Baleen

A static-partitioning separation kernel for AArch64/EL2, built so that its claims can be checked rather than believed.

View the Project on GitHub via-balaena/baleen

Milestones — the append-only log

⛔ This is a LOG, not status. It is append-only: entries describing something as “next” or “planned” are records of what was true when written, and are deliberately not updated. For where the project actually is, read the root README.md’s What this is, honestly.

★ It is kept in full, and moved here rather than trimmed, because the reasoning is the reusable part — each entry says what was built, why that thing next, and what it cost. That is the record this project’s whole discipline rests on. It lived in the root README until it was 561 of that file’s 850 lines, where its own “read this as a log” warning was doing work that a filename can do better: a reader who opens MILESTONES.md already knows what they are reading.

Where the metal is, in one line: two unmodified Alpine Linux kernels boot on hv-metal’s EL2 with two vCPUs each, time-slicing one physical CPU, owning no real device MMIO at all and half the RAM window each, hardware-refused from one another’s memory — with an SMMU denying bus-master DMA by default in the same machine, all under required CI gates.