What you need
- x86-64 Linux, or aarch64. Nothing has been run on real ARM64 hardware;
multiarch.mdsays what has been checked. - A Wayland session. X11 works too (ADR-024); Wayland is the primary backend.
- Roblox’s official Android client, which you supply. Cordial ships no Roblox code, APK or assets.
Getting Roblox’s build
On first run, press Download Roblox. Cordial fetches the newest build from a mirror, checks that Roblox’s own signing certificate signed it, and keeps its own copy in~/.local/share/cordial/builds/ (in the Flatpak,
~/.var/app/io.github.luohoa97.Cordial/data/cordial/builds/). Why:
ADR-015,
ADR-025,
ADR-054.
- Sober is installed: the first-run screen also offers Copy Sober’s build, and Settings → Roblox has an Import from Sober row while Sober holds a build Cordial does not. Either copies the files into Cordial’s own store after the same signature check. Cordial does not change Sober’s files and does not follow its updates: from then on the build changes when you update it in Cordial (Settings → Updates), not when Sober updates.
- You have your own APK: Settings → Roblox → Import from a file copies
it into the store the same way. Keep
base.apkandsplit_config.x86_64.apkin one folder: on a split build the engine is in the split, and Cordial says which file it looked for if it finds none. In the Flatpak the file chooser may hand Cordial only the file you picked, so a split build’s other half would not be seen (INFERRED, not tried): import a single combined APK there, or copy Sober’s build. To run one APK for a single launch without filing it, start Cordial withCORDIAL_APK=/path/to/base.apk. - Upgrading from an older Cordial: the first launch files whatever the old layout ran (Cordial’s own download, Sober’s copy, or an APK chosen in Settings) into the store, once. An APK chosen in Settings is imported, every profile with no pinned version is pinned to it so it keeps running that file, and the saved path is cleared.
Install
Every file on a release page can be verified before you install it; see Check what you downloaded.- Flatpak
- AppImage
- Debian / Ubuntu
- Fedora / RHEL
- Arch
- Nix
- From source
Recommended.Launch it from your application list, or with
To follow
flatpak run io.github.luohoa97.Cordial.Branches. The install above is
stable, which moves only on a tagged
release. master moves on every commit to main. The remote once published
only master, so an install from before stable existed is still on it. To
move it (add --user to both if that is how you installed):main on purpose, install io.github.luohoa97.Cordial//master.Flatpak limitation. The updater asks NetworkManager on the system bus
whether your connection is metered. The sandbox has no system bus, so the check
fails closed and a Flatpak install treats every connection as metered. It will
not download a Roblox build in the background unless you turn on Download on
metered connections. Manual downloads are unaffected.The Flatpak workflow
publishes only on a green run, so a red run on main means the remote is still
serving the previous build.Check what you downloaded
Files on a release page and the package repositories are verified differently.Release-page files (cosign)
Release-page files (cosign)
Every
.deb, .rpm, .AppImage and Arch package on a release page has a
.cosign.bundle beside it. The signature is keyless: there is no Cordial signing
key to trust or lose. It proves the file came out of this repository’s own
release workflow at that tag. Install
cosign, then:Verified OK is the whole answer. Do not drop the two --certificate-*
flags. Without them cosign confirms that somebody signed the file, which is not
the question you are asking. Every signature is recorded in Sigstore’s public
transparency log.This covers the release page only. The Flatpak remote and the apt, dnf and
pacman repositories use OpenPGP keys, below.Flatpak remote key
Flatpak remote key
The published A remote added while it was unsigned stays unverified. Flatpak recorded
cordial.flatpakrepo carries a GPG key, and the repository summary
has a detached signature, so flatpak install checks the download was signed by
it. Fingerprint:gpg-verify=false then, and a later signed definition does not change it. If you
added the remote before the key existed, remove and re-add it
(flatpak remote-delete cordial, then the remote-add above).INFERRED: the fingerprint was read from the published file on 2026-09-30, not
confirmed out of band. That day summary.sig was published and ostree remote refs verified the summary against the key in a throwaway repository;
flatpak install was not run against it.A signature does not make GitHub Pages trustworthy: whoever holds the private
key, a repository secret, can sign anything. That is a weaker arrangement than
Flathub’s, and if you would rather not extend that trust, build from source.
Cordial is not on Flathub and, on its current generative-AI policy, cannot be; the
remote is the distribution channel, not a stopgap
(why,
signing procedure).apt repository key
apt repository key
dists/stable/InRelease carries an OpenPGP signature from this key. INFERRED:
the fingerprint was read from the published keyring on 2026-09-30, not confirmed
out of band. InRelease verified against that keyring; apt install was not
run.dnf repository key
dnf repository key
.repo file sets repo_gpgcheck=1 and gpgcheck=0: each release
directory’s repodata/repomd.xml is signed, not the individual .rpm
(design note). INFERRED: the fingerprint was read
from the published site on 2026-09-30, not confirmed out of band.
rpm/44/x86_64/repodata/repomd.xml.asc verified against it; dnf install was
not run.pacman repository key
pacman repository key
Fingerprint, as used in the INFERRED: read from the published keyring on 2026-09-30, not confirmed out of
band.
pacman-key --lsign-key command above:cordial.db.sig verified against it. The release-page package needs no key
at all, see the cosign section.