Installer and first boot
Calamares, btrfs with automatic snapshots, encryption, swap, and the login screen.
Installer: Calamares (based on Debian's configuration)
- Alternatives: Ubuntu's Subiquity/Flutter installer, Fedora's Anaconda, debian-installer, writing our own.
- Why: Calamares is distribution-independent and used by Debian live, Manjaro, KDE neon, Lubuntu and many others. It handles the hard parts well: partitioning with KPMcore (erase, alongside, replace, manual), LUKS2 encryption, BIOS and UEFI boot loaders. Its modules are easy to extend in Python. Subiquity and Anaconda are tied to their own distributions. Writing our own partitioner would put users' data at risk.
- Aurora additions: our own branding and slideshow.
aurora-finalizesets up the login screen or automatic login and removes live-only files.aurora-sourceswrites deb822 apt sources with backports.aurora-securebootinstalls the signed shim and GRUB on UEFI. An offline package pool on the ISO means installing never needs a network. - Its look: Calamares lets a distribution replace its side bar with QML and restyle the rest with a Qt style sheet. Ours (
branding/calamares/) puts the steps across the top as dots that fill in (calamares-sidebar.qml, "sidebar: qml,top"), keeps the classic buttons at the bottom (so Alt+N still moves on, which the install test uses), and draws check marks as PNGs, because the image has no Qt SVG plugin. Two things it can't reach are worked around: names under the partition bars are painted in black, so they sit on a light strip; and Qt's own title bar, drawn inside the window, made dialogs too short for their text, so Wayfire draws title bars for Qt apps. - Keyboard page with "Detectโฆ": Calamares'
keyboardqmodule with our QML (keyboardq.qml). Detection asks which letters start the top row, then which character is next to L (or on the 3 keyโฆ), and selects the layout in the module's own model. It works by clicking only: Calamares shows QML pages in a widget that never gets the keyboard, which is also why the page has no search or "type here" field.
File systems: btrfs by default (ext4 and xfs available); LUKS2 encryption
- Alternatives: ext4 by default (Ubuntu, Debian), XFS (RHEL), ZFS (Ubuntu offered it experimentally).
- Why: btrfs makes snapshots instant and nearly free (copy-on-write), which is what lets Aurora take one before every update and boot into it (see Snapshots). It also compresses transparently (
compress=zstd:1: less disk space and fewer SSD writes, at no noticeable cost) and checksums data. Fedora and openSUSE have used it by default for years. ZFS can't ship in the kernel because of its license and needs DKMS modules. - Layout: Ubuntu-style subvolumes created by Calamares (
mount.conf):@(the system),@home(your files, never rolled back),@cacheand@log(so caches and logs aren't in snapshots and survive a rollback), and@swapfor the swap file, because btrfs can't snapshot a subvolume that holds an active swap file. - ext4 and xfs are still in the installer. On them, everything works except automatic snapshots (Timeshift can still make rsync copies).
System snapshots: Timeshift (btrfs mode) + grub-btrfs
- Alternatives: Snapper with
snapper-rollback(openSUSE's approach), Timeshift's rsync mode, ZFS boot environments, image-based OSes with A/B updates (Fedora Silverblue, Vanilla OS), no snapshots (Ubuntu). - Why: Timeshift is in Debian, has a clear graphical app for browsing and restoring snapshots, and in btrfs mode snapshots take a second. Its layout (
@,@home) is the one most tutorials describe. Snapper is more flexible, but rolling back a Debian-style layout with it needs extra tooling and has no GUI in Debian. Immutable A/B systems are robust, but they change how you install software, and Aurora wants to stay a normal Debian system. - How it fits together:
- the installer's
aurora-finalizemodule writes Timeshift's configuration (the btrfs device, including the LUKS container when encrypted) and turns the rest on, on btrfs only; aurora-first-snapshot.servicetakes a "Fresh install" snapshot at the first boot;- an apt hook (
/etc/apt/apt.conf.d/80aurora-snapshotโ/usr/libexec/aurora-snapshot apt) takes a snapshot before dpkg changes anything, at most one per ten minutes (an upgrade runs dpkg several times), and keeps the last - It skips itself inside the installer's chroot;
- Timeshift's own schedule keeps 5 daily and 3 weekly snapshots;
- grub-btrfs adds an "Aurora OS snapshots" submenu to GRUB, and its daemon (
grub-btrfsd --timeshift-auto) refreshes it whenever a snapshot appears or goes. It isn't packaged in Debian, so the build installs the upstream 4.13 release pinned by SHA-256. Its menu script stays disabled on the live system and on non-btrfs installs.
- the installer's
- Timeshift snapshots are writable, so the snapshotted system boots normally from the menu. Restoring it for good is one click in Timeshift.
Swap: zram (systemd-zram-generator) + optional swap file
- Alternatives: swap partition only, zswap, zram-tools.
- Why: compressed swap in RAM makes low-memory machines feel much faster and saves SSD writes. systemd's generator needs no configuration. Fedora made the same choice.
Login: greetd + Aurora Greeter
- Alternatives: GDM, SDDM, LightDM, ly.
- Why: greetd is a tiny, secure login daemon made for Wayland. The greeter is our own GTK 4 app, so the login screen matches the desktop. It talks greetd's simple JSON protocol, which the unit tests cover. GDM pulls in GNOME Shell, SDDM is Qt-based, and LightDM is X11-oriented.