SOVEREIGN SYSTEMS LANGUAGE // TECHNOLOGY PREVIEW
Fail-Closed by Design
openOODA is a
capability-secure
systems language where every effect requires an explicit,
unforgeable capability token.
Your process is born with
no privileges.
That is not an accident. That is the type system. A function that
touches the network takes &NetCap or it does not
compile — E_CAP
is not a warning.
> Agents are writing production code now. Ambient authority means anything they emit can touch everything. openOODA makes authority explicit — checked by the compiler, not the prompt.
curl -fsSL https://openooda.org/install.sh | bash
-- WHAT IT BRINGS --
Every effect — network, disk, process, GPU — requires a capability token held by the code that performs it. Missing a cap isn't a warning — the build refuses. 14 language tokens, 26 substrate capabilities, enforced at compile time.
oodac compiles .oo source to
LLVM IR
and lets clang emit the native binary. The
compiler is written in openOODA and
compiles itself.
Type-checks run in <3ms via
Merkle-AST caching.
The toolchain ships an
MCP server,
an
LSP,
and an llms.txt map — so agents read, check, and
build openOODA the way it was designed to be used.
-- ANATOMY OF A CAPABILITY: COMPILE-TIME ENFORCEMENT --
// ❌ UNPRIVILEGED: Ambient authority does NOT exist pub fn fetch_weights() { http_get("https://openooda.org/model.bin"); } // ✅ VERIFIED: Sealed effect requires explicit token import "std/net/http.oo"; pub fn fetch_weights(net: &TcpCap) -> Result[String, Error] { http_get(net, "https://openooda.org/model.bin") }
error[E_NAME]: undefined identifier http_get — import std/net/http.oo --> src/network.oo:3:5 | 3 | http_get("https://openooda.org/model.bin"); | ^^^^^^^^ did you forget `import "std/net/http.oo";`? | = note: sealed network ops live in the standard library, not the language; the symbol itself must be imported first, then the call still requires a cap token (E_CAP below). = help: import std and pass &TcpCap: import "std/net/http.oo"; pub fn fetch_weights(net: &TcpCap)
-- THE CONSTELLATION: 13 REPOSITORIES, ONE SYSTEM --
openOODAthe constitution — 24 laws, RFCs, governance↗
oodacthe self-hosting compiler — .oo → LLVM IR → native↗
oodarcapability-secure C substrate — PQC, Landlock, ROCm GPU↗
stdthe standard library — 188 modules across 8 domains↗
oodathe workflow driver — build, run, test, fix↗
clithe language CLI driver — build, run, fmt, update↗
tuithe line-mode coding harness — slash commands, LLM round-trip↗
installthe one-line toolchain bootstrap↗
opmthe package manager — capability-aware, signed, deterministic↗
catalogthe public package registry↗
lspthe language server — diagnostics, rename, go-to-def↗
mcpthe MCP server — 26 capability-aware tools for agents↗
bbthe flight recorder — agent-native crash autopsy↗