Not affiliated with secureblue. This is a personal overlay on their signed images. Stock secureblue is at secureblue.dev.
What's new
Rebuilt with the site from main. Factory-only commits (alarms, snapshot hashes, CI pins) stay off this list. Score vs stock: Compared. Every public subject: Changelog.
- Close this chat; resume from PROGRESS.md on GitHub main.
- Factory vendor-watch is contracts-green even when the bot cannot push HTML.
- GitHub sits with the other top links, not alone on the right. The left rail is grouped: Factory, On the disk, Project. Features and Shipped first can no longer push that rail aside.
- Clicking Shipped first no longer knocks the left menu over. That page had a heading id that matched the URL, and its feat cards could shove the rail aside.
- On a wide screen the primary pages stay in a slim top bar. The rest sit in a left rail so the menu is not one crowded wrap. Phones keep the wrapping bar.
- Factory now names every GitHub workflow, CODEOWNERS, the main-strict ruleset, receipt, and GHCR. After a green overlay, the two recommended Trivalent USBs wrap themselves. Sunday still wraps all twelve. Watch issues, not Actions.
About
Unwoke SecureBlue is a twice-daily BlueBuild overlay on official secureblue Fedora Atomic images. Kernel hardening, SELinux, hardened_malloc, closed firewall, and their ujust commands stay. We change house rules on top: no curator store, extra default-off locks (Flathub, brew, Bluetooth, toolbox, camera/mic), a first-day setup window, and a recommended *-trivalent house browser (Origin and browserless stay as named choices).
Recommended default: *-trivalent — stock Trivalent (Vanadium patches and their SELinux jail) plus extra reversible Chromium policies stock does not force. Unsuffixed names ship standalone Brave Origin (brave-origin, not full brave-browser) — looser SELinux, pick it on purpose. Browserless (*-browserless) strips Trivalent and installs nothing: no Origin, no brave_t, stock harden_userns. There is no GUI software store and no Flathub remote until ujust set-flathub verified. Every extra lock has a ujust to turn it off.
Shipped as OCI bootable container images. Empty disk: an Unwoke USB ISO (recommended Trivalent sticks wrap after each green overlay; all twelve on Sunday). Already on Fedora Atomic / secureblue: rebase. After login, walk After you log in: Unwoke setup is first-time setup, not GNOME Settings. If something looks broken: ujust why — same locks, no auto-unlock. Prove every overlay lock and shipped-first ticket on this disk: ujust unwoke-test (stock’s audit does not). Everyday tasks: Tutorials. Privacy vs stock: Privacy. Gaming vs stock: Gaming (play window restores). Full delta: Features. Scorecard: Compared. How the factory and GitHub sit: Factory.
Their hardening
Kernel args, SELinux, hardened_malloc, no Xwayland by default, USBGuard, run0. Inherited, not reimplemented. Unwoke navy wallpaper and blue accent on GNOME and KDE.
Three browser flavors
Recommended: -trivalent (stock jail plus extra locks). Unsuffixed: Brave Origin. -browserless: no image browser at all.
No curator store
Bazaar, GNOME Software, and Plasma Discover are gone. Flathub and Homebrew are off until you toggle them. Terminal: rpm-ostree, then ujust set-flathub verified / ujust set-brew on if you want those.
Unwoke look
Navy wallpaper, lock screen, dark style, blue accent. Every extra lock is a ujust. See Brand and toggles.
Privacy vs stock
We phone home less. Countme, connectivity check, DHCP hostname, Privacy Sandbox, Cast — off. Safe Browsing stays on. Every line reverts.
Gaming vs stock
Play window: GameMode for the match, full locks when you quit. Stock leaves Xwayland and anti-cheat on. No CachyOS kernel swap.
Anonymity
Not Tails. Hide the IP with official Whonix KVM. Host: timestamps off, no DHCP hostname. Do not mix accounts.
First day vs stock
Dark installer you can find. Setup on the dash. USBGuard in the window (default No). Steam restores. Signed reboot if you are not logged in.
Compared to stock
We beat stock on encrypt-on, harder LUKS, Flatpak record, extra folders, NFS/CIFS clients. Same kernel. No security cut.
Prove it on the disk
ujust unwoke-test — PASS/LOOSE/FAIL with a proof path. Stock audit-secureblue does not cover our extras. Nothing unlocks.
Shipped first
Their GitHub still has these open. Defaults here, with dates and a revert. We watch their tracker.
After you log in
Unwoke setup, not GNOME Settings. Daily user, signed reboot, leftover stock. Keep the locks for a day.
Tutorials
Apps without a store, Bluetooth, camera, USBGuard, updates, rollback. Secure path first.
Who this is for
People who already want Linux, already want secureblue’s hardening, and do not want a curated app catalog. Pick Origin, keep Trivalent, or run with no image browser.
The recommended image is *-trivalent: same house browser as stock, plus extra reversible policies. Origin images (unsuffixed) are not as locked down (no Vanadium patches, fat brave_t). Browserless is tighter than Origin until you install a browser; that install is blocked until ujust set-allow-browsers on ALLOW.
Honest limits
- Brave Origin is not Trivalent. No Vanadium-style Chromium patches, no tight Trivalent SELinux jail. Rebase to
*-trivalentfor that. - Extra Trivalent policies (JIT-less, no WebGL, extension block, Network Service Sandbox, …) are enterprise JSON / flags, not new compiler patches. They revert with
ujust. - On Origin images,
brave_tis an unconfined-like domain on the userns allow-list. Trivalent and browserless do not add that exception. - The signing key is a GitHub secret, not a hardware key.
- We do not rebuild their kernel or re-run their SLSA pipeline. We inherit whatever they already shipped, after checking their signature.