virtiofsd sat in the common optdepends, so aarch64 still advertised one third of a Cowork stack the package deliberately promises nothing else of there. It joins qemu and the firmware in optdepends_x86_64, and the virtiofsd shim moves under the same branch, so an aarch64 package carries no Cowork pieces at all.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
The app probes Debian's paths for its VM stack: /usr/libexec/virtiofsd then /usr/bin/virtiofsd, and /usr/share/OVMF/OVMF_CODE_4M.fd with the VARS path derived from it. Arch ships virtiofsd at /usr/lib/virtiofsd and the firmware at /usr/share/edk2/x64/OVMF_CODE.4m.fd, so installing the advertised optdepends still left Cowork reporting QEMU missing. Symlinks at the probed paths map them onto Arch's; the app's probe reads through them, they dangle harmlessly until the optdepends arrive, and /usr/libexec keeps the virtiofsd link out of $PATH while it does.
The firmware optdepend moves into optdepends_x86_64, and aarch64 loses its Cowork optdepends entirely: the aarch64 builds run against Arch Linux ARM, which ships no UEFI firmware package at all, so both the edk2 name and the qemu-system-aarch64 entry promised a VM that cannot boot there.
The embedded Claude Code diagnoses missing sandbox dependencies when bubblewrap and socat are absent; they join the optdepends under the same wording as the standalone claude-code package.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
Feed GitHub release pages to jq through stdin so real pages do not exceed Linux argument limits. Generate an oversized fixture response in the curl mock, and run hook fixtures against a temporary pinned PKGBUILD so routine package updates do not break repository self-tests.
Co-Authored-By: Codex GPT-6 XHigh <noreply@openai.com>
Anthropic ships the Claude desktop app for Linux only through its own
Debian repository, so the package repacks the deb the way
openai-codex-desktop does: extract data.tar.xz, replace the bare
/usr/bin symlink with a launcher that asks Chromium for Wayland
directly, and keep the vendor copyright as the license.
Updates come through the declarative "debian" upstream provider: the
apt Packages index names the newest version, and the per-architecture
pool debs are hashed when one appears. Verified by pinning 1.44121.2
and watching bin/sync-upstream rewrite it back to 1.46388.2
byte-identically.
Build on #306 without replacing its package or updater workaround. Exhaust the component feed before selecting a release and cover quarantine, version ordering, invalid input, and transport failures with offline fixtures.
Incremental advances collide with same-version artifacts that reached the
destination through another lineage — the stable -> rc bootstrap seed and
native rc builds are not byte-identical to edge's builds of the same
version. A collision means the package has not moved in the source since,
so keep the destination's published copy and continue; the hard failure
also aborted before the db rebuild and sync, leaving the advance half-done.
Also stop advancing pinned packages into rc: eligibility deferred to
package_builds_for_mirror, whose OMARCHY_RC_PINS gate is never set during
an advance, so edge's omarchy/omarchy-settings looked movable — and could
have overtaken an in-flight RC pin under a fresh filename.
1Password reads the display scale itself, the way Electron apps do, so
on a scaled monitor it comes up oversized next to every other window.
Pin it in the .desktop we install and let the compositor scale it.
Rewriting Exec on the way in is how spotify, perplexity and sublime-text
already fix up their entries here. Only the stable package: 1password-beta
syncs from the AUR, so a patch there would be overwritten.
Claude-Session: https://claude.ai/code/session_01JB9phxP56gnP7qSidkkUJE
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1.7.0 makes OpenSSL and libzstd hard CMake requirements; both are in
every build chroot transitively, so the sync's version-only bump in
auto/sync-upstream would have built and shipped them as undeclared
linkage rather than failing. Declare them, and pin the new optional
Wayland idle-inhibit feature on by adding wayland-protocols to
makedepends instead of leaving it to what the chroot happens to carry.
Checksum matches the release's SHA256SUMS manifest and an independent
download.
Released 06:46 UTC today, inside the quarantine window; shipped by hand
per BYPASS_MIN_RELEASE_AGE's intent. The feed's asset name matches the
one the PKGBUILD builds, the download's size and SHA-512 match the
electron-builder feed exactly (byte-identical to what the app's own
updater installs), and the SHA-256 here is from that verified download.
Release 2026.8.31-3 preserves upstream desktop settings and explicit launch environment without invoking the CLI sandbox setup. Keep incomplete runtimes from blocking the packaged fallback, and use the namespace sandbox consistently in both locations.
Co-Authored-By: Codex XHigh <noreply@openai.com>
Use the same direct executable path for menu launches and URLs, require working user namespaces, and retain only the first-update relaunch gate backport. This avoids the upstream CLI fallback that makes a helper in the user runtime setuid-root.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Track main while pinning the initial release commit. Ship the matching upstream installer and Linux namespace sandbox backport, and launch the native user build prepared by Omarchy.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Revert the native installer and updater packaging introduced by #325. Keep the prebuilt desktop and existing launcher, updating only the release tag, commit and archive checksum from the previous recipe.
0.11.2 is 14 hours old, inside the package's 24h min_release_age, so the
upstream sync would not pick it up until tomorrow; ship it now by hand.
Tarball commit b000b79 verified against the v0.11.2 tag, checksum from
an independent download. The new Cargo dependencies (ashpd, zbus,
gdk4-wayland) are vendored crates needing no new system libraries.
0.11.2 also ships FileManager1/portal integration files. Stage the
FileManager1 service under /usr/share/strata the way upstream's own
PKGBUILDs do — the app copies it per-user on opt-in. The portal files
stay unpackaged, matching upstream: enablement is per-user and
consent-gated in the app.
The package carries a deliberate commit pin (59d557a) so every
architecture packages the same tree. The AUR sync kept trying to revert
that to the unpinned branch-tip recipe, recording a version downgrade in
the process. Mark it local so exactly one source owns the recipe; it is
Omarchy-maintained until it moves to an upstream release feed.