Moving the whole module broke the rest of it: Writer::create needs a
runtime directory on a different filesystem from the copy, and with the
test root on /dev/shm none qualifies. Only
a_garbage_stream_falls_back_with_the_tree_untouched opens its manifest
in its own test dir, which the builder's /tmp refuses (EOPNOTSUPP).
omacom/omarchy#13362 sets HOOKS per platform inside 00-omarchy-hooks.conf,
with no column-0 HOOKS= line, so the aarch64 build failed on it; settings-dev
tracks quattro automatically and would break as soon as it lands. Wrap only a
single-line HOOKS=(...), refuse any other column-0 HOOKS=, then source the
shipped files onto a Mac line and a stock line: the Mac line must come through
unchanged and the stock one must not. Back up 00-omarchy-hooks.conf when it
ships, and refuse it without the omarchy-hw-platform copy it asks.
The test now uses the real v4.0.4 hooks file, #13362's two files and
omarchy-mac-boot's 90-94 fragments, and covers upgrades over a hand-restored
file.
A merged aarch64 tree without a PR build artifact (expired after 7 days,
or a dispatch) was rebuilt on the x86 droplet under QEMU: omarchy-mac-boot
took ~167 of the 240 minutes. A new job builds it on ubuntu-24.04-arm the
way build-pr.yml does and uploads it under the same label, so the publish
job signs and uploads it on the droplet like a PR artifact. The plan logs
reuse or rebuild for every package; x86_64, signing and the publish
concurrency are unchanged.
0.3.5's copymanifest::tests::a_garbage_stream_falls_back_... opens its
anonymous (O_TMPFILE) manifest directly in its /tmp test dir, which the
x86_64 builder's /tmp refuses with EOPNOTSUPP. The sibling tests pass
because Writer::create falls back across directories. Same reason the
other filesystem_tests already run on /dev/shm; none of these spawn.
The upstream hook refused v0.3.5 as missing a required security fix. It
was not missing: copy_file_at now opens through
open_if_regular_with_meta(src.at, O_NOFOLLOW), which open_if_regular
wraps, and the gate's regex wanted '(' right after open_if_regular.
The gate dates from 0.1.x, when Omarchy carried four upstream security
patches and needed releases to prove they had absorbed them. Every
release since 0.1.5 has, and matching literal source lines has since
caught only renames (#488 and this one), never a regression. Keep the
real checks -- SHASUMS256.txt match, tarball root, minimum release age
-- and drop the greps.
Update written by bin/sync-upstream; the checksum matches upstream's
SHASUMS256.txt.
Monologue now publishes a GitHub release for every version, so declare
its v{pkgver} tags as the upstream feed, as Hype does. The scheduled sync
picks up new releases and hashes the tag archive, instead of pinning a
commit by hand. This first release brings Monologue to 0.2.0, which
builds trimming in, so the omacut optdepend goes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Elsewhen moved into the Omarchy shell as omarchy.elsewhen (basecamp/omarchy#13429),
and a migration there removes the installed package. Nothing else in the repo
references it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The first pins (quattro ee8ebf6, omasnap eb22bfe) date from 2026-09-21.
Edge has since published omarchy-dev from quattro 7b336b1 through a
manual rebuild, so merging the old pin would ship older code under a
higher version. Moved with the tracker's own code:
bin/sync-upstream --lane auto-merge (BYPASS_MIN_RELEASE_AGE=1)
Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
With the search race skipped, the aarch64 main suite ran to the end:
2339 passed, 2 failed. a_missing_working_directory_... expects spawn to
fail on a missing cwd, which posix_spawn cannot report under QEMU
user-mode. in_place_retirement_... identifies its process by
/proc/<pid>/exe, which names /usr/bin/qemu-aarch64 there, not sleep.
Apple Silicon Macs install the aarch64 package too, and an unconditional
HOOKS= line would replace their asahi hooks. Apply Omarchy's HOOKS line only
when the incoming hooks lack asahi, in whichever drop-in carries it, and
rebuild omarchy-settings (4.0.4-3) so existing installs get the fix.
The droplet pool is x86, so aarch64 builds ran under QEMU about 30x slower;
omarchy-mac-boot's check() took 2h47m of the 180-minute job limit. Heavy
packages stay on the droplets until a native build of each is shown to fit.
From omacom/omarchy-mac#567 the add-on enables speakersafetyd itself and its
README says the recipe declares mkinitcpio and the protected speaker stack
(asahi-audio, which pulls speakersafetyd, alsa-ucm-conf-asahi, rtkit,
pipewire-alsa).
Both packages move to the same omarchy-mac commit, so speakersafetyd keeps
one owner (#567 with #535) and the boot entrypoints the runtime needs publish
first. omarchy-mac gains the Apple Silicon platform group its source's guard
contract names.
makepkg runs check() inside the build container and meson writes each
test's output to the build tree, not to stdout. A failing test therefore
leaves only a summary line in the job log. Diagnosing it means reading
the package source and inferring the cause.
bin/build bind-mounts $SRC_DIR at /src, so the logs outlive the
container at src/**/meson-logs/ on the runner. Upload them when the
build step fails.
owe 0.2.7 showed the cost: owe:transition failed on aarch64 and passed
on x86_64, and CI carried no record of which assertion tripped.
Co-authored-by: Bjarne Oeverli <1419214+bjarneo@users.noreply.github.com>
strata: the example actions' image test needs ImageMagick with WebP
(checkdepends), the checksum example dies printing a non-UTF-8 name
under the builder's en_US.UTF-8 locale (upstream bug, skipped), and on
aarch64 a search refresh test loses a race to the index worker.
flea: on aarch64 the 1900-deep dirsize walk hits its 2 s deadline, and a
process-group cancel test loses its 5 s race under emulation.
owe: on aarch64 the transition test cannot render enough blended frames
under emulation; run every other test there.
Versions and checksums as in sync PR #660.
Three things kept the upstream sync PR (#589) from ever finishing a build:
Scoped dispatches wiped the shared PR. A workflow_dispatch with `packages`
regenerates only those packages from master, and pushing that to
auto/sync-upstream replaced 38 pending updates with one. Scoped runs now
push to their own auto/sync-{upstream,rebuilds}-<packages> branch and PR;
scheduled runs keep the shared branch.
build-approved stopped working after the first bot push. A GITHUB_TOKEN
push creates pull_request runs held for approval but no pull_request_target
run, so approve-pr.yml never saw it: its last run on the branch was the
label itself (2026-09-25T19:26), and each of the next four syncs sat at
action_required. The sync workflows now release the held runs for the
commit they just pushed, from a separate job holding actions: write, and
only for their own bot-authored, same-repo PR while build-approved is on
it.
Each approved push cancelled the in-flight build. Approving the 21:43
sync's build cancelled the label-triggered one still queued on strata and
schist-bin. On auto/sync-* branches a new build now waits for the running
one instead, then reuses its artifacts. The approval script no longer
waits for a lone approved build to start before releasing tests, which a
queued build would have turned into a timeout.
TMOG 1.0.0 moved the site under /rtm/ and publishes each Linux tarball
under a versioned name with a .sha256 sidecar. The versionless
/downloads/TMOG-Task-Manager-Linux-x86_64.tar.gz path the hook fetched
now returns 404, so every upstream sync since 1.0.0 has failed.
Point source=() at the versioned tarball and have the hook read the
version from /rtm/version.txt and the checksum from the sidecar, which
drops the 8 MB download and the directory-name check the mutable URL
needed.