[1.13.0] — 2026-08-10 ("Security Ops" r11 · kernel 7.1.8 · authenticated substitutes)
Security
- Kernel → Linux 7.1.8-SecurityOps, the current kernel.org stable release,
with the existing portable nonguix driver base and KSPP/performance overlay. - Two explicit authenticated binary substitutes: the live daemon, generated
installed systems, installer invocation, and both build modes now use
https://substitutes.securityops.com.brfirst and official
https://ci.guix.gnu.orgsecond, with their pinned Ed25519 keys. No third
cache is inherited; misses deliberately build from source.
Changed
- Added the interactive/automation-friendly
./securityopsctlmaintainer tool
and canonicalsecurityops/settings.json: add/remove packages, fetch and
verify a new stable kernel.org release, inspect status, validate, and launch
an incremental pinned build without hand-editing Scheme../make-iso.sh
remains the hardened build engine: it serializes builds, verifies the ISO,
and can transactionally create/reassemble-check release parts with--bundle. - Channels refreshed and made reproducible: Guix, nonguix, sops-guix, gocix,
small-guix, and securityops are commit-pinned; every channel has its published
introduction. Explicit transitive pins prevent small-guix dependencies from
following mutable branches. Added the previously missing small-guix closure,
removed unused guix-xlibre, and moved Security Ops to its.com.brURL. - Current channel applications are used consistently: Evelin 4.3.0 and
VaptVupt/VaptVupt GUI 5.2.1 replace the shadowed older vendored bindings;
their unused legacy modules and archives were removed from the image source. - Release retention is latest-only: superseded remote releases, assets, and
tags are pruned after the new release is published to conserve VPS storage.
Fixed
- Completed
securityos→securityopsinternally. The module directory,
declarations, imports, embedded source path, installer paths, artifact name,
and documentation now agree; the half-renamed tree could not load its kernel
module and had also corrupted Git's index. - Restored the real
linux-securityopspackage binding inconfig.scmand
replaced the stale live-user SHA-512 hash, so the documentedsecurityops
login works again. - Hardened the embedded-source selector so ignored assistant histories, local
assistant settings, Python bytecode, build output, and common private-key/token filenames cannot leak
into the published image; sanitized provenance docs no longer repeat host
disk or resolver identifiers. - The installer-generated system now preserves the same substitute trust policy
and pinned channels instead of silently returning to Guix's defaults. Install
and reconfigure run through the pinned time-machine so channel modules exist;
generated configs are mode 0600, and Sway's browser shortcut has its matching
package. The destructive installer and its shortcut are now live-media-only. - Installed systems now retain Landlock activation and the live image's
default-drop nftables policy, while no SSH daemon is enabled implicitly. - The installer resolves the live medium from the kernel's real
root=device
and fails closed if it cannot protect that disk; it also rejects every account
name contributed by the generated desktop system. - Tor now exposes the loopback TransPort/DNSPort/ControlPort expected by Torando,
preventing its opt-in per-user killswitch from redirecting traffic to closed
ports. Removed the unsafe universaltsc=reliableboot override.
Download
The verified ISO is published as sub-2-GiB parts plus SHA256SUMS.parts on GitHub: https://github.com/cristiancmoises/securityops-os/releases/tag/v1.13.0