• 2026.09.03-alpha 0a79995645

    amnesia released this 2026-09-04 05:16:54 +02:00 | 7 commits to main since this release

    BIOS/libreboot bare-metal installation test completed.

    Awaiting UEFI bare-metal boot/installation test.

    This release is currently being daily driven on bare-metal with BIOS/libreboot, and is awaiting bare-metal installation testing with UEFI. Includes the lainos-dns-mediation and lainos-utils subsystems(from layer 02). Does not yet include the openrc-isolation and lainos-apparmor subsystems(also from layer 02; these will be included with the beta release later this week, and via portage sync/update for alpha users).

    Please report bugs to the lainOS discord or matrix space at the bottom of this page.


    Connect to the internet on layer 03

    WiFi is off by default to preserve privacy. To connect:

    ## Once wifi on has been run, scan with wscan
    
    wifi on && wscan
    

    Want WiFi to autostart on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable.
    USB automount is enabled with usb-automount enable.

    Automate all of this with quickstart.sh on first boot:

    ## Run this command once and you won't need to run it again:
    ./quickstart.sh
    
    ## The above script runs these commands:
    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
    

    DNS Mediation Architecture

    DNS Modes Quick Reference

    Note: if using a VPN, it must be turned on before activating encrypted mode.

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns private      # Tor DNSPort only
    lainos-dns status       # Show current mode and proxy state
    
    
    private-mode on         # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode)
    private-mode off        # Restore previous mode (plaintext or encrypted)
    

    First Commands

    A few things worth running right after your first boot, before anything else.

    1. Sync the package tree

    doas emerge --sync
    

    The Gentoo and GURU package trees are not bundled in the ISO to keep it smaller ~ this pulls a fresh copy. Run this before installing anything new.

    2. Update your system(this may or may not be time consuming)

    doas emerge -uDN @world
    

    Brings every installed package up to date against the tree you just synced.

    3. Check your environment

    doas emerge --info
    

    Prints your profile, USE flags, and build environment. Useful for your own sanity check.

    4. Install something

    doas emerge <package-name>
    

    5. Clean up unneeded packages

    doas emerge --depclean
    

    After updating, some packages may no longer be required by anything else on your system ~ old library versions, build-time-only dependencies that are no longer needed, packages you removed from your own package list. depclean finds and removes them.

    Always review the list it prints before it removes anything. It's a real, safe mechanism (it won't touch a package still required by something else, or anything in your world set), but it's still worth reading what's about to go, especially the first few times you run it.

    Run this after every emerge -uDN @world, not just once.


    Updating your kernel

    A routine emerge -uDN @world updates the kernel source (sys-kernel/gentoo-sources) but does not rebuild or activate a new kernel. Without a separate step, a kernel security fix could sit unapplied indefinitely even after a normal system update.

    Use lainos-kernel-update (included in app-lainos/lainos-utils) whenever you want to build and switch to the latest available kernel:

    doas lainos-kernel-update
    

    What it does:

    • Compares your currently running kernel against the newest available source
    • Reuses your currently running kernel's own config as the baseline (via /proc/config.gz, falling back to /boot/config-* if needed), so any local hardware tweaks you've made survive the update
    • Backs up your previous kernel and initramfs to /boot/backup/ before touching anything
    • Builds the kernel and its modules together, in one pass, from the same source tree ~ this matters specifically because of CONFIG_RANDSTRUCT: a kernel and its modules must come from the same build, or modules will fail to load
    • Regenerates your initramfs and GRUB configuration
    • Removes the kernel source afterward to save space (it re-fetches automatically the next time you run the tool)

    Reboot to activate the new kernel after it finishes. If anything goes wrong, your previous kernel and initramfs are still in /boot/backup/.

    Note: this is a real compile from source, not a binary package install ~ expect it to take a while depending on your hardware.

    Gentoo Handbook


    Get connected

    LALL<3


    Downloads