diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index 65ea8a6..13b321d 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -7,8 +7,8 @@ pkgname=omarchy-mac-boot # pkgver is the UTC commit date of _commit, so it sorts above the fork's # 20260921-N. Reset pkgrel to 1 when pkgver changes; bump it to re-pin or # rebuild on the same day. -pkgver=20260925 -pkgrel=4 +pkgver=20260927 +pkgrel=1 pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' arch=('aarch64') groups=('omarchy-platform-apple-silicon') @@ -20,20 +20,23 @@ conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install # An exact omarchy-mac commit, never a branch. -_commit=84352fdb8fd03d149682ac54466b1a1add176f84 +_commit=ff7ce0d4dfaea9e17270b3061e642ee095b7b265 source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('06514d03eef7e8468277ae97c3258bc595f307aa0cf3356d3f71cfb6b0d14fe2') +sha256sums=('7530c284cd323d451540205c0a677c4e187070f0b8c4081a2e85f487f2ebb985') prepare() { - # Tests and staging must not be able to read the surrounding desktop source. + # Staging must not be able to read the surrounding desktop source. rm -rf "$srcdir/boot" cp -a "$srcdir/omarchy-mac/packages/omarchy-mac/boot" "$srcdir/boot" [[ $(git -C "$srcdir/omarchy-mac" rev-parse HEAD) == "$_commit" ]] [[ $(TZ=UTC0 git -C "$srcdir/omarchy-mac" show -s --format=%cd --date=format-local:%Y%m%d HEAD) == "$pkgver" ]] } +# The tests run in the checkout: some compare the payload with the desktop +# source around it (the HOOKS baseline in etc/, the first-run user units and the +# default package lists, from omacom/omarchy-mac#582 and #598). check() { - "$srcdir/boot/test/all" + "$srcdir/omarchy-mac/packages/omarchy-mac/boot/test/all" } package() { diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index 269b37d..5b5340e 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -1,6 +1,6 @@ # omarchy-mac-boot -Apple Silicon boot support for Omarchy: the Mac mkinitcpio drop-ins and initcpio hooks, in-place LUKS conversion in the initramfs, vendor firmware in early boot, first boot of a Mac image, the Limine activation gate and the boot check. The source is `packages/omarchy-mac/boot/` in omacom/omarchy-mac, with its own tests. The recipe pins an exact omarchy-mac commit, copies that directory away from the surrounding desktop tree in `prepare()`, runs its `test/all` in `check()` and stages the package with its `install` script. The recipe itself holds only metadata, `backup=` and the pacman scriptlet. +Apple Silicon boot support for Omarchy: the Mac mkinitcpio drop-ins and initcpio hooks, in-place LUKS conversion in the initramfs, vendor firmware in early boot, first boot of a Mac image, the Limine activation gate and the boot check. The source is `packages/omarchy-mac/boot/` in omacom/omarchy-mac, with its own tests. The recipe pins an exact omarchy-mac commit, copies that directory away from the surrounding desktop tree in `prepare()` and stages the package from the copy with its `install` script. `check()` runs its `test/all` in the full checkout instead, because some tests compare the payload with the desktop source around it (omacom/omarchy-mac#582 and #598). The recipe itself holds only metadata, `backup=` and the pacman scriptlet. It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds/omarchy-mac-boot` at 20260921-10), which carried the payload as files in the recipe. @@ -21,6 +21,8 @@ A new pin publishes on merge, so check what the pinned source needs first: - **Settings baseline.** A pin that includes omacom/omarchy-mac#544 (no `93-omarchy-mac-plymouth.conf`) needs omarchy-settings with the HOOKS baseline (omacom/omarchy-mac#542) published on aarch64, and providing `omarchy-mkinitcpio-hooks-baseline`. Publish that first; otherwise this build cannot be installed. - **Update verification.** A pin that includes omacom/omarchy-mac#543 (`/usr/lib/omarchy/mac-boot/update-verify`) must publish before any runtime that carries #543. Otherwise that runtime blocks every update on Macs whose `omarchy-mac-boot` predates it. - **Reset and key-slot entrypoints.** A pin that includes omacom/omarchy-mac#552 (`reset-prepare`, `reset-verify`, `reset-commit`, `reset-rollback`) and #553 (`luks-slots`) must publish before any runtime that carries them. That runtime's `omarchy-lifecycle-dispatch` requires them on Apple Silicon, so otherwise factory reset, owner setup and `omarchy-drive-password` on the system disk fail on Macs whose `omarchy-mac-boot` predates them. +- **Reset first-boot markers.** A pin that includes omacom/omarchy-mac#579 (`reset-prepare` clears the factory root's first-boot state and arms `mac-first-boot/pending`) must publish before any runtime that carries #579's `omarchy-system-factory-reset`, which no longer does that inline. Otherwise a factory reset on a Mac whose `omarchy-mac-boot` predates it leaves the factory root without the Mac's first boot, and so without its package keyring, or with an older image's conversion token. A newer boot package with an older runtime is safe: the steps are idempotent. +- **Speaker safety owner.** A pin that includes omacom/omarchy-mac#567 no longer presets or enables `speakersafetyd`; `omarchy-mac` owns it from omacom/omarchy-mac#535. Re-pin `omarchy-mac` at or past #535 in the same merge as that pin, or publish it first. Edge `omarchy-mac` 0.1.0-5 (b4a79d83d) predates #535 and ships no preset for it, so with only the boot package re-pinned a `systemctl preset-all` on an edge Mac disables the speaker amps' safety daemon, and an image built from edge fails its image check. ## Transition @@ -35,3 +37,4 @@ Updates are reviewed pins, never a branch: 1. Set `_commit` to the full omarchy-mac SHA and `pkgver` to its UTC commit date (`TZ=UTC0 git show -s --format=%cd --date=format-local:%Y%m%d `); `prepare()` checks both. 2. Reset `pkgrel` to 1 when `pkgver` changes; bump it for a second pin on the same date or a rebuild. 3. Refresh `sha256sums` with `makepkg -g`. +4. Check the pin against [Publish order](#publish-order). Before the first pin that includes omacom/omarchy-mac#567 publishes, `omarchy-mac` must be published at or past #535, or re-pinned in the same pull request. diff --git a/pkgbuilds/omarchy-mac/PKGBUILD b/pkgbuilds/omarchy-mac/PKGBUILD index ec9b5e4..61d84fa 100644 --- a/pkgbuilds/omarchy-mac/PKGBUILD +++ b/pkgbuilds/omarchy-mac/PKGBUILD @@ -5,17 +5,18 @@ pkgname=omarchy-mac # pkgver matches packages/omarchy-mac/version at _commit. Bump pkgrel to re-pin # or rebuild the same add-on version; reset it to 1 when pkgver increases. pkgver=0.1.0 -pkgrel=5 +pkgrel=6 pkgdesc='Apple Silicon configuration and support services for Omarchy' arch=('aarch64') +groups=('omarchy-platform-apple-silicon') url='https://github.com/omacom/omarchy-mac' license=('MIT') makedepends=('git' 'findutils') checkdepends=('diffutils' 'python' 'systemd') # An exact quattro-upstream commit, never a branch. -_commit=b4a79d83d1144c4de90b29a2d8b4090090d7a9d8 +_commit=ff7ce0d4dfaea9e17270b3061e642ee095b7b265 source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('93676ce29791a29efe3b098fd8d129fa2248cd32d04253d9520a5b4c0697be6f') +sha256sums=('7530c284cd323d451540205c0a677c4e187070f0b8c4081a2e85f487f2ebb985') prepare() { # Tests and staging must not be able to read the surrounding desktop source. @@ -33,7 +34,8 @@ package() { # Runtime-only: the builder does not need the Omarchy desktop to stage or # test the add-on. depends=('omarchy' 'bash' 'coreutils' 'diffutils' 'grep' 'sed' 'gawk' 'systemd' 'pciutils' 'kmod' - 'networkmanager' 'iwd' 'python' 'pipewire' 'pipewire-pulse' 'libpulse' 'wireplumber') + 'mkinitcpio' 'networkmanager' 'iwd' 'python' 'pipewire' 'pipewire-pulse' 'libpulse' 'wireplumber' + 'asahi-audio' 'alsa-ucm-conf-asahi' 'rtkit' 'pipewire-alsa') "$srcdir/addon/install" "$pkgdir" install -Dm644 "$srcdir/addon/README.md" "$pkgdir/usr/share/doc/$pkgname/README.md"