This is the fifth in a series of blog posts about my experimental operating system, Eunomia.
This concludes the historical perspective. The project took around a month, a lot of which was prodding Claude to read this, write that, implement phase such and such.
The general workflow I eventually settled on was:
- (optional) Brainstorming with Claude
- Plan
- For each phase of the plan, split it into a detailed task-by-task plan
- Implement each of these tasks
- Review
Planning and reviewing went better using Claude Code's workflow ("ultracode") feature.
The project used one month of a Max plan, some usage credits, I also did some work with (unmetered) chatgpt.
Since the token counts are retained in Claude Code sessions, out of pure curiosity I computed how much would it all cost me at API prices.
Token counts per model:
| Model | Attempts | Uncached input | 5-minute cache writes | 1-hour cache writes | Cache reads | Output | All tokens |
|---|---|---|---|---|---|---|---|
| claude-fable-5 | 1,759 | 520,297 | 2,723,283 | 11,657,979 | 261,478,323 | 3,464,598 | 279,844,480 |
| claude-opus-4-8 | 38,565 | 8,444,816 | 70,484,137 | 109,802,427 | 6,111,138,334 | 46,457,407 | 6,346,327,121 |
| claude-sonnet-5 | 2,939 | 553,002 | 9,613,703 | 3,170,297 | 232,698,204 | 2,569,919 | 248,605,125 |
| claude-sonnet-4-6 | 412 | 526 | 34,089 | 1,012,822 | 28,908,373 | 199,557 | 30,155,367 |
| claude-haiku-4-5-20251001 | 7,372 | 203,036 | 19,415,583 | 0 | 230,492,946 | 2,463,355 | 252,574,920 |
| Total | 51,047 | 9,721,677 | 102,270,795 | 125,643,525 | 6,864,716,180 | 55,154,836 | 7,157,507,013 |
Assuming these prices:
| Model | Price model | Uncached input / MTok | 5-minute cache writes / MTok | 1-hour cache writes / MTok | Cache reads / MTok | Output / MTok |
|---|---|---|---|---|---|---|
| claude-fable-5 | Fable 5 | $10 | $12.50 | $20 | $1 | $50 |
| claude-opus-4-8 | Opus 4.8 | $5 | $6.25 | $10 | $0.50 | $25 |
| claude-sonnet-5 | Sonnet 5 | $2 | $2.50 | $4 | $0.20 | $10 |
| claude-sonnet-4-6 | Sonnet 4.6 | $3 | $3.75 | $6 | $0.30 | $15 |
| claude-haiku-4-5-20251001 | Haiku 4.5 | $1 | $1.25 | $2 | $0.10 | $5 |
It would add up to:
| Model | Uncached input | 5-minute cache writes | 1-hour cache writes | Cache reads | Output | Subtotal |
|---|---|---|---|---|---|---|
| claude-fable-5 | $5.202970 | $34.041038 | $233.159580 | $261.478323 | $173.229900 | $707.111811 |
| claude-opus-4-8 | $42.224080 | $440.525856 | $1,098.024270 | $3,055.569167 | $1,161.435175 | $5,797.778548 |
| claude-sonnet-5 | $1.106004 | $24.034258 | $12.681188 | $46.539641 | $25.699190 | $110.060280 |
| claude-sonnet-4-6 | $0.001578 | $0.127834 | $6.076932 | $8.672512 | $2.993355 | $17.872211 |
| claude-haiku-4-5-20251001 | $0.203036 | $24.269479 | $0.000000 | $23.049295 | $12.316775 | $59.838584 |
| Total | $48.737668 | $522.998464 | $1,349.941970 | $3,395.308937 | $1,375.674395 | $6,692.661434 |
Breaking it down by project phase:
| Dates | Major subdivisions | Commits | Active dates | Retained code-session tokens | API-equivalent price |
|---|---|---:|---:|---:|---:|
| 10–11 Jun | design/spec; M0–M5; fuzzing, time, and first hardening | 32 | 2 | 185,078,541 | $278.24 |
| 12–13 Jun | PR workflow; process closeout; Kani/kcore rewrite and audit | 66 | 2 | 588,875,995 | $467.60 |
| 14 Jun | Loom/Shuttle; IPC rewrite; Verus pilot and Kani-tier retirement | 59 | 1 | 501,731,982 | $369.35 |
| 15–19 Jun | full Verus rewrite; proof audit; documentation distillation; rev0 | 154 | 5 | 1,570,598,353 | $1,296.95 |
| 20–23 Jun | rev1 B/C implementation phases; ready queues; IRQ; storage/filesystem; rev2 audit | 197 | 4 | 1,392,263,236 | $1,257.47 |
| 24–26 Jun | Verus profiling; TLA optimization; concurrency onboarding; proof hygiene | 212 | 3 | 956,485,215 | $979.14 |
| 27 Jun–2 Jul | custom Rust target and std port; revised plan; independent correction | 83 | 4 of 6 | 1,039,071,741 | $964.96 |
| 3–5 Jul | rev3; policy/data-path completion; independent review; fix campaign; sweep | 88 | 3 | 644,164,169 | $590.99 |
| Shipped implementation | | 891 | 24 of 26 | 6,878,269,232 | $6,204.70 |
Some insights:
- Fable's initial estimates of how long would it take were wildly off base.
- It really wasn't a big deal that Verus was initially skipped. The initial MVP was dwarfed both in time and in token count by the Verus rewrite, and it's nice to have something working from the start.
- A lot of pointless cache read were caused by the Claude phone app being hot garbage (it wouldn't recognize
/clearwhile still pretending the context was cleared). - Even at API prices, the whole 61k lines of kernel and userspace would cost around 15 lines of seL4. Of course, that's not a fair comparison, as slapping some formal verification on top of Rust is not the same as writing a kernel verified end-to-end. Still, pretty nice.