Shadowfetch Linux 5.0.0 / ShadowCode

One Harness. All Models.

5.0.1 is out. It is an update through the signed APT repository, with no ISO of its own: installed systems run sudo apt update, then sudo apt full-upgrade, and new installs use this 5.0.0 ISO, then update. 5.0.1 release notes.

Shadowfetch Linux 5.0.0 "ShadowCode" is rebuilt around ShadowCode 1.0.0, preinstalled from its signed upstream .deb: the desktop's coding agent, reaching the models of the subscriptions (Codex, Claude Code, Cursor, Antigravity, Grok, through each vendor's own CLI), API keys (OpenRouter) and local runtime (a bundled llama.cpp) you already have, with you approving actions and reviewing diffs. Fire and Ice are replaced by one gold-and-steel-on-black look, and their security half survives as shadowfetch-agent-network online|offline. Welcome offers exactly three optional agents -- Grok Bot, Hermes Agent and OpenClaw -- then hands you to ShadowCode to connect your services. Buzz and the shadowfetch-codex / shadowfetch-code-agent helpers are removed.

Release facts

Version
5.0.0 «Umbra»
Edition
ShadowCode — “One Harness. All Models.”
APT suite
umbra
Architecture
amd64, hybrid ISO (BIOS + UEFI)
Desktop
KDE Plasma 6.7.4, Frameworks 6.30, Qt 6.10.2
Kernel
Linux 7.2.6
System
systemd 262, Mesa 26.1.6
Base
Debian testing snapshot 20260929T000000Z
ISO
shadowfetch-5.0.0-amd64.iso
Size
4.09 GB (3.81 GiB)
SHA-256
2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21
Published
2026-09-30
Signing key
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1
Source
commit 9587a7ca348e817870baffa9d390754acf331266, tree 2986e02421fc6af1353ce7e7b7695a390c724acf
ShadowCode
1.0.0 — ShadowCode_1.0.0_amd64.deb, 28,862,468 bytes, SHA-256 6439c6307478dabe0a439fb400549fd5328a3bc527a71cf2561d141260e9d61a

Download shadowfetch-5.0.0-amd64.iso Verify it →

Why 5.0.0 and not 4.2.0

5.0 changes what a working 4.1 setup sees and depends on. The desktop is rebuilt around a preinstalled coding agent, the two looks become one, the Fire/Ice switch becomes a separate network setting, three commands are removed, and Welcome offers a different set of agents. The breaking changes come first.

Read this first: what changes for a 4.1 system

1. Fire and Ice are gone; the agent network replaces the switch

shadowfetch-element is removed, with its boot and session scripts, shadowfetch-element-boot.service and its autostart entry. The switch did two things: it changed the desktop's colours, and in Ice it started agent sandboxes without network and paused cloud agents. The second half survives as its own setting:

shadowfetch-agent-network                          # prints online or offline
shadowfetch-agent-network status                   # value and where it came from
shadowfetch-agent-network set online|offline       # your setting
sudo shadowfetch-agent-network --system set online|offline   # system default

offline means Firebreak sandboxes default to --net none and Grok Bot, Hermes and OpenClaw setup, update and launch are paused. online is the default. Resolution order: $SHADOWFETCH_AGENT_NETWORK, then ~/.config/shadowfetch/agent-network, then /etc/shadowfetch/agent-network, then online.

An upgraded Ice machine stays offline. On upgrade, the postinst writes /etc/shadowfetch/agent-network from /etc/shadowfetch/element (ice becomes offline, fire becomes online). A per-user element file is still read as the legacy value until you run shadowfetch-agent-network set. If you used Ice only for its look, run shadowfetch-agent-network set online.

  • The kernel option is now sf.agent-network=online|offline; sf.element= is no longer read. The live boot menu has an “agents offline” entry, and the installer carries the choice into the installed system.
  • JSON output renamed its fields: shadowfetch-grok-bot status --json reports agent_network and blocked_by_offline; shadowfetch-workbench plans report agent_network / recommended_agent_network. Update scripts that parsed element, blocked_by_ice or recommended_element.

2. One look: the Ice theme and the Fire/Ice wallpapers are removed

Removed: the ShadowfetchIce colour scheme, the ShadowfetchGlacier Konsole scheme, the org.shadowfetch.ice look-and-feel, and the UmbraFire, UmbraIce, UmbraFrost, UmbraDrift and UmbraGold wallpapers. ShadowfetchDark, ShadowfetchUmbra, org.shadowfetch.dark and the umbra SDDM theme keep their ids and are restyled to gold (#F2B33D) and steel (#BCC0C6) on near-black. At your next login a one-time migration repoints only settings that name a removed asset; your own wallpaper or another colour scheme is left alone.

3. shadowfetch-codex and shadowfetch-code-agent are removed

ShadowCode connects the vendor command-line tools itself, so the 4.1 helpers that installed Codex, Claude Code, Grok Build and Cursor Agent are gone and Welcome no longer offers those installers. CLIs they already installed in ~/.local/bin are left in place; menu launchers they wrote are removed at login only if they still run a removed helper. On a new install, install a vendor CLI from the vendor, then use Connect in ShadowCode's Settings › Accounts.

4. Buzz is removed completely

The 4.x Buzz retirement helper and its autostart entry are removed. 4.1 already retired Buzz's integration; if that had not completed for a user, 5.0 does not retry it.

What is new

  • ShadowCode 1.0.0 is preinstalled as package shadow-code. Shadowfetch republishes upstream's .deb byte for byte; its Ed25519-signed release metadata is checked against a vendored trust policy at fetch, package-gate and ISO-gate time, and the bundled llama.cpp may live only under /usr/lib/shadowcode/.
  • One picker in ShadowCode: subscriptions through each vendor's own command-line tool, an OpenRouter API key billed per token, or a free local model run by the bundled llama.cpp. You approve actions and review each task's diff.
  • ShadowCode 1.0 is easy to start and ready for real work: free local models are listed first until you connect a subscription, a failed task says what went wrong in plain words with the next step, and ? opens a glossary. Approval cards say what an action does, how much it can affect and whether Rewind can undo it; Always allow here covers exact test and build commands per project. Commits, pushes and pull requests are checked for secrets first, new packages are looked up on npm, PyPI and crates.io, and API keys can move into the system keyring, which is created and unlocked at login so saving a key does not prompt. One rulebook reaches every agent; second opinions, per-step roles, spending limits ($1 a task and $10 a day by default), stuck detection, a code index for up to 250,000 files and review grouped by risk come with it.
  • One look: gold #F2B33D and steel #BCC0C6 on black, from a new emblem and wallpaper across Plasma, SDDM, Plymouth, GRUB and the installer. The Ice colour scheme, Glacier Konsole scheme, Ice look-and-feel and the Fire/Ice wallpapers are removed; a one-time login migration repoints only settings that named a removed asset.
  • shadowfetch-agent-network online|offline replaces the Fire/Ice switch's security half. Firebreak, Grok Bot, Hermes, OpenClaw, Workbench, Mission Control and Welcome read it; an upgraded Ice machine reads as offline, so no sandbox gains network. The boot menu offers the offline choice and the installer carries it to the installed system.
  • Welcome offers exactly three optional agents -- Grok Bot, Hermes Agent (Nous Research) and OpenClaw -- each installed only if you pick it, then opens ShadowCode to connect your services. None is preinstalled.
  • Removed: Buzz (including the 4.x retirement helper), shadowfetch-codex, shadowfetch-code-agent and shadowfetch-element. ShadowCode connects the vendor CLIs itself.

ShadowCode in 5.0 → · The three optional agents →

Smaller changes

  • Mission engine: read-only queries retry a transient “database is locked” instead of failing the call.
  • Missions: provenance names the provider that actually ran, receipts record the model, and an interrupted mission cleans up its partial work and can be undone.
  • Login keyring: a login keyring is created and unlocked at login, so saving service keys (such as ShadowCode's API keys) no longer prompts for a keyring password.
  • The live session no longer locks its screen after idle and does not show the KWallet setup prompt.
  • shadowfetch-doctor flags the shared 4.x DKMS signing key (sec.dkms_mok), and an upgraded system shows a one-time notice about it at login.
  • Guide (the System Passport) opens without crashing, both from Mission Control's sidebar and from Welcome's Check this computer. make test now checks every shipped Python file for undefined names.
  • The Shadowfetch Welcome menu entry reopens setup at any time, also after setup is finished: it runs shadowfetch-welcome --force and no longer shares the login autostart entry.
  • The Firebreak launcher stays open: it shows shadowfetch-firebreak --help and leaves a shell ready, instead of closing at once.
  • Missions: the retry budget counts runs that actually happened, so cancelling and retrying a mission that never ran no longer uses it up. Real runs still count.
  • shadowfetch-control --help lists every page, including shadowcode and optional-agents.
  • Licence: Shadowfetch's own packages move from MIT to GPL-3.0-or-later, matching the repository LICENSE. The DrKonqi pickup helper stays GPL-3.0-only and shadowfetch-themes LGPL-2.1-or-later. See licensing.
  • “Element Workbench” is now Workbench; profiles recommend an agent network instead of an element.
  • ShadowCode updates arrive as system updates; /etc/shadowcode/policy.yaml turns off ShadowCode's own GitHub update check.
  • New shipped docs: SHADOWCODE.md, HERMES.md and OPENCLAW.md.

Known issues

  • Update with apt for now, not fireproof update. When fireproof update installs a new version of Fireproof itself, which every 4.1 to 5.0 upgrade does, it stops partway through and can stay stuck for up to an hour. Fireproof's update plan can also currently remove the desktop metapackages (shadowfetch-desktop, shadowfetch-creative-base) and apps such as Krita and Kdenlive while Debian testing is in the middle of a library transition; apt holds those packages back instead. Until further notice, update from a terminal with sudo apt update, then sudo apt full-upgrade, and not with fireproof update or Control Center's Software page. If an update already stopped partway (sudo dpkg --audit prints anything, or apt asks for dpkg --configure -a): 1) if apt says the lock is held by fireproofd, run sudo systemctl kill --signal=KILL fireproofd.service (a normal restart is refused while it is stuck; sudo systemctl reboot -i also works); 2) run sudo dpkg --configure -a, then sudo apt full-upgrade, then sudo apt install shadowfetch-desktop shadowfetch-creative-base; 3) restart.
  • ShadowCode 1.0.0's window grows each time it opens on Wayland: each launch restores a slightly larger window, which can end up extending under the panel, and on a 1366x768 screen even the first window is larger than the screen. Workaround: maximize the window (its maximize button, or Meta+PgUp); ShadowCode then does not save the size. Fixed in ShadowCode 1.0.1, part of the 5.0.1 update.
  • Under very heavy disk load, Mission Control or a shadowfetch-missions command can briefly report "database is busy" while a mission is finishing a step. Nothing is lost; retry after a few seconds and it works. Fixed in the 5.0.1 update.
  • Live USB: about five minutes after login, KDE's update notifier refreshes the package lists, a download of about 200 MB that also takes about 350 MB of RAM because the live session keeps its changes in memory. Installed systems are not affected. If the computer is low on memory or the connection is metered, stay offline in the live session or stop the notifier with systemctl --user stop app-org.kde.discover.notifier@autostart.service. An update cannot change a USB stick: 5.0.1 is an APT update with no ISO of its own, so a 5.0.0 stick keeps the refresh.
  • The 5.0.1 update fixes the first three issues above: from 5.0.1 on, fireproof update can update Fireproof itself and removes no packages during an update. Install 5.0.1 itself with sudo apt update, then sudo apt full-upgrade, not with fireproof update. It arrives through the Shadowfetch APT repository and cannot change a live USB stick, so on a 5.0.0 stick use the workaround for the fourth.
  • Published 2026-09-30. The ISO, its signature and checksum, the CycloneDX SBOM, the package manifest, the release dossier and the QA evidence bundle are on the download server and attached to the v5.0.0 GitHub release; PUB-01 confirmed that GitHub, this site, the signed downloads and APT expose the same release.
  • Acceptance on this exact ISO: 12 cases pass (including EVIDENCE-01) and 6 are waived by the release owner, who chose to ship this image and deliver its fixes through APT updates, starting with 5.0.1. Four waivers are account or harness limits: MISSION-01's code missions need a paid vendor account (the media and cited-report missions pass); GROK-01 and GROK-VISUAL-01 need an X/Grok account (install, integrity, launch to sign-in and the URL handler are proven; a signed-in session is not); UPGRADE-01's recovery leg has no harness. Two are checks that did not pass: SHADOWCODE-01's open/close soak failed only its memory-drift check, which a diagnostic rerun traced to the live session's one-time package-list refresh rather than ShadowCode; STRESS-01's two 45-minute runs of combined stress left the system healthy, but in both runs its mission loop stopped on "database is busy" and its container loop on a podman run --rm client that did not exit.
  • The 4.1 -> 5.0 in-place upgrade passed with every migration check (gold accent, the doctor's shared-key check, the one-time notice, the agent-network migration, retired launchers removed, user data preserved). Its recovery leg is waived: the VM harness cannot roll an upgraded system back, so rollback after an upgrade was not exercised.
  • The APT suite name stays umbra, so 4.1 systems receive 5.0 from the suite they already track.
  • OpenClaw has a long security-advisory record. Shadowfetch pins its lockfile, sandboxes it in Firebreak and never installs its Gateway by default; that narrows exposure but does not make it safe, and an enabled Gateway runs outside the sandbox with your file access. Keep it updated.
  • Hermes Agent is not sandboxed: it runs commands and edits files as you.
  • shadowfetch-agent-network governs Firebreak sandboxes and the three optional agents only. ShadowCode starts Online by default; its own Settings › Permissions & network › Offline limits it to local models.
  • ShadowCode's own agent runs shell commands in its sandbox; vendor CLIs (Codex, Claude Code, Cursor, Antigravity, Grok) enforce their own sandbox and do not inherit it.
  • On a machine with no GPU render node (many virtual machines), ShadowCode's window would idle at high CPU: 122-174% in 5.0 VM qualification. Shadowfetch sets WEBKIT_DISABLE_DMABUF_RENDERER=1 for the session only on such machines, which brought it to about 7% over two minutes; ShadowCode 1.0.0 does not handle this itself yet.
  • ShadowCode's first run can open in its light theme on the dark desktop; choose Dark in ShadowCode's settings.
  • Secure Boot is not Microsoft-signed; disable Secure Boot or follow the documented enrollment path.
  • Grok Bot needs an eligible account and internet. Hermes and OpenClaw need your own model-provider key.
  • Security advisory for 4.x installs: earlier ISOs shipped a shared DKMS module-signing key. It matters only if you enrolled its certificate in Secure Boot; see the known-issues page for the check and the fix. 5.0.0 images are built without it.

All known issues →

Upgrading from 4.1

The supported in-place path is the signed Shadowfetch APT repository. It pulls in shadow-code as a new dependency of shadowfetch-desktop. It was proven from an installed, APT-updated 4.1.0 system: the gold accent, the agent-network migration, the doctor's shared-key check and one-time notice, the removal of retired launchers and the preservation of user data all checked out. Rolling an upgraded system back was not exercised (UPGRADE-01's recovery leg is waived).

sudo apt update
sudo apt full-upgrade     # not fireproof update for now; see Known issues
  1. Log out and back in once, so the look migration runs.
  2. Check shadowfetch-agent-network status. An Ice machine reports offline; change it if you used Ice only for its look.
  3. Update any script that called shadowfetch-element, shadowfetch-codex or shadowfetch-code-agent, passed sf.element=, or parsed the old JSON field names.
  4. Open ShadowCode and connect your services in Settings › Accounts.

Verify the download

The same method as 4.1: check the detached OpenPGP signature against fingerprint 8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1, then the SHA-256. The expected SHA-256 is 2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21. Step-by-step verification →

Acceptance

Every case due before publication is recorded against this exact ISO (SHA-256 2d8a72e044e8061bd616b2b4668425cc4d4ec0480a98975f961c0e58cba95e21). Twelve pass and six are waived by the release owner, who chose to ship this image and deliver its fixes through APT updates, starting with 5.0.1 (see known issues). An update cannot change a USB stick, so a 5.0.0 stick keeps the live session's package-list refresh. PUB-01 (GitHub, this site, the signed downloads and APT expose the same release) is proven after publication.

Pass: SRC-01, PKG-01, ISO-01, FIRE-01 (live desktop and Mission Control), ICE-01 (offline agent network), INSTALL-01 (fresh BIOS and UEFI installs boot from disk), SCOPE-01, DURABLE-01, RECOVERY-01, VISUAL-01, RESOURCE-01 and EVIDENCE-01 (the checksum, signature, SBOM, manifests and QA evidence bundle for this ISO).

Waived, approved by the release owner. Each waiver records what was and was not proven. Four are account or harness limits:

  • MISSION-01, code sub-part: a real code mission needs a paid vendor account. The media and cited-report missions pass with validated artifacts.
  • GROK-01 and GROK-VISUAL-01: signing in needs an X/Grok account. Package integrity, installation, launch to the sign-in screen and the URL-handler registration are proven; a signed-in session is not.
  • UPGRADE-01, recovery leg: the VM harness has no recovery leg for upgrades. The 4.1 → 5.0 upgrade and every migration check pass: gold accent, the doctor's shared-key check, the one-time notice, the agent-network migration, retired launchers removed, user data preserved.

Two are checks that did not pass on this image:

  • SHADOWCODE-01: ShadowCode 1.0.0 is installed at the pinned version, launches, and went through 24 open/close cycles with clean exits, no crashes and 1.6–6.0% idle CPU. The soak failed only its memory-drift check; a diagnostic rerun traced the drop to the live session's one-time package-list refresh, written to its RAM overlay, not to ShadowCode. The same run showed ShadowCode's window growing on each launch under Wayland, a known issue fixed in ShadowCode 1.0.1.
  • STRESS-01: two 45-minute runs of combined CPU, memory, disk, container and mission stress left the system healthy, with no crashes, out-of-memory kills, failed units or thermal events, and ShadowCode up throughout. Two workload loops stopped early: mission commands reported “database is busy” while the worker finished a step under disk stress, and in both runs a podman run --rm client produced the right output but did not exit within 120 seconds. The “database is busy” fix is in 5.0.1 (see known issues).

Release state

Measured on the release image's own source and on the image itself, not copied forward from an earlier candidate: make test (2,578 tests, including the adversarial suites), source_gate (which also runs the 1,087 missions tests), package_gate (ShadowCode's signature, pin, bytes and reviewed lintian list) and iso_gate (shadow-code 1.0.0 byte-identical to the signed archive) pass; drift_gate reports 0 DRIFT and 4 BLOCKED, all pre-existing. The image was built from commit 9587a7c. Earlier candidate images are superseded; nothing here is claimed from them.

Source: Shadowfetchapps/shadowfetch-linux, branch release/5.0.0. Release history: changelog.