• 2026.08.20 e0b9d6386e

    amnesia released this 2026-08-20 22:17:39 +02:00 | 0 commits to main since this release

    lainOS layer 02 ~ 2026.08.20 Changelog

    OpenRC Isolation/Containment Stack Debut

    • This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.

    OpenRC Isolation/Containment Architecture


    • Calamares rebuild ~ 2026.08.20
    • Fixed race condition preventing unbound DNS from shutting down during DNS mode transitions.

    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable.
    USB automount is enabled with usb-automount enable.

    Automate all of this with the following command on first boot:

    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
    

    DNS Mediation Architecture

    DNS Modes Quick Reference

    Note: if using a VPN, it must be turned on before activating encrypted mode.

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on         # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode)
    private-mode off        # Restore previous mode (plaintext or encrypted)
    

    New in 2026.08.20

    OpenRC Isolation Stack ~ Service Coverage

    Core OpenRC services are sandboxed by default with the following services currently verified:

    Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor
    dnsmasq ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    unbound ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dnscrypt-proxy ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    tor ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dhcpcd ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    chrony ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    sdwdate ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    syslog-ng ✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅
    acpid ✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅
    iwd ❌** ❌ ❌ ✅ ✅ ✅ ✅

    * Intentional ~ DHCP and NTP need host PID namespace visibility
    ** Intentional ~ rfkill device access requires mount namespace exception, documented


    Full Service List

    The isolation stack currently covers these OpenRC services:

    DNS & Networking:

    • dnsmasq ~ DNS forwarding (stateless, cache-zero)
    • unbound ~ DNSSEC-validating resolver
    • dnscrypt-proxy ~ Encrypted DNS with anonymized relay
    • tor ~ Tor daemon with DNSPort
    • dhcpcd ~ DHCP client
    • iwd ~ WiFi daemon (mount namespace exception)

    Time & System:

    • chrony ~ NTP client
    • sdwdate ~ Tor-based time sync (fingerprint-resistant)
    • syslog-ng ~ System logging (network-isolated)
    • acpid ~ ACPI event handler

    Protocol 7 Daemons (Protocol 7 has its own built in isolation):

    • lainos-dbus-bridge ~ D-Bus login1 facade
    • lainos-notifyd ~ sd_notify socket sink
    • lainos-init ~ Session initializer

    Verification

    openrc-security-status
    

    This will verify all containment layers are active and enforcing for every service listed above.


    • OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with openrc-security-status.

    • Security Verification Suite ~ Three tools now ship: lainos-security-status (read-only dashboard), openrc-security-status (isolation stack verification), and protocol7-core-security-status (36-test adversarial suite). Runtime verification, not config review.

    • AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd), media (pipewire, wireplumber), crypto (gpg, keepassxc), browsers (librewolf), and system utilities (chronyd, syslog-ng, acpid).

    • lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before pacman touches them. Safety net for kernel updates.

    • DNS Mediation Architecture (Improved) ~ dnsmasq as centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes: plaintext, encrypted, private. private-mode saves and restores your previous DNS mode.

    • ISO Size ~ 2.8GB


    Documentation


    Get connected

    LALL<3


    Downloads
  • 2026.08.19 a82b666c2d

    amnesia released this 2026-08-19 22:54:56 +02:00 | 5 commits to main since this release

    #this release is now having calamares rebuilt, wait for next release later today

    lainOS layer 02 ~ 2026.08.19 Changelog

    OpenRC Isolation/Containment Stack Debut

    • This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.

    OpenRC Isolation/Containment Architecture


    • Fixed race condition preventing unbound DNS from shutting down during DNS mode transitions.

    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable.
    USB automount is enabled with usb-automount enable.

    Automate all of this with the following command on first boot:

    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
    

    DNS Mediation Architecture

    DNS Modes Quick Reference

    Note: if using a VPN, it must be turned on before activating encrypted mode.

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on         # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode)
    private-mode off        # Restore previous mode (plaintext or encrypted)
    

    New in 2026.08.19

    OpenRC Isolation Stack ~ Service Coverage

    All OpenRC services are sandboxed by default with the following services currently verified:

    Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor
    dnsmasq ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    unbound ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dnscrypt-proxy ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    tor ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dhcpcd ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    chrony ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    sdwdate ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    syslog-ng ✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅
    acpid ✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅
    iwd ❌** ❌ ❌ ✅ ✅ ✅ ✅

    * Intentional ~ DHCP and NTP need host PID namespace visibility
    ** Intentional ~ rfkill device access requires mount namespace exception, documented


    Full Service List

    The isolation stack currently covers these OpenRC services:

    DNS & Networking:

    • dnsmasq ~ DNS forwarding (stateless, cache-zero)
    • unbound ~ DNSSEC-validating resolver
    • dnscrypt-proxy ~ Encrypted DNS with anonymized relay
    • tor ~ Tor daemon with DNSPort
    • dhcpcd ~ DHCP client
    • iwd ~ WiFi daemon (mount namespace exception)

    Time & System:

    • chrony ~ NTP client
    • sdwdate ~ Tor-based time sync (fingerprint-resistant)
    • syslog-ng ~ System logging (network-isolated)
    • acpid ~ ACPI event handler

    Protocol 7 Daemons (Protocol 7 has its own built in isolation):

    • lainos-dbus-bridge ~ D-Bus login1 facade
    • lainos-notifyd ~ sd_notify socket sink
    • lainos-init ~ Session initializer

    Verification

    openrc-security-status
    

    This will verify all containment layers are active and enforcing for every service listed above.


    • OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with openrc-security-status.

    • Security Verification Suite ~ Three tools now ship: lainos-security-status (read-only dashboard), openrc-security-status (isolation stack verification), and protocol7-core-security-status (36-test adversarial suite). Runtime verification, not config review.

    • AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd), media (pipewire, wireplumber), crypto (gpg, keepassxc), browsers (librewolf), and system utilities (chronyd, syslog-ng, acpid).

    • lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before pacman touches them. Safety net for kernel updates.

    • DNS Mediation Architecture (Improved) ~ dnsmasq as centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes: plaintext, encrypted, private. private-mode saves and restores your previous DNS mode.

    • ISO Size ~ 2.8GB


    Documentation


    Get connected

    LALL<3


  • 2026.08.15 8d74c854a0

    amnesia released this 2026-08-17 05:44:44 +02:00 | 11 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.08.15 Changelog

    • Routine build after two week hiatus due to broken computer charger.

    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable
    USB automount is enabled with usb-automount enable

    Automate all of this with the following command on first boot, and you will not have to set it up again on subsequent boots:

    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount-enable && wscan
    

    DNS Modes Quick Reference

    • Note: if using a vpn, it must be turned on before activating encrypted mode.
    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on        # Tor DNSPort (saves previous mode)
    private-mode off       # Restore previous mode (plaintext or encrypted)
    

    New in 2026.07.29

    • lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before pacman touches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility. See lainos-kernel-backup
    • lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd, stubby, snowflake-pt-client), media (pipewire, wireplumber, mpv, vlc), crypto/secrets (gpg, gpg-agent, keepassxc), browsers (librewolf, tor-browser standalone), and system utilities (chronyd, syslog-ng, nft, ssh, sshd, acpid).
    • DNS Mediation Architecture(Improved from rc7) ~ dnsmasq is now a centralized, stateless blind forwarding resolver. All applications resolve through 127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via unbound on :5053), and private (Tor DNSPort on :9059). Mode transitions are explicit and stateful; private-mode remembers and restores your previous mode on exit. lainOS DNS Mediation Architecture
    • lainos-dns utility ~ lainos-dns {plaintext|encrypted|status} toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respects private-mode state.
    • private-mode updated ~ Now tracks DNS mode state via /var/lib/lainos/dns-mode and /var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.
    • lainos-dns encrypted mode(improved from rc7) ~ dnsmasq now forwards to unbound on 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses to dnscrypt-proxy on 127.0.0.1:5300. dnscrypt-proxy encrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP.
    • DNS config templates ~dnsmasq.conf.plaintext, dnsmasq.conf.encrypted, dnsmasq.conf.private installed via airootfs overlay to avoid package conflicts.
    • ISO size ~ 2.8GB


    Documentation

    • User guide: Updated with lainos-dns and DNS architecture sections.
    • Privacy Guide: Updated private-mode description to reflect DNS mode restoration.
    • New document: lainOS DNS Mediation Architecture

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3


    Downloads
  • 2027.07.29 8d74c854a0

    amnesia released this 2026-07-30 19:10:21 +02:00 | 11 commits to main since this release

    Due to a broken developer machine, lainOS is on hiatus for a while. I'm unable to maintain realeases. Full disk encryption on this release might be broken(on Chromebooks) and I cannot fix it until I have a new machine.

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.29 Changelog


    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable

    Automate all of this with the following command on first boot, and you will not have to set it up again after the next boot:

    wifi on && wifi-autostart enable && wifi-autoconnect enable && wscan
    

    New in 2026.07.29

    • lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before pacman touches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility. See lainos-kernel-backup
    • lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd, stubby, snowflake-pt-client), media (pipewire, wireplumber, mpv, vlc), crypto/secrets (gpg, gpg-agent, keepassxc), browsers (librewolf, tor-browser standalone), and system utilities (chronyd, syslog-ng, nft, ssh, sshd, acpid).
    • DNS Mediation Architecture(Improved from rc7) ~ dnsmasq is now a centralized, stateless blind forwarding resolver. All applications resolve through 127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via unbound on :5053), and private (Tor DNSPort on :9059). Mode transitions are explicit and stateful; private-mode remembers and restores your previous mode on exit. lainOS DNS Mediation Architecture
    • lainos-dns utility ~ lainos-dns {plaintext|encrypted|status} toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respects private-mode state.
    • private-mode updated ~ Now tracks DNS mode state via /var/lib/lainos/dns-mode and /var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.
    • lainos-dns encrypted mode(improved from rc7) ~ dnsmasq now forwards to unbound on 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses to dnscrypt-proxy on 127.0.0.1:5300. dnscrypt-proxy encrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP.
    • DNS config templates ~dnsmasq.conf.plaintext, dnsmasq.conf.encrypted, dnsmasq.conf.private installed via airootfs overlay to avoid package conflicts.
    • ISO size ~ 2.8GB

    DNS Quick Reference

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on        # Tor DNSPort (saves previous mode)
    private-mode off       # Restore previous mode (plaintext or encrypted)
    

    Documentation

    • User guide: Updated with lainos-dns and DNS architecture sections.
    • Privacy Guide: Updated private-mode description to reflect DNS mode restoration.
    • New document: lainOS DNS Mediation Architecture

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3


    Downloads
  • 2026.07.28-rc8 80ea682249

    amnesia released this 2026-07-29 07:27:31 +02:00 | 12 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.28-rc8 Changelog

    Eighth release candidate. User-togglable encrypted DNS(unbound DoT or Tor DNSport) with stateful mode persistence, and a complete blind DNS mediation architecture that abstracts DNS resolver state away from the rest of the system.(this has been improved from the rc7 release for smoother mode transitions and private-mode operation.)

    RC phase almost completed. This release focuses on verifying that all loose ends have been tied up, and is undergoing bare metal testing to ensure complete functionality of all features and components. The next release will be the stable release if everything goes correctly. This testing will be completed by tomorrow(2026.07.29)


    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New in RC8

    • lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before pacman touches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility.
    • lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd, stubby, snowflake-pt-client), media (pipewire, wireplumber, mpv, vlc), crypto/secrets (gpg, gpg-agent, keepassxc), browsers (librewolf, tor-browser standalone), and system utilities (chronyd, syslog-ng, nft, ssh, sshd, acpid).
    • DNS Mediation Architecture(Improved from rc7) ~ dnsmasq is now a centralized, stateless blind forwarding resolver. All applications resolve through 127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via unbound on :5053), and private (Tor DNSPort on :9059). Mode transitions are explicit and stateful; private-mode remembers and restores your previous mode on exit. lainOS DNS Mediation Architecture
    • lainos-dns utility ~ lainos-dns {plaintext|encrypted|status} toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respects private-mode state.
    • private-mode updated ~ Now tracks DNS mode state via /var/lib/lainos/dns-mode and /var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.
    • lainos-dns encrypted mode(improved from rc7) ~ dnsmasq now forwards to unbound on 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses to dnscrypt-proxy on 127.0.0.1:5300. dnscrypt-proxy encrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP.
    • DNS config templates ~dnsmasq.conf.plaintext, dnsmasq.conf.encrypted, dnsmasq.conf.private installed via airootfs overlay to avoid package conflicts.
    • ISO size ~ 2.8GB

    DNS Quick Reference

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on        # Tor DNSPort (saves previous mode)
    private-mode off       # Restore previous mode (plaintext or encrypted)
    

    Documentation

    • User guide: Updated with lainos-dns and DNS architecture sections.
    • Privacy Guide: Updated private-mode description to reflect DNS mode restoration.
    • New document: lainOS DNS Mediation Architecture

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3


    Downloads
  • 2026.07.21-rc7 60cef3f22b

    amnesia released this 2026-07-22 02:46:23 +02:00 | 17 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.21-rc7 Changelog

    Seventh release candidate. User-togglable encrypted DNS(DoT or Tor DNSport) with stateful mode persistence, and a complete blind DNS mediation architecture that abstracts DNS resolver state away from the rest of the system.

    This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.


    First boot: getting online

    WiFi is off by default. To connect:

    wifi on
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New in RC7

    • DNS Mediation Architecture ~ dnsmasq is now a centralized, stateless blind forwarding resolver. All applications resolve through 127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via stubby on :5053), and private (Tor DNSPort on :9059). Mode transitions are explicit and stateful; private-mode remembers and restores your previous mode on exit. lainOS DNS Mediation Architecture
    • lainos-dns utility ~ lainos-dns {plaintext|encrypted|status} toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respects private-mode state.
    • private-mode updated ~ Now tracks DNS mode state via /var/lib/lainos/dns-mode and /var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private config until Tor DNSPort is ready.
    • Stubby DoT proxy ~stubby is the encrypted DNS proxy. Ships with OpenRC init script since Arch doesn't provide one. Auto-starts in default runlevel.
    • DNS config templates ~dnsmasq.conf.plaintext, dnsmasq.conf.encrypted, dnsmasq.conf.private installed via airootfs overlay to avoid package conflicts.
    • ISO size ~ 2.7GB

    DNS Quick Reference

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via stubby
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on        # Tor DNSPort (saves previous mode)
    private-mode off       # Restore previous mode (plaintext or encrypted)
    

    Documentation

    • User guide: Updated with lainos-dns and DNS architecture sections.
    • Privacy Guide: Updated private-mode description to reflect DNS mode restoration.
    • New document: lainOS DNS Mediation Architecture

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3


    Downloads
  • 2026.07.20 3bd8bf8681

    amnesia released this 2026-07-20 19:40:27 +02:00 | 28 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.20-rc6 Changelog

    Sixth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.

    This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.

    • Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.75GB down from 3.15GB(2026.07.16)
    • Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.
    • dnsmasq added as experimental privacy feature to hide dns state from the rest of the system. lainOS DNS Mediation Layer

    First boot: getting online

    WiFi is off by default. To connect:

    wifi on
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New Tool ~ tor1 / tor2 / tor3 / tor4 (Tor Stream Isolation)

    Four dedicated, isolated Tor circuits, matching the wg1-wg4 WireGuard tunnel model exactly. One command, works the same way for every application:

    tor1 profanity -a user@example.onion
    tor2 signal-desktop
    tor3 element-desktop
    tor4 gajim
    

    Whatever you run through tor1 never shares a circuit ~ or even a port ~ with anything run through tor2/tor3/tor4 or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly in torrc.

    Usage is seamless across every application type ~ tor1-tor4 auto-detect what they're launching and route it correctly without you needing to know or specify anything:

    • Plain CLI tools and GTK apps (curl, Gajim, Dino) route via torsocks, same as always.
    • Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own --proxy-server flag instead ~ torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional.
    • Detected Electron apps also get LD_PRELOAD stripped (alacritty's forced hardened_malloc wrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) and XDG_CURRENT_DESKTOP overridden to GNOME (Chromium's keyring backend detection doesn't recognize sway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).

    Privacy Guide

    lainos-privacy-help    # updated with a Tor Stream Isolation callout
    

    New Package ~ lainos-apparmor (AppArmor Mandatory Access Control)

    Per-daemon AppArmor profiles for all Protocol 7 components with external input surfaces (lainos-dbus-bridge, lainos-notifyd, lainos-init), loaded at boot by an OpenRC init script before the daemons start. The lainos-apparmor init script loads only Protocol 7 profiles, not all of /etc/apparmor.d/* indiscriminately.

    • Path-based MAC complements the existing seccomp filters and mount namespaces: if an attacker escapes the private mount namespace (e.g., via a kernel vulnerability), AppArmor still blocks access to real user data (/home/**, /root/**), sensitive kernel interfaces (/sys/kernel/security/**), and /etc/shadow.
    • Network denials are enforced independently of seccomp — inet, inet6, netlink, and packet are explicitly denied in the lainos-dbus-bridge and lainos-notifyd profiles.
    • Capability rules in the lainos-dbus-bridge and lainos-notifyd profiles grant only the seven capabilities required for pre-drop mount namespace setup (sys_admin, chown, fowner, setgid, setuid, setpcap, dac_override, mknod), then the daemons drop to nobody and clear their bounding set.
    • Verified via adversarial test suite: 26/26 tests passed, including nsenter-based namespace isolation effectiveness tests, path-blocking tests (/etc/shadow, /home, /root), capability-abuse tests, and AppArmor enforcement confirmation.

    This closes the largest remaining architectural gap in Protocol 7 Core's defensive stack.

    New Package ~ lainos-ram-wipe

    RAM-extraction attack defense, ported from Kicksecure/Whonix's ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongside init_on_alloc=1/init_on_free=1 kernel parameters that continuously poison memory pages on allocation and free.

    ram-wipe enable    # RAM wipe runs at shutdown/reboot (default)
    ram-wipe disable   # skip the wipe pass, faster shutdown
    ram-wipe status    # show current GRUB config and running kernel's cmdline
    

    Continuous protection (init_on_alloc/init_on_free) is always on and isn't affected by this toggle.

    ⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.


    New Section ~ Sandboxed Build Requirements

    Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (kernel.unprivileged_userns_clone = 0, set via /etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:

    doas sysctl -w kernel.unprivileged_userns_clone=1
    # build your software
    doas sysctl -w kernel.unprivileged_userns_clone=0    # restore afterward
    

    Resets to the hardened default automatically on reboot either way.


    Known Issues

    • Some Nvidia cards have trouble with Sway.

    Documentation

    • User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to tor1; Tor section cross-references stream isolation.
    • Privacy Guide: "During your session" (step 6) updated with tor1-tor4 guidance, the single-instance-app caveat, and the LibreWolf exception.

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.17 d60326084c

    amnesia released this 2026-07-18 02:59:07 +02:00 | 30 commits to main since this release

    this iso accidentally had linux firmware removed when i cut the package list down. building a new one now.

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.16-rc5 Changelog

    Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.

    This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.

    • Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.46GB down from 3.15GB(2026.07.16)
    • Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.

    First boot: getting online

    WiFi is off by default. To connect:

    wifi on
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New Tool ~ tor1 / tor2 / tor3 / tor4 (Tor Stream Isolation)

    Four dedicated, isolated Tor circuits, matching the wg1-wg4 WireGuard tunnel model exactly. One command, works the same way for every application:

    tor1 profanity -a user@example.onion
    tor2 signal-desktop
    tor3 element-desktop
    tor4 gajim
    

    Whatever you run through tor1 never shares a circuit ~ or even a port ~ with anything run through tor2/tor3/tor4 or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly in torrc.

    Usage is seamless across every application type ~ tor1-tor4 auto-detect what they're launching and route it correctly without you needing to know or specify anything:

    • Plain CLI tools and GTK apps (curl, Gajim, Dino) route via torsocks, same as always.
    • Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own --proxy-server flag instead ~ torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional.
    • Detected Electron apps also get LD_PRELOAD stripped (alacritty's forced hardened_malloc wrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) and XDG_CURRENT_DESKTOP overridden to GNOME (Chromium's keyring backend detection doesn't recognize sway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).

    Privacy Guide

    lainos-privacy-help    # updated with a Tor Stream Isolation callout
    

    New Package ~ lainos-apparmor (AppArmor Mandatory Access Control)

    Per-daemon AppArmor profiles for all Protocol 7 components with external input surfaces (lainos-dbus-bridge, lainos-notifyd, lainos-init), loaded at boot by an OpenRC init script before the daemons start. The lainos-apparmor init script loads only Protocol 7 profiles, not all of /etc/apparmor.d/* indiscriminately.

    • Path-based MAC complements the existing seccomp filters and mount namespaces: if an attacker escapes the private mount namespace (e.g., via a kernel vulnerability), AppArmor still blocks access to real user data (/home/**, /root/**), sensitive kernel interfaces (/sys/kernel/security/**), and /etc/shadow.
    • Network denials are enforced independently of seccomp — inet, inet6, netlink, and packet are explicitly denied in the lainos-dbus-bridge and lainos-notifyd profiles.
    • Capability rules in the lainos-dbus-bridge and lainos-notifyd profiles grant only the seven capabilities required for pre-drop mount namespace setup (sys_admin, chown, fowner, setgid, setuid, setpcap, dac_override, mknod), then the daemons drop to nobody and clear their bounding set.
    • Verified via adversarial test suite: 26/26 tests passed, including nsenter-based namespace isolation effectiveness tests, path-blocking tests (/etc/shadow, /home, /root), capability-abuse tests, and AppArmor enforcement confirmation.

    This closes the largest remaining architectural gap in Protocol 7 Core's defensive stack.

    New Package ~ lainos-ram-wipe

    RAM-extraction attack defense, ported from Kicksecure/Whonix's ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongside init_on_alloc=1/init_on_free=1 kernel parameters that continuously poison memory pages on allocation and free.

    ram-wipe enable    # RAM wipe runs at shutdown/reboot (default)
    ram-wipe disable   # skip the wipe pass, faster shutdown
    ram-wipe status    # show current GRUB config and running kernel's cmdline
    

    Continuous protection (init_on_alloc/init_on_free) is always on and isn't affected by this toggle.

    ⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.


    New Section ~ Sandboxed Build Requirements

    Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (kernel.unprivileged_userns_clone = 0, set via /etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:

    doas sysctl -w kernel.unprivileged_userns_clone=1
    # build your software
    doas sysctl -w kernel.unprivileged_userns_clone=0    # restore afterward
    

    Resets to the hardened default automatically on reboot either way.


    Known Issues

    • Some Nvidia cards have trouble with Sway.

    Documentation

    • User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to tor1; Tor section cross-references stream isolation.
    • Privacy Guide: "During your session" (step 6) updated with tor1-tor4 guidance, the single-instance-app caveat, and the LibreWolf exception.

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3

  • 2026.07.16-rc5 deb3df495b

    amnesia released this 2026-07-16 22:05:57 +02:00 | 42 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    protocol7-core-Security Analysis(new valgrind and static analysis sections~zero mem leaks detected)

    lainOS layer 02 ~ 2026.07.16-rc5 Changelog

    Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.

    This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.

    • Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.46GB down from 3.15GB(2026.07.16)
    • Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.

    First boot: getting online

    WiFi is off by default. To connect:

    wifi on
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New Tool ~ tor1 / tor2 / tor3 / tor4 (Tor Stream Isolation)

    Four dedicated, isolated Tor circuits, matching the wg1-wg4 WireGuard tunnel model exactly. One command, works the same way for every application:

    tor1 profanity -a user@example.onion
    tor2 signal-desktop
    tor3 element-desktop
    tor4 gajim
    

    Whatever you run through tor1 never shares a circuit ~ or even a port ~ with anything run through tor2/tor3/tor4 or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly in torrc.

    Usage is seamless across every application type ~ tor1-tor4 auto-detect what they're launching and route it correctly without you needing to know or specify anything:

    • Plain CLI tools and GTK apps (curl, Gajim, Dino) route via torsocks, same as always.
    • Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own --proxy-server flag instead ~ torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional.
    • Detected Electron apps also get LD_PRELOAD stripped (alacritty's forced hardened_malloc wrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) and XDG_CURRENT_DESKTOP overridden to GNOME (Chromium's keyring backend detection doesn't recognize sway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).

    Known exception: Firefox-based browsers (LibreWolf) don't work reliably through torsocks at all ~ this is a known, documented limitation of torsocks itself for Firefox's multi-process architecture, not something specific to tor1-tor4. Configure LibreWolf's SOCKS5 proxy natively instead (about:preferences -> Network Settings). See the user guide for exact settings.

    lainos-privacy-help    # updated with a Tor Stream Isolation callout
    

    New Package ~ lainos-ram-wipe

    RAM-extraction attack defense, ported from Kicksecure/Whonix's ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongside init_on_alloc=1/init_on_free=1 kernel parameters that continuously poison memory pages on allocation and free.

    ram-wipe enable    # RAM wipe runs at shutdown/reboot (default)
    ram-wipe disable   # skip the wipe pass, faster shutdown
    ram-wipe status    # show current GRUB config and running kernel's cmdline
    

    Continuous protection (init_on_alloc/init_on_free) is always on and isn't affected by this toggle.

    ⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.


    New Section ~ Sandboxed Build Requirements

    Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (kernel.unprivileged_userns_clone = 0, set via /etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:

    doas sysctl -w kernel.unprivileged_userns_clone=1
    # build your software
    doas sysctl -w kernel.unprivileged_userns_clone=0    # restore afterward
    

    Resets to the hardened default automatically on reboot either way.


    Known Issues

    • Some Nvidia cards have trouble with Sway.

    Documentation

    • User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to tor1; Tor section cross-references stream isolation.
    • Privacy Guide: "During your session" (step 6) updated with tor1-tor4 guidance, the single-instance-app caveat, and the LibreWolf exception.

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.15-rc5 deb3df495b

    amnesia released this 2026-07-16 01:30:36 +02:00 | 42 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    protocol7-core-Security Analysis(new valgrind and static analysis sections~zero mem leaks detected)

    lainOS layer 02 ~ 2026.07.15-rc5 Changelog

    Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.

    This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.


    First boot: getting online

    WiFi is off by default. To connect:

    wifi on
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New Tool ~ tor1 / tor2 / tor3 / tor4 (Tor Stream Isolation)

    Four dedicated, isolated Tor circuits, matching the wg1-wg4 WireGuard tunnel model exactly. One command, works the same way for every application:

    tor1 profanity -a user@example.onion
    tor2 signal-desktop
    tor3 element-desktop
    tor4 gajim
    

    Whatever you run through tor1 never shares a circuit ~ or even a port ~ with anything run through tor2/tor3/tor4 or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly in torrc.

    Usage is seamless across every application type ~ tor1-tor4 auto-detect what they're launching and route it correctly without you needing to know or specify anything:

    • Plain CLI tools and GTK apps (curl, Gajim, Dino) route via torsocks, same as always.
    • Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own --proxy-server flag instead ~ torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional.
    • Detected Electron apps also get LD_PRELOAD stripped (alacritty's forced hardened_malloc wrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) and XDG_CURRENT_DESKTOP overridden to GNOME (Chromium's keyring backend detection doesn't recognize sway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).

    Known exception: Firefox-based browsers (LibreWolf) don't work reliably through torsocks at all ~ this is a known, documented limitation of torsocks itself for Firefox's multi-process architecture, not something specific to tor1-tor4. Configure LibreWolf's SOCKS5 proxy natively instead (about:preferences -> Network Settings). See the user guide for exact settings.

    lainos-privacy-help    # updated with a Tor Stream Isolation callout
    

    New Package ~ lainos-ram-wipe

    RAM-extraction attack defense, ported from Kicksecure/Whonix's ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongside init_on_alloc=1/init_on_free=1 kernel parameters that continuously poison memory pages on allocation and free.

    ram-wipe enable    # RAM wipe runs at shutdown/reboot (default)
    ram-wipe disable   # skip the wipe pass, faster shutdown
    ram-wipe status    # show current GRUB config and running kernel's cmdline
    

    Continuous protection (init_on_alloc/init_on_free) is always on and isn't affected by this toggle.

    ⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.


    New Section ~ Sandboxed Build Requirements

    Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (kernel.unprivileged_userns_clone = 0, set via /etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:

    doas sysctl -w kernel.unprivileged_userns_clone=1
    # build your software
    doas sysctl -w kernel.unprivileged_userns_clone=0    # restore afterward
    

    Resets to the hardened default automatically on reboot either way.


    Known Issues

    • Some Nvidia cards have trouble with Sway.

    Documentation

    • User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to tor1; Tor section cross-references stream isolation.
    • Privacy Guide: "During your session" (step 6) updated with tor1-tor4 guidance, the single-instance-app caveat, and the LibreWolf exception.

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    • irc.libera.chat ~ #LainOS

    LALL<3

    Downloads