Add optional ABI-pinned Cua Hyprland plugin package - #346
Conversation
|
Reviewed Codex GPT-6 in T3 Code reviewed the package and its integration; a second Codex GPT-6 review at xhigh found no defects in that scope. Both read the source; shared filesystem access means strict reviewer independence is not guaranteed. The second review identified the Driver protocol mismatch below, which I verified against both releases.
No code or guards were changed. Keep scheduled builds disabled until a matching environment produces a package and passes native tests, package lifecycle, representative input, and fresh-session upgrade/rollback/removal. Those runtime gates were not reached here. Maintainer merge of the disabled recipe is a separate decision from enabling distribution. The CI self-test is now green; the body's pending-approval note is stale. 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
Publication architecture follow-up, targeting Cua Driver 0.24.0. The Driver package update is prepared in #375 at I recommend keeping this as an optional signed binary package, initially restricted to one qualified x86_64 channel. Updating the current hardcoded pins alone would not provide a sustainable publication path. Codex GPT-6 in T3 Code reassessed the source and current package machinery, with a Codex GPT-6 xhigh architecture review and a separate pipeline review. The reviewers support this direction; shared filesystem access does not enforce strict independence. The proposed work has four boundaries:
Keep discovery protocol v2, input protocol v3, native ABI qualification and application behavior separate. Driver 0.24.0's raw background input admits specific Calc/Inkscape versions; a successful ABI rebuild does not qualify arbitrary apps or layouts. Foreground and AT-SPI capabilities remain distinct. Hyprpm can remain a developer route, but local compilation does not replace these checks. This plugin review remains a design review, with no plugin source changes or new plugin build/runtime qualification. The prior clean disabled-recipe verdict stands; broad publication should wait for these bounded gates. The immediate next work is to inventory one channel's native and application versions on a worker, prepare the profile-aware tooling, and revise this PR against that measured target and the Driver 0.24.0 package in #375. Fresh direct channel metadata reads returned HTTP403 here, so I am not asserting new channel versions from this pass. Source anchors: release generator, load-time ABI check, application admission, current release sequence. 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
Rereview of
The remaining native blockers are reproducible:
All four package-repository self-test suites passed. The actual Codex GPT-6 in T3 Code reviewed the integration and worker results; a named Codex GPT-6 xhigh source reviewer found no new verified defect in the disabled recipe and confirmed the 0.24.0 client matches production protocol 3 and the plugin's Keep Published Driver artifact SHA-256: 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
Current stance: hold this PR until it provides an installable, validated optional plugin for a supported Omarchy environment. This replaces the earlier limited recommendation that we could merge the recipe while builds stayed disabled. That would preserve the recipe, but our acceptance goal is a working integration. Keep The plugin is valuable for a specific capability: raw mouse and keyboard actions in qualified native background applications through dedicated compositor input seats. The intended use is an agent working in a supported application while the person continues using another application. The v3 candidate provides two independent agent input lanes, exact live-target checks, conflict refusal and cancellation. Driver already owns CLI/MCP access, sessions and permission policy; its existing capture and accessibility capabilities remain usable independently. Some accessibility actions can also work in the background without synthetic input. The v3 exact-target foreground route also requires this plugin and its advertised foreground capability; it may change primary focus and cursor position. This is limited multi-agent input concurrency within one desktop account. The transport checks the compositor user's UID and trusts code running as that user. It does not provide multi-user authentication, separate desktop accounts, tenant isolation or a sandbox for mutually untrusted agents. Two lanes cannot freely control the same application client, and human focus on a background target client revokes that lane's authority. The v3 protocol defines these limits; foreground routing is separate from the isolated background route. The completed Omabot validation covers unchanged head Requested changes and dependencies before merge:
What we are waiting for: a qualified upstream build contract and the resulting native evidence. Merely waiting for mirrors to refresh will not make the historical dependency pins suitable. The package and documentation changes can be prepared now; the merge decision remains pending until the declared initial scope passes the checks above. trycua/cua#3636 fixes pacman-managed self-updates and is separate from these plugin blockers. Preserve the current package updater protection while targeting Driver 0.24.0. Adopting that upstream fix through a later suitable Driver release does not establish plugin ABI compatibility. 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
The upstream packaging follow-up is selected in trycua/cua#3698. It preserves the published 0.24.0 source archive and adds a separately identified environment profile, verifier and build kit. Native validation is still pending; A fresh public archive audit found matching base-package checksums across stable, RC and edge for Hyprland @spencerbull, can you confirm stable as the initial channel and the representative Omabot build/native environment for the final packaging-path replay? Cua will own the immutable kit/profile updates and input qualification. Who should own Omarchy's dependency-change trigger, package build, and deliberate signing/publication of the exact certified bytes? I am preparing the matched Fleet environment and native evidence in parallel. That will not substitute for the Omarchy packaging-path replay or your merge/publication decision. |
|
We confirm stable x86_64 as the initial supported release target, with edge and RC used for ongoing compatibility validation. We support the separately versioned build-kit/profile approach in Cua #3698, preserving the published Driver 0.24.0 source and its compatibility guards. Application scope: Driver 0.24.0's isolated background mouse/keyboard path currently admits two applications at exact versions:
This allowlist is enforced. Current Omarchy Calc is outside it, so the proposed first Omarchy qualification covers Inkscape; current Calc and broader application support require separate compatibility work and evidence. Foreground input, capture and accessibility have separate contracts. Two input lanes mean two concurrent agent owners, not a permanent limit of two supported applications or multi-user security isolation. Support model: Edge detects upcoming incompatibilities; RC validates the environment intended for stable; stable receives qualified optional packages. Qualification follows the actual Driver/plugin, Hyprland, runtime and application versions in each channel. On x86_64, Hyprland comes from the channel's Arch mirror, so mirror updates and channel switches must trigger compatibility checks. Matching version labels alone do not establish matching binaries. Maintenance is best effort, with no agreed turnaround or promise of a compatible plugin for every desktop update. If a matching replacement is unavailable, offer explicit plugin removal so the desktop can update. Require consent and a fresh-session procedure; declining removal preserves the dependency refusal. Keep a matching rollback set. Proposed ownership, for Cua to confirm: Cua maintains the profiles/build kits, fixes plugin incompatibilities and supplies native input evidence. Omarchy owns package integration, dependency-change detection, Omabot validation, and signing/publication decisions. Omarchy supplies upcoming RC environment details; Cua responds on a best-effort basis. Please confirm this split and name the Cua contact. Next steps:
Codex GPT-6 in T3 Code prepared this maintainer-directed proposal; Codex GPT-6 at xhigh checked its scope and wording. This is a comment-only review, with no new code review or Omabot runtime pass. 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
Confirmed on the proposed best-effort ownership split: Cua maintains the immutable profiles/build kits, plugin compatibility fixes, and native input evidence; Omarchy owns integration, dependency-change detection, Omabot validation, and signing/publication decisions. Francesco (@f-trycua) is the Cua contact through this PR. There is no turnaround commitment or guarantee of a compatible plugin for every desktop update. Stable x86_64 and Inkscape @spencerbull, who should be the named Omarchy package/release owner for the final Omabot replay and deliberate signing/publication? We will keep |
|
Omabot review of P2 — document the exact keymap prerequisite. The activation instructions say “canonical US” without specifying The complete unchanged Linux runner recorded 124 passes and four failures across 128 cells. This used source-built released Driver 0.24.0, separately from the installed-package native proofs:
The final evidence validator rejected the GTK3 case’s missing video/turn evidence, and the runner exited nonzero. These observations do not establish a common cause or an Inkscape background-lane defect. Interrupted actions were not replayed. Cua should diagnose these exact cells and requalify them using fresh fixtures and the original assertions; the existing exact-cell selector can support that investigation. Compositor leave-marshalling warnings are retained in the logs, but are not causally attributed to these failures. Seven native qualification cases remain unproven: move, resize, initial-primary conflict, active-primary takeover, peer conflict, target lifetime, and real idle expiry/reconnect. Their original helpers were invoked, but stopped before the intended action/fault. Bounded Inkscape observations omitted the required selection-status footer that fresh full snapshots and inspected images showed. Primary-conflict cleanup additionally accessed missing The tested pairing is plugin
The bounded source/security review found no additional verified causal defect. Production observer checks and diagnostic traces are separate evidence; lock/unlock transition isolation and interrupted saved-document effects remain unproven. Canonical tests used the full-resolution workaround for the existing Linux harness scaling issue, so the default resized-image path is not certified. The history gate rebuilt its source Driver as prescribed; neither source-built executable is being represented as the installed package binary. These VM results do not qualify bare metal, edge/RC, broader applications, or multi-user security isolation. Recorded SHA-256 identities:
Next steps:
Codex GPT-6 in T3 Code coordinated this Omabot run. A separate Codex GPT-6 reviewer at xhigh checked the exact source and independently reconciled raw evidence; two further Codex GPT-6 threads ran upstream/native and canonical validation. Shared filesystem access does not enforce read isolation. The reviewers’ reconciled recommendation is to retain the merge hold for the items above. 🤖 Generated by Codex GPT-6 in T3 Code. Reviewed by Codex GPT-6 XHigh. |
|
Cua-side validation is now complete and the PR body has been refreshed with immutable evidence. The exact Driver repair candidate passed all four previously failing canonical cells on Fleet, including GTK3; the separate seven-case recovery/lifecycle replay also passed and retired every case with verified cleanup. The repair is merged in trycua/cua#3732 and shipped in Cua Driver 0.27.0. Could Omabot please replay the focused package cells/cases against this PR and reconcile the exact Driver/module/profile identities? |
0c42d65 to
915e5a9
Compare
Import the unchanged recipe from the cua-driver-rs-v0.24.0 build kit. Keep fast-ring automatic builds disabled pending native channel qualification and document explicit ABI updates and compositor restarts.
915e5a9 to
6970a5d
Compare
|
Driver PR #395 is merged, and the stable x86_64 repository now serves This plugin branch is rebased onto the exact current @spencerbull, the exact-pair Omabot replay can proceed against the published Driver package when ready. |
|
Omabot re-review of exact head No verified source, package-shape, or security defect was found in the three-file PR diff. Codex GPT-5.6 Sol in T3 Code reviewed the exact current head, and a separate Codex GPT-5.6 Sol reviewer at xhigh found the plugin files byte-identical to the reviewed pre-rebase version and found no new defect; shared filesystem access means strict reviewer independence is not guaranteed. Both current CI checks are green. The replay used a fresh credential-free Omabot worker running Omarchy The exact PR recipe built through The supported production path passed with the actual installed packages. Explicit activation mapped the exact module with an ABI match, protocol 3 ready, and two idle lanes. Two independent Driver processes controlled two distinct native Inkscape clients concurrently; six background keyboard actions completed, both documents saved with exact SVG position oracles The complete unchanged 0.27 Linux canonical runner recorded 130 results: 82 deliveries, 41 expected refusals, seven failures, and no skips. Clean focused reruns cleared the Electron type-text, type-submit, press-key, and editor-save failures. The remaining reproducible failures are:
One installed-Driver focused Electron The current support promise remains intact: stable x86_64, native Wayland Inkscape Next steps: Cua should reproduce the two foreground drag cells on the recorded Omarchy/Hyprland environment and explain the difference from its exact-release Fleet evidence, then provide a Driver or plugin candidate if the failure is in production code. Cua should also align the GTK3 foreground-scroll test's declared route and target geometry with the path it actually exercises. Omarchy/Omabot can then replay only those affected cells plus the intermittent package-backed key action. Keep 🤖 Generated by GPT-5.6 Sol in T3 Code. Reviewed by GPT-5.6 Sol XHigh. |
|
I'm thinking we merge and open these as open issues for the plugin for further enablement. Thoughts @f-trycua? |
|
yeah, I agree. I'd merge the recipe with |
Scope
Update the optional Hyprland plugin package for the agreed stable x86_64
target. This PR remains held for Omarchy's own replay and release decision;
skip_build: truestays in place.The recipe downloads immutable build kit 1.1.0,
profile
omarchy-stable-20260910, instead of the historical 0.24.0 recipe.Cua #3698 is merged. The plugin source is
Driver 0.26.1,
including the separately reviewed desktop-fault cleanup repair.
The original 0.24.0 release assets remain untouched. Please review this explicit
source change as part of the package update.
The intended Omarchy publication pairing is
cua-driver-bin 0.27.0-1plusnative Wayland Inkscape
1.4.4-6, with two independent Driver processes anddistinct native clients. Plugin package version
0.26.1-2identifies itspinned compositor-module source, not the separately installed Driver client.
The production plugin source and protocol are unchanged in Driver 0.27.0; that
release adds the bounded client-side stale-geometry retry described below.
Input protocol v3 and discovery protocol v2 are separate. Omarchy's own build,
replay, signing, and publication of this exact pairing remain pending.
Package contract
0.56.2-2, header, GCC16.2.1 20260810, andshared-runtime identities; no compositor replacement or relaxed ABI guards.
executing tooling, and mandatory CTests even with
--nocheck,--repackage,or
--skipinteg.remains explicit after a fresh session and consumer compatibility check.
source: local,release_ring: fast, andscheduled-build exclusion. The Driver package and its update protection are
unchanged by this PR.
The README documents activation, disabling input, incompatible desktop updates,
removal, matching rollback sets, and the best-effort ownership split.
Cua qualification
The qualification record
and #3698 separate production-package observations from trace-enabled
diagnostics and identify exact evidence digests.
43da0b7318b0b78613b87ce6a7b9afba228dafcc80724cab4013d5088c797555433ce968ee164d5e8e3226e800db93a6recorded 128 required cells: 87 deliveries, 41 expected refusals, no failures/skips, using source-built Driver 0.24.0. A separate Omabot replay reported 124 passes and four failures.ea6ad2d40d4b018a216642177f907289c33a2c38passed Electron drag, Electron editor save, Tauri drag, and GTK3 desktop scroll. Driver binary SHA-256d6cb8756eb1520d1e3c6302527a270f6c6c847281e0ef8988b9c12e714671aa7; evidence SHA-2569adbba75b52481e93b5352052b88d572ee1686b85676d3054a51a5f7e49ba1e9; cleanup verified. The exact release head then passed the canonical Linux desktop E2E. The repair is shipped in Driver 0.27.0, whose Linux x86_64 binary archive has SHA-25687e547867ddb2a3ab7bb09ba79f7833f44a34ac11b21e7d150b867910d5999f2.bb1b65394e912246220f9f758c9efbbf6260cec16e3562e62a361fa95329377f, and exact Driver/harness source082de4344b731ae4738ddc6a6f13f21bb3c49a85passed all four production cells, including GTK3 desktop scroll in 3,952 ms. Sanitized evidence SHA-256b6c47278a3db398ecbb4d7aed2bce44a467e2af37e6d4ccfc236d1e07aa70af7; videos inspected; cleanup and independent namespace absence verified.Duplicate motion notifications remain counted. They are acceptable only when
pointer identity/coordinates, focus, held input, and foreground interaction
remain unchanged. Real motion, including an excursion and return, fails. An
inert agent pointer may remain parked after input is released and authority is
revoked.
Current Calc, Chromium/Electron raw background input, XWayland, Unicode/IME,
non-US keymaps, and modified pointer gestures remain outside this profile.
These are bounded action/interval claims, not arbitrary-app or multi-user
isolation. Screenshots and build success do not replace native qualification.
Remaining Omarchy gates
The confirmed ownership split
keeps Cua responsible for profiles, kits, fixes, and native input evidence.
Francesco (@f-trycua) is the Cua contact. Omarchy owns integration, dependency
change detection, Omabot replay, and signing/publication. Spencer (@spencerbull)
and Emir (@emirb) are the named Omarchy package and release owners for the
replay, merge, signing, and publication path.
them with the immutable Cua evidence above. A Fleet result is supporting
evidence, not an Omabot result; matching source alone does not certify
different binaries.
identities, including the Driver version that Omarchy intends to publish
alongside the plugin.
bytes. Keep
skip_build: trueuntil the declared gates pass; it is not anartifact-to-evidence publication gate by itself.
background-action, and cleanup smoke.
Omabot's downstream replay/reconciliation, signing, and Omarchy publication are
not claimed by this update. Broader channels and unattended publication remain
separate work.