| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| NeOS-Appliance.vbox | 2026-09-19 | 1.6 kB | |
| NeOS-Appliance.vmx | 2026-09-19 | 1.4 kB | |
| Totals: 2 Items | 3.0 kB | 0 | |
Changed
- Release metadata synchronized: bumped the project version and the embedded versions reported by the Go CLI and .NET diagnostics tool to
2026.09.18. - Architecture documentation corrected: clarified that NeOS supports x86_64 only, matching the shipped profile and architecture audit.
- Security and CI maintenance: documented the recent hardening, release-tagging, and SourceForge publishing updates.
- Documentation drift corrected: README and CONTRIBUTING no longer claim CI builds on
main(it triggers ontesting), the README's offline-install claim now states the condition under which it holds, ADR 0006 names the shippednvidia-open-dkmspackage and points at the real size gate, and the Handbook's clone URL, build command andprofile/paths were corrected. - Archived audits marked superseded:
docs/archive/DEEP_AUDIT.mdanddocs/archive/ISO_BUILD_FIX.mdcarry banners noting that theirDatabaseRequiredclaim no longer matches the shipped configuration. - CI permissions scoped per job (
build-iso.yml): the workflow is read-only by default and thebuildjob opts intocontents: writeonly for release creation. - ShellCheck coverage widened: scripts are selected by shebang rather than
*.sh, so the extensionless privileged scripts inprofile/airootfs/usr/local/bin/are now linted (67 scripts, up from 51).
Fixed
tools/gen-install-repo.shaborted every local build:((CACHED_COUNT++)),((REUSED_COUNT++))and((CLEANED++))were standalone statements underset -e, and a post-increment returns the pre-increment value — so the first increment from 0 returned status 1 and terminated the script. Sincebuild.shcalls it unguarded behind anERRtrap,sudo ./build.shdied at the offline-repo step on every normal build. Converted to assignment form.- Online installs preferred unverified packages:
neos-pacstrapprepended an unsignedSigLevel = Optional TrustAlllocal repo above/etc/pacman.conf, and pacman takes a package from the first repo that provides it — so a stale, unverified copy from the boot medium outranked the signed current package from the mirrors. The local repo is now offline-only, matching the script's documented "always latest" contract for online mode. - ShellCheck findings in two privileged scripts: quoting in
neos-driver-manager's exit trap (SC2016/SC2064), and inneos-operations-hubfive indirect$?checks (SC2181), two trap expansions (SC2064) and an unquoteddbus-sendcommand substitution (SC2046/SC2086).
Added
- Regression guard for bare arithmetic increments:
tests/verify_shell_arithmetic.shscans every shell script for standalone((VAR++))/((VAR--)), which abort aset -escript on the first increment from 0. Verified to match the buggy forms and to ignoreif ((i++)),((i++)) || trueandVAR=$((VAR+1)). - ISO size release gate:
tests/verify_iso_size.shenforces the 2048 MiB budget that README,profiledef.sh, PERFORMANCE.md and ADR 0006 all describe as enforced but nothing actually checked. Runs in CI's Validate ISO step; override withMAX_ISO_MIB. - Dependabot configuration: weekly updates for GitHub Actions plus the Cargo and Go toolchain modules, so the floating action tags used by the release workflow stay current and visible.
- Project knowledge graph in
graphify-out/: 372 nodes, 422 edges, 77 communities over all code and documentation, with god nodes, cohesion scores and an integrity diagnostic. Committed deliberately;.gitignorepreviously excluded it. - Deep audit report:
reports/v2026.09.18/AUDIT_AND_RECOMMENDATIONS.mddocuments the findings above, the fixes applied, what was deliberately left alone, and four open decisions (offline-repo vs size budget, build-path unification, real toolchain gates, boot/install verification).