Codename: Umbra (permanent — APT suite stays umbra; 3.0 is conveyed by the
"Backfire" subtitle, exactly as 2.0.0 used "Bedrock").
Status: RELEASED 2026-08-26. Built, signed, ISO_GATE_PASSED; boots BIOS+UEFI to the live Plasma desktop, survives a full CPU/memory/IO stress run with zero failed services, installs to disk and cold-boots from disk, and the Fireline tools run on both the live and installed systems.
- ISO:
shadowfetch-3.0.0-amd64.iso - Size: 3,967,508,480 bytes (3.97 GB / 3.69 GiB)
- SHA-256:
110b0d075e699a05a8a2f8f8dcd05f19454bc8ae09acd0745ca0d947db8c5e3c - Detached signature:
shadowfetch-3.0.0-amd64.iso.asc - Signing key:
8F13 CE15 35EE 1F4A 2916 A1F7 3C5C 900B 7BE8 0CA1 - Download: https://www.shadowfetch.com/linux/download/shadowfetch-3.0.0-amd64.iso
A backfire is a fire set deliberately to contain a larger fire. Agentic programs are now a fact of modern workflows — and running them full-auto on a bare host is the wildfire. Shadowfetch 3.0 is the controlled burn: the first desktop OS where autonomous agents are contained, observed, and reversible by default.
The agent-safe local-AI workstation: full-auto coding agents and local models turnkey out of the box — every agent sandboxed, every action auditable in Firewatch, every session one Phoenix Point away from undo — private, signed, zero-telemetry, on hardware you own.
in work/research-3.0/)
- 90% of developers use coding agents weekly (JetBrains 2026); consensus after the Replit DB wipe / Gemini CLI file loss: never run full-auto on the bare host — yet no desktop OS ships the safe harness. This is the gap.
- Windows 10 free consumer ESU quietly extended to 2027-10-12: the switcher wave runs through 3.0's entire cycle. Zorin 18 took 2M downloads in <3 months, ~75% from Windows. Remaining holdouts are risk-averse — Phoenix rollback is exactly their reassurance.
- MCP won (Linux Foundation governance, 10K+ servers) and its security is the ecosystem's open wound (30+ CVEs in 60 days; tool-poisoning worms). Only an OS with signed packaging can ship a trusted MCP surface.
- Local-AI trust moment: OpenAI's train-by-default ToS change, Recall's reputation — "the AI runs HERE and you can watch it" is the story.
- Our own 8/10 review said "AI-ready, not turnkey" (nouveau on an RTX 5080). NVIDIA-at-first-boot is the single highest-leverage adoption fix.
- Firebreak (
shadowfetch-firebreak, new packageshadowfetch-fireline) — run ANY installed agent (Claude Code, Codex CLI, Goose, Cursor, Grok Build, Aider) full-auto inside bubblewrap with per-project filesystem scope, hostname/session identity, and an automatic workspace checkpoint before the session. Kernel preconditions (unprivileged userns, Landlock) verified by a Passport check. - Agent Checkpoints (
shadowfetch-agent-workspacev2) — ~/Workspaces become Btrfs subvolumes; every Firebreak session takes a pre-run snapshot; post-session diff review ("what the agent touched"); one-commandundorestores the workspace. Phoenix philosophy at workspace granularity, fully user-space (no root needed for snapshot/diff). - Audit journal — Firebreak emits structured journald records (session
start/end, scope, checkpoint id, exit);
shadowfetch-firebreak logrenders the per-agent timeline. Firewatch integration follows in 3.x. - Shadowfetch MCP suite (
shadowfetch-mcp) — signed first-party MCP stdio servers:passport(read-only system self-check),phoenix(list/create restore points),checkpoint(workspace snapshot/diff), andfs(scoped read-only file access). An agent on Shadowfetch can literally call a checkpoint before touching anything. Zero third-party deps. - Secret hygiene — Firebreak strips known credential variables from the sandbox environment by default (opt-in passthrough per profile); KWallet broker follows in 3.x.
- AI Ignition — first-boot: hwscan/Passport size the GPU → consent-gated
proprietary NVIDIA driver via the proven
shadowfetch-gpupath (Phoenix Point first) → one-click Apache-2.0 model tiered by VRAM. Fixes the 8/10 review verbatim. (Welcome + gpu; config baked, bulk downloaded.) - Firebreak — see Fireline. (New
shadowfetch-firelinepackage.) - Agent Checkpoints — see Fireline. (
shadowfetch-agent-workspacev2.) - Shadowfetch MCP suite — see Fireline. (
shadowfetch-mcp.) - Audit journal + secret hygiene — see Fireline.
- Windows Exile mode — Calamares NTFS detect + user-folder/browser
import (extends shipped
shadowfetch-browser-import), Windows-familiar layout preset, first-week Guide checklist. (3.0.x train.) - Expanded verified-agent roster — add Goose (MCP-native) to the four shipped installers; fully-local lane: Aider preconfigured against Buzz's llama-server. OpenClaw only with the hardening wrapper (loopback-only, sandbox-wrapped) — its CVE record forbids a bare one-click.
- Offline voice — faster-whisper dictation + Kokoro TTS (NOT archived Piper), consent-gated model download. (3.0.x train.)
- Gaming bundle + anti-cheat honesty — one-click Steam/Proton-GE/ gamemode/MangoHud first-boot bundle + a Passport pre-check that NAMES the anti-cheat titles that will not run (Vanguard/EA/GTA-online).
- Published numbers — tokens/sec per reference GPU, ISO-to-first-token, rollback time, on the benchmark surface. Quantified claims beat adjectives (CachyOS lesson).
- shadowfetch-hardware ships — the staged, tested offline firmware
diagnoser leaves
next-release/and lands inshadowfetch-defaults.
| Audience | Pitch |
|---|---|
| Agentic developer (PRIMARY) | The only OS where full-auto is safe by default — and undo is one command. |
| Privacy local-AI user | No prompt leaves the machine; watch the tokens/sec to prove it. |
| Windows 10 refugee | Your PC isn't obsolete; this system can't be broken by an update — and you can always go back. |
| Curated-setup developer | One first-boot choice → a configured multi-agent + local-model environment; every choice one snapshot from undo. |
| Gamer (supporting) | Steam + Proton one click; an honest "will my games run?" answer first. |
| Creator | The full creative stack, plus local generation — no subscription, no cloud. |
| Homelab | One click turns this box into the private brain for your smart home. (3.0.x) |
- No bundled chat-widget gimmick. No Shadowfetch-hosted inference or relay.
- No gaming-distro positioning (Valve/Bazzite own that lane).
- No immutable/OSTree rebase — Phoenix+Fireproof already deliver the benefit.
- No Open WebUI bundling; no Ollama branding (llama.cpp engine, Ollama-compatible API).
- No Piper TTS (archived); no Llama-family models in the default catalog (Apache-2.0 only: Qwen, Gemma, gpt-oss, Devstral).
- Nothing heavy baked into the ISO — squashfs ceiling stands (~547 MiB head- room): bake config, download bulk.
- No first-party coding agent — Shadowfetch wins as the safest HOST for all vendor agents.
- One identity in marketing: the agent-safe local-AI workstation. Everything else is a hook, not a headline.
- No open model bundled in the ISO; every model download is consent-gated.
- Buzz remains optional and loopback-only by default.
- Every agent installer is release-pinned, SHA-256-verified, user-owned; no credential is ever embedded, copied, or read by Shadowfetch.
- NEW: any agent launched through Firebreak runs filesystem-scoped to its workspace, with a checkpoint taken first and an audit record written.
- NEW: first-party MCP servers are read-only by default; anything that writes (checkpoint create/restore) says so in its tool description and touches only the workspace it was scoped to.
- Source/behavior/ShellCheck/secret/retired-runtime gates pass.
- Firebreak: sandboxed agent cannot read outside its scope (adversarial fixture); checkpoint/undo round-trips byte-identical; audit records present.
- MCP servers: schema-valid initialize/list/call over stdio; passport output passes the privacy scrubber; fs server refuses paths outside scope.
- AI Ignition: NVIDIA path validated on the physical RTX 5060 Ti; simulate- first; Phoenix Point around the transaction; clean rollback proven.
- Full ISO structure/checksum/signature, BIOS+UEFI boot, clean installs, 2.1.5→3.0.0 upgrade preserving user files, Buzz state, and workspaces.
- Fresh screenshots from the exact final ISO; staged website/GitHub/Archive metadata verified before publication; publish only after all gates green.
Ride the 2026-10-13 Windows-10 consumer-ESU news moment; land before Ubuntu 26.10's AI previews. Lead story: "the first desktop OS built for the agentic era." Ship only when the NVIDIA path is bulletproof.