Commit Graph
1151 Commits
Author SHA1 Message Date
Spencer BullandCodex XHigh 2ffae36a18 Resolve the passwordless sudo helper by name in its migration
Pinning /usr/bin ran the packaged helper even where the migration came from somewhere else. Under a dev link the migration is read from the checkout while /usr/bin still holds the last installed package, and a package predating __migrate prints its usage and fails the update. By name, the unprivileged call goes through PATH and the sudo call through secure_path, which is how other migrations reach their helpers and which lands on /usr/bin on an install.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-26 14:43:00 -05:00
Ryan Hughes 7b336b1b0d Merge pull request #11486 from omacom/fix-remote-neovim-yanks
Migrate remote Neovim providers to reliable clipboard yanks and paste
2026-09-25 14:57:16 -05:00
Ryan Hughes 289f36ab97 Require the corrected Neovim package before clipboard migration 2026-09-25 15:35:10 -04:00
Erik Melton d201fb9564 Merge pull request #9467 from AFOliveira/codex/om-sec-12-update-inhibitor-identity
[codex] OM-SEC-12: Bind update inhibitor cleanup to process identity

Reported-by: Afonso "AFOliveira" Oliveira
2026-09-25 15:56:39 +02:00
Spencer Bull c3e67f5d40 Merge pull request #12844 from omacom/hermes-desktop-default-agent
Install Hermes for the default agent as the desktop app's self-updating runtime
2026-09-24 23:41:18 -05:00
Ryan Hughes 5bc098d749 Merge pull request #11690 from Yarlord/fix-hybrid-nvidia-vaapi
Only force NVIDIA VA-API/GLX env when NVIDIA drives the display
2026-09-24 21:52:04 -05:00
Ryan Hughes 28405af27f Request reboot for hybrid NVIDIA fix and streamline tests 2026-09-24 22:49:41 -04:00
Spencer Bull 73b4fc0d8a Rename the Elsewhen migration so the link repair reaches machines that already ran it
The re-point of a user plugin link stranded by the elsewhen package moving from plugins/ to shell/plugins/ landed in migration 1789581661, which every machine updated between that migration shipping and the package moving had already applied. omarchy-migrate keys completion on the filename alone, so the repair never ran where it was needed. On a dev checkout the shell discovers the packaged plugin only through that link, and a rescan drops a dangling one, so Elsewhen vanished from the bar on the first shell start after the package upgrade.

Renaming the file runs the whole migration again everywhere. Each step is safe to repeat: the package add is a no-op once installed, both link branches are guarded, the rescan is best-effort, and the put keeps an existing placement. The new test holds a state directory with only the old marker and checks the renamed file is still pending, which the old name could not pass.
2026-09-21 21:14:46 -05:00
Spencer Bull aa5c4beb50 Re-point the Elsewhen link stranded by the package's move
The 2026-09-19 revision of this migration, and a symlink then shipped under config/, pointed every install's ~/.config/omarchy/plugins/omacom.elsewhen at /usr/share/omarchy/plugins/omacom.elsewhen. elsewhen 1.0.0-2 moved to shell/plugins, so the link dangles, the shell lists the plugin as enabled but never loads it, and the bar carries an empty slot. The migration kept any existing link, resolving or not, so a rerun could not repair it. A link into /usr/share/omarchy that no longer resolves is Omarchy's own and is re-pointed; a link the user made is still left alone.
2026-09-21 19:34:04 -05:00
Spencer Bull 3208fe09ae Let the Elsewhen migration carry on without a shell to ask
A bare `omarchy-shell shell rescanPlugins` exits 1 when no shell answers on the caller's tree, and omarchy-migrate runs migrations under `set -e`, so an update run from a TTY or over ssh, or one whose shell had gone down while the package replaced its QML, died at "omarchy-shell is not running" before its post-update hooks, shell restart and reboot prompt, and re-failed the same way every time until a shell could be asked. The rescan is now best-effort, like `omarchy-bar put` already is and like #11117 makes the plugin commands' closing rescan: the update restarts the shell once the migrations are through, and a session without one has no bar to place on. An unknown widget on a live shell still leaves the migration pending.
2026-09-21 19:33:42 -05:00
7eb818e37b Install Hermes for the default agent as the desktop app's self-updating runtime
Choosing Hermes as the default agent built it through mise: a pipx environment with no checkout, so `hermes update` had nothing to move, and the only Hermes that could update itself was the one Hermes Desktop set up. Both paths now run the same setup. omarchy-install-hermes-cli installs the hermes-desktop package and runs upstream's installer from it, pinned to the packaged release and started on main, exactly as Install > AI did; omarchy-install-ai-hermes is that plus opening the app. The terminal, the default agent and the app share one runtime, and it updates itself.

--check answers whether --now has anything left to do, not merely whether a hermes runs: choosing Hermes from the menu asks first and opens a terminal only on a no, so a yes has to mean no minutes-long step would run where nobody can see it. With the app installed that means the runtime's own command, its completion marker and the seeded packaged app; a finished runtime whose command is gone, somebody else's, or its own but unable to run gets it back from upstream's path stage without bootstrapping again. Either way the command has to be the one PATH finds, because omarchy-agent runs bare `hermes` and Omarchy puts mise's shims ahead of ~/.local/bin; a command in the way is named rather than installed over. The modes are named outright because the app's launcher used to call this command with no arguments to reconcile a mise copy; a default of --now would turn every launch into an install. --check still refuses to run the retired wrapper, since running it built Hermes through mise, and a machine whose migration is pending can still have it on PATH.

Provisioning no longer writes the wrapper, Remove Preinstalls no longer looks for it, and the wrapper, the environment it built and what proves them Omarchy's are known to the installer alone: --retire-mise is the migration's whole job, and --now runs the same removal once the runtime installer has saved the wrapper aside, so a user who chose Hermes before their migration ran is not left with mise's shim answering `hermes`. Only the wrapper proves the environment is Omarchy's, at its path or in that saved copy, so the environment goes first and the wrapper last, judged by mise neither having it installed nor still requesting it; a removal that leaves either behind, or a listing that cannot be read, mise missing included, stops with the commands to finish by hand and leaves the migration pending. The migration that once installed the wrapper is kept as a no-op for late updaters, and one whose default agent was Hermes is told to choose it again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-21 19:26:02 -05:00
Afonso Oliveira 56ca654dc8 Merge quattro into update security foundation 2026-09-21 14:14:59 +01:00
Ryan Hughes 39d1cb956d Merge quattro into use-omasnap-for-screenshots 2026-09-21 02:19:10 -04:00
Ryan Hughes c0ba99670d Clean up legacy screenshot tools in Omasnap migration 2026-09-21 02:14:54 -04:00
David Heinemeier Hansson ab18321bb5 Merge pull request #12429 from omacom/owe-video-backgrounds
Replace the shell's desktop video path with OWE
2026-09-21 03:55:16 +02:00
David Heinemeier Hansson 0d5232ed7b Fix Elsewhen migration for dev checkouts 2026-09-21 03:38:10 +02:00
David Heinemeier Hansson b423f4993d Complete OWE service setup and lock feed fallback 2026-09-20 20:36:19 -05:00
Ryan Hughes 45748a2812 Remove obsolete Elsewhen plugin symlink 2026-09-20 14:25:34 -04:00
Ryan Hughes e265934bb1 Use Omasnap for screenshots 2026-09-20 13:18:36 -04:00
Spencer Bull 16cc7d7a9d Leave the shell restart to the update flow
Restarting immediately after the plugin rescan races Quickshell IPC handler creation and can crash the exiting shell. The normal update flow already restarts after migrations. Let this migration finish through live enablement and placement without adding timing workarounds.
2026-09-19 00:06:29 -05:00
Spencer Bull 9e3ff71f48 Simplify Elsewhen installation and bar migration
Link the package into the existing plugin directory and let bar put handle enablement, clock-relative placement, and the missing-clock fallback. Preserve user checkouts and existing placements, and seed the same link for new users. This removes the Atreyu packaged-discovery prerequisite and the checkout cleanup and JSON rewrite machinery.
2026-09-19 00:01:29 -05:00
Spencer BullandCodex XHigh e8a8236a22 Preserve local Elsewhen work and fallback bar layouts
Retire only checkouts whose refs and reflogs are reachable from recorded origin history, and preserve ignored files. Leave configs without an explicit supported bar layout untouched so migration does not replace the shell fallback with an almost empty bar.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-17 22:11:46 -05:00
Spencer Bull 49286d0e66 Place Elsewhen immediately before the center clock 2026-09-17 21:41:39 -05:00
Spencer Bull 531c3e890f Install Elsewhen, the world clock plugin, by default
Elsewhen (omacom.elsewhen) arrives as the elsewhen package under
/usr/share/omarchy/plugins, the packaged root the shell scans between its
bundled plugins and the user's. It opens the right section of the default
bar, just before the tray, and a migration installs the package, writes the
widget into a customized shell.json in the same spot, and retires a pristine
pre-package clone of the upstream repo that the package now shadows.
2026-09-17 21:41:01 -05:00
Afonso OliveiraandClaude Fable 5.1 99ddf35138 Merge the current passwordless sudo expiry head
Bring in the legacy-grant classifier fix and the reserved-prefix
quarantine from #9457 so this branch no longer carries a stale copy of
that command.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 10:44:30 +01:00
Afonso OliveiraandClaude Fable 5.1 4bd593f4ed Merge quattro and route refreshes through omarchy-update-pacman
Upstream now runs every Omarchy-owned pacman transaction through the
hidden omarchy-update-pacman helper so a mid-transaction systemd reexec
cannot kill it. Keep the deferred pre-refresh-pacman hook and the
command-scoped sudo wrapper, and call the helper from the refresh and
channel commands; the wrapper still applies to the helper's own sudo.

The sudo boundary fixture copies the helper into its root and runs a
systemd-run stand-in that execs the wrapped pacman step in place.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-16 21:54:06 +01:00
Erik Melton a73bcbfc0a Remove unsafe project bin PATH injection (#11336)
* Remove unsafe project bin PATH injection

* Cover customized unsafe Mise paths

* Revoke legacy Mise Work trust

* Harden legacy Mise trust cleanup

* Preserve ignored Mise Work configs

* Scope Mise path cleanup to env

* Accept paranoid Mise ignore marker

Reported-by: infosec-us-team
2026-09-15 18:02:17 +02:00
David Heinemeier Hansson f2b419d9a9 Merge pull request #11658 from omacom/tcp-bbr-fq
Switch TCP congestion control to BBR with fq pacing
2026-09-15 07:17:03 -04:00
Ryan Hughes 24417bf191 Treat matching kernel headers as a base system guarantee 2026-09-15 00:46:30 -04:00
Ryan Hughes 662051ecde Install matching kernel headers for every DKMS setup 2026-09-15 00:06:17 -04:00
Ryan Hughes ff85faf8dd Make linux-omarchy the default kernel except on T2 Macs 2026-09-14 16:32:09 -04:00
Ryan Hughes 905ff1f792 Replace Neovim providers atomically and preserve dotfile links 2026-09-13 19:48:41 -04:00
Ryan Hughes 8a972da975 Migrate Panther Lake systems to the Omarchy PTL kernel 2026-09-13 14:43:47 -04:00
David Heinemeier Hansson 90f0054658 Upgrade known clipboard providers with backups and package version guard 2026-09-13 17:46:13 +02:00
David Heinemeier Hansson a389bd1852 Add Cloudflare CLI lazy wrapper 2026-09-13 16:59:33 +02:00
David Heinemeier HanssonandClaude Fable 5.1 9246647071 Switch TCP congestion control to BBR with fq pacing
Cubic keeps pushing until packets drop, which stands queues up in the path
on fast links. BBR paces to its estimate of bottleneck bandwidth and minimum
RTT instead, cutting queueing latency while keeping throughput. fq is the
qdisc BBR is built to pace through.

tcp_bbr and sch_fq are modules in every kernel Omarchy ships and autoload
when the sysctls are set. The migration re-applies the shipped file so new
connections switch without a reboot, no-ops once the live values match, and
flags a reboot if applying fails.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-13 12:15:27 +02:00
David Heinemeier Hansson 7270ee5021 Fix automatic Neovim yanks in remote sessions 2026-09-12 16:48:59 +02:00
David Heinemeier HanssonandClaude Fable 5.1 31bd80daa4 Keep the KEF LSX II LT USB sink from suspending (#11318)
The speaker's USB firmware stops answering control requests when the host
stops the audio stream after WirePlumber's 5 s idle suspend. The kernel
then logs usb_set_interface failed (-110), clock source 1 is not valid,
and cannot set freq 48000 err -110; PipeWire fails to start the sink and
only a replug recovers it. On one machine this happened on six days over
three weeks, up to hundreds of timeouts a day.

A WirePlumber rule sets session.suspend-timeout-seconds = 0 for the KEF
node only, so the stream is never stopped and the trigger never fires.
Other sinks keep the default. The migration seeds the file for existing
installs and restarts WirePlumber if it is running, since conf.d is only
read at startup.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-11 21:51:13 +02:00
Ryan Hughes 262a779246 Activate T3 theme on existing installs 2026-09-10 22:57:04 -04:00
Afonso Oliveira c46f321680 Simplify passwordless sudo grant lifecycle 2026-09-10 22:01:09 +01:00
David Heinemeier HanssonandClaude Opus 5 5ead870507 Add basecamp (basecamp-cli) as a lazy-installed mise tool (#10943)
Mirrors the hey-cli stub: the wrapper in ~/.local/bin installs and
upgrades through mise on first run, so the CLI tracks releases instead
of going stale as a manually dropped binary.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-09 15:13:43 +02:00
Afonso Oliveira 60ac419f8c Merge current Quattro into sudo expiry fix 2026-09-08 15:28:24 +01:00
David Heinemeier HanssonandClaude Fable 5.1 7e8feb047d Relay the Elgato Cam Link 4K as a 16:9 virtual camera (#10809)
* Relay the Elgato Cam Link 4K as a 16:9 virtual camera

Browser meeting apps such as Zoom's web client ask the Cam Link for a
standard-definition stream, and Chromium settles on the smallest mode it
offers, 640x480. The Cam Link fills that 4:3 frame by cropping its 16:9
input, and the app then paints the frame into a 16:9 tile, so everyone
comes out stretched wide. The web client has no HD switch to avoid it.

Hide the raw capture node from users and re-expose it through v4l2-relayd
as a 1280x720 virtual camera with the same name, so there is still just
one "Cam Link 4K" to pick and no way to negotiate 4:3 from it. udev
starts the relay whenever the Cam Link enumerates and stops it on unplug,
and the relay only pulls frames while something is watching. The sink
runs unsynced because v4l2src stamps each frame with its capture time,
which a synced sink treats as already late and drops.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Take the review fixes for the Cam Link 4K relay

Tie only the device's stop into the relay instance. A start dependency on
it left a job waiting on a device that never comes whenever the base
v4l2-relayd.service is started without a Cam Link attached, since the
package generator wants every configured instance.

Let the loopback unit rerun on each relay start, so a deleted or unloaded
device is recreated on replug instead of the oneshot staying satisfied.

Start the relay outright at the end of the migration. The udev trigger
only starts it when the rule is new to the device, and a failed module
build would otherwise pass silently with the raw camera already hidden.

Run the hardware fix after the Panther Lake kernel swap, as it pulls in a
DKMS module that would otherwise build twice.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-08 14:09:51 +02:00
Ryan Hughes f5cd244ed0 Retire the stock user icon font missed by Quattro upgrades 2026-09-08 02:36:58 -04:00
Afonso Oliveira bc235d2807 Merge remote-tracking branch 'refs/remotes/portfolio/quattro' into codex/portfolio-9457-20260907 2026-09-07 21:27:40 +01:00
Ryan Hughes 0973169098 Merge pull request #7591 from omacom/mise-shim-preserve-argv0
Keep mise upgrades from pruning versions still in use
2026-09-07 12:57:43 -04:00
Ryan Hughes 37bb46e037 Make Kitty migration guidance easier to read 2026-09-07 01:49:49 -04:00
Ryan Hughes 4cb9c75a96 Move Kitty defaults into the system config 2026-09-07 01:24:12 -04:00
Ryan Hughes 04b0a47c9b Configure locate through the packaged service
Reported-by: uiop / @wasdhjklxyz <uiop@wasdhjkl.xyz>
2026-09-06 21:42:31 -04:00
Ryan Hughes c82a0837b0 Merge pull request #10425 from acrogenesis/security/root-owned-sleep-hooks
Harden ownership of installed sleep hooks
2026-09-06 19:36:07 -04:00