Repository navigation
Conversation
Resume target reconciliation, the resize geometry check, repair member and size validation, and atomic engine build promotion change inputs pinned in Engine/source-lock.json. Main's source-lock test rejects such changes unless the lock and the rebuilt engine artifact are refreshed together, so these must ship with an engine rebuild, not with the app hardening in PR 29. docs/engine-hardening.md records the coverage, the canary manifest provenance and the release boundary. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
installer-v0.9.2-omarchy.29.tar.gz, 17,844,091 bytes, SHA-256 3a87e43b..., reproduced twice with macOS /usr/bin/python3 3.9.6 from the authenticated .14 base and the locked v0.9.2 checkout. The same host first reproduced the recorded .28 digest exactly. Compared with .28 only omarchy_asahi.py, omarchy_repair.py, omarchy_stage1.py and version.tag change, and the modules match the repository sources byte for byte. The source lock records the new artifact and the refreshed source hashes. The packager, the Swift artifact pin and its test, and both release-input templates select .29, so the release scripts publish the engine the templates name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
malik-na
requested review from
maralcbr and
scottjones
and removed request for
maralcbr
October 7, 2026 09:52
malik-na
marked this pull request as ready for review
October 7, 2026 09:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Engine-side hardening split out of #29, shipped in a reproducibly rebuilt engine
.29. Draft until physical qualification.Engine changes
prepared resume target does not match checkpointbefore any further mutation if UUID, identifier, size, offset or type changed.build-locked-engine.shvalidates the temporary archive before atomically replacing an earlier artifact.Coverage and the real canary repair manifest's provenance are in
docs/engine-hardening.md.Engine
.29installer-v0.9.2-omarchy.29.tar.gz, 17,844,091 bytes, SHA-2563a87e43b023e050c725d2e005bddd3721cf00f5e77104635e6a1e35411804d50.Engine/rebuild-python-overlay.pyunder macOS/usr/bin/python33.9.6 from the authenticated.14base (SHA-256 verified) and the locked Asahiv0.9.2checkout (verify-source-lock.pypassed)..28digest exactly; two.29repacks were byte-identical;verify-archive-modes.pypassed..28, onlyomarchy_asahi.py,omarchy_repair.py,omarchy_stage1.pyandversion.tagchanged; the modules match the repository sources byte for byte..29. The archive itself is untracked, as before.Validation
apple,j614sremains blocked.Merge order
Merge #29 first: it teaches the app the new prepared-resume diagnostic. Without it the engine still refuses safely, but the app shows a generic failure.
🤖 Generated with Claude Code