From 865aaa3f65e2643b44e8b1428d06bbd4af934327 Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 25 Sep 2026 20:00:49 +1000 Subject: [PATCH 1/5] Add omarchy-mac-boot for aarch64 edge The Apple Silicon boot package (Mac initramfs, in-place encryption, first boot and the Limine activation gate) now builds from packages/omarchy-mac/boot in omacom/omarchy-mac at a pinned commit: the recipe runs the source's tests and install staging, and keeps only metadata, backup= and the pacman scriptlet from the fork recipe. aarch64 and edge only; 20260925-1 upgrades the fork's 20260921-10. It needs the Apple-gated limine-mkinitcpio-hook 1.39.0-2. --- .../omarchy-mac-boot/.omarchy/package.json | 1 + pkgbuilds/omarchy-mac-boot/PKGBUILD | 52 +++++++++++++++++++ pkgbuilds/omarchy-mac-boot/README.md | 25 +++++++++ .../omarchy-mac-boot/omarchy-mac-boot.install | 48 +++++++++++++++++ 4 files changed, 126 insertions(+) create mode 100644 pkgbuilds/omarchy-mac-boot/.omarchy/package.json create mode 100644 pkgbuilds/omarchy-mac-boot/PKGBUILD create mode 100644 pkgbuilds/omarchy-mac-boot/README.md create mode 100644 pkgbuilds/omarchy-mac-boot/omarchy-mac-boot.install diff --git a/pkgbuilds/omarchy-mac-boot/.omarchy/package.json b/pkgbuilds/omarchy-mac-boot/.omarchy/package.json new file mode 100644 index 0000000..9adf372 --- /dev/null +++ b/pkgbuilds/omarchy-mac-boot/.omarchy/package.json @@ -0,0 +1 @@ +{ "source": "local", "channels": ["edge"] } diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD new file mode 100644 index 0000000..00e920f --- /dev/null +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -0,0 +1,52 @@ +# Maintainer: Marcelo Alcantara +# Recipe from maralcbr/omarchy-pkgs asahi-quattro pkgbuilds/omarchy-mac-boot +# (20260921-10 at 0a55baeddecf59687c32b4bd4e1dee743605c183); the payload now +# builds from packages/omarchy-mac/boot in omacom/omarchy-mac. + +pkgname=omarchy-mac-boot +# pkgver is the UTC commit date of _commit, so it sorts above the fork's +# 20260921-N. Reset pkgrel to 1 when pkgver changes; bump it to re-pin or +# rebuild on the same day. +pkgver=20260925 +pkgrel=1 +pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' +arch=('aarch64') +url='https://github.com/omacom/omarchy-mac' +license=('MIT') +makedepends=('git') +provides=('omarchy-apple-boot' 'omarchy-first-boot') +conflicts=('omarchy-apple-boot' 'omarchy-first-boot') +replaces=('omarchy-apple-boot' 'omarchy-first-boot') +install=omarchy-mac-boot.install +# An exact omarchy-mac commit, never a branch. +_commit=1855e11294c7bb82f5832822a7a1185b23ff8492 +source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") +sha256sums=('e16c9765bf0f8a8f230021850d503e11edd4579857e9239c464f4f50d1104d0a') + +prepare() { + # Tests and staging must not be able to read the surrounding desktop source. + rm -rf "$srcdir/boot" + cp -a "$srcdir/omarchy-mac/packages/omarchy-mac/boot" "$srcdir/boot" + [[ $(git -C "$srcdir/omarchy-mac" rev-parse HEAD) == "$_commit" ]] + [[ $(TZ=UTC0 git -C "$srcdir/omarchy-mac" show -s --format=%cd --date=format-local:%Y%m%d HEAD) == "$pkgver" ]] +} + +check() { + "$srcdir/boot/test/all" +} + +package() { + # Runtime-only, so the builder stages and tests the payload without the + # desktop or a boot chain. 1.39.0-2 is the first limine-mkinitcpio-hook that + # leaves a Mac's /boot to mkinitcpio until Limine is activated. + depends=('omarchy' 'limine' 'limine-mkinitcpio-hook>=1.39.0-2' 'limine-snapper-sync' 'asahi-scripts' + 'bash' 'btrfs-progs' 'coreutils' 'cpio' 'cryptsetup' 'diffutils' 'gawk' 'gnupg' 'grep' 'gum' + 'gzip' 'kbd' 'mkinitcpio' 'sed' 'systemd' 'util-linux') + + "$srcdir/boot/install" "$pkgdir" + printf '%s\n' "$_commit" | install -Dm644 /dev/stdin "$pkgdir/usr/share/omarchy-mac/boot-source-revision" + + # Administrator-editable: every /etc path and the initramfs helpers an image + # may rewrite. + mapfile -t backup < <(cd "$pkgdir" && find etc usr/lib/omarchy/initcpio -type f | sort) +} diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md new file mode 100644 index 0000000..e85c38a --- /dev/null +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -0,0 +1,25 @@ +# omarchy-mac-boot + +Apple Silicon boot support for Omarchy: the Mac mkinitcpio drop-ins and initcpio hooks, in-place LUKS conversion in the initramfs, vendor firmware in early boot, first boot of a Mac image, the Limine activation gate and the boot check. The source is `packages/omarchy-mac/boot/` in omacom/omarchy-mac, with its own tests. The recipe pins an exact omarchy-mac commit, copies that directory away from the surrounding desktop tree in `prepare()`, runs its `test/all` in `check()` and stages the package with its `install` script. The recipe itself holds only metadata, `backup=` and the pacman scriptlet. + +It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds/omarchy-mac-boot` at 20260921-10), which carried the payload as files in the recipe. + +## Scope + +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It depends only on generic packages, and its only provides are the retired Apple-only names, so nothing generic can pull it onto non-Apple aarch64 machines. + +It requires `limine-mkinitcpio-hook` 1.39.0-2 or newer: that is the first build whose hooks leave a Mac's `/boot` to mkinitcpio until Limine is activated. With an older hook, Limine's kernel hook replaces mkinitcpio's by name, and this package's `limine-ready` gate stops it on a Mac that still boots GRUB, so a kernel update would never reach `/boot`. + +## Transition + +- It provides, conflicts with and replaces `omarchy-apple-boot` and `omarchy-first-boot`. The scriptlet moves a pending `omarchy-first-boot` marker to `omarchy-mac-first-boot`, drops the replaced unit's dangling enable link and points at a customised `90-omarchy-asahi.conf.pacsave`. +- `pkgver` is the UTC commit date of the pin, so `20260925-1` upgrades the fork's `20260921-10` on mx-mac Macs. The files the fork shipped that the source no longer does (the image finalize tools, the upstream ARM repository key and the GRUB snapshot-menu hook) are removed by that upgrade. +- `backup=` covers every `/etc` path and `/usr/lib/omarchy/initcpio`. It includes `/etc/default/update-m1n1`, which pins update-m1n1's device-tree order to the C locale. On a Mac that already has its own unowned copy, pacman keeps it and installs the shipped one as `.pacnew`. + +## Updates + +Updates are reviewed pins, never a branch: + +1. Set `_commit` to the full omarchy-mac SHA and `pkgver` to its UTC commit date (`TZ=UTC0 git show -s --format=%cd --date=format-local:%Y%m%d `); `prepare()` checks both. +2. Reset `pkgrel` to 1 when `pkgver` changes; bump it for a second pin on the same date or a rebuild. +3. Refresh `sha256sums` with `makepkg -g`. diff --git a/pkgbuilds/omarchy-mac-boot/omarchy-mac-boot.install b/pkgbuilds/omarchy-mac-boot/omarchy-mac-boot.install new file mode 100644 index 0000000..762cddf --- /dev/null +++ b/pkgbuilds/omarchy-mac-boot/omarchy-mac-boot.install @@ -0,0 +1,48 @@ +_omarchy_mac_boot_asahi_pacsave_notice() { + local pacsave=/etc/mkinitcpio.conf.d/90-omarchy-asahi.conf.pacsave + local shipped=/etc/mkinitcpio.conf.d/90-omarchy-mac.conf + + [[ -f $pacsave && -f $shipped ]] || return 0 + cmp -s "$pacsave" "$shipped" && return 0 + + cat < omarchy-mac-boot: a customized 90-omarchy-asahi.conf was preserved as: + $pacsave + The active mkinitcpio drop-in is now: + $shipped + Merge any remaining local changes into the new file. +EOF +} + +_omarchy_mac_boot_migrate_legacy_first_boot() { + local legacy=/var/lib/omarchy/first-boot/pending + local successor=/var/lib/omarchy/mac-first-boot/pending + + [[ -e $legacy ]] || return 0 + install -Dm644 /dev/null "$successor" + rm -f "$legacy" + systemctl --no-reload enable omarchy-mac-first-boot.service 2>/dev/null || { + install -d /etc/systemd/system/multi-user.target.wants + ln -sfr /usr/lib/systemd/system/omarchy-mac-first-boot.service \ + /etc/systemd/system/multi-user.target.wants/omarchy-mac-first-boot.service + } +} + +post_install() { + _omarchy_mac_boot_asahi_pacsave_notice + _omarchy_mac_boot_migrate_legacy_first_boot + _omarchy_mac_boot_drop_legacy_wants +} + +_omarchy_mac_boot_drop_legacy_wants() { + # The replaced omarchy-first-boot left its preset-enabled link behind. + local link=/etc/systemd/system/multi-user.target.wants/omarchy-first-boot.service + [[ -L $link && ! -e $link ]] && rm -f "$link" + return 0 +} + +post_upgrade() { + _omarchy_mac_boot_asahi_pacsave_notice + _omarchy_mac_boot_migrate_legacy_first_boot + _omarchy_mac_boot_drop_legacy_wants +} From c48f02942affaaf2d3d5ede127b1b485eb96fd23 Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 25 Sep 2026 20:20:01 +1000 Subject: [PATCH 2/5] omarchy-mac-boot: pin the first-boot manifest check, and say which dependency is Apple-only Moves the pin to 602266c8, where first boot of a fresh image refuses to finish without the build manifest that defers its hardware setup. asahi-scripts is the one Apple-only dependency; the README no longer calls them all generic. --- pkgbuilds/omarchy-mac-boot/PKGBUILD | 4 ++-- pkgbuilds/omarchy-mac-boot/README.md | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index 00e920f..65bbedb 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -19,9 +19,9 @@ conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install # An exact omarchy-mac commit, never a branch. -_commit=1855e11294c7bb82f5832822a7a1185b23ff8492 +_commit=602266c8887cbfe7d995be2d56f241d0c955bccb source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('e16c9765bf0f8a8f230021850d503e11edd4579857e9239c464f4f50d1104d0a') +sha256sums=('6d7d3fc59de5178b9acd62b81e3a279f75e099527b8210e5a338b3098c525e9e') prepare() { # Tests and staging must not be able to read the surrounding desktop source. diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index e85c38a..cc44c59 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -6,7 +6,7 @@ It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds ## Scope -The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It depends only on generic packages, and its only provides are the retired Apple-only names, so nothing generic can pull it onto non-Apple aarch64 machines. +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. It requires `limine-mkinitcpio-hook` 1.39.0-2 or newer: that is the first build whose hooks leave a Mac's `/boot` to mkinitcpio until Limine is activated. With an older hook, Limine's kernel hook replaces mkinitcpio's by name, and this package's `limine-ready` gate stops it on a Mac that still boots GRUB, so a kernel update would never reach `/boot`. From 134f2facc58278b6c9d4fc65d630a49f60a197d4 Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 25 Sep 2026 21:36:39 +1000 Subject: [PATCH 3/5] omarchy-mac-boot: tag it for Apple Silicon and pin #541's current head groups=('omarchy-platform-apple-silicon') is the platform tag the pacman platform guard reads (omacom/omarchy-mac#539); the package is not published yet, so it carries the tag from its first build. The pin moves to 3a58abb5, omacom/omarchy-mac#541 with #527's current head merged in. --- pkgbuilds/omarchy-mac-boot/PKGBUILD | 5 +++-- pkgbuilds/omarchy-mac-boot/README.md | 2 +- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index 65bbedb..0a9e7c3 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -11,6 +11,7 @@ pkgver=20260925 pkgrel=1 pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' arch=('aarch64') +groups=('omarchy-platform-apple-silicon') url='https://github.com/omacom/omarchy-mac' license=('MIT') makedepends=('git') @@ -19,9 +20,9 @@ conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install # An exact omarchy-mac commit, never a branch. -_commit=602266c8887cbfe7d995be2d56f241d0c955bccb +_commit=3a58abb5badf6595567695ad0db1bfe9150093ea source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('6d7d3fc59de5178b9acd62b81e3a279f75e099527b8210e5a338b3098c525e9e') +sha256sums=('c81a3ba25a27ee90092179dd48b98292cdfd04adfefcd4de40379f9b37d2de5b') prepare() { # Tests and staging must not be able to read the surrounding desktop source. diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index cc44c59..11eced1 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -6,7 +6,7 @@ It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds ## Scope -The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It carries the Apple platform tag, `groups=('omarchy-platform-apple-silicon')`, so omarchy-settings' pacman platform guard keeps it off other machines (omacom/omarchy-mac `docs/platform-guard.md`). Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. It requires `limine-mkinitcpio-hook` 1.39.0-2 or newer: that is the first build whose hooks leave a Mac's `/boot` to mkinitcpio until Limine is activated. With an older hook, Limine's kernel hook replaces mkinitcpio's by name, and this package's `limine-ready` gate stops it on a Mac that still boots GRUB, so a kernel update would never reach `/boot`. From 61bc72d00694a6889fd5f3e779bc346e78f03eec Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 25 Sep 2026 22:49:39 +1000 Subject: [PATCH 4/5] omarchy-mac-boot: pin the boot-set integration commit Pin a09ee0ca, the head of omacom/omarchy-mac integ/boot-set-1 (#547): quattro-upstream with #527, #540, #545 and #541 merged. The package then carries the Apple provisioning entrypoints from #545 and can publish before those PRs merge. --- pkgbuilds/omarchy-mac-boot/PKGBUILD | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgbuilds/omarchy-mac-boot/PKGBUILD b/pkgbuilds/omarchy-mac-boot/PKGBUILD index 0a9e7c3..a0fb5b9 100644 --- a/pkgbuilds/omarchy-mac-boot/PKGBUILD +++ b/pkgbuilds/omarchy-mac-boot/PKGBUILD @@ -8,7 +8,7 @@ pkgname=omarchy-mac-boot # 20260921-N. Reset pkgrel to 1 when pkgver changes; bump it to re-pin or # rebuild on the same day. pkgver=20260925 -pkgrel=1 +pkgrel=2 pkgdesc='Apple Silicon boot support for Omarchy: initramfs, in-place encryption, first boot and Limine activation' arch=('aarch64') groups=('omarchy-platform-apple-silicon') @@ -20,9 +20,9 @@ conflicts=('omarchy-apple-boot' 'omarchy-first-boot') replaces=('omarchy-apple-boot' 'omarchy-first-boot') install=omarchy-mac-boot.install # An exact omarchy-mac commit, never a branch. -_commit=3a58abb5badf6595567695ad0db1bfe9150093ea +_commit=a09ee0cadd8a78a774dab06eae2d6faa6a395255 source=("omarchy-mac::git+https://github.com/omacom/omarchy-mac.git#commit=${_commit}") -sha256sums=('c81a3ba25a27ee90092179dd48b98292cdfd04adfefcd4de40379f9b37d2de5b') +sha256sums=('45da7d2039a3196150fc4f7798210c5717dc9a0e9c0526de988759948f6f536f') prepare() { # Tests and staging must not be able to read the surrounding desktop source. From 020b28dd69afaab1559b0e843afb33cc31482d38 Mon Sep 17 00:00:00 2001 From: Marcelo Alcantara Date: Fri, 25 Sep 2026 23:08:14 +1000 Subject: [PATCH 5/5] omarchy-mac-boot: say the platform guard is still to ship, and drop the stale pkgrel from the README --- pkgbuilds/omarchy-mac-boot/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgbuilds/omarchy-mac-boot/README.md b/pkgbuilds/omarchy-mac-boot/README.md index 11eced1..17f1d7e 100644 --- a/pkgbuilds/omarchy-mac-boot/README.md +++ b/pkgbuilds/omarchy-mac-boot/README.md @@ -6,14 +6,14 @@ It follows the fork recipe in maralcbr/omarchy-pkgs (`asahi-quattro`, `pkgbuilds ## Scope -The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It carries the Apple platform tag, `groups=('omarchy-platform-apple-silicon')`, so omarchy-settings' pacman platform guard keeps it off other machines (omacom/omarchy-mac `docs/platform-guard.md`). Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. +The package is aarch64-only and published to edge only. It widens to rc and stable only after M1 and M2 cold-boot qualification. It carries the Apple platform tag, `groups=('omarchy-platform-apple-silicon')`, which omarchy-settings' pacman platform guard uses to keep it off other machines once that guard ships (omacom/omarchy-mac#539, `docs/platform-guard.md`). Its only provides are the retired Apple-only names, and nothing generic depends on it or on them, so nothing generic can pull it onto non-Apple aarch64 machines. Its one Apple-only dependency, `asahi-scripts`, comes from the asahi-alarm repository that only the Apple profile configures. It requires `limine-mkinitcpio-hook` 1.39.0-2 or newer: that is the first build whose hooks leave a Mac's `/boot` to mkinitcpio until Limine is activated. With an older hook, Limine's kernel hook replaces mkinitcpio's by name, and this package's `limine-ready` gate stops it on a Mac that still boots GRUB, so a kernel update would never reach `/boot`. ## Transition - It provides, conflicts with and replaces `omarchy-apple-boot` and `omarchy-first-boot`. The scriptlet moves a pending `omarchy-first-boot` marker to `omarchy-mac-first-boot`, drops the replaced unit's dangling enable link and points at a customised `90-omarchy-asahi.conf.pacsave`. -- `pkgver` is the UTC commit date of the pin, so `20260925-1` upgrades the fork's `20260921-10` on mx-mac Macs. The files the fork shipped that the source no longer does (the image finalize tools, the upstream ARM repository key and the GRUB snapshot-menu hook) are removed by that upgrade. +- `pkgver` is the UTC commit date of the pin, so any pin from `20260925` on upgrades the fork's `20260921-10` on mx-mac Macs. The files the fork shipped that the source no longer does (the image finalize tools, the upstream ARM repository key and the GRUB snapshot-menu hook) are removed by that upgrade. - `backup=` covers every `/etc` path and `/usr/lib/omarchy/initcpio`. It includes `/etc/default/update-m1n1`, which pins update-m1n1's device-tree order to the C locale. On a Mac that already has its own unowned copy, pacman keeps it and installs the shipped one as `.pacnew`. ## Updates