Shadowfetch Linux 5.0.1 «Umbra»
Documentation
25 guides, covering installation, verification, hardware and Secure Boot, project workspaces, the security model, the known issues and the release history. Each page separates what the system does today from what is planned.
Get it running
From nothing installed to a working desktop.
- ShadowCode/shadowcode
The coding agent preinstalled in 5.0: one picker for your subscriptions, OpenRouter key or local models, approvals and diff review, and how the signed .deb is verified into the image.
- Optional agents/agents
Grok Bot, Hermes Agent and OpenClaw: what Welcome offers, how each installs, OpenClaw's advisory record, and what the agent network setting pauses.
- Mission Control/mission-control
Create scoped code, source-report and media missions; inspect activity, files, changes and recovery.
- Grok Bot/grok-bot
The official native desktop: verified installation, administrator approval and cloud account sign-in.
- Overview/
What Shadowfetch Linux is: a Debian testing and KDE Plasma 6 desktop built around ShadowCode, with inspectable agent sandboxes and signed downloads.
- Screenshots/screenshots
Captures of the signed 5.0 ISO: the desktop, Welcome, ShadowCode, Mission Control, the installer and the boot and login screens.
- Download/download
The ISO, its exact size, the checksum and signature, resuming a large download, and how to write it to a USB stick.
- Verify/verify
Confirm the SHA-256 checksum and the GPG signature on Linux, macOS or Windows before you install.
- Install/install
Boot the ISO, review Calamares partitioning and encryption, reboot, and follow the first-boot notes.
- APT repository/apt
The signed repository (suite umbra, component main, amd64) for adding Shadowfetch packages to an existing Debian system.
- Workspaces/workspaces
Workbench profiles, project folders under ~/Workspaces, the agent network setting and offline media workflows.
- Local models/local-ai
Models that run on this computer: ShadowCode's bundled llama.cpp runtime, and Mission Control's on-device provider, which needs a model service you supply.
- Historical local AI benchmarks/benchmarks
Measured tokens-per-second and VRAM fit on the studio RTX 5060 Ti (16 GB).
Hardware and boot
What it runs on, and the one firmware setting that stops it.
- Hardware notes/hardware
64-bit Intel and AMD requirements, RAM and disk headroom, NVIDIA and hybrid laptops, peripherals and virtual machines.
- Secure Boot/secure-boot
The installer is not signed by a Microsoft-trusted shim, so Secure Boot must be off. What that costs and how to do it safely.
Know the limits
Read this before installing on a machine you depend on.
- Security model/security
What is inherited from Debian, what Shadowfetch adds, what it does not collect, and the current caveats.
- 4.0.0 launch record/preview
The historical 4.0.0 launch films, hashes and Archive.org copy, kept as published.
- 5.0.0 ShadowCode release notes/releases/5.0.0
What changes for a 4.1 system, what is new, known issues and how to upgrade.
- 5.0.1 update notes/releases/5.0.1
An update through APT, with no new ISO: what it fixes, how to update, and its known issues.
- Known issues/known-issues
Caveats for 5.0 and the current download: the shared DKMS key advisory, waived acceptance cases, OpenClaw's advisory record, Hermes running unsandboxed, unsigned Secure Boot, Debian testing, VM graphics limits and recovery boundaries.
- Roadmap/roadmap
What is shipping now versus what is planned, in stages. Dates are targets, not promises.
Reference
Answers, history, licensing.
- FAQ/faq
Direct answers on the Debian relationship, who it suits, NVIDIA, which workflows need online access, and verifying the ISO.
- Changelog/changelog
The release history, and what changed in each one.
- Licensing & source/licensing
Upstream licenses, the license Shadowfetch's own components carry, and the written offer for corresponding source.
- Support the project/donate
Shadowfetch Linux is free and stays free. There is a tip jar, with no tiers, perks or gated features.