Skip to content

Harden Apple Silicon provisioning and shared-ESP reinstalls - #19

Open
scottjones wants to merge 8 commits into
mainfrom
fix/image-provisioning
Open

scottjones wants to merge 8 commits into
mainfrom
fix/image-provisioning

Conversation

@scottjones

Copy link
Copy Markdown
Contributor

Summary

Checkpoint the accumulated Apple Silicon installer work through a successful fresh encrypted M3 (j613) install and subsequent reboot.

  • Build portable payload/ESP tester drops and sanitized validation reports; improve M3 USB, Bluetooth, LUKS growth, and installer timezone handling.
  • Keep per-root kernels and GRUB fragments, preserve existing ESP ownership, and restore the saved owner after NVMe installer placement. Do not replace Apple firmware or another OS's GRUB configuration.
  • Fix offline chroot provisioning order and command resolution, propagate failures, preserve installation diagnostics in @log, and finalize installed services correctly.
  • Include and preload test.mod in every standalone GRUB build. Refuse the recognized older owning loader that lacks it before partition creation/formatting; do not silently replace a preserved owner.
  • After an erased-root/free-space reinstall, transfer a confirmed-absent managed default to the new root and omit confirmed-absent canonical entries from the active menu. Keep present roots, locked LUKS roots, customized fragments, and uncertain discovery intact. Retain inactive files for recovery/reconnected disks.
  • Document artifact identity, historical failures, and final hardware evidence.

Verification

  • ./test/unit and whitespace checks pass.
  • Reinstall regression suite: 154 assertions pass for owned/piggyback ESPs, plain/encrypted roots, device-discovery failure, custom fragments, reconnects, and NVMe restoration. The same suite passes against the helper extracted from the freshly built payload. Removing default transfer or stale-menu filtering makes it fail.
  • Earlier disposable chroot/provisioning and btrfs log-preservation success/failure checks passed; these synthetic tests are not presented as hardware proof.
  • Full --usb --rootfs build completed at 2026-09-07T16:14:01Z: root filesystem, live/encrypted/plain initrds, and both GRUB loaders rebuilt. Packaged-source, hooks/modules/vermagic, hardware database, and GRUB-module checks passed.
  • Tested kernel: 7.2.2-omarchy-wip72+, source 236788cd2602a24c703fe7bdaddaf73ef77d2027; local desktop/settings packages 4.0.2-5, Snapper 0.13.1-3.
  • Transfer-volume tester drop verified and flushed. Manifest SHA-256: 5c2dedb1352968cee7422ae9182a82d90e383af7a8a980b801aba83087606e81.
  • Fresh encrypted M3 installation: provisioning and normal first boot succeeded; managed default/menu, preserved owning EFI, Snapper/factory snapshot, completed first-run marker, required services, installer-slice consumption, and root growth verified.
  • Tester subsequently confirmed another successful reboot after desktop updates, acceptable UI responsiveness, 1Password installation, and no repeated first-boot alerts. Those final observations are user-reported, not a second SSH audit.

Dependencies and limitations

  • Desktop companion: Harden Apple Silicon first login and snapshot setup omacom/omarchy-mac#372 (wrapper permissions, boot-layout migration guard, timezone notification, and Snapper setup).
  • Package companion: Fix ARM Snapper dependency and first-run keyboard service packaging omacom/omarchy-pkgs#341. The fresh image used these package fixes as well as the desktop companion; rebuilding with unfixed packages is not equivalent to the tested image.
  • An existing legacy GRUB owner required a separately authorized, backed-up repair before the fresh test. This PR detects that incompatibility but does not automatically migrate preserved owners.
  • This branch includes the earlier unmerged installer checkpoints, not just the final GRUB regression fix.
  • One M3 is validated, not every Apple Silicon model. The build recorded dirty source based on af06c22; source comparisons and artifact hashes identify the tested build without asserting byte-for-byte reproducibility.
  • No image binaries, raw hardware logs, or unrelated local experiments are included. See docs/provisioning-validation-20260907.md for the staged validation history.

Type-C stays in gadget mode without sn201202x in the initrds. BCM4388 OTP
asks for AMKOR firmware that vendorfw does not ship; alias the USI blob
on the root and rebind hci_bcm4377. Copy a real modules tree so dm-crypt
loads, keep the LUKS volume key out of the initrd keyring so consume can
grow without a passphrase, and leave timezone at UTC for the first-boot
toast (NTP is not ready in the live TUI).
Live install has no DNS: stub 1Password, optional-apps, and electron-gl
wrap off /tmp so provision-user does not curl or sudo; write the Chromium
wrapper as root after. usb-wait walks blkid/NVMe when udev has not made
by-uuid yet. Tight System ESPs drop unused NVMe live initrds before the
kernel copy. A leftover /EFI/omarchy/vmlinuz line is rewritten only when
its UUIDs are gone; a living second Omarchy root keeps that default.

USB builds write payload.img.zst for Drive/SHARE, bind-mount a side-loaded
modules tree for mkinitcpio, and drop linux-asahi.preset plus the pacman
mkinitcpio hooks so ISO-installed hosts do not rebuild a missing kernel.
Resolve stub paths inside the target, seed Chromium before user finalization, preserve @log output, and stop on provisioning errors. Restore installed services and guard shared ESP ownership.

Include regression rehearsals and validation of the full 7.2.2 image build. Fresh hardware installation remains in progress; this is not a release sign-off.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant