libcanberra: plasma-workspace calls find_package(Canberra) TYPE REQUIRED and includes <canberra.h> from four translation units with no HAVE_CANBERRA guard, one of them libnotificationmanager (the core notification library). It cannot be made optional, so it is ported for real. Built shared: it dlopens its backend through libltdl, the libtool recipe stages libltdl.so only (no .a), so a static build left every consumer with an undefined lt_dlopenext. Audio is SILENT. Upstream 0.30 offers alsa/oss/pulse/gstreamer/null and none speak Redox; the pulse driver needs PulseAudio's client library, which PipeWire does not provide. The null driver is real upstream code, so the API/ABI is genuine and all consumers work -- but nothing reaches the speakers until a native /scheme/audio driver exists. KX11Extras et al: gate the five X11-only KWindowSystem headers behind the HAVE_X11 that plasma-workspace already defines. X11 is compiled OUT, not added. gate-kx11extras.py brace-matches each block and keeps any trailing else outside the guard, since wrapping a whole if/else-if chain yields invalid C++. check-recipe-escapes.py: a single backslash in a TOML multi-line string is a TOML escape, so a sed written as \bFoo\b parses to <BS>Foo<BS> and silently matches nothing -- no TOML error, no sed error. This class bit the tree three times. Now gated in preflight; it also found openssh, which used an invalid \$ and could not be parsed by any compliant parser. cook_build.rs: build git-tracked vendored sources OUT OF TREE. Recipe scripts rewrite their source, so builds were mutating version-controlled files: a no-op sed became indistinguishable from a working one, and the integrity gate fired so often that clearing it stopped being protective. Uses cp -a --reflink=auto, not cp -al: sed -i is link-safe but `cp -f` and `>` truncate in place and would write through a hard link into the tracked original. Content hashing still runs against the pristine tree, so hashes now describe committed state. Escape hatch: REDBEAR_IN_TREE_BUILD=1.
Red Bear OS
A microkernel operating system written in Rust — derived from Redox OS, built for bare metal.
What is Red Bear OS?
Red Bear OS is a general-purpose, Unix-like operating system with a microkernel architecture,
written entirely in Rust. It is a full fork of Redox OS (baseline 0.3.2), actively developed
on branch 0.3.2 with hardware enablement, multiple filesystems, a native greeter and login
system, and a KDE Plasma desktop path.
We aim to stay close to upstream Redox — diverging only where necessary to add missing functionality, fix bugs, or support new hardware. The build system itself is under constant active development alongside the OS.
It ships with several first-in-class Rust-native tools found nowhere else in the OS world:
- cub — an AUR-inspired package manager with pacman-style CLI (
-S/-Q/-R) and a ratatui TUI that converts Arch Linux PKGBUILDs into Red Bear recipes on the fly - tlc (Twilight Commander) — a pure-Rust reimplementation of Midnight Commander; dual-panel file manager, built-in editor and viewer, 8 color themes, 1204 unit tests, zero unsafe code
- redbear-power — interactive ratatui TUI for live CPU frequency, governor, and thermal monitoring with on-the-fly P-state control
These are joined by dozens of redbear-* system utilities — redbear-netctl (network control),
redbear-info (hardware diagnostics), redbear-acmd (admin CLI), redbear-mtr,
redbear-nmap, redbear-btctl, and many more — all written in Rust, all built from source
alongside the OS.
Goals:
- AMD & Intel parity — equal-priority bare-metal support for both platforms
- KDE Plasma desktop — Wayland-based desktop environment via the KWin compositor
- Hardware GPU acceleration — AMD (amdgpu) and Intel GPU drivers via
redox-drm - cub package ecosystem — AUR → recipe.toml pipeline giving access to thousands of packages
- First-class subsystems — USB, Wi‑Fi, Bluetooth, ext4, FAT, GRUB, D-Bus (none optional)
- Power management — CPU frequency scaling, thermal monitoring, RAPL, sleep states
- Offline-first, reproducible builds — BLAKE3-verified source archives with content-hash caching
Our Git Server
Red Bear OS lives on a self-hosted Gitea instance at https://gitea.redbearos.org.
This is the canonical home — no GitHub, GitLab, or Codeberg mirror is authoritative.
There is exactly one repository: all component sources (kernel, relibc, drivers,
system utilities) live here as submodule branches or tracked trees in local/sources/.
| Field | Value |
|---|---|
| Host | https://gitea.redbearos.org |
| User | vasilito |
| Web UI | https://gitea.redbearos.org/vasilito |
| Main repo | https://gitea.redbearos.org/vasilito/RedBear-OS |
Authentication tokens are per-session credentials — never stored in the repo. See
local/AGENTS.md§ Our Git Server for the full operator runbook.
Quick Start
Prerequisites
Linux x86_64 host with Rust nightly, QEMU, nasm, and standard build tools. See the Redox Build Guide for full setup.
Build & Run
# Clone (read-only)
git clone https://gitea.redbearos.org/vasilito/RedBear-OS.git
cd RedBear-OS
# Authenticated clone — supply token via env var
git clone https://vasilito:${REDBEAR_GITEA_TOKEN}@gitea.redbearos.org/vasilito/RedBear-OS.git
# Canonical build entry point
./local/scripts/build-redbear.sh redbear-mini # Text-only target
./local/scripts/build-redbear.sh redbear-full # Desktop-capable target
./local/scripts/build-redbear.sh -j 8 --allow-dirty redbear-mini # flags: see --help
# Boot in QEMU
make qemu
local/scripts/build-redbear.shis the only supported build entry point. It handles.configparsing, prefix staleness detection, protected-recipe authorization, pre-cooking critical packages, and source fingerprint tracking. Directmakeinvocations bypass these gates. Runbuild-redbear.sh --helpfor flags. Full reference:local/docs/BUILD-SYSTEM.md; see alsoAGENTS.md§ Build Commands.
Config Targets
| Target | Type | Description |
|---|---|---|
redbear-full |
Desktop-capable | GPU drivers + Wayland compositor + Qt 6.11.1 + KF6 6.27.0 + KWin + SDDM + greeter + D-Bus |
redbear-mini |
Console | Text-only recovery / install target with tlc, cub, and redbear-* utilities |
redbear-grub |
Console | Text-only with GRUB boot manager |
Current Status
Red Bear OS boots to a login prompt in QEMU with working wired networking, D-Bus system bus,
hardware detection daemons, and three filesystem backends (RedoxFS, ext4, FAT). The ISO builds
successfully on branch 0.3.2. Graphics packages are frozen at latest upstream stable
(Qt 6.11.1, KF6 6.27.0, Plasma 6.7.2, SDDM 0.21.0, Mesa 26.1.4, wayland-protocols 1.49).
| Area | Status |
|---|---|
| Boot (ACPI, x2APIC, SMP) | ✅ Bare-metal proven — Ryzen Threadripper 128-thread verified |
| Userspace drivers (PCI, storage, net) | ✅ Working in QEMU |
| Filesystems — RedoxFS, ext4, FAT | ✅ Scheme daemons + mkfs/fsck tools |
| D-Bus system bus + services | ✅ Working — login1, PolicyKit, UDisks, UPower |
| cub package manager | 🟡 17-module Rust workspace; AUR → recipe pipeline; 70+ tests |
| tlc file manager | 🟡 113 .rs files, 46k+ lines; 1497 tests; 8 skins; VFS archives; first-paint panic fixed (2026-07-24) |
| IRQ / PCI / MSI-X / IOMMU | 🟡 QEMU-proven; shared-IRQ re-arm bug class swept across 11 drivers (2026-07-20); hardware validation open |
| POSIX gaps (relibc) | 🟡 ~85% coverage; PATCHED-VIA-PATH-FORK — relibc changes are committed directly to local/sources/relibc/; local/patches/relibc/ holds reference and archived patches only |
| DRM/KMS display drivers | 🟡 AMD + Intel + virtio-gpu compile; HW validation open |
| Mesa — llvmpipe + virgl | ✅ Builds; EGL platform real, virgl auto-probe wired (DRM_IOCTL_VERSION major=0 + name + PCI info) |
| Mesa redox gallium winsys | ✅ Source landed; BO byte count now correct; per-surface crtc_id tracking via redox_drm_surface_set_crtc; meson wires it on iris/radeonsi; compile unverified in current canonical build |
| 3D userland (iris / radeonsi / Vulkan) | 🟡 Recipe enabled; configure failed on libclc — now fixed (libclc in deps); needs canonical build-redbear.sh redbear-full to validate |
| Qt6 Wayland null+8 | 🟡 Compile-time null guards in qtwaylandscanner (init_listener wrap) and libwayland (all wl_proxy_* entry points); runtime re-verification pending — static diagnosis only, no QEMU run with instrumented rebuild yet |
| SDDM display manager + Greeter/Login | ✅ Built; service + PAM + kde-wayland.desktop + greeter user all in redbear-full.toml; runtime proof needs canonical build |
| Qt 6.11.1 (Core, Gui, DBus, Wayland) | 🟡 Builds; Wayland null+8 statically diagnosed; needs isolated runtime fix |
| KF6 Frameworks — 40/40 | 🟡 All frameworks build; KWin cooks successfully |
| Wayland compositor | 🟡 Bounded proof; blocked by Qt6 Wayland protocol crash |
| KWin | 🟡 Builds successfully (redox-drm + Qt6 Wayland); runtime blocked by Qt6 Wayland crash in wl_proxy_add_listener |
| KDE Plasma | 🟡 All 38 KF6 frameworks + KWin + plasma-framework + plasma-workspace + plasma-desktop un-deferred in redbear-full.toml; runtime blocked on Qt6 Wayland null+8 fix |
| Wi‑Fi (Intel iwlwifi) | 🟡 VFIO/passthrough bounded runtime validation framework exists |
| USB / Bluetooth | 🟡 xHCI mature in QEMU: 51-flag quirks, capability gating, 36-code error recovery, Linux hub enumeration state machine, hub + hub-child enumeration proven, storage BOT proven; USB 2.0 HW LPM (L1) attach path implemented; endpoint-indexing bug class fixed across acmd/ecmd/usbaudiod/usbhidd; UAS/HID-parser expansion in flight; Bluetooth controller path planned |
Where help is most wanted: Qt6 Wayland protocol crash — the #1 blocker for graphical desktop · AMD/Intel GPU hardware validation on bare metal · USB controller maturity · Wi‑Fi native control plane · cub AUR pipeline hardening · package maintainers for the growing recipe catalog · tlc VFS remote backends and archive support
How It Works
Red Bear OS uses a userspace driver model — all drivers run as unprivileged daemons communicating through the kernel's scheme-based IPC.
┌─────────────────────────────────────────────────────────────────┐
│ KERNEL (microkernel) │
│ schemes: memory · irq · event · pipe · debug │
└──────────────────────────┬──────────────────────────────────────┘
│
┌─────────────────────┼─────────────────────────┐
▼ ▼ ▼
┌──────────┐ ┌──────────────────┐ ┌──────────────────────┐
│ pcid │ │ e1000d xhcid │ │ vesad redox-drm │
│ PCI enum │ │ Intel USB 3.0 │ │ fbdev GPU manager │
└──────────┘ └──────────────────┘ └──────────────────────┘
┌──────────┐ ┌──────────────────┐ ┌──────────────────────┐
│ ext4d │ │ ps2d evdevd │ │ thermald cpufreqd │
│ fatd │ │ KB+mouse input │ │ thermal CPU freq │
└──────────┘ └──────────────────┘ └──────────────────────┘
┌──────────┐ ┌──────────────────┐ ┌──────────────────────┐
│ iommu │ │ acpid │ │ dbus-daemon │
│ DMA map │ │ power mgmt │ │ system + session │
└──────────┘ └──────────────────┘ └──────────────────────┘
The kernel provides minimal services: memory, interrupts, and IPC. Everything else —
filesystems, networking, graphics, input, power management, D-Bus — runs in userspace.
Hardware quirks are handled by a data-driven system in redox-driver-sys with compiled-in
tables, TOML runtime configuration, and DMI matching.
Engineering Standards
Red Bear OS operates under strict discipline. Full policies: local/AGENTS.md.
| Rule | |
|---|---|
| Never delete to "fix" a build | If a package breaks, fix the root cause. Never remove, ignore, or comment out a package, service, or config to make a build pass. |
| Zero stubs | No fake headers, #ifdef no-ops, or "make it compile" shortcuts. Missing functionality must be implemented properly in the right component. |
| Single repository | All component sources live here — no per-component repos. 9 submodule/<component> branches. |
| Local fork model | Core components (kernel, relibc, base, bootloader, installer, redoxfs, userutils) are maintained as local forks in local/sources/ with immutability guarantees; syscall and libredox are wired as Cargo path dependencies via redbear-rt consumers, not via recipes/<comp>/recipe.toml path =. |
| Adapt to upstream | Red Bear adapts to upstream API/ABI changes — never pins, downgrades, or holds back a dependency. |
| Free/libre only | No proprietary, source-unavailable, or redistributability-restricted dependencies. MIT licensed. |
Documentation
- Desktop Path Plan — Canonical plan v6.0 (2026-07-27): kernel → DRM → Mesa → Wayland → KDE
- Implementation Plan — Roadmap and execution model
- cub Package Manager — AUR → recipe pipeline, CLI reference, architecture
- tlc File Manager — Pure-Rust Midnight Commander replacement
- D-Bus Integration — Session bus architecture
- IRQ & Low-Level Controllers — IRQ delivery, MSI/MSI-X, IOMMU
- Greeter & Login — Native greeter, auth daemon, session launch
- 3D Desktop Plan — DRM/KMS display, Wayland compositor, 3D userland (consolidates former DRM/Wayland/3D-driver/SDDM-bringup docs, deleted 2026-07-27)
- USB Plan — USB stack design and implementation
- Collision Detection Status — runtime collision-detection current state
- Build Tools — 15-tool reference (patch-status, sync, verify, collision, release-bump, etc.)
- Wi‑Fi Plan — Wireless architecture and driver plan
- Bluetooth Plan — Bluetooth stack design
- Build Cache — Content-hash (BLAKE3) build cache system
- Quirks System — Hardware quirks infrastructure
- Documentation Index — Full doc map
Contributing
Red Bear OS is a full fork of Redox OS. Upstream sources are frozen and archived; all
custom work lives in local/ and survives every build operation.
local/
├── sources/ # Local forks of core components (kernel, relibc, base, bootloader, …)
├── recipes/ # Custom packages — drivers, GPU stack, system daemons, branding
├── patches/ # Durable changes to upstream source trees
│ └── (orphan-patch governance: every patch must correspond to work
│ present in the matching fork source tree. `verify-patch-content.sh`
│ enforces this on every build preflight. See
│ AGENTS.md § "Orphan-Patch Supersession Decision Tree" for the
│ decision flow when an orphan is detected.)
├── docs/ # Integration and planning documentation
└── scripts/ # Build, test, validation, and release tooling
We're Looking For
| Role | What you'd work on |
|---|---|
| Package maintainers | Port and maintain AUR packages through cub's pipeline; write and test recipe.toml files for Red Bear OS; improve the PKGBUILD → recipe conversion |
| Driver developers | AMD/Intel GPU drivers, USB controller maturity, Wi‑Fi native control plane, Bluetooth |
| Graphics stack engineers | Qt6 Wayland crash fix (the #1 desktop blocker), Mesa virgl runtime, KWin Wayland compositor |
| Systems/Rust engineers | Kernel syscalls, relibc POSIX gaps, filesystem daemons, D-Bus services, hardware quirks |
| TUI/app developers | tlc feature completion, cub TUI polish, redbear-power enhancements, new redbear-* utilities |
Contributions are welcome with or without AI assistance — we care about quality, not how the code was produced. Pick an area from the status table above, check the relevant plan doc, and dive in.
License
MIT — same as upstream Redox OS.