Skip to content

Land #503 with the review fixes and the gap-audit merge blockers - #527

Merged
maralcbr merged 46 commits into
quattro-upstreamfrom
mac/04-land-503
Sep 25, 2026
Merged

maralcbr merged 46 commits into
quattro-upstreamfrom
mac/04-land-503

Conversation

@maralcbr

@maralcbr maralcbr commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Ticket 04 of the Apple Silicon convergence plan: land #503 on quattro-upstream.

This carries Scott Jones's draft #503 (encryption, Limine and the omarchy-mac-boot subtree) with my review fixes (fix/pr503-review-findings, now pushed), merged unchanged on top of #517's generic re-key journal. #503 itself is untouched; the changes below sit on top of it. Thanks to Scott for the port.

Base is quattro-upstream (#517 is merged). quattro-upstream is merged in (merge commits only, since #538, #541 and #544 build on this branch). Conflicts resolved:

What changed on top of #503

Gap-audit blockers (#513, "Must fix before #503 merges")

  1. Push and fold in the review fixes: done.
  2. Port mx fix: keep optional recorder failures nonfatal #248 into the GRUB console leaf: done. The repair migration for Macs that already ran the old leaf, and the boot check's busybox acceptance, stay with tickets 35/43/45 as the ledger says.
  3. Move the boot payload into this repository at mx's current revision: done. The recipe (ticket 09) keeps only metadata, backup= and the pacman scriptlet.
  4. Make the omarchy-mac-boot dependency installable: added to install/omarchy-apple.packages. Don't publish a runtime with this change to testers before ticket 09 publishes the boot package.
  5. Merge criteria: this PR follows ticket 04's. The runtime suite, the boot package tests and these blockers gate the merge. Converge Apple installation with shared Omarchy and package boot support #503's complete candidate transaction and VM boots move to tickets 22 (signed candidate set) and 25 (first convergence install on the M2 Max). The M3 reinstall is out of scope for the convergence. This still needs Scott's agreement.
  6. Test the tree that merges: see below.

Testing

Latest tested revision 0b08030ae (after the merges), in an Arch Linux ARM container as a non-root user: ./test/all fails only in hermes-remove-test.sh and system-sleep-ownership-migration-test.sh, which are both on .github/known-test-failures (325 of 327 pass). The package and boot suites pass (49 and 94 checks). CI runs on the PR.

First tested revision 073e489b5, before the merges, in the same setup:

Not done: hardware. Qualification on the M2 Max and M1 Pro is tickets 25 and 26.

Second review: round one found that the HOOKS resolver rejected mkinitcpio's -- option terminator, which put the wait back on a busybox Mac. It is fixed. Round one also confirmed a license-staging fix I made during the review. Round two found no remaining issues.

Review notes (not blocking)

A later review found this PR safe to merge on its own, with two notes left for follow-up:

  • arm_reset_markers (factory reset) creates the Mac first-boot marker on every platform. On a non-Mac nothing reads it, so it is harmless.
  • Changing the disk password moves the owner's key slot, so owner_slot in encrypt.state goes stale and the boot check fails afterwards. This predates this PR; ticket 33 owns it.

scottjones and others added 30 commits September 22, 2026 09:37
Adapt Marcelo runtime source d418ab7 (PRs 192, 199, 211, 217-220). Preserve candidate/channel separation and restore existing menu, defaults and UKIs on failed reactivation. Fresh-image integration remains separately gated.
Adapt Marcelo runtime source d418ab7, originating in PR 185. Authenticate owner-slot reuse, sync committed state, preserve firmware and refuse cross-kernel factory resets. Retain existing raw LUKS parent discovery.
Selectively adapt Marcelo PRs #208/#209 at 979ed03; retain the pinned #219 no-GRUB path. Preserve existing visuals and refresh an active Limine UKI through its coordinated updater.
Restore the exact prior EFI loader, GRUB targets, UKI, menu and hooks on failure. Install the mandatory deploy hook before committing activation, scope cleanup traps, and check required writes even when callers suppress errexit.
Back up the live boot files the Apple rebuild writes and restore them, with
the reopened encrypt.state, when the reset fails before the root swap. Write
the Boot-partition unlock key only after activation, so an interrupted reset
never leaves the previous owner's system auto-unlocking.
…heck

Read the ESP from ESP_PATH and derive the expected root subvolume from fstab,
as omarchy-mx-mac does. Require the menu entry's hash to match the UKI and,
where binutils is present, the UKI to carry the installed kernel. A fresh
image's missing sync database warnings no longer count as altered files.
…resolved LUKS device, and parse every ESP_PATH form
Brings in #503 (integrate/quattro-encryption-limine) with the
owner's review fixes (fix/pr503-review-findings) on top of #517.

#503 adopts #517's journal: luks-recovery.sh drops its copies of luks_slot_for,
luks_dump_slots, rekey_state_get and rekey_state_put and keeps only the
recovery-passphrase and slot-reuse parts. Its rekey_state_put ran
install -d -m 700 on the provisioning directory, which would stop the new
user's setup reading the stashed Node tarball; #517's write leaves the mode
alone, and the Apple provisioning test now checks it.

The non-Apple re-key is #517's luks_rekey behind the Limine unlock callbacks,
replacing #503's rekey_luks_intel. Apple Silicon keeps #503's encrypt.state
re-key with the recovery slot until it moves behind the same callbacks.
Ports omarchy-mx-mac #248 (80a4c43) into the boot package. The leaf appended
rootflags=x-systemd.device-timeout=0 unconditionally, and #503 runs it from
install/hardware/all.sh on every Apple hardware setup. mkinitcpio's busybox
init keeps only the last rootflags=, so on a Mac that unlocks with the encrypt
hook and cryptdevice= it replaced 10_linux's rootflags=subvol=@ and the Mac
stopped booting.

The wait now goes on only when the initramfs boots systemd, joining a
rootflags= the line already has, and comes off a busybox line.
omarchy-mac-initramfs-hooks resolves the HOOKS mkinitcpio builds the installed
kernel with (preset, -c/-A/-S options, mkinitcpio.conf and its drop-ins in
version order); a configuration it cannot read keeps the wait, as every image
boots systemd.

The repair migration for Macs that already ran the old leaf and the boot
check's busybox acceptance stay with the existing-install tickets.
The initramfs, in-place encryption and first-boot payload lived only in the
boot recipe paired with #503 (omarchy-mac/omarchy-pkgs-aarch64#65), so the
package could not be built from a pinned quattro-upstream commit. It moves to
packages/omarchy-mac/boot/files at its installed paths, and install DESTDIR
stages it with the commands, modules and license. The recipe keeps only
packaging metadata and the pacman scriptlet.

The payload is brought to omarchy-mac-boot 20260921-10 (maralcbr/omarchy-pkgs
#202): 94-omarchy-mac-vconsole.conf gives the disk passphrase prompt the
owner's keyboard layout, keeping non-Latin layouts out as upstream does;
92-omarchy-mac-hid.conf early-loads thunderbolt and thunderbolt_apple so a
dock keyboard types at the prompt; the ALPM hook rebuilds the initramfs when
the new drop-in changes.

The payload tests move with it and run offline in test/all; with
OMARCHY_DISPOSABLE_BOOT_TESTS=1 they also build real images and convert
loop-device disks in privileged containers. A staging test checks every
payload path, mode and symlink, and that the ALPM hook matches every shipped
drop-in.
Owner provisioning and factory reset now refuse to run on Apple Silicon
without the boot package, and the GRUB console and Limine leaves need it too,
so the Apple fresh-install inputs carry it next to omarchy-mac.
A recipe copies packages/omarchy-mac/boot and runs its install, so the staged
license must come from inside the subtree, as packages/omarchy-mac does.
A default_options with -- made the HOOKS resolver fail, so the GRUB console
leaf treated the initramfs as unknown and put the root-device wait back on a
busybox Mac.
Brings in #517 (already this branch's base), the platform detector (#514), CI
(#518) and the other merged work. The Apple package list keeps
omarchy-mac-boot beside the video-decode packages; the optional availability
test takes quattro-upstream's omarchy-pkg-kernel-headers stub, since the menu
no longer asks omarchy-mac-kernel.
It read the host's /etc/machine-id, which CI's Arch container does not have,
so the whole file failed there. The script's read now comes from a fixture.
Brings in the password sync (#532), audio (#535), display (#533), Wi-Fi
resume (#529) and battery charge limit (#525) work.

omarchy-drive-password takes #532's version. It already carries what #503
added (no tracing, the new password over stdin), and it has no Apple branch.
#503's drive-password-apple-test.sh asserted that the disk password never
changes the login or root password, which ticket 19 replaced with a
journaled LUKS-first sync for the system disk; drive-password-test.sh covers
the shared behaviour, so the Apple copy goes.
Brings in the runtime profile and composed package lists (#542), the
platform mkinitcpio baseline (#536) and deferred first-boot setup (#528).

The Apple package list is #542's with omarchy-mac-boot after omarchy-mac.
The boot package's 90-94 drop-ins now sort after 00-omarchy-hooks.conf; a new
test composes the real baseline with them on an Apple Silicon fixture: the
encrypted systemd image gets asahi, omarchy-vendorfw, omarchy-mac-encrypt and
sd-encrypt once, a non-Latin layout stays out, and a legacy busybox encrypt
line is left as its owner set it up.
@maralcbr
maralcbr merged commit 418159a into quattro-upstream Sep 25, 2026
5 checks passed
maralcbr added a commit that referenced this pull request Sep 25, 2026
maralcbr added a commit that referenced this pull request Sep 25, 2026
Keep #527's direct Apple re-key until omarchy-mac-boot ships its dispatch
entrypoints: the provisioning and boot-rebuild operations stay optional on
Apple until tickets 32, 35 and 36 make them required.
maralcbr added a commit that referenced this pull request Sep 25, 2026
…sion

#540 landed with the provisioning operations optional on Apple, so owner
setup kept #527's direct Apple re-key until omarchy-mac-boot shipped its
entrypoints. This branch removes that direct path, so an optional operation
would now send a Mac to the generic Limine path, which leaves the
boot-partition key and rd.luks.key= behind. omarchy-mac-boot 20260925-2 ships
the entrypoints, so provision-prepare, -commit and -verify are required again,
as the contract planned for this ticket: a Mac with an older package stops
before the owner form naming it. boot-rebuild stays optional until tickets 35
and 36 ship it.
maralcbr added a commit that referenced this pull request Sep 25, 2026
…t-rebuild

The stale-entry refresh test only ran against a fake boot-rebuild the real
package does not ship. Also make the old-package case look like #527's
package, and correct the contract's boot-rebuild row.
maralcbr added a commit that referenced this pull request Sep 25, 2026
Apple Silicon test candidate set pinned to #527, with its signing tool
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants