Moving the whole module broke the rest of it: Writer::create needs a
runtime directory on a different filesystem from the copy, and with the
test root on /dev/shm none qualifies. Only
a_garbage_stream_falls_back_with_the_tree_untouched opens its manifest
in its own test dir, which the builder's /tmp refuses (EOPNOTSUPP).
0.3.2 moved the Quickshell entries into ui/boot, and the 0.3.4-1 package here does not
install them, so flea exits with "the shell config is missing" (thisisgm/flea#216).
This installs ui/boot with its Commons and Ui links, bumps to 0.3.5, and ships the
pacman hook that notes on removal what flea --default and --picker left behind.
0.3.5's copymanifest::tests::a_garbage_stream_falls_back_... opens its
anonymous (O_TMPFILE) manifest directly in its /tmp test dir, which the
x86_64 builder's /tmp refuses with EOPNOTSUPP. The sibling tests pass
because Writer::create falls back across directories. Same reason the
other filesystem_tests already run on /dev/shm; none of these spawn.
The upstream hook refused v0.3.5 as missing a required security fix. It
was not missing: copy_file_at now opens through
open_if_regular_with_meta(src.at, O_NOFOLLOW), which open_if_regular
wraps, and the gate's regex wanted '(' right after open_if_regular.
The gate dates from 0.1.x, when Omarchy carried four upstream security
patches and needed releases to prove they had absorbed them. Every
release since 0.1.5 has, and matching literal source lines has since
caught only renames (#488 and this one), never a regression. Keep the
real checks -- SHASUMS256.txt match, tarball root, minimum release age
-- and drop the greps.
Update written by bin/sync-upstream; the checksum matches upstream's
SHASUMS256.txt.
strata: the example actions' image test needs ImageMagick with WebP
(checkdepends), the checksum example dies printing a non-UTF-8 name
under the builder's en_US.UTF-8 locale (upstream bug, skipped), and on
aarch64 a search refresh test loses a race to the index worker.
flea: on aarch64 the 1900-deep dirsize walk hits its 2 s deadline, and a
process-group cancel test loses its 5 s race under emulation.
owe: on aarch64 the transition test cannot render enough blended frames
under emulation; run every other test there.
Versions and checksums as in sync PR #660.
Both upstreams set fat LTO in their release profile (strata also
codegen-units = 1), which compiles the final crate on one thread. That
is a reasonable trade for the binary users run, and build() keeps it.
check() then compiled the same crate a second time under the same
profile for the test harness, and threw it away. On the aarch64 builds,
which run under QEMU, those two serial compiles were 106 of strata's
118 minutes.
check() now builds the harness with thin LTO and 16 codegen units in
its own target directory. The shipped binary is unchanged. Measured on
the x86_64 builder for strata's test binary: 708 s serial, 223 s with
this profile. Local run: shipped strata still 7m30s from target/, tests
3m43s from target-check/, 1998 passed.
ttfx has the same upstream profile but no check(), so nothing to do.
flea 0.3.0 never published: its shelfundo suite (new in 0.3.0) failed check() on the 2026-09-18 publish build, and 0.3.1 fails the same way on the sync PR. undo_refuses_to_walk_a_stranger_back deletes a file, creates another under the same name, and expects undo to tell them apart by (dev, ino, kind). ext4 hands the freed inode number straight back to the next create, so on the droplet's /tmp the stranger is identical and undo walks it back into a directory that does not exist. tmpfs allocates inode numbers from a counter and never reuses one. The suite joins the filesystem tests that already run with TMPDIR on /dev/shm.
On aarch64 three more tests fail: two in backend::child and one in menu_registry expect spawning a missing program to be reported as not started. Under QEMU user-mode emulation glibc's posix_spawn cannot observe the child's failed execve; the spawn succeeds with exit 127. Skipped on aarch64 only.
Upstream sync has failed on every run since flea v0.3.0 was published, with
"Release v0.3.0 does not contain every required upstream security fix". Eight
of the nine required fixes are present. The ninth is too: the check is wrong.
The check pinned the literal call `regfile::open_if_regular(src, O_NOFOLLOW)`.
v0.3.0 introduced directory-relative opens and the first argument became
`src.at`. O_NOFOLLOW is still passed to the same function, on the same line,
under the same comment, and the release hardened symlink handling further --
it added copy_symlink_at, opens directories with O_DIRECTORY | O_NOFOLLOW, and
reaches every child through this process's own descriptor. The guard refused a
release that is strictly safer than the one it accepted.
The property worth asserting is that the copy opens its source with
O_NOFOLLOW, so a symlink swapped in cannot redirect the read. Pinning the
exact expression asserted the spelling instead, which is why a rename read as
a removed fix. The check now matches the call and the flag together.
Verified against the real archives rather than by inspection:
v0.3.0 (src.at, O_NOFOLLOW) accepted
v0.2.1 (src, O_NOFOLLOW) accepted, so the change is backwards
compatible with what is packaged today
first argument renamed accepted
extra flag or argument added accepted
O_NOFOLLOW dropped refused
call replaced with File::open refused
flag left only in a comment refused
End to end with the real feed: the hook on master exits 1 with the refusal,
and with this change exits 0 and reports 0.3.0 with its verified checksum.
The other eight literals are untouched.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Every channel has failed since 0.2.1 landed: one package failing fails the
whole build, and the build step aborts the release before sign, promote or
sync. Nothing has published on edge, rc or stable since 2026-09-11, and 26
built packages have been rebuilt and discarded every cycle.
backend::redo::tests::redo_refuses_changed_sources_and_destination_collisions
writes a file and immediately asks redo to notice the edit. flea decides
"changed" from ctime alone -- src/backend/undo.rs records (ctime, ctime_nsec)
as the whole identity -- and this kernel stamps ctime from the coarse clock,
so two writes microseconds apart share a timestamp and the guard sees no
change. redo returns Ok where the test demands Err, which is why it fails
almost every run rather than intermittently.
Measured on this builder: 196/200 back-to-back write pairs on /dev/shm and
192/200 on the root filesystem produced an identical ctime. That also retires
the premise of 82363cb: /dev/shm does not buy finer timestamps here, so moving
the suite to tmpfs could never have fixed this, and the comment saying it does
is corrected. A probe cannot decide this at runtime either -- one using stat
reports the filesystem as fine-grained, because the stat subprocess alone
costs more than the granule it is trying to measure.
Both halves belong upstream in thisisgm/flea: the test assumes a resolution
the kernel never promised, and the identity it exercises cannot see a
same-granule edit, which is a real hole in undo/redo rather than only a test
artifact. Skipping one test is the narrow fix; holding the package back would
have stalled the other 26.
Only this test is affected. new_file_is_recreated_but_changed_or_replaced_
files_survive_undo asserts the same refusal and passes, because enough work
separates its write from the identity capture to cross a granule.
Verified with bin/repo build --package flea: filesystem suite 63 passed,
main suite 528 passed, flea 0.2.1-3 built.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>