ANNOUNCING SUBSTRATE V0.1.0

Systems Software Engineered for Absolute Memory Safety and Host Confinement.

Root Access Software builds deterministic, low-level server infrastructure, Linux control plane tooling, and developer utilities designed from the kernel up in pure Rust.

substrate-daemon v0.1.0 (x86_64-unknown-linux-musl) UDS: /run/substrate/control.sock

dave@core01:~$ substrate status --verify-privilege-isolation

[INFO] Connecting to IPC socket via direct Unix Domain Socket (SO_PEERCRED validated)...

[OK] Peer UID: 1000, GID: 1000 | Privilege boundary bridge active via musl static helper

[OK] Linux Netlink IPS: 0 dropped packets | Dynamic nftables in-kernel sets synced

[OK] POSIX Sandbox: Landlock v3 + seccomp filter active (openat2, no ambient root)

[ACME] Automatic TLS: instant-acme certs active for *.rootaccess.software (ECDSA P-384)

[METRIC] RSS: 4.8MB | Thread pool: 2 workers (sync event stream) | Syscall latency: 12µs

Substrate Control Plane

A memory-safe, lightweight Linux server control plane built to replace legacy, uncontained multi-process monolithic panels with verifiable kernel-level isolation.

01 / STATE ISOLATION

Zero Global State Contamination

Eliminates arbitrary modifications to /etc/login.defs, PAM configs, or global sudoers. Operations are executed strictly in ephemeral, jailed process spaces without mutating base OS identity layers.

Boundary: User Namespace Purity: 100%
02 / PRIVILEGE BOUNDARY

Privilege Separation & Musl Bridge

Decouples UI and client tooling from privileged operations via strongly typed Unix Domain Sockets and an audited static musl setuid bridge enforcing strict SO_PEERCRED verification.

IPC: Unix Domain Socket Zero Ambient Root
03 / FILESYSTEM INTEGRITY

Deterministic POSIX File I/O

Filesystem mutations utilize directory file descriptor relative operations (openat(O_NOFOLLOW)) to completely eliminate TOCTOU race conditions, symlink escapes, and directory traversal vulnerabilities.

Primitive: openat2 / Landlock Anti-TOCTOU
04 / KERNEL FIREWALL

In-Kernel Netlink Firewall & IPS

Interacts directly with libnftables via kernel Netlink FFI. Maintains dynamic, hardware-accelerated timed ban sets in-kernel with zero external iptables forks or fragile log-scraping daemons.

Engine: Netlink FFI Zero Process Forking
05 / ZERO-DEPENDENCY TLS

Pure-Rust ACME TLS Engine

Integrated automated certificate issuance and renewals powered by pure Rust instant-acme and rcgen. Supports HTTP-01 and multi-provider RFC 2136 / DNS-01 challenges without external certbot scripts.

Crypto: ring / rustls Automated HTTP/DNS-01
06 / BACKUP PIPELINE

Authenticated Streaming Backups

Constant-memory buffered backup streams encrypted on-the-fly using ChaCha20-Poly1305 with HKDF key derivation. Direct streaming to remote object storage with cryptographic integrity validation per chunk.

Cipher: ChaCha20-Poly1305 Streaming Chunked I/O
SUBSTRATE RUNTIME PRIVILEGE & IPC ARCHITECTURE SECURE BOUNDARY ENFORCED
+-----------------------------------------------------------------------------------+
|  CLIENT LAYER (CLI / UI / Unprivileged Worker: UID 1000)                          |
|  - Strictly unprivileged process space                                            |
|  - JSON Schema-typed message requests over Unix Domain Socket                     |
+------------------------------------------+----------------------------------------+
                                           |
                              SO_PEERCRED Handshake Check
                                           v
+-----------------------------------------------------------------------------------+
|  SUBSTRATE ISOLATION GATEWAY (musl static binary)                                 |
|  - Validates caller UID/GID via kernel socket credentials                         |
|  - Drops all ambient capabilities, limits syscall vector via Seccomp-BPF          |
+------------------------------------------+----------------------------------------+
                                           |
                           openat(O_NOFOLLOW) / Netlink FFI
                                           v
+------------------------------------------+----------------------------------------+
|  LINUX KERNEL TARGET SUBSYSTEMS                                                   |
|  [ Landlock VFS Sandboxing ]  [ Netlink nftables In-Kernel Sets ]  [ Epoll I/O ]  |
+-----------------------------------------------------------------------------------+
          

Comparative Architecture Matrix

Direct comparison between Substrate's memory-safe, kernel-conforming architecture and legacy server administration software suites.

Architectural Metric Root Access Substrate Legacy Panels (cPanel, Plesk, Hestia)
Implementation Language Memory safety guarantees Pure Rust (100%)
Compile-time memory safety, zero data races, no garbage collector pauses.
Perl / PHP / Bash
Interpreted scripts vulnerable to injection, untyped IPC, and unmanaged memory wrappers.
Execution Model Subprocess and syscall architecture Direct Kernel Syscalls
Direct FFI to Linux kernel subsystems (Netlink, epoll, Landlock). Zero subprocess forking for routine tasks.
Shell Fork / Exec Pipes
Shells out to system(), iptables, useradd, and temporary shell scripts.
IPC & Authentication Inter-process communication security SO_PEERCRED + Strict UDS
Direct Unix domain socket with kernel credential validation and strongly-typed JSON schema payloads.
HTTP Root Daemons / Open Ports
Web servers running directly as root or unauthenticated local TCP listening ports.
Filesystem Security Path traversal & symlink handling Descriptor-Relative I/O
Guaranteed anti-TOCTOU via openat(O_NOFOLLOW) and Landlock filesystem sandboxing.
Global Path Manipulation
Prone to symlink directory traversal attacks and race conditions on multi-user hosting nodes.
Firewall & IPS Engine Intrusion prevention mechanism Direct Netlink nftables
In-kernel timed IP set expiration. Nanosecond evaluation with zero CPU degradation during heavy attacks.
fail2ban / iptables rules
Linear rule tables evaluated sequentially in user space, leading to CPU spikes and lock contention.
Resource Footprint Resident set size & startup time < 8 MB RSS | < 5ms Cold Boot
Runs efficiently on low-spec edge nodes without memory swapping.
500 MB - 2 GB RSS
Requires dedicated background web servers, database servers, and runtime interpreters.

Core Technical Tenets

We build systems under the strict paradigm of absolute resource scarcity and architectural predictability.

01 / DISCIPLINE

No Uncontrolled Process Spawning

Systems software must interface with the operating system through direct kernel syscalls and memory-safe typed IPC. Shelling out to external command strings introduces shell injection vectors, unbounded subprocess latencies, and untracked execution state.

02 / CONTAINMENT

Deterministic Sandboxing by Default

Software must never run with ambient authority. We enforce explicit capability dropping, restrictive seccomp filter profiles, and granular Landlock filesystem policies so that every operation is strictly confined to its immediate operational scope.

03 / SOVEREIGNTY

Open, Auditable, Zero Telemetry

We reject phone-home tracking, telemetry beacons, and cloud dependencies in server infrastructure. Our architectures are open, deterministic, fully verifiable, and designed to run independently on dedicated hardware without vendor lock-in.

The Root Access Ecosystem

Root Access Software operates in tandem with its sister organization, Root Access Games. We share a unified engineering mindset: pushing modern hardware to its limits through low-overhead systems programming, custom data-oriented pipelines, and zero-compromise architectural discipline.

Whether engineering bare-metal server infrastructure or building high-performance interactive simulation engines, our code is crafted to be lightweight, auditable, and resilient.

ROOT ACCESS SOFTWARE SYSTEMS

Linux control plane software, server infrastructure tooling, memory-safe kernels, and deterministic daemon architecture.

ROOT ACCESS GAMES STUDIO

High-performance simulation engines, data-oriented gameplay systems, and real-time graphics pipelines.