← All documentation
04 / UNDER THE HOOD

Architecture and system administration

A precise map of the verified operating-system layers, relevant systemd services, kernel, container boundaries and diagnostic commands.

LINUX SPECTRE 1.0Administrators and developers10 min read

System architecture

Linux Spectre combines a Debian-family desktop foundation with GNOME and custom Spectre integration. Kali packages are not installed into the host. Instead, the ToolHub runtime uses user-scoped rootless Podman to create and maintain a separate Kali Rolling container.

Host OS

Debian-based root filesystem, GNOME graphical session, Spectre appearance, installed desktop apps, and APT.

Custom kernel

Verified installed kernel string 7.1.8-spectre. Kernel update and third-party-module compatibility require explicit qualification.

ToolHub

Python GUI stack using GTK4/libadwaita plus a service/runtime layer for catalog, package and container operations.

Kali layer

Official rolling container image, Kali repository metadata, selected APT packages and retained container state.

Boundary and privilege model

The Podman client runs for the regular desktop user. A subordinate UID/GID mapping makes it possible for rootless containers to present root inside their own user namespace, without automatically granting host administrative rights. The container process still shares the Linux kernel with the host.

CHECK ROOTLESS ENGINE MODE
podman info --format "{{.Host.Security.Rootless}}"
DISPLAY USER SUBORDINATE MAPPING
grep "^$(id -un):" /etc/subuid /etc/subgid

On the evaluated installation, the account provisioning service completed successfully and podman info returned true. Do not change subordinate IDs on a working system without understanding how existing container storage depends on them.

Relevant systemd integration

spectre-rootless-podman-subids.service
System service provisioned subordinate IDs in the tested fresh install; reported Result=success and ExecMainStatus=0.
spectre-vbox-display.service
A conditional VirtualBox display integration service. It was active in the tested VM.
VBoxDRMClient / VBoxService
VirtualBox userspace components present and running in the tested installation. Their presence must not be interpreted as evidence of support for all host/guest VirtualBox combinations.
CHECK SYSTEM INTEGRATION RESULT
systemctl show spectre-rootless-podman-subids.service -p Result -p ExecMainStatus
CHECK DISPLAY INTEGRATION
systemctl is-active spectre-vbox-display.service
OBSERVE DISPLAY PROCESSES
pgrep -af "VBoxDRMClient|VBoxService"

File system and storage

The tested installed VM used an ext4 root filesystem. The main desktop applications and user home directories live on the host. Rootless Podman normally keeps images and containers under the calling user’s container storage area (commonly beneath ~/.local/share/containers/), but always query the running installation rather than assuming a path.

MOUNTED ROOT FILESYSTEM
findmnt -no SOURCE,FSTYPE /
PODMAN STORAGE OVERVIEW
podman info --format "{{json .Store}}"
CONTAINER INVENTORY
podman ps -a --format "{{.Names}} | {{.Status}}"

Updates and change management

Treat changes to the host kernel, GNOME environment, base packages and the Kali container as separate maintenance activities. Rolling Kali metadata can change independently from the Spectre host. Recommended administrator practice is backup → inspect → update in a test VM → verify services → record results.

  • Keep the original verified ISO and its SHA-256 alongside the release notes.
  • Do not patch a running guest and assume future clean installations inherit that patch.
  • Integrate approved changes into the authoritative source, build cumulatively, and run clean-install regression tests.
  • Keep an older known-good image or VM snapshot until the new release is accepted.

Release integrity

The developer-validated ISO was approximately 1.8 GB and passed a SHA-256 checksum verification. Its original internal build filename contained a development suffix. The public marketing name is simply Linux Spectre 1.0; changing the filename alone does not modify the ISO.

SHA-256 · a49d7602a772c2db1dfb72411e47574ec908c5337d05131cb10433119f689d76

When reproducing release artifacts, validate installer files, kernel/module inventory, boot entries, ToolHub behavior, and rootless Podman provisioning before approving publication.

Licenses and redistribution

This site’s manuals and screenshots can be published independently of the OS ISO. The OS image includes multiple upstream components and, in the tested build, exported VirtualBox Guest Additions userspace binaries. Before public ISO distribution, review the exact license texts, notices, corresponding-source requirements, and redistribution permissions for every embedded component.

The project is independent of Debian, Kali, Oracle VirtualBox and Ghost Spectre. Their names describe upstream technologies or inspirations; they do not constitute endorsement.

Technical reading

See the downloadable Technical Handbook and these upstream references: Podman manual, Debian APT handbook, and Kali container images.