• 2026.08.20 e0b9d6386e

    amnesia released this 2026-08-20 22:17:39 +02:00 | 0 commits to main since this release

    lainOS layer 02 ~ 2026.08.20 Changelog

    OpenRC Isolation/Containment Stack Debut

    • This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.

    OpenRC Isolation/Containment Architecture


    • Calamares rebuild ~ 2026.08.20
    • Fixed race condition preventing unbound DNS from shutting down during DNS mode transitions.

    First boot: getting online

    WiFi is off by default to preserve privacy. To connect:

    wifi on 
    wscan
    

    Want WiFi to come up automatically on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable.
    USB automount is enabled with usb-automount enable.

    Automate all of this with the following command on first boot:

    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
    

    DNS Mediation Architecture

    DNS Modes Quick Reference

    Note: if using a VPN, it must be turned on before activating encrypted mode.

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns status       # Show current mode and proxy state
    
    private-mode on         # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode)
    private-mode off        # Restore previous mode (plaintext or encrypted)
    

    New in 2026.08.20

    OpenRC Isolation Stack ~ Service Coverage

    Core OpenRC services are sandboxed by default with the following services currently verified:

    Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor
    dnsmasq ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    unbound ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dnscrypt-proxy ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    tor ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    dhcpcd ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    chrony ✅ ✅ (host) ❌* ✅ ✅ ✅ ✅
    sdwdate ✅ ✅ (host) ✅ ✅ ✅ ✅ ✅
    syslog-ng ✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅
    acpid ✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅
    iwd ❌** ❌ ❌ ✅ ✅ ✅ ✅

    * Intentional ~ DHCP and NTP need host PID namespace visibility
    ** Intentional ~ rfkill device access requires mount namespace exception, documented


    Full Service List

    The isolation stack currently covers these OpenRC services:

    DNS & Networking:

    • dnsmasq ~ DNS forwarding (stateless, cache-zero)
    • unbound ~ DNSSEC-validating resolver
    • dnscrypt-proxy ~ Encrypted DNS with anonymized relay
    • tor ~ Tor daemon with DNSPort
    • dhcpcd ~ DHCP client
    • iwd ~ WiFi daemon (mount namespace exception)

    Time & System:

    • chrony ~ NTP client
    • sdwdate ~ Tor-based time sync (fingerprint-resistant)
    • syslog-ng ~ System logging (network-isolated)
    • acpid ~ ACPI event handler

    Protocol 7 Daemons (Protocol 7 has its own built in isolation):

    • lainos-dbus-bridge ~ D-Bus login1 facade
    • lainos-notifyd ~ sd_notify socket sink
    • lainos-init ~ Session initializer

    Verification

    openrc-security-status
    

    This will verify all containment layers are active and enforcing for every service listed above.


    • OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with openrc-security-status.

    • Security Verification Suite ~ Three tools now ship: lainos-security-status (read-only dashboard), openrc-security-status (isolation stack verification), and protocol7-core-security-status (36-test adversarial suite). Runtime verification, not config review.

    • AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (dnsmasq, unbound, dnscrypt-proxy), networking (tor, iwd, dhcpcd), media (pipewire, wireplumber), crypto (gpg, keepassxc), browsers (librewolf), and system utilities (chronyd, syslog-ng, acpid).

    • lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before pacman touches them. Safety net for kernel updates.

    • DNS Mediation Architecture (Improved) ~ dnsmasq as centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes: plaintext, encrypted, private. private-mode saves and restores your previous DNS mode.

    • ISO Size ~ 2.8GB


    Documentation


    Get connected

    LALL<3


    Downloads