System architecture
Linux Spectre combines a Debian-family desktop foundation with GNOME and custom Spectre integration. Kali packages are not installed into the host. Instead, the ToolHub runtime uses user-scoped rootless Podman to create and maintain a separate Kali Rolling container.
Debian-based root filesystem, GNOME graphical session, Spectre appearance, installed desktop apps, and APT.
Verified installed kernel string 7.1.8-spectre. Kernel update and third-party-module compatibility require explicit qualification.
Python GUI stack using GTK4/libadwaita plus a service/runtime layer for catalog, package and container operations.
Official rolling container image, Kali repository metadata, selected APT packages and retained container state.
Boundary and privilege model
The Podman client runs for the regular desktop user. A subordinate UID/GID mapping makes it possible for rootless containers to present root inside their own user namespace, without automatically granting host administrative rights. The container process still shares the Linux kernel with the host.
podman info --format "{{.Host.Security.Rootless}}"grep "^$(id -un):" /etc/subuid /etc/subgidOn the evaluated installation, the account provisioning service completed successfully and podman info returned true. Do not change subordinate IDs on a working system without understanding how existing container storage depends on them.
Relevant systemd integration
- spectre-rootless-podman-subids.service
- System service provisioned subordinate IDs in the tested fresh install; reported
Result=successandExecMainStatus=0. - spectre-vbox-display.service
- A conditional VirtualBox display integration service. It was
activein the tested VM. - VBoxDRMClient / VBoxService
- VirtualBox userspace components present and running in the tested installation. Their presence must not be interpreted as evidence of support for all host/guest VirtualBox combinations.
systemctl show spectre-rootless-podman-subids.service -p Result -p ExecMainStatussystemctl is-active spectre-vbox-display.servicepgrep -af "VBoxDRMClient|VBoxService"File system and storage
The tested installed VM used an ext4 root filesystem. The main desktop applications and user home directories live on the host. Rootless Podman normally keeps images and containers under the calling user’s container storage area (commonly beneath ~/.local/share/containers/), but always query the running installation rather than assuming a path.
findmnt -no SOURCE,FSTYPE /podman info --format "{{json .Store}}"podman ps -a --format "{{.Names}} | {{.Status}}"Updates and change management
Treat changes to the host kernel, GNOME environment, base packages and the Kali container as separate maintenance activities. Rolling Kali metadata can change independently from the Spectre host. Recommended administrator practice is backup → inspect → update in a test VM → verify services → record results.
- Keep the original verified ISO and its SHA-256 alongside the release notes.
- Do not patch a running guest and assume future clean installations inherit that patch.
- Integrate approved changes into the authoritative source, build cumulatively, and run clean-install regression tests.
- Keep an older known-good image or VM snapshot until the new release is accepted.
Release integrity
The developer-validated ISO was approximately 1.8 GB and passed a SHA-256 checksum verification. Its original internal build filename contained a development suffix. The public marketing name is simply Linux Spectre 1.0; changing the filename alone does not modify the ISO.
When reproducing release artifacts, validate installer files, kernel/module inventory, boot entries, ToolHub behavior, and rootless Podman provisioning before approving publication.
Licenses and redistribution
This site’s manuals and screenshots can be published independently of the OS ISO. The OS image includes multiple upstream components and, in the tested build, exported VirtualBox Guest Additions userspace binaries. Before public ISO distribution, review the exact license texts, notices, corresponding-source requirements, and redistribution permissions for every embedded component.
The project is independent of Debian, Kali, Oracle VirtualBox and Ghost Spectre. Their names describe upstream technologies or inspirations; they do not constitute endorsement.
Technical reading
See the downloadable Technical Handbook and these upstream references: Podman manual, Debian APT handbook, and Kali container images.