FAQ

This page is only Unwoke SecureBlue. Stock secureblue questions (rollback, USBGuard, kargs, Trivalent, …) live in the mirrored secureblue FAQ, which updates daily from their repo.

Did you ship stock feature requests faster than they did?

Some. We watch official secureblue GitHub. Those tickets stay on Shipped first until they ship, then the card says they shipped after us. If we later copy their better patch, that is written on the same page. We do not auto-copy. We do not claim kernel/UKI/ARM work an overlay cannot do.

I installed it. I logged in. Now what?

Do not open GNOME Software or Settings looking for a store. Open Unwoke setup (app grid, or ujust setup). Ordered walkthrough: After you log in. Keep defaults unless you have a named need. If something looks broken, it is usually a lock: ujust why.

Are you affiliated with secureblue?

No. Personal overlay. Their project is secureblue.dev. Use that if you want the official images, Trivalent, Bazaar, and the Contributor Covenant. Our conduct is the opposite of that document.

Is this more secure than stock secureblue?

Origin images: no. Stock + Trivalent is tighter on the browser. -trivalent images: equal on the house browser (same binary, patches, SELinux), stricter on extra policies and house locks (no store, Flathub/brew/Bluetooth/toolbox off, camera lock, …). Browserless: tighter than Origin because there is no fat brave_t and no Chromium in the image. That only lasts until you install a browser. It is not “safer than Trivalent while browsing.” Living list (easy words + every lock): Compared to stock.

What is the Trivalent flavor?

Rebase to unwoke-silverblue-trivalent (or kinoite / nvidia-open). We keep stock Trivalent and trivalent-selinux. We do not load brave_t. Extra Chromium managed policies (JIT-less, no WebGL, extension block, device guards, extra sandbox) and two flag packs (Network Service Sandbox, punycode/referrers) default on and revert with ujust set-trivalent-* (same packs as set-brave-*). This does not add Vanadium compiler patches on top of what Trivalent already ships. Do not Bubblejail it.

What is the browserless flavor?

Same overlay: Trivalent, Bazaar, and GUI stores are gone. Unlike Origin (unsuffixed) images, we do not install Brave Origin, do not load brave_t, and do not add Flathub. Rebase to unwoke-silverblue-browserless (or kinoite / nvidia-open variants). The recommended default with a house browser is still *-trivalent.

Easy host browser installs are blocked until you opt in:

ujust set-allow-browsers on ALLOW

That unmasks common Flatpak browsers and drops the rpm-ostree exclude list. Flathub stays off until ujust set-flathub verified. A random Firefox is usually worse than stock Trivalent. AppImage and rpm-ostree --disableexcludes are not blocked. toolbox/distrobox stay off until ujust set-toolbox on.

What is Brave Origin, and is it “full Brave”?

Brave Origin is a separate Linux package (brave-origin) with extras compiled out. Binary path: /opt/brave.com/brave-origin/brave. We do not install brave-browser. It is still Chromium-family software, not Trivalent.

Where is the software store?

There isn’t one. Bazaar, GNOME Software, and Plasma Discover are removed. Flathub is off on every flavor until ujust set-flathub verified (stock-like) or full.

What ujust commands did you add?

Stock secureblue commands stay. Overlay extras, all reversible, are listed on Features. Short list:

ujust setup
ujust why
ujust unwoke-status
ujust audit-unwoke
ujust set-flathub verified|full|off
ujust set-flatpak-lockdown on|off
ujust set-brave-hardening on|off
ujust set-brave-devices on|off
ujust set-brave-jitless on|off
ujust set-brave-extensions block|allow
ujust set-brave-isolation on|off
ujust set-brave-sandbox on|off
ujust set-brave-devtools lock|allow
ujust set-brave-bubblejail on|off
ujust set-trivalent-network-sandbox on|off
ujust set-trivalent-referrers on|off
ujust set-brew on|off
ujust set-camera-mic on|off
ujust set-admin-split on|off|add NAME
ujust set-bluetooth on|off
ujust set-toolbox on|off
ujust set-extra-daemons on|off
ujust set-unwoke-theme apply
ujust set-allow-browsers on ALLOW

What is ujust setup / ujust why?

First graphical login opens a window that explains the locks. Nothing turns off unless you pick it. Same later: app grid → Unwoke setup, or ujust setup. Search GNOME/KDE for Bluetooth, camera, Flathub, or “websites broken.” ujust why / Setup → You loosened puts locks back. ujust unwoke-test prints PASS/LOOSE/FAIL with a proof line for every overlay addition (Setup has the same button). Tutorial buttons open offline help on the disk, then the site. Leftover stock steps (their Secure Boot key, kargs, USBGuard) are theirs, not overlay unlocks. The daily-user screen before the greeter is supposed to be there — not a hung install.

Do tutorials go stale?

The hub and the vendor blocks on Proton/IVPN/Mullvad (and any new tutorial slug) are rebuilt at Pages deploy from vendor-installers.json plus docs/_tools/tutorials-core.json. A new vendor stanza with "tutorial": "foo" gets a card and a page. Hand-written steps stay; the live command list is injected. Offline copies on the image follow the next overlay bake (sync-offline-help).

How do we add another strict app?

One stanza in files/system/usr/share/unwoke/vendor-installers.json (kind, URLs, title). That is the only list. vendor.py check/heal, Setup → Strict apps, ujust install-vendor NAME, search launchers, and twice-daily CI all iterate every key. Do not add a Proton/IVPN-only special case. Curated menus can stay as shortcuts.

Will Proton/IVPN installers break when they change their site?

Usual vendor-side breakage is handled without you: new version/SHA, redirects, www vs bare host, renamed JSON fields, checksum in a sidecar file, repo path change, short outages (retried). CI heals the list when the new location is still HTTPS on their host with SHA512/SHA256 or gpgcheck=1. 5xx/timeouts are retried, not rewritten. Flathub, HTTP, or no checksum still opens an issue. On the image: ujust check-vendor-installers.

How do I install Mullvad VPN?

VPN only, not Mullvad Browser. Same list as Proton/IVPN (watched + healed):

ujust install-mullvad

Default: WireGuard import from their account (filename ≤ 15 characters on GNOME). Official mullvad-vpn repo only if you accept an extra RPM origin. Tutorial.

How do I install IVPN?

IVPN is a VPN (AntiTracker is inside their official app — not a Mail/Pass suite). No store:

ujust install-ivpn

Default: import their WireGuard file in Network Settings (filename ≤ 15 characters on GNOME). Keep system DNS; no Trivalent DoH. Official ivpn / ivpn-ui from their Fedora repo only if you accept an extra RPM origin. Snap is not used. Long form: IVPN tutorial.

Does Unwoke hide my IP?

No. The host is still your ISP. Hide the IP with Whonix KVM. Host extras that do not turn off Safe Browsing or NTS: TCP timestamps off (ujust set-anon-net on puts stock timestamps back); optional ujust set-anon-hostname on. Long form: Anonymity.

How do I run Whonix?

Official KVM, not VirtualBox. OpenPGP is required. Clipboard/USB/mic stay off:

ujust install-whonix
ujust start-whonix

Not Qubes. Not Tails. Host stays Unwoke. Long form: Whonix tutorial.

Where did last boot’s logs / hibernate go?

Default: journal stays in RAM only, hibernate-to-disk is denied, crash dumps are not saved, the file indexer is off. That cuts forensic leftovers. It is not Tails (your ostree is still on disk). Need journalctl -b -1 or hibernate:

ujust set-disk-traces on

Do stock ujust install-* still work?

The names work. The stock scripts are intercepted so overlay locks are asked first (Flathub off, lockdown, toolbox stubs, temp noexec, Docker vs podman). Catalog: Stock installers. Vendor repos (Proton, IVPN, Mullvad, Tailscale) are watched and healed. Do not run ujust rebase-secureblue — that leaves Unwoke.

How do I game without leaving locks off?

Setup → Gaming, or:

ujust install-steam
# click Steam, play, close Steam

Restore is automatic. Optional: ujust play stop. Optional asked sched-ext. We do not ship the CachyOS kernel. Long form: Play window.

How do I install Steam?

Same command as stock, but Unwoke extras that would break games are asked first (Flathub is off; Steam is not verified; lockdown, temp noexec, mic, Bluetooth). Nothing silent:

ujust install-steam

Required: unfiltered Flathub. Optional per-app Steam grants (keep lockdown on other Flatpaks). Xwayland and anti-cheat stay leftover stock. Long form: Steam tutorial.

How do I install Proton Mail / Pass / VPN?

No store. Same pattern as their ujust install-steam, stricter path:

ujust install-proton

Default: open proton.me in Trivalent (Mail, Pass, Calendar, Drive). VPN: import WireGuard, keep system DNS. Desktop Mail/Pass: official RPM from proton.me, SHA512 from their JSON, then you must accept unconfined userns or we abort. Unverified Flathub packages are not used. Long form: Proton tutorial.

A site broke after install

Same menu: ujust why. JIT-less is on by default on Origin and Trivalent. Turn it off and restart the browser:

ujust set-brave-jitless off

Camera/mic/USB in the browser: ujust set-brave-devices off and if the kernel lock is on, ujust set-camera-mic on. WebGL/WebGPU: ujust set-brave-isolation off. Passwords/autofill: ujust set-brave-hardening off. Extensions: ujust set-brave-extensions allow. Trivalent cookie wipes: ujust set-trivalent-network-sandbox off.

Flatpaks do nothing / need a million permissions

Permission lockdown is on by default (stock ships it as opt-in). Grant per-app in Flatseal, or:

ujust set-flatpak-lockdown off

Bluetooth does not work

Off by default (service masked + rfkill block bluetooth). Wi-Fi is not touched. ujust set-bluetooth on.

toolbox / distrobox: command not allowed

Off by default. /usr/bin/toolbox and distrobox* are wrappers until ujust set-toolbox on. podman stays so Flatpak is not wrecked.

.local names / mobile broadband gone

Avahi and ModemManager are masked (stock still leaves those on; they already mask cups/geoclue). ujust set-extra-daemons on.

Does Unwoke make me easier to fingerprint?

Two different things. Phone-home off (countme, connectivity-check, DHCP hostname, thumbnails) does not fingerprint websites — leave those off. Extra browser packs (JIT-less, WebGL off, no extensions, devices blocked) make you rarer than stock Trivalent. We still ship those packs: security first. Best crowd on Unwoke is *-trivalent. If you choose to look closer to stock Trivalent, turn one pack off, then restart the browser. Full text: Fingerprinting vs locks. Setup has a read-only button; nothing auto-unlocks.

Countme, hotel Wi-Fi, hostname, no previews

We phone home less than stock. Fedora countme is masked, NetworkManager connectivity-check is off, DHCP does not send your hostname (IPv6 stable-privacy, no LLMNR/mDNS registration), GNOME/Dolphin thumbnails are off, Chromium Privacy Sandbox / Cast / Google time-query are off. Hyperlink ping is off in the hardening pack. Safe Browsing stays on. None of that turns off SELinux or USBGuard. Chromecast: ujust set-brave-hardening off (warned loosen). Hotel portal: ujust set-connectivity-check on.

ujust set-countme on
ujust set-connectivity-check on
ujust set-dhcp-hostname on
ujust set-thumbnails on

Where is brew?

Off by default — stock secureblue ships Homebrew. Enable: ujust set-brew on then a new shell.

Webcam and microphone are dead

Default lock: uvcvideo (and a few Intel IPU modules) blacklisted, V4L nodes and ALSA capture devices mode 000. Speakers and USB headsets (playback) stay. ujust set-camera-mic on then replug or run0 modprobe uvcvideo.

Can wheel log into GNOME/KDE?

On first boot a tty1 prompt asks for a daily (non-wheel) username and password before GDM/SDDM. After that, wheel is blocked from the greeter. TTY and run0 still work. Empty name or 5-minute timeout skips (lock stays pending). Skip forever: ujust set-admin-split off. Later: ujust set-admin-split add NAME.

Wallpaper, lock screen, accent

Default Unwoke navy wallpaper, a darker lock image, dark style, GNOME named accent blue, GTK/KDE #3b6cff. Gallery: Brand. GNOME has no classic screensaver; the lock screen is that image. Re-apply: ujust set-unwoke-theme apply.

What is set-brave-bubblejail?

Extra sandbox around Origin’s desktop launcher. Default on. GPU, PipeWire, and portals may break. ujust set-brave-bubblejail off if the window will not start. On -trivalent this command is refused: stock already jails Trivalent, and their FAQ says Bubblejail on Trivalent is broken.

Did you turn user namespaces back on?

Not globally. harden_userns stays on. On Origin images, Brave Origin is labeled brave_t and that domain is on secureblue’s userns allow-list. Trivalent images keep stock trivalent_t only. Browserless images do not add an extra domain — same as stock with Trivalent removed. Unconfined apps still cannot create user namespaces.

Why Unwoke SecureBlue that way?

Unwoke is the adjective/verb modifier. SecureBlue is one proper name (S and B capped), not “Secure Blue”. Repo and GHCR slugs stay lowercase because registries do.

Where is the changelog?

Changelog is rebuilt with the site from public git subjects (title + date + short hash). The top of that page, Home “What’s new”, and the Compared ledger are the people-facing cut (overlay, install, tutorials). Factory-only commits stay off those lists. Optional People: / Vs: / Where: in a commit body write the Compared row in easy words. No commit bodies, diffs, or file lists in the public log. Subjects that look like secrets are dropped.

How do updates work?

Not a git fork. CI pulls their signed image, verifies it with their public key, pins the digest, layers this overlay, and cosign-signs the result. Your machine follows ghcr.io/sergi270710267/… with rpm-ostree after the signed rebase. Rebuilds at 08:00 and 20:00 UTC. CI refuses to overlay if the stock image names this overlay (see Could stock target this overlay?).

Could stock target this overlay?

They cannot push to this GitHub repo or to ghcr.io/sergi270710267. After the signed rebase, your PC does not pull ghcr.io/secureblue/… anymore; it pulls Unwoke. Cosign on their base only proves they signed it — it does not prove the next image is friendly.

What they could do is ship a public signed base that stays quiet on stock and only acts if Unwoke files exist, then wait for our twice-daily overlay to republish it. They cannot give our CI different bits than everyone else for the same digest. A generic backdoor in the kernel that hits every secureblue user is the same trust you already accept by using their images; overlaying does not add a second magic seal against that.

What we do: before every image build, CI cosign verifys each official base, then inspects it with crane export (never docker-pull, never run) for this repo’s name, GHCR, and overlay paths. A hit fails the build — no new Unwoke image. Their key is vendored; if cosign.pub on their live branch moves, CI stops until a human updates keys/secureblue.pub. This does not catch obfuscated payloads or a backdoor aimed at everyone.

After a successful publish, CI crane-exports the new GHCR image and checks flavor, trampoline, and store launchers. The same inspect runs twice a day even if nothing was pushed. A red factory (canary, watch, build, or inspect) opens or comments on one GitHub issue labeled factory-alarm; it is closed when the overlay factory is green again. A canary hit or a new signing key is never auto-merged.

If a bad Unwoke image did get out: rpm-ostree rollback, or rebase to a previous digest you still trust. Keep 2FA on the GitHub account that holds SIGNING_SECRET. That secret is how Unwoke images are signed; stock does not have it.

Automatic split: their signed image (kernel, SELinux, Trivalent) is overlaid on a schedule. Copied helpers are not executed from stock /usr/libexec/secureblue/*.py. Stock ujust harden-flatpak still calls that path; the file in the image is an Unwoke trampoline that execs /usr/libexec/unwoke/harden-flatpak.sh. CI watches their harden_flatpak.py and flatpak.just. If they change and the new file does not name this overlay, Actions commits the snapshot and regenerates our Flatpak lockdown lists. Your PC still runs Unwoke scripts. A file that mentions Unwoke / our GHCR is refused (no auto-copy). Malloc preload stays our shell script so we do not exec their Python on the box.

Login MOTD is Unwoke’s, not their “welcome / donate / rebase” banner. Their deprecation notice, update-verification, and flatpak-setup user units are masked (they can re-add Flathub or tell you to rebase to stock). Bring them back with ujust set-stock-nags on. Their Secure Boot key check stays. Mirrored docs strip script-like HTML.

Can I trust the signing key?

You can verify with cosign.pub in the repo. The private key is a GitHub Actions secret, not a YubiKey. That is weaker than a hardware key. It is stated on the home page on purpose.

How do I contribute?

This overlay: our GitHub, Contributing, and our conduct. Fork → PR → green pr-gate + canary → the maintainer merges. No auto-merge. Workflows and alarms: Factory → GitHub map. Stock secureblue (Trivalent, their image recipes, their CoC): their mirrored contributing page. Do not send Unwoke patches to their repo or the other way around.

Can I install without stock secureblue first?

Yes. Actions → iso wraps the Unwoke GHCR image in a live/installer USB (Titanoboa). You flash that, not their ISO. GitHub will not host a ~4 GB file as a normal release, so the ISO is an Actions artifact (90 days) and a ghcr.io/sergi270710267/<name>-iso:latest package you pull with oras. The two recommended Trivalent sticks wrap after each green overlay; all twelve wrap on Sunday. Verify the package with cosign.pub, then the SHA256SUMS blob, then the file hash. Not Ventoy. Enroll your Secure Boot key from their post-install — the kernel is still stock. Stock-ISO-then-rebase remains valid. GitHub map, clock, and alarms: Factory.