Herizon Linux · Offline tools and qualification

The offline toolkit and the checks behind a release

By J.E. Herizon LLC · Published October 6, 2026

A disconnected workstation needs useful applications as well as a bootable desktop. Herizon Linux packages an offline toolkit, then tests installation and selected features against the exact image that contains it.

October 6 status: 1.2.0-rc1, R11 is the latest built candidate. Actual BIOS installation and the ten-pack offline run passed within their recorded scope. Stable qualification remains open, including final UEFI installed use, graceful-reboot persistence, installed update recovery, visual acceptance, and physical hardware gates.

Then: from a catalog to a working image

The original catalog selected 200 direct Debian packages: 30 core selections and 170 optional selections across nine packs. A catalog establishes intent. It does not prove that dependencies are available, packages install without a network, or applications work in an installed desktop.

The newer candidate expands that selection to 226, including a cybersecurity pack and additional development tools. More importantly, R11 has an actual installed BIOS guest receipt: all ten optional packs completed with APT's --no-download policy and external routes absent. The final package inventory matched every selected package's expected version and installed status.

Now: ten packs with a defined offline boundary

The 226 figure counts 30 core and 196 optional direct Debian package selections. Dependencies are additional. It is neither a count of distinct end-user applications nor a universal popularity ranking. The core includes the Xfce desktop's ordinary tools; optional packs group software around work people want to do.

PackExamples in the candidate catalogWork it supports
OfficeLibreOffice Writer, Calc, ImpressDocuments, spreadsheets, presentations
CreativeGIMP, Inkscape, Krita, BlenderImages, vector work, drawing, 3D
DevelopmentGit, Python, GCC, Rust, ripgrepBuild, debug, inspect, and navigate projects
CybersecurityNmap, Wireshark, YARA, Sleuth KitAuthorized analysis, packets, and forensics

Internet, media, accessibility, system, games, and science complete the ten optional categories. Installing their cached packages can work offline; an application's external service, online content, or current data feed may still need connectivity. The app-pack menu is available with AI off. Read the offline-pack evidence and scope before treating a package's presence as a tested workflow.

Let the package manager own installation

The pack installer accepts a selected cataloged pack and uses normal APT with its local archive cache. It does not accept an arbitrary generated package command. This gives a user an understandable choice and keeps package resolution within Debian's tooling.

Offline caches belong to a particular package snapshot. After online updates, cached dependencies can stop matching the installed system. A missing archive should produce an installation failure rather than an unnoticed download. Offline availability is therefore a tested property of a named image and package state, not a permanent guarantee for every future version.

Exercise tools, not just version strings

R11 also includes pinned upstream tool packages for uv, Ruff, Nuclei, and Trivy, with recorded download hashes and license notices. The installed run checked their exact versions and ten local positive and negative fixtures. This tests selected behavior as well as whether an executable starts.

A scanner finding a deliberately vulnerable local fixture says something useful about that test. It does not establish comprehensive detection, an up-to-date vulnerability database, or readiness to scan third-party systems. The same distinction applies to Suricata: its engine is available in the cybersecurity pack, but production rules were absent, and the candidate's default service interface failed to match the guest interface. Network protection remains unready.

Now: read the release gates separately

R11 passed 297 artifact-inspection checks. Its owned BIOS guest also exercised the graphical installer, cancellation, first-login setup, local CPU/controller operation, and package features. Each receipt answers a different question. An ISO hash binds evidence to bytes; it does not prove a successful install. An installed package inventory does not prove every application's full behavior.

Persistence needs the same discipline. Four actual assistant-state files remained byte-identical across a distinct recovery boot. That was a bounded preservation result after an aborted VM transition, not the required two graceful disk-only reboots. The candidate also has a measured keyboard-focus contrast failure. These findings remain visible rather than being folded into an overall pass.

Signed-update fixture results are separate from an installed R11 update and a working production endpoint. Physical hardware, complete USB flash readback, and final graphical acceptance also retain their own gates. The qualification summary records what remains open.

Vision: a toolkit that stays useful after installation

The next architecture brings local assistance to terminal, desktop, and selected-file search independently of chat visibility. Shift+Tab assistance and native per-user manifests are planned work; the current R11 assistant still follows its earlier opt-in chat lifecycle. The goal is to explain a package, file, or device operation using current evidence and route supported actions through established adapters.

Release promotion must follow fresh BIOS and UEFI installed tests, feature and persistence checks, update recovery, visual review, and designated hardware verification. For a developer, that should mean clearer expectations about offline work. For a system owner, it should mean knowing which image was tested, which state survived, and which recovery path has actually been exercised.

Explore Herizon Linux and the engineering behind its local assistant.