Skip to content

CLI Reference ​

All commands accept --help for usage.

onelf init ​

Scaffold a starter onelf.toml.

onelf init [-o FILE] [--binary PATH] [--force]
FlagDefaultDescription
-o, --outputonelf.tomlWhere to write the recipe
--binarynoneSeed name/command from this binary's basename
--forcefalseOverwrite existing file

onelf build ​

Run bundle-libs + pack from a recipe.

onelf build [PATH] [-o FILE]
Arg / FlagDefaultDescription
PATH.Directory or .toml file
-o, --output[package.output]Override recipe's output path

onelf run ​

Run an AppDir in place for dev iteration.

onelf run [PATH] [--command PATH] [--entrypoint NAME] [--bundle] [-- ARGS...]
FlagDescription
PATHAppDir or .toml file (default .)
--commandBinary to exec, relative to AppDir
--entrypointSelect a recipe-defined entrypoint
--bundleRun bundle-libs from the recipe first
-- ARGSPassed to the entrypoint

onelf pack ​

Pack a directory into an executable.

onelf pack DIRECTORY -o OUTPUT --command PATH [options]
FlagDefaultDescription
-o, --outputrequiredOutput file
--commandrequiredPath to main binary within DIRECTORY
--namecommand basenamePackage name
--entrypoint NAME=PATHAdd extra entrypoint (repeatable)
--default-entrypoint NAMESelect default entrypoint
--lib-dir DIR[auto]Library dir for LD_LIBRARY_PATH (repeatable)
--level N12Zstd compression level (0 to 22)
--block-size SIZE256KBytes per payload block, K/M suffix allowed (4K to 32M)
--dictfalseTrain shared zstd dictionary
--no-compressfalseStore payload raw, no zstd (overrides --dict)
--preload PATHLibrary dlopen'd on every exec via onelf-env (repeatable, re-exec-safe)
--memfdautoForce memfd eligibility on
--no-memfdForce memfd eligibility off
--working-dir MODEinheritinherit, package, or command
--update-url URLzsync URL; enables update runtime
--update-key PATH32-byte Ed25519 public key; required for self-update
--no-embed-updaterfalseRecord the update URL without embedding the updater (saves 1.36 MB)
--host-libs MODEautoauto, always, or never: expose the host's library dirs
--exclude GLOBExclude paths matching glob (repeatable)

onelf bundle-libs ​

Resolve and copy shared library dependencies.

onelf bundle-libs DIRECTORY [options]
FlagDefaultDescription
--target PATHall ELFAnalyze only this binary
--from-binary PATHCopy binary into DIRECTORY/bin/ first
--lib-dir DIRlibWhere to place bundled libs
--exclude PFXSoname prefixes to skip (comma/repeat)
--include SONAMEForce-include this soname (comma/repeat)
--search-path DIRExtra lib search dir (highest priority)
--dry-runfalseReport without copying
--no-recursivefalseDon't resolve transitive deps
--gl, --dri, --vulkan, --wayland, --gtkautoFramework bundlers. Auto-detect inspects both DT_NEEDED and versioned soname strings in the binary, so dlopen'd frameworks are picked up too
--no-gl, --no-dri, --no-vulkan, --no-wayland, --no-gtkfalseForce-off a framework, overriding auto-detection and the matching --* flag
--stripfalseRun strip --strip-unneeded
--strict-libcfalseSkip wrong-family libc libs
--scan-dlopenfalseScan binary strings for common dlopen sonames
--dlopen SONAMEExtra sonames for --scan-dlopen (comma/repeat)
--sysroot DIRTake the bundle's contents from this sysroot's package database; needs --target
--sysroot-optional PKGOptional dependency to include from the sysroot (repeatable)
--platform-line FILESoname prefixes the host provides, one per line
--policy FILEGlob patterns that never ship, one per line
--trace FILEPaths a test run opened, one per line

onelf sysroot ​

Obtain and inspect pinned sysroots. See Bundling from a Sysroot.

onelf sysroot fetch SOURCE DIR
onelf sysroot info DIR
onelf sysroot pack-gl DIR -o FILE
CommandDescription
fetch SOURCE DIRMaterialize a .tar or .tar.zst rootfs from a local path or an https:// URL into DIR
info DIRPrint the package count, file count and glibc version of a materialized sysroot
pack-gl DIR -o FILEPack a GL build for hosts without one from a tree holding lib/, share/vulkan/icd.d and friends, after verifying it is self-contained, and print the BLAKE3 hash to pin in platform.toml

onelf info ​

Show metadata.

onelf info BINARY

onelf list ​

List packaged files.

onelf list BINARY

onelf extract ​

Extract files from a packed binary.

onelf extract BINARY [-o OUT] [--file PATH ...]

Without --file, extracts everything to onelf_extracted/ (or -o). With one --file and -o -, pipes that file to stdout.

onelf verify ​

Recompute BLAKE3 of each file entry and compare against the manifest.

onelf verify BINARY

Exit 0 on match, 1 on mismatch.

onelf icon ​

Extract the bundled icon.

onelf icon BINARY [--entrypoint NAME] [-o FILE]

onelf desktop ​

Extract the bundled .desktop file.

onelf desktop BINARY [--entrypoint NAME] [-o FILE]

onelf integrate ​

Install desktop shortcut and icon for a packed binary.

onelf integrate BINARY [--entrypoint NAME]

Installs the icon to $XDG_DATA_HOME/icons/hicolor/ and a .desktop file to $XDG_DATA_HOME/applications/. The Exec=, TryExec=, and Icon= fields are patched automatically. If the package has no bundled desktop file, a minimal one is generated.

FlagDescription
--entrypointEntrypoint name (default: default entrypoint)

onelf unintegrate ​

Remove desktop shortcut and icon installed by integrate.

onelf unintegrate BINARY [--entrypoint NAME]

onelf key ​

Manage the Ed25519 keys that sign self-updates.

onelf key new [--secret PATH] [--public PATH]
onelf key show --secret PATH [-o PATH]
FlagDefaultDescription
--secret PATHonelf.keySecret key file, created owner-only
--public PATHonelf.pubPublic key file, 32 raw bytes for --update-key
-o, --output PATHstdoutWhere show writes the public key

new refuses to overwrite an existing key file.

onelf sign ​

Write the detached signature the runtime verifies before installing an update.

onelf sign BINARY --key PATH [-o PATH]
FlagDefaultDescription
--key PATHSecret key file from onelf key new
-o, --output PATHderived from the package's update URLSignature output path

The default output name comes from the update URL the package carries, because that is the only name the runtime requests: a package whose update URL is app.onelf.zsync needs its signature at app.onelf.zsync.sig. Signing refuses when the key does not match the one embedded in the package. See Self-Update for the full publish flow.

onelf cache ​

Manage the persistent cache: packages extracted by the cache mode, and the GL builds fetched for hosts without one. list shows both; gc removes packages and builds unused past the age threshold.

onelf cache list
onelf cache clear
onelf cache gc [--max-age DAYS]

Released under the MIT License.