Operating System written for me
Go to file
Daniel Samson 36a7cc5fe9
kernel: ring 0 cannot execute a user page
SMEP turns the classic escalation — divert kernel control flow into a page
the attacker wrote — from a silent takeover into an immediate fault with
the offending address in the log. The bit is per-core state, so it is set
where the syscall MSRs already are: in the per-CPU bring-up both the boot
processor and every application processor run on their way in. A core that
climbed the trampoline without it would be a hole no boot log would show,
which is why the SMP case now reads CR4 on each core it lands on and
requires every one of them to be hardened, not just the one that printed
the banner.

Enabling it that early is only safe because nothing ring 0 executes is
mapped for ring 3, and that had to be established rather than assumed:
kernel text carries only its ELF flags, the physmap is no-execute, the
trampoline page is mapped supervisor and the core running it has not
enabled the bit yet, and the boot processor turns it on while still on the
loader's tables — which map nothing user-accessible at all. The one
indirect call in the kernel takes a kernel address.

The CPUID probing that was scattered across the timer code becomes a small
shared helper, since the feature question is now asked from two places and
each wanted the same maximum-leaf guard. Absence is tolerated and reported,
like the IOMMU: danos still boots on a machine without the feature, and
says which one it is.

The test harness starts asking QEMU for a CPU that has the bit at all —
its default model has neither SMEP nor SMAP, so the code would otherwise
have been unreachable in every run. No case behaved differently under the
richer model.

Suite 112/112, with a new case that maps an executable user page, calls
into it from the kernel, and requires the fault the CPU is supposed to
raise.
2026-08-01 10:05:58 +01:00
boot reorg: move test fixtures to test/system/services (source + boot volume) 2026-07-23 00:11:07 +01:00
build build: the unix paths retire — configuration, logs, and volumes move into the danos tree 2026-07-31 19:41:35 +01:00
build-support build: delete module_homes — imports resolve through the declared zon 2026-07-30 07:49:19 +01:00
docs kernel: ring 0 cannot execute a user page 2026-08-01 10:05:58 +01:00
library library: the harness keeps the subscribers, and an id belongs to whoever opened it 2026-08-01 09:05:26 +01:00
system kernel: ring 0 cannot execute a user page 2026-08-01 10:05:58 +01:00
test kernel: ring 0 cannot execute a user page 2026-08-01 10:05:58 +01:00
tools boot: the capsule — one-file system image first, manifest and walk as fallbacks 2026-07-21 18:57:33 +01:00
usr/share/fonts assets: add font families under usr/share/fonts 2026-07-14 18:39:23 +01:00
.editorconfig editorconfig 2026-07-12 16:09:11 +01:00
.gitattributes gitattributes 2026-07-12 16:09:18 +01:00
.gitignore gitignore: /var/log — real-hardware log pulls stay out of the tree 2026-07-21 20:09:29 +01:00
README.md re-org docs 2026-07-23 00:25:34 +01:00
build.zig library: the harness keeps the subscribers, and an id belongs to whoever opened it 2026-08-01 09:05:26 +01:00
build.zig.zon library: the harness keeps the subscribers, and an id belongs to whoever opened it 2026-08-01 09:05:26 +01:00

README.md

DanOS

Codename: Shodan

A very small resilient operating system.

Zen of DanOS:

  • Resilient Micro-Kernel Architecture.
    • Every process run in an isolated user space not kernel space.
    • Processes cannot take down the entire OS with it when they die or is killed
  • Stable public runtime library, private OS ABI.
    • Keeps a stable runtime for user space processes between OS versions (great for backwards compatibility)
    • Allows the underlying OS to be changed without effecting applications
    • Provides a boundary to enable compatibility between OS's e.g. POSIX, MUSL etc
  • Drivers are just isolated processes in user space.
    • Thin binaries that can be restarted like applications.
    • Useful during driver development.
    • Drivers can claim MMIO / ports
    • Driver resources (e.g. IRQ/Port/MMIO) claims are automatically cleaned up if the driver dies or is killed
    • Drivers can also hook into the process lifecycle to clean up or reset hardware
  • No legacy to deal with
    • Zig code uses a clean coding style (Zen of Zig)
    • Favor reading code over writing code.
    • No magic numbers.
    • No shortened names unless its for ABI compatibility or acronyms
  • Inter-Process Communication (IPC)
    • Publish and subscribe to Asynchronous Messages
    • Talk to services and processes synchronously

Prerequisites

  • Zig 0.16.x — the build is pinned to this line (.zig-version); other minor versions are rejected, because Zig makes breaking changes between releases pre-1.0. A toolchain manager such as zvm or zigup will pick up .zig-version automatically.
  • QEMU (qemu-system-x86_64) — to run and test the kernel. On macOS, brew install qemu also bundles the OVMF firmware below.
  • OVMF UEFI firmware — the edk2-ovmf package (Arch), ovmf (Debian/Ubuntu), or edk2-ovmf (Fedora); on macOS it ships inside the Homebrew qemu formula. Both the build and the test harness probe the known Arch/Debian/Fedora/macOS layouts and use the first that exists, so no configuration is normally needed. Override with -Dovmf-code= / -Dovmf-vars= (build) if yours lives elsewhere.
  • Python 3 — for the QEMU integration test harness.

Build

zig build

Produces a FHS-shaped zig-out/ that is the danos filesystem and the boot volume: the UEFI bootloader at zig-out/EFI/BOOT/BOOTX64.efi, the kernel at zig-out/system/kernel, init at zig-out/system/services/init, drivers under zig-out/system/drivers/, the test fixtures under zig-out/test/system/services/, and the initial-ramdisk at zig-out/boot/.

Release media

zig build release-x86-64

Produces zig-out/danos-x86-64.iso, a hybrid ISO that boots flashed raw to a USB stick (balenaEtcher, dd) or burned to optical media — see docs/release-iso.md. zig build check-iso-image validates it without booting.

Run

Boot it in QEMU with OVMF (opens a display window):

zig build run-x86-64
# distro with OVMF elsewhere:
zig build run-x86-64 -Dovmf-code=/path/OVMF_CODE.fd -Dovmf-vars=/path/OVMF_VARS.fd

Test

zig build test            # host unit tests (the platform-independent shared code)
python3 test/qemu_test.py  # QEMU integration tests: boots the kernel and asserts
                           # on its serial output (see docs/testing.md)

The integration harness builds and boots the kernel once per test case, checking memory, the frame allocator, paging (incl. NX and the null guard), the heap, interrupts, and exception handling. It exits non-zero on any failure, so it drops straight into CI.

Documentation

Design notes explaining why behind the code live in docs/ — start with docs/README.md.

For the hardware needed to run DanOS — minimum specs plus a plain-language guide matching Intel/AMD CPU generations by name — see docs/system-requirements.md.

San Serif Text "Dan OS" with a black karate belt around it.