Add cua-driver-bin, the Cua computer-use driver, to the fast ring

cua-driver ships prebuilt from the trycua/cua monorepo release feed. The
declarative github provider reads a release feed as a single product and
trips on the monorepo's foreign and hyphenated tags, so a bespoke
.omarchy/upstream.sh selects the newest stable cua-driver-rs release by
tag shape (upstream flags every driver release prerelease; nightlies are
distinguished by tag prefix instead) and reads its checksums.txt manifest.

The vendor tree stays together under /usr/lib/cua-driver with a /usr/bin
symlink, matching upstream's own layout: the CLI resolves its cursor-theme
compiler as a sibling of /proc/self/exe. Verified by installing the built
package into a clean archlinux:base container and exercising the CLI.
This commit is contained in:
Spencer Bull committed 2026-09-04 16:52:37 -05:00
1 parent 99234a4fbb
commit d9127d7124
4 files changed
+177

No files matched your search

@@ -0,0 +1,5 @@
{
"source": "local",
"release_ring": "fast",
"min_release_age": "24h"
}
@@ -0,0 +1,90 @@
#!/bin/bash
# cua-driver ships from the trycua/cua monorepo, whose single release feed
# interleaves many products (cua-driver-rs-v*, fleet-v*, sandbox-v*, and
# nightly-* builds). The declarative github provider reads a feed as one
# product and stops on the first foreign tag, so this hook selects the newest
# stable cua-driver-rs release itself and reads its checksums.txt manifest.
set -euo pipefail
REPO="trycua/cua"
TAG_PREFIX="cua-driver-rs-v"
releases=$(curl -fsSL "https://api.github.com/repos/$REPO/releases?per_page=100")
min_age="${MIN_RELEASE_AGE_SECONDS:-0}"
now=$(date +%s)
candidates=0
best_pkgver="" best_tag="" best_published=""
while IFS=$'\t' read -r tag published_at; do
[[ "$tag" == "$TAG_PREFIX"* ]] || continue
pkgver=${tag#"$TAG_PREFIX"}
# Upstream marks every driver release "prerelease" so the monorepo's
# "latest" can point at another product; stability lives in the tag shape
# instead. Stable driver versions are plain dotted numbers -- nightlies
# carry a nightly- tag prefix and a -nightly.N version suffix, and both
# fall out here.
[[ "$pkgver" =~ ^[0-9]+(\.[0-9]+)*$ ]] || continue
# Strict ISO 8601 before GNU date sees it, matching bin/sync-upstream's
# backstop: date alone also accepts relative expressions, which would let a
# malformed feed fabricate an age instead of failing closed.
if [[ ! "$published_at" =~ ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}(\.[0-9]+)?(Z|[+-][0-9]{2}:?[0-9]{2})$ ]] \
|| ! published_epoch=$(date --date="$published_at" +%s 2>/dev/null); then
echo "$REPO release $tag has an invalid published_at: ${published_at:-<empty>}" >&2
exit 1
fi
candidates=$((candidates + 1))
if (( now - published_epoch < min_age )); then
if [[ "${BYPASS_MIN_RELEASE_AGE:-}" == "1" ]]; then
echo "Bypassing release-age gate for $REPO $tag" >&2
else
continue
fi
fi
if [[ -z "$best_pkgver" ]] || [[ "$(vercmp "$pkgver" "$best_pkgver")" -gt 0 ]]; then
best_pkgver=$pkgver
best_tag=$tag
best_published=$published_at
fi
done < <(jq -r '.[] | select(.draft | not) | [.tag_name // "", .published_at // ""] | @tsv' <<<"$releases")
# A feed page with no stable driver release at all is an anomaly worth a loud
# error; every candidate merely being inside the quarantine window is not.
if (( candidates == 0 )); then
echo "no stable $TAG_PREFIX releases in the feed for $REPO" >&2
exit 1
fi
if [[ -z "$best_tag" ]]; then
echo "every recent $TAG_PREFIX release is still inside the release-age quarantine; skipping" >&2
echo '{}'
exit 0
fi
current=$(grep -m1 '^pkgver=' PKGBUILD | cut -d= -f2- | tr -d "\"'")
if [[ -n "$current" ]] && [[ "$(vercmp "$best_pkgver" "$current")" -le 0 ]]; then
echo '{}'
exit 0
fi
checksums=$(curl -fsSL "https://github.com/$REPO/releases/download/$best_tag/checksums.txt")
sums_json='{}'
for arch in x86_64 aarch64; do
case "$arch" in
x86_64) platform="linux-x86_64" ;;
aarch64) platform="linux-arm64" ;;
esac
asset="cua-driver-rs-${best_pkgver}-${platform}.tar.gz"
sum=$(awk -v f="$asset" '$2 == f { print $1; exit }' <<<"$checksums")
if [[ ! "$sum" =~ ^[0-9a-f]{64}$ ]]; then
echo "no valid checksum for $asset in $REPO $best_tag checksums.txt" >&2
exit 1
fi
sums_json=$(jq -c --arg arch "$arch" --arg sum "$sum" '.[$arch] = [$sum]' <<<"$sums_json")
done
jq -n --arg pkgver "$best_pkgver" --arg published_at "$best_published" \
--argjson sums "$sums_json" \
'{pkgver: $pkgver, published_at: $published_at, sha256sums: $sums}'
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2025 Cua AI, Inc.
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
+61
View File
@@ -0,0 +1,61 @@
# Maintainer: Spencer Bull <spencerbull2554@gmail.com>
# cua-driver ships prebuilt from the trycua/cua monorepo release feed, so this
# repackages the vendor tarball. Upstream keeps the CLI, its cursor-theme
# compiler, and the SDK artifacts together in one directory and exposes the
# CLI through a symlink -- the binary resolves its helpers as siblings of
# /proc/self/exe -- so the whole tree lands under /usr/lib/cua-driver with a
# /usr/bin symlink. .omarchy/upstream.sh rewrites the version and checksums
# below from the release feed.
pkgname=cua-driver-bin
pkgver=0.23.2
pkgrel=1
pkgdesc="Computer-use driver for native GUI apps: accessibility-tree snapshots and input injection"
arch=('x86_64' 'aarch64')
url="https://github.com/trycua/cua"
license=('MIT')
# at-spi2-core carries the AT-SPI accessibility bus the driver reads GUI
# trees through; the X libraries are linked, not dlopen'd.
depends=(
'at-spi2-core'
'gcc-libs'
'glibc'
'libx11'
'libxcb'
'libxext'
'libxi'
'libxkbcommon'
)
provides=("cua-driver=${pkgver}")
conflicts=('cua-driver')
# Prebuilt Rust binaries ship byte-exact: their build ids are what upstream
# symbolication matches.
options=('!strip' '!debug')
source=('LICENSE')
source_x86_64=("https://github.com/trycua/cua/releases/download/cua-driver-rs-v${pkgver}/cua-driver-rs-${pkgver}-linux-x86_64.tar.gz")
source_aarch64=("https://github.com/trycua/cua/releases/download/cua-driver-rs-v${pkgver}/cua-driver-rs-${pkgver}-linux-arm64.tar.gz")
sha256sums=('c0779290c1d4783169aa3dbfb55feb505e563ef8a004bbf55298ceffcfbda8d9')
sha256sums_x86_64=('478e010d2b0426de9d8a07eb839802daa92137b33cb8affb93b991e91d76ce7e')
sha256sums_aarch64=('3ad2d6c7ca7356a08e534baa2f4ca84ad02cebb2d27caef66cb268b6df71210d')
package() {
local platform
case "${CARCH}" in
x86_64) platform="linux-x86_64" ;;
aarch64) platform="linux-arm64" ;;
esac
cd "${srcdir}/cua-driver-rs-${pkgver}-${platform}"
# The vendor tree stays together: cua-driver execs cua-cursor-theme as a
# sibling of the resolved binary, and the SDK library, node runtime, ABI
# header, and the GNOME wayland-helper extension are versioned with it.
install -d "${pkgdir}/usr/lib/cua-driver"
cp -a . "${pkgdir}/usr/lib/cua-driver/"
chmod -R a+rX "${pkgdir}/usr/lib/cua-driver"
install -d "${pkgdir}/usr/bin"
ln -s ../lib/cua-driver/cua-driver "${pkgdir}/usr/bin/cua-driver"
install -Dm644 "${srcdir}/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
}