Roadmap
Planned direction for CSharpDB — organized by timeframe and priority. Availability for the audited SQL surface is tracked separately.
Near-Term Completed
Recently completed improvements to query performance, storage behavior, provider/tooling compatibility, maintenance workflows, and developer ergonomics.
Source-Generated Collections
DoneNo-reflection, trim-safe typed collection API via CSharpDB.Generators with GetGeneratedCollectionAsync<T>(), GeneratedCollection<T>, generated field metadata, binary direct payloads for supported shapes, and NativeAOT-friendly model registration.
Collection Write-Path Performance
DoneSeparated collection write probes from the read-side B-tree routing-cache, reused traversal scratch during insert/replace, and buffered catalog mutation bookkeeping inside explicit transactions.
Covered Composite Index Fast-Path
DoneRecovered covered composite-index lookup optimization for queries that can be answered entirely from the index without touching the base table.
Durable-Write Batching
DoneConfigurable durable commit batch window to coalesce WAL fsync calls across concurrent transactions for higher write throughput.
DISTINCT & Composite Indexes
DoneDeduplicate SELECT output with DISTINCT. Multi-column indexes for broader query coverage.
Index Range Scans
DoneUse eligible single-column INTEGER and single-column ordered TEXT indexes for <, >, <=, >=, and BETWEEN predicates; REAL indexes remain equality-only.
Prepared Statement Cache
DoneCache parsed ASTs and query plans to avoid re-parsing identical SQL statements.
In-Memory Database Mode
DoneOpen a database fully in memory, load from disk, and save committed snapshots back to disk.
Collection Path Indexes
DoneNested scalar, array-element, nested array-object, Guid, temporal, and ordered text path indexes.
B+Tree Delete Rebalancing
DoneMerge underflowed pages on delete to reclaim space via borrow/merge with interior collapse.
Database Administration
DoneMaintenance report, REINDEX, VACUUM/compact, fragmentation analysis, and database size report.
Dedicated gRPC Daemon
DoneCSharpDB.Daemon host with full gRPC coverage for SQL, schema, procedures, collections, and maintenance.
Background WAL Checkpointing
DoneIncremental/sliced auto-checkpointing to move work off the triggering commit path.
Hybrid Storage Mode
DoneLazy-resident durable storage with on-demand page loading and gRPC tunable file-cache.
Table & Index Statistics
DoneANALYZE command with persisted row counts, column NDV/min/max, and initial stats-guided index selection.
Client Backup & Restore
DoneBackupAsync / RestoreAsync as first-class operations across direct, HTTP, gRPC, CLI, and Admin.
Native Table Archives & External Tables
DoneNative .csdbtable snapshots with fast Admin Import / Export, download or server-path destinations, CREATE EXTERNAL TABLE, sys.external_tables, read-only scans/joins, and embedded primary-key lookup indexes.
Older DB Foreign-Key Retrofit Migration
DoneValidate/apply maintenance workflow that rewrites existing child tables with persisted FK metadata across direct, HTTP, gRPC, CLI, and Admin.
Admin Reports Designer
DoneVisual banded-report designer with grouping, sorting, expressions, aggregate functions, page settings, and printable preview.
Mid-Term In Progress
SQL feature parity, provider/tooling compatibility, and ecosystem expansion.
SQL Feature Coverage
In ProgressThe bounded SQL implementation and its automated functional qualification gate are complete across the public reference, regression suite, versioned migration capability catalog, replayable EF SQL corpus, historical-database reopen coverage, fault-injected recovery, and a canonical typed parity workload plus feature-specific direct/ADO.NET/HTTP/gRPC coverage where applicable. Status remains In Progress until the release commit records two clean Windows, Linux, and macOS passes, two passing GitHub-hosted comparisons of the 18 stable master-table rows, and two passing sequential local durable-write comparisons on one idle fixed-SSD Windows machine using the same hash-verified harness and valid, stable raw evidence. The local gate must publish its success status on that exact release commit. Supplemental performance suites remain report-only or manual diagnostics. Advanced SQL work is tracked separately below and does not keep the bounded implementation slices partially complete.
User-Defined Functions and Commands
DoneDone for the trusted in-process model: host-registered C# scalar functions, common SQL/Admin built-ins, trusted commands, Admin Forms/Reports/pipeline hooks, declarative form action sequences, and local Admin Forms C# code modules. Untrusted sandboxed UDF execution is intentionally out of scope.
Writable External Tables
PlannedOpt-in writable external table registrations over mutable .csdbx files, backed by CSharpDB B+tree storage and limited to INSERT, UPDATE, and DELETE in v1 while .csdbtable archives remain read-only.
Window Functions
DoneDone as a bounded in-memory slice: ranking and common aggregate windows with partitioning, LAG/LEAD/FIRST_VALUE/LAST_VALUE, explicit ROWS frames, case-insensitive named windows, compatible shared ordering across different frames, deterministic NULL/peer behavior, prepared execution, cancellation, and configurable limits with explicit ResourceLimitExceeded failures. Disk spill is deferred and is not required for completion because memory growth is bounded; incompatible partition/order specifications and later SQL window forms remain explicitly unsupported.
EF Core Migration & Provider Validation
DoneDone for the bounded provider contract: a frozen, independently replayable three-version Up/Down SQL corpus covers empty and populated migrations, upgrade/downgrade paths, defaults/checks, composite keys, named relationships and immediate referential actions, primary-key changes, supported column rewrites, table/column/index rename chains, rollback, reopen, runtime CRUD, and ADO.NET schema inspection. Unsupported migration operations covered by this contract fail during SQL generation with stable CDBEF2001 diagnostics. EF migration execution remains embedded/direct; ordinary SQL and metadata transport parity is qualified separately.
Physical EXPLAIN & Profile
DoneDone for the bounded physical-plan contract: structural EXPLAIN and executing EXPLAIN ANALYZE rowsets distinguish estimates from actual rows, loops, and elapsed time; expose operator, access-path, index/join, predicate, and relative-cost metadata across direct, ADO.NET, HTTP, and gRPC; preserve normal DML transaction semantics; redact literal and prepared-parameter values from predicate metadata; and attach bounded partial diagnostics on cancellation or errors where safe.
DEFAULT & CHECK Constraints
DoneDone for the bounded literal and deterministic row-local slice: persisted literal defaults, DEFAULT markers, DEFAULT VALUES, named/unnamed column and table checks, stable CHECK identities, write enforcement, reopen persistence, catalogs, EF SQL, and metadata transport are qualified.
ALTER COLUMN Rewrites
DoneDone for the bounded ALTER COLUMN slice: exact INTEGER/REAL conversion with eligible index rebuilding, strict dependency-free UTF-8 TEXT/BLOB conversion, and indexed TEXT collation changes use transactional shadow-root rewrites; literal-default and nullability changes use validated transactional catalog updates. The rewrite paths preserve row ids, revalidate CHECK expressions and rebuilt uniqueness, roll back atomically after injected WAL failures, persist across reopen, and are emitted with the catalog operations in EF Core Up/Down migrations.
Primary & Unique Keys
DoneDone for the bounded key slice: named/unnamed single and composite INTEGER/TEXT primary/unique keys support persistence, enforcement, ordered catalogs, and EF migrations. Standalone primary-key add/drop covers validated logical-key changes with engine-owned backing-index creation/removal; adding a key to a populated table additionally supports bounded single-INTEGER physical rekeying with atomic eligible relational-index and complete ready full-text-owned-store rebuilding.
Foreign Key Constraints
DoneDone for immediate MATCH SIMPLE: column/table scalar and composite foreign keys have stable identities, candidate-key/type/collation validation, and the full RESTRICT/NO ACTION/CASCADE/SET NULL/SET DEFAULT matrix for deletes and referenced-key updates. Nested mutations preserve normal row semantics and transactional rollback across persistence, metadata, transports, archives, and tooling. EF-generated DDL covers the bounded relationships; SET DEFAULT and mutating ON UPDATE actions require explicit migration operations rather than relationship-model scaffolding.
Advanced Default & Check Expressions
PlannedStatement-time and computed default expressions plus broader safe check-expression forms beyond the completed deterministic row-local contract.
Advanced Rewrites & Physical Rekeying
PlannedIndexed TEXT/BLOB conversion, broader dependency-aware rewrites, additional key shapes and index families, and ordered/range REAL access beyond the completed bounded rewrite and single-INTEGER rekey paths.
Deferred Referential Semantics
PlannedDeferrable constraints and MATCH FULL/MATCH PARTIAL, separate from the completed immediate MATCH SIMPLE action matrix.
Broader ORM & Metadata Compatibility
PlannedAdditional third-party ORM suites and further normalized metadata surfaces beyond the qualified EF Core and ADO.NET contracts.
SQL Release Qualification
In ProgressThe automated GitHub gate blocks publishing on two clean full-suite passes for each supported operating system covering durable, in-memory, reopen/recovery configurations, historical-database upgrades, transport parity, the EF corpus, executable documentation, bounded property tests, and stable diagnostics for intentionally unsupported SQL. It also runs two balanced paired previous-release comparisons for the 18 persistent-read and in-memory master-table rows that are stable on hosted Windows runners. Disk-sensitive performance qualification is a required pre-tag local gate: two sequential balanced paired passes qualify each of the remaining ten durable SQL/collection single and batch write rows independently on one idle fixed-SSD Windows machine. Every exact row uses adjacent previous/candidate measurements, pass two reverses the starting order, and every individual measurement must retain at least 30 measured seconds and 10,000 latency samples within the bounded measurement cap. Each logical side has one predeclared attempt; evidence is not discarded, replaced, or silently retried. Both revisions use symmetrically conditioned artifacts with the same hash-recorded candidate benchmark harness; raw runs, recomputed aggregates, artifact closures, and pass reports are hash bound. After post-build quiescence, a required one-second Windows monitor covers every declared measurement. Five consecutive samples above 8% observable external process CPU, 0.5 CPU-core equivalent, or 4,194,304 observable external process I/O bytes per second contaminate the pass; named external build, test, installer, or update processes contaminate immediately. Missing monitor evidence, unavailable allowed runner-tree CPU, a coverage gap above five seconds, invalid benchmark evidence, unstable, order-sensitive, or regressed blocking assessments, and missing, unverifiable, or changed Windows Installer, Application event-log, or pending-file evidence fail closed; unavailable external-process counters remain explicit diagnostics. The expected local runtime is 3.5–4.5 hours. Stable comparisons enforce a 15% throughput limit and fail P95 only when regression exceeds both 25% and 0.05 ms; P99 remains diagnostic. Only the canonical durable-v3 local policy can publish a policy-bound status on the exact candidate commit. Its description is exactly policy=durable-v3; baseline=<40 lowercase hex>; design=<8 uppercase hex>; reports=<8 uppercase>/<8 uppercase>; older policy descriptions are rejected, and the release workflow requires the status from the configured attestor before publishing. Broader performance coverage remains in the existing scheduled report-only guardrails and manual supplemental suite diagnostics. This item closes when all automated functional and hosted-stable jobs and both local durable-write passes succeed for the release commit.
Remote Host Consolidation
DoneCSharpDB.Daemon now hosts the existing REST/HTTP /api surface and gRPC from one long-running process backed by the same warm daemon-hosted client. Standalone CSharpDB.Api remains supported for REST-only hosting.
Remote API-Key Protection
DoneOpt-in API-key mode protects REST /api/* and daemon gRPC calls with constant-time key comparison while keeping default no-auth behavior for compatibility.
Remote Host Security Hardening
PlannedAuthorization, protected admin endpoint scopes, JWT/RBAC options, and TLS/mTLS deployment helpers for remote HTTP and gRPC access.
Daemon Service Packaging
DoneCSharpDB.Daemon can be packaged as a persistent background service across systemd, Windows Service, and launchd.
Cross-Platform Distribution
In ProgressSelf-contained daemon archives and install scripts ship for Windows, Linux, and macOS; dotnet tool, Docker, Homebrew, and winget distribution remain future work.
ADO.NET GetSchema
DoneDbConnection.GetSchema() now exposes standard metadata collections for tooling and ORM schema discovery.
Collation Support
DoneBINARY, NOCASE, NOCASE_AI, and ICU:<locale> collation work across SQL schema/query semantics, metadata, ordered SQL text indexes, and collection path indexes.
Subqueries & Set Operations
DoneScalar subqueries, IN/EXISTS (including correlated), UNION, UNION ALL, INTERSECT, and EXCEPT across SELECT results. INTERSECT ALL and EXCEPT ALL remain unsupported.
Visual Query Designer
DoneAdmin query builder with source canvas, join editing, design grid, SQL preview, and saved layouts.
Long-Term Future
Advanced features and fundamental architecture enhancements, including long-range items that have since shipped.
Full-Text Search
DoneInverted index support with tokenization, stemming, and relevance ranking.
Source-Generated Collections
DoneCurrent phase is complete: opt-in generated models provide GetGeneratedCollectionAsync<T>, generated descriptors/index bindings, binary direct payloads for supported shapes, JSON fallback for unsupported shapes, and trim/NativeAOT smoke coverage.
Generated Collection Package Ergonomics
PlannedStreamline NuGet/analyzer packaging, templates, onboarding docs, and project setup for the opt-in generated collection path.
Broader Generated Model Coverage
PlannedExpand generator support beyond the current scalar, scalar collection, nested scalar, and nested collection-scalar shapes.
SQL Batched Row Transport
DoneInternal row-batch transport serves as the batch-first SQL execution foundation across batch-capable result boundaries, scans, joins, and generic aggregates.
External Table Index Coverage
PlannedFollow writable .csdbx storage with broader external-table indexes, planner costing, and multi-column lookup/range support beyond the current archive primary-key point-lookup path.
Page-Level Compression
PlannedDeep engine/page compression remains planned; application-level payload compression is available as a sample/SDK pattern without changing the storage format.
At-Rest Encryption
ResearchEncrypt database and WAL files with passphrase-based key management and explicit plaintext/encrypted migration/export paths; implementation must meet the database-encryption plan entry criteria before shipping.
Cost-Based Query Optimizer
DoneCurrent phase is complete: ANALYZE-driven stats-guided costing uses internal histograms, heavy hitters, composite-prefix summaries, skew-aware estimates, correlation-aware filters/joins, non-unique lookup costing, hash build-side choice, and bounded DP join reordering.
Adaptive Query Re-Optimization
DoneCurrent phase is complete: opt-in adaptive join execution can switch eligible index nested-loop joins to hash joins and flip inner hash build sides at safe pre-emission boundaries.
Public Planner Histogram Inspection
DoneStable SQL-first diagnostics expose sys.planner_histograms, sys.planner_heavy_hitters, sys.planner_index_prefix_stats, and EXPLAIN ESTIMATE FOR <query>.
Async I/O Batching
DoneCurrent phase is complete: WAL frame-chunk writes, chunked checkpoint page copies, shared snapshot/export batching, reusable B-tree copy utilities, and the close-out audit cover the main storage and maintenance write paths.
Low-Latency Durable Writes
DoneAdvisory planner-stat persistence can stay deferred without weakening committed-row durability, and sys.table_stats.row_count_is_exact makes exact versus estimated row-count semantics explicit.
Group Commit / Deferred WAL Flush
DoneOpt-in UseDurableCommitBatchWindow(...) batches durable WAL flushes across contending in-process transactions — an expert measure-first knob rather than default behavior.
Initial Multi-Writer Support
DoneExplicit WriteTransaction conflict-detected retry flow, shared auto-commit non-insert isolation, and opt-in ConcurrentWriteTransactions for shared implicit inserts.
Broader Multi-Writer Optimization
DoneOpt-in concurrent write transactions now reserve shared row-id ranges and rebase hot right-edge insert pages against pending WAL images for improved insert fan-in.
API-Level Sharding
DoneRoute-aware client, REST, gRPC, daemon, and ADO.NET surfaces can target single-shard operations across multiple warm CSharpDB database files using explicit keyspace/shard-key context and stable virtual-bucket ownership.
Replication & Change Feed
ResearchRetained commit-log change feeds and reactive query subscriptions for read replicas, live Admin views, and event-driven applications.
Current Limitations
Known simplifications in the current implementation:
| Area | Limitation |
|---|---|
| Functions and automation | CSharpDB's UDF/command model is trusted and in-process by design. Current supported surfaces include host-registered scalar functions, common built-ins, trusted commands, form/report/pipeline hooks, declarative action sequences, and local Admin Forms C# modules; untrusted sandboxed execution is intentionally out of scope |
| Query | Scalar/IN/EXISTS subqueries are supported, including correlated cases in WHERE, non-aggregate projection, and UPDATE/DELETE expressions; correlated subqueries are not yet supported in JOIN ON, GROUP BY, HAVING, ORDER BY, or aggregate projections |
| Query | UNION, UNION ALL, INTERSECT, and EXCEPT are implemented, with canonical direct, ADO.NET, REST, and gRPC parity coverage; INTERSECT ALL/EXCEPT ALL remain intentionally unsupported with stable diagnostics |
| Query | Window functions are complete for the bounded in-memory slice, including ranking, aggregate, navigation/value functions, explicit ROWS frames, named windows, compatible shared ordering, prepared execution, cancellation, controlled resource-limit failures, and physical window explain/profile rows. RANGE/GROUPS/EXCLUDE, DISTINCT windows, NULL-treatment syntax, incompatible partition/order specifications, mixed grouped/subquery window queries, and disk spill remain deferred |
| Schema | Literal SQL DEFAULT values, deterministic row-local CHECK constraints, stable table, column, CHECK, key, and foreign-key identities, logical composite INTEGER/TEXT primary/unique keys, standalone PRIMARY KEY add/drop with engine-owned backing-index maintenance plus bounded populated single-INTEGER rekeying on add across ready relational and complete ready full-text index families, table-level/composite INTEGER/TEXT foreign keys with MATCH SIMPLE and the full immediate RESTRICT/NO ACTION/CASCADE/SET NULL/SET DEFAULT delete and update action matrix, additive transport/archive and ADO.NET constraint metadata, SET/DROP DEFAULT, validated SET/DROP NOT NULL and named constraint changes, plus transactional shadow-root rewrites for exact indexed INTEGER/REAL changes, strict dependency-free UTF-8 TEXT/BLOB changes, and TEXT collation changes with inherited ordinary/unique SQL-index rebuilding are implemented and covered by deterministic WAL-failure recovery tests. Statement-time/function defaults, arbitrary functions/subqueries in checks, indexed TEXT/BLOB and broader dependency rewrites, broader physical rekey shapes/index kinds, deferred constraints, and MATCH FULL/PARTIAL are separate advanced work |
| Indexes | Equality lookups support INTEGER, TEXT, and hashed REAL SQL indexes. INTEGER-tag values on REAL-indexed columns must be exactly representable within ±253; ordered/range REAL access remains unsupported, while ordered range-scan pushdown supports eligible single-column INTEGER and single-column ordered TEXT index paths |
| RowId | Legacy table schemas without persisted high-water metadata may pay a one-time key scan on first insert |
| Collections | FindByIndexAsync supports declared field-equality lookups; FindByPathAsync and FindByPathRangeAsync support path-based queries on indexed paths; FindAsync remains a full scan for unindexed predicates. Generated collections require registered descriptors for existing collection indexes; unsupported generated model shapes warn and use the source-generated JSON fallback instead of binary direct payloads |
| External Tables | Native .csdbtable archives can be registered and queried as read-only external tables. Writable external tables are planned as an opt-in .csdbx format; current archives remain read-only, and broader external indexes, range seeks, and deeper planner costing remain planned |
| Sharding | API-level sharding routes explicit keyspace/shard-key requests to one database file at a time. Cross-shard SQL, cross-shard transactions, automatic resharding/data movement, replication, and failover remain planned or out of scope for v1 |
| Networking | CSharpDB.Daemon now hosts both REST and gRPC from one process; named pipes remain reserved but are not implemented end to end today |
| Security | Remote REST and daemon gRPC support opt-in API-key authentication, defaulting to None for compatibility. JWT, RBAC, mTLS helpers, TLS-specific configuration, and at-rest encryption are not implemented |
| Admin Forms | The Forms designer/runtime supports the core generated-form and data-entry path plus trusted command-backed automation, including lifecycle events, command buttons, selected-control events, conditional UI rules, domain formula helpers, declarative action sequences, and local C# code modules. It still needs Access-parity work for responsive runtime rendering, complete inferred validation, richer form modes, additional events, advanced filtering/sorting, report/query/import/export actions, macro loops/on-error/temp vars, and broader controls |
| Admin Reports | The Reports designer/runtime supports the core banded preview path plus trusted command-backed preview lifecycle events, but still needs Access-parity work for bounded saved-query previews, full report output/export, parameters, richer grouping and totals semantics, conditional formatting, subreports, and broader controls |
| Text / Multilingual | Text is stored as UTF-8 and supports all Unicode languages; default semantics remain ordinal, while opt-in BINARY, NOCASE, NOCASE_AI, and ICU:<locale> collation work across SQL schema/query semantics, metadata, ordered SQL text indexes, and collection path indexes |
| Concurrency | Physical WAL commit path is still serialized at the storage boundary. Initial multi-writer support is shipped, but observed gains depend on conflict shape and whether shared auto-commit INSERT is left on the default serialized path |
| Storage | No page-level compression; the compression SDK sample stores compressed payloads as ordinary application-managed BLOB values |
| Storage | No at-rest encryption for database/WAL files; on-disk storage is plaintext only |
| Storage | Memory-mapped reads are opt-in and currently apply only to clean main-file pages; WAL-backed reads still rely on the WAL/cache path |
| Storage | By default, durable auto-commit single-row writes still pay a physical WAL flush per commit; opt-in UseDurableCommitBatchWindow(...) can trade some commit latency for higher throughput |
| Query | Phase-2 cost-based planning is in place: ANALYZE, sys.table_stats, sys.column_stats, public planner-stat diagnostics, histogram/heavy-hitter/prefix estimates, and bounded small-chain join reordering now feed join/access-path costing. Stable physical EXPLAIN and executing EXPLAIN ANALYZE rowsets expose selected operators, relative row-work costs, nullable row estimates, and separate runtime rows, loops, and elapsed time. Their 256 KiB limit is an inline content budget rather than an exact serialized transport size. Profile mode executes its target under normal transaction semantics; cancellation and execution errors remain failures, with bounded redacted partial-profile diagnostics attached where safe. Opt-in adaptive join re-optimization can react to stale-stat or parameter-sensitive join cardinality misses, while adaptive stats persistence and arbitrary mid-plan reordering remain future work |
| Query | Internal row-batch transport is now the default scan-heavy execution foundation across batch-capable scans, joins, aggregates, and result boundaries; remaining work is broader kernel specialization and optional SIMD-style tuning rather than missing core batch coverage |
Completed Milestones
Major features already implemented and shipped: