Feed GitHub release pages to jq through stdin so real pages do not exceed Linux argument limits. Generate an oversized fixture response in the curl mock, and run hook fixtures against a temporary pinned PKGBUILD so routine package updates do not break repository self-tests.
Co-Authored-By: Codex GPT-6 XHigh <noreply@openai.com>
Build on #306 without replacing its package or updater workaround. Exhaust the component feed before selecting a release and cover quarantine, version ordering, invalid input, and transport failures with offline fixtures.
cua-driver update --apply pipes the vendor installer into bash, which
installs a second copy under ~/.cua-driver and links it into ~/.local/bin,
stepping around pacman and the repository's release gate. Upstream offers
no switch for that path, and a /usr/bin wrapper would not cover it either:
the MCP configurations the binary generates record the resolved executable.
prepare() rewrites the installer URL inside the binary, in place and at
equal length, to file:///usr/lib/cua-driver/pm.sh, a stand-in that declines
and names pacman. The build asserts the URL appears exactly twice before
the rewrite and not at all after it, so an upstream change to the updater
stops the build instead of shipping a live self-updater.
Verified in a clean archlinux:base container: pacman -Qkk is clean, the
CLI and cursor-theme helper still run, and on the nightly channel
update --apply prints the notice, exits 1, and creates nothing under
~/.cua-driver/packages or ~/.local/bin.
cua-driver ships prebuilt from the trycua/cua monorepo release feed. The
declarative github provider reads a release feed as a single product and
trips on the monorepo's foreign and hyphenated tags, so a bespoke
.omarchy/upstream.sh selects the newest stable cua-driver-rs release by
tag shape (upstream flags every driver release prerelease; nightlies are
distinguished by tag prefix instead) and reads its checksums.txt manifest.
The vendor tree stays together under /usr/lib/cua-driver with a /usr/bin
symlink, matching upstream's own layout: the CLI resolves its cursor-theme
compiler as a sibling of /proc/self/exe. Verified by installing the built
package into a clean archlinux:base container and exercising the CLI.
Schist is a layered image editor with PSD, Affinity and camera raw support,
developed by Infrawrench and packaged by its upstream author. The package
re-wraps the pacman-format payloads Schist's release workflow publishes for
x86_64 and aarch64, so the builder does no compiling, and both assets are
pinned by SHA-256.
Releases are tracked declaratively through the GitHub upstream provider,
which gains a "digests": true mode here: a vendor that publishes no checksum
manifest can have each asset's SHA-256 read from the digest GitHub's release
API reports, so the sync never downloads the artifacts. Exactly one of
"checksums" or "digests" must be set, and the provider enforces that itself
because scheduled runs reach it without the metadata validator.
Fresh releases wait 24 hours before the scheduled sync picks them up, as
mise-bin already does. vulkan-driver is an optional dependency rather than a
hard one: makepkg -s would otherwise satisfy the virtual package with
nvidia-utils in the build container, and Omarchy installs a Vulkan driver per
machine.
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Local-first block notes with a wiki-link graph and a built-in AI research agent. Electron over a Next.js server, x86_64 only, repackaged from the vendor tarball with a Wayland launcher.
Not in the AUR. The package follows its GitHub release feed through the declarative github upstream provider, reading each release's SHA256SUMS, with a 24h min_release_age quarantine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The recipe fetched the branch tip, so a rebuild on another architecture
could package a different tree than the one already published. Pin the
source to a commit and set pkgver to what that commit describes
(1.22.0.r96.g0331510, as an aarch64 build of it reports); bump both
together from now on.
Three opt-in knobs for bin/build, each defaulting to today's behaviour:
OMARCHY_KEEP_BUILD_WORKSPACE=1 keeps build-output/$MIRROR/$ARCH instead
of wiping it, and build/build.sh now folds any packages already there
into omarchy-build.db even when no database exists yet, so packages
built by an earlier job (or a previous, interrupted run) resolve as
dependencies of what builds next.
OMARCHY_SKIP_BUILDER_IMAGE=1 uses the omarchy-pkg-builder image already
present instead of building it, so a workflow can build the image once
with an external BuildKit cache and fan out over package jobs that all
run the same bytes. A missing image is an error, not a silent rebuild.
OMARCHY_DEFER_RUNTIME_DEPS=true builds the omarchy/omarchy-settings pair
with --nodeps, installing only their makedepends and checkdepends
explicitly. The pair depends on each other and on packages a sharded
pipeline builds in other jobs, so they cannot resolve in isolation; the
assembled set is installed in one verified transaction downstream. The
request is refused for anything but exactly that pair, on the host
before Docker starts and again inside the container.
Also fix make_dir_writable: chown -R can succeed on part of the tree
and fail on files a previous container left behind as another uid, and
the old `|| chmod` fallback only ran when chown failed outright. Always
follow with chmod.
The Omarchy payload is architecture-independent, but the package is not.
On x86_64 omarchy pulls the Limine + mkinitcpio hook + Snapper boot stack;
on Apple Silicon the system boots through m1n1 + GRUB from the Asahi
packages on Arch Linux ARM's kernel, so that stack does not apply, and
Wi-Fi on the Broadcom parts needs the iwd backend. The shipped /etc tree
differs too: mkinitcpio reads every file under /etc/mkinitcpio.conf.d/,
so shipping omarchy_hooks.conf on aarch64 injects the Limine hooks into
the Asahi kernel's initramfs, and the zram/zswap/oomd drop-ins and the
zram-tuned vm.* sysctls belong to the x86_64 memory stack.
makepkg only honours depends_<arch> and optdepends_<arch> on
arch-specific packages, so arch=('any') becomes ('x86_64' 'aarch64').
backup=() has no arch-suffixed form, so the x86_64-only entries are
appended under CARCH and each of those paths is removed from the aarch64
package in package(). The x86_64 package keeps exactly the contents it
had; only its filename suffix changes.
The install scriptlet applies the hardened cups-files.conf on every
platform, then on Apple Silicon keeps the Arch Linux ARM system identity
(/etc/os-release stays the distribution's symlink) instead of the
etc-overrides. The -dev pair carries the same change so the pairs stay in
lockstep.
The environment-theme patches shipped as a forked AppImage while
upstream lacked them. Keeping it current means a hand-built artifact
per release, and it has fallen three behind — 0.0.35 against 0.0.38.
t3code-bin tracks the upstream feed on its own, so drop the fork.
Nothing else in the repo referenced the package.
The AUR caught up: asusctl 6.4.0-1 (b0ec6ca) repoints source at the
GitHub repo upstream, which is what our patch existed to do. The new
PKGBUILD uses a release tarball instead of git+, so the patch context
no longer matches and every scheduled Sync AUR Packages run failed
applying it.
Remove the patch and resync from the AUR. With no .omarchy/patches
left, the package is no longer customized, so it tracks 6.4.0-1
without the .1 pkgrel suffix.
Package Link Studio 1.0.2 with its AUR-only MediaPipe and sounddevice dependencies. Wire Link Studio to GitHub release checksums, keep all three packages on the fast ring, and make MediaPipe's Bazel bootstrap a checksummed makepkg source.