Skip to content

Security Ops OS v1.13.0 — r11 · kernel 7.1.8 · authenticated substitutes

Latest

Choose a tag to compare

@cristiancmoises cristiancmoises released this 11 Aug 03:58

[1.13.0] — 2026-08-10 ("Security Ops" r11 · kernel 7.1.8 · authenticated substitutes)

Security

  • Kernel → Linux 7.1.8-SecurityOps, the current kernel.org stable release,
    with the existing portable nonguix driver base and KSPP/performance overlay.
  • Two explicit authenticated binary substitutes: the live daemon, generated
    installed systems, installer invocation, and both build modes now use
    https://substitutes.securityops.com.br first and official
    https://ci.guix.gnu.org second, with their pinned Ed25519 keys. No third
    cache is inherited; misses deliberately build from source.

Changed

  • Added the interactive/automation-friendly ./securityopsctl maintainer tool
    and canonical securityops/settings.json: add/remove packages, fetch and
    verify a new stable kernel.org release, inspect status, validate, and launch
    an incremental pinned build without hand-editing Scheme. ./make-iso.sh
    remains the hardened build engine: it serializes builds, verifies the ISO,
    and can transactionally create/reassemble-check release parts with --bundle.
  • Channels refreshed and made reproducible: Guix, nonguix, sops-guix, gocix,
    small-guix, and securityops are commit-pinned; every channel has its published
    introduction. Explicit transitive pins prevent small-guix dependencies from
    following mutable branches. Added the previously missing small-guix closure,
    removed unused guix-xlibre, and moved Security Ops to its .com.br URL.
  • Current channel applications are used consistently: Evelin 4.3.0 and
    VaptVupt/VaptVupt GUI 5.2.1 replace the shadowed older vendored bindings;
    their unused legacy modules and archives were removed from the image source.
  • Release retention is latest-only: superseded remote releases, assets, and
    tags are pruned after the new release is published to conserve VPS storage.

Fixed

  • Completed securityossecurityops internally. The module directory,
    declarations, imports, embedded source path, installer paths, artifact name,
    and documentation now agree; the half-renamed tree could not load its kernel
    module and had also corrupted Git's index.
  • Restored the real linux-securityops package binding in config.scm and
    replaced the stale live-user SHA-512 hash, so the documented securityops
    login works again.
  • Hardened the embedded-source selector so ignored assistant histories, local
    assistant settings, Python bytecode, build output, and common private-key/token filenames cannot leak
    into the published image; sanitized provenance docs no longer repeat host
    disk or resolver identifiers.
  • The installer-generated system now preserves the same substitute trust policy
    and pinned channels instead of silently returning to Guix's defaults. Install
    and reconfigure run through the pinned time-machine so channel modules exist;
    generated configs are mode 0600, and Sway's browser shortcut has its matching
    package. The destructive installer and its shortcut are now live-media-only.
  • Installed systems now retain Landlock activation and the live image's
    default-drop nftables policy, while no SSH daemon is enabled implicitly.
  • The installer resolves the live medium from the kernel's real root= device
    and fails closed if it cannot protect that disk; it also rejects every account
    name contributed by the generated desktop system.
  • Tor now exposes the loopback TransPort/DNSPort/ControlPort expected by Torando,
    preventing its opt-in per-user killswitch from redirecting traffic to closed
    ports. Removed the unsafe universal tsc=reliable boot override.

Download

The verified ISO is published as sub-2-GiB parts plus SHA256SUMS.parts on GitHub: https://github.com/cristiancmoises/securityops-os/releases/tag/v1.13.0