A package's .omarchy/package.json may now pin where it lives with
"channels": [...]. With the key present the package builds in each listed
channel except stable (stable is only fed by promotion); without it, today's
defaults hold (build for edge; fast-ring also builds stable directly).
package_moves_to_channel() is the advance/promote eligibility rule: a member
of the destination channel that is not built there natively.
The release pair (omarchy, omarchy-settings) is edge+rc+stable — edge stays
during the client-migration overlap window and drops later. The dev pair is
pinned to edge only.
- helpers/paths.sh: validate_mirror/require_valid_mirror for the edge|rc|stable
set, and REPO_ROOT (OMARCHY_REPO_ROOT override) so a secondary checkout like
the rc branch worktree publishes into the same channel tree as the primary
- validate --mirror everywhere it previously accepted any string (sync-repo,
promote-build, update-repo, clean-repo, remove-package) and widen the
edge|stable checks in build, deploy, push-build, auto-release
- build/Dockerfile: rc builds compile against rc-mirror.omarchy.org
GNU date accepts relative expressions like '2 days ago', which would let a
buggy hook fabricate a release age; the backstop now insists on an ISO 8601
timestamp before date parses it. The provider header now states, rather than
contradicts, the code's behavior for a feed with no stable releases: that is
a loud failure by design, while quarantined releases report no update.
An empty min_release_age string now maps to unparseable rather than absent,
so "min_release_age": "" fails validation instead of silently running
with a zero-second quarantine. The end-to-end fixtures extend the
checked-in pkgver (.90/.91) so the test keeps working at any future mise
version. A Tests workflow runs bin/sync-upstream self-test and
bin/omarchy-pkgs self-test on every PR in the Arch container, making the
proof machine-checked instead of author-supplied. The README package
metadata field list documents upstream and min_release_age.
The self-test now runs sync_package over the checked-in mise-bin package --
its real metadata and PKGBUILD, the full selection/validation/backstop/
rewrite/read-back path -- with only the two network fetches replaced by
mise-shaped fixtures, asserting the final PKGBUILD holds the quarantine-
cleared version, pkgrel 1, and both architecture checksums.
Review fixes: the release-row builder uses "" fallbacks instead of empty
so a malformed row cannot shift columns past the per-field checks, and
provider discovery now keys on the presence of an upstream declaration
rather than a well-formed one, with sync_package failing loudly on a
declaration it cannot use -- a malformed manifest can no longer silently
drop a package out of scheduled synchronization.
bin/sync-upstream self-test swaps the two network fetches in
helpers/upstream-github.sh for fixture readers and runs the production code
paths: fallback past a quarantined release, draft/prerelease filtering, the
deliberate bypass, unchanged-version and all-quarantined no-update paths,
unusable tags/timestamps and missing checksums failing the sync, {tag} and
{pkgver} asset templates with ./ and * manifest prefixes across both
architectures, the min_release_age backstop verdicts (now a testable
release_age_status function), the duration parser, and manifest validation.
Also fixes from the review: the duration parser forces base-10 arithmetic
(leading zeros no longer parse as octal) and bounds values to nine digits so
no suffix can overflow; jq // treating false as absent can no longer let
"min_release_age": false or "upstream": false slip through as unset; the
release feed page grew to the API maximum of 100 with the bounded search
documented; and the README package-metadata section documents the upstream
block, min_release_age, the bypass, and provider-versus-hook exclusivity.
After the quarantine moved into the manifest, all mise-bin's hook still knew
was data: the repository, the checksum manifest name, and the asset filename
patterns. That now lives in .omarchy/package.json as an upstream block --
"upstream": {
"github": "jdx/mise",
"checksums": "SHASUMS256.txt",
"assets": { "x86_64": "mise-{tag}-linux-x64.tar.xz", ... }
}
-- handled by helpers/upstream-github.sh inside bin/sync-upstream. The
provider walks the release feed (drafts/prereleases excluded), honors
min_release_age and BYPASS_MIN_RELEASE_AGE during selection, reports
published_at so the framework backstop still applies, fails closed on any
unreadable tag or timestamp, and skips the checksum fetch when the newest
qualifying release is already checked in.
upstream.sh remains the escape hatch for feeds that fit no convention
(openai-codex-desktop's Debian index, tmog's version.txt, t3code's
electron-builder manifest); declaring both is an error.
Move the hold from a mise-only hardcode to min_release_age in
.omarchy/package.json ("24h", "2d", or bare seconds), alongside source and
release_ring where package policy already lives. bin/sync-upstream exports
the window to every hook as MIN_RELEASE_AGE_SECONDS so a hook that can walk
its release feed selects the newest release that has cleared it, and
enforces it as a backstop: with a policy set, the hook must report
published_at, and a release younger than the window is treated as no
update. A hook that cannot prove the age fails the sync rather than
shipping unverified. BYPASS_MIN_RELEASE_AGE=1 replaces the package-specific
bypass for deliberate emergency updates; scheduled automation never sets it.
The mise hook keeps its release-list walk but reads the window from the
environment and reports published_at; the other upstream hooks are
untouched and unaffected until they opt in.
Gating on /releases/latest alone starves updates when mise's near-daily
cadence keeps the newest release perpetually inside the quarantine window:
today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past
24 hours. Walk the release list (drafts and prereleases excluded) and pick
the newest release, by vercmp, whose published_at is at least 24 hours old.
The quarantine guarantee is unchanged: nothing younger than the window ever
ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid
tags or timestamps still fail closed - now for every release in the feed,
plus a hard failure if the feed reports no stable releases at all.
Pin the official Linux .deb to Cursor stable 0.24.0 (commit 302d75da).
Upstream renamed the binary sand -> grok-bot and ships grok-bot icons
and a grokbot:// handler; keep a Wayland wrapper and /usr/bin/sand compat
symlink.
Linux still has no update feed. Leave pinning to update-pkgver.sh rather
than a sync-upstream hook, which cannot atomically rewrite _commit.
TMOG ships no source and no AUR package, so this repackages the vendor's
Linux tarball. That artifact is 7.9 MB against the system Qt, where the
AppImage is 55 MB carrying a second copy of the Qt the shell already
installs.
Every release is served from one versionless URL, so .omarchy/upstream.sh
reads /version.txt, computes the checksum from the artifact, and checks
the tarball's own directory name to confirm the mutable path really
served the version it announced.
The beta licence forbids public redistribution, so publishing this needs
the publisher's permission; .omarchy/README.md records that.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011K4ra2oZTtzUQZJ2kwP3io
Tidying the terminal agent's Hermes away only happened in the menu installer,
so `pacman -S hermes-desktop` on its own, or an install interrupted after the
package landed, left two Hermeses -- and by then the menu entry that would
have noticed is disabled, because we are installed.
Co-Authored-By: Codex XHigh <noreply@openai.com>
The package built from omacom-io/herdr, a fork pinned to a commit and versioned 0.8.0.r13. Its only divergence was three commits replaying an agent's CLI options when a session resumed, which upstream declined twice — from a contributor in herdrdev/herdr#2036 and from us in herdrdev/herdr#2614, closed in favour of an agent resume manifest meant to supersede it. Those three are dropped; every other commit the fork carried is in v0.8.2.
The fork also self-reported "0.8.0" while speaking wire protocol 20, which upstream's published 0.8.0 did not: it spoke 19. An official client attaching to an Omarchy host therefore saw a server claiming to be its own version yet refusing to talk to it, and offered to stop it without ever naming the protocol. That is omacom-io/omarchy-pkgs#161.
Upstream released v0.8.2 today, and it settles both halves. It carries protocol 20, and the stable manifest now publishes 0.8.2 at protocol 20, so an official client and this package agree. It also contains the five features Omarchy contributed after the v0.8.0 tag — configurable outer pane borders, direct pane resize keybindings, move tab keybind actions, centered tab labels and outer terminal window title sync — which is what made packaging the earlier release a regression rather than a return to upstream.
Because the build is now the release it claims to be, it needs no build-identity marking: HERDR_BUILD_CHANNEL and HERDR_BUILD_ID are gone, and the binary reports a bare 0.8.2. The package name is unchanged, so nothing needs a rename, a migration or a database removal to reach existing installs; 0.8.2-1 simply supersedes 0.8.0.r13-1.
🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.
apply_pkgrel_override compares the checked-in pkgver against the incoming one to decide whether Omarchy's pkgrel metadata has gone stale, but read the two sides differently: previous_pkgver came from get_pkgbuild_field, which strips quotes, while current_pkgver was parsed again in place and kept them. A PKGBUILD writing pkgver='1.0' therefore compared unequal to itself, and the pkgrel metadata of an unchanged package was deleted on every sync.
spotify, rustdesk and limine-mkinitcpio-hook all quote pkgver. None carries pkgrel metadata today, so nothing has been losing a suffix, but rebuild_on writes exactly that metadata and would have had it thrown away on the next sync.
Reading through the same accessor rather than parsing a second time removes the divergence instead of correcting one side of it.
🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.
Co-Authored-By: Codex XHigh <codex@openai.com>
A review at xhigh found several ways this command could report success while delivering nothing, which is the exact failure it exists to prevent.
A trigger named in rebuild_on but missing from rebuilt_against was never examined, because the comparison walked the record rather than the declared list. Adding a dependency to a package already opted in left that dependency untracked forever. The comparison now walks the declared triggers, so a name the record does not carry reads as changed.
That also retires the separate baseline path. Recording a package's triggers without bumping pkgrel certified a build nobody had checked: a package already broken by a release that moved before it opted in would be recorded as current and never rebuilt. Opting in now costs one rebuild, which is much the cheaper mistake.
A bumped version was only checked against the checked-in one. The floor is what users already have, so a checkout that had fallen behind the repository could be bumped to a version pacman orders below the package it means to replace, with the record advancing regardless. The published database is now the floor, and an unreadable one warns rather than blocks.
Metadata that did not parse dropped its package out of an unscoped run without a word, an unreadable rebuild_on being indistinguishable from an absent one. It is now reported and fails the run.
The workflow reads versions from mirror.omarchy.org, the mirror the x86_64 builder itself uses, rather than whichever mirror the container defaulted to. A mirror running ahead of the builder would record a version the build never linked against, and nothing re-fires once the record matches.
aarch64 stays uncovered and is documented as such: those builds resolve from Arch Linux ARM, one record cannot describe two architectures, and only x86_64 is published today.
bin/sync-rebuilds --self-test covers each of these against a throwaway repository root with pacman and curl stubbed.
🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.
Co-Authored-By: Codex XHigh <codex@openai.com>
Arch shipped qt6-base 6.11.2-2 on 2026-08-20, and the published 0.3.0.r20.g28771c7-1, built against 6.11.1, stopped starting: undefined symbol _ZN23QUntypedPropertyBindingC1EP23QPropertyBindingPrivate, version Qt_6_PRIVATE_API. quickshell-check.hook caught it post-transaction, but detecting is all it does, so pacman logged the failure and omarchy-update-restart went on to restart a shell whose binary could no longer launch.
The git rev has not moved, so the rebuild only reaches anyone through a pkgrel bump. rebuild_on names the three Qt packages quickshell actually links against: qt6-base for Core, Gui, Widgets, Network, DBus and OpenGL, qt6-declarative for Quick and the Qml libraries, qt6-wayland for WaylandClient. rebuilt_against is seeded with the versions this rebuild will link against, so bin/sync-rebuilds starts from a correct baseline and fires on the next Qt release rather than repeating this one.
🤖 Generated by Opus 5 in Claude Code.