• 2026.10.02 4f7cea5bbc

    amnesia released this 2026-10-03 00:02:57 +02:00 | 2 commits to main since this release

    layer 03 quickstart guide

    First layer 03 stable release

    Please report bugs to the lainOS discord, matrix space, or XMPP server at the bottom of this page.

    Notable Updates:

    • Latest kernel ~ linux 7.2.8
    • OpenRC 0.64 ==> OpenRC 0.64.1
    • Librewolf v156.0.1-1 ==> v157.0-1
    • Steam autoconfig script available for testing(work in progress)
    • USB automount support via udisks enabled
    • Bluetooth support added to kernel, bluetooth setup script in lainos-utils(directions below)
    • Enabled sync-openpgp-key-refresh for repo sync
    • Enabled GPG commit signing for cryptographic verification of lainos-overlay repo
    • Git-tracked repo syncronization
    • Custom Gentoo hardened stage 3 build
    • LUKS FDE fully integrated and operational

    Connect to the internet on layer 03

    WiFi is off by default to preserve privacy. To connect:

    ## Once wifi on has been run, scan with wscan
    
    wifi on && wscan
    

    Want WiFi to autostart on future boots instead? wifi-autostart enable.
    WiFi autoconnect is also disabled to preserve privacy, toggle it on with wifi-autoconnect enable.
    USB automount is enabled with usb-automount enable.

    Automate all of this with quickstart.sh on first boot:

    ## Run this command once and you won't need to run it again:
    doas ./quickstart.sh
    
    ## The above script runs these commands:
    wifi on && wifi-autostart enable && wifi-autoconnect enable && usb-automount enable && wscan
    

    lainos-dns-mediation

    DNS Modes Quick Reference

    Note: if using a VPN, it must be turned on before activating encrypted mode.

    lainos-dns plaintext    # Plaintext fallbacks (1.1.1.1, 9.9.9.9)
    lainos-dns encrypted    # Encrypted DoT via unbound + dnscrypt-proxy
    lainos-dns private      # Tor DNSPort only
    lainos-dns status       # Show current mode and proxy state
    
    
    private-mode on         # Tor DNSPort + Snowflake + sdwdate(NTP time-sync over TOR) (saves previous mode)
    private-mode off        # Restore previous mode (plaintext or encrypted)
    

    First Commands

    Screen Brightness(bind your own brightness keys)

    brightness 15     # maximum brightness
    brightness 5      # low brightness
    brightness 0      # screen off
    

    Bluetooth Setup (Opt-in)

    Bluetooth is disabled by default to minimize the attack surface and prevent MAC-based tracking. To enable it, use the new bluetooth utility:

    1. Run the setup script:

    bluetooth setup
    

    This installs the BlueZ stack, configures kernel module autoloading, adds your user to the plugdev group, and enables the OpenRC service.

    2. Apply group permissions:
    You must log out and log back in (or restart your Sway session via wlogout) for the plugdev group change to take effect.

    3. Manage the radio:
    To maintain privacy when not actively using Bluetooth devices, hardware-block the radio:

    bluetooth off    # Stops the service and hardware-blocks the radio
    bluetooth on     # Unblocks the radio and starts the service
    bluetooth status # Shows OpenRC, rfkill, and kernel module status
    

    A few things worth running right after your first boot, before anything else.

    1. Sync the package tree

    doas emerge --sync
    

    The Gentoo and GURU package trees are not bundled in the ISO to keep it smaller ~ this pulls a fresh copy. Run this before installing anything new.

    2. Update your system(this may or may not be time consuming)

    doas emerge -uDN @world
    

    Brings every installed package up to date against the tree you just synced.

    • To check what will be updated, run:
    doas emerge -pvuDN @world
    

    3. Check your environment

    doas emerge --info
    

    Prints your profile, USE flags, and build environment. Useful for your own sanity check.

    4. Install something

    doas emerge <package-name>
    

    5. Clean up unneeded packages

    doas emerge --depclean
    

    After updating, some packages may no longer be required by anything else on your system ~ old library versions, build-time-only dependencies that are no longer needed, packages you removed from your own package list. depclean finds and removes them.

    Always review the list it prints before it removes anything. It's a real, safe mechanism (it won't touch a package still required by something else, or anything in your world set), but it's still worth reading what's about to go, especially the first few times you run it.

    Run this after every emerge -uDN @world, not just once.


    Updating your kernel

    A routine emerge -uDN @world updates the kernel source (sys-kernel/gentoo-sources) but does not rebuild or activate a new kernel. Without a separate step, a kernel security fix could sit unapplied indefinitely even after a normal system update.

    Use lainos-kernel-update (included in app-lainos/lainos-utils) whenever you want to build and switch to the latest available kernel:

    doas lainos-kernel-update
    

    What it does:

    • Compares your currently running kernel against the newest available source
    • Reuses your currently running kernel's own config as the baseline (via /proc/config.gz, falling back to /boot/config-* if needed), so any local hardware tweaks you've made survive the update
    • Backs up your previous kernel and initramfs to /boot/backup/ before touching anything
    • Builds the kernel and its modules together, in one pass, from the same source tree
    • Regenerates your initramfs and GRUB configuration
    • Removes the kernel source afterward to save space (it re-fetches automatically the next time you run the tool)

    Reboot to activate the new kernel after it finishes. If anything goes wrong, your previous kernel and initramfs are still in /boot/backup/.

    Note: this is a real compile from source, not a binary package install ~ expect it to take a while depending on your hardware.

    Gentoo Handbook


    Get connected

    LALL<3


    Downloads