For me the 'logical' thing to do to build a 'safety first' OS in the 21st century would be: use the seL4 microkernel and then Rust to build the full OS kernel.
Though I don't know if Spectre changed this.
For me the 'logical' thing to do to build a 'safety first' OS in the 21st century would be: use the seL4 microkernel and then Rust to build the full OS kernel.
Though I don't know if Spectre changed this.
Edit: It seems RedLeaf is immune to meltdown due to its design while seL4 has meltdown mitigations[2]. I would assume the same goes for spectre, but that would be an assumption on my part. (Note again, I've only skimmed [2] so I can easily be wrong here.)
[1]: https://www.ics.uci.edu/~aburtsev/doc/redleaf-hotos19.pdf
[2]: https://www.usenix.org/system/files/osdi20-narayanan_vikram....
[0]: https://arxiv.org/abs/1902.05178 [1]: https://security.googleblog.com/2021/03/a-spectre-proof-of-c...
That said I can imagine a two layer system: if you use 100% safe Rust you have a 'fast path' direct access, otherwise you fallback to slower hardware protection.