Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Empty file added .codex
Empty file.
24 changes: 17 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,22 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# The repository is a pnpm project (pnpm-lock.yaml, lockfileVersion 9.0) and has no
# npm lockfile, so the previous actions/setup-node cache:"npm" + `npm ci` never
# reached a single gate: every run failed at setup-node with
# "Dependencies lock file is not found".
- uses: pnpm/action-setup@v4
with:
# pnpm 11 uses node:sqlite, so it needs Node >= 22. Both are pinned to the
# toolchain the gates were verified against locally (Node 22 + pnpm 11.6).
version: 11.6.0
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
- run: npm ci
- run: npm run typecheck
- run: npm run test
- run: npm run validate
- run: npm run lint
node-version: "22"
cache: "pnpm"
- run: pnpm install --frozen-lockfile
- run: pnpm typecheck
- run: pnpm test
- run: pnpm validate
- run: pnpm lint
- run: pnpm build
106 changes: 106 additions & 0 deletions docs/distro-data-evidence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# Distro data evidence

Every value in `src/data/distros.json` should be traceable to a source. This file records
the sources for values that were verified by hand, plus the operational definitions the
verification uses. Values not listed here are the pre-existing dataset values
(`verificationMethod` says whether they were verified or inferred).

## Operational definitions

**`proprietarySupport`** — how far a *default* install of the distro's main desktop edition
gets you to proprietary (non-free) drivers and codecs using only first-party means (its own
repositories, installers and tools), with no repository added or edited by the user:

- `FULL` — proprietary drivers/codecs are installed by default, **or** offered by default
(installer option, branded NVIDIA image, boot-menu driver choice, first-party driver GUI),
**or** installable from repositories enabled by default in a fresh install.
- `OPTIONAL` — nothing non-free is enabled or installed by default, but the distro documents
a first-party opt-in (enable `non-free`/`contrib`, RPM Fusion, NVIDIA repository, or run the
distro's driver tool after enabling a repository).
- `NONE` — no first-party path at all; the archive or image excludes non-free.

Firmware blobs (`non-free-firmware`) are deliberately excluded from this field: nearly every
distro ships them, and mixing them into the enum makes Debian-class entries unclassifiable.

**`secureBootOutOfBox`** — a default install boots and works with UEFI Secure Boot *enabled*,
without the user disabling it (signed shim + signed kernel, no hand-enrolled MOK).

## Verified values

| Distro | Field | Value | Source (read 2026-09-28) |
|---|---|---|---|
| ubuntu | secureBootOutOfBox | `true` (was `false`) | <https://help.ubuntu.com/community/UEFI> — "All current Ubuntu 64bit (not 32bit) versions now support this feature [Secure Boot]" |
| kubuntu, xubuntu, lubuntu, ubuntu_budgie, ubuntu_studio, ubuntu_mate | proprietarySupport | `FULL` (was `OPTIONAL`) | Official flavours are built from the same Ubuntu archive with the same default components (`main restricted universe multiverse`, "restricted: Proprietary drivers") and the same first-party `ubuntu-drivers` tooling, so they cannot differ from `ubuntu` on this field. Archive and shim are shared with `ubuntu`, whose value is `FULL`. |
| artix | installerExperience | `GUI` (was `MANUAL`) | <https://artixlinux.org/download.php> — graphical ISOs ship the Calamares installer and the page tells non-experts "use a graphical or community edition" |
| artix | supportedDesktops | `KDE, XFCE, MATE, CINNAMON, LXQT, OTHER` (was `OTHER, TILING`) | Same page: graphical images are "LXQt, LXDE, MATE, Cinnamon, KDE/Plasma, XFCE"; stable ISO listing confirms `artix-cinnamon-*`, `artix-mate-*`, `artix-plasma-*`, `artix-xfce-*`, `artix-lxqt-*` |
| artix | suitableForOldHardware | `true` (unchanged) | Same page: the `lowmem` ISO "can boot and install on machines with as little as 300MB of RAM" |

## Corrections applied from the verification records

Source records live in `docs/evidence/`. `upstream-verified` means the value was read off an
upstream doc/package page; `medium` means the upstream statement is indirect (forum post by a
maintainer, user-posted file contents, or inference from a shared archive).

| Distro | Field | Change | Confidence |
|---|---|---|---|
| linux_mint | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (default sources carry main/restricted/universe/multiverse; first-party Driver Manager) |
| linux_mint | secureBootOutOfBox | false → `true` | upstream-verified ("full support for SecureBoot" since 21.3) |
| lmde | proprietarySupport | OPTIONAL → `FULL` | medium (LMDE configures `main contrib non-free non-free-firmware`) |
| lmde | secureBootOutOfBox | false → `true` | medium (Debian signed chain; LMDE 6 shim later hit by an SBAT revocation) |
| zorin_os | secureBootOutOfBox | false → `true` | upstream-verified (help docs: works with Secure Boot on) |
| debian | secureBootOutOfBox | false → `true` | upstream-verified (shim since Debian 10) |
| arch | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (`nvidia-utils` is in `extra`, enabled by default) |
| endeavouros | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (ISO ships an NVIDIA boot entry + first-party `nvidia-inst`) |
| manjaro | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (installer offers free vs proprietary drivers; `mhwd`) |
| mx_linux | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (first-party "Nvidia Driver Installer" in MX Tools) |
| qubes_os | proprietarySupport | OPTIONAL → `NONE` | medium (no first-party non-free path; NVIDIA "may require significant troubleshooting"; only third-party repos) |
| whonix | proprietarySupport | OPTIONAL → `FULL` | medium (maintainer states non-free and contrib ship enabled; upstream wiki pages were unreachable) |
| parrot | proprietarySupport | OPTIONAL → `FULL` | upstream-verified (`parrot.list` ships `main contrib non-free non-free-firmware`) |

Unchanged after verification: `pop_os` (FULL, Secure Boot off), `mx_linux` Secure Boot (false),
`qubes_os` Secure Boot (false — upstream requires it disabled), Arch/EndeavourOS/Manjaro Secure
Boot (false), `debian` proprietarySupport (OPTIONAL — official media ship `main` +
`non-free-firmware` only).

## New entries

Field-level quotes for each entry are in `docs/evidence/new-distros-tier1.md`. Values I decided
against a direct upstream statement, and why:

| Entry | Field | Call | Reason |
|---|---|---|---|
| omarchy | installerExperience = `MANUAL` | the ISO ships the Omarchy Configurator, a guided **text-mode** wizard over `archinstall`; the enum has no "guided CLI" value, and `GUI` would hand Omarchy to a no-terminal beginner |
| omarchy | maintenanceStyle = `LOW_FRICTION` | updates run from the Omarchy menu and migrations are automatic (omarchy.org/manual/updates) |
| steamos | supportedArchitectures = `["x86_64"]` | Valve ships SteamOS on x86_64 handhelds/machines only; no ARM build exists |
| raspios | nvidiaExperience = `HARD` | no NVIDIA path on Raspberry Pi hardware; `UNKNOWN` is banned by the dataset invariant |
| rhel | maintenanceStyle = `HANDS_ON`, proprietarySupport = `OPTIONAL` | kept consistent with the existing rocky/alma/centos_stream entries rather than inventing a different standard for the same product family |
| antix | proprietarySupport = `OPTIONAL` | non-free is reachable through first-party opt-in tooling, not enabled by default (its FAQ also installs `broadcom-sta-dkms` from backports, which would read as FULL — flagged, not resolved) |
| devuan | initSystem = `OTHER` | sysvinit has no enum value |

## Second batch of new entries

Field-level quotes: `docs/evidence/new-distros-tier2.md`.

| Entry | Note |
|---|---|
| vanilla_os | immutable by design (ABRoot); `packageManager` APT on an immutable Debian base |
| guix | `proprietarySupport = NONE` ("All of It, Free Software"); `packageManager`/`initSystem` = OTHER (Guix + GNU Shepherd); `immutable = false` because generations are not a read-only rootfs |
| archcraft | Arch-based with a first-party Calamares installer; Secure Boot false, like Arch |

Two values were changed from the draft after the verification pass, because they were
unverified and would overpromise: `vanilla_os.secureBootOutOfBox` true → `false` (no upstream
statement that its kernel chain is signed) and `vanilla_os.nvidiaExperience` OK → `HARD`
(NVIDIA on an immutable ABRoot base is not a documented easy path).

**Architecture spellings normalised.** The draft used `aarch64`/`armv7`/`i686`; the engine only
consults `x86_64`, `arm64` and `x86` (`src/engine/eliminate.ts`), so `aarch64` would have made an
ARM answer silently miss the entry. Guix is now `x86_64, x86, arm64` and Archcraft `x86_64,
arm64`; 32-bit ARM and i686 are not expressible in the current vocabulary (same limitation as
Raspberry Pi OS's `armhf`). A new `unknown_architecture` invariant now fails the build on any
other spelling.

**Tiny Core Linux was not added.** It has no logo on Wikimedia Commons and the project's own site
was unreachable from the verification environment, so the entry could not satisfy the
`missing_core_data` invariant (which requires an image URL). Its prepared entry is easy to
re-add once a hotlinkable logo exists; dropping it was preferred over carving an exception into
the invariant.
Loading
Loading