Skip to content

Move Macs onto Omarchy's official packages with a standalone omarchy-mac-migrate - #690

Open
maralcbr wants to merge 7 commits into
quattrofrom
mac/migrate-standalone
Open

maralcbr wants to merge 7 commits into
quattrofrom
mac/migrate-standalone

Conversation

@maralcbr

@maralcbr maralcbr commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Moving existing Macs onto Omarchy's official packages is now a standalone script, not part of any package (agreed with Ryan on 2026-10-04: the Mac packages move to omacom/omarchy-mac-pkgs without the migration engine; omacom#13362 uses them).

What it adds

Supersedes #603. The code of #601, #602 and #607 is the tool's source.

Tests

  • New fixture suites mac-migrate-test.sh (tester cohort, engine), mac-migrate-legacy-test.sh, mac-migrate-mx-test.sh and mac-move-migration-test.sh: 104 checks. They cover kill -9 after, during and in the middle of every step, deferral before the switch and failure after it, the guard, channel detection and qualification, and leftovers.
  • VM runs on the M1 (aarch64 KVM with the Mac image harness, on the encrypted test image apple-test-f22c43fb7903). The target was a test-lane-signed set: the Converge omarchy-mac and omarchy-mx-mac into upstream Omarchy omarchy#13362 (69d80cc) dev pair, plus omarchy-mac and omarchy-mac-boot from proposal/main without the engine. Everything else came from the real edge.
    • Stable: deferred (75) with the Mac byte-identical.
    • Today's edge: deferred. The dev pair has no dispatcher, and the boot package carries the old engine.
    • Test image → edge: passed.
    • mx-mac → edge: the guest ran the fork's omarchy-dev 4.0.4.r7099 bundle. The rc lane deferred unchanged. On the edge lane, the fork's pair went down to the official build in one transaction, with kills during prefetch and the boot-chain rebuild resumed.
    • Encrypted legacy → edge: the guest was set up as quattro's layout (GRUB, busybox encrypt from cryptdevice=, ESP at /boot, [omarchy-aarch64] lane). The ESP moved to /boot/efi, the unlock to sd-encrypt and the loader to Limine.
    • After each move, pacman.conf was the core configuration and the migrated disk unlocked with the same password through its own boot files and reached a login. The boot unit's verification correctly refused the guest's generic kernel; completion needs a Mac.
  • Two design debate rounds and two code review rounds; every verified finding is fixed (boundary event, lock contention, retired keys in preflight, NoExtract/NoUpgrade, guard scope, update-hook exit, payload tool trust, resume unit kept through user-setup retries, HOOKS preview). The VM runs used an earlier build (879faa65); the fixes after it are covered by the fixture suites.
  • Not done: real Mac hardware (the post-reboot verification needs the Aurora kernel). A power loss inside the pacman transaction itself is not recoverable by the tool, as for any pacman upgrade.

Release (owner): merge, publish bin/omarchy-mac-migrate as release mac-migrate-v1, and publish a quattro omarchy build to the [omarchy-aarch64] lanes so packaged quattro installs get it (checkout installs get it from git pull). Nothing moves until omarchy-mac-pkgs' packages and a dev pair with omacom#13362 are on edge.

…c packages

The migration engine leaves omarchy-mac-boot (omacom/omarchy-mac-pkgs drops it):
one self-contained script built from migrate/src, journaled and resumable, that
moves a quattro, mx-mac or test-image Mac onto its channel's official packages
(the omarchy-dev pair on edge) and the core Apple Silicon pacman configuration,
and defers while that channel has no Mac release.
A migration marks the Mac; the next omarchy update runs omarchy-mac-migrate
before any fork step and stops there for the reboot, or updates the Mac as
before while its channel has no Mac release. The README gives testers the
one-line command.
The boundary is recorded right before the switch's first write, so a reset or
a refusal before it still defers. A second run never touches the state of the
run holding the lock. Preflight trusts no retired key, refuses NoExtract or
NoUpgrade patterns and IgnorePkg globs that hold back what the move installs,
and checks a busybox-encrypted Mac keeps its unlock under the new drop-ins.
Fork leftovers the Mac packages no longer retire are retired here. The update
hook stops the fork update only after a move.
…tion

Preflight runs only regular files from the verified omarchy-mac-boot, never a
link, and refuses a boot package without them. Its HOOKS preview drops the
drop-ins of the packages the transaction replaces. A user setup that succeeds
on a retry no longer releases the unit while the migration is still under way,
and a migration past its switch resumes whatever a detector says.
pacman -Qlq of a package that is not installed fails, which under pipefail
made the preview fail and an encrypted legacy Mac defer for good. The fixture
pacman now fails the same way. The boot unit also resumes a migration past its
switch whatever a detector says.
It runs as root in an empty environment and across the move to another
runtime, so it cannot depend on the runtime's helpers.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant