# Shadowfetch Linux 3.5.0 prepublication release dossier

Codename: Umbra

Evidence timestamp: 2026-08-27T19:49:47.235575+00:00

## Artifact identity

- ISO: `shadowfetch-3.5.0-amd64.iso`
- Size: `3980310528` bytes
- SHA-256: `2af853b1f5dedfca17a7a63783f4c881e72e912f26082b10c07d45aafe57b995`
- Detached signature: `shadowfetch-3.5.0-amd64.iso.asc`
- Signing fingerprint: `8F13CE1535EE1F4A2916A1F73C5C900B7BE80CA1`
- Canonical website: https://www.shadowfetchlinux.org
- Canonical source: https://github.com/ShadowfetchLinux/shadowfetch-linux

This is a prepublication dossier. It records the exact candidate and does not claim that any public destination has been updated.

## Release intent

Shadowfetch Linux 3.5.0 is the flagship Fire and Ice Workbench release. Fire is the connected production posture; Ice starts agent sessions without network access. Element Workbench creates Software Studio, AI Lab, Production Ops, and Creative AI projects from one audited plan. Shadowfetch Guide checks the computer without uploading machine identity. Buzz remains the single optional local-model workspace, and Codex, Claude Code, Grok Build, and Cursor Agent remain independent, verified, user-owned options with no credentials preloaded.

The release also strengthens safe updates and Phoenix rollback on separate-/boot Btrfs installations, preserves a tested 2.1.4 upgrade path, improves new-generation NVIDIA guidance, and keeps renderer claims measured rather than assumed.

## QA position

- Required prepublication cases passing before REL-01 packaging: 11 of 11
- Optional prepublication cases: 0
- Publication cases are intentionally pending until all prepublication gates pass.

## Disclosures

- No open model is bundled in the ISO. Buzz recommends and downloads a model only after the user confirms sharing in Settings > Compute.
- During the tested network interruption, Buzz did not falsely report success, but automatic transfer resume was not observed. The disclosed clean retry required removal of only the disposable incomplete cache object before real inference completed.
- Codex, Claude Code, Grok Build, and Cursor Agent require their own supported sign-in after installation; Shadowfetch includes no vendor credential.
- NVIDIA workflow and rollback were tested against the physical RTX 5060 Ti host. The ISO retains AMD and Intel Mesa paths, but no active physical AMD or Intel renderer was available, so performance on those paths is not claimed.
- Secure Boot remains an unsigned-image caveat documented on the site.

## Claims-to-evidence index

| Case | Requirement | Required | Status | Evidence |
| --- | --- | --- | --- | --- |
| SRC-01 | Source, parser, ShellCheck, desktop, secret and retired-runtime gates pass | yes | pass | `source/source-gate-d27e204.log` |
| PKG-01 | Exact signed 3.5.0 binary and source package allowlists pass | yes | pass | `packages/package-gate-d27e204.log` |
| ISO-01 | Fresh signed hybrid ISO passes the installed-image gate | yes | pass | `iso/iso-gate-2af853b1.log`<br>`release/iso-identity-2af853b1.log` |
| WB-01 | All four Workbench plans and project templates work as an unprivileged user | yes | pass | `vm-2af853b1/bios-fire-workbench-create-all.log`<br>`vm-2af853b1/uefi-ice-workbench-create-ai-lab.log` |
| FIRE-01 | Fire live VM boots, renders Workbench and reports the connected agent posture | yes | pass | `vm-2af853b1/fire-live-fresh-welcome-1366x768.png`<br>`vm-2af853b1/fire-live-fresh-desktop-1366x768.png`<br>`vm-2af853b1/fire-live-fresh-workbench-1366x768.png`<br>`vm-2af853b1/fire-live-firebreak-default.log` |
| ICE-01 | Ice live VM boots, renders Workbench and defaults Firebreak to no network | yes | pass | `vm-2af853b1/ice-live-boot-identity.log`<br>`vm-2af853b1/ice-live-fresh-welcome-1366x768.png`<br>`vm-2af853b1/ice-live-fresh-workbench-1366x768.png`<br>`vm-2af853b1/ice-live-firebreak-default.log` |
| INSTALL-01 | Calamares clean install boots from disk with the selected element | yes | pass | `vm-2af853b1/bios-fire-installed-audit.log`<br>`vm-2af853b1/uefi-ice-installed-audit.log`<br>`vm-2af853b1/bios-fire-installer-finish-1366x768.png`<br>`vm-2af853b1/uefi-ice-installer-finish-1366x768.png` |
| STRESS-01 | Concurrent CPU, memory, storage, container and UI load runs for at least 45 minutes | yes | pass | `vm-2af853b1/bios-fire-stress-45m/result.json`<br>`vm-2af853b1/bios-fire-stress-45m/timing.txt`<br>`vm-2af853b1/bios-fire-post-stress-installed-audit.log`<br>`vm-2af853b1/bios-fire-post-stress-graphics-audit.log`<br>`vm-2af853b1/bios-fire-ui-under-stress-t-plus-36m-1920x1080.png` |
| RECOVERY-01 | Cancelled and failed profile installs remain visible and recoverable | yes | pass | `vm-2af853b1/bios-fire-recovery/result.json`<br>`vm-2af853b1/bios-fire-recovery/offline-failure.log`<br>`vm-2af853b1/bios-fire-recovery/retry-success.log`<br>`vm-2af853b1/bios-fire-post-recovery-installed-audit.log` |
| VISUAL-01 | Fire and Ice screenshots pass 1366x768 and 1920x1080 visual QA | yes | pass | `vm-2af853b1/visual-audit-manual-ocr.log`<br>`vm-2af853b1/bios-fire-workbench-qxl-1366x768.png`<br>`vm-2af853b1/uefi-ice-workbench-qxl-1366x768.png`<br>`vm-2af853b1/bios-fire-ai-agents-1920x1080.png`<br>`vm-2af853b1/uefi-ice-ai-agents-1920x1080.png`<br>`vm-2af853b1/bios-fire-desktop-1920x1080.png`<br>`vm-2af853b1/uefi-ice-desktop-1920x1080.png` |
| EVIDENCE-01 | Dossier, SBOM, manifests, checksums, signature and evidence bundle verify | yes | pass | `release/evidence-gate-2af853b1.log` |
