Everything paradox 0.4 does, what you type to make it do it, and an honest list of what it can't do yet.
This is an archived handbook. It documents paradox 0.4, which is no longer the current version, and it will not be edited again — so that anyone still running 0.4 has documentation matching the software in front of them.
paradox is a Linux distribution built with the Linux From Scratch method — every package compiled from upstream source rather than pulled from another distribution's archive. There is no Debian, no Arch and no Red Hat underneath it.
As of 0.4 it installs itself, so this is the first release you can put on a machine without already owning one. new in 0.4
Worth being precise about, because the two halves differ. The live image boots on both UEFI and legacy BIOS machines — an older BIOS-only box will start the ISO and run the installer perfectly well. The system it installs is UEFI-only. The installer writes a UEFI GRUB bootloader and nothing else, so on a BIOS-only machine you would complete an install that then refuses to boot.
Legacy BIOS installs need a 32-bit BIOS GRUB that the current build toolchain cannot produce. It is a known gap, not an oversight, and it is on the list for 0.5.
This is the release where paradox stopped being something you cloned onto a disk by hand and became something that installs itself. new in 0.4 It has been through a real install on real hardware — burned to a USB stick, booted on a mini server, and running from that machine's own SSD afterwards.
The image is not published yet. The 0.4 ISO exists and works, but it is not available for download — hosting it is a 0.5 deliverable. What follows describes what happens when you boot it, so it is ready when the image is.
The image is a hybrid ISO: write it to a USB stick, boot it, and you get two choices.
The live system runs from a compressed squashfs image with a writable overlay on top, brought up by a tiny static busybox initramfs. Changes you make while running live are held in RAM and vanish on reboot, which is the point.
firmware mode: UEFI this installs paradox linux onto a disk you choose. nothing is written until you type YES to confirm. ctrl-c quits safely. press enter to begin >
The installer is deliberately boring, in the way that anything which erases a disk should be. Four steps, and nothing is written until you type YES. Ctrl-C quits safely at any point before that.
◆ step 1 of 4 · target disk 1 /dev/sda 240.0 GiB SAMSUNG SSD pick a disk [1-1] (q to quit): 1 … everything on /dev/sda will be erased. ◆ step 2 of 4 · identity hostname [paradox]: host username [pdxadmin]: user password: confirm : ◆ step 3 of 4 · confirm disk /dev/sda (240.0 GiB) layout GPT — ESP 1 GiB (fat32) + root (ext4) kernel linux-paradox 6.18.10-pdx bootloader grub — UEFI (removable) hostname host user user (wheel/sudo), root login disabled this erases /dev/sda. type YES to install: YES
The confirm screen is the whole safety model: everything the installer is about to do, on one screen, before anything happens. Read the disk line twice.
◆ step 4 of 4 · installing onto /dev/sda partitioning (GPT: ESP + root)… ✓ partitioned formatting… ✓ formatted (fat32 ESP · ext4 root) copying the system (this is the long part)… 5,727,612,829 88% 181.13MB/s 0:00:30 ✓ system copied ✓ live auto-login stripped ✓ fstab written ✓ bootloader installed ✓ identity set ✓ done ✓ paradox linux is installed on /dev/sda. remove the installer media, then reboot into paradox. [r] reboot now [s] drop to a shell :
Most live-image installers create your account and leave the live user sitting there with a default password. paradox doesn't. The installer renames the live account to the username you chose, so the installed system has exactly one administrator, at uid 1000, in the wheel group, with the password you set.
There is no leftover pdxadmin carrying the factory password, root login
is disabled, and the live session's auto-login is stripped during the install — the
installed disk always asks who you are.
/etc/fstab written by UUIDPicking try paradox live gives you the whole system running from the USB stick, with nothing written to any disk.
It logs you in automatically as pdxadmin — no password needed to reach
the shell — and the prompt tells you how to install if you change your mind:
pdxadmin@paradox:~$ sudo paradox-install
That one command needs no password in the live session. Anything else you run with
sudo will ask, and the live account's password is the image default,
paradox.
This auto-login is live-only. It is removed during installation, so an installed disk never inherits it. If you find yourself dropped at a shell with no login on a machine you installed, something has gone wrong — that is not normal behaviour.
Because the root filesystem is a RAM overlay, everything you change in a live session is gone at the next boot. Good for looking around, bad for anything you want to keep.
Remove the installer media and reboot. paradox boots UEFI through GRUB, and there is no initramfs on an installed system — the kernel finds the root filesystem by PARTUUID on its command line.
The kernel is 6.18.10-pdx, built for paradox with the networking,
firewall and filesystem support the system relies on. Since 0.4 it also carries a
built-in framebuffer console new in 0.4, which is what fixed installed machines booting to a
blank screen on UEFI hardware.
Boot is quiet by design. You will see very little before the login prompt, which is intentional rather than a sign something stalled.
paradox linux (aurora)
Kernel 6.18.10-pdx on an x86_64 (tty1)
paradox login: pdxadmin
Password:
reality is optional
aurora · 0.4
pdxadmin@paradox:~$
Log in with the username and password you set during the install. The system
identifies itself in /etc/os-release, which reads
VERSION="0.4 (aurora)" — the reliable place to check which release a machine
is running.
Every colour in paradox is deliberate. The rule the theme follows: the colours that tell you who you are stay separate from the colours that tell you what a file is, so nothing is ambiguous at a glance. The hostname is blue rather than cyan specifically so it is never mistaken for a directory.
Root and a normal user differ in exactly one way — the username colour. Yellow means you are root and should be paying attention.
pdxadmin@paradox:~$ whoami pdxadmin root@paradox:~# whoami root
ls is aliased to always use colour. The palette is the "aurora spectrum":
root@paradox:~# ls script.sh test_folder test.txt backup.tar.xz wallpaper.png
The MOTD is the wordmark, a divider, and the wordmark reflected and dimmed beneath it — which way is up. The banner is bright cyan and its reflection a dimmer cyan, reality is optional sits below in yellow, and the release line reads aurora in magenta beside the version in white.
Search matches highlight in magenta. nano is themed to match — cyan title bar with white text, cyan line numbers, bright cyan shortcut keys — and comes configured with line numbers, syntax highlighting, soft wrap, auto-indent, and 4-space tabs that insert spaces.
The Linux text console can only display 16 colours. The prompt and banner are written in 16-colour codes so they are exact, but the file listing palette uses 256-colour codes and will look approximate on the console. Over SSH or in a graphical terminal you see the real thing.
An installed 0.4 system has one administrator — the account you named during the install, at uid 1000, in the wheel group, which is what grants sudo. new in 0.4
Root exists but root login is disabled. Administrative work goes through
sudo, which asks for your password each time.
user@host:~$ id uid=1000(user) gid=1000(user) groups=1000(user),97(wheel)
The paradox- tools are run as your normal user — they ask for your
password themselves at the point they need it, rather than requiring you to remember a
prefix.
If you are running a live session rather than an installed system, the account
is pdxadmin with the password paradox. That account does not
survive the install.
Wi-Fi works. This is the headline of 0.3 and the thing that changes what paradox can be installed on — a laptop with no ethernet port is no longer a dead end.
Two commands cover almost everything. Both are run as your normal user, both figure out the hardware themselves, and both ask for your password only when they are about to change something.
Run it with no arguments and it scans, lists what it found, and connects to whichever
you pick. A network marked psk asks for its passphrase — typed blind, nothing
echoes back. Networks marked open connect straight away.
Once you have joined a network it is saved, so it reconnects on its own after a reboot and will not ask again.
pdxadmin@paradox:~$ paradox-wifi ↻ paradox-wifi scanning the airwaves on wlan0… 1 aurora-5G psk ●●●● (connected) 2 aurora psk ●●●● 3 nebula-guest psk ●●● 4 quasar_lab open ●●● 5 pulsar-2G psk ●● 6 corona_house psk ●● pick a network [1-6] (q to quit): 3 ↻ paradox-wifi connecting to nebula-guest… Passphrase for nebula-guest: (hidden) ✓ connected to nebula-guest radio wlan0 state connected network nebula-guest ip 192.168.10.36/24
The other things it does:
paradox-wifi status — radio, state, network and addressparadox-wifi --disconnect — drop the current connection but keep the network saved, so it reconnects next bootparadox-wifi --forget-networks — erase every saved network, so the machine stops connecting on its ownUnderneath it is iwd, which runs its own DHCP client — there is no
separate DHCP daemon to configure or fight with.
Wired ethernet uses DHCP out of the box and needs no attention. When you want a fixed
address — which on a machine running SSH you usually do — paradox-wired
walks through it and writes the systemd-networkd configuration for you.
pdxadmin@paradox:~$ paradox-wired 1 enp2s0 down 2 enp3s0 up 192.168.10.107/24 pick a nic [1-2] (q to quit): 1 ✎ paradox-wired static ip on enp2s0 ip address : 192.168.10.10 subnet (24 or mask) : 24 gateway (blank=none): 192.168.10.254 dns, comma-separated: 1.1.1.1,8.8.8.8 will write /etc/systemd/network/00-paradox-enp2s0.network: [Match] Name=enp2s0 [Network] Address=192.168.10.10/24 Gateway=192.168.10.254 DNS=1.1.1.1 DNS=8.8.8.8 … if enp2s0 is the link you're on, this can drop the session — reconnect on the new address. apply this? [y/N] y [paradox] password for pdxadmin: ✓ applied static 192.168.10.10/24 on enp2s0
paradox-wired status — list the wired interfaces and their addressesparadox-wired --dhcp — hand a port back to automatic addressingRead the warning it prints before answering yes. If you are connected over the port you are reconfiguring, applying the change drops your session and you reconnect on the new address — worth thinking about before doing this remotely over the only link you have.
The base ships firmware for the common Wi-Fi families — Intel, Atheros, Realtek, Broadcom, MediaTek and Marvell — along with wired NIC blobs, Bluetooth, Intel graphics and the wireless regulatory database, so most machines get online without hunting for anything. It is about 677 MB, and it is the reason a from-scratch distribution can be plug-and-play at all.
Everything else upstream ships — AMD and Nvidia graphics, server SmartNICs, audio and
SoC firmware — is available as linux-firmware-extra in the repository rather
than sitting unused in every install.
paradox now comes up firewalled on every boot. The policy is default-drop on input: unless a rule allows it, incoming traffic is discarded.
What is allowed:
Outbound traffic is unrestricted, and forwarding is off.
pdxadmin@paradox:~$ systemctl status nftables Loaded: loaded (nftables.service; enabled) Active: active (exited) pdxadmin@paradox:~$ sudo nft list ruleset
Default-drop means anything you host yourself is unreachable until you say otherwise. Start a web server, a game server or a database, connect from another machine, and it will simply hang — the service is running fine, the firewall is discarding the packets before they arrive.
Rules live in /etc/nftables.conf. Add a port alongside the existing SSH
line, then reload:
pdxadmin@paradox:~$ sudo nano /etc/nftables.conf tcp dport 22 accept tcp dport 8080 accept # check it parses before loading pdxadmin@paradox:~$ sudo nft -c -f /etc/nftables.conf pdxadmin@paradox:~$ sudo systemctl restart nftables
Check the file with nft -c -f before loading it. A syntax error in a
firewall you are editing over SSH is a bad way to end an evening.
Software is managed with paradox, a wrapper over the pacman package
engine. The verbs are themed; plain synonyms work identically, and any extra arguments
pass straight through.
| command | does | plain form |
|---|---|---|
| paradox glitch <pkg> | install a package | install |
| paradox collapse <pkg> | remove a package and its orphaned dependencies | remove |
| paradox shift | sync the database and upgrade everything | update / upgrade |
| paradox refresh | refresh the package database only | sync |
| paradox seek <term> | search the repository | search |
| paradox info <pkg> | show package details | — |
| paradox list | list installed packages | — |
| paradox help | print the menu | -h / --help |
Packages are served from a self-hosted repository at
repo.paradoxlinux.com, backed by Cloudflare R2. Each arrives as a
.pkg.tar.zst archive with a detached GPG signature, and
SigLevel = Required means an unsigned or badly signed package is refused
rather than installed.
The public key is published at
repo.paradoxlinux.com/paradox-linux.gpg. Verify it against the fingerprint
before trusting it:
0956915D16CAA24FD62E 8750 2D94 217B AAB7 6E21 0956 915D 16CA A24Fparadoxadmin <paradoxlinuxadmin@gmail.com>The private key lives only on the build host and is never shipped in the system.
Eighteen signed packages, up from one in 0.2. Everything is built from source with its own PKGBUILD rather than repackaged from elsewhere.
pdxadmin@paradox:~$ paradox seek tmux paradox/tmux 3.5a-1 pdxadmin@paradox:~$ paradox glitch tmux resolving dependencies... Proceed with installation? [Y/n] ✓ tmux 3.5a-1 installed
Downloads now go through curl rather than pacman's own sandboxed downloader, which was unreliable on some hardware — a change you will not notice except that transfers stop hanging.
linux-paradox is a signed package in the repository like anything else,
which is how future kernels will be delivered.
One honest caveat. The base system is hand-built rather than pacman-tracked, so
a stock 0.4 install still carries its kernel outside package management and
paradox shift will not pull a new one automatically. Moving the packaged
kernel onto an existing install is a deliberate manual step for now. Wiring the base
kernel into package management so shift upgrades it cleanly is planned for
0.5.
The catalogue is past twenty signed packages, with the installer's dependencies — grub and dosfstools — now built and signed alongside everything else. new in 0.4
"No bloat" is only useful if you know what you actually have. This is the tour.
Everyday tools that used to be missing now build as signed packages and ship in the base:
nano, and only nano. vim is not installed. If you are a vi person that is the first thing you will want to change — and now that the repository has eighteen packages in it, building one is a reasonable request rather than a project.
No desktop, no display server, no audio stack, no printing, and no vim. Bluetooth firmware is present but nothing is configured to use it. Nothing runs that you did not start.
paradox runs systemd, so services and logs behave the way they do on any modern distribution. Only a handful of the enabled units are paradox's own choices rather than systemd defaults.
The rest are systemd's own presets: oomd, pstore, sysext, confext, udev credentials and the journald sockets.
pdxadmin@paradox:~$ systemctl status sshd pdxadmin@paradox:~$ systemctl list-unit-files --state=enabled pdxadmin@paradox:~$ journalctl -b -p err pdxadmin@paradox:~$ journalctl -u iwd -f pdxadmin@paradox:~$ sudo systemctl poweroff
Kept current for every release, because finding this out at eleven at night is worse than reading it now.
paradox shift does not yet replace the base kernel on an existing install.Things that have actually caught someone out.
paradox-wired warns you before it applies.--disconnect keeps the network saved on purpose; use --forget-networks if you want it gone.root=PARTUUID=…./var/lib/pacman/db.lck; delete it before retrying./etc/ssl goes missing, downloads fail in ways that look like the network is down./usr/bin/paradox — the package manager wrapper/usr/bin/paradox-install — the installer, on the live image new in 0.4/usr/bin/paradox-info — system information/usr/bin/paradox-wifi · /usr/bin/paradox-wired — the network tools/etc/bashrc — the prompt, LS_COLORS, GREP_COLORS and the aliases/etc/motd — the mirror banner/etc/nanorc — the nano theme and behaviour/etc/os-release — version and identity/etc/pacman.conf — repositories and signature policy/etc/nftables.conf — the firewall ruleset/etc/iwd/main.conf · /var/lib/iwd/ — Wi-Fi config and saved networks/etc/systemd/network/ — wired configuration; paradox-wired writes 00-paradox-<nic>.network here/boot/grub/grub.cfg — the boot menu/etc/ssl/certs/ca-certificates.crt — the CA bundle/etc/fstab — written by the installer, root by UUID, ESP at /boot/efiGPT with two partitions: a 1 GiB fat32 EFI system partition and an ext4 root. The
kernel command line is root=PARTUUID=… ro quiet loglevel=3.
The release where paradox learned to install itself. What had been a hand-cloned disk became a bootable image with a guided installer, proven end to end on real hardware.
paradox-install — a four-step guided installer that the boot menu drops you straight intolinux-paradox, with a built-in framebuffer console that fixed blank screens after install on UEFI machinesUnchanged from 0.3: the LFS base and toolchain, the partition and UUID approach, the single-wheel-admin model, systemd init, and the colour and mirror theme.
The release where paradox learned to get online anywhere — a custom kernel, Wi-Fi end to end, a firewall at every boot, and a CPU-portable base. Read the 0.3 handbook.
The release where the package manager became real — a live signed repository and the first package installed end-to-end. Read the 0.2 handbook.
The first bootable state — base LFS, the console theme, and a package manager with nowhere to fetch from. Read the 0.1 handbook.
paradox shiftEvery version → — each release, its handbook, and whether an image exists