Couch installer v0.2.0 (acceptance prerelease: fresh installs start on alpha .215)
Pre-releaseSuperseded by installer v0.2.1, which installs the same OS image and adds reinstalling without the saved Android enrollment. The published install commands point at v0.2.1.
Couch installer v0.2.0 (draft)
Tag: installer-v0.2.0 · Repository: Couch-OS/couch-installer · Prerelease
This is an acceptance prerelease. It exists so the rebuilt image can be
installed on a real remote and checked. The published install commands still
point at installer-v0.1.1, and they stay there until that install has been
done and has passed.
This release changes what gets installed. The installer program itself is the
same one installer-v0.1.1 shipped — on Linux and macOS the binaries are
byte-for-byte identical. What is new is the operating system image it writes.
What is new for a fresh install
Installing with installer-v0.1.1 put a .170-era image on the remote, from
September 16th. This release installs an image built around Couch
v0.1.0-alpha.20260922.215. For somebody setting up a remote, that means:
It starts on a current Couch. Settings → About will say
v0.1.0-alpha.20260922.215 straight after installing, and Check for updates
will correctly say there is nothing newer. With the old image a brand-new
remote arrived several releases behind and had to update itself before it was
current.
It cannot get stuck in COUCH RECOVERY from the old boot script. The
previous image carried a boot script with the fault that strands a remote on
the COUCH RECOVERY screen after a runtime update fails its health check — the
fault installer-v0.1.1 added a rescue action for. This image carries the
fixed script, so a remote installed from it does not have that fault in the
first place. The rescue action is still here and still works for remotes
installed from older images.
Bluetooth is built in. The Bluetooth packages ship inside the image, so the
Bluetooth switch comes up and turns on without the extra "installing packages"
step older remotes show on first use.
Every remote gets its own identity. The image contains no machine ID; each
remote mints its own on first boot. Two remotes installed from this same image
will not share one.
Nothing about how the installer talks to the remote changes: same write path,
same wire protocol, same installation protocol 1, same saved-enrollment and
backup requirements.
Install
Linux x64 and macOS, from an interactive terminal:
curl --fail --location --proto '=https' --tlsv1.2 \
https://github.com/Couch-OS/couch-installer/releases/download/installer-v0.2.0/install.sh | shWindows x64, from PowerShell:
Invoke-RestMethod 'https://github.com/Couch-OS/couch-installer/releases/download/installer-v0.2.0/install.ps1' | Invoke-ExpressionThese are the commands for this prerelease. The commands published on the
website still fetch installer-v0.1.1 and will keep doing so until this image
is accepted on a remote.
The launcher downloads only the host, terminal and installer.json from this
release, checks each one's byte size and SHA-256 against the values written into
the script, and starts nothing on a mismatch. There is no latest URL and no
fallback to an unverified executable.
What it installs
installer.json is a schema-2 descriptor. It names the installer and the OS
separately:
| Installer version | v0.2.0 |
| Installer source commit | e805aebda718012d060c99040e7e1c84f0301d1a |
| OS version | v0.1.0-alpha.20260922.215 |
| OS source commit | eea577bbfaaa410bed0b1b80216bfe0b32b3dd56 |
| Installation protocol | 1 |
| Device model | sanytron-ha100 |
The OS payload is pinned at its immutable URL in Couch-OS/couch, by byte size
and SHA-256:
https://github.com/Couch-OS/couch/releases/download/v0.1.0-alpha.20260922.215/couch-v0.1.0-alpha.20260922.215-ha100-public-inputs.tar.gz
75312816 bytes
9dc6a34a38dd6f0d7a4510c82f92424b16e543bf6aba2308777de2042c64ee8e
This is a different payload from the one installer-v0.1.0 and
installer-v0.1.1 selected. It is the one thing that changes here.
About the OS image:
- The Couch runtime inside it is the published
.215release — all 27 files
match the signed release manifest byte for byte, checked against the finished
image rather than against a build plan. - The kernel is the signed one from the
v0.1.0-alpha.20260916.168release,
not rebuilt here: kernel source commit81d180fc19ec…,zImage
5a19cd5ffb36…. - The package closure is the retained authenticated 141-package solve
b51d36e9…, resolved offline. - The OS baseline id is unchanged:
ha100-alpine321-ffmpeg612-runtimeboot2. - The image's installer RAM stage was built from installer commit
656a20dc…— that isinstaller-v0.1.1's commit, not this release's. The RAM
stage inside the image and the desktop binaries in this release are versioned
separately and always have been. - The image contains no keys, no saved networks, no vendor files and no
machine ID.
Assets
| Asset | What it is |
|---|---|
install.sh, install.ps1 |
Generated launchers with every asset pin inlined |
installer.json |
Schema-2 release descriptor |
couch-installer-host-…, couch-installer-tui-… |
Native host and terminal UI for Linux x64, universal macOS and Windows x64 |
build-receipts.tar.gz |
Per-platform build receipts: exact commit, target, rustc -vV, cargo -vV, toolchain and sysroot hashes, binary hashes |
couch-installer-source.tar.gz |
Installer corresponding source |
release-provenance.json, SHA256SUMS |
Provenance record and digests for every asset |
Binaries were built by the repository's Build installer binaries workflow,
run 35717638766,
from commit e805aebda718012d060c99040e7e1c84f0301d1a with
rustc 1.98.1 (48a229cea 2026-09-01). The macOS binaries are lipo-combined
x86_64 + arm64 and ad-hoc signed. No binary was built on a developer machine.
The only source change between installer-v0.1.1 and this release is the
VERSION file, and that file is not compiled in — so the Linux and macOS host
and terminal binaries here are byte-for-byte identical to
installer-v0.1.1's. The two Windows binaries differ although their source did
not; that is MSVC build nondeterminism, the same difference seen between
installer-v0.1.0 and installer-v0.1.1.
Corresponding source
couch-installer-source.tar.gz covers this exact installer commit, all four
locked Cargo workspaces with their vendored dependency sources, dependency
notices, and one audited Rust standard-library source component. Its scope is
installer: os_source_covered is false.
The OS image's own corresponding source is published on the Couch OS release
v0.1.0-alpha.20260922.215, as five archives:
-corresponding-source.tar.gz (the Couch project at eea577bb… plus all nine
locked Cargo workspaces), -kernel-source.tar.gz, -busybox-source.tar.gz,
-bluez-source.tar.gz, and -exact-source-archive.tar.gz (the git archive
the build attestation names). The kernel and BusyBox archives are the same
bytes as the ones published on .168, because the kernel and the BusyBox
binary in this image are the same binaries; each archive's receipt names the
exact binary hash that is in this image. The BlueZ archive was collected from
this image's own build directory and is identical to .168's in all 23 source
members — it differs only in a one-sentence documentation edit in its
README.md and in the receipt line recording that file's hash.
Verified
couch-installer-host verify-publicagainst this release's descriptor and the
rebuilt payload, run with this release's macOS host, accepted the archive and
extracted all six public OS inputs with no device access. The extracted
manifest matches the OS identity and every file pin in the build report.- The host accepts installation protocol 1 and refuses 0, 2 and 3.
- This release's macOS host, with no remote attached, reaches the recovery
action's "No remote in Couch recovery is connected" screen through the real
macOS device search, asks for no release configuration, writes nothing and
exits 0. - Every SHA-256 in
installer.json, in both launchers and inSHA256SUMSwas
cross-checked against the actual asset bytes, and each launcher's download
URLs point only at this release's tag. - Each platform's build receipt names commit
e805aebda718012d060c99040e7e1c84f0301d1aand matches the published binary's
size and SHA-256.
Not established by this release
- Physical USB installation acceptance on an HA100. This is the whole point
of the prerelease and the gate before the public commands move. It needs a
full USB reinstall with the saved Android enrollment, not a recovery boot. - Release signatures.
- That every downloadable native binary used the audited Rust source component.
- Frozen Windows launcher acceptance, which
installer-v0.1.0ran against its
real binaries in a Windows ConPTY and this candidate has not repeated. - The image's display font assets were built using slightly older Pillow and
fontTools than the build recipe pins. Regenerating them with the pinned
Pillow 11.3.0 / fontTools 4.60.1 / brotli 1.1.0 is still open. - The retained 141-package closure archive is not yet published as an immutable
asset; it exists only on the build host and one Mac copy. - The Alpine aports and distfiles corresponding-source component was not
collected — no aports or distfiles cache exists on the build host. The OS
source set covers the Couch project, all Cargo dependencies, the kernel,
BusyBox and BlueZ, but not the Alpine package recipes.