One legible owner per decision

SouveraineOS is the operating-system layer around Souveraine: device profiles, package delivery, compositor, session authority and the agent substrate in one declared composition. Linux stays Linux; what changes is that every state that matters on a personal device gets one owner who can name it.

One common base that adapts. Per-device packages carry hardware facts; the system itself learns to ask which body it is in.

The bodies

A body is named only when its state is clear. A live workstation is not an installer claim; a reachable bootrom family is not a support matrix.

The daily body

Pixel 3

exercised on glass

A mainline-minded Linux phone where the shell, session authority, touch, audio, modem, sensors and package delivery meet on real glass.

The active bring-up body

iPhone 7

bring-up

Apple T8010 bring-up through an owned boot path. Storage, tether and the Souveraine session are alive; the display path remains active hardware research.

The daily workstation

HP ProBook 450 G6

SouveraineOS on x86

The x86_64 workstation carrying SouveraineOS on its EndeavourOS base. Its formal hardware profile and installer path are being completed this week.

The planned laptop transfer

Apple silicon

transfer planned

A future transfer of the same operating-system contract, not a special desktop edition with a different center of gravity.

The future mobile family

A5–A11 Apple mobile

hardware access established

Checkm8-class boot access opens iPhones and iPads in this range. Each exact device will earn its own profile and hardware proof as the family comes online.

The stack has an order

01

Body

A declared device profile names its boot package, kernel, hardware quirks and commissioning work.

02

Base

One common OS learns the body it inhabits. A per-device package carries differences; a forked userland is a defect.

03

Session

The compositor, PAM and the system session agree about lock, idle, step-up and sleep instead of maintaining competing guesses.

04

Presence

Souvie and the shell live above that authority: able to operate the device, unable to impersonate the person holding the credential.

Distribution is part of the body

Components build their own code, but they do not get to invent a private release path. A canonical manifest declares the packages and architectures that belong to a profile. A signed archive is the delivery surface. An eventual graphical installer selects a ready profile and follows that plan; it does not become a second device database.

This is deliberately honest about maturity. A planned profile is not sold as an installer. A capability is not called working because a node appeared in a log. Hardware proof lives on the glass.

ViewTop and the session

ViewTop is the Wayland compositor path: a small, purpose-built surface with no GNOME or KDE dependency gravity. The session authority keeps one source of truth for lock, idle and sleep, using the compositor and system protocols that already own those facts. PAM remains the credential gate. The agent can operate the device; it cannot approve its own step-up.

Read the operating-system guide →