312 Commits
Author SHA1 Message Date
c-ludenberg 64d5d7bf35 Profile trim: swap firefox->falkon, plasma->plasma-meta, drop mpv
- firefox (286 MiB) -> falkon (16 MiB): -270 MiB, KDE-native browser
- plasma group (665 MiB) -> plasma-meta (328 MiB): -337 MiB, drops
  unneeded wallpapers, X11-only packages, and dev tools
- mpv removed: -30 MiB, music preview feature long gone

ISO estimated ~2.8 GB -> ~2.15 GB, matching Artix Plasma size.
2026-07-08 18:21:41 +02:00
RaveCore-Labs 3d03d9b6ff Merge branch 'warn-codeql' into 'master'
docs: call out CodeQL/Copilot AI in warning header

See merge request moonlightos-dev/antergos-iso!3
2026-07-07 20:12:20 +02:00
c-ludenberg da3dc22379 docs: call out CodeQL/Copilot AI in warning header 2026-07-07 20:12:10 +02:00
c-ludenberg dcdc48817f docs: call out CodeQL/Copilot AI in warning header 2026-07-07 20:12:05 +02:00
RaveCore-Labs 9ce9203943 Merge branch 'revert-codeql' into 'master'
revert: basestrap/main.py to pre-CodeQL state with critical warning

See merge request moonlightos-dev/antergos-iso!2
2026-07-07 20:08:20 +02:00
c-ludenberg a9a46a519d revert: basestrap/main.py to pre-CodeQL state with critical warning
Restores original callback (hardcoded False), pretty_status_message refactor,
umask pattern, known_inits name, unguarded operations access, and inline
subst_locale — all of which were changed in earlier CodeQL fix commits.

Keeps only harmless changes: unused import removal (sys, re), PEP8 comma
space, and _change_mode zero-division guard.

Adds large ASCII warning header: DO NOT EDIT without full ISO test.
2026-07-07 20:08:07 +02:00
c-ludenberg 4b105c60da revert: basestrap/main.py to pre-CodeQL state with critical warning
Restores original callback (hardcoded False), pretty_status_message refactor,
umask pattern, known_inits name, unguarded operations access, and inline
subst_locale — all of which were changed in earlier CodeQL fix commits.

Keeps only harmless changes: unused import removal (sys, re), PEP8 comma
space, and _change_mode zero-division guard.

Adds large ASCII warning header: DO NOT EDIT without full ISO test.
2026-07-07 20:06:50 +02:00
RaveCore-Labs 1baaf5903f Merge branch 'fix-codeql' into 'master'
basestrap: fix remaining CodeQL findings

See merge request moonlightos-dev/antergos-iso!1
2026-07-07 19:40:36 +02:00
c-ludenberg 2d4694f3d0 basestrap: fix remaining CodeQL findings
- Guard _change_mode progress division against zero total_packages
- Document why -Syu is inappropriate in installer context (reproducibility)
- Promote known_inits to module-level KNOWN_INIT_PROVIDERS constant
2026-07-07 19:40:19 +02:00
c-ludenberg b4e1808e5f basestrap: fix remaining CodeQL findings
- Guard _change_mode progress division against zero total_packages
- Document why -Syu is inappropriate in installer context (reproducibility)
- Promote known_inits to module-level KNOWN_INIT_PROVIDERS constant
2026-07-07 19:37:54 +02:00
c-ludenberg 988547c94b fix: merge gitlab (keep -Sy with rationale comment) 2026-07-07 19:34:25 +02:00
c-ludenberg daf7c6e648 chore: minor PEP8 fixes, add -Sy rationale comment 2026-07-07 19:33:19 +02:00
c-ludenberg 7d081c4730 fix: pre-resolve subst_locale to avoid double call / locale drift 2026-07-07 19:32:02 +02:00
c-ludenberg de2d0959a1 fix: pre-resolve subst_locale to avoid double call / locale drift 2026-07-07 19:31:57 +02:00
c-ludenberg 0f3adc70b9 fix: address basestrap findings (format safety, umask removal, non-list guard) 2026-07-07 19:30:51 +02:00
c-ludenberg ab6c1c7192 fix: address basestrap findings (format safety, umask removal, non-list guard) 2026-07-07 19:30:26 +02:00
c-ludenberg 809f8bcafa fix: address basestrap module findings (callback, umask guard, operations guard) 2026-07-07 19:28:44 +02:00
c-ludenberg db809e6898 fix: address basestrap module findings (callback, -Sy->-S, umask guard, operations guard) 2026-07-07 19:26:50 +02:00
c-ludenberg 9dff90ef46 fix: set OpenRC critical to false (broken, should not block install) 2026-07-07 19:25:44 +02:00
c-ludenberg 9e55130d01 fix: set OpenRC critical to false (broken, should not block install) 2026-07-07 19:25:35 +02:00
c-ludenberg a381290740 fix: install antergos-release/grub-theme via basestrap (online), enable dinit-user-spawn, add dbus-dinit-user 2026-07-07 19:06:01 +02:00
c-ludenberg 4c697a9142 fix: install antergos-release/grub-theme via basestrap (online), enable dinit-user-spawn, add dbus-dinit-user 2026-07-07 19:05:47 +02:00
c-ludenberg f931f74fa9 docs: add real press links 2026-07-07 18:21:02 +02:00
c-ludenberg 194d169335 docs: add GitLab-specific README with the full story 2026-07-07 18:17:14 +02:00
c-ludenberg 5b0cbc5102 fix: install dinit service packages through netinstall Default group instead of packagechooser
basestrap module (from calamares-extensions) reads netinstallAdd only
for the init provider name (e.g. 'dinit') to add elogind-dinit. It
does NOT install the subgroup packages from the user's packagechooser
selection (networkmanager-dinit, pipewire-dinit, etc.). So these were
selected in the GUI but never present in the target system.

Since the netinstall view's packageOperations -> packages module flow
works correctly, move all required *-dinit service packages into the
netinstall.yaml Default group (online) and profile.yaml rootfs (offline).

Also revert settings.conf back to services-artix + postcfg — these
modules DO exist (from calamares-extensions) and work correctly when
the service packages are installed. Remove the unnecessary shellprocess
files that were added as a mistaken workaround.
2026-07-07 17:40:50 +02:00
c-ludenberg 0f3ed4f346 fix: replace broken services-artix/postcfg modules with shellprocess
services-artix and postcfg Calamares modules don't exist in upstream
Calamares (they're Garuda/Artix fork patches). Our custom Calamares
builds from pure upstream, so these steps get silently skipped during
installation, leaving NO services enabled in the installed system.

Replace them with shellprocess@enable-services, which uses the
built-in shellprocess module to run a post-install script that:
- Detects the init system (dinit/openrc/runit/s6)
- Enables all system services via boot.d symlinks or equivalent
- Sets up user services (pipewire, wireplumber) for the created user

Affects both online and offline installer settings.
2026-07-06 22:59:57 +02:00
c-ludenberg 2283ff2131 fix: add missing dinit service packages for live environment
add_svc_dinit() in services.sh creates boot.d symlinks for each service
listed in live-session: services: — but only if the service file exists
at /etc/dinit.d/<name>. Without the -dinit packages installed in the
livefs, all services were silently skipped and the display manager
never started.

Add acpid-dinit, bluez-dinit, cronie-dinit, cups-dinit,
networkmanager-dinit, power-profiles-daemon-dinit, sddm-dinit,
syslog-ng-dinit, dbus-dinit, pipewire-dinit, wireplumber-dinit
2026-07-06 21:41:48 +02:00
c-ludenberg 777dd07b74 fix: add branding, network, audio packages to netinstall + init chooser
- Plasma group in netinstall.yaml now includes antergos-plasma-theme,
  antergos-next-desktop-settings, and full KDE app list from branding
- Default group adds networkmanager, pipewire, pipewire-pulse,
  wireplumber, firefox, mesa for working network/audio out of the box
- Init chooser packagechooser.conf adds pipewire-dinit and
  wireplumber-dinit services to all four init sections (dinit, openrc,
  s6, runit) for audio service enablement
2026-07-06 20:49:18 +02:00
c-ludenberg 9bb6257dd2 fix: copy finished.conf to shared modules dir
finished.conf was only in calamares-online/modules/ and
calamares-offline/modules/, not in calamares/modules/. When
settings.conf gets copied at runtime, Calamares looks for
modules at /etc/calamares/modules/finished.conf which didn't
exist, silently falling back to defaults with systemctl reboot
(broken on Artix).
2026-07-06 20:24:53 +02:00
c-ludenberg 1233d21516 fix: mark OpenRC as broken in installer with warning
OpenRC conflicts with dinit-rc over virtual init-rc. Runit and S6
use different virtuals so they're fine. OpenRC stays listed but
with a visible warning until a fix is found.
2026-07-06 20:23:02 +02:00
c-ludenberg aad3d86af5 chore: clean up unreachable pass/else in run_pacman retry loop 2026-07-06 20:08:35 +02:00
c-ludenberg 023ee01cc2 chore: remove __pycache__ from repo, add to .gitignore 2026-07-06 20:07:37 +02:00
c-ludenberg 6d28e35d06 chore: fix CodeQL findings
- Remove unused sys import (basestrap/main.py)
- Remove unused target_env_call import (packages/main.py)
- Remove unused progress_match variable in both files
- Remove dead if False: callback branch (basestrap/main.py)
2026-07-06 20:07:32 +02:00
c-ludenberg 87518fba99 docs: add SECURITY.md, CONTRIBUTING.md, update maintainer name 2026-07-06 20:02:17 +02:00
c-ludenberg 5b4aade95f fix(ci): add sudo -E to build command, update IA metadata for Dinit 2026-07-06 19:56:25 +02:00
c-ludenberg 4fc2eaa262 docs: remove stale migration announcement, fix Polish README
- README.md: replace migration banner with branch link
- README.pl.md: same, plus Dlaczego Artix + OpenRC? -> Dlaczego Artix?
- docs/index.md: remove migration banner, update init refs
2026-07-06 19:51:35 +02:00
c-ludenberg 05ae4f25cc feat: switch default init from OpenRC to Dinit
All approaches to keep OpenRC as default failed:
  - --ignore: pacman ignores it during fresh install provider resolution
  - --assume-installed=init-logind: ALPM doesn't check assume-installed for virtual providers
  - --ask=12: infinite loop (pacman re-adds elogind-dinit after each removal)
  - dummy package in custom repo: init-rc conflict hits via different path

Dinit works because pacman --noconfirm naturally picks elogind-dinit
(alphabetically before elogind-openrc), pulling dinit-rc which has no
conflict. All inits (OpenRC, Runit, S6) remain selectable in the
online installer.

Changes:
  - buildiso: INITSYS='dinit', remove --assume-installed/--ask hacks
  - basestrap/main.py, packages/main.py: remove same hacks
  - profile.yaml: antergos-live-dinit for dinit, move openrc pkg to init-specific
  - packagechooser.conf (x2): default=Dinit, Dinit first in item list
  - packagechooser_dm.conf: *-dinit instead of *-openrc
  - README.md, README.pl.md, docs/*: update all OpenRC-first references
  - AGENTS.md: document dinit as default
2026-07-06 19:42:27 +02:00
c-ludenberg 64b08a95ad fix: replace --ignore with --assume-installed=init-logind to bypass provider selection
--ignore doesn't reliably prevent pacman from considering elogind-dinit
during fresh provider resolution on all pacman versions. --assume-installed
creates a dummy installed package for init-logind, satisfying the
dependency from base without needing any provider at all. The explicitly
listed elogind-openrc then gets installed normally and provides
init-logind for real.

Dropped --ignore entirely in favor of --assume-installed + --ask=4
(conflict resolution safety net). --assume-installed only added for
non-dinit providers (openrc, runit, s6).
2026-07-05 22:23:01 +02:00
c-ludenberg 69da290ac5 fix: add --ask=4 safety net for init-rc conflicts in all three pacman code paths
--ignore alone doesn't reliably prevent provider resolution during fresh
pacman -S installs. --ask=4 auto-answers YES to conflict resolution
questions (e.g. 'remove dinit-rc?') with --noconfirm, providing a safety
net when --ignore doesn't prevent the dinit-rc vs openrc conflict.

All three code paths updated:
  - buildiso: make_rootfs() basestrap call
  - basestrap/main.py: PMPacman.install()
  - packages/main.py: PMPacman.install()
2026-07-05 22:16:40 +02:00
c-ludenberg 2c0d2424b4 fix: add --ignore logic to packages module too
The branding's netinstall.yaml has a Base System group with 'base'
that gets added to packageOperations. The packages module then
reinstalls base without --ignore, triggering the same init-logind
resolution bug. Adding the same --ignore logic from the basestrap
module.
2026-07-05 22:03:03 +02:00
c-ludenberg 8a6fa3fa5d docs: update AGENTS.md with --ignore approach for init conflict 2026-07-05 21:42:14 +02:00
c-ludenberg fe4e86257b fix: use --ignore instead of separate provider call to prevent init conflict
Using --ignore=elogind-dinit (and alphabetically-before providers for
other inits) prevents pacman --noconfirm from resolving init-logind
to the wrong provider. This is more robust than installing the
provider separately, which can fail if base's deps are missing.
2026-07-05 21:41:53 +02:00
c-ludenberg 4e32d1de61 docs: add buildiso fix to init-rc conflict gotcha in AGENTS.md 2026-07-05 21:30:49 +02:00
c-ludenberg b0ec890760 fix: install init-logind provider before base in buildiso make_rootfs
Same fix as basestrap/main.py: when base depends on init-logind
virtual, pacman --noconfirm picks the first provider alphabetically
(elogind-dinit < elogind-openrc), pulling in dinit -> dinit-rc which
conflicts with openrc (both provide/conflict with init-rc).

Install elogind- as a separate basestrap call BEFORE the
full package list to satisfy init-logind before base needs it.
2026-07-05 21:30:33 +02:00
c-ludenberg 81f215166d fix: install init-logind provider before base to avoid dinit-rc/openrc conflict
dinit-rc and openrc both provide AND conflict with virtual init-rc and
cannot coexist. When base depends on init-logind (virtual), pacman with
--noconfirm picks the first alphabetically -- elogind-dinit over
elogind-openrc -- pulling in dinit -> dinit-rc, which conflicts with
openrc (pulled by elogind-openrc via dbus-openrc).

Fix: use operations.insert(0, ...) so elogind-{init} installs as a
separate pacman call BEFORE base, satisfying init-logind before base
needs it.
2026-07-05 21:11:00 +02:00
c-ludenberg ec65f721b9 fix: remove stale try_remove artix-release (package doesn't exist) 2026-07-05 21:05:32 +02:00
c-ludenberg 64e0990a50 fix: restore base_init logic in basestrap with init-filtered netinstallAdd 2026-07-05 20:54:05 +02:00
c-ludenberg fea5c3babe fix: add elogind-openrc to basestrap install to pin init-logind provider 2026-07-05 20:53:17 +02:00
c-ludenberg 8033575d50 fix: use --overwrite=* as single arg in packages module 2026-07-05 20:52:04 +02:00
c-ludenberg ac52aeea16 fix: restore packages/main.py corrupted by debugfs journal dump 2026-07-05 20:44:39 +02:00