Skip to content

Rebuild the engine with the overlay hardening, as .29 - #45

Open
malik-na wants to merge 3 commits into
mainfrom
codex/engine-hardening
Open

malik-na wants to merge 3 commits into
mainfrom
codex/engine-hardening

Conversation

@malik-na

@malik-na malik-na commented Oct 7, 2026

Copy link
Copy Markdown
Member

Engine-side hardening split out of #29, shipped in a reproducibly rebuilt engine .29. Draft until physical qualification.

Engine changes

  • Resumed stage one re-reads the saved APFS target and refuses with prepared resume target does not match checkpoint before any further mutation if UUID, identifier, size, offset or type changed.
  • Preflight rejects a changed source container endpoint or type before resizing.
  • Repair checks every payload member, local header, size and decoder before opening any disk for write, and requires manifest image sizes to fit their partitions with 4 KiB alignment.
  • build-locked-engine.sh validates the temporary archive before atomically replacing an earlier artifact.

Coverage and the real canary repair manifest's provenance are in docs/engine-hardening.md.

Engine .29

installer-v0.9.2-omarchy.29.tar.gz, 17,844,091 bytes, SHA-256 3a87e43b023e050c725d2e005bddd3721cf00f5e77104635e6a1e35411804d50.

  • Built with Engine/rebuild-python-overlay.py under macOS /usr/bin/python3 3.9.6 from the authenticated .14 base (SHA-256 verified) and the locked Asahi v0.9.2 checkout (verify-source-lock.py passed).
  • The same host first reproduced the recorded .28 digest exactly; two .29 repacks were byte-identical; verify-archive-modes.py passed.
  • Compared with .28, only omarchy_asahi.py, omarchy_repair.py, omarchy_stage1.py and version.tag changed; the modules match the repository sources byte for byte.
  • The source lock, packager, Swift artifact pin and test, and both release-input templates select .29. The archive itself is untracked, as before.

Validation

  • Local: all Python suites (39 engine tooling, 172 overlay, 30 scripts), preclean and 9 of 11 shell fixtures. The two Bash 5 shell fixtures and the Swift suites run in CI.
  • Not done: assembled-package validation, signing, publication, and physical qualification of interrupted stage-one resume and repair on authorized supported hardware. apple,j614s remains blocked.

Merge order

Merge #29 first: it teaches the app the new prepared-resume diagnostic. Without it the engine still refuses safely, but the app shows a generic failure.

🤖 Generated with Claude Code

malik-na and others added 2 commits October 7, 2026 01:38
Resume target reconciliation, the resize geometry check, repair member
and size validation, and atomic engine build promotion change inputs
pinned in Engine/source-lock.json. Main's source-lock test rejects such
changes unless the lock and the rebuilt engine artifact are refreshed
together, so these must ship with an engine rebuild, not with the app
hardening in PR 29. docs/engine-hardening.md records the coverage, the
canary manifest provenance and the release boundary.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
installer-v0.9.2-omarchy.29.tar.gz, 17,844,091 bytes, SHA-256
3a87e43b..., reproduced twice with macOS /usr/bin/python3 3.9.6 from the
authenticated .14 base and the locked v0.9.2 checkout. The same host
first reproduced the recorded .28 digest exactly. Compared with .28 only
omarchy_asahi.py, omarchy_repair.py, omarchy_stage1.py and version.tag
change, and the modules match the repository sources byte for byte.

The source lock records the new artifact and the refreshed source
hashes. The packager, the Swift artifact pin and its test, and both
release-input templates select .29, so the release scripts publish the
engine the templates name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@malik-na
malik-na requested review from maralcbr and scottjones and removed request for maralcbr October 7, 2026 09:52
@malik-na
malik-na marked this pull request as ready for review October 7, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant