Commit Graph
1092 Commits
Author SHA1 Message Date
Ryan Hughes 0393849285 bootstrap-rc: seed the release pair into rc, not just the promoted set
Eligibility used package_moves_to_channel, which excludes packages built
natively in the destination — right for ongoing edge -> rc advances (a native
build must not be raced under the same filename) but wrong for the bootstrap,
whose entire purpose is rc == stable. omarchy and omarchy-settings were
therefore left out, so a machine switched to the rc channel could not install
or update the release pair until the first RC was cut. The bootstrap now
requires only destination membership; nothing is built in rc yet, so there is
no native artifact to conflict with. The dev pair stays edge-only and
fast-ring replication is unchanged.
2026-08-27 01:10:33 -04:00
Ryan Hughes e50f868a10 Channel-correct Docker images: keyring from own channel; repo-add uses edge
The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo
pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works
only because a stale copy of the old layout still answers there, and it would
miss a keyring rotation. Each image now pulls omarchy-keyring from its own
channel (edge/rc/stable), matching the base mirror it already selects.

update-repo and remove-package switch to the edge x86_64 image: repo-add and
repo-remove compile nothing, and using the channel image would deadlock
bootstrap-rc — the rc image can only build once the rc channel it pulls the
keyring from exists remotely.
2026-08-27 01:10:33 -04:00
Ryan Hughes 49ca22fa9f bin/repo becomes a remote control: forward host-tree commands over ssh
With a repository host configured (OMARCHY_REPO_HOST / .repo-host), release,
build, sign, promote, update, clean, advance, bootstrap-rc, remove, sync, and
migrate exec on the host over ssh — same code, run where the published tree
lives, after sourcing the host credentials and a --ff-only pull. --local
forces local execution. list/push/deploy/setup never forward. The host itself
has no .repo-host, so ssh'd-in manual use is unchanged. omarchy-release's
advance now rides the same forwarding (one code path), and --host exports
OMARCHY_REPO_HOST so child bin/repo calls follow it.

This closes the gap where bootstrap-rc ran against a workstation's stale
local tree despite .repo-host being set.
2026-08-27 01:10:33 -04:00
Ryan Hughes 161eecd5ff Explicit host config outranks the local build-host inference; document it
The published-db marker also exists on any workstation that once ran a full
local release, so --host / OMARCHY_REPO_HOST / .repo-host are now checked
before on_repo_host everywhere (triggers, advances, doctor). README documents
the detection, the caveat, and the .repo-host tie-breaker.
2026-08-27 01:10:33 -04:00
Ryan Hughes 52475c4bbc Run host operations locally when this machine is the build host
Release commands now work from anywhere: on_repo_host (the published database
living in this checkout) routes build triggers, advances, and promotion to
local execution; other machines go over ssh to the configured destination.
The host setting is any ssh destination — root@<ip>, root@<hostname>, or an
~/.ssh/config alias — resolved from --host, OMARCHY_REPO_HOST, then the
one-line .repo-host file. doctor reports which mode applies, and the README
documents the format and precedence. All host connections are plain ssh.
2026-08-27 01:10:33 -04:00
Ryan Hughes a5cafb291c Push over SSH from the tmp clones; keep reads on anonymous HTTPS
The work/mirror clones were HTTPS end to end, so pushes went through git's
credential-helper config — which breaks the moment a stale absolute gh path
is baked into it (as gh auth setup-git once did with /usr/bin/gh). Reads stay
anonymous HTTPS; pushes now use an SSH push URL (derived from the clone URL,
overridable with OMARCHY_UPSTREAM_PUSH_URL), set idempotently on every run so
existing cached clones self-repair.
2026-08-27 01:10:33 -04:00
Ryan Hughes 97519fb0f1 pick: detect backported PRs by message reference, not just ancestry
Changes reach a release branch as backports — cherry-picks with new SHAs — so
the original quattro merge commit is never an ancestor of a patch branch and
the ancestry filter let already-applied PRs through. Candidates are now also
matched against the branch's own commit messages since it left quattro:
'backport of #N' / squash '(#N)' references and 'cherry picked from commit
<sha>' trailers (which pick -x itself writes). Explicitly named PRs/commits
that are already on the branch are skipped with a note instead of re-picked.

Verified against the live v4-0-2 branch: the five backported PRs it carries
filter out; un-backported ones are still offered.
2026-08-27 01:10:33 -04:00
Ryan Hughes 5fae475743 Address Momus branch-review findings: harden ship, advance, and locking
- ship: no interactive override of the untested-commit guard; the tag targets
  the pinned commit the artifacts were built from (never the branch head); a
  tagged-but-incomplete train is found and resumed instead of vanishing from
  open-train detection; a fully shipped train reports as such
- start: a failed edge→rc advance fails the command loudly (both start and
  the advance are idempotent) instead of opening a train against stale rc
- rc trigger: bootstraps the server's rc worktree on first use, so a host set
  up before the rc branch existed can run its first RC build
- advance-channel: fast-ring packages are excluded from edge→rc (the stable
  build replicated by parity is authoritative for rc — same filename, other
  bytes); differing destination bytes abort instead of warn; a package whose
  signature copy was interrupted gets its .sig restored on resume
- the release lock now also covers direct promote/update/clean/remove/sync
  invocations, not just release/advance/upload-prebuilt
2026-08-27 01:10:33 -04:00
Ryan Hughes da92095f75 advance-channel: refuse bare --package; correct the sig-backfill guidance 2026-08-27 01:10:33 -04:00
Ryan Hughes 2cea400cd1 Add bin/omarchy-release: the interactive release front door
A release train has three human moments, each one command: start (release
branch on basecamp/omarchy + notes staging PR + edge→rc advance for
minor/major), rc (pin both PKGBUILDs to the branch head as X.Y.ZrcN on the
pkgs rc branch, trigger the rc channel build, wait for publish, optional RC
ISO), and ship (final pins → promote rc→stable → tag → pins to master → GitHub
release from the staging PR body → final ISO → website bump, each step
skip-if-done so a crashed run resumes).

Bare omarchy-release is the shepherd: it derives the train state from observed
reality (remote branches, rc-branch pins, published channel dbs, tags — no
state files) and offers the correct next step. Versions are inferred from
branch names (v4-0-2 ⇒ 4.0.2rcN ⇒ v4.0.2). ship refuses to promote a commit
no RC was cut from. pick is a multi-select over merged quattro PRs,
cherry-picking merge commits. doctor pre-flights every credential and
connection. self-test wired into CI.

bin/omarchy-pkgs stays as the pin engine, driven with its db URL pointed at
the rc channel and pins committed to the standing rc branch (rebuilt as
master + pins per cut and force-pushed; the server rc worktree follows with
reset --hard).
2026-08-27 01:10:33 -04:00
Ryan Hughes dac5ba2b45 Document the three-channel pipeline in README 2026-08-27 01:10:33 -04:00
Ryan Hughes 726c9d1f29 Add rc auto-release timer/service and rc branch worktree to host setup
The rc service builds from the rc branch worktree (/root/omarchy-pkgs-rc,
created by bin/setup) but publishes into the primary checkout's channel tree
via OMARCHY_REPO_ROOT. The timer is a retry backstop: rc builds are normally
triggered immediately over SSH by the release orchestrator.
2026-08-27 01:10:33 -04:00
Ryan Hughes 63f6156f25 Replace migrate with manifest-driven advance-channel and add the release lock
bin/repo advance --from/--to moves packages forward through the pipeline
(edge → rc → stable), driven by the source channel's database rather than the
raw directory, copying packages AND their detached signatures (fixing the old
migrate bug that left promoted packages unverifiable), refusing to rewrite any
published filename, and requiring a .sig for everything it moves. stable → rc
is allowed only as --fast-ring parity replication or the one-time
--bootstrap seed (bin/repo bootstrap-rc). 'migrate' stays as a deprecated
alias for the transition.

helpers/lock-helpers.sh adds a host-wide flock shared by bin/release,
advance-channel, and upload-prebuilt (reentrant via OMARCHY_RELEASE_LOCK_HELD)
so timers and operators serialize instead of interleaving partial publishes.

bin/release gains a stable-only step 7: replicate fast-ring artifacts to rc so
rc and stable stay in parity between release trains (skipped until rc is
bootstrapped).
2026-08-27 01:10:33 -04:00
Ryan Hughes 26bde8fae3 Add channels metadata: membership and build-channel rules for edge/rc/stable
A package's .omarchy/package.json may now pin where it lives with
"channels": [...]. With the key present the package builds in each listed
channel except stable (stable is only fed by promotion); without it, today's
defaults hold (build for edge; fast-ring also builds stable directly).

package_moves_to_channel() is the advance/promote eligibility rule: a member
of the destination channel that is not built there natively.

The release pair (omarchy, omarchy-settings) is edge+rc+stable — edge stays
during the client-migration overlap window and drops later. The dev pair is
pinned to edge only.
2026-08-27 01:10:33 -04:00
Ryan Hughes e73b843bd2 Add rc as a first-class channel: validation, shared repo root, rc build mirror
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
  set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
  the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
  promote-build, update-repo, clean-repo, remove-package) and widen the
  edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
2026-08-27 01:10:33 -04:00
David Heinemeier HanssonandGitHub 5a73fd8999 Merge pull request #208 from jdx/chore/bump-mise-2026.8.14
chore(mise): bump to 2026.8.14
2026-08-26 11:43:41 +02:00
default 9eb78bc832 chore(mise): bump to 2026.8.14 2026-08-26 08:06:08 +00:00
Ryan HughesandGitHub f448847d1f Merge pull request #205 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-25 18:55:02 -04:00
Ryan HughesandGitHub 13259c4d99 Merge pull request #204 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-25 18:54:57 -04:00
dhhandgithub-actions[bot] 84cdb1b9f2 chore: sync upstream releases 2026-08-25 19:05:01 +00:00
ryanrhughesandgithub-actions[bot] 262dfd11b2 chore: sync AUR packages 2026-08-25 18:44:05 +00:00
David Heinemeier HanssonandGitHub 0ea0c5f8d1 Merge pull request #150 from spencerbull/dell-xps13-sidecar-amps
Add Dell XPS 13 sidecar amplifier workaround
2026-08-25 17:47:02 +02:00
David Heinemeier Hansson 044e81c636 Release omarchy 4.0.1 2026-08-25 13:04:07 +02:00
David Heinemeier Hansson 4db463cf3c Release omarchy 4.0.1rc5 2026-08-25 12:17:41 +02:00
David Heinemeier Hansson bf1f3e0d8e Release omarchy 4.0.1rc4 2026-08-25 09:28:21 +02:00
David Heinemeier HanssonandGitHub 292d27a4e4 Merge pull request #166 from omacom-io/hermes-agent
Add hermes-desktop
2026-08-25 07:49:30 +02:00
Ryan HughesandGitHub 74917b641a Merge pull request #174 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-24 22:59:38 -04:00
ryanrhughesandgithub-actions[bot] d839d8a49f chore: sync upstream releases 2026-08-25 02:45:50 +00:00
Ryan HughesandGitHub 4b1226ec17 Merge pull request #202 from omacom-io/mise-release-age-fallback
Quarantine fresh upstream releases via min_release_age in the package manifest
2026-08-24 22:44:17 -04:00
Ryan Hughes 92735d5539 Require strict ISO 8601 in the age backstop; document the no-stable-release stance
GNU date accepts relative expressions like '2 days ago', which would let a
buggy hook fabricate a release age; the backstop now insists on an ISO 8601
timestamp before date parses it. The provider header now states, rather than
contradicts, the code's behavior for a feed with no stable releases: that is
a loud failure by design, while quarantined releases report no update.
2026-08-24 20:32:20 -04:00
Ryan Hughes fd03757f22 Reject empty min_release_age, self-age the e2e fixtures, run self-tests in CI
An empty min_release_age string now maps to unparseable rather than absent,
so "min_release_age": "" fails validation instead of silently running
with a zero-second quarantine. The end-to-end fixtures extend the
checked-in pkgver (.90/.91) so the test keeps working at any future mise
version. A Tests workflow runs bin/sync-upstream self-test and
bin/omarchy-pkgs self-test on every PR in the Arch container, making the
proof machine-checked instead of author-supplied. The README package
metadata field list documents upstream and min_release_age.
2026-08-24 20:22:33 -04:00
Ryan Hughes 83bdfb5fa1 Prove the migrated mise path end to end and harden discovery per Momus
The self-test now runs sync_package over the checked-in mise-bin package --
its real metadata and PKGBUILD, the full selection/validation/backstop/
rewrite/read-back path -- with only the two network fetches replaced by
mise-shaped fixtures, asserting the final PKGBUILD holds the quarantine-
cleared version, pkgrel 1, and both architecture checksums.

Review fixes: the release-row builder uses "" fallbacks instead of empty
so a malformed row cannot shift columns past the per-field checks, and
provider discovery now keys on the presence of an upstream declaration
rather than a well-formed one, with sync_package failing loudly on a
declaration it cannot use -- a malformed manifest can no longer silently
drop a package out of scheduled synchronization.
2026-08-24 20:14:45 -04:00
Ryan Hughes 5777573a84 Harden the provider per Momus review and prove it with offline fixtures
bin/sync-upstream self-test swaps the two network fetches in
helpers/upstream-github.sh for fixture readers and runs the production code
paths: fallback past a quarantined release, draft/prerelease filtering, the
deliberate bypass, unchanged-version and all-quarantined no-update paths,
unusable tags/timestamps and missing checksums failing the sync, {tag} and
{pkgver} asset templates with ./ and * manifest prefixes across both
architectures, the min_release_age backstop verdicts (now a testable
release_age_status function), the duration parser, and manifest validation.

Also fixes from the review: the duration parser forces base-10 arithmetic
(leading zeros no longer parse as octal) and bounds values to nine digits so
no suffix can overflow; jq // treating false as absent can no longer let
"min_release_age": false or "upstream": false slip through as unset; the
release feed page grew to the API maximum of 100 with the bounded search
documented; and the README package-metadata section documents the upstream
block, min_release_age, the bypass, and provider-versus-hook exclusivity.
2026-08-24 20:07:10 -04:00
Ryan Hughes 699261471a Replace mise's upstream hook with a declarative GitHub-releases provider
After the quarantine moved into the manifest, all mise-bin's hook still knew
was data: the repository, the checksum manifest name, and the asset filename
patterns. That now lives in .omarchy/package.json as an upstream block --

  "upstream": {
    "github": "jdx/mise",
    "checksums": "SHASUMS256.txt",
    "assets": { "x86_64": "mise-{tag}-linux-x64.tar.xz", ... }
  }

-- handled by helpers/upstream-github.sh inside bin/sync-upstream. The
provider walks the release feed (drafts/prereleases excluded), honors
min_release_age and BYPASS_MIN_RELEASE_AGE during selection, reports
published_at so the framework backstop still applies, fails closed on any
unreadable tag or timestamp, and skips the checksum fetch when the newest
qualifying release is already checked in.

upstream.sh remains the escape hatch for feeds that fit no convention
(openai-codex-desktop's Debian index, tmog's version.txt, t3code's
electron-builder manifest); declaring both is an error.
2026-08-24 19:30:33 -04:00
Ryan Hughes 48ad6b9d7b Generalize the release-age quarantine into a manifest policy
Move the hold from a mise-only hardcode to min_release_age in
.omarchy/package.json ("24h", "2d", or bare seconds), alongside source and
release_ring where package policy already lives. bin/sync-upstream exports
the window to every hook as MIN_RELEASE_AGE_SECONDS so a hook that can walk
its release feed selects the newest release that has cleared it, and
enforces it as a backstop: with a policy set, the hook must report
published_at, and a release younger than the window is treated as no
update. A hook that cannot prove the age fails the sync rather than
shipping unverified. BYPASS_MIN_RELEASE_AGE=1 replaces the package-specific
bypass for deliberate emergency updates; scheduled automation never sets it.

The mise hook keeps its release-list walk but reads the window from the
environment and reports published_at; the other upstream hooks are
untouched and unaffected until they opt in.
2026-08-24 19:17:22 -04:00
David Heinemeier Hansson 405576f4e9 Release omarchy 4.0.1rc3 2026-08-24 22:00:51 +02:00
David Heinemeier HanssonandGitHub 1e64b129a3 Merge pull request #185 from tobi/update-omasnap-1.16.0
omasnap: update to 1.19.1
2026-08-24 21:56:47 +02:00
David Heinemeier HanssonandGitHub 720a21f5e9 Merge pull request #198 from fvdb/update-grok-bot-0.24.0
Update grok-bot to 0.24.0
2026-08-24 21:52:10 +02:00
David Heinemeier HanssonandGitHub 38c1b8eaed Merge pull request #203 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-24 21:51:19 +02:00
ryanrhughesandgithub-actions[bot] 5b51263adf chore: sync AUR packages 2026-08-24 18:44:12 +00:00
Ryan Hughes eca3ce7815 mise-bin: ship the newest release that has cleared the 24h quarantine
Gating on /releases/latest alone starves updates when mise's near-daily
cadence keeps the newest release perpetually inside the quarantine window:
today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past
24 hours. Walk the release list (drafts and prereleases excluded) and pick
the newest release, by vercmp, whose published_at is at least 24 hours old.

The quarantine guarantee is unchanged: nothing younger than the window ever
ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid
tags or timestamps still fail closed - now for every release in the feed,
plus a hard failure if the feed reports no stable releases at all.
2026-08-24 14:21:41 -04:00
David Heinemeier Hansson cc2413f0f3 Release omarchy 4.0.1rc2 2026-08-24 20:12:38 +02:00
Frank van den Brink cfa09a6719 Update grok-bot to 0.24.0
Pin the official Linux .deb to Cursor stable 0.24.0 (commit 302d75da).
Upstream renamed the binary sand -> grok-bot and ships grok-bot icons
and a grokbot:// handler; keep a Wayland wrapper and /usr/bin/sand compat
symlink.

Linux still has no update feed. Leave pinning to update-pkgver.sh rather
than a sync-upstream hook, which cannot atomically rewrite _commit.
2026-08-24 17:07:58 +02:00
Ryan HughesandGitHub 40ddd6be19 Merge pull request #192 from jdx/fix/mise-release-age
fix(mise-bin): delay upstream releases for 24 hours
2026-08-24 10:56:46 -04:00
Ryan HughesandGitHub 2f067f4e22 Merge pull request #173 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-24 09:04:46 -04:00
ryanrhughesandgithub-actions[bot] 78ce6429f1 chore: sync AUR packages 2026-08-24 01:24:35 +00:00
Ryan Hughes e5fb86e53d Release omarchy 4.0.1rc1 2026-08-23 20:14:52 -04:00
default f1e0ca526d fix(mise-bin): delay upstream releases for 24 hours
*AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.*
2026-08-23 22:10:19 +00:00
Tobi Lutke 5cf5ecb2a4 omasnap: update to 1.19.1 2026-08-23 15:51:49 -04:00
Tobi Lutke e60a5e68fb omasnap: update to 1.19.0 2026-08-23 14:57:53 -04:00