Prerequisites and environment
An i686-elf cross toolchain, a build, an emulator and a debugger, set up once so that every later phase builds and boots the same way.
One view over the whole project: the kernel (OSDev phases), the convergence that links the engine into ring-0, the engine, the mind and the library, and the docs, infrastructure and forge around them. Dependencies that cross from one project into another are drawn as merge links — that's where the repositories meet.
The freestanding i686 OS — OSDev learning path, phases 0→11.
An i686-elf cross toolchain, a build, an emulator and a debugger, set up once so that every later phase builds and boots the same way.
Boot through GRUB with Multiboot, print to VGA text mode and to COM1, scroll, use colors, and parse the Multiboot information.
Higher-half kernel at 0xC0000000, boot and runtime paging, a GDT with six segments and a loaded TSS.
IDT and ISRs 0 to 47, PIC remap, dedicated #PF, #GP and #DF handlers, LAPIC and IOAPIC, x2APIC, the MADT, and AP bring-up.
A physical memory manager, a kernel heap, slab caches, frame, pool and ring allocators, pinned DMA memory and a virtual range manager, with one memory stack per profile.
Draw text on the linear framebuffer from PC Screen Font bitmaps, and interpret ANSI escape sequences on the serial and screen terminals.
Study the boot sequence and write a loader that replaces GRUB, including reading the memory map itself (E820 on BIOS machines).
Find and fix the page fault that both the xmake and the build.sh graphics ISOs raised after the Phase 2 smoke test.
Read the OSDev pages docs/ROADMAP.md left unchecked: What Order Should I Make Things In, segmentation and segment limits, calling conventions and the System V ABI, IDT problems, Brendan's memory management guide, Processes and Threads, Brendan's multi-tasking tutorial, the OSI model, the recommended books, academic papers, Going Further on x86 and Creating an Operating System.
The OSDev allocator the kernel skipped: a bitmap frame allocator (one bit per 4 KiB frame, word-wide scans from a next-fit hint, contiguous runs).
Report the worst-case cost of one allocation and one free and the fragmentation reached under a frame-shaped workload, against the published bounds (168 instructions on x86; under 15 % mean and 25 % maximum fragmentation).
Add o1heap (half-fit) as a second allocator profile for paths that need a hard worst-case bound, parity-tested against a recorded allocation trace.
Keep virtual memory areas in a red-black or AVL tree so the VMM finds the range holding an address in O(log N).
A lock-free, log-free page-frame allocator built on compare-and-swap that scales across cores and keeps huge frames available.
A scheme that frees a lock-free node only when no core can still observe it.
An IRQ12 PS/2 mouse feeding the engine's input backend.
Expose which keys are down, queried by character through the active layout.
Read the real-time clock.
Bring up an Intel HD Audio controller and its codec, and run a capture stream into memory.
Make any future sound output capped and silent by default.
A modern virtio-pci transport (capability parsing, feature negotiation, descriptor, available and used rings) usable by every virtio device, with the low-level virtio API moved out of the public HAL header as its own change.
Drive the Intel 82540EM that the PCI scan finds on QEMU (BAR0 0xFEB80000) with descriptor rings, DMA, the TDT doorbell and completions, as the native replacement for /dev/lpl0. It covers the 8254x family QEMU emulates as -device e1000.
Drive the Dell's onboard Ethernet. It covers Intel's chipset-integrated LAN family (I217, I218, I219), which Linux drives with e1000e.
A driver for QEMU -device igb (Intel 82576, 16 transmit and 16 receive queues, SR-IOV), the next step in the e1000, e1000e, igb register lineage.
Run the router mini-PC's Intel i210, i211 or i226-V NICs from their public datasheets.
Drivers for the other OSDev-listed cards: Realtek RTL8139 and RTL8169/8111/8125, Ne2000, AMD PCnet and 3Com 3c90x.
A minimal NVMe driver: submission and completion queue pairs in shared memory, an MMIO doorbell, PRP lists aligned on 4 KiB, the phase bit, and deep queues from day one (about 1,000 requests in flight for decent throughput and 3,000 to saturate 8 SSDs, Haas and Leis, PVLDB 2023). ATA PIO is skipped.
A native AHCI driver: command lists and FIS in DMA memory, native command queuing up to 32 commands, then ATAPI.
ATA PIO, ATA DMA through bus-master IDE, and the floppy controller with ISA DMA, for machines that have no AHCI or NVMe.
High-frequency acquisition of the OpenBCI headset in ring 0 with native notch and bandpass filtering.
Host controller drivers and USB input devices, the 'real project' docs/ROADMAP.md names after storage and the NIC, with isochronous transfers for EEG headsets.
An output stream descriptor and buffer list so the kernel can play audio through the existing ceiling and mute.
Drivers for the PC speaker and the Sound Blaster 16 from the OSDev list.
VGA hardware programming, the Bochs graphics adapter, and double buffering on the linear framebuffer.
Configure the virtio-gpu cursor queue so a hardware pointer moves and changes image without the control queue.
On the future Framework Desktop, drive the parts the owner chose: the Zen 5 CPU (with AVX-512), PCIe 4.0 NVMe, the Radeon 8060S integrated GPU with unified memory, and the network.
Read a tracking source (an IMU or a headset) about every millisecond into a slot the engine's late latching reads.
Frames are composed in a back buffer and presented to the linear framebuffer in one pass.
Keep a single generated 8x16 font for the engine HUD and the kernel monitor.
Ring 0 drives real graphics hardware on many kinds of PCs, one driver per vendor family chosen at boot, with the firmware framebuffer as the fallback when nothing matches.
Allocate blob resources and a shared host-memory window and submit Vulkan commands serialised with Venus (or Gallium3D with virgl) for the host GPU to run, so a scene renders from the same Fixed32 state through the hardware path.
Every GPU transaction carries an explicit fence, and display changes are tested then committed atomically; the allocator and the scheduler are designed around those fences.
When a mouse is plugged in, the touchpad stops moving the pointer, and it comes back when the mouse is removed.
The Dell Precision 7710 is the first real test machine. Its parts are known from Dell's manual, not measured on this unit, so every driver for it starts from a recorded inventory.
Write bootable USB and disk images so the kernel runs on a physical machine, not only in QEMU and in the browser.
Find the RSDP, walk the tables and interpret AML, so the kernel can read objects such as _CST.
Read PCIe configuration through the memory-mapped ECAM window and walk the extended capability list, beyond legacy PCI enumeration and Plug-and-Play.
Let PCI devices deliver interrupts as MSI or MSI-X messages to a chosen core and vector instead of shared IOAPIC lines.
Add the HPET as a second precise reference, read the CMOS clock, and detect the CPU and TSC frequency.
Drive the LAPIC timer in TSC-deadline mode so each core arms an absolute deadline in TSC cycles.
Add a dedicated NMI path and the protections that keep a double fault from becoming a triple fault.
Save extended state with XSAVE and XRSTOR (CR4.OSXSAVE, XCR0 from CPUID), switch it lazily so integer-only tasks never touch vector registers, and write the policy for SIMD in ring 0: integer kernels as gate P14 does, or saved state.
An EDF scheduler with temporal reservations (a task asks for 2 ms of CPU every 11 ms and the kernel guarantees it), partitioned per core to avoid Dhall's anomaly, with the VR render loop and the BCI pipeline pinned to dedicated cores and a per-core Liu and Layland admission test.
Spinlocks, mutexes, semaphores and read-write locks, where a core that fails to take a lock waits on the lock word instead of spinning at full power.
Exchange data between components through a router that passes ownership of shared memory instead of copying payloads. The OSDev list named message passing, shared memory, remote procedure calls, pipes and sockets; in one ring-0 address space they reduce to rings that hand buffers over, and a call served on another core is a request ring (#273).
Spread the engine's work over the cores SMP bring-up already starts, beginning with scanline bands of the rasteriser across the application processors.
On the client, run the mind under hard budgets below rendering and simulation with truncation; on the server, use affinity, admission control and anti-starvation of the game and network paths, with contention, cache and allocation telemetry.
Order GPU command submissions and preempt so a heavy workload never starves the display or the frame deadline.
Tie last-level cache partitioning (Intel CAT, or AMD's equivalent) to the real-time guard so critical work keeps its cache share.
A background agent in ring 0 reads system state (load, network, memory, physics budget), decides, and applies bounded changes to kernel policies such as scheduling or networking, in the spirit of SchedCP.
Per-CPU data structures from the OSDev multiprocessing list: one block per online core holding its current task, its run queue, its idle and wake state and its counters, on cache lines no other core writes, reached by the running core in constant time.
One task control block (saved registers, stack, extended-state area, deadline and budget, state), the states ready, running and blocked, a task that waits on an event or an empty ring blocks until it is woken, and an asynchronous notification to a task in place of signals. A shell command that starts work starts a task (#280).
Round-robin first, the OSDev starting point, then priorities, with a multi-level feedback queue as the option the OSDev list names, for tasks that declare no deadline, next to the partitioned EDF that serves deadlines.
A VFS, an initrd first (no disk driver needed), then FAT and Ext2.
Update the system atomically by switching between two image partitions, as Bottlerocket does.
A zero-syscall asynchronous interface (submission and completion rings in shared memory), a single address space, and isolation between components, all without leaving ring 0.
Long mode with 4-level paging, UEFI boot, an interactive shell, and newlib and libsupc++ ports.
Snapshot a component's memory in O(1) by marking pages read-only and counting references in the PMM, roll it back, and fork a heavy component by sharing physical pages until a write.
Watch physical memory pressure and, instead of an out-of-memory crash, ask components to release non-critical pages, allocate on first touch, or compress pages in place.
Target other architectures (ARM, Raspberry Pi bare metal, RISC-V, PowerPC listed).
C-states with HLT and MONITOR/MWAIT, P-states through IA32_PERF_CTL, a tickless kernel, then DVFS and clock and power gating. Nothing claims a saving unless it is measured.
Ethernet, ARP, IPv4, ICMP, UDP, TCP, DHCP and DNS over the kernel's own NIC drivers, then a poll-mode zero-copy data plane: DMA from the NIC into pinned buffers of the ring-0 consumer, with RSS spreading flows across cores.
Over its own NIC driver, LplKernel builds BTH and RETH headers, PSN and ICRC, registers memory regions with an rkey, and performs RDMA_WRITE into a registered buffer of a Linux machine running rdma_rxe; what landed is folded on both sides.
The kernel submits compiled circuits to a quantum processor the way it submits compute work to a GPU, with deadlines aware of decoherence and memory with a bounded lifetime.
After the mapping is installed, map code and rodata read-only and prove that a write there faults.
Mark data, stacks and heaps non-executable so only code pages can run.
Compile the interactive console out of the shipped profiles.
Let the kernel boot without the engine, without the assistant, without the library and without the network, and check that path.
A periodic pass that compares what the kernel declared with what is running and counts drift.
Enumerate every SPSC ring with what a drop means, read capacities from the queues themselves, and treat corrupting drops as drift.
Place a small sample of allocations in a fixed pool against unmapped guard pages, aligned to one edge, so an out-of-bounds write or a use-after-free faults at the offending instruction, cheaply enough to stay on in release.
Never let objects of different types share a slab, so a use-after-free in one subsystem cannot hand its memory to another type.
Program the IOMMU so each device can DMA only into the ranges it was given, the 'safe DMA' lot that completes W^X.
Give cartridges an authenticator, not only the FNV-1a hash: an HMAC with a build key over BLAKE2s or SHA-256 (integer, freestanding, about 200 lines) rather than Ed25519, checked by engine::bootGame before a cartridge runs.
A TPM driver reads the PCRs and extends one with the hash of lpl.kernel and of each cartridge at load, for local attestation only.
Treat data crossing the submission and completion rings as untrusted (sizes, alignment, ranges), fuzz the interface, and log security events where they cannot be erased.
A written contract for the in-kernel mind: reserved memory, a strict list of allowed actions, quotas, a circuit breaker, no unbounded allocation in hot loops, fallback policies, and official limits (model size, memory budget, latency target, allowed action types).
Memory errors in ring 0 are fatal and a garbage collector would break real-time behaviour, so memory safety should hold by construction: formal verification at build time, or a memory-safe language for the most exposed components.
Compile the kernel, libk, libkxx and the ring-0 libraries with -fstack-protector-strong in every build path, and give the kernel its own __stack_chk_guard and __stack_chk_fail, as the OSDev Meaty Skeleton step asks.
One command that runs the host batteries, builds the three kernel paths, boots every image headless, and compares every fold signature against the oracle, with expected values read from the oracle at run time.
Build each profile twice from clean and compare the binaries byte for byte.
Give libknowledge and libassistant real Makefile targets and put them back into the PROJECTS lists of config.sh.
Run QEMU under KVM when the host allows it, measure the gain, and take the phase profile again before any rendering optimisation.
Record the .text, .data and .bss sizes of lpl.kernel with libengine and check them against the Multiboot and low-memory map, keeping the renderer optional if the budget is exceeded.
Collect PGO profiles by running the deterministic, replayable parity gates and feed them back into the build.
Measure -Os, -O2 and -O3 for instruction-cache misses and energy on the deterministic gates, then shrink the hot footprint with LTO, -ffunction-sections and --gc-sections, hot and cold splitting, branch hints and alignment.
Apply OSDev's build-system advice: a new source should need one edit, not three.
Make the kernel build CI build what validate.sh builds.
Run the kernel on Bochs with its debugger, and add unit testing following the OSDev guide.
Run clang-tidy with the C++ Core Guidelines checks, the Clang static analyzer and cppcheck on the kernel and the engine, beyond -Wall -Werror.
Kernel counters are emitted as one structured line, '[LPLTLM] <domain> <key>=<value> ...', read by an anchored reader in validate.sh, with format violations counted.
The scheduler and memory manager write events into lock-free single-producer rings that a consumer drains at its own pace, at no cost when nobody reads them, and the cost per event is measured.
A histogram of interrupt-to-handler latency and timer deadline jitter per profile, checked against the 1 ms requirement, with its numbers in the paper.
Per-stage boot timestamps across core counts.
Inference reports total, prefill, selection and formatting time and the latency of each token. On the client profile a gate requires the 99th percentile of token time under a budget with zero memory violations in hot loops, and a server gate checks stability across sessions.
CI builds the kernel with xmake and with build.sh on every PR, asserts that both give the same state hash against a single-threaded Linux oracle, forbids bare standard-library includes outside lpl/std/, and fails on a stale bake (validate.sh, extended to ai/ and ecology/).
A recorded decision: LplAssistant and LplKnowledge are git submodules of LplKernel, as LplPlugin is, or sibling directories found through LPLASSISTANT_ROOT and LPLKNOWLEDGE_ROOT.
LplAssistant and LplKnowledge get Fixed32, CORDIC and lpl::pmr from LplPlugin's lpl-core and lpl-math by one declared mechanism: an xmake package, or a recorded rule that LplPlugin is the foundation of the other three.
LplAssistant and LplKnowledge build without LplPlugin: a foundation option detects it, and standalone builds are host-only with plain type aliases and no Fixed32 substitute, so they can never claim parity. Binaries carry the lpl- prefix.
Put data written by different cores (ring head and tail counters, per-CPU heap state, per-core counters) on separate 64-byte lines, after measuring the coherence traffic.
Use non-temporal stores (movntdq) for framebuffer writes and packet copies, clflushopt or clwb to evict precisely, and prefetchnta on traversals known in advance, only where a measurement shows a gain.
Turn the server heap's per-CPU-slot domains into real per-CPU caches, then per-NUMA-node domains with first-touch placement, instrumented remote fallback and NUMA-affine workers.
Change a buffer's owner or size by editing page-table entries, leaving the bytes where they are.
Allocate and free large physically contiguous DMA buffers directly, skipping the virtual mapping, for devices that only DMA.
CPU and GPU see the same buffers at stable addresses: on unified memory (the Framework's Radeon 8060S) allocate in the GPU-visible region through a path both sides see, with the right barriers and cache invalidations; on discrete or virtual GPUs use shared virtual memory or virtio host-memory windows.
One counter per wake source, in the manner of powertop: the sleep path arms, and the first interrupt to reach the dispatcher while armed is the waker. Then serve close deadlines with one wake.
MWAIT receives a hint the CPU enumerates, never a guessed one, and the interrupt-break extension is set only when the CPU supports it.
Cores sleep with MONITOR armed on a device ring's write index and wake when DMA or a handler advances it: the console ring first, the HDA capture ring next, the NIC receive ring once a NIC driver exists.
Captured audio reaches the model's input buffers with no copy between the capture driver and inference.
Read APERF and MPERF to know whether the silicon applied the P-state written to IA32_PERF_CTL, and compare the reading with the request.
PCIe links, the SSD and the Ethernet PHY enter their low-power states between traffic, each with a latency policy chosen per profile in build.sh.
A joules-per-tick budget on real hardware that fails when it regresses, in the shape of test-tick-allocations, measuring what turbostat measures: RAPL, APERF/MPERF and residency per C-state. Then joules per token for ring-0 inference, with the idle draw subtracted and published separately.
Set CR4.PSE and map the direct map, the arenas, a model's weights, framebuffers and geometry with 4 MiB pages, mapped once at boot and never managed transparently or compacted in the background, as a first step toward direct segments (base, limit, offset).
A UDP packet goes from the NIC to the GPU with no intermediate copy: DMA regions shared by the NIC and the GPU, the SoA ECS feeding the upload, and a lock-free single-producer ring from the interrupt to the main loop. Then the path is measured with the benchmark harness.
Hot algorithms are chosen by memory-access cost: sequential O(n log n) over scattered O(n), cache-oblivious layouts, bit-packing and quantisation, incremental recomputation.
A bench shows, case by case, whether recomputing a value costs less energy than rereading it from memory.
NVMe queues placed in GPU memory, with GPU threads submitting their own requests through a software cache that coalesces accesses.
Data is placed and migrated across tiers (local and remote DRAM, CXL, and by extension VRAM and NVMe) so the hottest bytes sit in the fastest tier, chosen by measured access latency as in the Colloid algorithm.
Map the whole model, let a page fault pull an expert straight off NVMe by DMA, pin the shared experts and evict the specialists, and prefetch before the fault. A 236B mixture of experts reads only 21B per token, so it decodes faster than a dense 70B while knowing more.
Let the kernel's virtual memory page the KV cache, the way vAttention relies on the operating system instead of paging inside the application.
The two-repo merge: the engine linked natively into ring-0 (Model B, then U1→U5).
Link LplPlugin into the kernel as libengine.a, compiled -ffreestanding behind a thin C HAL that holds no engine logic, so the kernel runs the same engine object as the host client.
Make the full Engine facade compile freestanding, with no GLFW or BSD socket include on the kernel path, so it stops being host-only.
Every authoritative value (simulation state, consensus confidences, transformer activations, poses) is Q16.16 and trigonometry comes from CORDIC, so final states match bit for bit across machines. Float stays at the render, camera and wire edges.
The mind calls the library and never the reverse, so the kernel links the mind's archive first: -lassistant -lknowledge -lengine -lkxx -lk. When a lower archive needs something from an upper one, it declares an interface that the upper one implements and hands over at run time, as IClaimReader, agent::IDecider and history::IPlaceResolver already do.
The QEMU client kernel receives a generated .lplscene through the data plane and replays it, folding the same signature as the Linux oracle.
LplKernel provides a stable tick contract (clock_*) that LplPlugin consumes.
Robust prediction and reconciliation under 50 to 200 ms of network jitter, with the server's authority running in ring 0.
Telemetry plus action with a measured motion-to-photon latency under 20 ms: a constant frame rate, BCI processing kept off the render path, and BCI samples aligned to the image clock. Partitioned EDF guarantees the classifier finishes within the frame (about 11 ms at 90 Hz).
Integrate the critical engine components directly as kernel modules.
Load-test and validate the unified SMP architecture.
The cube pile (1024 Fixed32 entities, AABB collisions, a spatial hash) folds its state and its image identically on the host oracle and the booted kernel.
A codec/ module of integer-only GF(2) algebra, with no float and no libm, whose host path is vectorised and whose ring-0 path is scalar, folding the same signatures on both. It serves network erasure coding, robust cartridges and archival research.
Ten opcodes, a reference interpreter, and a specification written in bytes rather than prose; a machine rebuilt from the engraving runs the canonical program identically on both targets.
A history/ module where a fact is a sextuple (subject, predicate, object, interval, source, confidence in Fixed32), sources are weighted, independent confirmations fuse, a contradicted claim is demoted and never deleted, and the whole folds identically on the host and in ring 0.
A dated constraint seeds someone, he walks of his own accord along attested links, and his arrivals return to the chronicle as Cause::Emergent, where a divergence score can judge them.
One recipe, one world: the canonical WorldRecipe baked by the Linux oracle and by the kernel must fold to the same entity count, state, height and biome signatures.
A simulation that runs under contract: N deterministic ticks of a seeded population fold into population, genome, stigmergy and social signatures equal bit for bit between the host oracle and the kernel.
Chunked generation with no seams: a chunk generated alone folds like the same chunk generated among its neighbours, on both targets, from one world seed and absolute integer coordinates.
L-system growth under the same contract: conifer, broadleaf and shrub folds with segment and leaf counts.
Caves a body can enter in the streamed world, under the determinism contract: the warren, where the rock is, and what a body makes of it, each folded, with counters that prove the body went in.
Real elevation tiles projected, resampled, baked into a .lplknow section, reopened and walked, with the arithmetic proven equal on host and in ring 0.
Villages, castles, dungeons and megastructures placed by WFC with adjacency rules, transmitted as a seed and a theme rather than as geometry.
WFC runs on a 2D plan and the result is extruded into stacked layers, with stairs, columns and shafts handled by secondary passes.
Backrooms-like spaces: absurd global geometry with disturbingly perfect local detail, streamed by integer world coordinates.
Dendritic caverns grown by particles that random-walk until they stick to an open seed (fractal dimension about 1.71).
Each pass declares its grid level, a pass reading a finer level is a construction error, and coarse outputs are memoised by (level, coord).
Jittered sites partition space into provinces, biome patches or districts, with domain warping for organic borders and a choice of three metrics.
Road and river networks that follow the terrain without the model placing each segment: Parish-Mueller L-systems balancing global goals and local constraints along radial and grid tensor fields, with districts from Voronoi parcels.
Bodies made of chunks linked by springs, and a two-bone IK that grabs a target on the geometry and pulls the body.
Navigation whose search state is the cell and the arrival direction, so reversing has its own cost, with per-cell capability bits matched against each species.
Six personality traits derived from the creature id; asymmetric per-pair opinions with intensity, and a faction reputation that flips after an aggression; objects that advertise what can be done with them.
Creatures leave the viewer layer and become ECS entities the solver sees, collide with rocks and with each other, are declared by a Config flag like physics, and the living gate folds them, re-baselined equal on host and kernel.
The micron-to-world conversion, the threshold table, VerticalSpan and the march step stay in Fixed32 and testable; if a gate is wanted, it takes the shape of gate P21.
Fold the tool surface (schema and grammar) and the world after a fixed sequence of acts, on the host oracle and in the booted kernel, and compare them.
A transformer thinking in ring 0 that produces the same tokens as the host: eight-bit weights, Q16.16 activations, RMSNorm, base-two RoPE from CORDIC, causal attention with a bounded KV cache, SwiGLU, seeded top-k and grammar-constrained decoding.
A hosted room node, the kernel's satellite profile and an eventual microcontroller decide the same things: when to send, when to stop, whether the wake word was heard, whether the node is hearing itself.
mind/ in ring 0: a persona as data with Fixed32 traits, intent treated as an untrusted packet, a budget counted in work, a bounded memory, integer recall, and a ReAct loop over separate seams, so the assistant acts instead of only answering.
The demon picks every move of a turn with the ring-0 transformer under a grammar rebuilt from the action alphabet at each step.
Bake the canonical corpus of gate P13 into a .lplknow image with a host tool, read it back in ring 0 through libknowledge, rebuild the history from what came back, and fold exactly gate P13's signatures.
A canonical research corpus is baked into a checked-in blob (an lpl-ingest --header still to write), read in ring 0, and its findings, sources and agreement counts are folded.
The cross-platform engine — simulation, network, BCI, rendering.
Indirect calls through virtual ecs::ISystem in hot loops are watched and removed where they show up in profiles.
Explain why SoA and AoS differ by barely 1 %.
One constexpr, freestanding table describes every component (fields, types, offsets, defaults, bounds).
An ECS fed by a kernel ring buffer, pinned zero-copy memory, dynamic packets and a generic component dispatcher, validated by measurement.
Split the engine into flat modules built by xmake (C++23, no RTTI, no exceptions), with a facade, a BCI module, a software rasterizer and a GPU backend.
Every public claim about the engine's foundations matches the code and one measurement.
The CUDA physics backend stays as host code behind its cuda build option, off by default, and a CI job compiles it once with the option on so it keeps building. The roadmap says what it is: host-only, compiled but not yet run against the Fixed32 CPU path, with a vendor-neutral port as the target.
Reusable bricks written inside samples and viewers move into the engine library, each with a caller outside tests and a test target.
lock() doubles its run of pauses while the lock stays held, up to a ceiling, as its header promises; until that ships on main, the header says the back-off is planned and links this issue.
One worker per core, small jobs on lock-free queues, idle workers steal, a waiting thread runs jobs instead of blocking, and the two ends of every queue sit on separate cache lines.
The input layer records each key and button event in order, and the simulation consumes events rather than a per-frame snapshot.
Error carries a 128-byte message and 32-byte names, never a heap string, on host and kernel alike.
The engine exposes entities, textures and materials through opaque handles in an extern C facade.
Q32.32 arithmetic works on i686, with multiply and divide through a software 128-bit intermediate, or the limit is accepted until the 64-bit port.
Loops that divide many values by the same divisor compute the reciprocal once and multiply.
Physics hot loops process several bodies per instruction with integer SIMD over structure-of-arrays data, without giving up bit-identical results.
The chunk migration pass visits only the bodies that moved since the last tick.
Remote entities render with an interpolation delay or extrapolate by dead reckoning, a Hermite spline option is chosen by bandwidth, and each replicated entity knows how stale it is.
Run client and server with simulated latency, jitter and loss, then confirm on a real long-distance link.
Fast bodies are tested with a swept volume or a ray across chunks so they cannot pass through geometry.
Each chunk carries an active flag and only active chunks are updated.
engine::World owns its registry, scheduler and partition; engine::Server owns transport, netcode and N Worlds, routes each datagram to its sender's World and registers the per-instance systems.
Collisions resolve over one world index across all chunks, and physics runs once per tick on the server.
Each tick records its inputs and its folded state signature into a ring buffer; a replay re-runs the ticks from the start state and asserts every signature matches. A saved session is its inputs plus the initial seed.
On a late or mispredicted input the client restores the snapshot of that tick, applies the corrected input and resimulates to the present, saving snapshots on the way; 8 or more ticks of resimulation fit in one frame.
Clients send a per-tick FNV-1a hash of authoritative state; on divergence the server forces a resync or blocks the client, and both states at the divergent tick are kept for a component-by-component diff.
The server rewinds to the instant the client saw, validates the action there and resumes the present, using the same snapshot history as desync detection and rollback.
When the engine is fully deterministic, a server mode gathers each frame's inputs into one packet broadcast to every client, and each client simulates the whole world.
Player inputs pack into bit fields before they are sent 60 to 144 times per second.
A channel with selective acknowledgement and targeted retransmission over UDP.
The server predicts a client's trajectory while its inputs are late.
Fix the endianness and padding of the wire encoding and reject corrupted packets.
Publish the [EntityID][CompID][Data] packet format as an open standard for real-time MMO and VR.
engine::Server runs multi-instance in freestanding, so the kernel is a hosting server and not only a client, with transport and authoritative tick in ring 0.
The scene and recipe bytes a cartridge carries travel over the network, and the receiver rebuilds the world bit for bit.
Detect a sphere against a triangle by the signed distance to its plane, and resolve by pushing the centre out along the normal.
GJK for convex hulls and SAT for oriented boxes, beyond AABB.
Cloth, fluids and soft-body collisions in the physics module.
Transforms are recomputed only when their inputs change, and GPU work covers only the entities the network or the simulation touched.
Before a loop moves to wide SIMD, measure whether the core lowers its frequency.
Mean over channels of the 40 to 70 Hz power, exponentially smoothed, used as a gatekeeper before decoding.
Distance of the current feature vector to the calibrated class mean on 500 ms sliding windows, with its variance exported as a certainty.
delta_R(C1, C2) = sqrt(sum ln^2(lambda_i)) from the generalised eigenvalues of two windowed covariance matrices.
Acquisition, algorithms independent of any BCI library, OpenViBE adapters and an LSL gateway in separate modules, with contracts and unit tests.
Raw samples cross from acquisition to processing through a single-producer single-consumer lock-free ring.
A calibration phase of about 30 s at rest records the baseline, the class means and covariances, and the rest power that sets the muscle gatekeeper threshold, per user and per session.
Rebuild timestamps from the OpenBCI sample number as a linear time base and map them onto the engine clock by robust linear regression, so samples line up with frames.
Broadcast EEG with corrected timestamps over LSL, expose the stability and muscle-relaxation metrics as OpenViBE boxes, and enable the BrainFlow, LSL and OpenBCI sources.
The muscle metric refuses a command and tells the user to relax the face, the stability signal drives a visible cue such as a funnel opening or avatar transparency, and a high R(t) pauses or reduces haptic and visual feedback.
Common average reference, CSP spatial filters and LDA or SVM classify imagined left hand, right hand, feet and rest from mu-band desynchronisation at C3 and C4 after a 5 to 10 minute calibration, and the class becomes an ECS input component.
Notch and bandpass filters, FFT and band power, R(t), stability and the Riemannian distance run in ring 0 in fixed point, with in-house FFT, matrix inverse, symmetric eigendecomposition and logarithm, folding identically to the hosted oracle.
Gameplay reads band metrics: alpha concentration or relaxation powers magic, an EOG blink is a trigger, beta load drives difficulty, theta a trance or mana state, delta a loss-of-consciousness detector.
The server changes physics, rendering and pacing from the player R(t), Riemannian distance and emotional state.
A preprocessing chain: 0.5 to 45 Hz bandpass, notch, ICA to remove ocular components, amplitude thresholding of contaminated segments, and CSP before PSD.
World objects flicker at distinct frequencies and the occipital response selects menus or spells; P300 oddball responses give discrete selection for interfaces.
Detect the error-related potential when the avatar does something unintended and use it to correct the decoder online.
Classify motor imagery by minimum distance to Riemannian means or by LDA in the tangent space, instead of CSP plus LDA.
A small LSTM or transformer classifying EEG (motor imagery, P300) in real time, quantised to 8-bit integers, able to run without a GPU on a headset processor or in ring 0.
Neural states derived from the BCI stream are stored in the ECS as packed bit-fields rather than full-width fields.
Every neural signal passes a safety limiter before the interface and the game logic, and above a danger threshold the session disconnects at once.
A driver and signal path for the Galea headset behind the same BCI source interface as OpenBCI.
Facial EMG mapped to avatar expressions, EOG for gaze, EDA and PPG for stress and heart rate, and Ganglion boards on the arms, all as ECS components that raise events the world can react to.
A Cortex-M without FPU in the headset runs fixed-point acquisition and processing and sleeps with WFI between 250 Hz samples.
The GPU physics kernel stages its data in on-chip memory, and its memory accesses are profiled to confirm they coalesce.
Compressed world chunks and assets move from NVMe to GPU memory by DMA and are decompressed on the GPU, with transfers overlapping compute.
Delta compression of modified components, bit-packing and varints, quantised snapshots, and deltas against the last snapshot the client acknowledged.
Readers traverse the session table without locks; writers publish a new version atomically and free the old one after a grace period.
Client authentication, a whitelist and a blacklist, per-session packet count, latency and jitter, session structs from a slab, and optional compression and encryption layers on the stream.
Multi-server worlds where a chunk migrates to another node, entities stay readable on the old server during the move, and load rebalances chunks across nodes.
A fast binary format for offloading a chunk to disk or another server, and inactive chunks kept 5 to 30 s in memory before they are written out.
Engine allocators know NUMA nodes, tasks get CPU and node affinity, and server instances shard per node.
A benchmark holding 100k+ entities at a stable 60 FPS.
Each client receives only entities inside its interest radius as spawn, despawn and delta, update rate and precision fall with distance, entities go out by priority until a per-client byte budget is spent, and clients can declare interest queries.
The engine picks among full broadcast, interest management, deltas, relevancy and others at run time, from load, map and each client's network profile.
Build and measure in order: batched receive with a cap and a backpressure counter, receive-side scaling across queues, interest management with deltas, per-CPU and per-node sharding, then kernel bypass; set a load-test number next to each computed wall.
Tick the Server's N Worlds on a pool of workers instead of one after the other.
No heap allocation in a host tick, and only bounded allocations in ring 0.
The bounded slab operations of a ring-0 tick go away, and short-lived components come from pools or the frame arena.
Bodies store a chunk cell (two i32) and a Q16.16 offset, normalised in one place.
Build the broad-phase on the GPU, then run a selective narrow phase, and justify building volumes from triangle centroids with a short written proof.
Photorealistic rendering, haptic feedback, spatial audio, strict determinism and a direct NIC-to-GPU path, toward a FullDive prototype with multimodal feedback.
Full resolution only around the gaze, with density falling in the periphery, steered by an eye tracker.
A sensor task writes the latest head pose about every millisecond, and an asynchronous timewarp reprojects the rendered frame to that pose just before it is shown.
Variable rate shading on the periphery and on motion-blurred regions, dithered crossfade between LODs, ray-traced contact shadows, async compute and temporal upscaling.
The engine drives stimulation devices within published safety limits: galvanic vestibular stimulation to feel motion without moving, tDCS to aid BCI training, focused ultrasound, and somatosensory haptics.
Learned compression of sensory data run on the device, to cut the bandwidth and latency of bidirectional neural streams.
In-headset holographic menus follow model, view and controller wired to engine events, with gaze and hand gestures as controllers.
A local integer head on the gate P14 transformer chooses among the actions the world offers an NPC, for tactical decisions, folded like every gate.
The engine software rasterizer draws a whole generated world to the kernel display as the client profile, with terrain, climate, biomes, ai and ecology running in ring 0.
Close the visual deficit in order of cost: ambient occlusion, ground detail, clouds and slope blending first, then dense foliage and soft shadows.
The rasterizer fill processes four pixels per iteration with SSE2, already required by the determinism contract (-msse2 -mfpmath=sse -ffp-contract=off).
Split rendering into scanline bands across the application processors instead of running on the bootstrap processor alone.
Make Octree::queryVisible actually run in the kernel, where 17 resident chunks never cross the threshold of 48.
Confirm on a capture that the vertical grey artefact seen on 2026-08-01 was the chunk slit fixed the same day, before striking it.
Neighbouring chunks at different strides share a vertex chain along their seam, through a seam band or Transvoxel-style transition cells, instead of skirts.
A quadtree or clipmap loads large coarse chunks far away and small dense chunks under the camera, with the visible range growing with altitude.
Push each vertex down by its squared horizontal distance times a factor that grows with camera altitude, so curvature is invisible at sea level and visible from a plane or a summit.
Open sea as a sum of Gerstner waves: sharp crests, broad troughs, the deep-water dispersion relation and analytic normals.
A bounded raymarch between the water surface and the bed with per-channel extinction, in-scattering and volumetric shadow from crests, on top of the Fresnel already shipped.
Scatter routes generation attributes (elevation, distance to a river, local density, colour) into the instance data, and shading blends material layers such as moss, snow or mud from them.
The renderer consumes a general mesh, which would unblock cubed-sphere planets with gnomonic projection, Marching Cubes, Transvoxel, Dual Contouring or Surface Nets, displacement overhangs, Gerstner surfaces and 3D density caves.
Mesh procgen::buildingVolume, with its floors and grammar materials, for the software rasterizer, so buildings get doors, windows and room for inhabitants.
Fill the domains of the 50-criteria graphics grid where nothing exists: image import and export, image-sequence export, a dynamic cursor and vector drawing tools, multi-selection, transform history, imported 3D models, portals or render-to-texture in a scene, tessellation, HDRI environments, non-Cartesian coordinates, mesh animation and relief mapping.
Render passes declare what they read and write, and a small scheduler orders them, cleaning up multi-viewport and portal ordering.
The renderer reads vertex data in the ECS structure-of-arrays layout, removing the repack into interleaved Mesh vertices.
Render any chunked volume (CT, microscopy, simulation) directly: bricks, a measured density profile, transfer ramps, a mosaic where the finest level wins, near-to-far residency and a front-to-back raymarcher, with a free camera and a sheet tracer for the Herculaneum scrolls.
The Vulkan renderer becomes a real backend: render::Camera feeds a UBO instead of the hard-coded MVP in render/src/vk/buffers/Buffer.cpp, the wrapper gains a per-instance draw API from the Registry, and worldforge gets an orbit camera and selection gizmos on it.
Rendering submits its command lists on its own, and particles, cloth, fluids and motion trails run on asynchronous compute queues next to graphics.
A grapple moves the body root along a cubic Bezier curve whose control points simulate gravity, with an easing before impact; the same curves drive camera paths.
A heuristic IK solver (FABRIK or CCD) run after animation, with joint limits and eased weights: feet and ankles on rough ground, a pelvis offset, hands on tagged surfaces.
Each tick a cost over future trajectory, joint positions and velocity selects the best pose in a motion database (k-d tree or vector quantisation), with phase-matched crossfades against foot sliding.
Encode skeletal transforms as dual quaternions so twisted limbs keep their volume.
Invisible volumes on obstacles carry a surface normal and an expected height; entering one sets IK targets early (hand on wall, foot on step), and an animation layer adds a clamped look-at and ragdoll stiffness on landing.
A meta tier directs population and resources, a character tier turns input into intent, and an animation tier adds look-at on neck and spine with anatomical clamps and ragdoll stiffness on landings, each at its own rate.
Player input and AI emit continuous intent (trajectory, stamina, gaze, desire to traverse), and the locomotion subsystem alone decides how it shows.
A learned model in the style of phase-functioned networks generates or selects poses at runtime inside the engine.
Creatures are body chunks joined by springs, limbs placed by IK on grip points the AI chooses, and image fragments (head, tail segment, limb) projected on that skeleton every frame.
A controller that injects a constant velocity, velocity impulses with stamina, gravity inversion for wall run and climb, a landing rebound into horizontal momentum, and a zip along a cubic Bezier with easing.
Terrain as a 3D scalar density field (fBm in x, y and z) meshed by Marching Cubes with interpolated vertices and gradient normals, displacement along normals for overhangs, and true 3D caves.
Spherical planets: six cube faces projected by the equiangular gnomonic map, the metric tensor for exact cell areas, a quadtree per face for LOD, and noise sampled at normalised 3D positions so face borders are continuous.
A libm-free Fixed32 gradient or simplex noise beside the value noise, usable in 2D for terrain and climate and in 3D for density fields.
Mei et al.'s virtual-pipe model in five phases: precipitation, flux with a mass-conserving scale factor, depth and velocity, capacity erosion and deposition, semi-Lagrangian sediment advection with evaporation.
Tarboton's D-infinity (flow split over at most two cells along a continuous angle) or multiple-flow-direction routing beside D8.
Channel carving reads slope and discharge: steep high flow cuts a narrow canyon (Rosgen A), near-flat high flow a wide meandering bed (Rosgen C).
The talus threshold of thermal erosion is weighted by local rock hardness.
Build the diagram as polygons in O(n log n) with Fortune's sweep or the Delaunay dual, and use Jump Flooding when a distance texture is needed.
Compute a coarse fractal skeleton, upscale it twice and use it as a mask for interpolation or smoothing noise, instead of an exhaustive high-resolution walk.
Bias particle motion toward the centre to carve a large central clearing ringed by eroded borders.
When local repair fails, place an asymmetric, universally permissive filler (cliff, scree) that hides the error behind a natural-looking element.
Pre-generate tileable blocks offline, place them at runtime, then re-solve a chunk offset by half a block whose border is frozen from its neighbours, so seams disappear while each chunk stays isolated (Kleineberg's infinite city); heightmaps join WFC through quadtree clamping to unit steps with sloped connector blocks.
Solve Wave Function Collapse on the GPU when one is present.
In an endless world, rivers from a ridged multifractal noise run along the borders between climate regions, as Minecraft is said to do, checked against Minecraft's official docs and devblogs and the owner's playlist.
Erosion, global drainage, towns and roads run on the coarse HiGen level and constrain the fine chunks, so the endless mode shows more than noise, climate, local rivers and trunks; this gives HiGen its first production caller.
The six creature systems work where several floors share one column: a Y-aware terrain query and a layered scent window, so life can live in caves and other volumes.
generateLiminal becomes selectable as a CaveKind, so a liminal zone can open under the ground.
Restrict elevation-weighted A* to a Delaunay triangulation of villages and chokepoints, and bed the road into the terrain with a signed distance field.
Trees grow from rules reacting to gravity, light access and pruning by length from root or height, exposed through a few high-level parameters (age, stress), with a skeleton that bends in the wind.
Use global datasets (ETOPO, Natural Earth) for the real macro relief and coastlines, and HYDE population grids per period (10,000 BCE to today) to know where people were in a given year.
One Dijkstra map per goal (player, water, food, threat), shared by every agent that rolls downhill on it, with flight and weighted sums by per-creature coefficients (appetite, fear).
Threat, prey, hazard and den evaluators score in Fixed32 and arbitrate a Wander, Seek, Flee, Starving, Reproduce state machine, with personality modulating evaluators and physics, identical on host and kernel.
The road network from roadMap and connectPlaces becomes a macroscopic graph, so a migration crosses the map in O(edges).
The six personality traits also drive animation and physics parameters: nervous jitter, pupil dilation, reaction time to block a projectile.
Fitness accounts for what the player kills, so a guild that systematically kills slow monsters raises the population's speed within hours.
Species declare r or K (offspring count, maturity, parental care, reproduction threshold); a sector the player neglects reaches capacity and its survivors slowly evolve into apex predators.
At a generation boundary the fitness routine emits Boss_Emerged, and a global manager changes rank and appearance.
Vulnerable and better-defended individuals within one species stabilise predator-prey dynamics, alongside the logistic capacity and refuges.
A disease model where scent-marked territories flatten the infection curve: territorial species limit spread, gregarious r-strategists are decimated fast.
Exceeded carrying capacity drives starving creatures to ignore the human-zone repulsion and raid; a settled predator drives small creatures toward the only zone it avoids, the village valley.
test_ai_pathfinding, stigmergy, aco, boids, personality and budget, and seven test_ecology probes, as the category 3 plan named them.
Reports on UE5 and UE6 PCG, on macro terrain and erosion, on built and enclosed spaces, and on living ecosystems, each naming algorithms, multiplayer limits and workarounds.
Two finalities: walk through a world as faithful as possible to the available historical knowledge, and attend simulated historical moments reconstructed from the corpus, inside the world, through full immersion.
Move procgen kernels (point placement and filtering, WFC, cellular automata, Jump Flooding Voronoi, erosion) to the GPU only when the batch pays for its transfer, with erosion split into read and write passes instead of atomics.
A study of procedural generation for objects (props, assets) and materials (roughness, wear, layering), with cited sources.
Before any Caine code, validate.sh must be able to go green, a parity baseline must be recorded, and every planned symbol must be grounded by a search. Each later phase ends on three checks: one definition per new symbol, a caller outside tests, and a fresh binary.
A single constexpr declaration of the tools derives four things: the JSON-Schema, the per-step GBNF grammar, the call validator and an anti-drift fold. Tools are gated by world state, and every mutating call goes through the command journal.
Give the loop eyes: a deterministic capture a human can look at, critics that read the world and return actionable findings, a scene diff, and bounded returns to the model.
A reason-act-observe loop with a turn budget, a transcript that references the journal, and an end-to-end proof that it fixes a real defect unattended, run from lpl-demon.
Entities that reference other entities, a baked entities section, and sections scoped to the consumer that reads them.
Make plausible intents expressible: ai and ecology by declaration, creatures in the ECS, streaming by declaration, stigmergy policies, placement along the hot path, and a HiGen safety net.
worldforge shows the Caine loop at work and the layers mapview already shows.
Caine and Jarvis run at the same level, in ring 0. agent/, the dispatch through CommandProcessor and CommandJournal, and the DemonHost loop must enter the kernel, with the host build kept as the oracle.
Bounded actions (spawn, set_state, move, attach_behavior, emit_event, propose_scene, tune_policy) run as validated descriptors; a client may predict, only the server applies and replicates; anti-stomp, anti-spam, per-tick quotas and explicit rollback or rejection.
Expose the same tool surface over MCP, so an outside agent can build worlds with the grammar and validation the demon uses.
A runnable demo (provisionally CainePile) shows AI-directed generation: the kernel generates a world or scene and its quests, with effective actions in the simulation under a controlled budget.
Terrain edits are stacked modifiers in priority layers that can be reordered or removed, with a guard so a pass never reads the layer it writes.
A .lplpak and editor section describes a chunked world.
One JSON command entry point driving the registry and procgen, an undoable journal, a headless editing session, and inspection commands.
A scene format driven entirely by the reflection registry, with templates and prefab chains, grown into a game document with metadata, scoped resources, scenes, recipe, templates and entities.
A reference field type in the reflection registry, so an entity designates another by $name.
A standalone editor with a hierarchy, a reflection-driven inspector, procgen panels and simulation controls, all through EditorSession.
worldforge gains views for climate axes, caves, grammar volumes, liminal spaces, streaming and the living layer.
A binary cartridge with header, content hash and section table, a bounds-checked reader in ring 0, and viewer, editor, gate and kernel all building a world through the same pass order.
The cartridge carries species and the food web as data, and how the place looks (sky, water, palette), while machine budgets stay in the host profile.
The cartridge gains an entities section next to the recipe, the binary counterpart of the entities a .lplscene can hold.
Games are discovered by a manifest that names a repository and are cloned or updated from git, and an AI-generated world is a versioned repository.
A generic reader for OME-Zarr and Zarr v2 arrays through an injected store, with blosc and zstd decoding and a memory-mapped cache of fixed decompressed records.
Game logic and AI-written behaviour change without rebuilding the engine, behind a clear frontier: an API whitelist and no raw memory access. Two routes exist: a deterministic bytecode and native C compiled by libtcc.
A game updates itself from its published source, as Flakkari did with git.
The cartridge carries a world's history, a knowledge slice and model weights in its own sections, so everything the demon uses travels in one immutable image read in place in ring 0.
An in-tree harness with warm-up, wall-time budgets, median, CV, min and p99, optimisation barriers, a system-information block and a governor warning.
A voxel section and a --only SECTION filter, so one section runs without the full suite.
Run the suite with the performance governor and the process pinned to an isolated core.
A cycle-counter profiler around each frame phase, reported as shares rather than milliseconds.
Nanosecond-resolution profiling and tracing, including DMA events.
A solo client that hosts a World and shows procgen with every knob on the keyboard.
Every viewer is compiled by validate.sh.
LplPlugin always builds as its own project, and the validation counts object files per module.
Each lpl-benchmark row reports the package energy per repetition, so a speed-up and its energy cost are read side by side.
The local mind — inference in ring 0, directing a deterministic engine.
Inference matmuls get integer SIMD backends dispatched by quantization format and by what CPUID reports at startup, while the scalar reference stays the oracle. A gate requires a measured speedup and identical outputs.
A personal assistant that listens, thinks, remembers and searches, running entirely on the owner's machines in ring 0, at the same level as Caine. The capabilities llama.cpp offers (parallel slots, prefix reuse, embeddings, speculative decoding, expert offload, one model per role) are the checklist to reproduce natively.
LplAssistant follows the conventions of the other repositories so that its freestanding modules can be linked into the kernel without rewriting.
Predict decode tokens per second as memory bandwidth divided by active weight bytes, then measure it on two models of very different sizes, before any purchase or public claim.
Know what nondeterminism remains in a single-user local model at temperature 0, since reproducible means cacheable, testable and replayable.
Move the user's long memory from PostgreSQL and pgvector onto LplKnowledge: an append-only journal of what the assistant learns, baked periodically into a fresh image, so the mind needs no database process.
Decisions come out of one forward pass as typed values (a choice, a score, a probability with a confidence) instead of about 20 tokens of JSON. The owner's priority is to react in a few milliseconds with values, not text.
The base system context is fixed for an epoch, decoded once into a KV prefix, saved, and reused verbatim after a restart. Changes (the date, home events, a new speaker) enter as chronological system messages at safe boundaries, and compaction opens a new epoch. Each contextual fact is a typed producer with a stable key and pure renderers, composed in a fixed order.
Old turns are summarised while each tool call stays paired with its result at the cut. Compaction triggers near the context limit or on overflow, after reminding the mind to save its notes, and research rounds may start from a fresh workspace instead of a growing history.
A small draft (0.5 to 1.5B, or a draft head) proposes several tokens and the main model verifies them in one pass. Lookup decoding with n-gram caches and multi-token prediction are variants.
Store the KV cache in a narrower format, pin model memory, and give decode threads a fixed core.
Several sequences (researchers, speakers) decode at the same time on one resident model, each with its own KV sequence so contexts stay isolated.
A small model handles instant dialogue and page summaries, a larger one plans and writes, and an internal router picks one by task, latency budget and privacy. Small read-only sub-agents return compact handoffs.
Evaluate Topographical Sparse Mapping and its pruning variant ETSM (up to 99 % sparsity, local connectivity), prototype CPU kernels that compute only non-zero weights, and decide go or no-go on measured performance per watt.
Expose the assistant and its research engine to other agents over a standard agent protocol (an MCP facade among them), treated as a transport and never as a dialect the mind has to speak.
Talk to Jarvis by text or voice from messaging apps and let it complete a task, writing and running code locally when needed.
An IFTTT-like engine where the mind reads the intent, picks the triggers and configures the reactions across services (webhooks, messages, alerts).
If the human world can be seeded and Laplace can follow its course, the owner holds conversations with him about the real world's future, grounded in the simulation and the library.
Dense text is rendered to an image and read by a vision model, since image tokens grow with pixels and not with characters (a research note reports up to 85 % fewer tokens on reads).
Hooks before the prompt is built, around tool calls, on tool-result persistence, around compaction and at the start and end of a session, so extensions plug in without rewriting the loop.
Compare edge accelerators for running the mind on small boards: Jetson Orin Nano with unified memory, Pi 5 with Hailo-8L, RK3588, Coral TPU, integrated NPUs.
Doc comments mark a warning with the Doxygen @warning command, which renders as a warning block, instead of the U+26A0 glyph, which renders as plain text.
Research stops on a token budget, not an iteration count. Ten percent is reserved, and once it is crossed the agent must answer from what it has; reasoning per call is capped too.
A research loop that plans, searches, reads whole sources, names its gaps, searches again and writes a sourced report under a token budget, with persistent state, a fast mode and an explicit heavy mode. The owner's bet is a medium local model plus engineering rather than a paid cloud agent.
A fully local, key-free retrieval stack: a metasearch with a fallback, and structured providers (Wikipedia and any MediaWiki wiki, Stack Exchange, GitHub repositories, issues and docs, domain documentation, Reddit, Discourse forums, OpenAlex with its native filters, arXiv), each degrading on its own. Fetching obeys a domain allowlist and denylist and a concurrency cap.
Turn dynamic pages, pages behind cookie walls and PDFs into clean text for the model, with classified failures that never block the whole run.
Rank results by provider authority, freshness and overlap with the query, with category rebalancing and provider diversity, then a semantic score and a rerank. Deduplicate queries semantically and keep numbers and years from matching unrelated items.
Every page or large tool output is stored whole under a hash, the prompt gets a bounded skim plus the hash, and a retrieve tool fetches exact slices on demand, so pages are read in full without flooding the context. Stages pass only compressed findings to each other (columnar or ESON, keys once, row counts to detect truncation), and internal passes write terse output.
Write the report section by section, every claim with a numbered citation, never re-injected into the chat. Refuse to publish without per-branch metadata, checked URLs, a minimum number of sources and domain diversity, and always state the run's limits. A knowledge graph may be emitted as an output, never used as the store, and several reports can later be merged into one decision view.
Each finding carries a strength derived from how many independent sources agree on it.
The agent can run code it writes in a sandbox, the fourth canonical research tool after search, page reading and file parsing.
A fixed bench of 10 to 20 questions, built before optimising and scored at every change, covering API documentation, forum troubleshooting, repository exploration and reading a long PDF. It also tests the owner's bet that a medium local model with good context matches a large hosted model on the same questions.
Read fifteen deep-research projects and links first-hand, write one uniform report per source, and merge them into a master report that is the source of truth for the implementation plan.
Every query a research run generates hits local knowledge and memory as well as the web, and the results are merged before synthesis.
apps/satellite/main.cpp and backend/SatelliteLink.cpp use satellite/ and its 4-byte header instead of the headerless format.
Each room gets an ESP32-S3 with an ICS-43434 I2S microphone (the INMP441 is end of life) and an opto-coupled relay, for about 20 to 23 EUR. It runs only a small wake-word model, streams audio over Wi-Fi and UDP after detection, and switches GPIO on compact binary commands. BLE scans give room presence; Zigbee and Thread cannot carry continuous audio, and Matter adds nothing when both ends are owned.
Satellites use several MEMS microphones in a TDM array with home-made beamforming, acoustic echo cancellation and noise suppression; whether the DSP runs on the node or on the brain is open.
Transcribe speech captured by the satellites or the kernel's own microphone with a whisper-class model, in the same image as the language model.
The assistant speaks through a synthesis stage that starts on the first sentence of the answer, helped by a system prompt that puts the answer first and drops filler.
Identify speakers from spectral statistics and pitch over a PCM buffer, in Fixed32, so the kernel recognises voices and two machines recognise the same voice.
Speakers' inputs land in a durable inbox and reach the model only at a safe turn boundary (steer, follow-up, collect or interrupt). Each session's turns run through its own queue plus a global lane, and transcripts persist in order.
The brain treats the satellites as entities in a main loop that never blocks inference, generates from preallocated pools, and hands captured audio to the model's input buffers without redundant copies.
Satellites passively scan BLE beacons (a phone, a watch) without pairing and tell the brain which room is occupied.
The assistant reads sensors and switches plugs, lights and music, entirely locally, like a private Google Home.
The model decides WHAT a world should be in a few hundred tokens of tool calls, and the deterministic engine decides HOW. Every act is validated against a grammar derived from one component declaration, journalled, undoable and replayable. In the artistic direction the director is Laplace, the demon; Caine is a code name.
The grammar is regenerated at every step and names only what is callable now, so a tool the world cannot perform is one the sampler cannot spell.
A French sentence goes to the model, which emits tool calls constrained by the grammar of the current world; the engine executes them through the journal and the critics report back to the model.
The AI moves an invisible camera (take_screenshot at x, y, z, rotation), a small vision model looks at the frame and spots a semantic defect such as a bridge floating 2 m above the ground, and the AI re-calls the generation tool to fix it.
Beyond terrain, the director proposes interactive content: adventures, encounters, NPC directives and dialogue, decor, quests, gameplay constraints and scene variations. Each mode is a bounded structured output, and a short-range context memory keeps decisions coherent.
The mind generates graphic assets (images, 3D models) and places them in the kernel's renderer to build immersive worlds.
The library — a corpus the engine can read, and the demon can cite.
Every algorithm and idea the project rests on is traced back to the report that argued for it and forward to the code that implements it and the book section that explains it. It is the reverse index the book is written from.
A catalogue of what exists (holdings, works, places) is baked into .lplknow images as a stream, read by mapping and queried without a server. A catalogue too big for one image becomes several parts rather than widening every offset.
A bounded reader on the ring-0 side of the reader/writer line opens a .lplknow image with no heap, no network and no parser, and a world cites the sources it was built from.
LplKnowledge is the memory a model reads instead of RAG and its database: one versioned signature section in .lplknow and one implementation of 'filter first, similarity second', read by mapping and identical on the host and in ring 0. A strict structured filter removes most of the corpus, similarity ranks the subset, and a join, not the model, supplies the linked facts.
Metadata and access points, not full texts, of about 477 million works are baked into catalogue images, with publication types reconciled across bases.
Structured corpora are cloned or bulk-synced and ingested with the CTS URN or source identifier as key: First1KGreek and Open Greek and Latin, CSEL and Patrologia Latina, OpenMedFr, PROFITEROLE and SRCMF, the Middle English Texts Series, MGH and OPenn, plus static dumps such as Sefaria, OpenITI, SARIT, TLA, CBETA and Papyri.info. Repositories without a static publication come first, before they disappear.
Internet Archive and Open Library, Gallica, Europeana, the Library of Congress, Wikisource, the British Library and FranceArchives are catalogued, and fetched where free, next to the HathiTrust and Gutenberg parts, with heritage OAI-PMH endpoints such as Europeana EDM, Rijksmuseum, e-codices and BDRC.
A second pass over a written image fills CatalogueEntryV1::cluster when the bake was streamed, since clustering needs all keys at once.
The library is fed automatically and says when a newly harvested work matches a registered interest: feeds and source deltas are normalised, delivered as signed callbacks with a replay guard against loops, checked for relevance, then notified.
A reproducible offline mirror of the OSDev wiki built from its weekly XML dump: atomic acquisition, a streaming parse, the category taxonomy, a logical view over a single physical copy, rendering and offline search, usable while working on the kernel.
media/ extracts from a video its transcript, two or three informative frames per minute and its metadata, picks frames at motion troughs by reading codec motion vectors without decoding, and indexes the result as a source.
The owner's playlist on procedural generation (430 and more videos, 30 listed, from creators such as Sebastian Lague, SimonDev and Herbert Wolverson) gets its titles, descriptions, transcripts and keyframes indexed so procedural-generation work can cite it.
Large technical PDFs such as Intel's architecture manuals, papers and reports are ingested with their sections, tables and figures, so a model searches and cites them precisely.
The eight unbuilt headers of graph/ are deleted, and FOLDED.md, which says why lpl::history and gate P13 replaced them, moves to the repository's documentation, linked from the README.
Private source documents live only in the ignored store directory, and nothing left at the repository root can be published by accident.
Wikidata, GDELT, Internet Archive and FamilySearch crossed into one probabilistic model of history that can be simulated, queried statistically and cross-examined the way a historian would.
Birth, marriage and death records (FamilySearch, French departmental archives digitised from the 16th century to about 1902) seed and constrain a population simulation, within the 75 to 100 year privacy limits.
Host-side harvesters turn texts into dated, sourced facts (identity, dates as intervals, entities, witnesses and grounded claims), baked once into .lplknow and read in place in ring 0.
A conversation with a language model is a reading lead, never a source: a fact is admitted into the history corpus only together with the attestation that supports it.
Corrections are marked E (error), I (imprecision) or V (verified, the doubt was wrong), a confrontation table keeps what the source actually said, and the sources a text cites are listed apart from the sources used to verify it.
A reading report of a source conversation keeps its dated facts (the chronological index with turn references), its provenance lists and its verification table in a form the library can bake, and sibling reports join it.
HYDE 3.3 rasters (population density, cropland, pasture and urbanisation from 10,000 BCE to today, at 5 arc-minutes) are baked by a host tool into a per-chunk population map and interpolated between epochs, to place the right number of villages and people for the simulated year.
Year-by-year border polygons since 3000 BCE define territories according to the simulated year.
The simulation follows coastline and environment change over the Holocene (delta growth, isostatic rebound, desertification) rather than tectonics.
Each source conversation gets its own report: turn ids T01 to Tnn local to the file and taken at delivery, the source line of each turn, a fixed Question/Answer/Sources/Note block, derived views (tables, chronological index, sources) updated on each addition, and an append-only extension journal.
Sources that exist only on paper or unindexed microfilm get scanned, per item through institutional on-demand services or at scale through partnerships that scan for free in exchange for a copy.
Files become 150 to 200-base oligos with no homopolymers and 40 to 60 percent GC, protected by Reed-Solomon per strand and a fountain across strands. The encoder screens each droplet in silico at no bit cost and reaches about 1.98 bits per base. Dense decoders are fast enough to cut stored redundancy from 30 to 50 percent toward 10.
Choose and prototype a medium that needs no power once written and no proprietary reader: fused-quartz voxels (Project Silica), micro-engraved sapphire or ceramic readable with a microscope, M-DISC; LTO only as a migrating 10 to 15 year tier, DNA later.
Keep the DNA storage notes as a research thread: 2 bits per base, costly writes and cheap reads, decay by water, oxygen and UV, silica encapsulation, short redundant oligos, homopolymer and GC constraints, rotation coding, inner and outer codes, enzymatic synthesis and composite DNA.
If the library needs an immutable or shared index, it is content-addressed (a Merkle tree or a DHT), with an efficient transport and an archive interface; seeding obligations keep rare works alive.
Signal processing and alignment turn raw nanopore current traces into bases in real time with a small memory footprint, tested on public .fast5 and .pod5 traces.
The book, the READMEs and this site, and the talks and papers about the project.
A reserved book chapter on scheduling and multitasking: partitioned EDF, SMP, XSAVE state and the mind's budgets.
A reserved book chapter on storage and file systems (Phase 7), with the NVMe-before-ATA reasoning.
Chapter 10, Figure 10.1 and Annex D show what the code does: the engine (libengine.a), the mind (libassistant) and the library (libknowledge) linked in ring 0. The ring-3 design stays as a reference box: what it was, why the code surpasses it (no ring crossing left to cheapen, so no syscall, SWAPGS or PKRU switch), and what survives of it inside ring 0.
Chapters 1, 2, 5 and 7 describe what LplKernel's code does in ring 0, and keep each hosted Linux passage as the oracle side of the parity gates and as a reference, saying what the ring-0 design does instead and why.
The preface or chapter 1 states the law with its three angles and its figures, chapter 10 is organised around it, a section presents paging as an application cache (the expert is a page, a fault that reads NVMe, oracle-driven prefetch), and an inference section explains what mixture-of-experts decouples and why bandwidth decides.
New sections 9.2.5 (energy of data movement), 9.2.6 (determinism as an energy discipline), 9.6.4 (wake-up accounting), 9.9 (measuring energy, including energy per token) and optionally 9.3.4 (platform power: ASPM, EEE, APST, PSR).
Sections 9.4.3 and 9.5.1 describe what kernel/kernel/power does, and keep the book's older MWAIT snippet as a reference that says why it is wrong. Where the book describes a design the code lacks, the passage marks it as a target and links the code issue.
One chapter argues that NVMe, virtio, io_uring, AF_XDP and RDMA verbs converged on one design (descriptor ring, doorbell, completion) that LplKernel met several times: the measured cost of a copy and a syscall, a ring and doorbell in its own driver, NVMe, the rkey capability, and what RDMA does not bring when there is no kernel boundary.
Every passage that presents an unbuilt feature as shipped says it is a target and links the issue that builds it. Nothing is cut: the description stays, in the future tense or in a box marked target, until the code exists and the passage can name its file and test.
GPU and accelerator passages stop assuming NVIDIA (CDMM, CUDA, GSP, Tensor Cores), describe how the kernel detects what a machine offers at boot and which fallback it takes, and name which machine tests what.
A chapter presents the cross-ring gates P6 to P21 (rendering, world generation, living world, endless world, botany, erasure codes, Rosetta plate, reconstructed past, mind, satellite, agency, reasoning, corpus, caves, journey, relief), their folds, counters and controls, and the verification failures the project paid for: a check that cannot fail, a check satisfied for the wrong reason, a test green by symmetry of the bug.
A chapter covers LplAssistant as linked in ring 0: the integer transformer (8-bit weights, Q16.16, CORDIC rotary angles), grammar-constrained decoding, the satellite, the agency and reasoning gates, and the director role (code names Jarvis and Caine; Laplace the demon in the artistic direction).
Chapter 12 covers weighing knowledge (storage is not the bottleneck), what can be reached and what is lost, the temporal graph and contradiction, possible worlds, retrieving without hallucinating, the Rosetta plate, the .lplknow image and its ring-0 reader, how a world cites what it was built from, and the demon's test of rebuilding a real past.
Annex E covers Reed-Solomon over GF(256) (Berlekamp-Massey, inner and outer codes), fountain codes (LT, robust Soliton, peeling), rateless codes, GF(2) algebra (bit packing, vector XOR, the i686 scalar fallback), M4RI and Gray code, and the two uses of one engine (network, archive).
A new Part VI opens with chapter 11 in 17 sections, from why to generate rather than store to measuring rather than rereading. It fixes the architecture of these systems, including how they allocate memory, tells the inversion (the AI decides, deterministic C++ executes) and the lineage from Flakkari through EngineSquared to LplPlugin, and uses the measured tables as sidebars with four Mermaid diagrams.
A chapter covers the shipped drivers (PS/2 with layouts, PCI enumeration and BARs, HDA capture with the outputs muted, interrupt-driven input) and the decision to write NVMe before ATA.
Chapter, part and annex numbers are reserved before a chapter is written and recorded in one place, and new chapters are appended at the end, never inserted.
The preamble says six parts; the reading paths gain a game-engine path through chapter 11 and an archivist path to chapter 12; the vision states the four layers and the library's place; chapter 10 gains 'store the generator, not the result'; Annex B gains the new terms (temporal knowledge graph, fountain code, GF(2), M4RI, TEI/CTS, IIIF, GBNF, WFC, MCP and others); Annex C gains the sources of the new chapters.
Each existing chapter receives its share: ch1 the fixed step justified by biology; ch2 memory bandwidth as the inference bottleneck, pooling versus GC and entity budgets; ch3 the demon chapter (Laplace 1814 as a specification); ch4 possible worlds and transactional parallelism; ch5 unified memory and inverse kinematics; ch6 prediction as the demon predicting its master, state hashing as a fold, inputs as the only irreducible, erasure coding; ch7 decision-to-knowledge latency; ch8 the demon refuted; ch9 zero-watt archive media and the energy cost of hallucination; ch10 store the generator, not the result. The LplPlugin wiki is folded with a correct chapter mapping.
Every section, old and new, goes through humaniser-fr then profil-voix one at a time, and every ASCII diagram from the source documents (Rosetta decoding stack, DNA pipeline, webhook architecture, LT fountain, MCP) is redrawn in Mermaid with English node text.
Annex A, Annex C, Annex D, the colophon, the conventions and chapters 2 and 8 agree with each other, with the companion file and with the code.
The companion file of Annex A follows the engine's rules and is compiled by CI so it cannot rot.
Chapter 10 places LplKernel in the immutable-OS size table (a 7.5 MiB bootable ISO, about 9 MiB of RAM, no persistence, about 28 times smaller than Talos), uses the July 2024 CrowdStrike outage as the counter-example in 10.9 (a ring-0 agent whose bad update bricked machines) with the degraded boot of LPL_PLUGIN_UNAVAILABLE as the answer it lacked, and states the x86_64 dependency in 10.3.
A documented study of what a quantum-classical OS needs: no-cloning (no fork, copy-on-write, snapshot or swap), data movement by entanglement swapping, decoherence-aware scheduling, magic-state factories, logarithmic quantum forking, and the QPU as an offload accelerator.
A text on digital ownership and free knowledge: buying is not owning, games as cultural works and the Stop Killing Games demands, open access and the cost of closed science, and self-hosting as real sovereignty.
Where the code has moved past the book, the passage describes the code's method with its file or test, and keeps the book's older method in a reference box that says why it is worse and what surpasses it. Nothing is deleted.
Write and submit the paper ('Zero-Copy Event-Driven Architecture for Real-Time VR Simulation' in the wiki, 'Zero-Copy from NIC to GPU inside a Kernel-Space Engine' on the blog).
A formal architecture decision record that locks the mind entirely in ring 0 and states its consequences for the client, server and satellite profiles.
A follow-up blog article on driving game NPCs with the same deterministic local head.
The issues are the roadmap now and the site reads them, so docs/ROADMAP.md leaves the repository and goes to the owner's private archive, after every idea and piece of knowledge in it has an issue or a place in the book.
The README gives the current toolchain, says what the repository links and where each part comes from, and how to build and verify it.
The README describes the engine as it is: its modules and its two targets, the hosted parity oracle and ring 0 inside LplKernel.
The wiki describes the engine that runs in LplKernel's ring 0, and its pages agree with each other and with the code.
The published benchmarks post and the wiki give one set of numbers for one harness, with the build flags and the machine stated.
The site's roadmap page is built from the GitHub issues of the Laplace project: tracks, their items, states and priorities. site/src/data/roadmap.ts stays as the fallback when the issues cannot be read, and the page says so.
The roadmap shows the delivered LplPlugin phases and gates beyond P6, world generation and the AI director, and tracks for LplAssistant and LplKnowledge.
LplAssistant and LplKnowledge appear on the site as projects of Laplace, with a public link, in the Abysse and Ambre direction (0 px radius, sparing amber, monospace for data).
The site boots both kernel profiles in the visitor's browser (server as a terminal, client with graphics and keyboard), and CI rebuilds the ISOs and redeploys on every push to main.
The site uses an abyss-black background, off-white text, sparing amber and orange accents, JetBrains Mono and Inter, 0 px radius and 1 px blueprint lines, in a research-paper style with a bare-metal terminal edge.
Decide whether a subtle CRT grain or scanline effect strengthens the terminal feel without hurting the research-paper seriousness.
A projects page links every repository of the Laplace project, including the legacy Engine-3D and Flakkari, as its foundations.
Math renders on blog and paper pages as well as in the book.
astro and esbuild in site/ carry no known advisory, and the dev server serves /book.
The project's identity centres on Laplace's demon, who runs the worlds (LplPlugin) and the outside world (LplAssistant), and the borrowed code names Jarvis and Caine get real names consistent with that direction.
A reviewed guide, published in the repositories, fixes the role of each repository and which links which, the hard determinism contract, the per-slice parity workflow, naming with spelled-out acronyms, the dual build and the dev loop, the server and client profiles, the commit rules, and the two numbering rules (gates, book chapters).
Every parity gate is written with its module ('gate P18 corpus', 'gate P19 caves'), 'Phase N' is kept for the OSDev phases, and gate numbers are assigned at delivery, never reserved in advance.
The existing slice is written up: glFrustum, drawGizmo, and colour picking that encodes the entity index in a colour and reads back the pixel under the cursor.
A 3,000 to 4,000 word systems paper for the site blog, written by the author himself, one section per part of the talk, with each demo as a 'try it at home' box carrying its command.
A 45-minute talk (35 minutes plus 10 of questions) in eight parts, from the two price curves to 'everything is connected', with kernel boxes on paging and on the tick and IPIs, submitted in the software development and AI category with green computing in the abstract.
The post tells the real incident, the memory ordering used and the test that caught it.
The blog carries a technical postmortem of the lineage (Engine-3D, Flakkari, LplPlugin, LplKernel), next to systems papers on the hard problems and benchmarks from captured data.
The article on refactoring kernel.c into a linear orchestrator with a boot splash is published with its author placeholder resolved.
An IMRAD article on the convergence contract and its verification (the validate.sh checks, the booted artefacts, the cross-target folds of the gates) is deposited with a DOI, with the repository cited as reference.
The machines behind Laplace — remote access, private names and TLS, a home server, a router, backups.
From the metro on 4G, open VS Code on the home PC: the PC answers by name, SSH works, Moonlight shows the screen, and the link is direct, not relayed.
Every service has a name that resolves privately at home and from anywhere on the tailnet, with a certificate valid on every device.
The services run on a low-energy server described entirely in a versioned tree, backed up 3-2-1, with secrets out of the repository and an encrypted disk.
A mini-PC router replaces the Bbox: it gets the public address, routes IPv4 and IPv6, hosts WireGuard and a restricted UPnP, and later boots LplKernel.
The private working documents of the project (the ignored store/ folder of LplKnowledge, and the notes around it) have a backup outside git.
Buy a Framework Desktop with the maximum soldered memory, choosing between the AI Max+ 395 (128 GB, 256 GB/s) and the PRO 495 (192 GB, 273 GB/s, up to 160 GB allocatable to the GPU) after checking the GPU-allocatable share, the PCIe generation of the NVMe slots and sustained thermals. It hosts local large models, the infrastructure, and LplKernel as a second real test machine.
One day Laplace runs the forge: LplCraftSkills and forgeron on LplKernel servers.
Far future: Laplace replaces Claude. LplCraftSkills and its orchestrator forgeron run on LplKernel servers, write code, open pull requests and manage issues.
Nothing matches this filter.
This roadmap was read from the GitHub issues of the Laplace project on 2026-10-05, when the site was last built. Each track is a parent issue and each card one of its sub-issues, linked from its title; the steps below a card count into its progress.