Releases: Shadowfetchapps/shadowfetch-linux
Release list
Shadowfetch Linux 5.0.1 (Umbra) - update
Shadowfetch Linux 5.0.1 — update for 5.0
5.0.1 is an APT update for installed Shadowfetch Linux 5.0 and 4.1 systems. There is no new ISO: new installs use the 5.0.0 ISO and then update.
How to update
From 4.1 or 5.0.0, use apt for this update:
sudo apt update
sudo apt full-upgradeDon't use fireproof update or Control Center's Software page for this one: the older Fireproof can stop partway when it installs a new Fireproof. From 5.0.1 on, fireproof update is safe again. Log out and back in (or restart) afterwards.
If an earlier update already stopped partway: if apt says the lock is held by fireproofd, run sudo systemctl kill --signal=KILL fireproofd.service (or sudo systemctl reboot -i); then sudo dpkg --configure -a, sudo apt full-upgrade, sudo apt install shadowfetch-desktop shadowfetch-creative-base, and restart.
What's fixed
- ShadowCode 1.0.1 — the window no longer grows each time it opens on Wayland, and the first window fits small screens.
- Fireproof — updating Fireproof itself no longer stops the update partway; and an update never removes packages you didn't ask to remove. During a Debian testing library transition it holds the affected updates back and says why, instead of removing the desktop metapackages or apps such as Krita and Kdenlive.
- Mission Control — no more "database is busy" for reads under heavy disk load (Stop is saved even when the database is busy); missions created in the same second run in order; a held mission says why it is waiting.
- Live USB — the package-list refresh after login is turned off on future live images (a 5.0.0 USB stick keeps it; see the known issues).
Full notes: RELEASE-5.0.1.md · Known issues: https://www.shadowfetchlinux.org/known-issues
Verification
The signed repository (key 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1) serves every Shadowfetch package at 5.0.1-1 and ShadowCode 1.0.1. A 5.0.0 → 5.0.1 upgrade passed 19/19 checks in a VM (nothing removed, user data kept); SRC-01, PKG-01, UPGRADE-01 and DURABLE-01 pass, and MISSION-01 is waived for the paid-account code mission only (qa/5.0.1/acceptance.json).
Shadowfetch Linux 5.0.0 (Umbra) - ShadowCode
Shadowfetch Linux 5.0.0 — ShadowCode
One Harness. All Models. Shadowfetch Linux 5.0 is rebuilt around ShadowCode 1.0, a preinstalled desktop coding agent that connects your vendor CLIs and local models in one place. Codename Umbra; the APT suite stays umbra, so 4.1 systems upgrade in place.
Download and verify
| ISO | shadowfetch-5.0.0-amd64.iso — 4,085,778,432 bytes |
| SHA-256 | 2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21 |
| Signature | shadowfetch-5.0.0-amd64.iso.asc, key 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1 |
| Boot | BIOS and UEFI, amd64 |
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso.sha256
curl -LO https://www.shadowfetch.com/linux/download/shadowfetch-5.0.0-amd64.iso.asc
sha256sum -c shadowfetch-5.0.0-amd64.iso.sha256
gpg --verify shadowfetch-5.0.0-amd64.iso.asc shadowfetch-5.0.0-amd64.isoThe ISO is larger than GitHub's 2 GB asset limit, so it is served from the Shadowfetch download server; this release carries its checksum, signature, SBOM, manifests and the QA evidence bundle.
What's new
- ShadowCode 1.0, preinstalled — connect Codex, Claude Code and other CLIs, OpenRouter or on-device models from Settings › Accounts.
- One gold-and-steel look. Fire and Ice are gone; the old offline Ice behaviour lives on as a separate setting,
shadowfetch-agent-network online|offline. - Welcome offers only Grok Bot, Hermes and OpenClaw (each optional, latest versions, Hermes and OpenClaw installed into your home folder), then hands off to ShadowCode.
- Removed: Buzz,
shadowfetch-codex,shadowfetch-code-agent(ShadowCode connects the CLIs itself). - New platform: Debian testing snapshot 20260929, Linux 7.2.6, Plasma 6.7.4, systemd 262, Mesa 26.1.6.
- Saving service keys no longer prompts for a keyring password; Mission Control fixes (accurate report provenance, undo after an interrupted mission); build secrets scrubbed from the image.
- Shadowfetch's own packages are now GPL-3.0-or-later.
Full notes: RELEASE-5.0.0.md
Upgrading from 4.1
sudo apt update
sudo apt full-upgradeUse apt, not fireproof update, for now: it can stop partway when it installs a new Fireproof (every 4.1 → 5.0 upgrade does), and its plan can currently remove the desktop metapackages during a Debian testing transition. If an update already stopped partway: if apt says fireproofd holds the lock, run sudo systemctl kill --signal=KILL fireproofd.service (or sudo systemctl reboot -i); then sudo dpkg --configure -a, sudo apt full-upgrade, sudo apt install shadowfetch-desktop shadowfetch-creative-base, and restart.
Then log out and back in once, check shadowfetch-agent-network status, and connect your services in ShadowCode. Scripts that called shadowfetch-element, shadowfetch-codex or shadowfetch-code-agent need updating.
Known issues (fixes in 5.0.1)
- Upgrade with
sudo apt full-upgrade, notfireproof update, for now (see above). - ShadowCode's window grows each time it opens on Wayland, and on 1366×768 screens the first window is too large. Workaround: maximize it. Fixed in ShadowCode 1.0.1.
- "database is busy" in Mission Control under very heavy disk load while a mission finishes a step. Retry after a few seconds.
- Live USB only: KDE's update notifier refreshes package lists ~5 minutes after login (~200 MB download, ~350 MB RAM). Stay offline or run
systemctl --user stop app-org.kde.discover.notifier@autostart.service. - Security advisory: 4.x ISOs shipped a shared DKMS module-signing key. 5.0 removes it;
shadowfetch-doctorflags it on upgraded machines — see the release notes.
Acceptance
18 required pre-publication cases are recorded against this exact ISO: 12 pass, 6 waived by the release owner with written reasons (vendor-account cases for Grok Bot and paid code missions, the upgrade harness's recovery leg, and the ShadowCode soak and 45-minute stress cases that the known issues above explain). Details and evidence are in evidence-bundle-5.0.0.tar.gz; host paths in that evidence were redacted before publication, logged in qa/5.0.0/evidence-redactions.md.
Shadowfetch Linux 4.1.0 (Umbra) - Egress and Syscall Filters
Shadowfetch Linux 4.1.0 — Egress and Syscall Filters
Codename: Umbra (permanent — the APT suite stays umbra). Signing fingerprint
unchanged: 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1. The subtitle
names the two filters this release adds; it does not claim the sandbox as a
whole is now enforced, because the credential broker and the blast-radius
classifier are built and wired to nothing.
Status: NOT RELEASED. This file is a release contract, not a claim that 4.1.0
has shipped. 4.0.0 (2026-09-06) remains the current public release until an
image built from this source passes make iso-gate and the required acceptance
cases carry evidence bound to it. See Release state at the end for exactly
what stands in the way. There is no press release for 4.1.0, by decision.
- Version: 4.1.0
- Codename / repository suite:
umbra - Architecture: amd64; desktop KDE Plasma 6; installer Calamares
- Source branch:
release/4.0.0— the checkout path is named for 4.0.0 and is
not the version - Source commit the shipped image is built from:
78ee38ceac0ff989d596e5a5e0b97aac17c3b936
(tree163b434ebbd572522c781cc92ff48f90f7fda01c), on branchrelease/4.0.0.
The prior candidate wasa9e8cf21; this commit adds the mission-worker
idle-spin fix (see "Fixed after the first cut" below), so the ISO was rebuilt. - ISO:
shadowfetch-4.1.0-amd64.iso, 3,980,670,976 bytes, SHA-256
e19e96302f97e94d5284f8fbef181c9b0e49ca7b746afe5e66e4bc6d5c551f25, detached
signatureshadowfetch-4.1.0-amd64.iso.ascverifying against
8F13CE1535EE1F4A2916A1F73C5C900B7BE80CA1. The signed APTInReleasewas
re-signed in this build (Valid-Until 2027-03-09).
Fixed after the first cut: the mission worker idle CPU spin
A first 4.1.0 candidate (40cb0969) was cut and its acceptance cases proven,
then QA's under-load screenshot caught the shipped shadowfetch-missions
service worker holding ~100% of one CPU core continuously on an idle queue. The
Phase-3 event-driven worker loop inotify-watches the mission state directory,
and in WAL mode the worker's own queue reads open and close the database's
-wal/-shm sidecars in that same directory -- create/modify/close-write
events that Wakeup.wait() found readable immediately, every iteration, so the
worker woke itself on its own reads and never blocked. The loop was new since
4.0.0, so 4.1.0 would have been the first release to ship it. The fix drains the
inotify descriptor before select(), so self-generated events are discarded and
the worker blocks for a genuinely new external change; a regression test pins
both halves (a self-event must not wake it; an external write must). On a fresh
install of the corrected image the idle worker holds ~0.4% CPU and a new mission
is still picked up in under a second. The whole packages -> repo -> ISO chain was
rebuilt (candidate e19e9630) and every artifact-bound acceptance case
re-proven against the new digest.
Why 4.1.0 and not 4.0.1
Since 4.0.0 the sandbox gained controls that were previously declared and
applied by nothing, and several surfaces stopped saying things that were not
true. Both of those change behaviour that working setups depend on. Seven
changes will break something that worked on 4.0.0. They are first in this
document because a person whose cron job stops running deserves to find the
reason in the first screenful, not in a feature list.
READ THIS FIRST: what breaks
1. A mission created without --provider can now fail
Three providers serve code_change and sourced_report — codex, claude
and localmodel — and the engine will not choose between them:
More than one provider can do this; name one with --provider: <ids>
shadowfetch-missions create resolves the provider at creation, so this is a
creation-time failure, not a run-time one. Auto-selection survives in exactly
one case: where precisely one provider for that capability is READY (or exactly
one is installed at all). All three ship in shadowfetch-missions, so a machine
with two runtimes configured — and equally a machine with none configured — gets
the refusal. media_export is unaffected: offline-media is still the only
provider for it.
What you do: add --provider codex (or claude, or localmodel) to every
create. The 4.0.0 spelling --runtime is still accepted as an alias.
Why: choosing between two equally able providers is an orchestration
decision, and provider_for() is the one place that decision would be made. It
contains no provider names, and this phase deliberately did not teach it to
prefer one.
2. An approval recorded before this release stops covering a networked mission
Scope gained egress_hosts, because destinations became an enforced privilege
(see nftables egress filter below). An approval is bound to mission:<id> and
matched by containment against the mission's scope. A grant written before this
release carries no egress_hosts at all, which reads as no destinations: it
still covers a mission that wants none, and stops covering one that wants any.
this mission may reach destinations the approval does not cover: <hosts>
This hits any queued or retried mission on codex (api.openai.com,
chatgpt.com, auth.openai.com) or claude (api.anthropic.com) whose
network is not none. A mission created with --network none has its egress
allowlist cleared and is unaffected.
What you do: approve it again — shadowfetch-missions approve <id>.
Why: the direction is deliberate. The alternative is honouring an old grant
for destinations nobody was ever shown. Before this, attack_approval's
egress-widened-after-approval scenario reported THE DESTINATION CHANGE WAS NOT
PREVENTED AND WAS NOT DETECTED. It now reports PREVENTED.
One related refusal: an approval scope whose egress_hosts is a bare string is
rejected rather than parsed. tuple("corp*") is ('c','o','r','p','*'), and
'*' is the wildcard that would make the grant cover every destination.
3. --net allow no longer reaches anything on the host
Posture allow used to create no network namespace at all, so a sandbox that
merely needed the internet also kept the host's loopback services, the host's
abstract AF_UNIX namespace and every LAN service the desktop user could reach.
Both postures unshare the network now; allow reaches the outside through a
slirp4netns NAT attached to that namespace with --disable-host-loopback.
Measured through the real Firebreak against real listeners — a TCP server on
127.0.0.1 and an abstract AF_UNIX socket — not against argv:
before, net=allow loopback REACHED abstract REACHED internet REACHED
after, net=allow loopback blocked abstract blocked internet REACHED
after, net=none loopback blocked abstract blocked internet blocked
If an agent in a Firebreak session talked to a service on your 127.0.0.1 — a
local inference server, a database, a proxy — it now cannot.
What you do: expose the service over a unix domain socket and grant the
directory that contains it with --read. AF_UNIX is addressed by filesystem
path rather than by network namespace, so a bind-mounted socket is connectable
from a namespace with no interfaces at all, and a read-only bind is sufficient.
That is the transport the shipped localmodel provider uses, and
tests/test_localmodel_transport.py proves all three halves on this kernel:
socket bound → connect() succeeds and bytes flow; socket not bound → the path
does not exist; TCP to host 127.0.0.1 → connection refused. The grant
directory must contain the socket and nothing else.
Two more consequences of the same change:
- DNS now works inside a networked sandbox, and did not before. The bound
/etc/resolv.confnamed127.0.0.53, which inside the sandbox's own network
namespace is its own empty loopback, so every cloud provider failed at
getaddrinfowhile an IP address was reachable the whole time. A networked
sandbox now gets a resolver pointing at the NAT's forwarder at10.0.2.3.
The cost travels with it: see What is still not protected. - A networked run is refused, not degraded. If no
slirp4netnsexists at a
trusted absolute path, Firebreak refuses rather than falling back to sharing
the host's network — a fallback would hand back exactly the containment the
session asked for.
4. A syscall filter denies 46 calls in every sandbox
A classic-BPF filter is assembled in Firebreak's own source, sealed in a memfd,
self-tested against the real kernel before any argv exists, and handed to
bwrap --seccomp. If the kernel will not take it, the run is refused rather
than started unfiltered.
What that costs, plainly:
- No
ptrace,process_vm_readvorprocess_vm_writev— no debugger and
no profiler inside a sandbox. Attach from outside. - No
perf_event_open. - No
syslog—dmesgfrom inside a sandbox fails. - No nested bwrap.
mount,pivot_root,chroot,open_tree,fsopen
and the rest of that group are denied, so a payload cannot build its own
mount namespace.unshareandcloneare deliberately NOT denied, because
glibc, node and chrome build their own user namespaces and denying those
would break ordinary workloads; the filter is inherited into whatever
namespace the payload makes, and the operations that namespace would be for
are denied. - No
io_uring.io_uring_setupwasREACHED:3inside a Firebreak sandbox
before this. A runtime that requires a ring will not run. - A 32-bit payload is killed with SIGSYS. seccomp matches syscall NUMBERS,
and 165 ismounton x86_64 andgetpgrpon i386. The architecture gate
refuses the personality rather than filtering the wrong table, and this build
host does carry an i386 runtime.
The honest size of it, measured rather than asserted: 46 rows are denied, and
Firebreak's own seccomp_reachable() returns 24 — the subset...
Shadowfetch Linux 4.0.0 (Umbra) — Mission Control
Download the signed 4.0.0 ISO from the website:
https://www.shadowfetch.com/linux/download/shadowfetch-4.0.0-amd64.iso
GitHub only has the .asc signature and .sha256 sidecar. The ISO is 3.98 GB, which is over GitHub’s 2 GB asset limit.
- Signature: https://www.shadowfetch.com/linux/download/shadowfetch-4.0.0-amd64.iso.asc
- SHA-256 file: https://www.shadowfetch.com/linux/download/shadowfetch-4.0.0-amd64.iso.sha256
- Website: https://www.shadowfetchlinux.org/download
- Archive.org (optional mirror): https://archive.org/details/shadowfetch-linux-4-0-0
SHA-256: 137c1f29e206c0d0e26e524c8c34a7dfe43b24c1d1df29f85d6b15283bab67fc
Size: 3,980,261,376 bytes · OpenPGP 8F13CE1535EE1F4A2916A1F73C5C900B7BE80CA1
v4.0.0-preview is the earlier C11 preview tag. Do not treat the C11 ISO (a5391737…) as this release.
Shadowfetch Linux 4.0 Mission Control — preview (not stable)
This is a preview tag of the C11 release/4.0.0 branch. It is not a completed stable 4.0 ISO.
What this is
- Source commit:
c551dfcd0870dc3a00954dee2201a50bb36dadc3 - Website: 4.0 feature preview at https://www.shadowfetchlinux.org — stable download remains 3.5.0
- Preview page: https://www.shadowfetchlinux.org/preview
- Press packet: https://github.com/ShadowfetchLinux/shadowfetch-linux-4.0-preview
- Archive.org: https://archive.org/details/shadowfetch-linux-4-0-0-preview
Why it is not stable
Authenticated Codex code missions still fail: the code-mode host exits SIGTRAP inside Firebreak after cloud inference. Required file and test checks correctly reject the unmodified result. Fresh C11 Fire/Ice installed-boot acceptance is unfinished.
Do not merge this to main or replace the 3.5.0 download until those cases pass.
Supported claim: For the first time in Shadowfetch Linux, choose Grok Bot at startup. A world-first Grok-on-Linux claim is not established.
Shadowfetch Linux 3.5.0 "Umbra" - Fire and Ice Workbench
Shadowfetch Linux 3.5.0 "Umbra" - Fire and Ice Workbench
Shadowfetch Linux 3.5.0 turns the Fire and Ice identity into a practical operating model for production work. Fire starts connected and throughput-oriented; Ice starts agent sessions with no network. The new Element Workbench creates private, consequence-aware environments for software, AI, operations, and creative work without silently adding a model, cloud account, credential, or publishing right.
What is new
- Element Workbench: Software Studio, AI Lab, Production Ops, and Creative AI show storage, network, account, accelerator, and package consequences before one signed transaction creates a private project with agent rules, provenance, tests, runbooks, and receipts.
- Firebreak agent boundaries: project-only writes, stripped known-secret variables, an element-aware network default, read-only system scope, and visible launch receipts.
- Optional AI and coding tools: Buzz remains the consent-driven local-model workspace. Codex, Claude Code, Grok Build, and Cursor Agent are independent, digest-verified choices with their own native sign-in. No model weights or cloud credentials are bundled.
- Recovery-safe changes: Phoenix and Fireproof wrap profile installation, updates, and recovery with checkpoints, simulation, explicit confirmation, failure receipts, and tested retry paths.
- Refined Fire and Ice desktop: current menus, setup flow, Workbench surfaces, installer summaries, and 1366x768/1920x1080 layouts.
Tested release
- Fresh hybrid BIOS Fire and UEFI Ice installations booted from disk.
- All 15 required visual frames passed at 1366x768 and 1920x1080.
- A 2,709-second concurrent stress run completed with zero failures, including 214 rootless-container cycles and 239 Workbench/health probes.
- The signed APT repository contains 16 binary packages from 14 signed source packages.
- The CycloneDX 1.5 SBOM records 3,350 components.
- The reproducible QA bundle records 58 evidence inputs.
Download and verify
- ISO: shadowfetch-3.5.0-amd64.iso
- Size:
3980310528bytes - SHA-256:
2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995 - Signing fingerprint:
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1 - Exact tested source commit:
d27e204b0dc929c57980a9cfb2a5541c0b39cbc3 - Evidence bundle SHA-256:
69a57b09fc8c32369210ceef47290e9386c7b4c9033755a4ef66ba263aa8d009
Verification sidecars, the signing key, SBOM, package manifest, dossier, and QA evidence bundle are attached to this release and available from the official download page. Installation and signature instructions are on the verification page.
The dossier and release-facts-3.5.0.json intentionally preserve the prepublication evidence snapshot. publication-3.5.0.log records the final live publication state and is bound to the completed acceptance manifest by SHA-256.
Known boundaries
- Secure Boot is not Microsoft-signed; disable Secure Boot or use the documented enrollment path.
- VM validation covered Plasma, GLX, Vulkan initialization, and exact layouts through Mesa llvmpipe, not physical GPU performance.
- No multi-gigabyte Buzz model download or inference run was repeated for 3.5.0; model acquisition remains an explicit post-install action.
- Historical releases remain on Archive.org. No Archive.org mirror is claimed for 3.5.0.
Full details are in RELEASE-3.5.0.md.
Shadowfetch Linux 3.0.0 «Umbra» — Backfire
Shadowfetch Linux 3.0.0 «Umbra» — "Backfire"
The agent-safe local-AI workstation. The first desktop OS where autonomous coding agents are contained, observed, and reversible by default.
Download
- ISO: https://www.shadowfetch.com/linux/download/shadowfetch-3.0.0-amd64.iso — 3,967,508,480 bytes (3.97 GB / 3.69 GiB), BIOS + UEFI hybrid
- SHA-256:
110b0d075e699a05a8a2f8f8dcd05f19454bc8ae09acd0745ca0d947db8c5e3c - Signature: https://www.shadowfetch.com/linux/download/shadowfetch-3.0.0-amd64.iso.asc
- Signing key: https://www.shadowfetch.com/linux/shadowfetch.gpg.asc —
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1 - Verify guide: https://www.shadowfetchlinux.org/verify
New in 3.0 — the Fireline agent-safety system
- Firebreak (
shadowfetch-firebreak) — run any coding agent (Claude Code, Codex CLI, Cursor, Grok Build, Aider) full-auto inside a bubblewrap sandbox: system read-only, only your project writable, optional--net none, and API keys stripped from the agent environment. A checkpoint is taken first. - Agent Checkpoints (
shadowfetch-checkpoint) — snapshot / diff / undo one~/Workspacesproject; undo everything an agent did with one command. - Shadowfetch MCP suite (
shadowfetch-mcp) — four signed, dependency-free MCP servers (passport, phoenix, checkpoint, fs) so an agent can call a checkpoint before it touches anything. - AI Ignition (
shadowfetch-ai-ignition) — reads your VRAM and recommends an Apache-2.0 model that actually fits. - shadowfetch-hardware — offline firmware diagnoser for silent Wi-Fi/Bluetooth failures.
Carried forward from 2.1.5: Shadowfetch Guide + private System Passport, Phoenix restore points, Fireproof simulate-first updates, optional loopback-only Buzz, signed ISO + APT, zero telemetry, the full creative stack.
Base: Debian testing · KDE Plasma 6 · BIOS + UEFI.
QA: BIOS+UEFI boot, a clean UEFI Btrfs install that cold-boots from disk, a full CPU/memory/IO stress run with zero failed services, and the Fireline containment suite — all against this exact ISO.
Upgrading from 2.1.5? Use sudo apt update && shadowfetch-update — Fireproof takes a Phoenix snapshot before and after, so the upgrade is rollback-able. On a fresh major version, taking a manual Phoenix Point first is never a bad idea.
Shadowfetch Linux 2.1.5 «Umbra» — Fire Edition
Shadowfetch Linux 2.1.5 «Umbra» — Fire Edition
The Linux desktop that can explain itself. Before you install, it proves what works; after you install, it helps fix what doesn't.
Download
- ISO: https://www.shadowfetch.com/linux/download/shadowfetch-2.1.5-amd64.iso — 3,968,471,040 bytes (3.97 GB / 3.70 GiB), BIOS + UEFI hybrid
- SHA-256:
848f043e4d6f85c3607e7034ba911a1ce8b4a317674feebef8b07fcd8f531c24 - Signature: https://www.shadowfetch.com/linux/download/shadowfetch-2.1.5-amd64.iso.asc
- Signing key: https://www.shadowfetch.com/linux/shadowfetch.gpg.asc — fingerprint
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1 - Verify guide: https://www.shadowfetchlinux.org/verify
What's new
- Shadowfetch Guide + private System Passport — a deterministic, read-only, on-device check of graphics, networking, audio, firmware, memory, storage, recovery readiness, and local-AI capacity. Available from the live Ignition screen and as the first Control Center section. Its allowlisted schema omits host identity, serials, PCI-slot, and filesystem identifiers, and it exports a redacted HTML/JSON report.
- Buzz stays the single optional local-AI workspace, loopback-only by default, now guarded against the WebKitGTK DMA-BUF freeze on Plasma Wayland. No model is bundled; downloads are consent-gated.
- Optional verified coding agents at first-run setup — OpenAI Codex CLI, Claude Code, xAI Grok Build, Cursor Agent — unchecked by default, pinned and verified, with no bundled credentials.
- Verified in-place upgrade from 2.1.4 via the signed APT repository (
sudo apt update && shadowfetch-update); Phoenix rollback on separate-/bootBtrfs fixed and re-tested.
Base: Debian testing · Desktop: KDE Plasma 6 · Firmware: BIOS + UEFI.
Every required prepublication case in qa/2.1.5/acceptance.json passed against this exact ISO.