# Kodachi OS Change Log

**Written by Warith Al Maawali** (c) 2026

- [Website](https://www.digi77.com)
- [Kodachi Wiki](https://kodachi.cloud/)
- [GitHub](https://github.com/WMAL/kodachios)
- [Discord Channel](https://discord.gg/KEFErEx)
- [Twitter](https://twitter.com/warith2020)
- [LinkedIn](https://om.linkedin.com/in/warith1977)

> Kodachi OS/Software/Code are strictly protected by LICENSE terms located at [https://kodachi.cloud/wiki/bina/license.html](https://kodachi.cloud/wiki/bina/license.html)

---

## Important Notes

1. Avoid excessive bandwidth usage on Kodachi VPN to maintain optimal performance for all users.
2. Follow [@warith2020](https://twitter.com/warith2020) on Twitter for official Kodachi announcements.
3. Check the website for updated instructions with each new release.
4. Consider donating to support continued development of this project.

## Milestones

1. Kodachi 9.0.1 Desktop beta released (26.02.2026).
2. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.0.5 (12.03.2026).
3. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.0.8 (23.03.2026).
4. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.1.1 (30.03.2026).
5. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.1.6 (02.04.2026).
6. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.2.1 (08.04.2026).
7. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.2.6 (12.04.2026).
8. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.4.1 (01.05.2026).
9. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.4.8 (05.05.2026).
10. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.5.2 (08.05.2026).
11. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.5.3 (09.05.2026).
12. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.5.5 (10.05.2026).
13. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.5.9 (14.05.2026).
14. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.6.3 (17.05.2026).
15. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.2 (19.05.2026).
16. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.3 (25.05.2026).
17. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.4 (25.05.2026).
18. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.6 (27.05.2026).
19. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.7 (03.06.2026).
20. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.8 (10.06.2026).
21. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.7.9 (13.06.2026).
22. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.8.1 (24.06.2026).
23. Kodachi 9.0.1 Desktop & Binaries build update, stamp 9.8.2 (26.06.2026).
24. Kodachi 10.0.1 Desktop & Binaries beta release, stamp 10.0.1 (07.09.2026).
25. Kodachi 10.0.3 Desktop, Terminal & Binaries **first stable release of the 10 line**, stamp 10.0.3 (27.09.2026).
26. Kodachi 10.0.3 Desktop, Terminal & Binaries stable update, stamp 10.0.3 (05.10.2026).

---

## Version Policy

- Public release numbering follows the weighted Model 2 policy.
- Formula: `(binary x 0.5) + terminal + desktop`
- Every 5 weighted points advances one patch release.
- Patch numbering rolls into the next minor after patch `9`, and nine minor lines roll into the next major.
- Licensing covers the full current major line (for example `10.x.x`), not build counts.
- The live calculator on the support page uses a stored release anchor, so progress is measured from the last public release baseline instead of raw lifetime totals.
- The release metadata now publishes a shared `current_stamp` version plus the remaining weighted points and build-equivalent counts to the next patch, minor, and major milestones.
- The homepage stamp card, wiki support page, and changelog modal all read the same published policy fields so the explanation and countdowns stay aligned with build automation.

See the live release calculator at: <https://kodachi.cloud/docs/support.html>

---

## Version History

### Version 10.0.3 - Kodachi 10 Dragon Stable Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Builds** | Desktop 10.0.3.53 · Terminal 10.0.3.35 · Binary Pack 10.0.3.24 |
| **Version Stamp** | 10.0.3 |
| **Code Name** | Dragon |
| **Release date** | 05.10.2026 |
| **Status** | Stable |
| **APT** | stable `10.0.3-22` |

**Stable update of Kodachi 10, 05.10.2026.** It contains every change made after the stable update of 29.09.2026 (Desktop 10.0.3.50 · Terminal 10.0.3.33 · Binary Pack 10.0.3.11 · APT stable `10.0.3-11`), prompted by user reports of a black dashboard window, of **Kloak** failing to enable after an upgrade, of the dashboard still showing Tor after untorrify, of a microphone disable reporting a failure and of the security score flipping between two values (with a full debug report from that user's installed system), together with a round of everyday-use testing on installed and live systems. Installed systems receive it through `sudo apt upgrade` on the stable channel, and the stable downloads carry the new Desktop and Terminal images.

**Additions:**
- On kodachi.cloud, the five web tools (DNS Leak Test, IP Info, DNS Propagation, Domain Security Analyzer and IP Analytics) are now free to use, and the site menu marks each tool as Free or Premium
- The dashboard now notices a change made outside it, such as a torrify or detorrify from a terminal or the dock, within about five seconds, and shows the affected readings as not checked until it has read them again instead of showing the earlier state
- When an earlier start of the dashboard showed no picture and it switched to safe graphics mode, the dashboard now says so and offers to turn it off; `kodachi-dashboard --reset-graphics` does the same
- The dashboard shows a notice to restart it when `sudo apt upgrade` replaced it while it was open
- `kodachi-soc exposure qualification --explain` says why a machine is not qualified for full eBPF monitoring, and the debug report includes it

**Improvements:**
- The **SOC** watcher uses less CPU when idle: it no longer re-reads its acknowledgements, republishes an unchanged summary or re-reads process details for every event
- The **SOC** watcher uses far less CPU: it no longer reads the whole package database and every program's open files once a minute, which took about 2.6 seconds of CPU each time
- The Cairo dock, its command windows and the repository manager are now part of a Kodachi package, so `sudo apt upgrade` delivers their fixes; existing docks keep their layout
- Status checks run through sudo no longer write two session lines each to the system journal, which had made up more than a third of it; every command run as administrator is still recorded
- Tor Browser is updated to 15.0.24 and LibreWolf to 157, and `sudo apt upgrade` delivers both
- ExifCleaner is updated to 4.5.0
- The **Tirdad** kernel module is updated to 0.3.5
- **Prepare Tor on startup** is now off by default, because it started five Tor processes (about 650 MB of memory) from your real IP address for users who never use Tor; a setting saved by an earlier version is reset to off once
- IP forwarding is now off by default: no Kodachi feature forwards other machines' traffic, so VPN connections no longer switch it on, hardening no longer switches it back on, and the **SOC** note about it now points at Docker, libvirt or a manual setting
- The cryptocurrency and metals price ticker is on by default and can be switched off from the Vitals MARKETS or Health price panel; while it is off it contacts none of the seven price services it otherwise asks every minute, and the dashboard and the desktop panel show "Prices off"
- Google DNS servers and Google addresses are removed from Kodachi's network checks, fallbacks, built-in DNS server list, DNS health check and AI command catalogue; installed DNS server lists are cleaned automatically, and the network check's web reachability test now uses Cloudflare
- An idle desktop makes far fewer outside connections from your real IP address (measured about 11 web requests in ten minutes, down from about 36 a minute): Tor exit checks no longer run while the machine is known not to be torrified, the security score no longer contacts the Tor Project's check service while the Tor pool runs but nothing is torrified, the Tor exit lookup asks two IP services at a time instead of all 25 at once, and the public IP cache is no longer cleared on almost every desktop panel refresh
- An idle machine writes about twenty times less to the audit log, so the 40 MB audit buffer now holds about a day instead of about two hours, and the dashboard and the desktop panel open far fewer administrator (sudo) sessions (about 3 a minute instead of about 17)
- The desktop panel (conky) uses less than a third of the CPU it used when idle and starts about half as many processes
- An idle dashboard no longer re-checks every Kodachi program (about 364 MB) once a minute, which kept both CPUs busy on small machines
- The desktop panel and the dashboard no longer start the system time service on every refresh to read the time-sync state
- The security score is computed once and shared instead of separately for root and for your user, and runs each of its checks only once, so it no longer takes 5 to 12 seconds
- `routing-switch status` with no connection answers in about a tenth of a second instead of 2 to 3 seconds
- WireGuard connections are about 25 seconds faster, because connecting no longer tests a TCP port on a UDP service or waits a fixed 12 seconds
- The VPN Gate server list now downloads on slow links: the download used to stop after 30 seconds, while the list (about 1.3 MB) often arrives at 20 to 40 KB/s
- The dashboard's DNS-only network heartbeat now runs without administrator rights, and the full network check runs about every five minutes instead of every minute
- Android app links in the dashboard now point to F-Droid or the official release page where one exists, instead of Google Play
- Package upgrades now also update the desktop panel scripts in your home folder (files you changed yourself are left alone); before, the panel kept running the copy made at your first login, so no upgrade reached it
- Several desktop applets, the session report and helper files that came only from the ISO are now part of Kodachi packages, so `sudo apt upgrade` delivers their fixes
- The boot menu no longer forces 1920x1080 first and lets the firmware choose the display mode, so wide screens such as 3440x1440 can start in their native mode; installed systems get this on upgrade unless the boot theme settings were edited by hand
- Health and VPN logs no longer report a missing swap as disabled encryption, or say "Applied fix" for advice that nothing applied
- On kodachi.cloud, the download server now handles three times as many downloads at once, after the 10.0.3 release turned many downloads away at peak times

**Fixes:**
- The dashboard window could stay black with its web process at full CPU when one installed font has no family name, because the web engine loops on such a font (plain MiniBrowser shows the same); the dashboard now refreshes the font cache for it and keeps a font that is still broken away from its window, and a window that still shows nothing is restarted once with safer graphics settings; on the reporting system those fonts were Kodachi's own JetBrains Mono web fonts (.woff2), which are now removed from the font folder on new and existing installs
- Hysteria2 and the other tun2socks connections could refuse to start after the network gave the machine a new address or the Wi-Fi moved to another network, because their cleanup tried to restore a route the current network can no longer carry; such a route is now skipped, and a kernel setting changed by something else no longer blocks the next start
- A VPN disconnect no longer tries to put back a default route whose source address the network has since changed; it uses the same check as the tun2socks connections, so both decide the same way which old routes still fit the current network
- When a desktop session ended (a logout or a crashed session) while the user's background services kept running, the conky watchdog restarted the panels into the login screen every few seconds and each start crashed; it now waits until the next login can draw them
- Every dashboard language other than English failed to load, because one long help text was over a size limit; an over-long text is now skipped on its own
- After `sudo apt upgrade`, the ISO edition and build shown by the dashboard, the desktop panel and the dock could be lost; they are now kept, and installs that lost them are repaired
- An upgrade could replace a DNS setting made with `dns-switch` and remove its lock; it is now kept, and the DNS status no longer calls the installer's DNSCrypt-only setting "Non-Kodachi"
- After an upgrade, the **SOC** notifier and the session helper kept running the old program until the next sign-in; they are now restarted, the session helper only when it is idle
- Running the binary installer on a system that is updated through APT mixed two install methods; it now stops and says to run `sudo apt update && sudo apt full-upgrade`, and the desktop's install, dependency and system update windows stay open to show any failure and never run a download error page as an installer
- The hardening page showed 0% and 0/34 while its first scan was still running; it now says "Checking"
- The DNS page said the DNSCrypt upstream servers were not reported; it now names them, as the desktop panel does
- A `kodachi-soc` command that needs administrator rights now says to run it with sudo
- The dock's ISO update card could offer an edition this machine does not carry
- The **ColonyOps** isolated app launch workflow was refused when it was started without extra arguments
- The **security score** could flip between two values, for example 80 and 72, every 30 to 60 seconds: the desktop panel computed it without the kill switch, kernel hardening and privacy tool checks that the dashboard counted, and a score computed before a torrify or detorrify was still shown afterwards. Both now give the same score, and a change of state is reflected at once
- After a detorrify, the **SOC** posture could still say "Torrified: On" from an older panel reading
- While Tor handles DNS, switching to DNSCrypt from the dashboard, the Circle, the tray, a DNSCrypt restart, Fix DNS or Pi-hole could start DNSCrypt behind Tor's DNS redirect; this is now refused with a message saying to detorrify first, and the dashboard no longer starts DNSCrypt at startup while torrified
- A VPN started from a dock action was stopped at sign-out while the kill switch stayed on, which left the machine without a network; VPN tunnels now run in their own system scope, and every program started from the dock runs in its own scope, existing docks included from the next sign-in
- The **SOC** watcher reported Kodachi's own Tor service, Tor Browser, DNS lookups and firewall commands as warnings, and once a single event was lost it stayed "Degraded" until a restart; Kodachi's own components are now recorded as information, and a loss clears after a quiet minute
- The security status said RAM wipe was disabled on systems where it is installed, rated ptrace scope 1 as a high risk, left the hardening check at "checking", counted 0 connected USB devices and read the IPv6 state from the wrong places
- The desktop panel's uptime always showed 0m
- The Tor state could read unknown while another status check was reading the firewall
- The Pi-hole status reported an error on every check when Pi-hole is not installed, and the conntrack tool Kodachi uses to clear connections at torrify was missing from the dependency list
- The debug report collector included part of the account name and the disk serial in some files, made the audit log discard its whole history while it ran, and named the wrong install method for installed systems
- On installed systems the keyboard layout was reset to US at every sign-in; it now happens on the live system only
- Installed systems had two root= entries and an unused cryptdevice= entry on the kernel command line; new installs no longer get them and existing installs are cleaned once on upgrade
- The installer left the live-boot tools installed on the new system; new installs no longer get them, and existing installs remove them once, shortly after an upgrade, only when nothing else depends on them
- The dock could restart in a loop at sign-out with "cannot open display"
- The repository manager's upgrade could stop at a configuration file question it has no way to answer
- Display power saving and the screensaver, switched on by AutoShield, were not saved, so the power manager showed them off; the screen resolution check no longer re-reads the monitors every minute
- The login screen tried to read the user's wallpaper, an unused Whonix package source and key were removed, and a boot-time network setting error and unneeded Surface options were fixed
- The WireGuard log used local time while every other log uses UTC, the SOC score history labels could go out of order after a timezone change, and the IP lookup counters always showed 0
- **Kloak** could fail to enable after an upgrade with "service-units is not root-owned", because a background permission service handed that folder to the desktop account within a second; the folder is now protected, an upgrade restarts that service so the old copy stops running, and a failed enable prints one error instead of two
- Switching the **microphone** off could report a failure ending in "exact rollback could not be verified" while the microphone stayed off: after an earlier disable, or once the microphone guard's background service had stopped, the sound system no longer lists the microphone and the disable was judged failed. Switching it off now succeeds in both cases, restarts the guard when it had stopped, and keeps a working guard in place instead of reinstalling it
- The same permission service could hand root's firewall recovery records, panic journal and operation locks to the desktop account, so a later privileged unblock or recovery could refuse root's own records; these are now accepted when they sit in root's folders
- The dashboard's top Network pill could keep saying Tor for hours after untorrify, because it combined the live reading with a one-time reading from the Internet Recovery wizard; the Circle's Torrify System station, route text, TOR and DNS chips and Torrify row, the world map Tor badge, the quick actions, the AutoShield label and the tray now also follow the live reading
- After a detorrify with the Tor pool still running, the dashboard's DNS rows switched back to "Tor DNS" about every minute; Tor DNS is now reported from the firewall rules only, and the change shows within about five seconds instead of up to 35
- The desktop panel, workflows and the dashboard's Tor service row showed Tor as off while the Tor pool was running, because the main Tor service is no longer started by default
- After a torrify, a VPN change or a hostname, MAC, timezone, swap or USB Guard change, the desktop panel could keep showing the earlier reading as current for about two minutes; a change now marks older readings as out of date
- The desktop panel, the panel applets, the AutoShield login summary, ColonyOps, the session report, the panel's focus alerts and the tray no longer show an unanswered reading as Off, No, Offline, a red warning or a zero; they show it as unknown (?)
- The **ColonyOps** Torrify State cell never said torrified, and its IPv6 State cell said On when IPv6 was disabled
- The panel's country flag applet could show the country or the Tor flag of an address other than the one it displays
- The panel's focus alerts fired IP-change alerts when an IP lookup merely failed
- The session report could say "On, system traffic exits via Tor" or "Tor is reachable" without a reading, and "Firewall: Off" when the firewall was not read
- The Circle hub could show a different security score from the SYSTEM panel next to it
- Privacy: while torrified with nftables, connections to SSH servers on the internet (port 22) left directly from your real IP address; they now go through Tor as well, and SSH to your local network stays direct
- Privacy: the routine network check, run about every 100 seconds, sent unencrypted DNS queries with a Kodachi-specific label to public resolvers, which identified a Kodachi machine to its internet provider
- Privacy: your Kodachi session token, the Tor control password, the Mullvad account number and other secrets sent to web services were readable by any local user in the process list; they are now passed privately, and `online-auth check-all-status` shows the session token masked
- Root-run helpers no longer follow links or files that another local user planted in the shared temporary folder, and no longer take system tools from the caller's search path
- Signing out now stops the keep-alive first, so a background sender can no longer sign you back in during sign-out
- A log file created as root by a system service made later `dns-switch`, `tor-switch` and other commands run as your user fail; logging is now best effort and new log files get the right owner
- Checking whether the system is torrified without administrator rights now says unknown instead of "not torrified"
- Torrify and detorrify saved every firewall rule active at that moment, such as a VPN's NAT rule or an armed kill switch, into the firewall configuration loaded at every boot; only the base rules and Kodachi's own Tor tables are kept now, detorrify restores the base, and machines already affected are cleaned up at the next detorrify
- On a freshly installed system with the stable packages `10.0.3-13` (published on 02.10.2026 and replaced the same day), nftables torrify failed
- Torrify, detorrify, VPN connect and disconnect, ping blocking and other firewall changes could fail part way with "Can't lock /run/xtables.lock" when a status check was reading the firewall at the same moment; they now wait for the lock
- With ping blocked, every WireGuard connection failed with a false "server is down"; a failed ping block or unblock was shown as done in the Firewall panel; and unblocking left empty firewall tables behind
- Installing pending packages from the dashboard reported success and cleared the pending list when the installation failed
- Turning a VPN off while torrified locked every later VPN connection out, and recovery records written before 05.08.2026 blocked reset, recover, disconnect and connect
- `routing-switch recover` no longer reports an already removed routing table as a failure, and no longer clears its recovery record and reports the network as verified when the connection is blocked locally
- Every successful VPN connection logged a false "IPv4 NOT anonymized", and a VPN connection on a torrified machine could run past 100 seconds
- A UDP VPN (WireGuard, AmneziaWG, Hysteria2 or OpenVPN over UDP) started after torrify cannot reach its server; it is now refused within seconds with the order that works (connect the VPN first, then torrify) instead of failing after about 90 seconds and blaming the network
- A failed VPN or VPN Gate connection left a NAT rule behind and skipped wiping the VPN Gate login file from memory; a failed connection now removes exactly what it added and reports the failure at once
- Torrify right after a VPN connection could abort with "Only 1 healthy instances", and a torrify after turning the VPN off could wait about 90 seconds while the Tor instances restarted several times over
- The security score credited encrypted DNS and DNSSEC from the DNSCrypt settings file even when DNSCrypt was not running, credited DNS leak protection from two unrelated firewall rules, never credited Kodachi's own USB storage block, and did not recognise the iptables torrify modes as torrified
- Switching DNS by category could apply servers that do not answer and leave the machine without DNS; a switch now checks that the new servers answer first and otherwise keeps the working DNS
- The DNS leak test hung for minutes when DNS was down; it now ends with a network error within about a minute
- With **USB Guard** on, allowing or blocking a single USB device never took effect, because the rule was added after the policy's final reject; device rules are now placed where they apply
- Enabling **USB Guard** blocked a laptop's built-in Bluetooth; the default policy now allows Bluetooth adapters on internal ports, and machines that already had USB Guard on receive the corrected policy on upgrade, without a restart, unless the policy was changed by hand
- The **SOC** exposure watcher ran in snapshot-only mode on Debian kernel 6.12.111, the kernel in the 30.09 images and in the current Debian kernel update; it now has full eBPF support on live, installed encrypted and Secure Boot systems
- The dashboard's offline banner could stay up to five minutes after the connection came back
- After a completed recovery, the Internet Recovery wizard re-ran its checks about 21 times a minute while it stayed open
- The welcome script message during `sudo apt upgrade` showed a version arrow that looked like a downgrade
- On kodachi.cloud, signing in could time out at busy times, because the public status page ran slow DNS checks for every visitor at once
- On kodachi.cloud, the status page listed servers that were down as partly online
- On kodachi.cloud, the DNS Leak Test page could draw the resolver world map several times, and its hostname column now says "No reverse DNS (PTR)" or "Lookup failed" instead of "Unknown"
- On kodachi.cloud, network names on the DNS and IP pages showed a doubled prefix such as "ASAS13335"
- On kodachi.cloud, the "Open the gallery" card on the homepage was hidden under a screenshot at some screen widths

---

### Version 10.0.3 - Kodachi 10 Dragon Stable Release

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Builds** | Desktop 10.0.3.50 · Terminal 10.0.3.33 · Binary Pack 10.0.3.11 |
| **Version Stamp** | 10.0.3 |
| **Code Name** | Dragon |
| **Release date** | 27.09.2026 |
| **Status** | Stable |
| **APT** | stable `10.0.3-11` |

**The first stable release of Kodachi 10.** It contains everything in the Kodachi 10 beta record below, plus the changes listed here, which were made during the beta testing that followed that record (16.09.2026 to 26.09.2026). The stable downloads and the stable APT channel now carry Kodachi 10.0.3, and the Desktop, Terminal and Binary Pack editions all report the same version.

**Update of 29.09.2026, second release** (Desktop 10.0.3.50 · Terminal 10.0.3.33 · Binary Pack 10.0.3.11 · APT stable `10.0.3-11`):

- Switching the microphone off now stays off: the sound system could switch the capture back on about a second after a disable that had reported success, and the microphone guard now holds every sound card's capture switch off until you enable the microphone again
- A VPN connection that stopped unexpectedly (a crash, a reboot or an upgrade while connected) no longer blocks every later connection with "route restoration remains unverified"; connecting now restores and verifies the previous routing first, then connects
- The online status and public IP check answers in about 2 to 5 seconds instead of up to 25, so the desktop panel no longer shows the online status as empty
- A failed public IP or hardening check is now shown as unavailable instead of keeping the previous value, on the dashboard, the security overview and the welcome page
- Upgrading a machine whose microphone was already disabled keeps enable and disable working
- The comprehensive integrity check no longer reports "your build matches the current published version but the online hashes differ" after an update within the same version: it now downloads the current online manifest on every check instead of reusing the first one it ever saved, and when the manifest cannot be downloaded it says so and does not treat the comparison against an older saved copy as a result
- Privacy: the Kodachi binaries no longer contain the file paths of the machine they were built on; every binary is now built with those paths removed, and packing refuses any binary that still carries them

**Update of 29.09.2026** (Desktop 10.0.3.47 · Terminal 10.0.3.31 · Binary Pack 10.0.3.8 · APT stable `10.0.3-8`), prompted by a user report of the dashboard's Tor row switching between Torrified and Running every few seconds:

- The dashboard, the desktop panel and the tray no longer show Tor, VPN, DNS or sign-in as off when a status check fails or has not finished yet; they now say the state is unavailable or not checked, which also ends the Tor row flipping between two states
- The security overview no longer keeps showing an earlier reading (VPN protected, Tor active, DNS encrypted, time synchronised) as current after a later check fails
- Encrypted DNS can no longer be reported as encrypted, or as not encrypted, when the checks behind it did not answer
- Switching the microphone off no longer undoes itself with an error; it now reports what it verified, including that an application which already had the microphone open keeps it until that application closes it
- A microphone whose hardware capture switch is still on is no longer reported as disabled
- The desktop panel no longer keeps showing your last public IP address and country as current during a network outage
- An expired Kodachi session is now shown as signed out instead of unknown
- Machines on the stable line are no longer shown beta ISO notices, and a machine that follows both the stable and the beta sources now sees the beta line
- The version button no longer shows two tooltips at once, and the version badge is spaced correctly

**Additions:**
- The **Repository Manager** gains an **ISO IMAGES** card on its System updates page that compares your image with the latest stable and beta ISO, because apt alone cannot tell you a newer image exists
- The dashboard **Update Center** can now see the beta ISO line as well as the stable one, so a machine running a beta image is told when a newer beta image is published
- The release information published on kodachi.cloud now describes the **stable**, **beta** and **dev** lines side by side instead of the stable line only
- Tor Browser, Portmaster, Monero GUI and Mission Center are now installed as real packages, so `sudo apt upgrade` keeps them current, and machines installed from older images are moved over automatically
- The **Pi-hole** engine and web admin are now delivered as packages and updated by `sudo apt upgrade` instead of staying at the version copied from the image
- An installed system now keeps its installer log at `/var/log/installer/calamares-session.log`, so an install-time warning can still be read after the first reboot
- A started **lockdown** countdown can now be cancelled by root from the command line, and every cancel is logged with who made it

**Improvements:**
- The **Host Exposure** watcher is now off until you switch it on, and an APT upgrade no longer switches it back on after you turned it off in the dashboard
- The **SOC** panel now tells you what to do about a finding, not only what is wrong
- Blocking the internet now uses Kodachi's own firewall only instead of also switching on UFW in the background, and the dashboard's UFW view explains this in all eleven languages
- The **AmneziaWG** kernel module is updated to the latest upstream release, with fixes for newer kernels and for its obfuscation behaviour
- The dashboard's automatic kill-switch triggers read the VPN and DNS state live, so a VPN drop is acted on at once instead of being hidden by a cached reading
- Background checks cost far less: the session helper no longer runs a privileged check every minute, and checks that already run as root no longer open extra sudo sessions
- Logs now keep about a day of history for the busiest components, long enough for a next-morning bug report
- The **debug collector** no longer puts your hostname or login name into a bundle you share, and it now reports disk-encryption key slots and the nuke status correctly
- Bare-metal XFCE sessions no longer start a file indexer, a location demo agent and a VMware helper that serve no purpose outside their own environment
- The first system snapshot after installation no longer fails on slow machines or grows without a memory limit, and a failed first snapshot is retried on later boots

**Fixes:**
- A wrong disk-encryption passphrase at boot now shows a message and gives further attempts instead of dropping to a bare GRUB prompt, the retry survives GRUB updates, and running out of attempts returns to the boot menu instead of restarting the machine
- A correct disk-encryption passphrase could still land in GRUB's rescue mode after an update, because two updates rewrote the boot menu at the same moment
- An installed laptop could stop booting after a swap-encryption change and drop to a BusyBox shell; installed systems now rebuild their boot image automatically after such a repair
- An installed desktop could boot into emergency mode because of a shutdown setting that also shortened the wait for disks at boot
- The **Calamares** installer no longer aborts the whole install when a finishing step times out or cannot unmount the target
- Secure Boot installs now finish configuring the signed boot chain instead of leaving its packages half installed
- Installed systems no longer keep their kernel packages on hold, which had silently blocked kernel security updates, with both the Calamares and the classic Debian installer
- The classic Debian installer could remove Kodachi itself while cleaning up build tools, and a failed check skipped every later hardening step
- VPN connections could be refused after the network or the public IP address changed; moving between networks no longer locks connecting, and restoring routes no longer deletes your working default route
- `dns-switch status` and the desktop panel no longer report DNSCrypt as off when the reading merely failed; an unreadable state now shows Unknown
- DNS no longer points at a dead local resolver when the systemd resolver's stub listener is switched off
- A Quad9 filtering resolver was pinned although Kodachi requires unfiltered resolvers; only unfiltered resolvers are shipped now and existing installs are repaired
- Tor pool instances were killed when you logged out or the dock restarted while traffic stayed routed through them; they now keep running
- **New circuit** on the main Tor daemon now requests a fresh circuit instead of reloading every Tor instance without changing anything
- Tor status now reports the real main daemon, and memory and uptime for every pool instance
- The kill switch status claimed it was armed while nothing was being blocked; it now reports what is actually enforced
- The SUID and SGID audit reported zero binaries on every run, and a failed scan no longer reads as a clean result
- **USB Guard** now stays enabled after a reboot
- **RAM wipe on shutdown** reported itself armed when the shutdown hook was missing, and **cold-boot defence** reported protection that was not running
- Disabling the **microphone** was refused with no explanation on some machines; switching it off now proceeds and any refusal names the check that failed
- Changing hardening settings no longer strips the final line break from `sshd_config`, PAM and login files, which could merge the next added line into the last setting
- Encrypting swap could delete a valid encrypted swap at boot, and a swap file on an encrypted root was reported as encrypted while swap disappeared at the next boot
- Encrypting swap could leave an unbootable `/etc/fstab`, and could fill a nearly full disk because it never checked free space
- The disk-encryption status could never recognise LUKS2, the default encryption format
- A random timezone could leave the system clock zone broken while reporting success, and failed timezone, hostname and internet-recovery commands now report the failure instead of success
- Changing the hostname left behind cached thumbnails under the old names, which linked your randomized identities together
- Installed systems kept reporting the version of the ISO they were installed from after an upgrade, and AutoShield showed Kodachi 9 build numbers on Kodachi 10
- The **Host Exposure** watcher never started on installed systems, switched between healthy and degraded without cause, and its panel showed "Malformed watcher evidence" on the first machines where it did run
- A fresh install showed **SOC** warnings about Kodachi's own services, including a critical alert for its own Wi-Fi driver guard and an external tunnel warning on every SSH login
- The lockdown trigger's protection against faked input could be bypassed by a virtual input device, and triggers were wrongly blocked inside virtual machines
- The **Hardening** page search box could run a privileged command such as a RAM wipe straight from what you typed, without a confirmation, and **Apply Hardening** now asks before it runs
- The proprietary Broadcom Wi-Fi driver loaded on every Wi-Fi card, and Surface and VMware display modules loaded on all hardware; each now loads only on matching hardware
- LibreWolf lost its Kodachi launcher after an APT upgrade, and could not detect hardware acceleration
- The audit log filled with Kodachi's own dashboard activity and rotated away real root commands within seconds
- The time service answered time requests from the local network; the machine is now a time client only
- The `z` directory history could be read by another local user through a predictable temporary folder
- Health logs no longer record hundreds of false network-down lines while the network works, and idle machines no longer log false keyboard-disconnected warnings
- The launcher preview printed overlapping labels such as "Commar2l segments"
- On kodachi.cloud, the IP lookup that Kodachi machines use first now returns the city again instead of N/A

> **Notes:**
> 1. Kodachi 10.0.3 is now the **stable** release. The stable downloads on kodachi.cloud and the **stable** APT channel both serve it.
> 2. The **beta** channel continues for testing the next Kodachi 10 updates. You can move between stable and beta at any time from the **Repository Manager** or with the instructions on the Downloads page.
> 3. If you installed with the published unattended-install password, change it at first login.

---

### Version 10.0.3 - Kodachi 10 Beta (rolling record)

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 10.0.3.15 · Terminal 10.0.3.4 · Binary Pack 10.0.0.1 |
| **Version Stamp** | 10.0.3 |
| **Code Name** | Dragon |
| **Release date** | 16.09.2026 (first beta 07.09.2026) |
| **Status** | Beta |

**This is the single record for the whole Kodachi 10 beta.** Kodachi 10 is one major beta version, so every beta change lands here and the table above tracks the current stamp, rather than a new section being opened for each beta cut. The Terminal edition has now caught up to the 10.x line, so Desktop and Terminal are on the same number for the first time in this beta. All changes below were made after the last Kodachi 9 release (stamp 9.8.2) on 26.06.2026. Kodachi 10 keeps the Debian 13 base and the Rust service layer introduced in Kodachi 9, and adds two more dashboards, the return of the Cairo Dock with native GTK windows, two new obfuscated VPN transports, and installation and updates from Kodachi's own signed APT repository.

**Additions:**
- The version line is re-anchored to **Kodachi 10**, code name **Dragon**, and the published version now follows the computed stamp, so the dashboard, the desktop panel, the binaries and the download metadata all report one number instead of two unrelated ones
- **Five dashboards** now ship and share one left rail with section headings, a top-bar command box and a Ctrl+K command palette: **Circle**, **Lite**, **ColonyOps**, **Vitals** and **SOC**
- A new **ColonyOps** dashboard turns every Kodachi command, workflow and Linux utility into a placeable, runnable cell on a visual map, with a four-tab command library (Cells, Workflows, Linux, and your own commands), interval scheduling, danger badges and confirmation gates on destructive cells
- **ColonyOps** gains a **Colonies** tab with ready-made colonies, JSON import and export, country flags on the map, a map that grows when you drag empty grid, changeable execution order from all three surfaces, and a hover explanation on every field
- **ColonyOps** can run your own saved VPN connections: star a Mullvad, IVPN or imported WireGuard profile on the **Global VPN Providers** page and it appears on the map as a runnable cell
- **ColonyOps** lets you keep a colony you built by dragging it to the Colonies shelf, and ships fifteen more tested colonies across two new catalogue sections
- A new **Vitals** dashboard gives you a live terminal-style monitor of security score and modules, Tor, DNS and VPN state, CPU, RAM, swap, disks, top processes, connections and throughput
- The **SOC** security page becomes a dashboard in its own right, so you can open it directly instead of booting a whole dashboard to reach it as a tab
- The **Cairo Dock** returns to Kodachi, restored from Kodachi 8 and rebuilt around what people actually click: application launchers sit on the dock in named groups, clicking a group icon opens a proper **GTK window** instead of a sub-dock, and privileged actions run through an authenticating action runner
- A new **Kodachi Repository Manager** window replaces three terminal launchers, with a storefront package page, system and third-party APT source management, and a trust pane that reports this machine's own keyring
- **Recipes**, a twelfth dock icon, exposes 94 runnable workflows that nothing on the desktop could previously reach
- The dock ships **127 cells across 9 sub-docks**, 107 of them application launchers, and gains a penguin **application menu**, **Show Desktop** and a working **dustbin** applet. Thirteen cells open a native GTK window directly, out of 23 windows served by three GTK programs
- Kodachi now installs and updates from its own signed **APT repository**, consolidated into exactly three published lines, **stable**, **beta** and **dev**, with separate packages for the hooks, the desktop launcher, the desktop panel and each vendored privacy tool, verified on fresh Debian trixie and Ubuntu 24.04
- **Add repository** offers Kodachi stable, beta and dev as preconfigured entries, so choosing one writes the correct signed source automatically
- Kodachi now takes a **system snapshot before a risky APT transaction**, so a bad update has an undo, with the restore control in the **Repository Manager**
- The live ISO drops every one-click application installer in favour of the **Repository Manager**, whose **Favourite Apps** page installs from the Kodachi APT repository instead
- The update check now looks at the **APT channel your machine is actually on**, stable, beta or dev, instead of only the stable download metadata, so beta machines are told about beta updates
- Two new obfuscated VPN transports, **AmneziaWG** and **OpenVPN over Cloak**, work end to end: connect cards, the **VPN Providers** island, the **Circle** station list, the tray Connect menu, **ColonyOps**, the setup workflows and the connection-card generator all offer them, with a new obfuscated-preferred selection mode. Kodachi now carries 14 tunnel and proxy transports, up from 12
- **AmneziaWG** and the **Cloak** client install from the APT repository and the standalone installer, not only from the ISO
- A new **Quick Launch** startup screen replaces the full setup screen on every boot, with four dashboard cards and a gauge, plus **advanced** and **direct** alternatives; its picker is split into a **Control** group (Circle, Lite, ColonyOps) and a read-only **Monitor** group (Vitals, SOC)
- You can **switch dashboards from the keyboard**, with Ctrl+1 to Ctrl+6 plus a cycle key by default, remappable in **Settings** and shown beside the **Dashboards** menu rows
- The dashboard can be run in your own language: a new **Interface Language** selector in **Settings**, with 13,583 translated keys per locale across 11 languages, including the data-driven pages, and **Pakistani Urdu** joins the shipped languages with a right-to-left catalog covering the dashboard, the launcher and the dock picker
- **Guided tours** now cover all five dashboards and both startup launchers, with chapters, replay and keyboard navigation, and a rewritten **Help**, **Routing Guide** and onboarding section explains each screen as you use it
- The **Lite Actions** drawer becomes a three column command browser: categories on the left, commands with badges in the middle, and a detail pane that shows the exact command before it runs, with a breadcrumb and a basket that stages several commands and runs them in order
- The **Circle** command wheel gains new stations: Peripheral Guard (WiFi, Bluetooth, webcam, microphone, printer on and off), Lock and Power, Data Wipe, network block and kill, 5, 9 and 14-eyes Tor exit-node exclusion with a one-click clear, and VLESS, Shadowsocks and Dante for full protocol parity; dangerous slices ask for confirmation first
- The **Circle** dashboard lets you switch segment shape, capsule, tile, gauge or split, independently of the theme, so labels sit level and status is readable at a glance
- A shared **Appearance** panel brings the same backdrop and accent colour to all five dashboards, with 20 curated backdrops replacing the previous six portraits
- The **SOC** page gains an **Agents** cluster that detects AI agents running on your machine, which model they are talking to and under whose authority, and flags screen-capture activity
- A new always-on **Host Exposure** watcher raises alerts even while the dashboard is closed, with retained findings, paged history and exact evidence on the **SOC** page
- A new **Firmware & Platform Security** panel appears in both the dock **Status** window and the dashboard **Vitals** page from one shared producer, and `fwupd` is installed on both install paths
- The **Emergency** page gains a search box that finds any of its six tabs and around forty controls by name
- The **Decoy** traffic generator gains interest clustering, a day and night rhythm, and live gauges, so generated browsing looks like a person rather than a uniform draw
- A rootless **Containers** workbench and **Isolation Manager** join the dock, covering Podman and Firejail profiles with their own artwork and a catalog read from the machine
- **USB Guard** becomes a real on and off switch, persistence reaches the dock, and 26 of the dock's 31 switches now read the machine's true state instead of a guess
- The **Routing Guide** wizard is rebuilt as a departure board that asks real questions and only offers commands the binaries actually accept, and the **system tray** menu is rebuilt to offer every protocol plus the essential operations
- Dock answers that are too long for a notification open in a window with a **Close** button instead of timing out, and the network cut control carries its own undo and seven cut methods in the same window
- Kodachi gets a new brand mark: the hooded KO replaces the old shield across every icon surface, the wallpapers, the dashboard and kodachi.cloud, and the **Dragon** wallpaper set becomes the Kodachi 10 default
- The dashboard opens maximized and remembers that choice per dashboard, both startup screens gain an **About** icon that lands on the licence manager, and the **Welcome** auth chip shows your package on its face and your account identity on hover
- Installed systems enable an idle **screen lock**, which stays off on live sessions
- On kodachi.cloud, the **Downloads** page gains a **Stable / Beta** release-track switch with instructions for moving between channels in both directions, and its track buttons show each channel's major version
- On kodachi.cloud, the site is now one unified portal over the landing page, all 65 documentation pages and the online tools, with section-level full-text search that deep-links to the exact answer and a licence-key login that carries you into your dashboard
- Two new public tool pages: the **Workflow Simulator** plays any of 113 real Kodachi workflows step by step in your browser with nothing executing, and the **Command Library** lists every command of every signed binary
- The **License Portal** gains self-serve seat top-up, priced at your original rate, prorated and co-terminated with your existing keys, and Premium and Dedicated customers can choose which of their entitled **VPN nodes** serves the next connection
- What each licence tier unlocks is now decided on the server through a 27-item capability matrix, with per-user overrides, so entitlements can change without a dashboard update
- **Ctrl+R now searches your shell history properly.** Kodachi has shipped `fzf` for a long time without ever switching it on, so the binary was present and the key did nothing. Ctrl+R is now a fuzzy search over your history, **Ctrl+T** inserts a file path and **Alt+C** jumps to a directory, each with a preview pane
- **`z` jumps to any directory you have visited**, by a fragment of its name instead of its full path. `zoxide` was in the same state as `fzf`, installed and never wired. Plain `cd` is untouched, and the directory history is still held in RAM only, never written to disk and wiped at poweroff
- **Ctrl+G picks git objects visually**: Ctrl+G Ctrl+F for changed files, Ctrl+G Ctrl+B for branches, Ctrl+G Ctrl+H for commits, Ctrl+G Ctrl+T for tags, each with a preview of the diff, the log or the tag
- **`tldr`** gives the practical examples for a command instead of a full manual page, answered instantly from a local cache so it works with no network
- **`newsboat`** reads RSS and Atom feeds in the terminal, with no browser and no JavaScript, and follows the system proxy so feeds can be fetched over Tor
- **`asciinema`** records a terminal session to a local file you can replay or attach to a bug report; nothing is uploaded unless you explicitly run the upload command
- **`faker`** generates realistic but entirely fake names, addresses and records, so test data never has to be real data
- **`kew`** plays local music from the terminal on the Desktop edition, with no accounts and no network
- **`lolcat`** and **`cbonsai`** join `cmatrix` for the terminal that wants to look good
- The new command-line tools are standard Debian 13 packages present for both 64-bit Intel/AMD and ARM64, so both architectures ship the same command line. The shell changes apply to interactive bash only, leaving scripts, `scp` and `rsync` over SSH untouched

**Improvements:**
- The dashboard is markedly lighter on the processor: pages no longer rebuild themselves on a timer, on every keystroke, or while hidden behind another tab, the **ColonyOps** map stops redrawing its whole world every four seconds, the **Circle** ring measures itself once per drag instead of on every mouse move, 597 KB of stylesheets for dashboards you have not opened stop blocking the first paint, and the launcher stops polling eleven hooks every 30 seconds while hidden
- The desktop panel reads one snapshot for all its fields instead of paying per gauge, keeps its panel in place for the whole session, and lists every VPS node available to you instead of a fixed four
- Text is readable everywhere: every measured contrast failure across the 39 **Lite** states is repaired, the left rail's section headings reach a 4.5:1 ratio, and an 11px minimum type size is enforced across all 42 islands
- Destructive commands ask before they run, on every surface rather than only one, including 12 dock recipes and 7 data-destroying rows that were previously plain buttons, and confirmation prompts move from operating-system dialogs into the page itself
- Dock icons show what an action does instead of the logo of the program behind it, and a crowded 28-icon dock is condensed to 11 clear groups
- The **Lite** dashboard is consolidated down to 21 pages, 16 in the sidebar plus 5 standalone: ten Command Builder pages become one with a service switcher, seven Monitoring pages become one **Monitor** page with sub-tabs, Library and Favorites merge into one **Command Library**, and page bodies load on demand so Lite starts faster
- Tor **exit country** and **exclusion list** choices now apply to every running Tor instance, not just the system daemon, and a random exit can no longer be pinned to a country with no exit relays
- The **SOC** page adds four detectors, gates the keylogger and webcam checks on real device capability, and corrects its MITRE mapping and bidirectional-text-safe labels
- **Microphone** protection controls capture in the live desktop audio session, fails closed when the policy drifts, and recovers audio afterwards
- **ColonyOps** is easier to navigate: simplified command discovery with favourites, an off-screen chip that tells you which colonies and cells are out of view and takes you to them, new cells that land where you are looking, commands grouped by subject and listed once, and a typed confirmation phrase only for genuinely destructive commands
- The **Vitals** top strip and **Markets** panel are redesigned so headings and values read at a glance, and the **Lite** alert list becomes a compact signal board
- Searching the launcher by protocol name now finds all 14 protocols instead of 4, and the log viewer stops throwing away your scroll position every two seconds
- The **Premium appearance packs** work on every tier, reach the **Lite** page background, and are strong enough to see
- The dock **Tor pool** window shows flags and country names from Tor's own table, keeps its action buttons in a fixed column, and gives each rail row its own icon
- The **Downloads** binaries panel is rewritten with progressive disclosure and its own Fedora instructions for the portable route, and the **Support** page is rebuilt with the purchase widget in the hero so every plan tab shows a price and a buy action
- `kodachi-soc snapshot` gains an opt-in text mode alongside its JSON output

**Fixes:**
- Installing from the classic Debian installer now produces a complete Kodachi system; it previously left the Kodachi components out
- The **Calamares** installer now applies every Kodachi post-install step, so an installed system carries its full configuration
- Tab characters in the boot theme truncated **every GRUB menu title to 12 characters**, so entries such as "Kodachi Encrypted Persistence" and "Kodachi CPU Hardened" were indistinguishable at boot
- The installer no longer puts your hardware model in the hostname, no longer hides a security checkbox off-screen, and its timezone default, radio-button layout, label contrast and slideshow translations are corrected
- **Pi-hole** now ships with its admin interface, and its credentials are generated per installation rather than being fixed in the image
- Certificate material and administrative credentials are now generated on first use rather than carried in the image. **If you installed with the published unattended-install password, change it at first login.**
- File permissions and privileged file handling are hardened across the VPN and system components
- Large numbers of dashboard commands could not run at all: 41 of 52 unreachable catalog commands now dispatch, 430 of 441 commands that failed because the applet sent `--json` twice now work, and 11 more catalog rows plus 14 ColonyOps cells that named arguments their binary rejects are corrected
- Emergency and destructive controls no longer act without asking: the kill switch auto-confirmed a RAM wipe after 500 ms, pressing Enter on Cancel confirmed a shutdown, turning the firewall off skipped the confirmation that resetting it required, **Reset all settings** wiped everything even after the backend refused, and 25 destructive commands ran on a single press
- Dangerously mislabelled dock cells are corrected: a "Free Memory" cell that killed your largest process, a cell labelled **Disarm** pointed at a command that erases the LUKS header, two cells promising a sandbox and a settings dialog that ran the same command, a LUKS wipe form that split passwords on a character passwords contain, and **Apply** tearing down five hardening protections nobody had touched
- The desktop right-click menu in **Thunar** could wipe your Desktop folder with one click, "Print file/s" named a command that does not exist, and "Sandbox File Manager" opened nothing
- **Torrify** no longer breaks your connection: it stopped killing the very tunnel it was riding on, stopped stranding machines with IPv6 disabled off the network entirely, its firewall rules can be removed again, and it now torrifies DNS as its button always claimed
- Disconnecting a VPN no longer kills an OpenVPN session you started yourself, emergency cleanup no longer matches and kills unrelated programs such as `wget`, DNS is restored when anonymization fails, and the routing speed benchmark measures the tunnel instead of the web server on port 443
- A failed **VPN connect** printed nothing at all, so a failure looked like a hang
- The Tor DNS redirect hijacked the local resolver, **Random DNS** could only ever return one resolver, and a rate-limited reply from the Tor check service was reported as "not on Tor"
- The desktop panel claimed "OpenVPN On" on every install with no tunnel, and a single bad service name hid 40 of the 41 services it checks, so an active Shorewall firewall read as off
- The **SOC** page is corrected throughout, including a watcher that reported UNSUPPORTED across the whole 10.x line and SSH sign-in monitoring that saw nothing, plus a degraded system monitor that could override the real security score and a permanent finding created for every DNS query
- The rootkit scan reported "clean" for a scan that had never finished, the **DNS leak** notification read a field its producer has never emitted so it had never fired for anyone, and 14 of the 24 security fields on **Vitals** had no producer and read "Unavailable" forever
- **Hide Typing Rhythm** could never work on any installed Kodachi, and the standalone installer shipped its own unhardened copy with no keyboard attached while telling you to start it
- First-run setup armed two-factor authentication before the authenticator was ever paired, which could lock you out of your own dashboard
- The dock stacked a second copy of itself on every restart, a slow layout generator could cost you the dock entirely, several dock windows opened narrower than their own content, and three controls whose answer is a window got their window back
- A fresh user account lost four dock applets, 20 cells shared or copied another cell's icon, and the launcher menu published a LAN SOCKS5 proxy under Kodachi's own name
- Several faults that made the dashboard unusable are fixed: a white page caused by the native window background, a corrupt saved setting that took the whole app down at startup, the **AutoShield** protocol dropdown that never painted, **Settings** showing a literal placeholder where the build number belongs, and the **Workflows** page showing one profile's steps under another profile's name
- You can type in dashboard **modal text fields** again, nested command categories are reachable instead of resetting the menu to the top, and in **Workflows** the sudo gate, tag and amber Run control could not appear for 116 of 122 profiles
- A single malformed entry could disable every **ColonyOps** cell, and a restored cell now re-binds to the catalog so commands such as whois can run again
- A locked dashboard now refuses tray actions instead of running them above the lock screen, and a protected startup boots behind the lock gate
- The **Vitals** sparkline rendered as a blank gap in the shipped binary, a sub-dollar price printed eighteen digits and overflowed its tile, **Circle** station labels printed across the slice captions beside them, and a machine with no temperature sensor showed a broken CPU TEMP reading
- **Health** told you to start a systemd service that does not exist on the image, `create-recovery-point` backed up zero files while reporting success, and boot-nuke reported itself armed on every system
- The **debug collector** hung for tens of minutes on every Kodachi system, and its documented one-line install form never produced a bundle at all
- The **AutoShield** login script no longer changes shell settings in the terminals you open, honours Ctrl+C on the welcome path, shows the correct version, and no longer skips Connect Global VPN at boot, so external providers such as Proton come up as configured
- The **Tools** page **Oniux** section could never run on any install
- The shipped **LibreWolf** profile now starts with a clean history, and the desktop menu no longer advertises an application the ISO does not include
- On the live desktop, all three panel monitors and the disk applet were tied to one specific hardware layout, so they were blank on other machines, and the disk applet used far less processor on a CD-booted live ISO
- The ISO shipped a launcher promising a Firejail sandbox that is not installed, an installer that handed away ownership of `/opt/kodachi`, browser bookmarks still branded "Linux Kodachi", a mis-centred boot banner, and system monitor units that were installed but never enabled
- Hardware and application fixes on the image: the **8814au** Wi-Fi driver builds on the shipped 6.12 kernel, **Mission Center** matches its manifest version, and **OTPClient** keeps secrets out of swap
- Randomized MAC addresses survive a reconnect, unblocking the internet no longer erases the marker needed to restore your network card, and the shutdown RAM wipe no longer demands an online session at shutdown
- A sleep-inhibit change made the installer demand a password on every launch
- In the **License Portal**, the validity line now shows your real licence term, the premium bonus links work, the seat counter agrees with the seat list, and add-on seats are grouped with the order that added them

**Removals:**
- The **advanced** (full) dashboard is retired; anyone who had saved it as their startup dashboard is moved to a real one
- Every one-click application installer is removed from the live ISO in favour of the **Repository Manager** and the APT repository
- The retired **Queen** artwork and 36 older wallpapers are removed in favour of the **Dragon** set

> **Notes:**
> 1. This is a **beta** of the Kodachi 10 line. The current stable release remains Kodachi 9 (stamp 9.8.2).
> 2. Kodachi 10 keeps the Debian 13 (Trixie) base and the XFCE desktop of Kodachi 9. The 10 boundary is a version-policy re-anchor plus a licence-scope change, not a new base system.
> 3. Beta machines should switch to the **beta** APT channel to receive 10.x updates; the **stable** channel continues to serve the Kodachi 9 line.

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.174 · Terminal 9.0.1.179 · Binary Pack 9.0.1.316 |
| **Version Stamp** | 9.8.2 |
| **Code Name** | Queen |
| **Release date** | 26.06.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.8.1) on 24.06.2026.

**Additions:**
- New **Tor Bridges** support lets Tor start even on networks that block or interfere with it, including when running over a Reality/XTLS VPN: paste obfs4 bridges and manage them from **Settings → Tor Bridges**, the **Essentials** Tor group, the **Tor** page, and the Tor quick actions, with enable/disable, an **All** or **Random** bridge selection, and automatic rotation on a timer
- The **AI Assistant** page is reachable again from the **Lite** and **Circle** views (and the **Full** top bar) through a new **Bot** icon; the Lite and Circle layouts had previously lost all access to it
- The self-service **License Portal** gains a **Your Nodes** panel that shows the VPN nodes your license can use (IP, country, and flag), how many connection cards each one has available, and a live per-service status for every node
- Four new ready-to-run **Workflows** were added: set up obfs4 Tor bridges, disarm the emergency kill-switch, check **Backup** readiness, and keep **DNSCrypt** monitored with automatic recovery
- A new **Dashboard Gallery** lets you preview the Kodachi dashboard before installing, with annotated screenshots you can filter by topic (SOC, VPN, Tor, DNS, Mobile, and more) and open full-screen, at <https://www.kodachi.cloud/wiki/bina/gallery.html>

**Improvements:**
- The **SOC** security page now watches more signals: DNS health and leaks, your running Tor instances, notable background services, sign-in history, and several additional intrusion patterns
- The **SOC** page can now be restyled, with a choice of security-map themes and side-panel styles, and its controls now carry clear explanatory tooltips on a tidier layout
- The **SOC** page is lighter on low-power and single-core machines, capping its animation and easing back visual effects so the desktop stays responsive
- The **SOC** page now refreshes every 2 minutes by default instead of every 8 seconds, and you can choose the refresh interval from 15 seconds up to 10 minutes or **Manual**, with clearer status text and no more briefly stale readings
- The **DNS** page gains working **DNSCrypt** and **Pi-hole** on and off switches, with password validation when you enable Pi-hole
- The password generator can now create up to 500 passwords at once
- Light-theme polish: clearer contrast and more consistent colours across the dashboard, the **Circle** view, and the **SOC** page

**Fixes:**
- The **SOC** page no longer raises false critical alerts or shows blank readings: ordinary browser and just-in-time memory, the dashboard itself, and normal established connections are no longer flagged as threats, and panels that previously showed "?" when run with elevated privileges now read correctly
- The standalone dependency installer no longer aborts part-way on newer **Ubuntu** (26.04) systems, and it now installs the Tor location database so country-based Tor circuits work on plain Debian and Ubuntu installs
- Integrity verification of the shipped binaries now passes; the published checksums had been generated against the wrong copy of the files, which made verification wrongly report a failure
- Machines with a wrong hardware clock, common on live-USB boots, no longer stall when connecting a VPN or signing in, because the clock is now nudged forward early during boot
- **Workflows** that previously failed to load or run now execute correctly
- The emergency **panic** workflow now always asks for confirmation before wiping, where it could previously run without confirming
- The **Lite** dashboard menu had broken Tor exit-node choices and was missing many actions; the exit nodes are corrected and around twenty more commands are now available
- On the **Identity** page, changing your timezone or hostname now takes effect instead of being silently ignored
- The network routing speed benchmark now runs instead of failing with an error
- The built-in news feed now applies your chosen sources, and its **Hacker News** link was corrected
- Help for the **VPN Providers** and **Mobile** pages now opens correctly
- The **Essentials** Actions and **Settings** pages no longer go blank when a background command returns no data
- **Favorites** presets were fixed: a preset that showed only part of its actions now shows all of them, and unsafe or dead default favorites were removed
- The **Processes** page now shows a clear message when a process cannot be stopped

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.171 · Terminal 9.0.1.176 · Binary Pack 9.0.1.313 |
| **Version Stamp** | 9.8.1 |
| **Code Name** | Queen |
| **Release date** | 24.06.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.9) on 13.06.2026.

**Additions:**
- A new **SOC (Security Operations Center)** page joins the dashboard, opened from the new **Radar** icon in the sidebar just after System Health in both the Advanced and Lite views; it shows a live map of your machine's security signals built around a central security score and eight clusters (vitals, network, connections, processes, threats, sign-in activity, privacy, and system), with colour-coded findings, a top-findings list tagged with known attack techniques, a privacy summary, and a live alert feed, and it only observes without ever changing anything itself
- The **Destroy Kodachi** emergency-wipe control is now a skull icon at the bottom of the sidebar in the Full, Lite, and Circle views with an in-window confirmation step, replacing the old floating button; you can show or hide it and choose its confirmation behaviour under **Settings → Security**
- **Backup & Restore** (Settings → Backup) can now include your own custom folders and your cryptocurrency wallets, with Monero, Bitcoin, Electrum, and Wasabi detected automatically
- A new self-service **License Portal** lets you paste one or more license keys and see, in one place, each license's tier, seat usage, expiry, registered devices, purchase price, download links, and transaction history, and release a device seat remotely when you no longer have the original machine; a link to it now appears on your purchase-confirmation page and from the dashboard's **License Manager**

**Improvements:**
- On the **Mobile** page, the "open in app" shortcuts are now grouped one entry per app with separate iOS and Android links instead of duplicate rows, and the list of supported mobile apps for each protocol has been re-checked and expanded
- Dedicated-plan customers who need specific exit countries or providers can now spread their licensed devices across more than one isolated private server, up to one server for every ten devices, at no extra per-server charge; the support and pricing pages now explain how the allowance works
- The dashboard's backup passphrase box now matches the secure entry fields used elsewhere, and the Help button opens the Backup guide while you are on the Backup tab instead of always opening Security

**Fixes:**
- A **WireGuard** VPN connection that takes a little longer to complete its secure handshake is no longer wrongly reported as failed, so connections that previously timed out now succeed
- After you disconnect, leftover background helper processes, duplicate or stale network routes, and old lock files from the previous session are now cleaned up, so they can no longer block or misdirect your next connection, including when you reconnect as a normal non-administrator user; the disconnect message also no longer incorrectly blames your saved server profile
- Turning on **Tor** routing no longer wrongly reports Tor as stopped and refuses to start when an instance is in fact already running, because it now checks the live state instead of a saved status that could be out of date
- Randomizing the address of a wired (Ethernet) connection no longer changes your local IP address mid-session, which previously could break always-on apps such as Discord; the wired adapter now keeps a stable address
- A network-level anti-tracking protection that randomizes connection fingerprints now loads correctly again on the latest kernel, restoring a safeguard that had quietly stopped working
- On low-power single-core machines, the on-screen system monitor no longer overloads the processor, so the desktop stays responsive
- Drop-down menus in **Settings** and in AutoShield no longer spill past the edge of their panel
- The dashboard **Backup** tab no longer wrongly reports "No mountable volume found": the backup tool is now located reliably on the live system, and a connected drive that is unlocked but still needs a permission change is now listed with a clear "permissions needed" note and a hint to fix it, instead of being hidden

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.168 · Terminal 9.0.1.173 · Binary Pack 9.0.1.310 |
| **Version Stamp** | 9.7.9 |
| **Code Name** | Queen |
| **Release date** | 13.06.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.8) on 10.06.2026.

**Additions:**
- Kodachi downloads now come from the official `kodachi.cloud/downloads` page instead of SourceForge: large ISO downloads can be paused and resumed, live download counts are shown, and every edition lists its current version, build number, and verification checksum and signature so you can confirm the file you downloaded is genuine
- The dashboard gains a **Help Center**, a single, searchable place that explains every part of the app, reachable from the Full sidebar, the Lite **Help** tab, and the Circle view, with each topic marked for the dashboards it applies to and a shortcut to open the Routing Guide

**Improvements:**
- On the **Mobile** page, an Xray connection that provides several protocols (such as VLESS, Reality, Trojan, and VMess) now shows a separate row with its own QR code, copy, and export for each one, instead of a single QR that carried only one of them
- Readability and layout polish across the dashboard: the Lite view's bottom metrics bar uses larger text that wraps instead of overflowing, the Circle view groups its action icons at the top and information icons at the bottom, and the Routing Guide opens at full page size in the Full and Lite views
- The dashboard's built-in help and guides have been corrected to match how the app actually behaves, accurate keyboard shortcuts, command options, resolver and app lists, and clearer DNS leak-test guidance, so the instructions no longer mention features that were renamed or removed

**Fixes:**
- Randomizing your MAC address or identity no longer disturbs an active VPN tunnel; previously it could drop the protected route and briefly expose your real IP address while the dashboard still showed you as connected, and the VPN indicator now reflects traffic genuinely flowing through the tunnel rather than the tunnel merely existing
- The dashboard Firewall panel no longer shows a false "outgoing traffic is blocked" warning when your firewall is actually allowing outgoing connections
- The dashboard welcome screen is more dependable: it no longer stays stuck on a "no internet detected" notice once you are back online, the auto-launch countdown no longer freezes for signed-in users, and a price-feed glitch that could leave the screen blank has been fixed
- The dashboard no longer shows a second scrollbar with an empty black strip, or lets the page scroll out of view
- The system-hardening summary now explains why the number of hardened modules it reports can differ from the dashboard's **HARDEN** tile, some modules are turned off by your security profile, and disk hardening only takes full effect after a reboot, instead of appearing to contradict itself

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.166 · Terminal 9.0.1.171 · Binary Pack 9.0.1.308 |
| **Version Stamp** | 9.7.8 |
| **Code Name** | Queen |
| **Release date** | 10.06.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.7) on 03.06.2026.

**Additions:**
- AutoShield on the dashboard welcome screen gains a **Boot Profiles** category: pick a saved VPN provider or a security workflow to apply automatically at boot, with a search box and filter chips to find the one you want among long provider and profile lists
- The dashboard Firewall panel adds a **Restore safe defaults** button and a warning banner so you can recover outgoing internet access in one click if the firewall was ever left blocking it

**Improvements:**
- Encrypted DNS is now more private and self-repairing: Google's public resolver has been dropped from the default DNS pool, and if the system ever drops to unencrypted DNS it restores the encrypted connection on its own with no action needed from you
- The DNS leak test no longer reports a false leak when encrypted DNS is active, and now warns only when your internet provider is genuinely intercepting DNS queries
- The dashboard's Routing Guide has been refreshed to match the current VPN providers, protocols, and AutoShield options, so its recommendations reflect what the app can actually do
- A component that could create unencrypted swap files has been removed, so sensitive data such as encryption keys can no longer be written to disk in readable form

**Fixes:**
- Older computers (roughly pre-2013) that previously crashed during boot with an "invalid opcode" kernel panic now start up normally
- Waking the computer from sleep no longer occasionally trips the cold-boot memory protection and forces an abrupt shutdown
- Turning on the firewall, from the dashboard or the bundled `gufw` tool, no longer cuts your internet connection, and the firewall no longer reports itself as disabled after a reboot
- The VPN indicator at the top of the dashboard now correctly shows **On** when a VPN tunnel is running through Tor
- The security score now shows a consistent color across the desktop panel, the on-screen status readout, and the dashboard card instead of disagreeing between green, gold, and red

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.164 · Terminal 9.0.1.169 · Binary Pack 9.0.1.306 |
| **Version Stamp** | 9.7.7 |
| **Code Name** | Queen |
| **Release date** | 03.06.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.6) on 27.05.2026.

**Additions:**
- AutoShield is now a built-in tab on the dashboard welcome screen instead of a separate app: arm it once and it applies your chosen privacy hardening, VPN protocol, DNS mode, Tor / torrify mode, MAC and hostname randomization, and hardware and anti-forensics toggles, automatically at boot, with a live countdown, system-resource readout, and before / after summary
- New **External VPN DNS** control, in the dashboard DNS settings, in Quick Actions, and as `dns-switch external-dns`, lets third-party VPN apps such as Mullvad and ProtonVPN manage their own tunnel DNS; this clears the "internet blocked" error their apps previously hit on Kodachi, and the control stays usable even while a failing VPN has cut your connection
- Both the Terminal and Desktop editions now ship a set of modern command-line tools, `eza`, `duf`, `dust`, `zoxide`, `git-delta`, and `mc`, plus `trash-cli` for recoverable deletes, with the `zoxide` directory-jump history kept in memory only so it never persists to disk

**Improvements:**
- The dashboard's Kodachi AI assistant now understands and carries out almost any Kodachi action from plain-language requests, including multi-step instructions, goals such as "make me anonymous", and listing or running your saved security workflows, and reliably performs actions that need administrator rights
- The welcome screen now shows live local system metrics (uptime, processes, threads, network throughput) alongside live fleet figures (active users, logins in the last 24 hours, all-time peak) so you get an at-a-glance status the moment you sign in
- Quick Actions and the Commands Library in the dashboard now use the correct, verified command for every service, so the action you trigger runs reliably instead of occasionally doing nothing

**Fixes:**
- The External VPN Providers page now shows the connected provider correctly in both the catalog grid and your saved configurations, no longer displays a duplicate output console, and removes a deleted profile immediately instead of leaving a stale row until restart
- On the Desktop edition the dashboard again starts automatically at boot and from the panel, the panel launcher icons render instead of appearing blank, and the display now auto-detects its resolution instead of being forced to a fixed size that left some screens blank
- Several bundled apps work correctly again: large videos (wider than 2048 px) now play in virtual machines without 3D acceleration, ExifCleaner opens to its normal window instead of a blank one, saved and downloaded images open in the image viewer rather than the browser, and attaching files in LibreWolf no longer fails with a permission error
- DNS no longer leaks in plain text during the brief window before encrypted DNS finishes starting at boot, and IPv6 is now fully disabled at the kernel level on installed systems to match the live ISO
- `sudo` no longer leaves a `dead.letter` file containing your command history in your home folder, and emergency, power, and diagnostic shortcuts that had been silently blocked now work again
- Rounded menus and pop-ups no longer show black square corners on GNOME and other GTK 4 themes

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.161 · Terminal 9.0.1.166 · Binary Pack 9.0.1.303 |
| **Version Stamp** | 9.7.6 |
| **Code Name** | Queen |
| **Release date** | 27.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.4) on 25.05.2026.

**Additions:**
- New Kodachi-branded wallpaper collection - gothic, dragon, owl, panda, phoenix, and anonymous mascot designs replace the older set, with the gold-eyed gothic theme as the new default desktop background
- New DNSSEC and DoH controls in the dashboard DNS tab and the `dns-switch` command line (`dnssec-on/off`, `dot-on/off`); the security score now credits both when active, reading the live `dnscrypt-proxy` config that Kodachi actually uses instead of the unused `systemd-resolved` layer
- Microsoft Impact font now ships with the system, so security score and Conky panel titles render with the intended typeface instead of a wider, lighter Noto Sans fallback

**Improvements:**
- Bundled Xray is now 26.3.27 (up from 26.1.31) and V2Ray is now 5.49.0 (up from 5.40.0) on the client, the Kodachi VPS proxy fleet, and every fresh ISO build; this rolls in upstream XHTTP transport support so VLESS / VMess profiles using XHTTP that you paste into the Custom provider card now import and connect cleanly
- Stylized Conky panels are now correctly transparent on fresh non-ISO installs and on VMware/Hyper-V guests; both installer paths auto-enable the XFCE window-manager compositor that was leaving the panels with a solid black background
- The KODACHI SIGNAL DECK panel is tighter (~560 px wide instead of 720) with smarter text truncation so long IPv6 addresses, RSS headlines, and value rows stay inside the panel boundary
- Dashboard, AutoShield welcome screen, top status bar, and the Conky security tile now agree on what each security score band means - a score of 71 reads as Fair (yellow) everywhere instead of varying by panel
- XFCE panel disk-usage plugin shows a compact text label instead of a vertical full-height red bar on the deskbar layout, so a 95%-full disk no longer renders as an alarming wall of red
- ISO download is roughly 340 MB smaller this build: the bundled Xray / V2Ray / Hysteria / tun2socks archives no longer get baked into the squashfs (the chroot pulls fresh on install), and the stripped set now includes pocketsphinx, five enterprise firmware packages, the Java-only LibreOffice peripherals, and Debian's `desktop-base` branding
- Debug bundles produced by the dashboard's "Send debug logs" button now redact every raw IPv4, IPv6, and MAC address before zipping, including the kernel SSH-accept and INPUT-DROP lines that previously contained your LAN topology in plain text

**Fixes:**
- The dashboard no longer opens to a black window on hosts using the Nouveau open-source NVIDIA driver or legacy AMD radeon - the GPU fallback that already handled NVIDIA proprietary now applies to all Mesa-based and VM driver paths
- Authentication survives transient network outages: a brief connection loss no longer signs you out or clears your stored session - the cached login is trusted while its signed expiry is still valid
- DNS no longer leaks or breaks across VPN/proxy connect-and-disconnect cycles: tun2socks tunnels now snapshot `/etc/resolv.conf` on connect and restore it byte-for-byte on disconnect, and switch to public DNS when the existing nameservers are loopback-only and cannot reach the internet through the tunnel
- `dns-switch` controls work end-to-end again: `flush-cache`, `dnscrypt-remove`, and `set-mode modern` paths now exit cleanly, switching pihole off no longer leaves a stale symlink to the `systemd-resolved` stub that breaks name resolution, the fresh-boot DNS leak through 9.9.9.9 / 1.1.1.1 before `dnscrypt-proxy` finishes binding is gone, and WireGuard-pushed DNS is no longer injected into `/etc/resolv.conf` while DNSCrypt or torrify is active so the round-robin fallback cannot leak queries to the VPN's nameservers
- Conky's TOR card now shows your real Tor exit IP, country flag, and the green Websites tile when you are in torrified mode (the cloud and IP fetchers previously stuck on `N/A` and `Off` because they tried to use the direct route that no longer exists; they now fall back to the local Tor SOCKS5 port automatically)
- Boot and login quality: blueman-applet no longer adds a 25-second D-Bus activation timeout on machines with no Bluetooth hardware, pre-authentication log storms during the first session are throttled, and the security score tooltip on the desktop panel now renders the recommended `routing-switch connect <protocol>` text correctly instead of showing broken-XML `<lt;protocol>gt;`

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.158 · Terminal 9.0.1.163 · Binary Pack 9.0.1.300 |
| **Version Stamp** | 9.7.4 |
| **Code Name** | Queen |
| **Release date** | 25.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.3) on 25.05.2026.

**Additions:**
- Welcome screen now shows live crypto and metals prices (BTC, ETH, XMR, NEAR, AZERO, GOLD, SILVER) with per-asset glyphs so you get a market snapshot the moment you sign in
- Saved configs panel in the External VPN Providers tab now lives in its own tab above the catalog, with bulk Delete-all and Validate-all buttons and per-row valid / warn / invalid icons, so an imported VPN profile is always one click away
- VLESS URIs pasted into the Custom provider card are now connected as native VLESS over Xray with the correct transport (`ws`, `xhttp`, `tcp`, `grpc`) and security (`tls`, `reality`) inferred from the URI, instead of being misclassified and routed through VMess
- VM and headless users can opt out of evdev session corroboration by setting `KODACHI_EVDEV_CORROBORATION=off` so the session helper does not block on missing physical input devices

**Improvements:**
- Welcome screen launch flow is smoother: the auth probe is deferred until you accept the terms, IP and market prices force-refresh on the accept transition so cold-boot stale data clears, the prefetch gauge no longer freezes after auth, and the auto-accept countdown turns itself off as soon as you are signed in
- Dashboard sidebar fonts on 1080p displays were sized up so card labels and metric values are readable without leaning into the screen
- Conky security panels: the horizontal gap between the three right-side columns (resources, security, system) is now consistent across screen widths, and small-screen overflow no longer pushes the bottom row off the desktop
- SIGNAL DECK auth detail now renders tier values (`PREMIUM`, `NORMAL`, `VIP`) in uppercase to match the rest of the panel

**Fixes:**
- Connecting RiseUp VPN no longer breaks your internet: the OpenVPN profile's pushed DNS is now honoured, dnscrypt is re-established after the route change, and the route backup is restored on disconnect even when the connection was launched through `sudo`
- Security score no longer recommends Torify on a system already routing through Tor, or full-disk encryption on a system already encrypted at install; the Kodachi torrify path that uses a dedicated nftables table on port 14000 is now correctly detected by every scoring probe
- First-launch AUTH tile on the welcome screen no longer hangs on "Checking" before you have a login session: it now shows the not-signed-in state immediately and flips to live status the moment you sign in

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.156 · Terminal 9.0.1.161 · Binary Pack 9.0.1.298 |
| **Version Stamp** | 9.7.3 |
| **Code Name** | Queen |
| **Release date** | 25.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.7.2) on 19.05.2026.

**Additions:**
- New External VPN Providers panel in the dashboard lets you browse, import, and connect to public VPN providers (VPNGate, Riseup, Mullvad, IVPN, NordVPN, AirVPN, Windscribe, Proton, Express, TorGuard, PIA, Surfshark) with per-provider credentials, latency benchmarking, and an inline credentials editor; you can also paste your own OpenVPN, WireGuard, Shadowsocks, V2Ray, Xray, Hysteria2, or Mita config to connect through the same flow used for built-in cards. Saved usernames and passwords are now encrypted at rest
- New Mobile tab on the welcome screen and the Lite and Advanced dashboards shows QR codes at phone-scannable size, share URIs, and per-protocol file exports for moving your VPN configuration onto a phone; one click bulk-exports every protocol at once
- Tor-over-VPN now layers on top of any tunnel, not just WireGuard and OpenVPN: Shadowsocks, V2Ray, Xray, Hysteria2, and Mita underlays are supported; standalone Tor without an underlay VPN is refused with clear guidance so users do not end up unprotected
- Two new local AI tiers in the Trainer Studio model picker: `xlarge` (Qwen3-8B tuned for speed, needs 8 GB RAM) and `xlarge-hq` (Qwen3-8B tuned for quality, needs 16 GB RAM); the AI Chat engine chip now shows which Qwen variant is currently loaded and lists any other downloaded variants in its tooltip

**Improvements:**
- New welcome screen with a three-tab layout (Terms, Launch, Advanced) and a Launch Readiness card showing live security score, hardening, connectivity, DNS, auth, time sync, and Tor circuit status, plus your license tier and live fleet usage (users, nodes, cards) in one place
- Every Advanced dashboard page now opens with a live summary header and groups its controls into compact cards, so the common state and primary actions are visible without expanding every collapsible
- Light theme polish across the Lite dashboard, status tiles, output panel, and page summary headers: previously faded text on light backgrounds is now legible everywhere
- Tor pool size is now chosen automatically from system RAM (3 instances on 4 GB, 5 on 8 GB, 7 on 16 GB, 10 on 32 GB, capped at 20); the welcome screen's Prepare Tor checkbox respects this default instead of always spawning 10

**Fixes:**
- Disconnecting any VPN no longer kills your internet: the disconnect path was deleting the real ISP default route alongside the VPN's, so torrify, detorrify, Mullvad disconnect, and Tor-over-VPN teardown all now clean up correctly without leaving orphan firewall or routing rules
- WireGuard tunnels are now verified by handshake before they are trusted, so a dead relay, a stale card, or blocked UDP cannot leave you on a black-hole default route with no internet
- Internet Recovery now detects TCP-blind hijacks (where ping and DNS still work but every TCP connection silently fails) and surfaces the repair step automatically; the wizard also no longer reports failure after a successful recovery
- Hardened destructive controls: panic-soft no longer stalls for minutes on the clipboard cleanup, memory-wipe and RAM-wipe stop orphaning processes that eat RAM, the home-folder wipe targets your actual home folder instead of the root user's when invoked through sudo, and the Wipe Free Space and Schedule Scans buttons on the Emergency and Hardening pages now pass the right arguments instead of silently failing
- Live ISO install works on first login again: a polkit action-ID mismatch and two shell-syntax errors in the upstream Calamares launcher were aborting every first-boot install start, so the installer now reaches its wizard without manual intervention
- NetworkManager no longer leaks your hostname over DHCP: it was accepting the DHCP-server-supplied hostname (option 12) and sending the system hostname back to DHCP servers, overriding the boot-time `kodachi` value on every connect; it is now hardcoded never to accept or send
- Quieter and faster boot and shutdown: silenced repeating Avahi, I2C, llvmpipe compositor, and GLib-GIO noise across VMs and laptops, fixed the XFCE panel double-starting at login, and a new kodachi-fast-session-stop preset makes XFCE shutdown sub-second instead of waiting on a 10-second systemd timeout
- AI services start cleanly on a freshly installed ISO: `ai-gateway list`, `search`, and `doctor` no longer error out on first launch because the embedded model registry now parses correctly
- Conky security panels render correctly on 1366 and 1920 displays: the focus-alert column now computes its width and position against the actual screen size instead of assuming a 2560-wide display, so gauges no longer overlap on smaller monitors
- Hooks logs rotate automatically: per-binary logs under the hooks directory no longer grow unbounded, capped at 2000 lines per file with 5 rotations plus a system logrotate backstop

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.156 · Terminal 9.0.1.161 · Binary Pack 9.0.1.281 |
| **Version Stamp** | 9.7.2 |
| **Code Name** | Queen |
| **Release date** | 19.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.6.3) on 17.05.2026.

**Additions:**
- New startup and cleanup row on the welcome screen: toggle on automatic Detorrify and MAC reset at boot, plus one-click recovery buttons (Disconnect VPN, Flush firewall, Stop/Restart Tor, Detorrify) so a broken session can be reset without opening each tab
- Obsidian is now pre-installed, pinned to the XFCE panel dock and Whisker favorites, and survives a full install, so the note-taking workflow persists across reboots
- Pause, Resume, and Stop on AI model downloads in the AI Chat Commander: interrupted local LLM downloads now resume from where they stopped instead of starting over, and cancel cleanly without leaving stray background downloads
- Tor instance breakdown is now visible across the Lite, Circle, Advanced, and welcome status panels: the TOR card shows the running and stopped count for the main daemon plus every load-balanced instance, with a tooltip listing each one

**Improvements:**
- System-wide security hardening pass across every binary, closing well over a hundred reviewer-flagged issues. The user-visible result is a safer and more honest system: destructive commands (panic, wipe, MAC change, Tor lifecycle) all sit behind authentication; credentials, IPs, WireGuard keys, and session tokens are redacted from log files and the debug collector; sensitive cache files are written with restrictive permissions; and command errors now propagate as non-zero exits instead of silently reporting success, so scripts and the dashboard no longer treat failure as success
- Smaller, more capable local LLM: the bundled Qwen2.5 model pair (3.1 GB) has been replaced by a single agent-tuned Qwen3.5-2B (1.22 GB), cutting the ISO and first-run download in half. The AI model picker has also been clarified, with weak and legacy tiers hidden, `GenAI` renamed to `Custom Provider`, and offline and online engines grouped with per-engine strength and privacy scores
- Discontinued Kodachi Claw, Zero Claw, and Zero Claw Desktop. Keeping the Claw fork in sync with upstream had become a maintenance burden, so it has been removed in favour of a better local-first agent (Hermes) that will replace it going forward. The core Kodachi AI service is unaffected and still ships
- Public wiki sweep: the FAQ is now fully indexable without JavaScript (every question and answer is a native expandable block), retired Kodachi Claw references have been removed, new entries explain why the first-launch Terms screen exists, and AI-looking dashes used as in-sentence punctuation have been replaced with normal punctuation

**Fixes:**
- Backend services now behave the same on a freshly installed system as on the live ISO: `routing-switch`, `health-control`, AI discovery, the Conky panel adapters, and `permission-guard` were silently failing on real installs because they only knew the development layout, and the Tor instance list mis-assigned PIDs once 10 or more instances were running. Everything resolves correctly now
- IPv6 toggle is reliable again: `ipv6-disable` no longer crashes on running systems, the disable actually stops the network from re-adding addresses underneath you, and the status no longer flaps between disabled and enabled after a teardown
- Tor controls work end to end: `torrify` then `detorrify` then reboot no longer leaves the system stuck on Tor without internet, `clear-exit-node-all` and `reload-tor-config-all` now apply to every instance (were silently broken), and the system shuts down without the roughly 90-second Tor-pool teardown wait
- Dashboard and AutoShield buttons work on real installs: Torrify, Detorrify, and Flush firewall were silently no-ops, AutoShield "Show remote timezone" was mutating the system clock instead of just reading it, the Library tab failed to load because it still referenced the retired Kodachi Claw, AI Chat / Workflow Manager / Deploy buttons all hard-errored after a confirmation-flag regression, and the Command Builder emitted wrong subcommands for many `health-control`, `dns-switch`, `deps-checker`, and `integrity-check` entries
- Dashboard status now reflects reality immediately: the TOR card reads `Off` instead of the confusing `Idle`, refreshes right after Stop/Restart and cleanup actions, and the Tor instance counter on the welcome and Lite screens no longer freezes at `0/N` when instances finish starting after the panel has loaded
- Final dashboard polish: the app no longer starts in compact mode where the loading screen was unreadable, the log viewer no longer shows times roughly two hours behind reality on local systems, AI services start cleanly instead of crashing immediately at launch, and the debug collector now redacts a broader set of credentials and URL tokens before bundling logs
- Tabby terminal is no longer missing on the live ISO. A late-stage cleanup in the build was removing `gnome-keyring` as part of an unrelated login-noise fix, and because Tabby uses `gnome-keyring` to store SSH credentials it was being collaterally uninstalled in the same step. The login-noise is now silenced a different way that does not touch the package, so Tabby ships and launches normally

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.141 · Terminal 9.0.1.146 · Binary Pack 9.0.1.251 |
| **Version Stamp** | 9.6.3 |
| **Code Name** | Queen |
| **Release date** | 17.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.5.9) on 14.05.2026.

**Additions:**
- New troubleshooting and capabilities FAQ on the wiki, reachable from the Support menu - a searchable, categorised reference (Getting Started, Installation, Editions, Network, Security, Dashboard, AI, Support) that works even with JavaScript disabled
- New outbound ping (ICMP) block/unblock control, available in the dashboard Firewall tab and the terminal Rofi menu, so you can stop your machine answering pings without hand-writing firewall rules

**Improvements:**
- Larger, more readable fonts across the whole dashboard and the AutoShield app - previously the small status tiles and metric strips were hard to read
- Circle dashboard Torrify now routes all traffic through Tor with load balancing, matching the Lite dashboard, instead of only routing DNS

**Fixes:**
- The dashboard no longer opens to a blank black window on systems using the NVIDIA proprietary driver; the fix reaches already-installed systems through the install script and applies to every way you launch it (desktop icon, app menu, panel)
- The NETWORK card no longer falsely reports "Via Tor network" when you are actually on a VPN or a direct connection
- Turning off Tor routing now reliably restores connectivity by removing the active traffic redirect first
- The security score no longer shows false positives - firewall, DNS, and IPv6 protection are now verified against the live system instead of trusting status files; the Debug Collector now removes VPN, Tor, and proxy credentials before bundling logs; and turning off Tor no longer tears down an armed kill switch
- Resetting your MAC address now stays applied instead of being silently reverted moments later
- The bundled offline documentation site now opens correctly in the browser

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.134 · Terminal 9.0.1.139 · Binary Pack 9.0.1.244 |
| **Version Stamp** | 9.5.9 |
| **Code Name** | Queen |
| **Release date** | 14.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.5.5) on 10.05.2026.

**Additions:**
- Multi-boot installation now detects Windows and other Linux systems instead of silently dropping them from the GRUB menu
- New marketing-style landing page on the wiki home with an editions row, side-by-side comparison vs Tails / Whonix / Parrot / Qubes, live download and country counters, curated tools grid, and a "Verify ISO" button on every edition card
- Quick links to the wiki added to the kodachi.cloud anonymity verifier so visitors can reach the docs without leaving the diagnostics flow

**Improvements:**
- IPv6 is now enabled by default on Standard, Hardened, Performance, and Fallback live boot entries, the dashboard IPv6 toggle is the authoritative runtime control. The kernel-level disable is kept only on Maximum Privacy, Forensics, and Full Hardening
- LibreWolf now resolves DNS through the system resolver (DNSCrypt for normal sessions, Tor DNS for oniux sessions), with DNS prefetch disabled and WebRTC routed through the proxy to prevent IP leaks
- Security score no longer penalises users on kernel-hardened boot modes for checks they physically cannot pass (tirdad), and the Top Recommendations panel no longer suggests disk encryption on a live ISO where the check is already N/A
- DNS status in the dashboard no longer reports a stale "Tor" mode across reboots when no Tor redirect rules are actually loaded
- Command Library buttons are now runnable for every offline-* health-control entry, previously some commands would error with "required arguments not provided" when clicked
- Dashboard CUPS / Printer module no longer shows a red "Risk" indicator when its score is 100%
- Kodachi Claw refreshed with 47 more upstream commits, LM Studio configurability, OpenRouter prompt caching, WebSocket disconnect handling, multimodal marker normalisation, and several provider-compatibility fixes
- Wiki landing version stamp now reads the canonical release stamp (e.g. 9.5.9) and shows the next-patch projection
- Wiki accuracy sweep across desktop, terminal, binaries, network, AI, and security pages, corrected protocol counts, hash algorithms, AI tier counts, and panic-mode tables to match what the software actually does
- Score Levels page now documents the per-check applicability matrix (Installed vs Live ISO) and the BIOS-without-EFI ceilings, so users can see exactly why a live boot tops out at ~84/100

**Fixes:**
- Fixed oniux failing to launch on the live ISO when the kernel was booted with IPv6 disabled
- Fixed `oniux-launcher` killing LibreWolf at startup with "cannot open display", and fixed the related host-IP leak where commands typed inside the oniux-launched terminal (or LibreWolf / Firefox / Thunar) silently ran on the host
- LibreWolf can now create its content sandbox cleanly inside oniux on Debian (AppArmor user-namespace rule and glxtest path corrected)
- Fixed inconsistent IPv6 status reporting between `security-status` and `ipv6-status` on systems booted with IPv6 disabled, which was producing a false-positive "Harden" recommendation
- Fixed the wiki landing Download and top-nav buttons being unreadable on hover (text and background were collapsing to the same neon colour), and the back-to-top button is now reliably visible
- Cleaned up three wiki deployment scripts and one verifier link that were pointing at the old wiki home after the landing-page swap
- Fixed the Score Levels & Color Coding table alignment on the wiki terminal page
- Cosmetic "Permission denied" stderr no longer appears during ISO builds

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.125 · Terminal 9.0.1.130 · Binary Pack 9.0.1.235 |
| **Version Stamp** | 9.5.5 |
| **Code Name** | Queen |
| **Release date** | 10.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.5.3) on 09.05.2026.

**Additions:**
- New `fix-slow-login-installed.sh` repair script for already-deployed users, diagnoses (`--check`) and idempotently installs the missing dbus package that causes the long login delay, so users on existing installs can fix themselves without rebuilding the ISO

**Improvements:**
- Welcome-screen auto-accept countdown extended from 10 seconds to 30 seconds, and clicking the "What's new" / update-details footer now pauses the countdown, reading the release notes during auto-accept no longer gets the screen closed mid-read. Existing users keep their saved preference; only fresh installs see the new default
- DNSCrypt cold-start is cleaner, removed `dnsforge.de-nofilter` from the resolver whitelist because its bundled cert hash was stale, producing a CRITICAL log line and roughly 5-6 seconds of extra probe time on every boot. Cloudflare, Google, Scaleway-FR, and Quad9 still cover the same geographies
- Kodachi Claw refreshed with the upstream v0.7.4 → v0.7.5 batch (96 commits, the largest structural overhaul to date, workspace split, schema-driven config, new approval / gateway / channel / cost APIs) ported into the Kodachi flat layout with every Kodachi-specific module byte-identical and all customisations preserved (including 62 i18n entries across 31 locales)

**Fixes:**
- Fixed the roughly 2-minute-16-second post-login XFCE delay on installed systems, the `dbus-x11` package was missing, so every dbus-activated autostart had to wait for a per-service fallback timeout before the desktop became interactive. `dbus-x11` is now bundled in the desktop ISO, and a separate repair script ships for users on existing installs
- Fixed an additional XFCE login stall caused by the `xbrlapi` Xsession hook, it has been excluded from default live images
- Fixed the hostname-rotation command breaking apps that were already running, applications like `xfce4-terminal`, ICE, and dbus look up their original hostname via the loopback alias, so previous aliases are now preserved (capped at 5 entries) whenever the hostname rotates
- Fixed the WireGuard DNS update path under the new DNSCrypt-only architecture, `wg-quick` calls `resolvconf`, which was failing because `systemd-resolved` is masked. A new resolvconf shim passes through to `resolvectl` when the daemon is healthy and falls back to editing `/etc/resolv.conf` directly via an idempotent Kodachi-WG section when it is not
- Fixed an `AT_SPI_BUS` environment-variable leak that exposed the LightDM UID socket address to user processes, both `AT_SPI_BUS_ADDRESS` and `AT_SPI_BUS` are now unset to cover both naming conventions
- Fixed the installer's help text producing nothing when the script was invoked via `curl | bash`, the previous renderer used `sed` against the script path, which becomes the literal string `bash` under that pipeline. The help text is now rendered inline so it works identically whether the script is downloaded first or piped in directly

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.122 · Terminal 9.0.1.127 · Binary Pack 9.0.1.232 |
| **Version Stamp** | 9.5.3 |
| **Code Name** | Queen |
| **Release date** | 09.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.5.2) on 08.05.2026.

**Improvements:**
- The Dashboard's HTTP client for kodachi.cloud calls (KNet status, cloud stats, release info, licence fetch) is now reused across the whole session, TLS handshake and certificate pinning are no longer redone on every poll, cutting overhead on every cloud check
- AutoShield "detorrify" and "stop Tor DNS" steps are noticeably faster, the independent iptables and nftables rule subsystems now run in parallel instead of one after the other

**Fixes:**
- Fixed Dashboard KNet panel showing ", " and Cloud Status showing 0 after Let's Encrypt rotated the kodachi.cloud certificate on 08.05.2026, certificate pinning has been extended from a single leaf-only pin to a multi-pin chain (leaf plus the Let's Encrypt E8 intermediate), so future leaf renewals no longer break the Dashboard
- Fixed AutoShield action buttons (Execute / Restart / Reset / Dashboard / launches) being clipped at the bottom of the window when multiple step result panels were expanded, the action row is now anchored at the viewport bottom with reserved bottom padding, so all buttons stay reachable regardless of how much step output is shown above

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.119 · Terminal 9.0.1.124 · Binary Pack 9.0.1.229 |
| **Version Stamp** | 9.5.2 |
| **Code Name** | Queen |
| **Release date** | 08.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.4.8) on 05.05.2026.

**Additions:**
- User-runnable hotfix script for already-installed systems that rewrites the live `xfconf` config, on-disk `xfce4-keyboard-shortcuts.xml`, and panel launchers from the old per-user Rofi path to the new system-wide one, so users on non-`kodachi` accounts can restore their Super/Alt-F1/Alt-F3 shortcuts without rebuilding the ISO
- Massively extended self-diagnostic coverage in the debug collector (v1.4 + v1.5) so post-login stalls, install-pipeline issues, and session problems can be diagnosed from the bundle alone, with no follow-up commands needed: full XFCE session/journal capture, autostart Phase summary, dbus alias state, masked-services list, install-method detection (Calamares vs Debian-installer), live `xfce4-session` strace and process-tree, complete xfconf channel dump, autostart `.desktop` inventory, user shell init dotfiles, plus previous-boot journal, boot list, `systemd-analyze plot.svg`, cgroup tree, critical chains, and ordering-cycles summary

**Improvements:**
- CPU temperature gauges in Dashboard and AutoShield no longer show absurd readings (e.g. 230 °C / 269 °C), the readers now filter sensors by chip prefix (`coretemp`, `k10temp`, `zenpower`, `cpu_thermal`) instead of any sensor name containing "temp", clamp readings to a physically plausible CPU range, and use a robust median across the headline sensors (Package id 0 / Tctl / Tdie) so a single stuck sensor can never poison the gauge
- Dashboard now auto-restarts the permission-guard daemon at launch when the user is already authenticated, closes a long-standing reboot gap where a still-valid cached session would leave the daemon stopped because the start hook only fires on explicit authentication. Includes idempotent status pre-check and diagnostic logging
- Conky panel timer no longer fires during XFCE session startup, first invocation pushed from 15 s to 240 s after login and gated on `graphical-session.target`, eliminating contention with the desktop boot path
- All four locations of the running-system Conky user-systemd files are now kept in sync (`~/.config/systemd/user`, `~/.config/kodachi/conky/systemd`, `/usr/lib/systemd/user`, `/usr/share/kodachi/conky/systemd`) so future packaging runs cannot regress the stored timer values
- Debug collector now runs commands as the real user with full graphical-session env (`XDG_RUNTIME_DIR`, `DBUS_SESSION_BUS_ADDRESS`, `DISPLAY`, `HOME`), so user-mode systemd, journal, and xfconf data is captured correctly instead of producing empty output

**Fixes:**
- Fixed a 134-second post-login stall on installed systems, `pkcs11-register` autostart was running in the Initialization phase and blocking on a 60-second `pcscd` probe; the autostart entry has been hidden, and the Conky panel timer no longer fires during the same window
- Fixed Super_L (and Alt-F1, Alt-F3, Super-r, Ctrl-Esc) launching nothing on installed systems with non-`kodachi` usernames, the keyboard shortcuts and panel launchers now point at the system-wide `/usr/local/bin/kodachi-rofi-launcher` path, with a normalisation pass added to the collect/deploy pipeline so the per-user `/home/kodachi/.local/bin/...` path can never be re-injected from a maintainer's home directory
- Fixed `systemd-resolved` resurrecting itself via dbus alias, the second install-hook block was recreating the alias right after the first hook removed it; the alias is now replaced with a `/dev/null` tombstone in all three install paths (zzz hook, zzzzz hook, post-install) and `deb-systemd-helper` state is scrubbed
- Fixed a latent regression in the Conky service fallback heredoc that would have re-introduced the original 134 s post-login stall on systems where the canonical unit file was missing, both the timer fallback (now matches the canonical 240 s first-fire, 15 s randomised delay, 1 s accuracy) and the service fallback (`Requisite=graphical-session.target` plus session-token `ConditionPathExists` gate) are aligned across installer source, overlay copies, and binary install fallback heredocs
- Fixed the Conky service fallback heredoc writing a dead body to disk, the heredoc terminator was unquoted, so the inner `bash -c` loop variable was being substituted at install time to an empty string, producing a `[ -x "" ] && exec ""` line. The terminator is now quoted so the shell only expands the variable at service runtime

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.112 · Terminal 9.0.1.117 · Binary Pack 9.0.1.222 |
| **Version Stamp** | 9.4.8 |
| **Code Name** | Queen |
| **Release date** | 05.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.4.1) on 01.05.2026.

**Additions:**
- Kodachi-branded wallpaper enforced as the default desktop background on Calamares-installed systems, no more falling back to the stock Debian 13 ceratopsian theme on first login
- Default install wallpaper switched to Guardian Athena Owl (from Ninja Breakthrough) for better Conky readability across all install paths
- New "Online (no ICMP)" connectivity state across Dashboard and Conky, SOCKS5/proxy tunnels (Hysteria2, Shadowsocks) and ICMP-filtering ISPs are no longer mislabelled as "Limited" when DNS and HTTP are working fine
- Self-healing user-group service that converges already-installed systems onto the correct group set (notably the `input` group needed by the session helper for evdev anti-spoofing)
- Self-healing IPv6 link-local flush service that clears stale `fe80::` addresses left over after IPv6 is disabled, prevents `ntpd`/`postfix` bind failures on phantom addresses
- One-shot first-boot service that re-applies Plymouth removal in a clean post-install environment, even when Calamares re-installs Plymouth via initramfs Recommends
- Per-VPS hostname display on the homepage status board, VPN nodes now show as e.g. "Kodachi 9 VPN Node 1 (vpn-nl-001)" auto-discovered from existing card files; public IPs are still never exposed
- `fast.sh` field-fix script extended with a Plymouth removal step so users can fix the Debian splash on already-installed systems without rebuilding the ISO
- LightDM `xserver-command -keeptty` so the session helper's evdev anti-spoofing can open `/dev/input/event*` without elevating privileges

**Improvements:**
- Calamares hostname pinned to `kodachi` so installed systems no longer inherit the live VM hostname (e.g. "live-ubuntu-d") used during installation
- Default credentials no longer printed on the welcome screen / desktop branding, security hardening per user feedback
- USBGuard left disabled by default on installed systems, enabling it at install time would block the physical boot USB and cause SQUASHFS read errors. Users who want USB device protection can opt in any time with `sudo systemctl enable --now usbguard usbguard-dbus` (or via the dashboard's USBGuard toggle). OpenVPN also disabled by default on installed systems to reduce attack surface.
- DNS architecture switched fully to DNSCrypt-only, `systemd-resolved` is now masked, the dbus alias removed, and `NetworkManager` re-asserts `dns=none` at priority 99 so any vendor preset that re-enables resolved is overridden
- DNS leak closed, `systemd-resolved` cleartext FallbackDNS list is now cleared via a config drop-in instead of relying solely on masking
- MAC randomization re-enabled at priority 99 so it overrides upstream NetworkManager `no-mac-addr-change` defaults
- Plymouth boot splash fully removed across both install paths, three-layer fix: removed from Calamares exec sequence (it was re-adding `quiet`/`splash` after our removal), shell-process moved to run after initramfs, and a first-boot service re-applies removal as a final safety net
- Conky panels now degrade gracefully, a single slow sub-call (security score, security verify, net-check, version) no longer wipes the entire panel to all-zero. Each section reports independently, only escalating to "Degraded" when *every* sub-call fails
- Conky internet panel adds tier classification (green/yellow/red/off) with net-check-specific cache fallback so a single net-check timeout no longer flips the panel to "Off" for two minutes
- Conky restart storm eliminated, added a 25s settle delay and bumped miss/cooldown thresholds so the panel doesn't keep restarting itself during heavy boot
- Conky stop-timeout regression fixed, non-root cgroup members are now killed promptly while root children still self-drain, avoiding "result resources" failures
- Conky correctly shows premium licence group on hardened/offline boxes by overlaying the local `license.json` (the same source the dashboard uses) when the server cache lags behind
- DNS mode reporting in Conky and Dashboard is honest now, surfaces "DNSCrypt" when `dnscrypt-proxy` is the upstream resolver, and "Tor" when system torrification is active (instead of always saying "systemd-resolved")
- Security score band 40-59 renamed from "Basic" to "Partial" across health-control, Dashboard, and wiki, more neutral wording per user feedback that "Basic" still felt negative
- ISO is no longer bloated with build-time `-dev`/development packages on installed systems, purged at install time to reduce attack surface and disk footprint
- Username portability audit complete, every runtime-functional `/home/kodachi/` reference removed (panel launchers, xfconf paths, screenshot directories, Rofi launcher, browser download default), so installs with non-`kodachi` usernames work end-to-end
- Rofi launcher (Super, Alt-F1, Alt-F3, Super-r, Ctrl-Esc) moved from `/etc/skel/.local/bin/` to `/usr/local/bin/` so the keyboard shortcuts work on installed systems with any username
- WireGuard disconnect now restores the default route *before* tearing down the interface, eliminating the no-default-route window that caused intermittent internet loss when the wg-quick teardown failed and the force-delete fallback bypassed live PostDown hooks
- Kodachi Claw synced with 23 more upstream commits (PRs #5772, #6300) including Gemini extra-content round-trip support, while keeping the Kodachi anonymity pipeline, Tor identity modes, and Postgres memory backend
- Major dependency refresh across all 23 Rust services and the desktop dashboard, codebase now tracks current upstream releases and all checks pass
- Health-check internet probes parallelised with per-probe timeouts, total check now completes in under 8 seconds instead of 20s+ under load
- IP-fetch resilience improved, provider circuit-breaker demotion (3 failures in 5 min), HTML-response early-detection, forensic logging when all providers fail, per-source 5s timeouts
- Routing-switch state file ownership normalised to the invoking user after every write so unprivileged invocations no longer fail with "permission denied" after a previous sudo run
- GRUB cmdline writes are now idempotent, applying cold-boot defence twice no longer produces duplicate parameters or embedded-quote corruption
- Initramfs/dracut updates moved to plain OS-thread workers so they cannot be cancelled mid-flight by a Tokio runtime teardown; structured completion logging added
- Auto-login no longer misses the first attempt due to DNSCrypt warm-up, added a DNS pre-gate and one delayed retry, with timer cleanup on reset
- Conky systemd unit `KillMode=none` replaced with `KillMode=mixed` (Galaxy boot fix), old setting caused process-tree leaks into the user cgroup that, on `swapoff`, blew past the panel's MemoryMax and OOM-killed live processes including online-auth's curl
- `kodachi-session-helper` sudo-readiness poll capped at 30s instead of 5 minutes so the daemon enters its event loop quickly even when overlayfs sudo ownership remains stuck
- `smartmontools` and `ntp` log noise eliminated via explicit options and IPv4-only override on IPv6-disabled systems
- `rsyslog` restored in the terminal package list so persistent `/var/log` text logs work alongside the binary journal

**Fixes:**
- Fixed 90-second boot delay on Calamares-installed systems where `/dev/mapper/cryptswap1` never materialised, the cryptswap activation chain was broken, so a new dedicated activation service now creates the mapper device directly via `cryptsetup` before `swap.target`
- Fixed crypttab-repair sometimes stripping a legitimate user-managed encrypted swap on reboot, the fstab sweep ran before `/dev/mapper/cryptswap1` existed and would mark live entries as stale; now cross-checks `/etc/crypttab` first
- Fixed crypttab-repair being skipped on follow-up boots even when fstab/crypttab were still broken, the systemd unit's "skip if marker exists" condition has been removed, with the script's own version-aware fast-path replacing it
- Fixed crypttab-repair fixing the file but the current boot still waiting 90s for the stale device, service now does a `daemon-reload` and stops stale `dev-mapper-cryptswap*` units in the same boot
- Fixed `swap-encrypt`, `swap-enable`, `swap-disable`, `swap-decrypt`, `container-mount`, `container-unmount`, `container-create`, `luks-operation`, `encryption-tune`, and `storage-wipe` all printing a "✓ ... successfully" message and exiting 0 even when the underlying operation actually failed, every command now reports the real status (success/warning/failure) and exits non-zero on real failures so monitoring scripts can detect them
- Fixed WiFi regression on Broadcom (BCM43xx) and Realtek USB hardware, the previous blacklists silently broke real users; both have been removed since the originally-targeted issues are already addressed by `ibt=off` on the kernel cmdline
- Fixed `tirdad` / `tirdad-dkms` being silently purged on Debian-installer (d-i) installs, the live-build remove-list now whitelists them so the same mechanism that protects LibreWolf/VeraCrypt also protects tirdad
- Fixed the post-install service-disable block never running on d-i installs because the script crashed at a Bash-array line under `dash`, the array has been rewritten as a POSIX-sh space-separated string, restoring CUPS/Avahi/SSH/etc. disable on every d-i install
- Fixed Pi-hole FTL service restart-looping (54 restarts in 3 hours on one bundle) because the systemd unit type was set to `notify` but `pihole-FTL v6.x` never sends a readiness signal, switched to `simple` to match upstream
- Fixed integrity-check raising false-positive ALERTs for masked systemd units (which are symlinks to `/dev/null`, not regular files), the check now recognises the masked pattern as expected state
- Fixed `dashboard` showing `BLOCKED` (kill-switch) when nftables had a baseline hardened firewall (input drop, output accept), the policy-drop check is now scoped to the `OUTPUT` chain only
- Fixed nftables policy-drop scan missing the actual armed kill-switch state because `nft list ruleset` emits `type` and `policy` on the same line, the parser now handles the canonical format
- Fixed `health-control` reporting masked systemd units, ethtool speed on WLAN interfaces, swap-decrypt INFO-instead-of-ERROR, logind restart missing, and tainted-kernel false-positives in the rootkit hidden-process scan (M1, M2, M3, M5, M8 from the latest audit)
- Fixed `swap-encrypt` failing on systems with idle swapfiles by activating them in the early-return path and adding post-`swapon` verification with a `dd` fallback
- Fixed swap-decrypt spurious "decryption failed" exit codes on systems with only encrypted swap, now distinguishes decrypt completion from swap-active state
- Fixed IPv6 disable leaving global addresses behind, `health-control` now flushes both link-local and global addresses on disable
- Fixed rootkit hidden-process scanner false-positives on Tiger Lake / Broadcom-wl systems where 3 sequential PIDs would briefly show as suspicious, added a kernel-taint guard and race-tolerant double-pass
- Fixed `ip-fetch` reporting "all providers failed" on transient hiccups, providers now demote on a circuit-breaker pattern instead of being declared dead permanently
- Fixed debug-collector flagging exit-0-empty-output as a command failure and reporting "✗ NOT FOUND" for AI binaries that don't ship in v9.0.1, required vs optional binaries are now properly split
- Fixed the live ISO's xfce wallpaper still showing Ninja Breakthrough on installed systems because three stale config XML mirrors hadn't been updated, all four sources now consistently point at Guardian Athena Owl
- Fixed `sudo.conf` ending up owned by uid 65534 on first boot (a race where the heavy hooks-tree chown was killed by cgroup teardown before the sudo re-fix ran), sudo/sudoers re-chown now runs synchronously before the unit completes
- Fixed conky-snapshot-refresh systemd unit using a deprecated `KillMode` value that triggered `systemd-analyze verify` warnings, replaced with `KillMode=mixed`
- Fixed the kodachi-cryptswap-activate service overlay drifting from the corrected `fast.sh` v2 contents (stale `cryptdisks_start` condition), would have silently skipped on minimal installs and reintroduced the 90s boot hang

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.97 · Terminal 9.0.1.102 · Binary Pack 9.0.1.207 |
| **Version Stamp** | 9.4.1 |
| **Code Name** | Queen |
| **Release date** | 01.05.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.2.6) on 12.04.2026.

**Additions:**
- "Kodachi Live (IPv6 enabled)" boot menu entry under Advanced, for users who specifically need IPv6 without rebuilding the ISO
- Default USBGuard rule set shipped (allow keyboards/mice/audio/webcams, block mass-storage), applies the moment a user opts into USBGuard via `sudo systemctl enable --now usbguard usbguard-dbus` or the dashboard toggle. The service itself stays disabled by default on installed systems so it does not block the physical boot USB.
- Dedicated AppArmor sandbox profile for LibreWolf, confines the browser at boot instead of running unconfined
- Baseline audit logging rules shipped with the system for security event tracking
- Pause/resume button on the welcome-screen auto-accept countdown so users can hold the timer while reviewing settings
- Expand/paginate toggle in the Terms screen so all terms render by default with optional 5-per-page pagination on smaller screens
- Adaptive security score across Dashboard, AutoShield, and the wiki, checks that don't apply (live-ISO, no EFI, no swap, etc.) are excluded from the maximum so reasonable users are no longer labelled "Poor", and partial-Tor users now get partial credit
- IPv4-only and IPv6 path overrides in the homepage status checker so legitimate IPv6-only routes can be probed correctly
- New "Online Tools" and adaptive scoring documentation aligned with the actual scoring categories on the wiki
- Privacy-respecting LightDM greeter defaults (solid background, dark theme, no user images shown on login)

**Improvements:**
- Boot time on installed systems significantly reduced, switched ISO compression from xz to zstd, trimmed compile-only packages, batched systemctl calls, pre-generated console-setup, pinned AppArmor cache, and skipped slow virtual-CD probes (multiple minutes saved cumulatively)
- Boot-time chown on overlay filesystems optimized, saves about 1m34s on Live ISO startup
- DNSCrypt startup hardened, pinned servers, added fallback resolvers for first-try UDP bootstrap, removed unencrypted fallback DNS, scrubbed problematic resolvers (was probing 227 servers for 115s and cascading failures into Tor and online-auth)
- IPv6 link-local leak closed, IPv6 is now hard-disabled at boot via kernel cmdline so no `fe80::` address is ever assigned, with a separate boot menu entry for users who need it
- NetworkManager no longer competes with Kodachi DNS, DHCP-supplied DNS is fully ignored to stop leaks into systemd-resolved
- Welcome-screen first-run experience accelerated, network and offline lookups now run in parallel, and cloud stats are deferred until after the screen is interactive
- StatusInfoPanel redesigned with a card-based layout so the MAC address shows in full and all fonts meet the readability minimum; the wizard call-to-action button has stronger contrast against the background
- Conky panels now mirror the Dashboard's connectivity logic, Hysteria2, WireGuard, and Tor paths no longer flip Conky to "Off" when the connection is actually fine
- Conky cold-cache poisoning fixed, first-boot timeouts are now long enough for HTTPS handshakes over slow proxies and Hysteria2, so the auth panel no longer gets stuck on "Off"
- Conky always shows the effective public IP after a VPN switch, invalidates the IP cache on tunnel up/down events instead of displaying the pre-VPN ISP IP
- Routing anonymization checks no longer report a false "CRITICAL ANONYMIZATION FAILURE" during transient tunnel hiccups, added a 3-attempt retry with backoff before declaring failure
- online-auth heartbeat no longer reports a false "service not running" error on heavily loaded systems, replaced the fixed wait with progressive PID polling
- Tor circuit verification before every torrify command, prevents torrification with no working circuits and includes auto-healing recovery
- Default torrification upgraded to 2-step load-balanced round-robin across Dashboard, tray, Rofi, and quick actions for better anonymity and performance
- Kodachi Claw refreshed with 200+ upstream commits (cron scheduler, provider config, canvas security, skill gating, UF2/Pico flash support) while keeping the Kodachi anonymity pipeline, Tor identity modes, and integrated memory backend
- Build pipeline now automatically deploys freshly-signed binaries onto the system PATH after every successful build, eliminates the recurring "code shipped but the running system did not pick it up" problem
- Logging noise across the system reduced, Conky panel invocations, online-auth retries, NetworkManager dispatcher events, IPv6 sysctl on disabled stacks, and benign socket disconnects are no longer flooding the central log
- VPS hardening, CSF firewall now whitelists both `kodachi.cloud` and `digi77.com` automatically, the auth-burst port flood limit was relaxed so legitimate logins are not silently dropped, and cloud-stats now caches outage probes to stop thundering-herd checks
- Wiki and homepage stamp card now read the same shared release-policy fields as the build automation, so the version explanation, countdowns, and stamp number stay in sync everywhere

**Fixes:**
- Fixed dashboard showing contradictory swap-encryption status (one panel "Active 100%", another "No"), both panels now confirm the encrypted swap device is actually mounted before reporting "encrypted"
- Fixed `ipv6-enable` being a silent no-op after install, the toggle now also clears static blacklist entries and warns when IPv6 is disabled at the kernel level, with a clear hint pointing to the new GRUB entry
- Fixed Pi-hole logging "Cannot parse config file" errors 30+ times per session caused by duplicate port entries in `pihole.toml`
- Fixed Conky panel showing the old ISP IP after switching to VPN/Hysteria2, IP cache is now invalidated on tunnel events
- Fixed up to 90-second boot stall on Calamares-installed systems caused by broken `/swapfile` cryptswap entries, installer now detects and disables them
- Fixed up to 1m30s boot delay on systems where fstab still had a stale encrypted-swap entry but crypttab was empty
- Fixed Surface tablet boot logs spamming "Failed to find module" on every boot for all hardware, those modules ship only in the linux-surface kernel tree, not the stock Debian kernel
- Fixed PAM error spam from `gnome-keyring` and `ecryptfs` on installed systems, both unused PAM modules are now properly removed during install (Kodachi uses LUKS, not ecryptfs)
- Fixed Tor logging "Cannot parse config file line 7" runtime spam from three internal call sites that were missed in the previous fix
- Fixed `crypttab-repair` running on every single boot even after a successful repair, version-stamped marker now correctly satisfies the early-return check
- Fixed homepage showing `digi77.com` as offline when monitored from the VPS, root cause was the remote firewall blocking the VPS IP, restored once the firewall whitelist was applied
- Fixed retry-storm error spam in health-control when the timezone API is briefly unreachable, added a 5-minute cooldown between retries
- Fixed security-score color in the dashboard incorrectly showing orange/warning for live-ISO users with otherwise-perfect scores, color now compares against the adaptive maximum
- Fixed Tor "iptables not enforced" check being unreachable when the Tor daemon was off, hiding a real configuration gap
- Fixed conky-watchdog accidentally taking down the XFCE panel, Conky is now signaled gracefully when the X server is alive instead of being force-killed
- Fixed conky-status reporting "degraded" on every refresh because of an unrelated Tor SOCKS port check (Kodachi uses port range 10000-10009, not the default 9050)
- Fixed Conky logs flooding with INFO-level "starting" lines from the 5 panels invoking the binary every few seconds
- Fixed kernel-warning spam in the system journal, IPv6 sysctl directives are now silently no-op when IPv6 is disabled at the kernel level, and obsolete NetworkManager keys were removed
- Fixed the build pipeline re-downloading large GitHub-hosted assets (Tabby, ~122MB) every single build because of a CDN HEAD-request quirk, cache check is now resilient
- Fixed firewall-DROP messages flooding the console after login, kernel printk level adjusted
- Fixed wiki Desktop Debian page still claiming the old 5-category, 3-color score split, updated to match the new 7-category, 5-tier adaptive band system
- Fixed assorted welcome-screen polish issues: button contrast, mode-card readability at low resolutions, footer overlap, and stray diagnostic console output
- Fixed numerous TypeScript type-safety gaps and removed unused dashboard components per a verified GUI audit (45 confirmed findings, 0 outstanding)
- Fixed silent failure paths in the dashboard backend so settings rollback failures, config nuke failures, and other errors are now surfaced to the user instead of being swallowed

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.67 · Terminal 9.0.1.72 · Binary Pack 9.0.1.177 |
| **Version Stamp** | 9.2.6 |
| **Code Name** | Queen |
| **Release date** | 12.04.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.2.1) on 08.04.2026.

**Additions:**
- Mission Center system monitor AppImage bundled in ISO build pipeline with GitLab API helpers, local install, and FUSE2 dependency
- Bluetooth GUI (blueman) and WiFi scanner (linssid) for rogue/evil-twin AP detection added to ISO packages
- Internet Recovery Wizard launched via "Fix Now" on welcome screen and connectivity banner, replaces auto-recovery with guided troubleshooting
- Network health check probe interval made user-configurable in Settings (30s to 30m, default 60s)
- `--http-only` flag added to `net-check` for HTTP-probe-only connectivity checks; mutually exclusive with `--ip-only` and `--domain-only`
- Chart.js bar and doughnut visualizations on the wiki changelog page for at-a-glance release distribution insights
- APT pin permanently blocking PulseAudio daemon re-installation via blueman/pavucontrol Recommends, protects PipeWire audio stack

**Improvements:**
- 4-state connectivity model (full/tor/limited/offline) adopted across Dashboard, AutoShield, Lite mode, Circle layout, and all status bars, replaces binary online/offline check
- DNSCrypt cache false-positive detection in net-check, direct upstream DNS bypass via 1.1.1.1/9.9.9.9/8.8.8.8, random subdomain cache-busting, HTTP reachability probe, and TCP connect fallback for ICMP-blocked networks
- Tiered net-check strategy: DNS-only heartbeat between full probes cuts polling cost ~5x while keeping tooltip hydrated; heartbeat failure escalates to immediate full probe for accurate diagnosis
- Connectivity banner shows on every online→offline transition (not just the first), auto-hides with 30s visible countdown, and re-appears on subsequent incidents
- Auth polling gated on connectivity, preserves previous auth state across limited/offline transitions and re-checks when connectivity returns; prevents false "Logged Out" display when DNS is broken
- Network timing display upgraded: HTTP probe and IP ping timings shown in tooltip and speed bar instead of DNSCrypt-cached 1ms placeholders
- Connectivity settings UX: three confusing "Internet Health Check" rows renamed to plain-English labels with rewritten tooltips; full-probe interval derived dynamically from heartbeat cadence
- IP display: "IP Offline" replaced with "N/A" so limited/offline state reads as unknown value; duplicate country label suppressed when both IP and country are unavailable
- Conky IP display overhaul: effective IP always shows what ip-fetch returns (what the network sees) instead of duplicating Tor IP; stale ISP IP fallback fixed when torrified; `--refresh-cache` always passed to bypass 48h TTL
- Conky adapter timeout bumped from 7s to 12s and cache TTL from 20s to 30s in lockstep to prevent premature timeouts on slow links
- `kodachi-debug-collector.sh` included in binary pack tar.gz alongside install scripts
- Kodachi Claw merged 34 upstream ZeroClaw commits (Props subcommand, credential refactor) while preserving Kodachi integrations
- Privacy: target IPs/domains hidden from `net-check --http` plain output, details re-gated behind `--verbose` for troubleshooting
- AutoShield ported dashboard tor-aware speed determination method so both surfaces render identical connectivity labels and speed bars

**Fixes:**
- Fixed DNSCrypt cache fooling net-check into reporting false "Online", plausibility check on sub-5ms DNS responses, HTTP probe lifts dns_bypass_verified back to true when upstream is reachable
- Fixed `tor@default.service` failing on fresh Calamares installs, tmpfiles.d rule for 4 Tor runtime dirs, ownership repair helper in kodachi-finish-install, and one-shot migration service for existing broken systems (FIX-5)
- Fixed `dnscrypt-proxy.service` not starting on LUKS installed systems, NM dispatcher starts the service on network up and connectivity-change events (FIX-9)
- Fixed Hysteria2 kill-switch silent failure, post-kill /proc PID verification loop (5x200ms poll), pkill -9 fallback with exact name match, post-kill IP re-verification, and emergency-trigger as last resort (FIX-4)
- Fixed `dns-database-failed.json` growing unbounded, capped at 5,000 entries using LRU eviction on last_check_time with one-time migration and .bak backup (FIX-3)
- Fixed online-auth heartbeat ERROR spam on endpoint failures, non-2xx responses routed to WARN (4xx) and INFO (5xx/network) by HTTP status code; outer post-retry summary downgraded from ERROR to WARN (FIX-2)
- Fixed online-info-switch log spam on kodachi.cloud transient outages, HTTP severity routing with WARN for cloud-specific commands, ERROR preserved for genuine client failures (FIX-8)
- Fixed AAAA resolver warnings (305/hour) on IPv4-only VMs, cached `is_ipv6_enabled()` helper, A-only DNS lookup when IPv6 disabled, applied to both check_domain_native and check_domain_with_http paths (FIX-10)
- Fixed verify-tor-dns probe spam when Tor is intentionally off, early return with `skipped_tor_inactive` status gated on instance-aware tor service state (FIX-11)
- Fixed tor-switch config parse errors showing no file path, error context applied to runtime embedded_config.rs path so users see the exact file on key-exists/parse errors (FIX-6)
- Fixed Conky USBGuard/USBKill/AutoLogin status reading wrong JSON fields from health-control usb-status output
- Fixed Conky missing country flag when torrified, geo lookup on Tor exit IP and flag read from snapshot instead of ip-fetch tor
- Fixed Conky Ubuntu false-positive cache-clear loop caused by /proc tor-name scan, replaced heuristic with SOCKS5 port probe
- Fixed conky-status adapter JSON parse failures, replaced `serde_json::from_str` with `StreamDeserializer` for trailing whitespace tolerance; debug-level raw stdout capture on parse failure
- Fixed an infinite update loop in the connectivity store, replaced a no-op store update with a read-then-set pattern for object equality
- Fixed false Offline banner from IPC timeout/error, preserve previous state instead of fabricating all-FAIL probe signals; honor user-configured timeout with headroom
- Fixed connectivity banner 30s auto-dismiss poisoning dismissed flag for entire session, replaced with non-sticky autoHide gated on periodic check
- Fixed routing-switch status showing "Protocol: unknown" after Hysteria2 connect, added hysteria2/hy2/mieru to all state detection match statements with port-range fallback
- Fixed `cryptswap1` boot hang on fresh Calamares installs, sanitize helper comments out stale crypttab/fstab entries with ConditionFileNotEmpty guard and migration service (FIX-1)
- Fixed dashboard refreshAll watchdog and finally-clear so the refresh spinner can never stay stuck; re-entrancy guard on auto-refresh setInterval prevents slow runs from stacking
- Fixed net-check status_name casing inconsistency and bogus `http_response_time_ms=0.0` placeholder leaking into JSON output
- Fixed hickory-resolver 0.25.2 API change, `ResolveErrorKind` moved from proto module to crate root
- Fixed AutoShield net-check using deprecated `--domain-only` flag, switched to `--timeout 5` for consistent behavior

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.58 · Terminal 9.0.1.63 · Binary Pack 9.0.1.168 |
| **Version Stamp** | 9.2.1 |
| **Code Name** | Queen |
| **Release date** | 08.04.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.1.6) on 02.04.2026.

**Additions:**
- File integrity verification tool on the wiki, client-side SHA-256 and BLAKE3 hashing, RSA signature verification, speed indicator with ETA, and multi-file drag-and-drop support
- Debug log collector script (`kodachi-debug-collector.sh`) for remote troubleshooting, interactive category selection, privacy-hardened hardware collection (IPs, MACs, passwords, serials redacted), and curl-pipe safe
- Realtek RTL88xxAU and RTL8814AU USB WiFi DKMS drivers added to ISO for out-of-box adapter support
- Live GPU monitoring gauges (NVIDIA, AMD, Intel) in Dashboard and AutoShield with graceful fallback when no telemetry available
- Prepare Tor startup toggle on the welcome screen, pre-warms Tor instances at boot (fire-and-forget, non-blocking) for faster torrification
- Tor circuit verification before all torrify commands, auto-healing sequence (NEWNYM, restart, ABORT) prevents torrifying with no working circuits
- Default torrify upgraded from single-instance to 2-step load-balanced round-robin across all UI surfaces (Dashboard, tray, Rofi, quick actions) for improved anonymity and performance
- Online Tools section added to the Dashboard About page
- Auto-computed statistics dashboard on the wiki changelog page (project age, release count, cadence, fixes, features)

**Improvements:**
- Boot time reduced ~50s by replacing expensive find-exec chown with direct chown on known paths
- DNSCrypt startup probe cut from 40s to 10s by lowering ping retries, timeout, and netprobe_timeout
- GRUB theme service moved off critical boot path, skips on live ISO, deferred on installed systems
- Conky snapshot refresh delayed to 60s post-login, reduced frequency to 3-minute intervals, and lowered memory limits
- PulseAudio replaced with PipeWire audio stack, fixes audio service race condition in XFCE variant
- ip-fetch SOCKS5 error spam reduced ~96% via port pre-check before URL iteration loops
- conky-status performance overhaul, replaced ~200 subprocess spawns with single /proc scan, batched systemctl calls, async helpers, and concurrent firewall checks
- Kodachi Claw merged 65+ upstream ZeroClaw commits (cron scheduler fix, provider config, canvas security, skill gating, UF2/Pico flash support)
- Default wallpaper changed from ninja_breakthrough to guardian_athena_owl for better Conky readability
- GRUB modifications made transactional with per-run backups, structural validation, and auto-rollback to prevent boot bricking on LUKS systems
- Welcome screen: countdown banner and controls moved above privacy toggles for low-resolution screens; scrollable layout for 768p displays; MAC randomization default unchecked
- Routing wizard descriptions enriched with 37 practical tips across 11 sections from Issues 1-20 and G1-G17
- Torrification verification instructions in wizard and help content clarified per user feedback
- RAID kernel modules changed from hard-block to soft-block (blacklist) for compatibility with installed mdadm
- Build ISO script improved with preflight mount cleanup and Session Desktop JSON parsing fix
- Wiki boot sequence references updated from AutoShield to Kodachi Dashboard; login credentials box added before USB creation section
- sudo readiness retry extended from 5s single attempt to 90s (3 retries then 15 incremental) to survive background chown race on live ISO overlayfs
- Kernel module blacklist expanded to reduce attack surface on desktop (RAID, unused network modules)

**Fixes:**
- Fixed sudo ownership corruption on overlay filesystems, boot-time oneshot service repairs squashfs UID remapping breakage
- Fixed 3-minute boot delay from stale cryptswap1 entries referencing non-existent swap files
- Fixed DNSCrypt gap on installed systems, auto-activates resolver when running but not configured at boot
- Fixed DNS resolv.conf race with NetworkManager dispatcher, resilient retries and symlink management
- Fixed vnStat boot stall from future-dated state files, sanitize script runs before vnstat service starts
- Fixed SATA power-management timeouts from TLP AC configuration on laptops
- Fixed nftables firewall INPUT-DROP messages flooding console after login, kernel.printk suppresses KERN_WARNING and below
- Fixed GRUB theme service ordering cycle caused by graphical.target dependency, changed to local-fs.target
- Fixed nf_conntrack_helper sysctl warning on kernel 6.0+ with dash prefix
- Fixed kodachi-ai SIGILL crash on older CPUs without AVX2, feature gate added at startup for all 8 sub-binaries
- Fixed conky-status JSON parse failures from stale PID output leaking to stdout before JSON envelope
- Fixed routing wizard launch targets always showing unavailable, added test and which to system command whitelist
- Fixed desktop file resolution in app-verification so panel launcher desktop files correctly resolve via underlying command
- Fixed Session Desktop download URL parsing in build-iso.sh for both minified and pretty-printed JSON responses
- Fixed installed user sudo access and shadow file integrity via post-install cleanup scripts

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.48 · Terminal 9.0.1.53 · Binary Pack 9.0.1.158 |
| **Version Stamp** | 9.1.6 |
| **Code Name** | Queen |
| **Release date** | 02.04.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.1.1) on 30.03.2026.

**Additions:**
- Portmaster firewall service controls and GUI launcher added to the Dashboard firewall panel alongside UFW
- RAR archive support restored (unrar + 7zip-rar), was dropped during the Debian 13 Trixie migration
- NVIDIA GPU fallback boot mode hardened to prevent LightDM/X11 restart loops on unsupported hardware
- Four new wallpapers designed for better Conky panel readability and contrast

**Improvements:**
- All dependencies updated, including the Rust toolchain and the full dashboard build chain
- Kodachi Claw merged upstream ZeroClaw v0.6.8 with security policy and gateway improvements
- Boot performance optimized for standard and medium tiers, removed redundant init_on_free=1 memory zeroing that provided minimal security benefit at a measurable performance cost
- Conky VPN status now displays "On" instead of "Up" for consistency with other service indicators
- Firewall panel redesigned, separate UFW and Portmaster controls with independent boot persistence toggles
- UFW boot persistence decoupled from runtime state, enabling at boot no longer requires the firewall to be currently active

**Fixes:**
- Fixed DNSCrypt service not detected when stopped, dns-switch now auto-restarts the service during DNS operations instead of silently failing
- Fixed stale DNS lock files preventing concurrent DNS switches, lock detection now checks PID liveness
- Fixed UFW firewall not visible in Dashboard after disk installation, detection changed from --help probe to status check
- Fixed GUI apps (gufw, all pkexec-based tools) crashing on installed systems, root now has X11 display access via Xsession hook
- Fixed Dashboard segfault in virtual machines caused by AT-SPI2 accessibility bridge bug in libatk-bridge >= 2.59
- Fixed Portmaster being falsely detected on systems where it is not installed, now uses systemd LoadState probe
- Fixed Kodachi Claw icon rendering after the icon library removed brand icons (Github, Linkedin)

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.38 · Terminal 9.0.1.43 · Binary Pack 9.0.1.148 |
| **Version Stamp** | 9.1.1 |
| **Code Name** | Queen |
| **Release date** | 30.03.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.0.9) on 25.03.2026.

**Additions:**
- Startup privacy toggles on the welcome screen, configure MAC randomization, hostname randomization, timezone randomization, and DNSCrypt before entering the Dashboard, with a "Remember My Choice" option and auto-dismiss countdown
- DNSCrypt is now the default DNS resolver on boot, encrypted DNS out of the box with plain DNS failovers for resilient connectivity
- Sync System Time recovery action, 7-method NTP cascade available in the Internet Recovery Wizard, Lite panel Fast Access dropdown, and Rofi menu to fix TLS certificate errors from clock drift
- Medium security hardening profile, new tier between Standard and Paranoid for balanced security without the performance overhead of full paranoid mode
- Entropy hardening on boot, jitterentropy-rngd provides stronger cryptographic randomness, with kernel module blacklist reducing attack surface
- Kodachi Claw upstream merge, merged 136 commits from ZeroClaw v0.6.3 including new providers, skills, and memory improvements while preserving the Kodachi anonymity layer

**Improvements:**
- GRUB boot menu reordered from lightest to heaviest, standard boot loads faster as the default entry
- GRUB and ISOLINUX security parameters hardened, added debugfs=off, vsyscall=none, EFI DMA protection, randomize_kstack_offset, and improved AppArmor integration across all boot modes
- Security hardening scoring is now consistent, Standard shows 5/7, Medium 6/7, Paranoid 7/7 with a fixed denominator so progress is easier to understand
- Kloak keystroke anonymizer now managed exclusively through systemd, eliminates double-start bugs and hangs
- DNSCrypt boot reliability improved, fixed race conditions, pre-seeded server lists for offline boot, and resolved double privilege-drop crash
- Welcome screen now uses paginated terms view, accept checkbox is reachable on 768p displays and all resolutions
- GNUnet disabled at boot to prevent CPU spikes, users can start it manually when needed
- Connectivity banner auto-hides when internet is restored instead of staying visible after recovery
- Dashboard window is now properly resizable and maximizable after exiting the welcome screen
- Dependency installer retry logic improved with resume support, longer timeout, and wget fallback for slow connections
- VPS WireGuard peer lifecycle management, automatic cleanup of stale peers and worker-to-master card synchronization
- VPS network tuning, upgraded sysctl buffers to 256 MB, switched to BBR congestion control, and fixed CSF firewall throttling VPN connections

**Fixes:**
- Fixed DNSCrypt boot hang caused by a systemd race condition where the proxy started before the network was ready
- Fixed DNSCrypt crash from double privilege drop, systemd and config file both tried to switch user, causing a fatal error
- Fixed session helper crash on live ISO VMs from a read-only XDG_RUNTIME_DIR, added writability checks, environment variables, and X11 readiness wait
- Fixed security hardening modules not gated to correct profiles, process isolation, memory protection, kernel hardening, and monitoring now activate only at their intended security tier
- Fixed Conky snapshot refresh service being killed on slow VMs due to a short timeout
- Fixed Dashboard crash when launching GUI binaries through global-launcher, now uses exec instead of spawn with timeout
- Fixed Dashboard event listener accumulation on close that could cause memory leaks
- Fixed VPS card sync race conditions and consumed-card cleanup across multiple worker nodes

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.33 · Terminal 9.0.1.38 · Binary Pack 9.0.1.143 |
| **Version Stamp** | 9.0.8 |
| **Code Name** | Queen |
| **Release date** | 25.03.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.0.8) on 23.03.2026.

**Additions:**
- Kodachi Claw upstream sync, merged 83 commits from ZeroClaw upstream including SearXNG search provider, while preserving the Kodachi anonymity layer
- zeroclaw-desktop binary registered across the full build pipeline (signing, installer, livebuild overlays, deps-checker, and wiki documentation)
- Eight missing Kodachi Claw subcommands added to structured help output (estop, self-test, completions, desktop, memory, config, update, sop)

**Improvements:**
- Kodachi Claw branding restored across all user-visible strings, config paths, service names, and CLI output
- Conky snapshot refresh service now has memory limits to prevent OOM kills on live boot
- WireGuard status checks no longer require interactive sudo, added NOPASSWD entries for conky-status and mail alerts
- LUKS warning in Dashboard and AutoShield now uses a themed confirmation modal instead of the browser-native dialog

**Fixes:**
- Fixed Conky watchdog restart loop after security hardening, the panel count pattern did not match runtime config paths, causing infinite kill-restart cycles
- Fixed security hardening causing issues on LUKS-encrypted systems, hardening kernel parameters (init_on_alloc/init_on_free) combined with LUKS I/O overhead caused OOM kills and browser crashes; added memory pressure mitigation and recovery command
- Fixed 46 compilation errors in Kodachi Claw after upstream merge (duplicate enums, pattern matching, async/sync mismatches)
- Fixed zeroclaw-desktop build failure caused by a package name mismatch in Cargo.toml
- Fixed upstream sync script false-positive BEHIND detection for zeroclaw-desktop
- Fixed GNUnet config parse errors caused by a duplicate [arm] section logging errors every 5 minutes
- Fixed health-control PIE detection false positives for setuid binaries with modern binutils readelf output
- Fixed confusing hardening play buttons in AutoShield, replaced identical paranoid button with labeled dropdown to prevent accidental paranoid profile execution

**Documentation:**
- .onion access guide added to the desktop wiki with FoxyProxy configuration for single and load-balanced torrification modes
- Dashboard UI paths (AutoShield, Essentials, Advanced) added alongside CLI commands in the .onion access guide

---

### Version 9.0.1 - Desktop & Binaries Build Update

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.31 · Terminal 9.0.1.36 · Binary Pack 9.0.1.141 |
| **Version Stamp** | 9.0.8 |
| **Code Name** | Queen |
| **Release date** | 23.03.2026 |
| **Status** | Stable |

All changes below were made after the previous build update (stamp 9.0.5) on 12.03.2026.

**Additions:**
- Internet Recovery Wizard, floating step-by-step network fix panel with drag-and-drop step reordering, pre-fix diagnostics, and multiple launch points (welcome screen, connectivity banner, Net Control button)
- Onboarding Setup Guide, guided first-run wizard that walks new users through privacy preferences, routing mode, and security tier selection with personalized recommendations
- Routing Guide, interactive explainer built into the Dashboard that helps users understand and choose between VPN, Tor, and combined routing modes with profile comparison
- VPNGate free VPN integration, browse, filter, sort, connect, and export VPNGate servers directly from the Dashboard with dedicated Protocols and VPNGate tabs
- Conky privacy masking, three new commands to hide sensitive data on Conky desktop panels for safe screenshots and screen sharing
- DNS cache flush command added to the Dashboard and recovery wizard
- Internet health check on the welcome screen with configurable startup check, periodic timer, and auto-fix settings
- Separate Wizard and AutoShield buttons on the welcome screen so users can re-run the setup assistant independently
- Setup Guide can be replayed anytime from the Help menu or Settings reset section
- Browser bookmarks overhauled, 76 new entries added across security testing, cryptocurrency, AI tools, file sharing, short URL services, and pastebin services
- MAC address and timezone info now shown in the Fastfetch terminal display
- Connection tracking support added for smoother Tor traffic handling
- Added rsyslog for improved crash diagnostics and system log collection
- Auto-login toggle on the welcome screen and settings page for quick session setup
- Full startup service management, all services can now be enabled or disabled at boot, including previously locked critical services
- UFW firewall boot toggle, enable or disable the firewall at boot directly from the Firewall panel

**Improvements:**
- VPN and Tor connections are noticeably faster, reduced connection setup time with smarter caching and port detection
- Boot is faster, fixed a 38-second LightDM delay caused by recursive file ownership checks on overlay filesystem
- AutoShield stop button now runs detorrify immediately, no extra steps needed to restore direct routing
- Conky scripts no longer require sudo, improved security by removing all privilege escalation from desktop panels
- Conky uses significantly less memory on live boot, added memory limits and staggered panel startup to prevent crashes on low-RAM systems
- Conky data collection spawns 350+ fewer processes per refresh cycle by reading cached data directly instead of launching binaries
- Dashboard window opens at the correct size on first launch, no more clipped buttons or missing action bar
- Persistence and encrypted persistence now work correctly on installed systems following the Debian live-boot standard
- Certificate pinning hardened across all backend services for stronger protection against man-in-the-middle attacks
- Security hardening checks are now profile-aware, standard mode no longer flags expected system settings as problems
- DNS configuration handles symlinks properly, prevents DNS breakage on systems using systemd-resolved
- VPNGate works with OpenVPN 2.7 without breaking the standard Kodachi OpenVPN connection flow
- Qt applications now match the system dark theme on the Desktop edition via qt5ct and qt6ct integration

**Fixes:**
- Fixed Conky panels saving positions from a different machine, each system now generates its own layout
- Fixed Conky data refresh blocking, panels no longer freeze while waiting for backend updates
- Fixed DNS verification hanging indefinitely, now times out after 5 seconds instead of blocking the system
- Fixed wallpaper display showing zoomed instead of centered on real hardware
- Fixed background processes not being cleaned up after timeout, timed-out tasks are now properly terminated
- Fixed workflow conditions failing on certain filter patterns in automation profiles
- Fixed Tor load-balancing mode not detecting all active Tor instances correctly
- Fixed dropdown menus showing gray system-native popups instead of dark-themed menus
- Fixed light theme issues on the welcome screen, mode cards, text colors, and loading screen now render correctly
- Fixed welcome screen having visible side gaps on some resolutions
- Fixed DNSCrypt-proxy failing to start on live boots due to a missing system user

**Documentation:**
- Dashboard and AutoShield tips sections rewritten with scenario-based workflows and card layouts
- Routing Guide documentation added to the wiki explaining all privacy routing options
- VPNGate and network recovery features documented on the desktop wiki page
- Boot mode requirements for hardened modes documented across wiki pages
- Desktop wiki install guide updated with the correct ISO filename

---

### Version 9.0.1 - Desktop Stable Release

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Nightly Builds** | Desktop 9.0.1.26 · Terminal 9.0.1.31 · Binary Pack 9.0.1.136 |
| **Version Stamp** | 9.0.5 |
| **Code Name** | Queen |
| **Release date** | 12.03.2026 |
| **Status** | Stable |

All changes below were made after the Desktop beta release on 26.02.2026.

**Additions:**
- Emergency keyboard shortcuts, assign global hotkeys (e.g., Ctrl+Alt+Shift+F12) to trigger panic modes, internet kill, or data wipe instantly from anywhere on the desktop
- Rofi application launcher with themed menus for apps, power controls, screenshots, volume, brightness, and quick links
- Fastfetch branded terminal display with custom Kodachi tiger logo and system information
- Password generator and copy-to-clipboard buttons on all password fields in the Dashboard
- Display and power controls added to the Dashboard, manage screensaver, screen lock, suspend, logout, and Conky panels from one place
- Update notification system now shows detailed per-edition version tracking (Desktop, Terminal, Binary Pack) with clickable update details
- Output panel now shows the actual backend commands being executed for full transparency
- HiDPI auto-scaling for live sessions on high-resolution displays
- Offline wiki documentation bundled with the system as downloadable PDF books
- Domain checker, IP report, and DNS diagnostic tools added to the web platform
- Thunar right-click "Open as Root" and "Edit as Root" actions now work on installed systems without requiring full sudo access

**Improvements:**
- Conky desktop panels use significantly less CPU, reduced from 2.7% down to under 1.5%
- Live boot is faster, removed two startup delays that were adding up to 65 seconds
- AutoShield works with any username now, not just the default "kodachi" account
- Installer now properly preserves the username and password you choose during installation
- Application settings for VSCodium, Tabby terminal, and VeraCrypt are preserved after installation
- Dashboard and AutoShield resolve all paths dynamically, no more hardcoded locations
- Conky data collection is 30x faster using the new Rust-based conky-status service instead of shell scripts
- Emergency shortcuts include anti-spoof protection with automatic fallback for virtual machines

**Fixes:**
- Fixed Conky crash loop that could occur during system shutdown
- Fixed screensaver activating unexpectedly, now disabled by default (can be re-enabled in settings)
- Fixed false "update available" notifications appearing after binary pack installation
- Fixed installer accidentally removing external GUI applications during post-install cleanup
- Fixed GRUB theme unnecessarily restoring itself on every boot
- Fixed AutoShield showing false success for DNS setup when it actually failed
- Fixed AutoShield incorrectly reporting encryption status on LUKS-encrypted systems
- Fixed Rofi launcher fonts not rendering correctly on some language settings
- Removed broken OEM install option from boot menu, it was never functional
- Fixed duplicate entries appearing in the Dashboard output panel
- Fixed stale Conky status data persisting from previous sessions on fresh boots
- Fixed Conky IP display after torrification, the privacy panel now switches to the real Tor exit IP and clears stale cached direct-IP data
- Fixed DNSCrypt status reporting, now shown as enabled only when DNSCrypt is the active resolver, not merely a running background service
- Fixed Tor detection on non-systemd setups, torrification can now be inferred from verified Tor DNS even when no systemd service is present

**Documentation:**
- Desktop wiki page expanded with detailed Dashboard and AutoShield usage guides
- Downloadable offline PDF manuals (Security Manual and Binary Reference)
- Wiki landing page rewritten with benefit-first messaging

---

### Version 9.0.1 - Desktop Beta Release

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) |
| **System** | 64-bit (BIOS + UEFI + Secure Boot) |
| **Desktop** | XFCE |
| **Release date** | 26.02.2026 |
| **Status** | Beta |
| **Min Requirements** | 8GB RAM, 20GB disk space |
| **Code Name** | Queen |

The first **Kodachi Desktop edition** built on Debian 13 with a complete GUI experience, featuring a modern native dashboard, boot-time security automation, AI-powered command assistant, and full XFCE desktop environment.

**Kodachi Dashboard (NEW):**
- Complete rewrite of the system control interface as a **native desktop application**
- Replaces all legacy Gambas GUI applications with 281 modern interface components
- **Three dashboard modes**: Full (1800×1000), Lite (1128×774), Circle (720×720), optimized for different hardware capabilities
- 17 backend command modules integrating all Rust services over an async command bridge
- Real-time system monitoring with **Chart.js** visualization (CPU, memory, disk, network I/O)
- **Interactive world map** (D3-geo + TopoJSON) showing IP geolocation
- **Embedded terminal** (xterm.js 6.0) with multi-tab support
- **Workflow visual editor** with drag-and-drop, condition builder, and JSON export
- **Command queue** with sequential/parallel execution modes and real-time progress
- System tray integration with context menu
- Window state persistence (size, position)
- Toast notifications, confirm modals, audio feedback
- Favorites management for frequently used commands

**Dashboard Protection System (NEW):**
- **Multi-factor authentication**: Password + TOTP (RFC 6238) two-factor authentication
- **Argon2id** password hashing with **AES-256-GCM** encrypted TOTP secret storage
- **BLAKE3**-based machine-derived encryption keys
- Lock screen with auto-lock on inactivity
- **Nuke password** (duress feature): Multi-phase data destruction with wipe methods (Secure, Paranoid, Quick) and storage-aware wiping (HDD vs SSD/NVMe detection)
- **Fake update screen**: Deception display during nuke operations
- **HMAC-salted recovery codes** (10 codes)
- Threat response with progressive lockout and configurable automated responses
- Comprehensive audit logging for all authentication events

**Kodachi AutoShield (NEW):**
- **Boot-time security automation wizard** (16 components)
- Always-on-top window (1280×940) with countdown timer and visual shield strength indicator
- **10 configurable security hardening steps:**
  1. Cloud authentication with auto-relogin
  2. Random hostname generation (Windows-style)
  3. MAC address randomization
  4. Timezone randomization for location masking
  5. DNSCrypt encrypted DNS activation
  6. Comprehensive PC hardening (8 modules)
  7. Fast internet connectivity recovery
  8. WireGuard VPN tunnel establishment
  9. System-wide Tor routing via nftables
  10. Identity and network status refresh
- Configurable countdown timer (60s to 6 hours, or manual trigger)
- **Application launchers**: LibreWolf, Tor Browser, Rise VPN, Oniux Browser, Oniux Terminal
- Sound notifications for timer events (start, 15-second warning, per-step, completion)
- Real-time system resources monitoring (CPU, memory, disk, network)
- Recovery operations (internet, routing, MAC address reset, detorrify)
- Auto-close after completion with configurable delay

**AI Assistant Integration:**
- **Natural language command interface** via kodachi-ai for executing security operations in plain English
- **6-tier AI engine**: TF-IDF → ONNX → Mistral.rs → GenAI/Ollama → Legacy LLM → Claude CLI
- Command history with success rate tracking
- Proactive security suggestions based on system state
- Schedule manager for automated tasks (cron-based)
- Learning statistics dashboard with accuracy trends and top commands analytics

**System Monitoring Suite:**
- **Resources Panel**: CPU, memory, swap, disk, network I/O with Chart.js graphs
- **Processes Panel**: Process list with filtering and management
- **Network Panel**: Active connections, listening ports, traffic statistics
- **Firewall Panel**: nftables/iptables rule viewer
- **Logs Panel**: System log aggregation and filtering
- **Startup Panel**: Service autostart configuration

**Service Integration Panels:**
- **Authentication** (online-auth): Login, heartbeat monitoring, session management
- **Connections** (routing-switch): VPN/WireGuard/proxy protocol control with 12+ protocols
- **TOR** (tor-switch): Circuit management, exit node rotation, load balancing (107 commands)
- **DNS** (dns-switch): DNSCrypt, Pi-hole integration, leak detection
- **Health Control**: Emergency controls, panic modes (soft/medium/hard), network kill switches
- **Workflow Manager**: Visual workflow builder with JSON support and 92+ profiles
- **IP Fetch**: Geolocation lookup with multi-provider fallback
- **Online Info Switch**: RSS security feeds, cryptocurrency prices, paste services
- **Permission Guard**: File permission monitoring and enforcement
- **System Tools**: Dependency checker, global launcher integration

**Desktop Environment:**
- Full **XFCE desktop** with custom Kodachi theming
- **UEFI Secure Boot** support with auto-detection
- Custom **GRUB theme** with Kodachi branding, splash screen, and custom fonts
- 516 GUI-specific packages (on top of base system)
- Offline installation support (network disabled during install)

**Documentation:**
- **MkDocs-based wiki** with 62 pages at [kodachi.cloud/wiki/bina](https://kodachi.cloud/wiki/bina)
- Complete binary documentation and CLI reference for all 25 binaries
- User guides organized by category: Network, Security, Protection, Infrastructure, AI
- Material for MkDocs theme with dark mode, full-text search, Mermaid diagrams

---

### Version 9.0.1 - Terminal Release

| Property | Value |
|----------|-------|
| **Based on** | Debian 13 (Trixie) |
| **Format** | ISO (Live Boot) - 2.4GB |
| **System** | 64-bit (BIOS + UEFI compatible) |
| **Release date** | 30.10.2025 |
| **Status** | Stable |
| **Packages** | 1,181 total (247 terminal-specific components) |
| **Min Requirements** | 4GB RAM, 10GB disk space |
| **Code Name** | Queen |

A **minimal, terminal-only live ISO** designed for comprehensive security toolkit testing and deployment as a dedicated SOCKS proxy gateway for network-wide anonymity.

**Major Additions:**
- Complete rewrite of Kodachi OS as a terminal-focused privacy distribution
- All 16 core security binaries pre-installed
- **92+ security workflows** with 18 pre-built workflow tiers
- Interactive welcome menu with 25+ configuration options across 4 submenus
- DNSCrypt auto-configuration on first boot
- Security score and hardening status display
- Cryptocurrency prices and news headlines integration
- Auto-refresh with configurable timeout (10 minutes default)

**Routing Protocol Support (12+):**
- OpenVPN, WireGuard, Shadowsocks
- V2Ray, Xray (with VLESS and Trojan variants)
- Hysteria2, Mieru (MITA)
- Tor integration via Redsocks
- SOCKS5/HTTP proxy protocols

**Security Features:**
- **System-wide Torrification** - Layer Tor routing atop any VPN service
- **LUKS Nuke Password** - Emergency irreversible encrypted data destruction
- **Encrypted Persistence** - Optional LUKS-encrypted storage via `live-persist-encrypted` boot option
- Multi-level panic modes (soft/medium/hard)
- MAC address randomization and hostname management

**Hardware Compatibility:**
- 30+ firmware packages (WiFi, Ethernet, Bluetooth, GPU)
- Intel, Broadcom, Atheros/Qualcomm, Realtek, MediaTek chipsets
- No post-boot driver installation needed

**Live Build Features:**
- Lightweight GUI-free design (2.4GB ISO)
- Optimized 80x24 terminal resolution display
- Default credentials: `kodachi` / `r@@t00` with passwordless sudo
- Skip welcome via `KODACHI_SKIP_WELCOME=1` environment variable
- Force DNS setup via `--force-dns-setup` flag

**Primary Use Cases:**
- Network-wide SOCKS5 proxy deployment
- Isolated binary testing environments
- Portable security operations (no disk traces)

**Build System:**
- Interactive build script with 4 build modes: fast (5-10 min), clean (15-20 min), refresh (15-20 min), purge (45-60 min)
- Overlay configuration system with single source of truth for all customizations
- 18+ automated build hooks for chroot customization
- Offline installation (network disabled during install, Parrot OS pattern)
- ISO validator tool (v1.4.0) for comprehensive post-build diagnostics
- Automatic binary deployment from installer package
- External GUI app caching system for reproducible builds

**VPS Infrastructure:**
- 10+ routing protocols supported on VPS nodes: OpenVPN, WireGuard, Tailscale, Xray (latest), V2Ray (v5.44.1), Hysteria2 (v2.7.0), Shadowsocks, Dante (v1.4.4), Mita/Mieru (v3.27.0), DNSCrypt-proxy (v2.1.15), Tor
- 20+ automated VPS setup scripts with manual update detector
- Service health monitoring and configuration card generation

---

### Version 9.0.1 - Binary Pack Release

| Property | Value |
|----------|-------|
| **Format** | tar.gz (Binary Pack) |
| **System** | 64-bit |
| **Release date** | 03.10.2025 |
| **Status** | Stable |
| **Total Commands** | 438 (290 authenticated, 148 unrestricted) |
| **Min Requirements** | 4GB RAM, 20GB disk space |
| **Code Name** | Queen |

**25 Rust-based security and AI binaries** plus 2 shared libraries forming an enterprise-grade privacy infrastructure with zero-trust architecture, authentication-first design, memory-safe implementation, AI-powered operations, and forensic-resistant capabilities.

**All 25 Binaries with Descriptions:**

| Binary | Purpose |
|--------|---------|
| **tor-switch** | Advanced Tor network management with 107 commands. Controls multi-instance Tor (create, delete, start, stop, clone instances), exit node rotation, circuit management, HAProxy load balancing, and DNS leak prevention. |
| **oniux** | Tor isolation via Linux namespaces. Provides application-level Tor routing isolation using mount, user, and netlink namespace operations. From Tor Project (MIT/Apache-2.0). |
| **routing-switch** | Multi-protocol network routing supporting 12+ protocols: OpenVPN, WireGuard, Shadowsocks, V2Ray, Xray (VLESS/Trojan), Hysteria2, Mieru, SOCKS5, Dante, Tor via Redsocks. Includes QR code generation for mobile. |
| **ip-fetch** | IP geolocation service with multi-provider fallback support. Fetches current IP info, country mapping, IPv4/IPv6 verification, and API integration for location data. |
| **dns-switch** | DNS configuration management with 50+ resolver options. Supports DoH (DNS over HTTPS), DoT (DNS over TLS), and DNSCrypt. Includes health checking, server switching, and backup/restore. |
| **dns-leak** | DNS leak detection and analysis. Discovers network interfaces, tests for DNS leaks across all connections, and generates detailed leak reports. |
| **health-control** | Comprehensive system health and emergency response with 166 commands. Provides kill switches, panic modes (soft/medium/hard), MAC randomization, hostname management, multi-pass data wiping, RAM clearing, LUKS encryption management, USB Guard, and security scoring. |
| **integrity-check** | System integrity verification using SHA-256 hashing and digital signatures. Verifies file integrity, checks signatures, and generates hash reports for system files. |
| **permission-guard** | File permission monitoring and enforcement. Watches for permission changes in real-time, automatically corrects file ownership issues, runs as daemon for continuous protection. |
| **online-auth** | Secure authentication service with cryptographic API validation. Handles challenge-response authentication, session management, certificate handling, and secure credential storage. |
| **logs-hook** | Centralized secure logging system. Provides encrypted logging with automatic rotation, maintenance operations, and secure deletion for all Kodachi services. |
| **deps-checker** | Dependency checking and validation tool. Scans for missing dependencies, identifies security vulnerabilities, supports multiple distros, and generates installation scripts. |
| **global-launcher** | Global binary deployment system. Manages system-wide symlinks for dashboard binaries, performs integrity verification before deployment, supports rollback on failures. |
| **workflow-manager** | Batch command execution engine with 92+ built-in profiles. Supports conditional logic, pattern matching, JSON path evaluation, pause/resume controls, and comprehensive telemetry logging. |
| **online-info-switch** | Online information hub service. Aggregates RSS security news feeds, integrates paste services, generates freshness proofs, tracks cryptocurrency prices, and monitors Kodachi releases. |
| **kodachi-ai** | AI-powered natural language command platform with 8 sub-binaries: ai-cmd (NLP command execution), ai-admin (system administration), ai-gateway (request routing), ai-learner (model training), ai-trainer (pipeline management), ai-monitor (system monitoring), ai-discovery (automatic model discovery), ai-scheduler (task scheduling). 6-tier AI engine (TF-IDF → ONNX → Mistral.rs → GenAI/Ollama → Legacy LLM → Claude CLI), multi-provider support, intent classification, interactive mode, and command preview. |
| **kodachi-claw** | Fast AI assistant runtime. Zero-overhead, 100% Rust agent-based architecture with classifier and dispatcher. Privacy features (auth gate, circuit pool, DNS verification). Embedded hardware support (STM32, ESP32, Raspberry Pi GPIO). Secure-by-default with sandboxing and workspace scoping. |
| **zeroclaw** | Multi-platform autonomous agent runtime. Under 5MB RAM, sub-10ms cold start. Runs on $10 hardware (ARM, x86, RISC-V). Trait-driven provider/channel/tool system. OpenAI-compatible API plus custom endpoint support. Multi-language documentation. |
| **conky-status** | Unified Conky data gateway replacing shell-based data collection. 8 data adapters (system, health, tor, dns, routing, auth, ip, online_info). 198+ data keys with 128 legacy aliases for backward compatibility. 6-17ms response time (30× faster than shell scripts). Built-in signature verification and privacy masking. |

**Shared Libraries:**

| Library | Purpose |
|---------|---------|
| **cli-core** | CLI infrastructure library providing standardized command-line interfaces for all Kodachi services. Professional output formatting (JSON/text with colors), robust error handling with error codes, filesystem utilities with dynamic directory management, field filtering (`--fields`), pagination (`--offset`, `--limit`), pretty JSON (`--json-pretty`), and color control (`--no-color`). |
| **auth-shared** | Centralized authentication library with sub-millisecond cached authentication checks. AES-256-GCM with HMAC validation, machine-specific encryption, tamper-proof design preventing token portability. Thread-safe concurrent access. Used by all Kodachi services requiring authentication. |

**AI Libraries (13 shared libraries under kodachi-ai workspace):**
ai-config, ai-core, ai-engine, command-registry, db-layer, kodachi-gateway-core, learning-engine, nlp-engine, nlp-utils, profile-registry, recovery-engine, vector-ops, voice-engine

**Installer System:**
- **kodachi-binary-install.sh**: User-space binary installer (refuses root for security). Multi-location support (system, desktop, custom path). Comprehensive signature and SHA256 checksum verification. Automatic PATH configuration.
- **kodachi-deps-install.sh**: System dependency installer with 4 modes: full, minimal, interactive, proxy-only. Smart desktop detection (force-gui/skip-gui). Automatic DNS fix after systemd-resolved installation. Per-package DNS testing with retry logic.
- **pack-kodachi.sh**: Automated packaging with per-binary signature verification and checksum generation.

**Key Features:**
- Zero-trust architecture with memory-safe Rust implementation
- 25 binaries with comprehensive CLI command coverage across all services
- JSON-first output for automation integration

---

### Version 8.27

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernels** | 6.2 (default, no DKMS support), 5.4.231 (stable, Broadcom NIC support) |
| **System** | 64-bit |
| **Release date** | 22.02.2023 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade
- Added PicoCrypt application
- Added new bookmarks on Kodachi browsers + plugins update
- Added one new wallpaper

**Fixes:**
- System packages update + OpenSSL + Syncthing + Crypto wallets + Tor browser
- Random hardware ID is on by default and status added to Conky
- Fixed a bug with IP locator within the Dashboard GUI
- Fixed a bug with folder shredding within the Dashboard
- Fixed a bug with BTC balance checker within the Dashboard
- Fixed and repositioned items on Conky
- browser.disableResetPrompt (Firefox security setting) was set to true

**Removals:**
- Demonsaw chat removed (EOL)

> **Notes:**
> 1. Better get the fresh ISO instead of Dashboard upgrade
> 2. This should be stable release before we move to Debian

---

### Version 8.26

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.217 & 6.0.1 |
| **System** | 64-bit |
| **Release date** | 13.10.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade

**Fixes:**
- System packages update + system upgrade

> **Notes:**
> 1. Better get the fresh ISO instead of Dashboard upgrade
> 2. This should be stable release before we move to Debian

---

### Version 8.25

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.212 |
| **System** | 64-bit |
| **Release date** | 06.09.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Added new bookmarks on Kodachi browsers

**Fixes:**
- System packages update + system upgrade

---

### Version 8.24

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.18.11 |
| **System** | 64-bit |
| **Release date** | 14.07.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.18.4 to 5.18.11

**Fixes:**
- Fixed IPv6 bug - if disabled, system will enforce it to be disabled on startup
- System packages update + system upgrade

---

### Version 8.23

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.18.4 |
| **System** | 64-bit |
| **Release date** | 16.06.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.4.0.112 to 5.18.4

**Fixes:**
- System packages update + system upgrade

---

### Version 8.22

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.0.112 |
| **System** | 64-bit |
| **Release date** | 16.05.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.4.0.110 to 5.4.0.112
- Added new bookmarks on Kodachi browsers
- Tor browser and Session messenger updated

**Fixes:**
- Fixed a bug while minimizing Kodachi Dashboard you see 2 icons
- System packages update

---

### Version 8.21

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.0.110 |
| **System** | 64-bit |
| **Release date** | 28.04.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Added Whisker menu to application menu
- Added feature to change fonts color on Dashboard

**Fixes:**
- Dashboard bug fixed with periodic tasks timer
- Sphere browser fix
- AppArmor fix - disabled notifications
- Kodachi bookmarks modified - new web wallets and online OTP
- Themes bug fixed - now we have few more themes and icon sets

---

### Version 8.20

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.0.108 |
| **System** | 64-bit |
| **Release date** | 21.04.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Fixes:**
- Steam not installing fixed
- Fixed Tor issue with AppArmor
- System packages update
- New icon themes

**Removals:**
- One of the mixers was removed from Kodachi browser bookmarks

---

### Version 8.17

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.4.0.108 |
| **System** | 64-bit |
| **Release date** | 20.04.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Added Steam installer - just run: `sudo bash ~/.kbase/steaminstall`

**Fixes:**
- Fixed Tor issue with AppArmor - ignore the AppArmor message, Tor should work now
- System packages update
- Few scripts were fixed

**Removals:**
- One of the mixers was removed from Kodachi browser bookmarks
- Kernel downgrade from 5.16.19 to 5.4.0.108

---

### Version 8.16

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.16.19 |
| **System** | 64-bit |
| **Release date** | 10.04.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.16.9 to 5.16.19
- Added encrypt swap feature on the Dashboard
- Added periodic features on Dashboard - Settings
- Added new predefined profiles on Dashboard - Settings
- Added process killer on Dashboard - Settings
- Added NetHogs on system monitor section of the Dashboard
- Added new bookmarks on Kodachi browsers + redundant plugin removed
- GUI spinners added to the Dashboard
- Added AppArmor extra tools and profiles
- Added panic script placed on XFCE panel
- Added Warrant Canary on the OS (see [License](https://kodachi.cloud/wiki/bina/license.html))

**Fixes:**
- Dashboard will run once only
- IPv6 options is more stable on Dashboard
- Settings will be auto saved on Dashboard quit
- System packages update
- WPA error fixed
- Improved script control on Dashboard

**Removals:**
- Xpra removed
- Exif cleaner removed
- Broadcom sta dkms removed and replaced with bcmwl-kernel-source

> **Note:** Next major release could be based on Debian or MX Linux - tell me what you prefer via Discord or Twitter

---

### Version 8.15

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.16.9 |
| **System** | 64-bit |
| **Release date** | 14.02.2022 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.15.1 to 5.16.9
- On Kodachi Dashboard -> Panic room you can now disable Hardware ID and replace it with a random fake ID (Users request)
- Added MetaMask plugin on Firefox (Only on fresh ISO)
- Added Bitwarden plugin on Firefox to replace Myki (Only on fresh ISO)
- Added the following bookmarks on Firefox (Only on fresh ISO):
  - https://nomics.com/
  - https://txstreet.com/v/bch
  - https://www.blockonomics.co/
  - https://cryptorank.io/
  - https://www.marketcapof.com
  - https://mempool.space
  - https://lunarcrush.com
  - https://xsinator.com/
  - https://elude.in/

**Fixes:**
- Fixed Kodachi Dashboard font issues
- Tor browser updated (Only on fresh ISO)
- System updated

---

### Version 8.14

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.15.1 |
| **System** | 64-bit |
| **Release date** | 08.11.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.14.14 to 5.15.1
- Added Chameleon plugin on Firefox - replaced agent switcher (Only on fresh ISO)
- Added Bluetooth manager (Only on fresh ISO)

**Fixes:**
- Tor browser updated (Only on fresh ISO)
- System updated

---

### Version 8.13

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.14.14 |
| **System** | 64-bit |
| **Release date** | 26.10.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.14.8 to 5.14.14
- Added panic repair and restore on last menu of Cairo dock (Only on fresh ISO)
- Added Kodachi Dashboard to system toolbar (Only on fresh ISO)

**Fixes:**
- System upgraded to linux-firmware_1.201
- Monero wallet updated (Only on fresh ISO)
- Tor browser updated (Only on fresh ISO)
- System updated

---

### Version 8.12

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.14.8 |
| **System** | 64-bit |
| **Release date** | 29.09.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Added a button on VPN tab on the Dashboard to show the expected Kodachi VPN IP when you connect
- Added achievements on About tab on Dashboard
- Tools folder added on Kodachi browser bookmarks
- Addresses tools added on Crypto Kodachi browser bookmarks
- Kodachi Dashboard added on Desktop

**Fixes:**
- Dashboard update is via system terminal now
- Fixed issue where SSH keys were regenerated after the update
- Improved VPN connect/disconnect process
- System upgraded to linux-firmware_1.200
- Nvidia drivers updated to 470

**Removals:**
- Removed https://ethblender.com/ from bookmarks and added new onion site

---

### Version 8.11

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.6 LTS |
| **Kernel** | 5.14.2 |
| **System** | 64-bit |
| **Release date** | 09.09.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Upgraded from Ubuntu 18.04.5 to 18.04.6
- Added video guide URL on Dashboard - About
- Added download Kodachi ISO on Dashboard - About
- Added verify Kodachi ISO on Dashboard - About
- Added remote files restore on Dashboard - About
- Added onionmail.org to mail Kodachi browser bookmarks

**Fixes:**
- Improved settings backup/restore on Dashboard - now you can export and import to any location
- Improved VPN connect/disconnect process - less time
- Dashboard will restore automatically if JSON file was accidentally deleted

---

### Version 8.10

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.13.12 |
| **System** | 64-bit |
| **Release date** | 22.08.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.13.7 to 5.13.12
- Added enable terminal commands history feature
- Added Hash info on about tab

**Fixes:**
- Security bug fixed
- Dashboard improved
- Fixed network troubleshoot on startup
- Fixed bugs on Dashboard GUI
- Fixed Kodachi Terminal on Dashboard
- Shutter icon was put back on Cairo menu
- System and few apps were updated to latest

**Removals:**
- Junk files removed - ISO is smaller in size
- Forced DNS on Conky replaced with Auto DNS recovery

---

### Version 8.9

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.13.7 |
| **System** | 64-bit |
| **Release date** | 01.08.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.13.4 to 5.13.7
- Added update/upgrade progress window
- Added export/restore settings

**Fixes:**
- Fixed Tor bug
- Reduced Dashboard timer to 10000 ms from 20000 ms
- System and few apps were updated to latest including messengers and crypto wallets

---

### Version 8.8

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.13.4 |
| **System** | 64-bit |
| **Release date** | 23.07.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

> This is a security update to fix kernel security vulnerability recently announced: https://nvd.nist.gov/vuln/detail/CVE-2021-33909

**Additions:**
- Kernel upgrade from 5.13.2 to 5.13.4
- Added feature to enable/disable syslogs

**Fixes:**
- DNS script improved
- Fixed saving method on Kodachi Dashboard - all JSON values are auto saved without the need of save button
- Fixed font size bug

---

### Version 8.7

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.13.2 |
| **System** | 64-bit |
| **Release date** | 19.07.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.13 to 5.13.2
- Added Password change feature into Kodachi Dashboard
- Added UDP traffic blocker + clear firewall rules into Kodachi Dashboard
- Added WiFi scan feature in Dashboard -> Panic room
- Panic room and About tab redesigned
- Dashboard version added on About tab

**Fixes:**
- Fixed WiFi issue in some Broadcom devices
- Score set to 50 to give you green shield on Panic Tab instead of 60
- Disable RF will notify a message if no devices found
- VPN age bug fixed if +24 hours
- Few drivers updated
- Fixed a bug on RiseupVPN auto switch DNS
- Fixed typo on About tab
- Fixed VPN age on screen display information
- Rise VPN renamed to Riseup VPN
- Update scripts modified - now includes kernel auto upgrade

---

### Version 8.6

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.13 |
| **System** | 64-bit |
| **Release date** | 01.07.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Smooth ride |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.11.16 to 5.13 (Update available on fresh ISO only)
- Riseup VPN added to the list of free VPNs that users can connect to
- Lynis hardening and compliance tool added in Panic room
- json.log reduced from 10 MB to 2 MB - SSD life saver (Update available on fresh ISO only)
- rsyslog was disabled - SSD life saver (Update available on fresh ISO only)
- System journal limited to 50 MB - SSD life saver (Update available on fresh ISO only)
- KeePass theme changed to dark (Update available on fresh ISO only)
- GRUB entry for old LAN names `biosdevname=0` was added (Update available on fresh ISO only)
- New bookmarks: https://simpleswap.io/, https://anonfiles.com, https://mail.tm/en/, deepl.com/translator to Kodachi browsers (Update available on fresh ISO only)

**Fixes:**
- Fixed few typos on tray menu
- Fixed Kodachi VPN sentence on Kodachi Dashboard
- Fixed a bug on DNS manual editing
- Fixed a bug where if network is disabled Kodachi complains of no internet
- Fixed and improved auto update script - now it will verify SHA512 before accepting the updates from the website
- Fixed few bugs on Kodachi engine
- Kodachi Dashboard updated + Full system apt update
- Few applications were updated (Update available on fresh ISO only)

**Removals:**
- Disabled Discord redirection when banned

---

### Version 8.5

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.11.16 |
| **System** | 64-bit |
| **Release date** | 22.04.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.11.14 to 5.11.16
- Now from 8.5 you can update Kodachi (Patches) without downloading fresh ISO for live and installed modes - long time requested feature, here we go!
- More drivers support for Nvidia + ALFA AWUS1900 + AWUS036ACH + nouveau-firmware + xserver-xorg-video-nvidia + linux-firmware
- Torrent IP leak website checkers added on bookmarks
- XMR donation address and QR code added to Dashboard

**Fixes:**
- Full system update + MyMonero wallet
- Solved a bug where Kloak was running on background and some keyboards would stop functioning
- Dashboard UI improved
- Country locator bug on Dashboard fixed

---

### Version 8.4

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernels** | 5.11.14, 5.4.67 LTS |
| **System** | 64-bit |
| **Release date** | 16.04.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.11.10 to 5.11.14 (I will also provide an ISO with kernel 5.4.67 for those who have issues with latest kernels)
- Now you can connect to new Kodachi VPN nodes with Tor end enabled (You get new Tor IP each time you connect to those nodes so your VPN IP is hidden as well - gift for anonymous dudes and pen testers!)
- Now you can set the watched IP on VPN tab to auto update itself
- Keystroke anonymizer Kloak was added and you can control it from Panic room
- Now you can update Tor circuit with a click of a button
- Quad9 uncensored DNS added
- AdGuard DNS added
- WiFi Radar was added - this will detect Alpha devices
- `iommu=soft` boot parameter was added to installed GRUB

**Fixes:**
- Fixed kernel information display error on Dashboard
- Fixed Dashboard freezing issue
- Fixed "your own VPN" - has Kodachi word replaced with config
- Fixed a bug where top information area expander could not be hidden
- Online check script improved
- BTC balance checker improved

**Removals:**
- Replaced Onion Circuits with Tor Circuits NYX - very cool app, try it!

---

### Version 8.3

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.11.10 |
| **System** | 64-bit |
| **Release date** | 30.03.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.11.8 to 5.11.10
- Kodachi health status on Dashboard updated
- Kodachi Dashboard tray icon updated with Torify and health status
- `iommu=soft` boot parameter was added to legacy and UEFI boot failsafe options
- System, Tor browser and Session messenger were updated
- Digi77 server has been moved to new server with latest updates
- 2 extra VPN nodes were added to Kodachi VPN list

**Fixes:**
- AMD Ryzen blank screen fixed (Pending confirmation from users)
- Bug fixed where Tor and Torify had always the same country ID
- apt sources bug fixed
- Bug fixed when disabling Tor - remove tick on Torify checkbox

**Removals:**
- Dashboard timer moved to Panic room

---

### Version 8.2

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.11.8 |
| **System** | 64-bit |
| **Release date** | 22.03.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.11.7 to 5.11.8
- Now Kodachi can automatically spoof your MAC each time you connect to new VPN
- Now Kodachi can change your system time based on the new IP and timezone that is changed based on the IP address
- New MAC spoofing button was added if you needed to manually spoof a new MAC address
- GeoIP DB updated
- Few packages update

---

### Version 8.1

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.11.7 |
| **System** | 64-bit |
| **Release date** | 19.03.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Few packages update
- Sphere browser is back
- New bookmarks on search in Kodachi browser

**Fixes:**
- Fixed a bug where installation fails on some systems
- Dashboard Tor selection bug fixed
- Conky version display bug fixed
- Fixed few Kodachi scripts

**Removals:**
- Kodachi browser start home changed to new search engine Metager

---

### Version 8.0

| Property | Value |
|----------|-------|
| **Based on** | Ubuntu 18.04.5 LTS |
| **Kernel** | 5.11.7 |
| **System** | 64-bit |
| **Release date** | 18.03.2021 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Game changer |
| **Code Name** | Lion |

**Additions:**
- Kernel upgrade from 5.9.8 to 5.11.7
- Kodachi has new brand with new logo, wallpapers + Dashboard and system monitor
- New Dashboard with amazing unique features that you will never see in any other OS - I leave this for you to explore!
- Now you can automatically change your system timezone based on your new IP
- You can have fake hostname for your system!
- You can see Kodachi source codes - all shell scripts in Kodachi system monitor
- You can see/monitor all types of system logs in Kodachi system monitor
- You can generate passwords with Kodachi
- You can verify all Kodachi files sources and system files with a single click
- You can disable WiFi, Bluetooth, RF and block USB devices with single click
- VPN, DNS, Tor, Panic room management has totally changed
- 6 types of kill switches were added! By process, by IP, by VPN, by DNS! With sound alerts!
- Now you get warned if your security score is low
- Full system update
- OpenSnitch firewall - this is a powerful firewall, try it
- Right click on any files will give you more features like digest, GPG encryption, OpenSSL encryption, etc.
- Exif cleaner app added
- New exit country nodes for Tor - total of 36!
- GtkHash verification tool installed
- VBox guide on Kodachi website added
- New media codecs installed
- Timezone added to Conky
- Kodachi browser threat maps was added + fast swap of crypto currency bookmarks
- ShellCheck for Geany was added

**Fixes:**
- Swap issue after reboot was fixed
- Null country on some IPs was fixed
- "IP = IP not visible" fixed
- Bandwidth warning limit increased to 100 GB and 200 GB for shutdown
- All local common variables that are stored in local JSON file have been moved to a remote JSON
- Tor browser guarded node changes on reboot now - not fixed anymore
- IP country resolve has been improved for non-available records
- Torify script improved
- Conky information windows set to transparent
- Ping VPN nodes before connection disabled
- System health script improved
- Fixed right menu wipe option
- Bash command history disabled
- Postfix bugs fixed
- lz4 bug fixed
- Terminal slow launch fixed
- Syncthing same permanent ID issue solved - new ID will be generated after boot up
- Mullvad does not need IPv6 to be enabled - this was fixed
- DNSCrypt is only allowed via DNSSEC now

**Removals:**
- Reduced number of icons on bottom menu - most options moved to Kodachi Dashboard
- Sphere, Wire, Thunderbird, Signal, GIMP, OpenShot-Qt, snapd, XnView, Bettergram removed - by this I saved 400 MB on the ISO size

---

### Version 7.6

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04.5 LTS |
| **Kernel** | 5.9.8 |
| **System** | 64-bit |
| **Release date** | 14.11.2020 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Stable |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.9.2 to 5.9.8
- Full system update
- Session messenger, Tor browser, Firefox plugins, Ghacks updated

**Fixes:**
- Kodachi tag changed from "Simplifying anonymity" to "Security simplified"

---

### Version 7.5

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04.5 LTS |
| **Kernel** | 5.9.2 |
| **System** | 64-bit |
| **Release date** | 30.10.2020 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Stable |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.9.1 to 5.9.2 - latest and first OS on DistroWatch to deploy 5.9.2!
- New wipe feature was added to instantly wipe logs on Panic room -> System logs and info -> Option 9
- Full system update
- MyMonero updated

**Fixes:**
- Apt sources tweaked

**Removals:**
- Fcitx removed - not functioning properly

---

### Version 7.4

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04.5 LTS |
| **Kernel** | 5.9.1 |
| **System** | 64-bit |
| **Release date** | 23.10.2020 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Stable |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.8.0.23 to 5.9.1 - some hardware were not compatible with 5.8.0.23
- Firefox + Signal + Tor browser update
- Added new information on Panic room system information

---

### Version 7.3

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04.5 LTS |
| **Kernel** | 5.8.0.23 |
| **System** | 64-bit |
| **Release date** | 20.10.2020 |
| **Tag** | Security is the chief enemy of mortals! - William Shakespeare |
| **Code name** | Stable |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.4.0.42 to 5.8.0.23
- Full system update 18.04 to 18.04.5 LTS
- Added Demonsaw

**Fixes:**
- Fixed Tor browser issue
- Fixed SSH key generation
- Conky performance fixed
- Menu bug fixed
- VPN config files updated
- MyMonero, Electrum, Wire, XnView, VeraCrypt, Session messenger and full system update done

**Removals:**
- Replaced Nano with uBlock Origin on browsers
- Removed online installer - it caused issues when live image is too old
- Removed Tor redundancy from `/home/kodachi/.local/share/`

---

### Version 7.2

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 5.4.0.42 |
| **System** | 64-bit |
| **Release date** | 03.08.2020 |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code name** | Defeat |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.4.0.33 to 5.4.0.42
- Full system update
- Added Session messenger (One of the best secure messengers)
- Added Steghide-GUI - now you can hide your text messages encrypted in JPG or WAV files!
- Added `pci=noaer` (PCIe error handling) to GRUB options for error prevention
- Few icons changes
- Threema web added to bookmarks

**Fixes:**
- Conky improved and refresh timer reduced
- Yandex DNS moved to lower position
- Fixed bandwidth message length issue
- Fixed OnionShare update issue

**Removals:**
- Replaced Kodachi browser IP lookup plugin
- Replaced Riot with Element

---

### Version 7.1

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 5.4.0.33 |
| **System** | 64-bit |
| **Release date** | 25.05.2020 |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code name** | Katana |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.4.0.26 to 5.4.0.33
- System update

**Fixes:**
- Fixed model for DNS if system is Torified without VPN
- Fixed Tor enable with or without VPN scripts
- Few Conky labels changed

**Removals:**
- Removed empty link for Ring application

---

### Version 7.0

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 5.4.0.26 |
| **System** | 64-bit |
| **Release date** | 25.05.2020 |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code name** | Katana |
| **Code Name** | Tiger |

**Additions:**
- Kernel upgrade from 5.0.0.27 to 5.4.0.26
- Added FDN DNS
- Added NextDNS
- Added Cloudflare Family - malware and adult content filtering
- Added Neustar Family - malware and adult content filtering
- Added exFAT file system support
- Added Enigmail plugin for Thunderbird
- Added Tilix
- Added USBGuard
- Added USBKill
- Added proxychains
- Conky improved - new display items like Torify IP/country and font size
- Added MPV player
- Added new options to IP source control and syslogs scripts

**Fixes:**
- Fixed VPN <-> Torify to VPN -> Torify on screen score status
- Fixed i2p - now is working
- ProtonVPN moved to location 5 of VPN lists
- Fixed light browser spelling mistake
- Fixed Bisq wrong place on XFCE menu
- Fixed onion sites not working with Kodachi browser
- All scripts have been changed and improved to work with JSON
- All settings were moved to a single file JSON
- Casper, DKMS and GeoIP were updated from latest Ubuntu release with kernel

**Removals:**
- Jaxx wallet removed
- Exodus wallet removed
- Xelcore wallet removed
- Bisq exchange removed
- Tox chat removed
- Ring chat removed
- VLC removed
- Full system update
- Removed Tenta and Fourth Estate DNS (slow and dead)
- Kodachi browser changes:
  - DuckDuckGo plugin removed
  - Disable JavaScript removed
  - BP Privacy Block All Font and Glyph Detection replaced with Trace
  - Canvas Defender replaced with Trace
  - Canvas Blocker replaced with Trace
  - AudioContext Fingerprint Defender replaced with Trace
  - AdNauseam added
  - uBlock Origin replaced with Nano Adblocker
  - CSS Exfil Protection added
  - HTTPZ added
  - Privacy Badger and Privacy Possum removed
  - Buster added
  - Discord link added
  - MYKI plugin added
  - anonymousspeech link added to mails
  - ctemplar.com link added to mails
  - restoreprivacy link added to privacy bucket
  - Added get.webgl.org to Security check to test WebGL
  - Added WebGL Fingerprint Defender plugin
  - Public IP Display replaced with My Public IP plugin
  - Kodachi settings JSON added to browser

---

### Version 6.2

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 5.0.0.27 |
| **System** | 64-bit |
| **Release date** | 25.08.2019 (My birthday!) |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code Name** | Crocodile |

**Additions:**
- Kernel upgrade from 5.0.0.19 to 5.0.0.27
- Added Bisq decentralized exchange
- Added custom DNS script
- Added wicd network manager
- Added system logs information

**Fixes:**
- Solved WiFi not connecting for Mac and Broadcom
- Modified power settings
- MAC changer, storage, memory scripts improved
- Enable/Disable network interfaces script improved
- Updated Firefox plugins + bookmarks
- If system is live then stop unattended-upgrades service
- Reduced Kodachi Firefox profiles in size and quantity
- IP verify script improved
- Improved overall performance

**Removals:**
- Removed MAC changer from startup
- Check for updates set to never (Reduce bandwidth usage)
- Full system update
- Removed shadow over dock windows (Window Manager Tweaks -> Compositor -> Show Shadows Under Dock Windows)
- BleachBit settings changed to overwrite data
- Touchpad update

---

### Version 6.1

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 5.0.0.19 |
| **System** | 64-bit |
| **Release date** | 27.06.2019 |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code Name** | Crocodile |

**Additions:**
- Kernel upgrade from 4.19.0.12 to 5.0.0.19
- Added Zelcore Wallet
- Added Sphere anonymous browser
- Added Remmina remote tool
- Added SimpleScreenRecorder
- Added Riot chat
- Added Tox chat
- Added Zswap swap compression tool
- Added XnView
- Added IP verify on security services
- Added Mullvad VPN service
- Added Mullvad DNS
- Added 3 new profiles for Kodachi browser (Light, Loaded, NoScript, and Ghacks profile)
- Added Firefox plugins: Privacy Badger, Decentraleyes, Multi Account Containers, AudioContext fingerprinting, Private Bookmarks, Do Not Track Me Google, Searchonymous, NoScript, LibreJS, Canvas Defender, PeerName
- Added new bookmarks on Kodachi browser
- Added BTC donations balance - now you can see how much Kodachi has received in donations live on the screen!

**Fixes:**
- Fixed a bug where VPN password will be rejected if it contains letter `$`
- Fixed few DNS bugs

**Removals:**
- Conky performance improvement: `lsof` to `lsof -n`
- Memory tools will now show you keyboard status as well

---

### Version 6.0

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 4.19.0.12 |
| **System** | 64-bit |
| **Release date** | 09.02.2019 |
| **Tag** | Use Kodachi OS or be in the land of insecurity! - J.D |
| **Code Name** | Crocodile |

**Additions:**
- Kernel upgrade from 4.18.0.14 to 4.19.0.12 (Big jump)
- Storage tools added - now you can:
  1. USB persistence (casper-rw) for Kodachi
  2. USB encrypted persistence (casper-rw) for Kodachi (waiting for Ubuntu to allow this with casper boot!)
  3. USB persistence for other OS (Kali/ParrotOS/Tails) - yes with one click!
  4. USB encrypted persistence for other OS (Kali/ParrotOS/Tails)
  5. Mount storage device as read only (forensic)
  6. Wipe disk free memory
  7. Nuke LUKS encrypted storage device
  8. Add additional swap file
  9. Encrypt swap files - yes! With one click!
  10. Display advanced disk information
- Memory tools kept all in one place - now you can:
  1. Normal memory clean
  2. Force memory clean
  3. Memory wipe
  4. Memory wipe then shutdown
  5. Memory watch
- New app: Stacer Linux tuner
- New app: Grsync files sync
- Now with Tor you can exclude 14, 9, or 5 eyes countries with a single click (https://www.privacytools.io/)
- Added Tor obfuscation
- Added LUKS nuke feature for storage devices - not only the OS!
- New GRUB items to help assist your boot: Terminal boot, Full OS on RAM, forensic mode, failsafe, and old NIC names (eth0) for networking names
- Added Safe box feature in Kodachi - with a single click you can encrypt entire directory on the fly!
- Added Quad9 DNS to the DNS list
- Added wmctrl DuckDuckGo command line search tool
- Added few essential tools: lupin-casper, mesa-utils, update-notifier, xbrlapi, xfpanel-switch and speech-dispatcher
- Added buttons to disable or enable network cards
- Added buttons to enable or disable system swap
- Few more security related bookmarks were added to Kodachi browser

**Fixes:**
- Many code changes to improve and fix bugs in operational scripts
- Kodachi kill was improved to avoid wiping mounted devices - don't try it!
- GUI was tuned a bit with icons arrangement

**Removals:**
- muf was set as default PDF viewer
- Icon auto arrange button was added on left toolbar
- Information display shows faster on startup
- Now you can see Tor excluded countries, swap encryption on information display
- Ping speed on information display changed from Google to Cloudflare
- Exodus, Electrum wallet, Tor browser and many more packages were updated
- Thermald was removed - some PCs had issues with it

---

### Version 5.8

| Property | Value |
|----------|-------|
| **Based on** | Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.14 |
| **System** | 64-bit |
| **Release date** | 21.01.2019 |
| **Tag** | Simplifying Anonymity |
| **Code Name** | Vampire |

**Additions:**
- Kodachi has new green look!
- Kernel upgrade from 4.18.0.13 to 4.18.0.14
- Added MyMonero Wallet
- Added Electrum BTC Wallet
- Added KeePassXC (KeePassX/KeePass2 replacement)
- Added Double Commander (Krusader/Gnome-Commander replacement)
- Added GIMP
- Added MuPDF
- Added Thermald
- Added VokoScreen
- Added Qalculate
- New screen info look
- Ping speed on screen
- Now you can hide the screen info with single click
- Bandwidth info on screen
- Gateway info on screen
- Ping speed for each connection to VPN on windows popup
- `acpi=off` on GRUB menu for old PC support
- Bandwidth monitor on Panic room

**Fixes:**
- Set Viewnior as default image viewer
- Modified right side panel
- Modified icons theme
- Fixed a bug when connecting to Kodachi IP - the wrong country is displayed on popup window
- Renamed VPN names for better viewing
- Modified some bookmarks on Kodachi browser
- Fixed a bug where you can't Torify if force VPN traffic is on
- Now auto login is disabled if Kodachi is installed
- Fixed few other bugs on the scripts
- Few packages were updated including Office, Exodus, Jaxx, Wire, Signal, etc.
- Online installer was put back - make sure when you install Kodachi you don't change the username or scripts will fail!
- Bandwidth warning if you exceed 2 GB to 4 GB of Kodachi VPN bandwidth - fair BW for everyone to enjoy

**Removals:**
- Removed Inkscape
- Removed Blender
- Removed PCManFM
- Removed Krusader
- Removed Gnome-Commander
- Removed Waterfox browser (Trying to minimize the size of ISO)
- Removed Iridium browser (Trying to minimize the size of ISO)
- Removed KeePass2
- Removed KeePassX

---

### Version 5.7

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.13 |
| **System** | 64-bit |
| **Release date** | 01.01.2019 |
| **Tag** | Simplifying Anonymity |
| **Code Name** | Vampire |

**Additions:**
- ProtonVPN - welcome to Kodachi! Users can now use free or paid version of ProtonVPN
- Broadcom drivers added
- Bettergram added (Telegram replacement)
- Feature to increase/decrease screen font size (Conky)
- Feature to auto adjust screen font size (Conky) based on screen resolution
- Feature to control forced temp DNS
- Feature to show open local ports
- Gmerlin video codecs added
- TLP added for better power management
- `noapic` added to boot GRUB options for old PCs
- Now you can see live BTC/XMR price on your screen display (Conky)
- Added new privacy bookmarks to Kodachi browser

**Fixes:**
- Improved all scripts that work with interface cards including network boot and MAC changer
- Screen Conky redesigned to save space on lower resolution screens
- Fixed nuke issue - if password doesn't match then quit
- Printer CUPS, force DNS, Nuke, System encryption status were added to screen display (Conky)
- Fixed scoring test script - now nuke is counted along with system encryption
- Fixed printer CUPS disable script
- Fixed bug with FSlint search utility shortcut was wrong
- Fixed bug with Internet force via VPN script
- Some other system bugs were fixed including permissions and Tor start delay

**Removals:**
- System, Exodus, Jaxx, Waterfox updated
- Telegram removed

> **Note:** For those who had Broadcom, Internet connectivity or graphics cards issues hopefully this version has them fixed

---

### Version 5.6

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.13 |
| **System** | 64-bit |
| **Release date** | 15.12.2018 |
| **Tag** | Simplifying Anonymity |
| **Code Name** | Vampire |

**Additions:**
- Nuke system - Yes Kodachi can be nuked with a single button! Check website for more information
- USB persistence support! Tested and it works - check website for more information
- Light locker settings
- Startup Disk Creator
- FSlint search utility
- Force temp DNS on and off feature
- Printer CUPS port 631 on and off feature
- Force memory cleaner
- Memory watch
- Performance tab in Firefox
- New kernel updated

**Fixes:**
- Fixed performance issue - was there since 5.3
- Fixed network applet showing twice
- Fixed right menu Thunar directory size calculator
- Modified memory script
- Fixed typo mistake with myownVPNauth.txt
- Fixed Torified shell sudo error message
- Fixed and improved screen display fonts

**Removals:**
- Removed duplicate action buttons
- Super key assigned to left keyboard super key

---

### Version 5.5

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.12 |
| **System** | 64-bit |
| **Release date** | 05.12.2018 |
| **Code Name** | Vampire |

**Additions:**
- Security modeling with scoring system
- Now you can Torify entire system! Oh yes, I am serious - I made it!
- Kodachi has custom terminal with security info!
- Hide.me VPN - welcome to Kodachi
- Tor DNS added (Users request)
- NordVPN DNS added
- Censurfridns added
- FreeDNS added
- Display of total oVPN files downloaded
- Test speed any VPN provider nodes
- Option to enable/disable IPv6 (Users request)
- Option to enable/disable auto login
- More IP retrieval URLs
- VPN, IPv6, auto login, FW info with changes on screen display
- Kodachi browser has Canvas fingerprint blocker
- Kodachi browser blocks fonts fingerprinting
- Kodachi browser has new security check sites with blockchain bookmarks
- Confirmation window before wiping Kodachi script is executed
- New kernel updated

**Fixes:**
- Fixed bugs with oVPN files download of NordVPN and VPNGate
- Fixed Kodachi browser bugs - now Binance works!
- Fixed many bugs - if I name them you won't use earlier version!
- No hard coding Kodachi name on scripts - all based on variables (Users request)
- Increased file limit and placed open files counter on display screen

**Removals:**
- Google DNS removed (Users request)
- Hostname in live ISO changed to LIVE-OS (Users request)
- Background image changed

> I have put plenty of hours to improve the code so almost 80% of the code was altered - hence version jump from 5.3 to 5.5

---

### Version 5.3

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.11 |
| **System** | 64-bit |
| **Release date** | 21.11.2018 |
| **Code Name** | Vampire |

**Additions:**
- Added Jaxx wallet
- Added VPNGate free VPN service
- Added NordVPN paid VPN service
- Added VPNGate profiles download - daily updated twice
- Added NordVPN profiles download - weekly updated
- Added Ghacks privacy tweaks for Kodachi browser profile - better footprint online
- Added VPN port and protocol on display screen
- Added ISP IP information on display screen
- Added CUPS printer link on Kodachi browser local bookmarks
- Added Synaptic software manager
- Added Print manager
- System packages update

**Fixes:**
- Fixed bug when using own VPN
- Fixed other scripts to make Kodachi more stable

**Removals:**
- Kodachi based on Firefox again as Waterfox does not support onion URLs

---

### Version 5.2

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.11 |
| **System** | 64-bit |
| **Release date** | 13.11.2018 |
| **Code Name** | Vampire |

**Additions:**
- System packages update
- Few more URLs on Kodachi bookmarks

**Fixes:**
- Fixed critical issue on Exodus wallet to force new address on every boot for live ISO
- Fixed persistence install for UEFI - now you can install Kodachi on any UEFI bootable device

**Removals:**
- Display changes

> Installation instructions have been updated on the website.
> Kodachi browser won't have Tor enabled by default - it is optional from 5.1. If you want the traffic to pass through Tor, use the circle shape plugin on the address bar to toggle Tor or i2p traffic. This change is to make browsing faster.

**Pending issue to be fixed in future:**
- Kodachi browser is not supporting Tor onion URLs - you can use Tor browser instead for that. Waiting for Waterfox team to reply on the issue.

---

### Version 5.1

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.11 |
| **System** | 64-bit |
| **Release date** | 09.11.2018 |
| **Code Name** | Vampire |

**Additions:**
- Added Noisy crawler
- Added Syncthing file transfer service
- Added Tenta DNS
- Added OpenNIC DNS
- Added boot type on Desktop display (Legacy or UEFI)
- Added system persistence status on Desktop display
- Added Iridium browser
- Added Waterfox browser (Kodachi browser is based on Waterfox now)
- Added language-selector-gnome so you can easily change language layout

**Fixes:**
- Fixed DNSCrypt display
- Fixed VPN disconnect status
- Fixed Kodachi installation script
- Fixed force all traffic via VPN script
- Fixed few bugs on connectivity script

**Removals:**
- Removed Chromium (Iridium browser replacement)
- Removed Firefox (Waterfox replacement)
- Display changes with logo replacement

> Kodachi browser won't have Tor enabled by default - it will be optional from 5.1. If you want the traffic to pass by Tor, use the circle shape plugin on the address bar to toggle Tor or i2p traffic. This change is to make browsing faster.

**Pending issues to be fixed in future:**
- Kodachi browser is not supporting Tor onion URLs - you can use Tor browser for that.
- Kodachi can boot from Legacy + UEFI as live image but if you want to install it you have to boot from Legacy mode, so persistence mode is not supported in UEFI boot for now.

---

### Version 5.0

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 / Xubuntu 18.04 LTS |
| **Kernel** | 4.18.0.11 |
| **System** | 64-bit |
| **Release date** | 30.10.2018 |
| **Code Name** | Vampire |

**Additions:**
- Added Block all Internet traffic feature
- Added Chromium web browser
- Added Torified secure shell - now you can type all commands via Tor private network!
- Added Tor on direct Internet feature
- Added SSH key regeneration
- Added GNUNET switch on and off
- Added detect and install missing drivers
- Added Install Kodachi online and offline feature
- Added Gnome Commander
- Added GDebi
- Added Blender, Viewnior and Ristretto light image viewers
- With a right click of a file you can now get MD5, SHA256, SHA512, wipe, open/edit as root
- With a right click of a directory you can calculate the size of it or open as root

**Fixes:**
- Fixed installation script - no more hangs!
- Fixed VPN connection script
- GUI improvements - new icons, new bars
- Updated many packages
- Much better driver support
- Faster boot, more stable system - don't miss 5.0 with improved ISO size of 1.94 GB!

**Removals:**
- Removed Midori (Security concern - it's not updated!)
- Removed PeerGuardian (Security concern - it's not updated!)
- Removed Atom editor (Size is too large!)
- Removed snap installs and replaced with apt

---

### Version 4.3

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 XFCE / Mint 19 |
| **Kernel** | 4.18.15 |
| **System** | 64-bit |
| **Release date** | 20.10.2018 |
| **Code Name** | Venom |

**Additions:**
- New kernel - latest stable one!
- Added Telegram secure messenger
- Added Wire secure messenger
- Added VLC media player
- Added refresh status in Desktop
- Added custom installation slides
- Added more Tor fixed exit nodes
- Added snap installer

**Fixes:**
- Fixed bug - installer hangs if PC is connected to the Internet
- Fixed and improved couple of scripts - distro takes less resources and it's much faster
- Updated Exodus, Tor and Signal
- XFCE panel moved to left side
- Rearranged bottom panel icons

**Removals:**
- Removed VirtualBox - not compatible with kernel 4.18.15
- Disabled Cairo clipboard monitor (For better privacy)

---

### Version 4.2

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 XFCE / Mint 19 |
| **Kernel** | 4.15.0.36 |
| **System** | 64-bit |
| **Release date** | 14.10.2018 |
| **Code Name** | Venom |

**Additions:**
- New kernel!
- New installer with support for encrypted persistence mode
- Added Rootkit Hunter shortcut
- Added memory info and resolution on Desktop information
- Added Midori web browser
- Added SSH, DenyHosts control on services menu

**Fixes:**
- Fixed Redshift bug
- Fixed and improved couple of scripts
- ISO is 700 MB less than version 4.1

**Removals:**
- Window manager, icons, and theme changed

---

### Version 4.1

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 XFCE |
| **Kernel** | 4.9.0.8 |
| **Release date** | 06.10.2018 |
| **Code Name** | Venom |

**Additions:**
- Added ntp and rdate - now you can sync time on the running live system
- Added Screen Fetch
- Now you can see which network interface is active on Desktop
- Added country localization on login
- Kodachi has 2 new VPN nodes

**Fixes:**
- Fixed Exodus wallet shortcut that was missing
- Fixed MAC changer bug - now you can change your MAC address if Kodachi is running on VMware
- Fixed boot and network repair scripts

**Removals:**
- Window manager, icons, and theme changed
- XFCE panel modification

---

### Version 4.0

| Property | Value |
|----------|-------|
| **Based on** | Debian 9.5 XFCE |
| **Kernel** | 4.9.0.8 |
| **Release date** | 03.10.2018 |
| **Code Name** | Venom |

**Additions:**
- Added MenuLibre, Gnome Commander, Coyim, Ring, OpenShot, Icedove, Atom
- Added Rkhunter, Steghide, Gnome Nettool, GResolver, SiriKali, DenyHosts, Signal
- Added Nvidia Detect, Florence, i2p, ZuluCrypt, ZuluMount, Onion Circuits, OnionShare, GNUnet
- Added Cloudflare DNS over TLS via DNSCrypt
- Public IP resolver
- Firefox plugins
- Support for persistence encrypted volumes
- UEFI boot support

**Fixes:**
- Fixed Tor bug
- Fixed DNSCrypt bug
- Conky enhanced
- GUI enhanced

**Removals:**
- Replaced Komodo-Edit with Atom
- Replaced Electrum LTC/BTC with Exodus wallet
- Removed TrueCrypt (VeraCrypt still there)
- Improved almost all Kodachi scripts - much faster and optimized
- Themes, icons, wallpaper - all new look!
- Feature to disable Tor permanently

---

### Version 3.7

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 08.01.2017 |
| **Code Name** | Cobra |

**Additions:**
- Added data-urlencode to Curl post commands
- Added MAC address on display screen
- Added wlan0 changer - works if WiFi is disabled
- Added Anonymous wallpapers

**Fixes:**
- Changed Panel and Cairo position
- Repositioned Kodachi browser and few other icons were updated
- Changed Komodo Edit theme
- Improved own VPN script - if VPN config files are not set it will open the files for you to edit
- Improved update notification
- Fixed IP resolve issue
- Fixed VPN issues
- Fixed few other bugs
- Fixed version checker

**Removals:**
- Replaced VPN and Tor scripts with one single script
- Disabled mouse scroll on workspaces panel
- Kodachi source is on GitHub now!

---

### Version 3.6

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 30.12.2016 |
| **Code Name** | Cobra |

**Fixes:**
- Changed default editor from Komodo (slow) to Geany (fast)
- Improved own VPN script
- Improved VPN start/stop/reconnect - now VPN connectivity process is much faster
- Fixed bug in Tor connectivity

---

### Version 3.5

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 29.12.2016 |
| **Code Name** | Cobra |

**Additions:**
- Added Refracta Installer - now you can install Kodachi permanently on your PC
- Added new tool MAT - Metadata Anonymization Tool
- Introduced banned message if someone misuses the bandwidth or hosts illegal torrent files using our VPN network
- Added Gibiru engine to search bookmarks
- Added new version notification
- Added own VPN tool - now you can use your own VPN. All you need is paste your config on the right directory located on Kodachi Desktop

**Fixes:**
- Improved destroy Kodachi script
- Improved display script with new CPU/Network monitor on taskbar
- Detect screen resolution changes and display accordingly
- Fixed few bugs
- System updated
- Firefox/Firefox plugins/Tor/VeraCrypt/Komodo Edit/Electrum Bitcoin Wallet updated

---

### Version 3.4

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 17.10.2016 |
| **Code Name** | Cobra |

**Fixes:**
- Fixed bug on Destroy Kodachi script to avoid deleting the content of attached media

**Removals:**
- Replaced Google DNS with Level3 DNS if main DNSCrypt fails
- Normal Firefox browser moved to other apps dock
- System updated

---

### Version 3.3

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 13.10.2016 |
| **Code Name** | Cobra |

**Additions:**
- Added Firejail app

**Fixes:**
- Fixed DNS bug

**Removals:**
- Updated Firefox links
- System updated

---

### Version 3.2

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.6 XFCE |
| **Release date** | 12.10.2016 |
| **Code Name** | Cobra |

**Additions:**
- Additional show Desktop icon was added to the right

**Fixes:**
- Fixed DNS bug
- System updated
- Browser plugins updated
- Tor browser updated

**Removals:**
- Battery indicator was removed

---

### Version 3.1

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.5 XFCE |
| **Release date** | 17.07.2016 |
| **Code Name** | Cobra |

**Fixes:**
- Sound icon on panel
- Sound mixer on Other apps group
- Placed shortcut on the panel
- Removed Tor from startup
- Conky refresh rate reduced from 30 seconds to 15
- VPN connection establishment is faster now
- Pidgin Messenger updated
- Luminosity control and System info added to other apps panel
- Battery status added
- Moved show desktop icon location to left

---

### Version 3.0

| Property | Value |
|----------|-------|
| **Based on** | Debian 8.5 XFCE |
| **Release date** | 10.07.2016 |
| **Code Name** | Cobra |

**New Features:**
- RAM wiped out on shutdown and reboot
- Random MAC address generated on boot up
- More exit nodes for Tor
- Free space wipe
- Kill Kodachi - shred entire system!
- Repair Network feature
- Tor browser added
- Bitcoin/Litecoin wallets added
- VeraCrypt added
- UFW GUI added
- Force all traffic through VPN added - if enabled, non-VPN traffic will be blocked so no leakage!
- More DNS entries added
- Pidgin Messenger added with OTR as well
- Transmission client added
- fcitx, ibus, smbclient, syslinux-utils added
- Manually generate a random MAC address button added
- Lock screen button added
- Projector or secondary screen display button added
- New themes and icons
- New Firefox plugins on Kodachi Web Browser

**Fixes:**
- Tor will never connect until we have a valid VPN connection
- Conky display fixed
- Rearranged all Kodachi custom coding files
- Kodachi scripts have been rewritten
- Miner removed from the system
- Skype, VMware and many share tools have been removed
- Plymouth removed
- Nvidia drivers removed
- GNOME replaced with XFCE

---

### Version 2.0

| Property | Value |
|----------|-------|
| **Based on** | Debian with GNOME |
| **Release date** | 16.11.2013 |
| **Code Name** | Viper |

---

### Version 1.1

| Property | Value |
|----------|-------|
| **Based on** | Linux Mint |
| **Release date** | 01.11.2013 |
| **Code Name** | Stinger |

---

### Version 1.0

| Property | Value |
|----------|-------|
| **Based on** | Linux Mint |
| **Release date** | 20.10.2013 |
| **Code Name** | Stinger |
