5 ms·
CharlotteOS – An Experimental Modern Operating System
- pjmlp 11mo agoInteresting, and kudos for trailing other paths, and not being yet another POSIX clone.
- LavenderDay3544 11mo agoThanks and that was one of my main motivators for starting this. There just arent any options out there that aren't POSIX or Windows. I guess there's Haiku but even that's based on an older OS.
- embedding-shape 11mo agoThis is probably a better introduction it seems, than specifically the kernel of the OS: https://github.com/charlotte-os/.github/blob/main/profile/README.md https://github.com/charlotte-os/.github/blob/main/profile/RE... > URIs as namespace paths allowing access to system resources both locally and on the network without mounting or unmounting anything This is such an attractive idea, and I'm gonna give it a try just because I want something with this idea to succeed. Seems the project has many other great ideas too, like the modular kernel where implementations can be switched out. Gonna be interesting to see where it goes! Good luck author/team :) Edit: This part scares me a bit though: "Graphics Stack: compositing in-kernel", but I'm not sure if it scares me because I don't understand those parts deeply enough. Isn't this potentially a huge hole security wise? Maybe the capability-based security model prevents it from being a big issue, again I'm not sure because I don't think I understand it deeply or as a whole enough.
- Philpax 11mo agoThe choice of a pure-monolithic kernel is also interesting; I can buy that it's more secure, but having to recompile the kernel every time you change hardware sounds like it would be pretty tedious. Early days, though, so we'll see how that decision works out.
- Rohansi 11mo agoWhy would you need to recompile if hardware changes? Linux manages just fine as a monolithic kernel that ships with support for many devices in the same kernel build.
- ofrzeta 11mo agoIt's true that you can compile everything in but it's not really the standard practice. On a stock distro you have dozens of dynamic modules loaded.
- ori_b 11mo agoOpenBSD removed support for loadable modules. Hardware today is big enough that compiling everything in is fine, and we don't need a ton of fiddly code to put a special-purpose linker into the kernel. Saving a bit of memory isn't worth the risk.
- LavenderDay3544 11mo agoEven a fully loaded kernel with loads of drivers isn't that big. And not all of it has to be resident in memory at all times. Code in general is miniscule compared to data. And most of a kernel's data isn't baked into the executable. And this kernel in particular has very thin drivers that only abstract real devices to generic device class interfaces that userspace has to deal with directly. That's the part that's inspired by exokernels and hypervisor paravirtualization. That means that drivers for this kernel will be even smaller than those for other ones like Linux.
- vlovich123 11mo agoWhy would you buy it’s more secure. Traditionally in windows in-kernel compositing was a constant source of security vulnerabilities. Sure rust may help the obvious memory corruption possibilities but I’m not convinced.
- LavenderDay3544 11mo ago
- user3939382 11mo agoI’m working on one with a completely new hardware comms networking infra stack everything
- bionsystem 11mo agoI believe redox is doing the same (the everything as an URI part)
- yjftsjthsd-h 11mo agoSkimming https://doc.redox-os.org/book/scheme-rooted-paths.html https://doc.redox-os.org/book/scheme-rooted-paths.html and https://doc.redox-os.org/book/schemes.html https://doc.redox-os.org/book/schemes.html , I think they've slightly reworked that to a more-unixy approach, but yeah still fundamentally more URI than traditional VFS
- OJFord 11mo agoI don't think that's changed, it's just that /foo is an alias for /scheme/file/foo. You could roughly emulate it on Unix by assuming every filename starting /scheme/bar/ is a bar-type (special) file, but nothing stops you creating (and you'd necessarily have) 'files' of any type outside that. In Redox, everything has that scheme prefix describing its type (and if omitted, it's implicitly /scheme/file/).
- incognito124 11mo agoRecompiling the whole kernel just to change drivers seems like a deal-breaker for wider adoption
- pjmlp 11mo agoQuite common on Linux early days. Also the only approach for systems where people advocate for static linking everything, yet another reason why dynamic loading became a thing.
- surajrmal 11mo agoIf this kernel ever gets big enough where this might matter, I'm sure they can change the design. Nothing is set in stone forever and for the foreseeable future it's unlikely to matter.
- LavenderDay3544 11mo agoIf there's enough demand for dynamic kernel modules they can be added later. That's not a feature that you have to build ypur whole kernel around from that start. Linux definitely didn't but it has it now so it's definitely that can revisited or even made an opt-in feature.
- skissane 11mo agoRecompile (or at least relink) the kernel to change drivers (or even system configuration) is a bit of a blast from the past - in the 1960s thru 1980s it used to be a very common thing, it was called “system generation”. It was found in mainframe operating systems (e.g. OS/360, OS/VS1, OS/VS2, DOS/360); in CP/M; in Netware 2.x (3.x onwards dropped the need for it) Most of these systems came with utilities to partially automate the process, some kind of config file to drive it, Netware 2.x even had TUI menuing apps (ELSGEN, NETGEN) to assist in it
- Brian_K_White 11mo agoNot just old stuff like that either. At least also all the SCO Xenix & Unix'es up to the technically current OSR5, OSR6 and Unixware. I don't know about other (commercial) unixes as much as SCO but given where they all come from I assume Solaris and most of the other commercial unix that still technically exist today have something at least somewhat similar. The sys admin scripts would even relink just to merely change the ip address of the nic! (I no longer remember the details, but I think I eventually dug under the hood and figured out how you could edit a couple files and merely reboot without actually relinking a new kernel. But if you only followed the normal directions in the manual, you would use scoadmin and it would relink and reboot.) And this is not because SCO sux. Sure they did, but that was actually more or less normal and not part of why they sucked. Change anything about which drives are connected to which scsi hosts on which scsi ids? fuggeddabouddit. Not only relink and reboot, but also pray and have a bootable floppy and a cheat sheet of boot: parameters ready.
- BobbyTables2 11mo agoWish OP had put that as the main readme. The intro page is currently useless.
- embedding-shape 11mo agoTo be fair, the submission URL goes to the kernel specifically, so the README is good considering the repository it's in. The link I put earlier I found via the GitHub organization, which does give you an overview of the OS as a whole (not just the kernel): https://github.com/charlotte-os/ https://github.com/charlotte-os/
- KerrAvon 11mo agoIn practice, the problem with URIs is that it makes parsing very complex. You don’t really want a parser of that complexity in the kernel if you can avoid it, for performance reasons if nothing else. For low-level resource management, an ad-hoc, much simpler standard would be significantly better.
- embedding-shape 11mo agoChuck Multiaddr in there (https://multiformats.io/multiaddr/ https://multiformats.io/multiaddr/), can be used for URLs, file paths, network addresses, you name it. Easy to parse as well.
- miohtama 11mo agoYou can use a subset of easily parseable URIs
- whatpeoplewant 11mo agoThis looks like a very interesting project! Good luck to the team.
- LavenderDay3544 11mo agoThanks. And there isn't much of a permanent team so far so if anyone wants to help then I'd be happy to hear from them on our Discord, Matrix or by email at charlotte-os@outlook.com.
- jadbox 11mo agoIn theory, wouldn't it be possible for the Linux kernel to also provide a URI "auto mount" extension too?
- yencabulator 11mo agoPaths are not full URIs. You can do hacks like /https:/example.com/foo but.. why? I'm personally not at all convinced having a scheme multiplexer in front is a good thing, for a namespace like what a kernel would manage. It's just not really any different from having top-level /foo and /bar, and introduces a bunch of special cases. Windows drive letters suck for a reason.
- rasta57 11mo ago[flagged]
- LavenderDay3544 11mo agoOP here. The plan is to hand out panes which are just memory buffers to which applications write pixel data as they would on a framebuffer then when the kernel goes to actually refresh the display it composites any visible panes onto the back buffer and then swaps buffers. There is nothing unsafe about that any more so than any other use of shared memory regions between the kernel and userspace and those are quite prolific in existing popular OSes. If anything the Unix display server nonsense is overly convoluted and far worse security wise.
- idle_zealot 11mo agoDoes this mean that window management has to be handled in the kernel? Or is there some process that tells the kernel where those panes should be relative to one another/the framebuffer?
- LavenderDay3544 11mo agoThat's going to tentatively be handled in kernel unless there good reason to do otherwise. The idea is to expose low level hardware interfaces across the board and this seemed to be the best way to multiplex actual hardware framebuffers while still keeping things low level. From there each application can draw its own GUI and respond to events that happen in its panes like a mouse button down event while the cursor is at some coordinates and so forth using event capabilities. What any event or the contents of a pane mean to the application doesn't matter to the OS and the application has full control over all of its resources and its execution environment with the exception of not being allowed to do anything that could harm any other part of the system outside its own process abstraction. That's my rationale for why the display system and input events should work that way. Plus it helps latency to keep all of that in the kernel especially since we're doing all the rendering on the CPU and are thus bottlenecked by the CPU's memory bus having way lower throughput compared to that of a discrete GPU. But that's the way it has to be since there are basically no GPUs out there with full publicly available hardware documentation as far as I know and believe me I've looked far and wide and asked around. Eventually I'll want to port Mesa because redoing all the work develop something that complex and huge just isn't pragmatic.
- ofrzeta 11mo agoSo, what's modern about it? "novel systems like Plan 9" is quite funny because Plan 9 is 30 years old.
- pjmlp 11mo agoThe sad part is that there are too many ideas of old systems lost in a world that 30 years later seems too focused on putting Linux distributions everywhere.
- grepfru_it 11mo agoThere was also a period of time where everyone and their mom was writing a new operating system trying to replicate Linux’ success
- pjmlp 11mo agoIsn't what all those UNIX clones keep trying to do?
- Razengan 11mo agoYeah the more you read up on computing history from barely even 40 years ago, it seems that most of the things that we take for granted today became so more through politics (and in the case of Microsoft, bullying) than merit.
- Razengan 11mo agoRegarding Microsoft, this was before even the "Browser Wars" they'd send suited people to the offices of Japanese PC manufacturers and threaten to revoke their Windows licenses if they even OFFERED customers the CHOICE of an alternative operating system!! This and other dirt is on any YouTube video about the history/demise of alternative computing platforms/OSes.
- linguae 11mo agoIndeed. I am reminded of what Alan Kay has repeatedly referred to as a “pop culture” of computing that has become widespread in technical communities since the 1980s, when the spread of technology grew faster than educational efforts. One result is there are many inventions and innovations from the research community that never got adopted by major players. The corollary to “perfect is the enemy of the good” is good-enough solutions have amazingly long lifetimes in the marketplace. There are many great ideas in operating systems, programming languages, and other systems that have been developed in the fast 30 years, but these ideas need to work with existing infrastructure due to costs, network effects, and other important factors. What is interesting is how some of these features do get picked up by the mainstream computing ecosystem. Rust is one of the biggest breakthroughs in systems programming in decades, bringing together research in linear types and memory safety in a form that has resonated with a lot of systems programmers who tend to resist typical languages from the PL community. Some ideas from Plan 9, such as 9P, have made their way into contemporary systems. Features that were once the domain of Lisp have made their ways into contemporary programming languages, such as anonymous functions. I think it would be cool if there were some book or blog that taught “alternate universe computing”: the ideas of research systems during the past few decades that didn’t become dominant but have very important lessons that people working on today’s systems can apply. A lot of what I know about research systems comes from graduate school, working in research environments, and reading sites like Hacker News. It would be cool if this information were more widely disseminated.
- the__alchemist 11mo agoI love seeing projects in this space! Non-big-corp OSSes have been limited to Linux etc; would love to explore the space more and have non-Linux, non-MS/Apple options. For example, Linux has these at the core which I don't find to be a good match for my uses: - Multi-user and server-oriented permissions system. - Incompatible ABIs - File-based everything; leads to scattered state that gets messy over time. - Package managers and compiling-from-source instead of distributing runnable applications directly. - Dependence on CLI, and steep learning curve. If you're OK with those, cool! I think we should have more options.
- ogogmad 11mo ago> Package managers and compiling-from-source instead of distributing runnable applications directly. Docker tries to partially address this, right? > Dependence on CLI, and steep learning curve. I think this is partially eased by LLMs.
- the__alchemist 11mo agoBut you can see the theme here: Adding more layers of complexity to patch things. LLMs do seem to do a better job than searching forum posts! I would argue that Docker's point is to patch compatibility barriers in Linux.
- Levitating 11mo ago> Docker tries to partially address this, right? Docker is a good way of turning a 2kb shell script into a 400mb container. It's not a solution. Flatpak would be a better example.
- LavenderDay3544 11mo agoThey shouldn't have to. OS interfaces including commandline ones should be user oriented not bogged down by Unix dogma that was created wwhencomputerss used physical text terminals as their primary I/O device. It's not the 60s anymore and modern PC, servers, and embedded devices aren't ancient mainframes with physical terminal hardware where making everything appear to be a file and using convoluted scripting interfaces like the Unix shell made at least some sense.
- kragen 11mo agoIt's comforting to see that capabilities with mandatory access control have become the new normal.
- LavenderDay3544 11mo agoWhy choose one when combining both is better?
- kragen 11mo agoExactamente.
- varispeed 11mo agoModern operating system, ready to face challenges of today political landscape, should natively support "hidden" encrypted containers, that is you would log in to completely different, separate environment depending on password. So that when under threat could disclose a password to an environment you are willing to share and attacker would have no way of proving there is any other environment present.
- Razengan 11mo agoIt would be easy to tell for anyone seriously after you: If I kidnap you and make you log into your computer, and you log into the decoy state, it'd be obvious to see that the last time you visited any website etc. was over a month ago and so on.
- varispeed 11mo agoFor sure you'd have to use it from time to time.
- mixmastamyk 11mo agoOr, write a login script to touch files at random.
- Razengan 11mo agoThat won't mask your online interaction history etc. Maybe an LLM agent posting crap at random? lol
- varispeed 11mo agoCould also be a "cross-over", so your real account could mount certain parts of other file systems as an overlay. So if you could have a browser that would be the same across two environments. That way the throwaway account could be seen as real, but it wouldn't show things you don't want to be compromised.
- ForHackernews 11mo agoHow does this compare to SerenityOS? At a glance, it looks more modern and free from POSIX legacy?
- LavenderDay3544 11mo agoI don't know anything about SerenityOS so I can't really say but if you have any more specific questions I'd be happy to answer them.
- jancsika 11mo ago> GPLv3 or later (with proprietary driver clarification) What's that parenthetical mean?
- nathcd 11mo agoLooks like it's explained here: https://github.com/charlotte-os/Catten/blob/main/License/clarificiation.md https://github.com/charlotte-os/Catten/blob/main/License/cla... Specifically, "Users may link this kernel with closed-source binary drivers, including static libraries, for personal, internal, or evaluation use without being required to disclose the source code of the proprietary driver.".
- jancsika 11mo agoOk, even Doug Crockford has mucked around with licensing before, so this is definitely a digression and not aimed at CharlotteOS which looks fascinating: I wish there was a social stigma in Open Source/Free Software to doing anything other than just picking a bog standard license. I mean, we have a social stigma even for OS developers about rolling your own crypto primitives. Even though it's the same very general domain, we know from experience that someone who isn't an active, experienced cryptographer would have close to a zero percent chance of getting it right. If that's true, then it's even less likely that a programmer is going to make legally competent (or even legally relevant) decisions when writing their own open source compatible license, or modifying an existing license. I guess technically the "clarification" of a bog standard license is outside of my critique. Even so, their clarification is shoe-horned right there in a parenthetical next to the "License" heading, making me itchy... :)
- LavenderDay3544 11mo agoOP here, it's not mucking around with the license just making sure people know how the GPLv3 works. You are not required to provide source code for the combined work unless it is conveyed. If you combine the covered work with closed source but don't convey the resulting product you are not required to provide any source to anyone. Many people don't know that, hence the clarification note.
- shevy-java 11mo agoWritten in Rust. Hmm. SerenityOS is written in C++. I'd love some kind of meta-language that is easy to read and write, easy to maintain - but fast. C, C++, Rust etc... are not that easy to read, write and maintain.
- cultofmetatron 11mo agofast necessitates manual control -> more semantics for low level control) that need to be expressible, ie: more complex easy to understand, maintain -> computer does more work for you to "figure things out" in a way that simply can't be optimal under al conditions. TLDR: what you're asking for isn't really possible without some form of AGI
- card_zero 11mo agoWhat languages are easy to understand and maintain, anyway?
- cultofmetatron 11mo agoId argue that python, elixir, ruby and all manner of languages are easy to understand and maintain. I dont' have to think about memory management or buffer overuns. its much easier to avoid race conditions since I'm not stressing about low level details. by that same definition, rust is pretty easy to maintain. I won't say its easy to write though.
- LavenderDay3544 11mo agoBeing maintainable comes down to code quality, comments, and documentation. These are thing that I really want to emphasize for this project but for now I'm just one guy and it's very early days so I have to focus developing core kernel components first.
- not4uffin 11mo agoI’m very happy I’m seeing more open source kernels being released. More options (and thus) competition is very healthy.