From f6b9267b3b50277847259bbd713dbc5d0fc29899 Mon Sep 17 00:00:00 2001 From: Spencer Bull Date: Fri, 2 Oct 2026 21:21:37 -0500 Subject: [PATCH] Ship OpenClaw as the seed for a self-updating copy under ~/.openclaw (#651) A copy under /usr/lib/node_modules belongs to pacman, and upstream's updater refuses to write there, so neither `openclaw update` nor the Control UI's Update Gateway worked. The package now carries the release instead: the sha256-pinned npm tarball and the install-cli.sh that came in it, from which Omarchy seeds a copy under ~/.openclaw that updates itself. --- pkgbuilds/openclaw/PKGBUILD | 53 +++++++++-------------------- pkgbuilds/openclaw/openclaw.install | 20 +++++------ 2 files changed, 26 insertions(+), 47 deletions(-) diff --git a/pkgbuilds/openclaw/PKGBUILD b/pkgbuilds/openclaw/PKGBUILD index 95bc70e..b40338e 100644 --- a/pkgbuilds/openclaw/PKGBUILD +++ b/pkgbuilds/openclaw/PKGBUILD @@ -5,20 +5,26 @@ # Contributor: Wuxxin # Followed here straight from the npm registry (see .omarchy/package.json), since # upstream's release cadence outruns the AUR. +# +# This is the release Omarchy ships, not the OpenClaw that runs: a copy in /usr +# belongs to pacman, and `openclaw update` refuses to write there. +# omarchy-install-openclaw-cli seeds a copy under ~/.openclaw from this tarball +# with the installer that came in it, and that copy updates itself. pkgname=openclaw pkgver=2026.9.6 -pkgrel=1 +pkgrel=2 pkgdesc='Multi-channel AI gateway with extensible messaging integrations' arch=(x86_64 aarch64) url=https://github.com/openclaw/openclaw license=(MIT) -depends=('nodejs>=22') -makedepends=(npm) +# The installer brings its own Node, and git is the one thing it would +# otherwise try to install with sudo. +depends=(bash curl git) optdepends=( + 'omarchy: sets up the self-updating OpenClaw under ~/.openclaw' '1password-cli: 1password skill' - 'curl: weather, openai-whisper-api skills' 'ffmpeg: video-frames skill' 'github-cli: github, gh-issues skills' 'jq: session-logs, trello skills' @@ -35,38 +41,11 @@ install=$pkgname.install noextract=($pkgname-$pkgver.tgz) package() { - export SHARP_IGNORE_GLOBAL_LIBVIPS=1 - # npm 12 blocks install-time lifecycle scripts unless the package is - # allow-listed, and for a local tarball the allow-list key is the tarball's - # own file: spec, not the package name (arborist matches node.resolved). - # Upstream's postinstall prunes stale dist files and clears the - # .openclaw-lifecycle-pending marker the tarball ships with; without it, - # every openclaw invocation tries to finish that lifecycle itself and dies - # with EACCES on the root-owned install. - # That postinstall also migrates legacy state under whatever home it sees - # (pruning plugin-runtime-deps in ~/.openclaw and friends), so it gets a - # scratch home: a maintainer's own OpenClaw is not the build's to touch. - mkdir -p "$srcdir"/home - env -u OPENCLAW_HOME -u OPENCLAW_STATE_DIR -u OPENCLAW_CONFIG_PATH HOME="$srcdir"/home \ - npm install --silent --global --cache "$srcdir"/npm-cache \ - --allow-scripts="file:$srcdir/$pkgname-$pkgver.tgz" \ - --prefix "$pkgdir"/usr "$srcdir"/$pkgname-$pkgver.tgz - if [[ -e "$pkgdir"/usr/lib/node_modules/$pkgname/.openclaw-lifecycle-pending ]]; then - error "openclaw's postinstall did not run; the package would fail on first use" - return 1 - fi + install -Dm644 "$srcdir"/$pkgname-$pkgver.tgz "$pkgdir"/usr/share/$pkgname/$pkgname.tgz - cat > $pkgname <<'EOF' -#!/bin/sh -export SHARP_IGNORE_GLOBAL_LIBVIPS=1 -exec node /usr/lib/node_modules/openclaw/openclaw.mjs "$@" -EOF - install -Dm755 -t "$pkgdir"/usr/bin $pkgname - - cd "$pkgdir"/usr/lib/node_modules/$pkgname - install -Dm644 -t "$pkgdir"/usr/share/licenses/$pkgname LICENSE - install -Dm644 -t "$pkgdir"/usr/share/doc/$pkgname README.md CHANGELOG.md - for f in docs/* - do ln -s /usr/lib/node_modules/$pkgname/"$f" "$pkgdir"/usr/share/doc/$pkgname/ - done + bsdtar -xf "$srcdir"/$pkgname-$pkgver.tgz -C "$srcdir" \ + package/scripts/install-cli.sh package/dist/control-ui/apple-touch-icon.png package/LICENSE + install -Dm644 "$srcdir"/package/scripts/install-cli.sh "$pkgdir"/usr/share/$pkgname/install-cli.sh + install -Dm644 "$srcdir"/package/dist/control-ui/apple-touch-icon.png "$pkgdir"/usr/share/$pkgname/$pkgname.png + install -Dm644 -t "$pkgdir"/usr/share/licenses/$pkgname "$srcdir"/package/LICENSE } diff --git a/pkgbuilds/openclaw/openclaw.install b/pkgbuilds/openclaw/openclaw.install index dccd8c6..8f69058 100644 --- a/pkgbuilds/openclaw/openclaw.install +++ b/pkgbuilds/openclaw/openclaw.install @@ -1,17 +1,17 @@ post_install() { printf "%s\n" \ - "==> Install gateway service: openclaw gateway install --force" \ - "==> Perform onboarding once: openclaw onboard" + "==> This is the release a self-updating OpenClaw starts from." \ + "==> Set it up under ~/.openclaw: omarchy-install-openclaw-cli --now" } post_upgrade() { - # The gateway runs as a systemd user unit (openclaw-gateway.service in - # ~/.config/systemd/user), which a root pacman hook has no session bus - # to reach, so it cannot be restarted from here and keeps running the - # old code until the user restarts it. + # Earlier releases of this package were OpenClaw itself, under + # /usr/lib/node_modules/openclaw, and which of those a machine is leaving + # cannot be told from the version alone, since the upstream sync moves it. + # A root pacman hook has no session bus to move a user's OpenClaw, so + # Omarchy's migration does, and this says what happens either way. printf "%s\n" \ - "==> Restart the gateway to apply updates:" \ - " openclaw gateway restart" \ - "==> Run doctor to migrate configs, check gateway health, etc.:" \ - " openclaw doctor" + "==> OpenClaw runs from ~/.openclaw and updates itself: openclaw update" \ + "==> This package only sets the release new installs start from;" \ + " omarchy update moves an OpenClaw still running from /usr there." }