Omarchy 4 no longer uses Elephant or the omarchy-walker meta package, and
omarchy-upgrade-to-quattro removes them; every channel serves Omarchy 4.0.4.
Nothing else here depends on them. walker itself stays.
Deleting a recipe stops it building but leaves it in the channel databases,
and the only removal tool worked on the old repository host's local tree.
Add bin/unpublish-packages, publish-artifact's counterpart: pull the channel
database, repo-remove every entry built from the named pkgbases, upload it.
Package files stay in the bucket. unpublish.yml runs it per channel and
architecture under the publish lock, for packages with no recipe on master.
* Automate Grok Bot releases
* Refresh Grok Bot to apt 0.66.0 and harden upstream.sh
Bump both architectures to Cursor apt 0.66.0 with matching SHA256s,
introduce a versioned _pool URL helper, and filter Packages stanzas by
Package: grok-bot so sync stays correct if the index grows.
* grok-bot: bump to 0.68.1, drop manual hold, validate pool filename
Bump both architectures to Cursor apt 0.68.1 with the SHA256s from the
amd64/arm64 Packages indexes (verified against the downloaded debs).
Drop grok-bot from the manual holds list in docs/upstream-sources.md and
have upstream.sh check that the newest stanza's Filename is the versioned
pool path the PKGBUILD downloads from. Both additions come from #848.
Build it in edge and promote through rc to stable like other packages,
matching cua-hyprland-plugin, which left the fast ring in #432.
#693 held upstream sync while 0.28.3+ breaks screenshots. Make that the
standing policy: Omarchy bumps the driver by hand, so the PKGBUILD no
longer says to re-enable sync after the fix, and docs/upstream-sources.md
records the hold. The hook and min_release_age stay, so lifting the hold
is a one-line revert.
Publish as 0.28.2-3 so the PR builds; the payload is unchanged.
Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
The Panther Lake XPS 13 (audio subsystem 1028:0e54) drives all of its
speakers through two CS35L56 amplifiers behind the CS42L43 codec. Their
DSP firmware aliases (cs35l56-b2-dsp1-misc-10280e54-spkid{1,2,3}) were
added to linux-firmware on 2026-08-18 and ship in Arch's
linux-firmware-cirrus 20260910-2, but the stable channel's Arch snapshot
is still on 20260810-2. Without them the amps run ROM firmware and the
machine is completely silent; upstream 7.2 already selects the sidecar
amplifier path for this SSID, so no kernel change is involved.
Ship the 20260910-2 payload to stable as a self-retiring shim:
- fast ring, no upstream watch (sync: false): the version is deliberately
20260810-3, above the snapshot's 20260810-2 and below Arch's real
20260910-2, so the genuine package supersedes it in the same
transaction that upgrades linux-firmware-other once the snapshot
advances. Bumping pkgver would defeat that.
- the signed Arch package is verified against the Arch packager key in
keys/pgp/ and reinstalled as-is, minus the cs42l45 SDCA tree that Arch
moved out of linux-firmware-other in 20260910: on the stable snapshot
those 190 files are still owned by -other 20260810-2 and would
conflict. The nine 10280e54 links and the 39 new SDCA files are kept.
Verified on a DX13260: cold boot loads 10280e54-spkid1 v4.5.9 on both
amps with "Calibration applied", and a 440 Hz tone measured through the
internal microphones peaks 238x over the noise floor on the stock UCM
bridge route. Delete this recipe once stable's snapshot carries
linux-firmware >= 20260910.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>