Pre-alpha · cross-distro package manager for Linux

An RPM that installs on Ubuntu. A DEB that installs on Fedora.

Conary installs RPM, DEB, and Arch packages on Fedora, Ubuntu, and Arch hosts. Each package keeps its source format's exact lifecycle, dependency, version, and configuration semantics; Conary owns the transaction and the rollback. It never hands the work to dnf, apt, or pacman.

  • RPM · DEB · Arch · CCS
  • Fedora 44 · Ubuntu 26.04 LTS · Arch Linux
  • x86_64 · Rust · MIT OR Apache-2.0
Cross-format package executionRPM, Debian, and Arch packages each enter one Conary transaction that keeps the source package ABI, then execute against typed capabilities on a Fedora, Ubuntu, or Arch host.SOURCE PACKAGETARGET HOST.rpm.deb.pkg.tar.zstFedora 44Ubuntu 26.04Arch LinuxCONARYone transactionsource ABI preserved · typed target capabilitiesinstall · update · remove · rollback
A source package keeps its RPM, Debian, or ALPM semantics while typed target capabilities feed one Conary-owned package transaction.

Current status

Latest release
v0.17.2, an immutable GitHub release with checksums, a detached CCS signature, and a signed bootstrap manifest.
Maturity
Pre-alpha. Expect failures. Use a VM, a snapshot, or a host you can throw away. It is not a replacement for apt, dnf, or pacman on a machine you rely on.
External testing
Not open yet. No release is assigned as tester authority; the remaining launch gates are tracked in the open in launch-status.json.

The bet

A package format is a source input, not a wall.

A package belongs to the distribution that built it. If the software you need ships as an RPM and you run Ubuntu, you wait for a Debian maintainer, reach for a container, or change distributions. The same software gets packaged once per ecosystem, and the cost lands on maintainers and on anyone whose distro is not the popular one.

Conary's bet is that this boundary is mechanical, not fundamental. RPM, Debian, and ALPM each expose a finite, documented lifecycle ABI. Encode those exactly, describe what a host provides as typed capabilities, and a package stops being the property of one distribution, while Conary, not the distro's package manager, owns the transaction and the way back.

Existing distro repositories become source inputs to one package engine.

Today that holds for RPM, DEB, Arch, and CCS packages on Fedora 44, Ubuntu 26.04 LTS, and Arch Linux, x86_64 only. Everything on this site is labelled with how far it has actually been proven.

Who owns what

Three parties, one transaction.

The whole design reduces to a division of authority. Nothing in it is inferred from script text, distro names, or the host package manager's opinion.

The source format owns

The package ABI

  • Lifecycle events, their arguments, and their ordering
  • Dependency and version comparison rules
  • Payload layout and metadata
  • Configuration-file semantics
Conary owns

The transaction

  • Install, update, and remove
  • Rollback and the changeset record
  • Content-addressed storage of installed files
  • Generation publication on hosts that support it
The target supplies

Typed capabilities

  • Architecture, libc, and dynamic loader
  • Init and service-manager interfaces
  • Filesystem layout, users, and security policy
  • Interpreters and helper contracts

A package that needs a capability the host does not provide fails preflight before anything is mutated. A lifecycle form Conary has not modelled is a bug to fix, not a reason to guess.

What works today

Working on the three supported hosts.

Proof runs in the integration harness, inside Fedora, Ubuntu, and Arch containers against a harness-served fixture repository, on the current tree. The release matrix records the artifact proof and its limits for v0.17.2.

  • Installing RPM, DEB, and Arch artifacts through typed lifecycle, dependency, payload, and configuration contracts, on any of the three hosts.
  • Installing native CCS packages and Remi-converted RPM, DEB, and Arch packages with Conary as package authority.
  • Adopting packages already owned by dnf, apt, or pacman, and unadopting them without deleting anything.
  • Atomic package-state changesets, history, and rollback-oriented state tracking.
  • Immutable EROFS and composefs generations, plus raw, qcow2, and x86_64 UEFI ISO export, on hosts with the kernel and tooling.
  • A signed release: checksummed packages, a detached CCS signature, and an Ed25519-signed bootstrap manifest.

What will break

Known edges, stated up front.

  • A package that needs a target capability the host does not provide fails exact preflight before mutation.
  • Source lifecycle forms outside the implemented RPM, Debian, or ALPM ABI are bugs to model and test; Conary does not invent behaviour from command text.
  • Security-only updates fail closed unless a repository declares trusted advisory metadata support.
  • Native transaction-history import is not implemented.
  • Non-x86_64 generation boot assets are still reserved.
  • No SBOM or provenance sidecars are published for the current release.

The bounded loop · inactive until a release is pinned

Cross the format boundary, then prove you can come back.

Pick a source whose package format differs from the host. Every dry-run shows the package's typed lifecycle, dependencies, payload, and required host capabilities before any package transaction is applied. --yes is required only for commands the risk policy classes as active-host, selected-root, destructive-database, or always-live mutations, and only outside --dry-run. Everything else runs without confirmation even when it changes state. The policy classes and known exceptions are derived from apps/conary/src/command_risk.rs.

What changes

Conary owns the installed files, state, lifecycle transaction, and rollback record.

What stays source-native

The RPM, Debian, or ALPM ABI, not command-name guesses or the host's package manager.

source=ubuntu-26.04  # on Fedora or Arch; use fedora-44 on Ubuntu $sudo conary install htop --from "$source" --dry-run $sudo conary install ./package.deb --dry-run $sudo conary list $sudo conary update --dry-run

Dry runs plan and print without applying a package transaction or changing an installed dependency to an explicitly installed package. The live install, update, and remove loop is owned by the tester guide, which is paused until a release is pinned; the install page keeps its retained commands folded away. No output is shown because it varies by host.

Honest fit check

Evaluate package portability first, migration second.

apt, dnf, pacman, and Nix are mature systems with far larger ecosystems. Conary is not the mature choice today. Its bet is different: existing distro repositories become source inputs to one package engine, and adoption stays the bridge for the machine you already have.

Inspect it on a disposable host

Install the pre-alpha and read the plan before you apply it.

The bootstrap script verifies the signed release manifest and the package for your host before it touches anything, and previews by default. The external tester loop stays inactive until a release is pinned.