Repository navigation
Expand file tree
/
Copy pathhypervision.html
More file actions
350 lines (329 loc) · 18.2 KB
/
Copy pathhypervision.html
File metadata and controls
350 lines (329 loc) · 18.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Hypervision Plane — VirtIO Architecture & OS.1</title>
<link rel="stylesheet" href="index.css?v=6">
<style>
.grid-2 {
display: grid;
grid-template-columns: 1fr 1fr;
gap: 2rem;
margin-top: 2rem;
}
.grid-4 {
display: grid;
grid-template-columns: repeat(auto-fit, minmax(280px, 1fr));
gap: 1.5rem;
margin-top: 2rem;
}
.story-container {
max-width: 960px;
margin: 0 auto;
line-height: 1.8;
font-size: 1.05rem;
color: var(--text-secondary);
}
.story-container p {
margin-bottom: 1.5rem;
text-align: justify;
}
.story-container b {
color: var(--accent);
font-weight: 700;
}
.plane-header {
font-family: ui-monospace, monospace;
font-size: 1.3rem;
color: var(--accent-dark);
margin-top: 2.5rem;
margin-bottom: 0.75rem;
border-bottom: 1px solid var(--border);
padding-bottom: 0.4rem;
}
.ve-badge {
display: inline-block;
background: var(--accent);
color: #fff;
font-size: 0.8rem;
font-weight: 700;
padding: 2px 10px;
border-radius: 12px;
margin-bottom: 0.5rem;
text-transform: uppercase;
}
@media (max-width: 900px) {
.grid-2, .grid-4 {
grid-template-columns: 1fr;
}
}
</style>
</head>
<body>
<nav class="sticky">
<div class="nav-container">
<a href="index.html" class="logo"><img width="50" style="" src="https://n2o.dev/img/synrc.svg"></a>
<button class="nav-toggle" aria-label="Toggle navigation" onclick="document.querySelector('.nav-links').classList.toggle('open'); this.classList.toggle('open');">
<span class="hamburger"></span>
</button>
<ul class="nav-links">
<li><a href="index.html">Intro</a></li>
<li><a href="applications.html">Applications</a></li>
<li><a href="products.html">Products</a></li>
<li><a href="downloads.html">Downloads</a></li>
<li class="dropdown">
<a href="#" class="dropdown-toggle" onclick="event.preventDefault(); this.parentElement.classList.toggle('open');">Planes <span class="arrow">▾</span></a>
<ul class="dropdown-menu">
<li><a href="security.html">Security</a></li>
<li><a href="control.html">Control</a></li>
<li><a href="web.html">Web</a></li>
<li><a href="compute.html">Compute</a></li>
<li><a href="service.html">Service</a></li>
</ul>
</li>
<li class="dropdown">
<a href="#" class="dropdown-toggle" onclick="event.preventDefault(); this.parentElement.classList.toggle('open');">Languages <span class="arrow">▾</span></a>
<ul class="dropdown-menu">
<li><a href="language_beam.html">BEAM Elixir/Erlang</a></li>
<li><a href="language_clr.html">CLR F#/C#</a></li>
<li><a href="language_jvm.html">JVM Scala/Java</a></li>
</ul>
</li>
<li class="dropdown">
<a href="#" class="dropdown-toggle" onclick="event.preventDefault(); this.parentElement.classList.toggle('open');">Systems <span class="arrow">▾</span></a>
<ul class="dropdown-menu">
<li><a href="system_alpine.html">Alpine</a></li>
<li><a href="system_netbsd.html">NetBSD</a></li>
<li><a href="system_freebsd.html">FreeBSD</a></li>
<li><a href="system_btron.html">BTRON</a></li>
<li><a href="system_nuttx.html">NuttX</a></li>
<li><a href="system_lk.html">LK</a></li>
</ul>
</li>
<li><a href="hypervision.html" class="active">HV</a></li>
</ul>
</div>
</nav>
<header>
<div class="hero-content">
<h1>Hypervision Plane</h1>
<p class="hero-subtitle">High-assurance hypervisor (HV), poll-mode VirtIO engine (VIO), and operating system (OS.1) built for zero-copy, hard real-time microVMs, unikernels, and cloud virtualization environments.</p>
</div>
</header>
<main>
<section>
<h2>The Hypervision Triple: HV, VIO, OS.1</h2>
<div class="story-container">
<p>The <b>Hypervision Plane</b> brings together three foundational pillars of modern, capability-governed virtualization: the formally verified seL4 hypervisor wrapper (<b>HV</b>), the freestanding poll-mode VirtIO driver engine (<b>VIO / libvio</b>), and the unified virtualization environment and deployment platform (<b>OS.1</b>). Together, they eliminate legacy QEMU overhead and provide sub-millisecond boot latency with microsecond I/O responsiveness.</p>
</div>
<div class="package-cards-grid" style="margin-top: 2rem;">
<div class="package-card">
<span class="ve-badge">Hypervisor Root</span>
<h3>HV (Hypervisor)</h3>
<hr>
<p>Root isolation layer powered by the seL4 microkernel. Manages memory via strict capability derivations and runs unprivileged Protection Domains (PDs) in total hardware isolation.</p>
</div>
<div class="package-card">
<span class="ve-badge">VirtIO Poll Engine</span>
<h3>VIO (libvio)</h3>
<hr>
<p>Freestanding C11 VirtIO & NVMe engine engineered with TRON real-time discipline. Zero hidden heap allocations on hot paths, SPDK-style poll-mode queues, and zero-copy ring processing.</p>
</div>
<div class="package-card">
<span class="ve-badge">Deployment Platform</span>
<h3>OS.1</h3>
<hr>
<p>Complete Virtualization Environment (VE) and CI/CD platform unifying HV and VIO to orchestrate Alpine, NetBSD, Erlang BEAM unikernels, and C99 microVM protection domains.</p>
</div>
</div>
</section>
<section>
<h2>Target VirtIO Cloud Virtualization Environments (VEs)</h2>
<div class="story-container">
<p>Synrc Hypervision and VIO target four primary Virtualization Environments (VEs), ranging from bare-metal seL4 microkernels to enterprise cloud hypervisor clusters and containerized orchestration engines.</p>
</div>
<div class="grid-4">
<div class="package-card">
<span class="ve-badge">VE #0 — Native</span>
<h3>0) OS.1 VE</h3>
<hr>
<p>Native seL4/Microkit and microVM target providing poll-mode NVMe storage fast paths and sub-millisecond boot latency. Designed to challenge NanoVMs on density, memory footprint, and deterministic real-time discipline.</p>
</div>
<div class="package-card">
<span class="ve-badge">VE #1 — Foreign</span>
<h3>1) Proxmox VE</h3>
<hr>
<p>Seamless integration with Proxmox VE clusters via QEMU/KVM virtio devices and high-performance vhost-user backends over UNIX domain sockets for enterprise cloud workloads.</p>
</div>
<div class="package-card">
<span class="ve-badge">VE #2 — Virtual Machines</span>
<h3>2) NetBSD VirtIO</h3>
<hr>
<p>Direct integration with the seL4 Device Driver Framework (sDDF). Operates isolated Protection Domains (PDs) like <code>libseL4.c</code> and dedicated Crypto Enclaves backed by Trusted Storage Systems (TSS).</p>
</div>
<div class="package-card">
<span class="ve-badge">VE #3 — Orchestration</span>
<h3>3) Kubernetes</h3>
<hr>
<p>Cloud-native microVM virtualization via KubeVirt, <code>libkrun</code>, or <code>crosvm</code>. Enables containerized CI/CD pipelines to run ultra-dense Erlang and C99 workloads under Kubernetes.</p>
</div>
</div>
</section>
<section>
<h2>The VIO VirtIO Architecture</h2>
<div class="story-container">
<p>The architecture of <b>libvio</b> is structured around clean physical module boundaries, strict separation of device front-ends from platform backends, and hard real-time queue discipline.</p>
<div class="plane-header">1. Platform Control-Plane Backends (src/backend/platform/)</div>
<p>Platform abstractions isolate memory translation and interrupt routing via the <code>vio_platform_ops</code> interface across diverse control planes:</p>
<div class="grid-2">
<div class="package-card">
<h3>Platform Backends</h3>
<hr>
<ul>
<li><b>platform/sel4/libseL4.c:</b> seL4 Protection Domain & sDDF driver interface. Includes <code>tss_stub.c</code> for isolated Trusted Storage System key persistence.</li>
<li><b>platform/apple/libkrun.c:</b> macOS Hypervisor.framework RAM translation and <code>krun_create_ctx()</code> microVM context creation.</li>
<li><b>platform/linux/liblinux.c:</b> Linux VFIO userspace PCIe passthrough and portable <code>vhost-user</code> UNIX domain socket transport.</li>
<li><b>platform/hyperv/libhyperv.c:</b> Windows Hyper-V and VMBus control-plane integration.</li>
<li><b>platform/netbsd/libbsd.c:</b> NetBSD and BSD <code>/dev/pci</code> character device memory mapping.</li>
</ul>
</div>
<div>
<pre class="code-snippet">
/* vio_platform.h Interface Contract */
struct vio_platform_ops {
void *(*map_memory)(uint64_t phys_addr,
uint32_t len);
void (*unmap_memory)(void *virt_addr,
uint32_t len);
vio_status_t (*register_irq)(uint32_t irq,
void (*handler)(void *ctx),
void *ctx);
void (*mask_irq)(uint32_t irq);
void (*unmask_irq)(uint32_t irq);
};</pre>
</div>
</div>
<div class="plane-header">2. Low-Latency NVMe Fast Path (src/backend/nvme/)</div>
<p>The local block storage path achieves near-native PCIe performance by granting <code>libvio</code> exclusive ownership of the physical NVMe controller:</p>
<div class="grid-2">
<div class="package-card">
<h3>SPDK-Style Hardware Driver</h3>
<hr>
<p>Direct PCI BAR MMIO mapping, Controller Capability (<code>CAP</code>) register doorbell stride calculation, and lockless circular Submission Queues (SQ) and Completion Queues (CQ).</p>
<p>Phase-bit toggling enables lockless polling without hardware interrupt latency on hot paths.</p>
</div>
<div>
<pre class="code-snippet">
/* nvme_qpair.c Submission Fast Path */
uint16_t tail = qpair->sq_tail;
vio_memcpy(&qpair->sq[tail], cmd, sizeof(*cmd));
qpair->sq_tail = (tail + 1) % qpair->size;
/* Ring PCIe MMIO Doorbell */
*qpair->sq_db = qpair->sq_tail;</pre>
</div>
</div>
<div class="plane-header">3. Client Devices (src/devices/)</div>
<p>Modular device front-ends provide lightweight driver interfaces for guest protection domains:</p>
<div class="package-cards-grid" style="margin-top: 1.5rem;">
<div class="package-card">
<h3>devices/blk.c</h3>
<hr>
<p><b>VirtIO Block:</b> Poll-mode block I/O backed directly by the high-performance NVMe qpair layer.</p>
</div>
<div class="package-card">
<h3>devices/net.c</h3>
<hr>
<p><b>VirtIO Network:</b> Packet transmission and reception queues for virtio-net guests.</p>
</div>
<div class="package-card">
<h3>devices/console.c</h3>
<hr>
<p><b>VirtIO Console:</b> Low-latency serial streams for terminal vision and system diagnostics.</p>
</div>
<div class="package-card">
<h3>devices/crypto.c</h3>
<hr>
<p><b>VirtIO Crypto:</b> Enclave-isolated encryption/decryption operations backed by TSS key persistence.</p>
</div>
<div class="package-card">
<h3>devices/bus.c</h3>
<hr>
<p><b>VirtIO Bus:</b> Unified device enumeration for PCIe and MMIO discovery with minimal devicetree support.</p>
</div>
</div>
<div class="plane-header">4. VIO Core Components & Protocols (src/core/ & src/util/)</div>
<p>The core VirtIO protocol state engine operates with strict freestanding C11 discipline:</p>
<div class="grid-2">
<div class="package-card">
<h3>Core Protocol Engine</h3>
<hr>
<ul>
<li><b>core/queue.c:</b> Split-ring virtqueue layout mechanics (Descriptor Table, Available Ring, Used Ring).</li>
<li><b>core/transport_mmio.c & transport_pci.c:</b> Transport layers for MMIO memory mapped I/O and modern PCIe BAR configuration.</li>
<li><b>core/feature.c:</b> VirtIO 1.x feature bit negotiation protocols.</li>
<li><b>core/config.c:</b> VirtIO device configuration space read/write helpers.</li>
</ul>
</div>
<div class="package-card">
<h3>Freestanding Utilities (src/util/)</h3>
<hr>
<ul>
<li><b>atomic.c / atomic.h:</b> Hardware atomic memory barriers for lockless queue synchronization.</li>
<li><b>list.c / list.h:</b> Intrusive doubly-linked list routines.</li>
<li><b>mem.c / mem.h:</b> Freestanding memory copy/set/compare operations without <code>libc</code> dependency.</li>
<li><b>log.c / log.h:</b> Minimal, non-blocking logging routines.</li>
</ul>
</div>
</div>
</div>
</section>
<section>
<h2>Verified Test Assurance</h2>
<div class="story-container">
<p>The <code>libvio</code> engine is verified by a custom, zero-dependency unit and loopback test suite (<code>make test</code>) covering virtqueue byte movement, device front-ends, NVMe hardware simulation, and platform context creation.</p>
<pre class="code-snippet">
Starting libvio test suite...
Running test_queue_init_invalid... PASS
Running test_queue_init_valid... PASS
Running test_queue_has_used... PASS
Running test_virtio_data_transfer... PASS
Running test_blk_init... PASS
Running test_blk_read_unsupported... PASS
Running test_nvme_qpair_submit_poll... PASS
Running test_libkrun_mapping... PASS
Running test_libkrun_blk_init... PASS
Running test_libkrun_net_init... PASS
Running test_libkrun_create_context... PASS
=== TEST SUMMARY ===
Run: 11
Passed: 11
Failed: 0</pre>
</div>
</section>
</main>
<footer>
<div class="footer-columns">
<div>
<h4>Synrc Virtualization Environment</h4>
<p>OS.1 Hypervisor written in C, Erlang/OTP by <a rel="me" href="https://mathstodon.xyz/@5ht">5HT</a>.</p>
<p style="margin-top: 0.5rem; font-size: 0.9rem; color: var(--text-secondary);">Namdak Tonpa — BDFL VE OS.1 Architect</p>
</div>
<div>
<h4>Resources</h4>
<ul>
<li><a href="https://os.synrc.com/os-hyper.pdf">2026-08-19 SYNRC HYPERVISOR OS.1: VIRTIO XEN EXSI</a></li>
<li><a href="https://os.synrc.com/os.pdf">2026-07-19 SYNRC HYPERVISOR OS.1: GUEST ALPINE</a></li>
<li><a href="https://os.synrc.com/os-bsd.pdf">2026-07-19 SYNRC HYPERVISOR OS.1: GUEST NETBSD</a></li>
<li><a href="https://os.synrc.com/os.txt">2026-07-29 SYNRC HYPERVISOR OS.1: NIST 53</a></li>
<li><a href="https://hv.synrc.com/hv.pdf">2026-08-10 SYNRC HYPERVISOR: for OTP 20 Unicore seL4</a></li>
<li><a href="https://hv.synrc.com/hv-smp.pdf">2026-08-13 SYNRC HYPERVISOR: for OTP 30 4-Core seL4</a></li>
<li><a href="https://hv.synrc.com/hv-bc.pdf">2026-08-13 SYNRC HYPERVISOR: for Byte-code VMs</a></li>
<li><a href="https://hv.synrc.com/hv-infosec.pdf">2026-08-14 SYNRC HYPERVISOR: for Infosec OS.1</a></li>
<li><a href="https://hv.synrc.com/hv-crypto.pdf">2026-08-19 SYNRC HYPERVISOR: for LibreSSL CRYPTO</a></li>
</ul>
</div>
</div>
</footer>
</body>
</html>