http://redox-os.org/
The system call interface has no capability operations.
https://docs.rs/redox_syscall/0.3.4/syscall/call/index.html
https://news.ycombinator.com/item?id=31200562
http://redox-os.org/