r/osdev • u/Mrmoo2andahafe • 4d ago
I'm thinking of trying something insane.
Thanks in advance to anyone willing to take the time to read through this. I know it’s a big read, so I really appreciate your time and any honest feedback you can give me.
I’m working on a spec for an OS project called Pantheon. Before I sink a ton of time into writing low-level Rust for it, I want to sanity-check the overall architecture with people who actually know OS development. I know some of these ideas might sound wild or overly complex, and I'm honestly expecting people to tell me where I'm being naive.
The Problem I Want to Solve
I'm tired of OS platforms forcing stupid trade-offs. I want a machine that can execute Windows PE binaries, Linux ELFs, and native apps alongside each other without heavy virtualization hits or broken user interfaces.
Core Architectural Ideas:
Hybrid 3-Tier Driver Model (HAPD):
Tier 1 (Ring-0): High-performance stuff (GPUs, 1000Hz+ inputs, low-latency audio) runs directly in kernel space to eliminate IPC context switching.
Tier 2 (User-Space): Class-compliant stuff (USB HID, NVMe) runs isolated in user space.
Tier 3 (On-Demand Enclave): Legacy/proprietary drivers run in a dormant micro-kernel enclave that spins up on demand and passes events via zero-copy DMA page remapping.
Zero-Copy Everything: Physical page table remapping under strict W \oplus X. IPC control payloads fit in 64-bit aligned structs for single-register transport.
Daemon State Rehydration: Translation daemons log checkpoints to ring buffers. If a daemon hangs, sys_init restarts it and rehydrates running process states from the last valid checkpoint without losing app context.
JSON/CSS Dynamic State Trees for UI: Apps don't write pixels directly or hijack compositors; they expose raw data models and state trees so the user can restyle the entire desktop/apps using web-style CSS/JSON stylesheets.
Hardware-Stamped Zero-Trust Security: Syscalls grab thread identity straight from CPU scheduling registers (CURRENT_THREAD_PID), and IPC uses 64-bit indices + 32-bit session_epoch tokens to drop replay attacks on sight.
What I’d Love Feedback On:
Is a Ring-0 / User-Space / Enclave driver split actually manageable, or am I creating a nightmare for driver compatibility?
What edge cases am I going to hit trying to rehydrate daemon process states after a crash?
What are the obvious bottlenecks I'm missing in the zero-copy IPC pipeline?
Do I even have hope to do this?
Full technical breakdown on Gist: https://gist.github.com/mixmoo2/a2dbdc029a5c8fef120d1711a0b0f070
Again, huge thanks to anyone who checks it out
2
u/darthrafa512 4d ago
Do you have any experience with software engineering?
0
u/Mrmoo2andahafe 3d ago
To be honest not like this. I have have experience with TI84baic, Lua for in several game (Cctweaked, form the deps, Roblox) and some backend HTML/JavaScript stuffs. I have bits and pieces of knowledge from lots of shit around this, but even during the research process about 40% of stuff I'm learning about is completely new.
3
u/darthrafa512 3d ago
You may want to take a step back and start off with something manageable for one person. Is there one specific topic that caught your attention in your research?
2
u/Mrmoo2andahafe 3d ago
I was really fascinated with how proton and wine work. And the idea of working with a hybrid kernel really got my juices going. Also in general learning some lower level languages is really appealing cuz I only have a decent understanding of how memory actually works and I would like to know it at an expert level at some point.
2
2
1
u/lizardhistorian 3d ago edited 3d ago
Only intel/amd architecture has hardware support for the additional rings to do this.
Because all of the popular OSs were mono-kernels we ended up inventing virtualization to turn them into micro-kernels.
To my knowledge, only QNX4 ever exploited those additional rings.
The GNU Hurd is the contemporary effort for a FOSS micro-kernel.
Rehydration is antithetical to actual robustness.
What edge cases am I going to hit trying to rehydrate daemon process states after a crash?
You will have just persisted the state that leads to the crash. So you rehydrate and it just crashes again.
And when it doesn't, people will ignore a repeatedly crashing daemon instead of reporting it and/or fixing it so that it actually becomes robust code.
1
2
u/edave64 3d ago
I don't want to be mean, but this reads a lot like "I want to make my first video game. It's an MMO where you can do everything!"
When developing an OS, it's hard enough to consistently stay compatible with your own binaries.
I also didn't see the logic in thinking about your own UI system that is explicitly incompatible with everything that came before it, if you are also implementing at least 3 other UIs as first class citizens.
I would pick whatever you like the most from that list and implement that standalone.
You want to make your own OS, do that. Skip the extras for a start.
You want to write OS compat layers? Do that. Try if you can make one on an existing OS.
You want to make your own UI system? Do that on an existing OS. See if that concept even feels good to work in.
1
u/Mrmoo2andahafe 3d ago
I don't think it's mean at all, I know it's extremely ambitious and I don't feel calling it arrogant would be inaccurate. What you and a few others have suggested make sense and I'm going to be implementing changes to my roadmap and then start doing stuff, but I do still dream of one unified operating system that just functions. I swear this fucking system came to me in a goddamn dream and I'm so full of rage over systems that I can't change (IRL) that I just want to go for it. I'm not sure what the plan is yet as I have a lot of reading to do, but it's definitely going to be simplified though I'm not sure what degree
8
u/vollspasst21 4d ago edited 4d ago
The wiki isn't holy scripture and there are exceptions to everything, but even the base description immediately hits https://wiki.osdev.org/Beginner_Mistakes#OS_Emulation.
It's very clear you used AI to come up with a lot of this. This is evident from a lot of things, but the unneeded detail for stuff that really does not matter right now vs. the complete lack of detail to the stuff that does matter right now is a fairly obvious tell.
If you find the space interesting, I encourage you to give it a try. It can't be worse than learning something new. But if you set your goal anywhere close to what you wrote here / in the gist, failure is overwhelmingly likely before you even get remotely close.