Bambu Studio is the official slicer for Bambu Lab printers. Linux builds
are GitHub AppImages with a changing timestamp in the filename, so this
tracks the AUR bambustudio-bin package that already resolves those
assets, and puts it on the fast ring so stable users get updates with
omarchy update.
Two small Omarchy patches: skip stripping the extracted AppImage, and
clear the AppImage ELF magic byte so --appimage-extract works in the
build container. The desktop entry is labeled Bambu Studio and grouped
under Graphics.
Validation: bin/add-package + bin/sync-aur reapply the patches; AUR +
.omarchy reproduces the checked-in tree. Built and launched the 2.8.2.61
AppImage on Omarchy 4.0.3 (x86_64); bambu-studio --help reports
BambuStudio-02.08.02.61. AUR is currently 02.08.02.60; the next AUR bump
will sync through.
* Package Omawake 0.0.3 and Omaspeak 0.0.2
Bump both -bin packages to the model-support roadmap delivery:
Omawake 0.0.3:
- W02-W05 setup/activation/cache gates audited and closed
- W07 pinned catalog URL health checks and import diagnostics
- W08 Moonshine Small/Medium benchmarked; both deferred (Tiny default)
- W09 Spanish wake profile (multilingual Whisper Base INT8, es)
- W10 connection-owned playback pauses (HoldPause)
Omaspeak 0.0.2:
- S09 Kokoro 82M: Kokoro-capable packaged provider (supertonic;kokoro_tts)
with espeak-ng-data.bin shipped beside the executable, 54 named voices
- S10 catalog URL checks, Spanish speech profile, consistent status shape
- S07 streaming deferred at the current pin
Upstream: omawake v0.0.3, omaspeak v0.0.2 (aarch64 + x86_64 verified on
promaxgb10-d666 CUDA and local NPU installs).
* omaspeak-bin: install espeak-ng-data.bin beside the packaged library
* omaspeak-bin: bump to 0.0.3-rc.1 (catalog-managed eSpeak data)
- The tarball no longer ships espeak-ng-data.bin: the Kokoro catalog row
pins the data package as a model asset (downloaded/verified/installed
into the model directory with the GGUF), so the core package ships no
model data at all.
- Both arch checksums taken from the v0.0.3-rc.1 SHA256SUMS.txt.
* omaspeak-bin: finalize at 0.0.3
* Stop setup-created Oma services before pacman removes their binaries
* Drop stale release-verification fixtures from the branch
These were swept in by git add -A during the version bumps: packaged
copies of old releases (0.0.1 tarballs and extracted trees, ~80 MB)
belong to the local verification workflow, not to the package repo.
The consolidated upstream PR should carry only the package changes,
hooks and the removal regression suite.
* Update removal-test fixture versions to the packaged finals
* Ask systemd to reset only an Oma unit that actually failed
The removal helper reset the failed state of every unit it stopped, but
systemd accepts ResetFailed for a unit that is in the failed state alone.
For any other state it answers that the unit is not loaded and exits
non-zero, and because the helper runs under errexit while the hook aborts
on failure, a healthy unit then aborted the whole transaction:
(2/2) Stop and remove omaspeak user services before package removal
Failed to reset failed state of unit omaspeak.service: Unit omaspeak.service not loaded.
:: Could not clean up omaspeak for jacob; removal aborted.
That is the ordinary case, as the packaged service ships disabled and an
enabled one is commonly stopped rather than failed. Read the active state
after the stop and ask for the reset only where it applies, so a failed
unit still loses its failed state along with its rate and restart counters
while a clean unit no longer fails the removal. A reset that a reachable
manager still refuses stays fatal.
Model the rule in the removal suite, where reset-failed now follows the
active state the way a real manager does, and cover both outcomes: an
inactive unit must not be asked for, a failed one must be reset between
the stop and the disable, and a refused reset must still fail the hook.
* Keep removal cleanup faithful to how systemd reads configuration
Both defects from the review of e025111 sat in the shared package-remove
helper, so both packages were affected the same way.
An offline user's drop-in was recognised by grep '^ExecStart=', while the
configuration parser throws away the whitespace around an assignment
(parse_line() strips the line and both halves of the assignment). A drop-in
naming a development build as
ExecStart =
ExecStart = /home/alice/build/omawake daemon
therefore went unmatched, and the helper cleared away the generated base unit
beside with its enablement links, right behind a service that was never meant
to be the package's. Match an assignment the way the parser accepts one. The
gate that decides whether a unit file is the generated one stays strict on
purpose: only the exact generated shape is ever deleted.
systemctl show-environment also prints every value the way a shell would read
it, through shell_maybe_quote(SHELL_ESCAPE_POSIX), so an XDG_CONFIG_HOME with a
space arrives as $'/home/alice/custom config'. The XDG_CONFIG_HOME=/* case saw
neither form and kept the home's .config directory quietly, leaving the unit in
the directory the manager really reads pointing at the removed binary. Decode
that quoting character by character, without letting the text become shell
syntax, and refuse a value that is neither a plain path nor a closed $'...'
quote rather than delete what would have to be guessed at. A value that is not
an absolute path stays the fallback it is in systemd itself.
The fixtures now hand the helper the very text a manager prints, quoted by a
mirror of that printer, and cover a quoted path with a space, an apostrophe and
a backslash, an unreadable quoted value, a relative one, and each spacing of an
offline override. Verified with the removal suite, 15 tests; the eight new
assertions fail against the helper as it was. The other suites were not run
here, as they reach for the network.
pkgrel 3 -> 4 and the helper's checksum, in both recipes.
Reported-by: spencerbull
* Decode systemd control escapes during service removal
systemctl C-escapes control bytes in show-environment output. Rejecting those valid values aborted package removal for every user, even when the affected account had no Oma service. Decode the printer’s named and octal escapes without evaluating shell syntax or stripping trailing newlines, and cover the real printer format in the fixtures.
Co-Authored-By: GPT-6 XHigh <noreply@openai.com>
---------
Co-authored-by: Spencer Bull <spencer@omarchy.org>
Co-authored-by: GPT-6 XHigh <noreply@openai.com>
The package was added pointing at v0.1.0 with a placeholder checksum,
but that tag was never cut; upstream went straight to v1.0.0. The
package has never built anywhere. Point at the real tag and fill the
digest. The upstream watch keeps it current from here.
The lock screen draws video through Owe.LockFeed in omarchy#12429. The
module maps the frame slots the OWE renderer publishes, with no media
pipeline of its own. It builds from the qml-plugin directory of the owe
release and installs to the Qt QML module path.
The OWE engine owns desktop video backgrounds in omarchy#12429. This
recipe is imported from the owe AUR package and watches the vX.Y.Z tags
on omacom/owe. It builds for x86_64 and aarch64.
0.1.1 is the first release that plays the wallpaper audio track.
The root-run package hook changed ownership of paths below a
user-controlled home directory. A config symlink could redirect chown to
an arbitrary root-owned file during installation or upgrade.
Run the config writer as the target desktop user and remove the privileged
ownership changes. This also prevents the missing-config path from writing
through a user-controlled pathname as root. Add regression coverage and
bump the package release.
Reported-by: piratemoo (Esther) <22439214+piratemoo@users.noreply.github.com>
Link: https://github.com/piratemoo/Arbitrary-File-Ownership-Change-via-Symlink-LPE
Unset CONFIG_ZERO_CALL_USED_REGS to disable the kernel hardening
feature, allowing for older NVIDIA drivers to build successfully
against the new kernel.
Signed-off-by: Krzysztof Wilczyński <kwilczynski@omarchy.org>
The Panther Lake XPS 13 (audio subsystem 1028:0e54) drives all of its
speakers through two CS35L56 amplifiers behind the CS42L43 codec. Their
DSP firmware aliases (cs35l56-b2-dsp1-misc-10280e54-spkid{1,2,3}) were
added to linux-firmware on 2026-08-18 and ship in Arch's
linux-firmware-cirrus 20260910-2, but the stable channel's Arch snapshot
is still on 20260810-2. Without them the amps run ROM firmware and the
machine is completely silent; upstream 7.2 already selects the sidecar
amplifier path for this SSID, so no kernel change is involved.
Ship the 20260910-2 payload to stable as a self-retiring shim:
- fast ring, no upstream watch (sync: false): the version is deliberately
20260810-3, above the snapshot's 20260810-2 and below Arch's real
20260910-2, so the genuine package supersedes it in the same
transaction that upgrades linux-firmware-other once the snapshot
advances. Bumping pkgver would defeat that.
- the signed Arch package is verified against the Arch packager key in
keys/pgp/ and reinstalled as-is, minus the cs42l45 SDCA tree that Arch
moved out of linux-firmware-other in 20260910: on the stable snapshot
those 190 files are still owned by -other 20260810-2 and would
conflict. The nine 10280e54 links and the 39 new SDCA files are kept.
Verified on a DX13260: cold boot loads 10280e54-spkid1 v4.5.9 on both
amps with "Calibration applied", and a 440 Hz tone measured through the
internal microphones peaks 238x over the noise floor on the stock UCM
bridge route. Delete this recipe once stable's snapshot carries
linux-firmware >= 20260910.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Upstream 0.9.1 bumps vendored libghostty-vt's minimum_zig_version to
0.16.0, so the pinned Zig tarballs move from 0.15.2 to 0.16.0 with
checksums taken from ziglang.org's download index.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Upstream sync has failed on every run since flea v0.3.0 was published, with
"Release v0.3.0 does not contain every required upstream security fix". Eight
of the nine required fixes are present. The ninth is too: the check is wrong.
The check pinned the literal call `regfile::open_if_regular(src, O_NOFOLLOW)`.
v0.3.0 introduced directory-relative opens and the first argument became
`src.at`. O_NOFOLLOW is still passed to the same function, on the same line,
under the same comment, and the release hardened symlink handling further --
it added copy_symlink_at, opens directories with O_DIRECTORY | O_NOFOLLOW, and
reaches every child through this process's own descriptor. The guard refused a
release that is strictly safer than the one it accepted.
The property worth asserting is that the copy opens its source with
O_NOFOLLOW, so a symlink swapped in cannot redirect the read. Pinning the
exact expression asserted the spelling instead, which is why a rename read as
a removed fix. The check now matches the call and the flag together.
Verified against the real archives rather than by inspection:
v0.3.0 (src.at, O_NOFOLLOW) accepted
v0.2.1 (src, O_NOFOLLOW) accepted, so the change is backwards
compatible with what is packaged today
first argument renamed accepted
extra flag or argument added accepted
O_NOFOLLOW dropped refused
call replaced with File::open refused
flag left only in a comment refused
End to end with the real feed: the hook on master exits 1 with the refusal,
and with this change exits 0 and reports 0.3.0 with its verified checksum.
The other eight literals are untouched.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
A channels list of edge alone is the outer bound on where a package may build, so both packages were refused for rc and stable and could only ever reach edge users. The fast ring builds them natively for all three channels, each against its own base mirror, which is how the other prebuilt -bin applications here ship. The channels key has to go rather than sit beside the ring: package_builds_for_mirror checks it first, so an edge-only list would still block the rc and stable builds the ring asks for.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Each package ships libaudiocpp, which upstream's own third-party notices describe as Apache-2.0 with BSD-3-Clause PocketFFT-derived code retained in it, and installs those texts under /usr/share/licenses. A license array of MIT alone describes only the project's own source, so pacman -Qi misreports what the package contains.
Co-Authored-By: GPT-6 Astra XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The builder's makepkg.conf enables debug and emptydirs. With strip off, makepkg still takes the debug branch of tidy_strip, creates usr/src/debug/<pkgbase> inside the package to hold debug sources, finds none in a prebuilt tree, and emptydirs then ships the empty directory to every user. Seven of the ten -bin packages here that disable strip already disable debug with it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The top-level .gitignore excludes pkgbuilds/*/.SRCINFO and pkgbuilds/*/.gitignore, and none of the packages under pkgbuilds/ tracks either. These four were added under the retired pkgbuilds/edge/ path, which that rule does not cover, and the move to pkgbuilds/ carried them along as already-tracked files. The per-package .gitignore negates the repository rule for its own directory and its leading * hides every future file there, so a patch or an .omarchy/upstream.sh dropped beside the PKGBUILD would never show up in git status. The build planner reads PKGBUILD and .omarchy/package.json; the only other reader, bin/package-worktree, takes .SRCINFO as a fallback while importing from the AUR and then removes both files as AUR-only.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Give background agent seats independent keymaps and check foreground keyboard compatibility per operation. Package the downstream patch with separate source integrity and build provenance, retaining the upstream ABI verifier.
Co-Authored-By: Codex XHigh <noreply@openai.com>