Skip to content
Quad4-SoftwarePublic

About

pacman repository for Quad4 software.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Quad4 Arch

Unofficial pacman repository for Quad4 software. Hosted at arch.quad4.io.

Install

Append this to /etc/pacman.conf after the official [core] and [extra] blocks, or copy conf/pacman-quad4.conf:

[quad4]
SigLevel = PackageRequired DatabaseRequired
Server = https://cdn.quad4.io/arch/$arch
Server = https://arch.quad4.io/$arch

Then:

sudo pacman -Syu
sudo pacman -S reticulum-go-bin meshchatx-bin meshchatx-beta-bin meshchatx-testing-bin renbrowser-bin nullray-git ren-tui-bin ravenguard-git lyra-bin argus-bin rns lxmf nomadnet

The first Server is cdn.quad4.io. The second is a rolling GitHub Release named pkg-$arch.

Packages and the database are signed. Add the packaging key before the first update:

sudo pacman-key --recv-key 97B937E980BDD9C89F06D7FA3BCCE6B7FB4AE3B5 --keyserver keyserver.ubuntu.com
sudo pacman-key --lsign-key 97B937E980BDD9C89F06D7FA3BCCE6B7FB4AE3B5
Alternative: download the key directly

If you prefer not to use a keyserver, get the key from the site and add it manually:

curl -o /tmp/quad4.gpg https://arch.quad4.io/quad4.gpg
sudo pacman-key --add /tmp/quad4.gpg
sudo pacman-key --lsign 97B937E980BDD9C89F06D7FA3BCCE6B7FB4AE3B5

The public key is also in the repo at keys/quad4.gpg.

Packages

Package Description
reticulum-go-bin Reticulum-Go, prebuilt GitHub release (x86_64, aarch64, armv7h)
reticulum-go-git Reticulum-Go built from master
meshchatx-bin MeshChatX AppImage (x86_64, aarch64)
meshchatx-beta-bin MeshChatX beta AppImage (x86_64, aarch64)
meshchatx-testing-bin MeshChatX testing/nightly AppImage (x86_64, aarch64)
meshchatx-git MeshChatX built from master
renbrowser-bin Ren Browser for Reticulum (x86_64, aarch64)
renbrowser-git Ren Browser built from master
gorrcd-bin Go RRC hub daemon (prebuilt)
gorrcd-git Go RRC hub daemon from master
golxmd-bin Go LXMF daemon (prebuilt)
golxmd-git Go LXMF daemon from master
rns Python Reticulum Network Stack (PyPI, external)
lxmf Python LXMF (PyPI, external)
nomadnet Nomad Network client (PyPI, external)
lxmfy LXMF bot framework (PyPI)
rns-page-node RNS page/file node (PyPI)
pip-rns Install Python packages from Reticulum remotes (PyPI)
nullray-git nullray, built from master (x86_64)
ren-tui-bin Ren TUI, prebuilt GitHub release (x86_64, aarch64)
ravenguard-git RavenGuard built from master
lyra-bin Lyra, Firefox ESR fork, prebuilt release (x86_64)
argus-bin argus security/OSINT/linting tool, prebuilt release (x86_64, aarch64)

*-bin and *-git for the same app conflict and both provide the unversioned name (reticulum-go, meshchatx, …). Old bare names (reticulum-go, meshchatx, …) are replaced by the matching *-bin package on upgrade. Python packages stay unversioned (no -bin/-git). rns, lxmf, and nomadnet are third-party Markqvist packages mirrored for convenience.

Development

On Arch, makepkg and repo-add run on the host. Elsewhere, scripts use the pinned archlinux:base-devel image from conf/ci-pins.env.

make check
make build
make repo
make pages

Bump a binary package after an upstream release:

sh scripts/install-verify-tools.sh
sh scripts/bump-binary.sh reticulum-go-bin v1.1.1
sh scripts/bump-binary.sh meshchatx-bin v4.8.6

Binary bumps fail closed unless release assets verify:

  • reticulum-go-bin: cosign blob attestation (.cosign.bundle) against the pinned key in keys/upstream/reticulum-go.cosign.pub
  • meshchatx-bin: SLSA provenance (meshchatx-linux-v*.intoto.jsonl) via slsa-verifier for github.com/Quad4-Software/MeshChatX and the release tag

Tool versions and sha256 pins live in conf/ci-pins.env.

Scaffold a new package:

sh scripts/new-pkg.sh other-tool --kind binary --github Quad4-Software/other-tool --tag v0.1.0
sh scripts/new-pkg.sh other-tool --kind git --github Quad4-Software/other-tool

That creates pkg/other-tool-bin and pkg/other-tool-git. Edit package() in the new PKGBUILD, then add matrix rows in .github/workflows/ci.yml and publish.yml.

From another Quad4 repository (needs actions: write on this repo):

# Rebuild current package versions
gh api repos/Quad4-Software/arch/dispatches -f event_type=quad4-rebuild

License

PKGBUILDs, scripts, and CI are 0BSD.

Packaged software keeps its own license, recorded in each PKGBUILD license= field:

  • Reticulum-Go: Apache-2.0
  • MeshChatX: 0BSD, with upstream MIT

About

pacman repository for Quad4 software.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages