Everything paradox 0.2 does, what you type to make it do it, and an honest list of what it can't do yet.
This is an archived handbook. It documents paradox 0.2, which is no longer
the current version, and it will not be edited again — so that anyone still running
0.2 has documentation matching the software in front of them. An offline copy will ship inside the system — paradox help and
/usr/share/doc/paradox/handbook.txt — alongside the first image.
paradox is a Linux distribution built with the Linux From Scratch method — every package compiled from upstream source rather than pulled from another distribution's archive. There is no Debian, no Arch and no Red Hat underneath it.
You need:
What you will not need is patience for a graphical installer, because there isn't one yet. Read the next section before you plan an evening around this.
There is no ISO for 0.2. No installer image has been built for any release so far. Every paradox machine in existence was created by cloning an existing disk, which is not something you can do without already having one.
This is the honest state of the project: the system boots, runs and updates itself, but the part that gets it onto your hardware hasn't been written. ISO tooling is the next major piece of work. When images exist they will appear on the download page, with checksums, and this section will be replaced with real instructions.
If you are reading this because you already have a paradox machine in front of you, skip to the next section.
paradox boots UEFI through GRUB, with the boot menu embedded directly in
BOOTX64.EFI. There is no initramfs — the kernel finds the root filesystem
by PARTUUID on its command line, which is why the cmdline reads
root=PARTUUID=… rather than the more usual filesystem UUID.
Boot is quiet by design (quiet loglevel=3). You will see very little
before the login prompt, and that is intentional rather than a sign something stalled.
What you get at the console:
paradox linux (aurora)
Kernel 6.18.10 on an x86_64 (tty1)
paradox login: pdxadmin
Password:
reality is optional
aurora · 0.2
pdxadmin@paradox:~$
Log in as pdxadmin. The mirror banner prints, and you land at a shell.
Section five covers the account and what to change about it immediately.
The system identifies itself in /etc/os-release, which reads
VERSION="0.2 (aurora)" — worth checking if you are unsure which release a
machine is running, since paradox-info and the banner both read from
elsewhere.
Every colour in paradox is deliberate. The rule the theme follows: the colours that tell you who you are are kept separate from the colours that tell you what a file is, so nothing is ambiguous at a glance. The hostname is blue rather than cyan specifically so it never gets confused with a directory.
Root and a normal user differ in exactly one way — the username colour. Yellow means you are root and should be paying attention.
pdxadmin@paradox:~$ whoami pdxadmin root@paradox:~# whoami root
ls is aliased to always use colour. The palette is the "aurora spectrum":
root@paradox:~# ls script.sh test_folder test.txt backup.tar.xz wallpaper.png
The MOTD is the wordmark, a divider, and the wordmark reflected and dimmed beneath it — which way is up. The banner is bright cyan and its reflection a dimmer cyan, reality is optional sits below in yellow, and the release line reads aurora in magenta beside the version in white.
Search matches highlight in magenta. nano is themed to match — cyan title bar with white text, cyan line numbers, bright cyan shortcut keys — and comes configured with line numbers, syntax highlighting, soft wrap, auto-indent, and 4-space tabs that insert spaces.
The Linux text console can only display 16 colours. The prompt and banner are written in 16-colour codes so they are exact, but the file listing palette uses 256-colour codes and will look approximate on the console. Over SSH or in a graphical terminal you see the real thing.
The default account is pdxadmin, uid 1000, password paradox.
It belongs to the wheel group, which is what grants sudo.
Change that password before the machine is on a network you don't control. It is published in this handbook, which means it is not a secret.
pdxadmin@paradox:~$ passwd Changing password for pdxadmin. Current password: New password:
Administrative commands go through sudo, which asks for your password
every time — there is no passwordless drop-in, and attempts to add one have not taken
effect. Root exists as a separate account with its own password set during the build.
Software is managed with paradox, a wrapper over the pacman package
engine (7.1.0 / libalpm 16.0.0). The verbs are themed; plain synonyms work identically.
Any extra arguments pass straight through to pacman.
| command | does | plain form |
|---|---|---|
| paradox glitch <pkg> | install a package | install |
| paradox collapse <pkg> | remove a package and its orphaned dependencies | remove |
| paradox shift | sync the database and upgrade everything | update / upgrade |
| paradox refresh | refresh the package database only | sync |
| paradox seek <term> | search the repository | search |
| paradox info <pkg> | show package details | — |
| paradox list | list installed packages | — |
| paradox help | print the menu | -h / --help |
Packages are served from a self-hosted repository at
repo.paradoxlinux.com, backed by Cloudflare R2. Packages arrive as
.pkg.tar.zst archives, each with a detached GPG signature, and
SigLevel = Required means an unsigned or badly signed package is refused
rather than installed.
The public key is published at
repo.paradoxlinux.com/paradox-linux.gpg. Verify it against the fingerprint
before trusting it:
0956915D16CAA24FD62E 8750 2D94 217B AAB7 6E21 0956 915D 16CA A24Fparadoxadmin <paradoxlinuxadmin@gmail.com>The private key lives only on the build host and is never shipped in the system.
root@paradox:~# paradox seek paradox paradox/paradox-info 0.1-1 root@paradox:~# paradox glitch paradox-info resolving dependencies... Proceed with installation? [Y/n] ✓ paradox-info 0.1-1 installed root@paradox:~# paradox list paradox-info 0.1-1
The catalogue currently contains exactly one package. The mechanism is proven end-to-end — built, signed, published, downloaded, verified, installed — but there is very little in it yet.
The first published package is a system information tool in the house style:
paradox paradox linux (aurora) host paradox kernel 6.18.10 uptime 1 day, 4 hours, 56 minutes cpu Intel(R) Celeron(R) J4125 CPU @ 2.00GHz mem 183Mi / 7.6Gi disk 4.7G / 117G (5%) pkgs 1 shell bash
"No bloat" is only useful if you know what you actually have. This is the tour.
nano 9.1, and only nano. vim is not installed. If you are a vi person this will be the first thing you notice and the first thing you want to fix — which, in 0.2, you can do through the package manager once someone builds a vim package.
One package is installed from the repository: paradox-info 0.1-1. Because the base system was hand-compiled rather than installed from packages, paradox list shows only this — it is not a list of everything on the machine.
No desktop, no display server, no audio stack, no Bluetooth, no printing, no Wi-Fi tooling, no firewall configured yet, and no vim. Nothing runs that you did not start.
Wired ethernet with DHCP works. Wi-Fi does not exist. There is no iwd and no wireless firmware in the image, so a laptop with no ethernet port cannot get online.
Addresses come from systemd-networkd via
/etc/systemd/network/10-eth-dhcp.network, and name resolution goes through
systemd-resolved.
pdxadmin@paradox:~$ ip a 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> inet 192.168.1.42/24 … pdxadmin@paradox:~$ ping -c1 paradoxlinux.com
CA certificates are installed at /etc/ssl/certs/ca-certificates.crt, so curl, wget and the package manager can all validate TLS. This matters more than it sounds: without them, HTTPS requests fail in ways that look like network problems rather than certificate problems.
paradox runs systemd, so services and logs behave the way they do on any modern distribution. Twenty-six unit files are enabled at boot, and only a handful of them are paradox's own choices rather than systemd defaults.
The rest are systemd's own presets: oomd, pstore, sysext, confext, udev credentials, the journald audit socket and friends.
pdxadmin@paradox:~$ systemctl status sshd pdxadmin@paradox:~$ systemctl list-unit-files --state=enabled pdxadmin@paradox:~$ journalctl -b -p err pdxadmin@paradox:~$ sudo systemctl poweroff
Kept current for every release, because finding this out at eleven at night is worse than reading it now.
Things that have actually caught someone out.
root=PARTUUID=…. Using the filesystem UUID drops you to a kernel panic.rootwait — USB enumeration is slower than the kernel's patience.part_gpt, ext2, gzio and search_fs_uuid included.paradox glitch stalls at ldconfig while it rebuilds the linker cache, and again while the GPG agent starts for the first verification. It is slow exactly once. Let it finish./var/lib/pacman/local and /var/cache/pacman/pkg it fails with could not find or read directory./var/lib/pacman/db.lck; delete it before retrying./etc/ssl is missing, downloads fail in ways that look like the network is down./usr/bin/paradox — the package manager wrapper/usr/bin/paradox-info — the system information tool/etc/bashrc — the prompt, LS_COLORS, GREP_COLORS and the aliases/etc/motd — the mirror banner/etc/nanorc — the nano theme and behaviour/etc/os-release — version and identity/etc/pacman.conf — repositories and signature policy/etc/makepkg.conf — package build settings/etc/pacman.d/gnupg — the trusted keyring/var/lib/pacman and /var/cache/pacman/pkg — package database and cache/etc/systemd/network/10-eth-dhcp.network — the wired connection/etc/ssl/certs/ca-certificates.crt — the CA bundle/etc/fstab — root by filesystem UUID with noatime, ESP at /boot/efiGPT with two partitions: a FAT EFI system partition and an ext4 root. The kernel
command line is
root=PARTUUID=… rootwait ro quiet loglevel=3.
The release where the package manager became real. The repository at
repo.paradoxlinux.com went live on Cloudflare R2, the public signing key
was published, and the first signed package was built, uploaded, downloaded, verified
and installed end-to-end on a machine that had nothing to do with building it.
paradox-info 0.1-1.pkg.tar.zstfakeroot added to the build toolchain/etc/os-release was missedUnchanged from 0.1: the kernel, the boot method, the partition layout, the users, the enabled services, the colour theme and the nano configuration.
The first bootable state. Base LFS with systemd, the console theme, SSH and sudo, and a package manager with nowhere to fetch from.
Previous versions → — every release, its handbook, and whether an image exists