[TERM: tty1] sys@openooda:~# ooda context openOODA [SYS_OK]

SOVEREIGN SYSTEMS LANGUAGE // TECHNOLOGY PREVIEW

Fail-Closed by Design

openOODA is a capability-secure systems language where every effect requires an explicit, unforgeable capability token. Your process is born with no privileges. That is not an accident. That is the type system. A function that touches the network takes &NetCap or it does not compile — E_CAP is not a warning.

> Agents are writing production code now. Ambient authority means anything they emit can touch everything. openOODA makes authority explicit — checked by the compiler, not the prompt.

sys@openooda:~# curl -fsSL https://openooda.org/install.sh | bash

-- WHAT IT BRINGS --

01
OCAPS // Capability Security

Every effect — network, disk, process, GPU — requires a capability token held by the code that performs it. Missing a cap isn't a warning — the build refuses. 14 language tokens, 26 substrate capabilities, enforced at compile time.

02
LLVM IR // Self-Hosting Compiler

oodac compiles .oo source to LLVM IR and lets clang emit the native binary. The compiler is written in openOODA and compiles itself. Type-checks run in <3ms via Merkle-AST caching.

03
AGENT-NATIVE // Built for AI

The toolchain ships an MCP server, an LSP, and an llms.txt map — so agents read, check, and build openOODA the way it was designed to be used.

-- ANATOMY OF A CAPABILITY: COMPILE-TIME ENFORCEMENT --

SOURCE: src/network.oo [ TYPE SYSTEM ]
// ❌ UNPRIVILEGED: Ambient authority does NOT exist
pub fn fetch_weights() {
    http_get("https://openooda.org/model.bin");
}

// ✅ VERIFIED: Sealed effect requires explicit token
import "std/net/http.oo";
pub fn fetch_weights(net: &TcpCap) -> Result[String, Error] {
    http_get(net, "https://openooda.org/model.bin")
}
COMPILER DIAGNOSTIC: oodac check [ E_CAP: FATAL ]
error[E_NAME]: undefined identifier http_get — import std/net/http.oo
  --> src/network.oo:3:5
   |
 3 |     http_get("https://openooda.org/model.bin");
   |     ^^^^^^^^ did you forget `import "std/net/http.oo";`?
   |
   = note: sealed network ops live in the standard library, not the
        language; the symbol itself must be imported first, then the
        call still requires a cap token (E_CAP below).
   = help: import std and pass &TcpCap:
          import "std/net/http.oo";
   pub fn fetch_weights(net: &TcpCap)

-- THE CONSTELLATION: 13 REPOSITORIES, ONE SYSTEM --