$grep ^NAME= /etc/os-release

hideOS

A Linux workstation that can't change under you.

Built from source and sealed: the whole system is one signed image, checked on every read. Updates replace it whole, and if one doesn't boot, the machine goes back by itself. Your files, settings and apps live outside it.

# pre-alpha: it builds itself from source, installs from its own installer, sets itself up at the first start, installs beside Windows and boots sealed in QEMU, Minimal to a shell and Workstation to the COSMIC desktop. not on real hardware yet.

A seal ringed with the fs-verity digest of the hideOS Minimal image shown on this page a1769de2c221fdf627add148b1581aa1ed0dd83a4477d4ccc9ca845a40a3a54e hideOS minimal/x86_64 sealed

# the ring is the fs-verity digest of the image in the screenshot below. its kernel boots that image and no other; change one byte of it, and the boot stops.

$cat promises.txt

# the model is macOS. what it buys is a machine that is always in a state somebody tested.

sealed/usr

Everything in /usr is content-addressed and verified on every read. Nothing writes to it, root included, so a machine can't drift from the image it booted.

whole updatesrollback

An update is a new image next to the old one, never a change to the running one. It gets three tries to boot; after that, the machine goes back to the previous image by itself.

your things, elsewhere/home

/home, /etc and /var sit on their own encrypted volumes and no update touches them. Apps come from Flatpak; development tools run in containers.


$cat docs/boot-chain.log

# from power-on to desktop, nothing runs that the step before it didn't verify.

  1. UEFI Secure BootChecks the boot manager's signature against hideOS's key.
  2. hideBootPicks the newest image with tries left and falls back when an update keeps failing. When nothing starts, it boots the recovery system.
  3. signed kernel imageKernel, initrd and command line in one signed file. The command line carries the system image's digest, so the signature covers it.
  4. hidestageH2Unlocks the disk with the TPM, then mounts the system only if its digest matches the one the kernel was signed with.
  5. oxinitPID 1, in Rust. Starts and supervises everything else, and never panics.
  6. COSMICH5The desktop, also Rust, with hideOS's updates and recovery as pages in its Settings.

$cargo xtask screenshot --edition workstation --login

# hideOS Workstation: COSMIC epoch 1.9, Mesa and LLVM built from source, booted sealed from its own disk, logged in at cosmic-greeter, in hideOS's Dracula theme. drawn by llvmpipe on QEMU's virtio-gpu.

The COSMIC desktop on hideOS in the Dracula theme: a thin menu bar with the hideOS logo in the corner, status icons, the power menu and Sun, Oct 4 with the time on the right; a terminal, framed by its shadow alone, shows hide status — good, running, boots next; the disk not encrypted; updates from ghcr.io/youhide/hideos:workstation-edge — over the Orion nebula wallpaper, with the dock below.

# a menu bar laid out like a Mac's: the logo in the corner, opening Applications; the power menu and the clock on the right, the update applet beside them. the focused window has no coloured frame, only its shadow. hide status, as the person: the deployment that runs, the disk, and where updates come from.


$cargo xtask setup-test

# the installer only writes the disk. the first start sets the machine up, as a Mac's does: language, keyboard, Wi-Fi, time zone, the account, and on an encrypted disk its passphrase and a recovery key shown once.

hidesetup, full screen in Dracula's colours: Welcome to hideOS, choose your language, a list from Dansk and Deutsch to English, and Continue.

# hidesetup, in libcosmic, as the login screen's user. each page is a call to hideupd, which answers no one else, and no one once setup is done.


$cargo xtask screenshot

# not a mock-up. the kernel, glibc, oxinit, zsh and uutils below were built from source by hideOS's own build system, booted in QEMU, and photographed by this command.

The hideOS console: os-release reads hideOS (pre-alpha), uname reports Linux 7.2.8-hideos, oxctl list shows the setup, banner and console services and the multi-user and default targets, and ls / shows the merged /usr layout.

# the login shell a few seconds after boot: cat /etc/os-release, uname -sr, oxctl list, ls /

$git clone https://github.com/youhide/hideOS && cd hideOS
$cargo xtask builder build
$cargo xtask image
$cargo xtask boot

$hideforge build minimal

# every package builds in fresh Linux namespaces with no network, seeing only its declared inputs. sources are pinned by SHA-256 and checked against upstream signatures where they exist. the bootstrap follows Linux From Scratch.

stagebuilds2018 laptop
0A cross toolchain (binutils, GCC, glibc), then the temporary tools stage 1 runs on.42 min
1More temporary tools inside that tree: Perl, Python, bison, Texinfo.13 min
2The system itself, toolchain first. Only stage 2 goes into an image, and every library it links must come from stage 2.~1 h

$cat ROADMAP.md

# each milestone ends with something that boots and is checked, not with code that compiles.

  1. H0Repository, architecture, build environmentdone
  2. H1hideforge builds hideOS Minimal, which boots to a shelldone on x86_64
  3. H2The seal: composefs, fs-verity, signed kernel imagesdone on x86_64
  4. H3Whole-image updates and automatic rollbackdone
  5. H4Real hardware: TPM disk encryption, Wi-Fi, suspenddone
  6. H5hideOS Workstation: COSMIC, Flatpak, containers for developmentdone
  7. H6NVIDIA as a signed extension; ARM64NVIDIA's driver as a signed extension each update brings along; ARM64 next
  8. H7Installer, recovery, hideBootdone
  9. H8Rust replacements for the bridges, where there is a reasonhidelogin replaces elogind; eudev and dbus-daemon stay