Skip to content

Integration: boot set (#527, #540, #545, #541) — do not merge - #547

Closed
maralcbr wants to merge 75 commits into
quattro-upstreamfrom
integ/boot-set-1
Closed

maralcbr wants to merge 75 commits into
quattro-upstreamfrom
integ/boot-set-1

Conversation

@maralcbr

Copy link
Copy Markdown
Collaborator

Purpose: pin omarchy-mac-boot (omacom/omarchy-pkgs#637) to a commit that already holds the whole boot set, so the package is published before these PRs merge and quattro-upstream never depends on an unpublished package. Do not merge this PR; it exists so CI runs on the combined tree.

Merges, in order, onto quattro-upstream (1d24f65, with #546):

Not included: #543, #544.

Conflicts: bin/omarchy-provision-owner and test/shell.d/luks-rekey-journal-test.sh (#540 into #527) resolved exactly as #545 resolved them; bin/omarchy-provision-owner (#545) takes #545's version, the only change on either side since that resolution; docs/file-layout.md (#541) keeps #546's platform-manifest text and #540's dispatch sentence and adds #541's Mac first-boot text.

Tested: packages/omarchy-mac/test/all and packages/omarchy-mac/boot/test/all pass locally in an Arch container.

scottjones and others added 30 commits September 22, 2026 09:37
Adapt Marcelo runtime source d418ab7 (PRs 192, 199, 211, 217-220). Preserve candidate/channel separation and restore existing menu, defaults and UKIs on failed reactivation. Fresh-image integration remains separately gated.
Adapt Marcelo runtime source d418ab7, originating in PR 185. Authenticate owner-slot reuse, sync committed state, preserve firmware and refuse cross-kernel factory resets. Retain existing raw LUKS parent discovery.
Selectively adapt Marcelo PRs #208/#209 at 979ed03; retain the pinned #219 no-GRUB path. Preserve existing visuals and refresh an active Limine UKI through its coordinated updater.
Restore the exact prior EFI loader, GRUB targets, UKI, menu and hooks on failure. Install the mandatory deploy hook before committing activation, scope cleanup traps, and check required writes even when callers suppress errexit.
Back up the live boot files the Apple rebuild writes and restore them, with
the reopened encrypt.state, when the reset fails before the root swap. Write
the Boot-partition unlock key only after activation, so an interrupted reset
never leaves the previous owner's system auto-unlocking.
…heck

Read the ESP from ESP_PATH and derive the expected root subvolume from fstab,
as omarchy-mx-mac does. Require the menu entry's hash to match the UKI and,
where binutils is present, the UKI to carry the installed kernel. A fresh
image's missing sync database warnings no longer count as altered files.
…resolved LUKS device, and parse every ESP_PATH form
update-m1n1 concatenates the device trees in the order its unquoted $DTBS
glob expands, which follows the locale of whoever runs it; pacman's hook
inherits the caller's. On the M2 Max boot.bin was written in en_US order and
checks that rebuilt it in C order reported a mismatch. omarchy-mac-boot now
ships /etc/default/update-m1n1 exporting LC_ALL=C, so every rebuild is the
same image.
An image update-m1n1 wrote before the C locale was pinned carries the same
device trees in its caller's collation, and the check only rebuilt C and
session order. When the C rebuild differs, the check now reads the device
trees from the image's flattened device tree headers, requires exactly the
expected ones, each as often, rebuilds in that order and compares again.
#528 queues every hardware step of an image build for the machine's first
boot. Mac first boot now runs omarchy-provision-hardware after creating the
package keyring instead of sourcing the Limine activation leaf itself, and
omarchy-provision-hardware.service waits for first boot. The fresh-image
deferred-steps token stays only as the initrd's conversion gate.
omarchy-provision-hardware does nothing without #528's build manifest, so an
image from a builder that does not write one would finish first boot with no
hardware setup and Limine never activated. A fresh image (its deferred-steps
token present) now needs /var/lib/omarchy/image/target, or target.booted once
an earlier attempt retired it; a reset root has no token and is unaffected.
A platform first boot that runs omarchy-provision-hardware while the
service's start job waits would otherwise turn that job into a failure at
the next daemon-reload. With the unit kept, the emptied queue skips it.
Brings in #517 (already this branch's base), the platform detector (#514), CI
(#518) and the other merged work. The Apple package list keeps
omarchy-mac-boot beside the video-decode packages; the optional availability
test takes quattro-upstream's omarchy-pkg-kernel-headers stub, since the menu
no longer asks omarchy-mac-kernel.
The conversion gate reads only the first-boot marker and its token, never
the image hardware queue that @factory restores, and a reset now drops the
token from @factory and the next root.
The drop-in now also skips omarchy-provision-hardware.service while first
boot is pending, so nothing runs the queue before this Mac's keyring exists.
A failed step names both logs, and the tests check that the hand-off runs
before owner setup is staged.
It read the host's /etc/machine-id, which CI's Arch container does not have,
so the whole file failed there. The script's read now comes from a fixture.
The queue holds every hardware leaf, and some need the network, so a failed
step on an offline first boot left the owner at the failure screen with no
way to get online. The step now stays queued for
omarchy-provision-hardware.service, which retries it after first boot and on
later boots. A runtime without the command still stops first boot.
Also match the exact not-a-fresh-image message in the restored-queue case.
Brings in the password sync (#532), audio (#535), display (#533), Wi-Fi
resume (#529) and battery charge limit (#525) work.

omarchy-drive-password takes #532's version. It already carries what #503
added (no tracing, the new password over stdin), and it has no Apple branch.
#503's drive-password-apple-test.sh asserted that the disk password never
changes the login or root password, which ticket 19 replaced with a
journaled LUKS-first sync for the system disk; drive-password-test.sh covers
the shared behaviour, so the Apple copy goes.
…erface

# Conflicts:
#	bin/omarchy-provision-owner
#	test/shell.d/luks-rekey-journal-test.sh
omarchy-mac-boot now ships provision-prepare, provision-commit and
provision-verify in /usr/lib/omarchy/mac-boot, wrapping #503's provision
module. Owner provisioning keeps only dispatch calls for the Mac boot chain:
the Apple re-key folds into the shared journal, which keeps an acknowledged
recovery slot, and the Apple-only recovery key stays a core policy.

provision-prepare holds setup to the encryption install.conf asked for (an
absent one means encrypt), the vendor firmware before the password prompt
and the ESP the device tree names (omarchy-mac-esp, from omarchy-mx-mac).
A failed commit put rd.luks.key= back only when the same attempt had removed
it, so an attempt killed after rewriting GRUB's defaults left a retry with the
key on the boot partition but no command line naming it. Also drop a stale
recovery slot from encrypt.state, refuse an encrypt.state without a phase,
log the real reason provision-prepare refuses, and keep the password out of
xtrace in rekey_accepts_password.
Brings in the runtime profile and composed package lists (#542), the
platform mkinitcpio baseline (#536) and deferred first-boot setup (#528).

The Apple package list is #542's with omarchy-mac-boot after omarchy-mac.
The boot package's 90-94 drop-ins now sort after 00-omarchy-hooks.conf; a new
test composes the real baseline with them on an Apple Silicon fixture: the
encrypted systemd image gets asahi, omarchy-vendorfw, omarchy-mac-encrypt and
sd-encrypt once, a non-Latin layout stays out, and a legacy busybox encrypt
line is left as its owner set it up.
# Conflicts:
#	bin/omarchy-provision-owner
#	test/shell.d/luks-rekey-journal-test.sh
# Conflicts:
#	bin/omarchy-provision-owner
@maralcbr

Copy link
Copy Markdown
Collaborator Author

Superseded: #527, #540, #541 and #545 merged individually, and omarchy-mac-boot is now pinned to quattro-upstream (omacom/omarchy-pkgs#641, 20260925-3). Keeping the integ/boot-set-1 branch for provenance of the earlier 20260925-2 build.

@maralcbr maralcbr closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants