Docs / Use
Installing software
rime install for Fedora packages, Flatpaks, local .rpm, .deb and AppImage files, COPRs and capsules, and what it refuses.
On this page 8 sections
The commands
sudo rime install android-tools # a package from Fedora, RPM Fusion or an enabled COPR
sudo rime install org.gimp.GIMP # a reverse-DNS id installs the Flatpak from Flathub
sudo rime install ~/Downloads/app.rpm # a local .rpm file
sudo rime install --allow-unsigned ~/Downloads/app.deb # a local .deb file
sudo rime install --allow-unsigned ./Thing.AppImage # an AppImage
sudo rime remove android-tools
rime search wireshark # the repositories and Flathub
rime resolve obs-studio # which source Rime would use, and why
rime pkg list
Reading needs no root. Anything that installs or removes needs sudo. On a
machine that has not taken its first update since the rename, use apex in
place of rime.
Why not rpm-ostree install
Rime is an image-based system. Layering a package with rpm-ostree marks the
image as locally modified, and from then on bootc upgrade refuses to run:
installing one tool would stop the machine updating, without a word.
rime install builds a systemd system extension instead: one squashfs image
at /var/lib/extensions/rime-user.raw that systemd overlays onto /usr at boot.
- The OS image is never modified, so updates keep working.
- Programs land in the real
/usr/bin, with their launcher entries, icons, man pages, completions, systemd units and udev rules where the system already looks. - Everything you asked for lives in one extension, rebuilt from your list on every change.
rime rollback(the OS) andrime pkg rollback(your packages) are independent.
On an install, dnf resolves against the installed image and
downloads only what the image lacks, rpmkeys checks every RPM’s signature,
the files are extracted without running package scripts, shared caches are
rebuilt, SELinux labels are applied, and the new extension replaces the old one
in one step. A package’s /etc files go to the real /etc; if you edited one,
yours stays and the new version lands beside it as *.rimenew.
After an OS version change, rime-sysext-rebuild.service rebuilds the extension
on the first boot. Offline, it leaves the rebuild for later rather than failing
the boot. rime update also refreshes your packages, so they get Fedora’s
security fixes.
Where packages come from
-
Fedora, and RPM Fusion Free and Nonfree, enabled in every image.
-
COPRs you enable. COPRs are third-party repositories, run by neither Fedora nor Rime. Enabling one trusts its owner until you disable it:
sudo rime repo enable-copr OWNER/PROJECT rime repo list sudo rime repo disable-copr OWNER/PROJECTRime still checks every downloaded RPM against a trusted key. Disabling the COPR removes its key again.
-
Flathub, for any reverse-DNS application id (three or more dot-separated parts, such as
org.gimp.GIMP). A plain name likegimpmeans the RPM. -
Files you already have:
.rpm,.debor AppImage.
There is no Rime package registry.
A bare name can exist as an RPM, a Flatpak and a package inside a capsule, so
Rime ranks the sources. rime resolve NAME shows every candidate, what vouches
for each, the choice Rime would make and the command for each alternative. To
choose yourself for one install, add --source rpm, --source flatpak or
--source capsule.
Other install flags:
| Flag | Does |
|---|---|
--no-weak-deps |
Skip weak dependencies: a smaller install with fewer optional features. |
--enable-repo REPO |
Also consider a repository that is disabled by default. |
--allow-unsigned |
Accept a local file no trusted key covers (see below). |
--source rpm|flatpak|capsule |
Pick the source for a bare name. |
--env CAPSULE |
Which capsule --source capsule installs into. Defaults to your first. |
Local files
.rpm
sudo rime install ~/Downloads/some-app.rpm
The file goes through the same pipeline as a repository package. Rime copies it
to /var/lib/rime/pkg/local/, and every later rebuild uses that copy, so the
original can go. Its dependencies still come from the repositories. rime update
cannot update the file itself: install a newer file to move it.
An RPM that no trusted key covers is refused. If you accept where it came from:
sudo rime install --allow-unsigned ~/Downloads/some-app.rpm
--allow-unsigned applies only to the files named on that command, never to
repository packages. Rime records the decision against the file’s exact
checksum, and rime pkg list and rime pkg verify keep saying the package was
never verified.
Package scripts do not run. Most packages work anyway. A vendor RPM that creates
its short command name in a script may land under /opt with a working launcher
entry and no command on PATH; rime pkg info shows what was installed.
.deb
sudo rime install --allow-unsigned ~/Downloads/app_1.0_amd64.deb
rime install --help does not list .deb, but the engine accepts it. Rime
unpacks the package into the same extension. It is not an apt client:
- it fetches no
.deband resolves no Debian dependencies. It prints theDepends:line so you can install anything missing withrime install; - it never runs the maintainer scripts, and refuses a package whose program only a script would create;
- it accepts files only under
/usrand/opt, and refuses shared libraries in the system library paths; - every
.debneeds--allow-unsigned, because Debian signs the repository index, not the file.
AppImage
sudo rime install --allow-unsigned ./Thing.AppImage
sudo rime remove Thing # by the command name it installed
sudo rime remove ./Thing.AppImage # or by the file it came from
Rime unpacks the AppImage once into /usr/local/lib/rime-appimage/NAME/, with a
launcher entry, an icon and a command in /usr/local/bin. It never runs the
AppImage file itself.
An installed AppImage is pinned. rime update does not move it, says so by
name on every run, and never follows the vendor’s own update channel. To update,
install the newer file. It takes two to three times the file’s size on disk.
Every AppImage needs --allow-unsigned. If the software also comes as an RPM, a
COPR or a Flatpak, use that instead.
Managing what you installed
| Command | Does |
|---|---|
rime pkg list |
What you asked for, and what came in as dependencies. |
rime pkg status |
The extension’s state: what it was built for, whether it is merged. |
rime pkg info |
The full record of the last build. |
sudo rime pkg upgrade |
Re-resolve every package against the repositories. |
sudo rime pkg rebuild |
Rebuild for the running OS version. --if-needed does nothing unless it has to. |
sudo rime pkg rollback |
Restore the previous extension. |
rime pkg verify |
Check the extension against its recorded checksum, and each AppImage against the file you accepted. |
sudo rime pkg adopt |
Convert rpm-ostree layered packages into the extension, then reset the layers so updates work again. Restart afterwards. |
What rime install refuses
| Refused | Why |
|---|---|
Kernels, kmod-*, akmod-* |
They need an initramfs and a real image; kernel modules ship in the image. |
glibc, systemd, rpm, dnf, bootc, ostree, the bootloader, the SELinux policy, core tools |
A second copy of the running system’s foundations cannot be undone without a rollback. |
| A newer version of something the image ships | That is an OS update. |
| Anything the image already provides | Nothing to do. |
| An RPM for another architecture | It cannot run here. |
| A local RPM no trusted key covers | Unless you pass --allow-unsigned for that file. |
Flatpaks
Flathub is the only Flatpak remote Rime configures, added at first boot. Zen Browser is installed from it at first boot; Firefox stays the default browser. Bazaar, a graphical store for Flatpaks, is in the image.
rime update also updates Flatpak applications, system-wide and for you. Skip
that with --skip-flatpak.
Capsules: software that expects a mutable system
pip install --user, npm -g, an SDK that wants /opt, a package that exists
only for Ubuntu: these belong in a capsule, a rootless container that still sees
your home directory, your terminal and your devices. Capsules are yours, not the
machine’s, so no capsule command takes sudo.
rime env create ubuntu # aliases: fedora, ubuntu, arch, debian, python, cuda, rocm
rime env create cuda # an alias brings its device profile: this one sees the GPU
rime env create tools --gpu none # device access: nvidia, amd, hw or none (the default)
rime env enter ubuntu # a shell inside it
rime env exec ubuntu -- make test # one command, no terminal
rime env install ubuntu some-package # with the capsule's own package manager
rime env export ubuntu some-app # put its GUI application in your launcher
rime env list
rime env rm ubuntu
rime install --source capsule NAME also installs into a capsule, and it is the
one form of rime install that runs without sudo.
Capsules are built on distrobox and podman. They are not a security boundary: a capsule can reach your files.