Operating Systems
See all 16 articles in Operating Systems →
PointSav builds a family of purpose-built operating systems that share a common seL4 and Rust substrate. Each does one job, contains no features it does not need, and communicates through a common Diode-based protocol discipline. The result is a family that can be audited component by component, upgraded independently, and deployed in any configuration without unexpected coupling between systems.
Where to start
Sixteen articles cover the operating systems PointSav ships and the archive layer beneath them. These five come first: the family map, then the four systems the rest of the knowledge base refers to constantly.
- OS family — eight operating systems, one substrate — What each of the eight is for, what they share, and which parts of the shared substrate are roadmap rather than shipped.
- os-console — the Command Ledger — The human-facing surface: a single-binary, keyboard-native console that hosts independent F-key cartridges through one chassis.
- Sovereign vault and service host — The archive layer: one isolated vault per entity, holding inert flat files with no delete, exposed through the Diode only on command.
- Fleet aggregator — The commercial tier: one operator seeing, querying, and commanding many Totebox archives at once.
- os-infrastructure — PPN node operating system — The node OS under a private compute fleet: WireGuard tunnels, guest VMs, and the operator control plane, and nothing else.
The archive layer
The core record-keeping systems at the foundation of every deployment — where the canonical record lives and how it is coordinated across a fleet.
- Sovereign vault and service host — os-totebox is the archive layer of the PointSav family — one isolated vault per entity, storing inert flat files with no delete, exposed via the Diode on command. Its production path hosts a Linux guest under the seL4 microkernel; other host forms exist for compatibility and local development.
- Totebox orchestration — Totebox Orchestration is the coordination layer managing multiple Totebox data-archive containers, keeping execution engines isolated from passive corporate ledgers.
- VM-* architecture and OS family — The PointSav platform organises runtime deployments under five named VM types — Totebox, MediaKit, Orchestration, PrivateGit, Infrastructure — each mapping to one os-* binary.
- Scaling coordinated development across many Totebox Archives — Coordination bottlenecks past twenty archives — publication serialization, message relay latency, operator load, and the path to per-archive process isolation.
- os-totebox: the sovereign WORM data vault — os-totebox is designed to become a Type I bare-metal OS built on a formally verified seL4 microkernel, with a WORM data vault enforced by a compiled capability graph — the intended end state, not the software running today.
- How service-* Become seL4 Protection Domains on os-totebox — How os-totebox is designed to map Rust service binaries to seL4 Protection Domains: the planned seven-PD stack, capability confinement, startup ordering, and the two-bottom development path — Phase H1 roadmap work, not the binary running today.
Operator surfaces
The systems through which a human operator interacts with the platform — keyboard-driven, F-key-structured, and built around muscle memory rather than discoverability.
- os-console — the Command Ledger — os-console is the human-facing surface of the PointSav platform — a single-binary, keyboard-native Command Ledger that connects to a Totebox and hosts independent TUI cartridges through a unified chassis.
- os-console: The Totebox Orchestration Browser — os-console-totebox-browser has been folded into os-console's own 'Why this design: the browser analogy' section — this article is now a short pointer, not a separate deep dive.
- Input machine — The Input Machine is the mandatory document ingest gate in os-console, bound permanently to F12 and backed by service-input on the Totebox Archive.
- Sovereign desktop — os-workplace is the planned free desktop tier in the PointSav family — today a growing set of independent Rust and Tauri apps an operator runs on their own computer, joining the network as a station-* WireGuard peer; the intended adoption gateway to the commercial line.
- Fleet aggregator — os-orchestration is the commercial-tier OS letting a single operator see, query, and command many Totebox archives at once — the Fleet Aggregator for enterprise deployments.
Network control and infrastructure
The systems that manage the network fabric, the bootstrap path, and the underlying compute substrate.
- OS network admin — os-network-admin is the control plane for a PPN: WireGuard mesh routing, the node-join ceremony surface, and Diode-standard enforcement, without archive-tier authority.
- Private git OS — The OS layer hosting the private Git infrastructure underpinning the development workspace, staging-tier commit flow, and canonical repos for PointSav engineering.
- os-infrastructure — PPN node operating system — os-infrastructure is the OS layer for PPN nodes — its sole purpose is to set up and maintain a node: WireGuard tunnels, guest VMs, and the operator control plane.
Publishing and media
The public-facing OS that hosts the company's marketing surface, internal wiki, and compliance newsroom on a single sovereign appliance.
- OS mediakit — The public-web tier of the PointSav OS family — os-mediakit owns TLS, systemd lifecycle, and gateway-mediated data access; app-mediakit-knowledge/marketing/distribution own domain logic. Ubuntu 24.04 today; the planned end state is one seL4 VM per deployment instance, not a single combined appliance.
See also
- Architecture — cross-cutting platform architecture and the three-ring model
- Platform Services — the autonomous services that run within and across operating systems
- Infrastructure — fleet deployment topology and cloud operational runtime
- Core Concepts — the substrate disciplines and microkernel primitives the OS family inherits