Skip to content

Releases: ShadowfetchLinux/shadowfetch-linux

Shadowfetch Linux 3.5.0 "Umbra" - Fire and Ice Workbench

Choose a tag to compare

@ShadowfetchLinux ShadowfetchLinux released this 28 Aug 10:36

Shadowfetch Linux 3.5.0 "Umbra" - Fire and Ice Workbench

Shadowfetch Linux 3.5.0 turns the Fire and Ice identity into a practical operating model for production work. Fire starts connected and throughput-oriented; Ice starts agent sessions with no network. The new Element Workbench creates private, consequence-aware environments for software, AI, operations, and creative work without silently adding a model, cloud account, credential, or publishing right.

What is new

  • Element Workbench: Software Studio, AI Lab, Production Ops, and Creative AI show storage, network, account, accelerator, and package consequences before one signed transaction creates a private project with agent rules, provenance, tests, runbooks, and receipts.
  • Firebreak agent boundaries: project-only writes, stripped known-secret variables, an element-aware network default, read-only system scope, and visible launch receipts.
  • Optional AI and coding tools: Buzz remains the consent-driven local-model workspace. Codex, Claude Code, Grok Build, and Cursor Agent are independent, digest-verified choices with their own native sign-in. No model weights or cloud credentials are bundled.
  • Recovery-safe changes: Phoenix and Fireproof wrap profile installation, updates, and recovery with checkpoints, simulation, explicit confirmation, failure receipts, and tested retry paths.
  • Refined Fire and Ice desktop: current menus, setup flow, Workbench surfaces, installer summaries, and 1366x768/1920x1080 layouts.

Tested release

  • Fresh hybrid BIOS Fire and UEFI Ice installations booted from disk.
  • All 15 required visual frames passed at 1366x768 and 1920x1080.
  • A 2,709-second concurrent stress run completed with zero failures, including 214 rootless-container cycles and 239 Workbench/health probes.
  • The signed APT repository contains 16 binary packages from 14 signed source packages.
  • The CycloneDX 1.5 SBOM records 3,350 components.
  • The reproducible QA bundle records 58 evidence inputs.

Download and verify

  • ISO: shadowfetch-3.5.0-amd64.iso
  • Size: 3980310528 bytes
  • SHA-256: 2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995
  • Signing fingerprint: 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1
  • Exact tested source commit: d27e204b0dc929c57980a9cfb2a5541c0b39cbc3
  • Evidence bundle SHA-256: 69a57b09fc8c32369210ceef47290e9386c7b4c9033755a4ef66ba263aa8d009

Verification sidecars, the signing key, SBOM, package manifest, dossier, and QA evidence bundle are attached to this release and available from the official download page. Installation and signature instructions are on the verification page.

The dossier and release-facts-3.5.0.json intentionally preserve the prepublication evidence snapshot. publication-3.5.0.log records the final live publication state and is bound to the completed acceptance manifest by SHA-256.

Known boundaries

  • Secure Boot is not Microsoft-signed; disable Secure Boot or use the documented enrollment path.
  • VM validation covered Plasma, GLX, Vulkan initialization, and exact layouts through Mesa llvmpipe, not physical GPU performance.
  • No multi-gigabyte Buzz model download or inference run was repeated for 3.5.0; model acquisition remains an explicit post-install action.
  • Historical releases remain on Archive.org. No Archive.org mirror is claimed for 3.5.0.

Full details are in RELEASE-3.5.0.md.

Shadowfetch Linux 3.0.0 «Umbra» — Backfire

Choose a tag to compare

@ShadowfetchLinux ShadowfetchLinux released this 26 Aug 04:34

Shadowfetch Linux 3.0.0 «Umbra» — "Backfire"

The agent-safe local-AI workstation. The first desktop OS where autonomous coding agents are contained, observed, and reversible by default.

Download

New in 3.0 — the Fireline agent-safety system

  • Firebreak (shadowfetch-firebreak) — run any coding agent (Claude Code, Codex CLI, Cursor, Grok Build, Aider) full-auto inside a bubblewrap sandbox: system read-only, only your project writable, optional --net none, and API keys stripped from the agent environment. A checkpoint is taken first.
  • Agent Checkpoints (shadowfetch-checkpoint) — snapshot / diff / undo one ~/Workspaces project; undo everything an agent did with one command.
  • Shadowfetch MCP suite (shadowfetch-mcp) — four signed, dependency-free MCP servers (passport, phoenix, checkpoint, fs) so an agent can call a checkpoint before it touches anything.
  • AI Ignition (shadowfetch-ai-ignition) — reads your VRAM and recommends an Apache-2.0 model that actually fits.
  • shadowfetch-hardware — offline firmware diagnoser for silent Wi-Fi/Bluetooth failures.

Carried forward from 2.1.5: Shadowfetch Guide + private System Passport, Phoenix restore points, Fireproof simulate-first updates, optional loopback-only Buzz, signed ISO + APT, zero telemetry, the full creative stack.

Base: Debian testing · KDE Plasma 6 · BIOS + UEFI.

QA: BIOS+UEFI boot, a clean UEFI Btrfs install that cold-boots from disk, a full CPU/memory/IO stress run with zero failed services, and the Fireline containment suite — all against this exact ISO.

Upgrading from 2.1.5? Use sudo apt update && shadowfetch-update — Fireproof takes a Phoenix snapshot before and after, so the upgrade is rollback-able. On a fresh major version, taking a manual Phoenix Point first is never a bad idea.

Shadowfetch Linux 2.1.5 «Umbra» — Fire Edition

Choose a tag to compare

@ShadowfetchLinux ShadowfetchLinux released this 20 Aug 13:59

Shadowfetch Linux 2.1.5 «Umbra» — Fire Edition

The Linux desktop that can explain itself. Before you install, it proves what works; after you install, it helps fix what doesn't.

Download

What's new

  • Shadowfetch Guide + private System Passport — a deterministic, read-only, on-device check of graphics, networking, audio, firmware, memory, storage, recovery readiness, and local-AI capacity. Available from the live Ignition screen and as the first Control Center section. Its allowlisted schema omits host identity, serials, PCI-slot, and filesystem identifiers, and it exports a redacted HTML/JSON report.
  • Buzz stays the single optional local-AI workspace, loopback-only by default, now guarded against the WebKitGTK DMA-BUF freeze on Plasma Wayland. No model is bundled; downloads are consent-gated.
  • Optional verified coding agents at first-run setup — OpenAI Codex CLI, Claude Code, xAI Grok Build, Cursor Agent — unchecked by default, pinned and verified, with no bundled credentials.
  • Verified in-place upgrade from 2.1.4 via the signed APT repository (sudo apt update && shadowfetch-update); Phoenix rollback on separate-/boot Btrfs fixed and re-tested.

Base: Debian testing · Desktop: KDE Plasma 6 · Firmware: BIOS + UEFI.

Every required prepublication case in qa/2.1.5/acceptance.json passed against this exact ISO.