Installing my tools from repo.dixon.cx
I publish my command-line tools as signed packages at repo.dixon.cx, so they install with the package manager you already use and update with the rest of your system. Add the repository once, then apt upgrade, dnf upgrade or pacman -Syu picks up every new release by itself.
- Debian, Ubuntu
- Fedora, RHEL, Alma, Rocky
- openSUSE
- Arch, Manjaro
- Signed
| Package | Command | What it is |
|---|---|---|
dixon-vault | vault | vault: a post-quantum encrypted file vault that hides file names, sizes and dates, with an optional decoy passphrase. |
mapsize | mapsize | mapsize: a disk usage analyser for the terminal, drawn as a live treemap you can move around. |
Packages are built for 64-bit x86, ARM64, ARMv7 (Raspberry Pi 2 and later, in 32-bit mode), 32-bit x86 and RISC-V. Each one includes the manual pages, so man vault and man mapsize work straight away.
Debian, Ubuntu, Mint, Pop!_OS, Raspberry Pi OS
Fetch the signing key, add the repository, then install:
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://repo.dixon.cx/dixon.gpg | sudo tee /etc/apt/keyrings/dixon.gpg >/dev/null
echo "deb [signed-by=/etc/apt/keyrings/dixon.gpg] https://repo.dixon.cx/apt stable main" |
sudo tee /etc/apt/sources.list.d/dixon.list
sudo apt update
sudo apt install dixon-vault mapsize
The signed-by part means the key is trusted for this repository only, not for everything apt installs.
Fedora, RHEL, AlmaLinux, Rocky Linux, CentOS Stream
sudo curl -fsSL -o /etc/yum.repos.d/dixon.repo https://repo.dixon.cx/rpm/dixon.repo
sudo dnf install dixon-vault mapsize
The first install asks you to import the key, showing its fingerprint; check it against the one below before saying yes. dnf then checks the signature on both the repository and every package.
openSUSE
sudo zypper addrepo https://repo.dixon.cx/rpm/dixon.repo
sudo zypper install dixon-vault mapsize
zypper asks whether to trust the key the first time, in the same way.
Arch Linux, Manjaro, EndeavourOS
Import and locally sign the key, add a [dixon] section to the end of /etc/pacman.conf, then install:
curl -fsSL https://repo.dixon.cx/dixon.asc | sudo pacman-key --add -
sudo pacman-key --lsign-key C22FF7330668417C62C7A304CBC7951D7F2234D1
printf '\n[dixon]\nServer = https://repo.dixon.cx/arch/$arch\n' | sudo tee -a /etc/pacman.conf
sudo pacman -Sy dixon-vault mapsize
Every package and the repository database carry a detached signature, so pacman's default SigLevel = Required checks them all. There are builds for x86_64 and for Arch Linux ARM (aarch64 and armv7h).
The signing key
Everything in the repository is signed with one RSA 4096 key, kept only for this job:
repo.dixon.cx signing key <[email protected]>
C22F F733 0668 417C 62C7 A304 CBC7 951D 7F22 34D1
It is published as dixon.asc (ASCII armoured) and dixon.gpg (binary, for apt). To check what you downloaded before trusting it:
curl -fsSL https://repo.dixon.cx/dixon.asc | gpg --show-keys
Why the vault package is called dixon-vault
A package called plain vault already exists: HashiCorp's secrets manager, in Arch's own repositories and in HashiCorp's apt and dnf repositories. If mine had the same name, your package manager could quietly "upgrade" one into the other. So the package is dixon-vault, while the command it installs is still vault. Because both install /usr/bin/vault, the two are marked as conflicting, so your package manager will tell you rather than overwrite one with the other.
Removing the repository
# Debian, Ubuntu
sudo apt remove dixon-vault mapsize
sudo rm /etc/apt/sources.list.d/dixon.list /etc/apt/keyrings/dixon.gpg
# Fedora, RHEL
sudo dnf remove dixon-vault mapsize
sudo rm /etc/yum.repos.d/dixon.repo
# openSUSE
sudo zypper removerepo dixon
# Arch: delete the [dixon] section from /etc/pacman.conf, then
sudo pacman -Rs dixon-vault mapsize
sudo pacman-key --delete C22FF7330668417C62C7A304CBC7951D7F2234D1
How it's built
- From the release tag, not my working copy: one script in each project exports the tagged source, cross-compiles static Go binaries for every architecture and packages them with nfpm as
.deb,.rpmand Arch.pkg.tar.zst. - Signed throughout: apt gets a signed
InRelease, dnf gets signed RPMs and signed repository metadata, and pacman gets a detached signature for every package and for the database. - The native tools build the indexes:
apt-ftparchivefor apt,createrepo_cin a Fedora container for dnf andrepo-addin an Arch container for pacman, so the metadata is exactly what each package manager expects. - Tested the way you'll use it: before publishing these instructions I ran them, word for word, in fresh Debian, Ubuntu, Fedora, AlmaLinux, openSUSE and Arch containers.
If you'd rather not add a repository at all, every release is also on GitHub and at download.dixon.cx, and you can browse the repository itself at repo.dixon.cx.