The compositor now boots on the GOP framebuffer and upgrades to the virtio-gpu driver the moment it announces itself — the pluggable-scanout payoff. The shared surface. The scanout resource is an shm region the driver creates (shm_physical, a new syscall, hands it the guest-physical for attach_backing) and passes to the compositor as a capability. The compositor maps it and composites straight into it: on x86 DMA is cache-coherent, so the cacheable shared pages the CPU paints are exactly what the device transfers-and-flushes — no copy, no explicit flush. The handshake. After bring-up the driver looks up .display and sends attach_scanout with the geometry + the surface capability. The compositor maps the surface, looks up the driver's .scanout endpoint itself (the driver registered it — no need to pass it), switches to backend.VirtioGpu, and re-composites the current frame. present() over the native backend is a present request on .scanout -> transfer-to-host + resource flush. The first native present is deferred to a one-shot timer: presenting inline from the announce handler would deadlock, since the driver is still blocked on our reply and not yet serving .scanout. After it lands, the compositor reads a pixel back from the shared surface to confirm the frame reached the device's backing. - shm_physical (syscall 36) + runtime.shm.physical. - scanout-protocol (the compositor->driver present channel), separate from the client-facing display protocol; the display protocol gains attach_scanout. - backend.VirtioGpu joins backend.Gop in the tagged union; select() still boots GOP. - the virtio-gpu driver's scanout backing is now shm (was DMA); it announces + serves .scanout present requests (transfer-to-host + flush of the shared surface). Also fixes a latent framebuffer-geometry corruption the display service hit only when it enumerated the device tree alongside a busy device-manager: Gop.init now captures the geometry into a small value the instant device_enumerate returns (rather than re-reading the 328-byte descriptor across the later claim/mmio_map syscalls) and retries on a zero geometry. The underlying device-table clobber is a separate kernel bug, tracked apart. Gate: python3 test/qemu_test.py display-native (QEMU -device virtio-gpu-pci) — "display: scanout upgraded to virtio-gpu" + "display: native present verified" + "display-demo: ok", passing 3/3. host tests, display-service, display-demo, shm, and virtio-gpu still pass.
DanOS
Codename: Shodan Version: 1
A small resilient operating system, written from scratch in Zig.
Zen of DanOS:
- Resilient Micro-Kernel Architecture.
- Every process run in an isolated user space not kernel space.
- Processes cannot take down the entire OS with it when they die or is killed
- Stable public runtime library, private OS ABI.
- Keeps a stable runtime for user space processes between OS versions (great for backwards compatibility)
- Allows the underlying OS to be changed without effecting applications
- Provides a boundary to enable compatibility between OS's e.g. POSIX, MUSL etc
- Drivers are just isolated processes in user space.
- Thin binaries that can be restarted like applications.
- Useful during driver development.
- Drivers can claim MMIO / ports
- Driver resources (e.g. IRQ/Port/MMIO) claims are automatically cleaned up if the driver dies or is killed
- Drivers can also hook into the process lifecyle to clean up or reset hardware
- No legacy to deal with
- Zig code uses a clean coding style (Zen of Zig)
- Favor reading code over writing code.
- No magic numbers.
- No shortend names unless its for ABI compatibility or acronyms
- Inter-Process Communication (IPC)
- Publish and subscribe to Asynchronous Messages
- Talk to services and processes synchronously
Prerequisites
- Zig 0.16.x — the build is pinned to this line (
.zig-version); other minor versions are rejected, because Zig makes breaking changes between releases pre-1.0. A toolchain manager such as zvm orzigupwill pick up.zig-versionautomatically. - QEMU (
qemu-system-x86_64) — to run and test the kernel. On macOS,brew install qemualso bundles the OVMF firmware below. - OVMF UEFI firmware — the
edk2-ovmfpackage (Arch),ovmf(Debian/Ubuntu), oredk2-ovmf(Fedora); on macOS it ships inside the Homebrewqemuformula. Both the build and the test harness probe the known Arch/Debian/Fedora/macOS layouts and use the first that exists, so no configuration is normally needed. Override with-Dovmf-code=/-Dovmf-vars=(build) if yours lives elsewhere. - Python 3 — for the QEMU integration test harness.
Build
zig build
Produces a FHS-shaped zig-out/ that is the danos filesystem and the boot volume:
the UEFI bootloader at zig-out/EFI/BOOT/BOOTX64.efi, the kernel at
zig-out/system/kernel, init at zig-out/system/services/init, drivers under
zig-out/system/drivers/, and the initial-ramdisk at zig-out/boot/.
Run
Boot it in QEMU with OVMF (opens a display window):
zig build run-x86-64
# distro with OVMF elsewhere:
zig build run-x86-64 -Dovmf-code=/path/OVMF_CODE.fd -Dovmf-vars=/path/OVMF_VARS.fd
Test
zig build test # host unit tests (the platform-independent shared code)
python3 test/qemu_test.py # QEMU integration tests: boots the kernel and asserts
# on its serial output (see docs/testing.md)
The integration harness builds and boots the kernel once per test case, checking memory, the frame allocator, paging (incl. NX and the null guard), the heap, interrupts, and exception handling. It exits non-zero on any failure, so it drops straight into CI.
Documentation
Design notes explaining why behind the code live in
docs/ — start with docs/README.md.
For the hardware needed to run DanOS — minimum specs plus a plain-language guide
matching Intel/AMD CPU generations by name — see
docs/system-requirements.md.
Logo
San Serif Text "Dan OS" with a black karate belt around it.