Skip to content

Module themis Roadmap

github-actions[bot] edited this page Aug 31, 2026 · 1 revision

Themis Core Module Roadmap

Current Status

Production-usable themis core runtime exists for build identity, edition/license gating, secure module loading and verification, dependency resolution, and wire server operation.

In Progress

  • [~] hardening loader/verification behavior under platform and trust-edge scenarios (Target: Q3 2026)
  • [~] improving diagnostics consistency across license, verification, and wire runtime stages (Target: Q3 2026)
  • [~] stabilizing benchmark-backed release guardrails for themis core hot paths (Target: Q3 2026)

Planned Features

Short-term (3-6 months)

  • tighten deterministic outcomes for dependency and module trust edge cases (Target: Q4 2026)
  • expand stress coverage for wire-session and loader contention scenarios (Target: Q4 2026)
  • improve operator-facing diagnostics for load/verify/gating incidents (Target: Q4 2026)

Mid-term (6-12 months)

  • re-baseline p95/p99 envelopes for loader/gating/server-sensitive paths (Target: Q1 2027)
  • broaden benchmark depth for module lifecycle and wire runtime diversity (Target: Q1 2027)
  • harden long-run reliability under sustained core runtime pressure (Target: Q1 2027)

Implementation Phases

Phase 1: Design / API Contract

  • freeze themis core runtime/gating/lifecycle contracts for current major line (Target: Q3 2026)
  • define explicit error taxonomy for license/load/verify incident classes (Target: Q3 2026)

Phase 2: Core Implementation

  • complete hardening for loader/verifier and wire-server internals (Target: Q4 2026)
  • align platform-specific load behavior to bounded runtime contracts (Target: Q4 2026)

Phase 3: Error Handling and Edge Cases

  • standardize fail-safe behavior for signature, dependency, and runtime gate faults (Target: Q4 2026)
  • unify diagnostics across license, lifecycle, and wire incident classes (Target: Q4 2026)

Phase 4: Tests

  • expand focused regressions for loader/verify and wire-session edge scenarios (Target: Q4 2026)
  • extend deterministic stress fixtures for core runtime concurrency (Target: Q4 2026)

Phase 5: Performance and Hardening

  • lock benchmark-backed release gates for themis core hot paths (Target: Q4 2026)
  • validate p95/p99 and throughput behavior against release baselines (Target: Q4 2026)

Phase 6: Documentation and Acceptance

  • core themis module docs aligned to source-verifiable behavior
  • roadmap/future planning separated from historical changelog entries

Production Readiness Checklist

  • core themis surfaces documented and source-verified
  • module-level security and failure behavior documented
  • benchmark mapping documented in performance expectations
  • remaining hardening tasks closed for loader/gating/wire edge paths
  • release benchmark stabilization complete

Known Issues and Limitations

  • runtime behavior depends on platform loader constraints and trust material configuration.
  • selected verification and wire-session edge scenarios need continued hardening.
  • benchmark depth should continue expanding for wider core runtime workloads.

Breaking Changes

No breaking themis core contract planned. Any contract-breaking change requires migration notes and changelog entry before merge.

Program Execution Model — Wave Context

This module is a contributing module in the program-level Wave A → B → C → D execution model. It does not own a primary wave deliverable but must remain release_critical-green throughout all waves and must deliver Wave D operability improvements in Q1 2027. See [[../../ROADMAP.md|ROADMAP]] for the full wave model and exit criteria.

Wave D Contribution for themis

  • Deliver or validate distributed tracing, high-cardinality stress coverage, exporter reliability, and operator remediation hints as applicable to this module (Target: Q1 2027)
  • Contribute to or validate long-duration soak test coverage for this module's primary paths (Target: Q1 2027)
  • Ensure runbook coverage for operator-critical scenarios in this module (Target: Q1 2027)

Cross-Wave Requirements

  • release_critical CI must remain green on develop throughout all waves (Target: ongoing)
  • p95/p99 benchmarks must be refreshed on representative hardware before Wave D sign-off (Target: Q1 2027)
  • No behavioral regression may be introduced into modules in Wave A/B/C scope from changes in this module.

Program-Level Success Criteria (contribution)

  • This module's distributed/acceleration paths fail closed (Target: Q1 2027)
  • Benchmark-backed p95/p99 baselines exist on representative hardware (Target: Q1 2027)
  • Operator-critical paths have diagnostics, alerts, and runbooks (Target: Q1 2027)

Navigation

Home

Architecture

Governance

Modules

Developer

Clone this wiki locally