The package ABI
- Lifecycle events, their arguments, and their ordering
- Dependency and version comparison rules
- Payload layout and metadata
- Configuration-file semantics
Pre-alpha · cross-distro package manager for Linux
Conary installs RPM, DEB, and Arch packages on Fedora, Ubuntu, and Arch hosts. Each package keeps its source format's exact lifecycle, dependency, version, and configuration semantics; Conary owns the transaction and the rollback. It never hands the work to dnf, apt, or pacman.
The bet
A package belongs to the distribution that built it. If the software you need ships as an RPM and you run Ubuntu, you wait for a Debian maintainer, reach for a container, or change distributions. The same software gets packaged once per ecosystem, and the cost lands on maintainers and on anyone whose distro is not the popular one.
Conary's bet is that this boundary is mechanical, not fundamental. RPM, Debian, and ALPM each expose a finite, documented lifecycle ABI. Encode those exactly, describe what a host provides as typed capabilities, and a package stops being the property of one distribution, while Conary, not the distro's package manager, owns the transaction and the way back.
Existing distro repositories become source inputs to one package engine.
Today that holds for RPM, DEB, Arch, and CCS packages on Fedora 44, Ubuntu 26.04 LTS, and Arch Linux, x86_64 only. Everything on this site is labelled with how far it has actually been proven.
Who owns what
The whole design reduces to a division of authority. Nothing in it is inferred from script text, distro names, or the host package manager's opinion.
A package that needs a capability the host does not provide fails preflight before anything is mutated. A lifecycle form Conary has not modelled is a bug to fix, not a reason to guess.
What works today
Proof runs in the integration harness, inside Fedora, Ubuntu, and Arch containers against a harness-served fixture repository, on the current tree. The release matrix records the artifact proof and its limits for v0.17.2.
What will break
The bounded loop · inactive until a release is pinned
Pick a source whose package format differs from the host. Every dry-run shows the
package's typed lifecycle, dependencies, payload, and required host capabilities
before any package transaction is applied. --yes is required only for commands the risk policy classes as active-host, selected-root, destructive-database, or always-live mutations, and only outside --dry-run. Everything else runs without confirmation even when it changes state. The policy classes and known exceptions are
derived from apps/conary/src/command_risk.rs.
source=ubuntu-26.04 # on Fedora or Arch; use fedora-44 on Ubuntu $sudo conary install htop --from "$source" --dry-run $sudo conary install ./package.deb --dry-run $sudo conary list $sudo conary update --dry-runDry runs plan and print without applying a package transaction or changing an installed dependency to an explicitly installed package. The live install, update, and remove loop is owned by the tester guide, which is paused until a release is pinned; the install page keeps its retained commands folded away. No output is shown because it varies by host.
Honest fit check
apt, dnf, pacman, and Nix are mature systems with far larger ecosystems. Conary is not the mature choice today. Its bet is different: existing distro repositories become source inputs to one package engine, and adoption stays the bridge for the machine you already have.
Inspect it on a disposable host
The bootstrap script verifies the signed release manifest and the package for your host before it touches anything, and previews by default. The external tester loop stays inactive until a release is pinned.