Commit Graph
1095 Commits
Author SHA1 Message Date
Basti b422d37fa2 Drop privileges when seeding Dell haptic config (#497)
The root-run package hook changed ownership of paths below a
user-controlled home directory. A config symlink could redirect chown to
an arbitrary root-owned file during installation or upgrade.

Run the config writer as the target desktop user and remove the privileged
ownership changes. This also prevents the missing-config path from writing
through a user-controlled pathname as root. Add regression coverage and
bump the package release.

Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com>
Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
2026-09-18 15:24:41 +02:00
Spencer BullandCodex GPT-6 Astra xhigh f7577b59a6 Refresh Cua plugin profile for Aquamarine 0.15.1
Derive an exact Aquamarine 0.15.1-1 profile from the verified upstream kit so edge installations resolve without weakening native compatibility checks.

Co-Authored-By: Codex GPT-6 Astra xhigh <noreply@openai.com>
2026-09-18 01:34:01 -05:00
Spencer Bull 686c599f53 Merge pull request #483 from omacom/add-elsewhen
Add elsewhen, the Omarchy shell world clock plugin
2026-09-17 20:59:21 -05:00
Krzysztof Wilczyński 18433c2499 Update Linux kernel release to v7.2.5-6 for base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-18 04:18:47 +09:00
Krzysztof Wilczyński e2cea36daf Disable register zeroing on function exit for base and BORE kernels
Unset CONFIG_ZERO_CALL_USED_REGS to disable the kernel hardening
feature, allowing for older NVIDIA drivers to build successfully
against the new kernel.

Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-18 03:32:34 +09:00
Krzysztof Wilczyński 3e0cba033a Add missing patch signature files to the base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-18 03:15:43 +09:00
Ryan Hughes 1f025695d5 Build t3code-bin for aarch64 2026-09-17 13:35:33 -04:00
Spencer Bull 164e4a4f05 Merge pull request #496 from omacom/xps13-dx13260-firmware
Add linux-firmware-cirrus stable-snapshot shim for the Dell XPS 13 DX13260
2026-09-17 11:38:01 -05:00
Spencer BullandClaude Fable 5.1 afd75bc571 Add linux-firmware-cirrus stable-snapshot shim for the Dell XPS 13 DX13260
The Panther Lake XPS 13 (audio subsystem 1028:0e54) drives all of its
speakers through two CS35L56 amplifiers behind the CS42L43 codec. Their
DSP firmware aliases (cs35l56-b2-dsp1-misc-10280e54-spkid{1,2,3}) were
added to linux-firmware on 2026-08-18 and ship in Arch's
linux-firmware-cirrus 20260910-2, but the stable channel's Arch snapshot
is still on 20260810-2. Without them the amps run ROM firmware and the
machine is completely silent; upstream 7.2 already selects the sidecar
amplifier path for this SSID, so no kernel change is involved.

Ship the 20260910-2 payload to stable as a self-retiring shim:

- fast ring, no upstream watch (sync: false): the version is deliberately
  20260810-3, above the snapshot's 20260810-2 and below Arch's real
  20260910-2, so the genuine package supersedes it in the same
  transaction that upgrades linux-firmware-other once the snapshot
  advances. Bumping pkgver would defeat that.
- the signed Arch package is verified against the Arch packager key in
  keys/pgp/ and reinstalled as-is, minus the cs42l45 SDCA tree that Arch
  moved out of linux-firmware-other in 20260910: on the stable snapshot
  those 190 files are still owned by -other 20260810-2 and would
  conflict. The nine 10280e54 links and the 39 new SDCA files are kept.

Verified on a DX13260: cold boot loads 10280e54-spkid1 v4.5.9 on both
amps with "Calibration applied", and a 440 Hz tone measured through the
internal microphones peaks 238x over the noise floor on the stock UCM
bridge route. Delete this recipe once stable's snapshot carries
linux-firmware >= 20260910.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 10:58:46 -05:00
David Heinemeier Hansson 259aa68129 Add Monologue webcam recorder package (#495)
* Add Monologue webcam recorder package

* Update Monologue to latest published source
2026-09-17 11:36:14 -04:00
David Heinemeier HanssonandClaude Fable 5.1 750eb611f5 Update herdr to 0.9.1 with Zig 0.16.0 for the vendored libghostty-vt (#493)
Upstream 0.9.1 bumps vendored libghostty-vt's minimum_zig_version to
0.16.0, so the pinned Zig tarballs move from 0.15.2 to 0.16.0 with
checksums taken from ziglang.org's download index.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 15:54:55 +02:00
Ryan Hughes 1beee4695b Package Flea 0.3.0 phone backends and shelf 2026-09-17 09:34:56 -04:00
dhh 1bce595733 chore: sync upstream releases 2026-09-17 11:54:13 +00:00
github-actions[bot]anddhh afcd481422 chore: sync upstream releases (#481)
Co-authored-by: dhh <2741+dhh@users.noreply.github.com>
2026-09-17 13:20:13 +02:00
OmarchybotandClaude Opus 5 ce33f28414 Match flea's O_NOFOLLOW fix by behaviour, not by spelling (#488)
Upstream sync has failed on every run since flea v0.3.0 was published, with
"Release v0.3.0 does not contain every required upstream security fix". Eight
of the nine required fixes are present. The ninth is too: the check is wrong.

The check pinned the literal call `regfile::open_if_regular(src, O_NOFOLLOW)`.
v0.3.0 introduced directory-relative opens and the first argument became
`src.at`. O_NOFOLLOW is still passed to the same function, on the same line,
under the same comment, and the release hardened symlink handling further --
it added copy_symlink_at, opens directories with O_DIRECTORY | O_NOFOLLOW, and
reaches every child through this process's own descriptor. The guard refused a
release that is strictly safer than the one it accepted.

The property worth asserting is that the copy opens its source with
O_NOFOLLOW, so a symlink swapped in cannot redirect the read. Pinning the
exact expression asserted the spelling instead, which is why a rename read as
a removed fix. The check now matches the call and the flag together.

Verified against the real archives rather than by inspection:

  v0.3.0 (src.at, O_NOFOLLOW)      accepted
  v0.2.1 (src, O_NOFOLLOW)         accepted, so the change is backwards
                                   compatible with what is packaged today
  first argument renamed           accepted
  extra flag or argument added     accepted
  O_NOFOLLOW dropped               refused
  call replaced with File::open    refused
  flag left only in a comment      refused

End to end with the real feed: the hook on master exits 1 with the refusal,
and with this change exits 0 and reports 0.3.0 with its verified checksum.
The other eight literals are untouched.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-17 12:40:45 +02:00
Krzysztof Wilczyński 99b8005e73 Update Linux kernel release to v7.2.5-5 for base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-17 18:39:05 +09:00
Krzysztof Wilczyński d06bf4660a Add small AMD Zen 5 TLB sizes display fix to base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-17 18:32:22 +09:00
Krzysztof Wilczyński 1b8e0f3845 Use -O3 build optimization flag for base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-17 18:25:54 +09:00
Spencer Bull 52cba6cd95 Merge pull request #447 from jacob-vincent-mink/feature/omawake-omaspeak-rc
Add Omawake and Omaspeak to edge
2026-09-17 00:05:59 -05:00
Spencer BullandClaude Fable 5.1 c2f2345f0d Put Omawake and Omaspeak on the fast release ring
A channels list of edge alone is the outer bound on where a package may build, so both packages were refused for rc and stable and could only ever reach edge users. The fast ring builds them natively for all three channels, each against its own base mirror, which is how the other prebuilt -bin applications here ship. The channels key has to go rather than sit beside the ring: package_builds_for_mirror checks it first, so an edge-only list would still block the rc and stable builds the ring asks for.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 23:47:49 -05:00
Krzysztof Wilczyński f5c9441888 Add fix for swapped-out TTM resources never leaving their bulk_move range
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-17 08:54:42 +09:00
Spencer Bull 56eced522e Add elsewhen, the Omarchy shell world clock plugin 2026-09-16 13:17:37 -05:00
b836c23037 Declare the licenses of the bundled audio.cpp provider
Each package ships libaudiocpp, which upstream's own third-party notices describe as Apache-2.0 with BSD-3-Clause PocketFFT-derived code retained in it, and installs those texts under /usr/share/licenses. A license array of MIT alone describes only the project's own source, so pacman -Qi misreports what the package contains.

Co-Authored-By: GPT-6 Astra XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 11:10:50 -05:00
Spencer BullandClaude Fable 5.1 6ea162d2a4 Turn off debug packaging alongside !strip
The builder's makepkg.conf enables debug and emptydirs. With strip off, makepkg still takes the debug branch of tidy_strip, creates usr/src/debug/<pkgbase> inside the package to hold debug sources, finds none in a prebuilt tree, and emptydirs then ships the empty directory to every user. Seven of the ten -bin packages here that disable strip already disable debug with it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 11:10:50 -05:00
Spencer BullandClaude Fable 5.1 10a451abc7 Drop the .SRCINFO and .gitignore files the repository ignores
The top-level .gitignore excludes pkgbuilds/*/.SRCINFO and pkgbuilds/*/.gitignore, and none of the packages under pkgbuilds/ tracks either. These four were added under the retired pkgbuilds/edge/ path, which that rule does not cover, and the move to pkgbuilds/ carried them along as already-tracked files. The per-package .gitignore negates the repository rule for its own directory and its leading * hides every future file there, so a patch or an .omarchy/upstream.sh dropped beside the PKGBUILD would never show up in git status. The build planner reads PKGBUILD and .omarchy/package.json; the only other reader, bin/package-worktree, takes .SRCINFO as a fallback while importing from the AUR and then removes both files as AUR-only.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 11:10:50 -05:00
dhh 97871759bb chore: sync upstream releases 2026-09-16 11:50:57 +00:00
Krzysztof Wilczyński 42f3afd142 Merge pull request #475 from kwilczynski/feature/update-kernel-releases
Update Linux kernel release to v7.2.5-4 for base and BORE kernels
2026-09-16 14:19:01 +09:00
Krzysztof Wilczyński e95c6f37de Update Linux kernel release to v7.2.5-4 for base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-16 14:08:43 +09:00
Spencer Bull 1f5b7a0a30 Merge pull request #473 from spencerbull/cua-agent-keymap-remaps
Preserve user keyboard remaps in the Cua Hyprland plugin
2026-09-16 00:08:36 -05:00
Spencer Bull b2176d5cab Preserve Num Lock during compatible Cua foreground input 2026-09-15 23:55:59 -05:00
Krzysztof Wilczyński b9a3863787 Add Android Binder support back to the base and BORE kernels
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
2026-09-16 13:39:52 +09:00
Spencer BullandCodex XHigh f868f3c767 Preserve user keymaps in the Cua Hyprland plugin
Give background agent seats independent keymaps and check foreground keyboard compatibility per operation. Package the downstream patch with separate source integrity and build provenance, retaining the upstream ABI verifier.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-15 23:05:22 -05:00
Ryan Hughes 3c671736ec Put Ghostty on the fast release ring 2026-09-15 22:21:52 -04:00
Jacob Mink 46306a12eb Package Omawake 0.0.2 and Omaspeak 0.0.1 2026-09-15 16:09:13 -05:00
Ryan Hughes 5fe2367366 Release omarchy 4.0.4 2026-09-15 17:07:20 -04:00
Ryan Hughes edc411ae4d Build Ghostty for x86_64 with pinned Zig toolchain 2026-09-15 16:13:12 -04:00
Ryan Hughes b27f3fe62e Merge pull request #453 from scottjones/contrib/ghostty-aarch64
Build stable Ghostty and its split packages for aarch64
2026-09-15 12:29:03 -07:00
Ryan Hughes eeb137e055 Merge pull request #452 from scottjones/contrib/obs-aarch64
Add OBS Studio for aarch64 without the CEF browser plugin
2026-09-15 12:28:21 -07:00
Ryan Hughes 5b8ef2617a Merge pull request #450 from scottjones/contrib/pinta-aarch64
Add Pinta and its .NET 10 dependencies for aarch64
2026-09-15 12:27:13 -07:00
Ryan Hughes 7275574e77 Merge pull request #448 from scottjones/contrib/grok-bot-aarch64
Build Grok Bot 0.47.0 for aarch64 and fix desktop packaging
2026-09-15 12:19:25 -07:00
Jacob Mink 977e1c57ea Update Omawake to v0.0.1-rc.3 2026-09-15 14:06:38 -05:00
Jacob Mink f5b29f16e3 Update Omaspeak to v0.0.1-rc.3 2026-09-15 13:57:15 -05:00
Jacob Mink 4a5696c134 Support both Oma release architectures 2026-09-15 13:48:22 -05:00
Jacob Mink 55c564968c Update Oma apps to v0.0.1-rc.2 2026-09-15 13:46:55 -05:00
Spencer BullandGPT-6 Astra XHigh 9807177337 Register speech packages with the current edge builder
The builder discovers package directories directly under pkgbuilds and requires local package metadata. Move Omawake and Omaspeak out of the retired edge directory and restrict their channels to edge so the release pipeline builds them without promoting the release candidates.

Co-Authored-By: GPT-6 Astra XHigh <noreply@openai.com>
2026-09-15 13:46:55 -05:00
Jacob Mink e15d4aa61e Add Omawake and Omaspeak edge packages 2026-09-15 13:46:55 -05:00
dhh 1a40508b48 chore: sync upstream releases 2026-09-15 17:10:15 +00:00
Scott Jones c17a46e404 Use the MbedTLS CMake configuration for OBS 2026-09-15 08:16:34 -04:00
Scott Jones 5371afbbb3 Simplify Pinta packaging with the upstream release tarball 2026-09-15 08:16:34 -04:00
Ryan Hughes 34accaef7f Merge pull request #454 from omacom/fix/dkms-omarchy-headers
Remove kernel header dependencies from DKMS packages
2026-09-14 22:32:20 -07:00