Skip to content

Accept candidate sets built from omacom/omarchy - #53

Merged
maralcbr merged 1 commit into
mainfrom
candidate-source-upstream
Oct 10, 2026
Merged

maralcbr merged 1 commit into
mainfrom
candidate-source-upstream

Conversation

@maralcbr

Copy link
Copy Markdown
Collaborator

Summary

  • Converge omarchy-mac and omarchy-mx-mac into upstream Omarchy omarchy#14431 merged the runtime into upstream quattro, so a candidate set built from it (e.g. e1b0e5e9b) names omacom/omarchy as its source. The trust policy only accepted omacom/omarchy-mac, so verification refused it with "wrong build manifest".
  • policy.json now has source_repositories: ["omacom/omarchy", "omacom/omarchy-mac"]; both checks in candidate_set.py use it. Sets that name the fork keep verifying (it serves the same commits). Platform repositories are unchanged.
  • New test: a set naming either repository verifies, one naming another repository is refused.

Test plan

  • image-builder/test/all in an Arch Linux ARM container
  • CI
  • Lab/test image build on the M2 from a set naming omacom/omarchy at e1b0e5e9b

omacom/omarchy#14431 merged the runtime upstream, so a set built from it names
omacom/omarchy. The policy now lists both source repositories; sets that name
the omacom/omarchy-mac fork still verify.
@maralcbr
maralcbr merged commit 1b66b38 into main Oct 10, 2026
3 checks passed
@maralcbr
maralcbr deleted the candidate-source-upstream branch October 10, 2026 02:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant