From c030337cb66c9fb74a5ef01f711bf3b7d371b032 Mon Sep 17 00:00:00 2001 From: David Heinemeier Hansson Date: Sun, 19 Jul 2026 09:04:09 -0700 Subject: [PATCH] Only bundle vconsole.conf in the initramfs for Latin keyboard layouts Bundling vconsole.conf makes Plymouth apply the user's layout at the LUKS prompt, but for layouts whose letter keys aren't Latin (Hebrew, Greek, Cyrillic, Arabic, ...) that makes the necessarily-Latin passphrase untypeable and locks the user out of their machine. mkinitcpio sources its conf.d drop-ins as shell, so omarchy_hooks.conf now checks XKBLAYOUT at every rebuild and only bundles the file for Latin layouts; non-Latin layouts keep the US fallback the passphrase was set under. A migration strips the unconditional line and rebuilds the UKI on affected installs. Closes #6229. Co-Authored-By: Claude Fable 5 --- etc/mkinitcpio.conf.d/omarchy_hooks.conf | 12 +++++++++++- migrations/1784476564.sh | 20 ++++++++++++++++++++ 2 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 migrations/1784476564.sh diff --git a/etc/mkinitcpio.conf.d/omarchy_hooks.conf b/etc/mkinitcpio.conf.d/omarchy_hooks.conf index d75f4ac1..a8e39629 100644 --- a/etc/mkinitcpio.conf.d/omarchy_hooks.conf +++ b/etc/mkinitcpio.conf.d/omarchy_hooks.conf @@ -1,2 +1,12 @@ HOOKS=(base udev plymouth keyboard autodetect microcode modconf kms keymap consolefont block encrypt filesystems fsck btrfs-overlayfs) -FILES+=(/etc/vconsole.conf) + +# Bundle vconsole.conf so Plymouth uses the configured keyboard layout at the +# LUKS prompt, but only when that layout types Latin letters. Passphrases are +# Latin characters, so bundling a Hebrew/Greek/Cyrillic/Arabic layout would +# make the correct passphrase untypeable and lock the user out. +if [[ -f /etc/vconsole.conf ]]; then + case $(. /etc/vconsole.conf && echo "${XKBLAYOUT%%,*}") in + af | am | ara | bd | bg | by | et | ge | gr | il | in | iq | ir | kg | kh | kz | la | lk | mk | mm | mn | mv | np | rs | ru | sy | th | tj | ua) ;; + *) FILES+=(/etc/vconsole.conf) ;; + esac +fi diff --git a/migrations/1784476564.sh b/migrations/1784476564.sh new file mode 100644 index 00000000..1de97cd4 --- /dev/null +++ b/migrations/1784476564.sh @@ -0,0 +1,20 @@ +echo "Keep non-Latin keyboard layouts out of the initramfs so the LUKS passphrase stays typeable" + +# Bundling vconsole.conf in the initramfs makes Plymouth apply the user's +# layout at the LUKS prompt. For layouts that don't type Latin letters, that +# makes the (Latin) passphrase untypeable and locks the user out (#6229). +# Drop the bundling for those layouts and rebuild the UKI. The packaged +# omarchy_hooks.conf now applies the same condition on every rebuild. + +hooks_conf="/etc/mkinitcpio.conf.d/omarchy_hooks.conf" + +layout=$(. /etc/vconsole.conf 2>/dev/null && echo "${XKBLAYOUT%%,*}") + +if [[ $layout =~ ^(af|am|ara|bd|bg|by|et|ge|gr|il|in|iq|ir|kg|kh|kz|la|lk|mk|mm|mn|mv|np|rs|ru|sy|th|tj|ua)$ ]] && + [[ -f $hooks_conf ]] && grep -qx 'FILES+=(/etc/vconsole.conf)' "$hooks_conf"; then + sudo sed -i '\|^FILES+=(/etc/vconsole.conf)$|d' "$hooks_conf" + + if omarchy-cmd-present limine-mkinitcpio; then + sudo limine-mkinitcpio + fi +fi