MAS

Install MAS

The installer erases the whole disk you choose. Back up anything you need first.

1. Check the download

sha256sum masdistro-amd64.hybrid.iso

The result must match this checksum:

3670e65dd716164e2ae17a6419c1c8a88ba6c6da940227270610e95db65a0313

For a stronger check, download SHA256SUMS and SHA256SUMS.asc. Also download the public key. Its fingerprint is AD97 4298 3813 9A91 B6F0 01CD 7CEF 9838 D6C1 74C4. Check that it matches before you trust it. Then run:

gpg --import mas-distro-public-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS --ignore-missing

2. Write the ISO to a USB stick (8 GB or more)

Linux: find your stick with lsblk, then run this. The wrong device name will erase the wrong disk.

sudo dd if=masdistro-amd64.hybrid.iso of=/dev/sdX bs=4M status=progress oflag=sync

Windows or macOS: use balenaEtcher.

3. Boot and connect

Boot from the USB (usually F12, F10, Esc or Del at power-on). The live desktop opens and you can try MAS without installing. Connect to Wi-Fi or plug in Ethernet, because the install downloads packages.

Live session login: user live, password live. This is only for the USB session, not your installed system.

4. Run the installer

Double-click MAS Installer on the desktop. If the graphical one has a problem, use MAS Installer (terminal).

Nothing is written to disk until you confirm on the last screen. You can go back at any step.

Step What you choose
Disk The target disk. It refuses the disk you booted from or any disk in use.
Dual profile One system or two. See Two profiles.
Passphrase One per profile. It can be left blank, but then the disk is not protected.
Kernel stable (Debian default, recommended), backports (newer), or manual (advanced)
Graphics driver Detected for you
Secure Boot The installer checks whether it is on and tells you what that means for NVIDIA
Privacy A list of toggles, all on by default. See Privacy.
Sandboxing Optional firejail per-app sandboxing, off by default
Extras Firefox ESR (on) and fastfetch (off)
System setup Hostname, admin user, passwords
Locale and network Language, timezone, keyboard, Wi-Fi
Confirm Review everything, then start

The install takes a while. It downloads the base system, the kernel and KDE Plasma.

5. Save your LUKS header backups

When the install finishes, the installer says the LUKS header backups are in ~/mas-build/luks-headers. That folder is in the live session and is erased when you reboot. Copy it to a USB drive or another computer first. See Recovery for why.

6. First boot

  1. Remove the USB and reboot.
  2. Enter your passphrase once, at boot.
  3. Log in with the admin user you created.

If the install stops

Run the installer again without rebooting the USB. It finds the saved progress and offers to resume, and stages whose settings haven't changed are skipped. The progress is kept in the live session, so if you reboot the USB the install starts from the beginning. See How MAS works.

Updating

sudo apt update && sudo apt full-upgrade