Skip to content

fix: release binaries that run without Nix - #26

Merged
iamralch merged 2 commits into
mainfrom
fix/portable-binaries
Oct 6, 2026
Merged

iamralch merged 2 commits into
mainfrom
fix/portable-binaries

Conversation

@iamralch

@iamralch iamralch commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Problem

The 0.3.0 release binaries only run on machines with Nix:

Asset Depends on
keysafe-aarch64-darwin /nix/store/…-libiconv/lib/libiconv.2.dylib
keysafe-x86_64-linux interpreter /nix/store/…-glibc/lib/ld-linux-x86-64.so.2

On any other machine they fail to start. crates.io is not affected, since cargo install builds locally.

Fix

  • Build with plain cargo on the GitHub runners, not nix build:

    Runner Target Result
    ubuntu-latest x86_64-unknown-linux-musl static, runs on any distribution
    ubuntu-24.04-arm aarch64-unknown-linux-musl static, runs on any distribution
    macos-15 aarch64-apple-darwin system libraries only
    macos-15 x86_64-apple-darwin system libraries only (new: Intel Macs)
  • Assets are named after their target (keysafe-<target>). With [package.metadata.binstall] in Cargo.toml, cargo binstall keysafe installs the prebuilt binary, from the next release on.

  • The binaries are built on every CI run, not only on releases, and each is checked to start on its own: static on Linux, and no /nix/store in otool -L on macOS. They're uploaded only when a release is created.

  • The Nix package (nix profile install github:keysafe-dev/keysafe) is unchanged.

README

  • Badges: crates.io version, downloads, CI, license.
  • Installation: cargo install keysafe, cargo binstall keysafe, Nix, and a curl download using the releases/latest/download URL.

This is a fix:, so release-please will propose 0.3.1 with working downloads.

The release binaries were built with Nix and loaded libraries from
/nix/store: libiconv on macOS, the dynamic loader on Linux. They only
started on machines with those exact Nix paths.

Build them with plain cargo on the GitHub runners instead: macOS for
Apple Silicon and Intel, and static musl binaries for x86-64 and arm64
Linux, which run on any distribution. Name them after their target
(e.g. keysafe-aarch64-apple-darwin), so `cargo binstall keysafe`
downloads them.

The binaries are now built on every CI run and checked to start on
their own, not only when a release is cut. The README installs from
crates.io and shows the crates.io badges.
@iamralch
iamralch merged commit 01c2819 into main Oct 6, 2026
8 checks passed
@iamralch
iamralch deleted the fix/portable-binaries branch October 6, 2026 05:40
@ralch ralch Bot mentioned this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant