Windows compatibility
Run familiar applications directly against a native compatibility surface, with driver compatibility as a platform target.
Active developmentOnyxOS / Windows 11 target · One machine. Zero disguise.
Exact Windows 11 behavior. An Onyx-owned boot path. Native Linux workflows. One operating system built to run the software you already use—directly, without a virtual machine.
UEFI environment acquired. Preparing the measured OnyxBoot path.
This is OnyxOS
OnyxOS is an independently developed operating system targeting direct compatibility with Windows applications and hardware, while making Linux tools and services first-class parts of the same desktop.
It is not a theme, a remote desktop, or one operating system hidden inside another. The project spans the boot path, kernel, system services, compatibility layers, desktop, and developer environment as one coherent platform.
Run familiar applications directly against a native compatibility surface, with driver compatibility as a platform target.
Active developmentOne system owns startup, hardware, services, security boundaries, and the desktop experience from boot onward.
Verified foundationsA planned native Linux environment will bring shells, toolchains, services, and graphical apps into the OnyxOS desktop.
Architecture phaseWhat the live number means: 54% measures the public-preview gates shown below—not total feature completion. Build, boot, services, graphical logon, secure input, and hardware discovery are verified; the desktop, broader compatibility, native startup, and Linux environment remain in development.
OnyxOS is designed as a single native platform. The Windows compatibility environment and the planned Linux environment meet at shared system services and one desktop instead of crossing a virtual-machine boundary.
NOW Boot, core services, logon, input, and hardware foundations are verified.
NEXT Authentication, desktop continuity, compatibility depth, and native startup.
LATER LINE becomes the first-class Linux environment inside the unified desktop.
A new execution personality
LINE is the planned native Linux environment for OnyxOS. Unmodified x86-64 Linux programs execute directly on the CPU as Onyx kernel processes, then share one scheduler, one security authority, one compositor, and one desktop with Windows applications.
No Linux kernel. No CPU emulator. No RDP. No nested desktop.
OnyxOS › line shell
kain@onyx:~$ uname -a
Linux onyx-line x86_64 / native personality
kain@onyx:~$ sudo apt install kate
Dependencies verified · signed transaction ready
kain@onyx:~$ kate README.md
Kate opens as an ordinary OnyxOS window beside native Windows applications.
A per-process Linux x86-64 personality routes native syscalls into Onyx kernel primitives—without a guest kernel or general syscall proxy.
Foundation roadmapline shell opens an Onyx terminal with real PTYs, job control, signals, UTF-8, Bash, SSH, tmux, and developer tooling.
Linux GUI clients map to ordinary Onyx windows. Focus, input, clipboard, scaling, and presentation stay under the Onyx compositor.
Planned desktop profilelineinit supports rc.d and init.d, dependency-aware startup, bounded restarts, and clean shutdown—without systemd.
Signed profiles solve packages, symbols, services, and kernel capabilities before install, then publish or roll back as one transaction.
Planned package profileNative allocations, explicit fences, Vulkan and OpenGL target a measured zero-copy compositor path instead of streaming pixels.
Future accelerated profileSecurity by construction
LINE does not create a second privileged operating system. OnyxOS remains the only hardware owner and security authority, while Linux permissions can narrow access but never elevate beyond the caller’s Onyx token.
Linux UID 0 stays confined to its environment unless a specific Onyx capability is granted.
Host files, secrets, camera, microphone, capture, clipboard, and devices cross permissioned boundaries.
Signed roots, capability profiles, package transactions, and measured PID 1 prevent silent substitution.
W^X, ASLR, image validation, and seccomp policy constrain execution before native objects are acquired.
Descriptors and shared buffers cross only by allowlisted class, reduced rights, verified lifetime, and audit record.
Loaders, syscalls, portals, packages, graphics, and containers remain experimental until fuzz and negative gates pass.
The security promise is measurable: no fake success, no hidden fallback, no capability promotion without passing evidence, and no Linux failure allowed to take down the Onyx shell or compositor.
The shortest path to 1:1
We do not recode what already passes. Work moves through the dependency spine, replaces NT5-era production owners, and closes only when the real linked system matches the pinned Windows 11 oracle—including failure behavior.
Finish NTDLL, Kernel32, and KernelBase runtime ownership and differential behavior.
UEFI-first measured boot, signed manifests, recovery, and a verified native kernel handoff.
Credential providers, secure attention, tokens, lock, sign-out, and shell lifecycle.
Compositor-owned presentation, WDDM-class contracts, scaling, accessibility, and resilient input.
Automated Windows 11 versus OnyxOS probes across applications, drivers, installers, and hardware.
Atomic signed updates, A/B rollback, repair media, stress qualification, and reproducible releases.
Local authentication
6 of 12 public-preview gates have verified evidence.
Build console
12 gates · 54 verified points · evidence only
A gate earns its full weight only when its named evidence exists. Active work remains visible, but adds no progress until it clears.
6 / 12 Verified gates 6 gates remain
Live Status feed Checked every two minutes
Today Source activity Latest change verified today
Evidence ledger
These gates have named source evidence and currently contribute to the public-readiness score.
The percentage is calculated from twelve weighted public-preview gates. A gate contributes only after its named evidence exists; unfinished work receives no partial credit.
One system owns the hardware, the desktop, and the experience. No second OS hiding underneath.
Fast startup, direct execution, and a responsive desktop are architecture—not afterthoughts.
Every milestone earns its place through working evidence. The public signal moves only when the system does.
The next boot starts here
The first public preview will arrive when every release gate is ready—not a moment before.
Private build in progress