-
2026.07.02-beta layer 02: Protocol 7 Pre-release
released this
2026-07-02 22:54:08 +02:00 | 5 commits to main since this release####INSTALLATION####
####layer 01/layer 02 migration and user guide ####
Please read the lainOS layer 02 wiki links above before installing. INSTALLATION INSTRUCTIONS ARE IN THE WIKI. DO NOT USE BTRFS(it will likely be integrated within the month)
Changelog
2026-07-02
Calamares
- Added Calamares autolaunch on liveuser login via sway config exec
- Only triggers when session user is
liveuser~ does not affect installed systems
protocol7-core
providesupdated tosystemd=1:999~ epoch 1 satisfies any futuresystemd>=Xdependency permanently, no future PKGBUILD changes required
lainos-utils 2.0-3
- Added wg-vpn WireGuard tunnel manager
- Supports tunnels wg1 - wg4 (up) and wg1d - wg4d (down)
- Requires WireGuard configs at /etc/wireguard/wgX.conf
2026-07-01
LUKS / Full Disk Encryption
- Added
cryptandcrypt-libdracut modules to99-protocol7.conf - Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
- FDE confirmed working on baremetal (UEFI and BIOS)
Hardened Malloc
- Added
lainos-hardened-mallocto packages - Added
LD_PRELOAD=/usr/lib/libhardened_malloc.sowrappers for the following applications:- alacritty(all terminal applications)
- element(if installed)
- gnome-keyring-daemon
- keepassxc
- kleopatra
- mpv
- Added
LD_PRELOAD=/usr/lib/libhardened_malloc.soto/etc/conf.d/torfor the tor daemon - Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager
Kernel Hardening
- Added kernel parameters to
GRUB_CMDLINE_LINUX:init_on_alloc=1~ zero memory pages on allocationinit_on_free=1~ zero memory pages on freepage_alloc.shuffle=1~ randomize page allocator freelist
- Updated
/etc/sysctl.d/99-lainos-hardening.confwith additional hardening:kernel.yama.ptrace_scope = 1~ restrict ptrace to parent processeskernel.kexec_load_disabled = 1~ disable kexeckernel.unprivileged_userns_clone = 0~ disable unprivileged user namespaceskernel.randomize_va_space = 2~ full ASLRkernel.perf_event_paranoid = 3~ restrict perf eventsfs.suid_dumpable = 0~ disable setuid core dumpskernel.core_pattern = |/bin/false~ disable core dumps
Gnome Keyring
- Added
gnome-keyringto packages - Added
exec /usr/local/bin/gnome-keyring-daemon --start --components=secretsto skel sway config - Provides secrets service backend for Element and other Electron apps
Calamares / shellprocess-final
lainos-ghost-unitsrunlevel registration changed from sysinit to boot- doas.conf updated with
permit nopass :wheel cmd openrc-shutdownandpermit nopass :wheel cmd lainos-suspend - Added
rc-update delfor etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install
Overlay cleanup
- Removed
cgroup-delegateandlainos-ghost-unitsfromairootfs/etc/runlevels/sysinit/
Known issues
• STILL NOT BTRFS COMPATIBLE YET. Use ext4 for now.
• Some Nvidia cards have trouble with Sway(Follow Nvidia instructions above^^).
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
LALL<3
Downloads