Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
| A new Mac-only package | Here: open an issue first, then a pull request that meets the package contract |
| The Mac manual | Here, in the same pull request as the behaviour it describes |
| Release, acceptance or package-resolution tooling | Here, in `tools/` |
| The desktop, shell, bindings or shared helpers | [omacom/omarchy](https://github.com/omacom/omarchy). Apple Silicon desktop work that builds on [#14431](https://github.com/omacom/omarchy/pull/14431) goes to that pull request while it is open. omarchy-mac's `quattro-upstream` is frozen. |
| The desktop, shell, bindings or shared helpers | [omacom/omarchy](https://github.com/omacom/omarchy). Apple Silicon desktop work goes there too, now that [#14431](https://github.com/omacom/omarchy/pull/14431) has merged it. omarchy-mac's `quattro-upstream` is frozen. |
| Package recipes, signing and publication | [omacom/omarchy-pkgs](https://github.com/omacom/omarchy-pkgs) |
| The macOS app, the Linux image or anything that runs once to install | [omacom/omarchy-mac-installer](https://github.com/omacom/omarchy-mac-installer) |
| A hardware test report | [omarchy-m-testing.org](https://omarchy-m-testing.org) |
Expand All @@ -21,10 +21,10 @@ Omarchy keeps no Mac code of its own. It knows which platform it runs on and giv

**Upstream, in omacom/omarchy:**

- Platform detection: `omarchy-hw-platform` and the `omarchy-hw-apple-silicon` predicate.
- Platform detection: `omarchy-hw-platform`, which names an Apple Silicon Mac `aarch64-apple`, and the `omarchy-hw-aarch64-apple` predicate. The packages here call it by its old name, `omarchy-hw-apple-silicon`, which every runtime they support ships.
- The places a platform plugs in: the lifecycle dispatch operations (`setup-boot`, `setup-system`, `setup-user`, provisioning, reset, `update-verify`, `update-takeover`, the app install hooks), the platform root `/usr/share/omarchy-platform` and what Omarchy reads from it, the mkinitcpio HOOKS baseline, and the pacman platform guard.
- The default package lists, the Apple Silicon one included: adding or dropping a package every Mac gets by default is an upstream change to `install/omarchy-apple-silicon.packages`.
- Skipping a PC or Intel Mac quirk that misfires on Apple Silicon, behind `omarchy-hw-apple-silicon`.
- The default package lists, the Apple Silicon one included: adding or dropping a package every Mac gets by default is an upstream change to `install/omarchy-aarch64-apple.packages`.
- Skipping a PC or Intel Mac quirk that misfires on Apple Silicon, behind `omarchy-hw-aarch64-apple`.
- Fixes found during Mac work that help every machine, such as the battery, LUKS and keyboard-layout fixes in [#14431](https://github.com/omacom/omarchy/pull/14431), which superseded #13362.

**Here, in the packages:**
Expand All @@ -40,7 +40,7 @@ Omarchy keeps no Mac code of its own. It knows which platform it runs on and giv
| A bind or gesture behaves wrongly | Upstream, the same on every machine (the Apple SMC lid switch is the one Apple bind core keeps) |
| Wi-Fi drops after resume on one Broadcom chip | `omarchy-mac` |
| A new default package for every Mac | Upstream, in the Apple Silicon package list |
| A PC-only quirk also fires on Macs | Upstream, skipped behind `omarchy-hw-apple-silicon` |
| A PC-only quirk also fires on Macs | Upstream, skipped behind `omarchy-hw-aarch64-apple` |
| Encrypted first boot fails on every machine, Macs included | Upstream |
| The Mac's boot chain needs checking after an update | `omarchy-mac-boot`, in its `update-verify` entrypoint |
| The Mac needs to act at a moment Omarchy has no hook for | Both: see below |
Expand Down
2 changes: 1 addition & 1 deletion mac-manual/content/11-on-disk.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Package lists are composed from a base, an architecture and a platform. Only the

## Mac code stays on Macs

One detector, `omarchy-hw-platform`, answers `apple-silicon`, `generic-aarch64` or `generic`; a Snapdragon laptop is `generic-aarch64`. It reads the device-tree identity, falls back to what the kernel reports, and fails rather than guess when the evidence contradicts itself. Every Mac-only step asks it, and Mac services check again when they start, so nothing Apple-specific runs on x86 or on another ARM machine such as a Snapdragon laptop.
One detector, `omarchy-hw-platform`, answers `aarch64-apple`, `aarch64` or `x86`; a Snapdragon laptop is `aarch64`. It reads the device-tree identity, falls back to what the kernel reports, and fails rather than guess when the evidence contradicts itself. Every Mac-only step asks it, through its Apple predicate, and Mac services check again when they start, so nothing Apple-specific runs on x86 or on another ARM machine such as a Snapdragon laptop.

A pacman hook in `omarchy-settings` refuses a transaction that would install a package tagged for another platform. Image builds declare their target platform in a manifest rather than reading the build machine, and live system changes ignore environment overrides.

Expand Down
10 changes: 6 additions & 4 deletions omarchy-mac-boot/bin/omarchy-mac-snapshot-check
Original file line number Diff line number Diff line change
Expand Up @@ -180,14 +180,16 @@ restore_mode() {
}

# Only a Mac's restores are this hook's to check. A root from before the
# platform detector has only omarchy-hw-apple-silicon. Anything but a clear
# answer returns 2: the platform cannot be told, which is not waved through.
# platform detector has only omarchy-hw-apple-silicon, and one from before the
# rename names a Mac apple-silicon. Anything unclear returns 2, never waved through.
on_a_mac() {
local platform status
if command -v omarchy-hw-platform >/dev/null 2>&1; then
if platform=$(omarchy-hw-platform); then
[[ $platform == apple-silicon ]]
return
case $platform in
aarch64-apple | apple-silicon) return 0 ;;
*) return 1 ;;
esac
fi
else
omarchy-hw-apple-silicon
Expand Down
2 changes: 1 addition & 1 deletion omarchy-mac-boot/lib/provision.sh
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ refuse() {
}

require_apple_silicon() {
[[ $(omarchy-hw-platform 2>/dev/null) == apple-silicon ]] ||
omarchy-hw-apple-silicon 2>/dev/null ||
refuse "This omarchy-mac-boot entrypoint runs only on Apple Silicon Macs."
}

Expand Down
12 changes: 12 additions & 0 deletions omarchy-mac-boot/test/base-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,15 @@ requires_runtime() {
return 1
fi
}
# The runtime's Apple predicate over the stubbed detector, which names a Mac
# aarch64-apple, or apple-silicon on a runtime from before the platform rename.
stub_apple_predicate() {
cat >"$1/omarchy-hw-apple-silicon" <<'STUB'
#!/bin/bash
case $(omarchy-hw-platform) in
aarch64-apple | apple-silicon) exit 0 ;;
*) exit 1 ;;
esac
STUB
chmod +x "$1/omarchy-hw-apple-silicon"
}
7 changes: 4 additions & 3 deletions omarchy-mac-boot/test/mac-provision-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,9 @@ firmware_listing='./usr/lib/systemd/system-generators/systemd-cryptsetup-generat
./usr/lib/systemd/system/systemd-cryptsetup@.service.d/omarchy-vendorfw-initrd.conf'
cat >"$stub_bin/omarchy-hw-platform" <<'SH'
#!/bin/bash
echo "${TEST_PLATFORM:-apple-silicon}"
echo "${TEST_PLATFORM:-aarch64-apple}"
SH
stub_apple_predicate "$stub_bin"
cat >"$stub_bin/omarchy-mac-kernel" <<'SH'
#!/bin/bash
echo linux-aurora
Expand Down Expand Up @@ -184,7 +185,7 @@ run provision-prepare || fail "an encrypted image root is ready for owner setup"
[[ $(snapshot) == "$before" && ! -s $calls ]] || fail "provision-prepare changes nothing"
pass "provision-prepare accepts an encrypted image root and changes nothing"

for platform in generic-aarch64 qualcomm generic; do
for platform in aarch64 qualcomm x86; do
fixture
before=$(snapshot)
for name in provision-prepare provision-commit provision-verify luks-slots; do
Expand Down Expand Up @@ -598,7 +599,7 @@ TEST_KEYSLOTS="2 3 32" owner_refused "an owner slot out of range" "records owner
sed -i 's/^owner_slot=.*/owner_slot=/' "$root/boot/omarchy/encrypt.state"
TEST_KEYSLOTS="2 3" owner_refused "an empty owner slot" "records owner_slot=, which is not a LUKS key slot number"
sed -i 's/^owner_slot=.*/owner_slot=2/' "$root/boot/omarchy/encrypt.state"
TEST_PLATFORM=generic-aarch64 TEST_KEYSLOTS="2 3" owner_refused "off Apple Silicon" "runs only on Apple Silicon"
TEST_PLATFORM=aarch64 TEST_KEYSLOTS="2 3" owner_refused "off Apple Silicon" "runs only on Apple Silicon"
TEST_BOOT_UUID="" TEST_KEYSLOTS="2 3" owner_refused "an unmounted Boot partition" "Boot partition is not mounted at /boot"
mv "$root/dev/disk/by-uuid/$luks_uuid" "$test_tmp/by-uuid"
TEST_KEYSLOTS="2 3" owner_refused "a crypttab device that is not there" "Could not find the encrypted disk"
Expand Down
5 changes: 3 additions & 2 deletions omarchy-mac-boot/test/mac-reset-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -35,8 +35,9 @@ firmware_listing='./usr/lib/systemd/system-generators/systemd-cryptsetup-generat

cat >"$stub_bin/omarchy-hw-platform" <<'SH'
#!/bin/bash
echo "${TEST_PLATFORM:-apple-silicon}"
echo "${TEST_PLATFORM:-aarch64-apple}"
SH
stub_apple_predicate "$stub_bin"
cat >"$stub_bin/omarchy-mac-kernel" <<'SH'
#!/bin/bash
echo linux-aurora
Expand Down Expand Up @@ -225,7 +226,7 @@ done

fixture
before=$(boot_tree)
for platform in generic-aarch64 qualcomm generic; do
for platform in aarch64 qualcomm x86; do
if TEST_PLATFORM=$platform run reset-prepare "$next" "$root/dev/luks"; then fail "reset-prepare refuses to run on $platform"; fi
error_says "runs only on Apple Silicon"
for name in reset-commit reset-rollback; do
Expand Down
12 changes: 7 additions & 5 deletions omarchy-mac-boot/test/snapshot-check-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -36,14 +36,14 @@ mkdir -p "$fake" "$tmp/check-stub"
mkdir -p "$tmp/detector" "$tmp/no-detector"
cat >"$tmp/detector/omarchy-hw-platform" <<'SH'
#!/bin/bash
[[ ${TEST_PLATFORM:-apple-silicon} != error ]] || exit 1
echo "${TEST_PLATFORM:-apple-silicon}"
[[ ${TEST_PLATFORM:-aarch64-apple} != error ]] || exit 1
echo "${TEST_PLATFORM:-aarch64-apple}"
SH
# TEST_APPLE_STATUS: an exit status other than a clear answer, such as 127.
cat >"$fake/omarchy-hw-apple-silicon" <<'SH'
#!/bin/bash
[[ -z ${TEST_APPLE_STATUS:-} ]] || exit "$TEST_APPLE_STATUS"
[[ ${TEST_PLATFORM:-apple-silicon} == apple-silicon ]]
[[ ${TEST_PLATFORM:-aarch64-apple} == aarch64-apple || $TEST_PLATFORM == apple-silicon ]]
SH
printf '#!/bin/bash\nexit 0\n' >"$fake/limine-update"
# pacman -Q lists the snapshot's packages; everything else is the fixture's.
Expand Down Expand Up @@ -149,7 +149,7 @@ for hook_cmdline in "" "--add 3" "--no-force-save --add 3" "--debounce" "--no-ho
(( status == 0 )) && [[ ! -s $tmp/out && ! -s $tmp/err && ! -s $tmp/check-ran ]] ||
fail "limine-snapper-sync '$hook_cmdline' passes the hook untouched"
done
TEST_PLATFORM=generic TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$snapshot_cmdline"
TEST_PLATFORM=x86 TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$snapshot_cmdline"
(( status == 0 )) && [[ ! -s $tmp/err && ! -s $tmp/check-ran ]] || fail "a restore on anything but a Mac is not this hook's to check"
pass "the hook stays out of everything but a restore on a Mac"

Expand All @@ -160,7 +160,7 @@ pass "a restore is refused when the platform cannot be told"

TEST_NO_DETECTOR=1 TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$live_cmdline"
expect_refused "a restore from the running system of a root without the platform detector" "open Snapshots"
TEST_NO_DETECTOR=1 TEST_PLATFORM=generic TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$snapshot_cmdline"
TEST_NO_DETECTOR=1 TEST_PLATFORM=x86 TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$snapshot_cmdline"
(( status == 0 )) && [[ ! -s $tmp/err && ! -s $tmp/check-ran ]] || fail "a root without the detector and not a Mac is not this hook's to check"
TEST_NO_DETECTOR=1 TEST_APPLE_STATUS=127 TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$snapshot_cmdline"
expect_refused "a restore where omarchy-hw-apple-silicon is missing" "Cannot tell which platform this is"
Expand Down Expand Up @@ -244,6 +244,8 @@ expect_refused "a restore from the running system" \
"open Snapshots" "run omarchy-snapshot restore once it" \
"Snapshots taken before Limine was activated on this Mac cannot be restored" \
"that is gets refused"
TEST_PLATFORM=apple-silicon TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$live_cmdline"
expect_refused "a restore from the running system of a runtime from before the platform rename" "open Snapshots"
rm "$mac_root/var/lib/omarchy/limine.enabled"
TEST_PATH_FIRST=$tmp/check-stub run_check "--restore --no-mutex" "$live_cmdline"
expect_refused "limine-snapper-restore on a Mac that boots GRUB" \
Expand Down
Loading
Loading