Load a sandboxed program, prove it safe, JIT it, and attach it to a kernel hook
Guided views
Explore this system
Step through curated paths without changing the source diagram.
Beat
Next
ReadyChapter 01 / 01
Guided chapter
Diagram guideExplore this system
Inspecting compiled semantics
E ExportT ThemeS Style0 Reset+ Zoom in- Zoom outEsc Close
Find a node
⌕/
No matching nodes
Semantic passport
Verified source
Authored reach
Route probeChoose a start node
Pick two semantic nodes on the diagram
Choose the source, then the destination. Direction matters.
Semantic lensCompare system roles
Choose up to two semantic kinds. One reveals its real traffic; two compare only direct authored relationships.
Choose a kind to inspect its nodes and touching relationships.
Semantic radar
Building overview
Click nodeDrag to pan
Programs, not modules
• You write a small program that runs in the kernel
• Loaded at runtime — no kernel rebuild or reboot
• The same model powers tracing, networking, and security
Safe by verification
• The verifier proves the program can't crash or loop forever
• Rejected programs never run — safety is checked before load
• This is why running kernel code is safe
Maps share state
• Maps are the channel between kernel program and user space
• The program writes results; the app reads them
• No copying the whole kernel's data out — just what you need
Architecture diagram • Built with Archify • Create yours ↗ • Hover to trace • R route • Click to focus • +/− zoom • M radar • [/] views • P play story • T theme • E export