Goal: try Linux inside Windows, keep your work, and choose native boot later.

▶ A published native cycle with a green result, sped up. It shows the stages selected by that run; a Windows return is a separate check. Play the full timelapse. The publish gate needs a green run.
wootc installs a real Linux desktop from a bootc
image into root.disk, a file beside your Windows files. The native path adds a boot entry.
Current releases do not yet provide the complete Linux-inside-Windows journey.
The verification status describes the evidence and limits.
The roadmap keeps VM-first use and complete restoration as release requirements.
The setup form asks for a password. The app suggests your username and computer name from your PC. It sizes the disk from available space and selects TPM encryption by default. Advanced lets you change those choices. Supported migration helpers can carry files, Wi-Fi networks, wallpaper, and taskbar choices. Results depend on the image and helper.
⬇ Download the latest release — run the exe as Administrator. It fetches boot artifacts, checks hashes, and verifies a signed manifest. The current Wails interface needs the WebView2 runtime. Windows may prompt you to install it.
winget install TunaOS.wootc
(winget availability lands with the first accepted submission.)
Every release also ships branded installers — Bazzite-Installer.exe,
Bluefin-Installer.exe, Aurora-Installer.exe, TunaOS-Installer.exe — the
same engine with each distribution's identity and preselected images.
They can pre-download the OS on Windows for deployment without a network after reboot.
The binaries are not yet code-signed. Windows may show SmartScreen or an "unknown publisher" prompt. Policy can prevent continuation. First steps explains those prompts; the user guide describes later steps and uninstall limits. For a hardware trial, read the manual test guide first.
Windows 11 → wootc.exe (arms the system) → reboot
→ signed shim → GRUB → deployer initramfs
→ fisherman: bootc install into root.disk
→ reboot → Windows → Manage: choose Linux boot
→ native Linux, loop-mounted from root.disk
→ (optional, later) graduate to a real partition
- Arm. The app creates
root.diskon the selected drive and stages a signed boot chain on the ESP. It changes Windows startup settings and sets a one-shot boot entry before you restart. - Deploy. Under Secure Boot, the signed chain launches the installer environment.
It writes the chosen OS image into
root.disk, with optional LUKS/TPM2 encryption. Windows normally returns after deployment. Manage offers an explicit Linux boot choice. - Live in both. A boot hook attaches
root.diskand boots the native Linux system. Windows stays on the boot menu. Supported bridges expose your selected files from Windows in Linux. - Choose what comes next. Graduate Linux to a blank disk after explicit checks, or keep both systems. Uninstall tries cleanup; it can leave files or boot state behind. Linux data removal is a separate choice in Manage.
- A password is the whole form. Solid defaults for everything else, stated on screen and adjustable under Advanced.
- Migration helpers cover files, Wi-Fi networks, wallpaper, accent color, keyboard layout, and taskbar pins. They also cover browser profiles (Firefox, Chrome, Edge), Steam libraries, MS Office → LibreOffice choices, and WSL dotfiles/packages. A complete Firefox profile can include saved passwords. Other app sessions may need you to sign in again. See the user guide for each helper's limits.
- BitLocker-safe by design. C: is never decrypted — Linux gets its own unencrypted space while your Windows drive stays protected. Gated off in the alpha until the FDE path is matrix-green (#34). The app stops and explains this gate on an encrypted drive.
- Image catalog — GNOME, KDE Plasma, Niri, and XFCE desktops on Enterprise Linux, Fedora, Arch, and Debian bases. Custom OCI images need the channel and compatibility gates.
- VM-first goal — Linux must run inside Windows before native boot. The complete Windows-hosted desktop and persistent user-work journey remain unproved.
- An honest way back. Windows Apps offers uninstall. Cleanup can fail and report incomplete restoration. Partition removal needs current ownership and disk checks. Linux data removal is a separate choice.
Automatic tagged releases need a full end-to-end run on the selected build. The current tagged workflow uses the real GUI in Windows 11 with Secure Boot and TPM 2.0. It selects native deployment, Linux boot, and graduation. That path ends in graduated Linux; it does not prove a Windows return after graduation.
The manual emergency waiver remains in release instructions. Nightly green runs can cut automatic pre-releases from their tested commit. Required checks must pass before a normal release.
The matrix in docs/status.md records image families, Windows editions, filesystems, and encryption modes. Historical beta releases do not prove the current VM-first or native-shell journey. See the ROADMAP for the version ladder and evidence gates. docs/philosophy.md explains the product goals.
| Getting started | download → first boot, screen by screen |
| User guide | living in the migrated system, and the way back |
| Philosophy | the North Star, the Wubi heritage, why a file |
| Status | the proven matrix and its evidence |
| SPEC | the full specification |
| Architecture boundary | the generic-migration / bootc seam |
| NTFS on Linux | the known hazards, and why the design survives them |
| Borrowed from Libertix | six boot-chain and recovery designs, specified against wootc's code, with task lists |
| WinUI 3 shell | the native Windows shell that replaces Wails: architecture, engine protocol, cut-over |
| Branding & distribution | one engine, five installers |
| Manual testing | pre-flight for real-hardware runs |
The current Windows app uses Wails (Go + web). The stack also has a dracut deployer initramfs, POSIX-shell migration tools, and a KVM E2E harness. That harness drives the real GUI in Windows VMs.
just test # fast tier: bats + go, no containers
just build # deployer initramfs + custom GRUB
cd tests/gui && npx playwright test # GUI suite over the built frontendSee the contribution guide. Start with a red or unproven matrix cell or an incomplete milestone task on the task boards.
Installer components for Windows derive from WubiUEFI and use GPL-2.0 (LICENSE-GPL-2.0); the deployer initramfs and GRUB configuration are MIT (LICENSE-MIT). fisherman, bootc, bootupd, podman, and skopeo are separate binaries under their own (Apache-2.0) licenses, invoked over a process boundary.