Repository navigation
Migrate Macs from a verified download of omarchy-mac-boot, handing files over inside the transaction - #602
Merged
Conversation
…r inside its transaction omarchy-mac-migrate --payload DIR runs the engine, its adapters, helpers and target from an unpacked omarchy-mac-boot that only root can write, and preflight defers unless the transaction installs that same version. A planned removal that shares files with what stays installed stops the migration at prefetch, before anything changes, since pacman -R would delete them; omarchy-dev leaves through omarchy's conflict instead, so its commands pass to omarchy-mac-boot with no --overwrite. Preflight refusals exit 75, which omarchy-migrate defers. omacom's own omarchy-dev on official trust has nothing to migrate. A converted Mac records the migrations a fresh image has done (x86 boot-chain repairs, the Intel Broadcom quirk, systemd-oomd, the platform migration) and, from mx-mac, the ones the fork's runner settled as handled.
…al boot package It fetches omarchy-mac-boot from the Mac's channel on pkgs.omarchy.org, accepts it only with a signature by the pinned Omarchy packaging key, unpacks it into a root-only directory and runs its engine from there. Nothing runs until the published package ships a migration target; every reason to stop before a change exits 75. A channel other than the packaged one is kept in /etc/omarchy-mac/migration-target. --prime only fetches and unpacks.
maralcbr
changed the base branch from
mac/53-migrate-deferred
to
quattro-upstream
September 27, 2026 01:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket 53, owner decision 1: automatic delivery through
omarchy updateto Macs that have no officialomarchy-mac-boot. Stacked on #601 (the deferred result).Engine (
omarchy-mac-boot)omarchy-mac-migrate --payload DIRruns the engine, adapters, helper commands and packaged target from an unpackedomarchy-mac-bootthat is root's and writable by no one else (ancestors included). Preflight defers unless the transaction installs that same version.migrate-engine.sh:1066-1075path): a planned removal that shares files with what stays installed stops the migration at prefetch, before anything changes, and again before the post-transactionpacman -R, since-Rdeletes every file of the package it removes. On mx-mac,omarchy-devleaves inside the one transaction throughomarchy's conflict, so its five commands pass toomarchy-mac-bootwith no--overwrite.omarchy-dev(no fork updaters or records, no retired repo/key, no unsigned repo,[omarchy]on pkgs.omarchy.org): "nothing to migrate", exit 0. Beside retired trust it is a deferred refusal.handled(its.sh.skippedrecord says so) are recorded as done; the ones itskippedrun on the new packages. Everything else pending runs on the next update, as for any upgraded install.Runtime:
omarchy-mac-migrate-bootstrapfetchesomarchy-mac-bootfrom the Mac's channel on pkgs.omarchy.org, accepts it only with a signature by the pinned Omarchy key 40DFB630… (from omarchy-keyring, pacman's keyring or keys.openpgp.org), checks the repository's checksum, unpacks it into/var/lib/omarchy-mac/bootstrap/payload(root only) and runs its engine. Nothing runs until the published package ships a migration target; every stop before a change exits 75. A channel other than the packaged one is kept in/etc/omarchy-mac/migration-target(converted mx-mac Macs keep rc/edge). A migration in progress resumes with the download it started from, and with the installed package once the transaction ran.--primeonly fetches and unpacks (used by the final mx-mac release). The same script is vendored byte-identical into that release.Tests
packages/omarchy-mac/boot/test/mac-migrate-mx-test.sh: an mx-mac Mac withoutomarchy-mac-bootmigrating from the download (engine and adapter from the payload, the five commands change owner,omarchy-devremoved in the transaction, nothing overwritten, installed package finishes after reboot, download removed); no conflict ⇒ stops at prefetch with nothing changed; stale payload version ⇒ 75, nothing changed; group-writable payload refused; omacom dev channel ⇒ nothing to migrate, with a fork key ⇒ 75; settled-migrations table. Fixture pacman now records files on--dbonlyas pacman does. Refusal expectations move from 2 to 75.test/shell.d/mac-migrate-bootstrap-test.sh: file:// repositories and a throwaway key: other platform, no repo/package/target ⇒ 75, wrong signer or checksum ⇒ never unpacked, packaged target, keyring from omarchy.gpg, engine status passed through, kept channel, prime/reuse/refresh, resume before and after the transaction, admin candidate-set target left alone.shared_files: one-Sofomarchy+omarchy-mac-bootoveromarchy-devremoves it in that transaction and hands the five commands over with no--overwrite;--dbonlyrecords the new file lists; without the conflict the rehearsal keepsomarchy-dev, the guard names the five commands and the real transaction refuses them; with--overwrite,pacman -R omarchy-devdeletes them (why the guard exists). 10/10.test/alland runtimetest/allin an Arch container: only the files in.github/known-test-failuresfail. CI does not run on stacked PRs; it will once this is retargeted.Second review: no trust hole found in the payload or the bootstrap; fixed what it verified: failures before the journal now defer instead of failing the update, curl gets
--max-timeand--proto-redir, the download is dropped when a payload-run migration finishes, resume prefers the installed package after the transaction, 1784476564 joins the table. Left as risks:omarchy.dbitself is unsigned (only the package signature is pinned), and a post-transaction shared-file refusal needs a handpacman -R.Release order: merge #601, this, then #603; re-pin
omarchy-mac-bootin omarchy-pkgs from a commit with this PR before (or with) #603's target.