Skip to content

Module server Roadmap

github-actions[bot] edited this page Sep 28, 2026 · 27 revisions

Navigation: Home > Modules

Roadmap-Hinweis: Vage Bullets ohne Akzeptanzkriterien in Checkbox-Tasks ueberfuehren. Format: - [ ] <Task> (Target: <Q/Jahr>).

Server Module Roadmap

Current Status

Production-ready server stack with HTTP/1.1, HTTP/2, HTTP/3, WebSocket, MQTT, PostgreSQL wire protocol, gRPC, GraphQL, and MCP integration. Core API gateway, auth middleware, validation, and observability paths are available in production deployments.

Wave Alignment (see root ROADMAP.md Β§ Program Execution Model):

  • Wave A (Q3–Q4 2026): HTTP timeout patterns, graceful-shutdown drain semantics, wire-protocol retry
  • Wave A Exit Criteria: Deterministic chaos evidence (timeout/shutdown) + fail-closed verification + release-critical CI GREEN
  • Wave B (Q3–Q4 2026): Cluster-wide distributed rate-limit state, GraphQL federation hardening
  • Tier 1 Criticality: Runtime-critical path; thread-safety and fail-closed guarantees are mandatory

Recently Completed

  • Source-integrity remediation for BPMN API handler completed (2026-09-07)
    • Removed compile-breaking token corruption in bpmn_api_handler.cpp history serialization path (push_back(event)), restoring source-valid response assembly for instance history queries.
  • Wave 4-A residual server runtime contract hardening batch (Completed 2026-08-31)
    • gRPC-Web status now exposes an explicit availability/operator contract via requests_supported, backend_mode, and fail-closed reason reporting for non-gRPC builds
    • RoPE DELETE /api/v1/vector-index/{index}/rope/config now performs real runtime disablement via VectorIndexManager::disableRotaryEmbedding()
    • Unsupported exotic-platform MCP stdio transport now self-disables unless a StdioReadFn is injected, instead of advertising a started-but-deaf transport
    • Time-series metadata endpoints now return explicit source and degraded_mode fields so builtin/storage fallback is visible to operators and tests
  • Phase 5 Server Hardening β€” P5-S01 Wire-Protocol Retry + P5-S02 HTTP Timeout/Shutdown β€” Completed Q3 2026 (Validated 2026-07-20)
    • P5-S01: Exponential-backoff retry gate with configurable max_retries, base_delay, budget cap, and optional jitter
    • P5-S01: Retry eligibility gating (kTransient only; kFatal/kInvalidArg fail-fast)
    • P5-S01: Per-request retry-count tracking with thread-safe reset; concurrent sessions validated (2 threads Γ— 8 retries)
    • P5-S01: 16 deterministic WSR test cases; all pass (test_server_phase5_hardening)
    • P5-S02: In-process server stub with per-request deadline enforcement (kTimedOut on overrun)
    • P5-S02: Graceful-shutdown drain logic (ServerState kRunning β†’ kDraining β†’ kStopped)
    • P5-S02: Idle-connection and keepalive-timeout recycling semantics
    • P5-S02: 12 deterministic HST test cases; all pass (test_server_phase5_hardening)
  • Voice API Bearer-Token JWT/OIDC Validation (#302) β€” Completed Q2 2026 (Validated 2026-07-19)
    • JWT signature validation using JWTValidator from JWKS
    • Token expiry (exp claim) checking
    • Issuer (iss claim) validation
    • Audience (aud claim) validation ("themis-voice-api")
    • Token revocation (JTI blacklist) support
    • Fail-closed rejection on any validation failure
    • Comprehensive test coverage for all validation scenarios
  • P0 security/code-quality remediation wave for server paths (Completed Q3 2026)
    • Status: 2,172 verified gaps identified and categorized (2026-06-25); 654 actionable (Critical + High severity)
    • Finish remaining true-positive triage from gap scan and remove residual high-risk findings from active code paths β€” Phase 1 Security/Auth Hardening complete; all scanner-confirmed high-severity auth/logging findings closed with SCH-01..SCH-20 regression tests in tests/server/test_server_contract_hardening_focused.cpp (Target: Q2 2026 β†’ Completed Q3 2026)
    • Consolidate auth enforcement checks for all routing-layer special cases and keep regression tests green β€” include/server/server_api_contract.h Β§2 Auth Gate Contract frozen; all 12+ error classes with fail-closed semantics; SCH-01..SCH-20 all pass (Target: Q2 2026 β†’ Completed Q3 2026)
  • Phase 5-S kickoff: wire-protocol retry/idempotency hardening batch (Target: Q3 2026 β†’ delivered Q3 2026)
    • Idempotency cache lookup now serves thread-local snapshots and lookupSnapshot() exposes by-value reads without exposing unlocked internal storage
    • Zero-window idempotency configuration fails safe by disabling retention rather than growing unbounded state
    • P5-S01: wire-protocol retry with exponential backoff (16 WSR tests PASS) and P5-S02: HTTP timeout + graceful-shutdown (12 HST tests PASS) β€” tests/server/test_server_phase5_hardening.cpp
  • GA Sign-off evidence bundling for delivered Phase-5 hardening (Target: Q3 2026 β†’ delivered 2026-08-04)
    • Residual-risk register for retry/timeout/shutdown release-critical paths documented in docs/governance/GA_PROMOTION_SIGN_OFF.md
    • release_critical regression proof on develop confirmed via .github/workflows/09-pr-gates_release-critical-tests.yml
    • Failure/recovery sign-off evidence linked into root gate board docs and FINAL_GA_READINESS_CHECKLIST.md

Planned Features

Wave 4-A: Server Integrity Gate + Audit Completion (Target: Q4 2026)

Source: gap-verifier subagent triage 2026-08-25 Β· Inflation factor ~8–10Γ— (~158 raw CRITICAL β†’ 15–20 real)
FP closed: model_integrity_gap (10 scanner hits) β€” SHA-256 gate already at llm_api_handler.cpp:981; scanner fires on dispatch line + every post-gate loadModel() call
FP closed: iterator_invalidation in query_api_handler.cpp (3 hits) β€” container identity confusion (parent vs visited), read-only loops; no real invalidation
FP closed: data_race local [&] lambdas (~15 hits) β€” function-local variables, single-threaded dispatch
FP closed: new_without_raii / smart_ptr_misuse in shard_repair_api_handler.cpp (5 hits) β€” JS new Date()/new Error() inside C++ string literals
FP closed: missing_audit_log in http_server.cpp + session_api_handler.cpp (7 hits) β€” route through requireScope()/requireAccess() with centralised audit at lines 10073-10081

  • Model Integrity Gate: CONFIRMED IMPLEMENTED β€” ModelIntegrityVerifier::verifyModel() called at llm_api_handler.cpp:981; manifest lookup, SHA-256 match, reject on mismatch; closed as FP (2026-08-25)
  • Iterator Invalidation: CONFIRMED FP β€” parent is read-only inside BFS loop; scanner mislabeled separate pathVisited container as parent mutation (2026-08-25)
  • integrity_gate_bypass (llm_api_handler.cpp:978): if (!path.empty()) silently skips SHA-256 gate when path absent; replace with HTTP 400 reject (Target: Q4 2026 β†’ Completed 2026-08-26)
    • Tests: empty-path model-load returns 400, non-empty path proceeds normally
  • path_traversal (llm_api_handler.cpp:967-969): user-supplied path not validated; add weakly_canonical() + model-store root escape check before verifyModel/loadModel (Target: Q4 2026 β†’ Completed 2026-08-26)
    • Tests: ../ path blocked, absolute path outside model root blocked
  • missing_audit_log (lora_api_handler.cpp): add THEMIS_INFO("[AUDIT] authorize result={} scope={}", result, scope) after authorize() on ALLOW+DENY branches (Target: Q4 2026 β†’ Completed 2026-08-26)
  • missing_audit_log (import_api_handler.cpp): same pattern (Target: Q4 2026 β†’ Completed 2026-08-26)
  • missing_audit_log (~3 small handlers): bpmn_api_handler.cpp, cache_admin_api_handler.cpp, entity_api_handler.cpp β€” [AUDIT] authorize result={} scope={} injected on ALLOW and DENY branches (Target: Q4 2026 β†’ Completed 2026-08-26)
  • mcp_server.cpp:2814: 4-field // STUB/SIMULATION NOTE for non-Linux Unix socket path / abstract namespace gap with removal plan Q2 2027 (Target: Q4 2026 β†’ Completed 2026-08-26)
  • Regression tests: tests/server/test_wave4a_server_hardening.cpp (8 tests) + tests/server/test_wave4a_server_hardening2.cpp (14 tests, labels: wave_a release_critical)

Note: prompt_injection (src/llm/docs_assistant.cpp:678) and deadlock_risk (src/llm/ai_orchestrator.cpp:264–289) are real CRITICAL findings in the LLM module β€” tracked in LLM ROADMAP, not server scope.

Wave 2-A: Security Hardening (Target: Q3 2026)

Source: MODULE_GAP_ANALYSIS_WAVE2.md Β§Wave 2-A, gap scanner verified 2026-08-25
Gap count: ~10 model_integrity_gap (CRITICAL), ~3 iterator_invalidation (CRITICAL), ~53 data_race, ~12 missing_audit_log

  • Model Integrity Gate: FP β€” already implemented (see Wave 4-A above)
  • Iterator Invalidation Fix in query_api_handler.cpp:1426,1959,2005: cycle guards added in Wave 2-A; deep pagination fix tracked in Wave 4-A (Target: Q3 2026 β†’ partial)
  • Data Race audit: llm_api_handler.cpp:407, query_api_handler.cpp:1575,1635 β€” fixed 2026-08-26 (Wave-7: call_once OOM guard, explicit lambda captures; see test_wave7_server_llm_hardening.cpp)
  • [~] Missing audit log: ~12 handler files β€” tracked in Wave 4-A (Target: Q4 2026)

Short-term (3-6 months)

  • Residual runtime gap: replace the build-without-gRPC fallback in grpc_web_proxy_handler.cpp with an explicit feature/operator contract so non-gRPC builds advertise fail-closed availability via the status endpoint instead of a silent always-UNIMPLEMENTED path (Target: Q4 2026 β†’ Completed 2026-08-31)
  • [~] Residual runtime gap: make aggregate and retention providers first-class production dependencies for the time-series metadata endpoints in timeseries_api_handler.cpp; explicit source/degraded_mode signaling is now delivered, but full DI wiring remains open (Target: Q4 2026)
  • Residual runtime gap: DELETE /api/v1/vector-index/{index}/rope/config now disables rotary embeddings at runtime, and the stats path already uses real rotation metrics from VectorIndexManager (Target: Q4 2026 β†’ Completed 2026-08-31)
  • Residual request-validation gap: replace validateJsonStub() in http_server.cpp for content-import, PKI-sign, and PKI-verify routes with explicit schema validation entrypoints (Target: Q4 2026)
  • [~] Residual SQL-wire safety gap: tighten prepared-statement parameter handling in postgres_session.cpp with typed validation and placeholder-safe binding while deeper protocol-level bind execution remains open (Target: Q4 2026)
  • Residual deployment gap: unsupported non-Linux MCP stdio transport in mcp_server.cpp is now explicitly self-disabled and documented unless a StdioReadFn is injected; native platform implementation still remains future work (Target: Q4 2026 β†’ Completed 2026-08-31)
  • Plugin-based server adapter loading with signature validation and rollback guardrails (Target: Q4 2026)
  • Cluster-wide distributed rate-limit state hardening for mixed-node latency profiles (Target: Q4 2026)
  • GraphQL federation and schema governance hardening for multi-service deployments (Target: Q4 2026)
  • HTTP/3 congestion-control and connection migration tuning under production-like packet loss (Target: Q4 2026)
  • MCP Tool Extension β€” Group 1: Knowledge Graph tools (kg_neighbours, kg_shortest_path, kg_subgraph, kg_node_properties) (Target: Q4 2026 β†’ Completed 2026-08-26)
    • Inputs: node_id, depth (1–5), edge_type filter, max_nodes; output: nodes/edges list + truncation flag
    • Backend: graph_api_handler; cycle-safe traversal; max 1000 nodes per call
    • Tests: 16 GTest cases (depth 1/2/3, cycles, non-existent nodes) in tests/server/test_mcp_kg_tools.cpp
    • Perf: p99 ≀ 200ms at depth=3, fan-out ≀ 50
  • MCP Tool Extension β€” Group 2: Vector/Hybrid/RAG tools (semantic_search, hybrid_search, rag_retrieve, vector_index_list) (Target: Q4 2026 β†’ Completed 2026-08-26)
    • Inputs: text query or raw float32 vector, top_k (max 200), collection, filter, threshold
    • Backend: vector_api_handler + LLMPluginManager (auto-embed); rag_retrieve returns ranked chunks with sources
    • Tests: 16 GTest cases in tests/server/test_mcp_search_tools.cpp
    • Perf: p99 ≀ 500ms at top_k=10, 100k documents
  • MCP Tool Extension β€” Group 7: Schema extensions (schema_diff, schema_validate, explain_query) (Target: Q4 2026 β†’ Completed 2026-08-26)
    • explain_query returns execution plan without executing; schema_diff compares two named versions
    • Backend: schema_api_handler, query_api_handler
    • Tests: integrated into existing schema test suite (test_mcp_search_tools.cpp)

Mid-term (6-12 months)

  • [~] Passwordless WebAuthn/FIDO2 auth integration for admin and API scopes (Target: Q1 2027)
  • [~] CPU- and memory-governed WASM execution hardening with stricter runtime policy envelopes (Target: Q1 2027)
  • [~] Service-mesh policy sync hardening and failover behavior validation under partition scenarios (Target: Q1 2027)
  • [~] MCP Tool Extension β€” Group 3: Plugin & LLM management (plugin_list/load/unload, llm_model_list, llm_model_status) (Target: Q1 2027)
    • plugin_load/unload require admin scope and synchronous signature validation
    • Backend: LLMPluginManager (already available via attachAIOrchestrator)
    • Tests: 12 GTest cases in tests/server/test_mcp_plugin_tools.cpp
  • [~] MCP Tool Extension β€” Group 4: Operations & Monitoring (health_check, metrics_snapshot, shard_status, compaction_trigger, connection_pool_status) (Target: Q1 2027)
    • compaction_trigger requires admin scope; all others require read scope
    • Backend: health_error_service, monitoring_api_handler, shard_repair_api_handler
    • Tests: 12 GTest cases in tests/server/test_mcp_ops_tools.cpp
  • [~] MCP Tool Extension β€” Group 5: Updates & Backup (update_list_pending/apply/rollback, backup_create/list/restore) (Target: Q1 2027)
    • backup_restore requires one-time confirm_token from backup_list; update error codes follow [7400-7499]
    • Backend: update_api_handler; rollback uses Updates-module isolation model
    • Tests: 16 GTest cases in tests/server/test_mcp_update_tools.cpp
  • [~] MCP Tool Extension β€” Group 6: Security & Audit (audit_log_query, permission_check, token_validate, security_scan_status) (Target: Q1-Q2 2027)
    • audit_log_query RBAC-filtered to caller scope; token_validate never returns token value
    • Backend: audit_api_handler, auth_middleware
    • Tests: 12 GTest cases in tests/server/test_mcp_audit_tools.cpp
  • Complete implementation spec: docs/de/apis/MCP_TOOL_EXTENSION_PLAN.md (Target: Q4 2026 β€” done)

Implementation Phases

Phase 1: Security and Access Hardening

  • Complete route-by-route auth gate audit for privileged server endpoints β€” frozen API contract: include/server/server_api_contract.h (Β§2 Auth Gate Contract, Β§6 Error Taxonomy, Β§8 Threading Guarantees) (Target: Q2 2026)
  • Close remaining scanner-confirmed high-severity auth/logging findings with regression tests β€” include/server/server_api_contract.h documents all 12+ error classes and fail-closed semantics; SCH-01..SCH-20 regression tests in tests/server/test_server_contract_hardening_focused.cpp (Target: Q2 2026)

Phase 2: Protocol and Gateway Hardening

  • [~] Improve HTTP/3 production behavior under migration/retransmit stress (Target: Q4 2026) β€” SH3-01..SH3-12 in tests/server/test_server_http3_stress_focused.cpp; benchmarks SVR-H3-01..SVR-H3-02 in benchmarks/server/bench_server_http3_gates.cpp
  • [~] Extend gateway resilience tests for quorum loss and split-brain protection paths (Target: Q4 2026) β€” SGR-01..SGR-12 in tests/server/test_server_gateway_resilience_focused.cpp

Phase 3: Validation and Contract Governance

  • [~] Strengthen OpenAPI/JSON-Schema drift detection for handler registration changes (Target: Q4 2026) β€” captureSpecSnapshot() + detectDrift() + DriftReport in include/server/openapi_route_registry.h; SOD-01..SOD-08 in tests/server/test_server_openapi_drift_focused.cpp
  • [~] Add stricter backward-compat checks for gRPC and REST versioning contracts (Target: Q4 2026) β€” CompatPolicy + CompatChecker + SchemaFieldDescriptor in include/server/api_version.h; SCC-01..SCC-07 in tests/server/test_server_compat_contract_focused.cpp

Phase 4: Tests and Reliability Gates

  • Expand integration and soak coverage for mixed protocol traffic (HTTP/gRPC/WebSocket/MQTT) β€” 20 deterministic GTest cases SCH-01..SCH-20 in tests/server/test_server_contract_hardening_focused.cpp covering auth, retry, timeout, rate-limit, and protocol contracts (Target: Q4 2026)
  • Add deterministic fault-injection tests for distributed rate-limit and fallback behavior β€” SCH-15 (distributed backend fail-closed), SCH-17..SCH-20 (protocol/quorum fault injection) in tests/server/test_server_contract_hardening_focused.cpp (Target: Q4 2026)

Phase 5: Performance and Operational Hardening

  • P5-S01: Wire-protocol retry with exponential backoff (2-3 retries + budget cap + jitter) β€” Completed Q3 2026
  • P5-S02: HTTP timeout patterns + graceful shutdown drain semantics β€” Completed Q3 2026
  • Re-baseline server latency/throughput gates with production-like payload mixes β€” 8 release-gate benchmarks SVR-01..SVR-08 delivered in benchmarks/server/bench_server_hotpaths.cpp (Target: Q1 2027)
  • [~] Add adaptive tuning recommendations for queue/backpressure settings by deployment profile (Target: Q1 2027)

Phase 1: Top-Risk Module Hardening (Retry/Timeout/Graceful-Shutdown/Recovery)

  • Implemented Consistent Retry Semantics (Target: Q3 2026)
    • SRV-01..08: Retry exhaustion & backoff scenarios (8 tests) βœ“
    • SRV-01: Retry exhaustion when max_retries exceeded
    • SRV-02: Immediate success (no backoff)
    • SRV-03: Recovery on second attempt
    • SRV-04: Exponential backoff validation
    • SRV-05: Global budget timeout enforcement
    • SRV-06: Zero-latency success path
    • SRV-07: Fatal error fails fast (no retry)
    • SRV-08: Transientβ†’Fatal mixed error codes
  • Implemented Graceful Shutdown & In-Flight Cleanup (Target: Q3 2026)
    • SRV-09..16: Timeout edge cases (pre/at/post deadline) (8 tests) βœ“
    • SRV-17..24: Graceful shutdown ordering (drain, timeout, health checks) (8 tests) βœ“
    • SRV-09: Pre-deadline completion
    • SRV-10: Exact deadline boundary
    • SRV-11: Post-deadline timeout detection
    • SRV-12: Zero-budget immediate fail
    • SRV-13: Large timeout remote future
    • SRV-14: Retry with cumulative budget
    • SRV-15: Cancellation early return
    • SRV-16: Timer-driven context deadline
    • SRV-17: Phase ordering (Idleβ†’Draining)
    • SRV-18: Phase ordering (Drainingβ†’Complete)
    • SRV-19: Phase ordering (Completeβ†’Done)
    • SRV-20: Clean drain (no active requests)
    • SRV-21: Drain with pending requests
    • SRV-22: Forced close on timeout
    • SRV-23: Pre-shutdown health checks
    • SRV-24: Shutdown phase transition logging
  • Wave-7 Regression Validation (Target: Q3 2026)
    • Verified latency gates hold (read p99≀200Β΅s, writeβ‰₯80k ops/s)
    • No performance regressions from retry/timeout logic
  • Created 39 Focused Tests (Target: Q3 2026)
    • SRV-01..08: Retry exhaustion & backoff (8 tests)
    • SRV-09..16: Timeout edge cases (8 tests)
    • SRV-17..24: Graceful shutdown ordering (8 tests)
    • SRV-25..31: Fault-recovery scenarios (7 tests) βœ“
    • SRV-32..39: Chaos/failure injection (8 tests) βœ“
    • SRV-25: Transient error recovery
    • SRV-26: Permanent error no recovery
    • SRV-27: Circuit breaker open
    • SRV-28: Circuit breaker half-open probe
    • SRV-29: Connection pool reset after recovery
    • SRV-30: Request timeout then recovery
    • SRV-31: Idempotent recovery retry
    • SRV-32: Connection failure injection
    • SRV-33: Latency injection (request slowdown)
    • SRV-34: Connection pool exhaustion
    • SRV-35: Request cancellation under chaos
    • SRV-36: Timeout under high load
    • SRV-37: Partial message loss
    • SRV-38: Quiescent shutdown under chaos
    • SRV-39: Recovery stabilization (eventual consistency)
    • All tests: Use themis_register_module_focused_test(), tier unit, timeout 120s
    • Registered with label: release_critical;server;phase1
  • Phase 1 Exit Criteria (2026-08-31)
    • 0 new CRITICAL findings in CodeQL
    • 39 focused tests created and passing
    • Wave-7 gates remain PASS (no regressions)
    • Retry/timeout exception-safety audits complete with documented contracts
    • Module-level ROADMAP.md updated with closure status

Phase 6: Documentation and Release Readiness

  • Keep server developer docs aligned with source and routing behavior after each hardening wave β€” include/server/server_api_contract.h freezes all handler registration, auth gate, retry/timeout/backpressure, error taxonomy, lifecycle/ownership, and threading contracts for v1.x (Target: Q2 2026)
  • Ensure completed roadmap items are moved only to CHANGELOG and not retained in roadmap history blocks β€” server ROADMAP Phase 1, Phase 4, Phase 5 checkboxes updated with evidence references (Target: ongoing)

Wave 9 Block 1 β€” gRPC Core Service Layer (2026-08-26)

  • W9-1 Create RPC β€” db_->put(collection:key, data) wired; optional TxnManager session (transaction_id β†’ stoull) for transactional writes; returns CreateResponse.key + timestamp
  • W9-2 Read RPC β€” db_->get(collection:key) wired; ReadResponse.document populated; 404 on miss
  • W9-3 Update / Delete / Scan RPCs β€” Update: create_if_missing guard + db_->put(); Delete: db_->del(); ScanCollection: db_->scanPrefix(collection + ":") streams ScanResult rows via grpc::ServerWriter
  • W9-4 Batch RPCs (BatchCreate / BatchRead / BatchUpdate / BatchDelete) β€” iterate documents/keys, apply each, count successes; GetStatus returns version + uptime
  • W9-5 Transaction RPCs β€” BeginTransaction/CommitTransaction/RollbackTransaction wired to TransactionManager::beginTransaction() / commitTransaction() / rollbackTransaction() with protoβ†’themis::IsolationLevel mapping
  • W9-6 AQL RPCs (ExecuteAQL + StreamQuery) β€” forwarded to aql_engine_->execute(query) with null-check returning gRPC UNIMPLEMENTED when no engine is wired; AQLEngine type alias resolved to themis::IQueryEngine in header
  • Tests β€” tests/server/test_grpc_core_service.cpp β€” 16 always-on source/API tests (GCS-01..GCS-16) + 13 full RPC tests under THEMIS_HAS_CORE_GRPC guard (GCS-17..GCS-29)
  • CMake β€” THEMIS_HAS_CORE_GRPC compile definition added to themis_core (PUBLIC) and themis_server (PRIVATE) in cmake/CMakeLists.txt; test_grpc_core_service registered in tests/CMakeLists.txt (W10-B, 2026-08-27)
  • Resolved: src/STUB_INVENTORY.md entries for server/themis_core_grpc_service.cpp marked complete; src/server/MODULE_GAPS.md UNIMPLEMENTED grpc items closed

Production Readiness Checklist

  • Status: Tracking in progress (last validated 2026-08-17)
  • Nachweise: Integration tests, focused protocol tests, and security regression suites
  • Hinweis: Abgeschlossene Arbeit wird ausschliesslich in CHANGELOG dokumentiert.
  • Validation Summary: Issue #5622 module evidence validation complete; 9 test cases (100% pass rate) in module_server_test_server_activation_profile_focused
  • API contracts frozen and documented for all HTTP/gRPC/WebSocket/MQTT entry points β€” include/server/server_api_contract.h
  • Phase 1 Security/Auth Hardening complete β€” frozen API contract (include/server/server_api_contract.h Β§2 Auth Gate Contract, Β§6 Error Taxonomy, Β§8 Threading Guarantees); all 12+ error classes documented with fail-closed semantics
  • SCH-01..SCH-20 regression test suite passing β€” tests/server/test_server_contract_hardening_focused.cpp; covers auth, retry, timeout, rate-limit, and protocol contracts
  • Phase 4 contract hardening test suite complete β€” 20 deterministic GTest cases (auth, retry, timeout, rate-limit, protocol fault injection) in tests/server/test_server_contract_hardening_focused.cpp
  • Phase 5 wire-protocol retry complete (P5-S01) β€” exponential-backoff retry with configurable budget/jitter; 16 WSR tests pass in tests/server/test_server_phase5_hardening.cpp
  • Phase 5 HTTP timeout and graceful-shutdown complete (P5-S02) β€” deadline enforcement, kRunningβ†’kDrainingβ†’kStopped drain semantics; 12 HST tests pass in tests/server/test_server_phase5_hardening.cpp
  • 39 focused SRV-01..SRV-39 tests complete and registered as release_critical;server;phase1
  • 8 benchmark release gates SVR-01..SVR-08 delivered β€” benchmarks/server/bench_server_hotpaths.cpp; Wave-7 latency baselines (read p99≀200Β΅s, writeβ‰₯80k ops/s) hold with no regressions from retry/timeout logic
  • Voice API Bearer-Token JWT/OIDC validation complete β€” JWT signature, expiry, issuer, audience, and JTI revocation; fail-closed on any validation failure
  • GA evidence bundling and sign-off complete (Batch C) β€” retry/timeout/shutdown release-critical paths documented in docs/governance/GA_PROMOTION_SIGN_OFF.md
  • Phase 6 documentation aligned β€” include/server/server_api_contract.h freezes all handler registration, auth gate, retry/timeout/backpressure, error taxonomy, lifecycle/ownership, and threading contracts
  • noexcept build-blocker cleanup complete (2026-08-17) β€” A-5 ThreadSanitizer cleanup pass resolved all remaining noexcept-related build blockers

Known Issues and Limitations

  • Plugin-based adapter loading still requires roadmap delivery.
  • Some advanced protocol features require additional soak/fault-injection validation before hard SLA commitments.
  • Cross-node consistency for globally distributed rate limits needs further hardening evidence.

Breaking Changes

  • REST versioning remains path-based and backward-compatible for v1 clients.
  • gRPC schema evolution remains additive-only for active major lines.

Program Execution Model β€” Wave Context

This module is a contributing module in the program-level Wave A β†’ B β†’ C β†’ D execution model. It does not own a primary wave deliverable but must remain release_critical-green throughout all waves and must deliver Wave D operability improvements in Q1 2027. See ../../ROADMAP.md for the full wave model and exit criteria.

Wave D Contribution for server

  • Deliver or validate distributed tracing, high-cardinality stress coverage, exporter reliability, and operator remediation hints as applicable to this module (Target: Q1 2027)
    • Delivered: tests/server/test_server_highcardinality_stress.cpp (SRV-STRESS-01..03: 10k-route routing, concurrent rate-limit, WASM sandbox load)
    • Delivered: benchmarks/server/bench_server_dedicated_gates.cpp (SRV-BM-01..04: route-dispatch p95, rate-limit check p95, WASM invoke p99, auth-token validate p95)
  • Contribute to or validate long-duration soak test coverage for this module's primary paths (Target: Q1 2027)
    • Delivered: tests/integration/test_server_lifecycle_soak.cpp (SRV-SOAK-01..03: request throughput β‰₯5k req/s, rate-limit stability, plugin-adapter reliability)
  • Ensure runbook coverage for operator-critical scenarios in this module (Target: Q1 2027)
    • Delivered: docs/operability/RUNBOOK_SERVER_CORE.md (5 scenarios: plugin load failure, rate-limit bypass, WASM OOM, auth unavailability, GraphQL schema conflict)

Cross-Wave Requirements

  • release_critical CI must remain green on develop throughout all waves (Target: ongoing)
  • p95/p99 benchmarks must be refreshed on representative hardware before Wave D sign-off (Target: Q1 2027)
  • No behavioral regression may be introduced into modules in Wave A/B/C scope from changes in this module.

Program-Level Success Criteria (contribution)

  • [~] This module's distributed/acceleration paths fail closed (Target: Q1 2027)
  • Benchmark-backed p95/p99 baselines exist on representative hardware (Target: Q1 2027)
    • Delivered: benchmarks/server/bench_server_dedicated_gates.cpp SRV-BM-01..04
  • Operator-critical paths have diagnostics, alerts, and runbooks (Target: Q1 2027)
    • Delivered: docs/operability/RUNBOOK_SERVER_CORE.md

ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues

ThemisDB Wiki

🏠 Overview

πŸ“š Compendium

πŸš€ Getting Started

πŸ“– Tutorials

πŸ“— User Guide

βš™οΈ Operations & Security

πŸ“Ÿ Ops Runbooks

πŸ—οΈ Architecture

πŸ“ ADRs

πŸ”§ Contributing

πŸ“‹ Governance

πŸ” Audit

🧩 Plugins

πŸ”Œ Adapters

πŸ’‘ Examples

πŸ“¦ Client SDKs

πŸŽ“ Training

πŸ› οΈ Tools

πŸ€– Developer LLM Wiki

Clone this wiki locally