Shadowfetch Linux 5.0.1 «Umbra»
Roadmap
This page separates what is shipping from what is planned. Dates are targets, not promises.
Shipping
Now shipping: 5.0.1 «Umbra»
- ShadowCode 1.0.0 is preinstalled as package shadow-code. Shadowfetch republishes upstream's .deb byte for byte; its Ed25519-signed release metadata is checked against a vendored trust policy at fetch, package-gate and ISO-gate time, and the bundled llama.cpp may live only under /usr/lib/shadowcode/.
- One picker in ShadowCode: subscriptions through each vendor's own command-line tool, an OpenRouter API key billed per token, or a free local model run by the bundled llama.cpp. You approve actions and review each task's diff.
- ShadowCode 1.0 is easy to start and ready for real work: free local models are listed first until you connect a subscription, a failed task says what went wrong in plain words with the next step, and ? opens a glossary. Approval cards say what an action does, how much it can affect and whether Rewind can undo it; Always allow here covers exact test and build commands per project. Commits, pushes and pull requests are checked for secrets first, new packages are looked up on npm, PyPI and crates.io, and API keys can move into the system keyring, which is created and unlocked at login so saving a key does not prompt. One rulebook reaches every agent; second opinions, per-step roles, spending limits ($1 a task and $10 a day by default), stuck detection, a code index for up to 250,000 files and review grouped by risk come with it.
- One look: gold #F2B33D and steel #BCC0C6 on black, from a new emblem and wallpaper across Plasma, SDDM, Plymouth, GRUB and the installer. The Ice colour scheme, Glacier Konsole scheme, Ice look-and-feel and the Fire/Ice wallpapers are removed; a one-time login migration repoints only settings that named a removed asset.
- shadowfetch-agent-network online|offline replaces the Fire/Ice switch's security half. Firebreak, Grok Bot, Hermes, OpenClaw, Workbench, Mission Control and Welcome read it; an upgraded Ice machine reads as offline, so no sandbox gains network. The boot menu offers the offline choice and the installer carries it to the installed system.
- Welcome offers exactly three optional agents -- Grok Bot, Hermes Agent (Nous Research) and OpenClaw -- each installed only if you pick it, then opens ShadowCode to connect your services. None is preinstalled.
- Removed: Buzz (including the 4.x retirement helper), shadowfetch-codex, shadowfetch-code-agent and shadowfetch-element. ShadowCode connects the vendor CLIs itself.
- fireproof update can update Fireproof itself. Until now the incoming package's install script stopped fireproofd, the daemon that runs apt and dpkg, so dpkg was killed halfway through and the update could hang for up to an hour. No install script stops fireproofd any more, stopping it signals only the daemon (KillMode=mixed), needrestart leaves it alone, and the new daemon takes over once the update has finished. An earlier update that was interrupted is reported with the command that repairs it, sudo dpkg --configure -a && sudo apt -f install, instead of being built on.
- Fireproof never removes packages as a side effect of an update. While Debian testing is in the middle of a library transition, it keeps the packages an upgrade would remove and holds back only those upgrades, lists them and says why; the rest of the update goes ahead, and held-back updates are not counted on the update badge. shadowfetch-desktop, shadowfetch-creative-base and anything you installed yourself are never removed by an update.
- ShadowCode 1.0.1 fixes the window that grew each time it opened under Wayland: it no longer saves its size (position and maximized state are still restored), and the first window is fitted to the screen it opens on. shadowfetch-desktop now requires shadow-code (>= 1.0.1).
- Mission Control no longer answers "database is busy" under heavy disk load. No database connection copies SQLite's write-ahead log back on close any more, which held an exclusive lock through two disk syncs, and show, list, events and the desktop's views read while the worker writes. shadowfetch-missions now needs Python 3.12 or newer, which 5.0 already ships.
- Stop works while the database is busy. shadowfetch-missions cancel saves the request first and answers at once; the worker records it in the mission's history at its next check, and a queued mission whose stop is not yet recorded does not start. Mission Control shows "Stop requested: saved, waiting to be recorded" until then. A Stop that arrives while the mission is already finishing is recorded as asked for and not applied, never lost.
- Missions created in the same second run, and list, in the order you created them. 5.0.0 broke such ties on the random mission id.
- A queued mission held until you review another mission for the same project says so: show and list report a hold naming the mission to review, and Mission Control shows the reason on the queue row and under Waiting in the mission's Overview.
- shadowfetch-defaults no longer starts KDE's update notifier on a live USB, so a live session would not download package lists after login. An update cannot change a USB stick: this reaches the live USB only with a later ISO, and a 5.0.0 stick keeps the refresh. Installed systems keep update notifications.
After that
Focus after the next release
- Scheduled and folder-triggered missions with explicit permissions and durable receipts.
- Builder/reviewer workflows with independent checks before acceptance.
- Authenticated remote mission control and voice entry with a review step.
- Project memory with sources, editable scope and a delete-index control.
- More installer and post-install diagnostics that produce better bug reports.
- More hardware notes from real tester installs.
- NVIDIA / hybrid laptop documentation improvements.
- Repeatable physical NVIDIA, AMD, Intel, laptop, suspend, and local-model performance coverage.
Near-term
Near-term targets
- Reviewer kit with screenshots, press brief, verification commands, hardware notes, and known issues.
- Directory submissions for Linux discovery sites.
- Demo videos showing boot, install, Grok Bot, creative tools, and update path.
- Community feedback loop: collect install reports, update known issues, cut the next ISO from actual problems.
Later
Later, after the basics are boring
- Secure Boot signing path.
- More reproducible build documentation.
- Expanded hardware test matrix.
- Better disaster recovery and rollback guidance.
What is broken right now
A roadmap is not a defect list. Known issues tracks what is actually wrong with the shipping release, and the changelog records what each release changed.