Updates
A workstation needs to install and update software, so Runink River keeps pacman on the workstation (unlike a locked-down appliance, which would be updated only as a whole image).
linux-runink, runink-zfs, runink-zfs-utils,
runink-installer) are not yet served from a public, signed package repository: until
one exists they change only with a new release image. A signed [runink] repository and
river-update, which installs each release into a new boot environment, are planned
(Roadmap).Update the system
Snapshot the boot environment first, then update:
findmnt /boot # the EFI partition must be mounted
sudo zfs snapshot "$(findmnt -no SOURCE /)@pre-update-$(date +%Y%m%d)"
sudo pacman -SyuInstall software
pacman -Ss <word> # search the repositories
sudo pacman -S <package> # install
sudo pacman -Rns <package> # remove, with the dependencies nothing else needsA package that ships only a systemd unit for its daemon needs an s6 service definition
before it can run as a service (Services (s6)). The image carries
no container runtime, Flatpak or app store; installing one is your choice, outside what
Runink River supports and tests. Run code you do not trust under
river-sandbox.
If the update breaks something, roll back to
the snapshot. Your files in /home are not part of the rollback.
Kernel and ZFS updates
The kernel and its ZFS modules are one unit: the ZFS module must match the kernel release exactly, and a kernel is only released when the pinned OpenZFS release supports its series. When they change:
- Snapshot the boot environment (above), or better, upgrade a clone.
- Keep the previous packages (
linux-runink,linux-runink-headers,runink-zfs,runink-zfs-utils) so you can go back withpacman -U, offline. - Upgrade kernel and ZFS in one transaction, so
mkinitcpio -Psees both.
The kernel and initramfs are written to /boot, the EFI partition. It must be mounted when
you update, or the new kernel lands inside the encrypted boot environment, where GRUB cannot
see it, and the machine keeps booting the old one. findmnt /boot shows it.
Release notes
Changes that users notice are listed in CHANGELOG.md. Security fixes are
listed under Security, with their advisory or CVE ID once public.