Updates

Releases, fixes and package news — newest first. Every entry links to the artifacts it describes, so you can check the claim yourself.

R001.2 is the current release RSS
2026-09-14 Update

Known issues in R001.2

Three issues in the R001.2 release are confirmed and being worked. The first is serious and will be fixed and issued as an assistant package update on the mirror, ahead of the next point release; the other two are fixed in R001.3.

  • The browser chat cannot answer questions that need the language model. Any question the assistant has to write an answer for ends with the red message “Something went wrong on my end with that one. Could you try again?” Trying again does not help. Only the assistant’s fixed replies and its web-search answers get through. The cause is found: the browser side asks the assistant to compose a reply without first naming which conversation the reply belongs to, and the assistant refuses that by design. The fix ships as an update to the assistant package; pkm upgrade picks it up. There is no workaround in the meantime, and the console client takes the same path. We found this the same way we found the R001.1 conversation issues: a relative using the release for ordinary questions.
  • The release identity files disagree. On an R001.2 install cat /etc/*release shows R001.1 in the top lines and rc001.2 at the bottom. It has no effect on the system; it is fixed in R001.3 by a build gate that requires one release name everywhere.
  • Do not run pkm restart-services --all. It restarts the system bus and the display manager and ends your desktop session. Restart named services instead (pkm restart-services <package>). R001.3 limits --all to the packages that were actually upgraded and never live-restarts the bus or the display manager.
2026-09-05 Update

Verified access for security work with both AI vendors

InterGenOS is developed with AI seats from two vendors, and the code those seats review includes the installer, the package manager, the boot chain and the backup engine. Frontier models refuse or interrupt work that looks like security research by default. Both vendors run a verification program that lifts those default refusals for vetted organizations doing legitimate security work on systems they are authorized to protect. InterGenOS is accepted into both.

Anthropic’s Cyber Verification Program (accepted July 2026) is a free, application-based, organization-scoped program for Claude models. It lets approved professionals work on dual-use tasks, such as vulnerability exploitation and offensive tooling, that the safeguards would otherwise block. Activities with no legitimate defensive use, such as ransomware development and mass data exfiltration, stay blocked for everyone.

OpenAI’s Daybreak, its Trusted Access for Cyber program (accepted September 2026), gives verified organizations and practitioners access to OpenAI’s most capable models for dual-use cybersecurity work, with identity verification and account-security requirements, and usage monitored under restrictions for authorized work. It has two tiers: Blue, frontier general-purpose models with safeguards tuned for defensive work, and Red, purpose-trained cyber models for vulnerability research and exploit validation. InterGenOS is accepted into Daybreak Blue: fewer refusals from OpenAI’s most cyber-capable mainline model when a prompt is classified as higher risk, for the project’s approved use only; it does not include the purpose-trained cyber models of Daybreak Red, and OpenAI states that refusals may still occur in the highest-risk workflows such as red-teaming and penetration testing.

What it changes for you: nothing about what the project ships, and nothing about how you check it. The verification steps on the wiki’s Security Verification page remain the way to check every claim yourself. What it changes for us: the seats can review and fix the project’s own security-relevant code without being cut off mid-task, and every finding still lands in the public tree with its evidence.

2026-09-03 Update

How we're developing InterGen

A new page in the wiki's Developer & Contributor guide records how InterGen, the assistant inside InterGenOS, is being developed: what we built first, what it measured, where it was wrong, what one week of real use changed, and what we are doing now. It is written in the order things happened, and the failures carry the same weight as the successes.

The short version. We wrote several hundred scenarios from our own picture of a user, built a harness that drives the real assistant and grades the answers with a separate model family, measured all three tiers before training, and shipped one trained adapter out of three — the 9B — after judging each against the instrument's own noise floor. Then one relative's three days of ordinary use showed conversation shapes the corpus had never contained: an offer answered with “yes, please”, a question that depends on the previous turn, a live-data question routed to the clock. Two of those fixes ship in R001.2; the corpus is being reshaped around conversation shapes, with her traces as the holdout set.

2026-09-03 Point release

InterGenOS R001.2 released

The second point release of InterGenOS is available. R001.2 is an updated x86_64 UEFI live ISO built on R001's substrate, and it replaces R001.1 as the recommended download: boot it to try the system, or run FORGE from it to install a full desktop — encrypted disk, signed boot chain, and the local InterGen assistant included.

This release closes the five known issues published on 24 August. Privileged actions through the assistant work. The assistant's per-user files are created with owner-only permissions. GPU offload is planned from the card's own memory rather than the machine's hardware tier. A web search you ask for reaches the search tool, and a search looks up what the sentence asked about. The wiki index finishes building, so wiki-grounded answers use it rather than keyword matching (a run can still fall back to keywords; see the known limits in the CHANGELOG). Beyond those: on an NVIDIA machine the first-boot Welcomer now returns after the driver reboot and installs the CUDA toolkit and CUDA engine; a fresh installation passes pkm verify; upgrading a package whose application is fetched from a vendor keeps that application; and the package manager can install into a directory (pkm --root DIR install). The full list is in the CHANGELOG linked below.

Check the image before you boot it. The sha256 below is published beside the ISO as a file you can pass straight to sha256sum -c, and that checksum file carries a detached signature from the release key, whose fingerprint is also below. The package mirror's index is signed with the same key. None of these checks depends on trusting this page.

isointergenos-r001.2.iso — x86_64 UEFI live ISO, 9.7 GiB
sha25637b0d8fe4a48e56a6c6a4182d1f9a812cb123ed03ae5dfe934f3676f2d6fa6ff
signatureintergenos-r001.2.iso.sha256.asc — the checksum file, signed with the release key
release key5597 A3E0 587B 2530 06D0 DD7B 8C50 8261 8208 3050
2026-08-24 Update

Known issues in R001.1

Five issues in the R001.1 release are confirmed and being worked. Fixes land in the next point release.

  • Privileged actions through the assistant do not work in R001.1. The message “runner not found / package may be misinstalled” is incorrect — do not reinstall packages over it.
  • Wiki-grounded answering currently runs on keyword matching.
  • On machines with more than one local account, the assistant’s activity log (~/.local/state/intergen/intergen.log, which records web-search queries) is readable by other local accounts on a standard install. The personal-facts database and transcripts are created with loose permissions too, but on a standard install they sit behind a private ~/.local/share folder and are not reachable by other accounts. Run this now to close both: chmod 700 ~/.local/state/intergen ~/.local/share/intergen
  • Some discrete GPUs (3–7 GB VRAM) are not yet used for inference; replies are slower than intended on that hardware.
  • Web-search requests are phrasing-sensitive; “search the web for …” is the reliable form until R001.2.
2026-08-21 Update

Package manager rollback fix

Every pkm upgrade printed a warning for each package — “no cached archive … rollback unavailable if the install fails” — and the warning was wrong on both ends. The rollback copy it reported on was never actually being kept: the lookup used a filename shape the download cache never contains, so it missed every time, on every system. And the protection that does exist went unmentioned — the Chronicle backup engine captures a restore point before every package transaction, covering the files about to change and the package database.

pkm 0.2.0-62 fixes the lookup, so a rollback copy of each outgoing version is kept whenever the cache holds its archive, and replaces the per-package warning with a single line stating the protection actually in force: a captured restore point, kept rollback copies, or — normal for the first upgrade after a fresh installation — neither. Installed systems pick the fix up from the signed package mirror — run sudo pkm upgrade. One note: the upgrade that installs this fix still prints the old warnings a final time, since it runs the previous version's code; the first upgrade after it shows the new line.

2026-08-21 Update

Camera and virtual machine manager fixes

Two applications that failed at launch have been fixed and republished. The camera application's live preview required a GStreamer element that was not packaged — it now works end to end, verified on real hardware with a real camera. The virtual machine manager stopped opening after recent glib releases removed a compatibility alias its startup path still used — a startup patch restores it. Both were found by launch-testing every graphical application in the shipped set.

A new package, gst-plugin-gtk4 1.28.1, ships the missing element, version-matched to the GStreamer stack, and the camera application now declares it as a dependency so the pair installs together. Installed systems pick everything up from the signed package mirror — run sudo pkm upgrade. As with every package, the mirror's signed index covers the updates: they verify before they install.

2026-08-21 Update

Wiki documentation update

The InterGenOS wiki has been updated so its pages no longer name a specific “current release.” Pages now describe the system as it ships and point to the repository README and the mirror's image directory for the live answer — so the documentation cannot drift out of date when a new release publishes. The change covers both the wiki served at wiki.intergenos.org and the copy installed on every system.

Installed systems pick the update up from the signed package mirror as intergenos-wiki 1.0.0-13 — run sudo pkm upgrade. As with every package, the mirror's signed index covers it: the update verifies before it installs.

2026-08-20 Point release

InterGenOS R001.1 released

The first point release of InterGenOS is available. R001.1 is an updated x86_64 UEFI live ISO built against R001's proven substrate, and it replaces R001 as the recommended download: boot it to try the system, or run FORGE from it to install a full desktop — encrypted disk, signed boot chain, and the local InterGen assistant included.

This release addresses several small fixes, and delivers our first post-release package additions set. Some land on the image itself — log rotation on every install, USB and NVMe tooling, ethernet diagnostics, and hybrid-graphics switching — and the rest are ready to install from the signed package mirror: the full VPN client set, container tooling, and a network-diagnostics suite. One note regarding a cosmetic fix we'll finalize with our next point release— every Secure-Boot install prints a "...prohibited by secure boot policy" error at the boot menu (a flash on single-monitor machines, persistent on the second screen of multi-head machines); harmless to boot integrity — it's just Secure Boot doing its job against a GRUB font file the image should have carried built-in. Hit the 'Full CHANGELOG' link below for the complete list of changes included in this release.

Check the image before you boot it. The sha256 below is published beside the ISO as a file you can pass straight to sha256sum -c, and that checksum file carries a detached signature from the release key, whose fingerprint is also below. The package mirror's index is signed with the same key. None of these checks depends on trusting this page.

isointergenos-r001.1.iso — x86_64 UEFI live ISO, 9.7 GiB
sha25631b6e0a38ff74170a927413037e8b03b441e7178385d12ed8074c5041e0cd527
signatureintergenos-r001.1.iso.sha256.asc — the checksum file, signed with the release key
release key5597 A3E0 587B 2530 06D0 DD7B 8C50 8261 8208 3050
2026-08-20 Packages

The first package additions

R001.1 delivers the first post-release additions to the package set. Five land on the image itself: log rotation on every install, USB and NVMe tooling, ethernet diagnostics, and hybrid-graphics switching for dual-GPU laptops.

The rest are ready to install from the signed package mirror: the full VPN client set (OpenVPN, OpenConnect, and WireGuard tooling with NetworkManager integration), container tooling (compose, buildx, buildah, skopeo), and a network-diagnostics suite (mtr, tcpdump, iperf3, nmap, socat, and a meta-package that pulls the set in one install). Everything installs through pkm and verifies against the signed index like every other package.

2026-08-16 Release

InterGenOS R001 released

The first public release of InterGenOS is available. R001 is an x86_64 UEFI live ISO: boot it to try the system, or run FORGE from it to install a full desktop — encrypted disk, signed boot chain, and the local InterGen assistant included.

Check the image before you boot it. The sha256 below is published beside the ISO as a file you can pass straight to sha256sum -c, and that checksum file carries a detached signature from the release key, whose fingerprint is also below. The package mirror's index is signed with the same key. None of these checks depends on trusting this page.

isointergenos-r001.iso — x86_64 UEFI live ISO, 9.7 GiB
sha2561beeb90539bc1031ad135148f379e97a1830b835350f9c7924fd7b9fc3db07c7
signatureintergenos-r001.iso.sha256.asc — the checksum file, signed with the release key
release key5597 A3E0 587B 2530 06D0 DD7B 8C50 8261 8208 3050

This page carries every update we publish, newest first. The same entries are available as an RSS feed.