• 2026.07.28-rc8 80ea682249

    amnesia released this 2026-07-29 07:27:31 +02:00 | 1 commits to main since this release

    ####INSTALLATION####

    lainOS layer 02 user guide(access with lainos-help in the terminal.)
    lainOS Privacy Guide for Sensitive Work(access with lainos-privacy-help in the terminal)
    lainOS layer 02 security

    lainOS layer 02 ~ 2026.07.28-rc8 Changelog

    Eighth release candidate. User-togglable encrypted DNS(unbound DoT or Tor DNSport) with stateful mode persistence, and a complete blind DNS mediation architecture that abstracts DNS resolver state away from the rest of the system.(this has been improved from the rc7 release for smoother mode transitions and private-mode operation.)

    RC phase almost completed. This release focuses on verifying that all loose ends have been tied up, and is undergoing bare metal testing to ensure complete functionality of all features and components. The next release will be the stable release if everything goes correctly. This testing will be completed by tomorrow(2026.07.29)


    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable


    New in RC8

    • lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before pacman touches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility.
    • lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd, stubby, snowflake-pt-client), media (pipewire, wireplumber, mpv, vlc), crypto/secrets (gpg, gpg-agent, keepassxc), browsers (librewolf, tor-browser standalone), and system utilities (chronyd, syslog-ng, nft, ssh, sshd, acpid).
    • DNS Mediation Architecture(Improved from rc7) ~ dnsmasq is now a centralized, stateless blind forwarding resolver. All applications resolve through 127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via unbound on :5053), and private (Tor DNSPort on :9059). Mode transitions are explicit and stateful; private-mode remembers and restores your previous mode on exit. lainOS DNS Mediation Architecture
    • lainos-dns utility ~ lainos-dns {plaintext|encrypted|status} toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respects private-mode state.
    • private-mode updated ~ Now tracks DNS mode state via /var/lib/lainos/dns-mode and /var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.
    • lainos-dns encrypted mode(improved from rc7) ~ dnsmasq now forwards to unbound on 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses to dnscrypt-proxy on 127.0.0.1:5300. dnscrypt-proxy encrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP.
    • DNS config templates ~dnsmasq.conf.plaintext, dnsmasq.conf.encrypted, dnsmasq.conf.private installed via airootfs overlay to avoid package conflicts.
    • ISO size ~ 2.8GB

    DNS Quick Reference

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on        # Tor DNSPort (saves previous mode)
    private-mode off       # Restore previous mode (plaintext or encrypted)
    

    Documentation

    • User guide: Updated with lainos-dns and DNS architecture sections.
    • Privacy Guide: Updated private-mode description to reflect DNS mode restoration.
    • New document: lainOS DNS Mediation Architecture

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3


    Downloads