• 2026.07.07-rc2 b0c5316a56

    amnesia released this 2026-07-07 18:09:57 +02:00 | 34 commits to main since this release

    ####INSTALLATION####

    MAINTENANCE WAIT FOR NEXT ISO

    #### layer 01/layer 02 migration and user guide ####

    Changelog

    Second release candidate to fix issues in first release candidate

    All features are now fully functional. PipeWire capability (now handled by the lainos-audio-init package, which was relocated from within protocol7-core to its own separate package) and syslog-ng logging capability are fixed. The whole protocol7-core stack has undergone fuzz testing with dfuzzer, AddressSanitizer, and libFuzzer. All interfaces pass clean. This RC phase will continue for another week or two, and will be released as stable thereafter.

    protocol7-core-Security Analysis(final)

    2026.07.07-rc2

    fixed from rc1

    lainos-utils 2.0-5

    • Added disconnect option in wifi scan.

    Calamares / shellprocess-final(dhcpcd group and user)

    • Added groupadd -r dhcpcd 2>/dev/null || true ~ creates dhcpcd group on install
    • Added useradd -r -s /usr/bin/nologin -d /var/lib/dhcpcd dhcpcd 2>/dev/null || true ~
      creates dhcpcd user on install

    pacman.conf cleanup

    • Removed hardcoded mirror server lines from both pacman.conf files
      (profile root and airootfs/etc/) ~ replaced with Include = /etc/pacman.d/mirrorlist

    profiledef.sh

    • Added hardened_malloc wrapper scripts to file_permissions with 0:0:755 ~
      alacritty, element, gnome-keyring-daemon, keepassxc, kleopatra, mpv
    • Fixes wrappers being non-executable on installed systems in RC1

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

  • 2026.07.06-r1 b0c5316a56

    amnesia released this 2026-07-07 08:44:14 +02:00 | 34 commits to main since this release

    ####INSTALLATION####

    #### layer 01/layer 02 migration and user guide ####

    Missing dhcpcd user discovered upon router failure, wait until tomorrow or run this command to create it

    doas useradd -r -s /usr/bin/nologin -d /var/lib/dhcpcd dhcpcd
    

    Changelog

    This release marks the first layer 02 release candidate(with added cleanup and hardened_malloc activated).

    All features are now fully functional. PipeWire capability (now handled by the lainos-audio-init package, which was relocated from within protocol7-core to its own separate package) and syslog-ng logging capability are fixed. The whole protocol7-core stack has undergone fuzz testing with dfuzzer, AddressSanitizer, and libFuzzer. All interfaces pass clean. This RC phase will continue for another week or two, and will be released as stable thereafter.

    Security Analysis(final)

    2026-07-07

    pacman.conf cleanup

    • Removed hardcoded mirror server lines from both pacman.conf files
      (profile root and airootfs/etc/) ~ replaced with Include = /etc/pacman.d/mirrorlist

    profiledef.sh

    • Added hardened_malloc wrapper scripts to file_permissions with 0:0:755 ~
      alacritty, element, gnome-keyring-daemon, keepassxc, kleopatra, mpv
    • Fixes wrappers being non-executable on installed systems from RC1

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.05-rc1 6ee13b7146

    amnesia released this 2026-07-06 00:04:29 +02:00 | 35 commits to main since this release

    ####INSTALLATION####

    #### layer 01/layer 02 migration and user guide ####

    EDIT: The hardened-malloc for these apps needs to be activated with the following command because i forgot in this ISO(will fix later):

    doas chmod +x /usr/local/bin/{alacritty,element,gnome-keyring-daemon,keepassxc,kleopatra,mpv}

    Changelog

    This release marks the first layer 02 release candidate.

    All features are now fully functional. PipeWire capability (now handled by the lainos-audio-init package, which was relocated from within protocol7-core to its own separate package) and syslog-ng logging capability are fixed. The whole protocol7-core stack has undergone fuzz testing with dfuzzer, AddressSanitizer, and libFuzzer. All interfaces pass clean. This RC phase will continue for another week or two, and will be released as stable thereafter.

    Security Analysis

    2026-07-05

    PipeWire / Audio

    • Added lainos-audio-init to packages.x86_64
    • Added exec /usr/libexec/lainos/lainos-audio-init to skel sway config
    • Orchestrates PipeWire + WirePlumber + pipewire-pulse on session start
    • Double-fork pattern ~ no zombie processes, clean session lifecycle
    • Confirmed working: pactl connected, alsa_output sink available

    syslog-ng

    • Enabled daemon facility in ISO framework syslog-ng.conf (was commented out)
    • All Protocol 7 daemon logs now routed to /var/log/daemon.log
    • lainos-notifyd messages confirmed appearing with sender uid/pid

    protocol7-core 5.5.3-21

    • lainos-ghost-units: added after syslog-ng to depend() ~ fixes syslog-ng
      treating the system as systemd-based when /run/systemd/system existed before
      syslog-ng started, causing /dev/log to never be created
    • lainos-notifyd v4.6/v4.7: signal handler hang fixed, SCM_CREDENTIALS added,
      MSG_TRUNC detection, log injection prevention, broken shutdown unlink removed
    • lainos-net-init removed ~ dead code, no callers
    • lainos-audio-init removed from protocol7-core ~ now a separate package

    Calamares / shellprocess-final

    • Added notify to usermod group list ~ required for notifyd socket access

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.03-beta 6ee13b7146

    amnesia released this 2026-07-04 09:14:58 +02:00 | 35 commits to main since this release

    ####INSTALLATION####

    #### layer 01/layer 02 migration and user guide ####

    Changelog

    2026-07-03

    Signed Package Repositories

    • Both protocol_7_repo and lainos_repo now require signed packages and databases (SigLevel = Required)
    • All packages are signed with the LainOS maintainer PGP key
    • lainos-keyring package added ~ ships the LainOS public key so pacman can verify the full trust chain automatically
    • pacman-key --populate lainos runs at install time via Calamares

    Tor / nyx

    • Added DataDirectoryGroupReadable 1 to torrc ~ fixes nyx losing access to auth cookie after tor restarts
    • Removed legacy sudo -u tor nyx wrapper from skel zshrc ~ nyx now works directly without doas

    lainos-utils 2.0-4

    • Added lainos-secure-messaging ~ LainOS Ephemeral Secure Messaging Environment (LESME)
      • Automated RSA 4096 PGP keypair generation with random identity
      • Encrypted XMPP credential storage via pass
      • Tor configuration with obfs4 bridges
      • Profanity pre-configuration with OMEMO encryption and PGP-unlocked login
      • Connects to LainOS onion XMPP server

    2026-07-02

    BTRFS

    • BTRFS is now the default filesystem
    • Separate ext4 /boot partition created automatically ~ resolves GRUB compatibility issue with BTRFS root
    • btrfs already present in dracut force_drivers
    • BTRFS confirmed working on baremetal (UEFI and BIOS)

    Calamares

    • Added Calamares autolaunch on liveuser login via sway config exec
    • Only triggers when session user is liveuser ~ does not affect installed systems

    protocol7-core 5.5.3-12

    • provides updated to systemd=1:999 ~ epoch 1 satisfies any future systemd>=X dependency permanently
    • lainos-dbus-bridge fuzz tested with dfuzzer and AddressSanitizer ~ Exit status: 0
    • Systematic pointer type bug fixed across seven methods and properties
    • seccomp filter tightened ~ privilege-setting syscalls removed post-drop
    • See protocol7-core changelog for full details

    lainos-utils 2.0-3

    • Added wg-vpn WireGuard tunnel manager
    • Supports tunnels wg1 - wg4 (up) and wg1d - wg4d (down)
    • Requires WireGuard configs at /etc/wireguard/wgX.conf

    2026-07-01

    LUKS / Full Disk Encryption

    • Added crypt and crypt-lib dracut modules to 99-protocol7.conf
    • Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
    • FDE confirmed working on baremetal (UEFI and BIOS)

    Hardened Malloc

    • Added lainos-hardened-malloc to packages
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so wrappers for the following applications:
      • alacritty(all terminal applications)
      • element(if installed)
      • gnome-keyring-daemon
      • keepassxc
      • kleopatra
      • mpv
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so to /etc/conf.d/tor for the tor daemon
    • Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager

    Kernel Hardening

    • Added kernel parameters to GRUB_CMDLINE_LINUX:
      • init_on_alloc=1 ~ zero memory pages on allocation
      • init_on_free=1 ~ zero memory pages on free
      • page_alloc.shuffle=1 ~ randomize page allocator freelist
    • Updated /etc/sysctl.d/99-lainos-hardening.conf with additional hardening:
      • kernel.yama.ptrace_scope = 1 ~ restrict ptrace to parent processes
      • kernel.kexec_load_disabled = 1 ~ disable kexec
      • kernel.unprivileged_userns_clone = 0 ~ disable unprivileged user namespaces
      • kernel.randomize_va_space = 2 ~ full ASLR
      • kernel.perf_event_paranoid = 3 ~ restrict perf events
      • fs.suid_dumpable = 0 ~ disable setuid core dumps
      • kernel.core_pattern = |/bin/false ~ disable core dumps

    Gnome Keyring

    • Added gnome-keyring to packages
    • Added exec /usr/local/bin/gnome-keyring-daemon --start --components=secrets to sway config
    • Provides secrets service backend for Element and other Electron apps

    Calamares / shellprocess-final

    • lainos-ghost-units runlevel registration changed from sysinit to boot
    • doas.conf updated with permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend
    • Added rc-update del for etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install

    Overlay cleanup

    • Removed cgroup-delegate and lainos-ghost-units from airootfs/etc/runlevels/sysinit/

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3
    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.02-beta-3 6ee13b7146

    amnesia released this 2026-07-03 03:34:49 +02:00 | 35 commits to main since this release

    ####INSTALLATION####

    #### layer 01/layer 02 migration and user guide ####

    This ISO marks the completion of layer 02.

    Changelog

    2026-07-02

    Tor / nyx

    • Added DataDirectoryGroupReadable 1 to torrc ~ fixes nyx losing access to auth cookie after tor restarts
    • Removed legacy sudo -u tor nyx wrapper from skel zshrc ~ nyx now works directly without doas
    • User is added to tor group via Calamares shellprocess-final for nyx access on installed systems
    • nyx confirmed working out of the box on fresh installs

    lainos-utils 2.0-4

    • Added lainos-secure-messaging ~ LainOS Ephemeral Secure Messaging Environment (LESME)
      • Automated RSA 4096 PGP keypair generation with random identity
      • Encrypted XMPP credential storage via pass
      • Tor configuration with obfs4 bridges
      • Profanity pre-configuration with OMEMO encryption and PGP-unlocked login
      • Connect toany server or LainOS onion XMPP server
      • Added wg-vpn WireGuard tunnel manager
      • Supports tunnels wg1 - wg4 (up) and wg1d - wg4d (down)
      • Requires WireGuard configs at /etc/wireguard/wgX.conf

    BTRFS

    • BTRFS is now the default filesystem
    • Separate ext4 /boot partition created automatically ~ resolves GRUB compatibility issue with BTRFS root
    • btrfs already present in dracut force_drivers
    • BTRFS confirmed working on baremetal (UEFI and BIOS)

    Calamares

    • Added Calamares autolaunch on liveuser login via sway config exec
    • Only triggers when session user is liveuser ~ does not affect installed systems

    protocol7-core

    • provides updated to systemd=1:999 ~ epoch 1 satisfies any future systemd>=X dependency permanently, no future PKGBUILD changes required

    2026-07-01

    LUKS / Full Disk Encryption

    • Added crypt and crypt-lib dracut modules to 99-protocol7.conf
    • Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
    • FDE confirmed working on baremetal (UEFI and BIOS)

    Hardened Malloc

    • Added lainos-hardened-malloc to packages
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so wrappers for the following applications:
      • alacritty(all terminal applications)
      • element(if installed)
      • gnome-keyring-daemon
      • keepassxc
      • kleopatra
      • mpv
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so to /etc/conf.d/tor for the tor daemon
    • Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager

    Kernel Hardening

    • Added kernel parameters to GRUB_CMDLINE_LINUX:
      • init_on_alloc=1 ~ zero memory pages on allocation
      • init_on_free=1 ~ zero memory pages on free
      • page_alloc.shuffle=1 ~ randomize page allocator freelist
    • Updated /etc/sysctl.d/99-lainos-hardening.conf with additional hardening:
      • kernel.yama.ptrace_scope = 1 ~ restrict ptrace to parent processes
      • kernel.kexec_load_disabled = 1 ~ disable kexec
      • kernel.unprivileged_userns_clone = 0 ~ disable unprivileged user namespaces
      • kernel.randomize_va_space = 2 ~ full ASLR
      • kernel.perf_event_paranoid = 3 ~ restrict perf events
      • fs.suid_dumpable = 0 ~ disable setuid core dumps
      • kernel.core_pattern = |/bin/false ~ disable core dumps

    Gnome Keyring

    • Added gnome-keyring to packages
    • Added exec /usr/local/bin/gnome-keyring-daemon --start --components=secrets to sway config
    • Provides secrets service backend for Element and other Electron apps

    Calamares / shellprocess-final

    • lainos-ghost-units runlevel registration changed from sysinit to boot
    • doas.conf updated with permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend
    • Added rc-update del for etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install

    Overlay cleanup

    • Removed cgroup-delegate and lainos-ghost-units from airootfs/etc/runlevels/sysinit/

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.02-beta-btrfs 6ee13b7146

    amnesia released this 2026-07-03 00:33:28 +02:00 | 35 commits to main since this release

    ####INSTALLATION####

    #### layer 01/layer 02 migration and user guide ####

    Changelog

    2026-07-02

    BTRFS

    • BTRFS is now the default filesystem
    • Separate ext4 /boot partition created automatically ~ resolves GRUB compatibility issue with BTRFS root
    • btrfs already present in dracut force_drivers
    • BTRFS confirmed working on baremetal (UEFI and BIOS)

    Calamares

    • Added Calamares autolaunch on liveuser login via sway config exec
    • Only triggers when session user is liveuser ~ does not affect installed systems

    protocol7-core

    • provides updated to systemd=1:999 ~ epoch 1 satisfies any future systemd>=X dependency permanently, no future PKGBUILD changes required

    lainos-utils 2.0-3

    • Added wg-vpn WireGuard tunnel manager
    • Supports tunnels wg1 - wg4 (up) and wg1d - wg4d (down)
    • Requires WireGuard configs at /etc/wireguard/wgX.conf

    2026-07-01

    LUKS / Full Disk Encryption

    • Added crypt and crypt-lib dracut modules to 99-protocol7.conf
    • Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
    • FDE confirmed working on baremetal (UEFI and BIOS)

    Hardened Malloc

    • Added lainos-hardened-malloc to packages
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so wrappers for the following applications:
      • alacritty(all terminal applications)
      • element(if installed)
      • gnome-keyring-daemon
      • keepassxc
      • kleopatra
      • mpv
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so to /etc/conf.d/tor for the tor daemon
    • Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager

    Kernel Hardening

    • Added kernel parameters to GRUB_CMDLINE_LINUX:
      • init_on_alloc=1 ~ zero memory pages on allocation
      • init_on_free=1 ~ zero memory pages on free
      • page_alloc.shuffle=1 ~ randomize page allocator freelist
    • Updated /etc/sysctl.d/99-lainos-hardening.conf with additional hardening:
      • kernel.yama.ptrace_scope = 1 ~ restrict ptrace to parent processes
      • kernel.kexec_load_disabled = 1 ~ disable kexec
      • kernel.unprivileged_userns_clone = 0 ~ disable unprivileged user namespaces
      • kernel.randomize_va_space = 2 ~ full ASLR
      • kernel.perf_event_paranoid = 3 ~ restrict perf events
      • fs.suid_dumpable = 0 ~ disable setuid core dumps
      • kernel.core_pattern = |/bin/false ~ disable core dumps

    Gnome Keyring

    • Added gnome-keyring to packages
    • Added exec /usr/local/bin/gnome-keyring-daemon --start --components=secrets to sway config
    • Provides secrets service backend for Element and other Electron apps

    Calamares / shellprocess-final

    • lainos-ghost-units runlevel registration changed from sysinit to boot
    • doas.conf updated with permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend
    • Added rc-update del for etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install

    Overlay cleanup

    • Removed cgroup-delegate and lainos-ghost-units from airootfs/etc/runlevels/sysinit/

    Known issues
    • Some Nvidia cards have trouble with Sway (Follow Nvidia instructions above^^).

    Get connected
    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud
    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH
    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)
    • Website: https://lainos.net
    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.02 6ee13b7146

    amnesia released this 2026-07-02 22:54:08 +02:00 | 35 commits to main since this release

    ####INSTALLATION####

    ####layer 01/layer 02 migration and user guide ####

    Please read the lainOS layer 02 wiki links above before installing. INSTALLATION INSTRUCTIONS ARE IN THE WIKI. DO NOT USE BTRFS(it will likely be integrated within the month)

    Changelog

    2026-07-02

    Calamares

    • Added Calamares autolaunch on liveuser login via sway config exec
    • Only triggers when session user is liveuser ~ does not affect installed systems

    protocol7-core

    • provides updated to systemd=1:999 ~ epoch 1 satisfies any future systemd>=X dependency permanently, no future PKGBUILD changes required

    lainos-utils 2.0-3

    • Added wg-vpn WireGuard tunnel manager
    • Supports tunnels wg1 - wg4 (up) and wg1d - wg4d (down)
    • Requires WireGuard configs at /etc/wireguard/wgX.conf

    2026-07-01

    LUKS / Full Disk Encryption

    • Added crypt and crypt-lib dracut modules to 99-protocol7.conf
    • Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
    • FDE confirmed working on baremetal (UEFI and BIOS)

    Hardened Malloc

    • Added lainos-hardened-malloc to packages
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so wrappers for the following applications:
      • alacritty(all terminal applications)
      • element(if installed)
      • gnome-keyring-daemon
      • keepassxc
      • kleopatra
      • mpv
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so to /etc/conf.d/tor for the tor daemon
    • Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager

    Kernel Hardening

    • Added kernel parameters to GRUB_CMDLINE_LINUX:
      • init_on_alloc=1 ~ zero memory pages on allocation
      • init_on_free=1 ~ zero memory pages on free
      • page_alloc.shuffle=1 ~ randomize page allocator freelist
    • Updated /etc/sysctl.d/99-lainos-hardening.conf with additional hardening:
      • kernel.yama.ptrace_scope = 1 ~ restrict ptrace to parent processes
      • kernel.kexec_load_disabled = 1 ~ disable kexec
      • kernel.unprivileged_userns_clone = 0 ~ disable unprivileged user namespaces
      • kernel.randomize_va_space = 2 ~ full ASLR
      • kernel.perf_event_paranoid = 3 ~ restrict perf events
      • fs.suid_dumpable = 0 ~ disable setuid core dumps
      • kernel.core_pattern = |/bin/false ~ disable core dumps

    Gnome Keyring

    • Added gnome-keyring to packages
    • Added exec /usr/local/bin/gnome-keyring-daemon --start --components=secrets to skel sway config
    • Provides secrets service backend for Element and other Electron apps

    Calamares / shellprocess-final

    • lainos-ghost-units runlevel registration changed from sysinit to boot
    • doas.conf updated with permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend
    • Added rc-update del for etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install

    Overlay cleanup

    • Removed cgroup-delegate and lainos-ghost-units from airootfs/etc/runlevels/sysinit/

    Known issues

    STILL NOT BTRFS COMPATIBLE YET. Use ext4 for now.

    • Some Nvidia cards have trouble with Sway(Follow Nvidia instructions above^^).

    Get connected

    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud

    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH

    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)

    • Website: https://lainos.net

    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion

    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.01-beta-2 acd6b27e4b

    amnesia released this 2026-07-02 05:45:50 +02:00 | 36 commits to main since this release

    ####INSTALLATION####

    ####layer 01/layer 02 migration and user guide ####

    Please read the lainOS layer 02 wiki links above before installing. INSTALLATION INSTRUCTIONS ARE IN THE WIKI. DO NOT USE BTRFS(it will likely be integrated within the month)

    Changelog

    2026-07-01

    LUKS / Full Disk Encryption(tested ~ operational)

    • Added crypt and crypt-lib dracut modules to 99-protocol7.conf
    • Enables LUKS unlock at boot via dracut's non-systemd crypto hooks
    • FDE is opt-in via Calamares partition module — users select "Encrypt system" during install

    Hardened Malloc

    • Added lainos-hardened-malloc to packages
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so wrappers for the following applications:
      • alacritty
      • element
      • gnome-keyring-daemon
      • keepassxc
      • kleopatra
      • mpv
    • Added LD_PRELOAD=/usr/lib/libhardened_malloc.so to /etc/conf.d/tor for the tor daemon
    • Incompatible applications (mozjemalloc or bwrap/glycin conflicts): librewolf, torbrowser-launcher, signal, thunar, virt-manager

    Kernel Hardening

    • Added kernel parameters to GRUB_CMDLINE_LINUX:
      • init_on_alloc=1 — zero memory pages on allocation
      • init_on_free=1 — zero memory pages on free
      • page_alloc.shuffle=1 — randomize page allocator freelist
    • Updated /etc/sysctl.d/99-lainos-hardening.conf with additional hardening:
      • kernel.yama.ptrace_scope = 1 — restrict ptrace to parent processes
      • kernel.kexec_load_disabled = 1 — disable kexec
      • kernel.unprivileged_userns_clone = 0 — disable unprivileged user namespaces
      • kernel.randomize_va_space = 2 — full ASLR
      • kernel.perf_event_paranoid = 3 — restrict perf events
      • fs.suid_dumpable = 0 — disable setuid core dumps
      • kernel.core_pattern = |/bin/false — disable core dumps

    Gnome Keyring

    • Added gnome-keyring to packages
    • Added exec /usr/local/bin/gnome-keyring-daemon --start --components=secrets to skel sway config
    • Provides secrets service backend for Element and other Electron apps

    Calamares / shellprocess-final

    • lainos-ghost-units runlevel registration changed from sysinit to boot
    • doas.conf updated with permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend
    • Added rc-update del for etmpfiles-dev, etmpfiles-setup, esysusers to clean up unused OpenRC services on install

    Overlay cleanup

    • Removed cgroup-delegate and lainos-ghost-units from airootfs/etc/runlevels/sysinit/

    2026-07-01(build 1)

    doas

    • Added permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend to /etc/doas.conf so wlogout actions work correctly on the installed system without a TTY

    protocol7-core(cleaned up OpenRC boot runlevels)

    • Removed lainos-ghost-units init script and sysinit runlevel symlink from airootfs overlay ~ now correctly handled by the protocol7-core package post_install hook, users on past isos will need to run these commands before updating again:
    • doas rm -f /etc/init.d/lainos-ghost-units
    • doas rm -f /etc/runlevels/sysinit/lainos-ghost-units
    • doas rm -f /etc/runlevels/boot/lainos-ghost-units
    • doas rc-update del cgroup-delegate sysinit
    • doas rc-update del lainos-ghost-units sysinit
    • doas rc-update del etmpfiles-dev sysinit
    • doas rc-update del etmpfiles-setup boot
    • doas rc-update del esysusers boot
    • doas pacman -Syu

    Lid Close / Sleep

    • Added acpid event rule for lid close (/etc/acpi/events/lid-close)
    • Added dynamic lid-close handler (/etc/acpi/handlers/lid-close.sh)
      • Detects sway user dynamically via ps — works for any user on installed system and root on live ISO
      • Launches swaylock --daemonize in the correct Wayland session context
      • Skips su - when sway is running as root (live ISO)
      • Creates XDG_RUNTIME_DIR if not present
      • Suspends via echo mem > /sys/power/state (no elogind/logind required)
    • Added acpid to default runlevel

    Screen Lock

    • Added swaylock config to /root/.config/swaylock/config (live ISO) and /etc/skel/.config/swaylock/config (installed users via Calamares)
      • Uses /usr/share/lainos/wallpapers/layer02-wallpaper.png with scaling=fill

    Wlogout

    • Added lainos-suspend script (/usr/local/bin/lainos-suspend)
      • Suspends via echo mem > /sys/power/state
    • Added wlogout layout to /root/.config/wlogout/layout (live ISO) and /etc/skel/.config/wlogout/layout (installed users via Calamares)
      • Shutdown and reboot via doas openrc-shutdown
      • Suspend via doas lainos-suspend
      • Lock via swaylock -f
      • Logout via swaymsg exit

    Known issues

    STILL NOT BTRFS COMPATIBLE YET. Use ext4 for now.

    • Some Nvidia cards have trouble with Sway(Follow Nvidia instructions above^^).

    Get connected

    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud

    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH

    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)

    • Website: https://lainos.net

    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion

    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.07.01 acd6b27e4b

    amnesia released this 2026-07-01 21:19:26 +02:00 | 36 commits to main since this release

    ####INSTALLATION####

    ####layer 01/layer 02 migration and user guide ####

    Please read the lainOS layer 02 wiki links above before installing. INSTALLATION INSTRUCTIONS ARE IN THE WIKI. DO NOT USE BTRFS(it will likely be integrated within the month)

    Changelog

    2026-07-01

    doas

    • Added permit nopass :wheel cmd openrc-shutdown and permit nopass :wheel cmd lainos-suspend to /etc/doas.conf so wlogout actions work correctly on the installed system without a TTY

    protocol7-core(cleaned up OpenRC boot runlevels)

    • Removed lainos-ghost-units init script and sysinit runlevel symlink from airootfs overlay ~ now correctly handled by the protocol7-core package post_install hook, users on past isos will need to run these commands before updating again:
    • doas rm -f /etc/init.d/lainos-ghost-units
    • doas rm -f /etc/runlevels/sysinit/lainos-ghost-units
    • doas rm -f /etc/runlevels/boot/lainos-ghost-units
    • doas rc-update del cgroup-delegate sysinit
    • doas rc-update del lainos-ghost-units sysinit
    • doas rc-update del etmpfiles-dev sysinit
    • doas rc-update del etmpfiles-setup boot
    • doas rc-update del esysusers boot
    • doas pacman -Syu

    Lid Close / Sleep

    • Added acpid event rule for lid close (/etc/acpi/events/lid-close)
    • Added dynamic lid-close handler (/etc/acpi/handlers/lid-close.sh)
      • Detects sway user dynamically via ps — works for any user on installed system and root on live ISO
      • Launches swaylock --daemonize in the correct Wayland session context
      • Skips su - when sway is running as root (live ISO)
      • Creates XDG_RUNTIME_DIR if not present
      • Suspends via echo mem > /sys/power/state (no elogind/logind required)
    • Added acpid to default runlevel

    Screen Lock

    • Added swaylock config to /root/.config/swaylock/config (live ISO) and /etc/skel/.config/swaylock/config (installed users via Calamares)
      • Uses /usr/share/lainos/wallpapers/layer02-wallpaper.png with scaling=fill

    Wlogout

    • Added lainos-suspend script (/usr/local/bin/lainos-suspend)
      • Suspends via echo mem > /sys/power/state
    • Added wlogout layout to /root/.config/wlogout/layout (live ISO) and /etc/skel/.config/wlogout/layout (installed users via Calamares)
      • Shutdown and reboot via doas openrc-shutdown
      • Suspend via doas lainos-suspend
      • Lock via swaylock -f
      • Logout via swaymsg exit

    Known issues

    STILL NOT BTRFS COMPATIBLE YET. Use ext4 for now.

    • Some Nvidia cards have trouble with Sway(Follow Nvidia instructions above^^).

    Get connected

    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud

    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH

    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)

    • Website: https://lainos.net

    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion

    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads
  • 2026.06.30-beta acd6b27e4b

    amnesia released this 2026-06-30 20:57:52 +02:00 | 36 commits to main since this release

    ####INSTALLATION####

    ####layer 01/layer 02 migration and user guide ####

    Please read the lainOS layer 02 wiki links above before installing. INSTALLATION INSTRUCTIONS ARE IN THE WIKI. DO NOT USE BTRFS(it will likely be integrated within the month)

    Changelog(2026.06.30)(NEW ISO BUILDING, NEEDED TO FIX PROTOCOL7_CORE BUG)

    Replaced wifi utility with new version that uses number selection for network selection instead of tab autocomplete.


    Past changelogs:

    2026.06.29-beta

    Fixed:

    • Fixed torctl and kloak in lainos-utils ~ lainos-utils changelog
    • Default font (Love LetterTW) now applies correctly on fresh install without manual intervention
    • torctl now works correctly on fresh installs ~ tor OpenRC init script and user setup added
    • cgroup-delegate moved to boot runlevel ~ cleaner boot sequence
    • lainOS branding now visible in OpenRC boot string

    Known issues:

    • ext4 only. BTRFS not yet supported.
    • Some Nvidia cards have issues with Sway.

    Usability improved:(2026.06.28)

    • torctl utility fixed(lainos-utils)

    • New and improved hardware auto-detecting wifi script. To use, open a terminal and type wifi. You will be prompted with your available networks. To select, type the first 3 letters, press tab, and hit enter. Then type your network password and you will be connected.

    Core milestone:

    • lainOS layer 02 is now architecturally complete. Pure Arch Linux derivative, no Artix repositories required for openRC packages

    OpenRC:

    • OpenRC now built from upstream source with lainOS branding visible in the boot string
    • OpenRC packages fully self-hosted in protocol_7_repo

    System:

    • sudo replaced with a dummy package(or else it gets pulled in by base-devel). use doas for privilege escalation.
    • Stock Arch mirrorlist restored (/etc/pacman.d/mirrorlist)
    • 5 days daily driver stability confirmed, 3 kernel updates, initramfs rebuilt successfully each time

    Developement:

    • Protocol 7 Core runit and s6 variants have been developed, testing starts soon (protocol7-core-runit, protocol7-core-s6)

    Known issues:

    • ext4 only. BTRFS not yet supported(same as layer 01).
    • Some Nvidia cards have issues with Sway(same as layer 01)
    • Default font currently needs to be changed manually( super+spacbar, gtk-settings, Font: loveletter typewriter)

    ARTIX REPOS ELIMINATED, OPENRC PACKAGES FULLY SELF-HOSTED(2026.06.27):

    LainOS Layer 02 now ships with fully self-hosted OpenRC packages, eliminating the dependency on Artix Linux repositories entirely. All OpenRC init scripts and the OpenRC init system itself are now built and maintained by the LainOS project directly from upstream sources (github.com/OpenRC/openrc and github.com/gentoo/netifrc).
    lainOS layer 02 is now a pure Arch Linux derivative and is architecturally complete. Every package comes from official Arch repos or the lainOS protocol_7_repo, and lainos_repo. No third-party distribution repositories are required.

    The following packages were forked from Artix and rebuilt for lainOS:

    • openrc
    • libeinfo (split from openrc)
    • netifrc
    • dhcpcd-openrc
    • acpid-openrc
    • chrony-openrc
    • dbus-openrc (dummy package)
    • greetd-openrc
    • iwd-openrc
    • nftables-openrc
    • seatd-openrc
    • syslog-ng-openrc

    Added(2026.06.26)

    • BlackArch Repo installation script ~ install in home folder with bash blackarch-repos.sh
    • lainos-utils package ~ System utility scripts pre-installed(a few of these still need to be wired up):
      • torctl ~ OpenRC Tor service manager
      • kloak ~ Keystroke anonymization wrapper
      • wifi ~ Interactive iwd network scanner & connector
      • ani-cli ~ Terminal anime streaming
      • brightness ~ Direct sysfs backlight control
      • virtman ~ virt-manager launcher with libvirt group

    Other Changes

    • Steam and native gaming confirmed working on Protocol 7 (no hiccups or special setup required) . Install with doas pacman -S steam
    • Thumbnail previews added to file explorer
    • Wallpapers moved to repo to keep ISO lean(git clone them with the script in the home folder)
    • protocol7-core updated to version 5.5.3 to fix false positive lainos-dbus-bridge crash reported by OpenRC(it doesn't actually crash). More secure, more reliable compared to v5.4. protocol7-core full changelog

    Known issues

    STILL NOT BTRFS COMPATIBLE YET. Use ext4 for now.

    • Some Nvidia cards have trouble with Sway(Follow Nvidia instructions above^^).

    Get connected

    • LainOS Matrix Chat: https://matrix.to/#/#lainos:catgirl.cloud

    • Discord Server (Discord violates your privacy by spying on you): https://discord.gg/JdMQvkHqwH

    • Onion XMPP Server and Chat: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion + full setup guide at https://lain.rocks (and our anon community lainboard)

    • Website: https://lainos.net

    • Onion Service: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion

    irc.libera.chat ~ #LainOS

    LALL<3

    Downloads