* Bump libfprint-git for Synaptics 06cb:010b support
* Describe libfprint-git as the driver the fingerprint setup installs
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: powderluv <powderluv@powderluv.org>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
The file-scope case on CARCH ended in 'return 1', which aborted any
'source PKGBUILD' that did not export CARCH before pkgver and pkgrel
were assigned. check-versions reads PKGBUILDs that way, saw an empty
version, queued 8.12.34-35 on every tick, and promotion then refused to
overwrite the already-published artifact. Every channel has been in
backoff since 06:41 UTC today because of it.
Package OpenClaw 2026.9.1 as a local PKGBUILD based on the AUR one,
tracking the npm registry's latest dist-tag through the repository's
declarative npm upstream provider: upstream's release cadence outruns
the AUR maintainer, and the dist-tag is the stable channel where a plain
version-max would ship next cycle's betas. A 24h min_release_age
quarantines fresh releases, which matters more than usual here because
the npm tarball is not vendored: package() resolves ~330 transitive
dependencies from the live registry without integrity pins. The pinned
sha256 was verified against the registry by hand. The initial pin was
taken inside its quarantine window through the documented
BYPASS_MIN_RELEASE_AGE maintainer path, deliberately, and lands through
this reviewed change as that path intends.
The AUR post_upgrade restart attempt is replaced with printed guidance:
it targeted a nonexistent openclaw.service, and the real
openclaw-gateway.service is a systemd user unit a root pacman hook
cannot reach (voxtype-bin sets the precedent).
The builder ships npm 12, which refuses install-time lifecycle scripts unless
the package is allow-listed, and for a local tarball the allow-list key is the
tarball's own file: spec rather than the package name. Without it openclaw's
postinstall never runs, the .openclaw-lifecycle-pending marker ships in the
package, and every invocation dies trying to finish the lifecycle inside the
root-owned /usr/lib/node_modules/openclaw. package() now passes
--allow-scripts and fails the build if the marker survives.
That postinstall also runs upstream's legacy-state migration against whatever
home it sees, so the npm call gets a scratch HOME under $srcdir with the
OPENCLAW_* location overrides unset: a maintainer's own ~/.openclaw is not
the build's to prune.
Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.
Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.
Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
Schist is a layered image editor with PSD, Affinity and camera raw support,
developed by Infrawrench and packaged by its upstream author. The package
re-wraps the pacman-format payloads Schist's release workflow publishes for
x86_64 and aarch64, so the builder does no compiling, and both assets are
pinned by SHA-256.
Releases are tracked declaratively through the GitHub upstream provider,
which gains a "digests": true mode here: a vendor that publishes no checksum
manifest can have each asset's SHA-256 read from the digest GitHub's release
API reports, so the sync never downloads the artifacts. Exactly one of
"checksums" or "digests" must be set, and the provider enforces that itself
because scheduled runs reach it without the metadata validator.
Fresh releases wait 24 hours before the scheduled sync picks them up, as
mise-bin already does. vulkan-driver is an optional dependency rather than a
hard one: makepkg -s would otherwise satisfy the virtual package with
nvidia-utils in the build container, and Omarchy installs a Vulkan driver per
machine.
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Local-first block notes with a wiki-link graph and a built-in AI research agent. Electron over a Next.js server, x86_64 only, repackaged from the vendor tarball with a Wayland launcher.
Not in the AUR. The package follows its GitHub release feed through the declarative github upstream provider, reading each release's SHA256SUMS, with a 24h min_release_age quarantine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.
package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.
Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.
The recipe fetched the branch tip, so a rebuild on another architecture
could package a different tree than the one already published. Pin the
source to a commit and set pkgver to what that commit describes
(1.22.0.r96.g0331510, as an aarch64 build of it reports); bump both
together from now on.
The Omarchy payload is architecture-independent, but the package is not.
On x86_64 omarchy pulls the Limine + mkinitcpio hook + Snapper boot stack;
on Apple Silicon the system boots through m1n1 + GRUB from the Asahi
packages on Arch Linux ARM's kernel, so that stack does not apply, and
Wi-Fi on the Broadcom parts needs the iwd backend. The shipped /etc tree
differs too: mkinitcpio reads every file under /etc/mkinitcpio.conf.d/,
so shipping omarchy_hooks.conf on aarch64 injects the Limine hooks into
the Asahi kernel's initramfs, and the zram/zswap/oomd drop-ins and the
zram-tuned vm.* sysctls belong to the x86_64 memory stack.
makepkg only honours depends_<arch> and optdepends_<arch> on
arch-specific packages, so arch=('any') becomes ('x86_64' 'aarch64').
backup=() has no arch-suffixed form, so the x86_64-only entries are
appended under CARCH and each of those paths is removed from the aarch64
package in package(). The x86_64 package keeps exactly the contents it
had; only its filename suffix changes.
The install scriptlet applies the hardened cups-files.conf on every
platform, then on Apple Silicon keeps the Arch Linux ARM system identity
(/etc/os-release stays the distribution's symlink) instead of the
etc-overrides. The -dev pair carries the same change so the pairs stay in
lockstep.
The environment-theme patches shipped as a forked AppImage while
upstream lacked them. Keeping it current means a hand-built artifact
per release, and it has fallen three behind — 0.0.35 against 0.0.38.
t3code-bin tracks the upstream feed on its own, so drop the fork.
Nothing else in the repo referenced the package.
The AUR caught up: asusctl 6.4.0-1 (b0ec6ca) repoints source at the
GitHub repo upstream, which is what our patch existed to do. The new
PKGBUILD uses a release tarball instead of git+, so the patch context
no longer matches and every scheduled Sync AUR Packages run failed
applying it.
Remove the patch and resync from the AUR. With no .omarchy/patches
left, the package is no longer customized, so it tracks 6.4.0-1
without the .1 pkgrel suffix.
Package Link Studio 1.0.2 with its AUR-only MediaPipe and sounddevice dependencies. Wire Link Studio to GitHub release checksums, keep all three packages on the fast ring, and make MediaPipe's Bazel bootstrap a checksummed makepkg source.
Tracks Perplexity's own Debian repository, the feed the app updates
itself from, via .omarchy/upstream.sh -- same shape as
openai-codex-desktop. pkgver carries the build number from the pool
filename because the index's Version field drops it and upstream
rebuilds under the same marketing version; the pool wants the '+'
percent-encoded. The launcher replaces the postinst symlink pacman
never creates and defaults Chromium to Wayland.
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.