Read the boundary first
Comparisons include fresh process launch, key loading, filesystem I/O and the operation. Caches are warm; processes are not. They are not library-only algorithm timings. Security defaults differ; this corpus uses named caller-supplied keys, locally checked reference digests, RSA-2048/SHA-256 and AES-256-GCM.
RSS covers the complete process lifetime. Valgrind allocation and heap measurements are separate from latency, include native libraries, and exclude stacks and non-malloc memory mappings. Shared GitHub runners are noisy. Small sample counts do not establish reliable tail latency or superiority.
Loading validated measurements…
Latency summary: median of three repetition percentiles. CPU: median individual sample. RSS: maximum individual sample. Profiling measurements: one separate process per case. Counts and raw samples are downloadable, not inferred.
Environment, versions & provenance
Download raw comparison JSON · Builds and full measurement artifacts · Measurement contract
Not comparable in this chart
Standalone parse/C14N, retained-DOM operations, semantic projection, operation graph and policy phases remain xml-sec-only measurements. The CLIs do not expose equivalent boundaries. Multi-signature, nested-Manifest and external-reference workloads remain internal benchmarks until equivalent selection, resolver and trust semantics are demonstrated. No unsupported operation is timed as a successful one.