Configuration and policy

Configure OMG through config.toml and policy.toml. Learn file locations, security grades, version files, and environment variables.

File locations

On Linux, OMG follows the XDG base directory specification. macOS uses its Application Support directory. An empty configuration is valid. Every setting has a default, so most machines need no configuration.

Linux and WSL default paths

PathPurpose
~/.config/omg/config.tomlGeneral settings such as telemetry and AUR build tuning
~/.config/omg/policy.tomlPackage policy enforced against prepared Arch transactions
~/.local/share/omg/versions/Installed runtime versions
~/.local/share/omg/tools/CLI tools installed with omg tool
~/.local/share/omg/status-cache.jsonVersioned daemon status snapshot
~/.local/share/omg/completion-cache.jsonShell completion cache
~/.local/share/omg/history.jsonTransaction history
~/.local/share/omg/audit/audit.jsonlHash-chained audit log
Where the files live Your home folder holds the settings you edit and the data OMG keeps. Nothing in the figure is created until you ask for it.
Where the files liveWhere the files live. Steps in reading order: Home folder (the tilde, ~); config.toml (general settings); policy.toml (security policy); Local data (runtimes and history). Connections: Home folder to config.toml; Home folder to policy.toml; Home folder to Local data.Home folderthe tilde, ~config.tomlgeneral settingspolicy.tomlsecurity policyLocal dataruntimes and history

General settings in config.toml

Developer workstation example

telemetry_enabled = false

[aur]
build_concurrency = 8
enable_ccache = true
cache_builds = true

AUR build settings and defaults

SettingDefault and meaning
build_method"bubblewrap" by default; alternatives are "chroot" and "native"
build_concurrency1 by default; the config command accepts 1 through 8 parallel AUR builds
review_pkgbuildtrue by default; requires interactive PKGBUILD review before building
secure_makepkgtrue by default; uses stricter makepkg flags
allow_unsafe_buildsfalse by default; permits native builds without sandboxing
use_metadata_archivetrue by default; bulk AUR metadata for fast update checks
cache_buildstrue by default; reuses built packages
enable_ccachefalse by default; speeds up C and C++ builds
enable_sccachefalse by default; speeds up Rust builds
telemetry_enabledfalse by default; runtime telemetry is strictly opt-in

Read and change settings from the CLI

omg config list
omg config get data_dir
omg config set aur.build_concurrency 8
omg config set telemetry.enabled false
omg config validate

Security policy in policy.toml

Security grades from lowest to highest

GradeMeaning
RiskThe configured vulnerability scanner found a known vulnerability
CommunityAUR or another nonofficial package source
VerifiedOfficial repository metadata identifies the package
LockedReserved for provenance evidence that automatic grading does not yet assign
  1. Package grading. Every candidate gets a grade from the table above.

  2. Grade check. The grade must meet minimum_grade.

  3. AUR check. AUR packages are rejected when allow_aur is false.

  4. Trust check. Grades below Verified are rejected when require_pgp is true.

  5. License check. Licenses outside allowed_licenses are rejected when the list is set.

  6. Ban check. Packages in banned_packages are always rejected.

Corporate style policy

minimum_grade = "Verified"
allow_aur = false
require_pgp = true
allowed_licenses = ["Apache-2.0", "MIT", "BSD-3-Clause"]
banned_packages = []

The default policy uses a minimum_grade of Community. It allows AUR packages and does not require the Verified grade. Tighten minimum_grade, allow_aur, require_pgp, allowed_licenses, and banned_packages when the machine needs stricter controls. Explicit policy is enforced against prepared Arch transactions, including dependencies. Native APT, DNF, and Homebrew mutations refuse explicit policy because a precheck cannot guarantee their final transactions.

Version files OMG reads

Detected version files

FileRuntime
.nvmrcNode.js
.node-versionNode.js
.bun-versionBun
.python-versionPython
.ruby-versionRuby
.go-versionGo
.java-versionJava
rust-toolchainRust
rust-toolchain.tomlRust
.tool-versionsMultiple runtimes in asdf format
package.jsonNode.js and Bun through the engines or volta field
go.modGo through the go directive

Rust toolchain file format

[toolchain]
channel = "stable"
components = ["rustfmt", "clippy"]
profile = "minimal"

Environment variables

Variables OMG respects

VariablePurpose
OMG_SOCKET_PATHOverride the daemon socket path
OMG_DATA_DIROverride the data directory
OMG_CONFIG_DIROverride the configuration directory
RUST_LOGLogging filter. The CLI defaults to warn and the daemon defaults to info
GITHUB_TOKENRequired by omg env share
XDG_RUNTIME_DIRLinux socket directory. Falls back to /run/user/$UID or a private /tmp/omg-$UID directory
XDG_DATA_HOMELinux data directory. The default is ~/.local/share
XDG_CONFIG_HOMELinux configuration directory. The default is ~/.config

Running the daemon with systemd

The daemon omgd is optional. Without it, the CLI falls back to direct package-manager queries. On Linux, a systemd user unit can keep it running across logins.

  1. Create ~/.config/systemd/user/omgd.service with ExecStart pointing at %h/.local/bin/omgd and Restart=on-failure.

  2. Enable and start the unit.

    systemctl --user enable omgd && systemctl --user start omgd
  3. Check the result.

    omg daemon-status

When configuration misbehaves

Common configuration problems

SymptomFix
Config not loadingCheck the file path and TOML syntax, then run omg config validate
Permission deniedEnsure the socket and data directories are writable by your user
Policy blocks installsRaise or lower minimum_grade, or adjust allow_aur and require_pgp
Runtime not foundUse one of the documented native runtime names, such as node or python

Back up Linux or WSL configuration and reset

mv ~/.config/omg/config.toml ~/.config/omg/config.toml.bak
mv ~/.config/omg/policy.toml ~/.config/omg/policy.toml.bak
omg config validate