[fix] Rebuild compatible Hyprland dependencies for factory images - #142
Conversation
themartiano
left a comment
There was a problem hiding this comment.
Thanks for the pull request!
Codex comments
Please rebase after #136 and resolve the guest-contract conflict. Also record and verify the provenance of the vendored aquamarine archive: the new repository uses Optional TrustAll, and a SHA declared beside the binary does not establish its upstream origin. Include verified upstream signature evidence or a reproducible source build, then run the complete guest build to verify the changed CMake/Hyprland pins.
ALARM only publishes libaquamarine.so=14 while locked Hyprland still needs .so=13, so empty-root resolve fails and Omarchy updates break. Vendor the reviewed 0.14 package for builder resolve, refresh the lock, and hold aquamarine with Hyprland in the finished guest.
The factory pin cannot rely on a reconstructed unsigned archive plus TrustAll. Rebuild 0.14.0-2 from the Arch packaging commit and hyprwm tarball so empty-root resolve still gets libaquamarine.so=13 with verified upstream origin.
57892d9 to
3f78ed3
Compare
|
Rebased onto current Provenance: the reconstructed unsigned archive is gone. The factory now rebuilds
Locally: |
|
@itamblyn I'm reviewing this PR again. There has been a lot in motion in the past day, so let me see what is going on here. |
|
@itamblyn This should be in working shape again. Extra confirmation is very welcome--thanks! |
Arch Linux ARM now publishes only aquamarine 0.15 (libaquamarine.so=14) while the locked Hyprland still needs .so=13, so an empty-root resolve failed. Bring in the reviewed aquamarine 0.14.0-2 rebuild and refreshed package lock from omacom#142. Keep this fork's 150 GiB working-disk expectation in the verifier. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDi5Ufy1LWAPYcx2U3fvsp
…ilds work Arch Linux ARM rebuilt hyprtoolkit against libaquamarine.so=14 after upstream PR omacom#142 was written, so the locked Hyprland stack still could not resolve: hyprland -> hyprland-guiutils -> hyprtoolkit -> libaquamarine.so=14. Add hyprtoolkit 0.5.4-4 as a second reviewed ABI pin, rebuilt from the Arch PKGBUILD (aarch64 enabled) against the rebuilt aquamarine 0.14 package, and hold it on the guest IgnorePkg alongside aquamarine. Fix the aquamarine rebuild script so it actually runs on the ALARM builder: the mktemp stage was 0700 root so the makepkg user could not enter it; ALARM's makepkg.conf emits .pkg.tar.xz where the provenance check expects zstd (pin PKGEXT); and the randomized stage path leaked into the library so no two rebuilds produced the same digest (use a fixed stage path). Record the reproducible aquamarine, hyprtoolkit, and Rust 1.98.1 ttfx digests observed here, and refresh packages.lock.json against current mirrors. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DDi5Ufy1LWAPYcx2U3fvsp
|
🤖 Written by Claude Opus 5 (an Anthropic AI model) on behalf of @k5953837, who is blocked on this PR for #175 and ran the build to confirm it. Everything below is from one run on 2026-09-09. Confirmation from an Apple Silicon Mac, since you asked for it. Setup: macOS 15 on Apple Silicon, Docker 29.6.2 with native
|
|
@themartiano The lock refresh is pushed in 9e31d3b and CI is green. The fresh resolver confirmed that only Local validation also passes: the full test suite, complete factory/runtime/app build, pinned binary-hash checks, app signing verification, and macOS 15 compatibility checks. Could you take another look at the outstanding review and merge if everything is satisfactory? The provenance and complete-build work requested on the earlier revision is included. Since the build resolves against rolling repositories, a timely review would help avoid another lock refresh while this is pending. |
|
Great! Merging now, thanks |
Fresh ARM64 factory builds cannot resolve the rolling repository's mixed aquamarine ABIs: the pinned Hyprland needs
libaquamarine.so=13, while the current Hyprtoolkit needs.so=14.This rebuilds aquamarine 0.14 and Hyprtoolkit 0.5.4 from reviewed Arch recipes and verified upstream sources, then exposes the compatible pair through a disposable builder repository. Hyprtoolkit uses package release
6.1to distinguish the rebuild. The finished guest holds both packages alongside the patched Hyprland and does not retain the builder repository.The source builder now gives its unprivileged build user access to temporary directories, explicitly produces zstd packages, cleans up its build account on failure, and remaps temporary build paths. Library hashes are verified before packages enter the repository. The Rust/ttfx and pkgconf/Hyprland pins and the 614-package transaction lock are refreshed together.
Validation:
3f7ec01.make testpasses with the Xcode toolchain, including new regression tests for the compatible pair, missing archives, and guest/builder package holds.make buildpasses with a new, empty guest-work volume. The independent Hyprland rebuild reproduces its pinned hash and passes its installed version check inside the guest root.Fixes #171 and extends the factory-build work discussed in #134.