Merge remote-tracking branch 'origin/master' into flea-0.3.5

This commit is contained in:
Ryan Hughes committed 2026-09-27 23:05:03 -04:00
commit 132199cb9b
56 files changed
+1669 -198

No files matched your search

+14 -4
View File
@@ -1,7 +1,11 @@
const BUILD = '.github/workflows/build-pr.yml';
const TESTS = '.github/workflows/test.yml';
// pullRequest/action/since default to the pull_request_target event. The
// sync workflows pass them explicitly: GitHub creates no pull_request_target
// run for a GITHUB_TOKEN push, so they release their own pushes' held runs.
module.exports = async function approve({ github, context, core, vouchStatus,
pullRequest = context.payload.pull_request, action = context.payload.action, since,
sleep = ms => new Promise(resolve => setTimeout(resolve, ms)), attempts = 36 }) {
// Missing/failed vouch lookups must not become approval. Denouncements
// remain absolute, just as they are in the package build gate.
@@ -9,8 +13,8 @@ module.exports = async function approve({ github, context, core, vouchStatus,
throw new Error(`Cannot approve workflows: vouch status is ${vouchStatus || 'missing'}.`);
}
const expected = context.payload.pull_request;
const eventTime = Date.parse(expected.updated_at);
const expected = pullRequest;
const eventTime = Date.parse(since ?? expected.updated_at);
if (!Number.isFinite(eventTime)) throw new Error('Missing PR event timestamp.');
const approved = new Set();
let precedingBuild;
@@ -47,7 +51,7 @@ module.exports = async function approve({ github, context, core, vouchStatus,
const newestBuild = runs.findLast(run => run.path === BUILD);
if (!newestBuild || !(Date.parse(newestBuild.created_at) >= eventTime) ||
!runs.some(run => run.path === TESTS &&
(context.payload.action === 'labeled' || Date.parse(run.created_at) >= eventTime))) continue;
(action === 'labeled' || Date.parse(run.created_at) >= eventTime))) continue;
if (precedingBuild) {
const { data: run } = await github.rest.actions.getWorkflowRun({
@@ -71,7 +75,13 @@ module.exports = async function approve({ github, context, core, vouchStatus,
await github.rest.actions.approveWorkflowRun({ ...context.repo, run_id: run.id });
approved.add(run.id);
core.info(`Approved ${run.path} run ${run.id} for PR #${expected.number}.`);
if (run.path === BUILD) precedingBuild = run.id;
// Only a newer held build needs this one to take the concurrency slot
// first. A lone build may sit pending behind an in-flight build of an
// older commit (sync branches queue rather than cancel); waiting for it
// to start would time out before the tests run was released.
if (run.path === BUILD && pending.some(other => other.path === BUILD && other.id > run.id)) {
precedingBuild = run.id;
}
if (pending.length === 1) return;
}
throw new Error('Timed out waiting for PR workflows. Remove and reapply build-approved to retry.');
+33
View File
@@ -0,0 +1,33 @@
const approvePrWorkflows = require('./approve-pr-workflows.cjs');
const BOT = 'github-actions[bot]';
// A sync workflow pushes its branch with GITHUB_TOKEN. GitHub holds the
// resulting pull_request runs for approval and, unlike a person's push,
// creates no pull_request_target run, so approve-pr.yml never sees it. The
// sync workflow therefore releases the runs for the commit it just pushed,
// under the same rule approve-pr.yml applies: only while a maintainer's
// build-approved label is on the PR. It acts only on its own bot-authored,
// same-repository PR for the branch and commit it pushed.
module.exports = async function approveSyncPush({ github, context, core,
number, branch, headSha, since, approve = approvePrWorkflows, ...options }) {
if (!Number.isInteger(number) || !branch || !headSha || !since) {
throw new Error('Missing sync PR number, branch, head SHA or push time.');
}
const { data: pr } = await github.rest.pulls.get({ ...context.repo, pull_number: number });
const repository = `${context.repo.owner}/${context.repo.repo}`;
if (pr.user?.login !== BOT || pr.head.repo?.full_name !== repository ||
pr.base.repo?.full_name !== repository || pr.head.ref !== branch) {
throw new Error(`PR #${number} is not ${BOT}'s ${branch} PR in ${repository}; refusing to approve.`);
}
if (pr.state !== 'open' || pr.head.sha !== headSha) {
core.info(`PR #${number} is closed or has moved past ${headSha}; nothing to approve.`);
return;
}
if (!pr.labels.some(label => label.name === 'build-approved')) {
core.info(`PR #${number} has no build-approved label; its runs wait for a maintainer.`);
return;
}
await approve({ github, context, core, vouchStatus: 'bot', pullRequest: pr,
action: 'synchronize', since, ...options });
};
+40
View File
@@ -0,0 +1,40 @@
#!/bin/bash
# Usage: sync-pr-branch.sh BASE_BRANCH [PACKAGE...]
#
# Prints the branch a sync workflow run pushes to, as branch=/scope= lines for
# $GITHUB_OUTPUT. An unscoped (scheduled) run owns BASE_BRANCH and regenerates
# it from master every time. A run scoped to named packages regenerates only
# those, so it gets its own branch and PR: pushing it to BASE_BRANCH would
# replace every other pending update there with just the named packages.
set -euo pipefail
base=${1:?base branch required}
shift
if (( $# == 0 )); then
printf 'branch=%s\nscope=\n' "$base"
exit 0
fi
names=()
for name in "$@"; do
# Package directory names, as pacman allows them. Anything else is a typo
# or an attempt to smuggle something into a ref name or PR title.
if [[ ! $name =~ ^[a-z0-9@_+][a-z0-9@._+-]*$ ]]; then
echo "invalid package name: $name" >&2
exit 1
fi
names+=("$name")
done
mapfile -t names < <(printf '%s\n' "${names[@]}" | sort -u)
scope="${names[*]}"
slug=$(printf '%s\n' "${names[@]}" | sed 's/[^a-z0-9]\{1,\}/-/g; s/^-//; s/-$//' | paste -sd- -)
# Keep long package lists to a readable ref; the hash keeps distinct lists apart.
hash=$(printf '%s' "$scope" | sha256sum | cut -c1-10)
if [[ -z $slug ]]; then
slug=$hash
elif (( ${#slug} > 60 )); then
slug="${slug:0:48}"
slug="${slug%-}-$hash"
fi
printf 'branch=%s-%s\nscope=%s\n' "$base" "$slug" "$scope"
+18 -3
View File
@@ -20,9 +20,16 @@ on:
description: "Space-separated package directories to build"
required: true
# A new push normally cancels the PR's in-flight build. The sync bots'
# branches (auto/sync-*) are the exception: they are force-pushed with fresh
# upstream releases several times a day, which kept cancelling multi-hour
# aarch64 builds before they could finish. There the newest run waits
# instead (GitHub keeps at most one pending run per group, replacing older
# pending ones), and when it starts it reuses every artifact the finished
# build uploaded, so only packages whose tree changed are built again.
concurrency:
group: build-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true
cancel-in-progress: ${{ !(github.event.pull_request.head.repo.full_name == github.repository && startsWith(github.head_ref, 'auto/sync-')) }}
jobs:
# Builds cost real machines, so they run only for trusted authors:
@@ -88,8 +95,13 @@ jobs:
if [[ -n "${{ github.event.inputs.packages }}" ]]; then
names="${{ github.event.inputs.packages }}"
else
# The PR's own files, as GitHub lists them against the merge base.
# A two-dot diff against the current base tip also counted every
# package master changed after the PR branched, so a stale PR
# planned dozens of unrelated packages at its old versions. The
# checkout here is shallow, so there is no merge base to diff from.
# A package the PR deletes has nothing to build.
names=$(git diff --name-only "${{ github.event.pull_request.base.sha }}" "${{ github.event.pull_request.head.sha }}" -- pkgbuilds \
names=$(gh api --paginate "repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/files" --jq '.[].filename' \
| awk -F/ '$1=="pkgbuilds" && NF>2 {print $2}' | sort -u \
| while read -r name; do
if git cat-file -e "${{ github.event.pull_request.head.sha }}:pkgbuilds/$name" 2>/dev/null; then echo "$name"; fi
@@ -195,7 +207,10 @@ jobs:
git fetch --no-tags --depth=1 origin "${{ github.event.pull_request.head.sha }}"
git checkout "${{ github.event.pull_request.head.sha }}" -- pkgbuilds/
echo "tooling: $(git rev-parse --short HEAD) (base) packages: ${{ github.event.pull_request.head.sha }} (PR head)"
git status --short | head
# A preview only. `head` exits after ten lines and, under pipefail,
# git's SIGPIPE (141) failed the step for any PR far enough behind
# master to differ in more files; sed reads the whole stream.
git status --short | sed -n '1,10p'
- name: Build ${{ matrix.package }} (${{ matrix.arch }}, ships to ${{ matrix.channels }})
id: build
env:
+114 -8
View File
@@ -36,13 +36,18 @@ jobs:
outputs:
matrix: ${{ steps.list.outputs.matrix }}
count: ${{ steps.list.outputs.count }}
rebuild: ${{ steps.list.outputs.rebuild }}
rebuild_count: ${{ steps.list.outputs.rebuild_count }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: false
- id: list
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
if [[ -n "${{ github.event.inputs.packages }}" ]]; then
names="${{ github.event.inputs.packages }}"
else
@@ -53,17 +58,102 @@ jobs:
echo "matrix=$matrix" >> "$GITHUB_OUTPUT"
echo "count=$(jq '.include | length' <<<"$matrix")" >> "$GITHUB_OUTPUT"
jq -r '.include[] | "\(.package) \(.arch) -> \(.channels)"' <<<"$matrix"
# Reuse or rebuild, decided per entry and said out loud. An aarch64
# tree with no build artifact (PR artifacts last 7 days; a dispatch
# may name any package) goes to the rebuild job, which builds it
# natively on GitHub's arm64 runner. x86_64 builds inside the
# publish job on the droplet, as before.
rebuild=()
echo "| package | arch | tree | decision |" >> "$GITHUB_STEP_SUMMARY"
echo "| --- | --- | --- | --- |" >> "$GITHUB_STEP_SUMMARY"
while read -r entry; do
package=$(jq -r .package <<<"$entry"); arch=$(jq -r .arch <<<"$entry")
hash=$(git rev-parse "HEAD:pkgbuilds/$package")
label="$package-$arch-$hash"
found=$(curl -fsS -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/${{ github.repository }}/actions/artifacts?name=$label&per_page=5" \
| jq -r '[.artifacts[] | select(.expired|not)] | sort_by(.created_at) | last | select(. != null) | "run \(.workflow_run.id), expires \(.expires_at)"')
if [[ -n "$found" ]]; then
decision="reuse the build artifact ($found)"
elif [[ $arch == aarch64 ]]; then
decision="no build artifact: rebuild natively on ubuntu-24.04-arm"
rebuild+=("$entry")
else
decision="no build artifact: build in the publish job on the self-hosted builder"
fi
echo "==> $label: $decision"
echo "| $package | $arch | ${hash:0:12} | $decision |" >> "$GITHUB_STEP_SUMMARY"
done < <(jq -c '.include[]' <<<"$matrix")
echo "rebuild=$(printf '%s\n' "${rebuild[@]}" | jq -sc '{include: .}')" >> "$GITHUB_OUTPUT"
echo "rebuild_count=${#rebuild[@]}" >> "$GITHUB_OUTPUT"
# The aarch64 half of "build it now when there is none". It builds exactly
# as build-pr.yml's aarch64 path does (same runner, same builder image,
# same bin/build call) and uploads under the same label, so the publish
# job collects this run's artifact the way it collects a PR's. No secret
# reaches this runner; signing and upload stay on the self-hosted builder.
rebuild:
needs: changes
if: needs.changes.outputs.rebuild_count != '0'
runs-on: ubuntu-24.04-arm
timeout-minutes: 180
permissions:
contents: read
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.changes.outputs.rebuild) }}
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
# The same check the publish job makes before building: a re-run for a
# package the channel already holds at master's version builds
# nothing, and uploads nothing that could shadow the published file.
- name: Build ${{ matrix.package }} (${{ matrix.arch }}, native)
id: build
env:
CONTAINER_ENGINE: docker
run: |
set -euo pipefail
plan=$(bin/build --dry-run --mirror edge --arch "${{ matrix.arch }}" --package "${{ matrix.package }}" 2>&1 | grep -E '^==> Plan complete' || true)
if [[ -n "$plan" && -z "$(sed -E 's/.*would build: *//' <<<"$plan" | tr -d '[:space:]')" ]]; then
echo "==> ${{ matrix.package }} (${{ matrix.arch }}): already published at master's version, nothing to build"
echo "built=false" >> "$GITHUB_OUTPUT"
exit 0
fi
bin/build --mirror edge --arch "${{ matrix.arch }}" --package "${{ matrix.package }}"
echo "built=true" >> "$GITHUB_OUTPUT"
- name: Pack artifact
if: steps.build.outputs.built == 'true'
id: pack
run: |
source helpers/artifact-helpers.sh
pack_packages build-output/edge/${{ matrix.arch }} packages.tar
tar -tvf packages.tar
echo "label=${{ matrix.package }}-${{ matrix.arch }}-$(git rev-parse "HEAD:pkgbuilds/${{ matrix.package }}")" >> "$GITHUB_OUTPUT"
- name: Upload artifact
if: steps.build.outputs.built == 'true'
uses: actions/upload-artifact@v4
with:
name: ${{ steps.pack.outputs.label }}
path: packages.tar
if-no-files-found: error
retention-days: 7
# One job for the whole merge. It collects every PR artifact for the
# merged tree (building only what has none), then walks each channel and
# merged tree (building only what has none; aarch64 comes from the
# rebuild job above), then walks each channel and
# architecture slot exactly once: pull that database, add every package
# that belongs in it, upload. Six slots, six round trips, however many
# packages the merge carried. One process is the only writer, so there
# is no race between packages; the run-level concurrency group above
# keeps one merge from overlapping the next.
# It waits for the rebuild job and runs whatever that job's result: a
# failed rebuild leaves its package without an artifact, and the collect
# step below records that and stops before any publish.
publish:
needs: changes
if: needs.changes.outputs.count != '0'
needs: [changes, rebuild]
if: ${{ !cancelled() && needs.changes.result == 'success' && needs.changes.outputs.count != '0' }}
runs-on: [self-hosted, omarchy-builder]
environment: publish
timeout-minutes: 240
@@ -104,15 +194,22 @@ jobs:
label="$package-$arch-$hash"
found=$(curl -fsS -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/${{ github.repository }}/actions/artifacts?name=$label&per_page=5" \
| jq -r '[.artifacts[] | select(.expired|not)] | sort_by(.created_at) | last | .archive_download_url // empty')
| jq -r '[.artifacts[] | select(.expired|not)] | sort_by(.created_at) | last | select(. != null) | "\(.archive_download_url) \(.workflow_run.id)"')
read -r found from_run <<<"$found" || true
mkdir -p "build-output/edge/$arch"
if [[ -n "$found" ]]; then
echo "==> $label: PR artifact"
if [[ $from_run == "${{ github.run_id }}" ]]; then
kind=native-rebuild
echo "==> $label: artifact from this run's native $arch rebuild"
else
kind=pr-artifact
echo "==> $label: reusing the build artifact from run $from_run"
fi
rm -rf /tmp/artifact; mkdir -p /tmp/artifact
if curl -fsSL -H "Authorization: Bearer $GH_TOKEN" -o /tmp/artifact.zip "$found" \
&& unzip -oq /tmp/artifact.zip -d /tmp/artifact \
&& unpack_packages /tmp/artifact "build-output/edge/$arch"; then
jq -nc --arg p "$package" --arg a "$arch" '{package:$p, arch:$a, source:"pr-artifact"}' >> sources.jsonl
jq -nc --arg p "$package" --arg a "$arch" --arg s "$kind" '{package:$p, arch:$a, source:$s}' >> sources.jsonl
else
jq -nc --arg p "$package" --arg a "$arch" '{package:$p, arch:$a, source:"artifact-download-failed"}' >> sources.jsonl; failed=1; break
fi
@@ -128,6 +225,14 @@ jobs:
jq -nc --arg p "$package" --arg a "$arch" '{package:$p, arch:$a, source:"already-published"}' >> sources.jsonl
continue
fi
# aarch64 never builds here: this droplet is x86 and would
# emulate it. No artifact means the native rebuild failed (see
# the rebuild job), or an artifact expired between planning
# and now (re-run all jobs).
if [[ $arch == aarch64 ]]; then
echo "::error::$label: no artifact from the native rebuild; not building aarch64 under emulation"
jq -nc --arg p "$package" --arg a "$arch" '{package:$p, arch:$a, source:"native-build-failed"}' >> sources.jsonl; failed=1; break
fi
echo "==> $label: no artifact for this tree, building"
if OMARCHY_KEEP_BUILD_WORKSPACE=1 bin/build --mirror edge --arch "$arch" --package "$package"; then
jq -nc --arg p "$package" --arg a "$arch" '{package:$p, arch:$a, source:"built"}' >> sources.jsonl
@@ -269,7 +374,7 @@ jobs:
run: |
jq -r --arg outcome "${{ needs.publish.result }}" '
def pkgs: [.packages[] | select(test("-debug-")|not)] | join(", ");
def src: if .source=="pr-artifact" then "PR artifact" elif .source=="built" then "built here" elif .source=="already-published" then "already published, skipped" else "**" + .source + "**" end;
def src: if .source=="pr-artifact" then "PR artifact" elif .source=="native-rebuild" then "rebuilt natively on arm64" elif .source=="built" then "built here" elif .source=="already-published" then "already published, skipped" else "**" + .source + "**" end;
"### Publish " + (if $outcome=="success" then "succeeded" else "FAILED" end) +
" → **" + .target + "**" + (if .target!="live" then " (proof prefix, not live)" else "" end),
"",
@@ -322,5 +427,6 @@ jobs:
runs-on: ubuntu-latest
steps:
- run: |
echo "publish result: ${{ needs.publish.result }}"
echo "changes result: ${{ needs.changes.result }}, publish result: ${{ needs.publish.result }}"
[[ "${{ needs.changes.result }}" == "success" ]]
[[ "${{ needs.publish.result }}" == "success" || "${{ needs.publish.result }}" == "skipped" ]]
+59 -2
View File
@@ -17,6 +17,12 @@ jobs:
permissions:
contents: write
pull-requests: write
outputs:
branch: ${{ steps.branch.outputs.branch }}
pushed_at: ${{ steps.pushed.outputs.at }}
number: ${{ steps.cpr.outputs.pull-request-number }}
operation: ${{ steps.cpr.outputs.pull-request-operation }}
head_sha: ${{ steps.cpr.outputs.pull-request-head-sha }}
steps:
- name: Checkout repository
@@ -24,6 +30,17 @@ jobs:
with:
persist-credentials: false
# A scoped dispatch regenerates only the named packages. Pushed to the
# shared branch, that would replace every other pending update in its
# PR, so it gets a branch and PR of its own.
- name: Choose the PR branch
id: branch
env:
PACKAGES: ${{ github.event.inputs.packages }}
run: |
read -r -a package_args <<< "${PACKAGES:-}"
.github/scripts/sync-pr-branch.sh auto/sync-rebuilds "${package_args[@]}" | tee -a "$GITHUB_OUTPUT"
# Runs in an Arch container against the mirror the x86_64 builder itself
# uses, because the question being asked is what that builder will link
# against and a different mirror can be hours ahead of it. Recording a
@@ -68,13 +85,21 @@ jobs:
echo "has_changes=true" >> "$GITHUB_OUTPUT"
fi
# Runs created by this push are newer than this; the approve job
# waits for them. A minute's slack absorbs runner clock skew.
- name: Record push time
if: steps.changes.outputs.has_changes == 'true'
id: pushed
run: echo "at=$(date -u -d '-1 minute' +%Y-%m-%dT%H:%M:%SZ)" >> "$GITHUB_OUTPUT"
- name: Create Pull Request
if: steps.changes.outputs.has_changes == 'true'
id: cpr
uses: peter-evans/create-pull-request@v7
with:
token: ${{ secrets.GITHUB_TOKEN }}
commit-message: 'chore: rebuild against updated dependencies'
title: 'chore: rebuild against updated dependencies'
title: "chore: rebuild against updated dependencies${{ steps.branch.outputs.scope && format(' ({0})', steps.branch.outputs.scope) || '' }}"
body: |
Automated pkgrel bump for packages that link against a dependency
which has moved in the official repositories.
@@ -84,7 +109,7 @@ jobs:
bump is what makes the rebuilt package an upgrade pacman will offer;
without it the build produces the version already published and no
one receives it.
branch: auto/sync-rebuilds
branch: ${{ steps.branch.outputs.branch }}
delete-branch: true
labels: automated
reviewers: ryanrhughes
@@ -100,3 +125,35 @@ jobs:
"🔴 <strong>Rebuild trigger sync failed</strong><br><a href=\"${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}\">View run</a>" \
'{content: $content}')" \
"$BASECAMP_CHATBOT_URL"
# GitHub holds pull_request runs from a GITHUB_TOKEN push for approval and
# creates no pull_request_target run for it, so approve-pr.yml never sees
# the sync's own pushes. Once a maintainer has labelled the PR
# build-approved, release the held runs for the commit just pushed. A
# separate job, so the sync container's token never holds actions: write.
approve:
needs: sync
if: ${{ !cancelled() && needs.sync.outputs.operation == 'updated' }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
pull-requests: read
actions: write
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Release held build and test runs if build-approved
uses: actions/github-script@v7
env:
NUMBER: ${{ needs.sync.outputs.number }}
BRANCH: ${{ needs.sync.outputs.branch }}
HEAD_SHA: ${{ needs.sync.outputs.head_sha }}
SINCE: ${{ needs.sync.outputs.pushed_at }}
with:
script: |
const approve = require('./.github/scripts/approve-sync-push.cjs');
const { NUMBER, BRANCH, HEAD_SHA, SINCE } = process.env;
await approve({ github, context, core, number: Number(NUMBER),
branch: BRANCH, headSha: HEAD_SHA, since: SINCE });
+59 -2
View File
@@ -17,6 +17,12 @@ jobs:
permissions:
contents: write
pull-requests: write
outputs:
branch: ${{ steps.branch.outputs.branch }}
pushed_at: ${{ steps.pushed.outputs.at }}
number: ${{ steps.cpr.outputs.pull-request-number }}
operation: ${{ steps.cpr.outputs.pull-request-operation }}
head_sha: ${{ steps.cpr.outputs.pull-request-head-sha }}
steps:
- name: Checkout repository
@@ -24,6 +30,17 @@ jobs:
with:
persist-credentials: false
# A scoped dispatch regenerates only the named packages. Pushed to the
# shared branch, that would replace every other pending update in its
# PR, so it gets a branch and PR of its own.
- name: Choose the PR branch
id: branch
env:
PACKAGES: ${{ github.event.inputs.packages }}
run: |
read -r -a package_args <<< "${PACKAGES:-}"
.github/scripts/sync-pr-branch.sh auto/sync-upstream "${package_args[@]}" | tee -a "$GITHUB_OUTPUT"
# Runs in an Arch container for vercmp: whether a release is an upgrade has
# to be decided by the same comparator pacman will use on users' machines.
- name: Update packages from upstream release feeds
@@ -72,13 +89,21 @@ jobs:
echo "has_changes=true" >> "$GITHUB_OUTPUT"
fi
# Runs created by this push are newer than this; the approve job
# waits for them. A minute's slack absorbs runner clock skew.
- name: Record push time
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
id: pushed
run: echo "at=$(date -u -d '-1 minute' +%Y-%m-%dT%H:%M:%SZ)" >> "$GITHUB_OUTPUT"
- name: Create Pull Request
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
id: cpr
uses: peter-evans/create-pull-request@v7
with:
token: ${{ secrets.GITHUB_TOKEN }}
commit-message: 'chore: sync upstream releases'
title: 'chore: sync upstream releases'
title: "chore: sync upstream releases${{ steps.branch.outputs.scope && format(' ({0})', steps.branch.outputs.scope) || '' }}"
body: |
Automated update of packages that track an upstream vendor release
feed rather than the AUR.
@@ -86,7 +111,7 @@ jobs:
Release watches and providers are declared in `.omarchy/package.json`;
exceptional feeds use `.omarchy/upstream.sh`. Failed package updates
are left untouched; check the workflow result for outstanding failures.
branch: auto/sync-upstream
branch: ${{ steps.branch.outputs.branch }}
delete-branch: true
labels: automated
reviewers: ryanrhughes
@@ -102,3 +127,35 @@ jobs:
"🔴 <strong>Upstream sync failed</strong><br><a href=\"${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}\">View run</a>" \
'{content: $content}')" \
"$BASECAMP_CHATBOT_URL"
# GitHub holds pull_request runs from a GITHUB_TOKEN push for approval and
# creates no pull_request_target run for it, so approve-pr.yml never sees
# the sync's own pushes. Once a maintainer has labelled the PR
# build-approved, release the held runs for the commit just pushed. A
# separate job, so the sync container's token never holds actions: write.
approve:
needs: sync
if: ${{ !cancelled() && needs.sync.outputs.operation == 'updated' }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
pull-requests: read
actions: write
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Release held build and test runs if build-approved
uses: actions/github-script@v7
env:
NUMBER: ${{ needs.sync.outputs.number }}
BRANCH: ${{ needs.sync.outputs.branch }}
HEAD_SHA: ${{ needs.sync.outputs.head_sha }}
SINCE: ${{ needs.sync.outputs.pushed_at }}
with:
script: |
const approve = require('./.github/scripts/approve-sync-push.cjs');
const { NUMBER, BRANCH, HEAD_SHA, SINCE } = process.env;
await approve({ github, context, core, number: Number(NUMBER),
branch: BRANCH, headSha: HEAD_SHA, since: SINCE });
+1
View File
@@ -58,6 +58,7 @@ jobs:
python tests/neovim-clipboard-tmux.py
./tests/partial-release.sh
./tests/published-build-plan.sh
./tests/settings-boot-config.sh
./tests/pinned-sources.sh
./tests/controller.sh
./tests/artifact-helpers.sh
+16
View File
@@ -901,6 +901,22 @@ build-and-publish chain, so the tracker requires this secret before it runs.
The reviewed sync workflows continue to use `GITHUB_TOKEN` and require
maintainer approval as before. See [setup instructions](docs/upstream-sources.md#enable-unattended-branch-updates).
Scheduled runs regenerate one shared PR (`auto/sync-upstream`, `auto/sync-rebuilds`)
from master. A manual run with the `packages` input only regenerates those
packages, so it opens its own PR on `auto/sync-upstream-<packages>` (or
`auto/sync-rebuilds-<packages>`) rather than replacing the shared PR's other
pending updates. The next scheduled run still picks the same update up in the
shared PR if it has not merged by then; identical package trees reuse the same
build artifacts.
Sync PRs are pushed with `GITHUB_TOKEN`, so GitHub holds their build and test
runs for approval on every push and starts no `pull_request_target` workflow
for them. Once **`build-approved`** is on a sync PR, the sync workflow's own
`approve` job releases the held runs for each commit it pushes. A push to an
`auto/sync-*` branch does not cancel the PR's in-flight build: the new build
waits for it and then reuses its artifacts, so a long aarch64 build is not
restarted by every sync.
To approve builds for an unvouched contributor's PR, apply **`build-approved`**.
Until approval, the PR shows **Awaiting build approval** and its required
`result` check stays pending, keeping the PR blocked from merging without
+3 -2
View File
@@ -69,8 +69,9 @@ Watch it with `journalctl -u omarchy-controller -f` on the box.
different bytes under an existing name, accept identical bytes, upload
packages then signatures then the db.
- aarch64 under QEMU with credential-preserving binfmt. PR builds now run
aarch64 natively on `ubuntu-24.04-arm` (QEMU was up to ~15x slower); publish.yml
still builds under QEMU when a merged tree has no PR artifact.
aarch64 natively on `ubuntu-24.04-arm` (QEMU was up to ~15x slower). When a
merged aarch64 tree has no artifact, publish.yml rebuilds it there too, in its
own job, and signs and uploads it on the droplet like a PR artifact.
- Vouch gate: collaborators, `.github/VOUCHED.td`, or the `build-approved`
label; denounced authors cannot be overridden by the label.
- Tests run on PRs only; `result`, `self-tests`, `build-isolation` are the
+7 -33
View File
@@ -1,6 +1,12 @@
#!/bin/bash
# Verify Flea's published source archive against its checksum manifest when a
# newer stable release exists, then check its root and required security fixes.
# newer stable release exists, then check its root.
#
# Through 0.1.x this also grepped the source for the upstream security fixes
# Omarchy once carried as patches, so the package could not move to a release
# that lacked them. Every release since 0.1.5 has had them, and matching
# literal source lines only ever caught renames (#488, 0.3.5's
# open_if_regular_with_meta), never a regression.
set -euo pipefail
REPO='thisisgm/flea'
@@ -74,38 +80,6 @@ if [[ $served_roots != "$expected_root" ]]; then
exit 1
fi
archive_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archive.rs")
archiveops_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archiveops.rs")
run_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/run.rs")
archivereq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivereq.rs")
archivework_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/archivework.rs")
mediaprobe_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/mediaprobe.rs")
metareq_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/metareq.rs")
sharelink_qml=$(tar -xOzf "$tarball" "$expected_root/ui/ShareLink.qml")
copyfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/copyfile.rs")
regfile_rs=$(tar -xOzf "$tarball" "$expected_root/src/backend/regfile.rs")
# Every check below pins a literal line except the O_NOFOLLOW one. That check
# guards a property -- the copy opens its source with O_NOFOLLOW, so a symlink
# swapped in cannot redirect the read -- and pinning the exact call expression
# made it assert the spelling instead. v0.3.0 moved the first argument from
# `src` to `src.at` when directory-relative opens landed, kept O_NOFOLLOW, and
# hardened symlink handling further; the literal still refused it. Match the
# call and the flag together so a rename cannot read as a removed fix, while
# dropping O_NOFOLLOW still fails.
if ! grep -Fq 'a.push("--".to_string());' <<<"$archive_rs" ||
! grep -Fq 'let input = std::fs::canonicalize(input)' <<<"$archiveops_rs" ||
! grep -Fq 'if op != "compress" && op != "extract"' <<<"$run_rs$archivereq_rs" ||
! grep -Fq 'the sandbox is unavailable: bwrap or prlimit is not on PATH' <<<"$archivework_rs" ||
! grep -Fq 'if !sandbox::available()' <<<"$mediaprobe_rs" ||
! grep -Fq 'if !sandbox::available()' <<<"$metareq_rs" ||
! grep -Fq 'copyToClipboard.command = ["wl-copy", url]' <<<"$sharelink_qml" ||
! grep -Eq 'open_if_regular\(.*O_NOFOLLOW' <<<"$copyfile_rs" ||
! grep -Fq '.custom_flags(O_NONBLOCK | extra_flags)' <<<"$regfile_rs"; then
printf 'Release %s does not contain every required upstream security fix\n' "$best_tag" >&2
exit 1
fi
jq -n \
--arg pkgver "$best_version" \
--arg published_at "$best_published_at" \
+5
View File
@@ -116,7 +116,12 @@ check() {
# back to the next create, so on the builder's /tmp the stranger is
# identical and undo walks it back. tmpfs allocates inode numbers from a
# counter and never reuses one, which is what the test assumes.
# copymanifest's garbage-stream test opens its O_TMPFILE manifest in its
# own test dir; the module's other tests must stay off tmpfs, because
# Writer::create wants a runtime dir on a different filesystem from the
# copy and finds none when both live on /dev/shm.
local -a filesystem_tests=(
backend::copymanifest::tests::a_garbage_stream_falls_back_with_the_tree_untouched
backend::menu_actions::tests::
backend::menudelete::tests::
backend::redo::tests::
+3 -3
View File
@@ -5,7 +5,7 @@
pkgname=hermes-desktop
pkgver=2026.9.7
pkgrel=1
pkgrel=2
pkgdesc='Native desktop shell for Hermes Agent'
arch=('x86_64')
url='https://github.com/NousResearch/hermes-agent'
@@ -75,11 +75,11 @@ source=("${pkgname}-${pkgver}.tar.gz::${url}/archive/refs/tags/v${pkgver}.tar.gz
'runtime.patch'
'runtime-test.py')
sha256sums=('907c2a72db1c5dd637ea8eeae97f4cb5b32cef615c17258f6b190924ec5bf688'
'094d5f3191109a80eea9f23053b78a2e00dbecf90d62d1ca04c8e48866251469'
'c68233f93387251f08537559c072c9ec36ba9a304b1669decc56df17c464b252'
'3ef685bfcf366776b025d26c37d32854d8d4aa2023b2bd07c8e08b001ef1e8c4'
'd60d164e24fdcf6532133b8ea43c77a201e4b9e9dbc396187b58d51d8590ef52'
'9d5015d1be762a901f8f64319981ae862e9852fa5cb9a22a2ba1e691f90430a2'
'7337a12c71e8091ad5fc2e879e922c9cb1706c65f81b59d6dd70b12123dc7c00')
'514a5e7ab2b7262141a2588c5b5036832cb4ba789a9578b8b50b6d79a9d63deb')
build() {
cd "${srcdir}/${_srcdir}"
@@ -4,11 +4,6 @@ set -euo pipefail
unset ELECTRON_RUN_AS_NODE PYTHONPATH PYTHONHOME
export HERMES_DESKTOP_IGNORE_EXISTING=1
# Reconcile direct package installs and interrupted Omarchy setup as well.
if command -v omarchy-install-hermes-cli >/dev/null 2>&1; then
omarchy-install-hermes-cli >/dev/null 2>&1 || true
fi
hermes_home=$(realpath -ms -- "${HERMES_HOME:-$HOME/.hermes}")
parent=${hermes_home%/*}
if [[ ${parent##*/} == [Pp][Rr][Oo][Ff][Ii][Ll][Ee][Ss] ]]; then
+4 -2
View File
@@ -75,9 +75,11 @@ def with_hermes_node_path(env=None):
cli.write_text(forbidden)
cli.chmod(0o755)
(cli.parent / "python").symlink_to(sys.executable)
# The launcher used to call Omarchy's installer on every start; a launcher
# that reaches for it, or for sudo, fails here.
for command in ("sudo", "omarchy-install-hermes-cli"):
target = mock_bin / command
target.write_text(forbidden if command == "sudo" else '#!/bin/bash\nexit 0\n')
target.write_text(forbidden)
target.chmod(0o755)
output = root / "launch.json"
@@ -92,7 +94,7 @@ def with_hermes_node_path(env=None):
assert result == {"args": ["--disable-setuid-sandbox", *expected_args],
"home": str(home / ".hermes"), "store": store, "gpu": gpu,
"ozone": ozone, "cwd": str(home), "inherited": []}, result
assert not forbidden_output.exists(), "launcher invoked CLI or sudo"
assert not forbidden_output.exists(), "launcher invoked the Omarchy installer or sudo"
output.unlink()
wayland = {"WAYLAND_DISPLAY": "wayland-1"}
+4 -4
View File
@@ -1,7 +1,7 @@
# Maintainer: noureddinex
pkgname=lmstudio-bin
pkgver=0.4.25
pkgrel=1
pkgrel=2
_build=1
_pkgver=${pkgver}-${_build}
pkgdesc="LM Studio - A desktop app for exploring and running large language models locally"
@@ -16,7 +16,7 @@ conflicts=(lmstudio)
source=("https://installers.lmstudio.ai/linux/x64/${_pkgver}/LM-Studio-${_pkgver}-x64.AppImage"
"lmstudio.png"
"lmstudio.desktop")
sha256sums=('eca467446c833824697e8befab300fe5269fdf984e3ee4385fcbad8502f07c53' '9f791789c959a11316328692807737a5f1bc1c170ae99ec04c56bfd8ee8263e5' '635dec12f3e3a57136b9e6fd7c2839ed6da7287fa55b482d64debf6eacf36baa')
sha256sums=('eca467446c833824697e8befab300fe5269fdf984e3ee4385fcbad8502f07c53' '9f791789c959a11316328692807737a5f1bc1c170ae99ec04c56bfd8ee8263e5' '16b67b6cd672a05b9a0e012c8b9a91187ceda8f85b3391db471298c54e002bcd')
prepare() {
chmod +x "${srcdir}/${source[0]##*/}"
@@ -33,8 +33,8 @@ package() {
install -Dm644 "${srcdir}/lmstudio.png" "${pkgdir}/usr/share/icons/hicolor/512x512/apps/lmstudio-bin.png"
install -Dm644 "${srcdir}/lmstudio.png" "${pkgdir}/usr/share/pixmaps/lmstudio-bin.png"
# Desktop entry
install -Dm644 "$srcdir/lmstudio.desktop" "$pkgdir/usr/share/applications/lmstudio.desktop"
# Desktop entry, under LM Studio's own desktop ID, which matches its window class
install -Dm644 "$srcdir/lmstudio.desktop" "$pkgdir/usr/share/applications/ai.elementlabs.lmstudio.desktop"
# Symlink to binary
install -dm755 "$pkgdir/usr/bin"
+2 -2
View File
@@ -8,5 +8,5 @@ Type=Application
Categories=Development;ArtificialIntelligence;
Terminal=false
StartupNotify=true
StartupWMClass=LM-Studio
MimeType=text/plain;
StartupWMClass=ai.elementlabs.lmstudio
MimeType=x-scheme-handler/lmstudio;
@@ -0,0 +1,6 @@
{
"source": "local",
"channels": [
"edge"
]
}
@@ -0,0 +1,37 @@
From bd5d6119ca1ed030ad26d06d1b3e980873ff0336 Mon Sep 17 00:00:00 2001
From: Martin Stark <901824+martinstark@users.noreply.github.com>
Date: Sun, 13 Sep 2026 22:32:38 +0200
Subject: [PATCH 1/2] fix(displayport): allow detach when sink is unplugged
The HPD check in dpPreModeset() rejects detach-only requests after unplug. This skips DP library cleanup while NVKMS advances its head bookkeeping, leaving stale attached groups that can block subsequent link training.
Allow detach-only requests when HPD is low. Reject requests with an attachment target on any selected head, preserving the connector/discovery guards and forced-connected and dynamic-mux exceptions.
---
src/common/displayport/src/dp_connectorimpl.cpp | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/src/common/displayport/src/dp_connectorimpl.cpp b/src/common/displayport/src/dp_connectorimpl.cpp
index 99e0e97..7451e6c 100644
--- a/src/common/displayport/src/dp_connectorimpl.cpp
+++ b/src/common/displayport/src/dp_connectorimpl.cpp
@@ -3861,11 +3861,17 @@ void ConnectorImpl::dpPreModeset(const DpPreModesetParams &params)
return;
}
- // Skip gating modeset on HPD for DDS panels
+ // Allow detach bookkeeping even when HPD is low.
if(!previousPlugged && !bClientForcedConnected && !main->isInternalPanelDynamicMuxCapable())
{
- DP_ASSERT(0 && "DPCONN> dpPreModeset called when Plugged State is false!");
- return;
+ for (NvU32 i = 0; i < NV_MAX_HEADS; i++)
+ {
+ if ((params.headMask & NVBIT(i)) && params.head[i].pTarget != NULL)
+ {
+ DP_ASSERT(0 && "DPCONN> dpPreModeset attach called when Plugged State is false!");
+ return;
+ }
+ }
}
this->bFECEnable |= this->needToEnableFEC(params);
@@ -0,0 +1,23 @@
From a2e8b26b20dfb6f2fa3cb8985e3f1126cba38aae Mon Sep 17 00:00:00 2001
From: Martin Stark <901824+martinstark@users.noreply.github.com>
Date: Mon, 14 Sep 2026 10:43:16 +0200
Subject: [PATCH 2/2] Clarify DDS exception and unplugged detach bookkeeping
---
src/common/displayport/src/dp_connectorimpl.cpp | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/src/common/displayport/src/dp_connectorimpl.cpp b/src/common/displayport/src/dp_connectorimpl.cpp
index 7451e6c..0e81070 100644
--- a/src/common/displayport/src/dp_connectorimpl.cpp
+++ b/src/common/displayport/src/dp_connectorimpl.cpp
@@ -3861,7 +3861,8 @@ void ConnectorImpl::dpPreModeset(const DpPreModesetParams &params)
return;
}
- // Allow detach bookkeeping even when HPD is low.
+ // Skip gating modeset on HPD for DDS panels.
+ // Allow HPD-low detach bookkeeping; notifyLongPulse() permits detach.
if(!previousPlugged && !bClientForcedConnected && !main->isInternalPanelDynamicMuxCapable())
{
for (NvU32 i = 0; i < NV_MAX_HEADS; i++)
+12
View File
@@ -0,0 +1,12 @@
Copyright Arch Linux Contributors
Permission to use, copy, modify, and/or distribute this software for
any purpose with or without fee is hereby granted.
THE SOFTWARE IS PROVIDED “AS IS” AND THE AUTHOR DISCLAIMS ALL
WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE
FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY
DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN
AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+74
View File
@@ -0,0 +1,74 @@
# Maintainer: Sven-Hendrik Haase <svenstaro@archlinux.org>
# Maintainer: Peter Jung <ptr1337@archlinux.org>
# Contributor: James Rayner <iphitus@gmail.com>
# Contributor: Vasiliy Stelmachenok <ventureo@yandex.ru>
# Contributor: Thomas Baechler <thomas@archlinux.org>
# ARM-only carry of NVIDIA/open-gpu-kernel-modules#1359 by Martin Stark.
# Remove this overlay after a fixed Arch Linux ARM driver is validated.
pkgname=nvidia-open-dkms
pkgver=615.71.09
pkgrel=1.2
pkgdesc="NVIDIA open kernel modules - module sources"
arch=('aarch64')
url="https://www.nvidia.com/"
license=('MIT AND GPL-2.0-only')
depends=('dkms' "nvidia-utils=$pkgver")
conflicts=('nvidia-open' 'NVIDIA-MODULE')
provides=('nvidia-open' 'NVIDIA-MODULE' 'nvidia-dkms')
replaces=('nvidia-dkms')
options=('!strip')
_pkg_open="NVIDIA-kernel-module-source-${pkgver}"
source=("https://download.nvidia.com/XFree86/NVIDIA-kernel-module-source/${_pkg_open}.tar.xz"
'0001-allow-unplugged-dp-detach.patch'
'0002-clarify-unplugged-dp-detach.patch')
sha512sums=('0b32c1aaa5ed261bdee7232d5e5d293e53c42ac9896f49c4be4e6b9b6bce1370cb69a7f7fde5531a7537d5e925d651c36bcb512a2f827c2d2cb26ede33f7c057'
'48f802423399ce84a430b7accf10ea50847ea3fafcfe251e3bad2f741af9ca2162408a3109eb3c9fcdbe35ec35154a3dbcc8fe457ed617487c009abf2c9fc89a'
'a3ff65cb58d72815b272726c38d45148dfba73ea2a0d88672960d8f706c74e7c2b40ec599783acec46ba18433af45f38547a09b2caa985bd71895a64780c00da')
prepare() {
# Attempt to make builds reproducible
sed -i "s/^ HOSTNAME.*/ HOSTNAME = echo archlinux/" "${srcdir}/${_pkg_open}/utils.mk"
sed -i "s/^WHOAMI.*/WHOAMI = echo archlinux-builder/" "${srcdir}/${_pkg_open}/utils.mk"
sed -i "s/^DATE.*/DATE = date -r version.mk/" "${srcdir}/${_pkg_open}/utils.mk"
for conf in "${srcdir}/${_pkg_open}/kernel-open/dkms.conf"; do
sed -i "s/__VERSION_STRING/${pkgver}/" "$conf"
sed -i 's/__JOBS/`nproc`/' "$conf"
sed -i 's/__EXCLUDE_MODULES//' "$conf"
sed -i 's/__DKMS_MODULES//' "$conf"
sed -i 's/NV_EXCLUDE_BUILD_MODULES/IGNORE_PREEMPT_RT_PRESENCE=1 NV_EXCLUDE_BUILD_MODULES/' "$conf"
sed -i '$i\
BUILT_MODULE_NAME[0]="nvidia"\
DEST_MODULE_LOCATION[0]="/kernel/drivers/video"\
BUILT_MODULE_NAME[1]="nvidia-uvm"\
DEST_MODULE_LOCATION[1]="/kernel/drivers/video"\
BUILT_MODULE_NAME[2]="nvidia-modeset"\
DEST_MODULE_LOCATION[2]="/kernel/drivers/video"\
BUILT_MODULE_NAME[3]="nvidia-drm"\
DEST_MODULE_LOCATION[3]="/kernel/drivers/video"\
BUILT_MODULE_NAME[4]="nvidia-peermem"\
DEST_MODULE_LOCATION[4]="/kernel/drivers/video"' "$conf"
done
# Additional parameters for open kernel modules
cat <<EOF >>"${srcdir}/${_pkg_open}/kernel-open/dkms.conf"
BUILT_MODULE_LOCATION[0]="kernel-open"
BUILT_MODULE_LOCATION[1]="kernel-open"
BUILT_MODULE_LOCATION[2]="kernel-open"
BUILT_MODULE_LOCATION[3]="kernel-open"
BUILT_MODULE_LOCATION[4]="kernel-open"
EOF
# Exact PR head a2e8b26b20dfb6f2fa3cb8985e3f1126cba38aae.
cd "${srcdir}/${_pkg_open}"
patch --batch --fuzz=0 -p1 < "$srcdir/0001-allow-unplugged-dp-detach.patch"
patch --batch --fuzz=0 -p1 < "$srcdir/0002-clarify-unplugged-dp-detach.patch"
}
package() {
install -dm755 "$pkgdir/usr/src"
cp -dr --no-preserve=ownership "$srcdir/$_pkg_open" "$pkgdir/usr/src/nvidia-$pkgver"
mv "$pkgdir/usr/src/nvidia-$pkgver/kernel-open/dkms.conf" "$pkgdir/usr/src/nvidia-$pkgver/dkms.conf"
install -Dm644 "$srcdir/$_pkg_open/COPYING" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
}
@@ -0,0 +1,13 @@
# NVIDIA ARM DisplayPort detach fix
ARM-only edge package carrying Martin Stark's pending
[NVIDIA PR #1359](https://github.com/NVIDIA/open-gpu-kernel-modules/pull/1359)
to fix DisplayPort disconnect cleanup in 615.71.09. Based on
[Arch's DKMS recipe](https://gitlab.archlinux.org/archlinux/packaging/packages/nvidia-utils/-/commit/f9ae10b379f8b1d0832ec92bca1c12072aa123e9).
Requires `[omarchy]` before `[extra]` and matching `nvidia-utils=615.71.09`.
Update both NVIDIA packages together; automatic version tracking is disabled.
Remove this recipe and the published package/database entry once a fixed
Arch Linux ARM driver is validated. A stale package in the earlier repository
can block driver updates.
+3 -3
View File
@@ -1,13 +1,13 @@
# Maintainer: Ryan Hughes <ryan@omarchy.org>
pkgname='omarchy-dev'
pkgver=4.0.0.r6646.gbf44355
pkgver=4.0.0.r6663.g3faafba
pkgrel=1
# Pinned by the upstream watch in .omarchy/package.json (bin/sync-upstream):
# every quattro tip becomes a commit pin here, so the package is versioned,
# checksummed and built exactly like a release, just more often. The r-number
# is the branch's total commit count, not the distance from the last tag: the
# published history used the total, and pacman must never see it go down.
_commit=bf44355a985b1bb82cb33df47fc17f765f3b2c4f
_commit=3faafba234e530b0986196b98dc2c38951e7dd6f
pkgdesc='Beautiful, modern, and opinionated Arch Linux by DHH (quattro branch tip)'
# The payload is architecture-independent, but the dependency set is not: the
# boot stack differs per architecture (see depends_x86_64 / depends_aarch64),
@@ -81,7 +81,7 @@ makedepends=(
# build from a local source tree instead (mirrors omarchy-zsh/omarchy-fish DX);
# the arrays are emptied below so nothing is downloaded in that case.
source=("omarchy::git+https://github.com/basecamp/omarchy.git#commit=${_commit}")
sha256sums=('7a90239fd67124279817d614fa6aa19554f40796c523ba698669fbf57fa41668')
sha256sums=('d97e0f12d9f17bfd78872bdc12edb63184b59483f055178d8d80597ed132882f')
if [[ -n "${OMARCHY_SRC:-}" ]]; then
source=()
sha256sums=()
+76 -29
View File
@@ -1,19 +1,20 @@
# Maintainer: Ryan Hughes <ryan@omarchy.org>
pkgname='omarchy-settings-dev'
pkgver=4.0.0.r6646.gbf44355
pkgrel=1
pkgver=4.0.0.r6663.g3faafba
pkgrel=2
# Pinned by the upstream watch in .omarchy/package.json (bin/sync-upstream):
# every quattro tip becomes a commit pin here, so the package is versioned,
# checksummed and built exactly like a release, just more often. The r-number
# is the branch's total commit count, not the distance from the last tag: the
# published history used the total, and pacman must never see it go down.
_commit=bf44355a985b1bb82cb33df47fc17f765f3b2c4f
_commit=3faafba234e530b0986196b98dc2c38951e7dd6f
pkgdesc='Omarchy user defaults, /etc/skel content, fonts, plymouth theme, and support helpers (quattro branch tip)'
# Arch-specific because the shipped /etc tree is not the same on every
# architecture: the Limine, mkinitcpio, zram and oomd drop-ins belong to the
# x86_64 boot and memory stack and are left out of the aarch64 package (see
# package()). makepkg only honours the arch-suffixed arrays below on
# arch-specific packages.
# architecture: the zram and oomd drop-ins belong to the x86_64 memory stack
# and are left out of the aarch64 package (see package()). The Limine and
# mkinitcpio drop-ins ship on both: UEFI aarch64 installs (DGX Spark,
# Snapdragon X) boot with Limine and an encrypted root exactly like x86_64.
# makepkg only honours the arch-suffixed arrays below on arch-specific packages.
arch=('x86_64' 'aarch64')
url='https://github.com/basecamp/omarchy'
license=('MIT')
@@ -73,14 +74,17 @@ backup=(
'etc/udev/rules.d/99-omarchy-power-profile.rules'
'etc/udev/rules.d/99-omarchy-wifi-powersave.rules'
)
# Boot configuration is backed up on both architectures.
backup+=(
'etc/mkinitcpio.conf.d/omarchy_hooks.conf'
'etc/limine-entry-tool.d/omarchy-defaults.conf'
'etc/limine-entry-tool.d/omarchy-uki.conf'
)
# backup has no arch-suffixed form, so the x86_64-only drop-ins join it here.
# Each of these paths is removed from the aarch64 package in package().
if [[ $CARCH == x86_64 ]]; then
backup+=(
'etc/mkinitcpio.conf.d/omarchy_hooks.conf'
'etc/mkinitcpio.conf.d/thunderbolt_module.conf'
'etc/limine-entry-tool.d/omarchy-defaults.conf'
'etc/limine-entry-tool.d/omarchy-uki.conf'
'etc/modprobe.d/omarchy-usb-autosuspend.conf'
'etc/systemd/oomd.conf.d/10-omarchy.conf'
'etc/systemd/zram-generator.conf'
@@ -117,7 +121,7 @@ _etc_override_paths=(
# build from a local source tree instead (mirrors omarchy-zsh/omarchy-fish DX);
# the arrays are emptied below so nothing is downloaded in that case.
source=("omarchy::git+https://github.com/basecamp/omarchy.git#commit=${_commit}")
sha256sums=('7a90239fd67124279817d614fa6aa19554f40796c523ba698669fbf57fa41668')
sha256sums=('d97e0f12d9f17bfd78872bdc12edb63184b59483f055178d8d80597ed132882f')
if [[ -n "${OMARCHY_SRC:-}" ]]; then
source=()
sha256sums=()
@@ -131,6 +135,23 @@ prepare() {
fi
}
# Print the HOOKS that result from sourcing mkinitcpio drop-ins onto a line.
_omarchy_settings_hooks_after() {
local start=$1
shift
(
# Keep the build host's own tools, such as a platform detector, out of it.
PATH=/nonexistent
read -ra HOOKS <<<"$start"
MODULES=() FILES=()
for conf in "$@"; do
# shellcheck disable=SC1090
source "$conf" || exit 1
done
echo "${HOOKS[*]}"
)
}
package() {
cd "$srcdir/omarchy"
@@ -151,14 +172,6 @@ package() {
install -d "$pkgdir/usr/share/omarchy/config"
cp -a config/. "$pkgdir/usr/share/omarchy/config/"
# The Limine/Snapper notifier has nothing to notify about without the x86_64
# boot stack; drop it from both seeds so aarch64 users don't autostart a
# helper whose backing tool is not installed.
if [[ $CARCH == aarch64 ]]; then
rm -f "$pkgdir/etc/skel/.config/autostart/limine-snapper-notify.desktop" \
"$pkgdir/usr/share/omarchy/config/autostart/limine-snapper-notify.desktop"
fi
# Package-owned defaults with real system/XDG locations. User config remains
# higher priority: ~/.config/uwsm/default, ~/.config/uwsm/env.d,
# ~/.config/environment.d, ~/.config/fontconfig, ~/.config/xdg-terminals.list,
@@ -207,12 +220,44 @@ package() {
# stage separately below).
install -d "$pkgdir/etc"
cp -a etc/. "$pkgdir/etc/"
# omacom/omarchy#13362 moves the HOOKS baseline into its own drop-in.
[[ ! -f $pkgdir/etc/mkinitcpio.conf.d/00-omarchy-hooks.conf ]] ||
backup+=('etc/mkinitcpio.conf.d/00-omarchy-hooks.conf')
if [[ $CARCH == aarch64 ]]; then
# The x86_64 boot stack's drop-ins must not ship on aarch64: mkinitcpio
# reads every file under /etc/mkinitcpio.conf.d/, so omarchy_hooks.conf
# would inject the Limine hooks into the Asahi kernel's initramfs, and the
# Limine entry-tool config has no consumer without Limine.
rm -rf "$pkgdir/etc/limine-entry-tool.d" "$pkgdir/etc/mkinitcpio.conf.d"
# Keep omarchy_hooks.conf and the Limine entry-tool config: without them a
# kernel update on an encrypted aarch64 install rebuilds an initramfs with
# no encrypt hook and the machine cannot unlock its root. Only the
# Thunderbolt module request is x86-specific; ARM kernels lack the module
# and mkinitcpio treats a missing explicit module as an error.
rm -f "$pkgdir/etc/mkinitcpio.conf.d/thunderbolt_module.conf"
# Apple Silicon Macs install this package too. Their initramfs needs the
# asahi hook, which omarchy-mac-boot's 90-94 fragments (Aurora) or
# mkinitcpio.conf (legacy GRUB Macs) set, and an unconditional HOOKS= here
# would replace it. A source that sets HOOKS outright (v4.0.4) gets its line
# wrapped so it applies only when the hooks loaded so far lack asahi; one that
# already decides per platform (omacom/omarchy#13362) ships as it is. The
# wrapper reads configuration, not the running machine, so it also holds
# when the image is built in a chroot.
local hooks_conf hooks_confs=()
for hooks_conf in "$pkgdir"/etc/mkinitcpio.conf.d/{00-omarchy-hooks,omarchy_hooks}.conf; do
[[ -f $hooks_conf ]] || continue
hooks_confs+=("$hooks_conf")
sed -i 's/^\(HOOKS=([^#]*)\)[[:space:]]*$/if [[ " ${HOOKS[*]:-} " != *" asahi "* ]]; then\n \1\nfi/' "$hooks_conf"
if grep -q '^HOOKS=' "$hooks_conf"; then
echo "${hooks_conf#"$pkgdir"/}: cannot guard this HOOKS= line for Apple Silicon" >&2
return 1
fi
done
# Whatever the layout, a Mac's asahi line must come through the shipped
# files, and a stock line must not: that is where Omarchy's hooks come from.
local mac_line='base udev block asahi encrypt filesystems fsck' stock_line='base udev block filesystems fsck'
local mac_hooks stock_hooks
if ! mac_hooks=$(_omarchy_settings_hooks_after "$mac_line" "${hooks_confs[@]}") ||
! stock_hooks=$(_omarchy_settings_hooks_after "$stock_line" "${hooks_confs[@]}") ||
[[ $mac_hooks != "$mac_line" || $stock_hooks == "$stock_line" ]]; then
echo "etc/mkinitcpio.conf.d: the aarch64 hooks must keep a Mac's asahi line and set everyone else's" >&2
return 1
fi
# Memory stack: no zram device or zswap on the aarch64 install, and
# systemd-oomd is not enabled there, so the vm.* reclaim tuning written
# for zram would be wrong for it. Keep only the network tuning.
@@ -316,11 +361,6 @@ EOF
# live root config.
install -d "$pkgdir/usr/share/omarchy/default"
cp -a default/. "$pkgdir/usr/share/omarchy/default/"
# The Limine template is read by the x86_64 ISO orchestrator only.
if [[ $CARCH == aarch64 ]]; then
rm -rf "$pkgdir/usr/share/omarchy/default/limine"
fi
# Snapper config template used by the install-time `snapper create-config`.
install -Dm644 default/snapper/root \
"$pkgdir/etc/snapper/config-templates/omarchy"
@@ -368,6 +408,13 @@ EOF
install -Dm755 bin/omarchy-hw-platform \
"$pkgdir/usr/share/libalpm/scripts/omarchy-hw-platform"
fi
# 00-omarchy-hooks.conf places a Mac through this detector copy; without it
# an Aurora Mac gets the busybox line and its initramfs cannot unlock root.
if grep -qs omarchy-hw-platform "$pkgdir/etc/mkinitcpio.conf.d/00-omarchy-hooks.conf" &&
[[ ! -x $pkgdir/usr/share/libalpm/scripts/omarchy-hw-platform ]]; then
echo "etc/mkinitcpio.conf.d/00-omarchy-hooks.conf needs the omarchy-hw-platform copy the source does not ship" >&2
return 1
fi
# Branding assets (logos, icons).
install -Dm644 logo.txt "$pkgdir/usr/share/omarchy/logo.txt"
+73 -26
View File
@@ -13,13 +13,14 @@ pkgname='omarchy-settings'
_tag='v4.0.4'
_commit='c668141e9c42b13c80c9ca4ea108e11708c5e8a5'
pkgver=4.0.4
pkgrel=2
pkgrel=3
pkgdesc='Omarchy user defaults, /etc/skel content, fonts, plymouth theme, and support helpers'
# Arch-specific because the shipped /etc tree is not the same on every
# architecture: the Limine, mkinitcpio, zram and oomd drop-ins belong to the
# x86_64 boot and memory stack and are left out of the aarch64 package (see
# package()). makepkg only honours the arch-suffixed arrays below on
# arch-specific packages.
# architecture: the zram and oomd drop-ins belong to the x86_64 memory stack
# and are left out of the aarch64 package (see package()). The Limine and
# mkinitcpio drop-ins ship on both: UEFI aarch64 installs (DGX Spark,
# Snapdragon X) boot with Limine and an encrypted root exactly like x86_64.
# makepkg only honours the arch-suffixed arrays below on arch-specific packages.
arch=('x86_64' 'aarch64')
url='https://github.com/basecamp/omarchy'
license=('MIT')
@@ -78,14 +79,17 @@ backup=(
'etc/udev/rules.d/99-omarchy-power-profile.rules'
'etc/udev/rules.d/99-omarchy-wifi-powersave.rules'
)
# Boot configuration is backed up on both architectures.
backup+=(
'etc/mkinitcpio.conf.d/omarchy_hooks.conf'
'etc/limine-entry-tool.d/omarchy-defaults.conf'
'etc/limine-entry-tool.d/omarchy-uki.conf'
)
# backup has no arch-suffixed form, so the x86_64-only drop-ins join it here.
# Each of these paths is removed from the aarch64 package in package().
if [[ $CARCH == x86_64 ]]; then
backup+=(
'etc/mkinitcpio.conf.d/omarchy_hooks.conf'
'etc/mkinitcpio.conf.d/thunderbolt_module.conf'
'etc/limine-entry-tool.d/omarchy-defaults.conf'
'etc/limine-entry-tool.d/omarchy-uki.conf'
'etc/modprobe.d/omarchy-usb-autosuspend.conf'
'etc/systemd/oomd.conf.d/10-omarchy.conf'
'etc/systemd/zram-generator.conf'
@@ -136,6 +140,23 @@ prepare() {
fi
}
# Print the HOOKS that result from sourcing mkinitcpio drop-ins onto a line.
_omarchy_settings_hooks_after() {
local start=$1
shift
(
# Keep the build host's own tools, such as a platform detector, out of it.
PATH=/nonexistent
read -ra HOOKS <<<"$start"
MODULES=() FILES=()
for conf in "$@"; do
# shellcheck disable=SC1090
source "$conf" || exit 1
done
echo "${HOOKS[*]}"
)
}
package() {
cd "$srcdir/omarchy"
@@ -156,14 +177,6 @@ package() {
install -d "$pkgdir/usr/share/omarchy/config"
cp -a config/. "$pkgdir/usr/share/omarchy/config/"
# The Limine/Snapper notifier has nothing to notify about without the x86_64
# boot stack; drop it from both seeds so aarch64 users don't autostart a
# helper whose backing tool is not installed.
if [[ $CARCH == aarch64 ]]; then
rm -f "$pkgdir/etc/skel/.config/autostart/limine-snapper-notify.desktop" \
"$pkgdir/usr/share/omarchy/config/autostart/limine-snapper-notify.desktop"
fi
# Package-owned defaults with real system/XDG locations. User config remains
# higher priority: ~/.config/uwsm/default, ~/.config/uwsm/env.d,
# ~/.config/environment.d, ~/.config/fontconfig, ~/.config/xdg-terminals.list,
@@ -215,12 +228,44 @@ package() {
# stage separately below).
install -d "$pkgdir/etc"
cp -a etc/. "$pkgdir/etc/"
# omacom/omarchy#13362 moves the HOOKS baseline into its own drop-in.
[[ ! -f $pkgdir/etc/mkinitcpio.conf.d/00-omarchy-hooks.conf ]] ||
backup+=('etc/mkinitcpio.conf.d/00-omarchy-hooks.conf')
if [[ $CARCH == aarch64 ]]; then
# The x86_64 boot stack's drop-ins must not ship on aarch64: mkinitcpio
# reads every file under /etc/mkinitcpio.conf.d/, so omarchy_hooks.conf
# would inject the Limine hooks into the Asahi kernel's initramfs, and the
# Limine entry-tool config has no consumer without Limine.
rm -rf "$pkgdir/etc/limine-entry-tool.d" "$pkgdir/etc/mkinitcpio.conf.d"
# Keep omarchy_hooks.conf and the Limine entry-tool config: without them a
# kernel update on an encrypted aarch64 install rebuilds an initramfs with
# no encrypt hook and the machine cannot unlock its root. Only the
# Thunderbolt module request is x86-specific; ARM kernels lack the module
# and mkinitcpio treats a missing explicit module as an error.
rm -f "$pkgdir/etc/mkinitcpio.conf.d/thunderbolt_module.conf"
# Apple Silicon Macs install this package too. Their initramfs needs the
# asahi hook, which omarchy-mac-boot's 90-94 fragments (Aurora) or
# mkinitcpio.conf (legacy GRUB Macs) set, and an unconditional HOOKS= here
# would replace it. A source that sets HOOKS outright (v4.0.4) gets its line
# wrapped so it applies only when the hooks loaded so far lack asahi; one that
# already decides per platform (omacom/omarchy#13362) ships as it is. The
# wrapper reads configuration, not the running machine, so it also holds
# when the image is built in a chroot.
local hooks_conf hooks_confs=()
for hooks_conf in "$pkgdir"/etc/mkinitcpio.conf.d/{00-omarchy-hooks,omarchy_hooks}.conf; do
[[ -f $hooks_conf ]] || continue
hooks_confs+=("$hooks_conf")
sed -i 's/^\(HOOKS=([^#]*)\)[[:space:]]*$/if [[ " ${HOOKS[*]:-} " != *" asahi "* ]]; then\n \1\nfi/' "$hooks_conf"
if grep -q '^HOOKS=' "$hooks_conf"; then
echo "${hooks_conf#"$pkgdir"/}: cannot guard this HOOKS= line for Apple Silicon" >&2
return 1
fi
done
# Whatever the layout, a Mac's asahi line must come through the shipped
# files, and a stock line must not: that is where Omarchy's hooks come from.
local mac_line='base udev block asahi encrypt filesystems fsck' stock_line='base udev block filesystems fsck'
local mac_hooks stock_hooks
if ! mac_hooks=$(_omarchy_settings_hooks_after "$mac_line" "${hooks_confs[@]}") ||
! stock_hooks=$(_omarchy_settings_hooks_after "$stock_line" "${hooks_confs[@]}") ||
[[ $mac_hooks != "$mac_line" || $stock_hooks == "$stock_line" ]]; then
echo "etc/mkinitcpio.conf.d: the aarch64 hooks must keep a Mac's asahi line and set everyone else's" >&2
return 1
fi
# Memory stack: no zram device or zswap on the aarch64 install, and
# systemd-oomd is not enabled there, so the vm.* reclaim tuning written
# for zram would be wrong for it. Keep only the network tuning.
@@ -324,11 +369,6 @@ EOF
# live root config.
install -d "$pkgdir/usr/share/omarchy/default"
cp -a default/. "$pkgdir/usr/share/omarchy/default/"
# The Limine template is read by the x86_64 ISO orchestrator only.
if [[ $CARCH == aarch64 ]]; then
rm -rf "$pkgdir/usr/share/omarchy/default/limine"
fi
# Snapper config template used by the install-time `snapper create-config`.
install -Dm644 default/snapper/root \
"$pkgdir/etc/snapper/config-templates/omarchy"
@@ -376,6 +416,13 @@ EOF
install -Dm755 bin/omarchy-hw-platform \
"$pkgdir/usr/share/libalpm/scripts/omarchy-hw-platform"
fi
# 00-omarchy-hooks.conf places a Mac through this detector copy; without it
# an Aurora Mac gets the busybox line and its initramfs cannot unlock root.
if grep -qs omarchy-hw-platform "$pkgdir/etc/mkinitcpio.conf.d/00-omarchy-hooks.conf" &&
[[ ! -x $pkgdir/usr/share/libalpm/scripts/omarchy-hw-platform ]]; then
echo "etc/mkinitcpio.conf.d/00-omarchy-hooks.conf needs the omarchy-hw-platform copy the source does not ship" >&2
return 1
fi
# Branding assets (logos, icons).
install -Dm644 logo.txt "$pkgdir/usr/share/omarchy/logo.txt"
+3 -3
View File
@@ -1,15 +1,15 @@
pkgname=omarchy-steam-fex
pkgver=1.0.0
pkgrel=3
pkgrel=4
pkgdesc='Steam launcher with login workarounds for Apple Silicon using muvm and FEX'
arch=('aarch64')
url='https://github.com/omacom/omarchy-pkgs/tree/master/pkgbuilds/omarchy-steam-fex'
license=('MIT')
checkdepends=('python')
source=('omarchy-launch-steam' 'LICENSE' 'test-launcher.py')
sha256sums=('37ad2e8a863e90c2b3248f22d93b548c6070f396f631ad39cefc4745478515b4'
sha256sums=('d00742b36ba3d630b43cfe5ab7ac665625e113651d487630e2e440535c8dab64'
'717ba1949502290f8e47688ae2e323acd06c8ca47aec9f7596b15f678c1af4a2'
'fbab0f88ecdf3238bfb95a1523eef7de2ded2928c91c90e4e06435696dd86cdb')
'4584557d52d2a56d1edf082c0d0c0deaa3eed2959b02e6eb681c9dd36bc94f3f')
check() {
python test-launcher.py
+1 -1
View File
@@ -2,7 +2,7 @@
`omarchy-steam-fex` provides `omarchy-launch-steam` for the Asahi Linux `steam`, `muvm`, and `FEX-Emu` stack. Those runtime packages come from `asahi-alarm`; `FEX-Emu` provides `FEXBash`. The package is restricted to aarch64 and assumes that stack's `~/.local/share/fex-steam/steam-launcher/bin_steam.sh` layout.
The launcher runs Steam through `muvm` and `FEXBash` with the CEF occlusion workaround. Once Steam's client files are present, it also disables bootstrap verification and repair and patches the Steam UI network initialization block that can leave login waiting indefinitely. Initial bootstrap keeps the normal bootstrap flags. If the FEX launcher is unavailable, it falls back to `steam`.
The launcher runs Steam through `muvm` and `FEXBash` with the CEF occlusion workaround. Once Steam's client files are present, it patches the Steam UI network initialization block that can leave login waiting indefinitely. Initial bootstrap uses Steam's normal checks. Subsequent launches keep update and bootstrap checks enabled but pass `-noverifyfiles`: Steam otherwise detects the modified UI file, replaces it, and loses the login fix. After a client update replaces the UI file, launch again to reapply the patch. If the FEX launcher is unavailable, it falls back to `steam`.
`omarchy-launch-steam --prepare` creates the current user's desktop override with `Exec=omarchy-launch-steam %U` if it is missing, and applies the same UI patch. Existing overrides and symlinks are preserved on preparation and launch. If an existing override uses a different command, edit its `Exec` entry to use `omarchy-launch-steam %U` when you want this launcher. Each matching chunk is backed up as `.omarchy-bak` before its first patch; existing backups are preserved. The regex matches the original network initialization block, so a patched block is not changed again. An unrelated connected-state assignment elsewhere in the chunk does not suppress the fix. The regex depends on Valve's client code and may need updating when that code changes.
@@ -95,13 +95,10 @@ if [[ $(uname -m) == aarch64 ]] && command -v muvm >/dev/null && command -v FEXB
if [[ -f $launcher ]]; then
steam_args=(-cef-force-occlusion)
if steam_client_ready; then
# Steam's verifier replaces our patched UI chunk on every launch.
# Keep update/bootstrap checks enabled while preserving that patch.
steam_args+=(-noverifyfiles)
prepare_asahi
steam_args+=(
-noverifyfiles
-nobootstrapupdate
-skipinitialbootstrap
-norepairfiles
)
else
write_steam_desktop
fi
+2 -3
View File
@@ -25,7 +25,6 @@ ORIGINAL = (
'(0,Ab.cd)("System.Network.RegisterForConnectivityTestChanges")&&SteamClient.System.Network.RegisterForConnectivityTestChanges(this.OnConnectivityTestStateChanged),'
't||(this.m_bIsAwaitingInitialNetworkState=!1);after();'
)
SKIP_BOOTSTRAP = ['-noverifyfiles', '-nobootstrapupdate', '-skipinitialbootstrap', '-norepairfiles']
MOCK = '''
import json, os
@@ -200,11 +199,11 @@ class SteamLauncherTests(unittest.TestCase):
self.assert_fex(self.run_launcher(), ['-cef-force-occlusion'], [])
self.assertEqual(path.read_text(), ORIGINAL)
def test_ready_launch_patches_and_disables_bootstrap(self):
def test_ready_launch_patches_and_keeps_update_checks_enabled(self):
path = self.chunk()
self.client_ready()
args = ['steam://open/main']
self.assert_fex(self.run_launcher(*args), ['-cef-force-occlusion', *SKIP_BOOTSTRAP], args)
self.assert_fex(self.run_launcher(*args), ['-cef-force-occlusion', '-noverifyfiles'], args)
self.assertIn('m_bIsConnectedToANetwork=!0', path.read_text())
self.assert_desktop()
+6 -1
View File
@@ -2,5 +2,10 @@
"source": "local",
"rebuild_on": [
"hyprland"
]
],
"rebuilt_against": {
"x86_64": {
"hyprland": "0.56.2-3"
}
}
}
+1 -1
View File
@@ -2,7 +2,7 @@
pkgname=omareel
pkgver=0.1.0
pkgrel=1
pkgrel=2
pkgdesc='Screen recorder and editor for Omarchy with a synthetic cursor, auto zooms, and a camera bubble'
arch=('x86_64' 'aarch64')
url='https://github.com/omacom/omareel'
+9 -8
View File
@@ -2,9 +2,9 @@
pkgname=omaspeak-bin
_pkgname=${pkgname%-bin}
pkgver=0.0.3
_upstream_ver=0.0.3
pkgrel=4
pkgver=0.1.0
_upstream_ver=0.1.0
pkgrel=1
pkgdesc='Local-first text-to-speech application and daemon (pre-built binary)'
arch=('x86_64' 'aarch64')
url='https://github.com/jacob-vincent-mink/omaspeak'
@@ -16,9 +16,10 @@ depends=(
)
optdepends=(
'pipewire-audio: audio playback through pw-play'
'openvino: Intel CPU acceleration runtime'
'openvino-intel-gpu-plugin: Intel GPU device support for OpenVINO'
'openvino-intel-npu-plugin: Intel NPU device support for OpenVINO'
'openvino>=2026.4.0: Intel acceleration runtime'
'openvino-genai>=2026.4.0.0: Kokoro speech synthesis on OpenVINO'
'openvino-intel-gpu-plugin>=2026.4.0: Intel GPU device support for OpenVINO'
'openvino-intel-npu-plugin>=2026.4.0: Intel NPU device support for OpenVINO'
'cuda: NVIDIA CUDA libraries for an external CUDA runtime bundle'
'cudnn: NVIDIA neural-network libraries for an external CUDA runtime bundle'
)
@@ -34,8 +35,8 @@ sha256sums=('f1b527448529b45fee2f96b4c0a19b11087377c0ac9f43842bab0d04fcfd3b9f'
source_x86_64=("${_pkgname}-${_upstream_ver}-linux-x86_64.tar.xz::${url}/releases/download/v${_upstream_ver}/${_pkgname}-${_upstream_ver}-linux-x86_64.tar.xz")
source_aarch64=("${_pkgname}-${_upstream_ver}-linux-aarch64.tar.xz::${url}/releases/download/v${_upstream_ver}/${_pkgname}-${_upstream_ver}-linux-aarch64.tar.xz")
sha256sums_x86_64=('c72428bf6989582b5aa802f39e9390e4cacf26f7fbfacf76645118286c7d1ab2')
sha256sums_aarch64=('88fc4ea8c275b9d5b9d41602d32dbca77ee30de0fc7dcbc06ad0e819fd41545a')
sha256sums_x86_64=('56936bd17490a3fcf6c004413f1ba8b723d1e08256e215cae6434ef345c951ba')
sha256sums_aarch64=('10e6d07de03c8243cbb4172d0517653b82a4d1e785fdd1b6aaf5ae9618ea6171')
package() {
install -Dm755 "${srcdir}/package-remove" "${pkgdir}/usr/lib/${_pkgname}/package-remove"
+16 -5
View File
@@ -1,7 +1,7 @@
# Maintainer: David Heinemeier Hansson <david@hey.com>
pkgname=omatrack
pkgver=1.2.0
pkgver=1.8.6
pkgrel=1
pkgdesc="Cross-format motorsport telemetry analysis workstation"
arch=('x86_64' 'aarch64')
@@ -11,9 +11,17 @@ depends=('qt6-base' 'qt6-declarative' 'mpv' 'libyaml' 'gcc-libs' 'glibc' 'hicolo
makedepends=('cmake' 'ninja' 'rust')
options=('!debug' '!lto')
_commit=ebe7f4f6b05845a85a2b713f889e676442fd0e82
source=("omatrack-$_commit.tar.gz::$url/archive/$_commit.tar.gz")
sha256sums=('8e6c62de5f8c98239a84abe9696c83f1155bef12004ee2c028bd99d64b8263a4')
_commit=cd3fcdda3f8e15fda73288f6cf3803164138a7e4
source=(
"omatrack-$_commit.tar.gz::$url/archive/$_commit.tar.gz"
'lua-5.4.7.tar.gz::https://www.lua.org/ftp/lua-5.4.7.tar.gz'
'sol2-d805d027.tar.gz::https://github.com/ThePhD/sol2/archive/d805d027e0a0a7222e936926139f06e23828ce9f.tar.gz'
)
sha256sums=(
'6beb5703fe0b08a3bb99409581246498300f5cd91195239da00b91123681b8a3'
'9fbf5e28ef86c69858f6d3d34eccc32e911c1a28b4120ff3e84aaa70cfbf1e30'
'e7877a14e90d44e1b2d00ec77b85090b3b441f4634a63f23bfe44cedbac8ac9c'
)
prepare() {
cd "omatrack-$_commit/third_party/motorsport-telemetry"
@@ -26,7 +34,10 @@ build() {
cmake -B build -S . -G Ninja \
-DCMAKE_BUILD_TYPE=Release \
-DCMAKE_INSTALL_PREFIX=/usr
-DCMAKE_INSTALL_PREFIX=/usr \
-DFETCHCONTENT_SOURCE_DIR_LUA_SRC="$srcdir/lua-5.4.7" \
-DFETCHCONTENT_SOURCE_DIR_SOL2="$srcdir/sol2-d805d027e0a0a7222e936926139f06e23828ce9f" \
-DFETCHCONTENT_FULLY_DISCONNECTED=ON
cmake --build build
}
+9 -8
View File
@@ -2,9 +2,9 @@
pkgname=omawake-bin
_pkgname=${pkgname%-bin}
pkgver=0.0.3
_upstream_ver=0.0.3
pkgrel=4
pkgver=0.1.1
_upstream_ver=0.1.1
pkgrel=1
pkgdesc='Configurable local wake-word daemon (pre-built binary)'
arch=('x86_64' 'aarch64')
url='https://github.com/jacob-vincent-mink/omawake'
@@ -16,9 +16,10 @@ depends=(
)
optdepends=(
'pipewire-audio: PipeWire audio support'
'openvino: Intel runtime for an externally supplied OpenVINO provider bundle'
'openvino-intel-gpu-plugin: Intel GPU device support for OpenVINO'
'openvino-intel-npu-plugin: Intel NPU device support for OpenVINO'
'openvino>=2026.4.0: Intel runtime for the OpenVINO provider'
'openvino-genai>=2026.4.0.0: OpenVINO GenAI C provider for Whisper'
'openvino-intel-gpu-plugin>=2026.4.0: Intel GPU device support for OpenVINO'
'openvino-intel-npu-plugin>=2026.4.0: Intel NPU device support for OpenVINO'
'cuda: NVIDIA CUDA libraries for an external CUDA runtime bundle'
'cudnn: NVIDIA neural-network libraries for an external CUDA runtime bundle'
)
@@ -34,8 +35,8 @@ sha256sums=('f1b527448529b45fee2f96b4c0a19b11087377c0ac9f43842bab0d04fcfd3b9f'
source_x86_64=("${_pkgname}-${_upstream_ver}-linux-x86_64.tar.xz::${url}/releases/download/v${_upstream_ver}/${_pkgname}-${_upstream_ver}-linux-x86_64.tar.xz")
source_aarch64=("${_pkgname}-${_upstream_ver}-linux-aarch64.tar.xz::${url}/releases/download/v${_upstream_ver}/${_pkgname}-${_upstream_ver}-linux-aarch64.tar.xz")
sha256sums_x86_64=('fa374341f60760b04c9a97d76f7ad2679463f5b2b673ee6d9c1ceee97d3f0669')
sha256sums_aarch64=('384eb11872c873a33332acf51f567dc4d4e327e57563b61056e4d0aa7fe470eb')
sha256sums_x86_64=('adf8d93dd892fa77089384944a720de502d331582cc0e6eed66c9eaa2d31b568')
sha256sums_aarch64=('9929208a3166f0f1939a66d306018a7a861f92fca1d0e186ea8f9af93a947ecb')
package() {
install -Dm755 "${srcdir}/package-remove" "${pkgdir}/usr/lib/${_pkgname}/package-remove"
+3 -2
View File
@@ -1,11 +1,11 @@
pkgname=omazed
pkgver=2.2.0
pkgrel=1
pkgrel=2
pkgdesc="Live theme switching for Zed in Omarchy - automatically synchronize your Zed editor theme with your Omarchy system theme"
arch=('any')
url="https://github.com/aps6/omazed"
license=('MIT')
depends=('bash')
depends=('bash' 'jq' 'perl')
makedepends=('git')
backup=()
install=omazed.install
@@ -19,6 +19,7 @@ package() {
install -Dm755 omazed "$pkgdir/usr/bin/omazed"
install -Dm755 omazed-generator.sh "$pkgdir/usr/bin/omazed-generator.sh"
install -Dm644 omazed-theme.tpl "$pkgdir/usr/bin/omazed-theme.tpl"
install -Dm755 omazed-font.sh "$pkgdir/usr/bin/omazed-font.sh"
# Install documentation
install -Dm644 README.md "$pkgdir/usr/share/doc/$pkgname/README.md"
+7 -9
View File
@@ -1,8 +1,8 @@
# Maintainer: Spencer Bull <spencer@omarchy.org>
pkgname=openvino-genai
pkgver=2026.3.1.0
pkgrel=3
pkgver=2026.4.0.0
pkgrel=1
pkgdesc="OpenVINO GenAI C and C++ runtime libraries"
arch=('x86_64')
url="https://github.com/openvinotoolkit/openvino.genai"
@@ -12,7 +12,7 @@ depends=(
'gcc-libs'
'glibc'
'onetbb'
'openvino=2026.3.1' # Includes libopenvino_c.so.
'openvino=2026.4.0' # Includes libopenvino_c.so.
)
makedepends=(
'cmake'
@@ -25,24 +25,22 @@ optdepends=(
'openvino-intel-npu-plugin: inference on Intel NPUs'
)
_commit=56d9685302da2fc5cc7c9689cfab500fd0660a02
_commit=7ea2546852a382cd16bd22dea0cfad2db70ed744
source=(
"openvino.genai::git+$url.git#commit=$_commit"
'gcc-16-char8_t.patch'
'format-template-linkage.patch::https://github.com/openvinotoolkit/openvino.genai/commit/398fbc1450f7485368edf52dd82f45eba215d6c9.patch'
'linear-attention-guard-constructor.patch'
)
sha256sums=(
'SKIP'
'6e685c1e45d4b2314fd55e2f791846cc9086413ba62a6bb5e31be5a5878a243c'
'8c2a3e4bf1d33e00b780da7bec2d5e40b6fd26a4e518359d6ff7c59ca7f649e3'
'61958d64dd7510ff0cb6da010f26fddba3e5dbc38691828163a63d54951d1b2a'
)
prepare() {
cd openvino.genai
patch -Np1 -i "$srcdir/gcc-16-char8_t.patch"
# Backport upstream 398fbc14: GCC -O3 can otherwise leave format<int>
# unresolved in libopenvino_genai.so.
patch -Np1 -i "$srcdir/format-template-linkage.patch"
patch -Np1 -i "$srcdir/linear-attention-guard-constructor.patch"
git submodule update --init --recursive
}
@@ -0,0 +1,14 @@
diff --git a/src/cpp/src/continuous_batching/pipeline_impl.cpp b/src/cpp/src/continuous_batching/pipeline_impl.cpp
--- a/src/cpp/src/continuous_batching/pipeline_impl.cpp
+++ b/src/cpp/src/continuous_batching/pipeline_impl.cpp
@@ -529,6 +529,10 @@ void ContinuousBatchingPipeline::ContinuousBatchingImpl::step() {
const Scheduler::Output& m_scheduler_output;
bool m_armed = true;
+ BorrowedLinearAttentionRowsGuard(ContinuousBatchingImpl& impl, const Scheduler::Output& scheduler_output)
+ : m_impl(impl), m_scheduler_output(scheduler_output) {
+ }
+
~BorrowedLinearAttentionRowsGuard() {
if (m_armed) {
m_impl._release_linear_attention_borrowed_rows(m_scheduler_output);
@@ -7,9 +7,11 @@
"qt6-wayland"
],
"rebuilt_against": {
"qt6-base": "6.11.2-3",
"qt6-declarative": "6.11.2-1",
"qt6-wayland": "6.11.2-1"
"x86_64": {
"qt6-base": "6.11.2-3",
"qt6-declarative": "6.11.2-2",
"qt6-wayland": "6.11.2-1"
}
},
"origin": {
"aur": "quickshell-git",
+1 -1
View File
@@ -3,7 +3,7 @@
_pkgname=quickshell
pkgname="$_pkgname-git"
pkgver=0.3.0.r20.g28771c7
pkgrel=3
pkgrel=4
pkgdesc='Flexible toolkit for making desktop shells with QtQuick'
arch=(x86_64 aarch64)
url='https://git.outfoxxed.me/quickshell/quickshell'
+13 -3
View File
@@ -3,7 +3,7 @@
pkgname=supergfxctl
pkgver=5.2.7
pkgrel=2
pkgrel=3
pkgdesc="A utility for Linux graphics switching on Intel/AMD iGPU + nVidia dGPU laptops"
arch=('x86_64')
url="https://gitlab.com/asus-linux/supergfxctl"
@@ -13,11 +13,21 @@ makedepends=('rust')
provides=('supergfxctl')
conflicts=('supergfxctl-git'
'optimus-manager')
source=("https://gitlab.com/asus-linux/supergfxctl/-/archive/$pkgver/supergfxctl-$pkgver.tar.gz")
sha512sums=('bd94646d289c9f3398e1bf2a189554ac60d4db2d4d2cefddc0b342e8a128d4682e20268e0b1f9b168441136ada0b6fadb097a5a35d1023a77528dbf0540de3af')
source=("https://gitlab.com/asus-linux/supergfxctl/-/archive/$pkgver/supergfxctl-$pkgver.tar.gz"
"drop-nonexistent-sudo-group.patch")
sha512sums=('bd94646d289c9f3398e1bf2a189554ac60d4db2d4d2cefddc0b342e8a128d4682e20268e0b1f9b168441136ada0b6fadb097a5a35d1023a77528dbf0540de3af'
'c24de0e6a632fd98052eb3b265000cf15bf00ff46f7e52120e462715937df8135297d9f12725d1c303691c0db55b23d2b29671f020bd64e98a993b1ad9b8551e')
options=(!debug)
_gitdir=${pkgname%"-git"}
prepare() {
cd "$pkgname-$pkgver"
# Arch has no "sudo" group, so dbus-broker rejects that policy block by name on
# every bus reload ("Invalid group-name ... group=\"sudo\""). The block grants
# nothing here; the wheel policy in the same file is the one that applies.
patch -p1 -i "$srcdir/drop-nonexistent-sudo-group.patch"
}
build() {
cd "$pkgname-$pkgver"
make build
@@ -0,0 +1,13 @@
--- a/data/org.supergfxctl.Daemon.conf
+++ b/data/org.supergfxctl.Daemon.conf
@@ -6,10 +6,6 @@
<allow send_destination="org.supergfxctl.Daemon"/>
<allow receive_sender="org.supergfxctl.Daemon"/>
</policy>
- <policy group="sudo">
- <allow send_destination="org.supergfxctl.Daemon"/>
- <allow receive_sender="org.supergfxctl.Daemon"/>
- </policy>
<policy group="users">
<allow send_destination="org.supergfxctl.Daemon"/>
<allow receive_sender="org.supergfxctl.Daemon"/>
+12 -1
View File
@@ -1,3 +1,14 @@
{
"source": "local"
"source": "local",
"upstream": {
"git_tags": "https://github.com/tobi/try.git",
"tag_pattern": "v{pkgver}",
"sources": {
"any": [
"https://raw.githubusercontent.com/tobi/try/{tag}/try.rb",
"https://raw.githubusercontent.com/tobi/try/{tag}/lib/fuzzy.rb",
"https://raw.githubusercontent.com/tobi/try/{tag}/lib/tui.rb"
]
}
}
}
+7 -8
View File
@@ -1,9 +1,8 @@
# Maintainer: dhh
pkgname='tobi-try'
pkgver=1.8.1
_subver=d1bc484cc31a34db3d287550f4800e9a6e56bacd
pkgrel=3
pkgver=1.10.1
pkgrel=1
pkgdesc='Fresh directories for every vibe.'
url='https://github.com/tobi/try'
arch=('any')
@@ -13,12 +12,12 @@ provides=('try')
conflicts=('try')
options=('!debug')
source=("try-${pkgver}.rb::https://raw.githubusercontent.com/tobi/try/${_subver}/try.rb"
"fuzzy.rb::https://raw.githubusercontent.com/tobi/try/${_subver}/lib/fuzzy.rb"
"tui.rb::https://raw.githubusercontent.com/tobi/try/${_subver}/lib/tui.rb")
sha256sums=('55a968dc5b1536b338d8f96693576c8cb19ca6bcabbca9138591cd0518486b02'
source=("try-${pkgver}.rb::https://raw.githubusercontent.com/tobi/try/v${pkgver}/try.rb"
"fuzzy.rb::https://raw.githubusercontent.com/tobi/try/v${pkgver}/lib/fuzzy.rb"
"tui.rb::https://raw.githubusercontent.com/tobi/try/v${pkgver}/lib/tui.rb")
sha256sums=('2e52bcd81244ff59e4a51dda5d7ba446dabaa0d1c5e23f02902431ca8d091be9'
'cf815ed12c8147bbc7f67008cfc1f3fd05df1638ff290e2079188f1b9bf8f190'
'b62d2b61445d8266f064e2809e06ebc0a25da401ee5a13dc3a73d215c0a1ea71')
'0ea1b79975f2bcf36dbb29c5b76738e7cac81cedde24bf3bde85d8e2a42fd225')
build() {
cd "${srcdir}"
+2 -4
View File
@@ -1,7 +1,7 @@
# Maintainer: David Heinemeier Hansson <david@hey.com>
pkgname=ttfx
pkgver=0.4.0
pkgver=0.5.0
pkgrel=1
pkgdesc="Terminal text effects as a single static binary — Rust port of terminaltexteffects"
arch=('x86_64' 'aarch64')
@@ -9,12 +9,10 @@ url="https://github.com/omacom/ttfx"
license=('MIT')
depends=('gcc-libs' 'glibc')
makedepends=('cargo')
# the x86-64 assembly engine; without NASM the build falls back to pure Rust
makedepends_x86_64=('nasm')
options=('!debug')
source=("$pkgname-$pkgver.tar.gz::$url/archive/refs/tags/v$pkgver.tar.gz")
sha256sums=('90a057971973917a45ae1cb2fc795cfaea33afc265180ba4a963172daf9f64ee')
sha256sums=('2882c7e47011a95f4d136303f7320da71613299840f67f88fd1385ef53d5f2a0')
prepare() {
cd "$pkgname-$pkgver"
@@ -0,0 +1,37 @@
# The platform's HOOKS baseline. mkinitcpio sources mkinitcpio.conf and then
# every drop-in here in name order, so the baseline sorts first and the drop-ins
# after it add their hooks to it instead of being overwritten by it.
#
# Apple Silicon boots a systemd initramfs, and its platform package adds the
# firmware and encryption hooks. Every other machine keeps the busybox line. The
# runtime's detector answers, or else the copy omarchy-settings ships for its
# platform guard, so a settings package newer than the runtime still places a
# Mac. Without either, the busybox line stays. A detector that cannot place the
# machine stops the build rather than let it produce an image for the wrong
# platform.
_omarchy_platform=""
_omarchy_detector=$(command -v omarchy-hw-platform) || _omarchy_detector=/usr/share/libalpm/scripts/omarchy-hw-platform
if [[ -x $_omarchy_detector ]]; then
_omarchy_platform=$("$_omarchy_detector") || return 1
fi
# A Mac whose mkinitcpio.conf carries the asahi hook, or the busybox encrypt
# hook that unlocks it through cryptdevice= (sd-encrypt cannot parse that), boots
# the initramfs its platform set up without the Apple boot package, as a legacy
# install does. Its line stays as it is. The asahi hook also marks such a root
# off a Mac, as in a chroot or a VM.
if [[ " ${HOOKS[*]:-} " == *" asahi "* ]] ||
[[ $_omarchy_platform == "apple-silicon" && " ${HOOKS[*]:-} " == *" encrypt "* ]]; then
_omarchy_platform=platform-owned
fi
case $_omarchy_platform in
platform-owned) ;;
apple-silicon)
HOOKS=(base systemd plymouth autodetect microcode modconf kms keyboard sd-vconsole block filesystems fsck)
;;
*)
HOOKS=(base udev plymouth keyboard autodetect microcode modconf kms keymap consolefont block encrypt filesystems fsck btrfs-overlayfs)
;;
esac
unset _omarchy_platform _omarchy_detector
@@ -0,0 +1,53 @@
# Adjusts the baseline HOOKS from 00-omarchy-hooks.conf. It stays apart from
# the baseline because it reads what the hardware drop-ins sorting before it set.
# The proprietary NVIDIA driver does early KMS itself: nvidia.conf (written by
# install/hardware/nvidia.sh, sourced before this file) early-loads nvidia_drm
# with modeset=1. Keeping the kms hook on such a system makes autodetect pull
# in nouveau — and ~100 MB of its GSP firmware — for a driver that never runs.
# Drop kms only when nvidia_drm is early-loaded and NVIDIA owns every display
# controller. Hybrid systems keep kms: their iGPU still needs it for early
# KMS at the LUKS prompt. So does anything unexpected, like a PCI tree that
# cannot be read.
#
# This reads MODULES midway through mkinitcpio's drop-in sourcing, so a
# later-sorting drop-in that resets MODULES outright — surface_device_modules.conf
# does — would strip nvidia_drm after kms was already dropped. Every machine
# Omarchy writes such a file for carries an Intel iGPU, which keeps kms here
# through the scan below; keep it that way.
if [[ " ${MODULES[*]:-} " == *" nvidia_drm "* ]]; then
_omarchy_nvidia_gpu=0
_omarchy_other_gpu=0
for _omarchy_pci in "${OMARCHY_PCI_DEVICES_PATH:-/sys/bus/pci/devices}"/*; do
if [[ ! -r $_omarchy_pci/class || ! -r $_omarchy_pci/vendor ]]; then
# An unreadable device could be another GPU. Inconclusive keeps kms.
_omarchy_other_gpu=1
continue
fi
[[ $(<"$_omarchy_pci/class") == "0x03"* ]] || continue
if [[ $(<"$_omarchy_pci/vendor") == "0x10de" ]]; then
_omarchy_nvidia_gpu=1
else
_omarchy_other_gpu=1
fi
done
if ((_omarchy_nvidia_gpu && !_omarchy_other_gpu)); then
_omarchy_hooks=()
for _omarchy_hook in "${HOOKS[@]}"; do
[[ $_omarchy_hook == "kms" ]] || _omarchy_hooks+=("$_omarchy_hook")
done
HOOKS=("${_omarchy_hooks[@]}")
fi
unset _omarchy_nvidia_gpu _omarchy_other_gpu _omarchy_pci _omarchy_hooks _omarchy_hook
fi
# Bundle vconsole.conf so Plymouth uses the configured keyboard layout at the
# LUKS prompt, but only when that layout types Latin letters. Passphrases are
# Latin characters, so bundling a Hebrew/Greek/Cyrillic/Arabic layout would
# make the correct passphrase untypeable and lock the user out.
if [[ -f /etc/vconsole.conf ]]; then
case $(. /etc/vconsole.conf && echo "${XKBLAYOUT%%,*}") in
af | am | ara | bd | bg | by | et | ge | gr | il | in | iq | ir | kg | kh | kz | la | lk | mk | mm | mn | mv | np | rs | ru | sy | th | tj | ua) ;;
*) FILES+=(/etc/vconsole.conf) ;;
esac
fi
@@ -0,0 +1,18 @@
# Generated by the Omarchy Apple Silicon image builder.
_omarchy_asahi_hooks=()
_omarchy_asahi_added=false
for _omarchy_asahi_hook in "${HOOKS[@]}"; do
if [[ $_omarchy_asahi_hook == asahi ]]; then
_omarchy_asahi_added=true
fi
if [[ $_omarchy_asahi_hook == filesystems && $_omarchy_asahi_added == false ]]; then
_omarchy_asahi_hooks+=(asahi omarchy-vendorfw)
_omarchy_asahi_added=true
fi
_omarchy_asahi_hooks+=("$_omarchy_asahi_hook")
done
if [[ $_omarchy_asahi_added == false ]]; then
_omarchy_asahi_hooks+=(asahi omarchy-vendorfw)
fi
HOOKS=("${_omarchy_asahi_hooks[@]}")
unset _omarchy_asahi_hooks _omarchy_asahi_hook _omarchy_asahi_added
@@ -0,0 +1,90 @@
# Insert omarchy-mac-encrypt after vendorfw/block and sd-encrypt immediately
# before filesystems, each only if that hook is absent. 90-omarchy-mac.conf
# already put asahi and omarchy-vendorfw before filesystems; this drop-in is
# sourced after it.
#
# Both are systemd initrd units: the systemd hook replaces udev (mkinitcpio's
# stock HOOKS line) and keymap/consolefont become sd-vconsole. A HOOKS line
# carrying the busybox encrypt hook belongs to a Mac unlocked by cryptdevice=,
# which sd-encrypt cannot parse: that line is left exactly as it is.
_omarchy_mac_encrypt_hooks=()
_omarchy_mac_encrypt_have_systemd=false
_omarchy_mac_encrypt_have_vconsole=false
_omarchy_mac_encrypt_have_encrypt=false
for _omarchy_mac_encrypt_hook in "${HOOKS[@]}"; do
case $_omarchy_mac_encrypt_hook in
systemd) _omarchy_mac_encrypt_have_systemd=true ;;
sd-vconsole) _omarchy_mac_encrypt_have_vconsole=true ;;
encrypt) _omarchy_mac_encrypt_have_encrypt=true ;;
esac
done
if [[ $_omarchy_mac_encrypt_have_encrypt == false ]]; then
for _omarchy_mac_encrypt_hook in "${HOOKS[@]}"; do
case $_omarchy_mac_encrypt_hook in
udev)
if [[ $_omarchy_mac_encrypt_have_systemd == false ]]; then
_omarchy_mac_encrypt_hooks+=(systemd)
_omarchy_mac_encrypt_have_systemd=true
fi
;;
keymap|consolefont)
if [[ $_omarchy_mac_encrypt_have_vconsole == false ]]; then
_omarchy_mac_encrypt_hooks+=(sd-vconsole)
_omarchy_mac_encrypt_have_vconsole=true
fi
;;
*) _omarchy_mac_encrypt_hooks+=("$_omarchy_mac_encrypt_hook") ;;
esac
done
if [[ $_omarchy_mac_encrypt_have_systemd == false ]]; then
if [[ ${_omarchy_mac_encrypt_hooks[0]:-} == base ]]; then
_omarchy_mac_encrypt_hooks=(base systemd "${_omarchy_mac_encrypt_hooks[@]:1}")
else
_omarchy_mac_encrypt_hooks=(systemd "${_omarchy_mac_encrypt_hooks[@]}")
fi
fi
HOOKS=("${_omarchy_mac_encrypt_hooks[@]}")
_omarchy_mac_encrypt_hooks=()
_omarchy_mac_encrypt_have_ours=false
_omarchy_mac_encrypt_have_sd=false
_omarchy_mac_encrypt_added_ours=false
_omarchy_mac_encrypt_added_sd=false
for _omarchy_mac_encrypt_hook in "${HOOKS[@]}"; do
if [[ $_omarchy_mac_encrypt_hook == omarchy-mac-encrypt ]]; then
_omarchy_mac_encrypt_have_ours=true
fi
if [[ $_omarchy_mac_encrypt_hook == sd-encrypt ]]; then
_omarchy_mac_encrypt_have_sd=true
fi
done
for _omarchy_mac_encrypt_hook in "${HOOKS[@]}"; do
if [[ $_omarchy_mac_encrypt_hook == sd-encrypt && $_omarchy_mac_encrypt_have_ours == false &&
$_omarchy_mac_encrypt_added_ours == false ]]; then
_omarchy_mac_encrypt_hooks+=(omarchy-mac-encrypt)
_omarchy_mac_encrypt_added_ours=true
fi
if [[ $_omarchy_mac_encrypt_hook == filesystems ]]; then
if [[ $_omarchy_mac_encrypt_have_ours == false && $_omarchy_mac_encrypt_added_ours == false ]]; then
_omarchy_mac_encrypt_hooks+=(omarchy-mac-encrypt)
_omarchy_mac_encrypt_added_ours=true
fi
if [[ $_omarchy_mac_encrypt_have_sd == false && $_omarchy_mac_encrypt_added_sd == false ]]; then
_omarchy_mac_encrypt_hooks+=(sd-encrypt)
_omarchy_mac_encrypt_added_sd=true
fi
fi
_omarchy_mac_encrypt_hooks+=("$_omarchy_mac_encrypt_hook")
done
if [[ $_omarchy_mac_encrypt_have_ours == false && $_omarchy_mac_encrypt_added_ours == false ]]; then
_omarchy_mac_encrypt_hooks+=(omarchy-mac-encrypt)
fi
if [[ $_omarchy_mac_encrypt_have_sd == false && $_omarchy_mac_encrypt_added_sd == false ]]; then
_omarchy_mac_encrypt_hooks+=(sd-encrypt)
fi
HOOKS=("${_omarchy_mac_encrypt_hooks[@]}")
fi
unset _omarchy_mac_encrypt_hooks _omarchy_mac_encrypt_hook \
_omarchy_mac_encrypt_have_ours _omarchy_mac_encrypt_have_sd \
_omarchy_mac_encrypt_added_ours _omarchy_mac_encrypt_added_sd \
_omarchy_mac_encrypt_have_systemd _omarchy_mac_encrypt_have_vconsole \
_omarchy_mac_encrypt_have_encrypt
@@ -0,0 +1,31 @@
# Origin: omarchy-mx-mac install/hardware/apple/fix-asahi-hid-race.sh
# Apple Silicon internal keyboard and trackpad at the sd-encrypt passphrase
# prompt. dockchannel-hid creates the HID devices; hid_apple binds the
# keyboard and hid_magicmouse the SPI trackpad. MTP machines (M2 Air, M2 Max
# j416c) use dockchannel-hid — linux-aurora has no apple-mtp module. SPI HID
# (M1 Air, M1 Pro j314s) is spi-hid-apple-of, built-in on aurora. usbhid is
# an external USB keyboard at the prompt. thunderbolt (CONFIG_USB4=m) and
# thunderbolt_apple, the Apple Silicon USB4 host router (CONFIG_USB4_APPLE_SOC=m
# on linux-aurora), bring up the USB4/Thunderbolt tunnels, so a keyboard behind
# a USB-C or Thunderbolt dock types at the prompt too (omarchy-mx-mac#86).
#
# mkinitcpio fails the whole image over a MODULES entry it cannot find, or a
# built-in it reports as "(builtin)". Each name is added only when modinfo
# returns a real path. Ending on unset keeps the exit status zero.
for _omarchy_mac_hid_module in \
hid_apple hid_magicmouse dockchannel-hid usbhid \
spi-apple spi-hid-apple spi-hid-apple-of \
apple-dockchannel apple-rtkit-helper thunderbolt thunderbolt_apple; do
_omarchy_mac_hid_path=$(modinfo -k "${KERNELVERSION:-$(uname -r)}" -F filename \
"$_omarchy_mac_hid_module" 2>/dev/null) || continue
[[ $_omarchy_mac_hid_path == /* ]] || continue
MODULES+=("$_omarchy_mac_hid_module")
done
unset _omarchy_mac_hid_module _omarchy_mac_hid_path
# MTP trackpad firmware (apple/tpmtfw-<board>.bin) is not a MODULES entry.
# omarchy-vendorfw-initrd.service unpacks ESP vendorfw/firmware.cpio onto
# /lib/firmware/vendor (symlink to /vendorfw) before cryptsetup-pre.target.
# Do not FILES+= under /lib/firmware/vendor, and do not pre-create
# /vendorfw/apple in the image: that skipped ESP extraction.
@@ -0,0 +1,18 @@
# Plymouth draws the disk password prompt and the boot splash, as on x86
# Omarchy. It goes right after systemd so its initrd units order correctly,
# only when the hook is installed, and never twice.
if [[ -f /usr/lib/initcpio/install/plymouth && " ${HOOKS[*]} " != *" plymouth "* ]]; then
_omarchy_mac_plymouth_hooks=()
_omarchy_mac_plymouth_added=false
for _omarchy_mac_plymouth_hook in "${HOOKS[@]}"; do
_omarchy_mac_plymouth_hooks+=("$_omarchy_mac_plymouth_hook")
if [[ $_omarchy_mac_plymouth_hook == systemd && $_omarchy_mac_plymouth_added == false ]]; then
_omarchy_mac_plymouth_hooks+=(plymouth)
_omarchy_mac_plymouth_added=true
fi
done
if [[ $_omarchy_mac_plymouth_added == true ]]; then
HOOKS=("${_omarchy_mac_plymouth_hooks[@]}")
fi
unset _omarchy_mac_plymouth_hooks _omarchy_mac_plymouth_added _omarchy_mac_plymouth_hook
fi
@@ -0,0 +1,46 @@
# The disk passphrase prompt types with the owner's keyboard layout, as on
# x86 Omarchy: sd-vconsole loads KEYMAP on the console (systemd-ask-password)
# and /etc/vconsole.conf gives Plymouth its XKBLAYOUT. The aarch64
# omarchy-settings drops upstream's omarchy_hooks.conf, so this drop-in
# carries its guard: a layout that does not type Latin letters stays out of
# the initramfs, because a Latin passphrase would be untypeable in it
# (upstream #6229). The prompt then uses the kernel's US map, which is what
# such a passphrase was typed with.
#
# A systemd HOOKS line gets sd-vconsole exactly once, after keyboard (or
# after systemd without one); keymap and consolefont are its busybox
# counterparts and never belong on such a line. A busybox line (a Mac
# unlocked by cryptdevice=, which 91 leaves alone) keeps its hooks; it only
# gets the file for Plymouth, as upstream does.
# No vconsole.conf is the kernel's US map: sd-vconsole stays, nothing to bundle.
_omarchy_mac_vconsole_latin=true
if [[ -f /etc/vconsole.conf ]]; then
_omarchy_mac_vconsole_layout=$(unset XKBLAYOUT; . /etc/vconsole.conf 2>/dev/null; printf '%s' "${XKBLAYOUT:-}")
case ${_omarchy_mac_vconsole_layout%%,*} in
af | am | ara | bd | bg | by | et | ge | gr | il | in | iq | ir | kg | kh | kz | la | lk | mk | mm | mn | mv | np | rs | ru | sy | th | tj | ua)
_omarchy_mac_vconsole_latin=false ;;
esac
fi
if [[ " ${HOOKS[*]} " == *" systemd "* ]]; then
_omarchy_mac_vconsole_hooks=()
_omarchy_mac_vconsole_anchor=systemd
[[ " ${HOOKS[*]} " != *" keyboard "* ]] || _omarchy_mac_vconsole_anchor=keyboard
for _omarchy_mac_vconsole_hook in "${HOOKS[@]}"; do
case $_omarchy_mac_vconsole_hook in
sd-vconsole | keymap | consolefont) continue ;;
esac
_omarchy_mac_vconsole_hooks+=("$_omarchy_mac_vconsole_hook")
if [[ $_omarchy_mac_vconsole_hook == "$_omarchy_mac_vconsole_anchor" && $_omarchy_mac_vconsole_latin == true ]]; then
_omarchy_mac_vconsole_hooks+=(sd-vconsole)
_omarchy_mac_vconsole_anchor=
fi
done
HOOKS=("${_omarchy_mac_vconsole_hooks[@]}")
fi
if [[ $_omarchy_mac_vconsole_latin == true && -f /etc/vconsole.conf ]]; then
FILES+=(/etc/vconsole.conf)
fi
unset _omarchy_mac_vconsole_latin _omarchy_mac_vconsole_layout _omarchy_mac_vconsole_hooks \
_omarchy_mac_vconsole_anchor _omarchy_mac_vconsole_hook
+52
View File
@@ -0,0 +1,52 @@
HOOKS=(base udev plymouth keyboard autodetect microcode modconf kms keymap consolefont block encrypt filesystems fsck btrfs-overlayfs)
# The proprietary NVIDIA driver does early KMS itself: nvidia.conf (written by
# install/hardware/nvidia.sh, sourced before this file) early-loads nvidia_drm
# with modeset=1. Keeping the kms hook on such a system makes autodetect pull
# in nouveau — and ~100 MB of its GSP firmware — for a driver that never runs.
# Drop kms only when nvidia_drm is early-loaded and NVIDIA owns every display
# controller. Hybrid systems keep kms: their iGPU still needs it for early
# KMS at the LUKS prompt. So does anything unexpected, like a PCI tree that
# cannot be read.
#
# This reads MODULES midway through mkinitcpio's drop-in sourcing, so a
# later-sorting drop-in that resets MODULES outright — surface_device_modules.conf
# does — would strip nvidia_drm after kms was already dropped. Every machine
# Omarchy writes such a file for carries an Intel iGPU, which keeps kms here
# through the scan below; keep it that way.
if [[ " ${MODULES[*]:-} " == *" nvidia_drm "* ]]; then
_omarchy_nvidia_gpu=0
_omarchy_other_gpu=0
for _omarchy_pci in "${OMARCHY_PCI_DEVICES_PATH:-/sys/bus/pci/devices}"/*; do
if [[ ! -r $_omarchy_pci/class || ! -r $_omarchy_pci/vendor ]]; then
# An unreadable device could be another GPU. Inconclusive keeps kms.
_omarchy_other_gpu=1
continue
fi
[[ $(<"$_omarchy_pci/class") == "0x03"* ]] || continue
if [[ $(<"$_omarchy_pci/vendor") == "0x10de" ]]; then
_omarchy_nvidia_gpu=1
else
_omarchy_other_gpu=1
fi
done
if ((_omarchy_nvidia_gpu && !_omarchy_other_gpu)); then
_omarchy_hooks=()
for _omarchy_hook in "${HOOKS[@]}"; do
[[ $_omarchy_hook == "kms" ]] || _omarchy_hooks+=("$_omarchy_hook")
done
HOOKS=("${_omarchy_hooks[@]}")
fi
unset _omarchy_nvidia_gpu _omarchy_other_gpu _omarchy_pci _omarchy_hooks _omarchy_hook
fi
# Bundle vconsole.conf so Plymouth uses the configured keyboard layout at the
# LUKS prompt, but only when that layout types Latin letters. Passphrases are
# Latin characters, so bundling a Hebrew/Greek/Cyrillic/Arabic layout would
# make the correct passphrase untypeable and lock the user out.
if [[ -f /etc/vconsole.conf ]]; then
case $(. /etc/vconsole.conf && echo "${XKBLAYOUT%%,*}") in
af | am | ara | bd | bg | by | et | ge | gr | il | in | iq | ir | kg | kh | kz | la | lk | mk | mm | mn | mv | np | rs | ru | sy | th | tj | ua) ;;
*) FILES+=(/etc/vconsole.conf) ;;
esac
fi
+12 -3
View File
@@ -305,7 +305,13 @@ esac
def test_packaging_installs_hooks_and_helpers(self):
import shutil
for app, version in (("omawake", "0.0.3"), ("omaspeak", "0.0.3")):
for app in ("omawake", "omaspeak"):
directory = ROOT / f"pkgbuilds/{app}-bin"
version = next(
line.removeprefix("pkgver=")
for line in (directory / "PKGBUILD").read_text().splitlines()
if line.startswith("pkgver=")
)
source = self.root / app / "src"
package = self.root / app / "pkg"
release = source / f"{app}-{version}-linux-x86_64"
@@ -317,7 +323,6 @@ esac
target = release / path
target.parent.mkdir(parents=True, exist_ok=True)
target.write_text("fixture")
directory = ROOT / f"pkgbuilds/{app}-bin"
for name in ("package-remove", "remove-user-services.hook"):
shutil.copyfile(directory / name, source / name)
env = dict(self.env, srcdir=str(source), pkgdir=str(package), CARCH="x86_64")
@@ -338,7 +343,11 @@ esac
self.assertIn("When = PreTransaction", hook)
self.assertIn("AbortOnFail", hook)
self.assertIn(f"Exec = /usr/lib/{app}/package-remove {app}", hook)
self.assertIn("pkgrel=4", (directory / "PKGBUILD").read_text())
release = next(
line for line in (directory / "PKGBUILD").read_text().splitlines()
if line.startswith("pkgrel=")
)
self.assertGreaterEqual(int(release.removeprefix("pkgrel=")), 1)
scripts.append((directory / "package-remove").read_bytes())
self.assertEqual(*scripts)
+134
View File
@@ -186,6 +186,15 @@ test('a delayed tests workflow is also awaited', async () => {
assert.deepEqual(state.approved, [1, 2]);
});
test('a lone build left pending behind an older in-flight build does not hold back the tests', async () => {
// Sync branches queue rather than cancel, so an approved build can stay
// queued for hours. Only a newer held build needs to wait for it to start.
const { state, invoke } = fixture([run(1, BUILD), run(2, TESTS)], { queueUntil: Infinity });
await invoke();
assert.deepEqual(state.approved, [1, 2]);
assert.deepEqual(state.transitions, []);
});
test('reopening a labeled PR waits for its new tests, even if old tests passed at the same SHA', async () => {
const { state, invoke } = fixture([
run(1, TESTS, { created_at: earlier, conclusion: 'success' }), run(2, BUILD),
@@ -312,3 +321,128 @@ for (const [name, overrides] of [
assert.doesNotMatch(result.stdout, /::notice::Awaiting maintainer build approval/);
});
}
// A push to a sync branch must not cancel that PR's multi-hour build; any
// other PR still cancels its superseded build.
test('only same-repository sync branches queue behind an in-flight build', () => {
const expression = workflow.match(/^ cancel-in-progress: \$\{\{(.*)\}\}$/m)[1];
const cancels = (repo, ref) => new Function('github', 'startsWith', `return (${expression})`)(
{ repository: 'omacom/omarchy-pkgs', head_ref: ref,
event: { pull_request: { head: { repo: { full_name: repo } } } } },
(text, prefix) => text.startsWith(prefix));
assert.equal(cancels('omacom/omarchy-pkgs', 'auto/sync-upstream'), false);
assert.equal(cancels('omacom/omarchy-pkgs', 'auto/sync-upstream-ttfx'), false);
assert.equal(cancels('omacom/omarchy-pkgs', 'auto/sync-rebuilds'), false);
assert.equal(cancels('omacom/omarchy-pkgs', 'ttfx/fix'), true);
assert.equal(cancels('someone/omarchy-pkgs', 'auto/sync-upstream'), true);
assert.equal(cancels(undefined, ''), true); // workflow_dispatch
});
// The sync workflows release their own GITHUB_TOKEN pushes: GitHub creates
// no pull_request_target run for those, so approve-pr.yml never runs.
const approveSyncPush = require('../.github/scripts/approve-sync-push.cjs');
function syncFixture(options = {}) {
const f = fixture([run(1, BUILD, { head_branch: 'auto/sync-upstream' }),
run(2, TESTS, { head_branch: 'auto/sync-upstream' })], options);
Object.assign(f.state.pr, {
user: { login: 'github-actions[bot]' },
head: { ...f.state.pr.head, ref: 'auto/sync-upstream', repo: { id: 42, full_name: 'omacom/omarchy-pkgs' } },
base: { repo: { full_name: 'omacom/omarchy-pkgs' } },
});
const push = overrides => approveSyncPush({
github: f.github, context: { repo: { owner: 'omacom', repo: 'omarchy-pkgs' }, payload: {} },
core: { info() {} }, number: 390, branch: 'auto/sync-upstream', headSha: pr.head.sha,
since: earlier, attempts: 6, sleep: async () => {}, ...overrides,
});
return { ...f, push };
}
test('a labelled sync PR has its bot push released', async () => {
const { state, push } = syncFixture();
await push();
assert.deepEqual(state.approved, [1, 2]);
});
test('an unlabelled sync PR stays held for a maintainer', async () => {
const { state, push } = syncFixture();
state.pr.labels = [];
await push();
assert.deepEqual(state.approved, []);
});
test('runs older than the push are not taken for this push', async () => {
const { state, push } = syncFixture();
await assert.rejects(push({ since: '2026-09-19T03:00:00Z' }), /Timed out/);
assert.deepEqual(state.approved, []);
});
for (const [name, change] of [
['a contributor PR', current => { current.user.login = 'someone'; }],
['a fork PR', current => { current.head.repo.full_name = 'someone/omarchy-pkgs'; }],
['another branch', current => { current.head.ref = 'auto/sync-rebuilds'; }],
]) {
test(`the sync approver refuses ${name}, even when labelled`, async () => {
const { state, push } = syncFixture();
change(state.pr);
await assert.rejects(push(), /refusing to approve/);
assert.deepEqual(state.approved, []);
});
}
for (const [name, change] of [
['closed', current => { current.state = 'closed'; }],
['moved on', current => { current.head.sha = 'newer-sha'; }],
]) {
test(`a sync PR that has ${name} is left alone`, async () => {
const { state, push } = syncFixture();
change(state.pr);
await push();
assert.deepEqual(state.approved, []);
});
}
test('the sync approver needs the push it is approving for', async () => {
const { state, push } = syncFixture();
for (const missing of [{ number: NaN }, { headSha: '' }, { since: '' }, { branch: '' }]) {
await assert.rejects(push(missing), /Missing sync PR/);
}
assert.deepEqual(state.approved, []);
});
// A scoped dispatch must not push to the shared branch: it would replace the
// other pending updates in the open sync PR with just the named packages.
const branchScript = join(__dirname, '../.github/scripts/sync-pr-branch.sh');
const branchFor = (...names) => Object.fromEntries(execFileSync(branchScript,
['auto/sync-upstream', ...names], { encoding: 'utf8' })
.trim().split('\n').map(line => line.split(/=(.*)/s).slice(0, 2)));
test('scheduled runs keep the shared branch; scoped runs get their own', () => {
assert.deepEqual(branchFor(), { branch: 'auto/sync-upstream', scope: '' });
assert.deepEqual(branchFor('ttfx'), { branch: 'auto/sync-upstream-ttfx', scope: 'ttfx' });
assert.deepEqual(branchFor('ttfx', 'strata', 'ttfx'),
{ branch: 'auto/sync-upstream-strata-ttfx', scope: 'strata ttfx' });
assert.equal(branchFor('python-foo.bar').branch, 'auto/sync-upstream-python-foo-bar');
const names = ['a-very-long-package-name-one', 'another-very-long-package-name-two'];
const long = branchFor(...names, 'third');
assert.ok(long.branch.length <= 'auto/sync-upstream-'.length + 60);
assert.notEqual(long.branch, branchFor(...names).branch);
});
test('scoped branch names reject anything that is not a package name', () => {
for (const name of ['../x', 'A', 'x y', 'a@{b', '-x', '.x', 'x;true']) {
assert.equal(spawnSync(branchScript, ['auto/sync-upstream', name]).status, 1, name);
}
});
test('sync workflows push scoped runs aside and keep actions: write out of the sync job', () => {
for (const file of ['sync-upstream.yml', 'sync-rebuilds.yml']) {
const text = readFileSync(join(__dirname, '../.github/workflows', file), 'utf8');
const sync = text.slice(text.indexOf('\n sync:\n'), text.indexOf('\n approve:\n'));
const approveJob = text.slice(text.indexOf('\n approve:\n'));
assert.match(sync, /sync-pr-branch\.sh auto\/sync-[\w-]+ "\$\{package_args\[@\]\}"/, file);
assert.match(sync, /branch: \$\{\{ steps\.branch\.outputs\.branch \}\}/, file);
assert.doesNotMatch(sync, /^ +actions: write$/m, file);
assert.match(approveJob, /^ actions: write$/m, file);
assert.match(approveJob, /needs\.sync\.outputs\.operation == 'updated'/, file);
}
});
+352
View File
@@ -0,0 +1,352 @@
#!/bin/bash
# Exercise the real package functions with a minimal, synthetic runtime tree.
set -euo pipefail
BUILD_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
scratch=$(mktemp -d)
trap 'rm -rf "$scratch"' EXIT
fixture=$scratch/src/omarchy
files=(
config/autostart/limine-snapper-notify.desktop
etc/fastfetch/config.jsonc
etc/mkinitcpio.conf.d/omarchy_hooks.conf
etc/mkinitcpio.conf.d/thunderbolt_module.conf
etc/limine-entry-tool.d/omarchy-defaults.conf
etc/limine-entry-tool.d/omarchy-uki.conf
etc/security/faillock.conf
etc/nsswitch.conf
etc/cups/cups-browsed.conf
etc/cups/cups-files.conf
etc/plymouth/plymouthd.conf
etc/sysctl.d/99-omarchy-sysctl.conf
default/uwsm/env.d/10-omarchy
default/environment.d/10-omarchy-fcitx.conf
default/fontconfig/conf.avail/50-omarchy.conf
default/xdg-terminal-exec/hyprland-xdg-terminals.list
default/applications/mimeapps.list
default/systemd/user/bt-agent.service
default/systemd/user/omarchy-sleep-lock.service
default/systemd/user/omarchy-recover-internal-monitor.service
default/systemd/user/omarchy-migrate-notify.service
default/systemd/user/omarchy-tailscale-receive.service
default/systemd/user/omarchy-fcitx5.service
default/systemd/user/omarchy-crash-watch.service
default/systemd/user/app.slice.d/10-oomd.conf
default/systemd/zram-generator.conf.d/90-omarchy.conf
default/systemd/system/plocate-updatedb.service.d/10-omarchy.conf
default/systemd/system-sleep/unmount-fuse
default/bashrc
default/limine/default.conf
default/limine/limine.conf
default/snapper/root
default/sddm/omarchy/Main.qml
default/sddm/hyprland.lua
default/wayland-sessions/omarchy.desktop
default/plymouth/omarchy.plymouth
default/fonts/omarchy/omarchy.ttf
default/hypr/toggles/flags.lua
default/nautilus-python/extensions/localsend.py
default/nautilus-python/extensions/transcode.py
default/tensaku/state.toml
applications/example.desktop
bin/omarchy-upload-log
bin/omarchy-debug
bin/omarchy-debug-idle
logo.txt
logo.svg
icon.txt
icon.png
)
for path in "${files[@]}"; do
mkdir -p "$(dirname "$fixture/$path")"
printf 'fixture for %s\n' "$path" > "$fixture/$path"
done
fixtures=$BUILD_ROOT/tests/fixtures/settings-boot
# Omarchy's HOOKS line, as v4.0.4 ships it (omarchy_hooks-v4.0.4.conf).
omarchy_hooks='base udev plymouth keyboard autodetect microcode modconf kms keymap consolefont block encrypt filesystems fsck btrfs-overlayfs'
cp "$fixtures/omarchy_hooks-v4.0.4.conf" "$fixture/etc/mkinitcpio.conf.d/omarchy_hooks.conf"
for recipe in omarchy-settings omarchy-settings-dev; do
for target_arch in aarch64 x86_64; do
(
export CARCH=$target_arch OMARCHY_SRC=$fixture
export srcdir=$scratch/src pkgdir=$scratch/$recipe-$target_arch
backup=()
# shellcheck disable=SC1090 # Exercise each recipe's actual package function.
source "$BUILD_ROOT/pkgbuilds/$recipe/PKGBUILD"
package
for path in etc/mkinitcpio.conf.d/omarchy_hooks.conf \
etc/limine-entry-tool.d/omarchy-defaults.conf \
etc/limine-entry-tool.d/omarchy-uki.conf; do
printf '%s\n' "${backup[@]}" | grep -Fxq "$path"
done
for path in etc/limine-entry-tool.d/omarchy-defaults.conf etc/limine-entry-tool.d/omarchy-uki.conf; do
cmp "$fixture/$path" "$pkgdir/$path"
done
hooks_conf=etc/mkinitcpio.conf.d/omarchy_hooks.conf
if [[ $CARCH == aarch64 ]]; then
grep -Fxq 'if [[ " ${HOOKS[*]:-} " != *" asahi "* ]]; then' "$pkgdir/$hooks_conf"
bash -n "$pkgdir/$hooks_conf"
else
cmp "$fixture/$hooks_conf" "$pkgdir/$hooks_conf"
fi
for template in default.conf limine.conf; do
cmp "$fixture/default/limine/$template" "$pkgdir/usr/share/omarchy/default/limine/$template"
done
if printf '%s\n' "${backup[@]}" | grep -Fxq etc/mkinitcpio.conf.d/00-omarchy-hooks.conf; then
echo 'FAIL: backup names a 00-omarchy-hooks.conf the source does not ship' >&2
exit 1
fi
# The installer owns the machine-specific live configuration.
[[ ! -e $pkgdir/etc/default/limine ]]
if printf '%s\n' "${backup[@]}" | grep -Fxq 'etc/default/limine'; then
echo 'FAIL: installer-owned Limine configuration is in backup metadata' >&2
exit 1
fi
cmp "$fixture/config/autostart/limine-snapper-notify.desktop" \
"$pkgdir/etc/skel/.config/autostart/limine-snapper-notify.desktop"
cmp "$fixture/config/autostart/limine-snapper-notify.desktop" \
"$pkgdir/usr/share/omarchy/config/autostart/limine-snapper-notify.desktop"
thunderbolt=etc/mkinitcpio.conf.d/thunderbolt_module.conf
if [[ $CARCH == aarch64 ]]; then
[[ ! -e $pkgdir/$thunderbolt ]]
if printf '%s\n' "${backup[@]}" | grep -Fxq "$thunderbolt"; then
echo 'FAIL: removed ARM Thunderbolt config remains in backup metadata' >&2
exit 1
fi
else
cmp "$fixture/$thunderbolt" "$pkgdir/$thunderbolt"
printf '%s\n' "${backup[@]}" | grep -Fxq "$thunderbolt"
fi
echo "PASS: $recipe $CARCH retains boot configuration and matching backup metadata"
)
done
done
# The aarch64 packages also reach Apple Silicon Macs, whose initramfs needs the
# asahi hook. Source mkinitcpio.conf and the drop-ins in mkinitcpio's order and
# compare the resulting HOOKS for each kind of aarch64 install. Aurora Macs use
# omarchy-mac-boot's real 90-94 fragments (omacom/omarchy-mac ff7ce0d4d).
package_aarch64() {
local recipe=$1 source_tree=$2 out=$3
(
# package() builds from $srcdir/omarchy.
export CARCH=aarch64 OMARCHY_SRC=$source_tree srcdir=${source_tree%/omarchy} pkgdir=$out
backup=()
# shellcheck disable=SC1090 # Exercise the recipe's actual package function.
source "$BUILD_ROOT/pkgbuilds/$recipe/PKGBUILD"
package || exit 1
printf '%s\n' "${backup[@]}" > "$out.backup"
)
}
# omacom/omarchy#13362 asks omarchy-hw-platform which machine it is on.
for platform in apple-silicon qualcomm generic-aarch64; do
mkdir -p "$scratch/detector-$platform"
printf '#!/bin/sh\necho %s\n' "$platform" > "$scratch/detector-$platform/omarchy-hw-platform"
chmod +x "$scratch/detector-$platform/omarchy-hw-platform"
done
# effective_hooks ROOT [PLATFORM]
effective_hooks() {
local root=$1 platform=${2:-}
(
LC_ALL=C
[[ -z $platform ]] || PATH=$scratch/detector-$platform:$PATH
HOOKS=() MODULES=() FILES=()
# shellcheck disable=SC1091
source "$root/mkinitcpio.conf"
shopt -s nullglob
for conf in "$root"/mkinitcpio.conf.d/*.conf; do
# shellcheck disable=SC1090
source "$conf"
done
echo "${HOOKS[*]}"
)
}
# machine NAME MKINITCPIO_HOOKS PACKAGED_ETC [mac-boot]
machine() {
local root=$scratch/machines/$1
rm -rf "$root"
mkdir -p "$root/mkinitcpio.conf.d"
printf 'HOOKS=(%s)\n' "$2" > "$root/mkinitcpio.conf"
[[ -z $3 ]] || cp "$3"/*.conf "$root/mkinitcpio.conf.d/"
[[ ${4:-} != mac-boot ]] || cp "$fixtures"/omarchy-mac-boot/*.conf "$root/mkinitcpio.conf.d/"
printf '%s\n' "$root"
}
expect() {
local layout=$1 what=$2 got=$3 want=$4
[[ $got == "$want" ]] || { echo "FAIL: $layout: $what gets '$got', want '$want'" >&2; exit 1; }
}
arch_default='base udev autodetect microcode modconf kms keyboard keymap consolefont block filesystems fsck'
snapdragon='base systemd autodetect microcode modconf kms keyboard sd-vconsole block filesystems fsck'
legacy_mac='base udev autodetect modconf kms keyboard keymap consolefont block asahi encrypt filesystems fsck'
# Macs must come out exactly as they would without omarchy-settings' drop-ins.
check_macs() {
local layout=$1 packaged=$2 base
for base in "$arch_default" "$snapdragon"; do
expect "$layout" "an Aurora Mac" \
"$(effective_hooks "$(machine aurora "$base" "$packaged" mac-boot)")" \
"$(effective_hooks "$(machine aurora-bare "$base" "" mac-boot)")"
done
expect "$layout" "a legacy GRUB Mac" \
"$(effective_hooks "$(machine legacy "$legacy_mac" "$packaged")")" "$legacy_mac"
expect "$layout" "a legacy GRUB Mac with the Apple fragments" \
"$(effective_hooks "$(machine legacy-boot "$legacy_mac" "$packaged" mac-boot)")" \
"$(effective_hooks "$(machine legacy-boot-bare "$legacy_mac" "" mac-boot)")"
}
layout="HOOKS in omarchy_hooks.conf (v4.0.4)"
packaged=$scratch/omarchy-settings-aarch64/etc/mkinitcpio.conf.d
expect "$layout" Snapdragon "$(effective_hooks "$(machine snapdragon "$snapdragon" "$packaged")")" "$omarchy_hooks"
expect "$layout" "the DGX Spark" "$(effective_hooks "$(machine spark "$arch_default" "$packaged")")" "$omarchy_hooks"
check_macs "$layout" "$packaged"
echo "PASS: $layout: Snapdragon and the Spark get Omarchy's hooks; Macs keep theirs"
# omacom/omarchy#13362 decides per platform in 00-omarchy-hooks.conf; the
# package ships both of its files unchanged.
split=$scratch/split/omarchy
mkdir -p "$scratch/split"
cp -a "$fixture" "$split"
cp "$fixtures"/omarchy-13362/*.conf "$split/etc/mkinitcpio.conf.d/"
# Its 00-omarchy-hooks.conf asks the detector copy the platform guard ships.
for path in default/libalpm/hooks/00-omarchy-platform-guard.hook \
default/libalpm/scripts/omarchy-platform-guard bin/omarchy-hw-platform; do
mkdir -p "$(dirname "$split/$path")"
printf 'fixture for %s\n' "$path" > "$split/$path"
done
for recipe in omarchy-settings omarchy-settings-dev; do
package_aarch64 "$recipe" "$split" "$scratch/split-$recipe" >/dev/null
for conf in 00-omarchy-hooks.conf omarchy_hooks.conf; do
cmp "$fixtures/omarchy-13362/$conf" "$scratch/split-$recipe/etc/mkinitcpio.conf.d/$conf"
done
grep -Fxq etc/mkinitcpio.conf.d/00-omarchy-hooks.conf "$scratch/split-$recipe.backup"
[[ -x $scratch/split-$recipe/usr/share/libalpm/scripts/omarchy-hw-platform ]]
done
layout="omacom/omarchy#13362 (00-omarchy-hooks.conf)"
packaged=$scratch/split-omarchy-settings/etc/mkinitcpio.conf.d
for platform in "" qualcomm generic-aarch64; do
expect "$layout" "Snapdragon (${platform:-no detector})" \
"$(effective_hooks "$(machine snapdragon "$snapdragon" "$packaged")" "$platform")" "$omarchy_hooks"
expect "$layout" "the DGX Spark (${platform:-no detector})" \
"$(effective_hooks "$(machine spark "$arch_default" "$packaged")" "$platform")" "$omarchy_hooks"
done
expect "$layout" "a legacy GRUB Mac" \
"$(effective_hooks "$(machine legacy "$legacy_mac" "$packaged")" apple-silicon)" "$legacy_mac"
# An Aurora Mac builds on the systemd baseline and unlocks with sd-encrypt.
hooks=" $(effective_hooks "$(machine aurora "$arch_default" "$packaged" mac-boot)" apple-silicon) "
for hook in systemd asahi omarchy-vendorfw omarchy-mac-encrypt sd-encrypt; do
[[ $hooks == *" $hook "* ]] || { echo "FAIL: $layout: an Aurora Mac lacks $hook:$hooks" >&2; exit 1; }
done
for hook in udev encrypt; do
[[ $hooks != *" $hook "* ]] || { echo "FAIL: $layout: an Aurora Mac keeps $hook:$hooks" >&2; exit 1; }
done
echo "PASS: $layout: shipped unchanged and backed up; Snapdragon and the Spark get Omarchy's hooks; Macs keep theirs"
# Sources the recipe cannot make safe for Macs stop the aarch64 build, each
# with its own reason.
refuse() {
local what=$1 reason=$2 conf=$3 body=$4 bad=$scratch/bad/omarchy
rm -rf "$scratch/bad" "$scratch/bad-package"
mkdir -p "$scratch/bad"
cp -a "$fixture" "$bad"
rm -f "$bad"/etc/mkinitcpio.conf.d/{00-omarchy-hooks,omarchy_hooks}.conf
[[ -z $conf ]] || printf '%s\n' "$body" > "$bad/etc/mkinitcpio.conf.d/$conf"
if package_aarch64 omarchy-settings "$bad" "$scratch/bad-package" 2>"$scratch/bad.err"; then
echo "FAIL: the aarch64 package builds with $what" >&2
exit 1
fi
grep -Fq "$reason" "$scratch/bad.err" ||
{ echo "FAIL: $what stops the build for another reason: $(cat "$scratch/bad.err")" >&2; exit 1; }
echo "PASS: the aarch64 package refuses $what"
}
unsafe="must keep a Mac's asahi line"
unguardable="cannot guard this HOOKS= line"
refuse "no hooks file" "$unsafe" "" ""
refuse "a hooks file that sets no HOOKS" "$unsafe" omarchy_hooks.conf 'FILES+=(/etc/vconsole.conf)'
refuse "a HOOKS line with a trailing comment" "$unguardable" omarchy_hooks.conf "HOOKS=($omarchy_hooks) # local"
refuse "a HOOKS line split over lines" "$unguardable" omarchy_hooks.conf "HOOKS=(base udev"$'\n'" block encrypt filesystems)"
refuse "an indented HOOKS that ignores asahi" "$unsafe" 00-omarchy-hooks.conf "if true; then"$'\n'" HOOKS=($omarchy_hooks)"$'\n'"fi"
refuse "#13362's hooks without the platform detector" "needs the omarchy-hw-platform copy" \
00-omarchy-hooks.conf "$(cat "$fixtures/omarchy-13362/00-omarchy-hooks.conf")"
# Upgrades: pacman replaces an unmodified hooks file, keeps a modified one and
# leaves the guarded version as .pacnew, and installs it where it was absent.
# A file restored by hand after the stripped package (as the Spark and Surface
# owners did) is adopted: it stays in place and the guarded one is .pacnew.
if ((EUID != 0)) || ! command -v pacman >/dev/null; then
echo "SKIP: pacman upgrade checks need root"
exit 0
fi
unguarded=$fixture/etc/mkinitcpio.conf.d/omarchy_hooks.conf
guarded=$scratch/omarchy-settings-aarch64/etc/mkinitcpio.conf.d/omarchy_hooks.conf
printf '[options]\nArchitecture = auto\nSigLevel = Never\nLocalFileSigLevel = Never\n' > "$scratch/pacman.conf"
make_pkg() {
local ver=$1 hooks=${2:-} dir=$scratch/pkg-$1
mkdir -p "$dir/etc/mkinitcpio.conf.d"
[[ -z $hooks ]] || cp "$hooks" "$dir/etc/mkinitcpio.conf.d/omarchy_hooks.conf"
cat > "$dir/.PKGINFO" <<EOF
pkgname = omarchy-settings-upgrade-test
pkgbase = omarchy-settings-upgrade-test
pkgver = $ver
pkgdesc = omarchy-settings upgrade test
arch = any
size = 1
backup = etc/mkinitcpio.conf.d/omarchy_hooks.conf
EOF
(cd "$dir" && bsdtar -cf "$scratch/upgrade-test-$ver-any.pkg.tar" .PKGINFO etc)
printf '%s\n' "$scratch/upgrade-test-$ver-any.pkg.tar"
}
pacman_in() {
local root=$1
shift
mkdir -p "$root/var/lib/pacman" "$root/cache"
pacman --root "$root" --dbpath "$root/var/lib/pacman" --cachedir "$root/cache" \
--config "$scratch/pacman.conf" --logfile /dev/null --noconfirm --nodeps --noscriptlet "$@" >/dev/null
}
stripped=$(make_pkg 1-1)
old=$(make_pkg 2-1 "$unguarded")
new=$(make_pkg 3-1 "$guarded")
installed=etc/mkinitcpio.conf.d/omarchy_hooks.conf
pacman_in "$scratch/unchanged" -U "$old"
pacman_in "$scratch/unchanged" -U "$new"
cmp "$guarded" "$scratch/unchanged/$installed"
[[ ! -e $scratch/unchanged/$installed.pacnew ]]
pacman_in "$scratch/modified" -U "$old"
echo '# local change' >> "$scratch/modified/$installed"
pacman_in "$scratch/modified" -U "$new"
grep -Fxq '# local change' "$scratch/modified/$installed"
cmp "$guarded" "$scratch/modified/$installed.pacnew"
pacman_in "$scratch/absent" -U "$stripped"
pacman_in "$scratch/absent" -U "$new"
cmp "$guarded" "$scratch/absent/$installed"
pacman_in "$scratch/restored" -U "$stripped"
mkdir -p "$scratch/restored/etc/mkinitcpio.conf.d"
cp "$unguarded" "$scratch/restored/$installed"
pacman_in "$scratch/restored" -U "$new"
cmp "$unguarded" "$scratch/restored/$installed"
cmp "$guarded" "$scratch/restored/$installed.pacnew"
# Source what the upgrades installed.
for upgrade in unchanged absent; do
etc=$scratch/$upgrade/etc/mkinitcpio.conf.d
expect "$upgrade upgrade" Snapdragon "$(effective_hooks "$(machine "$upgrade-snapdragon" "$snapdragon" "$etc")")" "$omarchy_hooks"
check_macs "$upgrade upgrade" "$etc"
done
echo "PASS: pacman upgrades install the guarded hooks file and keep local changes"