paradox / handbook / 0.1

the paradox handbook

Everything paradox 0.1 does, what you type to make it do it, and an honest list of what it can't do yet.

documents aurora · 0.1 archived · superseded by 0.2 · 13 sections · offline copy ships with the first image

This is an archived handbook. It documents paradox 0.1, which is no longer the current version. If your machine reports 0.2 or newer, read the current handbook instead. This one is kept, and will not be edited again, so that anyone still running 0.1 has documentation that matches the software actually in front of them.

01 · before you start

paradox is a Linux distribution built with the Linux From Scratch method — every package compiled from upstream source rather than pulled from another distribution's archive. There is no Debian, no Arch and no Red Hat underneath it.

You need:

  • An x86_64 machine with UEFI firmware
  • Secure Boot turned off — the bootloader is self-signed and firmware will refuse it otherwise
  • A wired ethernet connection — Wi-Fi is not supported in 0.1
  • A few GB of disk

What you will not need is patience for a graphical installer, because there isn't one yet. Read the next section before you plan an evening around this.

02 · getting it running

There is no ISO for 0.1. No installer image has been built for any release so far. Every paradox machine in existence was created by cloning an existing disk, which is not something you can do without already having one.

This is the honest state of the project: the system boots, runs and updates itself, but the part that gets it onto your hardware hasn't been written. ISO tooling is the next major piece of work. When images exist they will appear on the download page, with checksums, and this section will be replaced with real instructions.

If you are reading this because you already have a paradox machine in front of you, skip to the next section.

03 · first boot

paradox boots UEFI through GRUB, with the boot menu embedded directly in BOOTX64.EFI. There is no initramfs — the kernel finds the root filesystem by PARTUUID on its command line, which is why the cmdline reads root=PARTUUID=… rather than the more usual filesystem UUID.

Boot is quiet by design (quiet loglevel=3). You will see very little before the login prompt, and that is intentional rather than a sign something stalled.

What you get at the console:

tty1 — first login●
paradox linux (aurora)
Kernel 6.18.10 on an x86_64 (tty1)

paradox login: pdxadmin
Password:

reality is optional

aurora · 0.1

pdxadmin@paradox:~$  

Log in as pdxadmin. The mirror banner prints, and you land at a shell. Section five covers the account and what to change about it immediately.

The system identifies itself in /etc/os-release, which reads VERSION="0.1 (aurora)" — worth checking if you are unsure which release a machine is running, since paradox-info and the banner both read from elsewhere.

04 · the prompt and the colours

Every colour in paradox is deliberate. The rule the theme follows: the colours that tell you who you are are kept separate from the colours that tell you what a file is, so nothing is ambiguous at a glance. The hostname is blue rather than cyan specifically so it never gets confused with a directory.

the prompt

Root and a normal user differ in exactly one way — the username colour. Yellow means you are root and should be paying attention.

who and where●
pdxadmin@paradox:~$ whoami
pdxadmin

root@paradox:~# whoami
root
  • magenta username — a normal user
  • yellow username — root
  • gray — the separator
  • blue — the hostname
  • white — where you are

file listings

ls is aliased to always use colour. The palette is the "aurora spectrum":

  • cyan — directories
  • teal — symlinks
  • green — executables
  • amber — archives and compressed files
  • pink — images
  • orange — audio
  • violet — video
  • gold — code and config
a listing●
root@paradox:~# ls
script.sh   test_folder   test.txt   backup.tar.xz   wallpaper.png

the login banner

The MOTD is the wordmark, a divider, and the wordmark reflected and dimmed beneath it — which way is up. The banner is bright cyan and its reflection a dimmer cyan, reality is optional sits below in yellow, and the release line reads aurora in magenta beside the version in white.

grep and nano

Search matches highlight in magenta. nano is themed to match — cyan title bar with white text, cyan line numbers, bright cyan shortcut keys — and comes configured with line numbers, syntax highlighting, soft wrap, auto-indent, and 4-space tabs that insert spaces.

one thing to know about colour

The Linux text console can only display 16 colours. The prompt and banner are written in 16-colour codes so they are exact, but the file listing palette uses 256-colour codes and will look approximate on the console. Over SSH or in a graphical terminal you see the real thing.

05 · users and sudo

The default account is pdxadmin, uid 1000, password paradox. It belongs to the wheel group, which is what grants sudo.

Change that password before the machine is on a network you don't control. It is published in this handbook, which means it is not a secret.

first thing you should do●
pdxadmin@paradox:~$ passwd
Changing password for pdxadmin.
Current password:
New password:

Administrative commands go through sudo, which asks for your password every time — there is no passwordless drop-in, and attempts to add one have not taken effect. Root exists as a separate account with its own password set during the build.

06 · packages

Software is managed with paradox, a wrapper over the pacman package engine (7.1.0 / libalpm 16.0.0). The verbs are themed; plain synonyms work identically. Any extra arguments pass straight through to pacman.

commanddoesplain form
paradox glitch <pkg>install a packageinstall
paradox collapse <pkg>remove a package and its orphaned dependenciesremove
paradox shiftsync the database and upgrade everythingupdate / upgrade
paradox refreshrefresh the package database onlysync
paradox seek <term>search the repositorysearch
paradox info <pkg>show package details—
paradox listlist installed packages—
paradox helpprint the menu-h / --help

the honest part

In 0.1 there is nothing to install. The engine, the wrapper, the signing key and the configuration all exist, but the [paradox] repository section is a stub with no reachable server. paradox help prints the menu; paradox glitch and paradox seek fail or return nothing.

This is the defining gap of 0.1 and the thing 0.2 fixes.

signing

The signing key exists — rsa4096, paradoxadmin, key id 0956915D16CAA24F — and the private half never leaves the build host. It is not used for anything in 0.1 because there is no repository to sign.

07 · what's installed

"No bloat" is only useful if you know what you actually have. This is the tour.

the toolchain

  • glibc 2.43 · gcc 15.2.0 · binutils 2.46
  • kernel 6.18.10, x86_64
  • systemd as init · bash as the shell · GRUB as the bootloader

the everyday commands

  • files and text — ls, cp, mv, rm, cat, grep, sed, awk, find, sort, head, tail, cut, tr, wc and the rest of GNU coreutils
  • archives — tar, gzip, xz, bzip2, zstd
  • network — ip, ping, curl 8.21.0, wget 1.25.0, ssh and scp (OpenSSH 10.5p1)
  • system — systemctl, journalctl, sudo 1.9.17p2, mount, umount
  • maths and docs — bc, man-db, groff 1.23.0

the editor

nano 9.1, and only nano. vim is not installed. If you are a vi person this will be the first thing you notice and the first thing you want to fix — which, in 0.2, you can do through the package manager once someone builds a vim package.

under the package manager

  • pacman 7.1.0 with libalpm 16.0.0, linked against gpgme, libarchive and libcurl
  • libarchive 3.8.9 · zstd 1.5.7
  • the GnuPG stack — gnupg 2.5.21, gpgme 2.1.2, libgcrypt 1.12.2, libgpg-error 1.61, libassuan 3.0.2, libksba 1.8.0, npth 1.8, pinentry 1.3.3
  • ca-certificates — the Mozilla bundle, without which every HTTPS request fails

what is deliberately absent

No desktop, no display server, no audio stack, no Bluetooth, no printing, no Wi-Fi tooling, no firewall configured yet, and no vim. Nothing runs that you did not start.

08 · networking

Wired ethernet with DHCP works. Wi-Fi does not exist. There is no iwd and no wireless firmware in the image, so a laptop with no ethernet port cannot get online.

Addresses come from systemd-networkd via /etc/systemd/network/10-eth-dhcp.network, and name resolution goes through systemd-resolved.

checking a connection●
pdxadmin@paradox:~$ ip a
2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP>
    inet 192.168.1.42/24 …

pdxadmin@paradox:~$ ping -c1 paradoxlinux.com

09 · services and logs

paradox runs systemd, so services and logs behave the way they do on any modern distribution. Twenty-six unit files are enabled at boot, and only a handful of them are paradox's own choices rather than systemd defaults.

  • getty@ — the console login prompt
  • sshd — remote access, enabled by default
  • systemd-networkd — the wired DHCP connection
  • systemd-resolved — DNS
  • systemd-timesyncd — clock

The rest are systemd's own presets: oomd, pstore, sysext, confext, udev credentials, the journald audit socket and friends.

the usual moves●
pdxadmin@paradox:~$ systemctl status sshd
pdxadmin@paradox:~$ systemctl list-unit-files --state=enabled
pdxadmin@paradox:~$ journalctl -b -p err
pdxadmin@paradox:~$ sudo systemctl poweroff

10 · what doesn't work

Kept current for every release, because finding this out at eleven at night is worse than reading it now.

  • Nothing can be installed. The package manager has no reachable repository. This is the defining limitation of 0.1.
  • Wi-Fi — not supported. Wired ethernet only.
  • No graphical session — console only.
  • No installer and no ISO — the only deployment method is cloning an existing disk.
  • Secure Boot must stay off — the bootloader is self-signed.
  • Audio, Bluetooth and printing — not configured. On some hardware you may see an snd_hda_intel probe message at boot; audio still isn't set up.

11 · gotchas

Things that have actually caught someone out.

booting

  • Root will not mount by filesystem UUID. There is no initramfs, so the kernel command line must use root=PARTUUID=…. Using the filesystem UUID drops you to a kernel panic.
  • Booting from USB needs rootwait — USB enumeration is slower than the kernel's patience.
  • GRUB drops to a bare prompt if it is rebuilt without part_gpt, ext2, gzio and search_fs_uuid included.
  • Secure Boot must be off or the firmware refuses the bootloader outright.

colour

  • The console and a terminal emulator do not look the same. 256-colour file listings collapse to their nearest 16-colour approximation on the text console. Nothing is broken; the console just cannot show them.

identity

  • HOME_URL in /etc/os-release points at https://paradox.linux, which is not a real domain. The site is paradoxlinux.com. Corrected in 0.2.

12 · where things live

  • /usr/bin/paradox — the package manager wrapper
  • /etc/bashrc — the prompt, LS_COLORS, GREP_COLORS and the aliases
  • /etc/motd — the mirror banner
  • /etc/nanorc — the nano theme and behaviour
  • /etc/os-release — version and identity
  • /etc/pacman.conf — repositories and signature policy
  • /etc/makepkg.conf — package build settings
  • /etc/pacman.d/gnupg — the trusted keyring
  • /var/lib/pacman and /var/cache/pacman/pkg — package database and cache
  • /etc/systemd/network/10-eth-dhcp.network — the wired connection
  • /etc/ssl/certs/ca-certificates.crt — the CA bundle
  • /etc/fstab — root by filesystem UUID with noatime, ESP at /boot/efi

the disk

GPT with two partitions: a FAT EFI system partition and an ext4 root. The kernel command line is root=PARTUUID=… rootwait ro quiet loglevel=3.

13 · version history

0.1 · aurora

The first bootable state. Base LFS with systemd, the console theme, SSH and sudo, the pdxadmin account, and the package manager engine built but not yet connected to anything.

All versions →