Arch Linux pacman repository support

ToDesktop can build pacman packages and serve them from a signed pacman repository, so users of Arch Linux and Arch-based distributions (including Manjaro and EndeavourOS) can:

  • Install your app with pacman, their system package manager
  • Receive updates with the rest of their system when they run pacman -Syu
  • Verify that the repository comes from you, using a PGP signature

Pacman packages are in beta.

Prerequisites

Enable the Linux Pacman artifact in your build settings:

  1. Navigate to your app's Build and Deploy settings in the ToDesktop dashboard
  2. Enable Linux Pacman
  3. To build for 64-bit ARM (aarch64) as well as x86_64, also enable Linux ARM64

Linux Pacman is available on the same plans as the Linux Debian and RPM packages.

WARNING

The repository only serves releases built with Linux Pacman enabled. After enabling it, create and release a new build.

Package name

The package is named after the name in your app's package.json, lowercased and with a -bin suffix, the Arch convention for prebuilt packages. Characters other than letters, numbers, - and _ become -. For example, my-app becomes my-app-bin.

The package also provides and conflicts with the name without the suffix (my-app). If an Arch repository has a package with the same name as your app, pacman offers to replace one with the other instead of installing both. The install command below names your repository explicitly, so pacman always installs your package.

WARNING

Changing your app's name changes the package name. Users who installed the old package will not receive updates under the new name.

Setting up the repository

The examples below use my-app-bin as the package name and {YOUR_APP_ID} as your ToDesktop app ID. If you use a custom download domain, replace https://dl.todesktop.com/{YOUR_APP_ID} with https://{YOUR_CUSTOM_DOMAIN}.

Your app's download page shows these commands with your app's values filled in, under Install with pacman.

1. Trust the signing key

The repository database is signed. Import the key and sign it locally, so pacman trusts it:

curl -fsSL 'https://dl.todesktop.com/{YOUR_APP_ID}/pacman/key.asc' | sudo pacman-key --add -
sudo pacman-key --lsign-key {KEY_FINGERPRINT}

To find the key's fingerprint for your instructions, run:

curl -fsSL 'https://dl.todesktop.com/{YOUR_APP_ID}/pacman/key.asc' | gpg --show-keys --with-colons | awk -F: '$1 == "fpr" { print $10; exit }'

2. Add the repository

This appends a section for your repository to /etc/pacman.conf, unless it is already there:

grep -qxF '[my-app-bin]' /etc/pacman.conf || curl -fsSL 'https://dl.todesktop.com/{YOUR_APP_ID}/pacman/my-app-bin.conf' | sudo tee -a /etc/pacman.conf > /dev/null

The appended section looks like this:

[my-app-bin]
SigLevel = PackageOptional DatabaseRequired
Server = https://dl.todesktop.com/{YOUR_APP_ID}/pacman/$arch

The database signature is required. It contains the checksum of each package, so pacman verifies the package it downloads against the signed database.

3. Install the app

sudo pacman -Syu my-app-bin/my-app-bin

Prefixing the package with the repository name (my-app-bin/) installs it from your repository even if another repository has a package with the same name.

Automatic updates

Your app updates with the rest of the system:

sudo pacman -Syu

Each release you publish in ToDesktop becomes the version in the repository. Prerelease versions such as 1.2.3-beta.1 are ordered before the release (1.2.3), so users on a beta upgrade to the release.

If a release has no pacman package for an architecture (for example, a release built without Linux Pacman, or without Linux ARM64), the repository serves an empty database for it. pacman -Syu keeps working for those users: they stay on the version they have until a release includes a package for their architecture.

Installing the package file directly

Users can also download the .pacman file from your download page and install it with sudo pacman -U. pacman -Syu only finds new versions in the repositories configured in /etc/pacman.conf, so without your repository, an app installed this way stays on the version they downloaded. To receive updates, those users need to set up the repository. They can do that at any time: the next pacman -Syu updates the installed package from your repository.

Uninstalling

To remove the app and the repository section added during setup:

sudo pacman -Rns my-app-bin
sudo sed -i '/^\[my-app-bin\]$/,/^Server = /d' /etc/pacman.conf

The signing key stays trusted, because other apps' repositories may use the same key. To remove it too, run sudo pacman-key --delete {KEY_FINGERPRINT}.

Custom PGP key for repository signing

The repository is signed with the same key as your Debian APT repository: ToDesktop's default key, or your own Linux PGP Key from the Certificates section of your app settings.

If you change the key, users who set up the repository with the previous key need to trust the new one by repeating step 1. Until they do, pacman -Sy fails with a signature error for your repository.

Restricting downloads

If your app restricts downloads by IP address, the policy also applies to the pacman repository. See Restricting downloads by IP address.