Manual signed updates
How Lunex updates work
The update framework is included in Lunex 0.8. Its production channel has not been activated.
No production verification key is enrolled in this build. Settings shows updates as not configured and disables online checks.
You stay in control
Opening Settings does not make an update request. After the owner activates the service and enrolls a trusted public key in a reviewed build, the intended process is:
- Check deliberately. Set the clock correctly, connect to the Internet, and choose Check for updates.
- Review and download. Read the release description. The client validates the signature, expiry, sequence, architecture, exact installed baseline, and downloaded file hashes.
- Review the saved bundle. Check the affected system files and keep an independent backup.
- Install from the installed rescue console. Save your work and follow the exact instructions displayed by the client. Updates never silently restart applications or install themselves.
- Reboot after success. Confirm that the updated installed system starts normally.
A focused maintenance channel
Only a fixed set of existing desktop and integration files can be updated. This is not a general Linux package manager, a seamless fleet updater, or an updater for the kernel, drivers, Firefox runtime, bootloader, installation system, or every application.
Old Aster 0.7 installations must use the separate, exact-baseline offline repair first. A disabled client cannot obtain its initial trust key from an untrusted website. Owner activation and key enrollment are separate security-sensitive steps.
Interruption and recovery
Original files are verified and durably backed up, but the full update is not one whole-filesystem atomic transaction. A power cut can require explicit recovery. If an update is pending, normal boot stops before networking and updated services. Follow the displayed rescue-recovery instructions rather than attempting to bypass the safeguard.
Recovery can refuse independently modified files or damaged backups. Keep the update’s root-owned backups. A completed most-recent update can be rolled back through the supported rescue workflow; do not delete security state to force an older release.
Privacy and trust
The updater has no feedback or telemetry feature, no scheduled checks, and no automatic installation. A deliberate request sends no username, hostname, account information, or device ID. Standard web hosting still sees connection information such as an IP address and the generic updater user agent.
Signatures help establish release integrity and publisher authorization. They do not prove software is harmless. The publisher’s private signing key must never be distributed with the OS, uploaded to the public web host, or shared in chat.
Until activation is completed and verified end to end, use only the reviewed release downloads and their documented installation or exact-version repair instructions.