Skip to main content

Roadmap

Last updated: 2026-09-02 | Status: Experiment under construction β€” not a deployment

Part of the TunaOS ecosystem. A Matrix homeserver that stores rooms as a linear log, so state resolution never runs on the hot path.

What this file is, and is not​

Milestone standings are not duplicated here. They live in docs/dashboard.md, which is generated from the router by scripts/coverage-dashboard.py and gated in CI on drift β€” so it matches main rather than matching whoever last edited a paragraph. A second hand-maintained milestone table would be a second thing to drift, and the org has already paid for that lesson once (tuna-os/.github ROADMAP-INDEX.md).

What this file carries is the part no generated artifact can produce: the maturity contract β€” what has to be demonstrated before Spindle stops being an experiment, and what is deliberately not being built yet.

Current foundation​

  • Rooms stored as an append-only log keyed by an i64 linear index that is the topological order; state materialized in a content-addressed HAMT
  • Client-server surface broad enough that Element, Element X, Cinny, Nheko and FluffyChat work unmodified against ordinary room version 11 rooms
  • Federation interoperating with real Synapse in both directions, and Spindle-to-Spindle remote joins proven by a two-instance test
  • Published benchmarks against Synapse, Continuwuity and Tuwunel β€” including the cells Spindle lost and two claims retracted after publication
  • CI gates: the Complement ratchet, config drift, dashboard drift, pinned actions, and a semgrep rule for the authorization-shaped defect

Release maturity​

Spindle has no tagged release. That is the correct standing for the current stage and the README says so plainly. What has been missing is a stated condition under which it changes β€” so this section is that condition, and the absence of a release is a decision with an exit rather than a default.

v0.0.x β€” an addressable prerelease​

The near-term step is not a stability promise. It is a name, so that a benchmark result, a security fix, and a storage-format change can each be said to belong to something.

GateRequired evidence
AddressabilityA v0.0.1 tag cut from main, with release notes stating what it is not: no upgrade path, no support window, storage format unstable
Storage format identityA storage-format version distinct from the binary version, with the already-broken transition recorded as a numbered format change in docs/lifecycle.md
Benchmark provenanceEvery published comparison names the Spindle build it measured, as it already names Synapse 1.159.0

Tracked by #308.

v0.1.0 β€” the first release an outsider could reason about​

Evidence-based, not a date. Each gate is a demonstration on one candidate commit, and the candidate's evidence links belong in the release notes.

GateRequired evidence
Authorization surface#268's systematic audit closed β€” the route table walked by a stranger for every room-scoped route, not "however much someone happened to look"
Vulnerability intakePrivate vulnerability reporting enabled on this repository and a SECURITY.md naming the server-software classes: authorization bypass, federation forgery, cross-account disclosure, unauthenticated resource exhaustion (#307)
The load-bearing claimThe SPEC Β§9.3 equivalence theorem's differential oracle against ruma-state-res passing on a schedule, not only on demand. A counterexample is a release blocker
Federation under adversity#16's fork-proof rig green, and #225 β€” a federated fork wedging a room permanently β€” fixed with a regression test
Lifecycle round tripbackup β†’ restore β†’ verify-media demonstrated across a version boundary, with at least one real migration in the migration table rather than synthetic fixtures
Performance parity#42's protocol-workload comparison against Tuwunel and Synapse published under the counting discipline the benchmark host requires
Operator readinessRate limits and resource caps inventoried with nothing load-bearing left unbounded (#299 began this), and a stated supported-version line

A v0.1.0 release note that cannot link evidence for a row above should not be published; the row should be moved instead. Maturity is not inferred from main being green or from a benchmark being fast.

Contributor entry​

The project's velocity has so far been single-author. Making Spindle joinable is a roadmap item, not an afterthought β€” it is the org's only fresh Rust codebase with an embedded store, no database to provision, and cargo test --workspace as the whole gate.

Near-term, tracked by #306:

  • Repository topics and a homepage link, so the benchmark site is reachable from the repository header
  • good first issue and help wanted applied to the issues that already qualify β€” the labels exist and have never been used
  • GitHub milestones matching the dashboard's M0–M7, so the frontier is visible where a newcomer would look for it

Build and test commands are in the README; org-wide contribution guidance is in tuna-os/.github.

Deliberately not now​

Recorded so that absence reads as a decision rather than an oversight:

  • Horizontal scale-out β€” deferred until after a single-node production gate (#24)
  • MLS β€” evaluated only after Megolm compatibility ships (#23)
  • Hub mode (MSC3995) β€” the differentiator, behind a feature flag, after the ordinary-federation path is proven (#22)
  • Synapse importer β€” parked behind the API surface and MatrixRTC (#240)
  • TURN, push gateway, identity server β€” deliberately unbundled services, per #4's what not to build early

Risks to the headline claim​

The claim that window-bounded state resolution equals full state resolution is the one that would invalidate the project if it broke. The enumerated risks live in SPEC Β§21, and the metric the architecture is falsified by β€” the fork-case counter β€” is exported and documented in docs/metrics.md. Two further caveats the README states and this roadmap inherits: the architectural win is a constant factor rather than an asymptotic one, and every federation number so far is a design target measured on one server.