Skip to content

Releases: FreeLinX/FreeLinX

FreeLinX base 1.3.2 (stable)

Choose a tag to compare

@Voctl Voctl released this 05 Oct 19:07

FreeLinX base 1.3.2

freelinx-base-x86_64.iso: 311 MB, BIOS and UEFI.
sha256 537e2ae5761727372cbc6fe9fea5f40f25b0da765479a509ddafaa1ab87cc106

What is new

  • The console banner (/etc/motd, /etc/issue) is plain text now, the way
    real systems keep it: a version line, what the session is, what to type.
    No ASCII art. The version line and the live-system sentence keep their
    exact form, so installs and upgrades rewrite them as before.
  • fastfetch prints the FreeLinX X logo with no colors at all: the logo is
    plain characters, key/title/percentage colors are off, the palette bar is
    gone.
  • flxupgrade tells the live session's automounter to step aside and
    unmounts what it holds before e2fsck, the way setup-disk already does.
    Upgrading 1.3.1 to 1.3.2 works; before, it died reporting filesystem
    errors that were not there (the check ran on a mounted filesystem).

Tested

test-ui.sh (74), test-setup-disk.sh, test-destructive.sh (52),
test-banner.sh (11), test-xsetup-qemu.sh BIOS (44) and UEFI (44),
test-upgrade-qemu.sh from 1.3.1 (14). All green.

Quick start

qemu-img create -f qcow2 flx.qcow2 20G
qemu-system-x86_64 -enable-kvm -cpu host -m 4096 -smp 2 \
  -drive file=flx.qcow2,if=virtio,format=qcow2 \
  -cdrom freelinx-base-x86_64.iso -boot d \
  -nic user,model=virtio-net-pci

Run xsetup as root to install. Upgrade a 1.3.1 system by booting this ISO
and running flxupgrade -y as root.

FreeLinX base 1.3.1 (stable)

Choose a tag to compare

@Voctl Voctl released this 04 Oct 19:43

FreeLinX base 1.3.1

freelinx-base-x86_64.iso: 311 MB, BIOS and UEFI.
sha256 7b679892ab70f214af0e6e70c51b1950d65dc2d2529374cf6f7eca8b2bef1669

Quick start

qemu-img create -f qcow2 flx.qcow2 20G
qemu-system-x86_64 -enable-kvm -cpu host -m 4096 -smp 2 \
  -drive file=flx.qcow2,if=virtio,format=qcow2 \
  -cdrom freelinx-base-x86_64.iso -boot d \
  -device VGA,xres=1600,yres=900 -nic user,model=virtio-net-pci

Run xsetup to install. Then boot the disk with the same command, without -cdrom … -boot d.

For a desktop: xpkg install xorg xinit openbox, then startx. Right-click the desktop for the menu.

What changed since 1.3.0

More room in the live session. It can now use 75% of RAM instead of half, so large packages such as Firefox fit in a 4 GB VM.

It builds from git alone. You need clean clones of FreeLinX-base, src, ports and drivers, plus the toolchain release. sh build-base.sh then produces the ISO with no environment variables set, no FreeLinX-desk and no xpkg on the host. What the build fetches, it checks:

  • If the host has no xpkg, the build fetches one from the signed repository and checks its signature and sha256.
  • The C headers come from the musl-dev package (20 MB instead of a 104 MB copy).
  • The NetBSD manual pages are now part of the source tree, so a fresh checkout includes them.
  • The file source comes from the source mirror and is checked by sha256.

README: how to try FreeLinX (QEMU, screen size, USB stick), how to set up a desktop, and how to build it step by step.

Package repository (since 1.3.0; no reinstall needed, just xpkg update && xpkg upgrade)

  • xorg xinit openbox now pulls in everything else: fonts, the st terminal and the keyboard layouts.
  • startx works on FreeLinX's sh. With no ~/.xinitrc it opens openbox with a terminal.
  • openbox has a right-click menu with Terminal, Reconfigure, Restart and Exit.
  • The terminal no longer sometimes fails to appear when the session starts.

Tested

In QEMU/KVM, on this exact ISO:

Test Result
Install, BIOS 44 / 0 (live session: 71 MB RAM)
Install, UEFI 44 / 0 (live session: 72 MB RAM)
Upgrade 1.1.0 → 1.3.1 14 / 0
Unit tests, shellcheck, GitHub Actions all pass
Build from fresh checkouts only 311 MB ISO, 0 GNU

The desktop was tested separately (live ISO + repository): startx brought up openbox and a terminal 8 times out of 8.

Not yet tested on real hardware.

FreeLinX base 1.3.0 (stable)

Choose a tag to compare

@Voctl Voctl released this 04 Oct 16:51

FreeLinX base 1.3.0 — light live system, the real logo

freelinx-base-x86_64.iso — 310 MB, BIOS and UEFI
sha256 3ebad1b5621a136841a3b58e63722a046deaf48504e76a04b97ad77780d683ee

What changed

The live ISO no longer copies the whole system into RAM. Before, a live session used ~680 MB right after boot. Now:

1.2.0 live 1.3.0 live
The system ~280 MB xz image, unpacked into RAM at boot boot/root.sfs (squashfs), read from the medium
Initramfs the whole system 284 KB: flxlive and a static sh
Writes into RAM into a tmpfs overlay (only what changes)
RAM after boot ~680 MB ~60–75 MB

This is how other distributions' live media work.

flxlive is a 46 KB static C program. It:

  1. finds the ISO 9660 volume FREELINX_LIVE (CD, USB stick or disk image);
  2. mounts the squashfs read-only, with a tmpfs overlay on top;
  3. makes the medium available at /media/flx;
  4. hands over to the system's /init.

If anything fails, it says why and gives a shell.

The installed system still runs from its own disk, as in 1.2.0, and uses ~55 MB after boot.

fastfetch shows the FreeLinX X logo, in red and orange.

Upgrading

From 1.0.13 – 1.2.0: boot this ISO on the installed machine and run flxupgrade, then doas xpkg upgrade. Installs from before 1.2.0 are converted to run from their disk.

Tested

QEMU/KVM, on this exact ISO:

Test Result
Install, BIOS: live root is an overlay, live RAM, 13 steps, boot from disk, logins, persistence 44 / 0 (live: 71 MB)
Install, UEFI (OVMF) 44 / 0 (live: 75 MB)
Upgrade 1.1.0 → 1.3.0 14 / 0
Upgrade 1.0.13 → 1.3.0 14 / 0
Unit suites (base and src), shellcheck, GitHub Actions all pass

In the first BIOS run, with four VMs running at once, one check failed: a file written to /etc was not found after the reboot. The re-run on the same ISO passed 44/0, and so did the UEFI run. The cause is not yet known.

Not yet tested on real hardware. eMMC cannot be the install disk yet (its driver is a kernel module).

FreeLinX base 1.2.0 (stable)

Choose a tag to compare

@Voctl Voctl released this 04 Oct 16:05

FreeLinX base 1.2.0 — runs from its disk

The base system is a shell on the console, with xpkg for everything else: Linux 6.18, a NetBSD userland, musl, built with LLVM, and no GNU code.

freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 7369ffa59e4bb1d3d6bd829218fc9070a7ce3bae28ca253702d0bc7288d1a9af

What changed: the installed system runs from its disk, like any other OS

Until 1.1.0, every boot of an installed system unpacked a ~280 MB system image into RAM and kept it there. Now:

1.1.0 1.2.0
How it boots system image unpacked into RAM, disk directories bound over it the kernel mounts the root partition (root=PARTUUID=… ro), no initramfs
RAM used after boot ~650 MB 55 MB
Installing packs the whole system with xz: minutes, and much longer without KVM copies the files to the disk: fast
Root filesystem — ext4, checked by e2fsck at every boot, then mounted read-write
  • Disk layout: ESP (kernel and Limine), BIOS boot, FLX_ROOT (/), FLX_HOME (/home). /etc/fstab names partitions by UUID, and /tmp is in RAM.
  • Rescue shell: the boot-menu entry now works. It mounts the filesystems, starts no services, and gives a root shell.
  • Clean shutdown: / is remounted read-only before power-off.
  • Live ISO: still runs from RAM, as live ISOs do.

Upgrading from 1.0.13 – 1.1.0

Boot this ISO on the installed machine and run flxupgrade. It replaces the system files, puts the new kernel and Limine on the boot partition, and converts the old layout: the old system partition becomes the root partition. Your /etc settings, users, packages and /home stay. Then run doas xpkg upgrade.

Tested

QEMU/KVM, on this exact ISO:

Test Result
Install, BIOS: 13 steps, then boot from disk; root on ext4 read-write, PARTUUID, /tmp tmpfs, logins, persistence 42 / 0
Install, UEFI (OVMF) 42 / 0
Upgrade 1.1.0 → 1.2.0 (converted to disk root): files, passwords, hostname, sshd kept 14 / 0
Upgrade 1.0.13 → 1.2.0 14 / 0
test-ui · setup-disk · destructive · banner 74 · 26 · 52 · 13, 0 failed
src console · flxconsole · mdev.conf; check-nognu 32 · 19 · 24; 0 violations
GitHub Actions passing

Known limitation: an eMMC disk cannot be the root disk yet, because the kernel builds the eMMC driver as a module. Not yet tested on real hardware.

FreeLinX base 1.1.0 (stable)

Choose a tag to compare

@Voctl Voctl released this 04 Oct 14:06

FreeLinX base 1.1.0 — the first stable release

A minimal FreeLinX: a shell on the console, and xpkg for everything else.

  • Linux 6.18, a NetBSD userland, musl, built with LLVM.
  • No GNU code: 589 ELF files checked, 0 failing.

freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 6c84b5a61530bbcfdc8d0b87371525456ea7044f0d568ecbbc442247c937ef49

Install

Boot the ISO and run xsetup as root. Thirteen steps, one question at a time; nothing is erased until you type yes. The installed system asks for a login on every console.

Upgrade from 1.0.13 – 1.0.15

Boot this ISO on the installed machine and run flxupgrade. Only the boot partition is rewritten; /usr, /etc, /var and /home stay. Then run doas xpkg upgrade.

On v1.0.11.1? Reinstall: on that image every console of an installed system was an unauthenticated root shell.

What changed since 1.0.15

This release comes from a full review of the installer and the system scripts.

Security

  • A user created by xsetup or flxadduser was always put in wheel, so they could become root with doas even when "no" was answered. Now only an admin you choose is in wheel.
  • Desktop leftovers that let wheel run some tools as root without a password were removed from doas.conf.
  • The no-GNU check in the src tree had never inspected a single file. It now checks every file and also finds GNU code linked in statically.

Fixes

  • flxupgrade now rewrites Limine's BIOS boot stage. Upgrading a 1.0.13 install (Limine 11.4.1 → 12.9.0) would otherwise have left it unbootable on BIOS.
  • Added passwd: there was no way to change a password after installing.
  • Passwords are asked twice, and a typo asks again instead of locking the account.
  • Hostnames ending in a dot or dash were accepted.
  • The proxy port was never written, and the proxy password was shown while typing.
  • A Wi-Fi passphrase containing " or \ broke the Wi-Fi configuration.
  • TERM is now right on the screen and on a serial line, and the prompt shows the current directory.
  • The live medium is mounted read-only, so the installer cannot erase the stick it booted from.
  • QEMU no longer writes Cloudflare and Google DNS servers.

Smaller and cleaner

  • fastfetch shows the FreeLinX logo.
  • Removed X11 and GTK leftovers.

Testing

  • CI (shellcheck and the unit suites) runs on every push.

Tested

Run in QEMU/KVM on this exact ISO:

Test Result
Install, BIOS: 13 steps, boot from disk, logins, persistence, fastfetch 41 / 0
Install, UEFI (OVMF) 41 / 0
Upgrade 1.0.13 → 1.1.0 (BIOS): files, passwords, hostname, services kept 12 / 0
test-ui · setup-disk · destructive · banner 74 · 26 · 55 · 13, 0 failed
src console · flxconsole · mdev.conf 32 · 19 · 24, 0 failed
GitHub Actions (FreeLinX-base, src) passing

Not yet tested on real hardware. Reports are welcome: https://github.com/FreeLinX/FreeLinX/issues

FreeLinX base 1.0.15

Choose a tag to compare

@Voctl Voctl released this 04 Oct 10:05

FreeLinX base 1.0.15 — stable

A shell on the console and xpkg for everything else: Linux 6.18, a NetBSD userland, musl, LLVM-built, no GNU code.

freelinx-base-x86_64.iso — 286 MB, BIOS and UEFI
sha256 6efe8b4b9795ddbbe136e9ef46a51b046eb5515ca5b45613194eff76a4497149

Install

Boot the ISO and run xsetup as root. It takes 13 steps, one question at a time, and nothing is erased until you type yes. The installed system asks for a login on every console.

What changed since 1.0.14

  • Smaller: 286 MB, down from 307 MB.
    • Removed a 10 MB static library that sat in /bin as openssl.
    • Removed unused static C++ libraries, vim's own test suite, and doom.
    • The kernel is no longer stored twice.
  • Installed systems:
    • The banner no longer says "Live system" after installation.
    • All seven system trees (/usr /etc /var /root /bin /sbin /lib) are mounted from the system partition, so changes to /etc survive a reboot.
    • /dev/null and /dev/tty are usable by every user.
    • The console shows a login prompt again after you log out.
  • Build: README explains how to build the ISO from a fresh clone. The build no longer needs a built desktop. BSD-2-Clause LICENSE added.

Tested

test-xsetup-qemu.sh:

  1. installs with all 13 xsetup steps;
  2. boots the installed disk without the medium;
  3. logs in as the user and as root;
  4. checks hostname, time zone, groups, shell, sshd, ntpd, UUID-pinned partitions, mounted system trees, /dev permissions, the banner and the console;
  5. reboots and checks that files in /home and /etc are still there.
Result
BIOS 39 passed, 0 failed
UEFI (OVMF) 39 passed, 0 failed
test-ui / setup-disk / destructive / banner 59 / 26 / 55 / 13, 0 failed
src console / flxconsole / mdev.conf 32 / 19 / 24, 0 failed
check-nognu 589 ELF files, 0 failing

Not tested on real hardware.

FreeLinX base 1.0.14

Choose a tag to compare

@Voctl Voctl released this 04 Oct 07:38

FreeLinX base 1.0.14

A shell on the console and xpkg for everything else. This is the first base image built entirely from git and the package repository.

freelinx-base-x86_64.iso — 307 MB, BIOS and UEFI
sha256 9feab32996486076eef18fe96c197488fc3e348e6a0285545e57f2f6ff2ad6ac

What changed since 1.0.13

  • Built from FreeLinX/src. The system comes from src/rootfs. The 25 packages base keeps (musl, openssl, dbus, linux, toybox, xpkg, …) are installed by name from the signed package repository. Anyone can now rebuild it with sh build-base.sh; it no longer depends on one machine's desktop build.
  • Package database is back. xpkg upgrade and later installs see the base packages as installed, and the repository key is in /etc/xpkg/keys.
  • One kernel. Linux 6.18.54, from the linux package, with exactly its own modules.
  • Up-to-date integration scripts in the src tree:
    • /init with the persistent FLX_SYS disk model;
    • WiFi password kept off command lines;
    • OpenSSH 10.5p1, curl 8.22, git 2.56.
  • Consoles: an installed system asks for a login on every console, and the prompt comes back after logout. The live medium still opens a root shell.
  • Cleanup: leftover desktop programs removed (dillo, netsurf, openbox helpers).

Tested

test-xsetup-qemu.sh runs all 13 xsetup steps, boots the installed disk without the medium, logs in as the user and as root, checks hostname, time zone, groups, shell, sshd, ntpd, UUID pins and the framebuffer console, then reboots and checks persistence.

  • BIOS: 29 passed, 0 failed
  • UEFI (OVMF): 29 passed, 0 failed

Unit suites: test-ui 59/0, test-setup-disk 26/0, test-destructive 34/0, test-banner 13/0, test-console 30/0. check-nognu (including statically linked GNU code): 0 failing.

Not tested on real hardware. Known: after login, the banner on an installed system still says "Live system".

FreeLinX base 1.0.13

Choose a tag to compare

@Voctl Voctl released this 04 Oct 00:11

FreeLinX base 1.0.13 — security fix for v1.0.11.1

If you installed FreeLinX from v1.0.11.1, reinstall from this image. On v1.0.11.1 every console of an installed system (tty1–tty3 and the serial line) had a root shell without asking for a password, so the root password set by xsetup protected nothing.

freelinx-base-x86_64.iso — 279 MB, BIOS and UEFI
sha256 aac5824f7fa86cd2f0e74edfc3a470408223a6eb9ee14bf73744d3c3c8a703cb

What changed

  • An installed system now asks for a login on every console (getty + login), as 1.0.8–1.0.11 did. The live medium still opens a root shell, as before.
  • If getty or login is missing, the console stays closed rather than giving a shell. Use "Rescue shell" in the boot menu to repair the system.
  • Otherwise the image has the same files as v1.0.11.1: the 1.0.12 installer, where root password and user creation work, and the new boot text.

Tested

test-xsetup-qemu.sh runs all 13 xsetup steps, boots the installed disk without the medium, logs in as the user and as root, checks hostname, time zone, groups, shell, sshd, ntpd, UUID pins and the framebuffer console, then reboots and checks persistence.

  • BIOS: 29 passed, 0 failed
  • UEFI (OVMF): 29 passed, 0 failed

check-nognu: 0 failing. Not tested on real hardware.

FreeLinX v1.0.11.1 (Improvment)

Choose a tag to compare

@KananMajidzada KananMajidzada released this 03 Oct 22:25

Superseded by v1.0.13 — security fix. On an installed system every console of this release opens a root shell without a password. Do not install from this image; reinstall from 1.0.13.

FreeLinX base 1.0.11-1
A shell on the console and xpkg for everything else. No desktop.
freelinx-base-x86_64.iso 281 MB, boots on BIOS
sha256 e6ce3d382eba04cb859aeb57e9e8a38a57dfc7ed572bffa5411b49c9ea633767
What works

  • It boots and shows the boot. The whole kernel log is on the screen, then the screen clears and shows the banner and a prompt. 1.0.11 booted with quiet loglevel=2, which prints nothing at all on a successful boot.
  • Ctrl-C works at the console. 1.0.11 printed mksh: No controlling tty on every boot and Ctrl-C reached nothing, because the shell had no controlling terminal. It does now.
  • The installer can set a password. Step 4 of thirteen. On 1.0.11 it called flxhash, which exists nowhere — not in the repositories, not on the image — so it stopped on its first line.
  • The installer can create a user. Step 9, same cause.
  • The other eleven steps are unchanged from 1.0.11.
    What was tested
    On a real QEMU boot, driving the guest over the serial line:

flxpasswd -e root:! → root:$6$Z--$IPl/… in /etc/shadow
flxuseradd creates the account, uid 1000, in wheel, shell /bin/mksh
flxhash no longer called from any installer file
screen cleared banner, prompt in /root, no mksh warning
stty present, so the password prompt does not echo
Test suites, all passing:
Suite Result
test-ui.sh 59 / 0
test-setup-disk.sh 26 / 0
test-destructive.sh 34 / 0
test-banner.sh 13 / 0
test-flxpart.sh (ports) 87 / 0
check-nognu.sh 0 violations, 355 ELF files
Not tested: test-xsetup-qemu.sh, which drives all thirteen steps and then boots the installed disk. Real hardware. UEFI — this host has no OVMF, so every boot here was BIOS.
What changed
The installer. setup-passwd, setup-user and lib/ui.sh called flxhash. They now use flxpasswd, which is the program that exists and is on the image, and which takes the password on stdin so it never appears in ps. Both binaries are now on the image, where 1.0.11 did not have them.
The console. console=tty0 is now last on every command line, so /dev/console is the screen rather than a serial line that may have nothing plugged into it. quiet loglevel=2 is gone.
The console shell. /sbin/flxconsole replaces the two services that drew the console before. It clears the screen before the banner, gives the shell a controlling terminal with setsid -c, and starts it in /root instead of the service directory. It takes the shell from /etc/flx-shell and shows /etc/motd.
The banner. Written by build-base.sh rather than edited out of the desktop's Plan 9 Rio banner, and the same bytes go to /etc/issue and /etc/motd. 1.0.11's /etc/issue had doubled backslashes, so the logo drew with a double stroke over SSH.
Three build blockers. base could not be built from a fresh clone: the version stamp never matched the desktop banner, a check tested a run script that no longer exists, and a console service exec'd /usr/bin/getty and /usr/libexec/toybox/login, one of which does not exist.
What this ISO is
It is the 1.0.11 image with those changes put in — limine.conf, three installer files, two binaries, the banner and the console service. It is not a build of this repository.

  • Its kernel is the 1.0.11 kernel, Linux 6.18.54. This repository's kernel is 6.6.157.
  • mkrootfs.sh did not run, so the package set is 1.0.11's.
  • The banner says 1.0.11, because VERSION was not changed inside the image.
  • test-xsetup-qemu.sh was not run against it.

FreeLinX base 1.0.11

Choose a tag to compare

@Voctl Voctl released this 03 Oct 07:52

FreeLinX base 1.0.11

freelinx-base-x86_64.iso   279 MB   BIOS and UEFI
sha256  dd79fc63fe09f6bda2cd333bcc1ee41251dff722bffeda5c000eb925bf4c1205

xsetup is the installer again. flxinstall is no longer on the base image.

xsetup is a manual installer: thirteen steps, one question at a time, and an
interrupted install carries on where it stopped (xsetup --status,
xsetup --reset STEP).

setup-keymap  setup-hostname  setup-interfaces  setup-passwd  setup-timezone
setup-proxy   setup-ntp       setup-apkrepos    setup-user    setup-sshd
setup-disk    setup-lbu       setup-apkcache

What had to change so that every step does what it says:

  • setup-disk installs what FreeLinX boots: the system image on the ESP
    (the running system, with everything the earlier steps set), persistent
    /usr /etc /var /root /bin /sbin /lib on FLX_SYS, /home on FLX_HOME, both
    pinned by UUID, and Limine for UEFI and BIOS. Before, it copied the system to
    an ext4 root that /init never switched to, so the installed disk booted back
    into the live system. The "data" mode is gone, because /init never mounted
    its partition.
  • setup-passwd and setup-user hid nothing: passwords were echoed on the
    screen. They are not shown now; stty is on the image for that. Both used
    flxpasswd and flxuseradd, which the image does not have. New users get mksh, wheel (doas) and the device
    groups, and their home moves onto FLX_HOME.
  • setup-user no longer rewrites /etc/doas.conf, which dropped the
    image's other rules.
  • setup-interfaces writes where the system reads: a static address or an
    ignored interface goes into /etc/dhcpcd.conf, and Wi-Fi goes to the
    networks the flxwifi service connects to at boot (0600). It used to write
    /etc/network/interfaces, which nothing reads.
  • setup-sshd and setup-ntp have the service definitions they enable,
    and sshd has its config, privilege-separation user and /var/empty.
  • setup-timezone writes /etc/TZ, which the system reads.
  • setup-lbu and setup-apkcache say what is kept and where, instead of
    asking for a disk to put configuration on that nothing used.

Tested in QEMU, BIOS and UEFI: test-xsetup-qemu.sh answers all 13 steps, then
boots the disk with the medium removed and checks it:

  • the user and root log in, the user has mksh and wheel
  • the hostname and the time zone are the ones chosen
  • sshd and ntpd run, the partitions are pinned, the console is a framebuffer
  • a file in the user's home survives another reboot

All release notes: RELEASE-NOTES.md