v2026.07.03
2026-07-03 LatestNew
- installer match the display setup to the gpu layout
- shedos-system warn when a driver is missing for an installed kernel
- live prompt to remove the install medium before rebooting
- encrypt add the carved swap to fstab so it activates at boot
- installer stash the install-time recovery key for the tour
- encrypt wire the recovery-key tour for in-place encryption
- tour add the mandatory recovery-key slide
- encrypt wire the --status and --resume subcommands
- encrypt commit the flip once sd-encrypt is proven
- encrypt run the boot reconfigure from a first-boot finalize service
- encrypt bridge the boot on a flip-pending container
- encrypt arm the in-place conversion from shedman encrypt
- encrypt rebuild the encrypted boot path on first boot
- encrypt enrol the recovery key on first boot after encryption
- encrypt hand the reencrypted containers to userspace for enrolment
- encrypt carve and format a ram-sized encrypted swap
- encrypt reencrypt the root in place inside the initramfs
- encrypt branch the reencrypt boot on isLuks and the ESP phase
- encrypt add the ESP state lib for reencryption orchestration
- encrypt scaffold the shedman encrypt subcommand with preflight
- installer tag recovery keyslots with a luks2 token
- key remove a keyslot without locking yourself out
- key add a fido2 keyslot for boot unlock
- key add a passphrase keyslot
- key rotate the recovery key without stranding a way in
- key add luks2 token helpers for slot roles
- key add the canonical recovery-key generator
- key change the disk passphrase across every container
- key scaffold the shedman key verb with status
- doctor surface secure boot regressions in doctor and status
- secureboot add enroll sign repair and disable to the shedman secureboot verb
- secureboot add status and verify to the shedman secureboot verb
- boot move the kernel cmdline reconciler onto the signed uki
- boot rebuild and sbverify the signed uki in the esp recovery tool
- boot rebuild the uki between the initramfs rebuild and the limine render
- boot lift the kernel cmdline into /etc/kernel for the signed uki
- tpm2 add the shedman tpm2 verb for passwordless unlock
- installer build and place signed ukis on uefi installs
- installer mint per-box secure boot keys during install
- boot build a signed uki for every installed kernel
- boot chainload signed ukis on uefi and keep raw boot on bios
- boot build and place signed unified kernel images
- boot bundle cpu microcode into the initramfs
- packaging add the secure boot and tpm2 unlock tooling
- build add iso-local for a one-command local ISO build
- greetd record the last login so the greeter can preselect it
- shedman add the login subcommand to toggle the username field
- installer wire the recovery-key escrow into the install flow
- installer enroll the luks recovery key as a second keyslot
- installer encrypt new installs by default with ram-sized swap
- prompt-ui add icons to the username and password fields
- prompt-ui float the current user to the top of the dropdown
- locker tear down the parallel greetd on logout
- locker switch users from the lock screen
- locker add the polkit-gated switch-user helper
- locker pick a free vt for a parallel login
- greeter show a username dropdown on the login prompt
- prompt-ui paint the username field and dropdown list
- prompt-ui model the username dropdown on the power menu
- prompt-ui add the shared pieces for the username dropdown
- shedman re-theme the Textual TUIs live
- screensaver re-theme the lock prompt live
- switcher re-theme the strip live on palette change
- greeter re-theme the idle login screen live
- tour re-theme live on palette change
- prompt-ui LiveTheme helper for live system-wide theming
- site rebuild the upgrading guide
- site rebuild the keybindings, faq and hardware docs
- site rebuild the commands reference
- site rebuild the getting-started guide
- site re-skin the docs layout and sidebar
- site rebuild the changelog page
- site rebuild the download page
- site rebuild the 404 page
- site rebuild the docs landing
- site rebuild the community page
- site rebuild the about page
- site rebuild the compare page
- site rebuild the features page
- site rebuild the home page
- site add the table, download and terminal components
- site add the content-block components
- site add the shared layout primitives
- site add the client interaction script
- site render the nav, footer and lightbox server-side
- installer screenshots in the install slideshow
- ci run the emergency and lock gates on every ISO build
- test build an installed image for the QEMU boot harnesses
- doctor show boot-safety in the waybar pill
- live run the full desktop from skel, not a stripped config tree
- screensaver unlock without a password on the live ISO
- boot guided emergency recovery instead of the sulogin dead-end
- fstab nofail on non-root mounts so a missing disk can't wedge boot
- site copyable terminal walkthrough for making the install USB
- site click to zoom screenshots in a lightbox
- site rewrite around ShedOS as its own OS, with screenshots
- system default to lumen, migrate existing installs
- branding Unsplash wallpaper set, lumen as default
- keyring rotation ceremony script that forces verified backups
- keyring trust the next signing key — rotation phase 1
- power hibernate everywhere, confirmation for everything but Lock
- hyprland ship Firefox as the default browser
- system hibernation on disk-swap machines
- migrate verify against the trusted-fingerprint set
- keyring staged signing-key rotation
- migrate adopt a running Arch install with --from-arch
- switcher native Alt-Tab window switcher
- shedman db create/drop/list — per-project databases
- shedman disk failure and scrub age in health
- tour first-run welcome tour
- hyprland explain auto-recovery on the desktop
- installer arm the boot-recovery hook on fresh installs
- system boot-failure auto-recovery
- desktop scheduled night light
- shedman shedman snapshot — manual checkpoints
- shedman say what's new after a ShedOS update
- system rank the mirrorlist on first boot
- site add changelog, faq, hardware, compare, and community pages
- shedman finish the completion matrix
- release make the RC soak real — channel bake + snapshot promote
- installer make BIOS installs actually bootable
- installer dual-boot — chainload Windows and register with NVRAM
- installer resolve airootfs.sfs for copytoram boots
- shedman teach the check tools the completion and help contract
- theme recolor the hardcoded half of the desktop
- shedman read keybindings from the compositor, not the config text
- hyprland migrate the config to Lua (Hyprland 0.55)
- theme render palette.lua for the Lua Hyprland config
- system arm fingerprint login at the greeter
- greeter run auth on a worker thread as a greetd conversation
- hyprland give the desktop feedback — OSD, screenshot fixes, DND
- power add Sleep everywhere and make logout actually log out
- nvim rebuild on LazyVim with every language server from the system
- packages ship the language servers nvim drives from the system
- security enable AppArmor by default
- system retire shedos-kernel only after linux-zen has booted
- boot repoint the boot path from shedos-kernel to linux-zen
- packages move the kernel from shedos-kernel to linux-zen
- hyprland open overskride for bluetooth and expire stray popups
- packages swap blueman for overskride
- system seed baked Claude Code into existing homes
- iso bake Claude Code from the official installer
- packages add six more linux-firmware splits
- system point nautilus-open-any-terminal at kitty
- packages add nautilus-open-any-terminal
- system make sshd a system.toml-managed service
Fixed
- key point status at sudo to read the keyslots
- secureboot point status at sudo to read the boot images
- secureboot sign the recovery image when enrolling
- ci unblock the recovery drill on release builds
- waybar restore the urgent workspace highlight
- system stop networkd from degrading every boot on WiFi installs
- installer drop the duplicate tmpfs /tmp fstab entry
- installer fall back to a loadable console keymap
- tour stop showing a blank recovery key after the first login
- repo keep [shedos] on the stable channel
- ci find limine.conf on the boot volume so the checks run
- ci run the boot-recovery and lock checks on the iso
- installer detect the nvidia gpu on more laptops
- shedos-system keep the old kernel until the new one has your drivers
- installer enable nvidia suspend and resume on supported gpus
- installer keep nvidia working across driver updates
- packages list libhwasan in the ISO package list
- installer set the finished page to restartNowMode user-unchecked
- packaging bundle libfido2 so shedos-system installs offline
- encrypt resolve the reencrypt target by PARTUUID not device path
- encrypt keep the ESP mounted for the first-boot enrol and finalize
- encrypt boot the encrypted disk through after conversion
- encrypt discover the ESP by its vfat filesystem
- encrypt strip the btrfs subvolume suffix from the root device
- encrypt pin the absolute shrink target at arm time
- encrypt order the reencrypt driver after the disk is probed
- encrypt do not resume a reencrypt that already finished
- encrypt mount the ESP in the reencrypt initramfs
- encrypt carve encrypted swap before reencrypting the root
- encrypt resume an interrupted in-place encryption after a power cut
- packaging install the shedman key verb
- key let remove-key drop a fido2 slot itself
- installer clear the installer's pyright errors
- test build a bootable base image on the new uki boot path
- installer move pcrbanks into the uki section of uki.conf
- installer register the recovery nvram entry before shedos
- secureboot fail verify when no boot images are found
- test start swtpm before building the qemu firmware args
- packages list sbsigntools in source list for shedos-system dep
- boot gate the uki signature check on uki.conf instead of db.pem
- installer always keep the microsoft ca on secure boot enroll
- installer arm secure boot only after the whole chain is signed
- boot stop sbctl double-signing the unified kernel image
- build set the build user's default rust toolchain
- screensaver keep the live ISO lock a pure screensaver
- hyprland switch waybar workspaces under the Hyprland Lua config
- packaging bump calamares to the recovery-key UX fixes
- branding make the Plymouth LUKS passphrase prompt usable
- boot keep the LUKS unlock prompt retrying instead of dead-ending
- installer enroll the recovery key on every boot-unlocked LUKS container
- build skip locally-built shedos packages in the AUR dep download
- build verify every AUR signing key landed before enforcing PGP
- build give the AUR build user working passwordless sudo
- build build packages on disk instead of a RAM-backed tmpfs
- packaging drop the rust version pin so rustup can build the crates
- live auto-start Calamares and suppress the first-run tour
- installer enroll the recovery key with the plaintext LUKS passphrase
- test pick the QEMU display + virtio GPU from what's installed
- ci inject every C-compat header ananicy needs under gcc 16
- ci patch ananicy sources missing <cstring> under gcc 16
- base-image refuse a tmpfs or too-small workdir up front
- base-image copy the kernels into /boot before mkinitcpio
- installer unlock the encrypted swap container so hibernation resumes
- locker keep the lock field on the owner after a switch
- greeter tear down the auth worker before rebinding users
- shell source powerlevel10k directly so the prompt loads
- locker never trust the environment in the root switch path
- test point the TUI suites at the tree's shedos_palette
- hyprland size the config-review window to the monitor
- shedman scope the config-review scan to dot-rooted trees
- prompt-ui fall back to a solid background on an unreadable wallpaper
- prompt-ui decode and refresh wallpapers by content
- tour render opaque from the first frame
- ci restore --privileged on the package-build container
- ci drop --privileged from the package-build container
- installer surface the specific bootloader-install failure reason
- installer give the efi mount nofail to match the written fstab
- iso null-safe the airootfs hook-removal cleanup
- iso pin the Claude Code hash in-repo, not the same-channel manifest
- ci anchor the local-hash rewrite so it can't touch the wrong line
- screensaver zeroize the lock password and tighten the fingerprint match
- greeter zeroize the password, time out greetd reads, degrade on shm failure
- ci don't persist the cut-release App token in the checkout
- installer stop blindly rmtree-ing home dirs during config deploy
- screensaver move the lock unit's StartLimit to [Unit] where it works
- installer reject control chars in the git name/email before writing
- installer bootstrap the postgres role under peer auth, no password
- ci gate AUR builds on a PKGBUILD hash ledger before signing
- boot make recover-esp fail loud when the ESP re-sync can't fit
- hyprland enable the surface per-user via skel, retire --global
- hyprland depend on awww and hypridle for the wallpaper and idle daemons
- shell point oh-my-zsh at its real /usr/share location
- test bring the base image up through uwsm so the gate sees the surface
- installer route installed login through greetd, mask getty@tty1
- greetd read config via a drop-in and self-heal the PAM stack
- live launch the live desktop through uwsm, not bare Hyprland
- test surface the base-image mkinitcpio error
- ci install the egl-headless display for the lock gate
- ci build the iso work tree on /mnt
- site point internal links at the directory routes
- test install the GL runtime the lock-gate qemu needs
- site drop the deprecated tsconfig baseUrl
- site use the static Inter and JetBrains Mono weights
- test create the base-image loop partition nodes by hand
- ci stop the bundled-AUR drift report from aborting the build
- ci patch all ananicy sources missing unistd.h under gcc 15
- test build the harness base image on a loop device
- ci keep the weekly aur refresh alive when one package breaks
- repo rename the testing repo to shedostest and publish its db
- iso drop the dead usr/local/bin chmod from prepare
- iso bake Claude Code by direct download, not the installer
- iso prefetch the iso-only-official packages too
- ci mount /usr and /opt instead of / for the disk cleanup
- packages match deps by bare name in the coverage check
- ci keep the new checks from blocking a release
- screensaver stop the lock's PAM account phase from setuid-failing
- screenshot save to ~/Pictures/screenshots, close after save/copy
- update don't open the config resolver when there's nothing to merge
- boot stop a full ESP from stranding linux-zen on migration
- mkinitcpio guard the linux-zen preset on the kernel being present
- theme stop waybar and the dock flickering on theme apply
- site show the testing ISO only when an RC is newer than stable
- system make boot-failure recovery runnable in the initramfs
- waybar give the doctor pill a glyph and the shared pill style
- hyprland reload the live desktop on theme apply
- hyprland require a shedos-system that renders palette.lua
- system don't fail a local build on an empty AUR bundle
- shedman updates tooltip rendered an empty box
- system LUKS-safe systemd-initrd everywhere
- meta keep live-ISO tooling out of the installed closure
- installer don't install the NVIDIA driver on GPUs it can't drive
- ci detect Rust packages by Cargo.toml in the build loop
- hyprspace follow hyprland to 0.55.4
- shedman logs TUI keeps its keybinding promises; review polish
- hyprland wire the doctor pill and sweep the dead waybar surface
- installer no autologin on installed systems
- shedman rank mirrors in the background, off the update screen
- installer drop the double initramfs build, raise the password floor
- screensaver resolve the username from passwd, not the environment
- shedman polish sweep across the core
- security scope the nvim sudoers env_keep, drop the 777 build dir
- shedman uninstall prompts before nuking a closure
- shedman AUR installs get review and signature checks back
- ci publish ISOs only from tag builds
- ci version the repackaged externals too
- ci exact-match AUR cache lookups and wipes
- ci let the weekly AUR refresh persist its work
- ci makepkg config that actually reaches the build user
- ci render the meta closure before the hash bump
- calamares declare the full runtime dependency closure
- keyring drop the self-contradictory GNUPGHOME guard
- keyring fail loud when the keyring files are missing
- migrate declare only the dependencies the script uses
- migrate write the canonical stable repo URL into the fence
- system sync kernels to the FAT boot volume on upgrades
- installer hard-block installs on too-small disks
- installer drop the GeoIP probe locale.conf still carried
- installer stop spawning login shells in finalize
- installer scan partitions for the root's LUKS UUID and fs type
- installer give the postgres role the user's real password
- shedman parse ufw port ranges and route rules, skip unknowns
- shedman services reads system.toml instead of fighting it
- shedman keep config review's --list and --dry-run read-only
- shedman adopt identical files instead of fabricating conflicts
- shedman per-signal status timeouts
- system stop shredding comma'd cmdline tokens in the backfill
- shedman let locale-restore actually heal
- shedman make planning read-only so doctor works without root
- hyprland sweep the backup litter the Lua migration walked past
- hyprspace pin the hyprland ABI and pick up the Lua overview functions
- dock supervise every child, not just the first
- hyprland declare the binaries the configs exec as depends
- hyprland stop clobbering the installer's locale, drop pacman aliases
- waybar point the battery click at shedman power, untangle RTMIN+8
- gitconfig repair the cm alias and ship the delta pager
- installer complete the calamares test mock for target_env_call
- hyprland retire blueman cleanly on upgrade
- system drop the dead blueman notification toggle
- packages restore the stock linux fallback kernel
- system skip apply's root check when surface roots are redirected
- system make upgrade-history work under password-required sudo
- security reject non-POSIX usernames in pg bootstrap
- security re-enable ufw after a firewall rollback
- build use an absolute keep-list path in the cache prune
- security require a password for wheel sudo
- archiso keep live-only and dead artifacts off installed systems
- installer lock root and remove the live user on install
- hyprland replace the lockdead screen with the lock wallpaper
- screensaver respawn the lock after a non-authenticated exit
- screensaver require authentication to release the session lock
Performance
- ci don't rebuild a package for a PKGBUILD comment edit
Internals
- screensaver one Wayland bring-up, greeting via the catalog
- system make _config-sync's conflict refresh overridable
Docs
- site show the real command output in the security guides
- site explain the secure boot and tpm2 flow end to end
- site document encrypting an existing install in place
- encrypt add the shedman encrypt man page and recovery runbook
- document the shedman key verb
- site add the secure boot and passwordless unlock guides
- document the secureboot and tpm2 verbs
- config document every system.toml section in the example
- install document full-disk encryption keys and recovery
- site remove the branding-license note from the about page
- keyring correct the rotation runbook's two traps
- tour the tour has six slides, not four
- repo truth-sync the READMEs and maintainer docs
- man catch the pages up with their tools
- site align the user docs with everything this cycle shipped
- hyprland man pages for the desktop subcommands
- shedman man pages for the eleven undocumented subcommands
- README and architecture truth pass
- site regenerate the keybindings page from the shipped metadata
- site document every shedman subcommand and fix install claims
- ops runbook for the account-side hardening
- packaging describe versioning as it actually works
- shedman tell the truth about update's consent flow
Testing
- encrypt prove in-place encryption resumes after a power-cut
- encrypt add a repeatable QEMU proof for in-place encryption
- iso add a secure boot mode to the qemu harness
- default the QEMU harness to 8 GiB for the installer RAM gate
- screensaver print lock/unlock markers for the boot harness
- health isolate the scrub check from the host's real btrfs
- emergency don't fail analyze-verify on a man-less runner
- ci assert every ISO boots before tags can publish
- smoke contract suite for the undedicated shedman tools
- rust unit suites for every overlay crate, wired into CI
- install close the failure-propagation gaps
- sync regression fixture for identical-content adoption
- aggregate target, HEAD-built screensaver, scriptlet coverage
- sync-configs neutralize the conflict-count side effect
- screensaver assert real logo variants, not figlet font names
- migrate update the execute-legacy fixture for hyprlock removal
- install rewrite for the current package installer
Chores
- ci drop the base image boot layout dump
- ci dump the base image boot layout to find the missing uki
- live capture the boot journal onto the target ESP at shutdown
- push refuse commits that carry CI-managed release bumps
- ci run the installer python suite in the tests workflow
- aur accept the upstream PKGBUILD bumps for yay chrome mise vscode
- site drop the superseded components
- site write the theme to a data attribute before paint
- site add the logo and favicon assets
- site drop tailwind for a single stylesheet
- ci move workflow actions off the deprecated Node 20 runtime
- screensaver clear three clippy lints in the lock surface
- site drop the repo footer link and the Arch meta line
- site drop the macOS comparisons from the FAQ and compare page
- hyprland drop the macOS comparisons from gesture configs
- branding clean the attic, name the assets, cite the real palette
- sweep the build, test and desktop litter
- iso live-ISO truth cleanup
- ci pin GitHub Actions by commit SHA
- shedman drop dead flags and stale packaging surface
- kernel align tests and docs with the linux-zen migration
- ci retire the shedos-kernel build machinery