PML 2

Installation

This document explains how to install PML 2.

Windows installation

  1. Download the installer from the official site / release page: pml2 setup <version> AOT.exe for x64, pml2_setup_arm64_<version>.exe for ARM64.
  2. Double-click it and follow the wizard (the default location is %LOCALAPPDATA%\PML 2).
  3. After installation, launch PML 2 from the desktop or the Start menu.
    While downloading, your browser or Windows Defender may warn that the file is unsafe. This is expected: the installer is not digitally signed. Choose to trust it.
The installer supports silent parameters: /silent /sp- /nocancel (identical for the AOT and Common builds).

Linux installation

Download pml2-<version>-linux-x64-aot.deb (...-linux-arm64-aot.deb for ARM64; a .rpm is provided as well). The install path is fixed at /opt/pml-2 and the app can be launched from the application menu.
This section assumes you know how to open a terminal on a Linux desktop, and that you are comfortable troubleshooting on your own with basic Linux knowledge.

Open a terminal and run:

# wget is required
sudo apt install wget

bash <(curl -sSL https://api.rycb.tech/api/pml2/install)

Follow the prompts to finish the installation.

macOS installation

Because of macOS security policies, you must complete the steps below after installing before PML 2 can run normally.
This section assumes you know how to open a terminal on macOS, and that you are comfortable troubleshooting on your own with basic macOS knowledge.
Download pml2-<version>-macos-x64-aot.dmg (...-macos-arm64-aot.dmg for Apple Silicon), double-click to mount it, then drag the app into "Applications".
The app bundle declares the pml2:// URL scheme (the TPCA universal link that starts a tunnel), so it can be launched from a browser or another app. On Windows / Linux it is registered automatically on first start (per-user, no administrator required). See the troubleshooting guide "Starting a tunnel from a link".

First run: the mefrpc client

When the first tunnel starts, the app downloads the mefrpc client into the bin/ directory (mefrpc.exe on Windows, mefrpc.tar on Linux/macOS) and, once the download finishes, unpacks/verifies it and starts the tunnel.

First fetch failures

ScenarioSymptomWhat to do
Download failureThe download dialog reports an error / closes, the tunnel does not startSwitch the download source (TPCA ↔ Official) on the Settings page and start the tunnel again
Verification failureA message says the client file failed verificationDelete the leftover mefrpc*.tmp and corrupted files under bin, then retry
Interrupted downloadThe progress in the download dialog stops / is cancelledStart the tunnel again to resume (the downloader retries 5 times internally)

The DownloadSource setting (default TPCA) applies to both the mefrpc client and application update packages. See the user guide "Download source".

First run: the lego component of the certificate assistant

The installer does not bundle lego (the ACME client). The first time you request a certificate in "Settings → Tunnel settings → Certificate assistant", the matching build for your platform is downloaded (about 20 MB, verified against the SHA-256 in the official checksums.txt) and unpacked into Tools/lego/<rid>/.

ScenarioSymptomWhat to do
Download failureStuck on "Preparing lego…" or told lego cannot be preparedCheck your network/proxy and retry (the app tries the primary GitHub source and a fallback mirror in turn)
Verification failureSame as above (the app refuses to use a binary that fails verification)Just retry; if it keeps failing, check whether your network is being rewritten by a man-in-the-middle proxy
Offline or intranet-only useThe download cannot completeAccess to GitHub or a mirror is currently required; see the troubleshooting guide "Certificate request failures"

In-app updates

Updates live on the "Update" page: check for updates → download and install. Failure paths (fetch failure, download failure, verification failure, retrying with a different source) are covered in the troubleshooting guide "Update failures".

Copyright © RYCBStudio 2026, All Rights Reserved.