Research program

ABSD is an experimental operating system used to investigate one systems question with a working kernel, a userspace, and real programs rather than in the abstract. This page describes the program for researchers and prospective collaborators. Its statements carry the same labels as the rest of the site; where it describes intent rather than results, it says so.

The question

Mainstream Unix-like systems enforce authority, failure, and durability rules defensively in userspace, on top of a substrate that grants ambient authority and reports success loosely. Capability systems such as KeyKOS, EROS, seL4, and Zircon made authority native, and crash-consistency work such as ALICE, CrashMonkey, and FSCQ made storage guarantees testable. ABSD asks what an operating system looks like when all of these rules are native together: when a process holds exactly the authority it was handed, when an update succeeds only from the state it was based on, and when "done" is stated at the strength the evidence supports. The organizing invariant is that no transition may claim more certainty, authority, effect, or durability than its inputs establish.

The hypothesis is not that this is free. It is that the costs are specific and measurable (few are measured yet; multicore throughput was found bounded by kernel serialization), and that a small system built this way can still run ordinary software. ABSD exists to find out where that holds and where it does not.

What exists today

On the main branches (2026-10-07) the kernel is about 46,000 lines of Rust and the platform (runtime, file server, SSH server, commands) about 32,000, counting tests and comments but not vendored code. One developer directs the work; AI coding agents did most of the implementation and the review described below.

Method: bounded acceptance

The method is part of the research. A result is accepted only in a named form:

This makes progress slower to state and easier to check. The evidence page shows the record kept for each milestone and release.

Selected milestones

DateResultLabel
2026-09-27General usability under QEMU: a single-operator system administered over stock OpenSSH, with 55 programs built reproducibly and durable state checked over hundreds of crash bootsMILESTONE-QUALIFIED
2026-09-30 to 10-03Misbehaving programs contained to themselves in every case tried; 87 adversarial program images (60 refused, 27 boundary cases accepted) left resources unchanged when run as their own stage; a scripted 28-check pass over kernel-to-process output paths, one CPU, found no kernel addresses or stale memory (side channels not assessed). The last two were later release-qualifiedVALIDATED
2026-10-04Release absd-20261003.1: the system under TCG or KVM, with update from the previous release and rollback to itRELEASE-QUALIFIED
2026-10-04Several-CPU scheduling and migration with 2, 4, and 6 virtual CPUs under KVM, as researchVALIDATED
2026-10-05A 64-bit ARM port of the kernel under QEMU, merged after a separate AI-run reviewVALIDATED
2026-10-05First read-only native boots on one physical machine, read from photographs of the screenEXPERIMENTAL-INTEGRATION
2026-10-10The main development line passes the whole platform check. It includes multi-sector block requests, a boot that survives a network link that is down, and a bounded recovery budget (the budget qualified by its own separate run). Not a releaseVALIDATED
2026-10-09 to 10-10On unmerged development branches, in virtual machines only: the filesystem on the ARM port, GICv3 support, and USB controller (xHCI) enumeration of one deviceVALIDATED
2026-10-10A seven-day unattended observation of the main development line under QEMU started; it ends 2026-10-17 and has no result yetEXPERIMENTAL-INTEGRATION

Questions under investigation

Authority at the time of an effect
A check made before an action can be stale by the time the action happens. Versioned cells and per-operation rights checks address this for state the kernel owns MILESTONE-QUALIFIED. Whether the same discipline can carry authority whose grounds expire, and how spent authority is kept from becoming unspent after a crash or a lost reply, is open PLANNED.
Durability as a stated contract
The filesystem's guarantees are qualified under two modeled failure laws MILESTONE-QUALIFIED. A native storage engine, admitted by the semantics its consumers need rather than by feature list, is current work and not claimed EXPERIMENTAL-INTEGRATION. Real power loss on real drives is not yet tested UNSUPPORTED.
Several CPUs without weakening the invariants
Multicore scheduling is validated as research, with each process on one CPU at a time and a measured serialization boundary VALIDATED. The open question is how far parallelism can go before lifetime and authority rules need new mechanisms, and which of those mechanisms earn their cost. A successor study of object lifetime across CPUs is current work EXPERIMENTAL-INTEGRATION.
Semantics across architectures
The ARM port runs a fixed workload whose results are compared with the x86-64 build VALIDATED. The question is whether the kernel's guarantees are properties of the design or of one architecture's memory model.
Several principals without accounts
Today one operator identity holds a fixed authority ceiling. How independently authenticated principals can hold different authority without importing user IDs and permission bits is an open design problem PLANNED.
Compatibility above native semantics
How much ordinary software runs above a native interface that differs from Unix, and where it stops, is measured for Rust programs MILESTONE-QUALIFIED. A foreign-binary personality is a deferred experiment, with a stop rule if it begins to pull the native design toward the foreign one PLANNED.
Operating the system, not just running it
Configuration, time, networking status, and failure records as explicit contracts with desired and observed state, rather than as files read once at boot PLANNED. The north star is a system that runs unattended for months within declared limits; that is a direction, not a claim.

Near-term program

What dedicated resources would change

The constraint is evidence, not ideas. Specific resources would turn current limits into testable claims:

What this is not

Adjacent work

Constellation, a separate project by the same author, is an experimental set of programs that keeps a worker's report that something is done apart from independent evidence that it is true now. It shares some of ABSD's ideas: refusal over guessing, and claims no stronger than their evidence. ABSD runs some of its programs as native workloads because they were not written for ABSD; nothing in ABSD depends on them, and ABSD's semantics are not defined in their terms. See research.