Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.
Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.
Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.
package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.
Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.
The recipe fetched the branch tip, so a rebuild on another architecture
could package a different tree than the one already published. Pin the
source to a commit and set pkgver to what that commit describes
(1.22.0.r96.g0331510, as an aarch64 build of it reports); bump both
together from now on.
Three opt-in knobs for bin/build, each defaulting to today's behaviour:
OMARCHY_KEEP_BUILD_WORKSPACE=1 keeps build-output/$MIRROR/$ARCH instead
of wiping it, and build/build.sh now folds any packages already there
into omarchy-build.db even when no database exists yet, so packages
built by an earlier job (or a previous, interrupted run) resolve as
dependencies of what builds next.
OMARCHY_SKIP_BUILDER_IMAGE=1 uses the omarchy-pkg-builder image already
present instead of building it, so a workflow can build the image once
with an external BuildKit cache and fan out over package jobs that all
run the same bytes. A missing image is an error, not a silent rebuild.
OMARCHY_DEFER_RUNTIME_DEPS=true builds the omarchy/omarchy-settings pair
with --nodeps, installing only their makedepends and checkdepends
explicitly. The pair depends on each other and on packages a sharded
pipeline builds in other jobs, so they cannot resolve in isolation; the
assembled set is installed in one verified transaction downstream. The
request is refused for anything but exactly that pair, on the host
before Docker starts and again inside the container.
Also fix make_dir_writable: chown -R can succeed on part of the tree
and fail on files a previous container left behind as another uid, and
the old `|| chmod` fallback only ran when chown failed outright. Always
follow with chmod.
The Omarchy payload is architecture-independent, but the package is not.
On x86_64 omarchy pulls the Limine + mkinitcpio hook + Snapper boot stack;
on Apple Silicon the system boots through m1n1 + GRUB from the Asahi
packages on Arch Linux ARM's kernel, so that stack does not apply, and
Wi-Fi on the Broadcom parts needs the iwd backend. The shipped /etc tree
differs too: mkinitcpio reads every file under /etc/mkinitcpio.conf.d/,
so shipping omarchy_hooks.conf on aarch64 injects the Limine hooks into
the Asahi kernel's initramfs, and the zram/zswap/oomd drop-ins and the
zram-tuned vm.* sysctls belong to the x86_64 memory stack.
makepkg only honours depends_<arch> and optdepends_<arch> on
arch-specific packages, so arch=('any') becomes ('x86_64' 'aarch64').
backup=() has no arch-suffixed form, so the x86_64-only entries are
appended under CARCH and each of those paths is removed from the aarch64
package in package(). The x86_64 package keeps exactly the contents it
had; only its filename suffix changes.
The install scriptlet applies the hardened cups-files.conf on every
platform, then on Apple Silicon keeps the Arch Linux ARM system identity
(/etc/os-release stays the distribution's symlink) instead of the
etc-overrides. The -dev pair carries the same change so the pairs stay in
lockstep.
The environment-theme patches shipped as a forked AppImage while
upstream lacked them. Keeping it current means a hand-built artifact
per release, and it has fallen three behind — 0.0.35 against 0.0.38.
t3code-bin tracks the upstream feed on its own, so drop the fork.
Nothing else in the repo referenced the package.
The AUR caught up: asusctl 6.4.0-1 (b0ec6ca) repoints source at the
GitHub repo upstream, which is what our patch existed to do. The new
PKGBUILD uses a release tarball instead of git+, so the patch context
no longer matches and every scheduled Sync AUR Packages run failed
applying it.
Remove the patch and resync from the AUR. With no .omarchy/patches
left, the package is no longer customized, so it tracks 6.4.0-1
without the .1 pkgrel suffix.
Package Link Studio 1.0.2 with its AUR-only MediaPipe and sounddevice dependencies. Wire Link Studio to GitHub release checksums, keep all three packages on the fast ring, and make MediaPipe's Bazel bootstrap a checksummed makepkg source.
Tracks Perplexity's own Debian repository, the feed the app updates
itself from, via .omarchy/upstream.sh -- same shape as
openai-codex-desktop. pkgver carries the build number from the pool
filename because the index's Version field drops it and upstream
rebuilds under the same marketing version; the pool wants the '+'
percent-encoded. The launcher replaces the postinst symlink pacman
never creates and defaults Chromium to Wayland.
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.