-
2026-09-10-beta layer 03: Circuit VIII Pre-release
released this
2026-09-10 21:09:20 +02:00 | 4 commits to main since this releaseAll bare-metal testing completed.
This release configuration has been daily driven for a week and is faring well. Includes the
lainos-utils,lainos-dns-mediation, andopenrc-isolationsubsystems(from layer 02).Does not yet include the
lainos-apparmorsubsystem from layer 02, this will be included in repo this week and pulled in by portage viaemerge --sync/@worldPlease report bugs to the lainOS discord, matrix space, or XMPP server at the bottom of this page.
Fixes in this release: CONFIG_RANDSTRUCT re-enabled in updated kernel(linux 7.2.4), lainOS branding added to OpenRC. Fixed missing entries in shadow file.
Notable Updates: Latest kernel(linux 7.2.4). Librewolf updated to v155. LLVM and cmake updated to latest versions.
Connect to the internet on layer 03
WiFi is off by default to preserve privacy. To connect:
## Once wifi on has been run, scan with wscan wifi on && wscanWant WiFi to autostart on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable.
USB automount is enabled withusb-automount enable.Automate all of this with
quickstart.shon first boot:## Run this command once and you won't need to run it again: ./quickstart.sh ## The above script runs these commands: wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
DNS Mediation Architecture
DNS Modes Quick Reference
Note: if using a VPN, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns private # Tor DNSPort only lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
First Commands
A few things worth running right after your first boot, before anything else.
1. Sync the package tree
doas emerge --syncThe Gentoo and GURU package trees are not bundled in the ISO to keep it smaller ~ this pulls a fresh copy. Run this before installing anything new.
2. Update your system(this may or may not be time consuming)
doas emerge -uDN @worldBrings every installed package up to date against the tree you just synced.
- To check what will be updated, run:
doas emerge -pvuDN @world3. Check your environment
doas emerge --infoPrints your profile, USE flags, and build environment. Useful for your own sanity check.
4. Install something
doas emerge <package-name>5. Clean up unneeded packages
doas emerge --depcleanAfter updating, some packages may no longer be required by anything else on your system ~ old library versions, build-time-only dependencies that are no longer needed, packages you removed from your own package list.
depcleanfinds and removes them.Always review the list it prints before it removes anything. It's a real, safe mechanism (it won't touch a package still required by something else, or anything in your world set), but it's still worth reading what's about to go, especially the first few times you run it.
Run this after every
emerge -uDN @world, not just once.
Updating your kernel
A routine
emerge -uDN @worldupdates the kernel source (sys-kernel/gentoo-sources) but does not rebuild or activate a new kernel. Without a separate step, a kernel security fix could sit unapplied indefinitely even after a normal system update.Use
lainos-kernel-update(included inapp-lainos/lainos-utils) whenever you want to build and switch to the latest available kernel:doas lainos-kernel-updateWhat it does:
- Compares your currently running kernel against the newest available source
- Reuses your currently running kernel's own config as the baseline (via
/proc/config.gz, falling back to/boot/config-*if needed), so any local hardware tweaks you've made survive the update - Backs up your previous kernel and initramfs to
/boot/backup/before touching anything - Builds the kernel and its modules together, in one pass, from the same source tree
- Regenerates your initramfs and GRUB configuration
- Removes the kernel source afterward to save space (it re-fetches automatically the next time you run the tool)
Reboot to activate the new kernel after it finishes. If anything goes wrong, your previous kernel and initramfs are still in
/boot/backup/.Note: this is a real compile from source, not a binary package install ~ expect it to take a while depending on your hardware.
Gentoo Handbook
Get connected
- Matrix: https://matrix.to/#/#lainos:catgirl.cloud
- Discord: https://discord.gg/JdMQvkHqwH (Discord spies on you)
- Onion XMPP: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion
- Website: https://lainos.net
- Onion: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
- IRC: irc.libera.chat #LainOS
LALL<3
Downloads