Project
MakopaOS
A small operating system lab for studying how a computer boots, runs isolated programs and controls access to resources.
Engineering reading paths
Connect repository policy with component evidence and explicit execution boundaries.
Start here
A passing check establishes only the decision it actually evaluates. Compare desired-state repository evaluation with component pre-admission checks, preserving missing evidence and the separate authority to act.
Curated connections
Project
A small operating system lab for studying how a computer boots, runs isolated programs and controls access to resources.
Project
A hands-on lab for building Linux images and learning how drivers communicate with simulated devices on two processor architectures.
Curated connections
Engineering update
OS041A adds bounded parsing, signatures, exact-byte binding and source inventory checks. A passing report still has admission_authority: false.
Engineering update
M9 adds a versioned desired-state contract and deterministic evaluator. Collected observations, hosting-service enforcement and continuous attestation remain separate responsibilities.
Engineering update
Closed lab manifests now separate x86-64 PCI MSI/INTx and bounded DMA from an ARM64 Device Tree and platform-driver path. The ARM64 peripheral has its own hardware contract and does not expose DMA.
Engineering update
The retained BIOS example is now accompanied by a freestanding Rust kernel and thin UEFI loader. Fixed workloads exercise task isolation, capability-mediated IPC, a bounded approval broker, and a supervisor-readable effect journal.
Curated connections
Article
MakopaOS binds component bytes to signatures and source evidence, while deliberately keeping admission authority false. A precheck and permission to execute are separate decisions.
Article
The Yocto and QEMU lab separates a versioned policy, a collected observation and a deterministic evaluator. A matching snapshot does not establish continuous enforcement.
Curated connections
Bounded evidence
Source-based explorer. Explore discovery, registers, interrupts and DMA in the two documented lab compositions. No virtual or physical device runs in this explorer.
Curated connections
System map and source
Explore the documented boundaries and pinned sources in this case study. Evidence reviewed 8 October 2026.
System map and source
Explore the documented boundaries and pinned sources in this case study. Evidence reviewed 8 October 2026.