Repository navigation
SharpMetal v2.0.0: The Microkernel Frontier
SharpMetal is an experimental, bare-metal x86_64 microkernel written in 100% pure C# and compiled to zero-dependency native code using .NET 10 Native AOT. Operating at Ring 0 with a capability-based security model inspired by seL4, it features zero garbage-collection overhead in core IPC/scheduler paths and executes within a Higher-Half Direct Map (HHDM) memory layout.
Version v2.0.0 introduces the Frontiers 1–5 architectural hardening milestone: a hardened VMM with demand paging and COW, dynamic ELF/PIE execution, a full Layer 2–4 network stack, a native USB 3.0 xHCI host driver with HID support, and a userland POSIX compatibility layer.
What's New in v2.0.0
1. Frontier 1: VMM & SMP Concurrency Hardening
- Lock-Free COW Refcounting:
PhysicalFrameRefcountconverted to atomic Compare-And-Swap (CAS) loops, eliminating spinlock contention during high-frequency Copy-On-Write page sharing and unsharing. - Inter-Processor TLB Shootdown:
SmpTlbShootdownintegrated across all mutation paths—both during frame duplication and when single-reference pages are upgraded back to writable mode. - Canonical Address Boundary Enforcement: The fault handler strictly enforces the
< 0x0000_8000_0000_0000bound, immediately terminating unprivileged processes that attempt to probe the higher-half direct map (HHDM).
2. Frontier 2: Dynamic ELF/PIE Relocation & Execution
Userland.PieLoadergains a zero-alloc ELF64 parser (Elf64_Ehdr/Phdr/Dyn/Rela) withPT_LOADsegments registered as demand-paged, file-backed VMAs.R_X86_64_RELATIVErelocations applied against an ASLR base; kernelSysSpawnElfsynthesizes the System V initial stack (argc/argv/envp +AT_PHDR/AT_ENTRY/AT_RANDOMauxv) and drops to Ring 3.
3. Frontier 3: VirtIO Network Driver & Microkernel IP Stack (net.stack)
- Layer 2/3/4: Ethernet framing, ARP cache with expiration, IPv4 routing with checksum calculation, ICMP echo responder, UDP sockets, and a full TCP state machine (CLOSED through TIME_WAIT) with RTO retransmission.
- POSIX-like Socket RPC:
socket,bind,listen,accept,connect,send,recv, andcloseexposed over the capability-securedINetworkServiceendpoint. - VirtIO-Net: Split RX/TX virtqueues with zero-alloc DMA replenishment and interrupt-driven RX via
sys_recv_any.
4. Frontier 4: USB 3.0 xHCI Controller & HID Drivers (bus.xhci)
- Native xHCI Subsystem: Full hardware lifecycle management—DCBAA, Command/Event/Transfer rings, ERST, per-ring cycle-bit tracking, doorbell arrays, and scratchpad provisioning.
- USB HID Boot Protocol: Keyboard and mouse enumeration, 8-byte boot report translation via HID usage tables, and keys injected into
input.hidvia theInjectKeyRPC. - Fail-Safe Legacy Handoff: The
USBLEGSUPownership handshake is timeout-bounded; on timeout, the driver cleanly aborts without disabling BIOS legacy emulation, keeping the PS/2 input path functional. A bare-metal safety gate spawnsbus.xhcionly whenxhci_native.flagis present in the initrd or a hypervisor is detected, keeping PS/2 authoritative on physical hardware unless explicitly opted in.
5. Frontier 5: POSIX / Libc & WASI Compatibility Layer (Microkernel.Posix)
- Syscall ABI Emulation: Per-thread Linux ABI mode in the kernel dispatch table translates Linux x86_64 syscall numbers (
read,write,open,close,mmap,brk,socket,exit) into SharpMetal capability RPCs. - FD Multiplexer: FDs 0/1/2 route to the console/input service; FDs >= 3 route to FAT32/VFS handles or network sockets.
- POSIX Host Runner:
posix_runnerhosts statically linked PIE binaries in isolated Ring 3 capability domains.
6. Freestanding Native AOT Runtime Stubs
- Standalone runtime stubs (
RhpAssignRef,RhpNewFast,RhpPInvoke,__security_cookie) implemented across all modular userland drivers, stripping away unnecessary CoreLib dependencies.
7. Build Pipeline & Concurrency Performance
Make-DiskImage.shpackages 12 initrd payloads (11 zero-alloc service binaries plus the xHCI native opt-in flag) intodisk.img.- Removed
-maxcpucount:1throttling, unlocking full multi-core Roslyn and NASM compilation with safe sequential project ordering. - Added
Rebuild-KernelOnly.shfor rapid kernel turnaround.
Quick Start & Installation
Running via QEMU (Recommended)
Ensure QEMU and OVMF UEFI firmware are installed, then execute:
qemu-system-x86_64 \
-M q35 \
-cpu host -enable-kvm \
-m 2G \
-smp 4 \
-bios /usr/share/ovmf/OVMF.fd \
-drive file=disk.img,format=raw,if=none,id=nvm \
-device nvme,serial=deadbeef,drive=nvm \
-netdev user,id=net0,hostfwd=udp::8080-:8080 \
-device virtio-net-pci,netdev=net0 \
-device qemu-xhci,id=xhci \
-device usb-kbd,bus=xhci.0 \
-serial stdio(Note: On systems without /usr/share/ovmf/OVMF.fd, install ovmf or edk2-ovmf via your system package manager).
Flashing to Physical USB Drive (Bare-Metal)
Identify your target USB drive (lsblk) and write the raw GPT disk image:
# Replace /dev/sdX with your actual USB target drive
sudo dd if=disk.img of=/dev/sdX bs=4M status=progress oflag=syncReboot into UEFI setup, disable Secure Boot, and select the USB drive. On bare metal, the PS/2/legacy keyboard path remains authoritative unless xhci_native.flag is added to the initrd.
Included Release Assets
disk.img: Complete 64MB GPT disk image containing the EFI system partition (FAT32), direct UEFI application boot, the SharpMetal microkernel binary, and the 12-payloadINITRD.IMG.nvme.img: 64MB NVMe storage disk image pre-formatted with FAT32 containing userland test binaries (/bin/test.pie,/bin/posix_test,/bin/cat.pie,/bin/hello.pie) and sample assets (/HELLO.TXT).BOOTX64.EFI: Standalone x86_64 UEFI Native AOT executable.