-
released this
2026-08-20 22:17:39 +02:00 | 0 commits to main since this releaselainOS layer 02 ~ 2026.08.20 Changelog
OpenRC Isolation/Containment Stack Debut
- This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.
OpenRC Isolation/Containment Architecture
- Calamares rebuild ~ 2026.08.20
- Fixed race condition preventing
unboundDNS from shutting down during DNS mode transitions.
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable.
USB automount is enabled withusb-automount enable.Automate all of this with the following command on first boot:
wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
DNS Mediation Architecture
DNS Modes Quick Reference
Note: if using a VPN, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
New in 2026.08.20
OpenRC Isolation Stack ~ Service Coverage
Core OpenRC services are sandboxed by default with the following services currently verified:
Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor dnsmasq✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ unbound✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dnscrypt-proxy✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ tor✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dhcpcd✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ chrony✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ sdwdate✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ syslog-ng✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅ acpid✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅ iwd❌** ❌ ❌ ✅ ✅ ✅ ✅ * Intentional ~ DHCP and NTP need host PID namespace visibility
** Intentional ~ rfkill device access requires mount namespace exception, documented
Full Service List
The isolation stack currently covers these OpenRC services:
DNS & Networking:
dnsmasq~ DNS forwarding (stateless, cache-zero)unbound~ DNSSEC-validating resolverdnscrypt-proxy~ Encrypted DNS with anonymized relaytor~ Tor daemon with DNSPortdhcpcd~ DHCP clientiwd~ WiFi daemon (mount namespace exception)
Time & System:
chrony~ NTP clientsdwdate~ Tor-based time sync (fingerprint-resistant)syslog-ng~ System logging (network-isolated)acpid~ ACPI event handler
Protocol 7 Daemons (Protocol 7 has its own built in isolation):
lainos-dbus-bridge~ D-Bus login1 facadelainos-notifyd~ sd_notify socket sinklainos-init~ Session initializer
Verification
openrc-security-statusThis will verify all containment layers are active and enforcing for every service listed above.
-
OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with
openrc-security-status. -
Security Verification Suite ~ Three tools now ship:
lainos-security-status(read-only dashboard),openrc-security-status(isolation stack verification), andprotocol7-core-security-status(36-test adversarial suite). Runtime verification, not config review. -
AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd), media (pipewire,wireplumber), crypto (gpg,keepassxc), browsers (librewolf), and system utilities (chronyd,syslog-ng,acpid). -
lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before
pacmantouches them. Safety net for kernel updates. -
DNS Mediation Architecture (Improved) ~
dnsmasqas centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes:plaintext,encrypted,private.private-modesaves and restores your previous DNS mode. -
ISO Size ~ 2.8GB
Documentation
- Privacy guide updated with
private-modeDNS restoration - New document: lainOS DNS Mediation Architecture
Get connected
- Matrix: https://matrix.to/#/#lainos:catgirl.cloud
- Discord: https://discord.gg/JdMQvkHqwH (Discord spies on you)
- Onion XMPP: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion
- Website: https://lainos.net
- Onion: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
- IRC: irc.libera.chat #LainOS
LALL<3
Downloads
-
released this
2026-08-19 22:54:56 +02:00 | 5 commits to main since this release#this release is now having calamares rebuilt, wait for next release later today
lainOS layer 02 ~ 2026.08.19 Changelog
OpenRC Isolation/Containment Stack Debut
- This is the first lainOS layer 02 ISO to ship with the full OpenRC service isolation stack ~ a complete, Rust-based containment system for all core OpenRC-managed services. This represents the culmination of weeks of engineering work to bring systemd-equivalent (and in some ways superior) service isolation to a systemd-free environment.
OpenRC Isolation/Containment Architecture
- Fixed race condition preventing
unboundDNS from shutting down during DNS mode transitions.
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable.
USB automount is enabled withusb-automount enable.Automate all of this with the following command on first boot:
wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
DNS Mediation Architecture
DNS Modes Quick Reference
Note: if using a VPN, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
New in 2026.08.19
OpenRC Isolation Stack ~ Service Coverage
All OpenRC services are sandboxed by default with the following services currently verified:
Service Mount NS Network NS PID NS Cgroups Seccomp Capabilities AppArmor dnsmasq✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ unbound✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dnscrypt-proxy✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ tor✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ dhcpcd✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ chrony✅ ✅ (host) ❌* ✅ ✅ ✅ ✅ sdwdate✅ ✅ (host) ✅ ✅ ✅ ✅ ✅ syslog-ng✅ ✅ (isolated) ✅ ✅ ✅ ✅ ✅ acpid✅ ✅ (host) ✅ ✅ ✅ ✅ (zeroed) ✅ iwd❌** ❌ ❌ ✅ ✅ ✅ ✅ * Intentional ~ DHCP and NTP need host PID namespace visibility
** Intentional ~ rfkill device access requires mount namespace exception, documented
Full Service List
The isolation stack currently covers these OpenRC services:
DNS & Networking:
dnsmasq~ DNS forwarding (stateless, cache-zero)unbound~ DNSSEC-validating resolverdnscrypt-proxy~ Encrypted DNS with anonymized relaytor~ Tor daemon with DNSPortdhcpcd~ DHCP clientiwd~ WiFi daemon (mount namespace exception)
Time & System:
chrony~ NTP clientsdwdate~ Tor-based time sync (fingerprint-resistant)syslog-ng~ System logging (network-isolated)acpid~ ACPI event handler
Protocol 7 Daemons (Protocol 7 has its own built in isolation):
lainos-dbus-bridge~ D-Bus login1 facadelainos-notifyd~ sd_notify socket sinklainos-init~ Session initializer
Verification
openrc-security-statusThis will verify all containment layers are active and enforcing for every service listed above.
-
OpenRC Service Isolation Stack ~ Complete Rust-based containment system for all OpenRC services. Four independent layers: namespace isolation (bwrap), cgroup-v2 limits, seccomp-bpf filtering, and Landlock LSM path enforcement. Services are sandboxed by default. Verifiable with
openrc-security-status. -
Security Verification Suite ~ Three tools now ship:
lainos-security-status(read-only dashboard),openrc-security-status(isolation stack verification), andprotocol7-core-security-status(36-test adversarial suite). Runtime verification, not config review. -
AppArmor Coverage Expanded ~ 20+ profiles covering Protocol 7 daemons, DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd), media (pipewire,wireplumber), crypto (gpg,keepassxc), browsers (librewolf), and system utilities (chronyd,syslog-ng,acpid). -
lainos-kernel-backup ~ Lightweight kernel backup and restore system. Snapshots running kernel, initramfs, modules, and headers before
pacmantouches them. Safety net for kernel updates. -
DNS Mediation Architecture (Improved) ~
dnsmasqas centralized stateless forwarding resolver. Split-controller privacy in encrypted mode: no single component sees both IP and query. Three modes:plaintext,encrypted,private.private-modesaves and restores your previous DNS mode. -
ISO Size ~ 2.8GB
Documentation
- Privacy guide updated with
private-modeDNS restoration - New document: lainOS DNS Mediation Architecture
Get connected
- Matrix: https://matrix.to/#/#lainos:catgirl.cloud
- Discord: https://discord.gg/JdMQvkHqwH (Discord spies on you)
- Onion XMPP: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion
- Website: https://lainos.net
- Onion: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
- IRC: irc.libera.chat #LainOS
LALL<3
-
released this
2026-08-17 05:44:44 +02:00 | 11 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.08.15 Changelog
- Routine build after two week hiatus due to broken computer charger.
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
USB automount is enabled withusb-automount enableAutomate all of this with the following command on first boot, and you will not have to set it up again on subsequent boots:
wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount-enable && wscan
DNS Modes Quick Reference
- Note: if using a vpn, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
New in 2026.07.29
- lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before
pacmantouches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility. See lainos-kernel-backup - lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd,stubby,snowflake-pt-client), media (pipewire,wireplumber,mpv,vlc), crypto/secrets (gpg,gpg-agent,keepassxc), browsers (librewolf,tor-browserstandalone), and system utilities (chronyd,syslog-ng,nft,ssh,sshd,acpid). - DNS Mediation Architecture(Improved from rc7) ~
dnsmasqis now a centralized, stateless blind forwarding resolver. All applications resolve through127.0.0.1:53. Three modes:plaintext(default, DHCP with fallbacks),encrypted(DoT viaunboundon:5053), andprivate(Tor DNSPort on:9059). Mode transitions are explicit and stateful;private-moderemembers and restores your previous mode on exit. lainOS DNS Mediation Architecture lainos-dnsutility ~lainos-dns {plaintext|encrypted|status}toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respectsprivate-modestate.private-modeupdated ~ Now tracks DNS mode state via/var/lib/lainos/dns-modeand/var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.- lainos-dns
encryptedmode(improved from rc7) ~dnsmasqnow forwards tounboundon 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses todnscrypt-proxyon 127.0.0.1:5300.dnscrypt-proxyencrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP. - DNS config templates ~
dnsmasq.conf.plaintext,dnsmasq.conf.encrypted,dnsmasq.conf.privateinstalled viaairootfsoverlay to avoid package conflicts. - ISO size ~ 2.8GB
Documentation
- User guide: Updated with
lainos-dnsand DNS architecture sections. - Privacy Guide: Updated
private-modedescription to reflect DNS mode restoration. - New document: lainOS DNS Mediation Architecture
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
-
released this
2026-07-30 19:10:21 +02:00 | 11 commits to main since this releaseDue to a broken developer machine, lainOS is on hiatus for a while. I'm unable to maintain realeases. Full disk encryption on this release might be broken(on Chromebooks) and I cannot fix it until I have a new machine.
####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.07.29 Changelog
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enableAutomate all of this with the following command on first boot, and you will not have to set it up again after the next boot:
wifi on && wifi-autostart enable && wifi-autoconnect enable && wscan
New in 2026.07.29
- lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before
pacmantouches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility. See lainos-kernel-backup - lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd,stubby,snowflake-pt-client), media (pipewire,wireplumber,mpv,vlc), crypto/secrets (gpg,gpg-agent,keepassxc), browsers (librewolf,tor-browserstandalone), and system utilities (chronyd,syslog-ng,nft,ssh,sshd,acpid). - DNS Mediation Architecture(Improved from rc7) ~
dnsmasqis now a centralized, stateless blind forwarding resolver. All applications resolve through127.0.0.1:53. Three modes:plaintext(default, DHCP with fallbacks),encrypted(DoT viaunboundon:5053), andprivate(Tor DNSPort on:9059). Mode transitions are explicit and stateful;private-moderemembers and restores your previous mode on exit. lainOS DNS Mediation Architecture lainos-dnsutility ~lainos-dns {plaintext|encrypted|status}toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respectsprivate-modestate.private-modeupdated ~ Now tracks DNS mode state via/var/lib/lainos/dns-modeand/var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.- lainos-dns
encryptedmode(improved from rc7) ~dnsmasqnow forwards tounboundon 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses todnscrypt-proxyon 127.0.0.1:5300.dnscrypt-proxyencrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP. - DNS config templates ~
dnsmasq.conf.plaintext,dnsmasq.conf.encrypted,dnsmasq.conf.privateinstalled viaairootfsoverlay to avoid package conflicts. - ISO size ~ 2.8GB
DNS Quick Reference
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
Documentation
- User guide: Updated with
lainos-dnsand DNS architecture sections. - Privacy Guide: Updated
private-modedescription to reflect DNS mode restoration. - New document: lainOS DNS Mediation Architecture
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
- lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before
-
2026.07.28-rc8 layer 02: Protocol 7 Pre-release
released this
2026-07-29 07:27:31 +02:00 | 12 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.07.28-rc8 Changelog
Eighth release candidate. User-togglable encrypted DNS(
unboundDoT or Tor DNSport) with stateful mode persistence, and a complete blind DNS mediation architecture that abstracts DNS resolver state away from the rest of the system.(this has been improved from the rc7 release for smoother mode transitions andprivate-modeoperation.)RC phase almost completed. This release focuses on verifying that all loose ends have been tied up, and is undergoing bare metal testing to ensure complete functionality of all features and components. The next release will be the stable release if everything goes correctly. This testing will be completed by tomorrow(2026.07.29)
First boot: getting online
WiFi is off by default to preserve privacy. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New in RC8
- lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before
pacmantouches them. This is a safety net in the unlikely but possible case that a kernel update causes an incompatibility. - lainos-apparmor (Coverage Expanded) ~ The package as a whole ships 20+ profiles covering the full lainOS stack ~ Protocol 7 daemons, the DNS mediation layer (
dnsmasq,unbound,dnscrypt-proxy), networking (tor,iwd,dhcpcd,stubby,snowflake-pt-client), media (pipewire,wireplumber,mpv,vlc), crypto/secrets (gpg,gpg-agent,keepassxc), browsers (librewolf,tor-browserstandalone), and system utilities (chronyd,syslog-ng,nft,ssh,sshd,acpid). - DNS Mediation Architecture(Improved from rc7) ~
dnsmasqis now a centralized, stateless blind forwarding resolver. All applications resolve through127.0.0.1:53. Three modes:plaintext(default, DHCP with fallbacks),encrypted(DoT viaunboundon:5053), andprivate(Tor DNSPort on:9059). Mode transitions are explicit and stateful;private-moderemembers and restores your previous mode on exit. lainOS DNS Mediation Architecture lainos-dnsutility ~lainos-dns {plaintext|encrypted|status}toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respectsprivate-modestate.private-modeupdated ~ Now tracks DNS mode state via/var/lib/lainos/dns-modeand/var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private(plaintext or encrypted) config until Tor DNSPort is ready.- lainos-dns
encryptedmode(improved from rc7) ~dnsmasqnow forwards tounboundon 127.0.0.1:5053, unbound validates DNSSEC, serves from cache, and forwards cache misses todnscrypt-proxyon 127.0.0.1:5300.dnscrypt-proxyencrypts the query via DNSCrypt and routes it through an anonymized relay. The relay forwards to the resolver. The relay knows the user's IP but not the query; the resolver knows the query but not the user's IP. - DNS config templates ~
dnsmasq.conf.plaintext,dnsmasq.conf.encrypted,dnsmasq.conf.privateinstalled viaairootfsoverlay to avoid package conflicts. - ISO size ~ 2.8GB
DNS Quick Reference
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
Documentation
- User guide: Updated with
lainos-dnsand DNS architecture sections. - Privacy Guide: Updated
private-modedescription to reflect DNS mode restoration. - New document: lainOS DNS Mediation Architecture
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
- lainos-kernel-backup ~ A lightweight, deterministic kernel backup and restore system. It snapshots the currently running kernel, initramfs, modules, and headers before
-
2026.07.21-rc7 layer 02: Protocol 7 Pre-release
released this
2026-07-22 02:46:23 +02:00 | 17 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.07.21-rc7 Changelog
Seventh release candidate. User-togglable encrypted DNS(DoT or Tor DNSport) with stateful mode persistence, and a complete blind DNS mediation architecture that abstracts DNS resolver state away from the rest of the system.
This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.
First boot: getting online
WiFi is off by default. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New in RC7
- DNS Mediation Architecture ~
dnsmasqis now a centralized, stateless blind forwarding resolver. All applications resolve through127.0.0.1:53. Three modes: plaintext (default, DHCP with fallbacks), encrypted (DoT via stubby on:5053), and private (Tor DNSPort on:9059). Mode transitions are explicit and stateful;private-moderemembers and restores your previous mode on exit. lainOS DNS Mediation Architecture lainos-dnsutility ~lainos-dns {plaintext|encrypted|status}toggles between plaintext and encrypted DNS, detects installed proxy, warns if not running. Respectsprivate-modestate.private-modeupdated ~ Now tracks DNS mode state via/var/lib/lainos/dns-modeand/var/lib/lainos/dns-mode-previous. When entering private mode, saves current mode; when exiting, restores it (plaintext or encrypted). Bootstrap DNS uses non-private config until Tor DNSPort is ready.- Stubby DoT proxy ~
stubbyis the encrypted DNS proxy. Ships with OpenRC init script since Arch doesn't provide one. Auto-starts in default runlevel. - DNS config templates ~
dnsmasq.conf.plaintext,dnsmasq.conf.encrypted,dnsmasq.conf.privateinstalled viaairootfsoverlay to avoid package conflicts. - ISO size ~ 2.7GB
DNS Quick Reference
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via stubby lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
Documentation
- User guide: Updated with
lainos-dnsand DNS architecture sections. - Privacy Guide: Updated
private-modedescription to reflect DNS mode restoration. - New document: lainOS DNS Mediation Architecture
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
- DNS Mediation Architecture ~
-
2026.07.20-rc6 layer 02: Protocol 7 Pre-release
released this
2026-07-20 19:40:27 +02:00 | 28 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.07.20-rc6 Changelog
Sixth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.
This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.
- Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.75GB down from 3.15GB(2026.07.16)
- Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.
dnsmasqadded as experimental privacy feature to hide dns state from the rest of the system. lainOS DNS Mediation Layer
First boot: getting online
WiFi is off by default. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New Tool ~
tor1/tor2/tor3/tor4(Tor Stream Isolation)Four dedicated, isolated Tor circuits, matching the
wg1-wg4WireGuard tunnel model exactly. One command, works the same way for every application:tor1 profanity -a user@example.onion tor2 signal-desktop tor3 element-desktop tor4 gajimWhatever you run through
tor1never shares a circuit ~ or even a port ~ with anything run throughtor2/tor3/tor4or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly intorrc.Usage is seamless across every application type ~
tor1-tor4auto-detect what they're launching and route it correctly without you needing to know or specify anything:- Plain CLI tools and GTK apps (curl, Gajim, Dino) route via
torsocks, same as always. - Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own
--proxy-serverflag instead ~torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional. - Detected Electron apps also get
LD_PRELOADstripped (alacritty's forcedhardened_mallocwrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) andXDG_CURRENT_DESKTOPoverridden toGNOME(Chromium's keyring backend detection doesn't recognizesway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).
Privacy Guide
lainos-privacy-help # updated with a Tor Stream Isolation callout
New Package ~
lainos-apparmor(AppArmor Mandatory Access Control)Per-daemon AppArmor profiles for all Protocol 7 components with external input surfaces (
lainos-dbus-bridge,lainos-notifyd,lainos-init), loaded at boot by an OpenRC init script before the daemons start. Thelainos-apparmorinit script loads only Protocol 7 profiles, not all of/etc/apparmor.d/*indiscriminately.- Path-based MAC complements the existing seccomp filters and mount namespaces: if an attacker escapes the private mount namespace (e.g., via a kernel vulnerability), AppArmor still blocks access to real user data (
/home/**,/root/**), sensitive kernel interfaces (/sys/kernel/security/**), and/etc/shadow. - Network denials are enforced independently of seccomp —
inet,inet6,netlink, andpacketare explicitly denied in thelainos-dbus-bridgeandlainos-notifydprofiles. - Capability rules in the
lainos-dbus-bridgeandlainos-notifydprofiles grant only the seven capabilities required for pre-drop mount namespace setup (sys_admin,chown,fowner,setgid,setuid,setpcap,dac_override,mknod), then the daemons drop tonobodyand clear their bounding set. - Verified via adversarial test suite: 26/26 tests passed, including
nsenter-based namespace isolation effectiveness tests, path-blocking tests (/etc/shadow,/home,/root), capability-abuse tests, and AppArmor enforcement confirmation.
This closes the largest remaining architectural gap in Protocol 7 Core's defensive stack.
New Package ~
lainos-ram-wipeRAM-extraction attack defense, ported from Kicksecure/Whonix's
ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongsideinit_on_alloc=1/init_on_free=1kernel parameters that continuously poison memory pages on allocation and free.ram-wipe enable # RAM wipe runs at shutdown/reboot (default) ram-wipe disable # skip the wipe pass, faster shutdown ram-wipe status # show current GRUB config and running kernel's cmdlineContinuous protection (
init_on_alloc/init_on_free) is always on and isn't affected by this toggle.⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.
New Section ~ Sandboxed Build Requirements
Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (
kernel.unprivileged_userns_clone = 0, set via/etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:doas sysctl -w kernel.unprivileged_userns_clone=1 # build your software doas sysctl -w kernel.unprivileged_userns_clone=0 # restore afterwardResets to the hardened default automatically on reboot either way.
Known Issues
- Some Nvidia cards have trouble with Sway.
Documentation
- User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to
tor1; Tor section cross-references stream isolation. - Privacy Guide: "During your session" (step 6) updated with
tor1-tor4guidance, the single-instance-app caveat, and the LibreWolf exception.
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
-
2026.07.17-rc5 layer 02: Protocol 7 Pre-release
released this
2026-07-18 02:59:07 +02:00 | 30 commits to main since this releasethis iso accidentally had linux firmware removed when i cut the package list down. building a new one now.
####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
lainOS layer 02 securitylainOS layer 02 ~ 2026.07.16-rc5 Changelog
Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.
This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.
- Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.46GB down from 3.15GB(2026.07.16)
- Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.
First boot: getting online
WiFi is off by default. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New Tool ~
tor1/tor2/tor3/tor4(Tor Stream Isolation)Four dedicated, isolated Tor circuits, matching the
wg1-wg4WireGuard tunnel model exactly. One command, works the same way for every application:tor1 profanity -a user@example.onion tor2 signal-desktop tor3 element-desktop tor4 gajimWhatever you run through
tor1never shares a circuit ~ or even a port ~ with anything run throughtor2/tor3/tor4or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly intorrc.Usage is seamless across every application type ~
tor1-tor4auto-detect what they're launching and route it correctly without you needing to know or specify anything:- Plain CLI tools and GTK apps (curl, Gajim, Dino) route via
torsocks, same as always. - Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own
--proxy-serverflag instead ~torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional. - Detected Electron apps also get
LD_PRELOADstripped (alacritty's forcedhardened_mallocwrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) andXDG_CURRENT_DESKTOPoverridden toGNOME(Chromium's keyring backend detection doesn't recognizesway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).
Privacy Guide
lainos-privacy-help # updated with a Tor Stream Isolation callout
New Package ~
lainos-apparmor(AppArmor Mandatory Access Control)Per-daemon AppArmor profiles for all Protocol 7 components with external input surfaces (
lainos-dbus-bridge,lainos-notifyd,lainos-init), loaded at boot by an OpenRC init script before the daemons start. Thelainos-apparmorinit script loads only Protocol 7 profiles, not all of/etc/apparmor.d/*indiscriminately.- Path-based MAC complements the existing seccomp filters and mount namespaces: if an attacker escapes the private mount namespace (e.g., via a kernel vulnerability), AppArmor still blocks access to real user data (
/home/**,/root/**), sensitive kernel interfaces (/sys/kernel/security/**), and/etc/shadow. - Network denials are enforced independently of seccomp —
inet,inet6,netlink, andpacketare explicitly denied in thelainos-dbus-bridgeandlainos-notifydprofiles. - Capability rules in the
lainos-dbus-bridgeandlainos-notifydprofiles grant only the seven capabilities required for pre-drop mount namespace setup (sys_admin,chown,fowner,setgid,setuid,setpcap,dac_override,mknod), then the daemons drop tonobodyand clear their bounding set. - Verified via adversarial test suite: 26/26 tests passed, including
nsenter-based namespace isolation effectiveness tests, path-blocking tests (/etc/shadow,/home,/root), capability-abuse tests, and AppArmor enforcement confirmation.
This closes the largest remaining architectural gap in Protocol 7 Core's defensive stack.
New Package ~
lainos-ram-wipeRAM-extraction attack defense, ported from Kicksecure/Whonix's
ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongsideinit_on_alloc=1/init_on_free=1kernel parameters that continuously poison memory pages on allocation and free.ram-wipe enable # RAM wipe runs at shutdown/reboot (default) ram-wipe disable # skip the wipe pass, faster shutdown ram-wipe status # show current GRUB config and running kernel's cmdlineContinuous protection (
init_on_alloc/init_on_free) is always on and isn't affected by this toggle.⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.
New Section ~ Sandboxed Build Requirements
Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (
kernel.unprivileged_userns_clone = 0, set via/etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:doas sysctl -w kernel.unprivileged_userns_clone=1 # build your software doas sysctl -w kernel.unprivileged_userns_clone=0 # restore afterwardResets to the hardened default automatically on reboot either way.
Known Issues
- Some Nvidia cards have trouble with Sway.
Documentation
- User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to
tor1; Tor section cross-references stream isolation. - Privacy Guide: "During your session" (step 6) updated with
tor1-tor4guidance, the single-instance-app caveat, and the LibreWolf exception.
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
-
2026.07.16-rc5 layer 02: Protocol 7 Pre-release
released this
2026-07-16 22:05:57 +02:00 | 42 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
protocol7-core-Security Analysis(new valgrind and static analysis sections~zero mem leaks detected)lainOS layer 02 ~ 2026.07.16-rc5 Changelog
Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.
This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.
- Package list reduced to remove redundant packages left over from the layer 01 package list. ISO is now 2.46GB down from 3.15GB(2026.07.16)
- Quickstart guide added. This pops up on first boot instead of the full user guide, provides the user with the needed commands to run the system, and directs the user to all of the other guides.
First boot: getting online
WiFi is off by default. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New Tool ~
tor1/tor2/tor3/tor4(Tor Stream Isolation)Four dedicated, isolated Tor circuits, matching the
wg1-wg4WireGuard tunnel model exactly. One command, works the same way for every application:tor1 profanity -a user@example.onion tor2 signal-desktop tor3 element-desktop tor4 gajimWhatever you run through
tor1never shares a circuit ~ or even a port ~ with anything run throughtor2/tor3/tor4or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly intorrc.Usage is seamless across every application type ~
tor1-tor4auto-detect what they're launching and route it correctly without you needing to know or specify anything:- Plain CLI tools and GTK apps (curl, Gajim, Dino) route via
torsocks, same as always. - Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own
--proxy-serverflag instead ~torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional. - Detected Electron apps also get
LD_PRELOADstripped (alacritty's forcedhardened_mallocwrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) andXDG_CURRENT_DESKTOPoverridden toGNOME(Chromium's keyring backend detection doesn't recognizesway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).
Known exception: Firefox-based browsers (LibreWolf) don't work reliably through
torsocksat all ~ this is a known, documented limitation oftorsocksitself for Firefox's multi-process architecture, not something specific totor1-tor4. Configure LibreWolf's SOCKS5 proxy natively instead (about:preferences-> Network Settings). See the user guide for exact settings.lainos-privacy-help # updated with a Tor Stream Isolation callout
New Package ~
lainos-ram-wipeRAM-extraction attack defense, ported from Kicksecure/Whonix's
ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongsideinit_on_alloc=1/init_on_free=1kernel parameters that continuously poison memory pages on allocation and free.ram-wipe enable # RAM wipe runs at shutdown/reboot (default) ram-wipe disable # skip the wipe pass, faster shutdown ram-wipe status # show current GRUB config and running kernel's cmdlineContinuous protection (
init_on_alloc/init_on_free) is always on and isn't affected by this toggle.⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.
New Section ~ Sandboxed Build Requirements
Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (
kernel.unprivileged_userns_clone = 0, set via/etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:doas sysctl -w kernel.unprivileged_userns_clone=1 # build your software doas sysctl -w kernel.unprivileged_userns_clone=0 # restore afterwardResets to the hardened default automatically on reboot either way.
Known Issues
- Some Nvidia cards have trouble with Sway.
Documentation
- User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to
tor1; Tor section cross-references stream isolation. - Privacy Guide: "During your session" (step 6) updated with
tor1-tor4guidance, the single-instance-app caveat, and the LibreWolf exception.
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
-
2026.07.15-rc5 layer 02: Protocol 7 Pre-release
released this
2026-07-16 01:30:36 +02:00 | 42 commits to main since this release####INSTALLATION####
lainOS layer 02 user guide(access with
lainos-helpin the terminal.)
lainOS Privacy Guide for Sensitive Work(access withlainos-privacy-helpin the terminal)
protocol7-core-Security Analysis(new valgrind and static analysis sections~zero mem leaks detected)lainOS layer 02 ~ 2026.07.15-rc5 Changelog
Fifth release candidate. Per-application Tor circuit isolation, and a RAM-extraction defense port from Whonix.
This RC phase will continue until 2026.07.23, and layer 02 will be released as stable thereafter.
First boot: getting online
WiFi is off by default. To connect:
wifi on wscanWant WiFi to come up automatically on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable
New Tool ~
tor1/tor2/tor3/tor4(Tor Stream Isolation)Four dedicated, isolated Tor circuits, matching the
wg1-wg4WireGuard tunnel model exactly. One command, works the same way for every application:tor1 profanity -a user@example.onion tor2 signal-desktop tor3 element-desktop tor4 gajimWhatever you run through
tor1never shares a circuit ~ or even a port ~ with anything run throughtor2/tor3/tor4or the default port (9050, which itself now also isolates by destination). The default port and all four dedicated ports are configured directly intorrc.Usage is seamless across every application type ~
tor1-tor4auto-detect what they're launching and route it correctly without you needing to know or specify anything:- Plain CLI tools and GTK apps (curl, Gajim, Dino) route via
torsocks, same as always. - Electron/Chromium apps (Signal, Element, confirmed) are detected automatically and routed via Chromium's own
--proxy-serverflag instead ~torsocks's usual interception never reaches Electron's sandboxed networking, so this is necessary, not optional. - Detected Electron apps also get
LD_PRELOADstripped (alacritty's forcedhardened_mallocwrapper otherwise gets inherited and crashes some Electron apps ~ confirmed with Signal) andXDG_CURRENT_DESKTOPoverridden toGNOME(Chromium's keyring backend detection doesn't recognizesway, incorrectly reporting no supported keyring even when one is genuinely available ~ confirmed and fixed with Element).
Known exception: Firefox-based browsers (LibreWolf) don't work reliably through
torsocksat all ~ this is a known, documented limitation oftorsocksitself for Firefox's multi-process architecture, not something specific totor1-tor4. Configure LibreWolf's SOCKS5 proxy natively instead (about:preferences-> Network Settings). See the user guide for exact settings.lainos-privacy-help # updated with a Tor Stream Isolation callout
New Package ~
lainos-ram-wipeRAM-extraction attack defense, ported from Kicksecure/Whonix's
ram-wipe: a dracut shutdown hook that wipes reclaimable disk cache from RAM at every reboot/poweroff, alongsideinit_on_alloc=1/init_on_free=1kernel parameters that continuously poison memory pages on allocation and free.ram-wipe enable # RAM wipe runs at shutdown/reboot (default) ram-wipe disable # skip the wipe pass, faster shutdown ram-wipe status # show current GRUB config and running kernel's cmdlineContinuous protection (
init_on_alloc/init_on_free) is always on and isn't affected by this toggle.⚠️ Known limitation: the dracut module is confirmed correctly installed and baked into the initramfs, and multiple reboots with it active completed cleanly with no hangs ~ but the actual on-screen shutdown message could not be visually confirmed on Sway/wlroots test hardware, most likely due to how the GPU driver hands the screen back to a plain text console during that specific shutdown transition. If you can confirm this visually on your hardware, we'd like to hear about it.
New Section ~ Sandboxed Build Requirements
Some software (LibreWolf's own build process, confirmed) needs unprivileged user namespaces for its own build-time sandboxing, which LainOS locks down by default (
kernel.unprivileged_userns_clone = 0, set via/etc/sysctl.d/99-lainos-hardening.conf). Temporarily enable it for builds that need it:doas sysctl -w kernel.unprivileged_userns_clone=1 # build your software doas sysctl -w kernel.unprivileged_userns_clone=0 # restore afterwardResets to the hardened default automatically on reboot either way.
Known Issues
- Some Nvidia cards have trouble with Sway.
Documentation
- User guide: new "Tor Stream Isolation," "ram-wipe," and "Building Software ~ Sandboxed Build Requirements" sections; LESME's connect instructions updated to
tor1; Tor section cross-references stream isolation. - Privacy Guide: "During your session" (step 6) updated with
tor1-tor4guidance, the single-instance-app caveat, and the LibreWolf exception.
Get connected
• LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
• Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
• Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
• Website: https://lainos.net
• Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
• irc.libera.chat ~ #LainOSLALL<3
Downloads
- Plain CLI tools and GTK apps (curl, Gajim, Dino) route via