100 Commits
Author SHA1 Message Date
Ryan HughesandGitHub 6774df1001 Merge pull request #259 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-09-01 10:38:15 -04:00
Ryan HughesandGitHub 8550bd3124 Merge pull request #258 from omacom/auto/sync-aur
chore: sync AUR packages
2026-09-01 10:38:04 -04:00
Ryan HughesandGitHub a3d150e2b0 Merge pull request #253 from omacom/add-link-studio-opr
Add Link Studio to the fast ring
2026-09-01 02:01:09 -04:00
Ryan Hughes 2fad766013 Add Link Studio to the fast ring
Package Link Studio 1.0.2 with its AUR-only MediaPipe and sounddevice dependencies. Wire Link Studio to GitHub release checksums, keep all three packages on the fast ring, and make MediaPipe's Bazel bootstrap a checksummed makepkg source.
2026-09-01 01:55:23 -04:00
Ryan HughesandGitHub c6e34f7949 Merge pull request #252 from omacom/add-omakade-opr
Add Omakade to the fast ring
2026-09-01 01:51:10 -04:00
Ryan Hughes a42235e1a5 Add Omakade to the fast ring
Build the upstream 1.2.0 source release for x86_64 and follow stable GitHub releases through the published SHA256SUMS manifest.
2026-09-01 01:25:44 -04:00
Ryan HughesandGitHub 899d5030ce Merge pull request #231 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-09-01 01:24:52 -04:00
Ryan HughesandGitHub eace5f13a9 Merge pull request #230 from omacom/auto/sync-aur
chore: sync AUR packages
2026-09-01 01:24:29 -04:00
Ryan HughesandGitHub 9995058806 Merge pull request #235 from jethrojones/add-omapresent-package
Add omapresent Markdown presentation package
2026-09-01 01:22:08 -04:00
Ryan Hughes e934aa9ee2 Mark omapresent for fast release ring 2026-09-01 01:21:34 -04:00
Ryan Hughes 28a4cfc662 Make release publication fail closed 2026-08-30 23:49:27 -04:00
Ryan Hughes 246eea9620 Fix Hermes Desktop keyring detection on Hyprland
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.
2026-08-30 23:49:02 -04:00
Ryan Hughes 4c41157163 Release omarchy 4.0.2 2026-08-30 23:22:02 -04:00
Ryan Hughes 8bfa054676 Cut the rc ISO under its numbered candidate version
cmd_rc handed maybe_iso the bare train version, so omarchy-iso-release
named every candidate omarchy-X.Y.Z-rc.iso — rc2 uploaded over rc1's
URL. Pass the pinned rcN version instead; paired with omarchy-iso's
f9be60b, the artifact becomes omarchy-4.0.2rc2.iso. The ship path
keeps passing the final version.
2026-08-30 17:15:52 -04:00
Ryan Hughes cb84ec0e69 Pin omarchy 4.0.2rc2 on master so edge carries it
Edge is the channel the 4.0.2 RC ISOs point pacman at until the rc-channel
migration lands, but edge only carried omarchy 4.0.1 — older than the
installed 4.0.2rc1, so those installs never saw an upgrade. Bumping master's
pin lets the normal edge pipeline build and publish 4.0.2rc2, whose migration
repoints [omarchy] at the rc channel.

Stable is unaffected: pinned packages never build for stable
(package_builds_for_mirror), it only receives them via the rc->stable advance
at ship time.

(cherry picked from rc-branch pin commit 11767d6)
2026-08-30 16:26:37 -04:00
Ryan Hughes 82b28bb6f3 Bust the CDN cache when reading published channel dbs
pkgs.omarchy.org sits behind Cloudflare, and right after a sync the
plain db URL keeps serving the previous file from the edge cache
(observed: a cache HIT with age 900s+ returning the pre-release db).
That made status report the old version, wait_for_published poll a
frozen file for its full timeout, and would let RC auto-numbering
count from last release's versions. A unique query string per fetch
skips the cached entry.
2026-08-30 13:35:44 -04:00
Ryan Hughes bde81c757c Forward OMARCHY_RC_PINS into the build container
package_builds_for_mirror gates pinned packages' rc builds on
OMARCHY_RC_PINS, but that check runs inside the container via
build.sh, and docker run only forwarded ARCH/MIRROR/PACKAGES —
so the rc trigger's pinned builds were always skipped as 'not
configured for direct rc builds'.
2026-08-30 13:27:32 -04:00
Ryan Hughes 00dd64db61 Accept multiple package names in bin/release --package
The rc trigger passes '--package omarchy omarchy-settings', and bin/build
already consumes every name up to the next --option, but bin/release only
took one — the second name fell through to 'Unknown option' and the
release exited before building anything. Parse greedily, like bin/build.
2026-08-30 13:25:13 -04:00
Ryan HughesandGitHub 4a87a738b2 Number asdcontrol's sudoers policy and add it to the fast ring (#243)
* Use a numbered asdcontrol sudoers priority

* Add asdcontrol to the fast ring
2026-08-30 13:02:46 -04:00
Ryan HughesandGitHub 30d03c4d26 Scope asdcontrol's passwordless sudo grant (#242)
Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.
2026-08-30 12:59:21 -04:00
Ryan Hughes cf39173553 Revert "Add hey-cli to the fast ring"
This reverts commit 3bfc267a0e.
2026-08-29 13:36:56 -04:00
Ryan Hughes 3bfc267a0e Add hey-cli to the fast ring 2026-08-29 12:09:48 -04:00
Ryan HughesandGitHub 6daa7c90e4 Stage CUPS authorization as settings override (#237) 2026-08-29 02:19:29 -04:00
Ryan Hughes 391b5a201f t3code-patched-bin: 0.0.35-5, rebuilt from v0.0.35-omarchy.5 2026-08-28 22:33:11 -04:00
Ryan HughesandGitHub 4776db7f31 Merge pull request #213 from jeremydixon22/fix/asusctl-6.4.0
Update asusctl to 6.4.0
2026-08-28 18:31:57 -04:00
Ryan Hughes f48d528ca4 t3code-patched-bin 0.0.35-4: rebuild after review
Same upstream release, so only pkgrel moves. Built from v0.0.35-omarchy.4,
which carries the fixes from nine rounds of review on the upstream PR: the
CLI no longer overwrites an unreadable settings.json, setting a
single-appearance theme actually switches the client, reconnects no longer
flash published themes back to stock, and already-shipped clients keep
their config subscription instead of losing it to an unknown event.
2026-08-28 17:46:51 -04:00
Ryan Hughes a8c9e2982e Stop pick from hiding long-lived PRs behind a creation-ordered window
`gh pr list` orders by creation date, so `--limit 30` cut the candidate set by
when PRs were opened, not when they merged. The `sort_by(.mergedAt)` that
followed only reordered whatever survived that cut. A PR opened before the
window but merged inside it — exactly the kind a release branch still needs —
never reached the already-on-branch check at all. #7649 and #7709 were both
missing from v4-0-2's list for this reason.

The window is now bounded by the branch point instead of a count: pull a wide
page and keep what merged after the merge-base's commit date, since anything
merged into the dev branch before the release branch left it is already there
by ancestry. v4-0-2 went from 11 candidates to 31.

Widening it surfaced a second gap. A change re-applied by hand carries neither
a PR number nor a cherry-pick trailer, so already_on_branch could not see it
and offered it again (#6939, applied as 33d7363c). It now also compares the PR
title against the branch's subjects, with any trailing "(#N)" stripped.
2026-08-28 15:13:58 -04:00
Ryan Hughes f84c89d8b3 t3code-patched-bin: record the full artifact-shipping recipe
Comment-only. The .env requirement and the fact that only a PKGBUILD
version change triggers the build server both bit us once each; the
recipe now lives where the next rebuild starts.
2026-08-28 01:32:02 -04:00
Ryan Hughes dd8fd2fed7 t3code-patched-bin 0.0.35-3: bake T3 Connect public config
The r2 artifact was built without the public Connect configuration official
artifacts carry (relay URL, Clerk publishable key, CLI OAuth client id), so
Connect prompted for login with no way to log in. Same code, rebuilt with
the configuration recovered from the published npm t3 package.
2026-08-28 01:27:55 -04:00
Ryan Hughes 267dbdefaa t3code-patched-bin 0.0.35-2: post-review rebuild, fast ring
Rebuilt from v0.0.35-omarchy.2 of the environment-theme branch: the stream
event is capability-gated so old clients keep their config subscription,
republish dedupe is structural, the connect stream is gap-free, default
adoption is scoped per environment and keyed on the set generation, and
reserved theme ids cannot be published over. Joins the fast ring like
t3code-bin so patch rebuilds reach machines quickly.
2026-08-28 01:07:37 -04:00
Ryan Hughes 0fb1c09041 t3code-patched-bin: T3 Code with the environment-theme patches
Built from the environment-theme branch of ryanrhughes/t3code (tag
v0.0.35-omarchy.1) until upstream ships it: the app follows themes the
machine publishes into its state directory -- Omarchy retints it live --
and t3 theme set works. Same packaging as t3code-bin, conflicts with it,
and the next upstream release supersedes it after a rebase.
2026-08-27 23:55:15 -04:00
Ryan Hughes 273dd810da t3code-bin: ship the bundled server CLI as /usr/bin/t3
The desktop bundle already contains the full server -- the same entrypoint
npm's t3 package runs -- so a launcher that starts it through the bundled
Electron as Node puts the CLI on PATH without a second runtime. Upstream
only distributes the CLI via npm, which Omarchy's install scripting cannot
assume.
2026-08-27 23:55:15 -04:00
Ryan HughesandGitHub 01a95d9c28 Merge pull request #217 from fvdb/update-grok-bot-0.29.0
Update grok-bot to 0.29.0
2026-08-27 23:27:32 -04:00
Ryan HughesandGitHub 02d0c4ccd1 Merge pull request #225 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-08-27 23:27:03 -04:00
Ryan HughesandGitHub 9ebab47ed4 Merge pull request #224 from omacom/auto/sync-aur
chore: sync AUR packages
2026-08-27 23:26:50 -04:00
Ryan Hughes dbb5e72051 Build fast-ring for rc as rc, instead of copying stable's artifacts
The rc channel's Arch base can sit anywhere between stable's snapshot and
edge's, so a package built against stable's libraries is not necessarily
correct for rc. Copying stable's fast-ring artifacts into rc therefore shipped
possibly-mislinked packages to RC testers. Fast-ring packages now build
natively for all three channels, each in its own image against its own base
mirror, and the stable release's replication step is gone.

That required separating 'may be built here' from 'whose version wins'. The
release pair is now marked "pinned": its version is set per release on the rc
branch, so it builds for rc only from that branch's worktree
(OMARCHY_RC_PINS=1, set by omarchy-release rc) — master's shipped pins can
never overwrite an in-flight RC, even though check-versions now discovers rc
work like it does for edge and stable.
2026-08-27 12:39:29 -04:00
Ryan Hughes 9fd75fc3ba Report the stable publish before the rc parity copy, and quiet the copy
The fast-ring replication announced itself before the release that triggered
it, so chat read as though an rc job had run on its own — the reverse of what
happened. The publish report now fires first, and the replication says only
how many packages were kept in parity: the release report immediately above it
already lists them by name.
2026-08-27 12:21:41 -04:00
Ryan HughesandGitHub 370c37670b Merge pull request #211 from tobi/update-omasnap-1.20.0
omasnap: update to 1.20.1
2026-08-27 11:01:26 -04:00
Ryan HughesandGitHub 23739852a5 Merge pull request #207 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-27 11:01:21 -04:00
Ryan HughesandGitHub f8156190b1 Merge pull request #206 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-27 11:01:17 -04:00
Ryan Hughes aa0a836c1c Update README for the three-channel pipeline and remote control
Sections that still described the old two-channel, host-only world:

- command scope: the host-tree commands forward over ssh now, and advance
  replaces the deprecated migrate
- global flags: --mirror takes edge|rc|stable, and --local exists
- build examples and directory structure: the rc channel and the release lock
- release section: omarchy-release is the front door; omarchy-pkgs is the pin
  engine it drives (and still usable directly)
- management: bin/repo timers, the backoff state files, and clearing a stale
  lock, instead of raw systemctl invocations that omitted the rc units
- a leftover reference to the 6-hourly timer as the trigger backstop

Also fixed an anchor that pointed at the section containing the link rather
than the Quick Start section it names.
2026-08-27 01:40:05 -04:00
Ryan Hughes 1512cb48d8 chore: sync t3code-bin to 0.0.34
Matches what is already published to edge: 0.0.34 was built on the server
before the bump reached git, so the checkout read as out of date and queued a
rebuild of the older 0.0.33-2 that promotion then refused. Produced by
bin/sync-upstream, the same path the scheduled workflow uses.
2026-08-27 01:16:55 -04:00
Ryan Hughes 5d501f8ef9 Stop treating a single shared chat as a misconfiguration
Reporting to BASECAMP_CHATBOT_URL is a working setup — the second variable
exists only for those who want release traffic in its own chat. setup now
states which chat receives reports instead of warning about the common case,
and the README frames the split as optional rather than expected.
2026-08-27 01:15:06 -04:00
Ryan Hughes 7c3cfc50e9 Fix silent notifications and stop stale checkouts queueing rebuild loops
Two failures from the first live run:

notify_basecamp declared 'local BASECAMP_CHATBOT_URL' and then called
release_chatbot_url, whose fallback reads that same global — bash locals are
visible to called functions, so the fallback saw the empty local and every
notification silently went nowhere for anyone with only the legacy variable
set. The local is now named 'url'.

check-versions compared PKGBUILD and published versions with !=, so a checkout
BEHIND the channel queued a rebuild of an older version every cycle: the
builder produced it and promotion refused it, because that exact filename is
already published with different bytes. It now skips (with a warning naming
the package) when an artifact for the PKGBUILD's version already exists in the
channel, whichever direction the versions differ.
2026-08-27 01:10:33 -04:00
Ryan Hughes 0eb592b624 Stop the rc unit failing before the first RC is cut
The rc service fetched and reset /root/omarchy-pkgs-rc in ExecStartPre, but
that worktree does not exist until the first RC creates the rc branch — so on
a freshly set up host the unit failed every five minutes, forever, and showed
up as a failed unit in the timer report.

It now runs bin/auto-release-rc from the main checkout, which always exists:
nothing queued exits silently, no rc branch is a clean no-op, and a missing
worktree is created on demand before handing off to the worktree's own
auto-release.
2026-08-27 01:10:33 -04:00
Ryan Hughes af1b9c7791 Restore README truncated in 74f0959, with both reporting edits applied
A bad in-place edit truncated the file to zero: open(p,'w') ran before
open(p).read(), so the read saw an already-empty file. Restored from c0a63dd
and reapplied the two intended changes — the start report now naming queued
packages, and the nothing-to-publish report described as the check/builder
disagreement signal it is.
2026-08-27 01:10:33 -04:00
Ryan Hughes f551ab922c Report queued runs that publish nothing, as the anomaly they are
Restores the no-change report now that it is clear it cannot fire on an idle
timer tick: releases only run when the version check queued work, so a run
that publishes nothing means check-versions and the builder disagree about
what is out of date. The report names the packages that were queued but never
built, so a recurring disagreement is diagnosable rather than invisible.
2026-08-27 01:10:33 -04:00
Ryan Hughes cb986c0985 Drop no-change reports; name the queued packages when a build starts
A release that published nothing is not news, and at a 5-minute cadence those
messages would bury the ones that matter — the log and bin/repo timers still
show the run happened.

Removing it would have left a start report with no follow-up, so the start
report now carries its own answer: check-versions writes the package names it
queued into the state file instead of touching an empty one, and the release
run reads them. 'A build is running' becomes 'your package is in this build',
which is the question the reports exist to answer.
2026-08-27 01:10:33 -04:00
Ryan Hughes e3c3b3e50a Report build starts and successes, not just failures, to their own chat
Only failures were reported, so a push could reach the mirror with no way to
know short of querying the database by hand. Release runs now report:

- start: channel, arch, host, and the commit being built
- published: the packages and versions that went out, duration, channel URL
- no-changes: the run found nothing to build
- promoted: what advance moved between channels, including the rc bootstrap
  and fast-ring replication
- failed: unchanged, plus the commit context the other reports carry

Release traffic goes to OMARCHY_RELEASE_CHATBOT_URL, falling back to
BASECAMP_CHATBOT_URL, so build reports stop drowning the repository chat the
sync workflows post to. bin/setup reports which destination is configured.

The published list is captured after the build step because promote moves the
files out of build-output, and is capped at 25 entries so a full rebuild does
not produce an unreadable wall of chat.
2026-08-27 01:10:33 -04:00
Ryan Hughes 71e72e581b Run the timers every 5 minutes, with overlap and failure guards
A push reaching the mirror should take minutes, not up to six hours. All four
units now fire every 5 minutes, staggered a minute apart. Three guards make
that cadence safe:

- Scheduled runs take the release lock NON-BLOCKING (try_release_lock) and
  skip the tick when a build is running. Blocking would stack one stalled
  process per tick behind a long build and stampede when it finished. Manual
  commands still wait, as an operator expects.
- check-versions takes the lock too, and now owns its git pull (--pull, passed
  by the unit) instead of an ExecStartPre: at this cadence an unlocked pull
  would swap PKGBUILDs out from under a running build.
- A failed release records .build-failed-<channel> and backs off
  exponentially (10m, 20m, 40m … capped at 6h) rather than rebuilding the same
  broken tree every 5 minutes. Any new commit clears the backoff, since a push
  is the most likely fix.

Idle ticks exit without output so the journal keeps showing the runs that
matter, and bin/repo timers reports backoff state — a paused channel is
otherwise indistinguishable from an idle one.
2026-08-27 01:10:33 -04:00
Ryan Hughes 9d86123264 Add bin/repo timers: release timer and queue status at a glance
Wraps systemctl list-timers with the things you actually want when checking on
the build host: per-unit enabled state, last run and whether it succeeded,
which channels have builds queued (state files), whether the release lock is
held by a live process, and any failed units. Units are discovered from
systemd/*.timer so the report cannot drift from what setup installs.

It forwards over ssh like the other host commands, so the build box's timer
state is one command away from a workstation (--local to inspect this machine).
2026-08-27 01:10:33 -04:00
Ryan Hughes db816061a6 setup --check: distinguish a missing rc worktree from no rc branch yet
--check warned 'rc worktree would be created' whenever the directory was
absent, implying a plain setup run would create it — but with no rc branch in
existence setup skips it, so the warning described something that would not
happen and asked for action that was not possible. It now reports the branch
state: present, would-create (branch exists), or nothing-to-do (no branch
yet — the first RC cut creates the branch and the build trigger creates the
worktree on demand). Branch detection is read-only, as --check must be.
2026-08-27 01:10:33 -04:00
Ryan Hughes 0393849285 bootstrap-rc: seed the release pair into rc, not just the promoted set
Eligibility used package_moves_to_channel, which excludes packages built
natively in the destination — right for ongoing edge -> rc advances (a native
build must not be raced under the same filename) but wrong for the bootstrap,
whose entire purpose is rc == stable. omarchy and omarchy-settings were
therefore left out, so a machine switched to the rc channel could not install
or update the release pair until the first RC was cut. The bootstrap now
requires only destination membership; nothing is built in rc yet, so there is
no native artifact to conflict with. The dev pair stays edge-only and
fast-ring replication is unchanged.
2026-08-27 01:10:33 -04:00
Ryan Hughes e50f868a10 Channel-correct Docker images: keyring from own channel; repo-add uses edge
The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo
pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works
only because a stale copy of the old layout still answers there, and it would
miss a keyring rotation. Each image now pulls omarchy-keyring from its own
channel (edge/rc/stable), matching the base mirror it already selects.

update-repo and remove-package switch to the edge x86_64 image: repo-add and
repo-remove compile nothing, and using the channel image would deadlock
bootstrap-rc — the rc image can only build once the rc channel it pulls the
keyring from exists remotely.
2026-08-27 01:10:33 -04:00
Ryan Hughes 49ca22fa9f bin/repo becomes a remote control: forward host-tree commands over ssh
With a repository host configured (OMARCHY_REPO_HOST / .repo-host), release,
build, sign, promote, update, clean, advance, bootstrap-rc, remove, sync, and
migrate exec on the host over ssh — same code, run where the published tree
lives, after sourcing the host credentials and a --ff-only pull. --local
forces local execution. list/push/deploy/setup never forward. The host itself
has no .repo-host, so ssh'd-in manual use is unchanged. omarchy-release's
advance now rides the same forwarding (one code path), and --host exports
OMARCHY_REPO_HOST so child bin/repo calls follow it.

This closes the gap where bootstrap-rc ran against a workstation's stale
local tree despite .repo-host being set.
2026-08-27 01:10:33 -04:00
Ryan Hughes 161eecd5ff Explicit host config outranks the local build-host inference; document it
The published-db marker also exists on any workstation that once ran a full
local release, so --host / OMARCHY_REPO_HOST / .repo-host are now checked
before on_repo_host everywhere (triggers, advances, doctor). README documents
the detection, the caveat, and the .repo-host tie-breaker.
2026-08-27 01:10:33 -04:00
Ryan Hughes 52475c4bbc Run host operations locally when this machine is the build host
Release commands now work from anywhere: on_repo_host (the published database
living in this checkout) routes build triggers, advances, and promotion to
local execution; other machines go over ssh to the configured destination.
The host setting is any ssh destination — root@<ip>, root@<hostname>, or an
~/.ssh/config alias — resolved from --host, OMARCHY_REPO_HOST, then the
one-line .repo-host file. doctor reports which mode applies, and the README
documents the format and precedence. All host connections are plain ssh.
2026-08-27 01:10:33 -04:00
Ryan Hughes a5cafb291c Push over SSH from the tmp clones; keep reads on anonymous HTTPS
The work/mirror clones were HTTPS end to end, so pushes went through git's
credential-helper config — which breaks the moment a stale absolute gh path
is baked into it (as gh auth setup-git once did with /usr/bin/gh). Reads stay
anonymous HTTPS; pushes now use an SSH push URL (derived from the clone URL,
overridable with OMARCHY_UPSTREAM_PUSH_URL), set idempotently on every run so
existing cached clones self-repair.
2026-08-27 01:10:33 -04:00
Ryan Hughes 97519fb0f1 pick: detect backported PRs by message reference, not just ancestry
Changes reach a release branch as backports — cherry-picks with new SHAs — so
the original quattro merge commit is never an ancestor of a patch branch and
the ancestry filter let already-applied PRs through. Candidates are now also
matched against the branch's own commit messages since it left quattro:
'backport of #N' / squash '(#N)' references and 'cherry picked from commit
<sha>' trailers (which pick -x itself writes). Explicitly named PRs/commits
that are already on the branch are skipped with a note instead of re-picked.

Verified against the live v4-0-2 branch: the five backported PRs it carries
filter out; un-backported ones are still offered.
2026-08-27 01:10:33 -04:00
Ryan Hughes 5fae475743 Address Momus branch-review findings: harden ship, advance, and locking
- ship: no interactive override of the untested-commit guard; the tag targets
  the pinned commit the artifacts were built from (never the branch head); a
  tagged-but-incomplete train is found and resumed instead of vanishing from
  open-train detection; a fully shipped train reports as such
- start: a failed edge→rc advance fails the command loudly (both start and
  the advance are idempotent) instead of opening a train against stale rc
- rc trigger: bootstraps the server's rc worktree on first use, so a host set
  up before the rc branch existed can run its first RC build
- advance-channel: fast-ring packages are excluded from edge→rc (the stable
  build replicated by parity is authoritative for rc — same filename, other
  bytes); differing destination bytes abort instead of warn; a package whose
  signature copy was interrupted gets its .sig restored on resume
- the release lock now also covers direct promote/update/clean/remove/sync
  invocations, not just release/advance/upload-prebuilt
2026-08-27 01:10:33 -04:00
Ryan Hughes da92095f75 advance-channel: refuse bare --package; correct the sig-backfill guidance 2026-08-27 01:10:33 -04:00
Ryan Hughes 2cea400cd1 Add bin/omarchy-release: the interactive release front door
A release train has three human moments, each one command: start (release
branch on basecamp/omarchy + notes staging PR + edge→rc advance for
minor/major), rc (pin both PKGBUILDs to the branch head as X.Y.ZrcN on the
pkgs rc branch, trigger the rc channel build, wait for publish, optional RC
ISO), and ship (final pins → promote rc→stable → tag → pins to master → GitHub
release from the staging PR body → final ISO → website bump, each step
skip-if-done so a crashed run resumes).

Bare omarchy-release is the shepherd: it derives the train state from observed
reality (remote branches, rc-branch pins, published channel dbs, tags — no
state files) and offers the correct next step. Versions are inferred from
branch names (v4-0-2 ⇒ 4.0.2rcN ⇒ v4.0.2). ship refuses to promote a commit
no RC was cut from. pick is a multi-select over merged quattro PRs,
cherry-picking merge commits. doctor pre-flights every credential and
connection. self-test wired into CI.

bin/omarchy-pkgs stays as the pin engine, driven with its db URL pointed at
the rc channel and pins committed to the standing rc branch (rebuilt as
master + pins per cut and force-pushed; the server rc worktree follows with
reset --hard).
2026-08-27 01:10:33 -04:00
Ryan Hughes dac5ba2b45 Document the three-channel pipeline in README 2026-08-27 01:10:33 -04:00
Ryan Hughes 726c9d1f29 Add rc auto-release timer/service and rc branch worktree to host setup
The rc service builds from the rc branch worktree (/root/omarchy-pkgs-rc,
created by bin/setup) but publishes into the primary checkout's channel tree
via OMARCHY_REPO_ROOT. The timer is a retry backstop: rc builds are normally
triggered immediately over SSH by the release orchestrator.
2026-08-27 01:10:33 -04:00
Ryan Hughes 63f6156f25 Replace migrate with manifest-driven advance-channel and add the release lock
bin/repo advance --from/--to moves packages forward through the pipeline
(edge → rc → stable), driven by the source channel's database rather than the
raw directory, copying packages AND their detached signatures (fixing the old
migrate bug that left promoted packages unverifiable), refusing to rewrite any
published filename, and requiring a .sig for everything it moves. stable → rc
is allowed only as --fast-ring parity replication or the one-time
--bootstrap seed (bin/repo bootstrap-rc). 'migrate' stays as a deprecated
alias for the transition.

helpers/lock-helpers.sh adds a host-wide flock shared by bin/release,
advance-channel, and upload-prebuilt (reentrant via OMARCHY_RELEASE_LOCK_HELD)
so timers and operators serialize instead of interleaving partial publishes.

bin/release gains a stable-only step 7: replicate fast-ring artifacts to rc so
rc and stable stay in parity between release trains (skipped until rc is
bootstrapped).
2026-08-27 01:10:33 -04:00
Ryan Hughes 26bde8fae3 Add channels metadata: membership and build-channel rules for edge/rc/stable
A package's .omarchy/package.json may now pin where it lives with
"channels": [...]. With the key present the package builds in each listed
channel except stable (stable is only fed by promotion); without it, today's
defaults hold (build for edge; fast-ring also builds stable directly).

package_moves_to_channel() is the advance/promote eligibility rule: a member
of the destination channel that is not built there natively.

The release pair (omarchy, omarchy-settings) is edge+rc+stable — edge stays
during the client-migration overlap window and drops later. The dev pair is
pinned to edge only.
2026-08-27 01:10:33 -04:00
Ryan Hughes e73b843bd2 Add rc as a first-class channel: validation, shared repo root, rc build mirror
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
  set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
  the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
  promote-build, update-repo, clean-repo, remove-package) and widen the
  edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
2026-08-27 01:10:33 -04:00
Ryan HughesandGitHub f448847d1f Merge pull request #205 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-25 18:55:02 -04:00
Ryan HughesandGitHub 13259c4d99 Merge pull request #204 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-25 18:54:57 -04:00
Ryan HughesandGitHub 74917b641a Merge pull request #174 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-24 22:59:38 -04:00
Ryan HughesandGitHub 4b1226ec17 Merge pull request #202 from omacom-io/mise-release-age-fallback
Quarantine fresh upstream releases via min_release_age in the package manifest
2026-08-24 22:44:17 -04:00
Ryan Hughes 92735d5539 Require strict ISO 8601 in the age backstop; document the no-stable-release stance
GNU date accepts relative expressions like '2 days ago', which would let a
buggy hook fabricate a release age; the backstop now insists on an ISO 8601
timestamp before date parses it. The provider header now states, rather than
contradicts, the code's behavior for a feed with no stable releases: that is
a loud failure by design, while quarantined releases report no update.
2026-08-24 20:32:20 -04:00
Ryan Hughes fd03757f22 Reject empty min_release_age, self-age the e2e fixtures, run self-tests in CI
An empty min_release_age string now maps to unparseable rather than absent,
so "min_release_age": "" fails validation instead of silently running
with a zero-second quarantine. The end-to-end fixtures extend the
checked-in pkgver (.90/.91) so the test keeps working at any future mise
version. A Tests workflow runs bin/sync-upstream self-test and
bin/omarchy-pkgs self-test on every PR in the Arch container, making the
proof machine-checked instead of author-supplied. The README package
metadata field list documents upstream and min_release_age.
2026-08-24 20:22:33 -04:00
Ryan Hughes 83bdfb5fa1 Prove the migrated mise path end to end and harden discovery per Momus
The self-test now runs sync_package over the checked-in mise-bin package --
its real metadata and PKGBUILD, the full selection/validation/backstop/
rewrite/read-back path -- with only the two network fetches replaced by
mise-shaped fixtures, asserting the final PKGBUILD holds the quarantine-
cleared version, pkgrel 1, and both architecture checksums.

Review fixes: the release-row builder uses "" fallbacks instead of empty
so a malformed row cannot shift columns past the per-field checks, and
provider discovery now keys on the presence of an upstream declaration
rather than a well-formed one, with sync_package failing loudly on a
declaration it cannot use -- a malformed manifest can no longer silently
drop a package out of scheduled synchronization.
2026-08-24 20:14:45 -04:00
Ryan Hughes 5777573a84 Harden the provider per Momus review and prove it with offline fixtures
bin/sync-upstream self-test swaps the two network fetches in
helpers/upstream-github.sh for fixture readers and runs the production code
paths: fallback past a quarantined release, draft/prerelease filtering, the
deliberate bypass, unchanged-version and all-quarantined no-update paths,
unusable tags/timestamps and missing checksums failing the sync, {tag} and
{pkgver} asset templates with ./ and * manifest prefixes across both
architectures, the min_release_age backstop verdicts (now a testable
release_age_status function), the duration parser, and manifest validation.

Also fixes from the review: the duration parser forces base-10 arithmetic
(leading zeros no longer parse as octal) and bounds values to nine digits so
no suffix can overflow; jq // treating false as absent can no longer let
"min_release_age": false or "upstream": false slip through as unset; the
release feed page grew to the API maximum of 100 with the bounded search
documented; and the README package-metadata section documents the upstream
block, min_release_age, the bypass, and provider-versus-hook exclusivity.
2026-08-24 20:07:10 -04:00
Ryan Hughes 699261471a Replace mise's upstream hook with a declarative GitHub-releases provider
After the quarantine moved into the manifest, all mise-bin's hook still knew
was data: the repository, the checksum manifest name, and the asset filename
patterns. That now lives in .omarchy/package.json as an upstream block --

  "upstream": {
    "github": "jdx/mise",
    "checksums": "SHASUMS256.txt",
    "assets": { "x86_64": "mise-{tag}-linux-x64.tar.xz", ... }
  }

-- handled by helpers/upstream-github.sh inside bin/sync-upstream. The
provider walks the release feed (drafts/prereleases excluded), honors
min_release_age and BYPASS_MIN_RELEASE_AGE during selection, reports
published_at so the framework backstop still applies, fails closed on any
unreadable tag or timestamp, and skips the checksum fetch when the newest
qualifying release is already checked in.

upstream.sh remains the escape hatch for feeds that fit no convention
(openai-codex-desktop's Debian index, tmog's version.txt, t3code's
electron-builder manifest); declaring both is an error.
2026-08-24 19:30:33 -04:00
Ryan Hughes 48ad6b9d7b Generalize the release-age quarantine into a manifest policy
Move the hold from a mise-only hardcode to min_release_age in
.omarchy/package.json ("24h", "2d", or bare seconds), alongside source and
release_ring where package policy already lives. bin/sync-upstream exports
the window to every hook as MIN_RELEASE_AGE_SECONDS so a hook that can walk
its release feed selects the newest release that has cleared it, and
enforces it as a backstop: with a policy set, the hook must report
published_at, and a release younger than the window is treated as no
update. A hook that cannot prove the age fails the sync rather than
shipping unverified. BYPASS_MIN_RELEASE_AGE=1 replaces the package-specific
bypass for deliberate emergency updates; scheduled automation never sets it.

The mise hook keeps its release-list walk but reads the window from the
environment and reports published_at; the other upstream hooks are
untouched and unaffected until they opt in.
2026-08-24 19:17:22 -04:00
Ryan Hughes eca3ce7815 mise-bin: ship the newest release that has cleared the 24h quarantine
Gating on /releases/latest alone starves updates when mise's near-daily
cadence keeps the newest release perpetually inside the quarantine window:
today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past
24 hours. Walk the release list (drafts and prereleases excluded) and pick
the newest release, by vercmp, whose published_at is at least 24 hours old.

The quarantine guarantee is unchanged: nothing younger than the window ever
ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid
tags or timestamps still fail closed - now for every release in the feed,
plus a hard failure if the feed reports no stable releases at all.
2026-08-24 14:21:41 -04:00
Ryan HughesandGitHub 40ddd6be19 Merge pull request #192 from jdx/fix/mise-release-age
fix(mise-bin): delay upstream releases for 24 hours
2026-08-24 10:56:46 -04:00
Ryan HughesandGitHub 2f067f4e22 Merge pull request #173 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-24 09:04:46 -04:00
Ryan Hughes e5fb86e53d Release omarchy 4.0.1rc1 2026-08-23 20:14:52 -04:00
Ryan HughesandGitHub c409cb6d6a Merge pull request #120 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-16 10:49:44 -04:00
Ryan Hughes d3298050bb Remove tag requirement 2026-08-14 11:08:39 -04:00
Ryan Hughes 2d8f35f43f Update 2026-08-12 00:14:02 -04:00
Ryan Hughes f8d8671514 Release omarchy 4.0.0beta3 2026-08-12 00:13:36 -04:00
Ryan Hughes 155ff25666 Add a rebuild option 2026-08-11 23:58:45 -04:00
Ryan Hughes f6c8d3d33b Handle prerelease 2026-08-11 23:42:39 -04:00
Ryan Hughes f609e6a31e Add omarchy-pkgs 2026-08-11 23:36:37 -04:00
Ryan Hughes 9323f13db1 Release omarchy 4.0.0rc1 2026-08-11 23:36:37 -04:00
Ryan Hughes abec5dd439 Add bin/omarchy-pkgs release command
One-command releases for the omarchy + omarchy-settings pair:
  bin/omarchy-pkgs release v4.0.0 | latest | rc [--commit sha] [--base X.Y.Z]

Rewrites both PKGBUILDs in lockstep (same _tag/_commit/pkgver/sha256sums,
pkgrel reset to 1), normalizes upstream tag forms to the vercmp-safe
attached rcN convention, refuses downgrades against the published edge DB,
regenerates and verifies checksums from a cached mirror clone, commits and
pushes to master, and triggers the build host when OMARCHY_BUILD_HOST is
configured. RCs stay on edge; finals are promoted with bin/repo migrate.
Includes a self-test covering tag normalization and pacman ordering, and a
README runbook.
2026-08-11 22:21:23 -04:00
Ryan Hughes 855942303f Pin omarchy-settings dependency to exact pkgver
omarchy-settings-dev provides omarchy-settings (unversioned), so an
unversioned dependency let the dev package satisfy stable omarchy's
settings requirement, allowing a mixed dev/stable install. A versioned
dependency (omarchy-settings=${pkgver}) can only be satisfied by the
real settings package from the same pinned commit and forces the pair
to upgrade together. Verified: requesting only omarchy on a system with
the -dev pair installed replaces both with the stable pair.
2026-08-11 22:19:58 -04:00
Ryan Hughes 0daad9992a Add commit-pinned release packages omarchy and omarchy-settings
Stable-track counterparts of the -dev packages. Source is pinned to a
single shared upstream commit with a real sha256 (pacman 7 validates
checksums on commit-pinned git sources), versioned per the attached-rcN
convention so vercmp orders rc1 < rc2 < final. Seeded at 4.0.0rc1 from
the quattro tip because no upstream 4.x tag exists yet and the packaging
requires the quattro tree (v3.8.x has no shell/ or etc/).

Both packages stay off the fast ring: RCs publish to edge only; stable
receives finals via bin/repo migrate.
2026-08-11 21:21:10 -04:00
Ryan HughesandGitHub 14b71bde37 Merge pull request #113 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-07-26 19:40:02 -04:00
Ryan Hughes 515b566cb9 Add skip_build 2026-07-13 19:55:23 -04:00
Ryan Hughes 162e9c0ec9 Update to restore .1 if patched 2026-06-26 00:25:52 -04:00
Ryan Hughes ba0292e4cb Clarify Snapper packaging ownership 2026-06-21 02:25:11 -04:00
Ryan Hughes 78e5cc8195 Add remote clipboard fix 2026-06-20 15:42:10 -04:00
Ryan HughesandGitHub 85491dd01d Merge pull request #112 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-06-17 21:27:23 -04:00
Ryan HughesandGitHub 3db678393e Merge pull request #111 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-06-16 11:30:20 -04:00
Ryan HughesandGitHub 4cf14e2261 Merge pull request #109 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-06-14 20:13:09 -04:00