From c71cfabed6e1de1701d2d17d33ea9dd1edbf7c6a Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 9 Oct 2026 08:06:39 +1000 Subject: [PATCH] Re-pin omarchy-mac-boot to omarchy-mac-pkgs 162f3599e (#873) main now has omarchy-mac-pkgs#20: a factory reset's reboot unlocks the disk with a key from the Boot partition, and systemd could mount that partition again just before switching to the real root without unmounting it (systemd/systemd#28021), leaving /boot read-only so owner setup's re-key failed. An initramfs drop-in makes the unmount finish before the switch. It also has #18 (first-boot encryption progress on the splash) and test-only changes (#11, #19). New UTC commit date, so 20261008-1. omarchy-mac stays at 2a3ed89. --- pkgbuilds/omarchy-mac-boot/PKGBUILD | 8 ++++---- pkgbuilds/omarchy-mac-boot/README.md | 4 +++- 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index e02f026..87c4a46 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -7,8 +7,8 @@ pkgname=omarchy-mac-boot # pkgver is the UTC commit date of _commit, so it sorts above the fork's # 20260921-N. Reset pkgrel to 1 when pkgver changes; bump it to re-pin or # rebuild on the same day. -pkgver=20261004 -pkgrel=3 +pkgver=20261008 +pkgrel=1 pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' arch=('aarch64') groups=('omarchy-platform-apple-silicon') @@ -22,9 +22,9 @@ conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install # An exact omarchy-mac-pkgs main commit, never a branch. -_commit=6bd123a6790e33e0ccb7ab09ac4eee7815c9a95b +_commit=162f3599ee1144d7cf44b1ae12a7eb14ba758b8a source=("omarchy-mac-pkgs::git+https://github.com/omacom/omarchy-mac-pkgs.git#commit=${_commit}") -sha256sums=('6af86c533129815653377731516cf5411fdd4f40e217687a8113ae33fc42c19f') +sha256sums=('31be04e5cd902403997756660bb50494c7f7978f1de1192edad426b543c15e01') prepare() { # Tests and staging must not be able to read the other package's tree. diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index 6b422a6..7fa3cbd 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -33,6 +33,8 @@ A new pin publishes on merge, so check what the pinned source needs first. The r - It provides, conflicts with and replaces `omarchy-apple-boot` and `omarchy-first-boot`. The scriptlet moves a pending `omarchy-first-boot` marker to `omarchy-mac-first-boot`, drops the dangling enable links of the replaced unit and of the removed migration verifier, and points at a customised `90-omarchy-asahi.conf.pacsave`. - `pkgver` is the UTC commit date of the pin, so any pin from `20260925` on upgrades the fork's `20260921-10` on mx-mac Macs. The files the fork shipped that the source no longer does (the image finalize tools, the upstream ARM repository key and the GRUB snapshot-menu hook) are removed by that upgrade. - **Device tree overlays (omacom/omarchy-mac-pkgs#3).** Other packages may drop overlays into `/usr/lib/omarchy-mac-boot/dtb-overlays/`, which this package owns; `/etc/default/update-m1n1` applies them and the boot check rebuilds `boot.bin` the same way. With none installed, `boot.bin` is unchanged. A Mac with its own copy of `/etc/default/update-m1n1` keeps it (the shipped one lands as `.pacnew`), and then update-m1n1 applies no overlays until it is merged; from `20261004-3` (omacom/omarchy-mac-pkgs#10) the boot check leaves them out too, with a warning, instead of failing that Mac's `boot.bin` and stopping `omarchy update`. The overlay hook does not run in the transaction that first installs it. +- **Factory reset keeps `/boot` writable (`20261008-1`, omacom/omarchy-mac-pkgs#20).** A reset reboot unlocks the disk with a key from the Boot partition, and systemd could mount that partition again just before the switch to the real root without unmounting it (systemd/systemd#28021), so `/boot` came up read-only and owner setup's re-key failed. An initramfs drop-in makes the unmount finish before the switch. +- **First-boot encryption progress on the splash (`20261008-1`, omacom/omarchy-mac-pkgs#18).** - `backup=` covers every `/etc` file and `/usr/lib/omarchy/initcpio`. It includes `/etc/default/update-m1n1`, which pins update-m1n1's device-tree order to the C locale. On a Mac that already has its own unowned copy, pacman keeps it and installs the shipped one as `.pacnew`. The snapshot restore hooks in `/etc/boot/hooks` are symlinks to `/usr/bin/omarchy-mac-snapshot-check`, not files, so they stay out of it. ## Updates @@ -44,4 +46,4 @@ Updates are reviewed pins, never a branch: 3. Refresh `sha256sums` with `makepkg -g`. 4. Check the pin against [Publish order](#publish-order). `omarchy-mac` must be published at or past omacom/omarchy-mac#535, or re-pinned in the same pull request. -`20261004-3` sorts above edge's `20261004-2`, the first draft of that pin (`20261004-1`) and every lab candidate up to `20260928-3`. +`20261008-1` sorts above edge's `20261004-3` and every earlier pin and lab candidate.