Skip to content

Let the Mac's platform package name the keyrings omarchy update refreshes - #667

Merged
maralcbr merged 2 commits into
quattro-upstreamfrom
mac/103-asahi-keyring-platform
Sep 28, 2026
Merged

maralcbr merged 2 commits into
quattro-upstreamfrom
mac/103-asahi-keyring-platform

Conversation

@maralcbr

Copy link
Copy Markdown
Collaborator

#652 kept asahi-alarm-keyring current through an Apple branch in quattro-upstream's omarchy-update-keyring. Upstream's version (omacom#13362) refreshes only Arch's and Arch Linux ARM's keyrings, so once Macs run it an Asahi key rotation would fail the upgrade's signature checks.

  • omarchy-mac ships /usr/share/omarchy-platform/keyrings naming asahi-alarm-keyring.
  • omarchy-update-keyring reinstalls each installed keyring that file names with the others, before the system upgrade. Names are validated (anything but a *-keyring package stops the update), uninstalled ones are skipped, and the rings to populate come from the /usr/share/pacman/keyrings/*.gpg files each package owns, read again after the reinstall.
  • A Mac whose omarchy-mac predates the file keeps the old Apple fallback.

Nothing in omarchy-mac alone can do this on omacom#13362's runtime: its update runs no platform step before the upgrade, and a pacman hook runs after signature checks and under the database lock. omacom#13362 needs the same few lines; the patch is in ticket 103's operations folder (13362-platform-keyrings.patch, tested against df41281), for the owner to apply there.

Testing (Arch container, non-root): update-keyring-test.sh (rewritten: platform list cases, invalid names, a package without a keyring, ring rename after reinstall, failure propagation), update-sequence-test.sh, apple-platform-hooks-test.sh, omarchy-mac's test/all. Second review: no blocking findings; its one hardening note (read the file list line by line) is applied. The design was debated once more beforehand; the platform-root file won over refreshing every installed keyring or a new dispatch operation.

…shes

omarchy-mac now ships /usr/share/omarchy-platform/keyrings naming asahi-alarm-keyring, and omarchy-update-keyring reinstalls and populates each installed keyring that file names, deriving the pacman-key rings from the files each package owns. Upstream's update has no Apple branch for [asahi-alarm], so the Mac's own package has to say which keyring to keep current; the same few lines read the file there. A Mac whose omarchy-mac predates the file keeps the Apple fallback.
@maralcbr
maralcbr merged commit e9f3e19 into quattro-upstream Sep 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant