Skip to content

packaging: a native Arch package, so pacman owns and tracks the daemon - #8

Merged
Ryanmello07 merged 2 commits into
urnetwork:mainfrom
Ryanmello07:upstream/arch-package
Aug 21, 2026
Merged

packaging: a native Arch package, so pacman owns and tracks the daemon#8
Ryanmello07 merged 2 commits into
urnetwork:mainfrom
Ryanmello07:upstream/arch-package

Conversation

@Ryanmello07

@Ryanmello07 Ryanmello07 commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

Stacked PR — depends on #5 (app id rename).
Opened against main because a cross-fork PR needs its base branch to exist in
this repo, so the diff below currently includes its parent's changes too.
Review after its parent lands.


Arch, CachyOS, EndeavourOS and Manjaro had exactly one daemon channel: the
install tarball. That means nothing on the machine knows the daemon is there.
pacman cannot list it, cannot verify it, cannot upgrade it, and pacman -R
cannot remove it — and the tarball can only complain about missing nftables or
fuse2 after it has already written files. This adds
urnetwork-daemon-<version>-<arch>.pkg.tar.zst, built the way the .deb and
.rpm already are.

Why nfpm and not a PKGBUILD

All the native packages are assembled from one meson install --destdir
staging tree through packaging/lib/common.sh's assemble_daemon_root(), so the
daemon inside each is the same bytes by construction rather than by review. A
PKGBUILD would be a fourth independent copy of the installed-path table, and it
would need an Arch machine or a container to run makepkg — which neither the
build server nor the workflow's ubuntu:22.04 container is. nfpm is pure Go down
to its zstd, so this builds anywhere the .deb does.

An AUR recipe remains reasonable later as a discovery channel. It is not a
replacement for a first-party binary package.

Three things make-arch.sh does that make-deb.sh does not

Each because pacman fails in a way the other formats do not:

  1. It moves the unit to /usr/lib/systemd/system. On Arch, /lib is a
    symlink to usr/lib owned by the filesystem package, and a .pkg.tar.zst
    carrying any member under lib/ does not merely offend a guideline — pacman
    aborts the transaction with /lib exists in filesystem (owned by filesystem) and installs nothing.

  2. It folds the whole version into pkgver, because pacman's pkgver may not
    contain - at all and nfpm silently mangles the other obvious shapes. The
    file is still named for the release version verbatim: pacman does not parse
    filenames, it reads .PKGINFO.

  3. It pins one timestamp and verifies the .MTREE, because pacman -Qkk
    the integrity check a careful user runs against a VPN daemon — is broken by
    two separate nfpm behaviours, both silent. type: tree writes Go's unmasked
    fs.FileMode for every directory, so every directory reports as altered
    forever; and the tar header mtime and the .MTREE time= come from different
    clocks. Both are worked around, and the script asserts the workarounds held
    rather than trusting them.

Install/remove hooks

They mirror the .deb's maintainer scripts, with the one pacman ordering
difference that matters: pre_remove stops and disables the unit while the
binary still exists
, so its ExecStopPost can tear the nftables ruleset down.

Not for SteamOS

SteamOS is Arch-family but immutable. Its /usr is read-only, pacman -U there
needs steamos-readonly disable, and the next system update reverts it.
Immutable Arch hosts stay on the install tarball, which installs under
/usr/local. packaging/distro-smoke.sh says so on a SteamOS host.

The tarball guards were hypothetical; now they are live

packaging/tarball/install.sh and uninstall.sh already refused to touch paths
that pacman -Qo reports as owned, but both comments described it as protection
against a future AUR package. It is now a real conflict against our own
package, and both comments say so — otherwise the next reader assumes the check
is theoretical and weakens it.

Verified

bash -n on make-arch.sh, all six packaging/arch/scripts/*, distro-smoke.sh
and both tarball scripts; yaml.safe_load on packaging/arch/nfpm.yaml; every
path make-arch.sh references exists in the tree.

Why this is split this way

It is the single largest body of genuinely new code in the series (≈1400 lines),
it is self-contained, and it needs a reviewer who cares about pacman semantics —
not the same reviewer who should be checking an app id or a screenshot. It only
needs PR 2 underneath it, so it does not have to queue behind the icon and
Flathub work.

One note on comment references

Four comments in packaging/make-arch.sh and packaging/arch/nfpm.yaml cite
.github/workflows/beta-build.yml as the source of the release-asset contract.
That mirrors the existing house style — packaging/make-rpm.sh,
packaging/rpm/nfpm.yaml, docs/DISTRO-SUPPORT.md and docs/linux_agent_help.md
on main all reference that same path today. They were left as-is for
consistency. If you would rather those references be repointed at whatever
workflow owns the contract in this repo, say so and it is a one-line change in
each.

The Android and Apple clients ship under `com.bringyour.network`. Linux was
the only platform on a different reverse-DNS id, and every place the id is
written down had to be told which one to use. This makes Linux match, and it
has to be done in one change because the id is a join key: the GTK
application id, the .desktop basename, the AppStream component id, the polkit
action namespace, the icon-theme name and the Flatpak app id must all agree or
the desktop stops recognising the app.

WHAT MOVES, AND WHY IT IS ALL ONE COMMIT

  main.cpp             Gtk::Application::create() -- the GApplication id
  *.desktop            filename, Icon=, StartupWMClass=
  metainfo.xml         filename, <id>, <launchable>
  polkit .policy       filename + all four action ids, matched in
                       ControlProtocol.hpp so the daemon asks about the
                       actions the file actually declares
  icons                hicolor basenames; Flatpak refuses to export an icon
                       whose name is not the app id
  flatpak manifest     filename + id + the desktop-file-edit paths
  deb/rpm/tarball/     the installed paths, the conffile entries, and the
  AppImage/snap        uninstaller's stale-path list

Splitting these would leave an intermediate commit where, for example, the
.desktop names an icon that does not exist, or the daemon checks polkit
actions the shipped .policy does not declare -- both of which fail silently
at runtime rather than at build time.

TWO THINGS THAT ARE NOT PURE SEARCH-AND-REPLACE

1. `UrTheme::kAppIconName`. The icon name was spelled as a literal in two
   places -- the by-path load in UrTheme.cpp and the by-name fallback in
   MainWindow.cpp. Renaming the packaging alone left both lookups pointing at
   a file that no longer existed, and `set_from_icon_name()` renders a blank
   image without raising anything, so the title-bar logo simply went empty.
   It is now one constant that the packaging and both call sites share.

2. The libsecret keyring attribute in SecretServiceRpcSessionStore.cpp moves
   with the id. This is deliberately NOT dual-read: an entry written by an
   older build is no longer found, the app falls back to a fresh RPC session
   (the same one-time cost as the Flatpak data path moving), and the previous
   app identity is not left holding live key material in the user's keyring
   with nothing to clean it up.

No behaviour changes beyond those two. `network.ur.urnetwork` no longer
appears anywhere in the tree.
Arch, CachyOS, EndeavourOS and Manjaro had exactly one daemon channel: the
install tarball. That means nothing on the machine knows the daemon is there.
pacman cannot list it, cannot verify it, cannot upgrade it, and `pacman -R`
cannot remove it -- and the tarball can only complain about missing nftables
or fuse2 after it has already written files. This adds
urnetwork-daemon-<version>-<arch>.pkg.tar.zst, built the same way the .deb and
.rpm are.

WHY nfpm AND NOT A PKGBUILD. All the native packages are assembled from ONE
`meson install --destdir` staging tree through packaging/lib/common.sh's
assemble_daemon_root(), so the daemon inside each is the same bytes by
construction rather than by review. A PKGBUILD would be a fourth independent
copy of the installed-path table, and it would need an Arch machine or a
container to run makepkg -- which neither the build server nor the workflow's
ubuntu:22.04 container is. nfpm is pure Go down to its zstd, so this builds
anywhere the .deb does. An AUR recipe remains reasonable later as a discovery
channel; it is not a replacement for a first-party binary package.

THREE THINGS make-arch.sh DOES THAT make-deb.sh DOES NOT, each because pacman
fails in a way the other formats do not:

1. It MOVES THE UNIT to /usr/lib/systemd/system. On Arch /lib is a symlink to
   usr/lib owned by the `filesystem` package, and a .pkg.tar.zst carrying any
   member under lib/ does not merely offend a guideline -- pacman ABORTS the
   transaction with "/lib exists in filesystem (owned by filesystem)" and
   installs nothing.

2. It FOLDS THE WHOLE VERSION INTO pkgver, because pacman's pkgver may not
   contain '-' at all and nfpm silently mangles the other obvious shapes. The
   file is still named for the release version verbatim: pacman does not parse
   filenames, it reads .PKGINFO.

3. It PINS ONE TIMESTAMP AND VERIFIES THE .MTREE, because `pacman -Qkk` -- the
   integrity check a careful user runs against a VPN daemon -- is broken by two
   separate nfpm behaviours, both silent. `type: tree` writes Go's unmasked
   fs.FileMode for every directory, so every directory reports as altered
   forever; and the tar header mtime and the .MTREE `time=` come from different
   clocks. Both are worked around, and the script asserts the workarounds held
   rather than trusting them.

The install/remove hooks mirror the .deb's maintainer scripts, with the pacman
ordering difference that matters: pre_remove stops and disables the unit while
the binary still exists, so its ExecStopPost can tear the nftables ruleset down.

NOT FOR SteamOS, even though SteamOS is Arch-family. Its /usr is read-only,
`pacman -U` there needs `steamos-readonly disable`, and the next system update
reverts it. Immutable Arch hosts stay on the install tarball, which installs
under /usr/local; packaging/distro-smoke.sh says so on a SteamOS host.

The tarball installer and uninstaller already refused to touch paths that
`pacman -Qo` reports as owned. That guard was written as protection against a
hypothetical future AUR package; it is now a live conflict, and both comments
are updated to say so rather than leaving the next reader to assume the check
is theoretical.
@Ryanmello07 Ryanmello07 changed the title PR 6 — upstream/arch-package packaging: a native Arch package, so pacman owns and tracks the daemon Aug 21, 2026
@Ryanmello07
Ryanmello07 marked this pull request as ready for review August 21, 2026 15:40
@Ryanmello07
Ryanmello07 merged commit 7d371b1 into urnetwork:main Aug 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant