Repository navigation
Conversation
Adapt Marcelo runtime source d418ab7 (PRs 192, 199, 211, 217-220). Preserve candidate/channel separation and restore existing menu, defaults and UKIs on failed reactivation. Fresh-image integration remains separately gated.
Adapt Marcelo runtime source d418ab7, originating in PR 185. Authenticate owner-slot reuse, sync committed state, preserve firmware and refuse cross-kernel factory resets. Retain existing raw LUKS parent discovery.
Restore the exact prior EFI loader, GRUB targets, UKI, menu and hooks on failure. Install the mandatory deploy hook before committing activation, scope cleanup traps, and check required writes even when callers suppress errexit.
Back up the live boot files the Apple rebuild writes and restore them, with the reopened encrypt.state, when the reset fails before the root swap. Write the Boot-partition unlock key only after activation, so an interrupted reset never leaves the previous owner's system auto-unlocking.
…heck Read the ESP from ESP_PATH and derive the expected root subvolume from fstab, as omarchy-mx-mac does. Require the menu entry's hash to match the UKI and, where binutils is present, the UKI to carry the installed kernel. A fresh image's missing sync database warnings no longer count as altered files.
…resolved LUKS device, and parse every ESP_PATH form
update-m1n1 concatenates the device trees in the order its unquoted $DTBS glob expands, which follows the locale of whoever runs it; pacman's hook inherits the caller's. On the M2 Max boot.bin was written in en_US order and checks that rebuilt it in C order reported a mismatch. omarchy-mac-boot now ships /etc/default/update-m1n1 exporting LC_ALL=C, so every rebuild is the same image.
An image update-m1n1 wrote before the C locale was pinned carries the same device trees in its caller's collation, and the check only rebuilt C and session order. When the C rebuild differs, the check now reads the device trees from the image's flattened device tree headers, requires exactly the expected ones, each as often, rebuilds in that order and compares again.
#528 queues every hardware step of an image build for the machine's first boot. Mac first boot now runs omarchy-provision-hardware after creating the package keyring instead of sourcing the Limine activation leaf itself, and omarchy-provision-hardware.service waits for first boot. The fresh-image deferred-steps token stays only as the initrd's conversion gate.
omarchy-provision-hardware does nothing without #528's build manifest, so an image from a builder that does not write one would finish first boot with no hardware setup and Limine never activated. A fresh image (its deferred-steps token present) now needs /var/lib/omarchy/image/target, or target.booted once an earlier attempt retired it; a reset root has no token and is unaffected.
A platform first boot that runs omarchy-provision-hardware while the service's start job waits would otherwise turn that job into a failure at the next daemon-reload. With the unit kept, the emptied queue skips it.
Brings in #517 (already this branch's base), the platform detector (#514), CI (#518) and the other merged work. The Apple package list keeps omarchy-mac-boot beside the video-decode packages; the optional availability test takes quattro-upstream's omarchy-pkg-kernel-headers stub, since the menu no longer asks omarchy-mac-kernel.
The drop-in now also skips omarchy-provision-hardware.service while first boot is pending, so nothing runs the queue before this Mac's keyring exists. A failed step names both logs, and the tests check that the hand-off runs before owner setup is staged.
It read the host's /etc/machine-id, which CI's Arch container does not have, so the whole file failed there. The script's read now comes from a fixture.
The queue holds every hardware leaf, and some need the network, so a failed step on an offline first boot left the owner at the failure screen with no way to get online. The step now stays queued for omarchy-provision-hardware.service, which retries it after first boot and on later boots. A runtime without the command still stops first boot.
Also match the exact not-a-fresh-image message in the restored-queue case.
Brings in the password sync (#532), audio (#535), display (#533), Wi-Fi resume (#529) and battery charge limit (#525) work. omarchy-drive-password takes #532's version. It already carries what #503 added (no tracing, the new password over stdin), and it has no Apple branch. #503's drive-password-apple-test.sh asserted that the disk password never changes the login or root password, which ticket 19 replaced with a journaled LUKS-first sync for the system disk; drive-password-test.sh covers the shared behaviour, so the Apple copy goes.
…erface # Conflicts: # bin/omarchy-provision-owner # test/shell.d/luks-rekey-journal-test.sh
omarchy-mac-boot now ships provision-prepare, provision-commit and provision-verify in /usr/lib/omarchy/mac-boot, wrapping #503's provision module. Owner provisioning keeps only dispatch calls for the Mac boot chain: the Apple re-key folds into the shared journal, which keeps an acknowledged recovery slot, and the Apple-only recovery key stays a core policy. provision-prepare holds setup to the encryption install.conf asked for (an absent one means encrypt), the vendor firmware before the password prompt and the ESP the device tree names (omarchy-mac-esp, from omarchy-mx-mac).
A failed commit put rd.luks.key= back only when the same attempt had removed it, so an attempt killed after rewriting GRUB's defaults left a retry with the key on the boot partition but no command line naming it. Also drop a stale recovery slot from encrypt.state, refuse an encrypt.state without a phase, log the real reason provision-prepare refuses, and keep the password out of xtrace in rekey_accepts_password.
Brings in the runtime profile and composed package lists (#542), the platform mkinitcpio baseline (#536) and deferred first-boot setup (#528). The Apple package list is #542's with omarchy-mac-boot after omarchy-mac. The boot package's 90-94 drop-ins now sort after 00-omarchy-hooks.conf; a new test composes the real baseline with them on an Apple Silicon fixture: the encrypted systemd image gets asahi, omarchy-vendorfw, omarchy-mac-encrypt and sd-encrypt once, a non-Latin layout stays out, and a legacy busybox encrypt line is left as its owner set it up.
# Conflicts: # bin/omarchy-provision-owner # test/shell.d/luks-rekey-journal-test.sh
# Conflicts: # bin/omarchy-provision-owner
# Conflicts: # docs/file-layout.md
This was referenced Sep 25, 2026
Collaborator
Author
|
Superseded: #527, #540, #541 and #545 merged individually, and omarchy-mac-boot is now pinned to quattro-upstream (omacom/omarchy-pkgs#641, 20260925-3). Keeping the integ/boot-set-1 branch for provenance of the earlier 20260925-2 build. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose: pin
omarchy-mac-boot(omacom/omarchy-pkgs#637) to a commit that already holds the whole boot set, so the package is published before these PRs merge andquattro-upstreamnever depends on an unpublished package. Do not merge this PR; it exists so CI runs on the combined tree.Merges, in order, onto
quattro-upstream(1d24f65, with #546):mac/04-land-503(0b08030)mac/20-lifecycle-dispatch(df641c8)mac/32-apple-provision(df30957)mac/09-mac-boot-source(3a58abb)Not included: #543, #544.
Conflicts:
bin/omarchy-provision-ownerandtest/shell.d/luks-rekey-journal-test.sh(#540 into #527) resolved exactly as #545 resolved them;bin/omarchy-provision-owner(#545) takes #545's version, the only change on either side since that resolution;docs/file-layout.md(#541) keeps #546's platform-manifest text and #540's dispatch sentence and adds #541's Mac first-boot text.Tested:
packages/omarchy-mac/test/allandpackages/omarchy-mac/boot/test/allpass locally in an Arch container.