The worst was fatal: push passed --skip-prod-check to upload-prebuilt, which
forwards every argument to sign, promote and update as well, and sign rejects
unknown options. Every non-dry-run push and deploy would have uploaded and
verified its artifacts and then failed before signing. upload-prebuilt now
routes publishing flags to sync alone.
The partial-tree guard was weaker than it looked:
- it counted archive files locally against package names in the remote
database, and this tree keeps two versions per package, so a checkout with
a spare version of half the repository could pass while still hiding
hundreds of packages. It now compares package-name sets and lists what
would be hidden.
- it treated any unreadable remote as an empty one, so an auth failure or a
corrupt database disabled it. Only rclone's "directory not found" now
counts as a fresh mirror; every other failure aborts.
Also:
- sync had no set -e, so a failed package upload fell through to publishing
the database, advertising packages that were never uploaded. Each transfer
is now checked before the next step.
- --package with no names silently meant "every package", which under --yes
could publish everything from one unset variable in a script.
- push now refuses to run when the host has packages staged from an earlier
failure, since publishing would sign and promote those too.
- epoch versions contain a colon, which rsync reads as host:path, so no
package with an epoch could be transferred. Sources are ./-prefixed.
- remote paths are quoted for the remote shell.
- sync spun forever on a missing option value.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
deploy runs build then push, which is the whole workflow on a local build
machine. It resolves the build host before building so a missing --host fails
in a second rather than after a long compile.
--host now overrides $OMARCHY_BUILD_HOST and .build-host on deploy, push, and
the build trigger in omarchy-pkgs release, so a server can be named per
invocation without arming the release auto-trigger.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Heavy packages build faster on a local machine, but there was no way to get
the artifacts to the server: bin/upload-prebuilt publishes to the rclone
remote from whatever tree it runs in, so the local -> host hop was manual.
bin/repo push rsyncs build-output artifacts to the host, verifies checksums,
and runs upload-prebuilt over ssh. Signing stays on the host, which is the
only machine with the key and the only one holding a complete repository.
Publishing from a local checkout was worse than merely unsupported. sync ran
rclone sync --delete-after against a tree that pkgs.omarchy.org/ gitignores,
so on any machine that had not run a full release it would have deleted the
production repository -- guarded only by a y/N prompt that --skip-prod-check
turns off. Package uploads are now additive, deletion moves behind --prune,
and sync refuses to publish a database built from a tree holding fewer
packages than the remote already lists.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The build image compresses at zstd's default level, which leaves these
unstripped driver blobs 22% larger than they need to be. Measured against the
packages on the quattro-beta3 ISO:
nvidia-580xx-utils 359.4 -> 276.2 MiB
lib32-nvidia-580xx-utils 74.2 -> 48.8 MiB
nvidia-580xx-dkms 85.5 -> 79.8 MiB
That is 114 MiB off the ISO's offline mirror, which stores packages
essentially uncompressed inside squashfs, so it comes straight off the image.
The dkms package rides along on its pkgbase.
Carried as .omarchy patches so they survive AUR syncs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The build image sets COMPRESSZST to zstd's default level, which leaves this
1.3 GB Electron tree at 448 MB -- larger than the 334 MB deb it repackages.
Maximum zstd brings it to 323 MB, beating xz on both size and decompression
speed, for ~4 extra minutes of build time.
Carried as an .omarchy patch so it survives AUR syncs. pkgrel picks up the
Omarchy suffix accordingly.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Official ChatGPT/Codex desktop app, now shipping native Linux debs from
OpenAI. Fast ring, so it lands in stable alongside edge.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One-command releases for the omarchy + omarchy-settings pair:
bin/omarchy-pkgs release v4.0.0 | latest | rc [--commit sha] [--base X.Y.Z]
Rewrites both PKGBUILDs in lockstep (same _tag/_commit/pkgver/sha256sums,
pkgrel reset to 1), normalizes upstream tag forms to the vercmp-safe
attached rcN convention, refuses downgrades against the published edge DB,
regenerates and verifies checksums from a cached mirror clone, commits and
pushes to master, and triggers the build host when OMARCHY_BUILD_HOST is
configured. RCs stay on edge; finals are promoted with bin/repo migrate.
Includes a self-test covering tag normalization and pacman ordering, and a
README runbook.
omarchy-settings-dev provides omarchy-settings (unversioned), so an
unversioned dependency let the dev package satisfy stable omarchy's
settings requirement, allowing a mixed dev/stable install. A versioned
dependency (omarchy-settings=${pkgver}) can only be satisfied by the
real settings package from the same pinned commit and forces the pair
to upgrade together. Verified: requesting only omarchy on a system with
the -dev pair installed replaces both with the stable pair.
Stable-track counterparts of the -dev packages. Source is pinned to a
single shared upstream commit with a real sha256 (pacman 7 validates
checksums on commit-pinned git sources), versioned per the attached-rcN
convention so vercmp orders rc1 < rc2 < final. Seeded at 4.0.0rc1 from
the quattro tip because no upstream 4.x tag exists yet and the packaging
requires the quattro tree (v3.8.x has no shell/ or etc/).
Both packages stay off the fast ring: RCs publish to edge only; stable
receives finals via bin/repo migrate.
Both fixes we carried are upstream now, in the only two commits made
since our pin: 43d4fa9 strips the crash relaunch environment and closes
the info fd, and 28771c7 makes IpcHandler deregister through the
registry it registered with rather than re-resolving its engine
generation.
Upstream reaches the IPC fix differently - IpcHandlerRegistry became a
QObject held in a QPointer, where we kept a raw back-pointer cleared
from ~IpcHandlerRegistry - but it covers the same two cases: a handler
outliving its QML context, and a registry destroyed before its handlers.
Built clean without the patches at 0.3.0.r20.g28771c7-1.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v0.1.1 was withdrawn upstream — it was tagged without the Cargo.toml
bump, so its binary reported 0.1.0. v0.1.2 corrects the version string.
Rebuilt with makepkg on x86_64; packaged binary reports ttfx 0.1.2.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The repo is now omacom-io/ttfx, matching the binary and package name, so
the source URL and archive checksum change with it (the tarball's
top-level directory is the repo name). v0.1.1 adds NOTICE and a
standard-form MIT LICENSE, both now installed.
Rebuilt and verified with makepkg on x86_64.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Rust port of terminaltexteffects that renders byte-identical frames to
the Python original, as one dependency-free binary.
- ~1 ms startup vs ~107 ms for the Python import alone
- median 9.6x faster rendering; heavy effects hold 120fps fullscreen
where Python drops to ~71fps
- CLI-compatible with tte: same option names, defaults, and exit codes
Built and verified locally with makepkg (x86_64): cargo test passes in
check(), package installs the binary plus shell completions.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>