paradox / handbook / 0.3

the paradox handbook

Everything paradox 0.3 does, what you type to make it do it, and an honest list of what it can't do yet.

documents aurora · 0.3 archived · superseded by 0.4 · 14 sections · offline copy ships with the first image

This is an archived handbook. It documents paradox 0.3, which is no longer the current version, and it will not be edited again — so that anyone still running 0.3 has documentation matching the software in front of them.

01 · before you start

paradox is a Linux distribution built with the Linux From Scratch method — every package compiled from upstream source rather than pulled from another distribution's archive. There is no Debian, no Arch and no Red Hat underneath it.

You need:

  • An x86_64 machine with UEFI firmware
  • Secure Boot turned off — the bootloader is self-signed and firmware will refuse it otherwise
  • A network connection — wired or Wi-Fi, both now work new in 0.3
  • Around 4.3 GB of disk for the base system and its firmware

paradox is built to run on old hardware and new. The base is compiled so that performance-critical libraries detect the processor at runtime and take the fast path where the hardware allows and a safe one where it doesn't — so a decade-old Celeron and a current Ryzen both run the same image without one of them crashing. new in 0.3

02 · getting it running

There is still no ISO. No installer image has been built for any release so far, and every paradox machine in existence was made by cloning an existing disk. ISO tooling is the next major piece of work — the kernel now carries the squashfs, overlayfs and loop support a live image needs new in 0.3, so the groundwork is in place, but the image itself does not exist yet.

For scale, when images do appear: the base system is roughly 3.6 GB installed, and the networking firmware adds about another 677 MB. A compressed server image should land somewhere around 1.4–1.7 GB.

If you already have a paradox machine in front of you, carry on to the next section.

03 · first boot

paradox boots UEFI through GRUB. There is no initramfs — the kernel finds the root filesystem by PARTUUID on its command line, which is why the cmdline reads root=PARTUUID=… rather than the more usual filesystem UUID.

The boot menu is now an editable file at /boot/grub/grub.cfg rather than being baked into the EFI binary. new in 0.3 The EFI stub is a small redirector that points at it, which means changing a boot entry no longer means rebuilding the bootloader.

The kernel is 6.18.10-pdx, built for paradox with the networking, firewall and filesystem support the system relies on. new in 0.3

Boot is quiet by design (quiet loglevel=3). You will see very little before the login prompt, which is intentional rather than a sign something stalled.

tty1 — first login●
paradox linux (aurora)
Kernel 6.18.10-pdx on an x86_64 (tty1)

paradox login: pdxadmin
Password:

reality is optional

aurora · 0.3

pdxadmin@paradox:~$  

Log in as pdxadmin. The mirror banner prints and you land at a shell. The system identifies itself in /etc/os-release, which reads VERSION="0.3 (aurora)" — the reliable place to check which release a machine is running.

04 · the prompt and the colours

Every colour in paradox is deliberate. The rule the theme follows: the colours that tell you who you are stay separate from the colours that tell you what a file is, so nothing is ambiguous at a glance. The hostname is blue rather than cyan specifically so it is never mistaken for a directory.

the prompt

Root and a normal user differ in exactly one way — the username colour. Yellow means you are root and should be paying attention.

who and where●
pdxadmin@paradox:~$ whoami
pdxadmin

root@paradox:~# whoami
root
  • magenta username — a normal user
  • yellow username — root
  • gray — the separator
  • blue — the hostname
  • white — where you are

file listings

ls is aliased to always use colour. The palette is the "aurora spectrum":

  • cyan — directories
  • teal — symlinks
  • green — executables
  • amber — archives and compressed files
  • pink — images
  • orange — audio
  • violet — video
  • gold — code and config
a listing●
root@paradox:~# ls
script.sh   test_folder   test.txt   backup.tar.xz   wallpaper.png

the login banner

The MOTD is the wordmark, a divider, and the wordmark reflected and dimmed beneath it — which way is up. The banner is bright cyan and its reflection a dimmer cyan, reality is optional sits below in yellow, and the release line reads aurora in magenta beside the version in white.

grep and nano

Search matches highlight in magenta. nano is themed to match — cyan title bar with white text, cyan line numbers, bright cyan shortcut keys — and comes configured with line numbers, syntax highlighting, soft wrap, auto-indent, and 4-space tabs that insert spaces.

one thing to know about colour

The Linux text console can only display 16 colours. The prompt and banner are written in 16-colour codes so they are exact, but the file listing palette uses 256-colour codes and will look approximate on the console. Over SSH or in a graphical terminal you see the real thing.

05 · users and sudo

The default account is pdxadmin, uid 1000, password paradox. It belongs to the wheel group, which is what grants sudo.

Change that password before the machine is on a network you don't control. It is published in this handbook, which means it is not a secret.

first thing you should do●
pdxadmin@paradox:~$ passwd
Changing password for pdxadmin.
Current password:
New password:

Administrative commands go through sudo, which asks for your password every time. The paradox- tools are run as your normal user — they ask for your password themselves at the point they need it, rather than requiring you to remember to prefix them.

06 · getting online

Wi-Fi works. new in 0.3 This is the headline of 0.3 and the thing that changes what paradox can be installed on — a laptop with no ethernet port is no longer a dead end.

Two commands cover almost everything. Both are run as your normal user, both figure out the hardware themselves, and both ask for your password only when they are about to change something.

paradox-wifi new in 0.3

Run it with no arguments and it scans, lists what it found, and connects to whichever you pick. A network marked psk asks for its passphrase — typed blind, nothing echoes back. Networks marked open connect straight away.

Once you have joined a network it is saved, so it reconnects on its own after a reboot and will not ask again.

connecting to Wi-Fi●
pdxadmin@paradox:~$ paradox-wifi
↻ paradox-wifi scanning the airwaves on wlan0…

  1  aurora-5G            psk    ●●●●  (connected)
  2  aurora               psk    ●●●●
  3  nebula-guest         psk    ●●●
  4  quasar_lab           open   ●●●
  5  pulsar-2G            psk    ●●
  6  corona_house         psk    ●●

pick a network [1-6]  (q to quit): 3
↻ paradox-wifi connecting to nebula-guest…
Passphrase for nebula-guest: (hidden)
✓ connected to nebula-guest

radio    wlan0
state    connected
network  nebula-guest
ip       192.168.10.36/24

The other things it does:

  • paradox-wifi status — radio, state, network and address
  • paradox-wifi --disconnect — drop the current connection but keep the network saved, so it reconnects next boot
  • paradox-wifi --forget-networks — erase every saved network, so the machine stops connecting on its own

Underneath it is iwd, which runs its own DHCP client — there is no separate DHCP daemon to configure or fight with.

paradox-wired new in 0.3

Wired ethernet uses DHCP out of the box and needs no attention. When you want a fixed address — which on a machine running SSH you usually do — paradox-wired walks through it and writes the systemd-networkd configuration for you.

setting a static address●
pdxadmin@paradox:~$ paradox-wired
  1  enp2s0        down
  2  enp3s0        up  192.168.10.107/24

pick a nic [1-2] (q to quit): 1
✎ paradox-wired static ip on enp2s0
ip address        : 192.168.10.10
subnet (24 or mask) : 24
gateway (blank=none): 192.168.10.254
dns, comma-separated: 1.1.1.1,8.8.8.8

will write /etc/systemd/network/00-paradox-enp2s0.network:
    [Match]
    Name=enp2s0

    [Network]
    Address=192.168.10.10/24
    Gateway=192.168.10.254
    DNS=1.1.1.1
    DNS=8.8.8.8

… if enp2s0 is the link you're on, this can drop
  the session — reconnect on the new address.
apply this? [y/N] y
[paradox] password for pdxadmin:
✓ applied static 192.168.10.10/24 on enp2s0
  • paradox-wired status — list the wired interfaces and their addresses
  • paradox-wired --dhcp — hand a port back to automatic addressing

Read the warning it prints before answering yes. If you are connected over the port you are reconfiguring, applying the change drops your session and you reconnect on the new address — worth thinking about before doing this remotely over the only link you have.

firmware new in 0.3

The base ships firmware for the common Wi-Fi families — Intel, Atheros, Realtek, Broadcom, MediaTek and Marvell — along with wired NIC blobs, Bluetooth, Intel graphics and the wireless regulatory database, so most machines get online without hunting for anything. It is about 677 MB, and it is the reason a from-scratch distribution can be plug-and-play at all.

Everything else upstream ships — AMD and Nvidia graphics, server SmartNICs, audio and SoC firmware — is available as linux-firmware-extra in the repository rather than sitting unused in every install.

07 · the firewall

paradox now comes up firewalled on every boot. new in 0.3 The policy is default-drop on input: unless a rule allows it, incoming traffic is discarded.

What is allowed:

  • Replies to connections you started (established and related traffic)
  • Loopback — the machine talking to itself
  • ICMP, so ping and path discovery work
  • SSH on port 22

Outbound traffic is unrestricted, and forwarding is off.

checking the firewall●
pdxadmin@paradox:~$ systemctl status nftables
   Loaded: loaded (nftables.service; enabled)
   Active: active (exited)

pdxadmin@paradox:~$ sudo nft list ruleset

the part that will catch you out

Default-drop means anything you host yourself is unreachable until you say otherwise. Start a web server, a game server or a database, connect from another machine, and it will simply hang — the service is running fine, the firewall is discarding the packets before they arrive.

Rules live in /etc/nftables.conf. Add a port alongside the existing SSH line, then reload:

opening a port●
pdxadmin@paradox:~$ sudo nano /etc/nftables.conf
        tcp dport 22 accept
        tcp dport 8080 accept

# check it parses before loading
pdxadmin@paradox:~$ sudo nft -c -f /etc/nftables.conf
pdxadmin@paradox:~$ sudo systemctl restart nftables

Check the file with nft -c -f before loading it. A syntax error in a firewall you are editing over SSH is a bad way to end an evening.

08 · packages

Software is managed with paradox, a wrapper over the pacman package engine. The verbs are themed; plain synonyms work identically, and any extra arguments pass straight through.

commanddoesplain form
paradox glitch <pkg>install a packageinstall
paradox collapse <pkg>remove a package and its orphaned dependenciesremove
paradox shiftsync the database and upgrade everythingupdate / upgrade
paradox refreshrefresh the package database onlysync
paradox seek <term>search the repositorysearch
paradox info <pkg>show package details—
paradox listlist installed packages—
paradox helpprint the menu-h / --help

where packages come from

Packages are served from a self-hosted repository at repo.paradoxlinux.com, backed by Cloudflare R2. Each arrives as a .pkg.tar.zst archive with a detached GPG signature, and SigLevel = Required means an unsigned or badly signed package is refused rather than installed.

The public key is published at repo.paradoxlinux.com/paradox-linux.gpg. Verify it against the fingerprint before trusting it:

  • key id 0956915D16CAA24F
  • fingerprint D62E 8750 2D94 217B AAB7 6E21 0956 915D 16CA A24F
  • owner paradoxadmin <paradoxlinuxadmin@gmail.com>

The private key lives only on the build host and is never shipped in the system.

the catalogue new in 0.3

Eighteen signed packages, up from one in 0.2. Everything is built from source with its own PKGBUILD rather than repackaged from elsewhere.

installing something●
pdxadmin@paradox:~$ paradox seek tmux
paradox/tmux 3.5a-1

pdxadmin@paradox:~$ paradox glitch tmux
resolving dependencies...
Proceed with installation? [Y/n]
✓ tmux 3.5a-1 installed

Downloads now go through curl rather than pacman's own sandboxed downloader, which was unreliable on some hardware — a change you will not notice except that transfers stop hanging. new in 0.3

09 · what's installed

"No bloat" is only useful if you know what you actually have. This is the tour.

the toolchain

  • glibc 2.43 · gcc 15.2.0 · binutils 2.46
  • kernel 6.18.10-pdx — the custom paradox build new in 0.3
  • systemd as init · bash as the shell · GRUB as the bootloader

the everyday commands

  • files and text — ls, cp, mv, rm, cat, grep, sed, awk, find, sort, head, tail, cut, tr, wc and the rest of GNU coreutils
  • archives — tar, gzip, xz, bzip2, zstd
  • network — ip, ping, curl, wget, ssh and scp
  • system — systemctl, journalctl, sudo, mount, umount
  • maths and docs — bc, man-db, groff

the comfort catalogue new in 0.3

Everyday tools that used to be missing now build as signed packages and ship in the base:

  • tmux — keep a session alive when SSH drops
  • htop — see what is using the machine
  • less — read long output without fighting it
  • rsync — move files properly
  • git — the obvious one
  • jq — read JSON without regret

networking and security new in 0.3

  • iwd with ell — the Wi-Fi daemon, running its own DHCP
  • nftables — the firewall, live at every boot
  • linux-firmware — the lean networking set, about 677 MB
  • paradox-wifi and paradox-wired — the in-house network tools

the editor

nano, and only nano. vim is not installed. If you are a vi person that is the first thing you will want to change — and now that the repository has eighteen packages in it, building one is a reasonable request rather than a project.

under the package manager

  • pacman 7.1.0 with libalpm 16.0.0
  • libarchive · zstd
  • the GnuPG stack — gnupg, gpgme, libgcrypt and friends, for signature checking
  • ca-certificates — the Mozilla bundle, without which every HTTPS request fails

what is deliberately absent

No desktop, no display server, no audio stack, no printing, and no vim. Bluetooth firmware is present but nothing is configured to use it. Nothing runs that you did not start.

10 · services and logs

paradox runs systemd, so services and logs behave the way they do on any modern distribution. Only a handful of the enabled units are paradox's own choices rather than systemd defaults.

  • getty@ — the console login prompt
  • sshd — remote access, enabled by default
  • systemd-networkd — wired connections
  • systemd-resolved — DNS
  • systemd-timesyncd — clock
  • iwd — Wi-Fi new in 0.3
  • nftables — the firewall, loaded before networking comes up new in 0.3

The rest are systemd's own presets: oomd, pstore, sysext, confext, udev credentials and the journald sockets.

the usual moves●
pdxadmin@paradox:~$ systemctl status sshd
pdxadmin@paradox:~$ systemctl list-unit-files --state=enabled
pdxadmin@paradox:~$ journalctl -b -p err
pdxadmin@paradox:~$ journalctl -u iwd -f
pdxadmin@paradox:~$ sudo systemctl poweroff

11 · what doesn't work

Kept current for every release, because finding this out at eleven at night is worse than reading it now.

  • No graphical session — console only. This is the next big piece of work.
  • No installer and no ISO — deployment is still a manual disk clone.
  • Secure Boot must stay off — the bootloader is self-signed.
  • Audio — no sound stack is configured.
  • Bluetooth — the firmware is present, but nothing is set up to use it.
  • Printing — not configured.

12 · gotchas

Things that have actually caught someone out.

networking new in 0.3

  • Self-hosted services are unreachable until you open a port. The firewall drops anything it was not told to allow, and a blocked port looks exactly like a broken service. See section seven.
  • Reconfiguring the link you are connected over drops the connection. paradox-wired warns you before it applies. On a machine with Wi-Fi as well, the wireless connection stays up as a way back in.
  • A disconnected Wi-Fi network still reconnects on boot. --disconnect keeps the network saved on purpose. Use --forget-networks if you want it gone.

booting

  • Root will not mount by filesystem UUID. There is no initramfs, so the kernel command line must use root=PARTUUID=….
  • Booting from USB needs rootwait — USB enumeration is slower than the kernel's patience.
  • Secure Boot must be off or the firmware refuses the bootloader outright.

packages

  • Interrupting an install leaves a lock behind. Ctrl-C during a package operation leaves /var/lib/pacman/db.lck; delete it before retrying.
  • The first install after a large system update is slow, once. It stalls rebuilding the linker cache and starting the GPG agent. It is not stuck.
  • TLS fails silently without CA certificates. If /etc/ssl goes missing, downloads fail in ways that look like the network is down.

colour

  • The console and a terminal emulator do not look the same. 256-colour file listings collapse to their nearest 16-colour approximation on the text console. Nothing is broken; the console just cannot show them.

13 · where things live

  • /usr/bin/paradox — the package manager wrapper
  • /usr/bin/paradox-info — system information
  • /usr/bin/paradox-wifi · /usr/bin/paradox-wired — the network tools new in 0.3
  • /etc/bashrc — the prompt, LS_COLORS, GREP_COLORS and the aliases
  • /etc/motd — the mirror banner
  • /etc/nanorc — the nano theme and behaviour
  • /etc/os-release — version and identity
  • /etc/pacman.conf — repositories and signature policy
  • /etc/nftables.conf — the firewall ruleset new in 0.3
  • /etc/iwd/main.conf — Wi-Fi daemon configuration new in 0.3
  • /var/lib/iwd/ — saved wireless networks new in 0.3
  • /etc/systemd/network/ — wired configuration; paradox-wired writes 00-paradox-<nic>.network here new in 0.3
  • /boot/grub/grub.cfg — the editable boot menu new in 0.3
  • /etc/ssl/certs/ca-certificates.crt — the CA bundle
  • /etc/fstab — root by filesystem UUID with noatime, ESP at /boot/efi

the disk

GPT with two partitions: a FAT EFI system partition and an ext4 root. The kernel command line is root=PARTUUID=… rootwait ro quiet loglevel=3.

14 · version history

0.3 · aurora current

The release where paradox learned to get online anywhere. A rebuilt kernel brought the networking stack to life, Wi-Fi works end to end, a firewall comes up at every boot, and the base was made portable enough to run on old processors as well as new ones.

  • Custom kernel 6.18.10-pdx, built for the hardware paradox actually runs on
  • Wi-Fi via iwd, tested on real hardware, with saved networks persisting across reboots
  • paradox-wifi and paradox-wired — in-house network tools
  • nftables firewall, default-drop, loaded before networking
  • A CPU-portable base, so an older processor no longer crashes on optimised code
  • Broad networking firmware in the base; the rest available as linux-firmware-extra
  • The comfort catalogue — tmux, htop, less, rsync, git, jq — taking the repository from one package to eighteen
  • Package downloads through curl, and an editable external boot menu

Unchanged from 0.2: the LFS method and toolchain, the partition and UUID layout, the users and groups, the init system and the colour theme apart from the version string.

0.2 · aurora

The release where the package manager became real — a live signed repository, a published key, and the first package installed end-to-end. Read the 0.2 handbook.

0.1 · aurora

The first bootable state — base LFS, the console theme, and a package manager with nowhere to fetch from. Read the 0.1 handbook.

Every version → — each release, its handbook, and whether an image exists