Project context

An old packaging idea, rebuilt from scratch.

Conary takes inspiration from a mid-2000s design that got several things right early, then starts again in Rust with a deliberately narrow public preview and a modern generation model.

Independent project

This is a ground-up reimplementation in Rust, not a fork, port, resurrection, or continuation of the original rPath Conary codebase. It is not affiliated with, endorsed by, or maintained by rPath, SAS, or the original Conary developers.

Origins

The ideas outlived the first implementation.

The name is carried forward as a tribute to the engineering that got there first.

  1. mid-2000s

    rPath builds the original Conary

    The original Conary package manager, developed by the rPath team, pioneered content-addressable package storage, repository-level binary diffs, a SAT-based resolver, and rollback of system state.

  2. 2011

    The implementation goes dormant

    The Python 2 implementation was tied to rPath Linux and Foresight Linux. After SAS acquired rPath, the project went dormant while its package-management ideas remained relevant.

  3. now

    Conary starts again in Rust

    The current project treats the filesystem as a content store, gives mutations explicit transaction and recovery boundaries, and resolves dependencies before applying changes, without reusing a line of the original codebase.

Who makes it

A Fieldmouse Works project.

Conary is built by Fieldmouse Works, the home for open tools aimed at closed, expensive, or restrictive software ecosystems. The source lives at github.com/FieldmouseWorks/Conary; the GitHub organization was previously named ConaryLabs, and old links redirect.

It is a single-maintainer project, which is why the verification layer carries the weight a team's review would otherwise carry. The integration harness runs the RPM, DEB, Arch, and CCS pipeline inside Fedora 44, Ubuntu 26.04, and Arch containers against a one-package fixture repository served from the harness's own loopback server: the native package managers and package payloads inside those containers are real, the repository is not. The only clean-host proof is the release artifact proof, which installs the published packages into clean base images of the three distributions through the signed bootstrap and is recorded in the release matrix. A documentation-truth check fails CI when the README, the roadmap, or this site claims something the code does not do.

Licensing

The Conary client and every library crate are licensed MIT OR Apache-2.0, so you may use either license. Remi, the hosted package service, is licensed AGPL-3.0-or-later: if you run a modified Remi as a service, its users are entitled to the source. Releases published through v0.16.1 remain MIT.

The problem

Linux package state is fragmented by distribution.

Every distribution maintains its own package format, repositories, tools, and transaction model. Switching hosts means changing commands and expectations, while package availability and recovery behavior vary.

Conary does not ask upstream maintainers to change their packages. RPM, DEB, and Arch inputs are converted into source-independent CCS transactions that retain the source package ABI and run against typed target capabilities, locally or through Remi.

The first cross-distro loop installs a foreign-format artifact, inspects it, plans an update, and removes it. Adoption remains a separate migration path for packages already owned by the host package manager.

Architecture

Package state, content, and generation artifacts stay distinct.

Format parsers
RPM, DEB, and Arch parsers preserve exact lifecycle, dependency, version, payload, and configuration semantics in one source-independent model.
Resolver
resolvo provides SAT-based dependency resolution across conflicts, virtual provides, and typed dependencies.
CAS layer
Files are stored by hash rather than only by package, so identical content is kept once.
Package changesets
Package operations commit database and file state through explicit changesets rather than implying a bootable generation for every install.
Generation artifacts
The advanced path builds EROFS images and can integrate composefs and fs-verity on compatible hosts, with raw, qcow2, and ISO export.
System model
Desired package state can be declared and inspected for drift; live application remains a VM-only path.
Remi
The conversion and package-serving service: authenticated source ingestion, immutable catalogs, signing, and atomic activation.
Bootstrap
A staged pipeline builds from cross-tools through a complete system image, with experimental architecture targets beyond the packaged x86_64 lane.

Implementation

The current stack

Language
Rust, Edition 2024 · one Cargo workspace, one synchronized release
Filesystem
EROFS · composefs and fs-verity for generations where the kernel supports them
Database
SQLite · explicit schema epoch with a rebuild boundary instead of migrations
Hashing
SHA-256 · XXH3 · FastCDC content-defined chunking
Signatures
Ed25519 for CCS artifacts and the release bootstrap manifest
Compression
Zstd · Gzip · XZ
Resolver
resolvo SAT solver
Server
Axum · Tantivy full-text search

Contribute

Help turn preview evidence into a trustworthy package manager.

The repository runs unit, integration, harness, formatting, lint, documentation-truth, and release workflows. Open issues and the contributing guide are the entry points.