Releases: timlinux/tuinix
Release list
Release v0.8.0
Changes
- Release v0.8.0 (ff41cf1)
- Merge pull request #20 from timlinux/feature/xfs-partition-dual-boot (6a77bb1)
- feat: add package set selection (TUI, Pentest, Games) and merge main (d849e2d)
- Merge remote-tracking branch origin/main into feature/xfs-partition-dual-boot (c06d8ba)
- Fix GRUB module conflict on shared ESP for dual-boot partition mode (571ca70)
- Fix partition path parsing for NVMe devices (17261ac)
- Add XFS existing partition install mode for dual-boot support (c343b28)
- Merge pull request #19 from timlinux/feature/v0.8.0-security-audit-package-sets (f321aa5)
- fix: add pull-requests write permission for PR comment, fix grep exit code (3c85349)
- fix: grep -c exit code handling in CI trivy step (42c424a)
- fix: format all nix files to pass CI nixfmt check (ab10c67)
- v0.8.0: Security audit, package sets, ISO hardening (a51d862)
Installation
Download the ISO image below and follow the installation guide.
sudo dd if=<downloaded-iso> of=/dev/sdX bs=4M status=progress oflag=sync
# Boot from USB, then run: sudo installerISO Details
| Metric | Value |
|---|---|
| ISO Size | 1.3G |
| Closure Size | 18.9 |
| Total Packages | 685 |
| SBOM Components | 34 |
| SHA-256 | 13c5b6824be67e8d3acb0c8d5af677a3db21a8beae5620c552d71868befb041b |
Security
✅ No HIGH/CRITICAL vulnerabilities found
Trivy scan results
Report Summary
┌──────────────────────┬───────┬─────────────────┬─────────┐
│ Target │ Type │ Vulnerabilities │ Secrets │
├──────────────────────┼───────┼─────────────────┼─────────┤
│ cmd/installer/go.mod │ gomod │ 0 │ - │
└──────────────────────┴───────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)
Top 100 packages by closure size
/nix/store/zy4js128dwd2b11sc4pxi1smmwldihrn-testdisk-7.2 2.0 MiB 86.2 MiB
/nix/store/zx7a5f5q0l9rngr4nrpwa313ak6xhxhb-hostname-hostname-debian-3.25 1.3 KiB 31.3 MiB
/nix/store/zwsdnsaayl0wj1ypx5jrgwgca2gz8anz-polkit-126 579.9 KiB 96.4 MiB
/nix/store/zsq35qbs90c1nkh51w3qkmp7x2zpgqw7-perl5.40.0-TimeDate-2.33 88.1 KiB 88.1 KiB
/nix/store/zqiwhmdnqclz0qcz2cjxljsbl3kpzy3g-su.pam 1.5 KiB 57.8 MiB
/nix/store/zq5rj2a0x6y9w6pfrwqjvpz2ldsgxhph-unit-script-nixos-activation-start 1.4 KiB 213.4 MiB
/nix/store/zn6wfngdpnfgz00f217hin0hiq6vmna6-X-Restart-Triggers-nix-daemon 0.2 KiB 0.9 KiB
/nix/store/zmpak7lswp8i1xdwdcm6an2qqfwmw56i-unit-linger-users.service 1.4 KiB 182.0 MiB
/nix/store/zks6khcgip0980r18rz5l38rm5mpghbn-security-wrapper-sudoedit-x86_64-unknown-linux-musl 70.0 KiB 66.5 MiB
/nix/store/zjiwv9y4jkdraw03vj88my3dylc04c9d-libressl-4.2.1 3.1 MiB 34.4 MiB
/nix/store/zhcfw0skbhw496dnqi1kjpna66iwb0yp-nsncd-1.5.2 1.4 MiB 42.4 MiB
/nix/store/zfs9l4azkc4iw48wbczymk2i765bznjd-unit-systemd-user-sessions.service 1.2 KiB 180.2 MiB
/nix/store/zf8qy81dsw1vqwgh9p9n2h40s1k0g2l1-systemd-258.2 55.0 MiB 171.9 MiB
/nix/store/zd7gz4pvxymrrkdxx3jcvfg5cs0prrjd-socat-1.8.0.3 830.2 KiB 46.8 MiB
/nix/store/zcfjv5z1v84svg8xnib116grhd32qa8f-aws-c-cal-0.9.2 158.7 KiB 41.4 MiB
/nix/store/za9aw3rh2zqwdqx16z3vbc4b24cvp9yp-libgcrypt-1.11.2-lib 1.7 MiB 33.9 MiB
/nix/store/z9f6g6j0jv8vvk9n1kc2k8pyzkghdh2r-e2fsprogs-1.47.3 4.8 MiB 38.0 MiB
/nix/store/z9ai27zxw7d54hl3xg1h93myxqydzvd6-screen-5.0.1 833.2 KiB 55.4 MiB
/nix/store/z7k98578dfzi6l3hsvbivzm7hfqlk0zc-set-source-date-epoch-to-latest.sh 1.7 KiB 1.7 KiB
/nix/store/z4gmnhf6y00qaggdahmry80digqh4q2m-unit-systemd-journal-flush.service 1.2 KiB 180.2 MiB
/nix/store/z3x59sslc6xzbpzx639fy51ivaqnwlb2-nfs-utils-2.8.4 1.9 MiB 334.4 MiB
/nix/store/z34g38hzz56f3c0pjxs2m90s51ga1y1x-libxdmcp-1.1.5 31.2 KiB 31.3 MiB
/nix/store/z255fkvmkg7gg4lkk1vjpbmnss6g5fgc-perl5.40.0-Net-SMTP-SSL-1.04 5.4 KiB 42.2 MiB
/nix/store/z0c4fgxzkk7avkba5bmj3zj6xd1ngghk-useradd.pam 1.1 KiB 50.9 MiB
/nix/store/yyi1rsddw0s98hx25zhmgsj68dxmxlav-etc-hostname 0.1 KiB 0.1 KiB
/nix/store/yy1mbjm19x1kcrkhyfsixca25c0v4f1x-sshd.conf-final 1.0 KiB 73.9 MiB
/nix/store/yxj2lwzhlzd41mhyv4dfcb4p6ib16jrx-etc-profile 0.8 KiB 4.8 KiB
/nix/store/yq5f67b3gfi2cg94w9s8n53cp5cp5f8j-mkpasswd-5.6.5 31.7 KiB 31.5 MiB
/nix/store/yl02x3mcii8qlv5dk6l06gqbrfbac8w6-tcpdump-4.99.5 2.6 MiB 36.2 MiB
/nix/store/yijlbn97iyrqj49qf565mdg3q4908qgl-unit-systemd-makefs-.service 2.6 KiB 547.7 MiB
/nix/store/yijhn548p2589pkybgvbhll09bqsxy0q-ncurses-6.5 3.6 MiB 34.9 MiB
/nix/store/yi5f1n53xr9pciknp14jfymdjp53d7a6-etc-zfs-zed.d-zed.rc 0.6 KiB 351.5 MiB
/nix/store/yi3c5karhx764ham5rfwk7iynr8mjf6q-gnutar-1.35 2.7 MiB 34.2 MiB
/nix/store/yghrmd3fmr889d66g33wqna832kriq1g-locale.conf 0.1 KiB 0.1 KiB
/nix/store/yfp2r8cjyajnsxzdz2sxdppir0f4gnw3-unit-nix-optimise.service 1.3 KiB 271.5 MiB
/nix/store/yf2zrw5ynsgqn9af8qxfky93vc1vdcab-perl5.40.0-File-Listing-6.16 17.2 KiB 120.5 KiB
/nix/store/ydrckgnllgg8nmhdwni81h7xhcpnrlhd-openssl-3.6.0-dev 2.1 MiB 43.6 MiB
/nix/store/y6wg05lbxkcxpd3vihszqla9jhd600vn-npth-1.8 50.8 KiB 31.4 MiB
/nix/store/y2wdhdcrffp9hnkzk06d178hq3g98jay-gawk-5.3.2 2.9 MiB 34.2 MiB
/nix/store/xyff06pkhki3qy1ls77w10s0v79c9il0-reproducible-builds.sh 0.6 KiB 0.6 KiB
/nix/store/xx7cm72qy2c0643cm1ipngd87aqwkcdp-glibc-2.40-66 28.8 MiB 31.3 MiB
/nix/store/xx5mwlfaj0i1nd3csy306x0akyxm5c4m-security-wrapper-su-x86_64-unknown-linux-musl 70.0 KiB 65.6 MiB
/nix/store/xw51sk0kyd5xv91kw3q7azhzz234gl4d-unit-zpool-trim.timer 0.4 KiB 0.4 KiB
/nix/store/xsf0bz2ikvimps02zyk65jm75yw9n6a0-tpm2-tss-4.1.3 3.2 MiB 64.3 MiB
/nix/store/xrrdz9ryg5acvafws5s1dc2x0rb0y3ds-db-5.3.28 4.2 MiB 45.2 MiB
/nix/store/xqzlic0za258j9i2jssqz3s325vc3l11-aws-c-mqtt-0.13.3 554.0 KiB 44.6 MiB
/nix/store/xq62nlqa14vdx3wc6p1bc1f2yq6p0b15-vlock.pam 1.0 KiB 50.9 MiB
/nix/store/xpi7n446hsm2di4887rbz45bk40lrsqr-unit-network-local-commands.service-disabled 0.3 KiB 0.3 KiB
/nix/store/xp07qz0bljf4rxzngksvdqj244q4cyww-user-generators 0.1 KiB 0.1 KiB
/nix/store/xnaf2w53yacjg7h3127ks7gf61pcs3n8-libselinux-3.8.1 686.7 KiB 34.0 MiB
/nix/store/xn2vzkk0ab5gn9d1h20yaghb652i34v1-perl-5.40.0-env 549.4 KiB 105.0 MiB
/nix/store/xm08aqdd7pxcdhm0ak6aqb1v7hw5q6ri-gcc-14.3.0-lib 9.5 MiB 41.0 MiB
/nix/store/xk3x9567nwma79iim3ar1ixl0rcf7449-libsm-1.2.6 44.6 KiB 33.4 MiB
/nix/store/xhy6fkifzmd664lk2s1w1zkk7r5khc5w-perl5.40.0-HTTP-Message-6.45 141.9 KiB 31.8 MiB
/nix/store/xhvjnvmha1zlz2l63g1wjaayxx3cgj0b-lowdown-2.0.4-lib 313.2 KiB 31.6 MiB
/nix/store/xgr0gawyyjv6jmk25022b1z53zxqhi4j-perl5.40.0-Digest-HMAC-1.05 9.2 KiB 9.2 KiB
/nix/store/xgavznqg1ay2hycpp7yy9ia1n751jcla-bzip2-1.0.8 82.9 KiB 31.4 MiB
/nix/store/xfxrsr7654p4xbhjyl4xds34pqlinpln-ppp-2.5.2 997.6 KiB 99.8 MiB
/nix/store/xddfwlk4yizb33a1swx63irf3gjk9sg8-p11-kit-0.25.10 5.2 MiB 36.7 MiB
/nix/store/xakjffr9bli9sms3f7kkli45qga7zxqh-etc-host.conf ...
v0.7.1 - Installer Trim, Ownership Fix
Hotfix release on top of v0.7.0.
Changes
- Remove unused packages from installer ISO (nano, wget, xfsprogs, gum, catimg, bc)
- Use zstd level 19 squashfs compression
- Disable unnecessary services (ModemManager, Bluetooth, printing, xdg)
- Fix post-install flake ownership: chown runs after nixos-enter with verification logging
Downloads
| File | Architecture | Size |
|---|---|---|
tuinix.v0.7.1.x86_64.iso |
x86_64 | 1.3 GB |
sudo dd if=tuinix.v0.7.1.x86_64.iso of=/dev/sdX bs=4M status=progress oflag=syncv0.7.0 - Display Fix, Kartoza Branding, Installer Improvements
What's New in v0.7.0
Bug Fixes
- Fix black screen on boot — Removed hardcoded
video=2560x1600that caused blank displays on non-Framework hardware. Added newtuinix.display.resolutionmodule option for per-host configuration with auto-detection at install time. - Fix post-install flake ownership —
~/tuinixis now the single source of truth, owned by your user account./etc/tuinixis a symlink. No moregit cloneneeded after installation. - Fix deprecated ZFS kernel selection — Use default LTS kernel instead of deprecated
latestCompatibleLinuxPackages.
New Features
tuinix.display.resolutionmodule — Set framebuffer console resolution per-host, or leave asnullfor kernel auto-detection.nix run .#test-install— One-command ISO build + QEMU VM launch for rapid development iteration.- Blockfont title rendering — TUINIX title now uses the blockfont library for beautiful block-character text.
- Display resolution auto-detection — Installer reads
/sys/class/graphics/fb0/virtual_sizeand configures the installed system accordingly.
Improvements
- Kartoza brand colours — Installer uses Kartoza orange (
#F4811F), blue (#2C3E50), gray (#7F8C8D), and white throughout. - Kartoza branding — Footer, splash screen, and completion screen include Kartoza credits and links.
- Smoother UI — Removed distracting spring slide-in panel animations from wizard steps.
- Smaller footprint — Removed
networkmanagerapplet(GTK/X11 dependency), trimmed dev shell packages. - Faster builds — All build scripts use
-j auto --cores 0for maximum parallelism. VM profile disables unnecessary services. - Clean vendor — Go vendor directory no longer tracked in git; dependencies fetched at build time via nix
vendorHash. - Updated documentation — Comprehensive post-install guide covering the edit-rebuild-commit workflow, module toggles, upstream updates, and backup strategy.
Downloads
| File | Architecture | Size |
|---|---|---|
tuinix.v0.7.0.x86_64.iso |
x86_64 | 1.3 GB |
Flash to USB and boot:
sudo dd if=tuinix.v0.7.0.x86_64.iso of=/dev/sdX bs=4M status=progress oflag=syncv0.6.0 - R36S Handheld Support
tuinix v0.6.0 - R36S Handheld Support
This release adds support for the R36S handheld gaming console (Allwinner A33 variant), making tuinix available on armv7l ARM devices.
What's New
R36S Handheld Support
- New architecture: armv7l-linux (32-bit ARM) support
- SD card image builder: Creates flashable images for R36S
- Stock kernel integration: Uses vendor Linux 3.4.39 kernel with proprietary display/GPU drivers
- Vendor module support: Includes Mali GPU, display, LCD, GPIO, and joystick drivers
Build System Improvements
- Cross-architecture builds: Added binfmt emulation configuration for building armv7l on x86_64
- Architecture-aware boot config: boot.nix now only applies x86-specific settings on x86 systems
Building the R36S Image
# Clone the repository
git clone https://github.com/timlinux/tuinix.git
cd tuinix
# Build the SD image (requires binfmt emulation for armv7l)
nix build .#sd-r36s
# Flash to SD card
sudo dd if=result of=/dev/sdX bs=4M status=progress conv=fsyncNote: First build may take several hours due to limited armv7l binary cache. See the R36S documentation for prerequisites.
Supported Architectures
| Architecture | Image Type | Target Devices |
|---|---|---|
| x86_64-linux | ISO | Standard PCs, laptops, servers |
| aarch64-linux | ISO | ARM64 devices with UEFI boot |
| armv7l-linux | SD Image | R36S handheld (Allwinner A33) |
Documentation
Known Limitations
- Uses stock vendor kernel (Linux 3.4.39) - cannot use mainline due to display driver requirements
- Serial console only at this time (display requires specific init sequence)
- Limited binary cache coverage means longer initial build times
Full Changelog
See the commit history for all changes.
Thank you for using tuinix!
Release v0.4.0
What's New in v0.4.0
Installer Improvements
- Spring physics animations: Smooth wizard panel slide-in effects using the harmonica library
- TTY-compatible borders: Switched to NormalBorder for proper rendering on Linux console
- Refactored codebase: Installer split into discrete Go source files for better maintainability
- Version info in footer: Version and build information now displayed in the installer footer
- SSH server option: New option to configure SSH server with GitHub key fetching during installation
UX Improvements
- Press
qkey to quit from any screen - Network connectivity check before installation
- Live log tail during installation process
- Improved install progress tracking
Documentation
- Updated bare-metal installation guide
- Added network check and live log tail documentation
Installation
Download tuinix.v0.4.0.iso and write it to a USB drive:
sudo dd if=tuinix.v0.4.0.iso of=/dev/sdX bs=4M status=progressReplace /dev/sdX with your actual USB device.
v0.3.0 — Multiple Storage Modes
What's New in v0.3.0
This release adds support for multiple storage configurations, giving users flexibility to choose the disk layout that best fits their needs — from maximum-performance XFS to fault-tolerant multi-disk ZFS arrays.
Storage Modes
The installer now supports five storage modes:
| Mode | Disks | Encryption | Redundancy |
|---|---|---|---|
| Encrypted ZFS (default) | 1 | AES-256-GCM | — |
| XFS unencrypted | 1 | None | — |
| Encrypted ZFS stripe | 2+ | AES-256-GCM | None (RAID0) |
| Encrypted ZFS raidz | 3+ | AES-256-GCM | 1-disk fault tolerance |
| Encrypted ZFS raidz2 | 4+ | AES-256-GCM | 2-disk fault tolerance |
- XFS mode uses the latest available kernel instead of constraining to ZFS-compatible versions, giving maximum I/O performance with no encryption overhead
- Multi-disk modes present a toggle-based disk selection UI (Space to select, Enter to confirm) with minimum disk count validation
- raidz/raidz2 modes dynamically generate disko configurations for N disks with correct parity settings
Install Log Persistence
The install log (/tmp/tuinix-install.log) is now automatically copied to the user's home directory at the end of installation, so it persists after the first reboot. Useful for troubleshooting post-install issues.
UI Improvements
- 24-bit ANSI color logos: The ASCII mascot has been replaced with catimg-rendered 24-bit color logos in both the installer header and the ISO welcome screen
- Centered welcome box: The boot welcome screen now uses rounded borders and is centered on the terminal
Conditional Kernel and Boot Configuration
- XFS installs use
pkgs.linuxPackages_latest(no ZFS compatibility constraint) - ZFS installs continue to use the latest ZFS-compatible kernel
- GRUB ZFS support is only enabled when ZFS is active
xfsprogsadded to the ISO environment for XFS formatting
Documentation
- Bare metal installation guide rewritten with all five storage modes
- Disk layout tables for each mode (partitions, datasets, pool configurations)
- Recovery procedures split into tabbed ZFS/XFS sections
- ISO filename and download links updated to use
tuinix.v0.3.0.iso
Download
Download tuinix.v0.3.0.iso below and flash it to a USB drive:
sudo dd if=tuinix.v0.3.0.iso of=/dev/sdX bs=4M status=progress oflag=syncReplace /dev/sdX with your USB device. An internet connection is required during installation.
Full Changelog
v0.2.0: Go TUI Installer
What's New
This is a major release that replaces the bash installer script with a polished interactive Go TUI wizard and overhauls the documentation and ISO build process.
Go TUI Installer
The centrepiece of this release is a brand-new terminal installer built with bubbletea and lipgloss:
- Wizard-style interface with step indicators, two-column layout, and rounded borders
- Animated splash screen with fire particle transition and figlet ASCII title
- Pre-rendered mascot logo — no GUI dependencies needed on the ISO
- 13-step wizard: username, full name, email, password, hostname, disk selection, ZFS encryption passphrase, locale, keyboard layout, summary, and confirmation
- Password masking with
*characters for all sensitive fields - Secure password storage — passwords hashed with
mkpasswd -m sha-512for NixOShashedPassword(no morechangemedefault) - ZFS encryption passphrase collected in the wizard and piped to disko's stdin
- Detailed logging to
/tmp/tuinix-install.logfor diagnostics - Subtle styling — off-white text with colour used sparingly for emphasis
Console Keymap Fix
console.keyMapnow correctly maps to Linux console keymap names (e.g.pt-latin1,br-abnt2,de-latin1)services.xserver.xkb.layoutuses the separate X11 layout code- Previously, both used the short code which caused
loadkeysto fail for non-US layouts like Portuguese
System Improvements
boot.consoleLogLevel = 3suppresses noisy kernel messages (e.g. TTM buffer eviction) from bleeding into the terminalvimandgitincluded as system packages in the generated host configscripts/rebuild.shupdated with generation cleanup and garbage collection (modelled after nix-config)- X11/Wayland completely stripped from the installer ISO — terminal only
- ISO welcome screen clears the terminal before displaying the mascot and instructions
Documentation Overhaul
- All references updated to
sudo installer(replacinginstall.shandtuinix-installer) - Wizard steps documented with password and passphrase collection
- Post-install guide updated for the new password-set-during-install workflow
- README updated with rebuild script references and Go TUI installer description
- MkDocs site restructured with improved navigation and styling
Installation
- Download the ISO below
- Flash to a USB drive:
Or use balenaEtcher / Ventoy
sudo dd if=tuinix.v1.iso of=/dev/sdX bs=4M status=progress oflag=sync
- Boot from USB (UEFI required, Secure Boot disabled)
- Run the installer:
sudo installer
Requirements
| Resource | Minimum | Recommended |
|---|---|---|
| CPU | x86_64 | Modern x86_64 |
| RAM | 4 GB | 8 GB+ |
| Storage | 20 GB | 50 GB+ SSD |
| Boot mode | UEFI | UEFI |
| Internet | Required | Required |
Full Changelog
Full changelog: v0.1.0...v0.2.0
For detailed installation instructions, see the documentation.
Release v0.1.0
Changes
- Fix Nix version in CI/release workflows, fix old project name references (d7d1df6)
- Add MkDocs documentation site, fix release workflow, remove ubuntu references (007248b)
- Add welcome experience to live ISO with mascot and install instructions (ae54ebf)
- Fix broken logo path in REQUIREMENTS.md after move to .github/docs/ (1f79fd2)
- Restructure docs around three environments and add AI/LLM tool policy (d3f78d0)
- Rename project from nixmywindows to nixtui (aee7aed)
- Add rebuild script for applying flake changes on installed systems (c9eaea8)
- Restore user imports in installer-generated host config (f1b921b)
- Fix ZFS boot in VMs and document VM setup requirements (b3208ee)
- Strip things down more (ce7b63d)
- Remove home manager stuff from admin (011e6a8)
- Claude code review applied and refactored system modules for correct separation of concerns (a8d6667)
- Strip packages from user profiles (dfb809c)
- Fixes for install process (1f160c1)
- Added build version script (cc008c6)
- WIP fixing vm creation and zfs boot (c656524)
- Add current build info files for ISO inclusion (bd9def3)
- Refactoring away unneeded stuff (d71fd27)
- Updating ISO creation to use gum (c469624)
- Template and vm setup fixes (5395d42)
- Improvements for installer script. (3a3bb7c)
- Template updates for disko (45866a5)
- Template updates for disko (d3f3d16)
- Enable flakes in teh iso installer (ff368a5)
- Added installer.nix (bba9833)
- Updated hardware to have host network id vfor zfs (cd8710f)
- Remove conflicting filesystem config from hardware.nix - use disks.nix for ZFS (c7586fc)
- Fix ISO configuration and build system (12a15cc)
- Add simplified installer configuration (42231f4)
- Adding run vm script (8bfd5fe)
- Added iso builder script (146ca2c)
- Added disks.nix (6f4361c)
- Merge pull request #1 from timlinux/copilot/update-readme-with-contributors (02733db)
- Strip away more stuff (9faeb36)
- Strip away more stuff (56404d9)
- Resolve merge conflicts (0fa85ca)
- Move vm to profiles (8c2c4ed)
- Initial project setup with Nix flake configuration (b1111cd)
- Fix subshell issue and remove redundant dependency installation (9e2ed5b)
- Fix trailing spaces and add final newline (6731258)
- Add contributors section with automation script and workflow (2897995)
- Initial plan (4752fba)
- Prompts for the first flake generation (ad39848)
- Prompts for the readme (1689030)
- docs: update PROMPT.log with complete session documentation (4a8229e)
- feat: add welcoming logo headers to all documentation (44aae1a)
- refactor: reorganize documentation into .github folder (495f5be)
- feat: comprehensive quality assurance and branding setup (bcfa93b)
- feat: initial repository setup with comprehensive GitHub structure (4140e74)
Installation
Download the ISO image below and follow the installation guide.
Flash to USB:
sudo dd if=tuinix-installer.iso of=/dev/sdX bs=4M status=progress oflag=sync