Features
Most of the security story is still secureblue’s (also mirrored here, updates daily). This page is everything this overlay adds or changes. Easy words + a living score vs stock: Compared — including prove it on the disk. Look is on Brand. What changed, day by day: Changelog. After login, Unwoke setup (app grid) explains the locks; ujust why maps “broken” to the matching toggle. ujust unwoke-test prints PASS/LOOSE/FAIL with a proof path for every overlay lock and shipped-first ticket (stock audit-secureblue does not). Strict apps: ujust install-proton, install-ivpn, install-mullvad (WireGuard first). Nothing unlocks unless you pick it.
Inherited from secureblue
We layer on their already-built, already-signed images. We do not reimplement these:
hardened_mallocglobally, including Flatpaks.- Kernel hardening via sysctl and kernel arguments, with their
ujust set-kargs-hardening. - SELinux enforcing. Unprivileged user namespaces off for the unconfined domain, on for Flatpak.
- Xwayland off by default. GNOME user extensions off. KDE GHNS off.
sudo/su/pkexecreplaced withrun0on their images. SUID stripped from many binaries. fuse2 gone.- USBGuard with their
ujusthelpers. firewalld closed by default. NTS for time. HTTPS rpm mirrors. DoT viaujust dns-selector. - Module blacklist, ptrace off, MAC randomization, coredumps off, brew-proxy, Bubblejail as a tool, LUKS TPM/FIDO helpers,
ujust audit-secureblue. - Automatic updates. Their full
ujustsurface still works.
Read their list if you want the complete inventory. We did not gut SELinux, kernel args, disk encryption, or Secure Boot enrollment.
What this overlay changes
Four columns, left to right: stock secureblue, Unwoke Origin, Unwoke Trivalent (*-trivalent, the recommended default), Unwoke browserless. Trivalent is the same house browser as stock, then extra reversible policies stock does not force. Scroll sideways on a phone. Reverts: toggles.
| Stock secureblue | Origin | Trivalent (*-trivalent) |
Browserless | |
|---|---|---|---|---|
| Browser | Trivalent — confined Chromium | Brave Origin RPM. Fat brave_t. |
Stock Trivalent (same binary, patches, SELinux) plus extra reversible policies | None. No Trivalent, no Origin, no brave_t |
| Vanadium / compiler patches | Yes (Trivalent) | No. Policies are not a substitute | Yes — inherited, not rebuilt | n/a (no browser) |
| Browser SELinux | Tight trivalent_t |
Fat brave_t (unconfined-like) |
Same tight trivalent_t as stock. No brave_t |
No extra domain |
| JavaScript JIT | Allowed | Blocked by default. ujust set-brave-jitless off |
Blocked by default. Same toggle (stock does not force this) | n/a |
| WebGL / WebGPU | Allowed | Off by default. ujust set-brave-isolation off |
Off by default. Same toggle (stock does not force this) | n/a |
| Extensions | Allowed | Installs blocked. ujust set-brave-extensions allow |
Installs blocked. Same toggle (stock does not force this) | n/a |
| Browser camera / mic / USB / BT / geo | Site permission prompts | Blocked by policy. ujust set-brave-devices off |
Blocked by policy. Same toggle (stock does not force this) | n/a |
| HTTPS-only / no passwords / no metrics / no ping | Compile-time defaults; not our JSON pack | Managed pack on (no ping, no Privacy Sandbox, no Cast, no Google time-query). ujust set-brave-hardening off is a warned loosen |
Same managed pack on (additive if Trivalent already compiled some of this in) | n/a |
| Extra sandbox pack | No | On: audio sandbox, no screen capture, JS optimizer off. ujust set-brave-sandbox off |
On. Same pack (stock does not force this) | n/a |
| Network Service Sandbox | Off in chrome://settings/security (can clear cookies) |
n/a (Origin launcher, not Trivalent conf.d) | Forced on. ujust set-trivalent-network-sandbox off |
n/a |
| Punycode / strip referrers | Optional chrome://flags | n/a | On via conf.d. ujust set-trivalent-referrers off |
n/a |
| Bubblejail on the house browser | Do not wrap Trivalent (their FAQ) | On. ujust set-brave-bubblejail off |
Refused. Stock already jails Trivalent | n/a |
| DevTools lock | Unlocked | Locked. ujust set-brave-devtools allow |
Locked. Same | n/a |
| App store | Bazaar — curated catalog | None. Flathub off until ujust set-flathub verified |
None. Same | None. Same |
| User namespaces | Off for unconfined; on for Flatpak and Trivalent | Same, plus brave_t on the allow-list |
Same as stock. No brave_t |
Stock with Trivalent gone: unconfined blocked, Flatpak only |
| Host browser installs | Trivalent is already there | Origin is the house browser | Trivalent is the house browser | Blocked until ujust set-allow-browsers on ALLOW |
| Flatpak permissions | Opt-in lockdown | Lockdown on plus extra xdg/host-root cuts. ujust set-flatpak-lockdown off |
Same extra cuts | Same extra cuts |
| Flatpak Pulse/PipeWire record | Open request; not default | Blocked. Independent of lockdown. ujust set-flatpak-record off |
Blocked. Same | Blocked. Same |
| NFS / CIFS | nfs-server masked; clients still load | Server stays masked. Client modules blacklisted until ujust set-network-fs on |
Same | Same |
| Empty-disk USB encryption | Encrypt checkbox off; weaker LUKS memory | LUKS on unless you untick. Argon2id 2 GiB | Same ISO hook | Same ISO hook |
| Homebrew | Shipped | Off until ujust set-brew on |
Off. Same | Off. Same |
| Camera / mic (kernel) | Available | Locked until ujust set-camera-mic on (speakers stay) |
Locked. Same | Locked. Same |
| Wheel on the greeter | Typical daily user is wheel | tty1 prompt, then wheel blocked from GDM/SDDM. ujust set-admin-split off |
Same prompt / lock | Same prompt / lock |
| Bluetooth | Available | Off until ujust set-bluetooth on. Wi-Fi stays |
Off. Same | Off. Same |
| toolbox / distrobox | Available | Off. /usr/bin/toolbox is a wrapper. ujust set-toolbox on |
Off. Same | Off. Same |
| Avahi / ModemManager | Typically on | Masked until ujust set-extra-daemons on |
Masked. Same | Masked. Same |
| Fedora countme | On | Masked. ujust set-countme on |
Masked. Same | Masked. Same |
| Connectivity check | On | Off. ujust set-connectivity-check on for hotel portals |
Off. Same | Off. Same |
| DHCP hostname / DUID | Sent | Not sent. ujust set-dhcp-hostname on |
Not sent. Same | Not sent. Same |
| Thumbnails | On | Off. ujust set-thumbnails on |
Off. Same | Off. Same |
| Disk traces | Persistent journal, hibernate, cores, indexer | Volatile journal, no hibernate. ujust set-disk-traces on |
Same | Same |
| RAM disks + /var/tmp | exec on /tmp, /dev/shm, and /var/tmp |
noexec. ujust set-ramdisk-exec on |
Same | Same |
| Intel CET | Open request | SHSTK+IBT tunables on. ujust set-cet off |
Same | Same |
/boot |
Typically world-readable | mode 700. ujust set-boot-perm off |
Same | Same |
| Extra Fedora CAs | Trusted | Blocklisted vs Mozilla website set. ujust set-extra-cas on |
Same | Same |
| Stock user nags | Deprecation / Flathub-setup timers | Masked. ujust set-stock-nags on |
Same | Same |
| Live ISO NTP | Cleartext fedora pool | NTS on the stick | Same ISO hook | Same ISO hook |
| Prove overlay on this disk | ujust audit-secureblue only |
ujust unwoke-test + see-it |
Same | Same |
| Look | Their defaults | Unwoke wallpaper, lock, blue accent. Brand | Same Unwoke look | Same Unwoke look |
Everything we add on top
- Strip Bazaar, GNOME Software, Plasma Discover. Hide leftover store launchers. Origin and browserless also strip Trivalent.
- Origin flavor (unsuffixed names): standalone
brave-originRPM (notbrave-browser). Binary/opt/brave.com/brave-origin/brave. House browser for that flavor only — not the recommended default. Leo/Rewards/Wallet/VPN/Tor compiled out by Brave. - Trivalent flavor: keep stock Trivalent +
trivalent-selinux. Nobrave_t. Extra managed policies in/etc/trivalent/policies/managed/plus launcher flags in/etc/trivalent/trivalent.conf.d/. - SELinux (Origin only): fat
brave_t(unconfined_domain) plus CIL allow-list so Chromium’s userns sandbox can start whileharden_usernsstays on. SUID stripped under/opt/brave.com/brave-origin. - Browserless flavor: nothing put back. systemd units remask Flatpak browsers and rpm-ostree-exclude them until the allow toggle.
- Chromium managed policies (Origin:
/etc/brave-origin/policies/managed/; Trivalent:/etc/trivalent/policies/managed/), split into reversible packs (hardening, devices, JIT-less, extensions, isolation, extra sandbox). - Flathub
offby default (stricter than stock).ujust set-flathub verifiedto match them. - Flatpak permission lockdown (same cuts as their
ujust flatpak-permissions-lockdown) default on. - Bubblejail wrapper on the Origin desktop launcher (default on;
ujust set-brave-bubblejail off). - Homebrew off (stock ships it). Camera/mic locked at module+udev. Wheel GUI lock after a daily user exists.
- Isolation pack (Origin + Trivalent): no WebGL/WebGPU, SitePerProcess, origin-keyed processes.
- First-boot: re-enable
harden_userns, apply defaults unless you stamped them off, promoteostree-unverified-registry→ostree-image-signed. - RAM-disk noexec plus
/var/tmpbind noexec (fail-closed after first boot), CET tunables,/boot700 plus compose-time 700 on/usr/srcand module dirs, Fedora-not-Mozilla CA blocklist (fail-closed), stock deprecation/Flathub-setup nags masked. All reversible. - Chrony NTS on the installed OS (
ujust set-nts off). USBGuard asked in Unwoke setup after login, default skip. - DevTools locked by default on Origin and Trivalent.
ujust set-brave-devtools allow. - Privacy apply-boot: countme masked, no connectivity GET, DHCP anonymity (no hostname, iaid=mac, send-release, no LLMNR/mDNS), thumbnails off.
- Vendor installers (Proton, IVPN, Mullvad, …): JSON list, WireGuard/web first, hashed official RPM only if you insist.
ujust install-vendor NAME. - Steam: stock Flatpak or Distrobox, but
ujust install-steamasks overlay locks first. Nothing silent. - Whonix: official KVM, OpenPGP-required, clipboard/USB/mic off.
ujust install-whonix/ujust start-whonix. Not VirtualBox, not Qubes. - First day: setup on the dash, USBGuard in the GUI (default No), live Install icon named Unwoke, Steam/Gaming/Whonix on Start. Compared.
- Play window:
ujust play steam— Fedora GameMode while the game runs, restore on exit/crash/reboot. Optional asked sched-ext. No CachyOS kernel. Setup → Gaming. - Every stock app installer is intercepted:
install-vpn,install-docker,enable-dangerzone,distrobox-assemble,set-flathub-unfiltered. Catalog: Stock installers. Tailscale yum-repo is watched. ujust unwoke-testplus see each lock yourself. Stockaudit-securebluedoes not list overlay extras.- Unwoke wallpaper, lock image, GTK
#3b6cff, GNOME namedblue, KDE accent, GDM wallpaper. See Brand. - This site. Daily mirror of their markdown under
/secureblue/(Apache-2.0). Our FAQ/Features/Install/Brand are never overwritten. - Conduct, donate, contributing, post-install pages that are Unwoke’s, not theirs.
Brave Origin
Not full brave-browser. Policies live in /etc/brave-origin/policies/managed/. Restart the browser after a toggle. brave_t is unconfined-like on purpose. You do not get Trivalent’s Chromium patches or tight SELinux. For that, rebase to a *-trivalent image.
Origin compiled out Leo, Rewards, Wallet, VPN, Tor, Talk, News, P3A. What we add on top is enterprise policy, not a new browser.
Trivalent flavor
Same house browser as stock: Vanadium-derived patches, trivalent_t SELinux, their userns allow-list. We do not rebuild Trivalent. We add Chromium enterprise JSON stock does not ship, plus flags their README lists as optional extra hardening. All of it reverts with ujust.
Policies: /etc/trivalent/policies/managed/ (and a copy under /etc/chromium/policies/managed/). Extra flags: /etc/trivalent/trivalent.conf.d/. set-brave-* and set-trivalent-* are the same packs. We do not wrap Trivalent in Bubblejail — their FAQ says that pairing is broken.
What this does not add: new compiler/seccomp patches. If a policy already matches something Trivalent compiled in, the JSON is a no-op. The extras that stock does not force are JIT-less, WebGL/WebGPU off, extension blocklist, device/API guards, HTTPS-only, extra sandbox (audio sandbox, no screen capture, JS optimizer off), Network Service Sandbox, and punycode + clear-cross-origin-referrers.
Overlay ujust extras
Stock secureblue commands still work. Every overlay switch reverts. Defaults apply on each boot unless you stamped them off.
| Command | Default | What it does | Revert |
|---|---|---|---|
ujust unwoke-status |
— | Flavor, remotes, policies, theme, stores. | — |
ujust audit-unwoke |
— | Fail if harden_userns / flavor browser / brave_t (Origin) / SUID invariants break. Warns (fails on browserless) if a Flatpak web browser is installed. Fails if the public mark file is missing. |
— |
ujust unwoke-test |
— | PASS/LOOSE/SKIP/FAIL with a proof path for every overlay lock and each shipped-first ticket. Does not unlock. Hand checks: see-it. | — |
| Public mark | on (not a ujust) |
Token UNWOKE-SHIPPED-FIRST plus MIT copyright on overlay sources, units, and generated drop-ins. Compose stamps a forgotten file. Ledger /usr/share/unwoke/SHIPPED-FIRST.txt. Not written into live Chromium/Brave/Trivalent managed policies (no extra unrecognized policy). |
Do not strip (MIT notice must travel with a copy) |
ujust set-flathub |
off all flavors |
System Flathub remote. Stock uses verified. | verified / full / off |
ujust set-flatpak-lockdown |
on |
Reject most Flatpak permissions plus extra xdg/host-root (not host-os). Apps need Flatseal. | off |
ujust set-flatpak-record |
on (blocked) |
Pulse + PipeWire capture blocked for Flatpaks. Independent of lockdown. Speakers in native apps stay. | off |
ujust set-network-fs |
off (locked) |
Blacklist NFS/CIFS client modules. nfs-server stays masked even if you turn clients on. | on |
ujust set-ramdisk-exec |
off (noexec) |
noexec,nosuid,nodev on /dev/shm, /tmp, and /var/tmp. |
on |
ujust set-cet |
on |
glibc SHSTK + IBT tunables (x86_64). | off |
ujust set-boot-perm |
on (/boot 700) |
Kernel dir not world-readable. Does not chmod ostree /usr. |
off |
ujust set-extra-cas |
off (trimmed) |
Distrust Fedora CAs that are not Mozilla website-trusted. Some TLS fails. | on |
ujust set-nts |
on |
Chrony NTS (Cloudflare + nts.ntp.se). Independent of dns-selector. | off |
ujust set-brave-hardening / set-trivalent-hardening |
on (Origin + Trivalent) |
HTTPS-only, no WebRTC IP leak, no metrics/sync/autofill/passwords/translate. | off |
ujust set-brave-devices / set-trivalent-devices |
on (Origin + Trivalent) |
Block camera, mic, geo, WebUSB/Bluetooth/serial/HID, file-system API. | off |
ujust set-brave-jitless / set-trivalent-jitless |
on (Origin + Trivalent) |
JavaScript JIT off. Breaks some sites. | off |
ujust set-brave-extensions / set-trivalent-extensions |
block (Origin + Trivalent) |
Extension install blocklist *. |
allow |
ujust set-brave-isolation / set-trivalent-isolation |
on (Origin + Trivalent) |
Disable3DAPIs (WebGL), WebGPU flag, SitePerProcess, origin-keyed processes. | off |
ujust set-brave-sandbox / set-trivalent-sandbox |
on (Origin + Trivalent) |
Audio sandbox, no screen capture, JS optimizer off, no WebRTC event logs / payment API / privacy-sandbox prompt. | off |
ujust set-brave-devtools / set-trivalent-devtools |
lock |
Lock chrome://devtools. |
allow |
ujust set-trivalent-network-sandbox |
on (Trivalent) |
Force Network Service Sandbox. Stock leaves this off because it can clear cookies on exit. | off |
ujust set-trivalent-referrers |
on (Trivalent) |
Punycode domains + clear-cross-origin-referrers (flags their README lists as extra hardening). | off |
ujust set-brave-bubblejail |
on (Origin) |
Wrap Origin’s desktop launcher in Bubblejail. GPU/audio may break. Refused on Trivalent. | off |
ujust set-brew |
off |
Homebrew not on PATH; brew-setup/update masked. Stock ships brew. | on |
ujust set-camera-mic |
locked | uvcvideo blacklisted; V4L and ALSA capture nodes mode 000. Speakers stay. | on |
ujust set-admin-split |
wanted | tty1 prompt before greeter creates a daily user, then wheel GUI lock. Empty name skips (5 min timeout). | off |
ujust set-bluetooth |
off |
Mask bluetooth.service, rfkill block bluetooth. Wi-Fi unchanged. | on |
ujust set-toolbox |
off |
/usr/bin/toolbox and distrobox* are wrappers. podman stays. |
on |
ujust set-extra-daemons |
off |
Mask Avahi and ModemManager. | on |
ujust set-countme |
off |
Mask Fedora rpm-ostree countme timer. | on |
ujust set-connectivity-check |
off |
No NetworkManager HTTP “am I online”. Hotel portals may need on. |
on |
ujust set-dhcp-hostname |
off |
Do not send hostname; IPv6 stable-privacy; MAC-based DHCP ids. | on |
ujust set-thumbnails |
off |
GNOME Files + Dolphin previews off. | on |
ujust set-disk-traces |
off |
Volatile journal, no hibernate-to-disk, no coredumps, indexer masked. Not Tails. | on |
ujust set-anon-net |
off |
TCP timestamps disabled (clock-skew). Not host Tor. | on (stock timestamps) |
ujust set-stock-nags |
off |
Mask stock deprecation / update-verify / flatpak-setup user units (can fight Flathub-off or tell you to rebase to them). Their Secure Boot key check stays. | on |
ujust set-allow-browsers |
off (browserless) |
Unmask Flatpak browsers, drop rpm exclude. Needs ALLOW. Seatbelt, not a prison. |
off |
ujust set-unwoke-theme |
applied | Wallpaper, lock, accent again. | Use GNOME/KDE Settings |
ujust unwoke-status
ujust audit-unwoke
ujust play steam
ujust install-whonix
ujust start-whonix
ujust install-steam
ujust install-vpn
ujust enable-dangerzone
ujust set-flathub verified|full|off
ujust set-flatpak-lockdown on|off
ujust set-flatpak-record on|off
ujust set-network-fs on|off
ujust set-ramdisk-exec on|off
ujust set-cet on|off
ujust set-boot-perm on|off
ujust set-extra-cas on|off
ujust set-nts on|off
ujust set-brave-hardening on|off
ujust set-brave-devices on|off
ujust set-brave-jitless on|off
ujust set-brave-extensions block|allow
ujust set-brave-isolation on|off
ujust set-brave-sandbox on|off
ujust set-brave-devtools lock|allow
ujust set-brave-bubblejail on|off # Origin only
ujust set-trivalent-network-sandbox on|off # Trivalent only
ujust set-trivalent-referrers on|off # Trivalent only
ujust set-brew on|off
ujust set-camera-mic on|off
ujust set-admin-split on|off|add NAME
ujust set-bluetooth on|off
ujust set-toolbox on|off
ujust set-extra-daemons on|off
ujust set-countme on|off
ujust set-connectivity-check on|off
ujust set-dhcp-hostname on|off
ujust set-thumbnails on|off
ujust set-disk-traces on|off
ujust set-anon-net on|off
ujust set-anon-hostname on|off
ujust set-stock-nags on|off
ujust set-unwoke-theme apply
ujust set-allow-browsers on ALLOW # browserless only
Honest limits
Calling this “insecure Fedora” is false. Calling it “identical to secureblue” is also false. Origin is weaker than stock + Trivalent. -trivalent equals stock on the house browser and is stricter on extra policies + house locks. Browserless is tighter than Origin until a browser is installed. Policies are not Vanadium patches.
- Origin: no Vanadium-style Chromium compiler/seccomp patches. JIT-less and enterprise policy are not a substitute. Rebase to
*-trivalentfor the patches. -trivalentextra packs are managed JSON /trivalent.conf.dflags. They do not add compiler patches on top of what Trivalent already ships.brave_t(Origin) is still unconfined-like. A tight jail is not shipped — Origin updates would break it, and it would still not be Trivalent.- Signing key is a GitHub secret, not a hardware key.
- We inherit their signed image; we do not rebuild their kernel or SLSA pipeline.
- Toolbox, brew, AppImage, and
rpm-ostree --disableexcludesbypass the browserless seatbelt. - GNOME Shell cannot take a custom accent hex. GTK and KDE can. See Brand.