-
2026.09.22-beta layer 03: Circuit VIII Pre-release
released this
2026-09-22 20:44:12 +02:00 | 2 commits to main since this releaselayer 03 quickstart guide
This is likely the last beta release. layer 03 stable will be released 2026.09.24
Please report bugs to the lainOS discord, matrix space, or XMPP server at the bottom of this page.
Notable Updates:
- USB automount support via udisks enabled
- Bluetooth support added to kernel, bluetooth setup script in lainos-utils(directions below)
- Enabled
sync-openpgp-key-refreshfor repo sync - Enabled GPG commit signing for cryptographic verification of
lainos-overlayrepo - Git-tracked repo syncronization
- New custom Gentoo hardened stage 3 build
- Kernel audio modules and volume keybinds added
- LUKS FDE fully integrated and operational
- OpenRC 0.63.4 ==> OpenRC 0.64
- Latest kernel ~ linux 7.2.7
- Librewolf v155.0.1-1 ==> v156.0-1
Connect to the internet on layer 03
WiFi is off by default to preserve privacy. To connect:
## Once wifi on has been run, scan with wscan wifi on && wscanWant WiFi to autostart on future boots instead?
wifi-autostart enable.
WiFi autoconnect is also disabled to preserve privacy, toggle it on withwifi-autoconnect enable.
USB automount is enabled withusb-automount enable.Automate all of this with
quickstart.shon first boot:## Run this command once and you won't need to run it again: doas ./quickstart.sh ## The above script runs these commands: wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
lainos-dns-mediationDNS Modes Quick Reference
Note: if using a VPN, it must be turned on before activating encrypted mode.
lainos-dns plaintext # Plaintext fallbacks (1.1.1.1, 9.9.9.9) lainos-dns encrypted # Encrypted DoT via unbound + dnscrypt-proxy lainos-dns private # Tor DNSPort only lainos-dns status # Show current mode and proxy state private-mode on # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode) private-mode off # Restore previous mode (plaintext or encrypted)
First Commands
Screen Brightness(bind your own brightness keys)
brightness 15 # maximum brightness brightness 5 # low brightness brightness 0 # screen offBluetooth Setup (Opt-in)
Bluetooth is disabled by default to minimize the attack surface and prevent MAC-based tracking. To enable it, use the new
bluetoothutility:1. Run the setup script:
bluetooth setupThis installs the BlueZ stack, configures kernel module autoloading, adds your user to the
plugdevgroup, and enables the OpenRC service.2. Apply group permissions:
You must log out and log back in (or restart your Sway session viawlogout) for theplugdevgroup change to take effect.3. Manage the radio:
To maintain privacy when not actively using Bluetooth devices, hardware-block the radio:bluetooth off # Stops the service and hardware-blocks the radio bluetooth on # Unblocks the radio and starts the service bluetooth status # Shows OpenRC, rfkill, and kernel module statusA few things worth running right after your first boot, before anything else.
1. Sync the package tree
doas emerge --syncThe Gentoo and GURU package trees are not bundled in the ISO to keep it smaller ~ this pulls a fresh copy. Run this before installing anything new.
2. Update your system(this may or may not be time consuming)
doas emerge -uDN @worldBrings every installed package up to date against the tree you just synced.
- To check what will be updated, run:
doas emerge -pvuDN @world3. Check your environment
doas emerge --infoPrints your profile, USE flags, and build environment. Useful for your own sanity check.
4. Install something
doas emerge <package-name>5. Clean up unneeded packages
doas emerge --depcleanAfter updating, some packages may no longer be required by anything else on your system ~ old library versions, build-time-only dependencies that are no longer needed, packages you removed from your own package list.
depcleanfinds and removes them.Always review the list it prints before it removes anything. It's a real, safe mechanism (it won't touch a package still required by something else, or anything in your world set), but it's still worth reading what's about to go, especially the first few times you run it.
Run this after every
emerge -uDN @world, not just once.
Updating your kernel
A routine
emerge -uDN @worldupdates the kernel source (sys-kernel/gentoo-sources) but does not rebuild or activate a new kernel. Without a separate step, a kernel security fix could sit unapplied indefinitely even after a normal system update.Use
lainos-kernel-update(included inapp-lainos/lainos-utils) whenever you want to build and switch to the latest available kernel:doas lainos-kernel-updateWhat it does:
- Compares your currently running kernel against the newest available source
- Reuses your currently running kernel's own config as the baseline (via
/proc/config.gz, falling back to/boot/config-*if needed), so any local hardware tweaks you've made survive the update - Backs up your previous kernel and initramfs to
/boot/backup/before touching anything - Builds the kernel and its modules together, in one pass, from the same source tree
- Regenerates your initramfs and GRUB configuration
- Removes the kernel source afterward to save space (it re-fetches automatically the next time you run the tool)
Reboot to activate the new kernel after it finishes. If anything goes wrong, your previous kernel and initramfs are still in
/boot/backup/.Note: this is a real compile from source, not a binary package install ~ expect it to take a while depending on your hardware.
Gentoo Handbook
Get connected
- Matrix: https://matrix.to/#/#lainos:catgirl.cloud
- Discord: https://discord.gg/JdMQvkHqwH (Discord spies on you)
- Onion XMPP: private-chat-c75bebbc-50f3-447d-811f-41f83de11811@conference.glcuf4hcwbm3lt6grg7jfwwus7sqpuojozfsnbzzcsf7vbm2jcfqckid.onion
- Website: https://lainos.net
- Onion: http://lainos3cbhrlsc4qyzu6o7jwhvnvakdtohcc46ds5aohdagakddftbid.onion
- IRC: irc.libera.chat #LainOS
LALL<3
Downloads