diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index 13b321d..5de9223 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -1,49 +1,50 @@ # Maintainer: Marcelo Alcantara # Recipe from maralcbr/omarchy-pkgs asahi-quattro pkgbuilds/omarchy-mac-boot # (20260921-10 at 0a55baeddecf59687c32b4bd4e1dee743605c183); the payload now -# builds from packages/omarchy-mac/boot in omacom/omarchy-mac. +# builds from omarchy-mac-boot/ in omacom/omarchy-mac-pkgs. pkgname=omarchy-mac-boot # pkgver is the UTC commit date of _commit, so it sorts above the fork's # 20260921-N. Reset pkgrel to 1 when pkgver changes; bump it to re-pin or # rebuild on the same day. -pkgver=20260927 +pkgver=20261004 pkgrel=1 pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' arch=('aarch64') groups=('omarchy-platform-apple-silicon') -url='https://github.com/omacom/omarchy-mac' +url='https://github.com/omacom/omarchy-mac-pkgs' license=('MIT') makedepends=('git') provides=('omarchy-apple-boot' 'omarchy-first-boot') conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install -# An exact omarchy-mac commit, never a branch. -_commit=ff7ce0d4dfaea9e17270b3061e642ee095b7b265 -source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('7530c284cd323d451540205c0a677c4e187070f0b8c4081a2e85f487f2ebb985') +# An exact omarchy-mac-pkgs main commit, never a branch. +_commit=43991059e17bb0ab7e0ecf0010aef1fa73c3e2c9 +source=("omarchy-mac-pkgs::git+https://github.com/omacom/omarchy-mac-pkgs.git#commit=${_commit}") +sha256sums=('654f54364a675ae9aa03728c49e5558121a7be70d60226cd8fdd4f901b195ee1') prepare() { - # Staging must not be able to read the surrounding desktop source. + # Tests and staging must not be able to read the other package's tree. rm -rf "$srcdir/boot" - cp -a "$srcdir/omarchy-mac/packages/omarchy-mac/boot" "$srcdir/boot" - [[ $(git -C "$srcdir/omarchy-mac" rev-parse HEAD) == "$_commit" ]] - [[ $(TZ=UTC0 git -C "$srcdir/omarchy-mac" show -s --format=%cd --date=format-local:%Y%m%d HEAD) == "$pkgver" ]] + cp -a "$srcdir/omarchy-mac-pkgs/omarchy-mac-boot" "$srcdir/boot" + [[ $(git -C "$srcdir/omarchy-mac-pkgs" rev-parse HEAD) == "$_commit" ]] + [[ $(TZ=UTC0 git -C "$srcdir/omarchy-mac-pkgs" show -s --format=%cd --date=format-local:%Y%m%d HEAD) == "$pkgver" ]] } -# The tests run in the checkout: some compare the payload with the desktop -# source around it (the HOOKS baseline in etc/, the first-run user units and the -# default package lists, from omacom/omarchy-mac#582 and #598). check() { - "$srcdir/omarchy-mac/packages/omarchy-mac/boot/test/all" + "$srcdir/boot/test/all" } package() { # Runtime-only, so the builder stages and tests the payload without the - # desktop or a boot chain. 1.39.0-2 is the first limine-mkinitcpio-hook that - # leaves a Mac's /boot to mkinitcpio until Limine is activated. + # desktop. 1.39.0-2 is the first limine-mkinitcpio-hook that leaves a Mac's + # /boot to mkinitcpio until Limine is activated. update-m1n1 builds stage 2 + # from m1n1 and U-Boot, so neither can be removed; m1n1 is the virtual name, + # leaving its provider (m1n1-aurora) to the image, as the kernel is. First + # boot populates the Asahi repository's keyring. depends=('omarchy' 'limine' 'limine-mkinitcpio-hook>=1.39.0-2' 'limine-snapper-sync' 'asahi-scripts' + 'm1n1' 'uboot-asahi' 'asahi-alarm-keyring' 'bash' 'binutils' 'btrfs-progs' 'coreutils' 'cpio' 'cryptsetup' 'diffutils' 'gawk' 'gnupg' 'grep' 'gum' 'gzip' 'kbd' 'mkinitcpio' 'sed' 'systemd' 'util-linux') diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index 5b5340e..71b3ad8 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -1,12 +1,12 @@ # omarchy-mac-boot -Apple Silicon boot support for Omarchy: the Mac mkinitcpio drop-ins and initcpio hooks, in-place LUKS conversion in the initramfs, vendor firmware in early boot, first boot of a Mac image, the Limine activation gate and the boot check. The source is `packages/omarchy-mac/boot/` in omacom/omarchy-mac, with its own tests. The recipe pins an exact omarchy-mac commit, copies that directory away from the surrounding desktop tree in `prepare()` and stages the package from the copy with its `install` script. `check()` runs its `test/all` in the full checkout instead, because some tests compare the payload with the desktop source around it (omacom/omarchy-mac#582 and #598). The recipe itself holds only metadata, `backup=` and the pacman scriptlet. +Apple Silicon boot support for Omarchy: the Mac mkinitcpio drop-ins and initcpio hooks, in-place LUKS conversion in the initramfs, vendor firmware in early boot, first boot of a Mac image, the Limine activation gate and the boot check. The source is `omarchy-mac-boot/` in [omacom/omarchy-mac-pkgs](https://github.com/omacom/omarchy-mac-pkgs), with its own tests. The recipe pins an exact `main` commit, copies that directory away from the rest of the checkout in `prepare()`, runs its `test/all` from the copy in `check()` and stages the package from the copy with its `install` script. The recipe itself holds only metadata, `backup=` and the pacman scriptlet. -It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds/omarchy-mac-boot` at 20260921-10), which carried the payload as files in the recipe. +It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds/omarchy-mac-boot` at 20260921-10), which carried the payload as files in the recipe. Up to 20260927-1 it built from `packages/omarchy-mac/boot/` in omacom/omarchy-mac. ## Scope -The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It carries the Apple platform tag, `groups=('omarchy-platform-apple-silicon')`, which omarchy-settings' pacman platform guard uses to keep it off other machines once that guard ships (omacom/omarchy-mac#539, `docs/platform-guard.md`). Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It carries the Apple platform tag, `groups=('omarchy-platform-apple-silicon')`, which omarchy-settings' pacman platform guard uses to keep it off other machines once that guard ships (omacom/omarchy-mac#539, `docs/platform-guard.md`). Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its Apple-only dependencies come from the asahi-alarm repository that only the Apple profile configures: `asahi-scripts`; `m1n1` (the virtual name, leaving its provider `m1n1-aurora` to the image, as the kernel is) and `uboot-asahi`, which update-m1n1 builds stage 2 from; and `asahi-alarm-keyring`, which first boot populates. It requires `limine-mkinitcpio-hook` 1.39.0-2 or newer: that is the first build whose hooks leave a Mac's `/boot` to mkinitcpio until Limine is activated. With an older hook, Limine's kernel hook replaces mkinitcpio's by name, and this package's `limine-ready` gate stops it on a Mac that still boots GRUB, so a kernel update would never reach `/boot`. @@ -16,7 +16,9 @@ From the source that drops the boot package's own Plymouth fragment (omacom/omar ## Publish order -A new pin publishes on merge, so check what the pinned source needs first: +A new pin publishes on merge, so check what the pinned source needs first. The rules name omacom/omarchy-mac pull requests; omacom/omarchy-mac-pkgs keeps their history, and every pin from it includes all of them. + +- **Runtime.** Publish with or before the runtime that needs it. The runtime from omacom/omarchy#13362 requires `setup-boot` (omacom/omarchy-mac#635) and `update-takeover` (#636) through `omarchy-lifecycle-dispatch`, calls `luks-slots --owner` (#659) before any drive password change, and no longer adds a recovery key, which the boot check accepts only from #657 on. With an older boot package, hardware setup, updates that take over unowned files, drive password changes and the boot check fail on Apple Silicon. - **Settings baseline.** A pin that includes omacom/omarchy-mac#544 (no `93-omarchy-mac-plymouth.conf`) needs omarchy-settings with the HOOKS baseline (omacom/omarchy-mac#542) published on aarch64, and providing `omarchy-mkinitcpio-hooks-baseline`. Publish that first; otherwise this build cannot be installed. - **Update verification.** A pin that includes omacom/omarchy-mac#543 (`/usr/lib/omarchy/mac-boot/update-verify`) must publish before any runtime that carries #543. Otherwise that runtime blocks every update on Macs whose `omarchy-mac-boot` predates it. @@ -26,6 +28,8 @@ A new pin publishes on merge, so check what the pinned source needs first: ## Transition +- **From omacom/omarchy-mac-pkgs (20261004-1).** The package no longer carries the migration engine: `omarchy-mac-migrate`, `/usr/lib/omarchy/mac-boot/migrate`, the `migrate-*.sh` modules and `omarchy-mac-migrate-verify.service`. pacman removes them on upgrade. Converting a fork or mx-mac Mac is a separate migration script. A Mac stopped between a migration's reboot and its verification (`/var/lib/omarchy-mac/migration/reboot-pending`) must finish it before this upgrade: afterwards its enable link dangles and nothing verifies that boot. + - It provides, conflicts with and replaces `omarchy-apple-boot` and `omarchy-first-boot`. The scriptlet moves a pending `omarchy-first-boot` marker to `omarchy-mac-first-boot`, drops the replaced unit's dangling enable link and points at a customised `90-omarchy-asahi.conf.pacsave`. - `pkgver` is the UTC commit date of the pin, so any pin from `20260925` on upgrades the fork's `20260921-10` on mx-mac Macs. The files the fork shipped that the source no longer does (the image finalize tools, the upstream ARM repository key and the GRUB snapshot-menu hook) are removed by that upgrade. - `backup=` covers every `/etc` file and `/usr/lib/omarchy/initcpio`. It includes `/etc/default/update-m1n1`, which pins update-m1n1's device-tree order to the C locale. On a Mac that already has its own unowned copy, pacman keeps it and installs the shipped one as `.pacnew`. The snapshot restore hooks in `/etc/boot/hooks` are symlinks to `/usr/bin/omarchy-mac-snapshot-check`, not files, so they stay out of it. @@ -34,7 +38,9 @@ A new pin publishes on merge, so check what the pinned source needs first: Updates are reviewed pins, never a branch: -1. Set `_commit` to the full omarchy-mac SHA and `pkgver` to its UTC commit date (`TZ=UTC0 git show -s --format=%cd --date=format-local:%Y%m%d `); `prepare()` checks both. +1. Set `_commit` to the full omacom/omarchy-mac-pkgs `main` SHA and `pkgver` to its UTC commit date (`TZ=UTC0 git show -s --format=%cd --date=format-local:%Y%m%d `); `prepare()` checks both. 2. Reset `pkgrel` to 1 when `pkgver` changes; bump it for a second pin on the same date or a rebuild. 3. Refresh `sha256sums` with `makepkg -g`. -4. Check the pin against [Publish order](#publish-order). Before the first pin that includes omacom/omarchy-mac#567 publishes, `omarchy-mac` must be published at or past #535, or re-pinned in the same pull request. +4. Check the pin against [Publish order](#publish-order). `omarchy-mac` must be published at or past omacom/omarchy-mac#535, or re-pinned in the same pull request. + +`20261004-1` sorts above edge's `20260927-1` and every lab candidate up to `20260928-3`. diff --git a/pkgbuilds/omarchy-mac/PKGBUILD b/pkgbuilds/omarchy-mac/PKGBUILD index 61d84fa..87026bd 100644 --- a/pkgbuilds/omarchy-mac/PKGBUILD +++ b/pkgbuilds/omarchy-mac/PKGBUILD @@ -2,28 +2,32 @@ # Ported from omarchy-mac/omarchy-pkgs-aarch64 pkgbuilds/omarchy-mac at 02ed7b250f7edcf7c5f748acaf7b21ef0a764e9d. pkgname=omarchy-mac -# pkgver matches packages/omarchy-mac/version at _commit. Bump pkgrel to re-pin -# or rebuild the same add-on version; reset it to 1 when pkgver increases. +# pkgver matches omarchy-mac/version at _commit. Bump pkgrel to re-pin or +# rebuild the same add-on version; reset it to 1 when pkgver increases. pkgver=0.1.0 -pkgrel=6 +pkgrel=11 pkgdesc='Apple Silicon configuration and support services for Omarchy' arch=('aarch64') groups=('omarchy-platform-apple-silicon') -url='https://github.com/omacom/omarchy-mac' +# Owns /usr/share/omarchy-platform: one platform package per machine. Nothing +# may depend on omarchy-platform; the provide exists only for the conflict. +provides=('omarchy-platform') +conflicts=('omarchy-platform') +url='https://github.com/omacom/omarchy-mac-pkgs' license=('MIT') makedepends=('git' 'findutils') checkdepends=('diffutils' 'python' 'systemd') -# An exact quattro-upstream commit, never a branch. -_commit=ff7ce0d4dfaea9e17270b3061e642ee095b7b265 -source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('7530c284cd323d451540205c0a677c4e187070f0b8c4081a2e85f487f2ebb985') +# An exact omarchy-mac-pkgs main commit, never a branch. +_commit=43991059e17bb0ab7e0ecf0010aef1fa73c3e2c9 +source=("omarchy-mac-pkgs::git+https://github.com/omacom/omarchy-mac-pkgs.git#commit=${_commit}") +sha256sums=('654f54364a675ae9aa03728c49e5558121a7be70d60226cd8fdd4f901b195ee1') prepare() { - # Tests and staging must not be able to read the surrounding desktop source. + # Tests and staging must not be able to read the other package's tree. rm -rf "$srcdir/addon" - cp -a "$srcdir/omarchy-mac/packages/omarchy-mac" "$srcdir/addon" + cp -a "$srcdir/omarchy-mac-pkgs/omarchy-mac" "$srcdir/addon" [[ $(<"$srcdir/addon/version") == "$pkgver" ]] - [[ $(git -C "$srcdir/omarchy-mac" rev-parse HEAD) == "$_commit" ]] + [[ $(git -C "$srcdir/omarchy-mac-pkgs" rev-parse HEAD) == "$_commit" ]] } check() { @@ -32,10 +36,16 @@ check() { package() { # Runtime-only: the builder does not need the Omarchy desktop to stage or - # test the add-on. + # test the add-on. What every Mac needs comes from here, so an image's first + # boot has it offline and no owner can remove it: the speaker stack (whose + # speakersafetyd unit this package presets), audio routing, the GPU's Vulkan + # driver and the keyring of the Asahi repository the platform root names. + # The runtime's Apple package list keeps the removable defaults (video + # decode, wf-recorder, widevine, asahi-bless). depends=('omarchy' 'bash' 'coreutils' 'diffutils' 'grep' 'sed' 'gawk' 'systemd' 'pciutils' 'kmod' 'mkinitcpio' 'networkmanager' 'iwd' 'python' 'pipewire' 'pipewire-pulse' 'libpulse' 'wireplumber' - 'asahi-audio' 'alsa-ucm-conf-asahi' 'rtkit' 'pipewire-alsa') + 'asahi-audio' 'speakersafetyd' 'alsa-ucm-conf-asahi' 'rtkit' 'pipewire-alsa' + 'vulkan-asahi' 'asahi-alarm-keyring') "$srcdir/addon/install" "$pkgdir" install -Dm644 "$srcdir/addon/README.md" "$pkgdir/usr/share/doc/$pkgname/README.md" diff --git a/pkgbuilds/omarchy-mac/README.md b/pkgbuilds/omarchy-mac/README.md index 49aa1e6..f51fb06 100644 --- a/pkgbuilds/omarchy-mac/README.md +++ b/pkgbuilds/omarchy-mac/README.md @@ -1,23 +1,32 @@ # omarchy-mac -Apple Silicon runtime support for Omarchy: Wi-Fi resume recovery, the headset microphone mapping, the notch modprobe default and the NetworkManager Wi-Fi backend. The source is `packages/omarchy-mac/` in omacom/omarchy-mac, with its own version and tests. The recipe pins an exact `quattro-upstream` commit and packages only that directory; `prepare()` copies it away from the surrounding desktop tree before `check()` runs its tests. +Apple Silicon runtime support for Omarchy: the platform root (key names, notch cutouts, display and audio hints, keyrings), Wi-Fi resume recovery and the iwd backend, the headset microphone mapping, speaker safety, the audio watchdog, setup and app hooks, battery charge limits and the hardware video decode default. The source is `omarchy-mac/` in [omacom/omarchy-mac-pkgs](https://github.com/omacom/omarchy-mac-pkgs), with its own version and tests. The recipe pins an exact `main` commit and packages only that directory; `prepare()` copies it away from the rest of the checkout before `check()` runs its tests. -Ported from Scott Jones's recipe in omarchy-mac/omarchy-pkgs-aarch64 (`pkgbuilds/omarchy-mac` at `02ed7b250f7edcf7c5f748acaf7b21ef0a764e9d`). It supersedes the unpublished `omarchy-settings-asahi` recipe. +Ported from Scott Jones's recipe in omarchy-mac/omarchy-pkgs-aarch64 (`pkgbuilds/omarchy-mac` at `02ed7b250f7edcf7c5f748acaf7b21ef0a764e9d`). It supersedes the unpublished `omarchy-settings-asahi` recipe. Up to 0.1.0-6 it built from `packages/omarchy-mac/` in omacom/omarchy-mac. ## Scope -The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It depends on the generic `omarchy` package and has no `provides`, so nothing generic can pull it onto non-Apple aarch64 machines. It ships no kernel, boot, installer or trust configuration; those belong to `omarchy-mac-boot`. +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It depends on the generic `omarchy` package. Its only `provides` is `omarchy-platform`, paired with `conflicts=('omarchy-platform')`: it owns `/usr/share/omarchy-platform`, the platform root Omarchy reads, so only one platform package can be installed. Nothing may depend on `omarchy-platform`, or a dependency could pull this package onto non-Apple aarch64 machines. It ships no kernel, boot, installer or trust configuration; those belong to `omarchy-mac-boot`. -Installing the package enables no services, but its vendor configuration applies on the next service start or module load: the iwd Wi-Fi backend for NetworkManager, the `appledrm` notch option and the WirePlumber headset microphone policy. `omarchy-mac-setup-system` and `omarchy-mac-setup-user` enable the Wi-Fi resume and microphone units, and they exit unless `omarchy-hw-apple-silicon` reports Apple Silicon. Stock Omarchy does not yet ship that detector or call these entrypoints, so on a stock install the units stay disabled until the platform detector and profile work lands. +Installing the package enables no system services, but its vendor configuration applies on the next service start or module load: the iwd Wi-Fi backend for NetworkManager, the `appledrm` notch option and the WirePlumber headset microphone policy. The audio watchdog user unit is enabled by a vendor link and starts with the next graphical session; its `ExecCondition` skips it where `omarchy-hw-apple-silicon` is missing or says no. Omarchy runs the system and user setup through `omarchy-lifecycle-dispatch` (`/usr/lib/omarchy/mac`); a runtime without the dispatcher leaves them to `omarchy-mac-setup-system` and `omarchy-mac-setup-user`. -Runtime dependencies are declared in `package()`, so the builder stages and tests the add-on without installing the desktop. +`depends` carries what every Mac needs, so an offline first boot has it and an owner can't remove it: the speaker stack with `speakersafetyd` named (its unit is this package's preset), `alsa-ucm-conf-asahi`, `rtkit`, `pipewire-alsa`, `pipewire-pulse`, `vulkan-asahi` and `asahi-alarm-keyring` (the keyring of the `[asahi-alarm]` repository, named in the platform root's `keyrings`). avd-fw, libva-v4l2_request-avd, wf-recorder and widevine stay out: they are removable defaults in the runtime's Apple package list. Runtime dependencies are declared in `package()`, so the builder stages and tests the add-on without installing the desktop. + +## What 0.1.0-11 drops + +From omacom/omarchy-mac-pkgs the package no longer ships the fork's `legacy/` copies (`/usr/share/omarchy-mac/legacy`) or the setup that retired them; pacman removes them on upgrade. The Apple pacman templates, the `omarchy-hw-apple` alias, the copies under `/usr/share/omarchy` and the platform Hyprland files that lab candidates 0.1.0-7 to 0.1.0-10 carried are gone too: Omarchy from omacom/omarchy#13362 owns the templates and the detector, and the Hyprland defaults wait for a core slot. Converting a fork or mx-mac Mac is a separate migration script, not this package. + +## Publish order + +- **Runtime.** Publish with or before the runtime from omacom/omarchy#13362, which reads `/usr/share/omarchy-platform` and dispatches setup to `/usr/lib/omarchy/mac`. That runtime with an older omarchy-mac loses the Mac's key names, notch cutouts and keyring refresh, and keeps Omarchy's generic setup. +- **Boot package.** `omarchy-mac-boot` no longer presets `speakersafetyd`; this package does, from omacom/omarchy-mac#535. Every pin from omacom/omarchy-mac-pkgs includes it, so publish this pin with or before the matching `omarchy-mac-boot` pin. ## Updates Updates are reviewed pins, never a branch. To release a change to the add-on: -1. Set `_commit` to the full `quattro-upstream` SHA and `pkgver` to `packages/omarchy-mac/version` at that commit. +1. Set `_commit` to the full omacom/omarchy-mac-pkgs `main` SHA and `pkgver` to `omarchy-mac/version` at that commit. 2. Reset `pkgrel` to 1 when `pkgver` increases; bump it to re-pin or rebuild the same version. 3. Refresh `sha256sums` with `makepkg -g`. -Desktop-only commits on `quattro-upstream` do not need a new pin. `0.1.0-5` sorts above the `0.1.0-4.` candidates the collaboration builder produced for test images. +Commits that touch only `omarchy-mac-boot/`, the manual or the tools do not need a new pin. `0.1.0-11` sorts above edge's `0.1.0-6` and every lab candidate up to `0.1.0-10`.