Features
Features
What makes Runink River different from a general-purpose desktop distribution, one page per feature. Each page says what exists today and marks what is still planned.
s6, s6-rc and s6-linux-init. Never systemd.
zen 7.2.x stable, verified sources, a data-work profile.
Encrypted ZFS root, boot environments, shadow-grade file modes.
Default-deny nftables for IPv4 and IPv6.
bubblewrap confinement for code you do not trust.
Measure, plan, confirm by serial, install.
river-guide: grounded answers, no network needed.
The design rules behind them
Every change to Runink River keeps a short list of invariants, written down in
AGENTS.md. Changing one needs a vote of the technical steering committee
(Governance). The ones a user notices:
- s6, never systemd.
- Exactly one kernel,
linux-runink, with OpenZFS as a separate module package. - ZFS root, encrypted. Never a dataset with
encryption=off. - Secrets are handled like
/etc/shadow: 0600 files in 0700 directories, and no secret or key ever baked into an image. - Untrusted code runs under
river-sandbox. - Every upstream is pinned by version and checksum, and by signature where the upstream signs.