Rime 2026.09.28.4
APEX-OS is now Rime
The first release under the Rime name: APEX-OS becomes Rime OS and APEX Shell becomes Rime Shell. The first boot and first login move your system and desktop settings to the new names, the old names keep working as aliases, and a rollback to APEX keeps working. The core layer was rebuilt, so this is a full download.
Highlights
APEX-OS is now Rime OS, and APEX Shell is now Rime Shell
The system, the shell, the boot splash wordmark (RIME OS) and the image carry the new name. The command is now rime; apex still works and prints a one-line note that the command is now rime.
The note goes to stderr only, so scripts and tools that read apex output keep working. The old names of 21 service units, 47 helper programs and the old /usr/share paths are kept as aliases. Some names stay as they were so existing machines and paired phones keep working: the APEX folder on the EFI system partition and the 'APEX-OS Primary' firmware boot entry, the Rime Remote pairing scheme, relay and wire labels, backup formats, and the apex image tag (with rime added beside it).
The first boot moves system state to the new names
A one-time service moves APEX's state and settings (/var/lib/apex* and /etc/apex*) to their Rime names, re-points which services are enabled, renames a saved Rime Remote firewall exception, and updates the login screen's remembered session to its new name.
Your first login moves your desktop settings to the new names
Your apex folders under ~/.config and the other XDG directories, ~/.config/hypr/apex, the shell's config, cache and state, and your user services move to their Rime names. The shell's old directories are left behind as links, and its migration never overwrites anything.
Your own files are rewritten only where an old name stops working. Because this release keeps every old name as an alias, Hyprland binds, niri's autostart, labwc commands and menus, and ~/.zshrc are left as they are. Quickshell IPC calls are the exception: they move to /usr/share/rime-shell now, and hypridle's lock command becomes a chain that tries the APEX path and then the Rime one, so the idle lock works on either image. On the first start the shell waits up to 2 seconds for its own migration; after that it starts without waiting.
Images are signed by the renamed repository
Because the repository is now AndreNijman/rime-os, images are signed by its build workflow. Machines on 2026.09.28.3 already accept that identity, so they verify and install this update.
System
ImprovedPackages you installed keep working
Packages added with
apex installlive in an extension named apex-user. The renamed package tool adopts it as-is, so nothing is rebuilt or downloaded at the first boot.ImprovedThe image moves to ghcr.io/andrenijman/rime-os
Every build is published under both ghcr.io/andrenijman/rime-os and ghcr.io/andrenijman/apex-os, with a new
rimetag besideapex. A machine on 2026.09.28.3 that tracks an apex-os tag switches to the same tag under rime-os on its next update.ImprovedRolling back to APEX keeps working
The secret store stays where APEX expects it, the generated Hyprland keybinds stay usable by APEX Shell, and niri's config no longer collects a duplicate block on each round trip.
A test build of this release was taken APEX to Rime to APEX to Rime in a VM. On every boot the first-run step succeeded, Hyprland reported no config errors, every keybind was registered once, a stored credential was readable and the idle lock reached the running shell. The niri fix came after that run and is covered by the automated tests.
rime-os #71rime-shell #29rime-os 01f9c56erime-shell 741cecb4rime-os 4d7ce31e
Known issues
Machines that skipped 2026.09.28.3 do not know the new signer
Images built after the rename carry a new signer, and machines learned it in 2026.09.28.3. A machine on an older image, with the default signature=enforce, refuses images signed only by the new identity.
Your own apex-shell IPC binds stop working after a rollback
A bind of your own in labwc or niri that calls
qs -p /usr/share/apex-shellis rewritten for Rime, so it does nothing if you roll back to APEX.labwc keybinds saved on Rime use the new command
labwc keybinds saved again on Rime run
rime shell …, which an APEX image does not have, so they fail after a rollback.Both package extensions merge after a rollback
If you change packages on Rime and then roll back to APEX, APEX merges both apex-user.raw and rime-user.raw.
Full download
This build rebuilt the core layer, so the update is a full download for every machine.
Provenance
- Release
- 2026.09.28.4
- OS revision
- 2d9c5438acf8bd5ea83e9c7d05332415b05be295
- Shell revision
- 6289d1f89916d3432ca3bd1f4ca68db7141559d9
- Image digest
- sha256:86180f68e80525052929ca1f40e67dbf9570dd7cdbe43e31e058c62028cb2f3b
- Reissued
- sha256:142bc4e2a5ff73b1b98c27cdfa1db8b453b19cb7301b69eeb97775cfe8747e7a
2026-09-28T14:22:55.000Z · AndreNijman/rime-os/actions/runs/36424778175 · Weekly scheduled rebuild of the same OS and Shell revisions, Fedora base and kernel. Every channel tag serves this digest now. - Channel
- edge
- Released
- 2026-09-28T13:45:01.000Z
Published to every image tag (apex, daily, edge, gaming-mesa, gaming-nvidia, rime). All of them are the edge channel today. This page explains the release; it is never consulted by an update. What a machine installs is decided by the registry and the image signature (see Security). Machine-readable: 2026.09.28.4.json.
If something is wrong
Go back to the image you were running before this one. It becomes the default at the next boot; your files and settings stay as they are.
sudo rime rollback && sudo systemctl rebootOn an APEX-named system the command is apex. You can also pick the previous entry in the boot menu. More in Rolling back and Recovery.
What this release does when you roll back
A rollback to APEX keeps working (found by booting the test image in a VM, then rolling back). The secret store stays at /var/lib/apex-secretd: APEX's apex-secretd.service refuses a symlinked StateDirectory, so rime-secretd.service declares StateDirectory=apex-secretd:rime-secretd and systemd links the new name to it. Users' files are rewritten only where the old name stops working on this image. This release carries every old name as an alias, so hyprland.lua binds, niri's autostart, labwc commands and menus, and ~/.zshrc are left as they are and work on both images; a later release that drops an alias rewrites what uses it. Quickshell IPC calls are the exception (quickshell finds an instance by the path as given, so the alias cannot carry them): they move to /usr/share/rime-shell now, and in hypridle.conf they become qs -c /usr/share/apex-shell … || qs -c /usr/share/rime-shell … so the idle lock works on both. The generated Hyprland keybinds keep the APEX shell's APEX-SHELL-GENERATED marker, so after a rollback APEX regenerates the file instead of moving it into shell-keybinds-user.lua, where it had required itself (every bind registered 63 times). A stale copy loaded under another name binds nothing. On niri, a rollback lets APEX's first-run step append its own include block; the next Rime login removes it again, so round trips do not stack blocks. Known limits of a rollback: a user's own qs -p /usr/share/apex-shell bind in labwc or niri is rewritten and does nothing on APEX; labwc keybinds re-saved on Rime run rime shell …; after a package change on Rime, a rollback merges both apex-user.raw and rime-user.raw.