Profile: mesh¶
Off-grid mesh messaging: Reticulum with NomadNet and LXMF, and the Meshtastic clients
Stage: post-1.0
Who it is for¶
An operator who wants encrypted off-grid messaging for EMCOMM or experiment, over a local network now and over LoRa when a board arrives.
At a glance¶
| Stage | post-1.0 |
| Units | 5 |
| Disk | about 70 MB of venvs, plus two apt packages |
| Hardware | None for Reticulum on a local network. A LoRa board (an RNode for Reticulum, a Meshtastic node) for radio links. No LoRa link has been run through this profile. |
| Consent | none |
| Install | hammunition install mesh |
What it installs¶
Two mesh networks that do not talk to each other, and the programs for each.
Reticulum is a general networking stack: addresses are keys, every packet is encrypted, and one network can run over a LoRa radio, a packet modem, a cable or an ordinary network with no router. rns is the stack, its command tools (rnstatus, rnpath, rnprobe, rncp, rnx, rnsh, rnid), the RNode flasher rnodeconf, and a systemd user service that keeps one shared instance running for your account. lxmf is the message layer and lxmd, a store-and-forward daemon you run only on purpose. nomadnet is the terminal messenger and page browser.
Meshtastic is a ready-made text mesh on LoRa with phone apps: the command-line client (python3-meshtastic) and a GTK desktop client (gtk-meshtastic-client) from the distribution's archive.
All of the Reticulum programs come from PyPI, hash-pinned, each in its own per-user virtualenv: no archive carries them. Reticulum's licence is its own (MIT plus two use restrictions) and is printed in the plan before you confirm.
Disk footprint: About 70 MB for the three Reticulum virtualenvs (20, 20 and 27 MB, measured 2026-10-03 on Python 3.13.5; each carries its own copy of rns), plus the two Meshtastic packages and their dependencies from the archive, which were not measured here.
Why these belong together¶
They are the two off-grid messaging networks a person with a LoRa board is most likely to meet, and they use the same boards, the same dialout group and the same serial tools, so one profile gets a laptop ready for either. They are a choice, not a bridge: a Meshtastic node and a Reticulum node do not exchange messages. Reticulum is the one with no central design and a wider reach (a laptop on one Wi-Fi, a TCP link, a LoRa RNode, a Direwolf modem, all one network); Meshtastic is the one with the ready hardware and the phone app.
Packages (5)¶
rns, lxmf, nomadnet, python3-meshtastic, gtk-meshtastic-client
What it deliberately excludes¶
Sideband, Reticulum's phone-style client: a 293 MB Kivy environment under a non-commercial Creative Commons licence, with a compiler build on arm64 (mesh-inventory.md); its own decision. Reticulum MeshChat, which ships only as an AppImage (a post-1.0 backend). meshtasticd, the Linux Meshtastic node daemon, which no distribution archive carries and which comes from a third-party repository (the next unit of this track), and MeshCore and its clients. Any TAK server or client. Any Reticulum configuration: the engine writes none, and the file is yours.
Install it¶
Read the plan first. It changes nothing and prints every package, build, file and system change, and every consent gate you will meet:
Then do it. The engine asks for your sudo password once, near the start,
and shows the same plan again before it asks you to confirm:
A member your machine cannot take is deferred by name and the rest installs (D-039); the plan lists each under Will NOT happen, with the reason and the command that fixes it. Installation explains how to read every part of the plan.
What you configure by hand afterward¶
Reticulum. Nothing is required for two machines on one local network: rnsd writes ~/.reticulum/config on first start with the AutoInterface on. Start the service now with systemctl --user start hammunition-rnsd (it is enabled and begins at your next login). For the internet add a TCPClientInterface; for LoRa flash an RNode with rnodeconf --autoinstall and add an RNodeInterface with a frequency you are allowed to use. The guide has the stanzas. Reticulum encrypts every packet, which matters on amateur frequencies (Part 97 in the United States): the guide states it as a disclosure and does not rule on it. NomadNet creates your identity in ~/.nomadnetwork on first run; keep it.
Meshtastic. Set the radio region on the node before it will transmit, and expect the client and the node's firmware to want matching versions. Add yourself to dialout for either family and log out and back in.
Your first ten minutes¶
- Read the plan first:
hammunition install mesh --dry-run. It names the Reticulum licence beside the venv step, the user service it will write, and any Meshtastic package your archive lacks, which it defers rather than refuses. - Install:
hammunition install mesh. The Reticulum programs are fetched from PyPI against pinned hashes, so it needs the network and takes a minute or two. - Start the shared instance now:
systemctl --user start hammunition-rnsd, thenrnstatus. It should show a shared instance and the AutoInterface. - Put
~/.local/binon your PATH if the shell saysrnstatus: command not found(a new shell usually does it), then runnomadnetand write down the address it shows. - On a second machine on the same network, install the profile too and message the first one. Mesh and Reticulum walks through it, then the internet and LoRa.
- For radio, read the legal note in the guide's section 6 before you transmit, add yourself to
dialout, and flash an RNode withrnodeconf --autoinstall.
Take it off again¶
This removes what Hammunition itself installed and nothing else. It does not remove dependencies apt pulled in, group memberships or configuration files it wrote; the plan says so and the transaction log records them (D-004).