packaging: a native Arch package, so pacman owns and tracks the daemon - #8
Merged
Merged
Conversation
The Android and Apple clients ship under `com.bringyour.network`. Linux was
the only platform on a different reverse-DNS id, and every place the id is
written down had to be told which one to use. This makes Linux match, and it
has to be done in one change because the id is a join key: the GTK
application id, the .desktop basename, the AppStream component id, the polkit
action namespace, the icon-theme name and the Flatpak app id must all agree or
the desktop stops recognising the app.
WHAT MOVES, AND WHY IT IS ALL ONE COMMIT
main.cpp Gtk::Application::create() -- the GApplication id
*.desktop filename, Icon=, StartupWMClass=
metainfo.xml filename, <id>, <launchable>
polkit .policy filename + all four action ids, matched in
ControlProtocol.hpp so the daemon asks about the
actions the file actually declares
icons hicolor basenames; Flatpak refuses to export an icon
whose name is not the app id
flatpak manifest filename + id + the desktop-file-edit paths
deb/rpm/tarball/ the installed paths, the conffile entries, and the
AppImage/snap uninstaller's stale-path list
Splitting these would leave an intermediate commit where, for example, the
.desktop names an icon that does not exist, or the daemon checks polkit
actions the shipped .policy does not declare -- both of which fail silently
at runtime rather than at build time.
TWO THINGS THAT ARE NOT PURE SEARCH-AND-REPLACE
1. `UrTheme::kAppIconName`. The icon name was spelled as a literal in two
places -- the by-path load in UrTheme.cpp and the by-name fallback in
MainWindow.cpp. Renaming the packaging alone left both lookups pointing at
a file that no longer existed, and `set_from_icon_name()` renders a blank
image without raising anything, so the title-bar logo simply went empty.
It is now one constant that the packaging and both call sites share.
2. The libsecret keyring attribute in SecretServiceRpcSessionStore.cpp moves
with the id. This is deliberately NOT dual-read: an entry written by an
older build is no longer found, the app falls back to a fresh RPC session
(the same one-time cost as the Flatpak data path moving), and the previous
app identity is not left holding live key material in the user's keyring
with nothing to clean it up.
No behaviour changes beyond those two. `network.ur.urnetwork` no longer
appears anywhere in the tree.
Arch, CachyOS, EndeavourOS and Manjaro had exactly one daemon channel: the install tarball. That means nothing on the machine knows the daemon is there. pacman cannot list it, cannot verify it, cannot upgrade it, and `pacman -R` cannot remove it -- and the tarball can only complain about missing nftables or fuse2 after it has already written files. This adds urnetwork-daemon-<version>-<arch>.pkg.tar.zst, built the same way the .deb and .rpm are. WHY nfpm AND NOT A PKGBUILD. All the native packages are assembled from ONE `meson install --destdir` staging tree through packaging/lib/common.sh's assemble_daemon_root(), so the daemon inside each is the same bytes by construction rather than by review. A PKGBUILD would be a fourth independent copy of the installed-path table, and it would need an Arch machine or a container to run makepkg -- which neither the build server nor the workflow's ubuntu:22.04 container is. nfpm is pure Go down to its zstd, so this builds anywhere the .deb does. An AUR recipe remains reasonable later as a discovery channel; it is not a replacement for a first-party binary package. THREE THINGS make-arch.sh DOES THAT make-deb.sh DOES NOT, each because pacman fails in a way the other formats do not: 1. It MOVES THE UNIT to /usr/lib/systemd/system. On Arch /lib is a symlink to usr/lib owned by the `filesystem` package, and a .pkg.tar.zst carrying any member under lib/ does not merely offend a guideline -- pacman ABORTS the transaction with "/lib exists in filesystem (owned by filesystem)" and installs nothing. 2. It FOLDS THE WHOLE VERSION INTO pkgver, because pacman's pkgver may not contain '-' at all and nfpm silently mangles the other obvious shapes. The file is still named for the release version verbatim: pacman does not parse filenames, it reads .PKGINFO. 3. It PINS ONE TIMESTAMP AND VERIFIES THE .MTREE, because `pacman -Qkk` -- the integrity check a careful user runs against a VPN daemon -- is broken by two separate nfpm behaviours, both silent. `type: tree` writes Go's unmasked fs.FileMode for every directory, so every directory reports as altered forever; and the tar header mtime and the .MTREE `time=` come from different clocks. Both are worked around, and the script asserts the workarounds held rather than trusting them. The install/remove hooks mirror the .deb's maintainer scripts, with the pacman ordering difference that matters: pre_remove stops and disables the unit while the binary still exists, so its ExecStopPost can tear the nftables ruleset down. NOT FOR SteamOS, even though SteamOS is Arch-family. Its /usr is read-only, `pacman -U` there needs `steamos-readonly disable`, and the next system update reverts it. Immutable Arch hosts stay on the install tarball, which installs under /usr/local; packaging/distro-smoke.sh says so on a SteamOS host. The tarball installer and uninstaller already refused to touch paths that `pacman -Qo` reports as owned. That guard was written as protection against a hypothetical future AUR package; it is now a live conflict, and both comments are updated to say so rather than leaving the next reader to assume the check is theoretical.
Ryanmello07
marked this pull request as ready for review
August 21, 2026 15:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Arch, CachyOS, EndeavourOS and Manjaro had exactly one daemon channel: the
install tarball. That means nothing on the machine knows the daemon is there.
pacman cannot list it, cannot verify it, cannot upgrade it, and
pacman -Rcannot remove it — and the tarball can only complain about missing
nftablesorfuse2after it has already written files. This addsurnetwork-daemon-<version>-<arch>.pkg.tar.zst, built the way the.deband.rpmalready are.Why nfpm and not a PKGBUILD
All the native packages are assembled from one
meson install --destdirstaging tree through
packaging/lib/common.sh'sassemble_daemon_root(), so thedaemon inside each is the same bytes by construction rather than by review. A
PKGBUILD would be a fourth independent copy of the installed-path table, and it
would need an Arch machine or a container to run
makepkg— which neither thebuild server nor the workflow's
ubuntu:22.04container is. nfpm is pure Go downto its zstd, so this builds anywhere the
.debdoes.An AUR recipe remains reasonable later as a discovery channel. It is not a
replacement for a first-party binary package.
Three things
make-arch.shdoes thatmake-deb.shdoes notEach because pacman fails in a way the other formats do not:
It moves the unit to
/usr/lib/systemd/system. On Arch,/libis asymlink to
usr/libowned by thefilesystempackage, and a.pkg.tar.zstcarrying any member under
lib/does not merely offend a guideline — pacmanaborts the transaction with
/lib exists in filesystem (owned by filesystem)and installs nothing.It folds the whole version into
pkgver, because pacman'spkgvermay notcontain
-at all and nfpm silently mangles the other obvious shapes. Thefile is still named for the release version verbatim: pacman does not parse
filenames, it reads
.PKGINFO.It pins one timestamp and verifies the
.MTREE, becausepacman -Qkk—the integrity check a careful user runs against a VPN daemon — is broken by
two separate nfpm behaviours, both silent.
type: treewrites Go's unmaskedfs.FileModefor every directory, so every directory reports as alteredforever; and the tar header mtime and the
.MTREEtime=come from differentclocks. Both are worked around, and the script asserts the workarounds held
rather than trusting them.
Install/remove hooks
They mirror the
.deb's maintainer scripts, with the one pacman orderingdifference that matters:
pre_removestops and disables the unit while thebinary still exists, so its
ExecStopPostcan tear the nftables ruleset down.Not for SteamOS
SteamOS is Arch-family but immutable. Its
/usris read-only,pacman -Uthereneeds
steamos-readonly disable, and the next system update reverts it.Immutable Arch hosts stay on the install tarball, which installs under
/usr/local.packaging/distro-smoke.shsays so on a SteamOS host.The tarball guards were hypothetical; now they are live
packaging/tarball/install.shanduninstall.shalready refused to touch pathsthat
pacman -Qoreports as owned, but both comments described it as protectionagainst a future AUR package. It is now a real conflict against our own
package, and both comments say so — otherwise the next reader assumes the check
is theoretical and weakens it.
Verified
bash -nonmake-arch.sh, all sixpackaging/arch/scripts/*,distro-smoke.shand both tarball scripts;
yaml.safe_loadonpackaging/arch/nfpm.yaml; everypath
make-arch.shreferences exists in the tree.Why this is split this way
It is the single largest body of genuinely new code in the series (≈1400 lines),
it is self-contained, and it needs a reviewer who cares about pacman semantics —
not the same reviewer who should be checking an app id or a screenshot. It only
needs PR 2 underneath it, so it does not have to queue behind the icon and
Flathub work.
One note on comment references
Four comments in
packaging/make-arch.shandpackaging/arch/nfpm.yamlcite.github/workflows/beta-build.ymlas the source of the release-asset contract.That mirrors the existing house style —
packaging/make-rpm.sh,packaging/rpm/nfpm.yaml,docs/DISTRO-SUPPORT.mdanddocs/linux_agent_help.mdon
mainall reference that same path today. They were left as-is forconsistency. If you would rather those references be repointed at whatever
workflow owns the contract in this repo, say so and it is a one-line change in
each.