Import the unchanged recipe from the cua-driver-rs-v0.24.0 build kit. Keep fast-ring automatic builds disabled pending native channel qualification and document explicit ABI updates and compositor restarts.
Every channel has failed since 0.2.1 landed: one package failing fails the
whole build, and the build step aborts the release before sign, promote or
sync. Nothing has published on edge, rc or stable since 2026-09-11, and 26
built packages have been rebuilt and discarded every cycle.
backend::redo::tests::redo_refuses_changed_sources_and_destination_collisions
writes a file and immediately asks redo to notice the edit. flea decides
"changed" from ctime alone -- src/backend/undo.rs records (ctime, ctime_nsec)
as the whole identity -- and this kernel stamps ctime from the coarse clock,
so two writes microseconds apart share a timestamp and the guard sees no
change. redo returns Ok where the test demands Err, which is why it fails
almost every run rather than intermittently.
Measured on this builder: 196/200 back-to-back write pairs on /dev/shm and
192/200 on the root filesystem produced an identical ctime. That also retires
the premise of 82363cb: /dev/shm does not buy finer timestamps here, so moving
the suite to tmpfs could never have fixed this, and the comment saying it does
is corrected. A probe cannot decide this at runtime either -- one using stat
reports the filesystem as fine-grained, because the stat subprocess alone
costs more than the granule it is trying to measure.
Both halves belong upstream in thisisgm/flea: the test assumes a resolution
the kernel never promised, and the identity it exercises cannot see a
same-granule edit, which is a real hole in undo/redo rather than only a test
artifact. Skipping one test is the narrow fix; holding the package back would
have stalled the other 26.
Only this test is affected. new_file_is_recreated_but_changed_or_replaced_
files_survive_undo asserts the same refusal and passes, because enough work
separates its write from the identity capture to cross a granule.
Verified with bin/repo build --package flea: filesystem suite 63 passed,
main suite 528 passed, flea 0.2.1-3 built.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
virtiofsd sat in the common optdepends, so aarch64 still advertised one third of a Cowork stack the package deliberately promises nothing else of there. It joins qemu and the firmware in optdepends_x86_64, and the virtiofsd shim moves under the same branch, so an aarch64 package carries no Cowork pieces at all.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
The app probes Debian's paths for its VM stack: /usr/libexec/virtiofsd then /usr/bin/virtiofsd, and /usr/share/OVMF/OVMF_CODE_4M.fd with the VARS path derived from it. Arch ships virtiofsd at /usr/lib/virtiofsd and the firmware at /usr/share/edk2/x64/OVMF_CODE.4m.fd, so installing the advertised optdepends still left Cowork reporting QEMU missing. Symlinks at the probed paths map them onto Arch's; the app's probe reads through them, they dangle harmlessly until the optdepends arrive, and /usr/libexec keeps the virtiofsd link out of $PATH while it does.
The firmware optdepend moves into optdepends_x86_64, and aarch64 loses its Cowork optdepends entirely: the aarch64 builds run against Arch Linux ARM, which ships no UEFI firmware package at all, so both the edk2 name and the qemu-system-aarch64 entry promised a VM that cannot boot there.
The embedded Claude Code diagnoses missing sandbox dependencies when bubblewrap and socat are absent; they join the optdepends under the same wording as the standalone claude-code package.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
Feed GitHub release pages to jq through stdin so real pages do not exceed Linux argument limits. Generate an oversized fixture response in the curl mock, and run hook fixtures against a temporary pinned PKGBUILD so routine package updates do not break repository self-tests.
Co-Authored-By: Codex GPT-6 XHigh <noreply@openai.com>
Anthropic ships the Claude desktop app for Linux only through its own
Debian repository, so the package repacks the deb the way
openai-codex-desktop does: extract data.tar.xz, replace the bare
/usr/bin symlink with a launcher that asks Chromium for Wayland
directly, and keep the vendor copyright as the license.
Updates come through the declarative "debian" upstream provider: the
apt Packages index names the newest version, and the per-architecture
pool debs are hashed when one appears. Verified by pinning 1.44121.2
and watching bin/sync-upstream rewrite it back to 1.46388.2
byte-identically.
Build on #306 without replacing its package or updater workaround. Exhaust the component feed before selecting a release and cover quarantine, version ordering, invalid input, and transport failures with offline fixtures.
1Password reads the display scale itself, the way Electron apps do, so
on a scaled monitor it comes up oversized next to every other window.
Pin it in the .desktop we install and let the compositor scale it.
Rewriting Exec on the way in is how spotify, perplexity and sublime-text
already fix up their entries here. Only the stable package: 1password-beta
syncs from the AUR, so a patch there would be overwritten.
Claude-Session: https://claude.ai/code/session_01JB9phxP56gnP7qSidkkUJE
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1.7.0 makes OpenSSL and libzstd hard CMake requirements; both are in
every build chroot transitively, so the sync's version-only bump in
auto/sync-upstream would have built and shipped them as undeclared
linkage rather than failing. Declare them, and pin the new optional
Wayland idle-inhibit feature on by adding wayland-protocols to
makedepends instead of leaving it to what the chroot happens to carry.
Checksum matches the release's SHA256SUMS manifest and an independent
download.
Released 06:46 UTC today, inside the quarantine window; shipped by hand
per BYPASS_MIN_RELEASE_AGE's intent. The feed's asset name matches the
one the PKGBUILD builds, the download's size and SHA-512 match the
electron-builder feed exactly (byte-identical to what the app's own
updater installs), and the SHA-256 here is from that verified download.
Release 2026.8.31-3 preserves upstream desktop settings and explicit launch environment without invoking the CLI sandbox setup. Keep incomplete runtimes from blocking the packaged fallback, and use the namespace sandbox consistently in both locations.
Co-Authored-By: Codex XHigh <noreply@openai.com>
Use the same direct executable path for menu launches and URLs, require working user namespaces, and retain only the first-update relaunch gate backport. This avoids the upstream CLI fallback that makes a helper in the user runtime setuid-root.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Track main while pinning the initial release commit. Ship the matching upstream installer and Linux namespace sandbox backport, and launch the native user build prepared by Omarchy.
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
Revert the native installer and updater packaging introduced by #325. Keep the prebuilt desktop and existing launcher, updating only the release tag, commit and archive checksum from the previous recipe.
0.11.2 is 14 hours old, inside the package's 24h min_release_age, so the
upstream sync would not pick it up until tomorrow; ship it now by hand.
Tarball commit b000b79 verified against the v0.11.2 tag, checksum from
an independent download. The new Cargo dependencies (ashpd, zbus,
gdk4-wayland) are vendored crates needing no new system libraries.
0.11.2 also ships FileManager1/portal integration files. Stage the
FileManager1 service under /usr/share/strata the way upstream's own
PKGBUILDs do — the app copies it per-user on opt-in. The portal files
stay unpackaged, matching upstream: enablement is per-user and
consent-gated in the app.