Skip to content

Integrate Apple Silicon stabilization fixes for 4.0.3rc1 - #377

Merged
malik-na merged 38 commits into
omacom:quattrofrom
scottjones:integration/4.0.3rc1-green
Sep 10, 2026
Merged

malik-na merged 38 commits into
omacom:quattrofrom
scottjones:integration/4.0.3rc1-green

Conversation

@scottjones

@scottjones scottjones commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Apple Silicon stabilization for the next 4.0.3 release candidate: first-login and Snapper fixes, bounded-sudo scheduling failure handling, lid locking, audio/recording repairs, and compositor update fixes. The combined branch passes hosted source CI and ARM fresh/repeat installation checks.

Changes

Validation

Tested head: 8ee210a57a4d263be874be374db659d7cd101303.

  • Hosted CI: PASS: test/all, tests/all, syntax, and ShellCheck.
  • Hosted ARM installation: PASS: real pacman transaction regressions, fresh installation, repeat installation, package-source assertions, and user finalization. Both passes retain the exact selected compositor versions, including hyprtoolkit 0.5.4-5.1.
  • Independent local QA and review passed; all four companion package self-tests passed. A sandbox-only routing test failure passed unchanged with routing access.

Dependencies and release gates

Package PR #341 must land before production builds can rely on upstream's default recipes; this PR pins it explicitly for CI. ISO companion omarchy-mac/omarchy-mac-iso#19 remains separate.

This PR does not bump the version or publish an RC. ARM channel isolation, published-artifact upgrade testing, M1/M2 hardware qualification, and canary validation remain required. M3 remains experimental. Passwordless sudo persistence across reboot is a preexisting separate gap; #376 fixes failure to schedule expiry. Hosted ARM containers do not qualify Apple boot, GPU, audio, or suspend behavior.

Closes #361
Closes #368

scottjones and others added 26 commits September 5, 2026 17:02
M3 has DCP scanout but no AGX render node, so Chromium and 1Password die
in the GPU process and stay running with no window. PATH wrappers on
/usr/local/bin add --ozone-platform=wayland --disable-gpu at launch when
renderD* is missing, and become a no-op once a render GPU appears.
omarchy-notification-send rejects a quoted whole command so it cannot
be split. The toast then exits 1, first-run skips the timezone card,
and a Mac left on UTC never gets asked. Match wifi.sh and welcome.sh.
Apple Silicon MacBooks report lid events under 'Apple SMC power/lid events'.
When Quattro introduced omarchy-system-lid-close to lock the session and
coordinate pre-suspend display state, the Mac-specific switch:on binding was
left wired to omarchy-hyprland-monitor-clamshell instead.

As a result, closing the lid on an Apple Silicon MacBook bypassed
omarchy-system-lid-close entirely, preventing the session from locking before
suspend.

Route switch:on:Apple SMC power/lid events to omarchy-system-lid-close,
mirroring the generic switch:on:Lid Switch bind, and assert both bindings
in monitor-recovery-test.sh.
wf-recorder follows the Asahi DSP clock into a 96 kHz AAC track that this PipeWire graph (and many players) play as silence. Pin the sample rate at 48 kHz.

Stop/bar/menu matched ^wf-recorder, which misses argv[0] when it is a full path. Match the basename at a path or line boundary so Capture Stop and the bar indicator work on Apple Silicon.

The webcam overlay already skipped initial focus; clicks still stole the session. Ignore focus and mouse-follow so the mini-me stays put.
asahi-audio publishes the beamformed laptop mics as AUX0. Recorders ask for FL/FR, so they fail to link or write left-only audio that loudnorm ruins. Duplicate AUX0 onto a low-priority stereo sink and use its monitor as the default source, without moving existing source-outputs (that steals the DSP capture).

speakersafetyd can hit start-limit after a bad IV-sense sample and leave the speakers muted at -100 dB; clear that and try once more.
A new null sink can steal the session output. Putting the speaker convolver back unconditionally bounced headphones and Bluetooth to the internal speakers on every login. Snapshot the default first and restore it; only fall back to the convolver when the dummy sink is what is left.
…rmed

Backport arm_expiry() from omacom/omarchy, which omarchy-mac does not carry.

Both systemd-run call sites ran unchecked, so a failure to schedule the expiry
timer left the NOPASSWD sudoers rule in place while the script still reported
that access would expire in N minutes. The timer's `rm` also lacked -f, so
disabling a window early caused the still-scheduled timer to fire against a
missing file, exit non-zero, and strand the transient unit in failed state --
which then blocked the next `systemd-run --unit=` and reproduced the fail-open
path on every subsequent enable.

arm_expiry() uses `rm -f --` so the unit cannot strand itself, checks
systemd-run's exit status, and revokes the grant immediately if the timer
cannot be scheduled. Callers use `arm_expiry || exit 1`.

The mac fork's restart-notice wording is intentionally kept: a file in
/etc/sudoers.d survives reboot and is only cleaned up on the script's next
invocation, so the existing message is more accurate than upstream's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R5z6wirF6matApdUKH4fFT
…ntegration/4.0.3rc1-green

# Conflicts:
#	install/user/all.sh
@scottjones
scottjones marked this pull request as draft September 9, 2026 00:50
@scottjones

Copy link
Copy Markdown
Collaborator Author

Stabilization status for this draft PR at 8ee210a57:

  • CI is green, including ARM installation testing.
  • Local installation of the matched desktop/settings packages on Scott's M2 passed, using the pinned package recipes from Fix ARM Snapper dependency and first-run keyboard service packaging omarchy-pkgs#341.
  • Post-install checks found no failed system/user units or pending migrations. Stereo microphone routing and protected speaker output were verified, and a short screen recording passed.
  • Scott confirmed that reopening the lid required his password and the display/desktop resumed normally after unlocking.
  • Reboot/login persistence and audible microphone, speaker, and headphone checks remain pending.

Keep this PR in draft while those local hardware checks are underway; mark it ready once they pass. These results cover a local package installation with the development checkout linked, not an upgrade through a published RC repository.

ARM RC repository isolation and testing the exact published packages remain release gates. They do not necessarily need to block review of this integration PR.

@malik-na

malik-na commented Sep 9, 2026

Copy link
Copy Markdown
Member

Review recommendation: request changes. The review found ten P2 issues in new behavior. The package-selection, boot-layout guard, immediate sudo-scheduling failure handling, and timezone changes passed their scoped checks. Existing repair gaps and release qualification limits are listed separately below.

Reviewed head: 8ee210a57a4d263be874be374db659d7cd101303
Reviewed base: 291a6989e2021afb4394199b2d13dbe3e5ad0a55
Companion package recipes: 6d27290193109c07b0134360d382e64790ae5dda
Stable source used for package compatibility checks: 346e69e1cec6c4e8924531874af6ba010a1bc99e

Five subagents covered four implementation scopes plus independent aggregate QA. The parent covered CI/integration and corroborated findings; two of the reviewers also performed targeted cross-reviews. All 45 changed files were covered. The PR head and base were checked again before posting and still match these revisions.

1. P2: Recorder detection can select unrelated applications

bin/omarchy-capture-screenrecording:54; the same pattern is used in default/omarchy/omarchy-menu.jsonc:60 and shell/plugins/bar/indicators/ScreenRecording.qml:18.

The new slash alternative is unanchored. Because the process queries use full-command-line matching, a path in another application's arguments can satisfy the recorder pattern even when that application is not a recorder. This affects more than the indicator: existing stop logic uses the same pattern for SIGINT and eventual SIGKILL, and the regular toggle can enter that stop path based on the false match.

Independent pure-string checks confirmed new false matches that the base rejected, alongside controls for legitimate absolute recorder paths and executable suffixes. No live process lookup or signaling was performed.

Please constrain selection to the recorder executable/process identity and use the same identity policy for start, status, and stop. Preserve absolute-path support; simply restoring the old pattern would lose that improvement.

2. P2: Failed microphone links can replace a working input with a silent monitor

bin/omarchy-audio-asahi-mic-map:45 and bin/omarchy-audio-asahi-mic-map:53.

Exhausting the port-readiness loop does not stop setup. Both channel-link errors are then ignored, and the mapper still selects the monitor as the default source. The readiness check also does not establish that the right-channel port exists.

Separate fixtures for absent ports, rejected links, and a missing right channel all replaced the previously working input. This is newly introduced behavior.

Please verify that both required links exist before changing the default input. Treat already-existing links as idempotent success, preserve the previous input on failure, and clean up only resources created by the failed invocation.

3. P2: A custom launcher blocks user finalization and later migrations

migrations/1788639443.sh:13 and install/user/hardware/apple/electron-gl.sh:13; refusal originates in bin/omarchy-cmd-electron-gl-wrap:46.

The wrapper helper correctly refuses to overwrite an unmanaged launcher or non-legacy symlink. However, both strict callers treat that ownership conflict as fatal. An otherwise valid administrator-managed Chromium launcher therefore aborts user finalization and stops the migration queue before unrelated later repairs. A custom 1Password launcher reaches the equivalent conflict later in the flow.

The same inert custom-launcher state completes the base user-stage driver, while head exits nonzero. An isolated migration-runner fixture leaves the failed and later completion markers absent.

Please preserve the ownership refusal while handling this optional wrapping conflict explicitly at the callers, for example by skipping with a clear diagnostic or using a distinct managed launcher. Actual write/install failures should still propagate.

4. P2: Chromium setup destroys existing desktop customizations

install/user/hardware/apple/electron-gl.sh:18.

The script writes a transformed copy of the system desktop file directly over the user's chromium.desktop, without checking ownership or preserving a backup. Existing profile arguments, custom actions, names, and other fields disappear. This write is outside the render-GPU-absence condition, so it also affects Apple systems with a render GPU during migration or repeated setup.

The custom-desktop fixture lost its profile selection and custom fields; the base had no corresponding writer.

Please preserve an existing user entry and make only the necessary targeted executable repair, retaining arguments and desktop actions. Seed a generated entry only when appropriate, and preserve a backup when changing existing content.

5. P2: An unseeded Chromium wrapper adds a background sudo requirement

install/user/hardware/apple/electron-gl.sh:13 and bin/omarchy-cmd-electron-gl-wrap:95.

The concrete failing state is pending or forced graphical user finalization on an Apple machine with Chromium installed, an absent/incorrect global Chromium wrapper, and no usable noninteractive sudo authorization. The newly added leaf reaches privileged operations in /usr/local/bin from the background first-run path. Failure aborts finalization before later leaves and leaves it retrying on future logins.

Static tracing of the real caller and exact companion recipes found no package or root hardware stage that guarantees the Chromium wrapper. A denying sudo mock produced a head-only failure at this new boundary.

This is not every first login: matching wrappers need no sudo, completed finalization skips the path, and the interactive installer can authenticate earlier. Successful fresh 1Password setup also seeds its own wrapper, so Chromium is the independently supported case. The hosted installation user's unrestricted NOPASSWD sudo does not exercise this condition.

Please provision machine-wide Chromium wrappers in root-scoped setup and leave per-user desktop work in the user leaf.

6. P2: Login replaces an explicitly selected external microphone

bin/omarchy-audio-asahi-mic-map:73.

When the built-in DSP source exists, every invocation selects its monitor regardless of whether the user selected a working USB, Bluetooth, or headset microphone. The new autostart repeats this at login. The fixture with a selected, available USB input was switched to the remap.

Please preserve explicit input choice and select the remap only when replacing the intended built-in source or establishing an otherwise unconfigured default. Output-device restoration does not preserve the input-device choice.

7. P2: Repeated mapping resets microphone gain

bin/omarchy-audio-asahi-mic-map:56.

DSP source, sink, and monitor volumes are reset to 100% even when reusing an existing mapping. A fixture with calibrated gain at 42% lost that setting on the next invocation. The new login call makes this a recurring reset.

Please separate initial graph setup from repeat invocation and retain the effective user-selected input gain and mapped-source volume.

8. P2: Restart Audio loses the new microphone mapping

default/hypr/autostart.lua:15 and bin/omarchy-audio-asahi-mic-map:40; related existing caller: bin/omarchy-restart-audio:6.

The null sink and links are created as runtime graph objects. The only creation paths are login and setup, while the existing Restart Audio command restarts the services owning those objects without rebuilding them. Static lifecycle tracing and an inert model of service restart leave the new mapping absent after the restart helper returns success.

Please tie graph creation/recovery to the audio-service or node lifecycle through persistent supported configuration or supervised remapping that also preserves user choice. This is a lifecycle gap in the new feature; physical audio recovery was not tested.

9. P2: The audio migration reports success after real mapper failures

install/user/hardware/apple/mic.sh:13, reached by migrations/1788820499.sh:10.

The standalone mapper returns nonzero when module creation fails, but the sourced leaf suppresses both status and diagnostics. The migration can consequently finish successfully without completing the live-session repair.

The standalone module-load-failure fixture correctly failed; the same failure through the leaf/migration was suppressed. Please distinguish expected deferral when no audio session exists from real failures in a live session, and propagate the latter.

The login autostart does retry on the next login. This finding concerns silent failure and migration completion during the current update, not a claim that retries can never occur.

10. P2: The migration overwrites a customized same-name WirePlumber policy

install/user/hardware/apple/mic.sh:10.

The new migration unconditionally copies over ~/.config/wireplumber/wireplumber.conf.d/asahi-headset-mic.conf. An existing customized file at that exact path loses its contents without backup or reconciliation. The base has no corresponding writer. The automatic migration makes this relevant independently of an explicitly requested configuration reset.

This is narrowly conditional on that exact filename; other drop-ins are unaffected. Normal login invokes the mapper rather than this copying leaf, so it is not an every-login overwrite.

Please seed absent files and preserve custom existing content. If a known managed version must be updated, identify it explicitly and preserve a backup or reconcile the intended property.

Existing defects / incomplete upgrade repairs, excluded from the ten new findings

  • 1Password desktop routing: the new installer repairs the desktop command, but the new migration only replaces the PATH launcher. Existing desktop entries using the absolute application path still bypass the adaptive wrapper after migration. A read-only check of existing installed and vendor-resource desktop entries corroborated this path shape. The actual GUI/GPU failure was not reproduced. Share a preserving desktop repair between installation and migration, without invoking download/reinstallation merely to repair routing.
  • Missing Snapper setup on existing installs: ordinary updates do not rerun apply-system, and completed migration markers prevent an old repair from retrying when the dependency later becomes available. Neither the two new migrations nor the inspected companion install hooks establish missing Snapper configuration. A new idempotent repair migration is needed before claiming coverage of these existing installs.
  • Partial Snapper configuration: the PR improves initial error propagation, but an existing partial config can still make a later retry skip backend creation and report success. Base exhibits the same gap. The mock establishes the partial-state contract, not the real backend's failure ordering.
  • The previously acknowledged sudo expiry-across-reboot gap is unchanged. Immediate scheduling-failure cleanup passed its scoped mocks. Recorder startup failure can also leave temporary audio modules behind at both base and head; that unchanged defect is not attributed to this PR.

Validation and limits

The added checks below are fixture assertions or reported scenarios, not independent full installations. Some checks deliberately assert expected failure handling or establish an unchanged baseline defect.

Added check group PASS Failed invariants
Native pacman resolver and mocked update/installer callers 74 0
Boot, sudo, Snapper and lid fixtures 37 0
Electron, setup, migration and timezone boundaries 39 5
Media selection, lifecycle and recorder boundaries 24 12
CI/source-staging/user-stage integration 8 0
Independent recorder string-match controls 12 0
Total 194 17

These 211 checks do not mean 17 distinct bugs: fourteen failed invariants support the ten new findings, one demonstrates the older 1Password repair gap, and two demonstrate the same pre-existing recorder cleanup defect at base/head. Native pacman tests used synthetic databases and print-only resolution, not host package installation.

Independent aggregate QA completed both revisions normally:

Revision / suite PASS files FAIL files SKIPPED files BLOCKED files
Head CLI 1 0 0 0
Head shell 240 0 20 2
Head Mac 8 1 1 0
Base CLI 1 0 0 0
Base shell 235 0 20 1
Base Mac 8 1 1 0

The Mac help assertion fails identically in unchanged baseline code in the isolated environment. The head-only pacman test is blocked by the aggregate executable restrictions but passed separately under the package reviewer's isolated native-pacman setup. The clipboard lifecycle test is blocked on both revisions because setpriv is outside the allowlist. Shell skips include ten deliberately excluded probe/namespace tests and ten compositor-only tests; additional partial skips remain documented in the retained logs. Disposable overlays redirect legacy temporary paths and restrict external actions, so these results are not a pristine, unrestricted full-suite PASS.

All eight settings-package staging combinations passed: stable/current source, stable/development flavor, and ARM/x86 architecture. The stable source pin was fetched explicitly to avoid silently skipping those cases. The Snapper dependency assertion also passed. Parse-only checks passed for 1,032 Bash and five Python files.

The existing source CI and ARM installation run were successful when reviewed. The ARM log independently records the exact head/base merge and pinned companion recipes. Both fresh and repeat installation assertions retain hyprland 0.56.2-3, hyprtoolkit 0.5.4-5.1, and hyprland-guiutils 0.2.2-3. No new hosted run was dispatched.

Release assessment: HOLD. The package-selection changes have positive bounded evidence, but existing-user migration behavior needs revision. Companion #341 was still open/unmerged when reviewed. Old published-package upgrades, physical M1/M2 boot/GPU/audio/recording/lid/suspend/recovery, isolated RC artifacts and canary qualification were not tested here. Current-stack remediation and repeat installation do not substitute for those gates.

Suggested repair order: constrain recorder selection; make microphone setup transactional and preserve device/gain choices; restore mapping across audio restarts and propagate real failures; preserve customized files and provision global wrappers at the correct privilege stage; then close existing-install migration gaps. Re-run the failed invariants and affected integration checks before merge approval, followed by qualification of the exact packaged artifacts before release.

@malik-na

malik-na commented Sep 9, 2026

Copy link
Copy Markdown
Member

Follow-up review (1/2): remaining findings at 40c5c15

Recommendation: hold approval pending the four P2 items below. Eight of the original ten findings are fixed; two are partially fixed. This follow-up also identifies two new Snapper service-repair regressions and one nonblocking P3 desktop-entry issue.

Reviewed the six commits after 8ee210a57a4d263be874be374db659d7cd101303, ending at 40c5c1533503435a0473166b2fc24dd62f36dba2, against unchanged base 291a6989e2021afb4394199b2d13dbe3e5ad0a55. The PR head was refreshed immediately before preparing these comments and still matches. These notes update the earlier review; they do not repeat its fixed findings as open defects. Fix dispositions and validation are in comment 2/2.

1. P2: an ordinary Chromium symlink still blocks setup and migrations

Original finding 3: PARTIAL, not a newly introduced follow-up defect.

At bin/omarchy-cmd-electron-gl-wrap:49, the same-file guard follows an administrator-created /usr/local/bin/chromium -> /usr/bin/chromium symlink and returns 1 before the unmanaged-launcher branch can return 3. Chromium cannot use the special legacy-1Password exception. Both normal provisioning and --check take this early failure path.

The symlink and real binary remain intact, but install/hardware/apple/electron-gl.sh:18 and install/user/hardware/apple/electron-gl.sh:27 propagate status 1. The new migrations/1788980682.sh:3 therefore still stops before its completion marker or later migrations, including when the earlier migration was already marked complete.

Regular custom launchers and other-target/dangling symlinks now pass the ownership-conflict handling. Three focused failing checks isolate the remaining same-target case: readiness, user finalization, and the follow-up migration queue. The previous reviewed head fails the same case; original base had no corresponding Electron leaf.

Please preserve this unmanaged alias and classify it consistently as an ownership conflict without weakening protection against overwriting a real binary. Actual I/O failures should remain fatal. An independent reviewer confirmed the default-path reachability and migration consequence.

2. P2: existing-root setup skips cleanup-timer repair

New follow-up regression affecting ARM and x86 service repair.

At install/config/snapper.sh:41, a valid registered root with a readable snapshot backend returns success before cleanup activation at line 58. If snapper-cleanup.timer needs activation, the leaf now succeeds without repairing it. Both original base and the previously reviewed head activated cleanup for an existing root.

This is an existing caller contract, not an assumption that every deliberately disabled administrator timer should be overridden: migrations/1781984677.sh:34 explicitly detects inactive/disabled cleanup and calls this leaf at line 44 to repair it. That action can now report success without satisfying its own service predicate. Shared setup and the new repair migration also reach the leaf. An already-completed old migration does not automatically rerun merely because its leaf changed.

In both ARM and x86 inert fixtures, earlier revisions finish with cleanup active; current head returns 0 with it inactive. The old service-normalization caller comparison confirms the same mismatch.

Please reconcile required cleanup readiness on the successful existing-root repair path, or move that responsibility to an explicit repair layer and update its callers. Preserve the new custom-config, registry, snapshot and global-timeline safeguards, and propagate service failures.

Impact is specifically missing scheduled cleanup under these preconditions. Already-active timers are not stopped, and explicit number cleanup in omarchy-snapshot remains; this does not demonstrate loss of all cleanup or universally unbounded snapshots.

3. P2: optional x86 Limine synchronization activation was removed

New follow-up regression, with conditional operational impact.

At the setup/service boundary install/config/snapper.sh:58, the previous availability check and enable/start of limine-snapper-sync.service have disappeared from both fresh and existing paths. Both earlier revisions performed this operation when the unit existed. The unchanged migrations/1781984677.sh:38 still considers inactive/disabled sync to require repair and delegates to this leaf.

No replacement activation was found in the reviewed shared service setup or exact settings-package hooks. The pinned companion recipes keep the Limine stack for x86. A fresh x86 fixture with the unit available but inactive now returns 0 with cleanup active and Limine sync inactive; both earlier revisions activate both.

Please restore availability-gated activation after backend validation, or provide an equivalent documented replacement and update the old repair caller. Keep ARM without the optional unit a no-op.

Qualification: the external Limine package payload's hooks, presets and path units were not independently audited. An inactive service alone does not prove that no equivalent trigger provides synchronization. The loss of this source-visible setup/repair operation is confirmed; an unconditional claim that every fresh x86 installation loses boot-entry synchronization is not supported. Already-working x86 sync is not stopped by this change.

A second reviewer independently confirmed findings 2 and 3 and checked the surrounding setup, migration and package paths. Five failed assertions support these two issues, not five separate defects. The new supplied Snapper tests pass, but removed service assertions and the current test's prohibition on Limine calls do not establish preservation of the old repair contract.

4. P2: a microphone choice during the final graph query is overwritten

Original finding 6: PARTIAL, not a duplicate new finding.

At bin/omarchy-audio-asahi-mic-map:183, the mapper queries the graph after reading the current default source. It validates endpoints and links, then compares that earlier input value before setting the monitor at line 190.

Concrete case: mapping is being established/recovered, the original input is the DSP microphone, the final default-source read still returns it, and the user chooses a USB/Bluetooth microphone during the subsequent graph query. The built-in endpoints remain valid, but the stale comparison then overwrites the newer choice with omarchy_asahi_mic.monitor.

The inert trace records the user choosing the USB input during final graph query 7, followed by the mapper selecting its monitor. This is a deterministic modeled interleaving checked against the current source, not a live timing/hardware demonstration. Stable external-device choices and changes observed before the final default read now pass.

Please retain the endpoint checks, then re-read the selected input immediately before deciding whether automatic selection is still appropriate. Add the case where selection changes during the graph query. This closes the avoidable query-sized window; separate read/write operations still do not establish atomic race freedom.

5. P3, nonblocking: spaced custom wrapper paths produce invalid TryExec values

At bin/omarchy-cmd-desktop-exec-repair:33, both Exec and TryExec receive executable-token quoting. A valid entry rewritten to a wrapper path containing spaces acquires literal quotes in TryExec; GLib's read-only desktop resolver rejects it. An otherwise identical unquoted TryExec control is accepted.

The Desktop Entry Specification treats TryExec as an executable path for availability checking, distinct from Exec command parsing.

Severity calibration: runtime code honors the override, but no documented or shipped production configuration establishing a spaced wrapper directory was found. Defaults are /usr/local/bin/chromium and /usr/local/bin/1password. A spaced HOME or checkout alone does not trigger the problem, and no valid default-path failure was demonstrated. The independent cross-check therefore lowers this to P3; it is not included in the four-P2 approval blocker count.

Please encode TryExec separately from Exec and add native validity coverage beginning with a valid desktop entry. The supplied test's byte-equality check of an already-quoted value does not establish desktop validity.

@malik-na

malik-na commented Sep 9, 2026

Copy link
Copy Markdown
Member

Follow-up review (2/2): fix dispositions and validation at 40c5c15

Scott's follow-up fixes eight of the original ten findings in the audited source and bounded fixtures. Two remain partial, as detailed in comment 1/2. The new migrations also close the previously identified 1Password and Snapper upgrade-repair gaps.

Current head: 40c5c1533503435a0473166b2fc24dd62f36dba2
Previously reviewed head: 8ee210a57a4d263be874be374db659d7cd101303
Original base: 291a6989e2021afb4394199b2d13dbe3e5ad0a55
Companion recipes: 6d27290193109c07b0134360d382e64790ae5dda

Five scoped reviewers covered the 26 follow-up files: recorder, audio/lifecycle, Electron/desktop/migrations, Snapper, and aggregate QA. Independent cross-checks challenged the remaining Snapper and Electron findings; the coordinator checked the audio interleaving against source and its retained trace.

Disposition of the original ten findings

Earlier finding Status Current evidence
1. Recorder argument matching selects unrelated processes FIXED Actual executable identity replaces command-line matching; callers share the helper. Absolute/deleted executable paths, owner filtering and mocked pidfd selection pass. No live signaling or kernel race-freedom claim.
2. Failed mic links select a silent monitor FIXED Required endpoints, link readiness and final identities are checked before selection; rollback preserves pre-existing resources.
3. Unmanaged launchers block finalization/migrations PARTIAL Regular custom files and other-target/dangling symlinks are handled. Same-target Chromium aliases still fail before ownership classification.
4. Chromium desktop customizations are overwritten FIXED Targeted token repair preserves arguments, actions and custom metadata, with backups and repeat/idempotence checks. Already-lost historical customization cannot be reconstructed.
5. Unseeded Chromium adds background sudo FIXED Root-scoped hardware setup provisions wrappers; user setup uses read-only readiness and safely skips unready wrappers without sudo.
6. Mapper overwrites the chosen microphone PARTIAL Stable USB/Bluetooth selections are preserved; a choice during the final graph query can still be overwritten.
7. Repeated mapping resets mic gain FIXED Asymmetric channel gains and mute survive repeat reconciliation and modeled daemon-loss restoration.
8. Restart Audio loses mapping FIXED in modeled lifecycle Supervised watcher and restart wiring recover from modeled daemon/DSP disappearance, query failure and link failure. Actual hardware/service lifecycle remains untested.
9. Mic migration hides mapper errors FIXED Real failures propagate with diagnostics. Explicit deferred status 75 is accepted intentionally with persisted service setup, rather than masking a live failure.
10. Customized WirePlumber policy is overwritten FIXED Absent policy is seeded; existing custom regular files and symlinks are preserved.

Additional existing-install repairs

  • 1Password direct-path desktop routing: FIXED in inert fixtures. The new migration reaches users with the old marker complete, repairs the effective desktop route without modifying the vendor file, preserves arguments/backups, and is idempotent. Fresh/repeat installation and second-user cases also pass.
  • Missing Snapper root after an old migration marker: FIXED through new migration 1788981069.sh. Old-marked users receive a new repair attempt; repeats and a second user's migration state do not recreate a healthy backend.
  • False readiness for a partial Snapper backend: FIXED. Registration, settings, non-symlink subvolume and successful listing are required. Partial/conflicting state is preserved and rejected; automatic reconstruction of arbitrary broken state is not implemented. Manual repair remains necessary, with migration completion withheld.
  • Preservation improvements: PASS. Custom root retention, additional configs, snapshots and global timeline scheduling survive the new Snapper setup fixtures.
  • The previously excluded recorder-startup audio-module cleanup limitation remains unchanged; it was not rerun or counted as a new regression here.

Targeted validation

Independent added checks PASS Failed invariants
Recorder identity and caller behavior 139 0
Audio endpoint, choice, gain, rollback and lifecycle 40 1
Electron, desktop, install and migration boundaries 46 4
Snapper backend, migration and service contracts 26 5
Total 251 10

These are 261 counted fixture checks/assertions, not full installations. The ten failures support five issues: four P2 findings and one P3. Supplied tests repeated by scoped reviewers overlap aggregate coverage and are not added again to this total. Seven additional native desktop-resolver cross-check observations matched expectations, including deliberately invalid-output controls.

One audio case initially hit a sandbox refusal to bind a dummy socket and passed its isolated retry; it is not a product failure. An initial Electron lifecycle harness omitted a fake filesystem parent and was excluded as invalid; the corrected fresh/repeat/second-user checks all passed. Raw logs and these adaptations were retained rather than presenting the initial attempts as product failures or silently discarding them.

Aggregate QA

Suite PASS files FAIL files SKIPPED files BLOCKED files Passing assertions Failing assertions
CLI 1 0 0 0 116 0
Shell 243 1 20 0 3,083 1
Mac 8 1 1 0 228 1
Total 252 2 21 0 3,427 2

No aggregate/file timeout occurred. All six changed/new supplied test files passed applicable checks. Parse-only checks passed for 1,037 Bash and eight Python files.

The aggregate is not entirely green:

  • The Mac piped-help failure matches the earlier baseline, in unchanged source.
  • The emoji fixture failed on head in the aggregate and a focused run; a focused original-base run passed. The fixture, command and relevant helpers are unchanged. Its removed delays around an asynchronous writer provide a plausible timing explanation, not an isolated causal proof. This is retained as an unresolved test failure, not established as an introduced product regression.
  • Safety/compositor/privileged skips remain documented. Private overlays redirected temporary paths and constrained external actions, so these are not unrestricted desktop/hardware suite results.

The earlier aggregate pacman and clipboard blockers were removed within the isolated QA setup: print-only native pacman resolution passed three assertions, and the clipboard suite passed 73 after exposing setpriv within the restriction. No host package installation occurred.

All eight settings staging combinations passed: current/stable source, settings/settings-dev, ARM/x86. These checks are already included in aggregate counts; stable-pin cases executed rather than being counted as skipped passes.

Hosted evidence and acceptance limits

All four checks were green when refreshed: syntax/shellcheck, test/all, tests/all, and ARM installation. See CI and ARM installation.

The CI merge commit 8738d9e has the same file tree as reviewed head 40c5c15. Its ARM log covers fresh setup and current-stack remediation/reinstallation, including system and user finalization on repeat. Selected versions remain hyprland 0.56.2-3, hyprtoolkit 0.5.4-5.1, and hyprland-guiutils 0.2.2-3.

That is not a real old-published-stack upgrade fixture. Companion omarchy-pkgs#341 was still open/unmerged at the pinned revision when revalidation completed.

NOT TESTED: physical Apple audio/DSP/hotplug, GPU/UI operation, native recorder signaling, real systemd lifecycle, suspend/resume, physical boot/upgrade/recovery, and actual snapshot restore. Earlier reported M2 checks were on the previous head, not this revision.

All generated fixtures, overlays, caches and logs used verified disk-backed storage. No source fixes, installed-system configuration changes, real host audio/service/boot operations or application launches were performed.

Next step: resolve the four P2 items from comment 1/2 and rerun those focused cases while retaining the passing preservation and lifecycle controls. Treat the P3 separately. Exact-package integration and physical acceptance remain distinct release gates, not claims established by hosted userspace success.

@scottjones

Copy link
Copy Markdown
Collaborator Author

Validation update at 02252ced1:

  • The four remaining P2 review findings and the TryExec P3 are addressed. Independent review and regression checks passed; all four hosted CI checks are green.
  • The matched local desktop/settings pair 4.0.2-202609092055, built with recipes 6d2729019 from Apple Silicon updates blocked by Aquamarine ABI mismatch #341, passed archive inspection and installed on Scott's M2.
  • Final-package reboot/login, Snapper cleanup activation, actual Restart Audio recovery, lid locking, s2idle suspend/resume and audible playback passed. No failed system/user units or pending migrations remained.
  • The Apple-only webcam renderer workaround passed three preview shutdowns and one full recording/stop test without another mpv core; the saved recording decoded correctly and contained the webcam overlay.

Ready for renewed review. #341 remains unmerged. These are local source-linked package tests; signed published-package upgrades, fresh encrypted installation, snapshot restore and canary qualification remain outstanding. Resume-time DCP and Wi-Fi/P2P warnings were recorded despite successful desktop/audio recovery.

@malik-na
malik-na requested review from malik-na and removed request for dhh and ryanrhughes September 10, 2026 03:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

5 participants