1Password reads the display scale itself, the way Electron apps do, so
on a scaled monitor it comes up oversized next to every other window.
Pin it in the .desktop we install and let the compositor scale it.
Rewriting Exec on the way in is how spotify, perplexity and sublime-text
already fix up their entries here. Only the stable package: 1password-beta
syncs from the AUR, so a patch there would be overwritten.
Claude-Session: https://claude.ai/code/session_01JB9phxP56gnP7qSidkkUJE
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1.7.0 makes OpenSSL and libzstd hard CMake requirements; both are in
every build chroot transitively, so the sync's version-only bump in
auto/sync-upstream would have built and shipped them as undeclared
linkage rather than failing. Declare them, and pin the new optional
Wayland idle-inhibit feature on by adding wayland-protocols to
makedepends instead of leaving it to what the chroot happens to carry.
Checksum matches the release's SHA256SUMS manifest and an independent
download.
Released 06:46 UTC today, inside the quarantine window; shipped by hand
per BYPASS_MIN_RELEASE_AGE's intent. The feed's asset name matches the
one the PKGBUILD builds, the download's size and SHA-512 match the
electron-builder feed exactly (byte-identical to what the app's own
updater installs), and the SHA-256 here is from that verified download.
Release 2026.8.31-3 preserves upstream desktop settings and explicit launch environment without invoking the CLI sandbox setup. Keep incomplete runtimes from blocking the packaged fallback, and use the namespace sandbox consistently in both locations.
Co-Authored-By: Codex XHigh <noreply@openai.com>
Use the same direct executable path for menu launches and URLs, require working user namespaces, and retain only the first-update relaunch gate backport. This avoids the upstream CLI fallback that makes a helper in the user runtime setuid-root.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Track main while pinning the initial release commit. Ship the matching upstream installer and Linux namespace sandbox backport, and launch the native user build prepared by Omarchy.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Revert the native installer and updater packaging introduced by #325. Keep the prebuilt desktop and existing launcher, updating only the release tag, commit and archive checksum from the previous recipe.
0.11.2 is 14 hours old, inside the package's 24h min_release_age, so the
upstream sync would not pick it up until tomorrow; ship it now by hand.
Tarball commit b000b79 verified against the v0.11.2 tag, checksum from
an independent download. The new Cargo dependencies (ashpd, zbus,
gdk4-wayland) are vendored crates needing no new system libraries.
0.11.2 also ships FileManager1/portal integration files. Stage the
FileManager1 service under /usr/share/strata the way upstream's own
PKGBUILDs do — the app copies it per-user on opt-in. The portal files
stay unpackaged, matching upstream: enablement is per-user and
consent-gated in the app.
The package carries a deliberate commit pin (59d557a) so every
architecture packages the same tree. The AUR sync kept trying to revert
that to the unpinned branch-tip recipe, recording a version downgrade in
the process. Mark it local so exactly one source owns the recipe; it is
Omarchy-maintained until it moves to an upstream release feed.
* Bump libfprint-git for Synaptics 06cb:010b support
* Describe libfprint-git as the driver the fingerprint setup installs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: powderluv <powderluv@powderluv.org>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Keep build-time registration private, verify the published launcher, and then let the native command register the final desktop entry. Keep that launcher first on the desktop environment PATH for subsequent registrations.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Stage the initial clone before publishing its ownership marker and build the desktop through the same native CLI used by updates. Keep a concurrent checkout intact and reset pkgrel for the version change.
Co-Authored-By: Claude Opus 5 (default) <noreply@anthropic.com>
Install Hermes into its writable native layout instead of shipping a frozen /opt desktop. Preserve the native update path, migrate tagged bootstraps, and keep existing CLI launchers until the desktop is ready.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
The file-scope case on CARCH ended in 'return 1', which aborted any
'source PKGBUILD' that did not export CARCH before pkgver and pkgrel
were assigned. check-versions reads PKGBUILDs that way, saw an empty
version, queued 8.12.34-35 on every tick, and promotion then refused to
overwrite the already-published artifact. Every channel has been in
backoff since 06:41 UTC today because of it.
Package OpenClaw 2026.9.1 as a local PKGBUILD based on the AUR one,
tracking the npm registry's latest dist-tag through the repository's
declarative npm upstream provider: upstream's release cadence outruns
the AUR maintainer, and the dist-tag is the stable channel where a plain
version-max would ship next cycle's betas. A 24h min_release_age
quarantines fresh releases, which matters more than usual here because
the npm tarball is not vendored: package() resolves ~330 transitive
dependencies from the live registry without integrity pins. The pinned
sha256 was verified against the registry by hand. The initial pin was
taken inside its quarantine window through the documented
BYPASS_MIN_RELEASE_AGE maintainer path, deliberately, and lands through
this reviewed change as that path intends.
The AUR post_upgrade restart attempt is replaced with printed guidance:
it targeted a nonexistent openclaw.service, and the real
openclaw-gateway.service is a systemd user unit a root pacman hook
cannot reach (voxtype-bin sets the precedent).
The builder ships npm 12, which refuses install-time lifecycle scripts unless
the package is allow-listed, and for a local tarball the allow-list key is the
tarball's own file: spec rather than the package name. Without it openclaw's
postinstall never runs, the .openclaw-lifecycle-pending marker ships in the
package, and every invocation dies trying to finish the lifecycle inside the
root-owned /usr/lib/node_modules/openclaw. package() now passes
--allow-scripts and fails the build if the marker survives.
That postinstall also runs upstream's legacy-state migration against whatever
home it sees, so the npm call gets a scratch HOME under $srcdir with the
OPENCLAW_* location overrides unset: a maintainer's own ~/.openclaw is not
the build's to prune.
Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.
Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.
Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
Schist is a layered image editor with PSD, Affinity and camera raw support,
developed by Infrawrench and packaged by its upstream author. The package
re-wraps the pacman-format payloads Schist's release workflow publishes for
x86_64 and aarch64, so the builder does no compiling, and both assets are
pinned by SHA-256.
Releases are tracked declaratively through the GitHub upstream provider,
which gains a "digests": true mode here: a vendor that publishes no checksum
manifest can have each asset's SHA-256 read from the digest GitHub's release
API reports, so the sync never downloads the artifacts. Exactly one of
"checksums" or "digests" must be set, and the provider enforces that itself
because scheduled runs reach it without the metadata validator.
Fresh releases wait 24 hours before the scheduled sync picks them up, as
mise-bin already does. vulkan-driver is an optional dependency rather than a
hard one: makepkg -s would otherwise satisfy the virtual package with
nvidia-utils in the build container, and Omarchy installs a Vulkan driver per
machine.
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Local-first block notes with a wiki-link graph and a built-in AI research agent. Electron over a Next.js server, x86_64 only, repackaged from the vendor tarball with a Wayland launcher.
Not in the AUR. The package follows its GitHub release feed through the declarative github upstream provider, reading each release's SHA256SUMS, with a 24h min_release_age quarantine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.
package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.
Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.