One legible owner per decision

SouveraineOS is the operating-system layer around Souveraine: device profiles, package delivery, compositor, session authority and the agent substrate in one declared composition. Linux stays Linux; what changes is that every state that matters on a personal device gets one owner who can name it.

One common base that adapts. Per-device packages carry hardware facts; the system itself learns to ask which body it is in.

The bodies

One system, carried into different hardware without forking its center of gravity. Each body keeps its own profile, boot path and unresolved edges.

The daily body

Pixel 3

A phone used daily on Casey's mainline-derived Linux 7.1.1 kernel. Calls, SMS and mobile data work on the physical device alongside the shell, session authority, touch, audio, sensors and package delivery.

The active bring-up body

iPhone 7

Apple T8010 bring-up through an owned boot path. NVMe root, tether, display and the Souveraine session reach glass; self-boot, touch events, Wi-Fi, modem and battery integration remain open.

The daily workstation

HP ProBook 450 G6

The x86_64 workstation runs the substrate and shell on its EndeavourOS base. Its formal hardware profile and installer path are not ready.

The planned laptop transfer

Apple silicon

A future transfer of the same operating-system contract, not a special desktop edition with a different center of gravity.

The future mobile family

A5–A11 Apple mobile

Checkm8-class boot access makes this family a research direction. Only an exact device with its own profile and hardware evidence earns a stronger state.

The stack has an order

01

Body

A declared device profile names its boot package, kernel, hardware quirks and commissioning work.

02

Base

One common OS learns the body it inhabits. A per-device package carries differences; a forked userland is a defect.

03

Session

The compositor, PAM and the system session agree about lock, idle, step-up and sleep instead of maintaining competing guesses.

04

Presence

Souvie and the shell live above that authority: able to operate the device, unable to impersonate the person holding the credential.

Distribution is part of the body

Components build their own code, but they do not get to invent a private release path. A canonical manifest declares the packages and architectures that belong to a profile. A signed archive is the delivery surface. An eventual graphical installer selects a ready profile and follows that plan; it does not become a second device database.

The current bodies do not all arrive the same way: the Pixel is daily-used, the iPhone path remains tethered, and planned families do not yet have installable profiles. Those differences live in the profile and device docs.

ViewTop and the session

ViewTop is the Wayland compositor path: a small, purpose-built surface with no GNOME or KDE dependency gravity. The session authority keeps one source of truth for lock, idle and sleep, using the compositor and system protocols that already own those facts. PAM remains the credential gate. The agent can operate the device; it cannot approve its own step-up.

Read the operating-system guide →