The builder stage never declared ARG MIRROR, so the keyring [omarchy] repo
pointed at the channel-less legacy pkgs.omarchy.org/$arch path — it works
only because a stale copy of the old layout still answers there, and it would
miss a keyring rotation. Each image now pulls omarchy-keyring from its own
channel (edge/rc/stable), matching the base mirror it already selects.
update-repo and remove-package switch to the edge x86_64 image: repo-add and
repo-remove compile nothing, and using the channel image would deadlock
bootstrap-rc — the rc image can only build once the rc channel it pulls the
keyring from exists remotely.
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
promote-build, update-repo, clean-repo, remove-package) and widen the
edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
The builder image is layer-cached, so its glibc drifts behind the
mirror while makepkg -s installs makedepends from the freshly synced
database. omarchy-settings-dev died on that partial upgrade: the new
imagemagick needs GLIBC_2.44 and magick refused to run in package().
pacman -Syu runs before the Omarchy repos are appended, so only
core/extra take part -- in-flight build-output packages can't be
pulled into the container.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: add nautilus-open-any-terminal
* Make this a normal edge package
* Move to correct package list
---------
Co-authored-by: David Heinemeier Hansson <david@hey.com>