Skip to content

v0.1.223

Choose a tag to compare

@github-actions github-actions released this 16 Sep 12:33
· 1392 commits to main since this release
321b302

Alpha

OMG is alpha software: the CLI, flags, and on-disk formats can change without a compatibility guarantee.

Breaking changes

These CLI and release changes shipped in 0.1.215 and remain in later alphas.

omg license removed

Local features are no longer license-gated. Dashboard identity is optional.

# Removed
omg license
omg license check
omg license pricing

# Use instead
omg account status
omg account link <token>
omg account unlink

Team, Enterprise, and Fleet commands no longer require a paid JWT. Scripts that expected those commands to fail without a license will now succeed locally. Remote dashboard sync still needs a valid token from omg account link.

Installation

Quick Install (Linux/macOS):

curl -fsSL https://getomg.xyz/install.sh | bash

Windows Subsystem for Linux: Use the Linux installer inside your WSL distribution.

What's New in v0.1.223

Matching CLI and daemon updates

Every Linux and macOS release archive now includes both omg and omgd.
The built-in updater requires both from the same checksum- and provenance-verified
archive, stages both before replacement, prevents concurrent updates, and restores
previous files on reported replacement failures. Each replacement is atomic;
the pair is not one power-loss-atomic filesystem transaction.

Upgrade instructions

For direct installations running v0.1.222, run:

omg self-update
omg self-update --force

The first command runs the old updater, which only replaces the CLI. The second
runs the fixed updater and repairs the daemon installation too. Subsequent updates
replace both binaries in one command. Older installations crossing the signing
repository migration should follow the v0.1.222 migration instructions first.
Package-managed installations should use their package manager instead.

Restart any already-running daemon to load its new executable. For the systemd
user service, use systemctl --user restart omgd.service. For a manually started
daemon, stop that process and run omg daemon. Updating files does not restart
existing processes.

QEMU and CI

Release-candidate QEMU testing also exposed a Debian daemon SIGSEGV during
foreground startup. Request and background status workers could concurrently
access libapt, whose Rust binding documents that it is not thread-safe. Native
APT cache construction, use and destruction now share a process-wide lock;
new tests exercise concurrent native status queries. Pure-Rust lookup paths
remain independent of this lock.

The stricter QEMU check found the missing daemon in the previously published
Ubuntu, Debian and Fedora archives (#433).
The packaging correction passed staged QEMU before this release; published
verification remains a separate requirement before closing that issue.

Every selected Linux guest checks direct and foreground daemon startup, real IPC,
private socket permissions, singleton rejection, graceful shutdown and restart.
Missing evidence fails closed. Missing daemon binaries now produce an explicit
diagnostic in guest logs.

Independent distro lanes remove the wait for unrelated builds. Verified base-image
caching preserves disposable overlays, digest checks and controller isolation.
GitHub-hosted runners replace the Blacksmith trial. Documentation-only changes
avoid unnecessary builds, with exact-commit release gates retained.

Complete changes since v0.1.222

  • 2df007e7: trial Blacksmith Linux runners (#429).
  • 58e7e15b: restore GitHub-hosted runners (#430).
  • ad500149: documentation build selection and quick-gate caching (#431).
  • b8fd7ce0: paired self-updates, all-target daemon packaging, shell startup correction and mandatory QEMU daemon coverage (#432).
  • Release preparation: bump package and lockfile versions, document migration and add missing-daemon diagnostics.

Full comparison.

See the release overview and complete commit ledger.

Daemon updates

  • Serialize native APT cache lifetimes across daemon request and background workers. A Debian QEMU restart exposed a SIGSEGV while both paths could enter libapt concurrently; retain the lock through cache destruction and test concurrent native status queries.
  • Update omg and omgd together from the same verified release archive. Refuse incomplete pairs, stage both binaries before replacing either, serialize concurrent updaters, and restore previous files on replacement failures.
  • Include omgd in every Linux and macOS release archive. Self-update now reports both installed binaries and reminds users to restart an already-running daemon.

CI and QEMU

  • Require real daemon startup, IPC, singleton, shutdown and restart checks in every selected Linux guest, with bounded evidence and mandatory receipts.
  • Explain missing daemon payloads explicitly in guest failure logs; v0.1.222 non-Arch archives do not satisfy the stricter check.
  • Start each distro guest as soon as its own build completes and cache only digest-verified base images.
  • Restore GitHub-hosted runners after the Blacksmith trial, skip documentation-only builds where appropriate, and restore quick-gate caching.
  • Check the current user's daemon socket at shell startup instead of trusting a global process-name match.

Platform Support

Platform Architecture Binary
Arch Linux x86_64 omg-v0.1.223-x86_64-linux-arch.tar.gz
Debian x86_64 omg-v0.1.223-x86_64-linux-debian.tar.gz
Ubuntu x86_64 omg-v0.1.223-x86_64-linux-ubuntu.tar.gz
Fedora/RHEL x86_64 omg-v0.1.223-x86_64-linux-fedora.tar.gz
macOS ARM64 omg-v0.1.223-aarch64-darwin.tar.gz
WSL x86_64 Use the binary matching the installed Linux distribution

Verification

Verify the downloaded archive before extracting or installing it.

Integrity (checksum):

Linux:

sha256sum -c omg-v0.1.223-*.sha256

macOS:

shasum -a 256 -c omg-v0.1.223-*.sha256

Provenance: every release archive carries a Sigstore build
provenance attestation generated by GitHub Actions. Verify it with the GitHub
CLI:

gh attestation verify omg-v0.1.223-x86_64-linux-arch.tar.gz -R omg-cli/omg --source-ref refs/tags/v0.1.223 --signer-workflow omg-cli/omg/.github/workflows/release.yml

install.sh requires GitHub CLI and successful provenance verification.
omg self-update also fails closed unless provenance verifies; its explicit
unverified-provenance override is a deliberate security downgrade.

Manual Installation

Download and verify exactly the archive matching your platform. For example,
after the checksum and provenance checks above, on Arch x86_64:

tar -xzf omg-v0.1.223-x86_64-linux-arch.tar.gz
cd omg-v0.1.223-x86_64-linux-arch
sudo install -m 0755 omg omgd /usr/local/bin/

Full Changelog: https://github.com/omg-cli/omg/blob/v0.1.223/docs/changelog.md