Commit Graph
6199 Commits
Author SHA1 Message Date
ZacharyZhang-NYandClaude Fable 5 3cdb3fa61c Display scale: verify both lines, fail on reload error, honest non-TTY path
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:48:35 -04:00
ZacharyZhang-NYandClaude Fable 5 fff49e747c Add display scale presets with revert confirmation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:46:26 -04:00
ZacharyZhang-NYandClaude Fable 5 4a762052ca IME hotkey: also unbind Apps menu key before menu migration
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:45:36 -04:00
ZacharyZhang-NYandClaude Fable 5 14b14f24fa Add IME hotkey command with menu-key migration and conflict detection
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:43:35 -04:00
ZacharyZhang-NYandClaude Fable 5 b7ced3b1b0 IME: dependency-free profile comparison
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:41:33 -04:00
ZacharyZhang-NYandClaude Fable 5 0a3cff60eb IME: content-diff backup condition, DefaultIM assertion
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:40:15 -04:00
ZacharyZhang-NYandClaude Fable 5 7b00f37c59 Add Fcitx5 Rime setup with default profile and status checks
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:37:29 -04:00
ZacharyZhang-NYandClaude Fable 5 2b799d4388 Font status: assert untagged CJK fallback reaches SC
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:35:01 -04:00
ZacharyZhang-NYandClaude Fable 5 92b0289dbb Fontconfig: restore SC-first generic alias preferences
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:34:32 -04:00
ZacharyZhang-NYandClaude Fable 5 19f7fff4de Fontconfig: scope ja/ko overrides to generic families
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:34:02 -04:00
ZacharyZhang-NYandClaude Fable 5 ae1083039b Fontconfig: untagged-request SC fallback, ja/ko native variants
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:33:22 -04:00
ZacharyZhang-NYandClaude Fable 5 d057c6f894 Locale apply: escaped matching, explicit generation assertions
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:26:31 -04:00
ZacharyZhang-NYandClaude Fable 5 843769bf77 Add CJK fonts, fontconfig priority, and locale commands
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:25:53 -04:00
ZacharyZhang-NYandClaude Fable 5 320ba5118a Update: strict-mode migrations, per-file completion markers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:24:12 -04:00
ZacharyZhang-NYandClaude Fable 5 b44380db1d Add omarchycn update for overlay installs with migration runner
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:12:46 -04:00
ZacharyZhang-NYandClaude Fable 5 1ef2743f9e Overlay: manifest-as-intent before copy, two-pass validated uninstall
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:11:34 -04:00
ZacharyZhang-NYandClaude Fable 5 88b933d2bc Overlay: validated manifest with dest record, ownership checks, clean reinstall
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:09:29 -04:00
ZacharyZhang-NYandClaude Fable 5 e3ca9ee493 Add overlay installer for existing Omarchy systems
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:06:29 -04:00
ZacharyZhang-NYandClaude Fable 5 fe42c049ff Use full -Syu transactions, no partial upgrades
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:05:24 -04:00
ZacharyZhang-NYandClaude Fable 5 afd75160b5 Document [omarchycn] pacman repository setup
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:02:23 -04:00
ZacharyZhang-NYandClaude Fable 5 738393851c Keyring: merge keys via gpg import/export, pkgrel 2
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:01:38 -04:00
ZacharyZhang-NYandClaude Fable 5 b7ff3a32c7 Keyring build: .key source names so makepkg does not treat them as sigs
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:00:49 -04:00
ZacharyZhang-NYandClaude Fable 5 a867157978 Add omarchycn-keyring package and container build script
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 19:00:28 -04:00
ZacharyZhang-NYandClaude Fable 5 04b2d8836e Doctor: accept all module arg, survive empty mirrorlist
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:58:27 -04:00
ZacharyZhang-NYandClaude Fable 5 386bf49758 Doctor: silence best-effort notification in headless runs
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:56:09 -04:00
ZacharyZhang-NYandClaude Fable 5 dd3b893137 Add cn doctor with mirror auto-failover and restore commands
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:55:08 -04:00
ZacharyZhang-NYandClaude Fable 5 d1a5ddfd02 dev-mirror: fix cargo official/duplicate handling, sed-free line set, gemrc safety
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:47:40 -04:00
ZacharyZhang-NYandClaude Fable 5 e48264373d dev-mirror docker: create /etc/docker before writing daemon.json
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:43:19 -04:00
ZacharyZhang-NYandClaude Fable 5 15bf72dfe3 dev-mirror lib: shellcheck directive for cross-file array
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:42:41 -04:00
ZacharyZhang-NYandClaude Fable 5 8dab891155 Add dev-mirror manager for npm, pip, cargo, go, gem, docker
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:42:29 -04:00
ZacharyZhang-NYandClaude Fable 5 aabe95b887 Mirror probe: guard failures under set -e, reject HTTP errors
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:40:27 -04:00
ZacharyZhang-NYandClaude Fable 5 434f848dd8 Mirror manager: shellcheck fixes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:35:11 -04:00
ZacharyZhang-NYandClaude Fable 5 2bcf0a20f0 Add Arch mirror manager: benchmark, apply, pin, restore, status
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:34:55 -04:00
ZacharyZhang-NYandClaude Fable 5 18041c7537 cn commands: use OMARCHY_PATH per runtime convention
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:32:51 -04:00
ZacharyZhang-NYandClaude Fable 5 d4002897e3 Add omarchycn CLI entry and cn command group
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:29:01 -04:00
ZacharyZhang-NYandClaude Fable 5 4f06b2364f Sync workflow: always open PR, report trial-merge status
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:24:38 -04:00
ZacharyZhang-NYandClaude Fable 5 2fd24589c2 Add automated upstream sync workflow
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:22:44 -04:00
ZacharyZhang-NYandClaude Fable 5 9ce9f300ae Add OmarchyCN release signing public key and verification docs
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:18:38 -04:00
ZacharyZhang-NYandClaude Fable 5 db5c7db39a Fix CONTRIBUTING sync wording to match current state
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:17:40 -04:00
ZacharyZhang-NYandClaude Fable 5 c1b9d655bb Add NOTICE and governance docs for OmarchyCN
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:15:43 -04:00
ZacharyZhang-NYandClaude Fable 5 743ae05acc Feature-focused Chinese README; move PRD and task list to local-only
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 18:06:40 -04:00
ZacharyZhang-NYandClaude Fable 5 8125f24531 Rewrite README in Chinese with OmarchyCN vs Omarchy comparison
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 15:58:00 -04:00
ZacharyZhang-NYandClaude Fable 5 50b6798467 Record T8-T9: release published, all tasks complete
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 15:26:33 -04:00
ZacharyZhang-NYandClaude Fable 5 3b0f02968a Record T5-T7: build env, baseline ISO build, checksum and boot smoke test
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
4.0.0.alpha-cn.1
2026-08-24 15:10:19 -04:00
ZacharyZhang-NYandClaude Fable 5 5fa312e0ca Record T1-T4 completion and review-corrected M0 partial scope
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 14:34:15 -04:00
ZacharyZhang-NYandClaude Fable 5 2c8a687434 Add OmarchyCN PRD and M0 execution task list
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QKxGW1raAWaqeU8WdHsMsp
2026-08-24 14:21:55 -04:00
5d3299fb94 Wait for the keypress ourselves instead of asking gum to (#8082)
* Wait for the keypress ourselves instead of asking gum to

gum 2.0 runs a spun command without the terminal attached, so the
`gum spin -- read -n 1` that held the presentation terminal open returned
at once. Every menu command that ended in a failure took its window down
with it before the error could be read, which is how a failed update
looked like a terminal that just quit.

Read the key directly. gum's own terminal query replies are still sitting
on the tty when the spinner stops, so drain those first or they answer the
prompt on the user's behalf.

The green dot reads better than the globe did, so the provisioning notice
uses it too and drops its spinner along the way.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Ask the terminal for itself before prompting on it

The /dev/tty node is there whether or not a terminal is behind it, so the
existence check passed on a headless run and left both reads failing with
"No such device or address". Open it instead.

Prompt on the terminal too, rather than stdout: a caller that redirects us
was sending the prompt to a file while the read waited on the terminal,
which looks like a hang with no instruction on screen.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-24 19:46:02 +02:00
1565919c87 Flag a reboot when the docker group changes (#8080)
Group membership is fixed at login, so removing (or adding) the docker group
does not take effect in the running session. The existing-user migration and the
Setup > Security toggles now call `omarchy-state set reboot-required`, so
omarchy-update-restart prompts for the reboot that actually applies the change
(and the bar shows it pending). A plain log out and back in still works.

The migration test now exercises the real removal command and omarchy-state
rather than a stub, asserting the reboot flag is set on removal and left alone
when the user is already out of the group.


Claude-Session: https://claude.ai/code/session_01Gb7x6poap4hGCndPx5qt5T

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-24 19:32:37 +02:00
b5ded31e2f Don't put the user in the docker group; make it opt-in (#8056)
* Don't put the user in the docker group; make it opt-in

The docker group is root-equivalent: anything in it can `docker run -v /:/host`
and rewrite the host as root with no password. On a single-user box that's not
an escalation (the owner is already a wheel/sudo user), but it hands any code
running as the user — a rogue plugin, a poisoned dependency — a silent, headless,
passwordless path to root that sudo's password prompt would otherwise gate.

Stop granting the docker group by default. The daemon still runs (docker.socket);
the Docker TUI and the Windows VM reach it through a polkit prompt, and the plain
`docker` CLI runs under sudo. Sudoless Docker is a warned opt-in via
Setup > Security (omarchy-setup-security-sudoless-docker).

No automatic path may re-grant it: install and first-boot provisioning never
record or apply the group (provisioning also filters a docker line left in an
older factory snapshot), and the Quattro upgrade no longer adds it.

The Windows VM keeps needing the root daemon for a privileged container (KVM,
NET_ADMIN), so it is reworked to run without the group and without becoming a new
way in:

- The compose lives in a root-owned dir and is only written by an elevated,
  input-validated writer. A root-invoked bring-up must never consume a file a
  user-process could rewrite to bind-mount / into the guest — the old
  ~/.config/windows compose was exactly that. Volume paths are rebuilt from
  $HOME on migration rather than trusted from the (user-writable) legacy file,
  path validation rejects traversal, and the privileged sub-action is checked
  against an allowlist before dispatch (a slash in it would otherwise run as a
  path).
- pkexec elevates a verified root-owned command path, not a PATH-resolved one,
  so an authorized prompt can't be redirected to an attacker's binary.
- The guest password is kept in a private 0600 per-user file for RDP instead of
  a world-readable compose, and a declined authorization is reported as such,
  never as a completed stop.

Existing installs auto-migrate the VM (no redownload) and refresh the stale
Docker launcher entry.

🤖 Generated by Opus 4.8 in Claude Code. Reviewed by Codex XHigh.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <codex@openai.com>
Claude-Session: https://claude.ai/code/session_01Gb7x6poap4hGCndPx5qt5T

* Migrate existing installs off the docker group

The default flip only reaches new installs; existing users keep their docker
group membership and stay exposed. Extend the migration that already refreshes
the Docker launcher to also remove the current user from the group when present,
reusing omarchy-remove-security-sudoless-docker so there is one source of truth
for the change and its notice. It takes effect at next login (the current
session keeps working), and passwordless docker can be turned back on from
Setup > Security > Sudoless Docker.

Migrations run with sudo available — during `omarchy update`, or in the terminal
the pending-migrations notification opens — so the privileged removal does not
prompt at an unattended login. The no-op path (already out of the group) needs
no privilege.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb7x6poap4hGCndPx5qt5T

* Refuse symlinked VM mount sources; correct the docker CLI docs

Review follow-ups.

valid_path keeps a traversal string (/./, //, ..) out of the compose, but it is
a string check: a symlink planted at ~/.windows or ~/Windows redirects the
privileged bind mount exactly as traversal would, because docker follows it. So
verify the mount sources as root immediately before bringing the VM up — refuse
a source that is a symlink or resolves through one — which is where the string
check cannot help. A missing source stays fine (docker creates a plain dir).

Also correct the development-tools manual: the CLI is not transparently elevated
(there is no docker wrapper and `d` is still plain docker), so say plainly that
docker on the command line takes `sudo` until sudoless Docker is enabled.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gb7x6poap4hGCndPx5qt5T

---------

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Codex XHigh <codex@openai.com>
2026-08-24 18:56:00 +02:00
Ryan Hughes 5afc9e1495 Revert "Require signed packages from the Omarchy repository"
Reverts 39cffb8f, which landed on quattro through an accidental direct
push. The change returns for review as a pull request.
2026-08-24 12:53:17 -04:00