About this project
Tock is an embedded operating system designed to run multiple concurrent, mutually distrustful applications on Cortex-M and RISC-V based embedded platforms. Its design centers on protection, both from potentially malicious applications and from device drivers.
Two mechanisms provide this protection. First, the kernel and device drivers are written in Rust, a systems language offering compile-time memory and type safety; this protects the kernel (scheduler and hardware abstraction layer) from platform-specific drivers and isolates drivers from each other. Second, memory protection units isolate applications from each other and from the kernel.
The project is on its second major release (Tock 2.x), with a changelog summarizing recent features and improvements.
Resources include the Tock Book for tutorials and documentation, a textbook on getting started with secure embedded systems, API docs, a contributing guide, and code review guidelines. Community support is available via Matrix, Slack, an email list, a blog, and social media.
The project follows the Rust Code of Conduct, and contributors are expected to adhere to it across repositories, chats, and events.
Tock has an academic background: the primary design paper was presented at SOSP'17 ("Multiprogramming a 64kB Computer Safely and Efficiently"), with additional papers on the security model (EuroSec'22), writing a kernel in Rust (APSys'17), and early experiences (PLOS'15). A SOSP'25 paper reflects on ten years of development.
Licensing is dual: Apache License 2.0 or MIT, at the user's option, with contributions dual-licensed under the same terms unless stated otherwise.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.