Commit Graph
1240 Commits
Author SHA1 Message Date
Ryan Hughes ea9f615884 Bump strata to 0.11.2 ahead of its release-age hold
0.11.2 is 14 hours old, inside the package's 24h min_release_age, so the
upstream sync would not pick it up until tomorrow; ship it now by hand.
Tarball commit b000b79 verified against the v0.11.2 tag, checksum from
an independent download. The new Cargo dependencies (ashpd, zbus,
gdk4-wayland) are vendored crates needing no new system libraries.

0.11.2 also ships FileManager1/portal integration files. Stage the
FileManager1 service under /usr/share/strata the way upstream's own
PKGBUILDs do — the app copies it per-user on opt-in. The portal files
stay unpackaged, matching upstream: enablement is per-user and
consent-gated in the app.
2026-09-07 02:38:01 -04:00
Ryan Hughes a5d95385ca Merge pull request #325 from spencerbull/hermes-native-updates
Let Hermes Desktop update its native installation
2026-09-07 02:22:49 -04:00
Ryan Hughes 0518902619 Merge pull request #296 from omacom/auto/sync-aur
chore: sync AUR packages
2026-09-07 01:27:50 -04:00
ryanrhughes 6dc21c7763 chore: sync AUR packages 2026-09-07 05:26:37 +00:00
Ryan Hughes ca63e47ecd Stop auto-syncing retroarch-joypad-autoconfig-git from the AUR
The package carries a deliberate commit pin (59d557a) so every
architecture packages the same tree. The AUR sync kept trying to revert
that to the unpinned branch-tip recipe, recording a version downgrade in
the process. Mark it local so exactly one source owns the recipe; it is
Omarchy-maintained until it moves to an upstream release feed.
2026-09-07 01:23:14 -04:00
Ryan Hughes 2a3b3b9c36 Merge pull request #322 from btsouth/omakade-1.6.1
omakade: update to 1.6.1 with full runtime deps and aarch64
2026-09-07 00:02:13 -04:00
Tyler South 29c621f835 omakade: update to 1.6.1 with full runtime deps and aarch64 2026-09-07 00:01:38 -04:00
Spencer Bull b36bfce109 Restore Hermes PKGBUILD formatting 2026-09-06 22:53:12 -05:00
Ryan Hughes 34c12d99c7 Merge pull request #313 from omacom/auto/sync-upstream
chore: sync upstream releases
2026-09-06 23:52:53 -04:00
Spencer Bull beb164a9a2 Resolve Hermes profile homes before package setup 2026-09-06 22:29:49 -05:00
Ryan Hughes cb85e6d289 Merge pull request #331 from omacom/fix/locate-service-defaults
Package the locate service defaults
2026-09-06 21:52:39 -04:00
Ryan Hughes 397cf6f527 Package the locate service options 2026-09-06 21:46:40 -04:00
dhh 908d99ad80 chore: sync upstream releases 2026-09-06 20:32:10 +00:00
David Heinemeier Hansson 2cfa93bfdc Revert "Package Muse Code from Meta's native binaries (#329)" (#330)
This reverts commit 377ca9cdfd.
2026-09-06 21:47:13 +02:00
David Heinemeier Hansson 377ca9cdfd Package Muse Code from Meta's native binaries (#329) 2026-09-06 21:46:10 +02:00
707b5e6c51 Bump libfprint-git for Synaptics fingerprint reader 06cb:010b (#321)
* Bump libfprint-git for Synaptics 06cb:010b support

* Describe libfprint-git as the driver the fingerprint setup installs

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: powderluv <powderluv@powderluv.org>
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-06 11:57:34 +02:00
Spencer BullandGPT-6 Codex 351f188d02 Register Hermes Desktop only after publishing its native CLI
Keep build-time registration private, verify the published launcher, and then let the native command register the final desktop entry. Keep that launcher first on the desktop environment PATH for subsequent registrations.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-06 02:21:16 -05:00
Spencer BullandClaude Opus 5 f4adf308f9 Make native Hermes setup retryable without a late sudo step
Stage the initial clone before publishing its ownership marker and build the desktop through the same native CLI used by updates. Keep a concurrent checkout intact and reset pkgrel for the version change.

Co-Authored-By: Claude Opus 5 (default) <noreply@anthropic.com>
2026-09-06 02:17:27 -05:00
Spencer Bull 2b1edd47b2 Revert "Keep in-app updates on the verified Hermes CLI"
This reverts commit 68a4a6cc22.
2026-09-06 02:02:52 -05:00
Spencer Bull 68a4a6cc22 Keep in-app updates on the verified Hermes CLI 2026-09-06 01:59:58 -05:00
Spencer BullandGPT-6 Codex 01e1a8de0f Exercise lock release on a cold terminal launch
Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-06 01:57:42 -05:00
Spencer BullandGPT-6 Codex 341299f477 Let the Hermes package bootstrap native desktop updates
Install Hermes into its writable native layout instead of shipping a frozen /opt desktop. Preserve the native update path, migrate tagged bootstraps, and keep existing CLI launchers until the desktop is ready.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-06 01:56:23 -05:00
Ryan Hughes b81d678b3f Merge pull request #320 from omacom/fix-check-versions-carch
Read PKGBUILDs with CARCH set; unblock the channels stuck on 1password
2026-09-05 17:08:58 -04:00
Ryan Hughes d673d67a1c Read PKGBUILD variables with CARCH set and refuse to queue a package whose version cannot be read
makepkg always exports CARCH, so PKGBUILDs may branch on it at file
scope. Every place the tooling sourced a PKGBUILD did so without CARCH,
taking the wrong branch or aborting partway, and check-versions turned
the resulting empty pkgver/pkgrel into the version '-', which never
matches a published version and queues an endless rebuild.

package_pkgbuild_var reads one variable the way makepkg would see it,
for the architecture being checked, and reports whether the source
succeeded. check-versions, sync-rebuilds and omarchy-pkgs use it.
check-versions now warns and skips a package whose pkgver or pkgrel is
empty instead of comparing a partial version. A self-test covers a
PKGBUILD that branches on CARCH before assigning its version.
2026-09-05 16:59:22 -04:00
Ryan Hughes d57a9955d5 1password: map the tarball architecture inside package() so the PKGBUILD's version can be read without CARCH
The file-scope case on CARCH ended in 'return 1', which aborted any
'source PKGBUILD' that did not export CARCH before pkgver and pkgrel
were assigned. check-versions reads PKGBUILDs that way, saw an empty
version, queued 8.12.34-35 on every tick, and promotion then refused to
overwrite the already-published artifact. Every channel has been in
backoff since 06:41 UTC today because of it.
2026-09-05 16:59:22 -04:00
Ryan Hughes cb7a1a8868 Merge pull request #317 from omacom/add-omareel
Add omareel, a screen recorder and editor for Omarchy
2026-09-05 15:27:46 -04:00
Ryan Hughes 2944f5e802 omareel: pin the v0.1.0 archive checksum 2026-09-05 14:47:12 -04:00
Ryan Hughes 3682eaf718 Add omareel, a screen recorder and editor for Omarchy 2026-09-05 14:20:51 -04:00
David Heinemeier Hansson 5d656b0b8a Add original vi package (#314) 2026-09-05 16:07:29 +02:00
Ryan Hughes fe0a3da325 Merge pull request #312 from omacom/fix/upstream-sync-git-dependency
Fix missing Git in upstream sync container
2026-09-05 02:36:11 -04:00
Ryan Hughes 7397d1fbfd Install Git for upstream syncs 2026-09-05 02:28:08 -04:00
Ryan Hughes bceab72f8c Merge pull request #277 from maralcbr/omacom/aarch64-host-pipeline
Make aarch64 a first-class architecture in the scheduled pipeline
2026-09-05 02:24:36 -04:00
Ryan Hughes ca99c24b01 Add ARM builds for 1Password and Voxtype 2026-09-05 01:09:11 -04:00
Ryan Hughes de57b5dfc2 Publish only intended package artifacts 2026-09-05 00:07:11 -04:00
Ryan Hughes 520dd5c3bb Repair aarch64 package coverage 2026-09-04 23:40:49 -04:00
Ryan Hughes 0b67dbab8e Harden emulated ARM builds 2026-09-04 23:40:49 -04:00
Ryan Hughes 9e9acb071a Support rootless Podman builds 2026-09-04 23:40:49 -04:00
Ryan Hughes 76687fcc82 Harden multi-architecture release pipeline 2026-09-04 23:40:49 -04:00
Marcelo Alcantara b677f50358 Pin PKGEXT to .pkg.tar.zst in the builder image
Arch Linux ARM's makepkg.conf defaults PKGEXT to .pkg.tar.xz. build/sign.sh
only signs *.pkg.tar.zst, and push-build, sync-rebuilds and the notifier
parse the same suffix, so an aarch64 package built under the stacked
pipeline came out as .xz and would have been skipped at signing. Seen on a
plain x86_64 runner building aarch64 under QEMU (fork run 33642125077).
Same fix as the PKGEXT line in #240.
2026-09-04 23:40:49 -04:00
Marcelo Alcantara 91843ab099 Make aarch64 a first-class architecture in the scheduled pipeline
One list, PUBLISHED_ARCHES in helpers/paths.sh (default x86_64,
overridable with OMARCHY_ARCHES), now drives everything the repository
host schedules. check-versions compares PKGBUILDs against each
architecture's channel databases and writes one queue per channel and
architecture; auto-release works through the queues one architecture at
a time, each with its own backoff, so a failing build on one never
blocks the other; advance-channel --arch all re-runs an advance for every
published architecture and omarchy-release uses it for start and ship,
building the pinned pair once per architecture in its rc trigger; the
train observes channels through the reference (first) architecture
instead of a hard-coded x86_64. Queue and backoff files written under
the old per-channel names are treated as x86_64 until consumed.

Two things made an aarch64 builder image impossible to create: the
keyring bootstrap fetched omarchy-keyring from the target architecture's
own channel tree, which does not exist before that architecture has
published anything, and the QEMU probe only knew the x86_64-host,
aarch64-target case. The keyring (arch=any) now always comes from the
x86_64 tree, and the probe compares host and target architectures and
runs a container for the target platform.

clean-repo grouped versions with a regex that only knew any, x86_64 and
i686, so aarch64 packages would never have been pruned.
2026-09-04 23:40:49 -04:00
Spencer Bull 069ffc8c3a Merge pull request #297 from spencerbull/fix/perplexity-lib-conflict
perplexity: fix /lib filesystem conflict breaking every install of 26.9.1
2026-09-04 21:52:57 -05:00
Spencer Bull 32bc673863 Merge pull request #307 from spencerbull/add-openclaw
Add OpenClaw to the fast ring, following the npm registry
2026-09-04 21:49:50 -05:00
Spencer Bull fe409baf00 Add OpenClaw to the fast ring, following the npm registry
Package OpenClaw 2026.9.1 as a local PKGBUILD based on the AUR one,
tracking the npm registry's latest dist-tag through the repository's
declarative npm upstream provider: upstream's release cadence outruns
the AUR maintainer, and the dist-tag is the stable channel where a plain
version-max would ship next cycle's betas. A 24h min_release_age
quarantines fresh releases, which matters more than usual here because
the npm tarball is not vendored: package() resolves ~330 transitive
dependencies from the live registry without integrity pins. The pinned
sha256 was verified against the registry by hand. The initial pin was
taken inside its quarantine window through the documented
BYPASS_MIN_RELEASE_AGE maintainer path, deliberately, and lands through
this reviewed change as that path intends.

The AUR post_upgrade restart attempt is replaced with printed guidance:
it targeted a nonexistent openclaw.service, and the real
openclaw-gateway.service is a systemd user unit a root pacman hook
cannot reach (voxtype-bin sets the precedent).

The builder ships npm 12, which refuses install-time lifecycle scripts unless
the package is allow-listed, and for a local tarball the allow-list key is the
tarball's own file: spec rather than the package name. Without it openclaw's
postinstall never runs, the .openclaw-lifecycle-pending marker ships in the
package, and every invocation dies trying to finish the lifecycle inside the
root-owned /usr/lib/node_modules/openclaw. package() now passes
--allow-scripts and fails the build if the marker survives.

That postinstall also runs upstream's legacy-state migration against whatever
home it sees, so the npm call gets a scratch HOME under $srcdir with the
OPENCLAW_* location overrides unset: a maintainer's own ~/.openclaw is not
the build's to prune.
2026-09-04 21:15:37 -05:00
Spencer Bull 1fa158942a perplexity: make the stray-entry guard type-blind
Review caught that the allowlist only listed files and symlinks, so a
future deb shipping an empty top-level bin/, sbin/ or lib64/ -- each a
filesystem-owned symlink here, the exact conflict class this guard
exists to close -- would pass it, as would FIFOs and device nodes.

Delete the one known unit, rmdir its emptied parents, and treat any
remaining entry outside opt/ and usr/ as unexpected, whatever its type.
This also stops silently rm -rf'ing future /lib content: anything new
there now fails the build for a human to look at instead.

Verified: clean build ships only etc/, opt/ and usr/; an injected empty
bin/, a stray lib64/ file, and a FIFO each abort package() with the
entry listed. Built via bin/build; installs clean in a fresh container.
2026-09-04 16:16:54 -05:00
99234a4fbb Add schist-bin, the Schist image editor, to the fast ring (#293)
Schist is a layered image editor with PSD, Affinity and camera raw support,
developed by Infrawrench and packaged by its upstream author. The package
re-wraps the pacman-format payloads Schist's release workflow publishes for
x86_64 and aarch64, so the builder does no compiling, and both assets are
pinned by SHA-256.

Releases are tracked declaratively through the GitHub upstream provider,
which gains a "digests": true mode here: a vendor that publishes no checksum
manifest can have each asset's SHA-256 read from the digest GitHub's release
API reports, so the sync never downloads the artifacts. Exactly one of
"checksums" or "digests" must be set, and the provider enforces that itself
because scheduled runs reach it without the metadata validator.

Fresh releases wait 24 hours before the scheduled sync picks them up, as
mise-bin already does. vulkan-driver is an optional dependency rather than a
hard one: makepkg -s would otherwise satisfy the virtual package with
nvidia-utils in the build container, and Omarchy installs a Vulkan driver per
machine.

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-04 13:09:12 +02:00
Jessyka_boatandClaude Opus 5 f620e9ee6b Add slap-notes-bin
Local-first block notes with a wiki-link graph and a built-in AI research agent. Electron over a Next.js server, x86_64 only, repackaged from the vendor tarball with a Wayland launcher.

Not in the AUR. The package follows its GitHub release feed through the declarative github upstream provider, reading each release's SHA256SUMS, with a 24h min_release_age quarantine.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-04 12:29:12 +02:00
Spencer Bull 55bc67834b perplexity: stop shipping upstream's /lib, fail closed on strays
26.9.1 added /lib/systemd/system/perplexity-local-runtime-setup.service
to the deb, and wholesale extraction made the package own /lib -- a
symlink owned by filesystem -- so pacman refused every install and
upgrade. The unit could never work here anyway: its setup script
apt-installs Docker and the NVIDIA Container Toolkit and exits on any
distro but Ubuntu, so the Arch equivalents ride optdepends instead.

package() now allowlists what leaves the deb: opt/, usr/, and that one
known unit path (deleted). Anything else stops the build rather than
shipping the next filesystem conflict.

Verified in a clean container: the published -1 reproduces the /lib
conflict; -2 installs fresh and upgrades from 26.8.4 cleanly.
2026-09-03 22:52:22 -05:00
Ryan Hughes 7860c4b2e4 Merge pull request #195 from oceanapplications/aarch64-arch-support
Own and build nine ARM-compatible packages
2026-09-03 22:19:39 -04:00
Ryan Hughes b89770c1da Expand declarative upstream providers 2026-09-03 22:13:59 -04:00
Ryan Hughes d9705d0e2f Own ARM-compatible recipes and sync upstream directly 2026-09-03 22:04:04 -04:00