Shadowfetch Linux · Umbra · 3.5.0 · Fire and Ice Workbench
Shadowfetch Linux 3.5.0
Fire for connected production. Ice for local-first agent work. Four consequence-aware workspaces, optional local AI, scoped coding agents, and a recovery path you can see before anything changes.
- GPL-3.0 · open source
- No telemetry
- GPG-signed ISO
- Built by one developer
Shadowfetch Linux is free and open-source software. Commercial product apps are separate atshadowfetch.com. The 3.5.0 image and its verification artifacts use the established signed download endpoint. Historical releases remain on Archive.org; a 3.5.0 Archive mirror is not claimed yet.
$ sha256sum shadowfetch-3.5.0-amd64.iso
2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995
shadowfetch-3.5.0-amd64.iso
$ gpg --verify shadowfetch-3.5.0-amd64.iso.asc shadowfetch-3.5.0-amd64.iso
gpg: Good signature from "Shadowfetch Linux"
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1
$ sudo dd if=shadowfetch-3.5.0-amd64.iso \\
of=/dev/sdX bs=4M status=progressLive walkthrough
Shadowfetch Linux 3.5 Fire and Ice
About five minutes on the current Fire and Ice desktop — Welcome, Element Workbench, and how the element changes the session.
The desktop as it ships
9 screenshots · captured from the current ISO

Fire: connected production posture 
Ice: local-first agent posture 
Pick your flame: Fire 
Pick your flame: Ice 
Four production environments, one plan 
AI Lab leads; network starts off 
Buzz, Codex, Claude, Grok, Cursor 
Calamares summary: nothing hidden 
UI at T+36 minutes of sustained load
Fire and Ice Workbench
The element changes how the work starts.
Element Workbench
Software Studio, AI Lab, Production Ops, and Creative AI show disk, network, account, accelerator, and package consequences before one signed transaction creates a private project with rules, provenance, tests, runbooks, and receipts.
Fire and Ice postures
Fire starts connected and throughput-oriented. Ice starts agent sessions with no network. The selected element changes the recommendations, Firebreak default, project manifest, and launch receipt — not only the wallpaper.
Buzz and optional coding agents
Buzz is the one optional local-model workspace and asks before downloading a model. Codex, Claude Code, Grok Build, and Cursor Agent remain independent, digest-verified choices with native sign-in and no embedded credential.
Firebreak and checkpoints
Agent sessions keep the system read-only, scope writes to the selected project, strip known secret variables, and record what launched. A project checkpoint supplies a visible diff and a practical undo path.
Phoenix and Fireproof
Profile installs and updates are simulated, explicitly confirmed, wrapped in restore points on Btrfs, checked afterward, and left with a failure receipt and retry path when something goes wrong.
Evidence, not adjectives
The exact signed ISO passed 11 of 11 prepublication gates, fresh BIOS and UEFI installs, 15 visual frames, recovery testing, and 2,709 seconds of concurrent load with zero failures.
SHA-256 2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995· Verify the image· More screenshots
Independent coverage
Already on DistroWatch, Linuxiac, and LinuxLinks.
Open-source companion tools
Public projects live next door, not in the ISO.
Agent News Bot is a separate free-software project. It is not a Linux package.
Open the lab