Package Link Studio 1.0.2 with its AUR-only MediaPipe and sounddevice dependencies. Wire Link Studio to GitHub release checksums, keep all three packages on the fast ring, and make MediaPipe's Bazel bootstrap a checksummed makepkg source.
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.
Edge is the channel the 4.0.2 RC ISOs point pacman at until the rc-channel
migration lands, but edge only carried omarchy 4.0.1 — older than the
installed 4.0.2rc1, so those installs never saw an upgrade. Bumping master's
pin lets the normal edge pipeline build and publish 4.0.2rc2, whose migration
repoints [omarchy] at the rc channel.
Stable is unaffected: pinned packages never build for stable
(package_builds_for_mirror), it only receives them via the rc->stable advance
at ship time.
(cherry picked from rc-branch pin commit 11767d6)
Ship the least-privilege rule with asdcontrol so authorization follows the package lifecycle. Install it after older broad rules for safe staggered upgrades.
Picks up the audience-window fix released in v0.1.1: the audience view is now
an independent native Wayland top-level, so a compositor or share portal can
offer it on its own instead of only exposing the editor window. Without it,
screen sharing a deck on a call does not work correctly.
pkgver carries the source URL, which interpolates it, so the package now builds
the immutable v0.1.1 tag archive. The checksum is that archive's sha256.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HzjoHuTSiuzFsMuJwnuQ7c
Same upstream release, so only pkgrel moves. Built from v0.0.35-omarchy.4,
which carries the fixes from nine rounds of review on the upstream PR: the
CLI no longer overwrites an unreadable settings.json, setting a
single-appearance theme actually switches the client, reconnects no longer
flash published themes back to stock, and already-shipped clients keep
their config subscription instead of losing it to an unknown event.
Comment-only. The .env requirement and the fact that only a PKGBUILD
version change triggers the build server both bit us once each; the
recipe now lives where the next rebuild starts.
The r2 artifact was built without the public Connect configuration official
artifacts carry (relay URL, Clerk publishable key, CLI OAuth client id), so
Connect prompted for login with no way to log in. Same code, rebuilt with
the configuration recovered from the published npm t3 package.
Rebuilt from v0.0.35-omarchy.2 of the environment-theme branch: the stream
event is capability-gated so old clients keep their config subscription,
republish dedupe is structural, the connect stream is gap-free, default
adoption is scoped per environment and keyed on the set generation, and
reserved theme ids cannot be published over. Joins the fast ring like
t3code-bin so patch rebuilds reach machines quickly.
Built from the environment-theme branch of ryanrhughes/t3code (tag
v0.0.35-omarchy.1) until upstream ships it: the app follows themes the
machine publishes into its state directory -- Omarchy retints it live --
and t3 theme set works. Same packaging as t3code-bin, conflicts with it,
and the next upstream release supersedes it after a rebase.
The desktop bundle already contains the full server -- the same entrypoint
npm's t3 package runs -- so a launcher that starts it through the bundled
Electron as Node puts the CLI on PATH without a second runtime. Upstream
only distributes the CLI via npm, which Omarchy's install scripting cannot
assume.
The rc channel's Arch base can sit anywhere between stable's snapshot and
edge's, so a package built against stable's libraries is not necessarily
correct for rc. Copying stable's fast-ring artifacts into rc therefore shipped
possibly-mislinked packages to RC testers. Fast-ring packages now build
natively for all three channels, each in its own image against its own base
mirror, and the stable release's replication step is gone.
That required separating 'may be built here' from 'whose version wins'. The
release pair is now marked "pinned": its version is set per release on the rc
branch, so it builds for rc only from that branch's worktree
(OMARCHY_RC_PINS=1, set by omarchy-release rc) — master's shipped pins can
never overwrite an in-flight RC, even though check-versions now discovers rc
work like it does for edge and stable.
Synced from the AUR at 04592d5. Two upstream releases land together: 4.29.5
hardened the aether protocol imports and moved the repository links from
bjarneo to omacom-io, which is why the url and every source line change here
as well; 4.29.6 disables WebView GPU acceleration on Linux. The packaging
itself is untouched between the two -- only pkgver and the checksums differ --
so taking HEAD rather than pinning 4.29.5 costs nothing and carries the
hardening either way.
aether is fast ring, so this reaches stable without an edge-to-stable
migration once it is built for that mirror.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Pin the official Linux .deb to Cursor stable 0.29.0 (commit f0e5bfce).
Binary, icons, and grokbot:// handler are unchanged from 0.24.0; keep the
Wayland wrapper and /usr/bin/sand compat symlink.
Linux still has no update feed. Leave pinning to update-pkgver.sh.
Matches what is already published to edge: 0.0.34 was built on the server
before the bump reached git, so the checkout read as out of date and queued a
rebuild of the older 0.0.33-2 that promotion then refused. Produced by
bin/sync-upstream, the same path the scheduled workflow uses.
A package's .omarchy/package.json may now pin where it lives with
"channels": [...]. With the key present the package builds in each listed
channel except stable (stable is only fed by promotion); without it, today's
defaults hold (build for edge; fast-ring also builds stable directly).
package_moves_to_channel() is the advance/promote eligibility rule: a member
of the destination channel that is not built there natively.
The release pair (omarchy, omarchy-settings) is edge+rc+stable — edge stays
during the client-migration overlap window and drops later. The dev pair is
pinned to edge only.