esOS 1.0 - Encryption Studio OS Release notes Copyright (c) 2026 Koray USTUNDAG. All rights reserved. https://esos.korayustundag.com.tr/ esOS is a live operating system for file encryption. It boots from a USB stick, runs entirely in RAM, has no network stack, and never writes to the computer's disks. It exists to run Encryption Studio X (esx) in a small, auditable environment. WHAT IS IN 1.0 - Encryption Studio X (esx): password- and RSA-based file encryption, RSA key generation (2048-16384 bit). Run "esx --help". - LUKS2 / dm-crypt containers with cryptsetup 2.8.8. - OpenSSL 3.5.8 (LTS). - Reads and writes USB, NVMe, SATA and SD/eMMC storage with ext4, FAT, exFAT, NTFS, ISO 9660, Btrfs and XFS file systems. - keyboard_setup: Turkish Q, Turkish F, English (US/UK), German, French, Spanish, Italian and Russian layouts, chosen from a menu or detected by pressing a few keys. - Boots on UEFI and legacy BIOS, from USB or optical media. SECURITY DESIGN - No TCP/IP: the kernel is built without an IP stack and without network drivers. - Root file system in RAM only; no swap, no hibernation, no core dumps. - Kernel lockdown (confidentiality mode), Yama ptrace restrictions, IOMMU enabled by default. - Memory is zeroed on allocation and on free. - Every third-party source package was verified against its upstream SHA-256 and PGP signature before building. SYSTEM REQUIREMENTS - 64-bit x86 processor with the x86-64-v3 feature level (AVX2, BMI2, FMA, MOVBE): Intel Haswell (2013) or newer, AMD Excavator / Zen or newer. On older processors esOS does not start, and may stop without an error message. - At least 1 GB of RAM (2 GB recommended; the default LUKS2 key derivation uses up to 1 GB). - UEFI with Secure Boot DISABLED, or legacy BIOS. The image is not signed for Secure Boot. - A USB stick of 64 MB or more. VERIFYING THE DOWNLOAD sha256sum -c SHA256SUMS gpg --verify SHA256SUMS.asc SHA256SUMS (when a signature is published) WRITING TO A USB STICK Linux / macOS: sudo dd if=esos-1.0-x86_64.iso of=/dev/sdX bs=4M status=progress conv=fsync (replace /dev/sdX with the USB stick - everything on it is erased) Windows: Rufus (choose "DD Image mode" when asked) or balenaEtcher. FIRST STEPS keyboard_setup choose the keyboard layout (the default is US) esx --help encrypt and decrypt files hwreport hardware and security summary poweroff shut down; mounted USB sticks are unmounted safely KNOWN LIMITATIONS - There is no network by design; files are exchanged with USB storage. - Nothing is saved between boots: settings such as the keyboard layout are chosen again after each start. - On Apple keyboards some punctuation keys are placed differently from PC keyboards; if automatic detection picks the wrong layout, choose it from the keyboard_setup menu. - Printing an encrypted file to the screen (cat file.enc) shows random characters; the console is restored automatically at the next prompt. Use "less file.enc" or "od -c file.enc | less" to inspect binary files. LICENSES AND SOURCE CODE esOS includes free software from many projects - the Linux kernel, GRUB, the GNU C Library, GNU tools, OpenSSL, cryptsetup and others - each under its own license. See THIRD-PARTY-NOTICES.txt, and LICENSES/ on the ISO (/usr/share/licenses inside esOS). The complete corresponding source code of the GPL- and LGPL-licensed components is published next to this release as esos-1.0-source.tar.