Skip to content

Features

What makes Runink River different from a general-purpose desktop distribution, one page per feature. Each page says what exists today and marks what is still planned.

The design rules behind them

Every change to Runink River keeps a short list of invariants, written down in AGENTS.md. Changing one needs a vote of the technical steering committee (Governance). The ones a user notices:

  1. s6, never systemd.
  2. Exactly one kernel, linux-runink, with OpenZFS as a separate module package.
  3. ZFS root, encrypted. Never a dataset with encryption=off.
  4. Secrets are handled like /etc/shadow: 0600 files in 0700 directories, and no secret or key ever baked into an image.
  5. Untrusted code runs under river-sandbox.
  6. Every upstream is pinned by version and checksum, and by signature where the upstream signs.