About this project

Linura is an experimental, intent-driven system layer for Linux that aims to convert human goals into declarative, policy-controlled and verified machine state. Rather than translating natural language into shell commands, it captures durable structured intent, resolves capabilities and conflicts, derives desired state, and routes every managed mutation through one canonical authority lifecycle. The project combines two ideas while keeping their trust boundaries separate. The authority/control plane provides a typed Linux model, providers, an eleven-stage mutation lifecycle (request/intent, observe, plan, validate, authorize, prepare, execute, verify, commit, audit, reconcile), policy and approval decisions, narrow privilege, independent verification, crash-safe commit, reconciliation and audit. The intelligence plane adds persistent user intent, reusable setups, a local-first Library, a system graph, capability composition, dependency and conflict solving, semantic provenance, specialist agents and first-boot UX. The control plane is usable without AI, and the intelligence plane can be replaced without changing the authority plane. Key concepts include Setups (reusable versioned slices of intent such as rust-development or postgresql-development) and Machine Profiles (whole-machine compositions). Setups store portable intent, composition and constraints rather than shell history or filesystem snapshots; exports carry secret references, never secret values. Reusing a setup always re-observes the target machine, re-resolves capabilities, derives fresh desired state and generates a new plan before any mutation. Exact snapshots remain a separate rollback/recovery mechanism. Stated invariants include: linurad runs unprivileged; no generic privileged shell execution API exists; agents receive no privileged executor handle; natural language produces an IntentProposal, never executable text; managed state retains semantic provenance explaining why it exists; unknown or unsupported state fails closed for mutations; executor success is treated as evidence of dispatch, not proof of resulting state; and local deterministic operation, Library use and recovery work without network or model access. The repository is organized as a Rust workspace with crates for core, intent, graph, capability SDK, planner, provenance, agent runtime, policy, protocol, provider SDK, SDK facade, control, lifecycle, bootstrap, migrations and update, plus apps for linurad, linuractl, first boot, control center, agent UI and a Quickshell/QML shell. It also includes bindings, capabilities, workflows, surfaces, agents, executors, interfaces, schemas, profiles, packaging and docs. Status is v0.9.0, described as experimental with an Experimental First Boot and a supported reference environment; the immutable release is independently verified. The first interactive workstation profile target is deliberately narrow (Arch Linux, systemd, Wayland/Hyprland, NetworkManager, PipeWire, BlueZ, UDisks2, Polkit, Btrfs/Snapper), with arch-hyprland-v1 positioned as a development candidate for v0.10 rather than part of the current support boundary. Development follows a narrow vertical-slice order, and the bootstrap quality gate pins Rust 1.98.0 with fmt, clippy, test and repository-check commands. Licensed under Apache 2.0.