Commit Graph
736 Commits
Author SHA1 Message Date
14eb9430c3 Close Hermes on removal instead of asking the user to close it
Remove > AI refused whenever anything had Hermes's files open and told the user to close it and try again, and the thing open was Hermes: the agent in the terminal that choosing it as the default agent leaves running, the desktop app, a gateway. Those are the removal's to close. It now stops the gateway unit that upstream's `hermes gateway install` wrote, since that unit starts the runtime about to be deleted and would start it again the moment it was killed, then ends every process whose program lives in that runtime or in the package, and only then refuses over whatever is left, which is somebody else's: an editor on a skill, a shell sitting in ~/.hermes, a writer on the state database. Both are judged by the program, never by a later argument or by the home served, so an editor opened on a runtime file is the user's and a unit running a Hermes kept elsewhere is left alone whatever home it serves; for an interpreter the program is the script it runs, so a gateway started by hand as `python .../hermes gateway run` is found too. The refusal comes before anything is touched, so a run that stops leaves Hermes running as it was. A unit that will not stop still aborts the removal, as dropping the package would strand a live gateway on deleted code.

Co-Authored-By: Codex XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-24 21:35:46 -05:00
f3989092b2 Refuse before anything of the user's is touched, whatever state the runtime is in
The refusals that leave a self-installed Hermes alone came before the command was replaced only for a finished runtime. An unfinished one was still bootstrapped over a git status that could not be read, since a failed status read as a clean tree, and a half-built app beside it, or an edit the Linux runtime patch could not land on, was found only after the user's command had been saved aside and replaced and main switched. All three are asked first now, in both states, so a run that is going to stop leaves the launcher, the checkout and ~/.local/bin as they were.

Co-Authored-By: Codex XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-23 00:05:51 -05:00
Spencer BullandClaude Fable 5.1 73a2b91cf5 Install Hermes Desktop whenever Hermes is chosen as the default agent
Hermes is only ever installed through the app. Choosing it as the default agent used to stand aside for a hermes that worked but came from somewhere else, and to refuse one that predated seeded sessions; both left the machine on a Hermes that was not the app's, which is the one Omarchy prepares for in-app updates and hands the theme to. Now --check answers only for the app's own Hermes, and --now installs the app whatever answered to hermes before, saving the previous command aside as it always did for the app path. The desktop installer no longer adds the package itself, since the shared install does.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 23:11:16 -05:00
44b0f2a70f Match the retired mise tool exactly in the global listing
Whether the environment mise built is gone was read by searching the global listing for the prefix `"pipx:hermes-agent`, so a tool that merely starts the same way, `pipx:hermes-agent-tools` say, read as the retired one still requested. Removing the real one changed nothing, the recheck failed again, and the migration stayed pending on every update. The key is matched whole now, with or without its options.

Co-Authored-By: Codex XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 20:42:26 -05:00
72608aed85 Find a busy git in the runtime by its path as well as its name
The wait before clearing a stale shallow.lock looked for a git whose command line began with `git`, so one started as `/usr/bin/git`, which is what a caller that resolved it with `which` runs, was never seen: its lock, once a minute old, would have been cleared under it and a second fetch started against the same shallow file. The path is allowed only ahead of the name, at the start of the command line, so a process that merely names git in an argument, an editor opened on /usr/bin/git from inside the runtime say, is not waited for.

Co-Authored-By: Codex XHigh <noreply@openai.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 20:42:26 -05:00
Spencer BullandClaude Fable 5.1 8bffe142ce Answer npx for upstream's installer so the menu install does not stop to ask
Upstream's installer runs `npx playwright install chromium` for the browser tools, and npx asks before fetching a package it does not have. Over ssh, with no terminal, it goes ahead; in the floating terminal the menu opens for choosing Hermes it printed "Ok to proceed? (y)" and waited, so an install a user had every reason to walk away from sat there until someone typed y. The mise-built Hermes this replaces never asked anything. `--skip-setup` already answers the wizard the same way, and the app's own bootstrap never had a terminal to ask in.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 20:42:26 -05:00
7eb818e37b Install Hermes for the default agent as the desktop app's self-updating runtime
Choosing Hermes as the default agent built it through mise: a pipx environment with no checkout, so `hermes update` had nothing to move, and the only Hermes that could update itself was the one Hermes Desktop set up. Both paths now run the same setup. omarchy-install-hermes-cli installs the hermes-desktop package and runs upstream's installer from it, pinned to the packaged release and started on main, exactly as Install > AI did; omarchy-install-ai-hermes is that plus opening the app. The terminal, the default agent and the app share one runtime, and it updates itself.

--check answers whether --now has anything left to do, not merely whether a hermes runs: choosing Hermes from the menu asks first and opens a terminal only on a no, so a yes has to mean no minutes-long step would run where nobody can see it. With the app installed that means the runtime's own command, its completion marker and the seeded packaged app; a finished runtime whose command is gone, somebody else's, or its own but unable to run gets it back from upstream's path stage without bootstrapping again. Either way the command has to be the one PATH finds, because omarchy-agent runs bare `hermes` and Omarchy puts mise's shims ahead of ~/.local/bin; a command in the way is named rather than installed over. The modes are named outright because the app's launcher used to call this command with no arguments to reconcile a mise copy; a default of --now would turn every launch into an install. --check still refuses to run the retired wrapper, since running it built Hermes through mise, and a machine whose migration is pending can still have it on PATH.

Provisioning no longer writes the wrapper, Remove Preinstalls no longer looks for it, and the wrapper, the environment it built and what proves them Omarchy's are known to the installer alone: --retire-mise is the migration's whole job, and --now runs the same removal once the runtime installer has saved the wrapper aside, so a user who chose Hermes before their migration ran is not left with mise's shim answering `hermes`. Only the wrapper proves the environment is Omarchy's, at its path or in that saved copy, so the environment goes first and the wrapper last, judged by mise neither having it installed nor still requesting it; a removal that leaves either behind, or a listing that cannot be read, mise missing included, stops with the commands to finish by hand and leaves the migration pending. The migration that once installed the wrapper is kept as a no-op for late updaters, and one whose default agent was Hermes is told to choose it again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-21 19:26:02 -05:00
bjarneo b8c382da9e Merge pull request #9656 from Chessing234/fix/sublime-default-editor-uses-subl
Use subl for the Sublime Text default editor
2026-09-21 23:11:07 +02:00
David Heinemeier Hansson 599a6a665b Report skipped checks separately in shell tests 2026-09-21 11:49:32 +02:00
David Heinemeier Hansson 961ec7f39f Merge pull request #12748 from omacom/simplify/network-qr-test-environment
Fall back to connected Wi-Fi when QR route lookup fails
2026-09-21 11:37:46 +02:00
David Heinemeier Hansson 07fc39c8be Merge pull request #12747 from omacom/simplify/pacman-test-environment
Isolate pacman tests from inherited LC_ALL
2026-09-21 11:37:20 +02:00
David Heinemeier Hansson 5c2be2e653 Fix Wi-Fi QR fallback after failed route lookup 2026-09-21 10:54:38 +02:00
David Heinemeier Hansson 6f9f31ecea Isolate pacman tests from inherited LC_ALL 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson 86bf7ebc71 Isolate About tests from inherited NO_COLOR 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson 5b22f50be3 Stub route discovery in network QR tests 2026-09-21 10:50:25 +02:00
David Heinemeier Hansson ef81d37a87 Merge pull request #12745 from omacom/simplify/locate-test-history
Remove obsolete repository scan from locate test
2026-09-21 10:46:36 +02:00
David Heinemeier Hansson 273c340dfa Remove obsolete repository scan from locate test 2026-09-21 10:40:17 +02:00
David Heinemeier Hansson faffb8ee4d Remove stale migration filename assertion 2026-09-21 10:40:17 +02:00
David Heinemeier Hansson 1aa1423eac Retire the shipped Copy URL migration test 2026-09-21 10:10:02 +02:00
Ryan Hughes 39d1cb956d Merge quattro into use-omasnap-for-screenshots 2026-09-21 02:19:10 -04:00
Ryan Hughes c0ba99670d Clean up legacy screenshot tools in Omasnap migration 2026-09-21 02:14:54 -04:00
David Heinemeier Hansson ab18321bb5 Merge pull request #12429 from omacom/owe-video-backgrounds
Replace the shell's desktop video path with OWE
2026-09-21 03:55:16 +02:00
David Heinemeier Hansson 0d5232ed7b Fix Elsewhen migration for dev checkouts 2026-09-21 03:38:10 +02:00
David Heinemeier Hansson b423f4993d Complete OWE service setup and lock feed fallback 2026-09-20 20:36:19 -05:00
Ryan Hughes 45748a2812 Remove obsolete Elsewhen plugin symlink 2026-09-20 14:25:34 -04:00
Ryan Hughes e265934bb1 Use Omasnap for screenshots 2026-09-20 13:18:36 -04:00
Spencer Bull 16cc7d7a9d Leave the shell restart to the update flow
Restarting immediately after the plugin rescan races Quickshell IPC handler creation and can crash the exiting shell. The normal update flow already restarts after migrations. Let this migration finish through live enablement and placement without adding timing workarounds.
2026-09-19 00:06:29 -05:00
Spencer Bull 9e3ff71f48 Simplify Elsewhen installation and bar migration
Link the package into the existing plugin directory and let bar put handle enablement, clock-relative placement, and the missing-clock fallback. Preserve user checkouts and existing placements, and seed the same link for new users. This removes the Atreyu packaged-discovery prerequisite and the checkout cleanup and JSON rewrite machinery.
2026-09-19 00:01:29 -05:00
Bjarne Oeverli eff410f91e Draw the lock screen video from the OWE lock feed
The shell drops its own player: BackgroundMedia is image-only, and the
lock loads Owe.LockFeedSurface through a Loader, so a system without the
module shows no lock video instead of losing the whole lock screen. The
feed pauses per output when the panel blanks or power saver turns on.

The lock view keeps its still effect path and darkens the feed for
legibility. QtMultimedia and the shell video pause policy are gone, and
the base package list requires owe and owe-lockfeed instead.
2026-09-18 22:49:47 +02:00
Bjarne Oeverli 831626daea Note that OWE plays the desktop video audio 2026-09-18 21:02:01 +02:00
Bjarne Oeverli dbebc458db Replace the desktop video path with OWE
The desktop background no longer plays videos. OWE owns video
backgrounds, and the shell layer stays empty behind one. The shell keeps
stills, which OWE hands back to it.

Remove the desktop video pause plumbing that only existed to stop an
unseen player: the lock, idle, and battery service lookups, the
per-output fullscreen check, the first-screen audio opt-in, and the audio
output in BackgroundVideo. The lock screen keeps its own silent playback.

Update the background tests, the manual, and the package note.
2026-09-18 18:46:17 +02:00
Bjarne Oeverli d01ef2d5d0 Let OWE own video backgrounds while it runs
The background plugin now watches for the OWE daemon socket. While OWE is
running, the desktop yields video playback to it and the shell keeps
stills. The lock screen keeps its own playback.

This lets Omarchy cooperate with OWE without OWE editing shell.json, so
the engine can ship as a package.

Add a package-list note that owe-wallpaper-engine must be added once it is
packaged.
2026-09-18 18:23:21 +02:00
Spencer BullandCodex XHigh e8a8236a22 Preserve local Elsewhen work and fallback bar layouts
Retire only checkouts whose refs and reflogs are reachable from recorded origin history, and preserve ignored files. Leave configs without an explicit supported bar layout untouched so migration does not replace the shell fallback with an almost empty bar.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-17 22:11:46 -05:00
Spencer Bull 49286d0e66 Place Elsewhen immediately before the center clock 2026-09-17 21:41:39 -05:00
Spencer Bull 531c3e890f Install Elsewhen, the world clock plugin, by default
Elsewhen (omacom.elsewhen) arrives as the elsewhen package under
/usr/share/omarchy/plugins, the packaged root the shell scans between its
bundled plugins and the user's. It opens the right section of the default
bar, just before the tray, and a migration installs the package, writes the
widget into a customized shell.json in the same spot, and retires a pristine
pre-package clone of the upstream repo that the package now shadows.
2026-09-17 21:41:01 -05:00
Erik Melton 9c5482c58d Merge pull request #8170 from Adolanium/hook-state-name-guard
Refuse hook and state names that are paths
2026-09-16 18:09:20 +02:00
Erik Melton f6ce7c554f Merge pull request #10379 from AksharP5/fix/factory-reset-password-hashes
Erase old password hashes during factory reset
2026-09-16 18:07:22 +02:00
David Heinemeier Hansson 2fbac0c8e8 Merge pull request #11934 from omacom/claude-browser-extension
Set up browser integration when choosing Claude
2026-09-15 12:41:39 -04:00
David Heinemeier Hansson 677e69d4f1 Make Claude browser extension installation best effort 2026-09-15 12:40:25 -04:00
David Heinemeier Hansson 8fa9f4d03e Leave Claude browser integration settings unchanged 2026-09-15 12:38:00 -04:00
Erik Melton a73bcbfc0a Remove unsafe project bin PATH injection (#11336)
* Remove unsafe project bin PATH injection

* Cover customized unsafe Mise paths

* Revoke legacy Mise Work trust

* Harden legacy Mise trust cleanup

* Preserve ignored Mise Work configs

* Scope Mise path cleanup to env

* Accept paranoid Mise ignore marker

Reported-by: infosec-us-team
2026-09-15 18:02:17 +02:00
b44fb74780 [Security] Keep screen-recording state out of world-writable /tmp (#8374)
* Keep screen-recording state out of world-writable /tmp

* Compare the /tmp name across the run instead of requiring it absent

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fall back to the state directory when there is no runtime dir

* Let the /tmp snapshot come back empty

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Resolve the region file the same way in the resizer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Protect recording fallback state and document its path

---------

Co-authored-by: Omabot <omabot@omarchy.org>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 17:53:37 +02:00
Adolanium 49418942c8 Merge pull request #7807 from Adolanium/keyring-fail-loud
Stop update-keyring from claiming success when key operations fail
2026-09-15 17:50:20 +02:00
David Heinemeier Hansson 45e32c8c2d Set up browser integration when choosing Claude 2026-09-15 08:10:58 -04:00
Ryan Hughes 24417bf191 Treat matching kernel headers as a base system guarantee 2026-09-15 00:46:30 -04:00
Ryan Hughes 662051ecde Install matching kernel headers for every DKMS setup 2026-09-15 00:06:17 -04:00
Ryan Hughes 08a875852e Leave fresh-install kernel selection to the ISO 2026-09-14 16:46:45 -04:00
Ryan Hughes ff85faf8dd Make linux-omarchy the default kernel except on T2 Macs 2026-09-14 16:32:09 -04:00
Ryan Hughes 8a972da975 Migrate Panther Lake systems to the Omarchy PTL kernel 2026-09-13 14:43:47 -04:00
David Heinemeier Hansson 8247eb36b7 Merge pull request #11637 from omacom/fix-powerprofile-poll-coredumps
Poll the active power profile over D-Bus instead of powerprofilesctl
2026-09-13 18:06:00 +02:00