* Bump libfprint-git for Synaptics 06cb:010b support
* Describe libfprint-git as the driver the fingerprint setup installs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: powderluv <powderluv@powderluv.org>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
makepkg always exports CARCH, so PKGBUILDs may branch on it at file
scope. Every place the tooling sourced a PKGBUILD did so without CARCH,
taking the wrong branch or aborting partway, and check-versions turned
the resulting empty pkgver/pkgrel into the version '-', which never
matches a published version and queues an endless rebuild.
package_pkgbuild_var reads one variable the way makepkg would see it,
for the architecture being checked, and reports whether the source
succeeded. check-versions, sync-rebuilds and omarchy-pkgs use it.
check-versions now warns and skips a package whose pkgver or pkgrel is
empty instead of comparing a partial version. A self-test covers a
PKGBUILD that branches on CARCH before assigning its version.
The file-scope case on CARCH ended in 'return 1', which aborted any
'source PKGBUILD' that did not export CARCH before pkgver and pkgrel
were assigned. check-versions reads PKGBUILDs that way, saw an empty
version, queued 8.12.34-35 on every tick, and promotion then refused to
overwrite the already-published artifact. Every channel has been in
backoff since 06:41 UTC today because of it.
Arch Linux ARM's makepkg.conf defaults PKGEXT to .pkg.tar.xz. build/sign.sh
only signs *.pkg.tar.zst, and push-build, sync-rebuilds and the notifier
parse the same suffix, so an aarch64 package built under the stacked
pipeline came out as .xz and would have been skipped at signing. Seen on a
plain x86_64 runner building aarch64 under QEMU (fork run 33642125077).
Same fix as the PKGEXT line in #240.
One list, PUBLISHED_ARCHES in helpers/paths.sh (default x86_64,
overridable with OMARCHY_ARCHES), now drives everything the repository
host schedules. check-versions compares PKGBUILDs against each
architecture's channel databases and writes one queue per channel and
architecture; auto-release works through the queues one architecture at
a time, each with its own backoff, so a failing build on one never
blocks the other; advance-channel --arch all re-runs an advance for every
published architecture and omarchy-release uses it for start and ship,
building the pinned pair once per architecture in its rc trigger; the
train observes channels through the reference (first) architecture
instead of a hard-coded x86_64. Queue and backoff files written under
the old per-channel names are treated as x86_64 until consumed.
Two things made an aarch64 builder image impossible to create: the
keyring bootstrap fetched omarchy-keyring from the target architecture's
own channel tree, which does not exist before that architecture has
published anything, and the QEMU probe only knew the x86_64-host,
aarch64-target case. The keyring (arch=any) now always comes from the
x86_64 tree, and the probe compares host and target architectures and
runs a container for the target platform.
clean-repo grouped versions with a regex that only knew any, x86_64 and
i686, so aarch64 packages would never have been pruned.
Package OpenClaw 2026.9.1 as a local PKGBUILD based on the AUR one,
tracking the npm registry's latest dist-tag through the repository's
declarative npm upstream provider: upstream's release cadence outruns
the AUR maintainer, and the dist-tag is the stable channel where a plain
version-max would ship next cycle's betas. A 24h min_release_age
quarantines fresh releases, which matters more than usual here because
the npm tarball is not vendored: package() resolves ~330 transitive
dependencies from the live registry without integrity pins. The pinned
sha256 was verified against the registry by hand. The initial pin was
taken inside its quarantine window through the documented
BYPASS_MIN_RELEASE_AGE maintainer path, deliberately, and lands through
this reviewed change as that path intends.
The AUR post_upgrade restart attempt is replaced with printed guidance:
it targeted a nonexistent openclaw.service, and the real
openclaw-gateway.service is a systemd user unit a root pacman hook
cannot reach (voxtype-bin sets the precedent).
The builder ships npm 12, which refuses install-time lifecycle scripts unless
the package is allow-listed, and for a local tarball the allow-list key is the
tarball's own file: spec rather than the package name. Without it openclaw's
postinstall never runs, the .openclaw-lifecycle-pending marker ships in the
package, and every invocation dies trying to finish the lifecycle inside the
root-owned /usr/lib/node_modules/openclaw. package() now passes
--allow-scripts and fails the build if the marker survives.
That postinstall also runs upstream's legacy-state migration against whatever
home it sees, so the npm call gets a scratch HOME under $srcdir with the
OPENCLAW_* location overrides unset: a maintainer's own ~/.openclaw is not
the build's to prune.
Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.
Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.
Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
Schist is a layered image editor with PSD, Affinity and camera raw support,
developed by Infrawrench and packaged by its upstream author. The package
re-wraps the pacman-format payloads Schist's release workflow publishes for
x86_64 and aarch64, so the builder does no compiling, and both assets are
pinned by SHA-256.
Releases are tracked declaratively through the GitHub upstream provider,
which gains a "digests": true mode here: a vendor that publishes no checksum
manifest can have each asset's SHA-256 read from the digest GitHub's release
API reports, so the sync never downloads the artifacts. Exactly one of
"checksums" or "digests" must be set, and the provider enforces that itself
because scheduled runs reach it without the metadata validator.
Fresh releases wait 24 hours before the scheduled sync picks them up, as
mise-bin already does. vulkan-driver is an optional dependency rather than a
hard one: makepkg -s would otherwise satisfy the virtual package with
nvidia-utils in the build container, and Omarchy installs a Vulkan driver per
machine.
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Local-first block notes with a wiki-link graph and a built-in AI research agent. Electron over a Next.js server, x86_64 only, repackaged from the vendor tarball with a Wayland launcher.
Not in the AUR. The package follows its GitHub release feed through the declarative github upstream provider, reading each release's SHA256SUMS, with a 24h min_release_age quarantine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.
package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.
Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.
The recipe fetched the branch tip, so a rebuild on another architecture
could package a different tree than the one already published. Pin the
source to a commit and set pkgver to what that commit describes
(1.22.0.r96.g0331510, as an aarch64 build of it reports); bump both
together from now on.