Commit Graph
1468 Commits
Author SHA1 Message Date
Scott Jones a1a32908c5 Build hyprland-preview-share-picker with stable Rust 2026-09-19 18:40:12 -04:00
Ryan Hughes 54ce26ccb8 Merge pull request #398 from omacom/add-omarchy-billboard-generator
Add omarchy-billboard-generator, the animated domain video maker
2026-09-19 15:21:16 -07:00
David Heinemeier Hansson 65ad77a63d Update Hype to 0.3.0 (#539) 2026-09-19 21:43:08 +02:00
David Heinemeier Hansson 85a89659dc Update Hype to 0.2.0 (#532) 2026-09-19 15:39:22 +02:00
Ryan Hughes 6afd935759 Merge pull request #64 from jacob-vincent-mink/feature/openvino-genai
Add OpenVINO GenAI C runtime package
2026-09-18 21:29:17 -07:00
Spencer BullandGPT-6 34257e0820 Update OpenVINO GenAI maintainer email
Co-Authored-By: GPT-6 (Codex) <noreply@openai.com>
2026-09-18 22:51:46 -05:00
Spencer BullandGPT-6 f2805a5a39 Keep the GenAI runtime PR independent of Voxtype 1.1
Move the Voxtype optional dependency metadata and release bump to a separate draft pending upstream 1.1. The GenAI runtime package can ship independently.

Co-Authored-By: GPT-6 (Codex) <noreply@openai.com>
2026-09-18 22:45:23 -05:00
Spencer BullandGPT-6 7bd8f5de1c Ship Voxtype OpenVINO metadata in a new package release
Bump pkgrel so the builder produces an artifact and installed packages receive the optional dependency metadata. Restrict the Intel/OpenVINO recommendations to x86_64, where these packages are available.

Co-Authored-By: GPT-6 (Codex) <noreply@openai.com>
Co-Authored-By: GPT-6 Astra XHigh (Codex) <noreply@openai.com>
2026-09-18 21:58:04 -05:00
Jacob Mink 3024302725 Ensure OpenVINO GenAI package includes both C bindings 2026-09-18 21:47:44 -05:00
Jacob Mink c779955714 Fix OpenVINO GenAI C runtime loading 2026-09-18 21:47:44 -05:00
Jacob Mink 2294bfa19c Update OpenVINO GenAI for Voxtype NPU support 2026-09-18 21:47:44 -05:00
Spencer Bull b7f44e4744 Add OpenVINO GenAI runtime package 2026-09-18 21:47:44 -05:00
David Heinemeier HanssonandClaude Fable 5.1 00685ab3e7 Package v0.1.2, the release carrying the reviewed fixes
Upstream merged the installer rollback, renderer Host check, contrast warning and playback fixes and cut v0.1.2 with them, plus a fullscreen intro that is canvas geometry only: no new dependencies, files or runtime paths. The checksum is the one its SHA256SUMS manifest publishes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-18 22:21:52 -04:00
02f63ae1f2 Add omarchy-billboard-generator, the animated domain video maker
Packages llstrk/omarchy-billboard-generator from its GitHub release archive: the runtime tree plus locked production npm dependencies under /usr/lib, entry-point symlinks in /usr/bin, a desktop entry whose WM class matches the Chromium app-mode window, and the fonts and provenance notices the project bundles. Chromium and ffmpeg are runtime dependencies found on PATH rather than downloaded, which is how the project itself works.

The desktop entry is written from the PKGBUILD rather than shipped as a second source because sync-upstream rewrites the checksum array wholesale from the release manifest. The catalog checks pin the data directories to empty scratch paths so the build reads bundled data rather than a synced snapshot in the builder's home.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-18 22:21:52 -04:00
fbfbda4eca Package Omawake 0.0.3 and Omaspeak 0.0.3 with service-removal cleanup hooks (#503)
* Package Omawake 0.0.3 and Omaspeak 0.0.2

Bump both -bin packages to the model-support roadmap delivery:

Omawake 0.0.3:
- W02-W05 setup/activation/cache gates audited and closed
- W07 pinned catalog URL health checks and import diagnostics
- W08 Moonshine Small/Medium benchmarked; both deferred (Tiny default)
- W09 Spanish wake profile (multilingual Whisper Base INT8, es)
- W10 connection-owned playback pauses (HoldPause)

Omaspeak 0.0.2:
- S09 Kokoro 82M: Kokoro-capable packaged provider (supertonic;kokoro_tts)
  with espeak-ng-data.bin shipped beside the executable, 54 named voices
- S10 catalog URL checks, Spanish speech profile, consistent status shape
- S07 streaming deferred at the current pin

Upstream: omawake v0.0.3, omaspeak v0.0.2 (aarch64 + x86_64 verified on
promaxgb10-d666 CUDA and local NPU installs).

* omaspeak-bin: install espeak-ng-data.bin beside the packaged library

* omaspeak-bin: bump to 0.0.3-rc.1 (catalog-managed eSpeak data)

- The tarball no longer ships espeak-ng-data.bin: the Kokoro catalog row
  pins the data package as a model asset (downloaded/verified/installed
  into the model directory with the GGUF), so the core package ships no
  model data at all.
- Both arch checksums taken from the v0.0.3-rc.1 SHA256SUMS.txt.

* omaspeak-bin: finalize at 0.0.3

* Stop setup-created Oma services before pacman removes their binaries

* Drop stale release-verification fixtures from the branch

These were swept in by git add -A during the version bumps: packaged
copies of old releases (0.0.1 tarballs and extracted trees, ~80 MB)
belong to the local verification workflow, not to the package repo.
The consolidated upstream PR should carry only the package changes,
hooks and the removal regression suite.

* Update removal-test fixture versions to the packaged finals

* Ask systemd to reset only an Oma unit that actually failed

The removal helper reset the failed state of every unit it stopped, but
systemd accepts ResetFailed for a unit that is in the failed state alone.
For any other state it answers that the unit is not loaded and exits
non-zero, and because the helper runs under errexit while the hook aborts
on failure, a healthy unit then aborted the whole transaction:

  (2/2) Stop and remove omaspeak user services before package removal
  Failed to reset failed state of unit omaspeak.service: Unit omaspeak.service not loaded.
  :: Could not clean up omaspeak for jacob; removal aborted.

That is the ordinary case, as the packaged service ships disabled and an
enabled one is commonly stopped rather than failed. Read the active state
after the stop and ask for the reset only where it applies, so a failed
unit still loses its failed state along with its rate and restart counters
while a clean unit no longer fails the removal. A reset that a reachable
manager still refuses stays fatal.

Model the rule in the removal suite, where reset-failed now follows the
active state the way a real manager does, and cover both outcomes: an
inactive unit must not be asked for, a failed one must be reset between
the stop and the disable, and a refused reset must still fail the hook.

* Keep removal cleanup faithful to how systemd reads configuration

Both defects from the review of e025111 sat in the shared package-remove
helper, so both packages were affected the same way.

An offline user's drop-in was recognised by grep '^ExecStart=', while the
configuration parser throws away the whitespace around an assignment
(parse_line() strips the line and both halves of the assignment).  A drop-in
naming a development build as

  ExecStart =
  ExecStart = /home/alice/build/omawake daemon

therefore went unmatched, and the helper cleared away the generated base unit
beside with its enablement links, right behind a service that was never meant
to be the package's.  Match an assignment the way the parser accepts one.  The
gate that decides whether a unit file is the generated one stays strict on
purpose: only the exact generated shape is ever deleted.

systemctl show-environment also prints every value the way a shell would read
it, through shell_maybe_quote(SHELL_ESCAPE_POSIX), so an XDG_CONFIG_HOME with a
space arrives as $'/home/alice/custom config'.  The XDG_CONFIG_HOME=/* case saw
neither form and kept the home's .config directory quietly, leaving the unit in
the directory the manager really reads pointing at the removed binary.  Decode
that quoting character by character, without letting the text become shell
syntax, and refuse a value that is neither a plain path nor a closed $'...'
quote rather than delete what would have to be guessed at.  A value that is not
an absolute path stays the fallback it is in systemd itself.

The fixtures now hand the helper the very text a manager prints, quoted by a
mirror of that printer, and cover a quoted path with a space, an apostrophe and
a backslash, an unreadable quoted value, a relative one, and each spacing of an
offline override.  Verified with the removal suite, 15 tests; the eight new
assertions fail against the helper as it was.  The other suites were not run
here, as they reach for the network.

pkgrel 3 -> 4 and the helper's checksum, in both recipes.
Reported-by: spencerbull

* Decode systemd control escapes during service removal

systemctl C-escapes control bytes in show-environment output. Rejecting those valid values aborted package removal for every user, even when the affected account had no Oma service. Decode the printer’s named and octal escapes without evaluating shell syntax or stripping trailing newlines, and cover the real printer format in the fixtures.

Co-Authored-By: GPT-6 XHigh <noreply@openai.com>

---------

Co-authored-by: Spencer Bull <spencer@omarchy.org>
Co-authored-by: GPT-6 XHigh <noreply@openai.com>
2026-09-18 20:32:11 -05:00
Ryan Hughes 722d65daff Merge pull request #523 from omacom/strict-off
Note why strict up-to-date is off
2026-09-18 15:57:19 -07:00
Ryan Hughes 3d208b340a Merge pull request #519 from omacom/add-owe
Add owe and owe-lockfeed
2026-09-18 15:57:06 -07:00
Ryan Hughes 868f2a1e18 Tests: note that publish, not strict protection, guards the merged tree 2026-09-18 18:46:54 -04:00
Ryan Hughes 81db8fa9a1 Merge pull request #522 from omacom/elsewhen-1.0.0
elsewhen: 1.0.0, the only tag upstream has
2026-09-18 15:44:43 -07:00
Ryan Hughes 2c3fbe38cb Merge branch 'master' into add-owe 2026-09-18 15:12:02 -07:00
Ryan Hughes fae6eaec1b elsewhen: 1.0.0, the only tag upstream has
The package was added pointing at v0.1.0 with a placeholder checksum,
but that tag was never cut; upstream went straight to v1.0.0. The
package has never built anywhere. Point at the real tag and fill the
digest. The upstream watch keeps it current from here.
2026-09-18 18:11:35 -04:00
Ryan Hughes bcb80f08ee Merge pull request #520 from omacom/report-dispatch-fix
Publish report: dispatch runs skip the PR comment; log before comment
2026-09-18 15:09:23 -07:00
Ryan Hughes da4e1b55a8 Publish report: no PR comment on dispatch runs; append the log before commenting
A workflow_dispatch runs from master's head. That commit's PR merged
something unrelated, so looking the PR up by commit attached a failed
elsewhen report to #515, whose merge had nothing to do with elsewhen.
Dispatch runs now go to the log only. The log append also moves ahead
of the PR comment so the record exists by the time anyone follows the
comment to it.
2026-09-18 18:07:43 -04:00
Bjarne Oeverli 0db6153420 Add owe-lockfeed, the lock screen video module
The lock screen draws video through Owe.LockFeed in omarchy#12429. The
module maps the frame slots the OWE renderer publishes, with no media
pipeline of its own. It builds from the qml-plugin directory of the owe
release and installs to the Qt QML module path.
2026-09-18 22:54:51 +02:00
Bjarne Oeverli e751da36fd Update owe to 0.2.0
The release brings the lock feed: the daemon hands the locked session's
video to the shell as shared memory frames.
2026-09-18 22:54:51 +02:00
Ryan Hughes ddeb75aa4f Merge pull request #517 from omacom/hype/add-package
Add Hype presentation editor package
2026-09-18 13:05:39 -07:00
David Heinemeier Hansson 4fb4dafa1d Package 4K PowerPoint export rendering 2026-09-18 21:29:00 +02:00
Bjarne Oeverli 9013b97fcc Add owe, the wallpaper engine for video backgrounds
The OWE engine owns desktop video backgrounds in omarchy#12429. This
recipe is imported from the owe AUR package and watches the vX.Y.Z tags
on omacom/owe. It builds for x86_64 and aarch64.

0.1.1 is the first release that plays the wallpaper audio track.
2026-09-18 21:26:58 +02:00
Ryan Hughes 509c24b8c2 Merge branch 'master' into hype/add-package 2026-09-18 12:14:15 -07:00
Ryan Hughes 5580f21725 Merge pull request #518 from omacom/builder-qemu-10
Builders emulate aarch64 with QEMU 10.2.3 instead of the abandoned 7.2 image
2026-09-18 12:13:49 -07:00
David Heinemeier Hansson ae0e7407e3 Package animated-image PowerPoint export support 2026-09-18 21:04:53 +02:00
David Heinemeier Hansson 16087f19b4 Verify Hype Git source with makepkg checksum 2026-09-18 20:57:38 +02:00
Ryan Hughes efff828746 Builders emulate aarch64 with QEMU 10.2.3 instead of the abandoned 7.2 image
multiarch/qemu-user-static stopped at QEMU 7.2 (January 2023). Under it,
qmake's compiler probe (`g++ -E -v` in toolchain.prf) returns nothing on the
current gcc 16 toolchain, so every qmake package fails on aarch64 with
"failed to parse default include paths from compiler output" (hype, PR #517).
The same PKGBUILD builds under QEMU 10.2.3 and 11.1.

Register through tonistiigi/binfmt at a pinned tag, on both the ephemeral
builder droplets and the rootful-Docker path of setup_qemu, uninstalling any
existing entry first because the tool keeps an older registration in place.
The tag is now the one place that decides what every emulated build runs
under. Flags stay F and C, which rootless sudo inside the builder needs.
2026-09-18 14:56:03 -04:00
David Heinemeier Hansson 5cdaca6048 Include animated WebP support in Hype package 2026-09-18 20:18:08 +02:00
David Heinemeier Hansson 8411b99fc4 Add Hype presentation editor package 2026-09-18 20:16:05 +02:00
Ryan Hughes 7a3f00b924 Merge pull request #515 from omacom/report-build-failures
Publish report covers build failures and package sources
2026-09-18 11:03:19 -07:00
Ryan Hughes a24c56cd52 Dispatch: a package already published at master's version is a no-op, not a failure
Re-running publish for a package that is already live (a dispatch for
something that turned out fine, or a retry after a partial failure) made
bin/build report nothing to build and exit 2, which the publish step
treated as an error. The collect step now dry-runs first: if the channel
already holds master's version the package is recorded as
already-published and skipped, and a run where every package is in that
state exits cleanly with a record saying so.
2026-09-18 14:01:07 -04:00
Ryan Hughes 4717cfec4e Publish record covers build failures, and says where each package came from
When a package had no PR artifact and its build failed, the publish
step never ran, no record was written, and the report job failed
looking for it. The collect step now records each package's source
(PR artifact, built here, or build-failed) and writes the record itself
when a build fails, so the report can say plainly that nothing was
published and why.
2026-09-18 13:39:56 -04:00
Ryan Hughes 16ce7ef109 Merge pull request #514 from omacom/empty-pr-fails
Fail the PR check when the diff against base is empty
2026-09-18 09:57:17 -07:00
Ryan Hughes 54685a55a1 PR check fails when the PR changes no files relative to its base
A PR whose diff against its base is empty has already landed some other
way, typically a sync PR carrying the same bump or a merge from master
that swallowed it. Merging it records a change that isn't one and could
mask a real mistake. result now fails with a message saying to close it.
2026-09-18 12:55:18 -04:00
Ryan Hughes 25862ce7bb Merge pull request #513 from omacom/publish-report
Report each publish on the PR and in a public JSON log
2026-09-18 09:52:57 -07:00
Ryan Hughes 902f6d3da9 Report each publish: comment on the merged PR, append to a JSON log in the bucket
The publish job now writes publish-record.json describing every
channel/architecture slot it touched: the packages, whether the slot was
published or failed, the target (live or a proof prefix), the commit and
the run. A report job renders that as a comment on the PR the merge
commit came from (looked up by commit, so squash and rebase merges work)
and appends the record as one line to publish-log.jsonl in the bucket,
served next to the packages at https://pkgs.omarchy.org/publish-log.jsonl.
Failures are reported too, with the slots that landed before the failure,
which is when a human most needs to know.
2026-09-18 12:42:47 -04:00
Ryan Hughes f1c8da41f5 Merge pull request #504 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-09-18 09:26:33 -07:00
Ryan Hughes 3260b21deb Merge branch 'master' into auto/sync-upstream 2026-09-18 09:02:19 -07:00
Ryan Hughes 290793fdcc Merge pull request #511 from omacom/upstream/ci-builds
Build PRs on ephemeral droplets; publish merged packages from CI
2026-09-18 08:55:11 -07:00
Ryan Hughes 5a701be9d1 PR plan job: bootstrap when the base branch has no bin/build-matrix yet 2026-09-18 11:46:50 -04:00
Ryan Hughes 537c377fa5 Build PRs on ephemeral droplets; publish merged packages from CI
Every pull request now builds the package directories it touches on
ephemeral DigitalOcean droplets, and every merge to master publishes the
resulting artifacts into the channels each package belongs to. The
repository host's timers become the fallback rather than the pipeline.

Build (.github/workflows/build-pr.yml)
  One job per package per architecture, always against edge. The artifact
  is labelled with the package directory's git tree hash. Tooling (bin/,
  helpers/, build/) is checked out from the base branch; the PR supplies
  only pkgbuilds/, so a PR can change what is built, never how. Builds
  run only for trusted authors: collaborators, .github/VOUCHED.td, or a
  PR carrying the build-approved label. A single required check, result,
  aggregates the matrix.

Publish (.github/workflows/publish.yml, bin/publish-artifact)
  One job per merge. It collects the PR artifacts for the merged tree,
  builds anything that has none, then walks each channel/architecture
  slot once: pull that database, repo-add every package that belongs in
  it, upload packages, signatures, then the database. A published
  filename is immutable; identical bytes under an existing name only
  gain a database entry, different bytes are refused. Fast-ring packages
  reach edge, rc and stable in the same run from the same file.

Matrix (bin/build-matrix)
  Package x architecture, with the channels the artifact ships to,
  decided by package_builds_for_mirror so CI and the host agree.
  arch=any packages build once and land in every architecture database.

Builder (build/build.sh, bin/build, build/Dockerfile)
  With no local published tree, plan against and resolve from the public
  channel over HTTPS. PACKAGER is set to Omarchy. rclone is in the image.

Runners (ci/)
  A controller droplet polls GitHub with curl and creates one g5 droplet
  per queued job from cloud-init, deleting them when off or over-age.
  Builders carry QEMU with credential support for aarch64. Operator SSH
  keys come from GitHub. tests/controller.sh and tests/publish-artifact.sh
  cover the decisions against fixtures and real makepkg output.

Tests run on pull requests only; branch protection requires result,
self-tests and build-isolation with up-to-date branches.
2026-09-18 11:25:32 -04:00
Basti b422d37fa2 Drop privileges when seeding Dell haptic config (#497)
The root-run package hook changed ownership of paths below a
user-controlled home directory. A config symlink could redirect chown to
an arbitrary root-owned file during installation or upgrade.

Run the config writer as the target desktop user and remove the privileged
ownership changes. This also prevents the missing-config path from writing
through a user-controlled pathname as root. Add regression coverage and
bump the package release.

Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com>
Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
2026-09-18 15:24:41 +02:00
dhh d7fe983681 chore: sync upstream releases 2026-09-18 11:30:05 +00:00
Spencer Bull 5cccebaa17 Merge pull request #507 from omacom/cua-aquamarine-0151
Refresh Cua plugin profile for Aquamarine 0.15.1
2026-09-18 01:54:11 -05:00