Repository navigation
Releases: FreeLinX/FreeLinX
Release list
FreeLinX base 1.3.2 (stable)
FreeLinX base 1.3.2
freelinx-base-x86_64.iso: 311 MB, BIOS and UEFI.
sha256 537e2ae5761727372cbc6fe9fea5f40f25b0da765479a509ddafaa1ab87cc106
What is new
- The console banner (
/etc/motd,/etc/issue) is plain text now, the way
real systems keep it: a version line, what the session is, what to type.
No ASCII art. The version line and the live-system sentence keep their
exact form, so installs and upgrades rewrite them as before. fastfetchprints the FreeLinX X logo with no colors at all: the logo is
plain characters, key/title/percentage colors are off, the palette bar is
gone.flxupgradetells the live session's automounter to step aside and
unmounts what it holds beforee2fsck, the waysetup-diskalready does.
Upgrading 1.3.1 to 1.3.2 works; before, it died reporting filesystem
errors that were not there (the check ran on a mounted filesystem).
Tested
test-ui.sh (74), test-setup-disk.sh, test-destructive.sh (52),
test-banner.sh (11), test-xsetup-qemu.sh BIOS (44) and UEFI (44),
test-upgrade-qemu.sh from 1.3.1 (14). All green.
Quick start
qemu-img create -f qcow2 flx.qcow2 20G
qemu-system-x86_64 -enable-kvm -cpu host -m 4096 -smp 2 \
-drive file=flx.qcow2,if=virtio,format=qcow2 \
-cdrom freelinx-base-x86_64.iso -boot d \
-nic user,model=virtio-net-pciRun xsetup as root to install. Upgrade a 1.3.1 system by booting this ISO
and running flxupgrade -y as root.
FreeLinX base 1.3.1 (stable)
FreeLinX base 1.3.1
freelinx-base-x86_64.iso: 311 MB, BIOS and UEFI.
sha256 7b679892ab70f214af0e6e70c51b1950d65dc2d2529374cf6f7eca8b2bef1669
Quick start
qemu-img create -f qcow2 flx.qcow2 20G
qemu-system-x86_64 -enable-kvm -cpu host -m 4096 -smp 2 \
-drive file=flx.qcow2,if=virtio,format=qcow2 \
-cdrom freelinx-base-x86_64.iso -boot d \
-device VGA,xres=1600,yres=900 -nic user,model=virtio-net-pciRun xsetup to install. Then boot the disk with the same command, without -cdrom … -boot d.
For a desktop: xpkg install xorg xinit openbox, then startx. Right-click the desktop for the menu.
What changed since 1.3.0
More room in the live session. It can now use 75% of RAM instead of half, so large packages such as Firefox fit in a 4 GB VM.
It builds from git alone. You need clean clones of FreeLinX-base, src, ports and drivers, plus the toolchain release. sh build-base.sh then produces the ISO with no environment variables set, no FreeLinX-desk and no xpkg on the host. What the build fetches, it checks:
- If the host has no
xpkg, the build fetches one from the signed repository and checks its signature and sha256. - The C headers come from the
musl-devpackage (20 MB instead of a 104 MB copy). - The NetBSD manual pages are now part of the source tree, so a fresh checkout includes them.
- The
filesource comes from the source mirror and is checked by sha256.
README: how to try FreeLinX (QEMU, screen size, USB stick), how to set up a desktop, and how to build it step by step.
Package repository (since 1.3.0; no reinstall needed, just xpkg update && xpkg upgrade)
xorg xinit openboxnow pulls in everything else: fonts, thestterminal and the keyboard layouts.startxworks on FreeLinX'ssh. With no~/.xinitrcit opens openbox with a terminal.- openbox has a right-click menu with Terminal, Reconfigure, Restart and Exit.
- The terminal no longer sometimes fails to appear when the session starts.
Tested
In QEMU/KVM, on this exact ISO:
| Test | Result |
|---|---|
| Install, BIOS | 44 / 0 (live session: 71 MB RAM) |
| Install, UEFI | 44 / 0 (live session: 72 MB RAM) |
| Upgrade 1.1.0 → 1.3.1 | 14 / 0 |
| Unit tests, shellcheck, GitHub Actions | all pass |
| Build from fresh checkouts only | 311 MB ISO, 0 GNU |
The desktop was tested separately (live ISO + repository): startx brought up openbox and a terminal 8 times out of 8.
Not yet tested on real hardware.
FreeLinX base 1.3.0 (stable)
FreeLinX base 1.3.0 — light live system, the real logo
freelinx-base-x86_64.iso — 310 MB, BIOS and UEFI
sha256 3ebad1b5621a136841a3b58e63722a046deaf48504e76a04b97ad77780d683ee
What changed
The live ISO no longer copies the whole system into RAM. Before, a live session used ~680 MB right after boot. Now:
| 1.2.0 live | 1.3.0 live | |
|---|---|---|
| The system | ~280 MB xz image, unpacked into RAM at boot | boot/root.sfs (squashfs), read from the medium |
| Initramfs | the whole system | 284 KB: flxlive and a static sh |
| Writes | into RAM | into a tmpfs overlay (only what changes) |
| RAM after boot | ~680 MB | ~60–75 MB |
This is how other distributions' live media work.
flxlive is a 46 KB static C program. It:
- finds the ISO 9660 volume
FREELINX_LIVE(CD, USB stick or disk image); - mounts the squashfs read-only, with a tmpfs overlay on top;
- makes the medium available at
/media/flx; - hands over to the system's
/init.
If anything fails, it says why and gives a shell.
The installed system still runs from its own disk, as in 1.2.0, and uses ~55 MB after boot.
fastfetch shows the FreeLinX X logo, in red and orange.
Upgrading
From 1.0.13 – 1.2.0: boot this ISO on the installed machine and run flxupgrade, then doas xpkg upgrade. Installs from before 1.2.0 are converted to run from their disk.
Tested
QEMU/KVM, on this exact ISO:
| Test | Result |
|---|---|
| Install, BIOS: live root is an overlay, live RAM, 13 steps, boot from disk, logins, persistence | 44 / 0 (live: 71 MB) |
| Install, UEFI (OVMF) | 44 / 0 (live: 75 MB) |
| Upgrade 1.1.0 → 1.3.0 | 14 / 0 |
| Upgrade 1.0.13 → 1.3.0 | 14 / 0 |
| Unit suites (base and src), shellcheck, GitHub Actions | all pass |
In the first BIOS run, with four VMs running at once, one check failed: a file written to /etc was not found after the reboot. The re-run on the same ISO passed 44/0, and so did the UEFI run. The cause is not yet known.
Not yet tested on real hardware. eMMC cannot be the install disk yet (its driver is a kernel module).
FreeLinX base 1.2.0 (stable)
FreeLinX base 1.2.0 — runs from its disk
The base system is a shell on the console, with xpkg for everything else: Linux 6.18, a NetBSD userland, musl, built with LLVM, and no GNU code.
freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 7369ffa59e4bb1d3d6bd829218fc9070a7ce3bae28ca253702d0bc7288d1a9af
What changed: the installed system runs from its disk, like any other OS
Until 1.1.0, every boot of an installed system unpacked a ~280 MB system image into RAM and kept it there. Now:
| 1.1.0 | 1.2.0 | |
|---|---|---|
| How it boots | system image unpacked into RAM, disk directories bound over it | the kernel mounts the root partition (root=PARTUUID=… ro), no initramfs |
| RAM used after boot | ~650 MB | 55 MB |
| Installing | packs the whole system with xz: minutes, and much longer without KVM | copies the files to the disk: fast |
| Root filesystem | — | ext4, checked by e2fsck at every boot, then mounted read-write |
- Disk layout: ESP (kernel and Limine), BIOS boot,
FLX_ROOT(/),FLX_HOME(/home)./etc/fstabnames partitions by UUID, and/tmpis in RAM. - Rescue shell: the boot-menu entry now works. It mounts the filesystems, starts no services, and gives a root shell.
- Clean shutdown:
/is remounted read-only before power-off. - Live ISO: still runs from RAM, as live ISOs do.
Upgrading from 1.0.13 – 1.1.0
Boot this ISO on the installed machine and run flxupgrade. It replaces the system files, puts the new kernel and Limine on the boot partition, and converts the old layout: the old system partition becomes the root partition. Your /etc settings, users, packages and /home stay. Then run doas xpkg upgrade.
Tested
QEMU/KVM, on this exact ISO:
| Test | Result |
|---|---|
| Install, BIOS: 13 steps, then boot from disk; root on ext4 read-write, PARTUUID, /tmp tmpfs, logins, persistence | 42 / 0 |
| Install, UEFI (OVMF) | 42 / 0 |
| Upgrade 1.1.0 → 1.2.0 (converted to disk root): files, passwords, hostname, sshd kept | 14 / 0 |
| Upgrade 1.0.13 → 1.2.0 | 14 / 0 |
| test-ui · setup-disk · destructive · banner | 74 · 26 · 52 · 13, 0 failed |
| src console · flxconsole · mdev.conf; check-nognu | 32 · 19 · 24; 0 violations |
| GitHub Actions | passing |
Known limitation: an eMMC disk cannot be the root disk yet, because the kernel builds the eMMC driver as a module. Not yet tested on real hardware.
FreeLinX base 1.1.0 (stable)
FreeLinX base 1.1.0 — the first stable release
A minimal FreeLinX: a shell on the console, and xpkg for everything else.
- Linux 6.18, a NetBSD userland, musl, built with LLVM.
- No GNU code: 589 ELF files checked, 0 failing.
freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 6c84b5a61530bbcfdc8d0b87371525456ea7044f0d568ecbbc442247c937ef49
Install
Boot the ISO and run xsetup as root. Thirteen steps, one question at a time; nothing is erased until you type yes. The installed system asks for a login on every console.
Upgrade from 1.0.13 – 1.0.15
Boot this ISO on the installed machine and run flxupgrade. Only the boot partition is rewritten; /usr, /etc, /var and /home stay. Then run doas xpkg upgrade.
On v1.0.11.1? Reinstall: on that image every console of an installed system was an unauthenticated root shell.
What changed since 1.0.15
This release comes from a full review of the installer and the system scripts.
Security
- A user created by
xsetuporflxadduserwas always put inwheel, so they could become root withdoaseven when "no" was answered. Now only an admin you choose is inwheel. - Desktop leftovers that let
wheelrun some tools as root without a password were removed fromdoas.conf. - The no-GNU check in the src tree had never inspected a single file. It now checks every file and also finds GNU code linked in statically.
Fixes
flxupgradenow rewrites Limine's BIOS boot stage. Upgrading a 1.0.13 install (Limine 11.4.1 → 12.9.0) would otherwise have left it unbootable on BIOS.- Added
passwd: there was no way to change a password after installing. - Passwords are asked twice, and a typo asks again instead of locking the account.
- Hostnames ending in a dot or dash were accepted.
- The proxy port was never written, and the proxy password was shown while typing.
- A Wi-Fi passphrase containing
"or\broke the Wi-Fi configuration. TERMis now right on the screen and on a serial line, and the prompt shows the current directory.- The live medium is mounted read-only, so the installer cannot erase the stick it booted from.
- QEMU no longer writes Cloudflare and Google DNS servers.
Smaller and cleaner
fastfetchshows the FreeLinX logo.- Removed X11 and GTK leftovers.
Testing
- CI (shellcheck and the unit suites) runs on every push.
Tested
Run in QEMU/KVM on this exact ISO:
| Test | Result |
|---|---|
| Install, BIOS: 13 steps, boot from disk, logins, persistence, fastfetch | 41 / 0 |
| Install, UEFI (OVMF) | 41 / 0 |
| Upgrade 1.0.13 → 1.1.0 (BIOS): files, passwords, hostname, services kept | 12 / 0 |
| test-ui · setup-disk · destructive · banner | 74 · 26 · 55 · 13, 0 failed |
| src console · flxconsole · mdev.conf | 32 · 19 · 24, 0 failed |
| GitHub Actions (FreeLinX-base, src) | passing |
Not yet tested on real hardware. Reports are welcome: https://github.com/FreeLinX/FreeLinX/issues
FreeLinX base 1.0.15
FreeLinX base 1.0.15 — stable
A shell on the console and xpkg for everything else: Linux 6.18, a NetBSD userland, musl, LLVM-built, no GNU code.
freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 6efe8b4b9795ddbbe136e9ef46a51b046eb5515ca5b45613194eff76a4497149
Install
Boot the ISO and run xsetup as root. It takes 13 steps, one question at a time, and nothing is erased until you type yes. The installed system asks for a login on every console.
What changed since 1.0.14
- Smaller: 286 MB, down from 307 MB.
- Removed a 10 MB static library that sat in
/binasopenssl. - Removed unused static C++ libraries, vim's own test suite, and doom.
- The kernel is no longer stored twice.
- Removed a 10 MB static library that sat in
- Installed systems:
- The banner no longer says "Live system" after installation.
- All seven system trees (
/usr /etc /var /root /bin /sbin /lib) are mounted from the system partition, so changes to/etcsurvive a reboot. /dev/nulland/dev/ttyare usable by every user.- The console shows a login prompt again after you log out.
- Build: README explains how to build the ISO from a fresh clone. The build no longer needs a built desktop. BSD-2-Clause LICENSE added.
Tested
test-xsetup-qemu.sh:
- installs with all 13 xsetup steps;
- boots the installed disk without the medium;
- logs in as the user and as root;
- checks hostname, time zone, groups, shell, sshd, ntpd, UUID-pinned partitions, mounted system trees, /dev permissions, the banner and the console;
- reboots and checks that files in /home and /etc are still there.
| Result | |
|---|---|
| BIOS | 39 passed, 0 failed |
| UEFI (OVMF) | 39 passed, 0 failed |
| test-ui / setup-disk / destructive / banner | 59 / 26 / 55 / 13, 0 failed |
| src console / flxconsole / mdev.conf | 32 / 19 / 24, 0 failed |
| check-nognu | 589 ELF files, 0 failing |
Not tested on real hardware.
FreeLinX base 1.0.14
FreeLinX base 1.0.14
A shell on the console and xpkg for everything else. This is the first base image built entirely from git and the package repository.
freelinx-base-x86_64.iso — 307 MB, BIOS and UEFI
sha256 9feab32996486076eef18fe96c197488fc3e348e6a0285545e57f2f6ff2ad6ac
What changed since 1.0.13
- Built from FreeLinX/src. The system comes from
src/rootfs. The 25 packages base keeps (musl, openssl, dbus, linux, toybox, xpkg, …) are installed by name from the signed package repository. Anyone can now rebuild it withsh build-base.sh; it no longer depends on one machine's desktop build. - Package database is back.
xpkg upgradeand later installs see the base packages as installed, and the repository key is in/etc/xpkg/keys. - One kernel. Linux 6.18.54, from the linux package, with exactly its own modules.
- Up-to-date integration scripts in the src tree:
/initwith the persistent FLX_SYS disk model;- WiFi password kept off command lines;
- OpenSSH 10.5p1, curl 8.22, git 2.56.
- Consoles: an installed system asks for a login on every console, and the prompt comes back after logout. The live medium still opens a root shell.
- Cleanup: leftover desktop programs removed (dillo, netsurf, openbox helpers).
Tested
test-xsetup-qemu.sh runs all 13 xsetup steps, boots the installed disk without the medium, logs in as the user and as root, checks hostname, time zone, groups, shell, sshd, ntpd, UUID pins and the framebuffer console, then reboots and checks persistence.
- BIOS: 29 passed, 0 failed
- UEFI (OVMF): 29 passed, 0 failed
Unit suites: test-ui 59/0, test-setup-disk 26/0, test-destructive 34/0, test-banner 13/0, test-console 30/0. check-nognu (including statically linked GNU code): 0 failing.
Not tested on real hardware. Known: after login, the banner on an installed system still says "Live system".
FreeLinX base 1.0.13
FreeLinX base 1.0.13 — security fix for v1.0.11.1
If you installed FreeLinX from v1.0.11.1, reinstall from this image. On v1.0.11.1 every console of an installed system (tty1–tty3 and the serial line) had a root shell without asking for a password, so the root password set by xsetup protected nothing.
freelinx-base-x86_64.iso — 279 MB, BIOS and UEFI
sha256 aac5824f7fa86cd2f0e74edfc3a470408223a6eb9ee14bf73744d3c3c8a703cb
What changed
- An installed system now asks for a login on every console (getty + login), as 1.0.8–1.0.11 did. The live medium still opens a root shell, as before.
- If getty or login is missing, the console stays closed rather than giving a shell. Use "Rescue shell" in the boot menu to repair the system.
- Otherwise the image has the same files as v1.0.11.1: the 1.0.12 installer, where root password and user creation work, and the new boot text.
Tested
test-xsetup-qemu.sh runs all 13 xsetup steps, boots the installed disk without the medium, logs in as the user and as root, checks hostname, time zone, groups, shell, sshd, ntpd, UUID pins and the framebuffer console, then reboots and checks persistence.
- BIOS: 29 passed, 0 failed
- UEFI (OVMF): 29 passed, 0 failed
check-nognu: 0 failing. Not tested on real hardware.
FreeLinX v1.0.11.1 (Improvment)
Superseded by v1.0.13 — security fix. On an installed system every console of this release opens a root shell without a password. Do not install from this image; reinstall from 1.0.13.
FreeLinX base 1.0.11-1
A shell on the console and xpkg for everything else. No desktop.
freelinx-base-x86_64.iso 281 MB, boots on BIOS
sha256 e6ce3d382eba04cb859aeb57e9e8a38a57dfc7ed572bffa5411b49c9ea633767
What works
- It boots and shows the boot. The whole kernel log is on the screen, then the screen clears and shows the banner and a prompt. 1.0.11 booted with quiet loglevel=2, which prints nothing at all on a successful boot.
- Ctrl-C works at the console. 1.0.11 printed mksh: No controlling tty on every boot and Ctrl-C reached nothing, because the shell had no controlling terminal. It does now.
- The installer can set a password. Step 4 of thirteen. On 1.0.11 it called flxhash, which exists nowhere — not in the repositories, not on the image — so it stopped on its first line.
- The installer can create a user. Step 9, same cause.
- The other eleven steps are unchanged from 1.0.11.
What was tested
On a real QEMU boot, driving the guest over the serial line:
flxpasswd -e root:! → root:$6$Z--$IPl/… in /etc/shadow
flxuseradd creates the account, uid 1000, in wheel, shell /bin/mksh
flxhash no longer called from any installer file
screen cleared banner, prompt in /root, no mksh warning
stty present, so the password prompt does not echo
Test suites, all passing:
Suite Result
test-ui.sh 59 / 0
test-setup-disk.sh 26 / 0
test-destructive.sh 34 / 0
test-banner.sh 13 / 0
test-flxpart.sh (ports) 87 / 0
check-nognu.sh 0 violations, 355 ELF files
Not tested: test-xsetup-qemu.sh, which drives all thirteen steps and then boots the installed disk. Real hardware. UEFI — this host has no OVMF, so every boot here was BIOS.
What changed
The installer. setup-passwd, setup-user and lib/ui.sh called flxhash. They now use flxpasswd, which is the program that exists and is on the image, and which takes the password on stdin so it never appears in ps. Both binaries are now on the image, where 1.0.11 did not have them.
The console. console=tty0 is now last on every command line, so /dev/console is the screen rather than a serial line that may have nothing plugged into it. quiet loglevel=2 is gone.
The console shell. /sbin/flxconsole replaces the two services that drew the console before. It clears the screen before the banner, gives the shell a controlling terminal with setsid -c, and starts it in /root instead of the service directory. It takes the shell from /etc/flx-shell and shows /etc/motd.
The banner. Written by build-base.sh rather than edited out of the desktop's Plan 9 Rio banner, and the same bytes go to /etc/issue and /etc/motd. 1.0.11's /etc/issue had doubled backslashes, so the logo drew with a double stroke over SSH.
Three build blockers. base could not be built from a fresh clone: the version stamp never matched the desktop banner, a check tested a run script that no longer exists, and a console service exec'd /usr/bin/getty and /usr/libexec/toybox/login, one of which does not exist.
What this ISO is
It is the 1.0.11 image with those changes put in — limine.conf, three installer files, two binaries, the banner and the console service. It is not a build of this repository.
- Its kernel is the 1.0.11 kernel, Linux 6.18.54. This repository's kernel is 6.6.157.
- mkrootfs.sh did not run, so the package set is 1.0.11's.
- The banner says 1.0.11, because VERSION was not changed inside the image.
- test-xsetup-qemu.sh was not run against it.
FreeLinX base 1.0.11
FreeLinX base 1.0.11
freelinx-base-x86_64.iso 279 MB BIOS and UEFI
sha256 dd79fc63fe09f6bda2cd333bcc1ee41251dff722bffeda5c000eb925bf4c1205
xsetup is the installer again. flxinstall is no longer on the base image.
xsetup is a manual installer: thirteen steps, one question at a time, and an
interrupted install carries on where it stopped (xsetup --status,
xsetup --reset STEP).
setup-keymap setup-hostname setup-interfaces setup-passwd setup-timezone
setup-proxy setup-ntp setup-apkrepos setup-user setup-sshd
setup-disk setup-lbu setup-apkcache
What had to change so that every step does what it says:
- setup-disk installs what FreeLinX boots: the system image on the ESP
(the running system, with everything the earlier steps set), persistent
/usr /etc /var /root /bin /sbin /libon FLX_SYS,/homeon FLX_HOME, both
pinned by UUID, and Limine for UEFI and BIOS. Before, it copied the system to
an ext4 root that/initnever switched to, so the installed disk booted back
into the live system. The "data" mode is gone, because/initnever mounted
its partition. - setup-passwd and setup-user hid nothing: passwords were echoed on the
screen. They are not shown now;sttyis on the image for that. Both used
flxpasswdandflxuseradd, which the image does not have. New users get mksh, wheel (doas) and the device
groups, and their home moves onto FLX_HOME. - setup-user no longer rewrites
/etc/doas.conf, which dropped the
image's other rules. - setup-interfaces writes where the system reads: a static address or an
ignored interface goes into/etc/dhcpcd.conf, and Wi-Fi goes to the
networks the flxwifi service connects to at boot (0600). It used to write
/etc/network/interfaces, which nothing reads. - setup-sshd and setup-ntp have the service definitions they enable,
and sshd has its config, privilege-separation user and/var/empty. - setup-timezone writes
/etc/TZ, which the system reads. - setup-lbu and setup-apkcache say what is kept and where, instead of
asking for a disk to put configuration on that nothing used.
Tested in QEMU, BIOS and UEFI: test-xsetup-qemu.sh answers all 13 steps, then
boots the disk with the medium removed and checks it:
- the user and root log in, the user has mksh and wheel
- the hostname and the time zone are the ones chosen
- sshd and ntpd run, the partitions are pinned, the console is a framebuffer
- a file in the user's home survives another reboot
All release notes: RELEASE-NOTES.md