Linux

Shadowfetch Linux 4.1.0

Release history

What changed in each published release. Download metadata and checksums come from the same signed release manifests used by the verification page.

Current release

Shadowfetch Linux 4.1.0 «Umbra»

Download current ISO

Shadowfetch Linux 4.1.0 turns three recorded intentions into enforced controls. Every sandbox now gets its own network namespace, so a task no longer reaches the host's loopback services or its abstract sockets in either network posture. Where a mission declares destinations, a default-DROP nftables ruleset in that namespace permits only the addresses those names resolved to. A seccomp-BPF filter denies 46 syscalls in every sandbox, self-tested against the real program before any command exists, and refuses the run rather than starting unfiltered. Declared masked paths are real mounts instead of a line in a record. An on-device provider ships, so local AI is no longer deferred. Seven changes break working setups; read the release notes before upgrading.

  • An egress allowlist that filters: nftables with default DROP inside the sandbox's own network namespace, permitting only the addresses the declared hostnames resolved to on the host at launch.
  • A syscall filter in every sandbox: 46 calls answer EPERM, applied through bwrap --seccomp from a sealed memfd, and not declarable by a provider because a provider choosing its own syscall surface is the thing a sandbox exists in order not to depend on.
  • Masked paths are mounts now, not records: an empty tmpfs over a directory, /dev/null over a file, applied by bwrap with no cooperation from the payload.
  • Both network postures unshare the network, so host loopback services and abstract AF_UNIX sockets are out of reach even when a task is online.
  • An on-device provider (localmodel) runs code and report missions with network policy none. No model weights are bundled: the installation reports installed-unavailable until you supply a model service.
  • A mission with more than one ready provider for its capability now refuses to guess -- pass --provider.
ISO
shadowfetch-4.1.0-amd64.iso
Size
3.98 GB (3.71 GiB)
SHA-256
e19e96302f97e94d5284f8fbef181c9b0e49ca7b746afe5e66e4bc6d5c551f25

Previous release

Shadowfetch Linux 4.0.0 «Umbra»

Retired release

Shadowfetch Linux 4.0.0 makes Mission Control the desktop for inspectable agent work. Fire and Ice are real install-time identities. Firebreak no longer pins process address space to the RSS budget, so the code-mode host can reserve V8 sandbox VA without SIGTRAP while MemoryMax, TasksMax and CPUQuota stay in place. Grok Bot is a featured startup choice. Local AI is deferred. This signed ISO passed fresh BIOS Fire and UEFI Ice Calamares installs, Core first-boot, and a code-mode session/execute with unlimited RLIMIT_AS. Upgrade, 45-minute stress, the full visual matrix, and the complete APT/evidence publication are not claimed.

  • Mission Control queues code, citation-backed report, and deterministic FFmpeg work against an approved project and records files, tests and changes for review.
  • Firebreak keeps MemoryMax at 3072 MiB and leaves RLIMIT_AS unlimited so Codex V8 sandbox VA reservation no longer SIGTRAPs.
  • Fire starts connected. Ice is chosen from the live Ice GRUB menu so sf.element=ice is present at install, and Ice stays offline.
  • For the first time in Shadowfetch Linux, choose Grok Bot at startup. A world-first Grok-on-Linux claim is not established.
  • Local AI / Buzz replacement is deferred. No model weights or cloud credentials are bundled.
ISO
shadowfetch-4.0.0-amd64.iso
Size
3.98 GB (3.71 GiB)
SHA-256
137c1f29e206c0d0e26e524c8c34a7dfe43b24c1d1df29f85d6b15283bab67fc

Previous release

Shadowfetch Linux 3.5.0 «Umbra»

Retired release

Shadowfetch Linux 3.5.0 turns the Fire and Ice identity into an operating model for production work. Fire starts connected and throughput-oriented; Ice starts agent sessions with no network. Element Workbench creates four private, consequence-aware project environments for software, AI, operations, and creative work. Buzz remains the optional local-model workspace, while Codex, Claude Code, Grok Build, and Cursor Agent remain independent, verified, user-owned choices. No model, cloud credential, account, OpenClaw runtime, or Hermes runtime is embedded. The exact signed ISO passed fresh BIOS Fire and UEFI Ice installs, recovery and visual gates, and a 2,709-second concurrent stress run with zero failures.

  • Element Workbench: Software Studio, AI Lab, Production Ops, and Creative AI show disk, network, account, accelerator, and package consequences before one signed transaction creates a private project with agent rules, provenance, tests, runbooks, and receipts.
  • Fire and Ice are real execution postures, not only themes: Firebreak defaults Fire sessions to connected and Ice sessions to no network, keeps the system read-only, scopes writes to the selected project, strips known secret variables, and records a visible launch receipt.
  • Buzz remains the sole optional local-model workspace. Model selection and download happen only after confirmation; no model weights are bundled. Codex, Claude Code, Grok Build, and Cursor Agent are optional, digest-verified installers with native sign-in and no preloaded credential.
  • Phoenix and Fireproof wrap profile installation, updates, and recovery with visible checkpoints, simulation, explicit confirmation, failure receipts, and tested retry paths.
  • Release QA: 11 of 11 prepublication gates passed; fresh BIOS Fire and UEFI Ice installs booted from disk; all 15 required visual frames passed at 1366x768 and 1920x1080; 214 rootless-container cycles and 239 Workbench/health probes completed during 2,709 seconds of sustained load with zero failures.
  • Supply-chain evidence includes the detached ISO signature, a 3,350-component CycloneDX 1.5 SBOM, manifests for 16 binary packages from 14 signed sources, and a 58-input reproducible QA evidence bundle.
ISO
shadowfetch-3.5.0-amd64.iso
Size
3.98 GB (3.71 GiB)
SHA-256
2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995

Previous release

Shadowfetch Linux 3.0.0 «Umbra»

View archived release

Shadowfetch Linux 3.0.0 «Backfire» makes Shadowfetch the agent-safe local-AI workstation: the first desktop OS where autonomous coding agents are contained, observed, and reversible by default. The new Fireline system runs any agent full-auto inside a bubblewrap sandbox with the entire system read-only and only your chosen project writable, cuts its network on request, strips your API keys from its environment, takes a checkpoint before every session, and lets you undo everything the agent did with one command. Four signed, dependency-free first-party MCP servers let an agent call a checkpoint before it touches anything, and AI Ignition recommends an Apache-2.0 open model that actually fits your GPU. Everything from 2.1.5 carries forward: Shadowfetch Guide and the private System Passport, Phoenix restore points, Fireproof simulate-first updates, the optional loopback-only Buzz workspace, signed ISO and APT chain, zero telemetry, and the full creative stack.

  • Firebreak (shadowfetch-firebreak): run any coding agent — Claude Code, Codex CLI, Cursor, Grok Build, Aider — in full-auto mode inside bubblewrap: system mounted read-only, only the chosen ~/Workspaces project writable, optional --net none, and known credential variables stripped from the agent environment by default. Every session gets a pre-run checkpoint, a session manifest, and a journald audit record.
  • Agent Checkpoints (shadowfetch-checkpoint): snapshot, diff, and undo one workspace — see exactly what an agent touched (content-hashed diff) and reverse everything it did with one command. Btrfs subvolume snapshots when available, portable archives otherwise; a safety point is taken before every undo.
  • Shadowfetch MCP suite (shadowfetch-mcp): four signed, dependency-free Model Context Protocol servers — passport (read-only, privacy-scrubbed self-check), phoenix (read-only restore points), checkpoint (snapshot/diff/undo one workspace), fs (scoped read-only files). One command prints ready-to-paste agent configuration.
  • AI Ignition (shadowfetch-ai-ignition): reads your GPU's VRAM and recommends an open model that actually fits, from an Apache-2.0-forward catalog (Qwen3, Devstral, gpt-oss) — CPU-only machines get a right-sized pick, never a 130 GB download. All model downloads remain consent-gated; nothing is bundled in the ISO.
  • shadowfetch-hardware: the offline firmware diagnoser — names the Debian package behind a silent Wi-Fi/Bluetooth failure and prints the exact fix, designed to work with no network at all.
  • Release QA: BIOS+UEFI boot, a clean UEFI Btrfs install that boots from disk, and a full stress run (all cores + memory + IO saturated) with the desktop staying responsive and zero failed services — plus the Fireline containment suite: sandbox escape attempts blocked, network cut verified, credential scrubbing verified, checkpoint undo byte-identical.
ISO
shadowfetch-3.0.0-amd64.iso
Size
3.97 GB (3.69 GiB)
SHA-256
110b0d075e699a05a8a2f8f8dcd05f19454bc8ae09acd0745ca0d947db8c5e3c

Previous release

Shadowfetch Linux 2.1.5 «Umbra»

View archived release

Shadowfetch Linux 2.1.5 makes the first Linux session more useful and more honest. The new Shadowfetch Guide and its private System Passport check graphics, networking, audio, firmware, memory, storage, recovery readiness, and local-AI capacity before you install, and remain the first Control Center section afterward. The Passport is deterministic, read-only, and on-device: host identity, account names, serials, PCI-slot, and filesystem identifiers are omitted from any report you choose to save as HTML or JSON. Buzz stays the single optional local-AI workspace, loopback-only by default, and is now guarded against the WebKitGTK DMA-BUF freeze on Plasma Wayland. Four independent coding agents are offered as unchecked, verified, user-owned options with no bundled credentials. The signed 2.1.4 upgrade path, Phoenix rollback on separate-/boot Btrfs, and BIOS and encrypted UEFI installs were all re-validated against the exact final ISO.

  • Shadowfetch Guide and System Passport: a deterministic, read-only check of graphics, networking, audio, firmware, memory, storage, recovery readiness, and local-AI capacity — available from the live Ignition screen and as the first Control Center section. Its public schema is allowlisted and omits host identity, account names, hardware serials, PCI-slot, and filesystem identifiers, and it can export a redacted report as HTML or JSON.
  • Buzz remains the one optional local-AI workspace, keeps its relay and compute listeners loopback-only by default, and is now guarded against the WebKitGTK DMA-BUF rendering freeze on Plasma Wayland while preserving the normal X11 path and explicit overrides. No open model is bundled; Buzz downloads one only after you confirm in Settings > Compute.
  • Optional coding agents at first-run setup — OpenAI Codex CLI, Claude Code, xAI Grok Build, and Cursor Agent — each unchecked by default, pinned and verified, installed for the desktop user, with all sign-in left to the tool itself and no credentials preloaded.
  • Verified in-place upgrade from 2.1.4 through the signed APT repository (sudo apt update && shadowfetch-update), exercised from a real 2.1.4 install with user files and Buzz state preserved and zero failed services.
  • Update safety and recovery re-validated: the Phoenix atomic-swap and separate-/boot Btrfs rollback defect found in VM stress was fixed and re-tested, interrupted and removal-seeking updates recover, and BIOS plus encrypted UEFI installs pass on both firmware paths.
  • New-generation NVIDIA workflow validated against a physical RTX 5060 Ti; renderer claims stay measured — AMD and Intel Mesa paths ship but are not performance-claimed without a physical card.
ISO
shadowfetch-2.1.5-amd64.iso
Size
3.97 GB (3.70 GiB)
SHA-256
848f043e4d6f85c3607e7034ba911a1ce8b4a317674feebef8b07fcd8f531c24

Previous release

Shadowfetch Linux 2.1.4 «Umbra»

View archived release

Shadowfetch Linux 2.1.4 is a focused modernization of 2.1.3. It strengthens the graphics path for new-generation NVIDIA cards, verifies NVIDIA's Debian 13 keyring, uses nvidia-driver-assistant to select the supported branch, simulates every transaction, refuses removals, and takes Btrfs Phoenix snapshots around driver changes. The workflow was validated in release QA against a physical RTX 5060 Ti with a removal-free transaction. Full upgrades are simulated and re-verified before applying, the 2.1.3 upgrade uses a removal-free bridge, and BIOS and UEFI encrypted installs were validated on both firmware paths.

  • Local model downloads remain optional and consent-gated; nothing is fetched until the user confirms the choice in Settings > Compute.
  • Graphics: new-generation NVIDIA cards no longer dead-end; keyring-verified nvidia-driver-assistant workflow with simulate-first, --no-remove, and Phoenix snapshots — validated against a physical RTX 5060 Ti.
  • Update safety: upgrades are simulated and re-verified before applying, refuse low-disk/active-package-manager/bad-power, and take a Phoenix pre/post pair; an interrupted update was killed mid-transaction in QA and recovered cleanly.
  • Removal-free 2.1.3 upgrade bridge; the migration retires only the signed legacy local-AI package set and preserves personal workspaces and downloaded models.
  • BIOS and UEFI encrypted installs (LUKS2 on Btrfs) validated on both firmware paths, including repeated reboot/unlock cycles and GRUB snapshot-boot recovery.
  • Launcher cleanup: the Local AI section and Lost & Found no longer duplicate after optional software is installed.
ISO
shadowfetch-2.1.4-amd64.iso
Size
3.97 GB (3.70 GiB)
SHA-256
81a906788ec48150d4a4527b4d9e7b09a974d3d577f1bd32ba3f333df8a1a86b

Previous release

Shadowfetch Linux 2.1.3 «Umbra»

View archived release

Shadowfetch Linux 2.1.3 is a security and stability release. A critical Calamares installer bug is fixed: sf-remove-live-user ran pkill -KILL -u shadow inside the target chroot to clear a defensive obstacle, but a chroot does not isolate the process table, so the signal killed the live desktop session instead, aborting every install at job 23/43 and leaving a half-installed system that retained the live shadow account with its published password and NOPASSWD sudo -- the exact exposure the script exists to close. The script no longer signals any process; it edits the target account database files directly, then verifies every artefact is gone and fails loudly if not. This release also stops shadowfetch-firstboot.service from running during a live session, which previously set the hardware clock and fetched Flatpak themes on a visitor's machine before the firewall was even up.

  • Critical fix: the installer no longer kills the live session mid-install.
  • Fixed a separate install-blocking bug found during QEMU verification: the removepackages step referenced two nonexistent live-task-* packages, aborting every install.
  • The live shadow account is now removed by editing target account files directly, with a fail-loud verification of every artefact -- account, password hash, home directory, sudoers, and autologin.
  • First-boot setup no longer runs when booting the ISO live (was setting the wrong hardware clock and fetching Flatpak themes on visitors' machines before the firewall was up).
  • No feature changes from 2.1.2 Fire Edition -- Ember Mode, Firewatch, Phoenix Recovery, Ignition Setup, and Fireproof Updates are unchanged.
ISO
shadowfetch-2.1.3-amd64.iso
Size
4.01 GB (3.73 GiB)
SHA-256
5f6a639b98e280c3fd46fc581ed899ec4ca861fb924bed266d4e13b9f4d0a2fd

Previous release

Shadowfetch Linux 2.1.2 «Umbra»

View archived release

Shadowfetch Linux 2.1.2 «Fire Edition» — a Debian-testing derivative with KDE Plasma 6. A focused release built to run hotter, update safer, recover faster, and launch local AI with less friction, with zero telemetry and no cloud accounts. Shadowfetch Control Center gains three sections: Ember Mode holds the machine in a performance profile and always returns to Balanced on its own; Firewatch shows temperatures, resource pressure, and a plain-language heat-map of what each application and agent consumes, with live tokens per second from local models; Phoenix Recovery takes automatic Btrfs restore points before every update, driver install, and AI-stack change, restorable in one click. llama.cpp with the Vulkan backend is preinstalled and models arrive through one-click, checksummed downloads that are never bundled; an Agent Workspace template starts a model server bound to localhost only. Ignition Setup lets first boot choose Core, Creator, Developer, AI Workstation, or Full Flame, and Fireproof Updates analyses pending changes, snapshots first, and offers rollback if verification fails. This is also the first Shadowfetch release that fits a FAT32 USB stick, and the first on which an encrypted install boots.

  • Ember Mode: one-switch performance profile with crash-safe auto-return to Balanced.
  • Firewatch: hardware and local-AI activity monitor with a per-application heat-map and tokens/second.
  • Phoenix Recovery: automatic Btrfs restore points before risky changes, one-click restore.
  • Local AI on first boot: llama.cpp + Vulkan preinstalled; models are one-click, checksummed, never bundled; localhost-only Agent Workspace.
  • Ignition Setup: first-run system chooser (Core / Creator / Developer / AI Workstation / Full Flame).
  • Fireproof Updates: analyse, warn, snapshot, verify, and offer rollback.
  • Under 4 GiB: the first release that fits a FAT32 USB stick, via curation not feature loss.
  • Encrypted installs boot: three defects fixed and verified booting end to end.
  • Reproducible builds against a pinned snapshot.debian.org archive from a signature-verified base.
ISO
shadowfetch-2.1.2-amd64.iso
Size
4.14 GB (3.85 GiB)
SHA-256
9374a233c1bd6f38bcbfad2bf041805568afb13ee455c482a7c7f68e7d0c56b1

Previous release

Shadowfetch Linux 2.1.1 «Umbra»

View archived release

Shadowfetch Linux 2.1.1 «Umbra» — a Debian-testing derivative with KDE Plasma 6. A correctness release: 2.1.0 shipped identifying itself as 2.0.1 in /etc/os-release, the login banner, the installer branding, the SDDM theme and every helper command. The build now stamps the version from the version it was invoked with, and the commands read it at run time rather than carrying a compiled-in constant. It also gives shadowfetch-welcome, the graphical first-boot wizard, the --help and --version it never had — previously asking it for a version opened the flow that installs Flathub applications and the local AI stack. Everything 2.1.0 delivered is unchanged: Intel Sound Open Firmware with the matching ALSA profiles, Cirrus amplifier firmware, and shadowfetch-facts.

ISO
shadowfetch-2.1.1-amd64.iso
Size
4.51 GB (4.20 GiB)
SHA-256
f5fe0f20dd24176839d0443f75ac4110587dff1a369785abdbe2121e213afdba

Previous release

Shadowfetch Linux 2.1.0 «Umbra»

View archived release

Shadowfetch Linux 2.1.0 «Umbra» — a Debian-testing derivative with KDE Plasma 6. This release ships Intel Sound Open Firmware and the matching ALSA use-case profiles, so laptops whose audio DSP previously loaded no firmware and played nothing now have working sound out of the box. It also adds shadowfetch-facts, a read-only hardware inventory that records the source of every reading, and gives all sixteen helper commands a --help that is safe to run.

ISO
shadowfetch-2.1.0-amd64.iso
Size
4.51 GB (4.20 GiB)
SHA-256
71ebae6632579b0f5d890dae7fc458edc99d01d0b9c6f28d40cddfaddd6cbe30

Previous release

Shadowfetch Linux 2.0.1 «Umbra»

View archived release

Shadowfetch Linux 2.0.1 «Umbra» — a Debian-testing derivative with KDE Plasma 6. This release repairs apt on installed systems, makes the on-device AI tools reachable from the application menu, and adds virtual-machine guest integration.

ISO
shadowfetch-2.0.1-amd64.iso
Size
4.50 GB (4.19 GiB)
SHA-256
b5e7fbe232027958aac2296c2e623a56e20f85c61d444fd59a784c2edbdb04be

Previous release

Shadowfetch Linux 2.0.0 «Umbra»

View archived release

Shadowfetch Linux 2.0.0 «Umbra» — a Debian-testing derivative with KDE Plasma 6, built 2026-07-21. amd64 hybrid ISO, BIOS and UEFI, 4.49 GB (4.18 GiB).

ISO
shadowfetch-2.0.0-amd64.iso
Size
4.49 GB (4.18 GiB)
SHA-256
0cbf9b90a4e561c57167cbac55d6fc4d02efc3dbd12a9c97c5034afc9fe6c671