Skip to content

Latest commit

 

History

363 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

OPEMOS gradient pill

OPEMOS

Command-line packaging and exact-kernel NVIDIA enablement for SteamOS.

OPEMOS checks status OPEMOS documentation status MIT license

OPEMOS—Open Packaging for Exact-kernel Modules on SteamOS—is the unofficial command-line and automation toolkit for building, authenticating, packaging, and installing NVIDIA open kernel modules matched to an exact SteamOS release, Neptune kernel, architecture, and NVIDIA userspace version. It fails closed rather than substituting a nearby kernel or unreviewed userspace payload.

Choose an interface

I want to… Use
Build a recovery image through a graphical macOS application OPEMOS.EXE · Documentation
View installed NVIDIA recovery health in SteamOS Desktop Mode OPEMOS native status companion
Test or integrate the temporary no-input boot display OPEMOS DRM/KMS interstitial
Inspect, build, validate, publish, or install from a terminal or automation OPEMOS CLI · continue below

Important

This project is under active development. Published artifacts are exact-kernel builds, but a completely fresh-stock installation and NVIDIA hardware boot still require end-to-end certification. Read the trust status shown by the resolver; do not treat locally-built-verified as certified-published.

Start here

OPEMOS documentation

Preview the no-input update interstitial

Host Bounded headless command Scope
macOS ./test_update_macos.sh --no-open --duration 5 Linux/SteamOS preview; no macOS driver update.
Linux ./test_update_linux.sh --no-open --duration 5 Loopback preview; no driver update or system change.
Windows .\test_update_windows.ps1 -NoOpen -Duration 5 Linux/SteamOS preview; no Windows driver update.

Steam Deck terminal installation

Open Konsole in Desktop Mode. Inspect the selected release without changing the system:

cd ~ && bash <(curl -fsSL "https://raw.githubusercontent.com/CorniiDog/OPEMOS/main/bootstrap/online_setup_nvidia.sh?x=$(date +%s)") --resolve-only

Install the matching published modules and userspace:

cd ~ && bash <(curl -fsSL "https://raw.githubusercontent.com/CorniiDog/OPEMOS/main/bootstrap/online_install.sh?x=$(date +%s)")

The canonical installer also installs a persistent boot guardian. On every activated SteamOS slot it verifies all five NVIDIA modules against the running kernel and installed userspace before the display manager starts. If an A/B update activates a kernel without matching modules, it enters a console-safe recovery profile instead of allowing a black graphical boot. Inspect or repair it through the UI-neutral JSON contract:

sudo /home/.steamos/open-gpu-kernel-modules-steamos-support/recovery/bootstrap/recoveryctl.sh status --json
sudo /home/.steamos/open-gpu-kernel-modules-steamos-support/recovery/bootstrap/recoveryctl.sh repair-online --json

Automatic fallback disables both NVIDIA and Nouveau. An Intel/AMD boot-VGA desktop is accepted only after hardware validation; Nouveau is experimental and requires the explicit --allow-nouveau option. Fallback is removed only after exact NVIDIA module verification succeeds.

The online bootstrap currently downloads from mutable main; review the public installer trust limitations before using it on a production system. For local review, clone the repository and inspect help before mutation:

git clone https://github.com/CorniiDog/OPEMOS.git opemos
cd opemos
./bootstrap/setup_nvidia.sh --resolve-only
./bootstrap/online_install.sh --help

Uninstall:

cd ~/opemos
./bootstrap/uninstall.sh

Development

Run the non-destructive local suite:

./tests/check.sh

On Apple Silicon, use the pinned x86_64 Fedora VM for Linux-only transaction, Btrfs, mount, chroot, and cancellation coverage:

./tests/vm/run.sh

Repository boundaries

Repository Responsibility
OPEMOS CLI workflows, exact artifact resolution, builds, userspace locks, offline installation, provenance, and publication
OPEMOS.EXE Desktop UI, recovery-image inspection, appliance lifecycle, safe image export, and independent final-image validation

The authoritative, read-only repository and UI exception rules are in BOUNDARIES.md. Responsibility summaries elsewhere are non-authoritative. | open-gpu-kernel-modules-steamos | Versioned NVIDIA source branches and SteamOS-specific patches |

Safety properties

  • Exact target kernel, architecture, NVIDIA version, module vermagic, and five-module inventory are mandatory.
  • Normal resolution fails closed instead of selecting a closest kernel.
  • Offline installation uses authenticated, reviewed local inputs and never examines the Fedora appliance's running kernel.
  • Image mutation is confined to a disposable overlay; the original recovery image must remain unchanged.
  • Failed or cancelled transactions require verified mount, compression-policy, and temporary-state cleanup before their result can be trusted.

See the security model and complete technical reference for the exact contracts and remaining certification gates.

About

Exact-kernel NVIDIA open-module packaging, verification, and offline installation for SteamOS.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages