Skip to content

Add linux-aarch64 kernel compatibility shim - #222

Open
birkskyum wants to merge 15 commits into
omacom:masterfrom
birkskyum:upstream/aarch64-limine
Open

birkskyum wants to merge 15 commits into
omacom:masterfrom
birkskyum:upstream/aarch64-limine

Conversation

@birkskyum

@birkskyum birkskyum commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds linux-aarch64-pkgbase-shim, which copies Arch Linux ARM's /boot/Image to usr/lib/modules/<ver>/vmlinuz and writes pkgbase next to it.

Limine needs this when it boots the kernel directly (ENABLE_UKI=no), as the DGX Spark does in omacom/omarchy#13426. The hook then takes the kernel from vmlinuz in the modules directory. Without it the hook stops with "vmlinuz not found" and writes no boot entry.

UKI installs no longer need it. Since limine-entry-tool 1.38 the hook finds the kernel through modules.builtin, and Arch Linux ARM's mkinitcpio locates /boot/Image itself.

  • Refreshes the image on kernel upgrades and on same-version reinstalls that change it.
  • Preserves package-owned files, copies atomically with the original permissions, and removes stale shim-only metadata without deleting DKMS leftovers.
  • Defers regeneration when the installer masks the normal hook, and reports rebuild failures.

The shim can go once the hook can take the kernel from /boot/Image for regular entries, or linux-aarch64 ships vmlinuz in its modules directory.

Dependencies

Targets omarchy-pkgs/master. The installer in omacom/omarchy-iso#129 is merged into dragon and installs this package. It can land and be published independently of #221.

Jimmy Van Veen authored the original shim, and Jim Martin added the shared-ownership fix. Original authorship is preserved.

Validation

On 4 October I ran an install, a 7.2.6 to 7.2.8 kernel update and a reboot in an aarch64 VM, with limine-mkinitcpio-hook 1.40.0 from the edge channel and Omarchy's Limine settings.

With a UKI ENABLE_UKI=no
With the shim boots the new kernel boots the new kernel
Without the shim boots the new kernel no boot entry is written

The branch is merged with current master, and the shim's regression suite passes there. Physical hardware was not part of this round.

Earlier validation

September 16 verification passed against master 5fe2367: native ARM64 build of 1-3, shim regressions, ShellCheck and whitespace checks. Hosted self-tests and build-isolation checks pass.

An isolated ARM container tested a real 7.2.3-to-7.2.4 kernel upgrade and same-version reinstall alongside a local #380 refresh for settings 4.0.4. Metadata was refreshed before the rebuild hook; real mkinitcpio output retained encryption and Plymouth support, and settings preserved a local edit. This used a Limine backend fixture.

The September 6 integration build built the shim and extractor. September 10 container tests also covered kernel upgrade/reinstall, stale-metadata cleanup and encrypted-root initramfs generation alongside #380.

The shim was included in the September 10 image that booted on the Yoga. That did not test upgrading the installed system. Integrated results and limits retain that distinction.

@birkskyum
birkskyum marked this pull request as ready for review August 27, 2026 21:50
@birkskyum

Copy link
Copy Markdown
Contributor Author

Native ARM64 validation: the cleaned package stack built successfully in the combined PR integration run. The run failed only in the later repository-database publishing step owned by #223, after all three requested packages had been produced. Build evidence: https://github.com/birkskyum/omarchy-pkgs/actions/runs/33118509188

@JimmayVV

JimmayVV commented Aug 27, 2026 •

Copy link
Copy Markdown

I think one piece of the shim this branch retires is still needed. Zesko !64 lets limine-mkinitcpio-install discover a kernel whose package ships no pkgbase. But the hook then runs mkinitcpio --kernel <version> without --kernelimage, and mkinitcpio only looks for the image at /lib/modules/<ver>/vmlinuz, /lib/modules/<ver>/vmlinux and /boot/vmlinuz-*. Arch Linux ARM installs /boot/Image, which matches none of those. So I'd expect the UKI build to fail with "Could not find kernel image" once nothing copies Image into the modules directory. That copy was the other half of what linux-aarch64-pkgbase-shim did, alongside writing pkgbase.

If your Yoga test ran with the shim still installed from the integration branch, that would explain it working. Two fixes I can see. Keep the shim here with its retirement note, or have this patch also point mkinitcpio at /boot/Image. Happy to be wrong if I've missed something in the branch.

@birkskyum

Copy link
Copy Markdown
Contributor Author

Good catch. Confirmed: MR 64 discovers the module directory but mkinitcpio still cannot find Arch Linux ARM's /boot/Image. I restored your three shim commits with authorship intact and added an ownership compatibility patch after MR 64, because the shim-written pkgbase is not package-owned. The PR is back in draft until the corrected exact stack passes a native ARM build.

@birkskyum
birkskyum marked this pull request as ready for review August 27, 2026 22:26
@birkskyum

Copy link
Copy Markdown
Contributor Author

Corrected native ARM validation passed, including linux-aarch64-pkgbase-shim 1-3, limine-mkinitcpio-hook 1.37.1-4, repository database creation, verification, and artifact upload: https://github.com/birkskyum/omarchy-pkgs/actions/runs/33122253609

JimmayVV and others added 5 commits September 6, 2026 00:48
Arch Linux ARM's kernel packages install the kernel as /boot/Image and ship
no usr/lib/modules/<ver>/{pkgbase,vmlinuz}, which is how mkinitcpio and
limine-entry-tool find kernels. One pacman hook, ordered 85- so it runs
before 90-mkinitcpio-install, writes both files into every package-owned
modules directory that lacks pkgbase; the usual hook then builds the UKI and
writes the Limine entry. It also covers kernels already present when the
shim itself is installed, cleans up the leftover directories of removed
kernels, and never touches a directory that has pkgbase, so it retires by
removal once archlinuxarm/PKGBUILDs#2215 (or its successor) lands.

Added to the aarch64 workflow's ISO package set.
…he 90 hook is masked

omarchy-iso's installer points 90-mkinitcpio-install.hook at /dev/null in
the target during the chroot phase and runs limine-update itself afterwards.
When the shim is installed in that phase it writes pkgbase and vmlinuz and
would otherwise start a UKI build that finalize_limine_boot throws away.
The aarch64 repo build only rebuilds packages whose version moved, so the
previous script fix never reached the repository.
@birkskyum
birkskyum force-pushed the upstream/aarch64-limine branch from adbec9d to df73713 Compare September 5, 2026 23:24
Handle shared kernel-directory ownership in the ARM boot shim
@ryanrhughes ryanrhughes added the build-approved Maintainer approved this PR to build on the self-hosted pool label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build-approved Maintainer approved this PR to build on the self-hosted pool

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants