Repository navigation
Land #503 with the review fixes and the gap-audit merge blockers - #527
Merged
Merged
Conversation
Adapt Marcelo runtime source d418ab7 (PRs 192, 199, 211, 217-220). Preserve candidate/channel separation and restore existing menu, defaults and UKIs on failed reactivation. Fresh-image integration remains separately gated.
Adapt Marcelo runtime source d418ab7, originating in PR 185. Authenticate owner-slot reuse, sync committed state, preserve firmware and refuse cross-kernel factory resets. Retain existing raw LUKS parent discovery.
Restore the exact prior EFI loader, GRUB targets, UKI, menu and hooks on failure. Install the mandatory deploy hook before committing activation, scope cleanup traps, and check required writes even when callers suppress errexit.
Back up the live boot files the Apple rebuild writes and restore them, with the reopened encrypt.state, when the reset fails before the root swap. Write the Boot-partition unlock key only after activation, so an interrupted reset never leaves the previous owner's system auto-unlocking.
…heck Read the ESP from ESP_PATH and derive the expected root subvolume from fstab, as omarchy-mx-mac does. Require the menu entry's hash to match the UKI and, where binutils is present, the UKI to carry the installed kernel. A fresh image's missing sync database warnings no longer count as altered files.
…resolved LUKS device, and parse every ESP_PATH form
Brings in #503 (integrate/quattro-encryption-limine) with the owner's review fixes (fix/pr503-review-findings) on top of #517. #503 adopts #517's journal: luks-recovery.sh drops its copies of luks_slot_for, luks_dump_slots, rekey_state_get and rekey_state_put and keeps only the recovery-passphrase and slot-reuse parts. Its rekey_state_put ran install -d -m 700 on the provisioning directory, which would stop the new user's setup reading the stashed Node tarball; #517's write leaves the mode alone, and the Apple provisioning test now checks it. The non-Apple re-key is #517's luks_rekey behind the Limine unlock callbacks, replacing #503's rekey_luks_intel. Apple Silicon keeps #503's encrypt.state re-key with the recovery slot until it moves behind the same callbacks.
Ports omarchy-mx-mac #248 (80a4c43) into the boot package. The leaf appended rootflags=x-systemd.device-timeout=0 unconditionally, and #503 runs it from install/hardware/all.sh on every Apple hardware setup. mkinitcpio's busybox init keeps only the last rootflags=, so on a Mac that unlocks with the encrypt hook and cryptdevice= it replaced 10_linux's rootflags=subvol=@ and the Mac stopped booting. The wait now goes on only when the initramfs boots systemd, joining a rootflags= the line already has, and comes off a busybox line. omarchy-mac-initramfs-hooks resolves the HOOKS mkinitcpio builds the installed kernel with (preset, -c/-A/-S options, mkinitcpio.conf and its drop-ins in version order); a configuration it cannot read keeps the wait, as every image boots systemd. The repair migration for Macs that already ran the old leaf and the boot check's busybox acceptance stay with the existing-install tickets.
The initramfs, in-place encryption and first-boot payload lived only in the boot recipe paired with #503 (omarchy-mac/omarchy-pkgs-aarch64#65), so the package could not be built from a pinned quattro-upstream commit. It moves to packages/omarchy-mac/boot/files at its installed paths, and install DESTDIR stages it with the commands, modules and license. The recipe keeps only packaging metadata and the pacman scriptlet. The payload is brought to omarchy-mac-boot 20260921-10 (maralcbr/omarchy-pkgs #202): 94-omarchy-mac-vconsole.conf gives the disk passphrase prompt the owner's keyboard layout, keeping non-Latin layouts out as upstream does; 92-omarchy-mac-hid.conf early-loads thunderbolt and thunderbolt_apple so a dock keyboard types at the prompt; the ALPM hook rebuilds the initramfs when the new drop-in changes. The payload tests move with it and run offline in test/all; with OMARCHY_DISPOSABLE_BOOT_TESTS=1 they also build real images and convert loop-device disks in privileged containers. A staging test checks every payload path, mode and symlink, and that the ALPM hook matches every shipped drop-in.
Owner provisioning and factory reset now refuse to run on Apple Silicon without the boot package, and the GRUB console and Limine leaves need it too, so the Apple fresh-install inputs carry it next to omarchy-mac.
A recipe copies packages/omarchy-mac/boot and runs its install, so the staged license must come from inside the subtree, as packages/omarchy-mac does.
A default_options with -- made the HOOKS resolver fail, so the GRUB console leaf treated the initramfs as unknown and put the root-device wait back on a busybox Mac.
This was referenced Sep 25, 2026
maralcbr
changed the base branch from
mac/18-generic-luks
to
quattro-upstream
September 25, 2026 10:21
Brings in #517 (already this branch's base), the platform detector (#514), CI (#518) and the other merged work. The Apple package list keeps omarchy-mac-boot beside the video-decode packages; the optional availability test takes quattro-upstream's omarchy-pkg-kernel-headers stub, since the menu no longer asks omarchy-mac-kernel.
It read the host's /etc/machine-id, which CI's Arch container does not have, so the whole file failed there. The script's read now comes from a fixture.
Brings in the password sync (#532), audio (#535), display (#533), Wi-Fi resume (#529) and battery charge limit (#525) work. omarchy-drive-password takes #532's version. It already carries what #503 added (no tracing, the new password over stdin), and it has no Apple branch. #503's drive-password-apple-test.sh asserted that the disk password never changes the login or root password, which ticket 19 replaced with a journaled LUKS-first sync for the system disk; drive-password-test.sh covers the shared behaviour, so the Apple copy goes.
This was referenced Sep 25, 2026
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
Brings in the runtime profile and composed package lists (#542), the platform mkinitcpio baseline (#536) and deferred first-boot setup (#528). The Apple package list is #542's with omarchy-mac-boot after omarchy-mac. The boot package's 90-94 drop-ins now sort after 00-omarchy-hooks.conf; a new test composes the real baseline with them on an Apple Silicon fixture: the encrypted systemd image gets asahi, omarchy-vendorfw, omarchy-mac-encrypt and sd-encrypt once, a non-Latin layout stays out, and a legacy busybox encrypt line is left as its owner set it up.
This was referenced Sep 25, 2026
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
Keep #527's direct Apple re-key until omarchy-mac-boot ships its dispatch entrypoints: the provisioning and boot-rebuild operations stay optional on Apple until tickets 32, 35 and 36 make them required.
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
…sion #540 landed with the provisioning operations optional on Apple, so owner setup kept #527's direct Apple re-key until omarchy-mac-boot shipped its entrypoints. This branch removes that direct path, so an optional operation would now send a Mac to the generic Limine path, which leaves the boot-partition key and rd.luks.key= behind. omarchy-mac-boot 20260925-2 ships the entrypoints, so provision-prepare, -commit and -verify are required again, as the contract planned for this ticket: a Mac with an older package stops before the owner form naming it. boot-rebuild stays optional until tickets 35 and 36 ship it.
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
…t-rebuild The stale-entry refresh test only ran against a fake boot-rebuild the real package does not ship. Also make the old-package case look like #527's package, and correct the contract's boot-rebuild row.
maralcbr
added a commit
that referenced
this pull request
Sep 25, 2026
Apple Silicon test candidate set pinned to #527, with its signing tool
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket 04 of the Apple Silicon convergence plan: land #503 on
quattro-upstream.This carries Scott Jones's draft #503 (encryption, Limine and the
omarchy-mac-bootsubtree) with my review fixes (fix/pr503-review-findings, now pushed), merged unchanged on top of #517's generic re-key journal. #503 itself is untouched; the changes below sit on top of it. Thanks to Scott for the port.Base is
quattro-upstream(#517 is merged).quattro-upstreamis merged in (merge commits only, since #538, #541 and #544 build on this branch). Conflicts resolved:install/omarchy-apple.packagesis Runtime settings profile and platform package lists #542's composed list withomarchy-mac-bootafteromarchy-mac.omarchy-drive-passwordtakes Change the root LUKS key before syncing login and root passwords #532's journaled version. It already carries Converge Apple installation with shared Omarchy and package boot support #503's additions. Converge Apple installation with shared Omarchy and package boot support #503'sdrive-password-apple-test.shasserted that the disk password never changes the account passwords, which ticket 19 replaced, so it is removed.omarchy-pkg-kernel-headersstub.refresh-limine-test.shuses a fixture machine id, since CI's container has none.00-omarchy-hooks.conf. A new test (mac-boot-mkinitcpio-compose-test.sh) composes the real baseline with them on an Apple Silicon fixture.What changed on top of #503
luks-recovery.shdrops its copies of the slot and journal helpers and usesluks-rekey.sh, keeping only the recovery-passphrase and slot-reuse parts. The non-Apple re-key is Journal the first-boot LUKS re-key and retire the staged install key #517'sluks_rekey. Apple Silicon keeps Converge Apple installation with shared Omarchy and package boot support #503'sencrypt.statere-key with the recovery slot. Converge Apple installation with shared Omarchy and package boot support #503's journal write set the provisioning directory to mode 700, which would have stopped the new user's setup reading the Node tarball. That write is gone, and the Apple provisioning test now checks the mode.rootflags=, and comes off a busybox line. Before, the leaf appended a secondrootflags=on every Apple setup, and a busyboxencryptMac then lostrootflags=subvol=@and stopped booting. A newomarchy-mac-initramfs-hooksresolves the HOOKS mkinitcpio builds with (preset,-c/-A/-S, drop-ins in version order).omarchy-mac-bootbuilds from this source. The initramfs, conversion and first-boot payload moves from the paired recipe (Package coordinated Apple encryption, Limine and boot helpers omarchy-mac/omarchy-pkgs-aarch64#65) intopackages/omarchy-mac/boot/files, andinstall DESTDIRstages the whole package. It is at omarchy-mac-boot 20260921-10 (omarchy-mac-boot: keyboard layout and dock keyboards at the disk prompt maralcbr/omarchy-pkgs#202): the owner's keyboard layout at the disk passphrase prompt, with non-Latin layouts kept out as upstream does, and dock keyboards viathunderbolt/thunderbolt_apple. The payload tests move with it.omarchy-mac-booton the Apple package list. Owner setup and factory reset refuse to run on Apple Silicon without it.Gap-audit blockers (#513, "Must fix before #503 merges")
backup=and the pacman scriptlet.omarchy-mac-bootdependency installable: added toinstall/omarchy-apple.packages. Don't publish a runtime with this change to testers before ticket 09 publishes the boot package.Testing
Latest tested revision
0b08030ae(after the merges), in an Arch Linux ARM container as a non-root user:./test/allfails only inhermes-remove-test.shandsystem-sleep-ownership-migration-test.sh, which are both on.github/known-test-failures(325 of 327 pass). The package and boot suites pass (49 and 94 checks). CI runs on the PR.First tested revision
073e489b5, before the merges, in the same setup:./test/all: 308 of 310 files pass. The two failures also fail on the base (mac/18-generic-luks, 2 of 289):hermes-remove-test.sh, which is in Run the shell suites in CI for quattro-upstream #518's known failures, anddesktop-entry-launch-test.sh, which fails in an aarch64 container because the Steam launcher is missing. The 21 new files pass.system-sleep-ownership-migration-test.sh, which Run the shell suites in CI for quattro-upstream #518 lists as flaky, failed once in four runs.packages/omarchy-mac/test/allandpackages/omarchy-mac/boot/test/all: pass (17 and 94 checks).OMARCHY_DISPOSABLE_BOOT_TESTS=1, privileged containers): in-place LUKS conversion on loop devices (33 checks), and real initramfs builds with the HID/thunderbolt modules and the keyboard layout (Danish in, Russian out). All pass.makepkgof the boot subtree the way Screenshot Remap #65's recipe consumes it passes: copyboot/,check()runstest/all,package()runsinstall.rootflags=on a busybox line.run_provisioning.Not done: hardware. Qualification on the M2 Max and M1 Pro is tickets 25 and 26.
Second review: round one found that the HOOKS resolver rejected mkinitcpio's
--option terminator, which put the wait back on a busybox Mac. It is fixed. Round one also confirmed a license-staging fix I made during the review. Round two found no remaining issues.Review notes (not blocking)
A later review found this PR safe to merge on its own, with two notes left for follow-up:
arm_reset_markers(factory reset) creates the Mac first-boot marker on every platform. On a non-Mac nothing reads it, so it is harmless.owner_slotinencrypt.stategoes stale and the boot check fails afterwards. This predates this PR; ticket 33 owns it.