Skip to main content
Use the Flatpak unless you have a reason not to. It is sandboxed, updates in place, and runs on one fixed runtime (GNOME 50), so the GTK, WebKit, Vulkan and audio libraries are the ones Cordial is tested against. Most compatibility problems reported with the other formats come from those libraries differing.

What you need

  • x86-64 Linux, or aarch64. Nothing has been run on real ARM64 hardware; multiarch.md says what has been checked.
  • A Wayland session. X11 works too (ADR-024); Wayland is the primary backend.
  • Roblox’s official Android client, which you supply. Cordial ships no Roblox code, APK or assets.

Getting Roblox’s build

On first run, press Download Roblox. Cordial fetches the newest build from a mirror, checks that Roblox’s own signing certificate signed it, and keeps its own copy in ~/.local/share/cordial/builds/ (in the Flatpak, ~/.var/app/io.github.luohoa97.Cordial/data/cordial/builds/). Why: ADR-015, ADR-025, ADR-054.
  • Sober is installed: the first-run screen also offers Copy Sober’s build, and Settings → Roblox has an Import from Sober row while Sober holds a build Cordial does not. Either copies the files into Cordial’s own store after the same signature check. Cordial does not change Sober’s files and does not follow its updates: from then on the build changes when you update it in Cordial (Settings → Updates), not when Sober updates.
  • You have your own APK: Settings → Roblox → Import from a file copies it into the store the same way. Keep base.apk and split_config.x86_64.apk in one folder: on a split build the engine is in the split, and Cordial says which file it looked for if it finds none. In the Flatpak the file chooser may hand Cordial only the file you picked, so a split build’s other half would not be seen (INFERRED, not tried): import a single combined APK there, or copy Sober’s build. To run one APK for a single launch without filing it, start Cordial with CORDIAL_APK=/path/to/base.apk.
  • Upgrading from an older Cordial: the first launch files whatever the old layout ran (Cordial’s own download, Sober’s copy, or an APK chosen in Settings) into the store, once. An APK chosen in Settings is imported, every profile with no pinned version is pinned to it so it keeps running that file, and the saved path is cleared.
Each profile runs the newest build in the store (Latest) or one version you pinned on Settings → Version. The store keeps the newest build, the one before it, any build a profile is pinned to and any a client is running; an update removes the rest. Settings → Roblox lists what is kept, where each build came from, how much disk it takes and which profiles use it, and removes a build that nothing needs. The engine and the game’s assets are unpacked next to the build they came from, and there is nothing to configure for either. Nothing else is needed to run a package. The Flatpak carries its own toolchain and libraries.

Install

Every file on a release page can be verified before you install it; see Check what you downloaded.
Recommended.
Launch it from your application list, or with flatpak run io.github.luohoa97.Cordial.Branches. The install above is stable, which moves only on a tagged release. master moves on every commit to main. The remote once published only master, so an install from before stable existed is still on it. To move it (add --user to both if that is how you installed):
To follow main on purpose, install io.github.luohoa97.Cordial//master.Flatpak limitation. The updater asks NetworkManager on the system bus whether your connection is metered. The sandbox has no system bus, so the check fails closed and a Flatpak install treats every connection as metered. It will not download a Roblox build in the background unless you turn on Download on metered connections. Manual downloads are unaffected.The Flatpak workflow publishes only on a green run, so a red run on main means the remote is still serving the previous build.

Check what you downloaded

Files on a release page and the package repositories are verified differently.
Every .deb, .rpm, .AppImage and Arch package on a release page has a .cosign.bundle beside it. The signature is keyless: there is no Cordial signing key to trust or lose. It proves the file came out of this repository’s own release workflow at that tag. Install cosign, then:
Verified OK is the whole answer. Do not drop the two --certificate-* flags. Without them cosign confirms that somebody signed the file, which is not the question you are asking. Every signature is recorded in Sigstore’s public transparency log.This covers the release page only. The Flatpak remote and the apt, dnf and pacman repositories use OpenPGP keys, below.
The published cordial.flatpakrepo carries a GPG key, and the repository summary has a detached signature, so flatpak install checks the download was signed by it. Fingerprint:
A remote added while it was unsigned stays unverified. Flatpak recorded gpg-verify=false then, and a later signed definition does not change it. If you added the remote before the key existed, remove and re-add it (flatpak remote-delete cordial, then the remote-add above).INFERRED: the fingerprint was read from the published file on 2026-09-30, not confirmed out of band. That day summary.sig was published and ostree remote refs verified the summary against the key in a throwaway repository; flatpak install was not run against it.A signature does not make GitHub Pages trustworthy: whoever holds the private key, a repository secret, can sign anything. That is a weaker arrangement than Flathub’s, and if you would rather not extend that trust, build from source. Cordial is not on Flathub and, on its current generative-AI policy, cannot be; the remote is the distribution channel, not a stopgap (why, signing procedure).
dists/stable/InRelease carries an OpenPGP signature from this key. INFERRED: the fingerprint was read from the published keyring on 2026-09-30, not confirmed out of band. InRelease verified against that keyring; apt install was not run.
The .repo file sets repo_gpgcheck=1 and gpgcheck=0: each release directory’s repodata/repomd.xml is signed, not the individual .rpm (design note). INFERRED: the fingerprint was read from the published site on 2026-09-30, not confirmed out of band. rpm/44/x86_64/repodata/repomd.xml.asc verified against it; dnf install was not run.
Fingerprint, as used in the pacman-key --lsign-key command above:
INFERRED: read from the published keyring on 2026-09-30, not confirmed out of band. cordial.db.sig verified against it. The release-page package needs no key at all, see the cosign section.