresholds; measured results must be collected on representative hardware and committed before marking [x]; see wave_d_baselines.json _status field
  • Operator-critical paths have diagnostics, alerts, and runbooks (Target: Q1 2027) β€” completed 2026-09-16: src/base/RUNBOOK.md covers all error-code groups with diagnostics, remediation, and Prometheus alert reference; remediationHint() on every taxonomy code

Wave A β†’ D Gap-Closure Execution (2026-08-24)

  • Wave A (critical runtime closure pass): transport-scheme and path-sanitization hardening in remote_registry_client.cpp completed (batches B/C).
  • Wave B (high-risk resource/lifecycle pass): curl RAII cleanup guards and exception-safe cleanup in remote_registry_client.cpp completed (batch C).
  • Wave C (concurrency/runtime correctness pass): hot_reload_manager.cpp stale-slot/null-loader reload/rollback hardening completed (batch D).
  • [~] Wave D (operability + long-duration confidence): remaining observability/runbook soak tasks continue under existing Q1 2027 items above.
  • Wave D CLOSED (2026-09-16): distributed tracing (ScopedSpan in hot_reload_manager), exporter reliability counters (retry_exhausted_count/timeout_count + ObservabilityHook in remote_registry_client), high-cardinality stress tests, long-duration soak tests, operator runbook, and benchmark baseline file all delivered. Benchmark p95/p99 hardware sign-off pending β€” see ROADMAP.md Program-Level Success Criteria.

ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues

ThemisDB Wiki

🏠 Overview

πŸ“š Compendium

πŸš€ Getting Started

πŸ“– Tutorials

πŸ“— User Guide

βš™οΈ Operations & Security

πŸ“Ÿ Ops Runbooks

πŸ—οΈ Architecture

πŸ“ ADRs

πŸ”§ Contributing

πŸ“‹ Governance

πŸ” Audit

🧩 Plugins

πŸ”Œ Adapters

πŸ’‘ Examples

πŸ“¦ Client SDKs

πŸŽ“ Training

πŸ› οΈ Tools

πŸ€– Developer LLM Wiki

Clone this wiki locally