Skip to content

v0.1.221

Choose a tag to compare

@github-actions github-actions released this 15 Sep 05:36
· 1426 commits to main since this release
b058c1a

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.221

Security release: changes since v0.1.220

This release brings the merged security work into an installable build, adds
layered mise configuration and AUR-only updates, and strengthens release
verification. The linked changes below are implementation evidence, not a claim
that untrusted packages become harmless or that OMG supports every mise feature.

Package, runtime and privilege protections

  • Upgrade rustls to 0.23.45 in both product and fuzz lockfiles for
    RUSTSEC-2026-0285,
    published September 14. The fix rejects TLS 1.3 handshake messages at an
    incorrect encryption level. The release audit caught this before publication.

  • AUR builds validate archive identity and metadata before elevation, reject
    unsafe paths and links, and require additional approval and paired-build
    evidence for high-risk payloads. Offline Git source preparation and tainted
    checkout replacement address separate build and host-execution boundaries.

  • Managed npm tools stage with lifecycle scripts disabled and verify available
    registry signature/provenance evidence before activation. Package-scoped
    exceptions remain explicit. pip, Cargo and Go installation paths constrain
    source/configuration inheritance according to their supported policies.

  • Managed tool receipts and entrypoint hashes record what was installed; failed
    activation rolls back and managed links remain within the owned tool root.

  • Privileged operations use validated executable and state paths. Root ignores
    caller-controlled state and trust overrides. Installer subprocesses use Linux
    no-new-privileges controls, and atomic replacement does not preserve set-ID bits.

  • CI/container configuration writers reject redirected destinations and unsafe
    parents. Daemon path failures remain errors. Signed package database handling,
    completion output and nested parsing gained additional validation.

See #394,
#399, and
#414 for scope, tests and limitations.

Features and compatibility changes

  • omg update --aur-only limits Arch updates to AUR packages; it is intended for
    workflows where the distribution's own updater continues to own official
    packages. This does not establish default adoption or complete integration
    with Omarchy. #401
  • Supported mise tool pins, environments and tasks now use layered discovery,
    local/selected-environment overrides and task dependencies. Previously ignored
    layers may now affect a project. Review the
    migration guide
    before upgrading. Unsupported mise constructs are not advertised as parity.
    #403,
    #404
  • Interactive Bash, Zsh and Fish hooks can advise when a newer OMG release is
    available. Daily checks run in the background, offline failures are silent,
    and installation remains explicit. The first check populates a cache for a
    later terminal opening. Set OMG_NO_UPDATE_CHECK=1 before the hook to opt out.
    Notice behavior
  • DNF/RPM inventory observation and cached/check-only update behavior include
    fixes; CLI and platform regression fixtures have been updated accordingly.

CI, QEMU and release verification

  • QEMU controllers move to architecture-pinned Debian Trixie images and require
    QEMU packages at or above Debian's fix for
    CVE-2026-48914
    before parsing guest images or booting. Installed package versions are exported
    with the run evidence; guest distributions remain unchanged.
  • Main-push guest runs consume the same staged artifact decision as preparation,
    preventing unpublished release versions from being selected as published inputs.
  • All eight release prerequisite workflows run on every main push, including
    workflow-only fixes. PR path filtering remains; main trades additional runs for
    complete evidence tied to the exact release commit.
  • Published QEMU inputs now require attestations tied to the repository, tag,
    source commit and release workflow; adjacent checksums alone are insufficient.
  • QEMU runs with UID/GID 65534, no effective capabilities, no-new-privileges and
    seccomp. Root/unfiltered fallbacks are rejected. Guest lifecycle, reboot,
    package transaction and inventory evidence remain separate checked outcomes.
  • Publication requires the latest successful push runs for the exact source
    commit across CI, benchmark, audit, secrets, CodeQL, coverage, Docker and staged
    QEMU. Older green results cannot override a newer failed run.
  • PR smoke/QEMU execution no longer receives Sentry credentials. KVM access and
    GitHub credentials are scoped. A default-branch reporter handles completed
    push/manual/nightly QEMU runs, validates run/attempt identity and reviewed case
    IDs, and creates a harness issue when failure evidence is absent or invalid.
    PR runs cannot invoke the privileged reporter. Only current-main successful
    push evidence can close matching issues.
  • Guest image verification binds publisher signatures to reviewed keys and
    image bytes. Debian cloud images retain an explicit unsigned-checksum
    exception. Reviews expire, with an advance maintenance issue and documented
    renewal procedure. An expired review cannot authorize image parsing.
  • Required inventory and skip policies bind exact inventory digests to expected
    cases. Offline cases use isolated network namespaces; explicitly networked
    cases retain their required behavior. Controller egress rejects private,
    metadata and runner destinations and permits public web traffic plus explicit
    DNS resolvers and configured public NTP servers. Public web destinations are not domain allowlisted.
  • Reset install/remove trials require distinct boot identities, matching initial
    state and health evidence for every trial. Final health admission checks kernel
    and product crash evidence, serial output and controller OOM state. Torn UTF-8
    console bytes do not disable crash-signature detection.
  • Privacy-export fault tests require observed full-storage/read-only conditions,
    injected fsync errors and interruption, preserved prior data and recovery.
    They do not claim whole-system power-loss coverage or physical-disk durability.
  • Main and release-tag rules prevent unreviewed direct main updates, require the
    configured PR checks, and prohibit changing published version tags. CI waits
    for independent release prerequisites before creating an immutable tag.
  • Compiled QEMU dependency caches reduce repeated build work. CodeQL Rust uses
    its supported build mode without the redundant release compilation; Actions
    analysis is separate. Fuzz toolchain/target selection and offline changelog
    generation are repaired.

These are intentional operator contract changes. ARM QEMU still requires an
authorized KVM-capable ARM runner; the published Linux archives are x86_64 and
macOS is ARM64. There is no measured universal security or performance guarantee.
See #413,
#415, and
#417, and
#421.

Complete source history

This ledger includes all 115 non-merge commits after v0.1.220 through 762e496b. It includes maintenance, documentation and intermediate fixes; entries are not counts of distinct security findings. The final comparison also includes later release-documentation and integration commits.

  • 94b31bf6 docs: elevate README to world class and align documentation with code stack (#393)
  • ecf049fe fix(security): land the pending security branch and remediate 2026-09-10 audit findings (#394)
  • bc7fe493 docs: update changelog [skip ci]
  • 04642bf7 Update benchmark results [skip ci]
  • 7dfcd9f8 Harden security boundaries and verify candidates through reviewed QEMU CI
  • abb42d1b Gate QEMU on harness fixtures and update vulnerable release tooling
  • 14e18d90 Fix hosted root and macOS regressions without weakening security gates
  • 8814f4b0 Require isolated elevated storage regression in security CI
  • 31dfcd06 Make disabled artifact cache lookup an associated function
  • b14fb667 Check ARM KVM runner capacity before staged builds
  • fa0fbf8a Preserve command failure diagnostics in Docker E2E tests
  • 81b05139 Avoid cosmetic cloud hostname failures and retain boot diagnostics
  • e1a454e8 Export safe readable QEMU evidence and diagnose lock contention
  • 739d8b67 Give pinned elevation fixture scoped procfs access
  • d649bbf8 Verify fakeroot under an explicit capability-free namespace
  • eee71fa4 Preserve transaction diagnostics and expose concurrency test failures
  • 6d6f384d Use display formatting for anchored lock diagnostics
  • 9276680b Handle macOS concurrent lock creation through anchored existing open
  • abaa465b Close installer and tool ownership gaps and enforce pipeline evidence
  • 54561c3b Clarify configurable runner authorization requirements
  • 1588aa3a Resolve Go metadata, RPM cache, container elevation and QA fixture issues
  • 8d7f2c82 fix(dnf): initialize WAL observation before caching inventory
  • ae5b6738 security: Harden Package-Manager Privilege Boundaries
  • 7efd233d fix(ci): run coverage fixtures with unprivileged identity
  • 9c938097 fix(privilege): import context for invoking account lookup
  • f46e85a2 fix(build): align AUR command types and gate Swift signing keys
  • 6ff5b921 test(dnf): expose cache observation changes in failing regressions
  • 03c692da security: Require Reproducible Builds for High-Risk AUR Packages
  • 7c3a7b6c fix(dnf): read inventory through the retained SQLite observer
  • fe9cee6d security: harden managed tool installations
  • 4c8c1917 security: pin tool installer executable path
  • f4a89bd4 security: surface tool policy overrides
  • d356fee5 security: verify npm packages before scripts
  • a5a9ec2b security: constrain Go tool builds
  • cbc9f73c security: reject alternate tool package sources
  • 503145cc security: isolate tool manager resolution
  • 7b0749d2 security: block parent manager configuration
  • 1fc5d2a8 security: record managed tool policy receipts
  • a246f423 security: contain managed tool binary links
  • 8e44e924 fix: roll back failed tool activation
  • 8bb84cbc security: hash managed tool entrypoints
  • 35923ad4 security: deny installer privilege gains
  • 559a95bf docs(readme): document release hardening and refresh platform guidance
  • b76bf0c7 fix: enforce tool privileges without unsafe
  • bf0e3e74 fix: satisfy portable tool hardening lints
  • 9aae0305 fix: fail closed on AUR paired builds
  • cc67ab89 test: seal AUR archive provenance fixtures
  • 56b0cd7f docs(omarchy): explain installation protections and integration proposal
  • 93bf46e0 docs(omarchy): clarify existing mise configuration support
  • 0de93ce6 docs(omarchy): substantiate managed-install default comparisons
  • 7de66699 fix(ci): repair hardening fixtures and platform test failures
  • bb90f18c test(container): expect the complete Go release version
  • b8f873fd fix(security): close remaining Arch trust gaps
  • 9af57baf fix(ci): combine identical cached update status branches
  • d25a7fd0 test(ci): align hardened update checks across runners
  • 9f00c7df test(security): verify GnuPG launcher trust before keybox round trip
  • b40fa3e9 test(update): enforce cached check-only behavior
  • 1a542e26 docs: update changelog [skip ci]
  • 098c132e feat(arch): add AUR-only update scope
  • 6d63611b docs(omarchy): define narrow AUR delegation contract
  • 93324301 test(cli): cover update --aur-only contract rows
  • 90c4384d fix(security): fail closed at the AUR-only transaction boundary
  • 28424bec test(arch): pass the explicit full-update scope
  • b0396be5 docs: update changelog [skip ci]
  • d6496c24 feat(config): load layered mise environment configuration
  • 98b1307d test(config): cover mise layers in the main regression suite
  • 7e2c3642 docs(config)!: document mise environment layer migration
  • 0226edc3 fix(config): remove superseded mise file parser
  • 15cc11ec fix(config): match mise environment precedence and config roots
  • a967090d fix(config): skip absent optional mise directory paths
  • 41fb3d43 docs: update changelog [skip ci]
  • 29e86925 feat(config)!: support layered mise pins and task dependencies
  • dfcbd5a1 docs: update changelog [skip ci]
  • 25951fb6 fix(ci): align QEMU release contracts and isolate workflow credentials
  • 245028e2 docs(ci): explain versioned QEMU release preparation
  • 69368d55 fix(security): isolate changelog write credentials
  • 7a603b0e fix(security): fail closed on daemon path resolution
  • 806ac70a fix(security): refuse redirected CI config writes
  • 59635d7c fix(security): reject symlinked CI config parents
  • 121aba94 fix(security): refuse redirected container config writes
  • b6a967ac fix(security): satisfy hardened CI writer lint
  • 57cbd2ca fix(ci): isolate smoke credentials and repair maintenance checks
  • b7f60b61 fix(security): verify QEMU provenance and drop guest process privileges
  • 5c2dd0f3 fix(ci): preserve QEMU spawn isolation and cache compiled dependencies
  • 47883e2c fix(release): require current security and staged guest evidence
  • cf7781b1 fix(test): exercise CI path protections with valid relative fixtures
  • 7b54efad docs: update changelog [skip ci]
  • 77c566db fix(ci): scope the public cache namespace scanner exception
  • 7a59c572 docs: update changelog [skip ci]
  • e8df5b22 fix(test): verify all hardened release prerequisite calls
  • 3fa68c89 docs: update changelog [skip ci]
  • 2344099f feat(shell): advise on newer OMG releases without blocking startup
  • ce146bf5 chore(release): prepare v0.1.221 with complete security changelog
  • 545a1981 fix(security): update rustls for RUSTSEC-2026-0285
  • 0a34fceb fix(shell): express private cache mode without lint violations
  • 53f153e1 docs(release): describe mandatory provenance and exact archive selection
  • 15e48470 fix(ci): use resolved staged artifacts for main QEMU guests
  • 2d57eddf fix(ci): schedule exact-commit release prerequisites on every main push
  • c12e3c10 fix(security): require patched QEMU controllers before guest boot
  • 2dd292ce fix(ci): use supported QEMU 10 privilege drop option
  • 6f028948 fix(ci): preserve setup failures and gate QEMU on final health
  • cfa1ba97 test(qemu): reject crash and missing health through lifecycle harness
  • e49847c8 test(qemu): distinguish health collection from product SSH fixtures
  • e0cb89dc fix(qemu): bind journal boot identity using supported option syntax
  • 60f8b0c6 fix(ci): enforce inventory policy and isolate QEMU issue reporting
  • bffe47ee test(qemu): validate native journal collection before guest builds
  • 031533de fix(qemu): normalize proc boot UUID for journal descriptors
  • 8231ea67 fix(security): verify guest signatures and gate immutable release tags
  • 5119fe6c fix(security): isolate hermetic QEMU inventory from network access
  • 3f2d005e fix(security): isolate privileged QEMU reporting
  • 3fe7c8b6 fix(ci): classify QEMU network dependencies and require reset trials
  • 68c6b1bb test(qemu): exercise atomic export under storage faults
  • 5d1cad7d fix(security): restrict QEMU egress and retain serial crash detection
  • 70064532 test(qemu): report confined controller configuration mismatches
  • 762e496b fix(ci): honor Docker capability names and protected main writes

Full comparison

See the release overview and complete commit ledger.

Dependency security

  • Upgrade rustls to 0.23.45 for RUSTSEC-2026-0285 (TLS 1.3 handshake encryption-level validation), including the fuzz lockfile.

QEMU and release assurance

  • Require patched QEMU controllers, reviewed guest-image provenance, exact inventory/skip policies, isolated offline tests and restricted controller egress.
  • Require reset install/remove trials and boot-scoped health checks; add privacy-export storage fault and recovery tests.
  • Preserve setup-failure evidence and report trusted push/manual/nightly failures using default-branch code. Daybreak's reporter changes exclude PR runs and require reviewed case identities.
  • Gate immutable release-tag creation on current independent workflow evidence; enforce main/check and release-tag rules.
  • Add expiring image reviews and advance maintenance warnings. Control scope and limitations.

Terminal update notices

  • Existing interactive Bash, Zsh and Fish hooks advise about newer OMG releases using a daily background check. No automatic installation. Behavior and opt-out.

⚠️ Breaking Changes

  • Config: Document mise environment layer migration ⚠️ BREAKING CHANGE

✨ New Features

  • Config: Support layered mise pins and task dependencies (#404) ⚠️ BREAKING CHANGE

feat(config)!: support layered mise pins and task dependencies

  • Config: Support layered mise pins and task dependencies ⚠️ BREAKING CHANGE
  • Config: Support layered mise project environments (#403) ⚠️ BREAKING CHANGE

feat(config)!: support layered mise project environments

  • Config: Load layered mise environment configuration
  • Arch: Add AUR-only update scope

🐛 Bug Fixes

  • Test: Verify all hardened release prerequisite calls
  • Ci: Scope the public cache namespace scanner exception
  • Release: Require current security and staged guest evidence
  • Ci: Preserve QEMU spawn isolation and cache compiled dependencies
  • Security: Verify QEMU provenance and drop guest process privileges
  • Test: Exercise CI path protections with valid relative fixtures
  • Security: Satisfy hardened CI writer lint
  • Security: Refuse redirected container config writes
  • Security: Reject symlinked CI config parents
  • Security: Refuse redirected CI config writes
  • Security: Fail closed on daemon path resolution
  • Security: Isolate changelog write credentials
  • Ci: Isolate smoke credentials and repair maintenance checks
  • Ci: Align QEMU release contracts and isolate workflow credentials
  • Config: Skip absent optional mise directory paths
  • Config: Match mise environment precedence and config roots
  • Config: Remove superseded mise file parser
  • Security: Fail closed at the AUR-only transaction boundary

Revalidate AUR-only conflicts inside the update handler so internal callers and future dispatch refactors cannot route a scoped request into fast or turbo system-update operations.

Assert the final selected transaction contains zero official packages before any update is installed. This second boundary catches future discovery regressions even if an official package reaches the combined update list.

Add regression coverage for handler-level flag confusion, injected official-package rejection, valid AUR-only selection, and unchanged full-update behavior.

Security impact: preserves Omarchy ownership of official upgrades and prevents a confused-deputy path from widening an AUR-only request after CLI parsing.

  • Ci: Combine identical cached update status branches
  • Security: Close remaining Arch trust gaps
  • Ci: Repair hardening fixtures and platform test failures
  • Fail closed on AUR paired builds
  • Satisfy portable tool hardening lints
  • Enforce tool privileges without unsafe
  • Roll back failed tool activation
  • Dnf: Read inventory through the retained SQLite observer
  • Build: Align AUR command types and gate Swift signing keys
  • Privilege: Import context for invoking account lookup
  • Ci: Run coverage fixtures with unprivileged identity
  • Dnf: Initialize WAL observation before caching inventory
  • Security: Land the pending security branch and remediate 2026-09-10 audit findings (#394)
  • fix(security): hooks refuse project _.path in automatic PATH output (csf_62033e8, csf_e757fdf, csf_f6e23cc, csf_c17f3813)

Entering a repository that declares mise _.path entries let the

automatic shell hook prepend repo-controlled directories to the

interactive PATH on every prompt, silently hijacking command resolution

with attacker-controlled executables. hook-env now applies only

tool-managed bin dirs (each validated against OMG's versions tree) and

warns once about refused project entries, mirroring the existing

_.source refusal. Explicit omg run / task execution still honors

project _.path.

  • fix(security): installer stages installs in private mktemp dirs (csf_00c97e45)

install_binary staged the copy at a PID-predictable ${dst}.tmp.$$

path inside the (potentially shared) install dir. A local attacker

watching the directory could pre-create that path as a symlink and

redirect the copy onto an unrelated file outside the install location.

Staging now happens inside an unpredictably named, mode-0700

mktemp -d directory that no other user can traverse, renamed over the

destination and removed on every exit path. Also documents that the

appended shell hook evaluates only the installed omg binary's validated

output, never repo-controlled files.

  • fix(security): pin audit migration ownership changes to the copied inode (csf_5eef98bc)

Path-based chown during cross-filesystem audit migration could be raced

into following a symlink swapped in between the metadata read and the

ownership change, transferring ownership of an unrelated inode. Add

fchown_path_no_follow (O_NOFOLLOW open + fchown on the descriptor) and

use it for the staging directory and every copied file and directory.

  • fix(security): validate the env-selected status cache before reading it (csf_fdd4999c)

The status snapshot fast path read fast_status_path() (selected via

OMG_SOCKET_PATH) directly, skipping the runtime-directory validation the

daemon and daemon clients apply. Route it through read_default/read_validated

so a foreign-owned, group-accessible, or symlinked cache parent is

rejected instead of trusted, and cover the rejection with a regression

test.

  • fix(security): neutralize control sequences in drift-report output (csf_dd687683)

Lockfile fields (package names, runtime names/versions) are remote or

user input and were printed verbatim by DriftReport::print, letting a

hostile gist lockfile inject OSC/CSI terminal output. Render the report

through render_lines(), which strips terminal control and bidi/zero-width

sequences from every dynamic field, with a regression test.

  • fix(security): bound dashboard/gist responses and sanitize remote metadata (csf_08340651, csf_4fe23b28, csf_861ca461)

    • Cap gist metadata, raw lockfile fetches, and licensed dashboard

endpoints with BoundedResponseExt so oversized bodies are rejected

before allocation instead of read unbounded into memory.

  • Read the local omg.lock through the hardened lockfile reader (regular

file, O_NOFOLLOW, 16 MiB cap) before backing it up, so a symlinked or

oversized lock cannot exhaust memory during a team pull.

  • Strip terminal control sequences from dashboard roster, policy, and

audit-log fields at the fetch boundary and from license error/tier

text before it reaches the terminal.

csf_08340651 (response size caps), csf_4fe23b28 (symlink/oversized

lockfile pull), csf_861ca461 (dashboard metadata neutralization).

  • fix(security): show declared install-hook contents in AUR review approval (csf_b6e85633)

  • fix(security): harden workspace consent display and omg resolution (csf_87e3f9f7dec33c3738538da3, csf_faa86205bd9c24d28b4e0c29)

Repo-defined workspace commands echo and prompt with project-controlled

strings; control sequences could redraw the terminal and spoof the yes/no

consent preview. Repo text now passes through sanitize_terminal_text.

'omg workspace check' resolved its helper through PATH, where a

project-controlled directory could shadow the real binary; it now

requires the sibling omg binary and refuses PATH fallback.

  • fix(security): isolate tool installs and guard shared-bin links (csf_4c5b8cb8ea49c0da05e0d928, csf_75e85ca8a86f51929ae0bed6)

cargo and npm discover configuration by walking up from the working

directory, so installing a tool from inside a project let that project's

.cargo/config.toml or .npmrc inject build settings into the install.

Package-manager commands now always run from the isolated staging dir.

link_binaries replaced any existing entry in the shared bin directory;

it now only swaps symlinks that point back into OMG's managed tools dir

and refuses to clobber foreign links or plain user files.

  • fix(security): resolve the self-update gh helper by absolute path (csf_cb969d754aa5a955660966ce)

The Sigstore attestation gate trusted whatever binary 'gh' resolved to;

a project-controlled directory earlier in PATH could ship an impostor gh

that approves a tampered archive. Attestation now consults only

well-known absolute install locations and otherwise fails closed to the

existing no-gh provenance outcome.

  • fix(security): bound and type-check project env-file reads (csf_af47b232dc7d26d308b3eda0)

_.file directives resolved during completion and automatic shell hooks

could point at special files: FIFOs block on open/read and device files

such as /dev/zero stream forever, hanging or exhausting memory in every

prompt hook. read_env_file now rejects non-regular files before opening,

re-checks the opened handle, and reads through a hard take() bound so a

file that lies about its size cannot exhaust memory.

  • fix(security): pin runtime downloads to https and reject private redirects (csf_984f3dd41c6f45d103740b57)

Runtime metadata supplies download URLs, so a tampered manifest could

aim the downloader at plain HTTP or at local/private-network services.

Vendor downloads now validate their entry URL (https, routable host;

plain-http loopback only under hermetic test mode for fixtures), and the

shared redirect policy refuses hops to private, loopback, or link-local

addresses in addition to the existing downgrade and hop-count checks.

  • fix(security): verify generated-container downloads and exclude credentials (csf_2cb1c9545ac0aca87aa1ae41, csf_ac3dc9bbbb878904d96e02c6)

Generated Dockerfiles piped remote installers straight into root shells

(rustup, bun, NodeSource) and untarred the Go toolchain with no integrity

check beyond TLS. 'omg container init' now pins the SHA-256 of each

remote artifact at generation time (go via go.dev's published release

metadata) and the emitted RUN steps verify with sha256sum before

executing; init fails closed when a digest cannot be pinned.

COPY . . also embedded untracked credentials and repository history into

every image; init now ensures .dockerignore excludes .git, .env files,

key material, and OMG state.

  • fix(security): keep write-scoped CI token out of PR-controlled workflow runs (csf_d960496333cbe84e21371e07)

pull_request events execute the merge-ref copy of ci.yml, so the

ci-success job's job-level contents:write/actions:write permissions

applied to PR-controlled workflow code. Move the privileged checkout

and release-tagging steps into a push-to-main-only release-tag job;

ci-success stays read-only.

  • fix(security): pin release-artifact digests before native smoke execution (csf_164322fe35bc00f3b4be880e)

The .sha256 sidecar ships with the release, so replacing both assets

defeats sidecar-only validation. Add OMG_SMOKE_DIGEST_PIN_FILE

(sha256sum-style pin file) checked after validate_checksum, and require

it for --executor native so the macOS host lane can no longer execute

unattested release code.

  • fix(security): gate AUR benchmark behind explicit host-mutation opt-in (csf_9d140ef71d51e291229ab753)

AUR VCS builds are mutable third-party code and cannot be digest-pinned,

so require OMG_AUR_BENCH_CONFIRM_HOST_MUTATION=yes before the benchmark

installs/uninstalls packages with sudo, and document the disposable-VM

requirement.

  • fix(security): scope docs: system-test opt-in mutates Fedora/AUR hosts (csf_6b6c47725ad3935c90e566d4)

tests/aur_dependency_resolution.rs performs real AUR installs gated only

by OMG_RUN_SYSTEM_TESTS and OMG_RUN_NETWORK_TESTS, never the destructive

flag. Document OMG_RUN_NETWORK_TESTS and warn that the system-test opt-in

is host-mutating on the Fedora and AUR lanes, so the destructive flag is

not the only mutation gate.

  • fix(security): authenticate the sudo policy handoff against root-trusted config (csf_640a559599992bb4a020f8d2)

The elevated child inherited the enforced package policy as raw argv bytes

(__omg_policy=), so anyone permitted to run 'sudo omg' could append a

forged marker and replace the policy presented to the root process (weaken

require_pgp/minimum-grade, empty the license allowlist, re-enable AUR).

The root child now re-derives the policy from a root-trusted location - the

invoking user's config directory, resolved through sudo's own SUDO_USER

identity - and only accepts a handoff that matches it exactly. Forged or

unverifiable handoffs (e.g. a custom OMG_CONFIG_DIR that cannot cross sudo

env_reset) fail closed.

  • fix(security): enforce SPDX AND/OR precedence in the license allowlist

license_matches_allowlist used any-token matching, so an SPDX conjunction

such as 'GPL-3.0 AND MIT' was treated as satisfied by the single allowed

'MIT' token - a compound license bypass of the allowed_licenses policy

(root cause at the former policy.rs license tokenization).

The allowlist now parses the SPDX expression with AND binding tighter than

OR: AND requires every operand allowed, OR requires any one (OR-any

semantics preserved per allowed_license_matches_spdx_tokens_not_substrings),

parentheses group sub-expressions, WITH exceptions evaluate by their base

identifier, and malformed expressions fail closed.

  • test(security): replace format! with to_string in sanitizer fixtures (clippy -D warnings)

  • fix(aur): support offline VCS sources and discard tainted checkouts

Two AUR build-integrity fixes.

VCS sources (git+, svn+, ...) are fetched by makepkg with a VCS client, but the

default offline sandbox runs makepkg under bwrap --unshare-net, so git clone

inside the namespace failed with a bare "Could not resolve host". Only plain

https tarballs were prefetched. Mirror git sources into SRCDEST before the

build: makepkg's extract_git then creates the working copy with a local

git clone -s, and its download_git only warns when a mirror fetch fails

("allow offline builds"). Sources omg cannot mirror are reported so the build

fails with an actionable message instead of a DNS error.

refresh_git_checkout ran git fetch/clean/reset inside a checkout that a

sandboxed PKGBUILD can write. .git/config and .git/info/attributes survive

git clean, so a planted filter.*.smudge (or core.worktree,

core.fsmonitor, core.hooksPath) executed on the host during the next

refresh: a regression of csf_63f859d75634568213c96858. Delete the checkout and

clone it again instead, and cover the config-selected vectors in the test.

📚 Documentation

  • Ci: Explain versioned QEMU release preparation

  • Omarchy: Define narrow AUR delegation contract

  • Omarchy: Substantiate managed-install default comparisons

  • Omarchy: Clarify existing mise configuration support

  • Omarchy: Explain installation protections and integration proposal

  • Readme: Document release hardening and refresh platform guidance

  • Elevate README to world class and align documentation with code stack (#393)

    • Overhaul README.md with high-contrast badges, Franken-stack comparison, ASCII architecture, and grounded disclosures

    • Align docs with 14 native runtimes across runtimes.md, cheatsheet.md, and shell-integration.md

    • Fix CLI aliases and flag discrepancies in cli.md (including install alias 'i' and hook options)

    • Update canonical domain references to getomg.xyz in telemetry, fleet, and tests

    • Document accurate cache tiers and AUR rollback mechanisms in cache.md and packages.md

🔒 Security

  • Ci: Align hardened update checks across runners

Inspect the std::process::Command wrapped by Tokio before asserting that the resolved bubblewrap launcher is absolute. Tokio's command wrapper does not expose get_program directly, which caused the Arch staged build and coverage compilation gates to fail before exercising the security tests.

Update the Docker E2E assertion to require the hardened check-only status, 'Checking for updates · cached'. This preserves the no-refresh contract added to prevent a read-only update check from mutating package databases or invoking elevation.

Together these changes restore executable coverage for the trusted launcher boundary and make the container test verify the intended least-privilege behavior.

  • Deny installer privilege gains
  • Hash managed tool entrypoints
  • Contain managed tool binary links
  • Record managed tool policy receipts
  • Block parent manager configuration
  • Isolate tool manager resolution
  • Reject alternate tool package sources
  • Constrain Go tool builds
  • Verify npm packages before scripts
  • Surface tool policy overrides
  • Pin tool installer executable path
  • Harden managed tool installations
  • Require Reproducible Builds for High-Risk AUR Packages

Detect AUR artifacts that integrate with privileged system surfaces, rebuild them in an independent private invocation, and require exact archive hashes before installation. Use a source-derived SOURCE_DATE_EPOCH, process-local verification caching, auditable evidence, and required CI regression coverage while preserving the single-build path for ordinary packages.

  • Harden Package-Manager Privilege Boundaries

🧪 Testing

  • Config: Cover mise layers in the main regression suite
  • Arch: Pass the explicit full-update scope

Supply aur_only=false to the legacy update-phase assertion after the helper gained an explicit scope parameter. Coverage and the staged Arch build both compile the cfg(test) module and therefore caught this omitted argument before any test execution.

All update_phase_context and should_sync_official_databases call sites were enumerated after the fix, preserving explicit scope at every production and regression-test boundary.

  • Cli: Cover update --aur-only contract rows

The new flag was missing from the declared-long-flag inventory, which would fail when this stack retargets main.

  • Update: Enforce cached check-only behavior

Update the comprehensive CLI and package-operation assertions to match the hardened update contract: --check reads cached package databases and must not refresh catalogs or request privilege.

The coverage workflow reached the executable suite and exposed the stale expectation after 2,783 tests began running. Keeping these assertions explicit prevents a future regression from turning a read-only status check back into a mutating or privilege-bearing operation.

  • Security: Verify GnuPG launcher trust before keybox round trip
  • Container: Expect the complete Go release version
  • Seal AUR archive provenance fixtures
  • Dnf: Expose cache observation changes in failing regressions

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.221-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.221-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.221-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.221-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.221-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.221-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.221-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.221-x86_64-linux-arch.tar.gz -R PyRo1121/omg --source-ref refs/tags/v0.1.221 --signer-workflow PyRo1121/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.221-x86_64-linux-arch.tar.gz
cd omg-v0.1.221-x86_64-linux-arch
sudo cp omg /usr/local/bin/

Full Changelog: https://github.com/PyRo1121/omg/blob/v0.1.221/docs/changelog.md