From bc9a4daca83a7ea01d2ebe43f94fec87b18c4206 Mon Sep 17 00:00:00 2001
From: Sten Tijhuis <102481635+Stensel8@users.noreply.github.com>
Date: Wed, 25 Feb 2026 00:35:24 +0100
Subject: [PATCH 1/4] chore: Maintaining docs
- Migrated docs under categories for better readability
- Shifted focus from Fedora to Arch (CachyOS)
- Updated the hextra theme submodule to the latest commit.
---
README.md | 23 +-
README.nl.md | 22 +-
content/_index.md | 104 +++--
content/_index.nl.md | 104 +++--
content/docs/_index.md | 100 +++-
content/docs/_index.nl.md | 100 +++-
content/docs/applications.md | 358 ++++++++++++++
content/docs/applications.nl.md | 358 ++++++++++++++
content/docs/getting-started.md | 435 ++----------------
content/docs/getting-started.nl.md | 435 ++----------------
content/docs/hardware/_index.md | 7 +
content/docs/hardware/_index.nl.md | 7 +
.../{ => hardware}/asusctl-rog-control.md | 78 +---
.../{ => hardware}/asusctl-rog-control.nl.md | 78 +---
.../nvidia-driver-installation.md | 314 +++++--------
.../nvidia-driver-installation.nl.md | 312 +++++--------
content/docs/hardware/secure-boot.md | 263 +++++++++++
content/docs/hardware/secure-boot.nl.md | 263 +++++++++++
content/docs/known-issues.md | 10 +
content/docs/known-issues.nl.md | 10 +
content/docs/networking/_index.md | 7 +
content/docs/networking/_index.nl.md | 7 +
.../eduroam-network-installation.md | 4 +-
.../eduroam-network-installation.nl.md | 4 +-
content/docs/news.md | 37 ++
content/docs/news.nl.md | 37 ++
content/docs/security/_index.md | 7 +
content/docs/security/_index.nl.md | 7 +
content/docs/{ => security}/autologin.md | 0
content/docs/{ => security}/autologin.nl.md | 0
content/docs/{ => security}/yubikey.md | 6 +-
content/docs/{ => security}/yubikey.nl.md | 6 +-
content/docs/virtualization/_index.md | 7 +
content/docs/virtualization/_index.nl.md | 7 +
.../looking-glass-attempt.md | 18 +-
.../looking-glass-attempt.nl.md | 18 +-
content/docs/{ => virtualization}/vm-setup.md | 6 +-
.../docs/{ => virtualization}/vm-setup.nl.md | 6 +-
static/icc-profiles/GA605WV_1002_104D158E.icm | Bin 3324 -> 0 bytes
static/icc-profiles/GA605WV_1002_834C41AE.icm | Bin 3536 -> 0 bytes
static/icc-profiles/GA605WV_1002_E5090C19.icm | Bin 3324 -> 0 bytes
static/icc-profiles/GA605WV_10DE_104D158E.icm | Bin 3324 -> 0 bytes
static/icc-profiles/GA605WV_10DE_834C41AE.icm | Bin 3536 -> 0 bytes
static/icc-profiles/GA605WV_10DE_E5090C19.icm | Bin 3324 -> 0 bytes
.../LS27B800TGUXEN - S80TB/SxxB80xT.icm | Bin 0 -> 536 bytes
static/icc-profiles/README.md | 121 +++--
.../Zephyrus G16 (2024) GA605WV/SxxB80xT.icm | Bin 0 -> 536 bytes
static/images/rog-control-system-control.png | Bin 0 -> 134361 bytes
static/images/secure-boot-fwupdmgr-after.png | Bin 0 -> 191145 bytes
static/images/secure-boot-gnome-after.png | Bin 0 -> 103816 bytes
static/images/secure-boot-hsi-report.png | Bin 0 -> 236734 bytes
static/images/secure-boot-sbctl-status.png | Bin 0 -> 33921 bytes
themes/hextra | 2 +-
53 files changed, 2147 insertions(+), 1541 deletions(-)
create mode 100644 content/docs/applications.md
create mode 100644 content/docs/applications.nl.md
create mode 100644 content/docs/hardware/_index.md
create mode 100644 content/docs/hardware/_index.nl.md
rename content/docs/{ => hardware}/asusctl-rog-control.md (68%)
rename content/docs/{ => hardware}/asusctl-rog-control.nl.md (69%)
rename content/docs/{ => hardware}/nvidia-driver-installation.md (61%)
rename content/docs/{ => hardware}/nvidia-driver-installation.nl.md (61%)
create mode 100644 content/docs/hardware/secure-boot.md
create mode 100644 content/docs/hardware/secure-boot.nl.md
create mode 100644 content/docs/known-issues.md
create mode 100644 content/docs/known-issues.nl.md
create mode 100644 content/docs/networking/_index.md
create mode 100644 content/docs/networking/_index.nl.md
rename content/docs/{ => networking}/eduroam-network-installation.md (90%)
rename content/docs/{ => networking}/eduroam-network-installation.nl.md (90%)
create mode 100644 content/docs/news.md
create mode 100644 content/docs/news.nl.md
create mode 100644 content/docs/security/_index.md
create mode 100644 content/docs/security/_index.nl.md
rename content/docs/{ => security}/autologin.md (100%)
rename content/docs/{ => security}/autologin.nl.md (100%)
rename content/docs/{ => security}/yubikey.md (83%)
rename content/docs/{ => security}/yubikey.nl.md (84%)
create mode 100644 content/docs/virtualization/_index.md
create mode 100644 content/docs/virtualization/_index.nl.md
rename content/docs/{ => virtualization}/looking-glass-attempt.md (94%)
rename content/docs/{ => virtualization}/looking-glass-attempt.nl.md (94%)
rename content/docs/{ => virtualization}/vm-setup.md (97%)
rename content/docs/{ => virtualization}/vm-setup.nl.md (97%)
delete mode 100644 static/icc-profiles/GA605WV_1002_104D158E.icm
delete mode 100644 static/icc-profiles/GA605WV_1002_834C41AE.icm
delete mode 100644 static/icc-profiles/GA605WV_1002_E5090C19.icm
delete mode 100644 static/icc-profiles/GA605WV_10DE_104D158E.icm
delete mode 100644 static/icc-profiles/GA605WV_10DE_834C41AE.icm
delete mode 100644 static/icc-profiles/GA605WV_10DE_E5090C19.icm
create mode 100644 static/icc-profiles/LS27B800TGUXEN - S80TB/SxxB80xT.icm
create mode 100644 static/icc-profiles/Zephyrus G16 (2024) GA605WV/SxxB80xT.icm
create mode 100644 static/images/rog-control-system-control.png
create mode 100644 static/images/secure-boot-fwupdmgr-after.png
create mode 100644 static/images/secure-boot-gnome-after.png
create mode 100644 static/images/secure-boot-hsi-report.png
create mode 100644 static/images/secure-boot-sbctl-status.png
diff --git a/README.md b/README.md
index e3e32f6..48a5180 100644
--- a/README.md
+++ b/README.md
@@ -2,18 +2,18 @@
English | [Nederlands](README.nl.md)
-Fedora 43 on the ASUS ROG Zephyrus G16 GA605WV (2024). My personal setup log — documenting what worked, what didn't, and how I fixed it.
+CachyOS on the ASUS ROG Zephyrus G16 GA605WV (2024). My personal setup log — documenting what worked, what didn't, and how I fixed it.
**Browse the full documentation site: [zephyrus-linux.stentijhuis.nl](https://zephyrus-linux.stentijhuis.nl/)**
## About this project
-This is my personal setup log for running Fedora Linux on this laptop. I'm not a software engineer or developer — just someone who switched to Linux and ran into a lot of things that didn't work out of the box. I figured I'd write it all down so others don't have to go through the same trial and error I did.
+This is my personal setup log for running CachyOS on this laptop. I'm not a software engineer or developer — just someone who switched to Linux and ran into a lot of things that didn't work out of the box. I figured I'd write it all down so others don't have to go through the same trial and error I did.
I'm still actively testing and experimenting — things may change, break, or turn out to be wrong. Everything here is based on my own experience and should be taken as-is, at your own risk.
-I am not affiliated with, endorsed by, or acting on behalf of ASUS, NVIDIA, Microsoft, Fedora, or any other company or project mentioned here.
+I am not affiliated with, endorsed by, or acting on behalf of ASUS, NVIDIA, Microsoft, CachyOS, or any other company or project mentioned here.
## System specs
@@ -24,8 +24,8 @@ I am not affiliated with, endorsed by, or acting on behalf of ASUS, NVIDIA, Micr
| **CPU** | AMD Ryzen AI 9 HX 370 |
| **iGPU** | AMD Radeon 890M |
| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
-| **OS** | Fedora 43 |
-| **Kernel** | 6.18+ |
+| **OS** | CachyOS |
+| **Kernel** | 6.19.3-2-cachyos |
| **Desktop** | GNOME 49 / Wayland |
| **Secure Boot** | Enabled |
@@ -35,8 +35,14 @@ I am not affiliated with, endorsed by, or acting on behalf of ASUS, NVIDIA, Micr
This documentation site is built with [Hugo](https://gohugo.io/) using the [Hextra](https://imfing.github.io/hextra/) theme. The theme is included as a git submodule.
**Prerequisites:**
-- [Hugo extended](https://gohugo.io/installation/) (v0.152.2 or later)
+- [Hugo extended](https://gohugo.io/installation/) v0.156.0 (built with this version)
- Git
+- Visual Studio Code
+
+On Arch Linux / CachyOS:
+```bash
+sudo pacman -S hugo
+```
**Clone with submodules:**
```bash
@@ -68,9 +74,8 @@ The output is written to `./public/`. On push to `main`, GitHub Actions builds a
This project wouldn't exist without the work of these people and communities:
-- **[Luke Jones](https://asus-linux.org/)** — Creator of `asusctl`, `rog-control-center`, and the `asus-armoury` kernel driver. The ASUS Linux project is the reason modern ASUS laptops work well on Linux at all.
-- **[RPM Fusion](https://rpmfusion.org/)** — Provides the packaged NVIDIA proprietary drivers for Fedora, making installation and Secure Boot enrollment straightforward.
-- **[Fedora Project](https://fedoraproject.org/)** — The distribution itself, with excellent hardware support and a fast release cycle.
+- **[Luke Jones](https://asus-linux.org/)** — Creator of `asusctl`, `rog-control-center`, and the `asus-armoury` kernel driver. The ASUS Linux project is the reason modern ASUS laptops work well on Linux at all. His patches have been merged into CachyOS, making it the best supported distribution for ASUS ROG hardware.
+- **[CachyOS](https://cachyos.org/)** — The distribution powering this setup. CachyOS is an Arch-based distro with extensive hardware-specific optimizations: an improved scheduler (BORE/EEVDF), better power management, dynamic refresh rate support, and built-in drivers for both the AMD iGPU and NVIDIA dGPU — including integrated GPU switching. Of all the distributions I tested (including Fedora, which came close), CachyOS is by far the strongest on this device.
- **[lz42/libinput-config](https://github.com/lz42/libinput-config)** — Third-party workaround for GNOME/Wayland's missing scroll speed setting.
- **[Looking Glass](https://looking-glass.io/)** — Low-latency VM display project. Didn't work on this hardware, but the project and documentation are excellent.
- **[Mastermindzh/tidal-hifi](https://github.com/Mastermindzh/tidal-hifi)** — Community Electron client for Tidal on Linux.
diff --git a/README.nl.md b/README.nl.md
index 1bff935..76ddced 100644
--- a/README.nl.md
+++ b/README.nl.md
@@ -2,18 +2,18 @@
Nederlands | [English](README.md)
-Fedora 43 op de ASUS ROG Zephyrus G16 GA605WV (2024). Mijn persoonlijke setup-log — wat werkte, wat niet, en hoe ik het heb opgelost.
+CachyOS op de ASUS ROG Zephyrus G16 GA605WV (2024). Mijn persoonlijke setup-log — wat werkte, wat niet, en hoe ik het heb opgelost.
**Bekijk de volledige documentatiesite: [zephyrus-linux.stentijhuis.nl](https://zephyrus-linux.stentijhuis.nl/nl/)**
## Over dit project
-Dit is mijn persoonlijke setup-log voor Fedora Linux op deze laptop. Ik ben geen software-engineer of developer — gewoon iemand die naar Linux is overgestapt en daarna tegen van alles aanliep wat niet meteen werkte. Ik heb alles opgeschreven zodat anderen niet hetzelfde hoeven uitzoeken als ik.
+Dit is mijn persoonlijke setup-log voor CachyOS op deze laptop. Ik ben geen software-engineer of developer — gewoon iemand die naar Linux is overgestapt en daarna tegen van alles aanliep wat niet meteen werkte. Ik heb alles opgeschreven zodat anderen niet hetzelfde hoeven uitzoeken als ik.
Ik ben nog actief aan het testen en experimenteren — dingen kunnen veranderen, kapot gaan of achteraf onjuist blijken. Alles wat hier staat is gebaseerd op mijn eigen ervaring en is op eigen risico.
-Ik ben niet gelieerd aan, goedgekeurd door, of handelend namens ASUS, NVIDIA, Microsoft, Fedora, of enig ander bedrijf of project dat hier wordt genoemd.
+Ik ben niet gelieerd aan, goedgekeurd door, of handelend namens ASUS, NVIDIA, Microsoft, CachyOS, of enig ander bedrijf of project dat hier wordt genoemd.
## Systeemspecificaties
@@ -24,8 +24,8 @@ Ik ben niet gelieerd aan, goedgekeurd door, of handelend namens ASUS, NVIDIA, Mi
| **CPU** | AMD Ryzen AI 9 HX 370 |
| **iGPU** | AMD Radeon 890M |
| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
-| **OS** | Fedora 43 |
-| **Kernel** | 6.18+ |
+| **OS** | CachyOS |
+| **Kernel** | 6.19.3-2-cachyos |
| **Desktop** | GNOME 49 / Wayland |
| **Secure Boot** | Ingeschakeld |
@@ -35,9 +35,14 @@ Ik ben niet gelieerd aan, goedgekeurd door, of handelend namens ASUS, NVIDIA, Mi
Deze documentatiesite is gebouwd met [Hugo](https://gohugo.io/) en het [Hextra](https://imfing.github.io/hextra/)-thema. Het thema is opgenomen als git submodule.
**Vereisten:**
-- [Hugo extended](https://gohugo.io/installation/) (v0.152.2 of later)
+- [Hugo extended](https://gohugo.io/installation/) v0.156.0 (gebouwd met deze versie)
- Git
+Op Arch Linux / CachyOS:
+```bash
+sudo pacman -S hugo
+```
+
**Clone met submodules:**
```bash
git clone --recurse-submodules https://github.com/Stensel8/Zephyrus-Linux.git
@@ -68,9 +73,8 @@ De output wordt geschreven naar `./public/`. Bij een push naar `main` bouwt GitH
Dit project zou niet bestaan zonder het werk van deze mensen en communities:
-- **[Luke Jones](https://asus-linux.org/)** — Maker van `asusctl`, `rog-control-center` en de `asus-armoury` kernel driver. Het ASUS Linux project is de reden dat moderne ASUS laptops goed werken op Linux.
-- **[RPM Fusion](https://rpmfusion.org/)** — Levert de verpakte NVIDIA proprietary drivers voor Fedora, waardoor installatie en Secure Boot enrollment eenvoudig zijn.
-- **[Fedora Project](https://fedoraproject.org/)** — De distributie zelf, met uitstekende hardware-ondersteuning en een snelle release-cyclus.
+- **[Luke Jones](https://asus-linux.org/)** — Maker van `asusctl`, `rog-control-center` en de `asus-armoury` kernel driver. Het ASUS Linux project is de reden dat moderne ASUS laptops goed werken op Linux. Zijn patches zijn gemerged in CachyOS, waardoor dit de best ondersteunde distributie is voor ASUS ROG hardware.
+- **[CachyOS](https://cachyos.org/)** — De distributie die deze setup aandrijft. CachyOS is een op Arch gebaseerde distro met uitgebreide hardware-specifieke optimalisaties: een verbeterde scheduler (BORE/EEVDF), beter energiebeheer, ondersteuning voor dynamische verversingsfrequentie, en ingebouwde drivers voor zowel de AMD iGPU als de NVIDIA dGPU — inclusief geïntegreerde GPU-switching. Van alle distributies die ik getest heb (waaronder Fedora, dat dicht in de buurt kwam), is CachyOS veruit de sterkste op dit apparaat.
- **[lz42/libinput-config](https://github.com/lz42/libinput-config)** — Third-party workaround voor de ontbrekende scroll speed-instelling in GNOME/Wayland.
- **[Looking Glass](https://looking-glass.io/)** — Low-latency VM display project. Werkt niet op deze hardware, maar het project en de documentatie zijn uitstekend.
- **[Mastermindzh/tidal-hifi](https://github.com/Mastermindzh/tidal-hifi)** — Community Electron-client voor Tidal op Linux.
diff --git a/content/_index.md b/content/_index.md
index 9b7c89f..9272691 100644
--- a/content/_index.md
+++ b/content/_index.md
@@ -11,7 +11,7 @@ toc: false
{{< hextra/hero-subtitle >}}
- What I learned running Fedora 43 on my Zephyrus — and what I wish someone had told me
+ Personal Linux setup and configuration notes for the ROG Zephyrus G16
{{< /hextra/hero-subtitle >}}
@@ -25,28 +25,16 @@ toc: false
{{< callout type="info" >}}
-**Personal documentation.** I'm not a developer or Linux expert — just someone who switched to Linux on this laptop and figured things out along the way. I share what worked for me so others don't have to start from scratch. Everything here is at your own risk. Feel free to reach out if something doesn't work; I'm happy to think along. Requires kernel 6.18+.
+**Personal documentation.** I'm not a developer or Linux expert — just someone who switched to Linux on this laptop and figured things out along the way. I share what worked for me so others don't have to start from scratch. Everything here is at your own risk. Feel free to reach out if something doesn't work; I'm happy to think along. Running kernel 6.19.3-2 on CachyOS (Arch).
{{< /callout >}}
## News
-### Kernel 7.0: ASUS laptop quirks + newer AMDGPU enablement
+- **Moved to CachyOS** — settled on CachyOS as daily driver after testing multiple distros; best hardware support for the G16
+- **Kernel 7.0** — ASUS laptop quirks and AMDGPU enablement for RDNA 3.5; Radeon 890M expected ~20% uplift
+- **Kernel 6.19** — `asus-armoury` driver merged into mainline Linux; CachyOS 6.19.3-2 includes it
-Linus confirmed the next kernel will be 7.0, with the merge window now open and a stable release expected mid-April 2026. For this ASUS ROG G16, the headline is better graphics driver coverage: the DRM updates bring AMDGPU enablement for newer RDNA 3.5-class IP blocks (GFX11.5.4) plus ongoing NVIDIA Nova/Nouveau work, which should translate into better handling of both the iGPU and dGPU. Early expectations are that the Radeon 890M could see around a 20% uplift moving from kernel 6.18 to 7.0. Not a drop-in upgrade for Fedora 43 yet, but a good sign for upcoming releases.
-
-**Sources:** [Linus confirms Linux 7.0](https://www.phoronix.com/news/Linux-7.0-Is-Next) · [HID laptop quirks for ASUS ROG models](https://www.phoronix.com/news/Linux-7.0-HID) · [Linux 7.0 DRM/AMDGPU updates](https://www.phoronix.com/news/Linux-7.0-Graphics-Drivers)
-
-### Kernel 6.19: asus-armoury driver lands in mainline
-
-The `asus-armoury` driver has been [merged into Linux 6.19](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19). This new `platform/x86` driver replaces parts of the older `asus-wmi` with a cleaner sysfs-based API, enabling panel mode switching, APU memory allocation, PPT tuning, and more directly from the kernel. The driver is entirely community-developed by [Luke Jones](https://asus-linux.org/) (ASUS Linux project), with no involvement from ASUS themselves. It's not just for handhelds like the ROG Ally; any recent ASUS gaming laptop benefits, including features in ROG Control Center like power limit adjustments.
-
-Currently on kernel 6.18, the driver is not yet available:
-
-
-
-Fedora 44 is expected to ship with kernel 6.19, bringing native asus-armoury support.
-
-**Sources:** [Phoronix article](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19) · [Community discussion](https://www.phoronix.com/forums/forum/software/linux-gaming/1593500-asus-armoury-driver-set-to-be-introduced-in-linux-6-19) · [Patch series (lore.kernel.org)](https://lore.kernel.org/all/20251102215319.3126879-1-denis.benato@linux.dev/)
+[Read all news →](/docs/news)
## Current System Configuration
@@ -56,8 +44,8 @@ Fedora 44 is expected to ship with kernel 6.19, bringing native asus-armoury sup
| **CPU** | AMD Ryzen AI 9 HX 370 |
| **iGPU** | AMD Radeon 890M |
| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
-| **OS** | Fedora 43 |
-| **Kernel** | 6.18.10-200.fc43.x86_64 |
+| **OS** | CachyOS (Arch) |
+| **Kernel** | 6.19.3-2 |
| **Display Server** | Wayland (GNOME 49) |
| **Secure Boot** | Enabled |
@@ -66,56 +54,88 @@ Fedora 44 is expected to ship with kernel 6.19, bringing native asus-armoury sup
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="Getting Started"
- subtitle="From fresh Fedora install to fully configured system"
+ subtitle="From fresh CachyOS install to fully configured system"
icon="play"
link="docs/getting-started"
>}}
{{< /hextra/feature-grid >}}
-## Reference Guides
+## Hardware & Drivers
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="NVIDIA Driver Installation"
- subtitle="Proprietary NVIDIA drivers with Secure Boot on Fedora 43"
+ subtitle="Proprietary NVIDIA drivers with Secure Boot on CachyOS"
icon="chip"
- link="docs/nvidia-driver-installation"
+ link="docs/hardware/nvidia-driver-installation"
>}}
{{< hextra/feature-card
- title="Windows 11 VM Setup"
- subtitle="KVM/QEMU VM with VirtIO and SPICE GL"
- icon="desktop-computer"
- link="docs/vm-setup"
+ title="Secure Boot"
+ subtitle="Custom signing keys with sbctl, HSI:3 to HSI:4"
+ icon="shield-check"
+ link="docs/hardware/secure-boot"
>}}
{{< hextra/feature-card
- title="GDM Autologin"
- subtitle="Skip GDM login after LUKS unlock"
- icon="lock-open"
- link="docs/autologin"
+ title="asusctl & ROG Control Center"
+ subtitle="Fan curves, performance profiles, GPU switching, Slash LED"
+ icon="adjustments"
+ link="docs/hardware/asusctl-rog-control"
>}}
+{{< /hextra/feature-grid >}}
+
+## Security & Privacy
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="YubiKey 5C NFC"
subtitle="FIDO2 LUKS unlock and what currently works"
icon="key"
- link="docs/yubikey"
+ link="docs/security/yubikey"
>}}
{{< hextra/feature-card
- title="Looking Glass Attempt"
- subtitle="GPU passthrough attempt, not working on this hardware"
- icon="eye"
- link="docs/looking-glass-attempt"
+ title="GDM Autologin"
+ subtitle="Skip GDM login after LUKS unlock"
+ icon="lock-open"
+ link="docs/security/autologin"
>}}
+{{< /hextra/feature-grid >}}
+
+## Applications
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
- title="asusctl & ROG Control Center"
- subtitle="Fan curves, performance profiles, GPU switching, Slash LED"
- icon="adjustments"
- link="docs/asusctl-rog-control"
+ title="Applications"
+ subtitle="Browser, communication, development tools, and system configuration"
+ icon="collection"
+ link="docs/applications"
>}}
+{{< /hextra/feature-grid >}}
+
+## Networking
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="eduroam Network Installation"
subtitle="PEAP/MSCHAPv2 setup that actually works on Linux"
icon="wifi"
- link="docs/eduroam-network-installation"
+ link="docs/networking/eduroam-network-installation"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Virtualization
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Windows 11 VM Setup"
+ subtitle="KVM/QEMU VM with VirtIO and SPICE GL"
+ icon="desktop-computer"
+ link="docs/virtualization/vm-setup"
+ >}}
+ {{< hextra/feature-card
+ title="Looking Glass Attempt"
+ subtitle="GPU passthrough attempt, not working on this hardware"
+ icon="eye"
+ link="docs/virtualization/looking-glass-attempt"
>}}
{{< /hextra/feature-grid >}}
diff --git a/content/_index.nl.md b/content/_index.nl.md
index 2f25d77..5120686 100644
--- a/content/_index.nl.md
+++ b/content/_index.nl.md
@@ -11,7 +11,7 @@ toc: false
{{< hextra/hero-subtitle >}}
- Wat ik leerde van Fedora 43 op mijn Zephyrus — en wat ik had willen weten voordat ik begon
+ Persoonlijke Linux setup en instellingen voor de ROG Zephyrus G16
{{< /hextra/hero-subtitle >}}
@@ -25,28 +25,16 @@ toc: false
{{< callout type="info" >}}
-**Persoonlijke documentatie.** Ik ben geen developer of Linux-expert — gewoon iemand die overgestapt is naar Linux op deze laptop en dingen uitzoekende onderweg. Ik deel wat werkte zodat anderen niet helemaal opnieuw hoeven te beginnen. Alles is op eigen risico. Kom je ergens niet uit, laat het gerust weten — ik denk graag mee. Vereist kernel 6.18+.
+**Persoonlijke documentatie.** Ik ben geen developer of Linux-expert — gewoon iemand die overgestapt is naar Linux op deze laptop en dingen uitzoekende onderweg. Ik deel wat werkte zodat anderen niet helemaal opnieuw hoeven te beginnen. Alles is op eigen risico. Kom je ergens niet uit, laat het gerust weten — ik denk graag mee. Draait kernel 6.19.3-2 op CachyOS (Arch).
{{< /callout >}}
## Nieuws
-### Kernel 7.0: ASUS laptop quirks + nieuw AMDGPU-werk
+- **Overgestapt naar CachyOS** — dagelijkse driver na het testen van meerdere distro's; beste hardware-ondersteuning voor de G16
+- **Kernel 7.0** — ASUS laptop quirks en AMDGPU-ondersteuning voor RDNA 3.5; Radeon 890M verwacht ~20% sneller
+- **Kernel 6.19** — `asus-armoury` driver gemerged in mainline Linux; CachyOS 6.19.3-2 bevat het al
-Linus heeft bevestigd dat de volgende kernel 7.0 is, met de merge window nu open en een stabiele release verwacht rond midden april 2026. Voor deze ASUS ROG G16 is het belangrijkste nieuws betere grafische driver-ondersteuning: de DRM-updates brengen AMDGPU-ondersteuning voor nieuwere RDNA 3.5-klasse IP blocks (GFX11.5.4) plus verder werk aan NVIDIA Nova/Nouveau, wat moet zorgen voor betere afhandeling van zowel de iGPU als dGPU. Verwachting is dat de Radeon 890M ongeveer 20% sneller kan worden bij de stap van kernel 6.18 naar 7.0. Nog geen directe upgrade voor Fedora 43, maar wel een goed teken voor komende releases.
-
-**Bronnen:** [Linus bevestigt Linux 7.0](https://www.phoronix.com/news/Linux-7.0-Is-Next) · [HID laptop quirks voor ASUS ROG modellen](https://www.phoronix.com/news/Linux-7.0-HID) · [Linux 7.0 DRM/AMDGPU updates](https://www.phoronix.com/news/Linux-7.0-Graphics-Drivers)
-
-### Kernel 6.19: asus-armoury driver in mainline Linux
-
-De `asus-armoury` driver is [gemerged in Linux 6.19](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19). Deze nieuwe `platform/x86` driver vervangt delen van de oudere `asus-wmi` met een schonere sysfs-gebaseerde API, waarmee o.a. paneel modus wisselen, APU geheugentoewijzing, PPT tuning en meer mogelijk wordt direct vanuit de kernel. De driver is volledig ontwikkeld door de community, door [Luke Jones](https://asus-linux.org/) (ASUS Linux project), zonder enige betrokkenheid van ASUS zelf. Het is niet alleen voor handhelds zoals de ROG Ally; elke recente ASUS gaming laptop profiteert ervan, inclusief functies in ROG Control Center zoals power limit aanpassingen.
-
-Op kernel 6.18 is de driver nog niet beschikbaar:
-
-
-
-Fedora 44 zal naar verwachting met kernel 6.19 worden geleverd, met native asus-armoury ondersteuning.
-
-**Bronnen:** [Phoronix artikel](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19) · [Community discussie](https://www.phoronix.com/forums/forum/software/linux-gaming/1593500-asus-armoury-driver-set-to-be-introduced-in-linux-6-19) · [Patch series (lore.kernel.org)](https://lore.kernel.org/all/20251102215319.3126879-1-denis.benato@linux.dev/)
+[Bekijk al het nieuws →](/nl/docs/news)
## Huidige Systeemconfiguratie
@@ -56,8 +44,8 @@ Fedora 44 zal naar verwachting met kernel 6.19 worden geleverd, met native asus-
| **CPU** | AMD Ryzen AI 9 HX 370 |
| **iGPU** | AMD Radeon 890M |
| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
-| **OS** | Fedora 43 |
-| **Kernel** | 6.18.10-200.fc43.x86_64 |
+| **OS** | CachyOS (Arch) |
+| **Kernel** | 6.19.3-2 |
| **Display Server** | Wayland (GNOME 49) |
| **Secure Boot** | Ingeschakeld |
@@ -66,56 +54,88 @@ Fedora 44 zal naar verwachting met kernel 6.19 worden geleverd, met native asus-
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="Aan de slag"
- subtitle="Van schone Fedora-installatie tot volledig geconfigureerd systeem"
+ subtitle="Van schone CachyOS-installatie tot volledig geconfigureerd systeem"
icon="play"
link="docs/getting-started"
>}}
{{< /hextra/feature-grid >}}
-## Referentie Handleidingen
+## Hardware & Drivers
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="NVIDIA Driver Installatie"
- subtitle="Proprietary NVIDIA drivers met Secure Boot op Fedora 43"
+ subtitle="Proprietary NVIDIA drivers met Secure Boot op CachyOS"
icon="chip"
- link="docs/nvidia-driver-installation"
+ link="docs/hardware/nvidia-driver-installation"
>}}
{{< hextra/feature-card
- title="Windows 11 VM Setup"
- subtitle="KVM/QEMU VM met VirtIO en SPICE GL"
- icon="desktop-computer"
- link="docs/vm-setup"
+ title="Secure Boot"
+ subtitle="Aangepaste ondertekeningssleutels met sbctl, HSI:3 naar HSI:4"
+ icon="shield-check"
+ link="docs/hardware/secure-boot"
>}}
{{< hextra/feature-card
- title="GDM Autologin"
- subtitle="GDM inlogscherm overslaan na LUKS ontgrendeling"
- icon="lock-open"
- link="docs/autologin"
+ title="asusctl & ROG Control Center"
+ subtitle="Fan curves, performance profielen, GPU switching, Slash LED"
+ icon="adjustments"
+ link="docs/hardware/asusctl-rog-control"
>}}
+{{< /hextra/feature-grid >}}
+
+## Beveiliging & Privacy
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="YubiKey 5C NFC"
subtitle="FIDO2 LUKS poging en wat vandaag werkt"
icon="key"
- link="docs/yubikey"
+ link="docs/security/yubikey"
>}}
{{< hextra/feature-card
- title="Looking Glass Poging"
- subtitle="GPU passthrough poging (werkt niet op deze hardware)"
- icon="eye"
- link="docs/looking-glass-attempt"
+ title="GDM Autologin"
+ subtitle="GDM inlogscherm overslaan na LUKS ontgrendeling"
+ icon="lock-open"
+ link="docs/security/autologin"
>}}
+{{< /hextra/feature-grid >}}
+
+## Applicaties
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
- title="asusctl & ROG Control Center"
- subtitle="Fan curves, performance profielen, GPU switching, Slash LED"
- icon="adjustments"
- link="docs/asusctl-rog-control"
+ title="Applicaties"
+ subtitle="Browser, communicatie, ontwikkeltools en systeemconfiguratie"
+ icon="collection"
+ link="docs/applications"
>}}
+{{< /hextra/feature-grid >}}
+
+## Netwerk
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="eduroam Setup"
subtitle="PEAP/MSCHAPv2 configuratie die daadwerkelijk werkt op Linux"
icon="wifi"
- link="docs/eduroam-network-installation"
+ link="docs/networking/eduroam-network-installation"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Virtualisatie
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Windows 11 VM Setup"
+ subtitle="KVM/QEMU VM met VirtIO en SPICE GL"
+ icon="desktop-computer"
+ link="docs/virtualization/vm-setup"
+ >}}
+ {{< hextra/feature-card
+ title="Looking Glass Poging"
+ subtitle="GPU passthrough poging (werkt niet op deze hardware)"
+ icon="eye"
+ link="docs/virtualization/looking-glass-attempt"
>}}
{{< /hextra/feature-grid >}}
diff --git a/content/docs/_index.md b/content/docs/_index.md
index a1c96be..a3ca48c 100644
--- a/content/docs/_index.md
+++ b/content/docs/_index.md
@@ -6,62 +6,116 @@ toc: false
# My Setup Notes
-Everything I've documented while running Fedora Linux on the ROG Zephyrus G16. Start with Getting Started if you're setting up from scratch, or jump to whichever guide is relevant to your situation.
+Everything I've documented while running CachyOS on the ROG Zephyrus G16. Start with Getting Started if you're setting up from scratch, or jump to whichever section is relevant to your situation.
## Getting Started
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="Getting Started"
- subtitle="From fresh Fedora install to fully configured system"
+ subtitle="From fresh CachyOS install to fully configured system"
icon="play"
link="getting-started"
>}}
{{< /hextra/feature-grid >}}
-## Reference Guides
+## Hardware & Drivers
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="NVIDIA Driver Installation"
- subtitle="Proprietary NVIDIA drivers with Secure Boot on Fedora 43"
+ subtitle="Proprietary NVIDIA drivers with Secure Boot on CachyOS"
icon="chip"
- link="nvidia-driver-installation"
+ link="hardware/nvidia-driver-installation"
>}}
{{< hextra/feature-card
- title="Windows 11 VM Setup"
- subtitle="KVM/QEMU VM with VirtIO and SPICE GL"
- icon="desktop-computer"
- link="vm-setup"
+ title="Secure Boot"
+ subtitle="Custom signing keys with sbctl, HSI:3 to HSI:4"
+ icon="shield-check"
+ link="hardware/secure-boot"
>}}
{{< hextra/feature-card
- title="GDM Autologin"
- subtitle="Skip GDM login after LUKS unlock"
- icon="lock-open"
- link="autologin"
+ title="asusctl & ROG Control Center"
+ subtitle="Fan curves, performance profiles, GPU switching, Slash LED"
+ icon="adjustments"
+ link="hardware/asusctl-rog-control"
>}}
+{{< /hextra/feature-grid >}}
+
+## Security & Privacy
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="YubiKey 5C NFC"
subtitle="FIDO2 LUKS unlock and what currently works"
icon="key"
- link="yubikey"
+ link="security/yubikey"
>}}
{{< hextra/feature-card
- title="Looking Glass Attempt"
- subtitle="GPU passthrough attempt, not working on this hardware"
- icon="eye"
- link="looking-glass-attempt"
+ title="GDM Autologin"
+ subtitle="Skip GDM login after LUKS unlock"
+ icon="lock-open"
+ link="security/autologin"
>}}
+{{< /hextra/feature-grid >}}
+
+## Applications
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
- title="asusctl & ROG Control Center"
- subtitle="Fan curves, performance profiles, GPU switching, Slash LED"
- icon="adjustments"
- link="asusctl-rog-control"
+ title="Applications"
+ subtitle="Browser, communication, development tools, and system configuration"
+ icon="collection"
+ link="applications"
>}}
+{{< /hextra/feature-grid >}}
+
+## Networking
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="eduroam Network Installation"
subtitle="PEAP/MSCHAPv2 setup that actually works on Linux"
icon="wifi"
- link="eduroam-network-installation"
+ link="networking/eduroam-network-installation"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Virtualization
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Windows 11 VM Setup"
+ subtitle="KVM/QEMU VM with VirtIO and SPICE GL"
+ icon="desktop-computer"
+ link="virtualization/vm-setup"
+ >}}
+ {{< hextra/feature-card
+ title="Looking Glass Attempt"
+ subtitle="GPU passthrough attempt, not working on this hardware"
+ icon="eye"
+ link="virtualization/looking-glass-attempt"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## News
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="News"
+ subtitle="CachyOS updates, kernel releases, and hardware-relevant changes"
+ icon="rss"
+ link="news"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Known Issues
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Known Issues"
+ subtitle="Issues without a solution yet"
+ icon="exclamation-circle"
+ link="known-issues"
>}}
{{< /hextra/feature-grid >}}
diff --git a/content/docs/_index.nl.md b/content/docs/_index.nl.md
index 8dd3222..0fbf64b 100644
--- a/content/docs/_index.nl.md
+++ b/content/docs/_index.nl.md
@@ -6,62 +6,116 @@ toc: false
# Mijn setup-notities
-Alles wat ik heb opgeschreven tijdens het draaien van Fedora Linux op de ROG Zephyrus G16. Begin bij Aan de slag als je vanaf nul instelt, of ga direct naar de handleiding die je nodig hebt.
+Alles wat ik heb opgeschreven tijdens het draaien van CachyOS op de ROG Zephyrus G16. Begin bij Aan de slag als je vanaf nul instelt, of ga direct naar de handleiding die je nodig hebt.
## Aan de slag
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="Aan de slag"
- subtitle="Van schone Fedora-installatie tot volledig geconfigureerd systeem"
+ subtitle="Van schone CachyOS-installatie tot volledig geconfigureerd systeem"
icon="play"
link="getting-started"
>}}
{{< /hextra/feature-grid >}}
-## Referentie Handleidingen
+## Hardware & Drivers
{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="NVIDIA Driver Installatie"
- subtitle="Proprietary NVIDIA drivers met Secure Boot op Fedora 43"
+ subtitle="Proprietary NVIDIA drivers met Secure Boot op CachyOS"
icon="chip"
- link="nvidia-driver-installation"
+ link="hardware/nvidia-driver-installation"
>}}
{{< hextra/feature-card
- title="Windows 11 VM Setup"
- subtitle="KVM/QEMU VM met VirtIO en SPICE GL"
- icon="desktop-computer"
- link="vm-setup"
+ title="Secure Boot"
+ subtitle="Aangepaste ondertekeningssleutels met sbctl, HSI:3 naar HSI:4"
+ icon="shield-check"
+ link="hardware/secure-boot"
>}}
{{< hextra/feature-card
- title="GDM Autologin"
- subtitle="GDM inlogscherm overslaan na LUKS ontgrendeling"
- icon="lock-open"
- link="autologin"
+ title="asusctl & ROG Control Center"
+ subtitle="Fan curves, performance profielen, GPU switching, Slash LED"
+ icon="adjustments"
+ link="hardware/asusctl-rog-control"
>}}
+{{< /hextra/feature-grid >}}
+
+## Beveiliging & Privacy
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="YubiKey 5C NFC"
subtitle="FIDO2 LUKS poging en wat vandaag werkt"
icon="key"
- link="yubikey"
+ link="security/yubikey"
>}}
{{< hextra/feature-card
- title="Looking Glass Poging"
- subtitle="GPU passthrough poging, werkt niet op deze hardware"
- icon="eye"
- link="looking-glass-attempt"
+ title="GDM Autologin"
+ subtitle="GDM inlogscherm overslaan na LUKS ontgrendeling"
+ icon="lock-open"
+ link="security/autologin"
>}}
+{{< /hextra/feature-grid >}}
+
+## Applicaties
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
- title="asusctl & ROG Control Center"
- subtitle="Fan curves, performance profiles, GPU switching, Slash LED"
- icon="adjustments"
- link="asusctl-rog-control"
+ title="Applicaties"
+ subtitle="Browser, communicatie, ontwikkeltools en systeemconfiguratie"
+ icon="collection"
+ link="applications"
>}}
+{{< /hextra/feature-grid >}}
+
+## Netwerk
+
+{{< hextra/feature-grid >}}
{{< hextra/feature-card
title="eduroam Setup"
subtitle="PEAP/MSCHAPv2 configuratie die daadwerkelijk werkt op Linux"
icon="wifi"
- link="eduroam-network-installation"
+ link="networking/eduroam-network-installation"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Virtualisatie
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Windows 11 VM Setup"
+ subtitle="KVM/QEMU VM met VirtIO en SPICE GL"
+ icon="desktop-computer"
+ link="virtualization/vm-setup"
+ >}}
+ {{< hextra/feature-card
+ title="Looking Glass Poging"
+ subtitle="GPU passthrough poging, werkt niet op deze hardware"
+ icon="eye"
+ link="virtualization/looking-glass-attempt"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Nieuws
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Nieuws"
+ subtitle="CachyOS updates, kernel releases en hardware-relevante wijzigingen"
+ icon="rss"
+ link="news"
+ >}}
+{{< /hextra/feature-grid >}}
+
+## Bekende Problemen
+
+{{< hextra/feature-grid >}}
+ {{< hextra/feature-card
+ title="Bekende Problemen"
+ subtitle="Problemen waarvoor nog geen oplossing is"
+ icon="exclamation-circle"
+ link="known-issues"
>}}
{{< /hextra/feature-grid >}}
diff --git a/content/docs/applications.md b/content/docs/applications.md
new file mode 100644
index 0000000..40fc32f
--- /dev/null
+++ b/content/docs/applications.md
@@ -0,0 +1,358 @@
+---
+title: "Applications"
+weight: 25
+---
+
+Everything I installed after the initial CachyOS setup. Organized loosely by category. Most of this is personal preference, but the Brave and libinput-config sections include non-obvious workarounds that aren't documented elsewhere.
+
+## Initial System Setup
+
+### Set the hostname
+
+Nothing special — just set the hostname via System Settings so the machine has a proper name on the network.
+
+
+
+### GNOME window buttons — adding minimize & maximize back
+
+By default, GNOME 49 only shows the close button. One command fixes it:
+
+```bash
+gsettings set org.gnome.desktop.wm.preferences button-layout 'appmenu:minimize,maximize,close'
+```
+
+
+
+### GNOME keyboard shortcuts — making it feel more like Windows
+
+Coming from Windows, some things feel off without the right shortcuts. These are the ones I set up to make the transition smoother.
+
+**Built-in shortcuts (via Settings > Keyboard > Keyboard Shortcuts):**
+
+| # | Action | Shortcut |
+|---|--------|----------|
+| 1 | Show desktop (hide all windows) | `Super+D` |
+| 2 | Take a screenshot interactively | `Shift+Super+S` |
+| 3 | Record a screencast interactively | `Shift+Super+R` |
+| 4 | Open Settings | `Super+I` |
+
+**Custom shortcut (via Settings > Keyboard > Keyboard Shortcuts > Custom Shortcuts):**
+
+| # | Action | Command | Shortcut |
+|---|--------|---------|----------|
+| 5 | Open file manager | `nautilus` | `Super+E` |
+
+GNOME doesn't have a built-in shortcut for the file manager, so this one needs to be created manually.
+
+### Touchpad scroll speed — no native GNOME setting (yet)
+
+As of GNOME 49, there is simply **no native setting** for touchpad scroll speed anywhere in the Settings panel. KDE Plasma has had this for years. There are merge requests open in [mutter](https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1840) and [GNOME Control Center](https://gitlab.gnome.org/GNOME/gnome-control-center/-/merge_requests/991) to add it, but they've been sitting there for years. See the [GNOME Discourse thread](https://discourse.gnome.org/t/adding-scroll-speed-setting-in-gnome/25893) for context.
+
+[libinput-config](https://github.com/lz42/libinput-config) by lz42 is a third-party workaround that intercepts libinput events and applies a scroll multiplier.
+
+**Install (one-time):**
+
+```bash
+# 1. Install dependencies
+sudo pacman -S meson ninja libinput git
+
+# 2. Clone libinput-config
+git clone https://github.com/lz42/libinput-config.git
+cd libinput-config
+
+# 3. Build
+meson setup build
+ninja -C build
+
+# 4. Install system-wide
+sudo ninja -C build install
+
+# 5. Cleanup (optional)
+cd ..
+rm -rf libinput-config
+```
+
+**Configuration for slower touchpad scroll:**
+
+```bash
+sudo tee /etc/libinput.conf >/dev/null << 'EOF'
+# libinput-config configuration
+override-compositor=enabled
+
+# Make touchpad scroll slower (lower = slower)
+# Default: 1.0, tested value: 0.25
+scroll-factor=0.25
+
+# Keep mouse wheel behavior normal
+discrete-scroll-factor=1.0
+EOF
+```
+
+Log out and back in (or reboot), then adjust `scroll-factor` to your liking.
+
+**Rollback:**
+
+```bash
+sudo rm /etc/libinput.conf
+```
+
+---
+
+## Browser
+
+### Brave
+
+I use Brave as my main browser. I started with the Flatpak version but switched to the native package — the RPM version feels more native and offers better performance. There's a catch though: Brave 1.82+ has two crash bugs on GNOME Wayland that need workarounds before it's actually stable.
+
+- **Native (pacman):** More native feel, better performance. This is what I use.
+- **Flatpak:** Might work better in some situations, but feels a bit more isolated.
+
+**Installation**
+
+{{< callout type="warning" >}}
+On CachyOS/Arch with GNOME + Wayland, Brave 1.82+ has two known crash bugs that require workarounds. The first is applied via the desktop entry; the second requires a setting in `brave://flags`.
+{{< /callout >}}
+
+```bash
+sudo pacman -S brave-bin
+```
+
+
+
+**Workaround 1: patch the desktop entry**
+
+Copy the system desktop entry to your user directory so it doesn't get overwritten by updates:
+```bash
+sudo cp /usr/share/applications/brave-browser.desktop ~/.local/share/applications/
+```
+
+Patch all three `Exec=` lines with the flag:
+```bash
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable %U|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1 %U|' \
+ ~/.local/share/applications/brave-browser.desktop
+
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable$|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1|' \
+ ~/.local/share/applications/brave-browser.desktop
+
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable --incognito$|Exec=/usr/bin/brave-browser-stable --incognito --disable-features=WaylandWpColorManagerV1|' \
+ ~/.local/share/applications/brave-browser.desktop
+```
+
+Verify it worked — you should see exactly three `Exec=` lines:
+```bash
+grep "^Exec" ~/.local/share/applications/brave-browser.desktop
+```
+
+**What this flag actually does (as far as I understand it):**
+
+`--disable-features=WaylandWpColorManagerV1` — Brave 1.82+ introduced some Wayland color management extension that apparently conflicts with the AMD amdgpu driver on GNOME Wayland. Without this flag, Brave triggers GPU ring timeouts that crash the entire GNOME Shell session.
+
+**A note on `--ozone-platform=x11`:** I tried this flag as a workaround for a crash when opening or downloading Bitwarden attachments. It turned out to cause a worse problem: gnome-shell crashing with `SIGABRT` (`g_assertion_message_expr` in `meta_window_unmanage`), triggered during Picture-in-Picture video — the same underlying mutter crash documented in [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625). That takes down the entire desktop session and requires a hard reboot. The flag is gone. Brave now runs on native Wayland. The Bitwarden attachment crash still exists, but a Brave crash is preferable to losing the whole session.
+
+**Workaround 2: disable hardware video decode in `brave://flags`**
+
+{{< callout type="warning" >}}
+Hardware video decode still causes crashes even with the flag above. As long as the AMD VCN decoder is active, GNOME Shell crashes with SIGABRT — reproducible during Picture-in-Picture video. See [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625). Hardware video decode is **not yet stable** on the AMD Radeon 890M with GNOME Wayland.
+{{< /callout >}}
+
+Go to `brave://flags` and disable:
+
+- **Hardware-accelerated video decode** → `Disabled`
+
+
+
+Video now decodes in software. After this, `brave://gpu` will show:
+
+- `Video Decode: Software only. Hardware acceleration disabled`
+- `Video Encode: Software only. Hardware acceleration disabled`
+
+
+
+**Flatpak alternative**
+
+If the native package gives you trouble:
+
+```bash
+flatpak install flathub com.brave.Browser
+```
+
+
+
+---
+
+## Communication & Productivity
+
+### Bitwarden
+
+Password manager. Available via Flathub and works well.
+
+
+
+### Signal Messenger
+
+Signal is my main messaging app. Officially only supported on Debian/Ubuntu, but the Flatpak version works fine on CachyOS.
+
+
+
+### Proton Mail
+
+Proton Mail desktop app is a wrapper around the web app rather than a native client. Works fine and shows up in the app launcher like any other app.
+
+
+
+---
+
+## Development
+
+### Git & GitHub CLI
+
+```bash
+sudo pacman -S git github-cli
+```
+
+### Visual Studio Code
+
+```bash
+sudo pacman -S code
+```
+
+{{< callout type="warning" >}}
+On kernel 6.18.x/6.19.x, VS Code hardware acceleration can trigger an amdgpu page fault causing a full system freeze. Disable hardware acceleration by adding to `~/.config/Code/User/settings.json`:
+```json
+{
+ "disable-hardware-acceleration": true
+}
+```
+See the [NVIDIA Driver Installation Guide]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) Known Issues section for details.
+{{< /callout >}}
+
+### Kleopatra & GPG commit signing
+
+I sign my Git commits and tags with a GPG key. Kleopatra makes generating and managing keys straightforward via a GUI instead of having to figure out the GPG command line.
+
+After installing VS Code and Git, install Kleopatra and create your keys there. Then configure Git to use them:
+
+```bash
+git config --global user.name "YOUR_NAME"
+git config --global user.email "YOUR_EMAIL"
+git config --global user.signingkey YOUR_GPG_KEY_ID
+git config --global commit.gpgsign true
+git config --global tag.gpgsign true
+git config --global gpg.program gpg
+```
+
+To find your key ID:
+```bash
+gpg --list-secret-keys --keyid-format=long
+```
+Use the ID from the `sec` line (e.g., `rsa4096/YOUR_GPG_KEY_ID`).
+
+### Archi (ArchiMate modeling tool)
+
+[Archi](https://www.archimatetool.com/) is a free ArchiMate modeling tool. The Linux package is a portable archive — no installer. To make it show up in GNOME with an icon, you have to place the files yourself and create a desktop entry manually.
+
+{{< callout type="info" >}}
+Archi's download page warns about possible UI issues on Wayland. In my experience it runs fine on GNOME 49 Wayland.
+{{< /callout >}}
+
+
+
+```bash
+# Download and extract
+cd /tmp
+curl -L https://github.com/archimatetool/archi.io/releases/download/5.7.0/Archi-Linux64-5.7.0.tgz | tar -xz
+
+# Move to /opt
+sudo mv Archi-Linux64-5.7.0/Archi /opt/
+
+# Cleanup
+rm -rf Archi-Linux64-5.7.0
+cd ~
+
+# Create symlink so you can run 'archi' from the terminal
+sudo ln -s /opt/Archi/Archi /usr/local/bin/archi
+```
+
+Create a desktop entry so Archi shows up in GNOME:
+```bash
+sudo nano /usr/share/applications/archi.desktop
+```
+
+```ini
+[Desktop Entry]
+Version=1.0
+Type=Application
+Name=Archi
+Comment=ArchiMate Modelling Tool
+Exec=/opt/Archi/Archi
+Icon=/opt/Archi/plugins/com.archimatetool.editor_5.7.0.202509230807/img/app-128.png
+Terminal=false
+Categories=Development;IDE;
+StartupWMClass=Archi
+```
+
+After saving, Archi appears in the GNOME app launcher:
+
+
+
+
+
+---
+
+## Gaming & Media
+
+### Steam
+
+On CachyOS, Steam is available directly from the `multilib` repository — no extra repos needed.
+
+```bash
+sudo pacman -S steam
+```
+
+
+
+Reboot after installing. Steam includes Proton out of the box for running Windows games on Linux.
+
+{{< callout type="info" >}}
+If Steam won't launch, try running it from the terminal with:
+```bash
+__GL_CONSTANT_FRAME_RATE_HINT=3 steam
+```
+{{< /callout >}}
+
+### Tidal Hi-Fi
+
+There's no official Tidal client for Linux. [Tidal Hi-Fi](https://github.com/Mastermindzh/tidal-hifi) by Rick van Lieshout is a community-made Electron wrapper around the Tidal web player, with Hi-Fi and Max quality support.
+
+
+
+---
+
+## Utilities
+
+### Bottles — running Windows software
+
+[Bottles](https://usebottles.com/) lets you run Windows software via Wine. Install from Flathub — version 61 or newer.
+
+- Open GNOME Software Center, search for "Bottles", select the **Flathub** source
+
+For anything that doesn't work under Wine — like Microsoft 365 — I use a Windows VM instead. See [Windows 11 VM Setup]({{< relref "/docs/virtualization/vm-setup" >}}).
+
+
+
+### Solaar for Logitech devices
+
+[Solaar](https://github.com/pwr-Solaar/Solaar) manages Logitech keyboards, mice, and other peripherals. Version 1.1.19 or newer.
+
+```bash
+sudo pacman -S solaar
+```
+
+
+
+Runs in the system tray with battery notifications. You can also configure DPI, polling rate, and buttons from there.
+
+
diff --git a/content/docs/applications.nl.md b/content/docs/applications.nl.md
new file mode 100644
index 0000000..f168158
--- /dev/null
+++ b/content/docs/applications.nl.md
@@ -0,0 +1,358 @@
+---
+title: "Applicaties"
+weight: 25
+---
+
+Alles wat ik heb geïnstalleerd na de initiële CachyOS-setup. Losjes georganiseerd per categorie. De meeste keuzes zijn persoonlijk, maar de secties over Brave en libinput-config bevatten niet-voor-de-hand-liggende workarounds die nergens anders gedocumenteerd staan.
+
+## Initiële systeeminstellingen
+
+### Hostname instellen
+
+Gewoon de hostname instellen via Systeeminstellingen zodat de machine een fatsoenlijke naam heeft op het netwerk.
+
+
+
+### GNOME-vensterknoppen — minimize en maximize terug
+
+Standaard toont GNOME 49 alleen de sluitknop. Eén commando lost het op:
+
+```bash
+gsettings set org.gnome.desktop.wm.preferences button-layout 'appmenu:minimize,maximize,close'
+```
+
+
+
+### GNOME-sneltoetsen — meer als Windows
+
+Als je vanuit Windows komt, voelt een paar dingen meteen anders zonder de juiste sneltoetsen. Dit zijn de sneltoetsen die ik heb ingesteld.
+
+**Ingebouwde sneltoetsen (via Settings > Keyboard > Keyboard Shortcuts):**
+
+| # | Actie | Sneltoets |
+|---|-------|-----------|
+| 1 | Desktop tonen (alle vensters verbergen) | `Super+D` |
+| 2 | Interactieve screenshot | `Shift+Super+S` |
+| 3 | Interactieve schermopname | `Shift+Super+R` |
+| 4 | Instellingen openen | `Super+I` |
+
+**Custom shortcut (via Settings > Keyboard > Keyboard Shortcuts > Custom Shortcuts):**
+
+| # | Actie | Commando | Sneltoets |
+|---|-------|----------|-----------|
+| 5 | Bestandsbeheer openen | `nautilus` | `Super+E` |
+
+GNOME heeft standaard geen sneltoets voor de bestandsbeheerder, dus die moet je handmatig aanmaken.
+
+### Touchpad-scrollsnelheid — geen native GNOME-instelling (nog niet)
+
+GNOME 49 heeft simpelweg **geen instelling** voor touchpad-scrollsnelheid. KDE Plasma heeft dat al jaren. Er zijn merge requests open in [mutter](https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1840) en [GNOME Control Center](https://gitlab.gnome.org/GNOME/gnome-control-center/-/merge_requests/991), maar die staan al jaren open. Zie de [GNOME Discourse-discussie](https://discourse.gnome.org/t/adding-scroll-speed-setting-in-gnome/25893) voor meer context.
+
+[libinput-config](https://github.com/lz42/libinput-config) van lz42 is een third-party workaround die libinput events onderschept en een scrollmultiplicator toepast.
+
+**Installatie (eenmalig):**
+
+```bash
+# 1. Dependencies installeren
+sudo pacman -S meson ninja libinput git
+
+# 2. libinput-config clonen
+git clone https://github.com/lz42/libinput-config.git
+cd libinput-config
+
+# 3. Bouwen
+meson setup build
+ninja -C build
+
+# 4. Systeembreed installeren
+sudo ninja -C build install
+
+# 5. Opruimen (optioneel)
+cd ..
+rm -rf libinput-config
+```
+
+**Configuratie voor langzamere touchpad-scroll:**
+
+```bash
+sudo tee /etc/libinput.conf >/dev/null << 'EOF'
+# libinput-config configuration
+override-compositor=enabled
+
+# Touchpad-scroll langzamer (lager = langzamer)
+# Standaard: 1.0, geteste waarde: 0.25
+scroll-factor=0.25
+
+# Muiswiel normaal houden
+discrete-scroll-factor=1.0
+EOF
+```
+
+Uitloggen en weer inloggen (of reboot), dan `scroll-factor` aanpassen naar voorkeur.
+
+**Terugdraaien:**
+
+```bash
+sudo rm /etc/libinput.conf
+```
+
+---
+
+## Browser
+
+### Brave
+
+Brave is mijn standaardbrowser. Ik begon met de Flatpak-versie maar ben overgestapt naar het native pakket — dat voelt nativer en biedt betere prestaties. Er is alleen een addertje: Brave 1.82+ heeft twee crashbugs op GNOME Wayland waarvoor workarounds nodig zijn.
+
+- **Native (pacman):** Nativer gevoel, betere prestaties. Dit gebruik ik.
+- **Flatpak:** Kan in sommige situaties beter werken, maar voelt wat geïsoleerder.
+
+**Installatie**
+
+{{< callout type="warning" >}}
+Op CachyOS/Arch met GNOME + Wayland heeft Brave 1.82+ twee bekende crashbugs waarvoor workarounds nodig zijn. De eerste wordt via de desktop entry toegepast; de tweede vereist een instelling in `brave://flags`.
+{{< /callout >}}
+
+```bash
+sudo pacman -S brave-bin
+```
+
+
+
+**Workaround 1: de desktop entry patchen**
+
+Kopieer de systeem-desktop entry naar je gebruikersmap zodat hij niet wordt overschreven bij updates:
+```bash
+sudo cp /usr/share/applications/brave-browser.desktop ~/.local/share/applications/
+```
+
+Patch alle drie de `Exec=` regels met de flag:
+```bash
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable %U|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1 %U|' \
+ ~/.local/share/applications/brave-browser.desktop
+
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable$|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1|' \
+ ~/.local/share/applications/brave-browser.desktop
+
+sed -i \
+ 's|Exec=/usr/bin/brave-browser-stable --incognito$|Exec=/usr/bin/brave-browser-stable --incognito --disable-features=WaylandWpColorManagerV1|' \
+ ~/.local/share/applications/brave-browser.desktop
+```
+
+Controleer of het gelukt is — je zou exact drie `Exec=` regels moeten zien:
+```bash
+grep "^Exec" ~/.local/share/applications/brave-browser.desktop
+```
+
+**Wat deze flag doet:**
+
+`--disable-features=WaylandWpColorManagerV1` — Brave 1.82+ introduceerde een Wayland color management extensie die conflicteert met de AMD amdgpu-driver op GNOME Wayland. Zonder deze flag veroorzaakt Brave GPU ring timeouts die de volledige GNOME Shell-sessie neerhalen.
+
+**Een noot over `--ozone-platform=x11`:** Geprobeerd als workaround voor een crash bij Bitwarden-bijlagen. Bleek een erger probleem te veroorzaken: gnome-shell met `SIGABRT` bij Picture-in-Picture video — zie [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625). De flag is weg. Brave draait nu op native Wayland. De Bitwarden-bijlage-crash bestaat nog, maar een Brave-crash is te verkiezen boven het verliezen van de hele sessie.
+
+**Workaround 2: hardware video decode uitschakelen in `brave://flags`**
+
+{{< callout type="warning" >}}
+Hardware video decode veroorzaakt nog steeds crashes, ook met de flag hierboven. Zolang de AMD VCN decoder actief is, crasht GNOME Shell met SIGABRT bij Picture-in-Picture video. Zie [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625). Hardware video decode is **nog niet stabiel** op de AMD Radeon 890M met GNOME Wayland.
+{{< /callout >}}
+
+Ga naar `brave://flags` en schakel uit:
+
+- **Hardware-accelerated video decode** → `Disabled`
+
+
+
+Video wordt nu via software gedecodeerd. In `brave://gpu` staat daarna:
+
+- `Video Decode: Software only. Hardware acceleration disabled`
+- `Video Encode: Software only. Hardware acceleration disabled`
+
+
+
+**Flatpak alternatief**
+
+Geeft het native pakket problemen:
+
+```bash
+flatpak install flathub com.brave.Browser
+```
+
+
+
+---
+
+## Communicatie & Productiviteit
+
+### Bitwarden
+
+Wachtwoordbeheerder. Beschikbaar via Flathub en werkt goed.
+
+
+
+### Signal Messenger
+
+Signal is mijn belangrijkste berichtenapp. Officieel alleen ondersteund op Debian/Ubuntu, maar de Flatpak-versie werkt prima op CachyOS.
+
+
+
+### Proton Mail
+
+De Proton Mail desktop-app is een wrapper rondom de webapp, geen native client. Werkt gewoon en staat in de app launcher zoals elke andere app.
+
+
+
+---
+
+## Ontwikkeling
+
+### Git & GitHub CLI
+
+```bash
+sudo pacman -S git github-cli
+```
+
+### Visual Studio Code
+
+```bash
+sudo pacman -S code
+```
+
+{{< callout type="warning" >}}
+Op kernel 6.18.x/6.19.x kan hardware acceleration in VS Code een amdgpu page fault veroorzaken waardoor het systeem bevriest. Zet hardware acceleration uit door dit toe te voegen aan `~/.config/Code/User/settings.json`:
+```json
+{
+ "disable-hardware-acceleration": true
+}
+```
+Zie de [NVIDIA Driver Installatie]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) sectie Bekende Problemen voor details.
+{{< /callout >}}
+
+### Kleopatra & GPG commit signing
+
+Ik onderteken mijn Git commits en tags met een GPG-sleutel. Kleopatra maakt het aanmaken en beheren van sleutels makkelijk via een GUI.
+
+Na het installeren van VS Code en Git, installeer Kleopatra en maak je sleutels daarin aan. Daarna Git configureren:
+
+```bash
+git config --global user.name "JOUW_NAAM"
+git config --global user.email "JOUW_EMAIL"
+git config --global user.signingkey JOUW_GPG_KEY_ID
+git config --global commit.gpgsign true
+git config --global tag.gpgsign true
+git config --global gpg.program gpg
+```
+
+Je sleutel-ID vinden:
+```bash
+gpg --list-secret-keys --keyid-format=long
+```
+Gebruik de ID van de `sec` regel (bijv. `rsa4096/JOUW_GPG_KEY_ID`).
+
+### Archi (ArchiMate-modelleertool)
+
+[Archi](https://www.archimatetool.com/) is een gratis ArchiMate-modelleertool. Het Linux-pakket is een portable archief — geen installer. Om het netjes in GNOME te laten verschijnen met een icoon, moet je de bestanden zelf plaatsen en een desktop entry handmatig aanmaken.
+
+{{< callout type="info" >}}
+De downloadpagina van Archi waarschuwt voor mogelijke UI-problemen op Wayland. In mijn ervaring werkt hij prima op GNOME 49 Wayland.
+{{< /callout >}}
+
+
+
+```bash
+# Download en extraheer
+cd /tmp
+curl -L https://github.com/archimatetool/archi.io/releases/download/5.7.0/Archi-Linux64-5.7.0.tgz | tar -xz
+
+# Verplaats naar /opt
+sudo mv Archi-Linux64-5.7.0/Archi /opt/
+
+# Opruimen
+rm -rf Archi-Linux64-5.7.0
+cd ~
+
+# Symlink zodat je 'archi' kunt starten vanuit de terminal
+sudo ln -s /opt/Archi/Archi /usr/local/bin/archi
+```
+
+Desktop entry aanmaken zodat Archi in GNOME verschijnt:
+```bash
+sudo nano /usr/share/applications/archi.desktop
+```
+
+```ini
+[Desktop Entry]
+Version=1.0
+Type=Application
+Name=Archi
+Comment=ArchiMate Modelling Tool
+Exec=/opt/Archi/Archi
+Icon=/opt/Archi/plugins/com.archimatetool.editor_5.7.0.202509230807/img/app-128.png
+Terminal=false
+Categories=Development;IDE;
+StartupWMClass=Archi
+```
+
+Na het opslaan verschijnt Archi in de GNOME-app launcher:
+
+
+
+
+
+---
+
+## Games & Media
+
+### Steam
+
+Op CachyOS is Steam beschikbaar vanuit de `multilib` repository — geen extra repos nodig.
+
+```bash
+sudo pacman -S steam
+```
+
+
+
+Herstart na installatie. Steam bevat Proton standaard voor het draaien van Windows-games op Linux.
+
+{{< callout type="info" >}}
+Als Steam niet wil starten, probeer het dan vanuit de terminal:
+```bash
+__GL_CONSTANT_FRAME_RATE_HINT=3 steam
+```
+{{< /callout >}}
+
+### Tidal Hi-Fi
+
+Er is geen officiële Tidal-client voor Linux. [Tidal Hi-Fi](https://github.com/Mastermindzh/tidal-hifi) van Rick van Lieshout is een community-Electron-wrapper rondom de Tidal-webapp, met Hi-Fi en Max kwaliteitsondersteuning.
+
+
+
+---
+
+## Hulpprogramma's
+
+### Bottles — Windows-software draaien
+
+[Bottles](https://usebottles.com/) laat je Windows-software draaien via Wine. Installeer via Flathub — versie 61 of nieuwer.
+
+- Open GNOME Software Center, zoek naar "Bottles", selecteer de **Flathub** bron
+
+Voor wat niet werkt onder Wine — zoals Microsoft 365 — gebruik ik een Windows VM. Zie [Windows 11 VM Setup]({{< relref "/docs/virtualization/vm-setup" >}}).
+
+
+
+### Solaar voor Logitech-apparaten
+
+[Solaar](https://github.com/pwr-Solaar/Solaar) beheert Logitech-toetsenborden, muizen en andere randapparatuur. Versie 1.1.19 of nieuwer.
+
+```bash
+sudo pacman -S solaar
+```
+
+
+
+Draait in het systray met batterijnotificaties. Je kunt er ook DPI, polling rate en knoppen mee configureren.
+
+
diff --git a/content/docs/getting-started.md b/content/docs/getting-started.md
index b5b1d7a..b3f9a29 100644
--- a/content/docs/getting-started.md
+++ b/content/docs/getting-started.md
@@ -3,427 +3,60 @@ title: "Getting Started"
weight: 2
---
-This is my personal setup log for the ROG Zephyrus G16 running Fedora Linux. I'm not a software engineer or developer — I'm just someone who switched to Linux and ran into a lot of things that didn't work out of the box. I figured I'd write it all down so others don't have to go through the same trial and error I did.
+This is my personal setup documentation for the ROG Zephyrus G16 running CachyOS (Arch). I'm not a software engineer or developer — just someone who switched to Linux and ran into a lot of things that didn't work out of the box. I figured I'd write it all down so others don't have to go through the same trial and error.
-If something here helps you, great. If you run into something I haven't covered, feel free to reach out — I'm happy to think along. I don't always have the answer, but I'll do my best.
+If something here helps you, great. If you run into something I haven't covered, feel free to reach out — I'm happy to think along.
-The steps below are roughly in the order I set things up after a fresh Fedora 43 install.
+## Hardware
-{{% steps %}}
-
-### Brave browser — RPM with Wayland workarounds
-
-I use Brave as my main browser. I started with the Flatpak version but switched to the native RPM — according to people on Reddit, the RPM version feels more native and offers better performance and efficiency. There's a catch though: Brave 1.82+ has two crash bugs on GNOME Wayland that need workarounds before it's actually stable. I don't fully understand why these crashes happen — they seem to involve GPU drivers and Wayland protocols that are apparently not playing well together — but the fixes below work for me.
-
-- **RPM (native):** More native feel, better performance and efficiency. This is what I use.
-- **Flatpak:** Might work better in some situations, but it feels a bit more isolated and slightly slower.
-
-**RPM Installation**
-
-{{< callout type="warning" >}}
-On Fedora with GNOME + Wayland, Brave 1.82+ has two known crash bugs that require workarounds. The first is applied via the desktop entry; the second requires a setting in `brave://flags`.
-{{< /callout >}}
-
-```bash
-sudo dnf install dnf-plugins-core
-sudo dnf config-manager addrepo --from-repofile=https://brave-browser-rpm-release.s3.brave.com/brave-browser.repo
-sudo dnf install brave-browser
-```
-
-
-
-**Workaround 1: patch the desktop entry**
-
-Copy the system desktop entry to your user directory so it doesn't get overwritten by updates:
-```bash
-sudo cp /usr/share/applications/brave-browser.desktop ~/.local/share/applications/
-```
-
-Patch all three `Exec=` lines with the flag:
-```bash
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable %U|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1 %U|' \
- ~/.local/share/applications/brave-browser.desktop
-
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable$|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1|' \
- ~/.local/share/applications/brave-browser.desktop
-
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable --incognito$|Exec=/usr/bin/brave-browser-stable --incognito --disable-features=WaylandWpColorManagerV1|' \
- ~/.local/share/applications/brave-browser.desktop
-```
-
-Verify it worked — you should see exactly three `Exec=` lines:
-```bash
-grep "^Exec" ~/.local/share/applications/brave-browser.desktop
-```
-
-**What this flag actually does (as far as I understand it):**
-
-`--disable-features=WaylandWpColorManagerV1` — Brave 1.82+ introduced some Wayland color management extension that apparently conflicts with the AMD amdgpu driver on Fedora + GNOME Wayland. Without this flag, Brave triggers GPU ring timeouts that crash the entire GNOME Shell session. I have no idea why a browser color management feature would take down the whole desktop, but here we are.
-
-**A note on `--ozone-platform=x11`:** I tried this flag as a workaround for a crash when opening or downloading Bitwarden attachments — Brave does something with a Wayland protocol in a way that's not valid and immediately crashes. Running via XWayland sidesteps that. It turned out to cause a worse problem though: gnome-shell crashing with `SIGABRT` (`g_assertion_message_expr` in `meta_window_unmanage`), triggered during Picture-in-Picture video while Brave was running via XWayland — the same underlying mutter crash documented in [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625) and [Fedora bugzilla #2440608](https://bugzilla.redhat.com/show_bug.cgi?id=2440608). That takes down the entire desktop session and requires a hard reboot. The flag is gone. Brave now runs on native Wayland. The Bitwarden attachment crash still exists, but a Brave crash is preferable to losing the whole session.
-
-**Second workaround: disable hardware video decode in `brave://flags`**
-
-{{< callout type="warning" >}}
-Hardware video decode still causes crashes even with the flag above. As long as the AMD VCN decoder is active, GNOME Shell crashes with SIGABRT (`g_assertion_message_expr`) — reproducible during Picture-in-Picture video and intensive video activity. See [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625) and [Fedora bugzilla #2440608](https://bugzilla.redhat.com/show_bug.cgi?id=2440608). Hardware video decode is **not yet stable** on the AMD Radeon 890M with GNOME Wayland.
-{{< /callout >}}
-
-Go to `brave://flags` and disable:
-
-- **Hardware-accelerated video decode** → `Disabled`
-
-
-
-Video now decodes in software. You lose hardware acceleration for video, but the session stays stable. After this, `brave://gpu` will show:
-
-- `Video Decode: Software only. Hardware acceleration disabled`
-- `Video Encode: Software only. Hardware acceleration disabled`
-
-Brave://gpu config — video decode set to software (stable):
-
-
-
-**Flatpak Installation**
-
-If the RPM version gives you trouble, the Flatpak is worth trying:
-
-```bash
-flatpak install flathub com.brave.Browser
-```
-
-
-
-### Setting the hostname
-
-Nothing special here — just set the hostname via System Settings so the machine has a proper name on the network.
-
-
-
-### GNOME window buttons — adding minimize & maximize back
-
-By default, GNOME 49 only shows the close button. I personally want minimize and maximize visible too — it's one of those small things that bugged me coming from Windows. One command fixes it:
-
-```bash
-gsettings set org.gnome.desktop.wm.preferences button-layout 'appmenu:minimize,maximize,close'
-```
-
-
-
-### Bitwarden desktop (Flathub)
-
-I use Bitwarden for password management. The desktop app is available via Flathub and works well.
-
-
-
-### Signal Messenger (Flathub)
-
-Signal is my main messaging app. Officially it's only supported on Debian/Ubuntu, but the Flatpak version works perfectly fine on Fedora. It's Electron-based, so performance is decent.
-
-
-
-### Git & GitHub CLI
-
-Git comes pre-installed on Fedora. If for some reason it's not there, or if you also want the GitHub CLI (`gh`):
-
-```bash
-sudo dnf install git gh
-```
-
-### Proton Mail (Flathub)
-
-I use Proton Mail as my email provider. The desktop app is a wrapper around the web app rather than a native client. For web-based mail that's fine by me — it works, and it lives in the app launcher like any other app.
-
-
-
-### Visual Studio Code
-
-I install VS Code via the official RPM repo and Microsoft GPG key, as described in the [official instructions](https://code.visualstudio.com/docs/setup/linux):
-
-```bash
-# Import Microsoft GPG key and add repo
-sudo rpm --import https://packages.microsoft.com/keys/microsoft.asc
-
-echo -e "[code]\nname=Visual Studio Code\nbaseurl=https://packages.microsoft.com/yumrepos/vscode\nenabled=1\nautorefresh=1\ntype=rpm-md\ngpgcheck=1\ngpgkey=https://packages.microsoft.com/keys/microsoft.asc" | sudo tee /etc/yum.repos.d/vscode.repo > /dev/null
-
-# Update repo cache
-dnf check-update
-
-# Install VS Code
-sudo dnf install code
-```
-
-{{< callout type="warning" >}}
-On kernel 6.18.x, VS Code hardware acceleration can trigger an amdgpu page fault. Disable hardware acceleration. See the [NVIDIA Driver Installation Guide]({{< relref "/docs/nvidia-driver-installation" >}}).
-{{< /callout >}}
-
-### Kleopatra & GPG commit signing
-
-I sign my Git commits and tags with a GPG key. It's one of those things I set up once and then never think about again. Kleopatra makes generating and managing keys straightforward via a GUI instead of having to figure out the GPG command line.
-
-After installing VS Code and Git, install Kleopatra and create your keys there. Then configure Git to use them:
-
-```bash
-git config --global user.name "YOUR_NAME"
-git config --global user.email "YOUR_EMAIL"
-git config --global user.signingkey YOUR_GPG_KEY_ID
-git config --global commit.gpgsign true
-git config --global tag.gpgsign true
-git config --global gpg.program gpg
-```
+| Component | Specification |
+|-----------|---------------|
+| **Model** | ASUS ROG Zephyrus G16 GA605WV (2024) |
+| **CPU** | AMD Ryzen AI 9 HX 370 |
+| **iGPU** | AMD Radeon 890M |
+| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
+| **OS** | CachyOS (Arch) |
+| **Kernel** | 6.19.3-2 |
+| **Display Server** | Wayland (GNOME 49) |
+| **Secure Boot** | Enabled |
-To find your key ID:
-```bash
-gpg --list-secret-keys --keyid-format=long
-```
-Use the ID from the `sec` line (e.g., `rsa4096/YOUR_GPG_KEY_ID`).
+## Recommended setup order
-### Tidal Hi-Fi (Electron)
+After a fresh CachyOS install, this is the order that made sense for me:
-There's no official Tidal client for Linux. [Tidal Hi-Fi](https://github.com/Mastermindzh/tidal-hifi) by Rick van Lieshout is a community-made Electron wrapper around the Tidal web player, with Hi-Fi and Max quality support. It's not official, but it works well and is available via Flathub.
-
-
-
-### NVIDIA GPU drivers
-
-The G16 has an RTX 4060 alongside the AMD iGPU. The open-source Nouveau driver doesn't perform well on modern NVIDIA hardware, so proprietary drivers are needed for anything graphics-intensive.
-
-{{< callout type="info" >}}
-Full installation guide: [NVIDIA Driver Installation Guide]({{< relref "/docs/nvidia-driver-installation" >}})
-{{< /callout >}}
-
-**What I ended up with:**
-- NVIDIA driver 580.119.02 via RPM Fusion
-- MOK enrollment for Secure Boot
-- A kernel parameter workaround for an AMD GPU crash with external monitors
-
-After this, the GPU works correctly on Wayland with CUDA 13.0 support.
-
-### Bottles — running Windows software
-
-[Bottles](https://usebottles.com/) lets you run Windows software via Wine. Install it from Flathub — the RPM packages in Fedora's repos are deprecated and ship much older versions. Make sure you get version 61 or newer.
-
-- Open GNOME Software Center
-- Search for "Bottles"
-- Select the **Flathub** source (not Fedora Linux / RPM)
-- Click Install
-
-For anything that doesn't work under Wine — like Microsoft 365 — I use a Windows VM instead.
-
-
-
-### Archi (ArchiMate modeling tool)
-
-I use [Archi](https://www.archimatetool.com/) for ArchiMate modeling. It's free and open-source, but the Linux package is just a portable archive — no installer, no `.deb`, no `.rpm`. To make it show up properly in GNOME with an icon, you have to place the files yourself and create a desktop entry manually.
-
-
-
-{{< callout type="info" >}}
-Archi's download page warns about possible UI issues on Wayland. In my experience it runs fine on GNOME 49 Wayland — no issues so far.
-{{< /callout >}}
-
-```bash
-# Download and extract in one flow
-cd /tmp
-curl -L https://github.com/archimatetool/archi.io/releases/download/5.7.0/Archi-Linux64-5.7.0.tgz | tar -xz
-
-# Move to /opt
-sudo mv Archi-Linux64-5.7.0/Archi /opt/
-
-# Cleanup
-rm -rf Archi-Linux64-5.7.0
-cd ~
-
-# Create symlink so you can run 'archi' from the terminal
-sudo ln -s /opt/Archi/Archi /usr/local/bin/archi
-```
-
-Create a desktop entry so Archi shows up in GNOME:
-```bash
-sudo nano /usr/share/applications/archi.desktop
-```
-
-```ini
-[Desktop Entry]
-Version=1.0
-Type=Application
-Name=Archi
-Comment=ArchiMate Modelling Tool
-Exec=/opt/Archi/Archi
-Icon=/opt/Archi/plugins/com.archimatetool.editor_5.7.0.202509230807/img/app-128.png
-Terminal=false
-Categories=Development;IDE;
-StartupWMClass=Archi
-```
-
-After saving, Archi appears in the GNOME app launcher:
-
-
-
-
-
-### Windows 11 VM with virt-manager (KVM/QEMU)
-
-Some things just don't run on Linux — Microsoft 365 being the obvious one. For those cases I have a Windows 11 VM running via KVM/QEMU.
-
-{{< callout type="info" >}}
-Full setup guide: [Windows 11 VM Setup Guide]({{< relref "/docs/vm-setup" >}})
-{{< /callout >}}
-
-**My setup:**
-- Windows 11 Enterprise, Q35 chipset, UEFI Secure Boot, emulated TPM 2.0
-- virt-manager with KVM/QEMU, host-passthrough CPU, 8 GB RAM, 8 cores
-- VirtIO disk (writeback cache, threaded I/O, TRIM/discard), VirtIO network
-- SPICE display with GL acceleration via AMD iGPU
-- Hyper-V enlightenments for better Windows performance
-- VirtIO Guest Tools and SPICE Guest Tools inside the VM
-
-### Steam
-
-I game on this machine too, so Steam is a must. It needs the RPM Fusion nonfree repo. The [official Fedora gaming documentation](https://docs.fedoraproject.org/en-US/gaming/proton/) is worth a read for the latest instructions.
-
-**Enable RPM Fusion repositories (free + nonfree):**
-```bash
-sudo dnf install \
- https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm \
- https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm -y
-```
-
-**Enable the Cisco OpenH264 repository:**
-```bash
-sudo dnf config-manager setopt fedora-cisco-openh264.enabled=1
-```
-
-**Install Steam:**
-```bash
-sudo dnf install steam -y
-```
-
-
-
-Reboot after installing. Steam includes Proton out of the box, which lets you run a lot of Windows games on Linux. You can pick specific Proton versions per game via Steam Settings > Compatibility.
-
-{{< callout type="info" >}}
-If Steam won't launch, try running it from the terminal with:
-```bash
-__GL_CONSTANT_FRAME_RATE_HINT=3 steam
-```
-{{< /callout >}}
-
-### Solaar for Logitech devices
-
-[Solaar](https://github.com/pwr-Solaar/Solaar) manages Logitech keyboards, mice, and other peripherals connected via Unifying, Lightspeed, Nano receiver, USB, or Bluetooth. Install it from Flathub — the Fedora RPM version is outdated. You want version 1.1.19 or newer.
-
-- Open GNOME Software Center
-- Search for "Solaar"
-- Select the **Flathub** source (not Fedora Linux / RPM)
-- Click Install
-
-
-
-It runs in the system tray and shows battery notifications for your devices. You can also configure DPI, polling rate, and buttons from there.
-
-
-
-### GNOME keyboard shortcuts — making it feel more like Windows
-
-Coming from Windows, some things feel off without the right shortcuts. These are the ones I set up to make the transition smoother.
-
-**Built-in shortcuts (via Settings > Keyboard > Keyboard Shortcuts):**
-
-| # | Action | Shortcut |
-|---|--------|----------|
-| 1 | Show desktop (hide all windows) | `Super+D` |
-| 2 | Take a screenshot interactively | `Shift+Super+S` |
-| 3 | Record a screencast interactively | `Shift+Super+R` |
-| 4 | Open Settings | `Super+I` |
-
-**Custom shortcut (via Settings > Keyboard > Keyboard Shortcuts > Custom Shortcuts):**
-
-| # | Action | Command | Shortcut |
-|---|--------|---------|----------|
-| 5 | Open file manager | `nautilus` | `Super+E` |
-
-GNOME doesn't have a built-in shortcut for the file manager, so this one needs to be created manually.
-
-### Touchpad scroll speed — no native GNOME setting (yet)
-
-This one frustrated me. As of GNOME 49 and Fedora 43, there is simply **no native setting** for touchpad scroll speed anywhere in the Settings panel. KDE Plasma has had this for years. There are merge requests open in [mutter](https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1840) and [GNOME Control Center](https://gitlab.gnome.org/GNOME/gnome-control-center/-/merge_requests/991) to add it, but they've been sitting there for years and it's unclear when or if they'll ship. See the [GNOME Discourse thread](https://discourse.gnome.org/t/adding-scroll-speed-setting-in-gnome/25893) if you're curious about the discussion.
-
-In the meantime, [libinput-config](https://github.com/lz42/libinput-config) by lz42 is a third-party workaround that intercepts libinput events and applies a scroll multiplier. It's not elegant, but it works.
-
-**Install (one-time):**
-
-```bash
-# 1. Install dependencies
-sudo dnf install -y meson ninja-build libinput-devel git
-
-# 2. Clone libinput-config
-git clone https://github.com/lz42/libinput-config.git
-cd libinput-config
-
-# 3. Build
-meson setup build
-ninja -C build
-
-# 4. Install system-wide
-sudo ninja -C build install
-
-# 5. Cleanup (optional)
-cd ..
-rm -rf libinput-config
-```
+{{% steps %}}
-**Configuration for slower touchpad scroll:**
+### Hardware & Drivers
-```bash
-sudo tee /etc/libinput.conf >/dev/null << 'EOF'
-# libinput-config configuration
-override-compositor=enabled
+Install NVIDIA drivers, set up Secure Boot with your own signing keys, and configure ASUS ROG hardware features (fan curves, performance profiles, GPU switching).
-# Make touchpad scroll slower (lower = slower)
-# Default: 1.0, tested value: 0.25
-scroll-factor=0.25
+→ [NVIDIA Driver Installation]({{< relref "/docs/hardware/nvidia-driver-installation" >}})
+→ [Secure Boot]({{< relref "/docs/hardware/secure-boot" >}})
+→ [asusctl & ROG Control Center]({{< relref "/docs/hardware/asusctl-rog-control" >}})
-# Keep mouse wheel behavior normal
-discrete-scroll-factor=1.0
-EOF
-```
+### Security & Privacy
-Log out and back in (or reboot), then adjust `scroll-factor` to your liking.
+Set up hardware-backed LUKS unlock with a YubiKey, and optionally configure GDM to skip the login screen after disk unlock.
-**Rollback:**
+→ [YubiKey 5C NFC]({{< relref "/docs/security/yubikey" >}})
+→ [GDM Autologin]({{< relref "/docs/security/autologin" >}})
-```bash
-sudo rm /etc/libinput.conf
-```
+### Applications
-### eduroam (university Wi-Fi)
+Install and configure applications — browser, communication tools, development environment, and utilities. Includes non-obvious workarounds for Brave on GNOME Wayland and touchpad scroll speed.
-Getting eduroam to work on Linux was genuinely painful. The official installers didn't work, community tools failed, and it took me a while to land on a setup that actually connects reliably. A manual PEAP/MSCHAPv2 configuration via nmcli ended up being the solution.
+→ [Applications]({{< relref "/docs/applications" >}})
-{{< callout type="info" >}}
-Full setup guide: [eduroam Network Installation]({{< relref "/docs/eduroam-network-installation" >}})
-{{< /callout >}}
+### Networking
-**What worked for me:**
-- PEAP / MSCHAPv2 with CA validation via the system trust store
-- `domain-suffix-match` instead of the deprecated `altsubject-matches`
-- An automated Python script or manual nmcli command
+Get eduroam working. The official installers don't work on Linux; a manual PEAP/MSCHAPv2 configuration via nmcli does.
-### GDM autologin after LUKS
+→ [eduroam Network Installation]({{< relref "/docs/networking/eduroam-network-installation" >}})
-After unlocking the disk with my LUKS password at boot, I didn't want to type a second password to log in. This skips the GDM login screen so the desktop loads immediately after the disk unlock.
+### Virtualization
-{{< callout type="info" >}}
-Full setup guide: [GDM Autologin Guide]({{< relref "/docs/autologin" >}})
-{{< /callout >}}
+Set up a Windows 11 VM for software that doesn't run on Linux (Microsoft 365, etc.).
-**Setup:**
-- Edit `/etc/gdm/custom.conf`
-- Set `AutomaticLoginEnable=True` and `AutomaticLogin=sten` under `[daemon]`
-- Reboot
+→ [Windows 11 VM Setup]({{< relref "/docs/virtualization/vm-setup" >}})
{{% /steps %}}
diff --git a/content/docs/getting-started.nl.md b/content/docs/getting-started.nl.md
index 0e41677..7e5049a 100644
--- a/content/docs/getting-started.nl.md
+++ b/content/docs/getting-started.nl.md
@@ -3,427 +3,60 @@ title: "Aan de slag"
weight: 2
---
-Dit is mijn persoonlijke setup-log voor de ROG Zephyrus G16 op Fedora Linux. Ik ben geen software-engineer of developer — ik ben gewoon iemand die overgestapt is naar Linux en daarna tegen van alles aan liep wat niet meteen werkte. Ik heb alles opgeschreven zodat anderen niet hetzelfde hoeven uit te zoeken als ik.
+Dit is mijn persoonlijke setup-documentatie voor de ROG Zephyrus G16 op CachyOS (Arch). Ik ben geen software-engineer of developer — gewoon iemand die overgestapt is naar Linux en daarna tegen van alles aanliep wat niet meteen werkte. Ik heb alles opgeschreven zodat anderen niet hetzelfde hoeven uit te zoeken als ik.
-Als iets hier je helpt: mooi. Loop je ergens tegenaan wat ik niet behandeld heb, laat het gerust weten — ik denk graag mee. Ik heb niet altijd het antwoord, maar ik doe mijn best.
+Als iets hier je helpt: mooi. Loop je ergens tegenaan wat ik niet behandeld heb, laat het gerust weten — ik denk graag mee.
-De stappen hieronder zijn in grote lijnen de volgorde waarop ik dingen heb opgezet na een schone Fedora 43-installatie.
+## Hardware
-{{% steps %}}
-
-### Brave browser — RPM met Wayland-workarounds
-
-Brave is mijn standaardbrowser. Ik begon met de Flatpak-versie maar ben overgestapt naar de native RPM — mensen op Reddit zeggen dat de RPM-versie nativer aanvoelt en betere prestaties en efficiëntie biedt. Er is alleen een addertje: Brave 1.82+ heeft twee crashbugs op GNOME Wayland die je moet oplossen voordat het écht stabiel is. Ik snap niet helemaal waarom die crashes plaatsvinden — het gaat om GPU-drivers en Wayland-protocollen die blijkbaar niet goed samenwerken — maar de onderstaande fixes werken voor mij.
-
-- **RPM (native):** Nativer gevoel, betere prestaties en efficiëntie. Dit gebruik ik.
-- **Flatpak:** Kan in sommige situaties beter werken, maar voelt wat meer geïsoleerd en iets trager.
-
-**RPM Installatie**
-
-{{< callout type="warning" >}}
-Op Fedora met GNOME + Wayland heeft Brave 1.82+ twee bekende crashbugs waarvoor workarounds nodig zijn. De eerste wordt via de desktop entry toegepast; de tweede vereist een instelling in `brave://flags`.
-{{< /callout >}}
-
-```bash
-sudo dnf install dnf-plugins-core
-sudo dnf config-manager addrepo --from-repofile=https://brave-browser-rpm-release.s3.brave.com/brave-browser.repo
-sudo dnf install brave-browser
-```
-
-
-
-**Workaround 1: de desktop entry patchen**
-
-Kopieer de systeem-desktop entry naar je gebruikersmap zodat hij niet wordt overschreven bij updates:
-```bash
-sudo cp /usr/share/applications/brave-browser.desktop ~/.local/share/applications/
-```
-
-Patch alle drie de `Exec=` regels met de flag:
-```bash
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable %U|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1 %U|' \
- ~/.local/share/applications/brave-browser.desktop
-
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable$|Exec=/usr/bin/brave-browser-stable --disable-features=WaylandWpColorManagerV1|' \
- ~/.local/share/applications/brave-browser.desktop
-
-sed -i \
- 's|Exec=/usr/bin/brave-browser-stable --incognito$|Exec=/usr/bin/brave-browser-stable --incognito --disable-features=WaylandWpColorManagerV1|' \
- ~/.local/share/applications/brave-browser.desktop
-```
-
-Controleer of het gelukt is — je zou exact drie `Exec=` regels moeten zien:
-```bash
-grep "^Exec" ~/.local/share/applications/brave-browser.desktop
-```
-
-**Wat deze flag doet (voor zover ik het begrijp):**
-
-`--disable-features=WaylandWpColorManagerV1` — Brave 1.82+ introduceerde een Wayland color management extensie die blijkbaar conflicteert met de AMD amdgpu-driver op Fedora + GNOME Wayland. Zonder deze flag veroorzaakt Brave GPU ring timeouts die de volledige GNOME Shell-sessie laten crashen. Ik heb geen idee waarom een browser-kleurbeheerfunctie het hele bureaublad kan neerhalen, maar hier zijn we dan.
-
-**Een noot over `--ozone-platform=x11`:** Ik heb deze flag geprobeerd als workaround voor een crash bij het openen of downloaden van Bitwarden-bijlagen — Brave doet dan iets met een Wayland-protocol op een manier die niet geldig is en crasht direct. Via XWayland omzeil je dat. Maar het bleek een erger probleem te veroorzaken: gnome-shell crashte met `SIGABRT` (`g_assertion_message_expr` in `meta_window_unmanage`), getriggerd tijdens Picture-in-Picture video terwijl Brave via XWayland draaide — dezelfde onderliggende mutter-crash als gedocumenteerd in [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625) en [Fedora bugzilla #2440608](https://bugzilla.redhat.com/show_bug.cgi?id=2440608). Die crash slaat de hele bureaublad-sessie neer en vereist een harde herstart. De flag is weg. Brave draait nu op native Wayland. De Bitwarden-bijlage-crash bestaat nog steeds, maar een Brave-crash is te verkiezen boven het verliezen van de hele sessie.
-
-**Tweede workaround: hardware video decode uitschakelen in `brave://flags`**
-
-{{< callout type="warning" >}}
-Hardware video decode veroorzaakt nog steeds crashes, ook met de flag hierboven. Zolang de AMD VCN decoder actief is, crasht GNOME Shell met een SIGABRT (`g_assertion_message_expr`) — reproduceerbaar bij Picture-in-Picture video en bij intensief videobeheer. Zie [gnome-mutter issue #4625](https://gitlab.gnome.org/GNOME/mutter/-/issues/4625) en [Fedora bugzilla #2440608](https://bugzilla.redhat.com/show_bug.cgi?id=2440608). Hardware video decode is **nog niet stabiel** op de AMD Radeon 890M met GNOME Wayland.
-{{< /callout >}}
-
-Ga naar `brave://flags` en schakel uit:
-
-- **Hardware-accelerated video decode** → `Disabled`
-
-
-
-Video wordt nu via software gedecodeerd. Je verliest hardware-versnelling voor video, maar de sessie blijft stabiel. In `brave://gpu` staat daarna:
-
-- `Video Decode: Software only. Hardware acceleration disabled`
-- `Video Encode: Software only. Hardware acceleration disabled`
-
-Brave://gpu config — video decode op software (stabiel):
-
-
-
-**Flatpak Installatie**
-
-Geeft de RPM-versie je problemen, dan is de Flatpak het proberen waard:
-
-```bash
-flatpak install flathub com.brave.Browser
-```
-
-
-
-### Hostname instellen
-
-Niets bijzonders — gewoon de hostname instellen via Systeeminstellingen zodat de machine een fatsoenlijke naam heeft op het netwerk.
-
-
-
-### GNOME-vensterknoppen — minimize en maximize terug
-
-Standaard toont GNOME 49 alleen de sluitknop. Ik wil minimize en maximize ook zichtbaar — één van die kleine dingetjes die me stoorde na jaren Windows. Eén commando lost het op:
-
-```bash
-gsettings set org.gnome.desktop.wm.preferences button-layout 'appmenu:minimize,maximize,close'
-```
-
-
-
-### Bitwarden desktop (Flathub)
-
-Ik gebruik Bitwarden voor wachtwoordbeheer. De desktop-app is beschikbaar via Flathub en werkt goed.
-
-
-
-### Signal Messenger (Flathub)
-
-Signal is mijn belangrijkste berichtenapp. Officieel wordt alleen Debian/Ubuntu ondersteund, maar de Flatpak-versie werkt prima op Fedora. Het is gebaseerd op Electron, dus de prestaties zijn redelijk.
-
-
-
-### Git & GitHub CLI
-
-Git wordt standaard meegeleverd op Fedora. Als het om wat voor reden dan ook niet geïnstalleerd is, of als je ook de GitHub CLI (`gh`) wilt:
-
-```bash
-sudo dnf install git gh
-```
-
-### Proton Mail (Flathub)
-
-Ik gebruik Proton Mail als e-mailprovider. De desktop-app is een wrapper rondom de webapp, geen echte native client. Voor webgebaseerde mail is dat prima voor mij — hij werkt, en hij zit gewoon in de app launcher zoals elke andere app.
-
-
-
-### Visual Studio Code
-
-Ik installeer VS Code via de officiële RPM-repo en Microsoft GPG key, zoals beschreven in de [officiële instructies](https://code.visualstudio.com/docs/setup/linux):
-
-```bash
-# Microsoft GPG key importeren en repo toevoegen
-sudo rpm --import https://packages.microsoft.com/keys/microsoft.asc
-
-echo -e "[code]\nname=Visual Studio Code\nbaseurl=https://packages.microsoft.com/yumrepos/vscode\nenabled=1\nautorefresh=1\ntype=rpm-md\ngpgcheck=1\ngpgkey=https://packages.microsoft.com/keys/microsoft.asc" | sudo tee /etc/yum.repos.d/vscode.repo > /dev/null
-
-# Repo cache updaten
-dnf check-update
-
-# VS Code installeren
-sudo dnf install code
-```
-
-{{< callout type="warning" >}}
-Op kernel 6.18.x kan hardware acceleration in VS Code een amdgpu page fault veroorzaken waardoor het systeem bevriest. Zet hardware acceleration uit. Zie de [NVIDIA Driver Installatie]({{< relref "/docs/nvidia-driver-installation" >}}).
-{{< /callout >}}
-
-### Kleopatra & GPG commit signing
-
-Ik onderteken mijn Git commits en tags met een GPG-sleutel. Eenmalig instellen, daarna denk je er nooit meer aan. Kleopatra maakt het aanmaken en beheren van sleutels makkelijk via een GUI, zonder dat je de GPG-commandoregel hoeft uit te zoeken.
-
-Na het installeren van VS Code en Git, installeer Kleopatra en maak je sleutels daarin aan. Daarna Git configureren:
-
-```bash
-git config --global user.name "JOUW_NAAM"
-git config --global user.email "JOUW_EMAIL"
-git config --global user.signingkey JOUW_GPG_KEY_ID
-git config --global commit.gpgsign true
-git config --global tag.gpgsign true
-git config --global gpg.program gpg
-```
+| Onderdeel | Specificatie |
+|-----------|--------------|
+| **Model** | ASUS ROG Zephyrus G16 GA605WV (2024) |
+| **CPU** | AMD Ryzen AI 9 HX 370 |
+| **iGPU** | AMD Radeon 890M |
+| **dGPU** | NVIDIA GeForce RTX 4060 Laptop (Max-Q) |
+| **OS** | CachyOS (Arch) |
+| **Kernel** | 6.19.3-2 |
+| **Display Server** | Wayland (GNOME 49) |
+| **Secure Boot** | Ingeschakeld |
-Je sleutel-ID vinden:
-```bash
-gpg --list-secret-keys --keyid-format=long
-```
-Gebruik de ID van de `sec` regel (bijv. `rsa4096/JOUW_GPG_KEY_ID`).
+## Aanbevolen volgorde
-### Tidal Hi-Fi (Electron)
+Dit is de volgorde die logisch aanvoelde na een schone CachyOS-installatie:
-Er is geen officiële Tidal-client voor Linux. [Tidal Hi-Fi](https://github.com/Mastermindzh/tidal-hifi) van Rick van Lieshout is een community-Electron-wrapper rondom de Tidal-webapp, met Hi-Fi en Max kwaliteitsondersteuning. Niet officieel, maar werkt goed en staat op Flathub.
-
-
-
-### NVIDIA GPU drivers
-
-De G16 heeft een RTX 4060 naast de AMD iGPU. De open-source Nouveau driver werkt slecht op moderne NVIDIA-hardware, dus proprietary drivers zijn nodig voor alles wat graphics-intensief is.
-
-{{< callout type="info" >}}
-Volledige installatie-handleiding: [NVIDIA Driver Installatie]({{< relref "/docs/nvidia-driver-installation" >}})
-{{< /callout >}}
-
-**Waar ik op uitkwam:**
-- NVIDIA driver 580.119.02 via RPM Fusion
-- MOK enrollment voor Secure Boot
-- Een kernel parameter-workaround voor een AMD GPU-crash met externe monitoren
-
-Daarna werkt de GPU correct op Wayland met CUDA 13.0-ondersteuning.
-
-### Bottles — Windows-software draaien
-
-[Bottles](https://usebottles.com/) laat je Windows-software draaien via Wine. Installeer het via Flathub — de RPM-pakketten in Fedora's repos zijn verouderd en bevatten veel oudere versies. Zorg dat je versie 61 of nieuwer hebt.
-
-- Open GNOME Software Center
-- Zoek naar "Bottles"
-- Selecteer de **Flathub** bron (niet Fedora Linux / RPM)
-- Klik op Installeren
-
-Voor wat niet werkt onder Wine — zoals Microsoft 365 — gebruik ik een Windows VM.
-
-
-
-### Archi (ArchiMate-modelleertool)
-
-Ik gebruik [Archi](https://www.archimatetool.com/) voor ArchiMate-modellering. Gratis en open-source, maar het Linux-pakket is een portable archief — geen installer, geen `.deb`, geen `.rpm`. Om het netjes in GNOME te laten verschijnen met een icoon, moet je de bestanden zelf plaatsen en een desktop entry handmatig aanmaken.
-
-
-
-{{< callout type="info" >}}
-De downloadpagina van Archi waarschuwt voor mogelijke UI-problemen op Wayland. In mijn ervaring werkt hij prima op GNOME 49 Wayland — tot nu toe geen problemen.
-{{< /callout >}}
-
-```bash
-# Download en extraheer in één keer
-cd /tmp
-curl -L https://github.com/archimatetool/archi.io/releases/download/5.7.0/Archi-Linux64-5.7.0.tgz | tar -xz
-
-# Verplaats naar /opt
-sudo mv Archi-Linux64-5.7.0/Archi /opt/
-
-# Opruimen
-rm -rf Archi-Linux64-5.7.0
-cd ~
-
-# Symlink zodat je 'archi' kunt starten vanuit de terminal
-sudo ln -s /opt/Archi/Archi /usr/local/bin/archi
-```
-
-Desktop entry aanmaken zodat Archi in GNOME verschijnt:
-```bash
-sudo nano /usr/share/applications/archi.desktop
-```
-
-```ini
-[Desktop Entry]
-Version=1.0
-Type=Application
-Name=Archi
-Comment=ArchiMate Modelling Tool
-Exec=/opt/Archi/Archi
-Icon=/opt/Archi/plugins/com.archimatetool.editor_5.7.0.202509230807/img/app-128.png
-Terminal=false
-Categories=Development;IDE;
-StartupWMClass=Archi
-```
-
-Na het opslaan verschijnt Archi in de GNOME-app launcher:
-
-
-
-
-
-### Windows 11 VM met virt-manager (KVM/QEMU)
-
-Sommige dingen draaien gewoon niet op Linux — Microsoft 365 is het meest voor de hand liggende voorbeeld. Daarvoor heb ik een Windows 11 VM draaien via KVM/QEMU.
-
-{{< callout type="info" >}}
-Volledige setup-handleiding: [Windows 11 VM Setup Guide]({{< relref "/docs/vm-setup" >}})
-{{< /callout >}}
-
-**Mijn setup:**
-- Windows 11 Enterprise, Q35 chipset, UEFI Secure Boot, geëmuleerde TPM 2.0
-- virt-manager met KVM/QEMU, host-passthrough CPU, 8 GB RAM, 8 cores
-- VirtIO disk (writeback cache, threaded I/O, TRIM/discard), VirtIO netwerk
-- SPICE display met GL-acceleratie via AMD iGPU
-- Hyper-V enlightenments voor betere Windows-prestaties
-- VirtIO Guest Tools en SPICE Guest Tools in de VM
-
-### Steam
-
-Ik game ook op deze machine, dus Steam is een must. Dat heeft de RPM Fusion nonfree repo nodig. De [officiële Fedora gaming documentatie](https://docs.fedoraproject.org/en-US/gaming/proton/) is de moeite waard voor de meest actuele instructies.
-
-**RPM Fusion repositories activeren (free + nonfree):**
-```bash
-sudo dnf install \
- https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm \
- https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm -y
-```
-
-**Cisco OpenH264 repository inschakelen:**
-```bash
-sudo dnf config-manager setopt fedora-cisco-openh264.enabled=1
-```
-
-**Steam installeren:**
-```bash
-sudo dnf install steam -y
-```
-
-
-
-Herstart na installatie. Steam bevat Proton standaard, waarmee je veel Windows-games op Linux kunt draaien. Per game kun je een specifieke Proton-versie kiezen via Steam Settings > Compatibility.
-
-{{< callout type="info" >}}
-Als Steam niet wil starten, probeer het dan vanuit de terminal:
-```bash
-__GL_CONSTANT_FRAME_RATE_HINT=3 steam
-```
-{{< /callout >}}
-
-### Solaar voor Logitech-apparaten
-
-[Solaar](https://github.com/pwr-Solaar/Solaar) beheert Logitech-toetsenborden, muizen en andere randapparatuur via Unifying, Lightspeed, Nano receiver, USB of Bluetooth. Installeer het via Flathub — de Fedora RPM-versie is verouderd. Je wilt versie 1.1.19 of nieuwer.
-
-- Open GNOME Software Center
-- Zoek naar "Solaar"
-- Selecteer de **Flathub** bron (niet Fedora Linux / RPM)
-- Klik op Installeren
-
-
-
-Het draait in het systray en toont batterijnotificaties voor je apparaten. Je kunt er ook DPI, polling rate en knoppen mee configureren.
-
-
-
-### GNOME-sneltoetsen — meer als Windows
-
-Als je vanuit Windows komt, voelt een paar dingen meteen anders zonder de juiste sneltoetsen. Dit zijn de sneltoetsen die ik heb ingesteld om de overstap soepeler te laten lopen.
-
-**Ingebouwde sneltoetsen (via Settings > Keyboard > Keyboard Shortcuts):**
-
-| # | Actie | Sneltoets |
-|---|-------|-----------|
-| 1 | Desktop tonen (alle vensters verbergen) | `Super+D` |
-| 2 | Interactieve screenshot | `Shift+Super+S` |
-| 3 | Interactieve schermopname | `Shift+Super+R` |
-| 4 | Instellingen openen | `Super+I` |
-
-**Custom shortcut (via Settings > Keyboard > Keyboard Shortcuts > Custom Shortcuts):**
-
-| # | Actie | Commando | Sneltoets |
-|---|-------|----------|-----------|
-| 5 | Bestandsbeheer openen | `nautilus` | `Super+E` |
-
-GNOME heeft standaard geen sneltoets voor de bestandsbeheerder, dus die moet je handmatig aanmaken.
-
-### Touchpad-scrollsnelheid — geen native GNOME-instelling (nog niet)
-
-Dit frustreerde me. GNOME 49 en Fedora 43 bieden simpelweg **geen instelling** voor touchpad-scrollsnelheid. KDE Plasma heeft dat al jaren. Er zijn merge requests open in [mutter](https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/1840) en [GNOME Control Center](https://gitlab.gnome.org/GNOME/gnome-control-center/-/merge_requests/991) om het toe te voegen, maar die staan al jaren open en het is onduidelijk wanneer het er ooit van komt. Zie de [GNOME Discourse-discussie](https://discourse.gnome.org/t/adding-scroll-speed-setting-in-gnome/25893) als je nieuwsgierig bent.
-
-In de tussentijd is [libinput-config](https://github.com/lz42/libinput-config) van lz42 een third-party workaround die libinput events onderschept en een scrollmultiplicator toepast. Niet elegant, maar het werkt.
-
-**Installatie (eenmalig):**
-
-```bash
-# 1. Dependencies installeren
-sudo dnf install -y meson ninja-build libinput-devel git
-
-# 2. libinput-config clonen
-git clone https://github.com/lz42/libinput-config.git
-cd libinput-config
-
-# 3. Bouwen
-meson setup build
-ninja -C build
-
-# 4. Systeembreed installeren
-sudo ninja -C build install
-
-# 5. Opruimen (optioneel)
-cd ..
-rm -rf libinput-config
-```
+{{% steps %}}
-**Configuratie voor langzamere touchpad-scroll:**
+### Hardware & Drivers
-```bash
-sudo tee /etc/libinput.conf >/dev/null << 'EOF'
-# libinput-config configuration
-override-compositor=enabled
+Installeer NVIDIA-drivers, stel Secure Boot in met je eigen ondertekeningssleutels, en configureer ASUS ROG hardware-functies (fan curves, prestatieprofielen, GPU-switching).
-# Touchpad-scroll langzamer (lager = langzamer)
-# Standaard: 1.0, geteste waarde: 0.25
-scroll-factor=0.25
+→ [NVIDIA Driver Installatie]({{< relref "/docs/hardware/nvidia-driver-installation" >}})
+→ [Secure Boot]({{< relref "/docs/hardware/secure-boot" >}})
+→ [asusctl & ROG Control Center]({{< relref "/docs/hardware/asusctl-rog-control" >}})
-# Muiswiel normaal houden
-discrete-scroll-factor=1.0
-EOF
-```
+### Beveiliging & Privacy
-Uitloggen en weer inloggen (of reboot), dan `scroll-factor` aanpassen naar voorkeur.
+Stel hardware-gebaseerde LUKS-ontgrendeling in met een YubiKey, en configureer optioneel GDM om het inlogscherm over te slaan na schijfontsluiting.
-**Terugdraaien:**
+→ [YubiKey 5C NFC]({{< relref "/docs/security/yubikey" >}})
+→ [GDM Autologin]({{< relref "/docs/security/autologin" >}})
-```bash
-sudo rm /etc/libinput.conf
-```
+### Applicaties
-### eduroam (universiteits-wifi)
+Installeer en configureer applicaties — browser, communicatietools, ontwikkelomgeving en hulpprogramma's. Inclusief niet-voor-de-hand-liggende workarounds voor Brave op GNOME Wayland en touchpad-scrollsnelheid.
-eduroam werkend krijgen op Linux was echt gedoe. De officiële installers werkten niet, community-tools ook niet, en het kostte me een tijdje voordat ik een setup had die betrouwbaar verbindt. Een handmatige PEAP/MSCHAPv2-configuratie via nmcli bleek de oplossing.
+→ [Applicaties]({{< relref "/docs/applications" >}})
-{{< callout type="info" >}}
-Volledige handleiding: [eduroam Netwerkinstallatie]({{< relref "/docs/eduroam-network-installation" >}})
-{{< /callout >}}
+### Netwerk
-**Wat bij mij werkte:**
-- PEAP / MSCHAPv2 met CA-validatie via de systeem-truststore
-- `domain-suffix-match` in plaats van het verouderde `altsubject-matches`
-- Een geautomatiseerd Python-script of handmatig nmcli-commando
+eduroam werkend krijgen. De officiële installers werken niet op Linux; een handmatige PEAP/MSCHAPv2-configuratie via nmcli wel.
-### GDM autologin na LUKS
+→ [eduroam Netwerkinstallatie]({{< relref "/docs/networking/eduroam-network-installation" >}})
-Na het invoeren van mijn LUKS-wachtwoord bij het opstarten wilde ik niet nog een keer een wachtwoord invoeren om in te loggen. Dit slaat het GDM-inlogscherm over zodat het bureaublad direct laadt na de schijfontsluiting.
+### Virtualisatie
-{{< callout type="info" >}}
-Volledige handleiding: [GDM Autologin]({{< relref "/docs/autologin" >}})
-{{< /callout >}}
+Windows 11 VM opzetten voor software die niet op Linux draait (Microsoft 365, etc.).
-**Setup:**
-- Bewerk `/etc/gdm/custom.conf`
-- Stel `AutomaticLoginEnable=True` en `AutomaticLogin=sten` in onder `[daemon]`
-- Herstart
+→ [Windows 11 VM Setup]({{< relref "/docs/virtualization/vm-setup" >}})
{{% /steps %}}
diff --git a/content/docs/hardware/_index.md b/content/docs/hardware/_index.md
new file mode 100644
index 0000000..4a4218b
--- /dev/null
+++ b/content/docs/hardware/_index.md
@@ -0,0 +1,7 @@
+---
+title: "Hardware & Drivers"
+weight: 10
+toc: false
+---
+
+Guides for NVIDIA drivers, Secure Boot, and ASUS ROG hardware features on the Zephyrus G16.
diff --git a/content/docs/hardware/_index.nl.md b/content/docs/hardware/_index.nl.md
new file mode 100644
index 0000000..33ea13a
--- /dev/null
+++ b/content/docs/hardware/_index.nl.md
@@ -0,0 +1,7 @@
+---
+title: "Hardware & Drivers"
+weight: 10
+toc: false
+---
+
+Handleidingen voor NVIDIA drivers, Secure Boot en ASUS ROG hardware-functies op de Zephyrus G16.
diff --git a/content/docs/asusctl-rog-control.md b/content/docs/hardware/asusctl-rog-control.md
similarity index 68%
rename from content/docs/asusctl-rog-control.md
rename to content/docs/hardware/asusctl-rog-control.md
index a9894fa..303d678 100644
--- a/content/docs/asusctl-rog-control.md
+++ b/content/docs/hardware/asusctl-rog-control.md
@@ -3,79 +3,23 @@ title: "asusctl & ROG Control Center"
weight: 22
---
-The Zephyrus G16 has a lot of hardware features that don't work out of the box on Linux — fan curves, performance profiles, the Slash LED on the lid, GPU switching, battery charge limiting. This page documents how I got all of it working using asusctl and the ASUS Linux project tools. It took some digging to figure out the Fedora-specific parts that their documentation doesn't cover, so I'm writing it down here.
+The Zephyrus G16 has a lot of hardware features that don't work out of the box on Linux — fan curves, performance profiles, the Slash LED on the lid, GPU switching, battery charge limiting. This page documents how I got all of it working using asusctl and the ASUS Linux project tools. On CachyOS, these tools are available directly from the package repos.
**Package Information:**
- `asusctl` 6.3.2-1 — CLI for fan curves, profiles, battery limit, RGB, Slash LED
- `asusctl-rog-gui` 6.3.2 — ROG Control Center GUI
- `supergfxctl` 5.2.7-8 — GPU mode switching
-- Source: [lukenukem COPR](https://copr.fedorainfracloud.org/coprs/lukenukem/asus-linux/) (maintained by Luke Jones, primary asusctl developer)
-
-
-## Prerequisites
-
-{{% details title="Why lukenukem COPR and not a regular repo" closed="true" %}}
-
-COPR is Fedora's official community package hosting platform (similar to AUR for Arch). The `lukenukem` COPR is maintained by Luke Jones (flukejones), the primary developer of asusctl itself — not a random third party.
-
-The packages are GPG-signed (`gpgcheck=1`) and this is the officially recommended installation method by the asus-linux project.
-
-**Note:** If you search for "lukenukem COPR" on Reddit, you may find threads raising concerns. These are typically about the openSUSE repository going temporarily offline — not a security issue with the COPR itself.
-
-{{% /details %}}
-
-{{% details title="Compatibility with tuned (power-profiles-daemon conflict) — Fedora-specific" closed="true" %}}
-
-`asusctl` requires the `power-profiles-daemon` D-Bus API to manage performance profiles (Silent/Balanced/Performance). On Arch Linux, you simply install `power-profiles-daemon` and it works. On Fedora however, this conflicts with `tuned`, which [replaced `power-profiles-daemon` as the default power management daemon since Fedora 41](https://fedoraproject.org/wiki/Changes/TunedAsTheDefaultPowerProfileManagementDaemon).
-
-The solution is `tuned-ppd`, a Fedora-provided compatibility layer that exposes the `power-profiles-daemon` D-Bus interface while using `tuned` internally. This allows `asusctl` to manage profiles without removing `tuned`.
-
-**Note:** The asus-linux project does not document this because it is a Fedora-specific issue. Their [FAQ](https://asus-linux.org/faq/) and [ArchWiki page](https://wiki.archlinux.org/title/Asusctl) only state that `power-profiles-daemon` must be running.
-
-If you have `tuned` installed (Fedora default), you must switch to `tuned-ppd` before installing asusctl, otherwise profile switching will not work.
-
-**References:**
-- [Fedora Wiki: Tuned as Default Power Profile Daemon (F41)](https://fedoraproject.org/wiki/Changes/TunedAsTheDefaultPowerProfileManagementDaemon)
-- [Phoronix: Fedora 41 Goes Tuned PPD](https://www.phoronix.com/news/Fedora-41-Goes-Tuned-PPD)
-- [asus-linux FAQ](https://asus-linux.org/faq/)
-- [asusctl ArchWiki](https://wiki.archlinux.org/title/Asusctl)
-
-{{% /details %}}
+- Source: CachyOS/Arch repos (packages maintained by Luke Jones, primary asusctl developer)
## Installation
{{% steps %}}
-### Add lukenukem COPR repository
-
-```bash
-sudo dnf copr enable lukenukem/asus-linux
-```
-
-### Switch from tuned to tuned-ppd (Fedora-specific)
-
-`asusctl` needs the `power-profiles-daemon` D-Bus API. On Fedora 41+, `tuned` is the default and conflicts with `power-profiles-daemon`. Install `tuned-ppd` as the compatibility layer:
-
-```bash
-sudo dnf install tuned-ppd
-sudo systemctl disable tuned.service
-sudo systemctl enable --now tuned-ppd.service
-```
-
-`tuned-ppd` exposes the `power-profiles-daemon` D-Bus interface while using `tuned` profiles internally. `asusctl` talks to `tuned-ppd` as if it were `power-profiles-daemon` — no modifications needed.
-
-**Verify:**
-```bash
-systemctl status tuned-ppd
-```
-
-**Note:** On Arch Linux, install `power-profiles-daemon` directly instead. This step is only needed on Fedora.
-
### Install asusctl, ROG Control Center, and supergfxctl
```bash
-sudo dnf install asusctl asusctl-rog-gui supergfxctl
+sudo pacman -S asusctl supergfxctl power-profiles-daemon rog-control-center
```
This installs:
@@ -114,7 +58,7 @@ Board name: GA605WV
Useful utilities for monitoring hardware alongside asusctl:
```bash
-sudo dnf install nvtop powertop s-tui lm_sensors i2c-tools
+sudo pacman -S nvtop powertop s-tui lm_sensors i2c-tools
```
| Package | Description |
@@ -211,7 +155,7 @@ asusctl profile --next
asusctl profile
```
-> **Note:** Profile switching requires `tuned-ppd` to be running. See the installation steps above.
+> **Note:** Profile switching requires `power-profiles-daemon` to be running. See the installation steps above.
{{% /details %}}
@@ -240,7 +184,7 @@ supergfxctl --mode Integrated
> **Note:** Switching between Hybrid and Integrated requires a logout/login. Switching to AsusMuxDgpu requires a reboot.
-> **Important:** `nvidia-powerd.service` must remain disabled and **masked** on this laptop. It conflicts with AMD ATPX power management and causes soft lockups and reboot hangs (black screen, backlights stay on). Masking is essential because `supergfxd` directly calls `systemctl start nvidia-powerd.service` during GPU mode switches — `disable` alone does not prevent this. The mask (symlink to `/dev/null`) blocks both `supergfxd` and NVIDIA driver updates from re-enabling it. GPU power is managed via ATPX (via ACPI). See [NVIDIA Driver Installation Guide]({{< relref "/docs/nvidia-driver-installation" >}}) for diagnosis details and commands.
+> **Important:** `nvidia-powerd.service` must remain disabled and **masked** on this laptop. It conflicts with AMD ATPX power management and causes soft lockups and reboot hangs (black screen, backlights stay on). Masking is essential because `supergfxd` directly calls `systemctl start nvidia-powerd.service` during GPU mode switches — `disable` alone does not prevent this. The mask (symlink to `/dev/null`) blocks both `supergfxd` and NVIDIA driver updates from re-enabling it. GPU power is managed via ATPX (via ACPI). See [NVIDIA Driver Installation Guide]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) for diagnosis details and commands.
{{% /details %}}
@@ -331,7 +275,7 @@ sudo journalctl -b -u supergfxd
ROG Control Center shows a warning that the `asus-armoury` kernel driver is not loaded. Some advanced features (PPT power limits, APU memory allocation, MUX switch control) are unavailable.
**Cause:**
-The `asus-armoury` driver was merged into the Linux mainline kernel in version 6.19. On kernel 6.18.x (current Fedora 43 default), the driver does not exist.
+The `asus-armoury` driver was merged into the Linux mainline kernel in version 6.19. CachyOS ships kernel 6.19.3-2 which includes this driver, so it should be available.
**What still works without the driver:**
- Fan curves (basic)
@@ -342,9 +286,7 @@ The `asus-armoury` driver was merged into the Linux mainline kernel in version 6
- GPU switching via supergfxctl
**Solution:**
-Wait for Fedora 43 to ship kernel 6.19 via `dnf update`. No manual action required.
-
-After the kernel update, verify the driver loaded:
+Verify the driver is loaded:
```bash
lsmod | grep asus_armoury
```
@@ -380,5 +322,5 @@ If it loads, reopen ROG Control Center — the warning should be gone and advanc
- [asus-linux.org](https://asus-linux.org/) — Official project site
- [asusctl GitLab](https://gitlab.com/asus-linux/asusctl) — Source code and issue tracker
-- [lukenukem COPR](https://copr.fedorainfracloud.org/coprs/lukenukem/asus-linux/) — Fedora package repository
-- [NVIDIA Driver Installation Guide]({{< relref "/docs/nvidia-driver-installation" >}}) — NVIDIA driver setup and known issues
+- [CachyOS Wiki: ASUS](https://wiki.cachyos.org/) — CachyOS-specific documentation
+- [NVIDIA Driver Installation Guide]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) — NVIDIA driver setup and known issues
diff --git a/content/docs/asusctl-rog-control.nl.md b/content/docs/hardware/asusctl-rog-control.nl.md
similarity index 69%
rename from content/docs/asusctl-rog-control.nl.md
rename to content/docs/hardware/asusctl-rog-control.nl.md
index f72894e..ccd8d91 100644
--- a/content/docs/asusctl-rog-control.nl.md
+++ b/content/docs/hardware/asusctl-rog-control.nl.md
@@ -3,79 +3,23 @@ title: "asusctl & ROG Control Center"
weight: 22
---
-De Zephyrus G16 heeft veel hardware-functies die op Linux niet zomaar werken — fan curves, performance-profielen, de Slash LED op het deksel, GPU-switching, batterijlaadlimiet. Op deze pagina staat hoe ik dat allemaal werkend heb gekregen met asusctl en de tools van het ASUS Linux-project. De Fedora-specifieke onderdelen staan niet in hun eigen documentatie, dus ik heb ze hier opgeschreven.
+De Zephyrus G16 heeft veel hardware-functies die op Linux niet zomaar werken — fan curves, performance-profielen, de Slash LED op het deksel, GPU-switching, batterijlaadlimiet. Op deze pagina staat hoe ik dat allemaal werkend heb gekregen met asusctl en de tools van het ASUS Linux-project. Op CachyOS zijn deze tools direct beschikbaar vanuit de package repos.
**Package informatie:**
- `asusctl` 6.3.2 — CLI voor fan curves, profielen, batterijlimiet, RGB, Slash LED
- `asusctl-rog-gui` 6.3.2 — ROG Control Center GUI
- `supergfxctl` 5.2.7 — GPU mode switching
-- Bron: [lukenukem COPR](https://copr.fedorainfracloud.org/coprs/lukenukem/asus-linux/) (beheerd door Luke Jones, primaire asusctl developer)
-
-
-## Vereisten
-
-{{% details title="Waarom lukenukem COPR en geen reguliere repo" closed="true" %}}
-
-COPR is Fedora's officiële community-package-hostingplatform (vergelijkbaar met AUR voor Arch). De `lukenukem` COPR wordt beheerd door Luke Jones (flukejones), de primaire developer van asusctl zelf — geen willekeurige derde partij.
-
-De packages zijn GPG-gesigned (`gpgcheck=1`) en dit is de officieel aanbevolen installatiemethode door het asus-linux project.
-
-**Let op:** Als je zoekt naar "lukenukem COPR" op Reddit, vind je mogelijk threads met zorgen. Deze gaan doorgaans over de openSUSE repository die tijdelijk offline was — geen beveiligingsprobleem met de COPR zelf.
-
-{{% /details %}}
-
-{{% details title="Compatibiliteit met tuned (power-profiles-daemon conflict) — Fedora-specifiek" closed="true" %}}
-
-`asusctl` vereist de `power-profiles-daemon` D-Bus API om performance profielen te beheren (Silent/Balanced/Performance). Op Arch Linux installeer je simpelweg `power-profiles-daemon` en het werkt. Op Fedora conflicteert dit echter met `tuned`, dat [sinds Fedora 41 de standaard power management daemon is](https://fedoraproject.org/wiki/Changes/TunedAsTheDefaultPowerProfileManagementDaemon).
-
-De oplossing is `tuned-ppd`, een door Fedora aangeboden compatibiliteitslaag die de `power-profiles-daemon` D-Bus interface beschikbaar stelt terwijl het intern `tuned` gebruikt. Hiermee kan `asusctl` profielen beheren zonder `tuned` te verwijderen.
-
-**Let op:** Het asus-linux project documenteert dit niet omdat het een Fedora-specifiek probleem is. Hun [FAQ](https://asus-linux.org/faq/) en [ArchWiki-pagina](https://wiki.archlinux.org/title/Asusctl) vermelden alleen dat `power-profiles-daemon` moet draaien.
-
-Als je `tuned` hebt geïnstalleerd (Fedora standaard), moet je overstappen naar `tuned-ppd` vóór de installatie van asusctl, anders werkt profielwisseling niet.
-
-**Referenties:**
-- [Fedora Wiki: Tuned as Default Power Profile Daemon (F41)](https://fedoraproject.org/wiki/Changes/TunedAsTheDefaultPowerProfileManagementDaemon)
-- [Phoronix: Fedora 41 Goes Tuned PPD](https://www.phoronix.com/news/Fedora-41-Goes-Tuned-PPD)
-- [asus-linux FAQ](https://asus-linux.org/faq/)
-- [asusctl ArchWiki](https://wiki.archlinux.org/title/Asusctl)
-
-{{% /details %}}
+- Bron: CachyOS/Arch repos (packages beheerd door Luke Jones, primaire asusctl developer)
## Installatie
{{% steps %}}
-### lukenukem COPR repository toevoegen
-
-```bash
-sudo dnf copr enable lukenukem/asus-linux
-```
-
-### Van tuned naar tuned-ppd overstappen (Fedora-specifiek)
-
-`asusctl` heeft de `power-profiles-daemon` D-Bus API nodig. Op Fedora 41+ is `tuned` de standaard en conflicteert met `power-profiles-daemon`. Installeer `tuned-ppd` als compatibiliteitslaag:
-
-```bash
-sudo dnf install tuned-ppd
-sudo systemctl disable tuned.service
-sudo systemctl enable --now tuned-ppd.service
-```
-
-`tuned-ppd` stelt de `power-profiles-daemon` D-Bus interface beschikbaar terwijl het intern `tuned`-profielen gebruikt. `asusctl` communiceert met `tuned-ppd` alsof het `power-profiles-daemon` is — geen aanpassingen nodig.
-
-**Verifieer:**
-```bash
-systemctl status tuned-ppd
-```
-
-**Let op:** Op Arch Linux installeer je `power-profiles-daemon` direct. Deze stap is alleen nodig op Fedora.
-
### asusctl, ROG Control Center en supergfxctl installeren
```bash
-sudo dnf install asusctl asusctl-rog-gui supergfxctl
+sudo pacman -S asusctl supergfxctl power-profiles-daemon rog-control-center
```
Dit installeert:
@@ -114,7 +58,7 @@ Board name: GA605WV
Handige tools voor hardware monitoring naast asusctl:
```bash
-sudo dnf install nvtop powertop s-tui lm_sensors i2c-tools
+sudo pacman -S nvtop powertop s-tui lm_sensors i2c-tools
```
| Package | Beschrijving |
@@ -211,7 +155,7 @@ asusctl profile --next
asusctl profile
```
-> **Let op:** Profielwisseling vereist dat `tuned-ppd` actief is. Zie de installatiestappen hierboven.
+> **Let op:** Profielwisseling vereist dat `power-profiles-daemon` actief is. Zie de installatiestappen hierboven.
{{% /details %}}
@@ -240,7 +184,7 @@ supergfxctl --mode Integrated
> **Let op:** Wisselen tussen Hybrid en Integrated vereist uitloggen/inloggen. Overstappen naar AsusMuxDgpu vereist een herstart.
-> **Belangrijk:** `nvidia-powerd.service` moet uitgeschakeld en **gemaskt** blijven op deze laptop. Het conflicteert met AMD ATPX power management en veroorzaakt soft lockups en reboot hangs (zwart scherm, backlights blijven aan). Masken is essentieel omdat `supergfxd` direct `systemctl start nvidia-powerd.service` aanroept tijdens GPU mode switches — `disable` alleen voorkomt dit niet. De mask (symlink naar `/dev/null`) blokkeert zowel `supergfxd` als NVIDIA driver updates. GPU-vermogensbeheer loopt via ATPX (via ACPI). Zie de [NVIDIA Driver Installatie Guide]({{< relref "/docs/nvidia-driver-installation" >}}) voor diagnosedetails en commando's.
+> **Belangrijk:** `nvidia-powerd.service` moet uitgeschakeld en **gemaskt** blijven op deze laptop. Het conflicteert met AMD ATPX power management en veroorzaakt soft lockups en reboot hangs (zwart scherm, backlights blijven aan). Masken is essentieel omdat `supergfxd` direct `systemctl start nvidia-powerd.service` aanroept tijdens GPU mode switches — `disable` alleen voorkomt dit niet. De mask (symlink naar `/dev/null`) blokkeert zowel `supergfxd` als NVIDIA driver updates. GPU-vermogensbeheer loopt via ATPX (via ACPI). Zie de [NVIDIA Driver Installatie Guide]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) voor diagnosedetails en commando's.
{{% /details %}}
@@ -331,7 +275,7 @@ sudo journalctl -b -u supergfxd
ROG Control Center toont een melding dat de `asus-armoury` kernel driver niet geladen is. Geavanceerde functies (PPT vermogensgrenzen, APU geheugenallocatie, MUX switch besturing) zijn niet beschikbaar.
**Oorzaak:**
-De `asus-armoury` driver is samengevoegd in de Linux mainline kernel in versie 6.19. Op kernel 6.18.x (huidige Fedora 43 standaard) bestaat de driver niet.
+De `asus-armoury` driver is samengevoegd in de Linux mainline kernel in versie 6.19. CachyOS levert kernel 6.19.3-2 inclusief deze driver, dus hij zou beschikbaar moeten zijn.
**Wat nog wel werkt zonder de driver:**
- Fan curves (basis)
@@ -342,9 +286,7 @@ De `asus-armoury` driver is samengevoegd in de Linux mainline kernel in versie 6
- GPU switching via supergfxctl
**Oplossing:**
-Wacht tot Fedora 43 kernel 6.19 uitbrengt via `dnf update`. Geen handmatige actie vereist.
-
-Na de kernel update, verifieer dat de driver geladen is:
+Verifieer dat de driver geladen is:
```bash
lsmod | grep asus_armoury
```
@@ -380,5 +322,5 @@ Als hij laadt, heropen ROG Control Center — de melding zou verdwenen moeten zi
- [asus-linux.org](https://asus-linux.org/) — Officiële projectsite
- [asusctl GitLab](https://gitlab.com/asus-linux/asusctl) — Broncode en issue tracker
-- [lukenukem COPR](https://copr.fedorainfracloud.org/coprs/lukenukem/asus-linux/) — Fedora package repository
-- [NVIDIA Driver Installatie Guide]({{< relref "/docs/nvidia-driver-installation" >}}) — NVIDIA driver setup en bekende problemen
+- [CachyOS Wiki: ASUS](https://wiki.cachyos.org/) — CachyOS-specifieke documentatie
+- [NVIDIA Driver Installatie Guide]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) — NVIDIA driver setup en bekende problemen
diff --git a/content/docs/nvidia-driver-installation.md b/content/docs/hardware/nvidia-driver-installation.md
similarity index 61%
rename from content/docs/nvidia-driver-installation.md
rename to content/docs/hardware/nvidia-driver-installation.md
index 88aa0da..1ed0807 100644
--- a/content/docs/nvidia-driver-installation.md
+++ b/content/docs/hardware/nvidia-driver-installation.md
@@ -3,21 +3,43 @@ title: "NVIDIA Driver Installation"
weight: 11
---
-The G16 has an NVIDIA RTX 4060 alongside the AMD iGPU. The open-source Nouveau driver doesn't perform well on modern NVIDIA hardware, so proprietary drivers are necessary. Getting them working on Fedora with Secure Boot enabled takes a few steps — this is what worked for me. I also ran into several crashes and lockups after installation that took some time to track down, so I've documented those too.
+The G16 has an NVIDIA RTX 4060 alongside the AMD iGPU. The open-source Nouveau driver doesn't perform well on modern NVIDIA hardware, so proprietary drivers are necessary.
**Driver I'm running:**
-- Version: 580.119.02
-- Source: RPM Fusion
-- Installation Method: akmod (automatic kernel module rebuilding)
+- Version: 590.48.01
+- CUDA Version: 13.1
+- Source: CachyOS/Arch repos
+- Installation Method: nvidia-dkms (DKMS-based automatic kernel module rebuilding)
+## CachyOS (Arch)
+
+CachyOS ships with NVIDIA drivers pre-installed as part of the installer. If you selected the NVIDIA option during setup, no manual driver installation is needed — the driver is already active and fully configured.
+
+See [Post-Installation Verification](#post-installation-verification) to confirm everything is working correctly.
+
+
+## Fedora
+
+The following covers the full manual installation process. I ran into several crashes and lockups during setup that took some time to track down — those are documented in the [Known Issues](#known-issues) section.
+
## Prerequisites
+### Enable RPM Fusion
+
+RPM Fusion provides the NVIDIA drivers for Fedora. Enable both repositories before installing:
+
+```bash
+sudo dnf install \
+ https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm \
+ https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm
+```
+
### System Verification
{{% details title="Check kernel version" closed="true" %}}
-Required: Kernel 6.18+ for Ryzen AI 9 HX 370 support.
+Required: Kernel 6.19+ for Ryzen AI 9 HX 370 support.
```bash
uname -r
@@ -45,27 +67,10 @@ The open-source Nouveau driver has poor performance on modern NVIDIA GPUs. The p
{{% steps %}}
-### Resolve repository issues
-
-If encountering checksum errors during `dnf update`, clean the cache:
-
-```bash
-sudo dnf clean all
-sudo dnf makecache
-```
-
-### Add RPM Fusion repositories
-
-RPM Fusion provides NVIDIA drivers for Fedora. NVIDIA's official CUDA repository does not yet support Fedora 43.
-
-```bash
-sudo dnf install https://download1.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm https://download1.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm -y
-```
-
### Update system
```bash
-sudo dnf update -y
+sudo dnf upgrade
```
Wait for update completion.
@@ -78,30 +83,26 @@ Check available NVIDIA driver version:
dnf info akmod-nvidia
```
-Confirm the version matches the current release for Fedora 43.
-
### Install NVIDIA driver
Install driver with CUDA support:
```bash
-sudo dnf install akmod-nvidia xorg-x11-drv-nvidia-cuda -y
+sudo dnf install akmod-nvidia xorg-x11-drv-nvidia-cuda xorg-x11-drv-nvidia-libs.i686
```
This installs the driver, CUDA libraries, and build dependencies (about 1 GB).
-- `akmod-nvidia` - Automatic kernel module builder
-- `xorg-x11-drv-nvidia` - NVIDIA driver (supports both X11 and Wayland)
-- `xorg-x11-drv-nvidia-cuda` - CUDA libraries
-- Build dependencies (gcc, kernel-devel, etc.)
-
-Note: A MOK password prompt may not appear during installation. This is normal.
+- `akmod-nvidia` - NVIDIA driver using akmods for automatic kernel module building and signing
+- `xorg-x11-drv-nvidia-cuda` - CUDA support and driver utilities (includes Wayland support)
+- `xorg-x11-drv-nvidia-libs.i686` - 32-bit NVIDIA libraries (needed for Steam/Proton)
### Build kernel modules
-Force akmod to build NVIDIA kernel modules:
+akmods automatically builds and signs kernel modules on installation. To manually trigger a rebuild:
```bash
sudo akmods --force
+sudo dracut --force
```
This process may take 5-10 minutes.
@@ -111,23 +112,21 @@ This process may take 5-10 minutes.
Check that kernel modules were built:
```bash
-ls /lib/modules/$(uname -r)/extra/nvidia/
+ls /lib/modules/$(uname -r)/kernel/drivers/video/
```
-All five kernel modules should be present.
+The NVIDIA modules should be present.
-### First reboot and check GNOME Software
+### Enroll MOK signing key
+
+If Secure Boot is enabled, import the akmods signing key and set a password for the enrollment prompt:
```bash
-sudo reboot
+sudo mokutil --import /etc/pki/akmods/certs/public_key.der
```
-After reboot, open GNOME Software and note the MOK enrollment code. The driver is not yet active.
-
### MOK enrollment on next boot
-Reboot again:
-
```bash
sudo reboot
```
@@ -136,26 +135,18 @@ During boot, the MOK Management screen (blue screen) will appear:
1. Select "Enroll MOK"
2. Select "Continue"
3. Select "Yes"
-4. Enter the MOK enrollment code from GNOME Software
+4. Enter the password you set in the previous step
5. Reboot
The system will boot normally after MOK enrollment.
-### Rebuild modules after MOK enrollment
-
-After MOK enrollment, rebuild the kernel modules. They will now be signed with the enrolled key.
-
-```bash
-sudo akmods --force --rebuild
-```
-
### Final reboot
```bash
sudo reboot
```
-The NVIDIA driver will now load correctly. GNOME Software should show the driver as installed (not pending).
+The NVIDIA driver will now load correctly.
### Enable NVIDIA power management services
@@ -196,7 +187,7 @@ sudo systemctl enable --now nvidia-powerd.service
```
**Reference:**
-- [NVIDIA Power Management Documentation](https://download.nvidia.com/XFree86/Linux-x86_64/580.119.02/README/powermanagement.html)
+- [NVIDIA Power Management Documentation](https://download.nvidia.com/XFree86/Linux-x86_64/590.48.01/README/powermanagement.html)
{{% /steps %}}
@@ -215,14 +206,6 @@ nvidia-smi
You should see the NVIDIA driver and CUDA versions listed.
-### Verify Wayland session
-
-Confirm running Wayland (not X11):
-
-```bash
-echo $XDG_SESSION_TYPE
-```
-
### Check loaded kernel modules
```bash
@@ -231,150 +214,110 @@ lsmod | grep nvidia
The NVIDIA modules are loaded and the driver is functional.
-### Verify in GNOME Software
+{{% /steps %}}
-Open GNOME Software (white bag icon):
-- Navigate to "Installed"
-- Search for "NVIDIA Linux Graphics Driver"
-- Status should show "Installed" (not "Pending")
-- "Uninstall" button is visible
-This confirms the system recognizes the driver as properly installed.
-{{% /steps %}}
+## ICC Color Profiles
+
+{{% details title="Install ASUS GameVisual color profiles for GA605WV built-in display" closed="true" %}}
-## Performance Optimizations
+The GA605WV ships with a 16" 2560x1600 240Hz ROG Nebula Display. ASUS factory-calibrates each panel and provides color profiles via their ASUS System Control Interface. On Windows, these are automatically applied by Armoury Crate/GameVisual. On Linux, we must install them manually.
-{{% details title="Kernel parameters for improved performance and stability" closed="true" %}}
+The GA605WV was shipped with different panels depending on the unit. The standard model uses an IPS panel (ROG Nebula Display); some configurations ship with an OLED panel instead:
-Adding certain kernel parameters can improve NVIDIA driver performance, especially for Wayland sessions and dual-GPU setups.
+| Panel ID | Manufacturer | Model | Type |
+|---|---|---|---|
+| `104D158E` | Sharp | LQ160R1JW02 | IPS (ROG Nebula Display) |
+| `834C41AE` | Samsung | ATNA60DL04-0 ([LaptopMedia](https://laptopmedia.com/screen/atna60dl04-0-sdc41ae/) · [Linux Hardware](https://linux-hardware.org/?id=eisa:samsung-sdc41ae)) | OLED |
+| `E5090C19` | Unknown | — (present in ASUS driver package, not yet publicly identified) | Unknown |
-**Step 1: Add recommended kernel parameters**
+To check which panel your unit has:
```bash
-sudo grubby --update-kernel=ALL --args="rd.driver.blacklist=nouveau modprobe.blacklist=nouveau nvidia-drm.modeset=1 nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1"
+cat /sys/class/drm/card*-eDP-*/edid | edid-decode 2>/dev/null | grep -i "manufacturer\|model\|product name"
```
-**Step 2: Verify parameters were added**
+These color profiles were obtained by reverse engineering the ASUS Windows driver package. By analyzing the ASUS CDN structure and the contents of the driver ZIP files, all factory-calibrated profiles for this laptop were recovered. The ICC metadata was then modified so the profiles appear with readable names directly in GNOME Color Management.
-```bash
-sudo grubby --info=ALL | grep args
-```
+**Install the color profiles:**
-Expected output should include the added kernel parameters.
+The ICC color profiles are located in the [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) directory of this repository. Clone the repository or manually download the profiles and copy them to either location:
-**Step 3: Reboot to apply changes**
+| Location | Scope |
+|---|---|
+| `/usr/share/color/icc/colord/` | System-wide (all users, requires root) |
+| `~/.local/share/icc/` | Current user only |
```bash
-sudo reboot
-```
+# System-wide install:
+sudo cp GA605WV_1002_104D158E_CMDEF.icm /usr/share/color/icc/colord/
-**What these parameters do:**
-
-- `rd.driver.blacklist=nouveau` - Prevents the open-source Nouveau driver from loading during early boot (initramfs)
-- `modprobe.blacklist=nouveau` - Prevents Nouveau from loading after boot
-- `nvidia-drm.modeset=1` - Enables NVIDIA kernel mode setting for better Wayland support and performance
-- `nvidia-drm.fbdev=1` - Makes NVIDIA use its framebuffer via the kernel DRM framework instead of a generic framebuffer. Improves handoff between console and Wayland/GNOME and prevents race conditions during suspend/resume on hybrid GPU laptops
-- `nvidia.NVreg_PreserveVideoMemoryAllocations=1` - Preserves VRAM allocations during suspend/resume instead of releasing and rebuilding them. Prevents corrupted VRAM after resume, which can cause soft lockups
+# Or per-user install:
+mkdir -p ~/.local/share/icc
+cp GA605WV_1002_104D158E_CMDEF.icm ~/.local/share/icc/
+```
-**Why blacklist Nouveau:**
-- The proprietary NVIDIA driver and Nouveau cannot coexist
-- Blacklisting prevents conflicts and ensures the proprietary driver is always used
-- If the NVIDIA driver fails, you can remove these parameters from GRUB to fall back to Nouveau
+**Activate your profile in GNOME:**
-**Benefits:**
-- Better Wayland performance and stability
-- Prevents driver conflicts during boot
-- Improved external monitor support
-- More stable suspend/resume cycles on hybrid GPU setups
-- Smoother graphics performance in general
+1. Open **Settings** → **Color Management**
+2. Select your display (e.g. **Built-In Screen**)
+3. Click **Add Profile**
+4. Select the profile matching your display and GPU combination (e.g. **Native** for AMD iGPU + Sharp LQ160R1JW02)
+5. Click **Add**
-**Note:** These parameters are optional but recommended for optimal performance.
+**Note:** If GNOME Settings shows old technical names (e.g., "ASUS GA605WV 1002 104D158E CMDEF" instead of "Native"), close Settings and reopen, or log out/in to refresh the color cache.
-**Re-enable graphical boot splash:**
+The filename encodes your GPU (`1002` = AMD, `10DE` = NVIDIA) and panel ID — match these to your unit using the panel table above. All profiles are in the [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) directory.
-Fedora uses `rhgb` (Red Hat Graphical Boot) and `quiet` to show a Plymouth splash screen during boot instead of scrolling kernel text. If you removed these while debugging NVIDIA or boot issues, re-add them:
+**Background:**
-```bash
-sudo grubby --update-kernel=ALL --args="rhgb quiet"
+The profiles were found through analysis of ASUS Windows driver packages. The ASUS CDN URL structure:
+```
+https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/{id}-{code}-{hash}.zip
```
-The default Plymouth theme (`bgrt`) shows the ASUS/BIOS manufacturer logo. To debug boot issues in the future, you can temporarily remove them:
+For the GA605WV, this is: `20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip`
-```bash
-sudo grubby --update-kernel=ALL --remove-args="rhgb quiet"
-```
+**Technical Details:**
-**References:**
-- [NVIDIA Driver Modesetting - Arch Wiki](https://wiki.archlinux.org/title/NVIDIA)
-- [Understanding nvidia-drm.modeset=1 - NVIDIA Developer Forums](https://forums.developer.nvidia.com/t/understanding-nvidia-drm-modeset-1-nvidia-linux-driver-modesetting/204068)
-- [NVIDIA Power Management Documentation](https://download.nvidia.com/XFree86/Linux-x86_64/580.119.02/README/powermanagement.html)
+The profiles in this repository are pre-processed with custom ICC metadata 'desc' tags so they appear with readable names directly in GNOME Color Management. For users interested in how such modifications work, you can implement similar ICC 'desc' tag manipulation yourself using Python's PIL/ImageCms.
{{% /details %}}
+{{% details title="Install Samsung color profile for LS27B800TGUXEN (S80TB) Thunderbolt display" closed="true" %}}
-## ICC Color Profiles
-
-{{% details title="Install ASUS GameVisual color profiles for Sharp LQ160R1JW02 panel" closed="true" %}}
+The Samsung ViewFinity S8 Thunderbolt (LS27B800TGUXEN) ships with a factory color profile (`SxxB80xT.icm`) included in the Windows INF driver package. On Linux this profile must be installed manually.
-The GA605WV ships with a Sharp LQ160R1JW02 16" 2560x1600 240Hz display. ASUS factory-calibrates each panel and provides color profiles via their ASUS System Control Interface. On Windows, these are automatically applied by Armoury Crate/GameVisual. On Linux, we must install them manually.
+The profile is located in the [`/icc-profiles/LS27B800TGUXEN - S80TB/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles/LS27B800TGUXEN%20-%20S80TB) directory of this repository.
-These color profiles were obtained through a combination of reverse engineering and dissecting ASUS Windows driver packages. By analyzing the ASUS CDN structure and the contents of the driver ZIP files, all factory-calibrated color profiles for this specific panel were recovered. The ICC metadata was then modified so the profiles appear with readable names directly in GNOME Color Management.
+**Install the color profile:**
-**Install the color profiles:**
+Linux stores ICC profiles in one of two locations depending on scope:
-The ICC color profiles are located in the [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) directory of this repository. Clone the repository or manually download the profiles and copy them to `~/.local/share/icc`:
+| Location | Scope |
+|---|---|
+| `/usr/share/color/icc/colord/` | System-wide (all users, requires root) |
+| `~/.local/share/icc/` | Current user only |
```bash
-mkdir -p ~/.local/share/icc
-
-# If you've already cloned the repository:
-cp /icc-profiles/*.icm ~/.local/share/icc/
+# System-wide install (recommended):
+sudo cp SxxB80xT.icm /usr/share/color/icc/colord/
-# Or download the specific profiles you need from the repository
+# Or per-user install:
+mkdir -p ~/.local/share/icc
+cp SxxB80xT.icm ~/.local/share/icc/
```
-**Activate Native profile in GNOME:**
+**Activate in GNOME:**
1. Open **Settings** → **Color Management**
-2. Select **Built-In Screen**
+2. Select the **Samsung display** (e.g. "LS27B800TGUXEN")
3. Click **Add Profile**
-4. Select **Native**
+4. Select `SxxB80xT`
5. Click **Add**
-**Note:** If GNOME Settings shows old technical names (e.g., "ASUS GA605WV 1002 104D158E CMDEF" instead of "Native"), close Settings and reopen, or log out/in to refresh the color cache.
-
-**Available color profiles:**
-
-| GNOME Name | File | Description |
-|---|---|---|
-| **Native** | `GA605WV_1002_104D158E_CMDEF.icm` | **Recommended** - Factory-calibrated for Sharp LQ160R1JW02 panel, best color accuracy |
-| DCI-P3 | `ASUS_DCIP3.icm` | Saturated DCI-P3 colors for gaming/media (Vivid mode) |
-| Display P3 | `ASUS_DisplayP3.icm` | Display P3 colorspace for Apple-compatible workflows |
-| sRGB | `ASUS_sRGB.icm` | sRGB standard for web/photo work |
-
-**Recommendation:**
-
-Use **Native** for best color accuracy. This profile contains factory calibration specific to the Sharp LQ160R1JW02 panel in this laptop. The other profiles (DCI-P3, Display P3, sRGB) are generic colorspaces without panel-specific corrections.
-
-**Note:** The `_1002_` in the filename refers to the AMD iGPU (Vendor ID 0x1002), which drives the internal eDP display on this hybrid GPU laptop.
-
-**Background:**
-
-The profiles were found through analysis of ASUS Windows driver packages. The ASUS CDN URL structure:
-```
-https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/{id}-{code}-{hash}.zip
-```
-
-For the GA605WV, this is: `20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip`
-
-The profiles contain factory color corrections specific to the Sharp LQ160R1JW02 panel (Panel ID: 104D158E) used in this laptop model.
-
-**Technical Details:**
-
-The profiles in this repository are pre-processed with custom ICC metadata 'desc' tags so they appear with readable names directly in GNOME Color Management. For users interested in how such modifications work, you can implement similar ICC 'desc' tag manipulation yourself using Python's PIL/ImageCms.
-
{{% /details %}}
@@ -394,15 +337,11 @@ amdgpu 0000:66:00.0: amdgpu: GPU reset begin!
This laptop has dual GPUs (AMD Radeon 890M integrated + NVIDIA RTX 4060 discrete). The AMD GPU's PSR (Panel Self Refresh) feature has a bug causing crashes with external Thunderbolt monitors.
**Solution:**
-Disable AMD PSR by adding a kernel parameter:
+Disable AMD PSR by adding a kernel parameter. Edit `/etc/default/grub` and add `amdgpu.dcdebugmask=0x600` to `GRUB_CMDLINE_LINUX_DEFAULT`, then regenerate:
```bash
-sudo grubby --update-kernel=ALL --args="amdgpu.dcdebugmask=0x600"
-```
-
-Verify it was added:
-```bash
-sudo grubby --info=ALL | grep args
+sudo nano /etc/default/grub
+sudo grub2-mkconfig -o /boot/efi/EFI/fedora/grub.cfg
```
Reboot:
@@ -548,9 +487,9 @@ sudo systemctl stop nvidia-powerd.service
sudo systemctl mask nvidia-powerd.service
```
-2. Add kernel parameters for more stable NVIDIA power management:
-```bash
-sudo grubby --update-kernel=ALL --args="nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1"
+2. Add kernel parameters for more stable NVIDIA power management (edit `/etc/default/grub` and add to `GRUB_CMDLINE_LINUX_DEFAULT`, then `sudo grub-mkconfig -o /boot/grub/grub.cfg`):
+```
+nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1
```
3. Reboot:
@@ -583,7 +522,8 @@ sudo journalctl -b | grep nvidia
Rebuild kernel modules:
```bash
-sudo akmods --force --rebuild
+sudo akmods --force
+sudo dracut --force
sudo reboot
```
@@ -596,7 +536,8 @@ If you receive the error `modprobe: ERROR: could not insert 'nvidia': Key was re
Solution:
```bash
# Rebuild modules after MOK enrollment
-sudo akmods --force --rebuild
+sudo akmods --force
+sudo dracut --force
# Reboot
sudo reboot
@@ -611,37 +552,18 @@ Reboot and attempt enrollment again.
{{% /details %}}
-{{% details title="Running X11 instead of Wayland" closed="true" %}}
-
-Check session type:
-```bash
-echo $XDG_SESSION_TYPE
-```
-
-If output is `x11`, ensure Wayland is enabled in GDM:
-```bash
-sudo nano /etc/gdm/custom.conf
-```
-
-Verify this line is present and not commented:
-```
-WaylandEnable=true
-```
-
-Reboot after changes.
-
-{{% /details %}}
{{% details title="Kernel module build failures" closed="true" %}}
Ensure kernel headers match running kernel:
```bash
-sudo dnf install kernel-devel-$(uname -r)
+sudo dnf install kernel-devel
```
Force rebuild:
```bash
sudo akmods --force
+sudo dracut --force
```
{{% /details %}}
@@ -650,18 +572,16 @@ sudo akmods --force
## Technical Notes
### Package Naming
-The package `xorg-x11-drv-nvidia` is a legacy name. The driver supports both X11 and Wayland. Fedora 43 defaults to Wayland with GNOME.
+The `akmod-nvidia` package is the recommended NVIDIA driver for Fedora. It uses the akmods framework to rebuild kernel modules automatically after kernel updates.
### Secure Boot
-Akmod handles Secure Boot module signing automatically. The akmods systemd service rebuilds kernel modules automatically after kernel updates.
-
-### GNOME Software
-GNOME Software may show "NVIDIA Linux Graphics Driver" with "Pending install" status. This is a GUI synchronization issue and can be ignored. The driver is properly installed via DNF.
+akmods rebuilds and re-signs kernel modules automatically after kernel updates. On Fedora, `sbctl` can also be used to manage Secure Boot keys.
## Additional Resources
-- [RPM Fusion NVIDIA Driver Guide](https://www.if-not-true-then-false.com/2015/fedora-nvidia-guide/)
+- [CachyOS Wiki: NVIDIA](https://wiki.cachyos.org/configuration/nvidia/)
+- [Arch Wiki: NVIDIA](https://wiki.archlinux.org/title/NVIDIA)
- [Ryzen AI 9 HX 370 Linux Support](https://forums.linuxmint.com/viewtopic.php?t=429052)
- [NVIDIA vs Nouveau Performance](https://machaddr.substack.com/p/nouveau-vs-nvidia-the-battle-between)
- [Zephyrus G16 2024 Linux Guide](https://www.ehmiiz.se/blog/linux_asus_g16_2024/)
diff --git a/content/docs/nvidia-driver-installation.nl.md b/content/docs/hardware/nvidia-driver-installation.nl.md
similarity index 61%
rename from content/docs/nvidia-driver-installation.nl.md
rename to content/docs/hardware/nvidia-driver-installation.nl.md
index 373660d..cc796e0 100644
--- a/content/docs/nvidia-driver-installation.nl.md
+++ b/content/docs/hardware/nvidia-driver-installation.nl.md
@@ -3,21 +3,43 @@ title: "NVIDIA Driver Installatie"
weight: 11
---
-De G16 heeft een NVIDIA RTX 4060 naast de AMD iGPU. De open-source Nouveau driver werkt niet goed op moderne NVIDIA-hardware, dus proprietary drivers zijn nodig. Ze werkend krijgen op Fedora met Secure Boot ingeschakeld kost een paar stappen — dit is wat bij mij werkte. Ik liep ook tegen meerdere crashes en lockups aan na de installatie die wat tijd kostten om op te sporen, dus die heb ik ook gedocumenteerd.
+De G16 heeft een NVIDIA RTX 4060 naast de AMD iGPU. De open-source Nouveau driver werkt niet goed op moderne NVIDIA-hardware, dus proprietary drivers zijn nodig.
**Driver die ik gebruik:**
-- Versie: 580.119.02
-- Bron: RPM Fusion
-- Installatiemethode: akmod (automatisch kernel module rebuilding)
+- Versie: 590.48.01
+- CUDA-versie: 13.1
+- Bron: CachyOS/Arch repos
+- Installatiemethode: nvidia-dkms (DKMS-gebaseerd automatisch kernel module rebuilding)
+## CachyOS (Arch)
+
+CachyOS levert NVIDIA drivers standaard mee als onderdeel van de installer. Als je tijdens de installatie voor de NVIDIA-optie hebt gekozen, is de driver al aanwezig en volledig geconfigureerd — handmatige installatie is niet nodig.
+
+Ga naar [Verificatie Na Installatie](#verificatie-na-installatie) om te bevestigen dat alles correct werkt.
+
+
+## Fedora
+
+De volgende stappen behandelen het volledige handmatige installatieproces. Ik liep tijdens de installatie tegen meerdere crashes en lockups aan die wat tijd kostten om op te sporen — die staan gedocumenteerd in het onderdeel [Bekende Problemen](#bekende-problemen).
+
## Vereisten
+### RPM Fusion inschakelen
+
+RPM Fusion levert de NVIDIA drivers voor Fedora. Schakel beide repositories in voordat je installeert:
+
+```bash
+sudo dnf install \
+ https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm \
+ https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm
+```
+
### Systeem Verificatie
{{% details title="Check kernel versie" closed="true" %}}
-Vereist: Kernel 6.18+ voor Ryzen AI 9 HX 370 ondersteuning.
+Vereist: Kernel 6.19+ voor Ryzen AI 9 HX 370 ondersteuning.
```bash
uname -r
@@ -45,27 +67,10 @@ De open-source Nouveau driver heeft slechte prestaties op moderne NVIDIA GPU's.
{{% steps %}}
-### Repository problemen oplossen
-
-Bij checksum errors tijdens `dnf update`, clean de cache:
-
-```bash
-sudo dnf clean all
-sudo dnf makecache
-```
-
-### RPM Fusion repositories toevoegen
-
-RPM Fusion biedt NVIDIA drivers voor Fedora. NVIDIA's officiële CUDA repository ondersteunt Fedora 43 nog niet.
-
-```bash
-sudo dnf install https://download1.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm https://download1.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm -y
-```
-
### Systeem updaten
```bash
-sudo dnf update -y
+sudo dnf upgrade
```
Wacht tot update voltooid is.
@@ -78,28 +83,26 @@ Check beschikbare NVIDIA driver versie:
dnf info akmod-nvidia
```
-Controleer dat de versie overeenkomt met de huidige release voor Fedora 43.
-
### NVIDIA driver installeren
Installeer driver met CUDA ondersteuning:
```bash
-sudo dnf install akmod-nvidia xorg-x11-drv-nvidia-cuda -y
+sudo dnf install akmod-nvidia xorg-x11-drv-nvidia-cuda xorg-x11-drv-nvidia-libs.i686
```
Dit installeert de driver, CUDA libraries en build dependencies (ongeveer 1 GB).
-- `akmod-nvidia` - Automatische kernel module builder
-- `xorg-x11-drv-nvidia` - NVIDIA driver (ondersteunt X11 en Wayland)
-- `xorg-x11-drv-nvidia-cuda` - CUDA libraries
-- Build dependencies (gcc, kernel-devel, etc.)
+- `akmod-nvidia` - NVIDIA driver via akmods voor automatisch kernel module bouwen en signeren
+- `xorg-x11-drv-nvidia-cuda` - CUDA ondersteuning en driver utilities (inclusief Wayland ondersteuning)
+- `xorg-x11-drv-nvidia-libs.i686` - 32-bit NVIDIA libraries (nodig voor Steam/Proton)
### Kernel modules bouwen
-Forceer akmod om NVIDIA kernel modules te bouwen:
+akmods bouwt en signeert kernel modules automatisch bij installatie. Om handmatig te triggeren:
```bash
sudo akmods --force
+sudo dracut --force
```
Dit proces kan 5-10 minuten duren.
@@ -109,23 +112,21 @@ Dit proces kan 5-10 minuten duren.
Check dat kernel modules gebouwd zijn:
```bash
-ls /lib/modules/$(uname -r)/extra/nvidia/
+ls /lib/modules/$(uname -r)/kernel/drivers/video/
```
-Alle vijf kernel modules moeten aanwezig zijn.
+De NVIDIA modules moeten aanwezig zijn.
+
+### MOK signing key enrollen
-### Eerste reboot en GNOME Software checken
+Als Secure Boot is ingeschakeld, importeer de akmods signing key en stel een wachtwoord in:
```bash
-sudo reboot
+sudo mokutil --import /etc/pki/akmods/certs/public_key.der
```
-Na reboot, open GNOME Software en noteer de MOK enrollment code. De driver is nog niet actief.
-
### MOK enrollment bij volgende boot
-Reboot opnieuw:
-
```bash
sudo reboot
```
@@ -134,26 +135,18 @@ Tijdens boot verschijnt het MOK Management scherm (blauw scherm):
1. Selecteer "Enroll MOK"
2. Selecteer "Continue"
3. Selecteer "Yes"
-4. Voer de MOK enrollment code in van GNOME Software
+4. Voer het wachtwoord in dat je in de vorige stap hebt ingesteld
5. Reboot
Het systeem boot normaal na MOK enrollment.
-### Modules rebuilden na MOK enrollment
-
-Na MOK enrollment, rebuild de kernel modules. Ze worden nu gesigneerd met de enrolled key.
-
-```bash
-sudo akmods --force --rebuild
-```
-
### Definitieve reboot
```bash
sudo reboot
```
-De NVIDIA driver laadt nu correct. GNOME Software toont de driver als geïnstalleerd (niet pending).
+De NVIDIA driver laadt nu correct.
### NVIDIA power management services activeren
@@ -194,7 +187,7 @@ sudo systemctl enable --now nvidia-powerd.service
```
**Referentie:**
-- [NVIDIA Power Management Documentatie](https://download.nvidia.com/XFree86/Linux-x86_64/580.119.02/README/powermanagement.html)
+- [NVIDIA Power Management Documentatie](https://download.nvidia.com/XFree86/Linux-x86_64/590.48.01/README/powermanagement.html)
{{% /steps %}}
@@ -212,14 +205,6 @@ nvidia-smi
Je ziet de NVIDIA driver- en CUDA-versies in de output.
-### Verifieer Wayland sessie
-
-Bevestig dat Wayland draait (niet X11):
-
-```bash
-echo $XDG_SESSION_TYPE
-```
-
### Check geladen kernel modules
```bash
@@ -228,150 +213,110 @@ lsmod | grep nvidia
De NVIDIA modules zijn geladen en de driver is functioneel.
-### Verifieer in GNOME Software
+{{% /steps %}}
-Open GNOME Software (witte tas icoon):
-- Ga naar "Installed"
-- Zoek "NVIDIA Linux Graphics Driver"
-- Status moet "Installed" zijn (niet "Pending")
-- "Uninstall" knop is zichtbaar
-Dit bevestigt dat het systeem de driver erkent als correct geïnstalleerd.
-{{% /steps %}}
+## ICC Kleurprofielen
-## Performance Optimalisaties
+{{% details title="ASUS GameVisual kleurprofielen installeren voor GA605WV ingebouwd display" closed="true" %}}
-{{% details title="Kernel parameters voor verbeterde performance en stabiliteit" closed="true" %}}
+De GA605WV wordt geleverd met een 16" 2560x1600 240Hz ROG Nebula Display. ASUS kalibreert elk paneel in de fabriek en levert kleurprofielen via hun ASUS System Control Interface. Op Windows worden deze automatisch toegepast door Armoury Crate/GameVisual. Op Linux moeten we deze handmatig installeren.
-Het toevoegen van bepaalde kernel parameters kan de NVIDIA driver performance verbeteren, vooral voor Wayland sessies en dual-GPU setups.
+De GA605WV werd geleverd met verschillende panelen afhankelijk van het exemplaar. Het standaard model gebruikt een IPS-paneel (ROG Nebula Display); sommige configuraties worden geleverd met een OLED-paneel:
-**Stap 1: Voeg aanbevolen kernel parameters toe**
+| Panel ID | Fabrikant | Model | Type |
+|---|---|---|---|
+| `104D158E` | Sharp | LQ160R1JW02 | IPS (ROG Nebula Display) |
+| `834C41AE` | Samsung | ATNA60DL04-0 ([LaptopMedia](https://laptopmedia.com/screen/atna60dl04-0-sdc41ae/) · [Linux Hardware](https://linux-hardware.org/?id=eisa:samsung-sdc41ae)) | OLED |
+| `E5090C19` | Onbekend | — (aanwezig in ASUS driver package, nog niet publiek geïdentificeerd) | Onbekend |
+
+Controleer welk paneel jouw exemplaar heeft:
```bash
-sudo grubby --update-kernel=ALL --args="rd.driver.blacklist=nouveau modprobe.blacklist=nouveau nvidia-drm.modeset=1 nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1"
+cat /sys/class/drm/card*-eDP-*/edid | edid-decode 2>/dev/null | grep -i "manufacturer\|model\|product name"
```
-**Stap 2: Verifieer dat parameters toegevoegd zijn**
+Deze kleurprofielen zijn verkregen door het reverse engineeren van het ASUS Windows driver package. Door de structuur van de ASUS CDN en de inhoud van de driver ZIP-bestanden te analyseren, zijn alle factory-gekalibreerde profielen voor deze laptop gevonden. De ICC metadata is vervolgens aangepast zodat de profielen direct met leesbare namen verschijnen in GNOME Color Management.
-```bash
-sudo grubby --info=ALL | grep args
-```
+**Installeer de kleurprofielen:**
-Verwachte output moet de toegevoegde kernel parameters bevatten.
+De ICC kleurprofielen staan in de [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) map van deze repository. Clone de repository of download de profielen handmatig en kopieer ze naar één van deze locaties:
-**Stap 3: Reboot om wijzigingen toe te passen**
+| Locatie | Bereik |
+|---|---|
+| `/usr/share/color/icc/colord/` | Systeem-breed (alle gebruikers, vereist root) |
+| `~/.local/share/icc/` | Alleen huidige gebruiker |
```bash
-sudo reboot
-```
-
-**Wat deze parameters doen:**
+# Systeem-brede installatie:
+sudo cp GA605WV_1002_104D158E_CMDEF.icm /usr/share/color/icc/colord/
-- `rd.driver.blacklist=nouveau` - Voorkomt dat de open-source Nouveau driver laadt tijdens early boot (initramfs)
-- `modprobe.blacklist=nouveau` - Voorkomt dat Nouveau laadt na boot
-- `nvidia-drm.modeset=1` - Schakelt NVIDIA kernel mode setting in voor betere Wayland ondersteuning en performance
-- `nvidia-drm.fbdev=1` - Laat NVIDIA zijn framebuffer via het kernel DRM framework lopen in plaats van een generiek framebuffer. Verbetert de handoff tussen console en Wayland/GNOME en voorkomt race conditions bij suspend/resume op hybrid GPU laptops
-- `nvidia.NVreg_PreserveVideoMemoryAllocations=1` - Behoudt VRAM-allocaties tijdens suspend/resume in plaats van ze vrij te geven en opnieuw op te bouwen. Voorkomt corrupte VRAM na resume, wat soft lockups kan veroorzaken
+# Of per-gebruiker installatie:
+mkdir -p ~/.local/share/icc
+cp GA605WV_1002_104D158E_CMDEF.icm ~/.local/share/icc/
+```
-**Waarom Nouveau blacklisten:**
-- De proprietary NVIDIA driver en Nouveau kunnen niet samen bestaan
-- Blacklisting voorkomt conflicten en zorgt ervoor dat de proprietary driver altijd gebruikt wordt
-- Als de NVIDIA driver faalt, kun je deze parameters verwijderen uit GRUB om terug te vallen op Nouveau
+**Activeer je profiel in GNOME:**
-**Voordelen:**
-- Betere Wayland performance en stabiliteit
-- Voorkomt driver conflicten tijdens boot
-- Verbeterde externe monitor ondersteuning
-- Stabielere suspend/resume cycli op hybrid GPU setups
-- Soepelere graphics performance in het algemeen
+1. Open **Instellingen** → **Color Management**
+2. Selecteer je display (bijv. **Built-In Screen**)
+3. Klik **Add Profile**
+4. Selecteer het profiel dat overeenkomt met jouw display en GPU-combinatie (bijv. **Native** voor AMD iGPU + Sharp LQ160R1JW02)
+5. Klik **Add**
-**Opmerking:** Deze parameters zijn optioneel maar aanbevolen voor optimale performance.
+**Opmerking:** Als GNOME Settings de oude technische namen toont (bijv. "ASUS GA605WV 1002 104D158E CMDEF" in plaats van "Native"), sluit Settings af en heropen, of log uit/in om de color cache te verversen.
-**Grafische boot splash opnieuw inschakelen:**
+De bestandsnaam bevat je GPU (`1002` = AMD, `10DE` = NVIDIA) en paneel-ID — match deze aan jouw exemplaar via de paneeltabel hierboven. Alle profielen staan in de [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) map.
-Fedora gebruikt `rhgb` (Red Hat Graphical Boot) en `quiet` om een Plymouth splash scherm te tonen tijdens het booten in plaats van scrollende kernel tekst. Als je deze hebt verwijderd tijdens het debuggen van NVIDIA- of boot-problemen, voeg ze opnieuw toe:
+**Achtergrond:**
-```bash
-sudo grubby --update-kernel=ALL --args="rhgb quiet"
+De profielen zijn gevonden door analyse van ASUS Windows driver packages. De ASUS CDN URL structuur:
+```
+https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/{id}-{code}-{hash}.zip
```
-Het standaard Plymouth-thema (`bgrt`) toont het ASUS/BIOS fabrikantlogo. Om in de toekomst boot-problemen te debuggen, kun je ze tijdelijk verwijderen:
+Voor de GA605WV is dit: `20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip`
-```bash
-sudo grubby --update-kernel=ALL --remove-args="rhgb quiet"
-```
+**Technische Details:**
-**Referenties:**
-- [NVIDIA Driver Modesetting - Arch Wiki](https://wiki.archlinux.org/title/NVIDIA)
-- [Understanding nvidia-drm.modeset=1 - NVIDIA Developer Forums](https://forums.developer.nvidia.com/t/understanding-nvidia-drm-modeset-1-nvidia-linux-driver-modesetting/204068)
-- [NVIDIA Power Management Documentatie](https://download.nvidia.com/XFree86/Linux-x86_64/580.119.02/README/powermanagement.html)
+De profielen in deze repository zijn al voorbewerkt met aangepaste ICC metadata 'desc' tags, zodat ze direct met leesbare namen verschijnen in GNOME Color Management. Voor gebruikers die geïnteresseerd zijn in hoe deze modificaties werken, kun je zelf vergelijkbare ICC 'desc' tag manipulatie implementeren met Python's PIL/ImageCms.
{{% /details %}}
+{{% details title="Samsung kleurprofiel installeren voor LS27B800TGUXEN (S80TB) Thunderbolt display" closed="true" %}}
-## ICC Kleurprofielen
-
-{{% details title="ASUS GameVisual kleurprofielen installeren voor Sharp LQ160R1JW02 panel" closed="true" %}}
+De Samsung ViewFinity S8 Thunderbolt (LS27B800TGUXEN) wordt geleverd met een fabriekskleurprofiel (`SxxB80xT.icm`) dat is opgenomen in het Windows INF driver package. Op Linux moet dit profiel handmatig worden geïnstalleerd.
-De GA605WV wordt geleverd met een Sharp LQ160R1JW02 16" 2560x1600 240Hz display. ASUS kalibreert elk paneel in de fabriek en levert kleurprofielen via hun ASUS System Control Interface. Op Windows worden deze automatisch toegepast door Armoury Crate/GameVisual. Op Linux moeten we deze handmatig installeren.
+Het profiel staat in de [`/icc-profiles/LS27B800TGUXEN - S80TB/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles/LS27B800TGUXEN%20-%20S80TB) map van deze repository.
-Deze kleurprofielen zijn verkregen door een combinatie van reverse engineering en het uit elkaar trekken van ASUS Windows driver packages. Door de structuur van de ASUS CDN en de inhoud van de driver ZIP-bestanden te analyseren, zijn alle factory-gekalibreerde kleurprofielen voor dit specifieke paneel gevonden. De ICC metadata is vervolgens aangepast zodat de profielen direct met leesbare namen verschijnen in GNOME Color Management.
+**Installeer het kleurprofiel:**
-**Installeer de kleurprofielen:**
+Linux slaat ICC profielen op in één van twee locaties, afhankelijk van het bereik:
-De ICC kleurprofielen staan in de [`/icc-profiles/`](https://github.com/Stensel8/Zephyrus-Linux/tree/main/static/icc-profiles) map van deze repository. Clone de repository of download de profielen handmatig en kopieer ze naar `~/.local/share/icc`:
+| Locatie | Bereik |
+|---|---|
+| `/usr/share/color/icc/colord/` | Systeem-breed (alle gebruikers, vereist root) |
+| `~/.local/share/icc/` | Alleen huidige gebruiker |
```bash
-mkdir -p ~/.local/share/icc
+# Systeem-brede installatie (aanbevolen):
+sudo cp SxxB80xT.icm /usr/share/color/icc/colord/
-# Als je de repository al hebt gecloned:
-cp /icc-profiles/*.icm ~/.local/share/icc/
-
-# Of download de specifieke profielen die je nodig hebt uit de repository
+# Of per-gebruiker installatie:
+mkdir -p ~/.local/share/icc
+cp SxxB80xT.icm ~/.local/share/icc/
```
-**Activeer Native profiel in GNOME:**
+**Activeer in GNOME:**
1. Open **Instellingen** → **Color Management**
-2. Selecteer **Built-In Screen**
+2. Selecteer het **Samsung display** (bijv. "LS27B800TGUXEN")
3. Klik **Add Profile**
-4. Selecteer **Native**
+4. Selecteer `SxxB80xT`
5. Klik **Add**
-**Opmerking:** Als GNOME Settings de oude technische namen toont (bijv. "ASUS GA605WV 1002 104D158E CMDEF" in plaats van "Native"), sluit Settings af en heropen, of log uit/in om de color cache te verversen.
-
-**Beschikbare kleurprofielen:**
-
-| GNOME Naam | Bestand | Beschrijving |
-|---|---|---|
-| **Native** | `GA605WV_1002_104D158E_CMDEF.icm` | **Aanbevolen** - Factory-gekalibreerd voor Sharp LQ160R1JW02 panel, beste kleurnauwkeurigheid |
-| DCI-P3 | `ASUS_DCIP3.icm` | Verzadigde DCI-P3 kleuren voor gaming/media (Vivid mode) |
-| Display P3 | `ASUS_DisplayP3.icm` | Display P3 colorspace voor Apple-compatibele workflows |
-| sRGB | `ASUS_sRGB.icm` | sRGB standaard voor web/foto werk |
-
-**Aanbeveling:**
-
-Gebruik **Native** voor de beste kleurnauwkeurigheid. Dit profiel bevat factory-kalibratie die specifiek is voor het Sharp LQ160R1JW02 panel in deze laptop. De andere profielen (DCI-P3, Display P3, sRGB) zijn generieke kleurruimten zonder panel-specifieke correcties.
-
-**Opmerking:** Het `_1002_` in de bestandsnaam verwijst naar de AMD iGPU (Vendor ID 0x1002), die het interne eDP display aanstuurt op deze hybrid GPU laptop.
-
-**Achtergrond:**
-
-De profielen zijn gevonden door analyse van ASUS Windows driver packages. De ASUS CDN URL structuur:
-```
-https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/{id}-{code}-{hash}.zip
-```
-
-Voor de GA605WV is dit: `20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip`
-
-De profielen bevatten factory color corrections die specifiek zijn voor het Sharp LQ160R1JW02 panel (Panel ID: 104D158E) dat in dit model laptop wordt gebruikt.
-
-**Technische Details:**
-
-De profielen in deze repository zijn al voorbewerkt met aangepaste ICC metadata 'desc' tags, zodat ze direct met leesbare namen verschijnen in GNOME Color Management. Voor gebruikers die geïnteresseerd zijn in hoe deze modificaties werken, kun je zelf vergelijkbare ICC 'desc' tag manipulatie implementeren met Python's PIL/ImageCms.
-
{{% /details %}}
@@ -391,15 +336,11 @@ amdgpu 0000:66:00.0: amdgpu: GPU reset begin!
Deze laptop heeft dual GPUs (AMD Radeon 890M integrated + NVIDIA RTX 4060 discrete). De PSR (Panel Self Refresh) feature van de AMD GPU heeft een bug die crashes veroorzaakt met externe Thunderbolt monitoren.
**Oplossing:**
-Disable AMD PSR door een kernel parameter toe te voegen:
+Disable AMD PSR door een kernel parameter toe te voegen. Bewerk `/etc/default/grub` en voeg `amdgpu.dcdebugmask=0x600` toe aan `GRUB_CMDLINE_LINUX_DEFAULT`, daarna regenereer:
```bash
-sudo grubby --update-kernel=ALL --args="amdgpu.dcdebugmask=0x600"
-```
-
-Verifieer dat het toegevoegd is:
-```bash
-sudo grubby --info=ALL | grep args
+sudo nano /etc/default/grub
+sudo grub2-mkconfig -o /boot/efi/EFI/fedora/grub.cfg
```
Reboot:
@@ -545,9 +486,9 @@ sudo systemctl stop nvidia-powerd.service
sudo systemctl mask nvidia-powerd.service
```
-2. Voeg kernel parameters toe voor stabielere NVIDIA power management:
-```bash
-sudo grubby --update-kernel=ALL --args="nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1"
+2. Voeg kernel parameters toe voor stabielere NVIDIA power management (bewerk `/etc/default/grub`, voeg toe aan `GRUB_CMDLINE_LINUX_DEFAULT`, daarna `sudo grub-mkconfig -o /boot/grub/grub.cfg`):
+```
+nvidia-drm.fbdev=1 nvidia.NVreg_PreserveVideoMemoryAllocations=1
```
3. Reboot:
@@ -580,7 +521,8 @@ sudo journalctl -b | grep nvidia
Rebuild kernel modules:
```bash
-sudo akmods --force --rebuild
+sudo akmods --force
+sudo dracut --force
sudo reboot
```
@@ -593,7 +535,8 @@ Als je de error krijgt `modprobe: ERROR: could not insert 'nvidia': Key was reje
Oplossing:
```bash
# Rebuild modules na MOK enrollment
-sudo akmods --force --rebuild
+sudo akmods --force
+sudo dracut --force
# Reboot
sudo reboot
@@ -608,37 +551,18 @@ Reboot en probeer enrollment opnieuw.
{{% /details %}}
-{{% details title="Draait X11 in plaats van Wayland" closed="true" %}}
-
-Check sessie type:
-```bash
-echo $XDG_SESSION_TYPE
-```
-
-Als output `x11` is, zorg dat Wayland ingeschakeld is in GDM:
-```bash
-sudo nano /etc/gdm/custom.conf
-```
-
-Verifieer dat deze regel aanwezig is en niet uitgecommentarieerd:
-```
-WaylandEnable=true
-```
-
-Reboot na wijzigingen.
-
-{{% /details %}}
{{% details title="Kernel module build failures" closed="true" %}}
Zorg dat kernel headers overeenkomen met draaiende kernel:
```bash
-sudo dnf install kernel-devel-$(uname -r)
+sudo dnf install kernel-devel
```
Forceer rebuild:
```bash
sudo akmods --force
+sudo dracut --force
```
{{% /details %}}
@@ -647,18 +571,16 @@ sudo akmods --force
## Technische weetjes
### Package Naming
-De package `xorg-x11-drv-nvidia` is een legacy naam. De driver ondersteunt zowel X11 als Wayland. Fedora 43 gebruikt standaard Wayland met GNOME.
+Het `akmod-nvidia` package is de aanbevolen NVIDIA driver voor Fedora. Het gebruikt het akmods framework om kernel modules automatisch te rebuilden na kernel updates.
### Secure Boot
-Akmod handelt Secure Boot module signing automatisch af. De akmods systemd service rebuildt kernel modules automatisch na kernel updates.
-
-### GNOME Software
-GNOME Software toont "NVIDIA Linux Graphics Driver" met "Pending" status na initiële installatie. Dit is normaal. Na MOK enrollment en module rebuild wordt de status "Installed".
+akmods rebuildt en signeert kernel modules automatisch na kernel updates. Op Fedora kan `sbctl` ook worden gebruikt voor Secure Boot sleutelbeheer.
## Aanvullende Bronnen
-- [RPM Fusion NVIDIA Driver Guide](https://www.if-not-true-then-false.com/2015/fedora-nvidia-guide/)
+- [CachyOS Wiki: NVIDIA](https://wiki.cachyos.org/configuration/nvidia/)
+- [Arch Wiki: NVIDIA](https://wiki.archlinux.org/title/NVIDIA)
- [Ryzen AI 9 HX 370 Linux Support](https://forums.linuxmint.com/viewtopic.php?t=429052)
- [NVIDIA vs Nouveau Performance](https://machaddr.substack.com/p/nouveau-vs-nvidia-the-battle-between)
- [Zephyrus G16 2024 Linux Guide](https://www.ehmiiz.se/blog/linux_asus_g16_2024/)
diff --git a/content/docs/hardware/secure-boot.md b/content/docs/hardware/secure-boot.md
new file mode 100644
index 0000000..67a1ca9
--- /dev/null
+++ b/content/docs/hardware/secure-boot.md
@@ -0,0 +1,263 @@
+---
+title: "Secure Boot"
+weight: 12
+---
+
+To install CachyOS, Secure Boot has to be off first. Unlike Ubuntu or Fedora, CachyOS doesn't use shim — a Microsoft-signed bootloader that lets third-party systems boot under Secure Boot. Without it, Secure Boot blocks the CachyOS bootloader before it even starts, so it has to be disabled for installation ([CachyOS installation docs](https://wiki.cachyos.org/installation/installation_on_root/)).
+
+After installation, it's possible to re-enable it with your own signing keys. This is how I did that using `sbctl`.
+
+> **Result:** UEFI Secure Boot goes from **Fail** to **Pass** after completing this guide. The overall HSI score remains **HSI:3!** — the Encrypted RAM check at HSI-4 is not supported on this hardware, which prevents reaching HSI:4.
+
+
+## Security Report Context
+
+Running `fwupdmgr security` shows what passes and what doesn't. After enabling Secure Boot, the remaining failures on this hardware are:
+
+| Test | After this guide | Reason |
+|---|---|---|
+| UEFI Secure Boot | ✓ Pass | Fixed by this guide |
+| Encrypted RAM (HSI-4) | ✗ Not Supported | Hardware limitation — Ryzen AI 9 HX 370 does not implement AMD SME/TME |
+| Linux Kernel Verification | ✗ Tainted | Proprietary NVIDIA driver permanently taints the kernel — expected |
+| Linux Kernel Lockdown | ✗ Not Enabled | Requires kernel lockdown mode — not covered here, conflicts with proprietary modules |
+
+
+
+
+## How It Works
+
+Instead of the shim → MOK → kernel chain that many distributions use, `sbctl` enrolls custom Secure Boot keys directly into the UEFI firmware. The bootloader and kernel EFI images are then signed with those keys. No shim or MOK Manager needed.
+
+`sbctl` also ships with a pacman hook that automatically re-signs all registered EFI binaries after kernel or bootloader updates — so it's not something you have to think about after the initial setup.
+
+
+## Installation
+
+```bash
+sudo pacman -S sbctl
+```
+
+
+## Step 1 — Enter UEFI Setup Mode
+
+Setup Mode is a UEFI state where no Secure Boot keys are enrolled yet, which allows new ones to be added. You need to get into this state before creating keys.
+
+Reboot into the ASUS UEFI:
+
+```bash
+systemctl reboot --firmware-setup
+```
+
+In the ASUS UEFI (press **F7** for Advanced Mode if needed):
+
+1. Go to the **Security** tab
+2. Select **Secure Boot**
+3. Set **Secure Boot Control** to **Enabled**
+4. Open **Key Management**
+5. Select **Clear Secure Boot Keys** (or **Reset to Setup Mode** if available)
+6. Confirm and **Save & Exit** (F10)
+
+After rebooting into CachyOS, verify Setup Mode is active:
+
+```bash
+sudo sbctl status
+```
+
+Expected output:
+
+```
+Installed: ✗ sbctl is not installed
+Owner GUID:
+Setup Mode: ✗ Enabled
+Secure Boot: ✗ Disabled
+Vendor Keys: none
+```
+
+`Setup Mode` showing `Enabled` confirms the UEFI is ready for key enrollment. The `✗` symbols aren't errors here — they just mean the keys haven't been set up yet, which is exactly where we want to be at this point.
+
+
+## Step 2 — Create Keys
+
+```bash
+sudo sbctl create-keys
+```
+
+
+## Step 3 — Enroll Keys
+
+This enrolls the custom keys into the firmware, including Microsoft's UEFI CA certificates. The `--microsoft` flag is required on ASUS hardware — without it, option ROMs (GPU firmware) and other UEFI drivers signed by Microsoft refuse to load. I was a bit hesitant about including Microsoft's certificates here, but without them the system won't boot properly.
+
+```bash
+sudo sbctl enroll-keys --microsoft
+```
+
+
+## Step 4 — Sign EFI Binaries
+
+The signing process differs slightly depending on your bootloader.
+
+### systemd-boot
+
+Sign all EFI binaries and register them in sbctl's database. The `-s` flag is important — it ensures files are automatically re-signed after future updates:
+
+```bash
+sudo sbctl verify
+sudo sbctl-batch-sign
+sudo sbctl verify
+```
+
+All entries should show `✓`. If any show `✗`, sign them individually:
+
+```bash
+sudo sbctl sign -s /path/to/unsigned.efi
+```
+
+CachyOS uses `systemd-boot-update.service` to update the systemd-boot binary. This runs outside the standard sbctl hook, so the source binary needs to be signed explicitly to ensure it's re-signed on every bootloader update:
+
+```bash
+sudo sbctl sign -s -o /usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
+ /usr/lib/systemd/boot/efi/systemd-bootx64.efi
+```
+
+### Limine
+
+Limine handles its own signing process and doesn't require kernel image signatures:
+
+```bash
+sudo limine-enroll-config
+sudo limine-update
+```
+
+
+## Step 5 — Enable Secure Boot
+
+Reboot into the ASUS UEFI again:
+
+```bash
+systemctl reboot --firmware-setup
+```
+
+1. Go to **Security** → **Secure Boot**
+2. Set **Secure Boot Control** to **Enabled**
+3. Confirm the keys are present under **Key Management** (DB, KEK, PK should all be populated)
+4. Save & Exit (F10)
+
+
+## Verification
+
+After rebooting, this is what things look like:
+
+```bash
+sudo sbctl status
+```
+
+```
+Installed: ✓ sbctl is installed
+Owner GUID:
+Setup Mode: ✓ Disabled
+Secure Boot: ✓ Enabled
+Vendor Keys: microsoft
+```
+
+
+
+```bash
+fwupdmgr security
+```
+
+The **UEFI Secure Boot** line under HSI-1 should now show **Enabled**. The overall score remains **HSI:3!** — Encrypted RAM at HSI-4 is not supported on this hardware, which is a hardware limitation unrelated to this guide.
+
+
+
+GNOME Settings → Privacy & Security → Device Security also confirms it:
+
+
+
+
+## NVIDIA and Kernel Updates
+
+UEFI Secure Boot only verifies the bootloader and kernel EFI image. The NVIDIA driver is loaded as a DKMS module by the kernel. In this configuration, the kernel does not enforce module signatures, so the NVIDIA module continues to work but the kernel is marked as tainted. Signing NVIDIA modules is therefore outside the scope of this guide.
+
+> Those who want to cryptographically enforce kernel modules must sign NVIDIA modules with the same key or avoid the proprietary driver.
+
+After a kernel update, pacman triggers both:
+1. sbctl's hook → re-signs the new kernel EFI image
+2. DKMS → rebuilds NVIDIA modules for the new kernel
+
+No manual intervention needed after updates.
+
+> **Kernel taint:** The proprietary NVIDIA driver will continue to taint the kernel. This shows as `Linux Kernel Verification: Tainted` in the HSI report. This is expected — it means non-open-source code is loaded, not that the system is compromised.
+
+
+## Remaining HSI Failures Explained
+
+### Encrypted RAM (HSI-4)
+
+**Not fixable on this hardware.** The Ryzen AI 9 HX 370 does not support AMD Secure Memory Encryption (SME) in the mode fwupd checks for. This is a hardware capability limitation, not a configuration issue.
+
+### Linux Kernel Lockdown
+
+Kernel lockdown can be enabled by adding `lockdown=integrity` to kernel parameters. However, lockdown restricts unsigned kernel modules and certain privileged operations — the proprietary NVIDIA driver would break under lockdown mode. Not something I'd recommend for day-to-day use on this hardware.
+
+### Linux Kernel Verification (Tainted)
+
+Caused by the proprietary NVIDIA driver. Can't be resolved while using proprietary NVIDIA drivers. Not a security vulnerability.
+
+
+## Troubleshooting
+
+{{% details title="sbctl status still shows 'Setup Mode: Disabled' after clearing keys" closed="true" %}}
+
+Some ASUS UEFI versions require the platform key (PK) to be explicitly deleted before Setup Mode activates.
+
+In the ASUS UEFI:
+1. Go to **Security** → **Secure Boot** → **Key Management**
+2. Select **Platform Key (PK)** → **Delete**
+3. Save & Exit and reboot
+
+After rebooting, `sudo sbctl status` should show Setup Mode: Enabled.
+
+{{% /details %}}
+
+{{% details title="System does not boot after enabling Secure Boot" closed="true" %}}
+
+If the system doesn't boot after enabling Secure Boot, one or more EFI files weren't signed.
+
+1. Reboot into the ASUS UEFI and temporarily disable Secure Boot
+2. Boot into CachyOS
+3. Check which files are unsigned:
+```bash
+sudo sbctl verify
+```
+4. Sign any missing files:
+```bash
+sudo sbctl sign -s /path/to/file.efi
+```
+5. Or re-run the batch sign:
+```bash
+sudo sbctl-batch-sign
+```
+6. Reboot and re-enable Secure Boot
+
+{{% /details %}}
+
+{{% details title="fwupdmgr shows HSI:3 instead of HSI:4 after enabling Secure Boot" closed="true" %}}
+
+The fwupd daemon caches results. Refresh the report:
+
+```bash
+fwupdmgr refresh
+fwupdmgr security --force
+```
+
+If Secure Boot shows Pass but the score is still HSI:3, check whether any other HSI-4 tests are failing. Encrypted RAM is a hardware limitation on this platform and does not count towards the score here.
+
+{{% /details %}}
+
+
+## References
+
+- [CachyOS Wiki: Secure Boot Setup](https://wiki.cachyos.org/configuration/secure_boot_setup/)
+- [Arch Wiki: Secure Boot](https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot)
+- [sbctl GitHub](https://github.com/Foxboron/sbctl)
+- [fwupd HSI Documentation](https://fwupd.github.io/hsi.html)
diff --git a/content/docs/hardware/secure-boot.nl.md b/content/docs/hardware/secure-boot.nl.md
new file mode 100644
index 0000000..8cc294e
--- /dev/null
+++ b/content/docs/hardware/secure-boot.nl.md
@@ -0,0 +1,263 @@
+---
+title: "Secure Boot"
+weight: 12
+---
+
+Om CachyOS te installeren moet Secure Boot eerst uit. Anders dan Ubuntu of Fedora gebruikt CachyOS geen shim — een door Microsoft ondertekende bootloader waarmee distributies van derden kunnen opstarten onder Secure Boot. Zonder shim blokkeert Secure Boot de CachyOS-bootloader bij het opstarten, waardoor het voor de installatie uitgeschakeld moet worden ([CachyOS installatiedocumentatie](https://wiki.cachyos.org/installation/installation_on_root/)).
+
+Na de installatie kan Secure Boot opnieuw worden ingeschakeld met je eigen ondertekeningssleutels. Dit is hoe ik dat heb gedaan met `sbctl`.
+
+> **Resultaat:** UEFI Secure Boot gaat van **Fail** naar **Pass** na het voltooien van deze handleiding. De algehele HSI-score blijft **HSI:3!** — de Encrypted RAM-check op HSI-4 wordt niet ondersteund op deze hardware, waardoor HSI:4 niet haalbaar is.
+
+
+## Context van het beveiligingsrapport
+
+Het uitvoeren van `fwupdmgr security` toont wat slaagt en wat niet. Na het inschakelen van Secure Boot zijn de overgebleven fouten op deze hardware:
+
+| Test | Na deze handleiding | Reden |
+|---|---|---|
+| UEFI Secure Boot | ✓ Pass | Opgelost door deze handleiding |
+| Encrypted RAM (HSI-4) | ✗ Not Supported | Hardwarebeperking — Ryzen AI 9 HX 370 implementeert AMD SME/TME niet |
+| Linux Kernel Verification | ✗ Tainted | Proprietary NVIDIA-driver vervuilt de kernel permanent — verwacht gedrag |
+| Linux Kernel Lockdown | ✗ Not Enabled | Vereist kernel lockdown-modus — niet behandeld hier, conflicteert met proprietary modules |
+
+
+
+
+## Hoe het werkt
+
+In plaats van de shim → MOK → kernel-keten die veel distributies gebruiken, schrijft `sbctl` aangepaste Secure Boot-sleutels rechtstreeks in de UEFI-firmware in. De bootloader en het kernel EFI-image worden daarna ondertekend met die sleutels. Geen shim of MOK Manager nodig.
+
+`sbctl` wordt ook geleverd met een pacman-hook die alle geregistreerde EFI-binaries automatisch opnieuw ondertekent na kernel- of bootloader-updates — iets wat je na de initiële setup niet meer handmatig hoeft te doen.
+
+
+## Installatie
+
+```bash
+sudo pacman -S sbctl
+```
+
+
+## Stap 1 — UEFI Setup Mode activeren
+
+Setup Mode is een UEFI-toestand waarbij er nog geen Secure Boot-sleutels zijn ingeschreven, waardoor nieuwe sleutels kunnen worden toegevoegd. Je moet eerst in deze toestand komen voordat je sleutels aanmaakt.
+
+Herstart naar de ASUS UEFI:
+
+```bash
+systemctl reboot --firmware-setup
+```
+
+In de ASUS UEFI (druk op **F7** voor Geavanceerde Modus indien nodig):
+
+1. Ga naar het tabblad **Security**
+2. Selecteer **Secure Boot**
+3. Zet **Secure Boot Control** op **Enabled**
+4. Open **Key Management**
+5. Selecteer **Clear Secure Boot Keys** (of **Reset to Setup Mode** indien beschikbaar)
+6. Bevestig en **Save & Exit** (F10)
+
+Controleer na het herstarten in CachyOS of Setup Mode actief is:
+
+```bash
+sudo sbctl status
+```
+
+Verwachte uitvoer:
+
+```
+Installed: ✗ sbctl is not installed
+Owner GUID:
+Setup Mode: ✗ Enabled
+Secure Boot: ✗ Disabled
+Vendor Keys: none
+```
+
+`Setup Mode` met de waarde `Enabled` bevestigt dat de UEFI klaar is voor sleutelinschrijving. De `✗`-symbolen zijn hier geen fouten — ze geven alleen aan dat de sleutels nog niet zijn aangemaakt, wat precies de bedoeling is op dit punt.
+
+
+## Stap 2 — Sleutels aanmaken
+
+```bash
+sudo sbctl create-keys
+```
+
+
+## Stap 3 — Sleutels inschrijven
+
+Dit schrijft de aangepaste sleutels in de firmware in, inclusief de UEFI CA-certificaten van Microsoft. De `--microsoft`-vlag is vereist op ASUS-hardware — zonder die certificaten weigeren option ROMs (GPU-firmware) en andere UEFI-drivers van Microsoft te laden. Ik aarzelde een beetje om de sleutels van Microsoft mee te nemen, maar zonder die vlag start het systeem niet goed op.
+
+```bash
+sudo sbctl enroll-keys --microsoft
+```
+
+
+## Stap 4 — EFI-binaries ondertekenen
+
+Het ondertekeningsproces verschilt iets per bootloader.
+
+### systemd-boot
+
+Onderteken alle EFI-binaries en registreer ze in de sbctl-database. De `-s`-vlag is belangrijk — die zorgt ervoor dat bestanden automatisch opnieuw worden ondertekend na toekomstige updates:
+
+```bash
+sudo sbctl verify
+sudo sbctl-batch-sign
+sudo sbctl verify
+```
+
+Alle vermeldingen moeten `✓` tonen. Als er `✗` staan, onderteken ze dan handmatig:
+
+```bash
+sudo sbctl sign -s /pad/naar/niet-ondertekend.efi
+```
+
+CachyOS gebruikt `systemd-boot-update.service` om de systemd-boot binary bij te werken. Dit werkt buiten de standaard sbctl-hook om, dus de bronbinary moet expliciet worden ondertekend zodat die bij elke bootloader-update opnieuw wordt meegenomen:
+
+```bash
+sudo sbctl sign -s -o /usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
+ /usr/lib/systemd/boot/efi/systemd-bootx64.efi
+```
+
+### Limine
+
+Limine beheert zijn eigen ondertekeningsproces en vereist geen handtekeningen op kernel-images:
+
+```bash
+sudo limine-enroll-config
+sudo limine-update
+```
+
+
+## Stap 5 — Secure Boot inschakelen
+
+Herstart opnieuw naar de ASUS UEFI:
+
+```bash
+systemctl reboot --firmware-setup
+```
+
+1. Ga naar **Security** → **Secure Boot**
+2. Zet **Secure Boot Control** op **Enabled**
+3. Bevestig dat de sleutels aanwezig zijn onder **Key Management** (DB, KEK, PK moeten allemaal gevuld zijn)
+4. Save & Exit (F10)
+
+
+## Verificatie
+
+Na het herstarten ziet het er zo uit:
+
+```bash
+sudo sbctl status
+```
+
+```
+Installed: ✓ sbctl is installed
+Owner GUID:
+Setup Mode: ✓ Disabled
+Secure Boot: ✓ Enabled
+Vendor Keys: microsoft
+```
+
+
+
+```bash
+fwupdmgr security
+```
+
+De regel **UEFI Secure Boot** onder HSI-1 moet nu **Enabled** tonen. De algehele score blijft **HSI:3!** — Encrypted RAM op HSI-4 wordt niet ondersteund op deze hardware en staat los van deze handleiding.
+
+
+
+GNOME Instellingen → Privacy & Beveiliging → Apparaatbeveiliging bevestigt ook het resultaat:
+
+
+
+
+## NVIDIA en kernelupdates
+
+UEFI Secure Boot verifieert alleen de bootloader en het kernel-EFI-image. De NVIDIA-driver wordt als DKMS-module door de kernel geladen. In deze configuratie staat de kernel module-signatures niet af te dwingen, waardoor de NVIDIA-module blijft werken, maar de kernel als tainted wordt gemarkeerd. Extra module-signing voor NVIDIA valt daarom buiten de scope van deze handleiding.
+
+> Wie ook kernelmodules cryptografisch wil afdwingen, moet NVIDIA-modules met dezelfde sleutel signen of de proprietary driver vermijden.
+
+Na een kernelupdate activeert pacman beide:
+1. sbctl-hook → ondertekent het nieuwe kernel EFI-image opnieuw
+2. DKMS → bouwt NVIDIA-modules voor de nieuwe kernel opnieuw
+
+Na updates is geen handmatige actie nodig.
+
+> **Kernelvervuiling:** De proprietary NVIDIA-driver zal de kernel blijven vervuilen. Dit verschijnt als `Linux Kernel Verification: Tainted` in het HSI-rapport. Dit is verwacht — het betekent dat niet-open-source code is geladen, niet dat het systeem is aangetast.
+
+
+## Overgebleven HSI-fouten uitgelegd
+
+### Encrypted RAM (HSI-4)
+
+**Niet oplosbaar op deze hardware.** De Ryzen AI 9 HX 370 ondersteunt AMD Secure Memory Encryption (SME) niet op de manier waarop fwupd dit controleert. Dit is een hardwarebeperking, geen configuratieprobleem.
+
+### Linux Kernel Lockdown
+
+Kernel lockdown kan worden ingeschakeld door `lockdown=integrity` toe te voegen aan de kernelparameters. Lockdown beperkt echter niet-ondertekende kernelmodules en bepaalde bevoorrechte bewerkingen — de proprietary NVIDIA-driver zou niet werken onder lockdown-modus. Niet iets wat ik zou aanraden voor dagelijks gebruik op deze hardware.
+
+### Linux Kernel Verification (Tainted)
+
+Veroorzaakt door de proprietary NVIDIA-driver. Kan niet worden opgelost zolang proprietary NVIDIA-drivers worden gebruikt. Dit is geen beveiligingslek.
+
+
+## Probleemoplossing
+
+{{% details title="sbctl status toont nog steeds 'Setup Mode: Disabled' na het wissen van sleutels" closed="true" %}}
+
+Sommige ASUS UEFI-versies vereisen dat de platformsleutel (PK) expliciet wordt verwijderd voordat Setup Mode wordt geactiveerd.
+
+In de ASUS UEFI:
+1. Ga naar **Security** → **Secure Boot** → **Key Management**
+2. Selecteer **Platform Key (PK)** → **Delete**
+3. Save & Exit en herstart
+
+Na het herstarten moet `sudo sbctl status` Setup Mode: Enabled tonen.
+
+{{% /details %}}
+
+{{% details title="Systeem start niet op na het inschakelen van Secure Boot" closed="true" %}}
+
+Als het systeem niet opstart na het inschakelen van Secure Boot, zijn een of meer EFI-bestanden niet ondertekend.
+
+1. Herstart naar de ASUS UEFI en schakel Secure Boot tijdelijk uit
+2. Start op in CachyOS
+3. Controleer welke bestanden niet zijn ondertekend:
+```bash
+sudo sbctl verify
+```
+4. Onderteken ontbrekende bestanden:
+```bash
+sudo sbctl sign -s /pad/naar/bestand.efi
+```
+5. Of voer de batch-ondertekening opnieuw uit:
+```bash
+sudo sbctl-batch-sign
+```
+6. Herstart en schakel Secure Boot opnieuw in
+
+{{% /details %}}
+
+{{% details title="fwupdmgr toont HSI:3 in plaats van HSI:4 na het inschakelen van Secure Boot" closed="true" %}}
+
+De fwupd-daemon slaat resultaten op in cache. Ververs het rapport:
+
+```bash
+fwupdmgr refresh
+fwupdmgr security --force
+```
+
+Als Secure Boot Pass toont maar de score nog steeds HSI:3 is, controleer dan of andere HSI-4-tests falen. Encrypted RAM is een hardwarebeperking op dit platform en telt hier niet mee voor de score.
+
+{{% /details %}}
+
+
+## Referenties
+
+- [CachyOS Wiki: Secure Boot Setup](https://wiki.cachyos.org/configuration/secure_boot_setup/)
+- [Arch Wiki: Secure Boot](https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot)
+- [sbctl GitHub](https://github.com/Foxboron/sbctl)
+- [fwupd HSI-documentatie](https://fwupd.github.io/hsi.html)
diff --git a/content/docs/known-issues.md b/content/docs/known-issues.md
new file mode 100644
index 0000000..1f38963
--- /dev/null
+++ b/content/docs/known-issues.md
@@ -0,0 +1,10 @@
+---
+title: "Known Issues"
+weight: 99
+---
+
+This page will document hardware or software issues on the Zephyrus G16 that I've run into but haven't found a reliable solution for yet.
+
+{{< callout type="info" >}}
+Nothing here yet. Issues with known fixes are already documented in the relevant guides (see the [NVIDIA Driver Installation]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) guide for GPU-related issues).
+{{< /callout >}}
diff --git a/content/docs/known-issues.nl.md b/content/docs/known-issues.nl.md
new file mode 100644
index 0000000..3c5d972
--- /dev/null
+++ b/content/docs/known-issues.nl.md
@@ -0,0 +1,10 @@
+---
+title: "Bekende Problemen"
+weight: 99
+---
+
+Op deze pagina komen hardware- of softwareproblemen met de Zephyrus G16 te staan waarvoor ik nog geen betrouwbare oplossing gevonden heb.
+
+{{< callout type="info" >}}
+Nog niets hier. Problemen met bekende oplossingen staan al gedocumenteerd in de relevante handleidingen (zie de [NVIDIA Driver Installatie]({{< relref "/docs/hardware/nvidia-driver-installation" >}}) handleiding voor GPU-gerelateerde problemen).
+{{< /callout >}}
diff --git a/content/docs/networking/_index.md b/content/docs/networking/_index.md
new file mode 100644
index 0000000..c9e7a09
--- /dev/null
+++ b/content/docs/networking/_index.md
@@ -0,0 +1,7 @@
+---
+title: "Networking"
+weight: 30
+toc: false
+---
+
+Network configuration that required more than just clicking connect.
diff --git a/content/docs/networking/_index.nl.md b/content/docs/networking/_index.nl.md
new file mode 100644
index 0000000..cbda8e0
--- /dev/null
+++ b/content/docs/networking/_index.nl.md
@@ -0,0 +1,7 @@
+---
+title: "Netwerk"
+weight: 30
+toc: false
+---
+
+Netwerkconfiguratie die meer vereiste dan alleen op verbinden klikken.
diff --git a/content/docs/eduroam-network-installation.md b/content/docs/networking/eduroam-network-installation.md
similarity index 90%
rename from content/docs/eduroam-network-installation.md
rename to content/docs/networking/eduroam-network-installation.md
index 02b4419..fbd1230 100644
--- a/content/docs/eduroam-network-installation.md
+++ b/content/docs/networking/eduroam-network-installation.md
@@ -3,12 +3,12 @@ title: "eduroam Network Installation"
weight: 23
---
-Getting eduroam to work on Linux is more painful than it should be. Every "official" method I tried failed on Fedora 43 — the connection would just hang during the TLS handshake and never connect. I eventually figured out a manual setup that works reliably and wrote a script around it. Sharing it here so you hopefully don't have to go through the same process.
+Getting eduroam to work on Linux is more painful than it should be. Every "official" method I tried failed — the connection would just hang during the TLS handshake and never connect. I eventually figured out a manual setup that works reliably and wrote a script around it. Sharing it here so you hopefully don't have to go through the same process.
## What doesn't work
{{% details title="cat.eduroam.org installer (official)" closed="true" %}}
-The Python installer from [cat.eduroam.org](https://cat.eduroam.org/) provides a graphical interface and creates a connection profile. On some recent Linux distributions (such as Fedora 43), the connection may hang during the TLS handshake due to changes in NetworkManager.
+The Python installer from [cat.eduroam.org](https://cat.eduroam.org/) provides a graphical interface and creates a connection profile. On some recent Linux distributions, the connection may hang during the TLS handshake due to changes in NetworkManager.

{{% /details %}}
diff --git a/content/docs/eduroam-network-installation.nl.md b/content/docs/networking/eduroam-network-installation.nl.md
similarity index 90%
rename from content/docs/eduroam-network-installation.nl.md
rename to content/docs/networking/eduroam-network-installation.nl.md
index f7eca8f..d4e81db 100644
--- a/content/docs/eduroam-network-installation.nl.md
+++ b/content/docs/networking/eduroam-network-installation.nl.md
@@ -3,12 +3,12 @@ title: "eduroam Netwerkinstallatie"
weight: 23
---
-eduroam werkend krijgen op Linux is pijnlijker dan het zou moeten zijn. Elke "officiële" methode die ik probeerde faalde op Fedora 43 — de verbinding bleef gewoon hangen tijdens de TLS-handshake en verbond nooit. Uiteindelijk heb ik een handmatige setup gevonden die betrouwbaar werkt en daar een script omheen geschreven. Ik deel het hier zodat jij hopelijk niet hetzelfde proces hoeft door te maken.
+eduroam werkend krijgen op Linux is pijnlijker dan het zou moeten zijn. Elke "officiële" methode die ik probeerde faalde — de verbinding bleef gewoon hangen tijdens de TLS-handshake en verbond nooit. Uiteindelijk heb ik een handmatige setup gevonden die betrouwbaar werkt en daar een script omheen geschreven. Ik deel het hier zodat jij hopelijk niet hetzelfde proces hoeft door te maken.
## Wat niet werkt
{{% details title="cat.eduroam.org installer (officieel)" closed="true" %}}
-De Python-installer van [cat.eduroam.org](https://cat.eduroam.org/) biedt een grafische interface en maakt een verbindingsprofiel aan. Op sommige recente Linux-distributies (zoals Fedora 43) kan de verbinding blijven hangen tijdens de TLS-handshake door wijzigingen in NetworkManager.
+De Python-installer van [cat.eduroam.org](https://cat.eduroam.org/) biedt een grafische interface en maakt een verbindingsprofiel aan. Op sommige recente Linux-distributies kan de verbinding blijven hangen tijdens de TLS-handshake door wijzigingen in NetworkManager.

{{% /details %}}
diff --git a/content/docs/news.md b/content/docs/news.md
new file mode 100644
index 0000000..7bd168b
--- /dev/null
+++ b/content/docs/news.md
@@ -0,0 +1,37 @@
+---
+title: "News"
+weight: 90
+toc: false
+---
+
+## Moved to CachyOS (Arch) — the best distro for this hardware
+
+After testing multiple distributions, I've settled on CachyOS (Arch) as my daily driver. CachyOS is an Arch-based distribution with deep hardware-specific optimizations that make it stand out for the Zephyrus G16:
+
+- **BORE/EEVDF scheduler** — CachyOS ships with an improved CPU scheduler that provides better responsiveness and lower latency under mixed workloads
+- **Improved power management** — Better handling of suspend/resume and ACPI power states on AMD+NVIDIA hybrid setups
+- **Dynamic refresh rate support** — Out-of-the-box support for variable refresh rate on the ROG Nebula Display
+- **Built-in iGPU and dGPU drivers** — The AMD Radeon 890M and NVIDIA RTX 4060 work correctly from a fresh install, including GPU switching via `supergfxctl`
+- **ASUS Linux patches merged** — The work of [Luke Jones](https://asus-linux.org/) (asus-linux.org), including the `asus-armoury` driver and `asusctl` tooling, has been merged into CachyOS. This gives native support for ROG-specific features like fan curves, performance profiles, and the Slash LED panel
+
+My first choice is CachyOS for this hardware. Fedora is a strong second — it came close and is also an excellent option if you prefer a more stable release cycle over rolling.
+
+## Kernel 7.0: ASUS laptop quirks + newer AMDGPU enablement
+
+Linus confirmed the next kernel will be 7.0, with the merge window now open and a stable release expected mid-April 2026. For this ASUS ROG G16, the headline is better graphics driver coverage: the DRM updates bring AMDGPU enablement for newer RDNA 3.5-class IP blocks (GFX11.5.4) plus ongoing NVIDIA Nova/Nouveau work, which should translate into better handling of both the iGPU and dGPU. Early expectations are that the Radeon 890M could see around a 20% uplift. CachyOS will pick this up as it ships.
+
+**Sources:** [Linus confirms Linux 7.0](https://www.phoronix.com/news/Linux-7.0-Is-Next) · [HID laptop quirks for ASUS ROG models](https://www.phoronix.com/news/Linux-7.0-HID) · [Linux 7.0 DRM/AMDGPU updates](https://www.phoronix.com/news/Linux-7.0-Graphics-Drivers)
+
+## Kernel 6.19: asus-armoury driver lands in mainline
+
+The `asus-armoury` driver has been [merged into Linux 6.19](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19). This new `platform/x86` driver replaces parts of the older `asus-wmi` with a cleaner sysfs-based API, enabling panel mode switching, APU memory allocation, PPT tuning, and more directly from the kernel. The driver is entirely community-developed by [Luke Jones](https://asus-linux.org/) (ASUS Linux project), with no involvement from ASUS themselves. CachyOS ships kernel 6.19.3-2 which includes this driver and additional ASUS-specific patches.
+
+**Before** — basic asusctl controls without Armoury settings:
+
+
+
+**After** — full Armoury settings exposed, including PPT/power limit tuning:
+
+
+
+**Sources:** [Phoronix article](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19) · [Community discussion](https://www.phoronix.com/forums/forum/software/linux-gaming/1593500-asus-armoury-driver-set-to-be-introduced-in-linux-6-19) · [Patch series (lore.kernel.org)](https://lore.kernel.org/all/20251102215319.3126879-1-denis.benato@linux.dev/)
diff --git a/content/docs/news.nl.md b/content/docs/news.nl.md
new file mode 100644
index 0000000..9bd3128
--- /dev/null
+++ b/content/docs/news.nl.md
@@ -0,0 +1,37 @@
+---
+title: "Nieuws"
+weight: 90
+toc: false
+---
+
+## Overgestapt naar CachyOS (Arch) — de beste distro voor deze hardware
+
+Na het testen van meerdere distributies ben ik overgestapt op CachyOS (Arch) als mijn dagelijkse driver. CachyOS is een op Arch gebaseerde distributie met diepgaande hardware-specifieke optimalisaties die het onderscheiden voor de Zephyrus G16:
+
+- **BORE/EEVDF scheduler** — CachyOS wordt geleverd met een verbeterde CPU-scheduler die betere responsiviteit en lagere latency biedt bij gemengde workloads
+- **Verbeterd energiebeheer** — Betere afhandeling van suspend/resume en ACPI power states op AMD+NVIDIA hybride setups
+- **Ondersteuning voor dynamische verversingsfrequentie** — Standaard ondersteuning voor variable refresh rate op het ROG Nebula Display
+- **Ingebouwde iGPU- en dGPU-drivers** — De AMD Radeon 890M en NVIDIA RTX 4060 werken correct vanaf een verse installatie, inclusief GPU-switching via `supergfxctl`
+- **ASUS Linux-patches gemerged** — Het werk van [Luke Jones](https://asus-linux.org/) (asus-linux.org), waaronder de `asus-armoury`-driver en `asusctl`-tooling, is gemerged in CachyOS. Dit geeft native ondersteuning voor ROG-specifieke functies zoals fan curves, prestatieprofielen en het Slash LED-paneel
+
+Mijn eerste keuze is CachyOS voor deze hardware. Fedora is een sterke tweede — het komt dicht in de buurt en is ook een uitstekende optie als je de voorkeur geeft aan een stabielere releasecyclus boven rolling.
+
+## Kernel 7.0: ASUS laptop quirks + nieuw AMDGPU-werk
+
+Linus heeft bevestigd dat de volgende kernel 7.0 is, met de merge window nu open en een stabiele release verwacht rond midden april 2026. Voor deze ASUS ROG G16 is het belangrijkste nieuws betere grafische driver-ondersteuning: de DRM-updates brengen AMDGPU-ondersteuning voor nieuwere RDNA 3.5-klasse IP blocks (GFX11.5.4) plus verder werk aan NVIDIA Nova/Nouveau, wat moet zorgen voor betere afhandeling van zowel de iGPU als dGPU. Verwachting is dat de Radeon 890M ongeveer 20% sneller kan worden. CachyOS pikt dit op zodra het beschikbaar is.
+
+**Bronnen:** [Linus bevestigt Linux 7.0](https://www.phoronix.com/news/Linux-7.0-Is-Next) · [HID laptop quirks voor ASUS ROG modellen](https://www.phoronix.com/news/Linux-7.0-HID) · [Linux 7.0 DRM/AMDGPU updates](https://www.phoronix.com/news/Linux-7.0-Graphics-Drivers)
+
+## Kernel 6.19: asus-armoury driver in mainline Linux
+
+De `asus-armoury` driver is [gemerged in Linux 6.19](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19). Deze nieuwe `platform/x86` driver vervangt delen van de oudere `asus-wmi` met een schonere sysfs-gebaseerde API, waarmee o.a. paneel modus wisselen, APU geheugentoewijzing, PPT tuning en meer mogelijk wordt direct vanuit de kernel. De driver is volledig ontwikkeld door de community, door [Luke Jones](https://asus-linux.org/) (ASUS Linux project), zonder enige betrokkenheid van ASUS zelf. CachyOS levert kernel 6.19.3-2, inclusief deze driver en aanvullende ASUS-specifieke patches.
+
+**Voor** — basale asusctl-bediening zonder Armoury-instellingen:
+
+
+
+**Na** — volledige Armoury-instellingen zichtbaar, inclusief PPT/vermogenslimiet tuning:
+
+
+
+**Bronnen:** [Phoronix artikel](https://www.phoronix.com/news/ASUS-Armoury-Driver-Linux-6.19) · [Community discussie](https://www.phoronix.com/forums/forum/software/linux-gaming/1593500-asus-armoury-driver-set-to-be-introduced-in-linux-6-19) · [Patch series (lore.kernel.org)](https://lore.kernel.org/all/20251102215319.3126879-1-denis.benato@linux.dev/)
diff --git a/content/docs/security/_index.md b/content/docs/security/_index.md
new file mode 100644
index 0000000..ea2c51d
--- /dev/null
+++ b/content/docs/security/_index.md
@@ -0,0 +1,7 @@
+---
+title: "Security & Privacy"
+weight: 20
+toc: false
+---
+
+Guides for hardware-backed authentication, disk unlock, and login security on CachyOS.
diff --git a/content/docs/security/_index.nl.md b/content/docs/security/_index.nl.md
new file mode 100644
index 0000000..7a1ba86
--- /dev/null
+++ b/content/docs/security/_index.nl.md
@@ -0,0 +1,7 @@
+---
+title: "Beveiliging & Privacy"
+weight: 20
+toc: false
+---
+
+Handleidingen voor hardware-gebaseerde authenticatie, schijfontvergrendeling en inlogbeveiliging op CachyOS.
diff --git a/content/docs/autologin.md b/content/docs/security/autologin.md
similarity index 100%
rename from content/docs/autologin.md
rename to content/docs/security/autologin.md
diff --git a/content/docs/autologin.nl.md b/content/docs/security/autologin.nl.md
similarity index 100%
rename from content/docs/autologin.nl.md
rename to content/docs/security/autologin.nl.md
diff --git a/content/docs/yubikey.md b/content/docs/security/yubikey.md
similarity index 83%
rename from content/docs/yubikey.md
rename to content/docs/security/yubikey.md
index 0bf9ddd..a66d310 100644
--- a/content/docs/yubikey.md
+++ b/content/docs/security/yubikey.md
@@ -3,9 +3,9 @@ title: "YubiKey 5C NFC"
weight: 20
---
-I wanted to use my YubiKey to unlock the LUKS-encrypted drive at boot — plug it in, touch it, and the desktop loads. Turns out that's not really possible right now on Fedora 43. I spent a fair amount of time on it before giving up for now. This page documents what I tried, why it failed, and what actually works in the meantime.
+I wanted to use my YubiKey to unlock the LUKS-encrypted drive at boot — plug it in, touch it, and the desktop loads. This page documents what I tried, why it failed at first, and what actually works in the meantime.
-> **Status:** LUKS unlock with FIDO2 is too unreliable on Fedora 43 (systemd 258). This page documents what was attempted, what the root cause is, and what to do instead. Revisit when Fedora 44 ships with systemd 259+.
+> **Status:** LUKS unlock with FIDO2 has been unreliable on systemd 258. This page documents what was attempted, what the root cause is, and what to do instead. The situation may improve with systemd 259+.
## What Works Today
@@ -89,7 +89,7 @@ sudo dracut --force --regenerate-all
## When to Retry
-Wait for **Fedora 44** (expected to ship systemd 259+). Systemd 259 adds `token-timeout=` as a proper crypttab option, which gives a configurable wait window for the touch prompt. Combined with a fix for the fallback regression, FIDO2 LUKS unlock should become reliable.
+Wait for **systemd 259+** to become available. Systemd 259 adds `token-timeout=` as a proper crypttab option, which gives a configurable wait window for the touch prompt. Combined with a fix for the fallback regression, FIDO2 LUKS unlock should become reliable on CachyOS as well.
When retrying, the enrollment procedure itself is correct — only the systemd version is the blocker.
diff --git a/content/docs/yubikey.nl.md b/content/docs/security/yubikey.nl.md
similarity index 84%
rename from content/docs/yubikey.nl.md
rename to content/docs/security/yubikey.nl.md
index 14fdbc1..2101545 100644
--- a/content/docs/yubikey.nl.md
+++ b/content/docs/security/yubikey.nl.md
@@ -3,9 +3,9 @@ title: "YubiKey 5C NFC"
weight: 20
---
-Ik wilde mijn YubiKey gebruiken om de LUKS-schijfversleuteling bij het opstarten te ontgrendelen — inpluggen, aanraken, en het bureaublad laadt. Bleek dat dat momenteel niet goed werkt op Fedora 43. Ik heb er flink wat tijd in gestoken voordat ik ermee gestopt ben. Op deze pagina staat wat ik geprobeerd heb, waarom het niet werkt, en wat er in de tussentijd wél werkt.
+Ik wilde mijn YubiKey gebruiken om de LUKS-schijfversleuteling bij het opstarten te ontgrendelen — inpluggen, aanraken, en het bureaublad laadt. Op deze pagina staat wat ik geprobeerd heb, waarom het aanvankelijk niet werkte, en wat er in de tussentijd wél werkt.
-> **Status:** LUKS ontgrendeling met FIDO2 is te onbetrouwbaar op Fedora 43 (systemd 258). Deze pagina documenteert wat geprobeerd is, wat de oorzaak is, en wat je in de tussentijd kunt doen. Mijn advies: opnieuw proberen als Fedora 44 verschijnt met systemd 259+.
+> **Status:** LUKS ontgrendeling met FIDO2 is onbetrouwbaar geweest op systemd 258. Deze pagina documenteert wat geprobeerd is, wat de oorzaak is, en wat je in de tussentijd kunt doen. De situatie kan verbeteren met systemd 259+.
## Wat op dit moment werkt
@@ -89,7 +89,7 @@ sudo dracut --force --regenerate-all
## Wanneer Opnieuw Proberen
-Wachten op **Fedora 44** (verwacht met systemd 259+). Systemd 259 voegt `token-timeout=` toe als crypttab optie, wat een configureerbaar wachtvenster geeft voor de touch prompt. Gecombineerd met een fix voor de fallback regressie zou FIDO2 LUKS ontgrendeling betrouwbaar moeten worden.
+Wachten op **systemd 259+**. Systemd 259 voegt `token-timeout=` toe als crypttab optie, wat een configureerbaar wachtvenster geeft voor de touch prompt. Gecombineerd met een fix voor de fallback regressie zou FIDO2 LUKS ontgrendeling ook op CachyOS betrouwbaar moeten worden.
Bij een nieuwe poging is de enrollment procedure zelf correct — alleen de systemd versie is het obstakel op dit moment.
diff --git a/content/docs/virtualization/_index.md b/content/docs/virtualization/_index.md
new file mode 100644
index 0000000..3227ac5
--- /dev/null
+++ b/content/docs/virtualization/_index.md
@@ -0,0 +1,7 @@
+---
+title: "Virtualization"
+weight: 40
+toc: false
+---
+
+Running Windows workloads and GPU passthrough experiments on the Zephyrus G16.
diff --git a/content/docs/virtualization/_index.nl.md b/content/docs/virtualization/_index.nl.md
new file mode 100644
index 0000000..a976464
--- /dev/null
+++ b/content/docs/virtualization/_index.nl.md
@@ -0,0 +1,7 @@
+---
+title: "Virtualisatie"
+weight: 40
+toc: false
+---
+
+Windows draaien via een VM en GPU passthrough-experimenten op de Zephyrus G16.
diff --git a/content/docs/looking-glass-attempt.md b/content/docs/virtualization/looking-glass-attempt.md
similarity index 94%
rename from content/docs/looking-glass-attempt.md
rename to content/docs/virtualization/looking-glass-attempt.md
index 440f2e5..008f3b9 100644
--- a/content/docs/looking-glass-attempt.md
+++ b/content/docs/virtualization/looking-glass-attempt.md
@@ -5,7 +5,7 @@ weight: 21
I wanted to try GPU passthrough with Looking Glass — running Windows in a VM but with the real NVIDIA GPU assigned to it, getting near-native performance. Spent a good few hours on it. It doesn't work on this laptop, and the reason is a hardware limitation that Looking Glass can't work around. I'm documenting the full attempt here so others can save themselves the time.
-> **Prerequisite:** This assumes you already have a working Windows 11 VM set up with virt-manager. If not, follow the [VM Setup Guide]({{< relref "/docs/vm-setup" >}}) first.
+> **Prerequisite:** This assumes you already have a working Windows 11 VM set up with virt-manager. If not, follow the [VM Setup Guide]({{< relref "/docs/virtualization/vm-setup" >}}) first.
> **TL;DR:** Looking Glass does **not** work on the ASUS ROG Zephyrus G16 GA605WV. The RTX 4060 has no physical display outputs — all ports (HDMI, USB-C) are routed through the AMD iGPU. Windows can't find a "valid output device" for frame capture, so the host application fails immediately. This document describes everything that was tried and why it failed.
@@ -165,15 +165,15 @@ git submodule update --init --recursive
### Installing dependencies
-The dependencies had to be discovered one by one. The complete list for Fedora 43:
+The dependencies had to be discovered one by one. The complete list on CachyOS:
```bash
-sudo dnf install cmake gcc gcc-c++ libglvnd-devel fontconfig-devel \
- spice-protocol wayland-devel wayland-protocols-devel pipewire-devel \
- libxkbcommon-devel libsamplerate-devel libudev-devel nettle-devel \
- desktop-file-utils libXi-devel libXfixes-devel libXScrnSaver-devel \
- libXinerama-devel libXcursor-devel libXpresent-devel libXrandr-devel \
- libdecor-devel pulseaudio-libs-devel binutils-devel
+sudo pacman -S cmake gcc libglvnd fontconfig \
+ spice-protocol wayland wayland-protocols pipewire \
+ libxkbcommon libsamplerate systemd nettle \
+ desktop-file-utils libxi libxfixes libxss \
+ libxinerama libxcursor libxpresent libxrandr \
+ libdecor libpulse binutils
```
Missing packages per build error:
@@ -408,7 +408,7 @@ Restore VM XML via `sudo virsh edit win11`: remove the two `` blocks an
Looking Glass is an impressive project but requires hardware that is simply not present on the Zephyrus G16. For Windows applications on this laptop, the best options are:
-- **[virt-manager with VirtIO + SPICE GL]({{< relref "/docs/vm-setup" >}})** — good performance for office/productivity (see the [VM Setup Guide]({{< relref "/docs/vm-setup" >}}) for configuration details)
+- **[virt-manager with VirtIO + SPICE GL]({{< relref "/docs/virtualization/vm-setup" >}})** — good performance for office/productivity (see the [VM Setup Guide]({{< relref "/docs/virtualization/vm-setup" >}}) for configuration details)
- **Bottles/Wine** — for compatible Windows applications
- **Native Linux alternatives** — when available
diff --git a/content/docs/looking-glass-attempt.nl.md b/content/docs/virtualization/looking-glass-attempt.nl.md
similarity index 94%
rename from content/docs/looking-glass-attempt.nl.md
rename to content/docs/virtualization/looking-glass-attempt.nl.md
index 7b0aaae..162ec48 100644
--- a/content/docs/looking-glass-attempt.nl.md
+++ b/content/docs/virtualization/looking-glass-attempt.nl.md
@@ -5,7 +5,7 @@ weight: 21
Ik wilde GPU passthrough proberen met Looking Glass — Windows in een VM draaien maar met de echte NVIDIA GPU toegewezen, zodat je near-native performance hebt. Ik heb er een flink aantal uren aan besteed. Het werkt niet op deze laptop, en de reden is een hardwarebeperking waar Looking Glass niets aan kan doen. Ik documenteer de volledige poging hier zodat anderen die tijd kunnen besparen.
-> **Vereiste:** Dit gaat ervan uit dat je al een werkende Windows 11 VM hebt opgezet met virt-manager. Zo niet, volg eerst de [VM Setup Handleiding]({{< relref "/docs/vm-setup" >}}).
+> **Vereiste:** Dit gaat ervan uit dat je al een werkende Windows 11 VM hebt opgezet met virt-manager. Zo niet, volg eerst de [VM Setup Handleiding]({{< relref "/docs/virtualization/vm-setup" >}}).
> **TL;DR:** Looking Glass werkt **niet** op de ASUS ROG Zephyrus G16 GA605WV. De RTX 4060 heeft geen fysieke display-outputs — alle poorten (HDMI, USB-C) lopen via de AMD iGPU. Windows kan daardoor geen "valid output device" vinden voor frame capture, waardoor de host-applicatie direct faalt. Dit document beschrijft alles wat is geprobeerd en waarom het mislukt.
@@ -165,15 +165,15 @@ git submodule update --init --recursive
### Dependencies installeren
-De dependencies moesten stuk voor stuk worden uitgezocht. De complete lijst voor Fedora 43:
+De dependencies moesten stuk voor stuk worden uitgezocht. De complete lijst op CachyOS:
```bash
-sudo dnf install cmake gcc gcc-c++ libglvnd-devel fontconfig-devel \
- spice-protocol wayland-devel wayland-protocols-devel pipewire-devel \
- libxkbcommon-devel libsamplerate-devel libudev-devel nettle-devel \
- desktop-file-utils libXi-devel libXfixes-devel libXScrnSaver-devel \
- libXinerama-devel libXcursor-devel libXpresent-devel libXrandr-devel \
- libdecor-devel pulseaudio-libs-devel binutils-devel
+sudo pacman -S cmake gcc libglvnd fontconfig \
+ spice-protocol wayland wayland-protocols pipewire \
+ libxkbcommon libsamplerate systemd nettle \
+ desktop-file-utils libxi libxfixes libxss \
+ libxinerama libxcursor libxpresent libxrandr \
+ libdecor libpulse binutils
```
Ontbrekende packages per build-fout:
@@ -408,7 +408,7 @@ VM XML herstellen via `sudo virsh edit win11`: verwijder de twee `` blo
Looking Glass is een indrukwekkend project maar vereist hardware die op de Zephyrus G16 simpelweg niet aanwezig is. Voor Windows applicaties op deze laptop zijn de beste opties:
-- **[virt-manager met VirtIO + SPICE GL]({{< relref "/docs/vm-setup" >}})** — goede performance voor office/productiviteit (zie de [VM Setup Handleiding]({{< relref "/docs/vm-setup" >}}) voor configuratiedetails)
+- **[virt-manager met VirtIO + SPICE GL]({{< relref "/docs/virtualization/vm-setup" >}})** — goede performance voor office/productiviteit (zie de [VM Setup Handleiding]({{< relref "/docs/virtualization/vm-setup" >}}) voor configuratiedetails)
- **Bottles/Wine** — voor compatibele Windows applicaties
- **Native Linux alternatieven** — wanneer beschikbaar
diff --git a/content/docs/vm-setup.md b/content/docs/virtualization/vm-setup.md
similarity index 97%
rename from content/docs/vm-setup.md
rename to content/docs/virtualization/vm-setup.md
index 8027190..e8df41a 100644
--- a/content/docs/vm-setup.md
+++ b/content/docs/virtualization/vm-setup.md
@@ -5,7 +5,7 @@ weight: 14
Some things simply don't run on Linux — Microsoft 365 being the obvious example. For those cases I set up a Windows 11 VM using KVM/QEMU with virt-manager. With VirtIO drivers and SPICE GL acceleration via the AMD iGPU, performance is good enough for everyday office work.
-> **Want GPU passthrough?** If you want near-native GPU performance in your VM, see the [Looking Glass Attempt]({{< relref "/docs/looking-glass-attempt" >}}). Spoiler: it doesn't work on this laptop due to hardware limitations, but the documentation may be useful for other hardware.
+> **Want GPU passthrough?** If you want near-native GPU performance in your VM, see the [Looking Glass Attempt]({{< relref "/docs/virtualization/looking-glass-attempt" >}}). Spoiler: it doesn't work on this laptop due to hardware limitations, but the documentation may be useful for other hardware.
## Windows 11 Enterprise ISO
@@ -47,10 +47,10 @@ Use the official Windows 11 Media Creation Tool with an activation method:
**1. Install packages:**
```bash
-sudo dnf install @virtualization swtpm swtpm-tools edk2-ovmf
+sudo pacman -S virt-manager qemu-full swtpm edk2-ovmf dnsmasq
```
-**Note:** The `virtio-win` package is not available in Fedora's default repositories. We'll download the ISO directly in a later step.
+**Note:** The `virtio-win` package is available from the AUR (`yay -S virtio-win`) or you can download the ISO directly in a later step.
**2. Add user to libvirt group:**
```bash
diff --git a/content/docs/vm-setup.nl.md b/content/docs/virtualization/vm-setup.nl.md
similarity index 97%
rename from content/docs/vm-setup.nl.md
rename to content/docs/virtualization/vm-setup.nl.md
index ffd176e..43a1dfc 100644
--- a/content/docs/vm-setup.nl.md
+++ b/content/docs/virtualization/vm-setup.nl.md
@@ -5,7 +5,7 @@ weight: 14
Sommige dingen draaien gewoon niet op Linux — Microsoft 365 is het meest voor de hand liggende voorbeeld. Daarvoor heb ik een Windows 11 VM opgezet met KVM/QEMU via virt-manager. Met VirtIO-drivers en SPICE GL-acceleratie via de AMD iGPU is de performance goed genoeg voor dagelijks kantoorwerk.
-> **GPU passthrough gewenst?** Als je near-native GPU performance wilt in je VM, zie de [Looking Glass Poging]({{< relref "/docs/looking-glass-attempt" >}}). Spoiler: het werkt niet op deze laptop door hardwarebeperkingen, maar de documentatie kan nuttig zijn voor andere hardware.
+> **GPU passthrough gewenst?** Als je near-native GPU performance wilt in je VM, zie de [Looking Glass Poging]({{< relref "/docs/virtualization/looking-glass-attempt" >}}). Spoiler: het werkt niet op deze laptop door hardwarebeperkingen, maar de documentatie kan nuttig zijn voor andere hardware.
## Windows 11 Enterprise ISO
@@ -47,10 +47,10 @@ Gebruik de officiële Windows 11 Media Creation Tool met een activatiemethode:
**1. Packages installeren:**
```bash
-sudo dnf install @virtualization swtpm swtpm-tools edk2-ovmf
+sudo pacman -S virt-manager qemu-full swtpm edk2-ovmf dnsmasq
```
-**Let op:** Het `virtio-win` pakket is niet beschikbaar in de standaard Fedora repositories. We downloaden de ISO direct in een latere stap.
+**Let op:** Het `virtio-win` pakket is beschikbaar vanuit de AUR (`yay -S virtio-win`) of je kunt de ISO direct downloaden in een latere stap.
**2. Gebruiker toevoegen aan libvirt groep:**
```bash
diff --git a/static/icc-profiles/GA605WV_1002_104D158E.icm b/static/icc-profiles/GA605WV_1002_104D158E.icm
deleted file mode 100644
index 62bf577900b2764b473339e265371b942494abd2..0000000000000000000000000000000000000000
GIT binary patch
literal 0
HcmV?d00001
literal 3324
zcmcha3piBk8ppr2=4uSN-!J19GMI78eZshvVRDxw#<+wrjUgkuRHW@vbXT%>*^xFC
z?Gn*ODix)z(!EsJB&8CS!&!^HpPciY_CBYl=e*Ce*8JA{{lE8nzqQ`^*0%s4PqO^n
z{9y_Ji9Dge*WH;C9I}i;_#Hq%6UYJupcuhP=A#;bn3G?C9}O{-|1b!E_qP!>V%^4Q
z`=1T}<*$4cH<<$fl!@q5IDCN+;R%FIqY`;h0Kf(ahestwp}YmvB%~z90f0de$gL6b
z5j{o@<;eIMM)h)>1T+rD9^rKYWI_lxqW+j!?wZlh@^h30{=P1V1{oJ7$ILJui*n=)
z6Qxk*^I{SKAgLkx<$Ruyk8m2war7C!iEtR7gXSP^F{9x`MIu~?GA9x3D?W^HhC7SJ
z27nxk@b=lcBLsjddhf#BovdhJpI<7b%Dkaw(A_
zijxbAO)&^GGch-z8UAgU|56`k$Sk{;0($fA+myI#bt>LdRzxK(jy(pV=BidjO0t
z7b(xbFsByv007(tTrTe~RQh{DA7T$WC!`>E{L3bzi+|5`n49OOeE`_zqCGz6=_3t5
zT{Qq=q|ZKGBLF1Y0k|UKqzF=HM?n6#I=}!>0S#CJ8{hz(fg4y1e1Jb#4!D31z61H-
z05}0IfCpdy#B~U!H6{>~q!Z1vQL*N|v3_OIv6eO{ZC
zi&UGmhjgcmzsy6~SlRb-+42hVl?sjuw-k9wVoDXtZps5HxvDhP9<@w$s`@>RTulef
zQA(v&q_&3k1Dz7xa6MhU;rXZavkd$V^$q{A;I>gMwa}Pv;%90@qtHq8akGB&9*e7%
zEmmh2p0Td8X|Vm(?xKB{!vn`5#wRC9XB`(?rk^X%EzkXDj}Fh*OXR)mSyA2vK4;j^
ze5L#x{SyO91G|FpA&g}ip-o}X3Xkv|E1yKtIoVP7qb*~KVqdRX8h&c9x-;Zx(yb2ZIHt;ub{
z7a8paR}?ykozvGRZj5!0-THV3+#@`Yex&?_@>K7+VZXueIz!6Cq?co_?u|CQ-8Hsq
z-1Y!+o`bI;Km=bx
zIbo9MN30ejibacEAnB8GNw39 PQzap&IB+J@6(x-r3zqHR!#(z;jV&H+G
zYay6rwxP+(PlUY+r>{(nXyOo~0=VVTA7j~ZmGQU)PU86_eg4+fAChB)cT-tw+C+@>
z#ti%Kn%BE$c5MvZG?<;1L)ucBYmwJc5WNj9JhYv;V{ljD9_zim`*KUH4)p!7`=DnT
z_^G};^@wHV#LrFD*~fiq)N4n6X*s>;48Os<(d?W`GofYt{NRNLm%1*uUp?R1e7)ty
z`R?{x*LrT>eRO}|;mG4Rz3-mA>l+<-G5F*~*UQFNKaJ+R<&H7N$jl>?pKF1m2l5ll+81IcQ!4DG{gdK!Iq7!jHaa=4w>=a3n
zw3gH>?kQeN)*$DTKS?A?^hyRwb|R}ns}w`(oHRqaRmNTBnrx74uN+TqQocYzQ{kkd
zr(&;ChO(0KX_X+A52~eVOtqKldo^4yG^p;|IpSG99=Ty^ofSM&?!{DFhNofP`K`k!FC`1SQrb-ATn40(Lo1f-UH{z?%AE$-NRq|JLe^z_q)IQy}#V|d-vV|
zAm8N|>=gpj0Z2-gh=W)j^sw*005(g
zFm=5|gv4VQD032L*bQZ_5Y@q;IcJNJAB6Bd)E_^~FHq*p@+8XQkRVS0u*kSDDSn3W
zS}1d7m|%jkC^
znVW>_kYW+eWcm38Ap8@;`^0=SULMf}(X(@c5CEF!oW`)+?U{C=t7EK~OzRj&8(U9X
zEB9qH?eqE};b$N@0N|M-l8OcK2@(cflE9~P#eB9TMNChLLv97BbdfkEP9Wq1Fegvk
z|M2YpGWR+9nx1T-fFov0_;ikx?(XRqKsQ-!ZDC`28;hxP!NAU;yIe`4PDdfx-U67%`Ve-cG^3A=&m_7J8aGyd<5
zQjXgghh*?2rxGjVNoJxwzWCfy0XUlnfK2TdpPn^R%M$=}5V>jM^w|-R7n%gfKnc)*
z8qfr~Kp&U@OW*+9fiH*v0w4vu!BNlzZiD9#1nEF7P!zNgIu5l%qp&8-f+cVj+>Ie%
zTrd($J!TMVh~;3bumd<#oCx;~9>)9Q%kVE{TxIsk3=)qs=x7SgCZNB*9|3WXN3Be{`cL8(_{C^jfrD_u}tqI`oIOnpX6Q2{DNswS%6sfDVI
zsqfLS(CE@k)l%1L)lSq=)48rIrJK|H^~&@^4X6fp4NDe;8_|u1jGIihnueGen@uh3
zW}Gq4w-8$TF_~5>R#Vo`ZSL59XLri}s6&xsuG8j48=Ny1r@N%PN|$80ZFA4_*zb9K
z>A7WXUXNI#D~R64J}ln^zkL65E1v`sgPentLyoU{9I74`9$p?X5Xp?%6#ZkY340T#
zm*>Pk6gQQ?7F7nUS_N?9wqFJ`4Sr!mqiGc=?n8YLoNk_N@`yhIeG;kaH_{+vnXXh~D#dZ*GxZ
zadT<#{*i-)hi%GwkK|N19eY!CqFPX6S^Hbv?fS|F>6ySrvvatnz6;+sS67u%mOkTfV9iW^?@%J+@asKHyg
z@mKFVCr*CcKDp+TM=M_v9j*w~O0t$h$T@jr!>E(WQD!y%+jb25dt;
z!~O*)jMf=1Hjy*wH9c*%V_^)#*<9WHgGH}p3$xlP-+H|b$2P#u&EDF<*iqL>Z4u2`
zc`?;R%~gBJ0yn1nVh_V}@LZRbLLjzBH0EwsKtg-Q8dJeDM1CakB1H==AiQ
zJsCzej(N4Y+Q{ZLuQo>;V>RF6NTzf2;rW*TKhV~cPh(qxohWo>!YQ
zXO1=uCS&Ftor?U!LC0cP&)zTfToGV17iuY#qE4yH3TyE|S*rqq)Dw`kib@r$NM%{=B(#ropWSwMANoE|lHa`Z|Nh@QGw;lN0iaI$
zhj=YUSpaG2S<+x{cUE{rB#Sf*2xwWIB}*304c%r*&>NF3*(Fph~!i<9wsnI<(mEeQaJAuw{Y
zB$yt@ka28^oMn23C{^Zzn}>0c6gwb{TV?r#DejW%r}(jqrHg|FmO|gBF%_TN)-c4tCR45T;o5ieVV_vK$w~oD-~vm
zS+RL6H-Uc;%Pfp*&9k;O|3jPqSs?56Uk9O91+r@kpK_y%rl%gnh~xxdSL)2e`%*WlM9WX25P-F4%)JxPv$NK`<LYW=o5>>z{t8DG8H)LeLli&C87iAvOC!+=XroFAN(0J~%6;?@
zdXLItl|I!d)kkWHYOfiE>SXm=4HJzf%>|kdW=XXawe~Vynf=;DIxL;bx+!`Ly*B*}
z7K_zuu+h-d2r+6iUTxydR$|{XJ!qC^9x$72fm#e&Ua;C{y~!rWHkK2}b>(sAu=%=n
z8go_c=?-*9H7Ct^I?hHemh<_pu5SMBQG#TT0?*A}yS>XMdc52D%2wr4<)Rkz>Woa>2g~qXKM9;;+@!up`CDo-+Q&**pX2eVSr4gC8
zvx9TGR|e58%
z-Jx9Hwk!KDmV1Wx9Xyb6$oUAp;rqsxW7Q{;PYIgznkUcpw_N(`p>L`#C`7918*sJv0lRh?8TV^A5j
z>IUkK8qOLwHJ59?omHV_pw+?*W4_g{(c$ad)h*F8*Xz|UWARu|4R#oY8L1d`8CRKv
zv31$QrcGw+&6m#RThJ|DS$0{Swyv{TYb)glxxqZoIZk|@o%LJ`dkY6EM~>6nc`nZ0
zE{oO)y*>g(wz_Fo%tIIt_|eXvnT(BhKN6Jbxo4I*M9
zcSj9J^OmiSxh=GaEf+l!yT>0$R7%Q89!&L3JCk81sgtT^ZpVcZlTB9u;+tRmd)V0;8?$X|UeNV|g`~71F
zn-3Q?_%x~?9XfveWa;UUX0x;Cxxv<<%2mufR
z;SeovLPQzVI$PSUN{Nua0gx@1VkTkM8c7k$XCdD69Bo5?#IbQp
zaW%M3JO%HAufSg?&hbpV6l7ul_(IRpWzZ^(?bl7qp_Z
z#+kL+cG~xJigitOyY-6nt@Q_4UmExs5)CgKl^J`PP)&N-yG%38+{`u1U(UW}amcd5
zD&0EN#>Lj0qroL`-|?Q!>F3|J>zw2aO$
z+=OjONOE#YZ<>4haf$JYuQC}~l{vKB$~;DXeWAsw*5aU&XRBA2>#jMsE`0rX#nw%Z
zn;%vdR~c4csY$L?-g0_d^mbz1iF)BK)!prT3isLVe|PZQ;j)InMxCQCj<=rNd|KFS
ze^&L}Xlv*BV{O$JbFfZu@36Qw>pJ!*mL3TSpE3&_xcm}C%^pQ`|;zncQPt_>CI$J_qLr$W6W!sH;yyY
z=D+nvIe%X5f2Ow~$MWAUG-Cw*9-dy-Ng`~qI-@b|n%MI!Z7t<%-AwG?hHNfN?$ox2
Zz$b_&Pw;+8BxOocg?UrS8LdZV_A|b?2r2*o
diff --git a/static/icc-profiles/GA605WV_10DE_104D158E.icm b/static/icc-profiles/GA605WV_10DE_104D158E.icm
deleted file mode 100644
index 03f05ff539d7329226da441628b60fb2c740f339..0000000000000000000000000000000000000000
GIT binary patch
literal 0
HcmV?d00001
literal 3324
zcmcha3piBk8ppr2=4uSN-!J19GA`qm`-E{T!{jbWjB&{r(-<)KG=VHo0E&_9WIn0^h&lTQ`kNt!@*f5P@cuTUMy%Ty
zZU3|3zx=kl8UWY;;fUzOXq3008g5ErJOCI3f!rD)
zAJJpvP>xENVN@^2=Av;h4hXLkAQM8k5%tH;a@UN0mY<_62=H@7G|0FxId+EeSd^n?
zm?(uZpBI}507(teFX!`we1y|bj;GD=O@zbwY%~XP%NY$jItt-Jl-Y@BU-4mtGd!3~
z769ZpgtyPm9U%Zz(R&x+;cRVY6&w^nGh?_RCrbv+%EoP`{hOYIoHQg)09=#!B0+p?
zoRCTp#&IZY0Vh(JB%mb4AeZsU6uuxSCZ5XyU{0R6uXx6PoBN#js;-gT_$Wc7kVAW^NG@@L=Mr89L6DRg}H0W=Hr@SUwOv>>7`3pWM1<6kxzUHp5F$q?E}Cr7wz#mPhV*O
z>Z$<{BYpPi8UY~D4!{)=J4KK>I|A~@)d2>83e12Numz651-OI7z!wC7<$weD;5(2H
z4uBKj0(bz%pm`7#S^_0NTcKL$E)2s|I26u-&%i?%O-vAGE9Np5hh<>1v6paUoIkDv
z*N?ZrZ^U;K<`dEhH;4;}*~F(}&SHm1IMOQ84RJg1!(>_VM)F&U7>WCmev%#YJm$4Y
zxk|N3drEi81jsy;jgx&Zmo2X#U#Z}va7&S=B&JlM?5;eZlB;T_+M|}KPF26Bk*n#b
zIZCP2iqh85exOsL8=KtpQ51~>pZV1OmSAB2NAkOH#6PEZaSKo=N*0Hg}p
zK*7)&s2FO3p26am{%^EyS4b3h}mX^KNJMH5-
zTwSW}h+ge{k-n>el))3j+67yTR#NSam5e7$?wS5-RzcftzTSdo8EF-4&05H`VcN3n
zg6tz45**W=^63W`)jM~)ykbbWQQdt!R(tODYFgaqEy=X;iSjLA)i3SymkC%Dm>6^*
z_*y7tnO#`&@)O~&B4{g9Bb(U7=s-?+%*QxZd}RWT%T7F>q|e{F`a^Q8@NOz|O`C|G
z-k9O=UGsX6%&v`Ln+CJfa!6ZBb1m~a3Szdwg@?8?b`0(+++(x1cVBLa^?|-0b|3UA
z13%T5ryjAYocOt^I{Ub9je70KFD<9{oZ&b4G@74NX(qIcpC7#N;8NG+_N(VRo3FRr
zIN#lV>srt4yN~VZj41x12HhxZFhF$J)uYQ}lnU
z1rOxevygQl6s!PIAQmJbt3e8~9&83hpcGVrCZrPjz$7FGnL^&sDku-ChJJ%4U@dqF
zoCcS}Js2^J6Gn)s#tdL}uu<4U*ylJyToSGh5959CCHP?iov?#2NOUIdCyt8+ik%`U
zlGc)X#l6I9$r|K*@+XNziC)Pd$xdWdXqBQ%os*_Zx5{|PT$2r!?Um!nP0AN2Xeyjk
z^iu3q%1~BPKCKe0@#BB+j+-uC_ljQO{7`*8{dWcz
z4fiidHu9w!8%r9$F}Y*fVpdJtZ=P?FX_;!px8^S7+VE_Jb{Y0L4!ax=JDs6-F6wsy
zuBr@Mw-EPqj{}~qUV}@dz3rGBpCaFLtYJSjfA4^Gfi*#WA!?z4%ZkFf!lhOOL=>;=
zjiRze(d{uRu}N_kS7{`OxVL#$NqhNIg1F?HDU8&*G-FZuTAhrtb@SI(Z?N9jn&q4Q
zIA`_uxZM5u76qN#;)@8|D|dSDdc9|NF@4`)$*xkjAI1+>m2nPhmp?sHaWtvQ{uuFi
zPtB2&YfrK2^y{I9$BixLDw?;oirUy0ecJ7=7<4FK6Td!nW3;>f*2A9eyO-{teOUFl
zxHs!rLLX~@HYhRFKin{q_d4{A&fB4}W8=IJMj!hoOQw9Mr{}zrVe>D)j=rj8Zfvu!
zity!5b7Es?-#R!l?40;8?aOI=Rm=Y=wlyP3#u7)
nX0Mx!d~Kj(QO#$s8LnO|iy4Q-ACCBBJ~vV{>-?tqpuzqL{pl)3
diff --git a/static/icc-profiles/GA605WV_10DE_834C41AE.icm b/static/icc-profiles/GA605WV_10DE_834C41AE.icm
deleted file mode 100644
index 441cd2870f71040f87fdeeb012cbedf07987fa7d..0000000000000000000000000000000000000000
GIT binary patch
literal 0
HcmV?d00001
literal 3536
zcmds)c~n!^7KiuEKmthsnF$DCo@=BV#NW|7q
zU$AEgh6W%=7mI?t+-Ttuku<_EAfN;QRA9t&GKG>D^bVN8p~04DlklGn0hs7TqtVu5
zF7f~6_#dyTTwW#z0I5Rbvp7PL7yu)WvISR=&PCZ3(0&>w{I4T(KzhKD7bFvD*pED8x?0pQSaG32CameQ1P
z!ZZ_&B`i!&5&+29qVZ9}bg>ZS%@XEYP4fuK(Xq)~5dg_|I))?3htxR3+ynqJPQo04
zM28%Qa=w?JUjWJjC~pz*B=Hnf7h-1S1SJ3s$(+V|G3Qy@vBP4mEZsd~9c*k_wpL7!
zY5!;a67!a$IRLOSgt;PqQnHv%6DRX%91$;GoFSrRB%-(cOqx)Xk;qTu0nEx1{|RgV
z!Q5x*Yp~+e_z9wTF^`szOJlP90%*oz)(jhlrO5|nJ~}}14E)sz;dafh-zAKtH&d+LQDEY!DAE+rMdxs5(agyhJ=+`rky+IN{ycUbnO?bjIJ`ElQaxFoTtptF
za4CJV0kWNPEV*`hXZe$JT;`lr@KU&<$W|OwN>ln>xm1O!(yZ#L+N+kXPE>E8GO2?a
zYc!2CyXIzV>1bWiE~Ht}9_rNSvh@`8y7emz*oIn$!$xh!>rBE;8D>PY2lTV%^^6h=
zfn}(bt2Nz*YD==6v>Tr{V*kitX#UWGhYNpoeBt!c1zbr?H8(?+y}P$Zl&8pRgLi|^
znML<}5kGx@?1H+2h?csk!x-Kn=>WR^h&5i3$U~tN~FA~F&PV-Gt
zDpIEeg7g8Q|FR!59mQ?gRyhZ9tyZ+x7;!?&H2NmEn*Rtp%w0}*6^0`j1Y?g~0!0yf|Rz7Pp1kPn-n
z0ggjAj37kB0C7inND1;Savgb%(Z%>-R$!VieONNq6`PH1!4Bi}aPhc0+#p^b&&MCc
zzmj4}ZIb$#z#tS6ZV*k0tBC{B4$@yqPsoJJoFM6tN=akn81f~`LQ1nNO}0{wB3B}h
zkuQ>;nzKp)r?5d$L2-wYky4wohw?3zR8>%|QnOLJs-8}jr5@5?YfNf3&JESVX|-vm
z&}g(iol4zcJte(c`ZWeTLrcRyjJk|#O~j^)%?#)W{hoO{qu!#_QfL)n?O|hWt81q?
zk1%i2e!^jN{__RT7Cv_zb9(7K=}KTKxM{P@-JLxAJ>$Kyyf^wZEIPgTw(o0y>Jq1b
zguv3E!@+k$Wy4(9;_#M;CrizvGNVt%lH#J{4|B*|KCd&$Jh_7ZCY76ZE!{bzWtq09
zLQKdi$R1ywp8GhDmw&&IvvO!v^6IB+vx=dltaR>%0~=Xo{hKn&Ww$hM^{X7+wym1E
z{n^f4yMpUTyD!uif9v|PzdF)7fwMhj3N}o3|Wi_kj+RN
zGJwHjEHP1-4VdGY5iAWGiY>#Q$00apTmkMB9`GLcFYrB5bEWuFM+gK$1fiLTAx02e
zr76-W(w#DyT&4pPJ)5r(MBap;IwX@wQT;
z(zx;(6=ju1RcFWD_Uri13-+%m0&S|i%Ev``(2&PCl~Jx_h2ewRU|
zVVn`eXv(<9WS{9;vpBk|xef!*7_qo%*>1Jpy2fUc?OMD1dD-@2hphRz3sx>%@3_@z
zk8`U_higA`lqK!1@8Rkh?N#7i>vL|=u&!TjW*v77oyOChbDdOHvoS#&k{3azX^}N6$eY=pjY=!8Vn45JcCw%$M6`^^z3Ze?{
z7YSCqTC;YYLh+vUwxt)ph}rnhFTdPuT;5T^t0a82uPUJW)sFg_kXmBh**z;8nBNfg
z_B1too4Y^YfY~8p>+pA%zCU!d`grjVIj2(En1R@zWA26jvg85tq4}`F)wQpSB_D^O^P0iYq
zG1l+jjy}mVTifcB6yD!ymNwSvbBm+H&eF$xZu$QMZCxw+e?7#;vi#gVJQ;k>^g-qQ
z%lFZqS##!KL${<)pQAI;e>jq{=+-m$?kt}Gn`wj1p9X%WFfBfJ#`w`=eyGE&oN(5b
L^FI{+(f)q{zW^Cr
diff --git a/static/icc-profiles/GA605WV_10DE_E5090C19.icm b/static/icc-profiles/GA605WV_10DE_E5090C19.icm
deleted file mode 100644
index 1a7462db85bc8648b4f32cef00d05ae14dd50e65..0000000000000000000000000000000000000000
GIT binary patch
literal 0
HcmV?d00001
literal 3324
zcmcJS30M1Hmh(QiPARHp6AjlzN2m!(w!zG6tf){Ejl%iHd
zU2mm$g9>Z$Kv}B-g47d`wTem=t4L*8?F_V!bf4XJcOUvbPmNMZ+A|3L?nki1PJH?6BL0i6lF+p4PfCG5*lKI1
ziSPe)$A9^&7AMXS0U*VgK1(E(Wn%mj#@2DEX>kCkDaJ8zsc|^3$2BQgsS*GJhQQ3p
zlwx`U6X)3ENyha|Q3~!un1^wp3_BovcR$InJU~d@OYs;{tDg
z{~!QbBF0ry$Bq$z7Jlwxyxr_<_)EfKxHcZ1F`j%I2O9y`VRHYBer1YRVs!!t(xtgF
zNkU?#1t&96%n`}N!pw9TCp{k9lw@$Evh;XKiWp#8ouvQc8vkMK)BLpr!W2oYOqeO=
z#O89`1pYxB(=b~ro|TQ+AKLuS0=(CM9fVrudtb(;r
z2|J+yTA>GCAOwVsI3bZpKC%;OLw-OtPys4K_n^H5D#4wQPiP{H68Xd&VlxRL`H-qf
z19H}KMRK>uCgfG*UJ948nKCTzFMm{lsgS2INcE$hp&8R^=wy06eMB)qv0o`tsh1JL
z=vH2=+^Z6$@<=sN^)<6VjiOegZlvC*u|VU&ESaW)=3bU7t52&?o1=YMCz;J;x9X;I
zIGi56jryJjh(W92Y9nuBMdN!W2TgO$0%jYVqvit^7cBQ#ZL-d`iRA{`y7Fx281r@P
z)aR<$GaML>s!kg7w4DuHEavlFUETcMqXbDF`JS7-c6&E1=&OZGGN_YO!7tPE;i
z^fW|mv3F=e*r_G2BY2T{QCFfhmZipA6&l8_5j__N$A6P(DXC4SrL0OFNspKI$s#gt
zX9Z_>tqjiX&5tg4Qn;e%V@XA+UfHR&KI;ZHwof0&%nHZL6tKAOZ=Bx1OJI}@0
z+hx)GXxAjST=#Opc8>0v1Ou1V)yt1iHef!q=6LQ)HCU((ps5H#>OmCcF9U4w=7@2psJ8v
zRA1twAj#+3z1c
z*mStC-lswB=-~0=CreI;G?|`7&keL(Jio7X<3-u!s4HIWbFLX*XWwLXYTRP>Fncxb
zXx(E!(CgD5&>LhwW<60JB0hWjqW_1sR|j9Oexxkzh<%
zN~k7u5UE5TVma|Ti9uRI+DUpQ$CoRU>meJH^T?ePQ%WhNPkx?!t^5ZCp~6+F6?H3(
zK$Ft?>4Ef%igt?iN`^{x3>IUHvbypX6_!e!s-bE!f7Nx~?
z#M>rplORb+$vvs=X~(68E56ELW>#d=b1HI~d36Qmt6GYJil41sU8b|<+`91fW93^n
zIc|PfQBrU-MVk~3NlZuT>vKL~gL
diff --git a/static/icc-profiles/LS27B800TGUXEN - S80TB/SxxB80xT.icm b/static/icc-profiles/LS27B800TGUXEN - S80TB/SxxB80xT.icm
new file mode 100644
index 0000000000000000000000000000000000000000..05da48414b46e172ef505a7ac07a617e56c9e31f
GIT binary patch
literal 536
zcmZQzV3J?}0wx6phTOc8q9AuCg^0)~1@?yw%nW=CybKl$42j9b1-`*?8=g1H>*b
zDFBKw&H=HDLV|z}V%z{^3#3EX2SDs32>Swvom@}^QvU$Rwt(6NWHJZ@C*~HH=A|nH
zS5#KGW-Su!vPG9koN)-y2hYcen#*ntrH
zwhI!zmtvAji^`zxV`MUBU?9XVNv!~dAA@s#L1j^9dPa#xvZjKOfsv5{%=fN2smUcp
U`FWYi#R|^(dO8X|B`FLH06Ldcxc~qF
literal 0
HcmV?d00001
diff --git a/static/icc-profiles/README.md b/static/icc-profiles/README.md
index 5e211a7..499b1c0 100644
--- a/static/icc-profiles/README.md
+++ b/static/icc-profiles/README.md
@@ -1,46 +1,111 @@
-# ICC Color Profiles - GA605WV (2024)
+# ICC Color Profiles
-Factory-calibrated ICC profiles for the Zephyrus G16 GA605WV display.
+Factory-calibrated and manufacturer-provided ICC profiles, organized per device.
-## Source
-
-These profiles were extracted from the ASUS Windows driver package. I found them by reverse engineering the Windows driver stack and researching how ASUS deploys and applies the profiles. That work revealed the CDN hosting path and clarified what each profile actually represents.
+## Directory Structure
```
-https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip
+icc-profiles/
+├── Zephyrus G16 (2024) GA605WV/ # Profiles for the ASUS ROG Zephyrus G16 GA605WV
+│ └── SxxB80xT.icm # Samsung Thunderbolt display profile (external monitor)
+├── LS27B800TGUXEN - S80TB/ # Profiles for the Samsung ViewFinity S8 Thunderbolt
+│ └── SxxB80xT.icm # Samsung color profile
+├── GA605WV_*_CMDEF.icm # Factory-calibrated profiles for the built-in OLED panel
+├── ASUS_*.icm # Generic ASUS colorspace profiles
+└── README.md
```
-## Files
+## System Install Path
+
+On Linux, color profiles can be installed either system-wide or per-user:
+
+| Location | Scope |
+|---|---|
+| `/usr/share/color/icc/colord/` | System-wide (all users, requires root) |
+| `~/.local/share/icc/` | Current user only |
+
+---
-| Filename | Description | For GNOME |
-|---|---|---|
-| `GA605WV_1002_104D158E_CMDEF.icm` | **Recommended** - Factory-calibrated native profile for Sharp LQ160R1JW02 + AMD 890M | Import this |
-| `ASUS_sRGB.icm` | sRGB colorspace (web, photo) | Optional |
-| `ASUS_DisplayP3.icm` | Display P3 colorspace (Apple) | Optional |
-| `ASUS_DCIP3.icm` | DCI-P3 colorspace (cinema) | Optional |
+## Zephyrus G16 (2024) GA605WV — Built-in Display
-### Filename Reference
+Factory-calibrated ICC profiles for the Zephyrus G16 GA605WV built-in display.
-`GA605WV_1002_104D158E_CMDEF`:
-- `GA605WV` = ASUS ROG Zephyrus G16 model
-- `1002` = AMD GPU ID (Radeon 890M iGPU)
-- `104D158E` = Sharp LQ160R1JW02 panel ID
-- `CMDEF` = Factory-calibrated profile
+The GA605WV was shipped with different panels depending on the unit. The standard model uses an IPS panel (ROG Nebula Display); some configurations ship with an OLED panel instead. Three panel variants are known:
-## Install
+| Panel ID | Manufacturer | Model | Type | Source |
+|---|---|---|---|---|
+| `104D158E` | Sharp | LQ160R1JW02 | IPS (ROG Nebula Display) | Verified via EDID on device |
+| `834C41AE` | Samsung | ATNA60DL04-0 | OLED | [LaptopMedia](https://laptopmedia.com/screen/atna60dl04-0-sdc41ae/) · [Linux Hardware](https://linux-hardware.org/?id=eisa:samsung-sdc41ae) |
+| `E5090C19` | Unknown | — | Unknown | Present in ASUS driver package; not yet publicly identified |
-Copy your GPU/panel profile and optional color spaces to GNOME:
+To check which panel your unit has:
```bash
-mkdir -p ~/.local/share/icc
+cat /sys/class/drm/card*-eDP-*/edid | edid-decode 2>/dev/null | grep -i "manufacturer\|model\|product name"
+```
+
+### Source
+
+Profiles were extracted from the ASUS Windows driver package by reverse engineering the ASUS CDN structure and driver ZIP contents:
+
+```
+https://dlcdn-rogboxbu1.asus.com/pub/ASUS/APService/Gaming/SYS/ROGS/20016-BWVQPK-01624c1cdd5a3c05252bad472fab1240.zip
+```
+
+The ICC metadata `desc` tags were modified so profiles appear with readable names in GNOME Color Management.
+
+### Files
+
+| Filename | GPU | Panel | Description |
+|---|---|---|---|
+| `GA605WV_1002_104D158E_CMDEF.icm` | AMD Radeon 890M (`1002`) | Sharp LQ160R1JW02 (`104D158E`) | **Recommended for most units** |
+| `GA605WV_1002_834C41AE_CMDEF.icm` | AMD Radeon 890M (`1002`) | Samsung ATNA60DL04-0 (`834C41AE`) | For Samsung panel variant |
+| `GA605WV_1002_E5090C19_CMDEF.icm` | AMD Radeon 890M (`1002`) | Unknown (`E5090C19`) | For unknown panel variant |
+| `GA605WV_10DE_104D158E_CMDEF.icm` | NVIDIA RTX 4060 (`10DE`) | Sharp LQ160R1JW02 (`104D158E`) | For NVIDIA-primary mode |
+| `GA605WV_10DE_834C41AE_CMDEF.icm` | NVIDIA RTX 4060 (`10DE`) | Samsung ATNA60DL04-0 (`834C41AE`) | For NVIDIA-primary + Samsung panel |
+| `GA605WV_10DE_E5090C19_CMDEF.icm` | NVIDIA RTX 4060 (`10DE`) | Unknown (`E5090C19`) | For NVIDIA-primary + unknown panel |
+| `ASUS_sRGB.icm` | Any | Any | sRGB colorspace (web, photo) |
+| `ASUS_DisplayP3.icm` | Any | Any | Display P3 colorspace (Apple) |
+| `ASUS_DCIP3.icm` | Any | Any | DCI-P3 colorspace (cinema) |
+
+### Install
-# Your GPU/panel combination
+```bash
+# System-wide install:
+sudo cp GA605WV_1002_104D158E_CMDEF.icm /usr/share/color/icc/colord/
+
+# Or per-user install:
+mkdir -p ~/.local/share/icc
cp GA605WV_1002_104D158E_CMDEF.icm ~/.local/share/icc/
+```
+
+Then activate in **GNOME Settings** → **Color Management** → select your display → **Add Profile** → select the profile matching your GPU and panel combination.
+
+---
+
+## LS27B800TGUXEN - S80TB — Samsung ViewFinity S8 Thunderbolt
+
+Color profile for the Samsung ViewFinity S8 Thunderbolt (LS27B800TGUXEN) external monitor.
-# Optional: Universal color spaces
-cp ASUS_sRGB.icm ~/.local/share/icc/
-cp ASUS_DisplayP3.icm ~/.local/share/icc/
-cp ASUS_DCIP3.icm ~/.local/share/icc/
+### Source
+
+Extracted from the Samsung Windows driver package (`S80TB-INF-Driver-Win11x64`).
+
+### Files
+
+| Filename | Description |
+|---|---|
+| `SxxB80xT.icm` | Samsung factory color profile for the S80TB Thunderbolt display |
+
+### Install
+
+```bash
+# System-wide (all users):
+sudo cp SxxB80xT.icm /usr/share/color/icc/colord/
+
+# Or per-user:
+mkdir -p ~/.local/share/icc
+cp SxxB80xT.icm ~/.local/share/icc/
```
-Then activate in **GNOME Settings** → **Color Management** → **Add Profile** → Select `GA605WV_1002_104D158E_CMDEF`.
+Then activate in **GNOME Settings** → **Color Management** → select the Samsung display → **Add Profile** → select `SxxB80xT`.
diff --git a/static/icc-profiles/Zephyrus G16 (2024) GA605WV/SxxB80xT.icm b/static/icc-profiles/Zephyrus G16 (2024) GA605WV/SxxB80xT.icm
new file mode 100644
index 0000000000000000000000000000000000000000..05da48414b46e172ef505a7ac07a617e56c9e31f
GIT binary patch
literal 536
zcmZQzV3J?}0wx6phTOc8q9AuCg^0)~1@?yw%nW=CybKl$42j9b1-`*?8=g1H>*b
zDFBKw&H=HDLV|z}V%z{^3#3EX2SDs32>Swvom@}^QvU$Rwt(6NWHJZ@C*~HH=A|nH
zS5#KGW-Su!vPG9koN)-y2hYcen#*ntrH
zwhI!zmtvAji^`zxV`MUBU?9XVNv!~dAA@s#L1j^9dPa#xvZjKOfsv5{%=fN2smUcp
U`FWYi#R|^(dO8X|B`FLH06Ldcxc~qF
literal 0
HcmV?d00001
diff --git a/static/images/rog-control-system-control.png b/static/images/rog-control-system-control.png
new file mode 100644
index 0000000000000000000000000000000000000000..9d57d20ed9c58fb734a041adb8def7d578d0c83d
GIT binary patch
literal 134361
zcmc$FXEdB^8!jR-g6J)x6GRJ1^xiv(L~qeWndn4I)X_!nB?yT+%IG8vqSt7n1ko9N
zlu^zrd++bt->mLa_1t7#tX{j>ft?s$+BsTbc!C-DpD|clnKSS|<`-ai{8)rvSmYTW
zgRK0^k9*oYz?-OV-lPq-cJqAgVufMj1a`FIcC~P^vT|~@1-tFuYLmdg!dFn1lYZ%y
zx!rQx%xE(0tI&HN#?aTL#yxEf!d=ae#T%T
z8PMOqsJLrtYGz`LeGBs??_qo}UO{nxwT>;(k{@ULCE
zD%j-z`6MDVw;*J)Up&3Ny~8RI3-&2WEWYTw&O0oDcmH!s2(cm&h?A4EiG1jtsDvIJ
z31wAl>%4)1fkKoXL`ukMR>-vO1Km*QHwZ`ttq?J6xNbi=Jp6dwo>KVW2lL4S1J-{n
zV?O?&UibO)#oLu1AhvTK^dPyR?(3~gpkPq$_x5TcGin16^lhctKu>LcbV##DO(cro
z<$4n9zm3Lcb{Qr`HQS1Z+y0=PStp_1fKU(;Sl_zLWTNzeDA0<7i3NF$mI1A#KgTJ5
zohMCH6b;I|)!-45kP-4P+hc>g>a_?%Fz!p`(n$JW#AWA;5=lYhxoR-(=Ne(_z!pRO
z%f5cSPlEaM+cTPV;r}s+-#siktVOK|+lIAG9^w%#EdztiA>juMuqpydMqg>hIW(Rh
zPk8RXuATEFl|}j%W=Z=Z32WG)5s}>d;^q+1Ew_3Q-z#*GoYsGg4T5S)kGH>Ysh4JX
zuz46Nl-u!|HO@ci|o_vi9vbZyguN21gtL^57
z3iMI3D0%$8Z(2>APjqNB@Fr(n2@6A3TU$Lcn<^$XrWgMhA{6sZ?)Ay_)k1U7uqD6U
zvuDp>?~dR29E~WJefjbQ;X-9g=kkNmV?y6%dbYv!GB@k8&S~xqq1fJg@x%Tntz>(9Oz8#tpALsfSdM*GuXYo06rA_UZ#i9xdrqbhvvOX4so(s^4h`bhmr1vf0p;-=l!CIrSY
zzRENafh2l*XeNT3vvIovg|ooVcUw&GuzZEqF+4Yk)nh-kaoYCCsnT#huo_{7WX
zS@r#lV|l_5TnqNwGSt!4wehnW`6Q15U!%Y#kINtd6#n81w-JD0pP0{#7Q1yKm&vVm(Bs_R$
zy1F|yfKIpqEu|z$QA#Lg423w=1<~V&v&w+qB4hoJ@=b~h
zV@$6OQo`i_)IzzF$5+&9wmCB2g+4fI<;f3Ufr7^u3sX!s$7G%^m#p-q7@A63(%mJl
zk(@*Vo;Wd)4LBdmX{OYc_^grjM%Toz*=PIM)I12!rRvnt<4I{Q32jKf_=ya+&_xiw*NA+Xo44LN@jp
z`ZDQdyNxP)bdu|y4smSdTy5kuciK>GGsQE>(D`gbufV-6%Q2$ct!U&S=Nf+0kkB%|
z=x+1jMJvA6!a;J~)Xh!lZmZ625bFeCMC^r=cN`8$?%vjsXxpyp+b+(JIoR>-7M*_`
zD~?JPzdRbdiD%G<_qDupUv5R^5gon5;~Zb$M{liOALd-o;^nn`Z$AV3AJS}bO0#nn
z{7?-zW-GtI#Cc#wY3d6l+z6h0UcN>$Q5k@)3$O2eS7kx^`vF~Q7zCzoElarOk=e?HJrz|~=nBTzs7)QncXL}j0I
z)x70+CS*(^%g1r%C~iFY0B$e9dm5619b4-qrk7v+HdIXyocCY12jlve%5VF01zZx)
z!cU3?RdxR{C`ReMiE?Aa>$4uI$9gf@?>4{C2C2zO&dybLs!DA$uRff}1bukW-A4az
zo$;F5oSup0Egg32EI$zmxPCD-#`RV^7w7&NL+j5GMf$mYL8u(DYqj*-vhs4+^;ypK
zesb}9d3JMKC5iW`r(ZPvdM5>G;N67&dqJqVUH?hKblGn{T=Z08nmH14-QU_H-h1gK
zuxTQNC`$B$CwKjJeOfQsvb{bTyN$?a^(sm%lu*X$!Y6U
ztDjG|Gbx)!4Pn4($NYhSp#L;t;mQMyiw4Z_Mk${2rd;MnfBbcqp1lUtn_4cJ951V$
zw>7$8AEwkJBW9u)^|SJvMUBLw_WCg3Dwfu5SlVN^<>a0HR4a=}?`Pf#IEnP1KB9mD
zas