-
released this
2026-08-19 22:54:56 +02:00 | 5 commits to main since this release#this release is now having calamares rebuilt, wait for next release later today
lainOS layer 02 ~ 2026.08.19 Changelog
OpenRC Isolation/Containment Stack Debut
- This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.
OpenRC Isolation/Containment Architecture
- Fixed race condition preventing
unboundDNS from shutting down during DNS mode transitions.
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable.
USB automount is enabled withusb-automount enable.Automate all of this with the following command on first boot:
wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
DNS Mediation Architecture
DNS Modes Quick Reference
Note: if using a VPN, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
New in 2026.08.19
OpenRC Isolation Stack ~ Service Coverage
All OpenRC services are sandboxed by default with the following services currently verified:
Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor dnsmasq✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ unbound✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dnscrypt-proxy✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ tor✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dhcpcd✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ chrony✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ sdwdate✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ syslog-ng✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅ acpid✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅ iwd❌** ❌ ❌ ✅ ✅ ✅ ✅ * Intentional ~ DHCP and NTP need host PID namespace visibility
** Intentional ~ rfkill device access requires mount namespace exception, documented
Full Service List
The isolation stack currently covers these OpenRC services:
DNS & Networking:
dnsmasq~ DNS forwarding (stateless, cache-zero)unbound~ DNSSEC-validating resolverdnscrypt-proxy~ Encrypted DNS with anonymized relaytor~ Tor daemon with DNSPortdhcpcd~ DHCP clientiwd~ WiFi daemon (mount namespace exception)
Time & System:
chrony~ NTP clientsdwdate~ Tor-based time sync (fingerprint-resistant)syslog-ng~ System logging (network-isolated)acpid~ ACPI event handler
Protocol 7 Daemons (Protocol 7 has its own built in isolation):
lainos-dbus-bridge~ D-Bus login1 facadelainos-notifyd~ sd_notify socket sinklainos-init~ Session initializer
Verification
openrc-security-statusThis will verify all containment layers are active and enforcing for every service listed above.
-
OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with
openrc-security-status. -
Security Verification Suite ~ Three tools now ship:
lainos-security-status(read-only dashboard),openrc-security-status(isolation stack verification), andprotocol7-core-security-status(36-test adversarial suite). Runtime verification, not config review. -
AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd), media (pipewire,wireplumber), crypto (gpg,keepassxc), browsers (librewolf), and system utilities (chronyd,syslog-ng,acpid). -
lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before
pacmantouches them. Safety net for kernel updates. -
DNS Mediation Architecture (Improved) ~
dnsmasqas centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes:plaintext,encrypted,private.private-modesaves and restores your previous DNS mode. -
ISO Size ~ 2.8GB
Documentation
- Privacy guide updated with
private-modeDNS restoration - New document: lainOS DNS Mediation Architecture
Get connected
- Matrix: https://matrix.to/#/#lainos:catgirl.cloud
- Discord: https://discord.gg/JdMQvkHqwH (Discord spies on you)
- Onion XMPP: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion
- Website: https://lainos.net
- Onion: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
- IRC: irc.libera.chat #LainOS
LALL<3