Commit Graph
827 Commits
Author SHA1 Message Date
Ryan Hughes 699261471a Replace mise's upstream hook with a declarative GitHub-releases provider
After the quarantine moved into the manifest, all mise-bin's hook still knew
was data: the repository, the checksum manifest name, and the asset filename
patterns. That now lives in .omarchy/package.json as an upstream block --

  "upstream": {
    "github": "jdx/mise",
    "checksums": "SHASUMS256.txt",
    "assets": { "x86_64": "mise-{tag}-linux-x64.tar.xz", ... }
  }

-- handled by helpers/upstream-github.sh inside bin/sync-upstream. The
provider walks the release feed (drafts/prereleases excluded), honors
min_release_age and BYPASS_MIN_RELEASE_AGE during selection, reports
published_at so the framework backstop still applies, fails closed on any
unreadable tag or timestamp, and skips the checksum fetch when the newest
qualifying release is already checked in.

upstream.sh remains the escape hatch for feeds that fit no convention
(openai-codex-desktop's Debian index, tmog's version.txt, t3code's
electron-builder manifest); declaring both is an error.
2026-08-24 19:30:33 -04:00
Ryan Hughes 48ad6b9d7b Generalize the release-age quarantine into a manifest policy
Move the hold from a mise-only hardcode to min_release_age in
.omarchy/package.json ("24h", "2d", or bare seconds), alongside source and
release_ring where package policy already lives. bin/sync-upstream exports
the window to every hook as MIN_RELEASE_AGE_SECONDS so a hook that can walk
its release feed selects the newest release that has cleared it, and
enforces it as a backstop: with a policy set, the hook must report
published_at, and a release younger than the window is treated as no
update. A hook that cannot prove the age fails the sync rather than
shipping unverified. BYPASS_MIN_RELEASE_AGE=1 replaces the package-specific
bypass for deliberate emergency updates; scheduled automation never sets it.

The mise hook keeps its release-list walk but reads the window from the
environment and reports published_at; the other upstream hooks are
untouched and unaffected until they opt in.
2026-08-24 19:17:22 -04:00
Ryan Hughes eca3ce7815 mise-bin: ship the newest release that has cleared the 24h quarantine
Gating on /releases/latest alone starves updates when mise's near-daily
cadence keeps the newest release perpetually inside the quarantine window:
today that left Omarchy on 2026.8.8 while 2026.8.11 had already aged past
24 hours. Walk the release list (drafts and prereleases excluded) and pick
the newest release, by vercmp, whose published_at is at least 24 hours old.

The quarantine guarantee is unchanged: nothing younger than the window ever
ships without the explicit MISE_BIN_BYPASS_RELEASE_AGE=1 bypass, and invalid
tags or timestamps still fail closed - now for every release in the feed,
plus a hard failure if the feed reports no stable releases at all.
2026-08-24 14:21:41 -04:00
David Heinemeier Hansson cc2413f0f3 Release omarchy 4.0.1rc2 2026-08-24 20:12:38 +02:00
Ryan HughesandGitHub 40ddd6be19 Merge pull request #192 from jdx/fix/mise-release-age
fix(mise-bin): delay upstream releases for 24 hours
2026-08-24 10:56:46 -04:00
ryanrhughesandgithub-actions[bot] 78ce6429f1 chore: sync AUR packages 2026-08-24 01:24:35 +00:00
Ryan Hughes e5fb86e53d Release omarchy 4.0.1rc1 2026-08-23 20:14:52 -04:00
default f1e0ca526d fix(mise-bin): delay upstream releases for 24 hours
*AI-assisted — Tool: Codex; model: openai/gpt-5; version: unavailable.*
2026-08-23 22:10:19 +00:00
David Heinemeier HanssonandClaude Opus 5 808a66a670 Add tmog-bin, the TMOG system monitor
TMOG ships no source and no AUR package, so this repackages the vendor's
Linux tarball. That artifact is 7.9 MB against the system Qt, where the
AppImage is 55 MB carrying a second copy of the Qt the shell already
installs.

Every release is served from one versionless URL, so .omarchy/upstream.sh
reads /version.txt, computes the checksum from the artifact, and checks
the tarball's own directory name to confirm the mutable path really
served the version it announced.

The beta licence forbids public redistribution, so publishing this needs
the publisher's permission; .omarchy/README.md records that.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011K4ra2oZTtzUQZJ2kwP3io
2026-08-23 16:23:05 +02:00
David Heinemeier HanssonandGitHub 0276a5155b Merge pull request #170 from omacom-io/herdr-track-upstream
Package the herdr 0.8.2 release instead of the fork
2026-08-22 16:49:50 +02:00
Omabot 40a094c32a Package the herdr 0.8.2 release instead of the fork
The package built from omacom-io/herdr, a fork pinned to a commit and versioned 0.8.0.r13. Its only divergence was three commits replaying an agent's CLI options when a session resumed, which upstream declined twice — from a contributor in herdrdev/herdr#2036 and from us in herdrdev/herdr#2614, closed in favour of an agent resume manifest meant to supersede it. Those three are dropped; every other commit the fork carried is in v0.8.2.

The fork also self-reported "0.8.0" while speaking wire protocol 20, which upstream's published 0.8.0 did not: it spoke 19. An official client attaching to an Omarchy host therefore saw a server claiming to be its own version yet refusing to talk to it, and offered to stop it without ever naming the protocol. That is omacom-io/omarchy-pkgs#161.

Upstream released v0.8.2 today, and it settles both halves. It carries protocol 20, and the stable manifest now publishes 0.8.2 at protocol 20, so an official client and this package agree. It also contains the five features Omarchy contributed after the v0.8.0 tag — configurable outer pane borders, direct pane resize keybindings, move tab keybind actions, centered tab labels and outer terminal window title sync — which is what made packaging the earlier release a regression rather than a return to upstream.

Because the build is now the release it claims to be, it needs no build-identity marking: HERDR_BUILD_CHANNEL and HERDR_BUILD_ID are gone, and the binary reports a bare 0.8.2. The package name is unchanged, so nothing needs a rename, a migration or a database removal to reach existing installs; 0.8.2-1 simply supersedes 0.8.0.r13-1.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.
2026-08-22 07:41:39 -07:00
Omabot ced6963010 Rebuild quickshell-git against Qt 6.11.2
Arch shipped qt6-base 6.11.2-2 on 2026-08-20, and the published 0.3.0.r20.g28771c7-1, built against 6.11.1, stopped starting: undefined symbol _ZN23QUntypedPropertyBindingC1EP23QPropertyBindingPrivate, version Qt_6_PRIVATE_API. quickshell-check.hook caught it post-transaction, but detecting is all it does, so pacman logged the failure and omarchy-update-restart went on to restart a shell whose binary could no longer launch.

The git rev has not moved, so the rebuild only reaches anyone through a pkgrel bump. rebuild_on names the three Qt packages quickshell actually links against: qt6-base for Core, Gui, Widgets, Network, DBus and OpenGL, qt6-declarative for Quick and the Qml libraries, qt6-wayland for WaylandClient. rebuilt_against is seeded with the versions this rebuild will link against, so bin/sync-rebuilds starts from a correct baseline and fires on the next Qt release rather than repeating this one.

🤖 Generated by Opus 5 in Claude Code.
2026-08-20 03:44:56 -07:00
OmabotandClaude Opus 5 0607b4ece4 Remove packages Arch has since absorbed
intel-lpmd, pinta and umu-launcher arrived together in the bulk AUR import of 2026-05-07, and all three have since been deleted from the AUR, which is what happens when Arch moves a package into its own repositories. extra now carries intel-lpmd 0.1.0-4 and pinta 3.1.2-2, and multilib carries umu-launcher 1.4.4-1, against the 0.1.0-2, 3.1.2-1 and 1.1.3-1.1 checked in here.

Nothing noticed because bin/sync-aur treats a missing AUR package as a warning rather than an error, so the sync has completed green every run since May while these three sat frozen.

They were never reachable in any case: pacman stops at the first repository carrying a name, and [omarchy] is ordered below core, extra and multilib, so every machine has been resolving the official builds. That also makes the umu-launcher patch here dead code -- it stripped the build down from the AUR's dependency list, but multilib's package is what actually gets installed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-20 00:28:37 -07:00
OmabotandCodex XHigh e2e916f3c9 Track upstream herdr instead of the Omarchy fork
The fork carried three commits that replayed an agent's CLI options when Herdr resumed its session. Upstream declined that work twice — once from a contributor in #2036 and once from us in #2614, closed in favour of an agent resume manifest system that is meant to supersede it — so the fork was a permanent rebase treadmill for one feature, and it is dropped here.

Packaging the v0.8.0 release instead would have regressed more than the fork gained: configurable outer pane borders, direct pane resize keybindings, move tab keybind actions, centered tab labels and outer terminal window title sync all merged upstream after that tag, so the release predates five features Omarchy contributed. The package follows upstream master and takes the -git name that says so, replacing both herdr and omarchy-herdr.

Master's Cargo.toml reads 0.8.1, a release upstream cut and withdrew hours later, while the wire protocol is already 20 against the published release's 19. An unmarked build therefore self-reports a version that no release carries, which is how an official client came to insist on stopping an Omarchy host's server without saying why. HERDR_BUILD_CHANNEL and HERDR_BUILD_ID make it report 0.8.1-omarchy.<commit>. The channel is not "preview" because that gates is_preview(), which makes the stable updater treat every published release as installable and overwrite /usr/bin/herdr outside pacman.

pkgver() excludes the preview tags that sit on master between releases; describing without that returns a preview build id that pacman ranks below the version already shipped. It fails rather than falling back for the same reason: with no release tag reachable, every version it could invent sorts lower than what users already have.

Cross-architecture remote attach cannot bootstrap a helper for this build, because the stable manifest lists only published releases. That is true of any build from master, marked or not: an unmarked one asks the manifest for 0.8.1 and is told it does not exist.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Codex XHigh <codex@openai.com>
2026-08-19 07:52:27 -07:00
Omabot f6d441c235 Drop "(Alpha)" from the T3 Code desktop entry
The entry comes from upstream's AppImage rather than a hand-written one, because that is what carries the t3code:// scheme handlers, and it arrives named "T3 Code (Alpha)" from electron-builder's productName. That name is stale: the app's own code calls it `legacyUserDataDirName` and has already moved its data to ~/.config/t3code, so the launcher was advertising an identity upstream has moved off.

Rewrite Name= alongside the Exec= rewrite already there. The scheme handlers, the MimeType line and the rest of upstream's entry are untouched.

pkgrel goes to 2 because 0.0.33-1 is already published, and a packaging-only change reaches an installed machine only through a new release.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 07:39:16 -07:00
ryanrhughesandgithub-actions[bot] 97fe236208 chore: sync AUR packages 2026-08-19 12:52:51 +00:00
OmarchybotandGitHub 454462ec75 Merge pull request #157 from omacom-io/auto/sync-aur
chore: sync AUR packages
2026-08-19 12:15:29 +02:00
David Heinemeier HanssonandGitHub 1e7031933d Merge pull request #167 from omacom-io/t3code-bin
Add t3code-bin, the T3 Code desktop app
2026-08-19 05:04:17 -05:00
OmabotandCodex XHigh 7ee0003106 Keep the sandbox up on hardened kernels, and stop deleting what we have not read
Three fixes from a review of the previous commit.

Chromium's sandbox helper ships setuid, the way Arch's own electron and chromium packages ship theirs. Dropping --no-sandbox was right, but it left the app relying on unprivileged user namespaces alone: on linux-hardened, or anywhere else they are denied, Electron falls back to the helper and aborts because it is not root-owned 4755.

The AppImage's usr/ tree is now read before it is removed. Deleting it wholesale is correct for what upstream ships today, and the version bumps arrive unattended, so a release that starts putting something needed in there would have had it dropped on the way past without anyone seeing it. Anything that is not a known icon or a known compatibility library stops the build instead.

The upstream hook checks that the feed still names the asset the PKGBUILD builds. It hashes whatever the feed points at, so a rename — or an arm64 build reaching the Linux feed first — would have pinned that file's checksum to a URL nobody fetches, and the failure would have surfaced a build later as a checksum mismatch.

🤖 Generated by Opus 5 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Codex XHigh <codex@openai.com>
2026-08-19 02:56:22 -07:00
David Heinemeier HanssonandGitHub a9ceb83b17 Merge pull request #151 from tobi/update/omatrack-1.2.0
Update omatrack to 1.2.0
2026-08-19 04:52:19 -05:00
Omabot 17b06216fb Own the T3 Code PKGBUILD instead of syncing the AUR's
The AUR package installs the AppImage payload as it comes out of the image: AppRun, .DirIcon, the app's own desktop file and six compatibility libraries — libgconf, libappindicator, libindicator, libXss, libXtst, libnotify — bundled for distributions that do not ship them. Arch does, and nothing in the tree links the bundled copies anyway, so they were only along for the ride. The launcher's APPDIR, PATH, XDG_DATA_DIRS and GSETTINGS_SCHEMA_DIR exports existed to serve that layout, and CODEX_CLI_PATH is not a variable the app reads at all.

So the tree now goes to /usr/lib/t3code as a plain Electron install, next to how openai-codex-desktop ships. Cleaning that up meant rewriting most of package(), which is more than a patch should carry over an upstream we do not control, hence a local PKGBUILD and an .omarchy/upstream.sh that follows the electron-builder feed the app updates itself from.

Three things the AUR package lost that this keeps: the AppImage's own 16px-512px icons, rather than a separately downloaded 1024px PNG; upstream's desktop entry, which carries the t3code:// scheme handlers a hand-written one drops; and libnotify in depends, which Electron dlopens for notifications.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 02:41:15 -07:00
David Heinemeier HanssonandGitHub 12b322dd5c Merge pull request #164 from omacom-io/auto/sync-upstream
chore: sync upstream releases
2026-08-19 04:34:56 -05:00
Omabot ab154a00dd feat(t3code-bin): add T3 Code desktop from the AUR
T3 Code is an open-source control plane for coding agents — Claude Code, Codex, OpenCode, Cursor and Grok driven from one desktop app, on the user's own subscriptions. Upstream ships a Linux x86_64 AppImage only, and the AUR's t3code-bin already tracks it, so this syncs from there in the fast ring.

One Omarchy patch: the AUR launcher runs Electron with --no-sandbox. Chromium falls back to a user-namespace sandbox when it finds no setuid helper, which is what happens on Arch, so the flag only turns the sandbox off. Verified both ways against the built package — sandboxed it reaches display setup, and only with namespaces restricted does it abort on the setuid helper.

🤖 Generated by Opus 5 in Claude Code.
2026-08-19 02:28:30 -07:00
ryanrhughesandgithub-actions[bot] 4d0ef37f05 chore: sync AUR packages 2026-08-19 06:48:27 +00:00
dhhandgithub-actions[bot] 2df2f8ccbc chore: sync upstream releases 2026-08-18 19:03:10 +00:00
Tobi Lutke 687fbf9e3d omasnap: update to 1.15.0 2026-08-18 13:13:47 -04:00
dhhandgithub-actions[bot] 7629aaa583 chore: sync upstream releases 2026-08-17 19:03:59 +00:00
David Heinemeier HanssonandGitHub 045740e78f Merge pull request #156 from jdx/codex/mise-bin
feat(mise-bin): add optimized mise binaries
2026-08-17 03:06:46 -05:00
Omabot 6284fcf437 Update ttfx to v0.3.2 2026-08-17 00:20:45 -07:00
default 68460950b4 feat(mise-bin): add optimized mise binaries 2026-08-16 18:32:07 +00:00
Tobi Lutke f02cc65ba6 Update omatrack to 1.2.0
Pin the local PKGBUILD to the signed v1.2.0 release commit.
2026-08-15 18:06:52 -04:00
ryanrhughesandgithub-actions[bot] 51cc23684d chore: sync AUR packages 2026-08-15 18:34:51 +00:00
David Heinemeier HanssonandClaude Opus 5 f92de9c440 Make the upstream rewrite verify its own result
A second review pass found the PKGBUILD rewriting could still go wrong in ways
the pattern matching did not anticipate: an array element carrying a ")" in a
comment left the tail of the old array behind, and jq's "$" also matches before
a trailing newline, so a pkgver of "1.0\n" passed validation and then broke sed
after the checksum arrays had already been written.

Rather than chase each shape, prove the result. Every edit now lands on a
scratch copy that is parsed with bash -n and read back to confirm it holds the
version and checksums we meant to write, and only then replaces the PKGBUILD in
a single rename. Corruption that slips past the matching fails loudly with the
original untouched instead of landing in a pull request.

The validation anchors are \A and \z accordingly, empty checksum lists are
rejected rather than written as '', and the hook picks the newest stanza with
vercmp so it agrees with the comparator the updater uses.

Also stop the launcher probing /.config when HOME and XDG_CONFIG_HOME are both
unset, and require a regular file, so a directory at that path is skipped
instead of crashing the app on startup.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-15 08:34:42 -07:00
David Heinemeier HanssonandClaude Opus 5 1a61278911 Take over openai-codex-desktop from the AUR
OpenAI ships the ChatGPT desktop app several times a week and the AUR
packaging trails it -- as of this commit by a full version, 26.803.81509
against 26.810.52044. Every sync we took from there was a sync we could have
taken from OpenAI directly.

So track OpenAI's own Debian repository instead. Its per-architecture package
index carries the version and SHA256 of every deb, which makes an update two
small HTTP requests rather than a 750 MB download, and the pool keeps old
versions, so the URLs pinned here stay resolvable after the next release.

Omarchy now maintains the package outright: the max-zstd patch is simply part
of the PKGBUILD, chatgpt-launcher.sh is ours, and the Arch REUSE files are
gone -- they annotated packaging paths (.SRCINFO, keys/**, .nvchecker.toml)
that do not exist here. The app's own license still ships; package() installs
upstream's copyright file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-15 08:18:54 -07:00
David Heinemeier HanssonandClaude Opus 5 5575275941 Update aether to v4.28.9
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-14 11:37:10 -07:00
David Heinemeier Hansson bb66b9dafc Release omarchy 4.0.0 2026-08-14 08:23:21 -07:00
David Heinemeier Hansson 85551de4f0 Release omarchy 4.0.0rc6 2026-08-14 08:13:27 -07:00
David Heinemeier Hansson c24302e65e Release omarchy 4.0.0rc5 2026-08-14 00:31:33 -07:00
David Heinemeier Hansson e4e7b9abf9 Release omarchy 4.0.0rc4 2026-08-13 13:53:24 -07:00
David Heinemeier Hansson b252a1cfb3 Latest from AUR 2026-08-13 11:58:32 -07:00
Tobi Lutke dbee603e5b Add grok-bot 0.18.0
Package the official Grok Bot Linux .deb (internal name: sand) for Arch.
Wraps /opt/Grok Bot/sand with a Wayland launcher and grok-bot desktop entry.

Linux has no latest feed; update-pkgver.sh resolves version+commit from the
darwin-arm64 sand feed and HEAD-checks the Linux deb before pinning.
2026-08-13 10:17:24 -04:00
David Heinemeier Hansson 84b86195cd Release omarchy 4.0.0rc3 2026-08-13 06:54:43 -07:00
David Heinemeier HanssonandGitHub 143a1697b0 Merge pull request #142 from axelfontaine/dbxcli-bin
Add dbxcli-bin from AUR
2026-08-13 14:52:56 +02:00
David Heinemeier HanssonandGitHub 437f66df41 Merge pull request #139 from tobi/update-omasnap-1.11.0
Update omasnap to 1.12.0
2026-08-13 14:52:19 +02:00
David Heinemeier HanssonandClaude Opus 5 f20649b0a4 Ship the aether plugin cache under the name Omarchy 4 asks for
Omarchy 4 generates most theme specs from default/themed/neovim.lua.tpl on
top of aether, pinned as `name = "aether", branch = "v3"`. lazy indexes
specs by url and lets an explicit name rename the merged plugin, so the
bare "bjarneo/aether.nvim" entry here built the cache into lazy/aether.nvim
while every aether-themed install renamed that same plugin to lazy/aether at
runtime -- a directory the package never shipped. Picking one of those themes
on a fresh install cloned aether over the network at first launch and left
the session on tokyonight until nvim was restarted. Six stock Omarchy 4
themes route through the template, plus last-horizon.

Naming the entry to match builds the cache into lazy/aether directly. There
is still only one clone: Omarchy 3.8's hackerman theme depends on the bare
"bjarneo/aether.nvim" url, which merges into the same plugin, so 3.8 keeps
resolving offline as before.

Also keep refs/remotes/origin/HEAD when slimming. It pins no objects, but
lazy.nvim resolves the default branch through it for plugins parked on a
detached HEAD by a version pin -- lazy.nvim, LazyVim and blink.cmp. Without
it get_branch() returns nil and every lockfile write asserts, so :Lazy
install/update/sync died with E5113 on a fresh install, taking out the usual
self-heal path too. Regression from 45ca871.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 04:31:10 -07:00
David Heinemeier HanssonandClaude Opus 5 3d3ace990b Update ttf-jetbrains-mono-nerd-basic to v3.5.0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 03:33:32 -07:00
David Heinemeier HanssonandClaude Opus 5 5a83d2e470 Update omatrack to v0.9.11
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 03:32:48 -07:00
David Heinemeier HanssonandClaude Opus 5 385ef1eca4 Update omasnap to v1.12.0
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 03:32:48 -07:00
David Heinemeier HanssonandClaude Opus 5 7c908cb9b7 chore: sync AUR packages
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 03:31:01 -07:00
David Heinemeier HanssonandClaude Opus 5 0f038a0dcc Update aether to v4.28.4
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-13 03:21:25 -07:00