CRITICAL F002 from NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1: worker_pool::OwnedFd::from_raw_fd accepted 'raw: usize' and called libc::dup(raw as i32) on it. A garbage 64-bit value that happens to cast to a valid i32 fd would clone whatever file was at that fd number — a confused-deputy vulnerability in a sandboxed microkernel. Fix: change the parameter type to std::os::fd::RawFd (the platform c_int). A garbage 64-bit value cannot be cast to a valid i32 fd anymore; the value can only have come from a previously-validated fd (via IntoRawFd::into_raw_fd, libredox::Fd::raw, or a similar source that went through the kernel's open-fd table). Callers in scheme/mod.rs use 'File::from_raw_fd(nf.into_raw() as RawFd)', so the cast site moves from inside from_raw_fd to the caller (where the value is known to be a real fd at that point). The function-level unsafe invariant is now stronger: 'the parameter is a RawFd that came from a real fd' rather than 'the parameter is any integer that might be a real fd'.
Base
Repository containing various system daemons, that are considered fundamental for the OS.
You can see what each component does in the following list:
- audiod : Daemon used to process the sound drivers audio
- bootstrap : First code that the kernel executes, responsible for spawning the init daemon
- daemon : Redox daemon library
- drivers
- init : Daemon used to start most system components and programs
- initfs : Filesystem with the necessary system components to run RedoxFS
- ipcd : Daemon used for inter-process communication
- logd : Daemon used to log system components and daemons
- netstack : Daemon used for networking
- ptyd : Daemon used for pseudo-terminal
- ramfs : RAM filesystem
- randd : Daemon used for random number generation
- zerod : Daemon used to discard all writes and fill read buffers with zero
How To Contribute
To learn how to contribute you need to read the following document:
If you want to contribute to drivers read its README
Development
To learn how to do development with these system components inside the Redox build system you need to read the Build System and Coding and Building pages.
How To Build
It is recommended to build this system component via the Redox build system, you can learn how to do it on the Building Redox page.
To build and test outside the build system, install redoxer then use check.sh script to build or test:
./check.sh- Check build for x86_64./check.sh --arch=ARCH- Check build for specific ARCH (aarch64,i586,riscv64gc)./check.sh --all- Check build for all ARCH./check.sh --test- Check the base system boots up on x86_64
You can also use make install to inspect the content on ./sysroot, or make test-gui to test booting with orbital interactively.