MAKE / BREAK issue #06 · every other week · text version
MAKEissue #06

Boot your own OS

This week's security in plain English, a two-minute check on what your phone's apps can reach, and the project: boot a tiny operating system I built, then bring the plasma from #00 back to life as one of its apps.

this week in security·beginner's corner·the project·your turn

Two BREAK issues on the bounce, so we're owed a proper MAKE. And this one's a bit personal: for the last few weeks I've been building an operating system. A small one — desktop, windows, a terminal, a tracker, a handful of games — called acid OS. Today you boot it, write an app for it, and then crash that app on purpose to see why the rest of the system doesn't care. It's free, it's open source, and you don't need to flash anything.

> this week in security

Three quick ones — and a theme you'll spot again in the project: keep things in separate boxes.

A robot broke into a security charity — on its own. On 21 September an autonomous AI agent, with no human driving it, chained two unknown bugs in Zammad (a popular open-source helpdesk) and got root on a server at DIVD, the Dutch volunteer group that literally warns people about vulnerabilities. DIVD called it "loud and very, very messy" — it even tripped over its own password-spraying. What stopped it going further wasn't cleverness: their network was split into compartments.

→ do this: if you run anything at home that faces the internet — a NAS, a Plex box, a little server — switch on its automatic updates, and put it on its own network (your router's "guest" Wi-Fi will do). One break-in, one room. (source)

Police took down a ransomware gang allegedly run by a 16-year-old. Operation KillSwitch, on 30 September, seized KillSec's servers and leak site — and at least 110 terabytes of stolen data — after around 1,000 attacks. Searches took place in four countries, the UK among them.

→ do this: the thing that makes ransomware toothless is a backup the attacker can't reach. Copy the photos and documents you'd cry over to an external drive this weekend, then unplug it. (source)

Chrome patched a bug that attackers were already using. CVE-2026-85046, a flaw in Chrome's JavaScript engine, let a booby-trapped web page run code on your machine — and Google confirmed it was being exploited in the wild. Fixed in Chrome 152.

→ do this: in Chrome go to ⋮ → Help → About Google Chrome. If it says "Relaunch", the fix is sitting there doing nothing until you click it. (source)

> beginner's corner

Today's project is all about apps that live in their own little box. Your phone already works that way — the trick is checking what each box is allowed to reach.

Do a two-minute permissions audit. On an iPhone open Settings → Privacy & Security; on Android, search Settings for Permission manager. Tap Location, then Microphone, then Camera. Anything that doesn't obviously need it — a torch app with your location, a game with your microphone — set it to Never or Ask every time. An app can't leak what it was never given.

The project — boot your own OS

acid OS runs in a window on your Linux desktop, so nothing gets installed over anything. You'll boot it, give it a new app, then break that app and watch the OS shrug.

What you'll need: a Linux machine with a desktop (X11 or Wayland — any distro), about ten minutes for the first build, and a willingness to type cargo.

↗ acid OS on GitHub

Prefer to grab the finished app? plasma.lua and plasma.app.toml — drop both into v3/apps/.

01Boot it

Install the build tools (Debian/Ubuntu shown — the Fedora and Arch lines are in the repo's README):

sudo apt install build-essential pkg-config libasound2-dev git curl
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"

Then grab it and run it:

git clone https://github.com/NorfolkHacker/Acid-OS-V3.git
cd Acid-OS-V3
cargo run --release --manifest-path v3/Cargo.toml -p acid-os

The first build takes a few minutes; after that it boots in seconds. Pick a screen size (or just wait three seconds) and you're on the desktop. Have a poke: Menu is top left, and the File Manager → Games folder has AcidStorm, Acid Invaders and a Tetris that will eat your evening. Stay in the top folder of the repo when you run it — acid OS finds its apps by a path relative to it.

02Bring the plasma back

Remember the plasma from issue #00 — four sine waves stacked into something that looks alive? We're giving it a home. An acid OS app is just two files in v3/apps/: a Lua script, and a tiny "manifest" saying what it's called and how big its window is.

v3/apps/plasma.app.toml

name = Plasma
w = 240
h = 176
desc = Issue #00's plasma, now an app

v3/apps/plasma.lua

local Plasma = AcidGame:extend("Plasma")
Plasma.TICK_MS = 40              -- 25 frames a second

local CELL = 4                   -- each "pixel" is a 4x4 block
local TOP = 16                   -- the title bar is 16px tall

function Plasma:on_create()
  self.w, self.h = acid_window_size()
  self.cx, self.cy = self.w // 2, self.h // 2   -- where the ripple starts
  self.t = 0
end

function Plasma:on_touch(x, y, pressed)
  if pressed then self.cx, self.cy = x, y end   -- drag the ripple about
end

function Plasma:on_tick()
  self.t = self.t + 0.08
  if not self:focused() then return end

  local t, cx, cy = self.t, self.cx, self.cy
  acid_begin_frame()
  acid_draw_window_frame(self:window_title())
  for y = TOP, self.h - 1, CELL do
    for x = 0, self.w - 1, CELL do
      -- the same four ripples as issue #00, stacked
      local v = math.sin(x * 0.04 + t)
              + math.sin(y * 0.03 - t)
              + math.sin((x + y) * 0.03 + t)
              + math.sin(math.sqrt((x - cx)^2 + (y - cy)^2) * 0.04 - t * 1.5)
      -- v runs from -4 to 4: turn it into a spot on the 256-colour wheel
      acid_fill_rect(x, y, CELL, CELL, AcidPalette.hue(math.floor(v * 32 + t * 20)))
    end
  end
  acid_draw_window_border()
  acid_end_frame()
end

Plasma:new():start()

Run it straight into the desktop:

cargo run --release --manifest-path v3/Cargo.toml -p acid-os -- --app plasma
The acid OS desktop with a Plasma window showing a colour-cycling plasma in chunky 4-pixel blocks

The real thing: acid OS at 640×480, plasma window up front.

There it is — the plasma, in a window, in an OS. Click and drag inside it and the ripple follows you. What's going on:

03Now break it (on purpose)

This is the bit I'm proudest of. Add one line at the top of on_tick — a loop that never ends:

  while true do end

Run it again. The plasma freezes… and about two seconds later its window just goes. Look in the terminal you launched from:

the terminal you ran cargo from
Acid OS v3: v3/apps/plasma.lua: stopped responding

Everything else — desktop, clock, any games you had open — carried on as if nothing happened. That's because every app gets its own Lua brain on its own thread, and the OS keeps a stopwatch on each one. Hog it for more than two seconds and you're out. (Try error("boom") instead and you'll get your own message in the same spot.) Real operating systems do exactly this, just with more paperwork — it's the same "one break-in, one room" idea as this week's news. Take the line back out before you carry on.

> your turn

Fold it. Issue #01 turned the plasma into a kaleidoscope with one line — measure from the centre and mirror it with math.abs. Do the same here: before the sums, swap x and y for math.abs(x - self.w // 2) and math.abs(y - self.h // 2) and watch it go symmetrical. Then make it sing: in on_touch, play a note whose pitch follows your finger (acid_play_note(0, 30 + y // 4, 60) on press, acid_stop_note(0) on release — chapter 5 of the manual in docs/manual-v3/ has the rest). Built something good? Open a pull request on the repo with your app in v3/apps/ — the neatest one ships with acid OS.

Stop scrolling. Start making.

A new one every other week — free, right here.

Follow via RSS ▚

— the Norfolk Hacker

No paywall, no ads, no sponsor telling me what to say. If an issue earned you a brew, ☕ buy me a coffee — it keeps the soldering iron hot.