Build and run software on JefeOS
A practical front door for humans and coding agents working with an early-1.x hobby OS. Pick the native or Linux-compatible path, boot a disposable VM, transfer one program, and expand the reference only when you need it.
Native JefeOS
Best-supported. Build an x86_64 ELF for the native INT 0x80 ABI and run it with exec.
Linux ABI (JSL-1)
Use an x86_64 Linux ELF that fits the translated syscall surface. Start with static musl and run with exec_linux.
POSIX measurement
POSIX is a portability target, not a third runtime. Its May coverage estimate needs a refreshed measurement; do not use it as a release headline.
Current downloads
Unless a task names JefeRust, this manual targets the immutable C++ 1.1.2 release. The separate JefeRust 1.1.0 release is bound to exact commit 80e07d9b; its ordinary SMP0 image is the primary Rust download, while SMP1 was built and checked but not live-proven. Facts labeled development describe moving master and are not ISO claims.
JefeRust 1.1.0 is qualified: final gate accounting recorded 17 PASS, 0 FAIL, and 2 NOT-RUN. Operational validation observed the exact-product bot for 8,527 seconds with 30/30 READY samples and no product failure.
Baseline constraints
512 MiB, BIOS/legacy boot, IDE storage, E1000-class networking, and normal single-core operation. Hyper-V requires Generation 1 plus a Legacy NIC. Native virtio block/network is absent.
The 1.1.2 lab SSH identity is ephemeral and its demo password must stay on loopback/NAT. C++ strict TLS chain/signature enforcement is off by default.
Recommended first boot: QEMU
qemu-system-x86_64 -cdrom jefeos-1.1.2.iso -m 512M -serial stdio \
-netdev user,id=net0,hostfwd=tcp:127.0.0.1:2222-:22 -device e1000,netdev=net0
At the shell, run help. For a first program, attach a clone of the examples VHD and try exec /programs/hello, or transfer a static-musl ELF and run exec_linux /programs/hello-linux. Keep automation to one command per SSH transaction; && and general Ctrl+C job control are absent. /run is volatile, while /tmp is persistent only with writable NTFS mounted.
Boot and VM recipes
QEMU with a cloned examples disk
qemu-system-x86_64 -cdrom jefeos-1.1.2.iso -m 512M -serial stdio \
-netdev user,id=net0,hostfwd=tcp:127.0.0.1:2222-:22 -device e1000,netdev=net0 \
-drive file=jefeos-examples.vhd,format=raw,if=ide
VirtualBox
Create an Other/Unknown (64-bit) VM with 512 MiB, attach the ISO as optical media, use NAT with Intel PRO/1000 MT Desktop (82540EM), and attach only a disposable or cloned VHD.
Hyper-V
Use Generation 1, 512 MiB, the ISO as DVD, and a Legacy Network Adapter on the Default Switch. Remove the unsupported synthetic NIC.
# Elevated PowerShell
$vm = "JefeOS"
New-VM -Name $vm -Generation 1 -MemoryStartupBytes 512MB -SwitchName "Default Switch" -NoVHD
Set-VMDvdDrive -VMName $vm -Path (Resolve-Path .\jefeos-1.1.2.iso)
Get-VMNetworkAdapter -VMName $vm | Remove-VMNetworkAdapter
Add-VMNetworkAdapter -VMName $vm -IsLegacy $true -SwitchName "Default Switch"
Set-VMBios -VMName $vm -StartupOrder @("CD","IDE","LegacyNetworkAdapter","Floppy")
Start-VM -Name $vm
OpenStack
JefeOS 1.1.2 is validated as a Nova guest from a Glance ISO with an ISO 9660 config-2 config drive. Keep BIOS, IDE, and E1000 properties. DHCP data, hostname, and authorized keys are consumed; arbitrary static network data is not.
Connect and automate
The 1.1.2 release lab image uses an ephemeral SSH identity and demo login jefe / jefe. Keep it on loopback/NAT; never expose it through a bridged or untrusted network. Verify the first fingerprint through trusted local console/boot evidence, then pin it:
plink -P 2222 -ssh -batch -pw jefe -hostkey "SHA256:<verified-fingerprint>" jefe@127.0.0.1 "help"
ssh-keyscan discovers a key but is not trust proof. restore-network.ps1 is maintainer infrastructure, not public trust bootstrap. The development tree instead expects provisioned persistent trusted identity and disables password authentication if that identity is unavailable.
Treat each remote command as one transaction. Use SFTP only after confirming the destination is mounted writable NTFS; never host-edit a VHD while the guest owns it.
JefeRust's COM1 pipe is output-only: use it for boot evidence and SSH for commands.
Shell and automation rules
Pipes and >/>>/< redirection work. &&, ||, and ; chaining do not, and there is no general Ctrl+C foreground job-control path.
ps | grep shell
echo hello > /tmp/hello.txt
cat /tmp/hello.txt
exec_linux -bg /programs/server
jobs
Core commands include ls cd pwd mkdir rm cp mv cat stat chmod chown df du, grep head tail wc cut sort uniq tee tr, ps tasks jobs kill id sleep time sysinfo uptime free cpus, and ping dns dhcp ifconfig netstat curl ssh sftp ntp nts wsconnect.
Filesystems and writable-state rules
| Surface | State |
|---|---|
/run | Volatile tmpfs; cleared at reboot. |
/tmp | Persistent only when backed by the mounted NTFS data disk; not tmpfs. |
| NTFS data | Read/write, including non-resident and directory-index growth. |
| FAT32 | Read-only. |
NTFS lookup follows case-sensitive POSIX behavior. ATA PIO remains the C++ mounted block backend; AHCI transfer code is not the canonical mount path. JefeFS is a Rust surface, not C++. Keep a pristine VHD, operate on a clone, and shut down before host-side mounting or filesystem checks.
Build and run native programs
Native x86_64 ELFs use the JefeOS INT 0x80 ABI. Read BUILD-FOR-JEFEOS.md, start from the examples disk or userspace/programs, copy the result to writable NTFS, then run:
exec /programs/yourprog
The native process model centers on asynchronous sys_spawn. Fork exists but eagerly copies every present page, has no COW, and fails closed under SMP. Never invent syscall numbers; kernel/src/syscall.cpp is authoritative.
The 1.1.2 user/kernel boundary enforces SMAP/uaccess discipline: user buffers must be mapped, bad access returns EFAULT or a documented short copy, and kernel code uses copy_from_user/copy_to_user.
Build and run Linux programs / ABI status
JSL-1 translates x86_64 Linux SYSCALL operations into JefeOS; it is not a Linux kernel. The generated surface contains 160 syscall entries, but entry presence does not promise every Linux semantic corner.
- Tiers 1β4 are green: static musl, static glibc, dynamic linking, and busybox/Alpine-rootfs under
chroot. - Tier 5 is multi-part and partial: real OpenRC
sysinit β boot β defaultandapk infoare complete; the remaining proof is interactivegetty β /bin/loginon the console. fork()is eager-copy, UP-only, and has no COW.- Confirmed gaps include
clone3,io_uring,aio_*,inotify, andvmsplice.pidfdis partial;sendfile,splice, andteeare implemented.
exec_linux /programs/hello-linux
lcompat
exec_linux -bg /programs/server --port 8080
Unimplemented calls fail and appear in diagnostics. POSIX is measured separately; the old ~83% number is a May estimate awaiting refresh.
Networking and TLS
The C++ kernel includes Ethernet, ARP, IPv4, ICMP, DHCP, DNS, UDP, TCP client/server, IPv6 link-local/NDP, NTP/NTS, TLS 1.3, HTTPS, SSH client/server, SFTP, and WebSocket-over-TLS.
ifconfig
ping 8.8.8.8
dns example.com
curl https://example.com/
netstat
TLS boundary: C++ hostname checks, supported-invalid signatures, and Finished verification fail closed, but strict_chain_verify and strict_sig_verify are off by default. Do not send sensitive credentials based on default validation. JefeRust is strict by default and requires a chain terminating at a pinned anchor plus CertificateVerify processing.
The kernel HTTP server supports GET/HEAD and a small GET /api/status snapshot. Most detailed state remains shell text over SSH.
Worked example: static Linux hello
On a Linux build host:
// hello.c
#include <unistd.h>
int main(void) {
static const char msg[] = "hello from JefeOS via JSL-1\n";
return write(1, msg, sizeof(msg) - 1) < 0;
}
musl-gcc -static -O2 -s -o hello-linux hello.c
file hello-linux
Transfer the file to a writable NTFS-backed /programs/hello-linux, then run exec_linux /programs/hello-linux. If it fails, verify the ELF architecture, path, and permissions; run lcompat; and inspect serial diagnostics for an unimplemented syscall number.
Limits and safety notes
- VM-first, no installer, no supported physical-hardware path.
- Clone writable disks; never attach one writable image to two running VMs.
- Normal operation is single-core. Shell chaining and general Ctrl+C job control are absent.
- DHCP addresses and guest host keys can change. Hyper-V needs a Legacy NIC.
- FAT32 is read-only; AHCI is not the mount backend; native virtio block/network is absent.
- JSL-1 is incomplete; Tier 5 remains multi-part. Fork has no COW and is UP-only.
- The C++ TLS client does not enforce strict chain/signature validation by default; do not send sensitive credentials based on it.
- Graphics and the in-kernel window manager are experimental, not a supported desktop or quickstart path.
- There is no stable public Xylem application API or production-safe cross-vessel workload contract.
Compact capability reference
| Area | Available | Boundary |
|---|---|---|
| Native | x86_64 ELF, libc, INT 0x80, spawn | Use build guide and current syscall map |
| Linux ABI | 160 generated entries; Tiers 1β4 green | Tier 5 partial; not full Linux semantics |
| Storage | C++: NTFS r/w, tmpfs, FAT32 read | JefeFS is Rust; clone disks; ATA PIO is C++ backend |
| Network | TCP/IP, SSH/SFTP, TLS/HTTPS, NTP/NTS, WS | C++ strict public-PKI mode off by default |
| Graphics | Experimental framebuffer/WM code | Not a supported desktop entry point |
| JefeRust | Separate 1.1 kernel; ordinary SMP0 and built/checked SMP1 images | Bounded Xylem release, not full current-C++ parity; SMP1 lacks live proof |
For release evidence and the larger status ledger, see the Dashboard.
Xylem: current clustering boundary
Xylem is the native-clustering direction, not a prerequisite for ordinary applications.
- JefeOS 1.1.2, both kernels: SWIM membership and failure detection, proven C++βC++ and C++βRust.
- JefeOS 1.1.2, C++: first-class
Service, local reconcile, crash-loop guard, and a deterministic-primary stateless singleton failover demo/self-test/harness. - JefeRust 1.1.0: a bounded service/local-reconcile path, stateless
desired=1placement, canonical signed grants, mirrored durable authority floors and revocation, authority-gated lifecycle, and one bounded real-panic recovery/reconvergence proof. - Qualification: qualified, with final gate accounting of 17 PASS / 0 FAIL / 2 NOT-RUN. Operational validation observed the exact-product bot for 8,527 seconds with 30/30 READY samples and no product failure.
- Open: full current-C++ parity, authenticated membership, production quorum, resource-side fencing, N-of-M placement, a stable service front door, fleet observability, migration, state transfer, general stateful failover, and SMP1 live proof.
The C++ and Rust evidence paths remain distinct. JefeRust 1.1 proves a bounded compiled-in stateless singleton lifecycle and panic recovery; it does not migrate a process, preserve application state, or make split-brain writes safe. Read the Xylem whitepaper and current-status boundary.