An open-source RISC-V firmware platform for ESP32-C6(8MB Flash). Implements a BIOS/Payload architecture with a custom system call interface (ABI), independent LP-Core coprocessor management, and an anti-brick A/B OTA system. Tested on ESP32-C6-Zero.
C
297
18 commits
updated Oct 1, 2026
OpenC6 is an open-source, high-performance BIOS and microkernel architecture designed for the ESP32-C6 (RV32IMAC). It decouples platform-level hardware initialization from user-space execution, bringing PC/Workstation architecture paradigms to microcontrollers.
Instead of deploying monolithic firmwares, OpenC6 acts as an operating host. It manages bare-metal silicon resources, runs an autonomous out-of-band supervisor on the LP-Core coprocessor, enforces hardware memory protection via Physical Memory Protection (PMP), and exposes a standardized System Call ABI. This allows dynamic loading, multitasking execution, and network deployment of unprivileged User-Mode (U-Mode) payloads without recompiling the host operating system.
Classic 5:4 blue-screen configuration utility hosted directly on ESP32-C6 via standalone AP mode (192.168.4.1).

Local Micro UNIX Shell monitoring active process states, dynamic 4 KB page allocation, CPU load, and governor state.

Lightweight streaming terminal interface running on port 80 over local Wi-Fi.

Real-time register dump and fault diagnosis when an untrusted U-Mode binary attempts illegal memory access.

Safe host firmware flashing over Wi-Fi backed by hardware A/B partition rollback logic.

Single-cycle atomic WS2812 driver scaling pulse timings to match active CPU frequency (80/120/160 MHz).

User applications execute strictly in unprivileged RISC-V User Mode (U-Mode). Top-of-Range (TOR) Physical Memory Protection registers isolate the execution arena from the host:
0x60000000+) is hardware-blocked (Default Deny).ecall with atomic stack switching via mscratch.sandbox_intr_trampoline) resolves FreeRTOS context-switch privilege leakage bugs on RISC-V.libnet80211). OpenC6 bypasses FreeRTOS primitives for process isolation, memory allocation, virtual filesystems, and trap handling, operating as a true microkernel supervisor over bare-metal RISC-V hardware.An out-of-band supervisor running independently on the Low-Power (ULP) RISC-V coprocessor:
LP_WDT) at 75 deg C.Autonomous CPU frequency scaling running on the LP-Core:
0x60096118).Preemptive job control supporting up to 8 concurrent processes:
boot <path> bg), foreground management (fg, bg), process suspension, and termination (kill).Ctrl+X) have their memory pages compressed into RAM via the custom ZC6 algorithm (~1.2 KB match-finder footprint), releasing physical 4 KB pages back to the arena..zc6 archives on flash are decompressed into RAM on the fly prior to launch.High-performance circular filesystem residing in a dedicated SPI Flash partition:
RamNode) with dynamic chunk-based caching.gc_step) with sector-erase watchdog yielding.ls, cd, mkdir, cat, write, cp, mv, rm).c6wsh): Non-blocking HTTP console on port 80 with chunked output streaming and input queue multiplexing.| Pin | Identifier | Hardware Function | Description |
|---|---|---|---|
| GPIO 3 | PIN_BTN_GND | Output (0V) | Virtual ground latch for power button |
| GPIO 4 | PIN_BTN_SENSE | Input (Pull-Up) | Power sense line (Wakeup / 3s Reset / Setup trigger) |
| GPIO 8 | WS2812_GPIO | Output | Addressable RGB POST diagnostics & Aura Sync LED |
| GPIO 9 | PIN_BTN_BOOT | Input (Pull-Up) | Physical BOOT button; hold during power-on for Boot Menu |
| GPIO 1, 2 | CLEAR_NVRAM | Input / Ground | Hardware Clear CMOS jumper (Short during boot to reset) |
| Type-C | Native USB | D- / D+ PHY | Direct USB CDC console, binary loader, and JTAG |
Connect to the USB Type-C interface using any serial monitor (115200 baud, 8N1):
help - Display available shell commands.info - View hardware CPU frequency, governor load, tick counts, temperature, and ME state.mem - Display dynamic arena capacity and internal DRAM allocation.top - Display process table, CPU governor metrics, and page pool status.reboot - Warm restart of the processor.poweroff / exit - Terminate running processes and enter S5 Soft-Off state.boot <path> [bg] - Execute binary in foreground or background (bg or &).fg <pid> - Bring background or suspended process to foreground.bg <pid> - Resume suspended process in background.suspend [pid] - Suspend running process and compress memory via ZSWAP (Ctrl+X in console).kill <pid> - Terminate process and cleanly release socket descriptors.serial [path] - Receive binary over USB CDC via openc6_loader (Default: /downloaded/payload.bin).pxe <url> - Download payload over Wi-Fi directly into Flash storage.wifi scan - Scan 2.4 GHz spectrum (Channels 1-13) and print RSSI table.wifi connect <ssid> [pass] - Associate with AP and commit credentials to NVRAM.wifi status - Print MAC address, L3 IPv4 address, and link parameters.wifi disconnect - Disconnect station interface.ls [path] - List directory contents.cd <path> - Change active directory.mkdir <path> - Create directory node.cat <path> - Print file contents.write <path> <text> - Write text stream to file.cp <src> <dst> - Duplicate file.mv <src> <dst> - Move or rename file.rm <path> - Delete file or empty directory node.format - Erase filesystem partition and initialize blank ring structure.OpenC6 features a standalone C99 TUI deployment wizard that automatically configures host prerequisites, installs the ESP-IDF v6.1 RISC-V toolchain, compiles the BIOS, wipes stale flash partitions, and programs the target hardware.
Ensure make is installed on your host system:
# Arch Linux / Manjaro
sudo pacman -S make
# Ubuntu / Debian
sudo apt update && sudo apt install -y make
Clone the repository and launch the automated setup wizard:
git clone https://github.com/Rompass/openc6-bios.git
cd openc6-bios
make setup
If you already have ESP-IDF v6.1+ configured and sourced in your active shell:
. $IDF_PATH/export.sh
idf.py build erase-flash flash monitor -p /dev/ttyACM0
The tools/ directory includes an automated build system that compiles host utilities (openc6_loader, zc6_pack) alongside bare-metal RISC-V payloads in tools/example/*.c:
cd tools
# Builds host tools and cross-compiles all example/*.c payloads
make
Build outputs are placed in tools/build/bin/:
tools/build/bin/openc6_loader — Host deployment utility.tools/build/bin/zc6_pack — ZC6 payload compression tool.tools/build/bin/payloads/*.bin — Compiled flat RISC-V binary payloads.To stream and execute a compiled payload over the native USB CDC interface:
# 1. In the OpenC6 interactive shell, arm the receiver:
openc6_fs [Dir: 0] /> serial
# 2. On your host machine, stream the generated binary:
./tools/build/bin/openc6_loader /dev/ttyACM0 tools/build/bin/payloads/payload.bin
# 3. Launch the deployed binary in the U-Mode Sandbox:
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin
To run the payload as a preemptive background job:
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin bg
OpenC6 supports network payload loading and full host updates over Wi-Fi:
python3 -m http.server 8080
openc6_fs [Dir: 0] /> pxe http://<HOST_IP>:8080/payload.bin
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin
idf.py build) and serve openc6_bios.bin over HTTP.BIOS_SETUP_C6, open http://192.168.4.1).For complete architectural specifications, memory maps, system call tables, C runtime examples, and compiler flags:
Refer to Payload Development & ABI Reference.
This project is licensed under the MIT License. See LICENSE for details.
This project was developed in Ukraine. Consider supporting verified charities such as Come Back Alive to aid the defense against Russian aggression.
23 followers · starred Jun 2026
946 followers · starred Jun 2026
35 followers · starred Jun 2026
165 followers · starred Jun 2026
C
91.4%
HTML
3.3%
Assembly
2.3%
C++
1.4%
CMake
1.3%
An open-source RISC-V firmware platform for ESP32-C6(8MB Flash). Implements a BIOS/Payload architecture with a custom system call interface (ABI), independent LP-Core coprocessor management, and an anti-brick A/B OTA system. Tested on ESP32-C6-Zero.
C
297
18 commits
updated Oct 1, 2026
OpenC6 is an open-source, high-performance BIOS and microkernel architecture designed for the ESP32-C6 (RV32IMAC). It decouples platform-level hardware initialization from user-space execution, bringing PC/Workstation architecture paradigms to microcontrollers.
Instead of deploying monolithic firmwares, OpenC6 acts as an operating host. It manages bare-metal silicon resources, runs an autonomous out-of-band supervisor on the LP-Core coprocessor, enforces hardware memory protection via Physical Memory Protection (PMP), and exposes a standardized System Call ABI. This allows dynamic loading, multitasking execution, and network deployment of unprivileged User-Mode (U-Mode) payloads without recompiling the host operating system.
Classic 5:4 blue-screen configuration utility hosted directly on ESP32-C6 via standalone AP mode (192.168.4.1).

Local Micro UNIX Shell monitoring active process states, dynamic 4 KB page allocation, CPU load, and governor state.

Lightweight streaming terminal interface running on port 80 over local Wi-Fi.

Real-time register dump and fault diagnosis when an untrusted U-Mode binary attempts illegal memory access.

Safe host firmware flashing over Wi-Fi backed by hardware A/B partition rollback logic.

Single-cycle atomic WS2812 driver scaling pulse timings to match active CPU frequency (80/120/160 MHz).

User applications execute strictly in unprivileged RISC-V User Mode (U-Mode). Top-of-Range (TOR) Physical Memory Protection registers isolate the execution arena from the host:
0x60000000+) is hardware-blocked (Default Deny).ecall with atomic stack switching via mscratch.sandbox_intr_trampoline) resolves FreeRTOS context-switch privilege leakage bugs on RISC-V.libnet80211). OpenC6 bypasses FreeRTOS primitives for process isolation, memory allocation, virtual filesystems, and trap handling, operating as a true microkernel supervisor over bare-metal RISC-V hardware.An out-of-band supervisor running independently on the Low-Power (ULP) RISC-V coprocessor:
LP_WDT) at 75 deg C.Autonomous CPU frequency scaling running on the LP-Core:
0x60096118).Preemptive job control supporting up to 8 concurrent processes:
boot <path> bg), foreground management (fg, bg), process suspension, and termination (kill).Ctrl+X) have their memory pages compressed into RAM via the custom ZC6 algorithm (~1.2 KB match-finder footprint), releasing physical 4 KB pages back to the arena..zc6 archives on flash are decompressed into RAM on the fly prior to launch.High-performance circular filesystem residing in a dedicated SPI Flash partition:
RamNode) with dynamic chunk-based caching.gc_step) with sector-erase watchdog yielding.ls, cd, mkdir, cat, write, cp, mv, rm).c6wsh): Non-blocking HTTP console on port 80 with chunked output streaming and input queue multiplexing.| Pin | Identifier | Hardware Function | Description |
|---|---|---|---|
| GPIO 3 | PIN_BTN_GND | Output (0V) | Virtual ground latch for power button |
| GPIO 4 | PIN_BTN_SENSE | Input (Pull-Up) | Power sense line (Wakeup / 3s Reset / Setup trigger) |
| GPIO 8 | WS2812_GPIO | Output | Addressable RGB POST diagnostics & Aura Sync LED |
| GPIO 9 | PIN_BTN_BOOT | Input (Pull-Up) | Physical BOOT button; hold during power-on for Boot Menu |
| GPIO 1, 2 | CLEAR_NVRAM | Input / Ground | Hardware Clear CMOS jumper (Short during boot to reset) |
| Type-C | Native USB | D- / D+ PHY | Direct USB CDC console, binary loader, and JTAG |
Connect to the USB Type-C interface using any serial monitor (115200 baud, 8N1):
help - Display available shell commands.info - View hardware CPU frequency, governor load, tick counts, temperature, and ME state.mem - Display dynamic arena capacity and internal DRAM allocation.top - Display process table, CPU governor metrics, and page pool status.reboot - Warm restart of the processor.poweroff / exit - Terminate running processes and enter S5 Soft-Off state.boot <path> [bg] - Execute binary in foreground or background (bg or &).fg <pid> - Bring background or suspended process to foreground.bg <pid> - Resume suspended process in background.suspend [pid] - Suspend running process and compress memory via ZSWAP (Ctrl+X in console).kill <pid> - Terminate process and cleanly release socket descriptors.serial [path] - Receive binary over USB CDC via openc6_loader (Default: /downloaded/payload.bin).pxe <url> - Download payload over Wi-Fi directly into Flash storage.wifi scan - Scan 2.4 GHz spectrum (Channels 1-13) and print RSSI table.wifi connect <ssid> [pass] - Associate with AP and commit credentials to NVRAM.wifi status - Print MAC address, L3 IPv4 address, and link parameters.wifi disconnect - Disconnect station interface.ls [path] - List directory contents.cd <path> - Change active directory.mkdir <path> - Create directory node.cat <path> - Print file contents.write <path> <text> - Write text stream to file.cp <src> <dst> - Duplicate file.mv <src> <dst> - Move or rename file.rm <path> - Delete file or empty directory node.format - Erase filesystem partition and initialize blank ring structure.OpenC6 features a standalone C99 TUI deployment wizard that automatically configures host prerequisites, installs the ESP-IDF v6.1 RISC-V toolchain, compiles the BIOS, wipes stale flash partitions, and programs the target hardware.
Ensure make is installed on your host system:
# Arch Linux / Manjaro
sudo pacman -S make
# Ubuntu / Debian
sudo apt update && sudo apt install -y make
Clone the repository and launch the automated setup wizard:
git clone https://github.com/Rompass/openc6-bios.git
cd openc6-bios
make setup
If you already have ESP-IDF v6.1+ configured and sourced in your active shell:
. $IDF_PATH/export.sh
idf.py build erase-flash flash monitor -p /dev/ttyACM0
The tools/ directory includes an automated build system that compiles host utilities (openc6_loader, zc6_pack) alongside bare-metal RISC-V payloads in tools/example/*.c:
cd tools
# Builds host tools and cross-compiles all example/*.c payloads
make
Build outputs are placed in tools/build/bin/:
tools/build/bin/openc6_loader — Host deployment utility.tools/build/bin/zc6_pack — ZC6 payload compression tool.tools/build/bin/payloads/*.bin — Compiled flat RISC-V binary payloads.To stream and execute a compiled payload over the native USB CDC interface:
# 1. In the OpenC6 interactive shell, arm the receiver:
openc6_fs [Dir: 0] /> serial
# 2. On your host machine, stream the generated binary:
./tools/build/bin/openc6_loader /dev/ttyACM0 tools/build/bin/payloads/payload.bin
# 3. Launch the deployed binary in the U-Mode Sandbox:
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin
To run the payload as a preemptive background job:
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin bg
OpenC6 supports network payload loading and full host updates over Wi-Fi:
python3 -m http.server 8080
openc6_fs [Dir: 0] /> pxe http://<HOST_IP>:8080/payload.bin
openc6_fs [Dir: 0] /> boot /downloaded/payload.bin
idf.py build) and serve openc6_bios.bin over HTTP.BIOS_SETUP_C6, open http://192.168.4.1).For complete architectural specifications, memory maps, system call tables, C runtime examples, and compiler flags:
Refer to Payload Development & ABI Reference.
This project is licensed under the MIT License. See LICENSE for details.
This project was developed in Ukraine. Consider supporting verified charities such as Come Back Alive to aid the defense against Russian aggression.
23 followers · starred Jun 2026
946 followers · starred Jun 2026
35 followers · starred Jun 2026
165 followers · starred Jun 2026
C
91.4%
HTML
3.3%
Assembly
2.3%
C++
1.4%
CMake
1.3%