A one-package merge took 9 to 15 minutes to publish for about 15 seconds of
signing and upload. The run-wide concurrency group made each merge wait for
every earlier run, builds included (#854 waited 13 minutes behind an aarch64
batch), and the publish job waited about 3 minutes for a builder droplet
even when every package had a PR artifact and nothing needed building.
Build x86_64 trees that have no artifact in the rebuild job, one droplet per
entry, as aarch64 already builds there on arm64 runners: in parallel, with
no secrets, and outside any lock. The publish job now only collects
artifacts, signs and uploads, on ubuntu-latest with the GHCR builder image
(#850), and only it holds the publish group.
#867 auto-merged only PRs changing nothing outside pkgbuilds/, so it would
have left #854 open too: like voxtype-bin and the IPU7 camera before it,
Superwhisper added tests/superwhisper-bin-install.sh and one test.yml line
running it.
Count those as package changes: a new file under tests/, and a test.yml
change whose every line adds a ./tests/*.sh call. test.yml runs on PRs only.
Editing an existing test still needs a maintainer, since builder-images.yml
runs tests/build-isolation.sh on master with packages: write.
A builder droplet starts with no images, so publish.yml built
omarchy-pkg-builder from the Dockerfile each time: about 100 s of
pacstrap, keyring setup and toolchain install, to run gpg, repo-add,
bsdtar and rclone for about 14 s.
builder-images.yml already publishes the tested image for the current
build inputs to ghcr.io/omacom/omarchy-pkg-builder under bin/builder-image
key. Pull that, check its org.omarchy.builder.key label, and tag it as the
local name the rest of the step uses.
Build as before when no image carries the key, which is what a merge
that changes build/ sees until the refresh it triggered has finished.
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
A package PR approved to build, by its author being trusted or by the
build-approved label, sat open after going green until someone merged it by
hand, so nothing it built was published. Enable GitHub's auto-merge on it
with PKGS_BOT_TOKEN, so the merge lands once the required checks pass and
starts publish.yml.
The trust rule is build-pr.yml's. Only PRs changing nothing outside
pkgbuilds/ qualify: a PR's own tooling never runs in its build, and after
merge it runs with the publish secrets. The upstream sync, which labels its
own PRs, stays on the reviewed lane. Removing build-approved withdraws the
auto-merge.
tobi/omatrack no longer exists on GitHub, so the pinned commit's archive is
404 and 1.8.6 cannot be rebuilt; the old repository host's sync deleted the
published 1.8.6-1 from R2, leaving edge at 1.2.0. A public copy serves the
same commit with an archive matching the pinned sha256 byte for byte.
pkgrel 2 gives the rebuild a new filename, so no cache can serve the
deleted 1.8.6-1 bytes for it.
A droplet DigitalOcean still reports as "new" never registers a runner, but
the controller counted it as one booting and created no replacement until
MAX_AGE_MINUTES. A publish job sat queued for minutes behind one in mkc1.
Delete droplets still provisioning after MAX_BOOT_MINUTES (10) and leave them
out of the live count, so the same tick creates a replacement.
sync-rebuilds now runs on the unattended lane like track-branches: it
opens the pkgrel bump PR with PKGS_BOT_TOKEN and enables auto-merge, so a
Qt (or any rebuild_on) update reaches users without a maintainer merge.
Branch protection still requires result, self-tests and build-isolation
to pass; a failed rebuild stays an open red PR.
The PAT is required because a GITHUB_TOKEN merge does not start
publish.yml. PAT pushes are not held for approval, so the approve job,
the build-approved label and the review request go away.
Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* Keep builders coming when DigitalOcean sells out a droplet size
ric1 sold out of g5-32vcpu-64gb-50gb, and every create came back 422. curl -f
dropped the reason and set -e ended the tick, so builders only appeared when
capacity happened to free up, and the journal showed nothing but "curl: (22)".
Try each of SIZES in turn, logging DigitalOcean's refusal message, and fail
the tick only when every size is refused. Builders now power off however
start.sh exits, so a failed registration is reaped instead of counting as a
booting runner until MAX_AGE_MINUTES. The controller unit pulls the checkout
before each tick, so merged controller fixes reach the box.
* Create builders in any region that has the size in stock
ric1 sold out of g5-32vcpu-128gb-50gb within minutes of the box switching to
it. Builders need nothing from a particular region, so read DigitalOcean's
size catalog once per tick and try each of SIZES in every region it lists in
stock, REGIONS first if set. A refused pair is dropped for the rest of the
tick.
Tracks tagged releases from the quickshell-mirror GitHub repository
through an upstream watch, so new versions arrive via sync-upstream.
The recipe follows Arch's extra/quickshell, builds for x86_64 and
aarch64, ships the Qt compatibility check hook, and rebuilds on Qt
updates like quickshell-git. It conflicts with quickshell-git.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The native Hyprland plugin behind Omarchy's floating workspaces: themed
titlebars and edge snapping, built from a hyprbars fork. It is rebuilt
with every Hyprland change, since a plugin only loads into the exact
build it was compiled against.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Upstream's 6771b19 ("keep smoke artifacts in the build directory") made
omasnap-smoke reject positional paths; the directory is now passed with
--output-dir. check() still passed it positionally, so every build of a
pin at or past that commit failed with "Unexpected positional argument;
use --output-dir <directory>."
Pass it as --output-dir and move the pin to 6771b19, the tip the branch
tracker has been trying to merge since October 4. The two have to land
together: the old pin does not know --output-dir.
* Update OWE to 0.2.10 and package its lock feed
* Print OWE regression failures during package checks
* Make OWE package regression independent of timestamp precision
Arch ships steam for x86_64 only, so on AArch64 `omarchy-pkg-add steam`
found nothing. This aarch64 build installs the same Valve launcher files
(desktop entry, icons, steam-devices udev rules) but replaces the x86
bootstrap with Valve's native arm64 client, which then updates itself from
the stable steam_client_linuxarm64 channel.
The bootstrap is just the client binary, which links only glibc, taken
from the manifest's bins_linuxarm64_linuxarm64 zip and pinned to the sha2
the manifest publishes. /usr/bin/steam unpacks it on first launch, keeps
the ~/.steam links the client requires, and restarts the client when it
exits with 42 after updating. Valve's bin_steam.sh cannot do this: it only
knows the ubuntu12_32 bootstrap.
Beyond Arch's dependencies the client needs gtk2 and libibus for its UI,
and lsof, which it runs to find its own IPC ports.
Valve's native arm64 Steam client loads GTK 2 from the host, and Arch
Linux ARM no longer ships it. Imported from the AUR recipe unchanged
apart from the architecture: x86_64 Steam brings its own copy in its
runtime, so gtk2 builds for aarch64 only.
Omarchy is getting an Install > Service > Slack menu entry, and that
needs the package on every channel. slack-desktop has only been built
for edge so far. The fast ring builds it for rc and stable as well,
like the other service packages (Spotify, Dropbox, 1Password, NordVPN).
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Dropbox publishes its Linux client for x86_64 only, so on AArch64 the
dropbox package installs that same client and runs it under box64. Only
dropboxd changes: it execs the client through box64, and /usr/bin/dropbox
points at it, so the systemd units and `dropbox-cli start` both go through
the emulator. The x86_64 package is unchanged.
dropbox-cli is a Python script and becomes arch=any.
Dropbox publishes its Linux client for x86_64 only. box64 lets the aarch64
dropbox package run that client, and it has to be published before dropbox
can build for aarch64.
Pinned past v0.4.5-1 because that release crashes in its glib wrapper when
Dropbox starts its tray icon. It ships without a binfmt handler so it does
not compete with qemu-user-static-binfmt.
The upstream and rebuild syncs push with GITHUB_TOKEN, so GitHub holds
their build and test runs for approval. Their approve job only released
those runs once a maintainer had applied build-approved, and never ran
for the push that opened the PR, so every sync PR sat waiting.
The sync now labels its own PR build-approved, and the approve job runs
for created PRs as well as updated ones.
Give the DX13260 aliases their own ownership paths so a stable refresh can retain them while Arch continues updating the stock firmware. Include every speaker ID and target in the boot image. Retain the package identity across channel transitions so pacman can restore the overlay on downgrades. Keep the existing shim for the staged consumer migration.
Co-authored-by: Codex GPT-6.1-Sol XHigh <noreply@openai.com>
Ship Slack's own x86_64 build unchanged so Omarchy controls the package
on both architectures instead of relying on the AUR recipe for x86_64.
The Electron swap and native module replacements stay AArch64-only.
Update both package recipes and source checksums to OWE 0.2.9. The release adds owe intro --start first-frame, so a login intro can start on its own first frame. Package builds pass on x86_64 and aarch64.