Making Changes in Thinux
Our Neo and Micro ranges of products come pre-installed with our Thinux Embedded Linux operating system.
Thinux is based on Ubuntu Linux. At the time of writing, it is based on Ubuntu 20.04.4 LTS on the Micro 5 and Ubuntu 22.04.1 on the Micro 6. However, Thinux differs from Ubuntu in some significant ways. First, we include drivers specific to our hardware that are not available in upstream repositories. We also include system services that protect the hardware from damage. This may seem unusual to people who are used to PCs with a BIOS. Intel and AMD processors have built-in thermal protection: they reduce their clock speed and turn off some cores when they approach overheating. In the worst case, the processor and the BIOS abruptly power off the computer to prevent damage. ARM processors do not yet provide this level of protection. The U-Boot bootloader used on ARM systems does not stay in memory after it transfers control to Linux, so it does not protect hardware components from thermal or other damage in the background.
For this reason, when customers ask us to disable or replace Thinux on our ARM-based products, we inform them that this will void their hardware warranty. This policy is similar to the policy of Android phone manufacturers for unlocking bootloaders. To get the system root password, you must call or write to us. If your device is ARM-based, we must mark it as warranty void before we give you the password.
The main difference between Thinux and Ubuntu is that Thinux mounts its root file system read-only. You therefore cannot use apt and other commands to make changes to the OS. If you have the root password, you can make changes to /etc and /var. Processes that run with root privileges also make changes to /etc and /var, even when the user does not have the root password. Thinux stores these changes in the /overlay partition, not in the / partition. You can read more about the overlay filesystem on kernel.org.
To make changes to /, you must first remount the / filesystem in read-write mode. Run the following commands in a terminal:
su - # enter the root password when prompted
umount -l /etc
umount -l /var
mount -o rw,remount /
You can now make changes to /. When you have finished, reboot the system to return the root filesystem to read-only (ro) mode.
If you no longer want to use the read-only root feature of Thinux, you can turn it off permanently by making the following changes to /etc/fstab. First, lazily unmount /etc as shown in the previous code block. A typical /etc/fstab file looks like this:
proc /proc proc defaults 0 0
LABEL=thinux / ext4 defaults,ro,noatime 0 1
LABEL=data /overlay data defaults,noatime 0 2
mount_over /etc over defaults,x-systemd.requires-mounts-for=/overlay 0 0
mount_over /var over defaults,x-systemd.requires-mounts-for=/overlay 0 0
mount_over /home over defaults,x-systemd.requires-mounts-for=/overlay 0 0
mount_over /tmp over defaults,x-systemd.requires-mounts-for=/overlay 0 0
/overlay/swapfile swap swap pri=-1,x-systemd.requires-mounts-for=/overlay 0 0
Change it to look like this:
proc /proc proc defaults 0 0
LABEL=thinux / ext4 defaults,rw,noatime 0 1
LABEL=data /overlay data defaults,noatime 0 2
#mount_over /etc over defaults,x-systemd.requires-mounts-for=/overlay 0 0
#mount_over /var over defaults,x-systemd.requires-mounts-for=/overlay 0 0
mount_over /home over defaults,x-systemd.requires-mounts-for=/overlay 0 0
mount_over /tmp over defaults,x-systemd.requires-mounts-for=/overlay 0 0
/overlay/swapfile swap swap pri=-1,x-systemd.requires-mounts-for=/overlay 0 0
We use a read-only root filesystem for the following reasons. More than 99% of our customers do not need to install new software on their computers. They use their computers as thin clients or cloud computers, and do most of their work in the RDP client or the web browser. The pre-installed software, such as LibreOffice, is enough for their work. Instead of updating individual packages with apt, we upgrade the entire root file system at once, as a single binary image. Other embedded operating systems, such as Android and iOS, update in a similar way (although they have apps and Thinux does not). This allows us to test each update thoroughly on our own hardware before we release it, and to ensure that all changes and updated applications in the update work well together. It also prevents a user’s computer from becoming unusable when an apt or dpkg upgrade is interrupted, as our update system handles abrupt power-offs safely.