Generated by Proof — the verification layer for AI-assisted development and continuous correctness audit.

Audit Cycle Report — fmggxe6eq39aplh79bgvh273.git

Executive Summary

Verdict: No new bugs introduced and none resolved in this window — posture unchanged.

Signal Count Detail
✅ Resolved this cycle 0 —
🔴 Introduced this release (still open) 0 0 regression + 0 net-new
🟥 …of which HIGH-severity 0 —
📋 Pre-existing backlog (gated, reproduced) 73 —
**Range:** _snapshot (no commit window)_

⚠️ no –from given: report is a point-in-time snapshot; every artifact is treated as in-range

Summary

Rows are non-overlapping: every open KnownIssue is counted exactly once — either as introduced this release (regression + net-new) or in the pre-existing still-open backlog.

Bucket Count
KnownIssues resolved this cycle 0
Defects introduced this release (0 regression + 0 net-new) 0
Pre-existing still-open backlog 73
Historical coverage backfill (fixed before baseline; not in window) 0
Accepted risks (active) 0

Corpus totals: 73 KnownIssues, 0 ProblemReports.

1. KnownIssues Resolved This Cycle

Issues we previously reported to you that this release fixes — verified by tripwire tests that now pass.

None resolved in this window.

2. Defects Introduced In This Release

The audit’s headline finding: bugs whose introducing change lands inside this window (snapshot) and that are STILL OPEN at HEAD. 0 qualify: 0 regression and 0 net-new. Each is also tracked as an open known issue and carries a committed reproducer; its introducing commit is linked below.

2a. Regression(s) introduced this release

No regressions introduced this release.

2b. Net-new defects introduced this release

No net-new defects introduced this release.

3. Pre-Existing Still-Open Backlog

Issues still present in this release, each gated to a requirement and reproduced.

73 active KnownIssues total — all listed individually below. Severity (holistic across all dimensions) and CVSS (security-only score from the source vector) render as separate columns, so a MEDIUM correctness item is not lost behind a HIGH security item.

KI Status Severity CVSS Age Title
KI-APPLY-LOCK-EXPORTED-FUNCTIONS-ROOT open 🟧 HIGH — since inception Exported bash functions execute as root inside apply-lock despite the trusted-PATH replacement
KI-LOCK-PAM-FLIP-ENGAGES-LOCK open 🟧 HIGH — since inception Lock engages when password PAM disappears during the stabilize window; the stranded watchdog stands down
KI-260930-2FBE reviewed 🟨 MEDIUM — since inception omarchy-system-lock exits 0 when lock engagement fails, leaving the dismissed Lock row silent
KI-APPLY-LOCK-FPRINT-GATE-FAIL-OPEN open 🟨 MEDIUM — since inception Fingerprint gate fail-open: substring grep treats not-enrolled or failed fprintd-list probes as enrolled
KI-APPLY-LOCK-PAM-NONATOMIC-WRITE reviewed 🟨 MEDIUM — since inception omarchy-apply-lock rewrites the lock PAM stacks in place; an interrupted run leaves a torn stack on the live path
KI-APPLY-LOCK-TARGET-USER-DEGRADES-ROOT open 🟨 MEDIUM — since inception Failed PKEXEC_UID/user mapping silently degrades target_user to root, configuring PAM for the wrong account
KI-LOCK-FPRINT-PROBE-FAIL-OPEN open 🟨 MEDIUM — since inception Lock-service fingerprint probe fail-open: substring grep treats zero-enrollment fprintd-list output as configured
KI-LOCK-SPONTANEOUS-UNLOCK-FAIL-OPEN reviewed 🟨 MEDIUM — since inception Compositor-side lock loss with a request outstanding is treated as a finished unlock; no re-lock
KI-MENU-IMAGES-VIPS-NO-TIMEOUT reviewed 🟨 MEDIUM — since inception vipsthumbnail still-image lane has no timeout; a stalled conversion wedges its fan-out lane indefinitely
KI-MENU-JSONC-COMMA-IN-STRING open 🟨 MEDIUM — since inception stripJsonc comma regex rewrites strings that carry a comma before } or ] (omacom/omarchy#13250)
KI-MENU-JSONC-UNICODE-WHITESPACE open 🟨 MEDIUM — since inception Unicode or control whitespace between JSONC tokens empties the whole menu file
KI-MENU-KEYBINDINGS-CODE-REWRITE-OVERREACH open 🟨 MEDIUM — since inception parse_keycodes rewrites code:N/mouse:N tokens anywhere in a record, corrupting descriptions and commands
KI-MENU-KEYBINDINGS-CSV-DESC-COMMA open 🟨 MEDIUM — since inception Comma in a binding description shifts every later CSV field: truncated label, wrong dispatcher, failed dispatch
KI-MENU-KEYBINDINGS-FUNC-BIND-NO-DISPATCH open 🟨 MEDIUM — since inception Lua function binds (Select all, Universal copy/paste/cut, Zoom in, Reset zoom) render in the menu but dispatch nothing
KI-MENU-KEYBINDINGS-SCAN-DOFILE-ABORT open 🟨 MEDIUM — since inception Lua bind scan aborts on the first throwing require; every later Lua bind silently vanishes from the menu cache
KI-MENU-KEYBINDINGS-STALE-LUA-CACHE open 🟨 MEDIUM — since inception Warm keybindings cache serves a stale Lua command after the user edits only the command a __lua bind runs
KI-MENU-KEYBINDINGS-STDERR-FAILS-DISPATCH open 🟨 MEDIUM — since inception Successful hyprctl dispatch with a stderr warning is treated as a refusal and the exec command runs twice
KI-MENU-SELECT-POLL-DEADLOCK reviewed 🟨 MEDIUM — since inception omarchy-menu-select hangs forever when the summoned menu dies before writing done_file
KI-MENU-SELECT-SUMMON-UNBOUNDED open 🟨 MEDIUM — since inception omarchy-menu-select blocks forever inside the omarchy-shell summon call when the IPC never returns
KI-SLEEP-LOCK-BUDGET-NONPOSITIVE open 🟨 MEDIUM — since inception Non-positive sleep-lock budget for logind windows <= 1s: suspend proceeds with no lock attempt
KI-LOCK-EMPTY-READLINK-WIPES-WALLPAPER reviewed 🟩 LOW — since inception Failed/empty readlink result stored as backgroundPath, wiping a good lock-screen wallpaper
KI-LOCK-FPRINT-START-FAIL-NO-RETRY reviewed 🟩 LOW — since inception fingerprintPam.start() returning false disables fingerprint auth for the rest of the lock with no retry
KI-LOCK-PAM-ERROR-DOUBLE-COUNT open 🟩 LOW — since inception Abnormal PAM error increments failedAttempts twice (onError and onCompleted both run handlePasswordFailure)
KI-LOCK-PROBE-HYPRCTL-NO-TIMEOUT reviewed 🟩 LOW — since inception omarchy-hyprland-session-locked has no deadline on hyprctl -j monitors; a stalled compositor IPC hangs the probe
KI-LOCK-SCREENS-CHANGE-BLANK-LOST reviewed 🟩 LOW — since inception Screen add/remove while locked clears the blank intent and never re-arms the idle blank timer
KI-LOCK-STALE-POSTER-INPLACE-OVERWRITE reviewed 🟩 LOW — since inception In-place video wallpaper overwrite during a running poster job keeps the stale poster frame
KI-MENU-APP-ACTIVATE-NULL-LIBRARY open 🟩 LOW — since inception Activating an app row while appLibrary is null closes the menu and skips the launch
KI-MENU-APPS-SORT-LOCALE open 🟩 LOW — since inception Apps submenu sorts with code-unit < on lowercased labels while search sorts with localeCompare
KI-MENU-CARET-COUNT-HIDDEN-CHILDREN open 🟩 LOW — since inception childCount counts when-hidden children and duplicate itemOrder entries, so the submenu badge disagrees with what renders
KI-MENU-CLI-EXIT-CODE-WRITE-RACES open 🟩 LOW — since inception Contracted exit codes lost when the usage/diagnostic write fails: unknown verb exits 1, help exits 1
KI-MENU-CLI-JQ-FAIL-LOOKS-SUCCESS open 🟩 LOW — since inception Failed jq payload build still execs the menu IPC with an empty payload and exits 0
KI-MENU-DETAIL-WHITESPACE-QUERY open 🟩 LOW — since inception A whitespace-only filter is not a search for rebuildDisplay but is truthy for the detail gates
KI-MENU-DMENU-NAN-GEOMETRY open 🟩 LOW — since inception Non-numeric dmenu width/maxHeight become NaN and collapse the card layout
KI-MENU-FILEVIEW-FAILURE-ASYMMETRY open 🟩 LOW — since inception Failed menu FileView reloads are asymmetric: user handler wipes last good items, default keeps stale set
KI-MENU-FOLD-HEIGHT-EXCEEDS-AVAILABLE open 🟩 LOW — since inception foldedListHeight returns a height above the available cap; availableRowsHeight never clamps at zero
KI-MENU-GOBACK-ROOT-STRAND open 🟩 LOW — since inception goBack refuses to retrace while activeMenu is root, stranding navStack after a drill that landed on root
KI-MENU-GUARD-BATCH-NO-DEADLINE reviewed 🟩 LOW — since inception Menu guard batch runs as one bash child with no deadline; a blocking guard freezes guard answers for the session
KI-MENU-GUARD-BATCH-STALE-APPLY open 🟩 LOW — since inception Guard batches carry no generation token: a batch computed for the previous items publishes onto the new set
KI-MENU-GUARD-ID-INJECTION-BATCH-ABORT open 🟩 LOW — since inception Guard ids interpolated unquoted into the shared bash batch: metacharacter ids break the protocol or execute commands
KI-MENU-INPUT-ESCAPE-CLEARS-FILTER open 🟩 LOW — since inception Escape in input mode clears the entered text instead of cancelling the request
KI-MENU-ISDESCENDANT-ROOT-ALWAYS open 🟩 LOW — since inception isDescendantOf reports every non-root id as a descendant of root, including ids absent from the menu
KI-MENU-ITEM-PROTOTYPE-LEAK open 🟩 LOW — since inception Map reads walk Object.prototype: item(), results maps, providersLoaded treat constructor/toString as real entries
KI-MENU-ITEMS-KEY-AMBIGUITY open 🟩 LOW — since inception A flat menu containing an entry id ‘items’ is parsed as a wrapper and every sibling entry is silently discarded
KI-MENU-JSONC-ARRAY-ROOT open 🟩 LOW — since inception parseMenuJsonc reads a top-level JSON array as entries with ids 0, 1, … (omacom/omarchy#13492)
KI-MENU-JSONC-CR-LINE-ENDINGS open 🟩 LOW — since inception A whole-line comment in a CR-only menu file swallows the rest of the file
KI-MENU-JSONC-INLINE-COMMENT open 🟩 LOW — since inception stripJsonc removes only whole-line // comments; an inline comment tail empties the whole file (omacom/omarchy#13493)
KI-MENU-JSONC-STRIP-GAPS open 🟩 LOW — since inception stripJsonc has no block-comment pass: a /* */ comment empties the whole file
KI-MENU-KEYBINDINGS-NO-TIMEOUT reviewed 🟩 LOW — since inception Keybindings menu build has no deadline on hyprctl binds or xkbcli compile-keymap; a stalled callee blocks the menu
KI-MENU-KEYBINDINGS-SENDKEY-UP-FAIL-STUCK open 🟩 LOW — since inception Refused key-up after an accepted key-down leaves a synthetic key stuck down and skips the sendshortcut fallback
KI-MENU-LINK-SINGLE-HOP open 🟩 LOW — since inception openRoute follows a link one hop and never re-inspects the target kind: link-to-action opens as a menu
KI-MENU-MERGE-OVERRIDE-WIPES-DEFAULTS open 🟩 LOW — since inception normalize-before-merge wipes unspecified defaults: a label-only user entry erases action/aliases/guards
KI-MENU-MERGE-PROTOTYPE-IDS open 🟩 LOW — since inception mergeMenuSources stores prototype-named ids but drops them from itemOrder - the row is written and never rendered
KI-MENU-MERGE-STALE-ORDER-ALIASED-ROWS open 🟩 LOW — since inception mergeAppRows/swapProviderRows keep stale .order values and mutate caller-owned rows in place
KI-MENU-NORMALIZE-EDGE-CASES open 🟩 LOW — since inception normalizeItem edge cases: null parent kept, boolean guards preserved, action:0 mis-kinded, numeric labels
KI-MENU-OPEN-LEAVES-CONFIRM open 🟩 LOW — since inception A menu summon leaves a pending uninstall question on top of the new prompt
KI-MENU-OPEN-NULL-PAYLOAD open 🟩 LOW — since inception open() throws on a JSON null payload: parse succeeds, the catch does not run, the property read throws
KI-MENU-OPEN-QUADRATIC open 🟩 LOW — since inception Opening a select menu walks its rows quadratically (omacom/omarchy#10601)
KI-MENU-PATH-HELPERS-COERCION open 🟩 LOW — since inception pathFor coerces a null parent to the id ’null’/‘0’ row while parentPathFor returns empty
KI-MENU-PENDING-INITIAL-MENU-DEAD open 🟩 LOW — since inception pendingInitialMenu is stored and never read: a route summoned before the JSONC loads opens root and stays there
KI-MENU-PROVIDER-PARTIAL-COMMIT open 🟩 LOW — since inception Failed/killed providers commit their partial stdout and stay marked loaded; apps provider loads with no AppLibrary
KI-MENU-PROVIDER-SLUG-COLLISION-DROPPED open 🟩 LOW — since inception Provider rows colliding with a static id are silently dropped: takenIds only records batch-minted ids
KI-MENU-REQUEST-LIFECYCLE open 🟩 LOW — since inception dmenu request lifecycle drops waiters on re-summon, on a busy resultProc, and for doneFile-only requests
KI-MENU-RESOLVE-ROUTE-FOLDING open 🟩 LOW — since inception resolveRoute folds the input before the exact-id lookup and returns the normalized string as fallthrough
KI-MENU-REVEAL-CURSOR-PEEK open 🟩 LOW — since inception revealCursor loses the directional peek: an uninstantiated delegate skips it and the underhang write undoes it
KI-MENU-SEARCH-SCORE-CRASH-NAN open 🟩 LOW — since inception searchScore throws on a label-less merged row and returns a NaN rank that displayRow coerces to the best tier
KI-MENU-SEARCH-SCORE-RANKING open 🟩 LOW — since inception searchScore ranking anomalies: apps promoted in-tier, root exact-labels swamped, multi-term matches collapse
KI-MENU-SEARCH-TEXT-NORMALIZATION-MISSES open 🟩 LOW — since inception Search text misses: whole-word description matching drops punctuation-glued words and hyphenated alias forms
KI-MENU-SELECT-GEOMETRY-INT-COERCION open 🟩 LOW — since inception Geometry flags silently coerce non-numeric and flag-like values: –width abc summons width 0
KI-MENU-SELECT-HANDSHAKE-TMP-LEAK open 🟩 LOW — since inception Failed second mktemp leaks the selection handshake temp file: cleanup trap installed only after both files exist
KI-MENU-STICKY-FONTFAMILY open 🟩 LOW — since inception Payload fontFamily is sticky: a later open that omits it keeps the previous caller’s font
KI-MENU-SUMMON-ACTION-EMPTY-PAYLOAD open 🟩 LOW — since inception summonAction rewrites an explicitly empty quoted payload to {} - the in-process summon diverges from the bash bytes
KI-SLEEP-LOCK-BUDGET-ARG-OCTAL open 🟩 LOW — since inception argv budget with a leading zero (08/09) bypasses the validation guard via an octal arithmetic error
KI-SLEEP-LOCK-DEADLINE-INVARIANT-GAPS open 🟩 LOW — since inception Header invariant ’every call bounded by the budget remainder’ unenforced on three external calls

6. Historical Coverage Backfill — bugs fixed in prior releases, coverage added this cycle

(internal) Bugs both introduced AND fixed before the baseline — not in the audited window. Listed only to record the coverage (requirement + tripwire) this audit added so they cannot silently regress.

These bugs were both introduced and fixed before the baseline — this release did not introduce them and they are not in the audited window; listed here only to record the coverage (requirement + tripwire) this audit added so they cannot silently regress.

No historical-backfill defects in scope.

Worst-case rollup — obligation consequences

Requirements graded by their worst-case consequence per obligation class, severity-descending. Each row pairs an authored consequence (or a catalog-generic fallback, marked) with the class it grades. Consequence severity is authored — the catalog cannot silently promote or demote a project’s judgment.

REQ Class Severity Rollup Consequence
SYS-REQ-260922-6642 error_handling high high an action script that neither performs its side effect nor refuses loudly: the menu closes (the row activation consumed the click), nothing happens, and the user cannot tell success from failure - silent wrong-target execution is this project documented historical bug class (wrong same-named plugin enabled), which is why the loud-refusal half of the contract is graded high
SW-REQ-260929-REJT error_handling medium medium a converter that fails for an environmental reason rather than a file reason (e.g. ffmpegthumbnailer briefly missing during a partial upgrade, or a transient ENOSPC) records a standing .failed marker, and the video row stays suppressed on every later open until the file signature (size+mtime) changes - the marker conflates file defect with environment defect
SW-REQ-260929-THMB external_call_timeout_bounded medium medium vipsthumbnail runs with no timeout wrapper: a still image that stalls vips (corrupt/pathological file, stalled mount) wedges its fan-out lane forever; in –preload mode drain_pending_thumbnails runs before the picker opens, so enough wedged stills block the image picker open, and lazy opens leak one orphaned vipsthumbnail per open into the menu process
SYS-REQ-260922-0M8A atomicity medium medium a provider rerun that swaps rows in place loses the write (QML var-property writes are occasionally dropped): orphan ids linger in itemOrder with no item behind them, the next merge carries the orphan forward, and the launcher lists the same app twice - the exact historical defect the fresh-object merge semantics exist to prevent
SYS-REQ-260922-X6Z5 error_handling medium medium the summoned picker surface dies after a successful select IPC and before writing the answer file: the synchronous caller waits on a file that will never appear - the reproduced poll-deadlock class; the bound is owned at the dmenu children (9ABD/Q6ZS) as a KI-tracked deferral on KI-MENU-SELECT-POLL-DEADLOCK, so the parent records the decision rather than duplicating the debt row
SYS-REQ-260927-WC89 error_handling medium medium the Lock row activation closes the menu and forks omarchy-system-lock, which then fails silently (binary absent after a partial sync, or the lock component refuses without a notification surface): the menu is already dismissed so no error reaches the user, and the user walks away from a session they believe locked - impact high, likelihood near zero (the lock binary is a default-set runtime invariant), graded medium on impact times the one-way visibility loss; the callees own lock engagement and its failure surfacing (SYS-REQ-260912-T0XP family, reviewed in batch A)
SW-REQ-260929-REJT malformed_input low medium a corrupt video that crashes ffmpegthumbnailer with a non-timeout status is marker-suppressed until edited; acceptable by design, but a file whose size+mtime are restored (touch -d) after a real repair re-inherits the stale marker
SW-REQ-260929-B8N9 malformed_input low low an id that names an Object.prototype member (constructor, toString, valueOf - all pure a-z, so slugify preserves them and a desktop app literally named Constructor gets slug id constructor) escapes the
SW-REQ-260929-DXFJ edge_case low low the freeze capture lands while the active filter has zero visible rows: maxRowsHeight pins at 0 and cardTop pins at the centered position, so the card grows downward from a top computed for an empty card until the menu closes - a cosmetic wedge the freeze-once semantics makes sticky for the whole open
SW-REQ-260929-T378 edge_case low low synthetic hover churn under a stationary pointer (a redraw loop or a stray device emitting move events with sub-threshold deltas) repeatedly re-enters selectFromPointer; the gate exists precisely so this cannot walk the selection, but a gate threshold crossed by accumulated sub-threshold jitter across one event burst would land the cursor on a row the user never aimed at - the disarm enumeration (keyboard nav, filtering, menu transition, delete dialog, open) must keep covering every interaction that should reset intent
SYS-REQ-260922-J0AN error_handling low low the dispatcher exec fails (omarchy-shell not running, socket refusal): the keybind or script caller sees a one-line error on the invoking terminal and no menu - recoverable and loud, graded low because refusal is immediate rather than hung, and the verb surface is fixed (toggle/summon/close/refresh/ping) with jq –arg payload construction making payload injection structurally impossible
SYS-REQ-260922-P708 boundary low low a drill-down or filter rebuild lands the cursor on a row that is now disabled (row set changed under the held selection index): the user presses Enter and the activation targets a row that renders dimmed - the contract forbids cursor-on-disabled and the children guard it (disabled rows skipped on cursor moves, no parked cursor when all rows are disabled), so the residual is only a rebuild racing an open dialog, graded low
SYS-REQ-260922-PPDW error_handling low low one syntax slip in the user menu JSONC (unbalanced brace a hundred rows in) silently drops the ENTIRE user extension for that session: parseMenuJsonc catches and returns [], the menu renders defaults only, and no diagnostic anywhere tells the user their customization was discarded - fail-visible only by absence, recovery documented but undiscoverable
SYS-REQ-260922-R8DQ boundary low low route precedence ambiguity: a user-declared alias that equals another item exact id (alias power on the item whose id is also power, or a slugified app claiming a menu id) flips which entry an alias route opens - resolution iterates itemOrder, so merged order (default-then-user, provider swaps) decides the winner; the exact-id-first partition and single-claim merge keep the wrong-target window at config-authoring time, graded low

Appendix: Entity Detail

One record per entity shown in this profile. Headings are the verbatim entity id, so the in-table links above resolve here.

KI-APPLY-LOCK-EXPORTED-FUNCTIONS-ROOT

KI-LOCK-PAM-FLIP-ENGAGES-LOCK

KI-260930-2FBE

KI-APPLY-LOCK-FPRINT-GATE-FAIL-OPEN

KI-APPLY-LOCK-PAM-NONATOMIC-WRITE

While tee writes, the live path holds only a prefix of the new stack, and the previous stack is already gone. An interrupted run can stop in that window: a killed installer or update, a lost session, or a power cut. The lock screen then authenticates against a torn stack. A torn password stack can lack the pam_unix line, so password unlock fails until the helper runs again. A torn fingerprint stack can cut the pam_fprintd line short.

The window is short, because one process writes a few hundred bytes. The likelihood is low, but the impact on a lock screen is high. pocs/apply-lock-pam-torn-write.sh reproduces the defect on the real helper. It pauses each write after 60 bytes and kills the run. The live file then holds the torn 60-byte prefix of 549 and 122 bytes.

The seeded previous stack is gone, and the inode does not change. The control arm shows that an uninterrupted run writes both stacks byte-identical to the heredocs.

Do the same for omarchy-lock-fingerprint, and optionally fsync before the rename. Then remove the atomic_write deferrals on SYS-REQ-260912-JW2J and SW-REQ-260912-Y0WT and add witnesses. Close criterion: pocs/apply-lock-pam-torn-write.sh flips red, because the interrupted write leaves the previous complete stack on the live path.

KI-APPLY-LOCK-TARGET-USER-DEGRADES-ROOT

KI-LOCK-FPRINT-PROBE-FAIL-OPEN

KI-LOCK-SPONTANEOUS-UNLOCK-FAIL-OPEN

KI-MENU-IMAGES-VIPS-NO-TIMEOUT

KI-MENU-JSONC-COMMA-IN-STRING

JSON.parse accepts the rewritten text, so nothing fails. The label “x, ]y” renders as “x ]y”. The action “mv f{.bak,}” runs as “mv f{.bak}” with the user privileges. Upstream issue: omacom/omarchy#13250. Report intake validated it (report cmulr8l6h0i461gw40vqqv64c).

KI-MENU-JSONC-UNICODE-WHITESPACE

Anywhere else between tokens, JSON.parse throws. The catch then returns an empty item set for the whole file. A user extension pasted from a web page or a word processor often carries no-break spaces. That file silently loses every entry, with no diagnostic.

We checked this live under Quickshell 0.3.1. FileView keeps these characters as read and drops only a leading byte-order mark. The real MenuModel.js parses a file with one U+00A0 or U+000B between tokens to 0 rows. pocs/menu-jsonc-unicode-whitespace.sh reproduces it for all 21 characters against an ASCII-space control.

test/shell.d/menu-test.sh pins it as a green tripwire.

KI-MENU-KEYBINDINGS-CODE-REWRITE-OVERREACH

KI-MENU-KEYBINDINGS-CSV-DESC-COMMA

KI-MENU-KEYBINDINGS-FUNC-BIND-NO-DISPATCH

KI-MENU-KEYBINDINGS-SCAN-DOFILE-ABORT

KI-MENU-KEYBINDINGS-STALE-LUA-CACHE

KI-MENU-KEYBINDINGS-STDERR-FAILS-DISPATCH

KI-MENU-SELECT-POLL-DEADLOCK

KI-MENU-SELECT-SUMMON-UNBOUNDED

KI-SLEEP-LOCK-BUDGET-NONPOSITIVE

KI-LOCK-FPRINT-START-FAIL-NO-RETRY

KI-LOCK-PAM-ERROR-DOUBLE-COUNT

KI-LOCK-PROBE-HYPRCTL-NO-TIMEOUT

The stranded-lock recovery path calls this probe. That path then waits on a probe that never reports, so recovery makes no progress for the duration of the stall. The Hyprland failsafe lock screen is the backstop, so the session stays locked. pocs/eh0k-hyprctl-monitors-no-timeout.sh reproduces the defect. With hyprctl stalled, an external 5s watchdog kills the real probe (rc=124). The control arms answer 0 (locked) and 1 (unlocked) immediately.

KI-LOCK-SCREENS-CHANGE-BLANK-LOST

KI-LOCK-STALE-POSTER-INPLACE-OVERWRITE

KI-MENU-APP-ACTIVATE-NULL-LIBRARY

KI-MENU-APPS-SORT-LOCALE

KI-MENU-CARET-COUNT-HIDDEN-CHILDREN

KI-MENU-CLI-EXIT-CODE-WRITE-RACES

KI-MENU-CLI-JQ-FAIL-LOOKS-SUCCESS

KI-MENU-DETAIL-WHITESPACE-QUERY

KI-MENU-DMENU-NAN-GEOMETRY

KI-MENU-FILEVIEW-FAILURE-ASYMMETRY

KI-MENU-FOLD-HEIGHT-EXCEEDS-AVAILABLE

KI-MENU-GOBACK-ROOT-STRAND

KI-MENU-GUARD-BATCH-NO-DEADLINE

One blocking guard expression keeps the whole batch alive indefinitely. Examples are a wait on a lock, a slow probe or a hung device query.

No later evaluation then starts. For the rest of the session the menu shows the last complete answer set. Rows stay checked, visible or dimmed for a state that no longer holds. A killed batch keeps the last complete set and does not adopt a half-read one. A when: hides a row only on an explicit false, so the failure shows stale rows, not hidden ones.

pocs/47t8-guard-batch-no-deadline.sh reproduces the defect. It runs the real evaluateGuards() and guardProc handlers from Menu.qml with the real MenuModel.guardScript(). The test adds a guard that waits on a held lock. At 4s the batch still runs with zero exits, and a re-evaluation spawns nothing (guardsPending=true).

A row’s checked answer stays false after its state turns true. The control arm shows a healthy batch that lands its answers and refreshes after a state flip.

Pair the fix with an explicit staleness policy for the answers of a killed batch. Then remove the SYS-REQ-260922-47T8 external_call_timeout_bounded deferral and add a witness. Close criterion: pocs/47t8-guard-batch-no-deadline.sh flips red, because the blocked batch exits inside the observation window.

KI-MENU-GUARD-BATCH-STALE-APPLY

KI-MENU-GUARD-ID-INJECTION-BATCH-ABORT

KI-MENU-INPUT-ESCAPE-CLEARS-FILTER

KI-MENU-ISDESCENDANT-ROOT-ALWAYS

KI-MENU-ITEM-PROTOTYPE-LEAK

KI-MENU-ITEMS-KEY-AMBIGUITY

KI-MENU-JSONC-ARRAY-ROOT

The default file and the user extension file use the same parser, and mergeMenuSources merges both. Upstream issue: omacom/omarchy#13492. Report intake validated it (report cmulr8j7z0hy31gw4pne8v6u4).

KI-MENU-JSONC-CR-LINE-ENDINGS

In such a file the first whole-line // comment runs to the end of the file. The pass deletes the rest of the document, JSON.parse fails, and parseMenuJsonc returns an empty item set. We checked this live under Quickshell 0.3.1. FileView keeps CR as read.

The real MenuModel.js parses a CR-only file with one comment line to 0 rows. LF and CRLF files parse correctly, and so do CR-only files without comments. pocs/menu-jsonc-cr-line-endings.sh reproduces it with LF, CRLF and comment-free controls. test/shell.d/menu-test.sh pins it as a green tripwire.

KI-MENU-JSONC-INLINE-COMMENT

One inline note in the user extension drops every user entry; in the default file it drops every row. docs/menu.md documents this limitation. Upstream issue: omacom/omarchy#13493. Report intake validated it (report cmulr8j7w0hy01gw4menggvbx).

KI-MENU-JSONC-STRIP-GAPS

KI-MENU-KEYBINDINGS-NO-TIMEOUT

On the stalled-hyprctl path the script calls hyprctl binds three times in sequence: cache key, cache refresh, and the uncached fallback after the refresh fails. A per-call bound therefore costs about three times its value. pocs/9dms-keybindings-no-timeout.sh reproduces both arms on the real script in –print mode. With hyprctl stalled, the build is still blocked at a 10s watchdog (rc=124). With xkbcli stalled, the build is still blocked at a 5s watchdog (rc=124). The control arm builds the stubbed bind row in about a second, with its keycode resolved through the stubbed keymap.

Then remove the SW-REQ-260922-9DMS external_call_timeout_bounded deferral and add a witness for the bounded paths. Close criterion: both stall arms of pocs/9dms-keybindings-no-timeout.sh finish inside their watchdogs, and the tripwire flips red.

KI-MENU-KEYBINDINGS-SENDKEY-UP-FAIL-STUCK

KI-MENU-MERGE-OVERRIDE-WIPES-DEFAULTS

KI-MENU-MERGE-PROTOTYPE-IDS

KI-MENU-MERGE-STALE-ORDER-ALIASED-ROWS

KI-MENU-NORMALIZE-EDGE-CASES

KI-MENU-OPEN-LEAVES-CONFIRM

KI-MENU-OPEN-NULL-PAYLOAD

KI-MENU-OPEN-QUADRATIC

A menu of N rows thus costs about N(N+1)/2 row visits. 231 rows take 232 height passes and 27,027 row visits. 462 rows take 463 passes and 107,415 visits.

The Super+K keybindings menu is the realistic large case. Upstream issue: omacom/omarchy#10601. Report intake validated it (report cmulr8ysi0jwr1gw4fjmt9khq). Upstream PR 10631 does not change the counts.

KI-MENU-PATH-HELPERS-COERCION

KI-MENU-PENDING-INITIAL-MENU-DEAD

KI-MENU-PROVIDER-PARTIAL-COMMIT

KI-MENU-PROVIDER-SLUG-COLLISION-DROPPED

KI-MENU-REQUEST-LIFECYCLE

finishRequest wipes requestActive and both paths BEFORE resultProc.running = true. Quickshell therefore ignores a command change while the previous write runs, and the new selection disappears (SX26/C14; the empty-selectionFile redirect variant is SX26/C15 and HFY2/C36).

KI-MENU-RESOLVE-ROUTE-FOLDING

KI-MENU-REVEAL-CURSOR-PEEK

KI-MENU-SEARCH-SCORE-CRASH-NAN

KI-MENU-SEARCH-SCORE-RANKING

KI-MENU-SEARCH-TEXT-NORMALIZATION-MISSES

KI-MENU-SELECT-GEOMETRY-INT-COERCION

KI-MENU-SELECT-HANDSHAKE-TMP-LEAK

KI-MENU-STICKY-FONTFAMILY

KI-MENU-SUMMON-ACTION-EMPTY-PAYLOAD

KI-SLEEP-LOCK-BUDGET-ARG-OCTAL

KI-SLEEP-LOCK-DEADLINE-INVARIANT-GAPS


Appendix: Data-Gap Analysis

Fields this report had to infer or reconstruct because the model does not carry them as first-class data. Occurrences = records hitting the gap in this run.

Field Severity Occurrences Came from Proposed model addition
KnownIssue.resolved_at lossy 0 inferred from history[].at of the entry whose detail matches a status->fixed transition add resolved_at string (RFC3339), set when proof known-issue edit --set-status fixed records the transition
KnownIssue.resolved_in blocking 0 reconstructed from non-model fixing_reference: key, else scavenged #PR/SHA from history detail or remediation prose add resolved_in string (fixing commit-ish); promote the de-facto fixing_reference YAML key into the model so it stops being dropped on load
KnownIssue.created_at lossy 0 inferred from the first history[] entry (action=created) add created_at string; age/SLA math currently depends on a history convention
ProblemReport.detected_at lossy 0 source.date, else regression.detected_at (when a date), else first history entry add a report-level detected_at; regression.detected_at is overloaded (sometimes a SHA, not a date)
ProblemReport.regression.dwell cosmetic 0 read directly when present; frequently empty — not derivable without bisect auto-derive dwell from introduced_in..fixed_in via git, or require it on regression closure