Features

Most of the security story is still secureblue’s (also mirrored here, updates daily). This page is everything this overlay adds or changes. Easy words + a living score vs stock: Compared — including prove it on the disk. Look is on Brand. What changed, day by day: Changelog. After login, Unwoke setup (app grid) explains the locks; ujust why maps “broken” to the matching toggle. ujust unwoke-test prints PASS/LOOSE/FAIL with a proof path for every overlay lock and shipped-first ticket (stock audit-secureblue does not). Strict apps: ujust install-proton, install-ivpn, install-mullvad (WireGuard first). Nothing unlocks unless you pick it.

Inherited from secureblue

We layer on their already-built, already-signed images. We do not reimplement these:

Read their list if you want the complete inventory. We did not gut SELinux, kernel args, disk encryption, or Secure Boot enrollment.

What this overlay changes

Four columns, left to right: stock secureblue, Unwoke Origin, Unwoke Trivalent (*-trivalent, the recommended default), Unwoke browserless. Trivalent is the same house browser as stock, then extra reversible policies stock does not force. Scroll sideways on a phone. Reverts: toggles.

Stock secureblue Origin Trivalent (*-trivalent) Browserless
Browser Trivalent — confined Chromium Brave Origin RPM. Fat brave_t. Stock Trivalent (same binary, patches, SELinux) plus extra reversible policies None. No Trivalent, no Origin, no brave_t
Vanadium / compiler patches Yes (Trivalent) No. Policies are not a substitute Yes — inherited, not rebuilt n/a (no browser)
Browser SELinux Tight trivalent_t Fat brave_t (unconfined-like) Same tight trivalent_t as stock. No brave_t No extra domain
JavaScript JIT Allowed Blocked by default. ujust set-brave-jitless off Blocked by default. Same toggle (stock does not force this) n/a
WebGL / WebGPU Allowed Off by default. ujust set-brave-isolation off Off by default. Same toggle (stock does not force this) n/a
Extensions Allowed Installs blocked. ujust set-brave-extensions allow Installs blocked. Same toggle (stock does not force this) n/a
Browser camera / mic / USB / BT / geo Site permission prompts Blocked by policy. ujust set-brave-devices off Blocked by policy. Same toggle (stock does not force this) n/a
HTTPS-only / no passwords / no metrics / no ping Compile-time defaults; not our JSON pack Managed pack on (no ping, no Privacy Sandbox, no Cast, no Google time-query). ujust set-brave-hardening off is a warned loosen Same managed pack on (additive if Trivalent already compiled some of this in) n/a
Extra sandbox pack No On: audio sandbox, no screen capture, JS optimizer off. ujust set-brave-sandbox off On. Same pack (stock does not force this) n/a
Network Service Sandbox Off in chrome://settings/security (can clear cookies) n/a (Origin launcher, not Trivalent conf.d) Forced on. ujust set-trivalent-network-sandbox off n/a
Punycode / strip referrers Optional chrome://flags n/a On via conf.d. ujust set-trivalent-referrers off n/a
Bubblejail on the house browser Do not wrap Trivalent (their FAQ) On. ujust set-brave-bubblejail off Refused. Stock already jails Trivalent n/a
DevTools lock Unlocked Locked. ujust set-brave-devtools allow Locked. Same n/a
App store Bazaar — curated catalog None. Flathub off until ujust set-flathub verified None. Same None. Same
User namespaces Off for unconfined; on for Flatpak and Trivalent Same, plus brave_t on the allow-list Same as stock. No brave_t Stock with Trivalent gone: unconfined blocked, Flatpak only
Host browser installs Trivalent is already there Origin is the house browser Trivalent is the house browser Blocked until ujust set-allow-browsers on ALLOW
Flatpak permissions Opt-in lockdown Lockdown on plus extra xdg/host-root cuts. ujust set-flatpak-lockdown off Same extra cuts Same extra cuts
Flatpak Pulse/PipeWire record Open request; not default Blocked. Independent of lockdown. ujust set-flatpak-record off Blocked. Same Blocked. Same
NFS / CIFS nfs-server masked; clients still load Server stays masked. Client modules blacklisted until ujust set-network-fs on Same Same
Empty-disk USB encryption Encrypt checkbox off; weaker LUKS memory LUKS on unless you untick. Argon2id 2 GiB Same ISO hook Same ISO hook
Homebrew Shipped Off until ujust set-brew on Off. Same Off. Same
Camera / mic (kernel) Available Locked until ujust set-camera-mic on (speakers stay) Locked. Same Locked. Same
Wheel on the greeter Typical daily user is wheel tty1 prompt, then wheel blocked from GDM/SDDM. ujust set-admin-split off Same prompt / lock Same prompt / lock
Bluetooth Available Off until ujust set-bluetooth on. Wi-Fi stays Off. Same Off. Same
toolbox / distrobox Available Off. /usr/bin/toolbox is a wrapper. ujust set-toolbox on Off. Same Off. Same
Avahi / ModemManager Typically on Masked until ujust set-extra-daemons on Masked. Same Masked. Same
Fedora countme On Masked. ujust set-countme on Masked. Same Masked. Same
Connectivity check On Off. ujust set-connectivity-check on for hotel portals Off. Same Off. Same
DHCP hostname / DUID Sent Not sent. ujust set-dhcp-hostname on Not sent. Same Not sent. Same
Thumbnails On Off. ujust set-thumbnails on Off. Same Off. Same
Disk traces Persistent journal, hibernate, cores, indexer Volatile journal, no hibernate. ujust set-disk-traces on Same Same
RAM disks + /var/tmp exec on /tmp, /dev/shm, and /var/tmp noexec. ujust set-ramdisk-exec on Same Same
Intel CET Open request SHSTK+IBT tunables on. ujust set-cet off Same Same
/boot Typically world-readable mode 700. ujust set-boot-perm off Same Same
Extra Fedora CAs Trusted Blocklisted vs Mozilla website set. ujust set-extra-cas on Same Same
Stock user nags Deprecation / Flathub-setup timers Masked. ujust set-stock-nags on Same Same
Live ISO NTP Cleartext fedora pool NTS on the stick Same ISO hook Same ISO hook
Prove overlay on this disk ujust audit-secureblue only ujust unwoke-test + see-it Same Same
Look Their defaults Unwoke wallpaper, lock, blue accent. Brand Same Unwoke look Same Unwoke look

Everything we add on top

Brave Origin

Not full brave-browser. Policies live in /etc/brave-origin/policies/managed/. Restart the browser after a toggle. brave_t is unconfined-like on purpose. You do not get Trivalent’s Chromium patches or tight SELinux. For that, rebase to a *-trivalent image.

Origin compiled out Leo, Rewards, Wallet, VPN, Tor, Talk, News, P3A. What we add on top is enterprise policy, not a new browser.

Trivalent flavor

Same house browser as stock: Vanadium-derived patches, trivalent_t SELinux, their userns allow-list. We do not rebuild Trivalent. We add Chromium enterprise JSON stock does not ship, plus flags their README lists as optional extra hardening. All of it reverts with ujust.

Policies: /etc/trivalent/policies/managed/ (and a copy under /etc/chromium/policies/managed/). Extra flags: /etc/trivalent/trivalent.conf.d/. set-brave-* and set-trivalent-* are the same packs. We do not wrap Trivalent in Bubblejail — their FAQ says that pairing is broken.

What this does not add: new compiler/seccomp patches. If a policy already matches something Trivalent compiled in, the JSON is a no-op. The extras that stock does not force are JIT-less, WebGL/WebGPU off, extension blocklist, device/API guards, HTTPS-only, extra sandbox (audio sandbox, no screen capture, JS optimizer off), Network Service Sandbox, and punycode + clear-cross-origin-referrers.

Overlay ujust extras

Stock secureblue commands still work. Every overlay switch reverts. Defaults apply on each boot unless you stamped them off.

CommandDefaultWhat it doesRevert
ujust unwoke-status Flavor, remotes, policies, theme, stores.
ujust audit-unwoke Fail if harden_userns / flavor browser / brave_t (Origin) / SUID invariants break. Warns (fails on browserless) if a Flatpak web browser is installed. Fails if the public mark file is missing.
ujust unwoke-test PASS/LOOSE/SKIP/FAIL with a proof path for every overlay lock and each shipped-first ticket. Does not unlock. Hand checks: see-it.
Public mark on (not a ujust) Token UNWOKE-SHIPPED-FIRST plus MIT copyright on overlay sources, units, and generated drop-ins. Compose stamps a forgotten file. Ledger /usr/share/unwoke/SHIPPED-FIRST.txt. Not written into live Chromium/Brave/Trivalent managed policies (no extra unrecognized policy). Do not strip (MIT notice must travel with a copy)
ujust set-flathub off all flavors System Flathub remote. Stock uses verified. verified / full / off
ujust set-flatpak-lockdown on Reject most Flatpak permissions plus extra xdg/host-root (not host-os). Apps need Flatseal. off
ujust set-flatpak-record on (blocked) Pulse + PipeWire capture blocked for Flatpaks. Independent of lockdown. Speakers in native apps stay. off
ujust set-network-fs off (locked) Blacklist NFS/CIFS client modules. nfs-server stays masked even if you turn clients on. on
ujust set-ramdisk-exec off (noexec) noexec,nosuid,nodev on /dev/shm, /tmp, and /var/tmp. on
ujust set-cet on glibc SHSTK + IBT tunables (x86_64). off
ujust set-boot-perm on (/boot 700) Kernel dir not world-readable. Does not chmod ostree /usr. off
ujust set-extra-cas off (trimmed) Distrust Fedora CAs that are not Mozilla website-trusted. Some TLS fails. on
ujust set-nts on Chrony NTS (Cloudflare + nts.ntp.se). Independent of dns-selector. off
ujust set-brave-hardening / set-trivalent-hardening on (Origin + Trivalent) HTTPS-only, no WebRTC IP leak, no metrics/sync/autofill/passwords/translate. off
ujust set-brave-devices / set-trivalent-devices on (Origin + Trivalent) Block camera, mic, geo, WebUSB/Bluetooth/serial/HID, file-system API. off
ujust set-brave-jitless / set-trivalent-jitless on (Origin + Trivalent) JavaScript JIT off. Breaks some sites. off
ujust set-brave-extensions / set-trivalent-extensions block (Origin + Trivalent) Extension install blocklist *. allow
ujust set-brave-isolation / set-trivalent-isolation on (Origin + Trivalent) Disable3DAPIs (WebGL), WebGPU flag, SitePerProcess, origin-keyed processes. off
ujust set-brave-sandbox / set-trivalent-sandbox on (Origin + Trivalent) Audio sandbox, no screen capture, JS optimizer off, no WebRTC event logs / payment API / privacy-sandbox prompt. off
ujust set-brave-devtools / set-trivalent-devtools lock Lock chrome://devtools. allow
ujust set-trivalent-network-sandbox on (Trivalent) Force Network Service Sandbox. Stock leaves this off because it can clear cookies on exit. off
ujust set-trivalent-referrers on (Trivalent) Punycode domains + clear-cross-origin-referrers (flags their README lists as extra hardening). off
ujust set-brave-bubblejail on (Origin) Wrap Origin’s desktop launcher in Bubblejail. GPU/audio may break. Refused on Trivalent. off
ujust set-brew off Homebrew not on PATH; brew-setup/update masked. Stock ships brew. on
ujust set-camera-mic locked uvcvideo blacklisted; V4L and ALSA capture nodes mode 000. Speakers stay. on
ujust set-admin-split wanted tty1 prompt before greeter creates a daily user, then wheel GUI lock. Empty name skips (5 min timeout). off
ujust set-bluetooth off Mask bluetooth.service, rfkill block bluetooth. Wi-Fi unchanged. on
ujust set-toolbox off /usr/bin/toolbox and distrobox* are wrappers. podman stays. on
ujust set-extra-daemons off Mask Avahi and ModemManager. on
ujust set-countme off Mask Fedora rpm-ostree countme timer. on
ujust set-connectivity-check off No NetworkManager HTTP “am I online”. Hotel portals may need on. on
ujust set-dhcp-hostname off Do not send hostname; IPv6 stable-privacy; MAC-based DHCP ids. on
ujust set-thumbnails off GNOME Files + Dolphin previews off. on
ujust set-disk-traces off Volatile journal, no hibernate-to-disk, no coredumps, indexer masked. Not Tails. on
ujust set-anon-net off TCP timestamps disabled (clock-skew). Not host Tor. on (stock timestamps)
ujust set-stock-nags off Mask stock deprecation / update-verify / flatpak-setup user units (can fight Flathub-off or tell you to rebase to them). Their Secure Boot key check stays. on
ujust set-allow-browsers off (browserless) Unmask Flatpak browsers, drop rpm exclude. Needs ALLOW. Seatbelt, not a prison. off
ujust set-unwoke-theme applied Wallpaper, lock, accent again. Use GNOME/KDE Settings
ujust unwoke-status
ujust audit-unwoke
ujust play steam
ujust install-whonix
ujust start-whonix
ujust install-steam
ujust install-vpn
ujust enable-dangerzone
ujust set-flathub verified|full|off
ujust set-flatpak-lockdown on|off
ujust set-flatpak-record on|off
ujust set-network-fs on|off
ujust set-ramdisk-exec on|off
ujust set-cet on|off
ujust set-boot-perm on|off
ujust set-extra-cas on|off
ujust set-nts on|off
ujust set-brave-hardening on|off
ujust set-brave-devices on|off
ujust set-brave-jitless on|off
ujust set-brave-extensions block|allow
ujust set-brave-isolation on|off
ujust set-brave-sandbox on|off
ujust set-brave-devtools lock|allow
ujust set-brave-bubblejail on|off          # Origin only
ujust set-trivalent-network-sandbox on|off # Trivalent only
ujust set-trivalent-referrers on|off       # Trivalent only
ujust set-brew on|off
ujust set-camera-mic on|off
ujust set-admin-split on|off|add NAME
ujust set-bluetooth on|off
ujust set-toolbox on|off
ujust set-extra-daemons on|off
ujust set-countme on|off
ujust set-connectivity-check on|off
ujust set-dhcp-hostname on|off
ujust set-thumbnails on|off
ujust set-disk-traces on|off
ujust set-anon-net on|off
ujust set-anon-hostname on|off
ujust set-stock-nags on|off
ujust set-unwoke-theme apply
ujust set-allow-browsers on ALLOW   # browserless only

Honest limits

Calling this “insecure Fedora” is false. Calling it “identical to secureblue” is also false. Origin is weaker than stock + Trivalent. -trivalent equals stock on the house browser and is stricter on extra policies + house locks. Browserless is tighter than Origin until a browser is installed. Policies are not Vanadium patches.