Skip to content

Shadowfetch Linux 3.0.0 «Umbra» — Backfire

Choose a tag to compare

@ShadowfetchLinux ShadowfetchLinux released this 26 Aug 04:34
· 17 commits to main since this release

Shadowfetch Linux 3.0.0 «Umbra» — "Backfire"

The agent-safe local-AI workstation. The first desktop OS where autonomous coding agents are contained, observed, and reversible by default.

Download

New in 3.0 — the Fireline agent-safety system

  • Firebreak (shadowfetch-firebreak) — run any coding agent (Claude Code, Codex CLI, Cursor, Grok Build, Aider) full-auto inside a bubblewrap sandbox: system read-only, only your project writable, optional --net none, and API keys stripped from the agent environment. A checkpoint is taken first.
  • Agent Checkpoints (shadowfetch-checkpoint) — snapshot / diff / undo one ~/Workspaces project; undo everything an agent did with one command.
  • Shadowfetch MCP suite (shadowfetch-mcp) — four signed, dependency-free MCP servers (passport, phoenix, checkpoint, fs) so an agent can call a checkpoint before it touches anything.
  • AI Ignition (shadowfetch-ai-ignition) — reads your VRAM and recommends an Apache-2.0 model that actually fits.
  • shadowfetch-hardware — offline firmware diagnoser for silent Wi-Fi/Bluetooth failures.

Carried forward from 2.1.5: Shadowfetch Guide + private System Passport, Phoenix restore points, Fireproof simulate-first updates, optional loopback-only Buzz, signed ISO + APT, zero telemetry, the full creative stack.

Base: Debian testing · KDE Plasma 6 · BIOS + UEFI.

QA: BIOS+UEFI boot, a clean UEFI Btrfs install that cold-boots from disk, a full CPU/memory/IO stress run with zero failed services, and the Fireline containment suite — all against this exact ISO.

Upgrading from 2.1.5? Use sudo apt update && shadowfetch-update — Fireproof takes a Phoenix snapshot before and after, so the upgrade is rollback-able. On a fresh major version, taking a manual Phoenix Point first is never a bad idea.