// the find
oxidecomputer/hubris
A lightweight, memory-protected, message-passing kernel for deeply embedded systems.
Hubris is a message-passing, memory-protected microkernel from Oxide Computer for deeply embedded ARM targets (Cortex-M), built to run the actual firmware on Oxide's server hardware (Gimlet, Sidecar, PSC, Cosmo). It's for teams building safety- or reliability-critical embedded systems in Rust who want real process isolation between tasks, not a superloop or a general RTOS like FreeRTOS/Zephyr.
The kernel enforces MMU/MPU-backed memory protection between tasks and uses synchronous IPC instead of shared memory or a global allocator, so a driver crash doesn't take down the whole system — this is the actual design win over most embedded RTOSes. It's been running in production on Oxide's own server sleds for years, not a research toy, and the buildomat CI matrix building every board/app.toml combination is real evidence of that. The custom xtask build system, Idol IDL for typed IPC interfaces, and Humility debugger integration are a coherent, opinionated toolchain rather than bolted-on tooling. i2c_codegen with committed snapshot tests is a nice touch for catching regressions in generated peripheral code.
You cannot use cargo build/run directly — everything goes through xtask, which is a real onboarding tax and means the usual Rust muscle memory doesn't apply. Hardware support is narrow and Oxide-specific: STM32F3/F4/G0/H7, LPC55, and Oxide's own boards; there's no path to, say, RISC-V or ESP32 without writing a chip crate yourself. Windows/Linux are the only tier-1 build platforms and the README explicitly warns that linker output differs across platforms, so 'works on my machine' is a real risk for anyone not on Oxide's blessed Linux setup. The LPCXpresso55S69 debug story requires reflashing the onboard debugger with a custom 'RickLink' firmware build — that's a multi-hour side quest before you can even flash your first image on that board.