Configuration and policy
Configure OMG through config.toml and policy.toml. Learn file locations, security grades, version files, and environment variables.
File locations
On Linux, OMG follows the XDG base directory specification. macOS uses its Application Support directory. An empty configuration is valid. Every setting has a default, so most machines need no configuration.
Linux and WSL default paths
| Path | Purpose |
|---|---|
| ~/.config/omg/config.toml | General settings such as telemetry and AUR build tuning |
| ~/.config/omg/policy.toml | Package policy enforced against prepared Arch transactions |
| ~/.local/share/omg/versions/ | Installed runtime versions |
| ~/.local/share/omg/tools/ | CLI tools installed with omg tool |
| ~/.local/share/omg/status-cache.json | Versioned daemon status snapshot |
| ~/.local/share/omg/completion-cache.json | Shell completion cache |
| ~/.local/share/omg/history.json | Transaction history |
| ~/.local/share/omg/audit/audit.jsonl | Hash-chained audit log |
General settings in config.toml
Developer workstation example
telemetry_enabled = false
[aur]
build_concurrency = 8
enable_ccache = true
cache_builds = trueAUR build settings and defaults
| Setting | Default and meaning |
|---|---|
| build_method | "bubblewrap" by default; alternatives are "chroot" and "native" |
| build_concurrency | 1 by default; the config command accepts 1 through 8 parallel AUR builds |
| review_pkgbuild | true by default; requires interactive PKGBUILD review before building |
| secure_makepkg | true by default; uses stricter makepkg flags |
| allow_unsafe_builds | false by default; permits native builds without sandboxing |
| use_metadata_archive | true by default; bulk AUR metadata for fast update checks |
| cache_builds | true by default; reuses built packages |
| enable_ccache | false by default; speeds up C and C++ builds |
| enable_sccache | false by default; speeds up Rust builds |
| telemetry_enabled | false by default; runtime telemetry is strictly opt-in |
Read and change settings from the CLI
omg config list
omg config get data_dir
omg config set aur.build_concurrency 8
omg config set telemetry.enabled false
omg config validateSecurity policy in policy.toml
Security grades from lowest to highest
| Grade | Meaning |
|---|---|
| Risk | The configured vulnerability scanner found a known vulnerability |
| Community | AUR or another nonofficial package source |
| Verified | Official repository metadata identifies the package |
| Locked | Reserved for provenance evidence that automatic grading does not yet assign |
Package grading. Every candidate gets a grade from the table above.
Grade check. The grade must meet minimum_grade.
AUR check. AUR packages are rejected when allow_aur is false.
Trust check. Grades below Verified are rejected when require_pgp is true.
License check. Licenses outside allowed_licenses are rejected when the list is set.
Ban check. Packages in banned_packages are always rejected.
Corporate style policy
minimum_grade = "Verified"
allow_aur = false
require_pgp = true
allowed_licenses = ["Apache-2.0", "MIT", "BSD-3-Clause"]
banned_packages = []The default policy uses a minimum_grade of Community. It allows AUR packages and does not require the Verified grade. Tighten minimum_grade, allow_aur, require_pgp, allowed_licenses, and banned_packages when the machine needs stricter controls. Explicit policy is enforced against prepared Arch transactions, including dependencies. Native APT, DNF, and Homebrew mutations refuse explicit policy because a precheck cannot guarantee their final transactions.
Version files OMG reads
Detected version files
| File | Runtime |
|---|---|
| .nvmrc | Node.js |
| .node-version | Node.js |
| .bun-version | Bun |
| .python-version | Python |
| .ruby-version | Ruby |
| .go-version | Go |
| .java-version | Java |
| rust-toolchain | Rust |
| rust-toolchain.toml | Rust |
| .tool-versions | Multiple runtimes in asdf format |
| package.json | Node.js and Bun through the engines or volta field |
| go.mod | Go through the go directive |
Rust toolchain file format
[toolchain]
channel = "stable"
components = ["rustfmt", "clippy"]
profile = "minimal"Environment variables
Variables OMG respects
| Variable | Purpose |
|---|---|
| OMG_SOCKET_PATH | Override the daemon socket path |
| OMG_DATA_DIR | Override the data directory |
| OMG_CONFIG_DIR | Override the configuration directory |
| RUST_LOG | Logging filter. The CLI defaults to warn and the daemon defaults to info |
| GITHUB_TOKEN | Required by omg env share |
| XDG_RUNTIME_DIR | Linux socket directory. Falls back to /run/user/$UID or a private /tmp/omg-$UID directory |
| XDG_DATA_HOME | Linux data directory. The default is ~/.local/share |
| XDG_CONFIG_HOME | Linux configuration directory. The default is ~/.config |
Running the daemon with systemd
The daemon omgd is optional. Without it, the CLI falls back to direct package-manager queries. On Linux, a systemd user unit can keep it running across logins.
Create ~/.config/systemd/user/omgd.service with ExecStart pointing at %h/.local/bin/omgd and Restart=on-failure.
Enable and start the unit.
systemctl --user enable omgd && systemctl --user start omgdCheck the result.
omg daemon-status
When configuration misbehaves
Common configuration problems
| Symptom | Fix |
|---|---|
| Config not loading | Check the file path and TOML syntax, then run omg config validate |
| Permission denied | Ensure the socket and data directories are writable by your user |
| Policy blocks installs | Raise or lower minimum_grade, or adjust allow_aur and require_pgp |
| Runtime not found | Use one of the documented native runtime names, such as node or python |
Back up Linux or WSL configuration and reset
mv ~/.config/omg/config.toml ~/.config/omg/config.toml.bak
mv ~/.config/omg/policy.toml ~/.config/omg/policy.toml.bak
omg config validate