Software Requirements Specification

Omarchy Lock Dogfood

This document was auto-generated by ReqProof on 2026-10-03 03:26:08 UTC. Do not edit manually; regenerate from source requirements.

Table of Contents


1. Introduction

1.1 Purpose

External codebase audit

This document is intended for engineers, reviewers, program managers, and automated verification tools that need to understand and validate the requirements for Omarchy Lock Dogfood.

1.2 Scope

Incrementally model externally-owned source code, tests, and documentation before enforcing release gates.

FieldValue
Project NameOmarchy Lock Dogfood
Versionnot specified
Default Assurance LevelC
Total Requirements87
Total Components2
Generated2026-10-03 03:26:08 UTC

1.3 Definitions, Acronyms, and Abbreviations

TermDefinition
SRSSoftware Requirements Specification
FRETishFormal Requirements Elicitation Tool language — a restricted natural language for writing unambiguous requirements
LTLLinear Temporal Logic — a formal logic for specifying properties over time
FLIPFormal LTL-based Input Partitioning — NASA algorithm for generating MC/DC test cases from temporal logic formulas
MC/DCModified Condition/Decision Coverage — a structural coverage criterion required by DO-178C for Level A software
CoCoSpecCompositional Contract Specification — a Lustre-based contract language used by Kind2
Kind2 / JKindSMT-based model checkers for Lustre contracts used for realizability and consistency checking
MCPModel Context Protocol — a standardized interface for AI agent tool integration
NPR 7150NASA Procedural Requirements for Software Engineering
DALDesign Assurance Level (A = highest criticality, E = lowest)
DO-178CSoftware Considerations in Airborne Systems and Equipment Certification

1.4 References

DocumentDescription
NPR 7150.2DNASA Procedural Requirements for Software Engineering, NASA Office of the Chief Engineer, 2020
DO-178C / ED-12CSoftware Considerations in Airborne Systems and Equipment Certification, RTCA/EUROCAE, 2011
ISO/IEC/IEEE 29148:2018Systems and software engineering — Life cycle processes — Requirements engineering
Giannakopoulou et al.Formal Requirements Elicitation with FRET, RLSS 2020 (NASA Ames)
Mavridou et al.The Ten Lockheed Martin Cyber-Physical Challenges, IEEE S&P 2020

1.5 Overview

This document is organized as follows: Section 2 provides a general description of the product, its context, capabilities, users, constraints, and interface requirements (user interfaces, software component boundaries, and communication protocols). Sections 3 through 5 contain requirements organized hierarchically by specification level, with each level grouping requirements by component and category. Section 6 presents the verification status matrix showing formalization, realizability, and review status for each requirement. Section 7 provides a traceability matrix linking requirements to parent requirements, tests, and implementation artifacts. Section 8 summarizes gap analysis findings. Section 9 contains appendices with variable definitions.

2. General Description

2.1 Product Perspective

This section describes Omarchy Lock Dogfood in the context of its requirements. The product perspective is derived from the project configuration and the requirements captured in this specification; no product-specific positioning is asserted beyond what the project defines.

Stakeholder Perspectives

The following stakeholder personas describe the key users and their needs. Each stakeholder requirement captures a user story and acceptance criteria that decompose into formal system requirements.

PersonaRequirementDescriptionStory / Need
Omarchy user STK-REQ-260912-XJ5D The user shall lock the session on demand. The system shall lock the session before suspend. The session shall unlock only after a successful password or fingerprint authentication. As an Omarchy user, I want the session to lock reliably on demand and before suspend. An unattended machine must never expose an unlocked session.
Omarchy user STK-REQ-260922-XTNR Users reach system actions, settings, and applications through the Omarchy menu. Scripts pose picker and input prompts and read back the answer. Menu rows reflect current system state without stale or contradictory display. As an Omarchy user, I want every system action, setting, and application reachable through one menu. Its rows must reflect the machine's current state. I never want to hunt for a command or act on a stale row.

2.2 Product Functions

At a high level, Omarchy Lock Dogfood is organized into the following components, whose detailed functions are specified in Section 3:

Acceptance Criteria by Stakeholder Requirement

STK-REQ-260912-XJ5D (Omarchy user):

CriterionDescriptionVerification MethodDerived Reqs
AC-001 Locking the session (omarchy system lock or sleep path) results in a compositor-reported locked session, or a visible failure. test SYS-REQ-260912-T0XP, SYS-REQ-260912-HC86, SYS-REQ-260912-FRG0, SYS-REQ-260912-JW2J, SYS-REQ-260912-H8A5, SYS-REQ-260927-WC89

STK-REQ-260922-XTNR (Omarchy user):

CriterionDescriptionVerification MethodDerived Reqs
AC-001 Opening the menu (omarchy menu toggle) presents the menu UI and routes summon/close verbs to the correct plugin targets. A pick in a script-driven select or input prompt returns the chosen answer to the calling script. test SYS-REQ-260922-J0AN, SYS-REQ-260922-X6Z5, SYS-REQ-260922-47T8, SYS-REQ-260922-0M8A, SYS-REQ-260922-6642, SYS-REQ-260922-P708, SYS-REQ-260922-PPDW, SYS-REQ-260922-R8DQ, SYS-REQ-260922-V7W6
AC-002 A menu entry whose label or action contains a comma before a closing brace or bracket keeps its text verbatim. The menu displays and executes it exactly as written. JSONC trailing-comma stripping must never mutate it silently. test SYS-REQ-260922-PPDW

2.3 User Characteristics

The following user classes (stakeholder personas) are derived from the stakeholder requirements captured for this project:

2.4 Constraints

The design constraints for Omarchy Lock Dogfood are the requirements classified as constraints; they are specified in full in Section 3 under each component's "Design Constraints". The assurance levels assigned to requirements in this specification determine the rigor of the verification evidence required.

2.5 Assumptions and Dependencies

The assumptions for Omarchy Lock Dogfood are the requirements classified as assumptions in this specification; they are specified in Section 3 alongside the guarantees that depend on them. Inter-component dependencies are captured by the interface definitions in Section 2.8 and the traceability links in Section 7.

2.6 Components

#ComponentRequirements
1lock21
2menu66

2.7 Variable Summary

Total variables across all components: 198

2.7b Specification Hierarchy

The project organizes requirements into a multi-level specification hierarchy. Each level represents a tier of decomposition from stakeholder needs down to implementation details.

LevelSpec PathTypePrefixRequirements
L0 specs/stakeholder stakeholder STK-REQ 2
L1 specs/system system SYS-REQ 15
L2 specs/software subsystem SW-REQ 70

Specification Hierarchy Diagram

graph TD
  n_specs_software["specs/software\nL2 #124; subsystem\n70 reqs"]
  n_specs_stakeholder["specs/stakeholder\nL0 #124; stakeholder\n2 reqs"]
  n_specs_system["specs/system\nL1 #124; system\n15 reqs"]

  n_specs_stakeholder --> n_specs_system
  n_specs_system --> n_specs_software

2.8 Interface Requirements

2.8.1 User Interfaces

User interface requirements for Omarchy Lock Dogfood, where applicable, are captured as interface-category requirements in Section 3.

2.8.2 Software Interfaces (Component Boundaries)

Caller Callee Type Signature Description Assumptions Guarantees
menu lock subprocess omarchy-system-lock() -> exit 0 The menu Lock row invokes the lock component's CLI entry point omarchy-system-lock with no arguments. The callee engages the session lock and exits 0. This is the only menu-to-lock interaction; lock never calls menu. Caller provides no arguments; PATH resolves omarchy-system-lock; a Hyprland session with omarchy-shell IPC answers the lock verb. Callee engages the session lock via omarchy-shell lock lock, resets keyboard layout, locks 1password when running, stops the ttfx screensaver, and exits 0.

Component Boundary Diagram

graph LR
  n_lock["lock"]
  n_menu["menu"]

  n_menu -->|subprocess| n_lock

2.8.3 Communication Interfaces

The communication protocols used between components are summarized by the interface types in the Software Interfaces table above (Section 2.8.2).

3. Stakeholder Requirements (L0)

3.1 lock

Requirements: 1 total (1 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

STK-REQ-260912-XJ5D review shall Guarantee DAL-C
Description: The user shall lock the session on demand. The system shall lock the session before suspend. The session shall unlock only after a successful password or fingerprint authentication.
Rationale: A session left unlocked exposes the user's data. Suspend without a secure lock is the highest-risk case because the machine sleeps unattended.
Strategy: informal
Verification Method:
Verified: No

3.2 menu

Requirements: 1 total (1 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

STK-REQ-260922-XTNR review shall Guarantee DAL-C
Description: Users reach system actions, settings, and applications through the Omarchy menu. Scripts pose picker and input prompts and read back the answer. Menu rows reflect current system state without stale or contradictory display.
Rationale: The menu is the primary UX surface of omarchy and its top churn/bug hotspot. bin/omarchy-menu history shows 304 commits, 13 bug fixes, and 3 cascade episodes. Its rows make claims about system state that must not lie.
Strategy: informal
Verification Method:
Verified: No

4. System Requirements (L1)

4.1 lock

Requirements: 5 total (5 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

SYS-REQ-260912-FRG0 review shall Guarantee DAL-C
FRETish: when lock_state_queried the lock_component shall always satisfy lock_state_reported & stranded_lock_recovered
Description: The system shall report the compositor session-lock state as an exit code. Exit 0 means some monitor reports LOCK blocking it. Exit 1 means a monitor answered and none shows LOCK. Exit 2 means the probes cannot determine the state. When the shell detects a stranded lock left by a dead client and password PAM exists, the shell shall take the lock once. It shall record the recovery in the journal.
Rationale: ext-session-lock outlives its client. A restart leaves an orphan lock behind the Hyprland failsafe that nobody can unlock, so the shell must detect and reclaim it.
Strategy: fretish
SYS-REQ-260912-H8A5 review shall Guarantee DAL-C
FRETish: when update_run_requested the update_lock shall always satisfy update_lock_exclusive & held_state_reported
Description: While an Omarchy update runs, the system shall hold an exclusive update lock. A second update shall not enter its pre-update snapshot while the lock is held. The system shall answer whether the caller holds the update lock.
Rationale: Two concurrent updates can interleave snapshots and package transactions. The lock makes the second update fail before it can snapshot.
Strategy: fretish
SYS-REQ-260912-HC86 review shall Guarantee DAL-C
FRETish: when suspend_imminent the sleep_lock shall eventually satisfy lock_requested_first & (session_secure | unsecured_suspend_reported) & !(session_secure & unsecured_suspend_reported)
Description: When suspend is imminent, the system shall request the session lock before it reconciles clamshell state. The system shall bound the wait by a budget derived from the logind inhibitor window and capped at 12000 ms. The system shall report an unsecured suspend and fail when the budget expires before the session is secure.
Rationale: logind stops honouring the delay inhibitor after its window. A suspend that beats the lock leaves the session exposed, so the deadline must enforce itself.
Strategy: fretish
SYS-REQ-260912-JW2J review shall Guarantee DAL-C
FRETish: when lock_auth_config_run the apply_lock shall always satisfy password_pam_installed & (fingerprint_pam_installed | fingerprint_pam_removed) & !(fingerprint_pam_installed & fingerprint_pam_removed)
Description: The system shall install the PAM password stack for the lock screen. The system shall install the PAM fingerprint stack only when the target user has an enrolled fingerprint, and shall remove it otherwise. When started as root, the helper shall restrict PATH to trusted system directories and shall invoke fprintd-list only by its packaged absolute path.
Rationale: Install and upgrade callers start this helper as root. A user-writable PATH entry or a PATH-resolved fprintd-list would run attacker-controlled code with root privileges.
Strategy: fretish
SYS-REQ-260912-T0XP review shall Guarantee DAL-C
FRETish: when user_lock_requested the lock_component shall eventually satisfy session_lock_engaged & keyboard_layout_default & screensaver_stopped
Description: When the user locks the session, the system shall engage the session lock through the shell IPC. The system shall reset the keyboard layout to the default. The system shall stop the ttfx screensaver and wait for it to exit before closing its terminal. The system shall lock 1Password when it is running.
Rationale: bin/omarchy-system-lock is the user-facing lock entry point. It delegates the lock to the Quickshell lock plugin and cleans up interactive session state. Nominal floor: this guarantee is the positive-path lock engagement. STK-REQ-260912-XJ5D AC-001 exercises it. This child carries the nominal obligation class for the stakeholder checklist.
Strategy: fretish

4.2 menu

Requirements: 10 total (10 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

SYS-REQ-260922-0M8A review shall Guarantee DAL-C
FRETish: when provider_rows_arrive the menu_model shall eventually satisfy dynamic_rows_swapped
Description: Dynamic rows (apps, provider enumerations) replace their source's previous batch atomically: orphans dropped, duplicates listed once, static rows untouched.
Rationale: A lost in-place write once left orphan ids that compounded into duplicate launcher rows; the swap semantics exist to make that impossible.
Strategy: fretish
SYS-REQ-260922-47T8 review shall Guarantee DAL-C
FRETish: when guards_evaluated the guard_pipeline shall eventually satisfy system_state_reflected
Description: All when/checked/disabled expressions evaluate in one batched bash run whose per-item results drive row visibility, checkmarks, and dimming.
Rationale: The menu opens on the last evaluation's answers; per-row forks made the shipped menu spend over a second contradicting the state it describes.
Strategy: fretish
SYS-REQ-260922-6642 review shall Guarantee DAL-C
FRETish: when action_script_invoked the menu_action_scripts shall eventually satisfy intended_side_effect
Description: Menu action scripts (plugin picker, share, timezone, images, keybindings, file picker, emoji insert) perform their documented side effect or a loud, exit-coded refusal.
Rationale: These scripts are the menu's hands; silent wrong-target actions (e.g. enabling the wrong same-named plugin) are the historical bug class.
Strategy: fretish
SYS-REQ-260922-J0AN review shall Guarantee DAL-C
FRETish: when menu_invoked the menu_dispatcher shall eventually satisfy menu_presented
Description: omarchy-menu routes each verb (toggle/summon/close/refresh/ping) to the matching omarchy-shell IPC call so the menu opens, closes, refreshes, or answers ping.
Rationale: The dispatcher is the single entry point; every keybind and script reaches the menu through it.
Strategy: fretish
SYS-REQ-260922-P708 review shall Guarantee DAL-C
FRETish: when selection_made the menu_navigation shall eventually satisfy action_executed_or_submenu_opened
Description: Activating a row runs its action, follows its link, or drills into its submenu. The cursor never rests on a disabled row. Back navigation retraces the drill path.
Rationale: Navigation semantics define what Enter/click does; a cursor parked on a disabled row would activate nothing.
Strategy: fretish
SYS-REQ-260922-PPDW review shall Guarantee DAL-C
FRETish: when menu_sources_loaded the menu_model shall eventually satisfy item_tree_merged
Description: The default JSONC and the user extension merge into one ordered item tree: per-key user overrides, stable order, inferred kinds and parents, injected root.
Rationale: The merge defines what the menu shows; a lost or duplicated row here is user-visible on every open.
Strategy: fretish
SYS-REQ-260922-R8DQ review shall Guarantee DAL-C
FRETish: when route_given the menu_router shall eventually satisfy routed_to_intended_item
Description: A route string (exact id, declared alias, or normalized spelling) opens the item it denotes; unknown strings fall through as literal ids.
Rationale: Routes are user-facing (omarchy menu summon power); mis-resolution opens the wrong submenu or shadows menu items behind installed apps.
Strategy: fretish
SYS-REQ-260922-V7W6 review shall Guarantee DAL-C
FRETish: when search_entered the menu_search shall eventually satisfy matching_rows_ranked
Description: A filter query narrows to visible, selectable rows whose name or description matches every term, ranked by match quality.
Rationale: Search is the power-user path; ranking decides which row Enter activates.
Strategy: fretish
SYS-REQ-260922-X6Z5 review shall Guarantee DAL-C
FRETish: when picker_active & selection_made the dmenu_protocol shall eventually satisfy picker_answer_returned
Description: A script-driven select/input prompt delivers the picked value to the caller (glyph stripped, subtext kept as the stable key); cancellation reaches the caller as no-selection.
Rationale: Scripts block on the answer file; a lost answer or a glyph leaking into the result breaks every caller.
Strategy: fretish

Interface Requirements

SYS-REQ-260927-WC89 review shall Guarantee DAL-C
FRETish: when lock_row_activated the menu shall eventually satisfy system_lock_invoked
Description: The menu Lock row invokes the lock component's CLI entry point omarchy-system-lock with no arguments. The callee engages the session lock and exits 0. This is the only menu-to-lock interaction; lock never calls menu.
Rationale: The default menu config carries a Lock row whose action is omarchy-system-lock (default/omarchy/omarchy-menu.jsonc:38). This row is the single menu-to-lock call path; the lock component never invokes menu.
Strategy: fretish

5. Subsystem Requirements (L2)

5.1 lock

Requirements: 15 total (15 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

SW-REQ-260912-0Y70 review shall Guarantee DAL-C
FRETish: when held_state_queried the update_lock shall always satisfy held_true_only_for_owning_fd
Description: omarchy-update-lock held shall exit 0 only when OMARCHY_UPDATE_LOCK_FD names an open descriptor. That descriptor shall resolve to the update lock path, and flock shall take the lock on it.
Rationale: A bare lock-file existence check cannot tell this process's lock from another's. The descriptor identity is the proof of ownership.
Strategy: fretish
SW-REQ-260912-41VV review shall Guarantee DAL-C
FRETish: when fingerprint_sensor_configured the lock_view shall always satisfy fingerprint_indicator_tracks_sensor
Description: When fingerprint authentication is available, the lock view shall show the fingerprint indicator next to the password field. When no fingerprint sensor is available, the lock view shall reserve no space for the indicator.
Rationale: An indicator without a working sensor invites a touch that can never authenticate. Space reserved for a missing sensor shifts the password field.
Strategy: fretish
SW-REQ-260912-EH0K review shall Guarantee DAL-C
FRETish: when lock_state_queried the session_locked shall always satisfy exit_zero_on_lock & exit_one_on_answerable_unlocked & exit_two_on_undetermined
Description: omarchy-hyprland-session-locked shall exit 0 when any monitor lists LOCK in solitaryBlockedBy. It shall exit 1 when no monitor shows LOCK and at least one monitor is not blocked by WORKSPACE. It shall exit 2 when hyprctl fails or every monitor answer comes back undetermined.
Rationale: Hyprland stops at the first solitary blocker on a monitor with no workspace yet, so a missing LOCK there means the probe never asked. Callers that branch only on success treat 2 as unlocked.
Strategy: fretish
SW-REQ-260912-EKJP review shall Guarantee DAL-C
FRETish: when running_as_root the apply_lock shall always satisfy trusted_path_only
Description: When omarchy-apply-lock runs with EUID 0, it shall replace the inherited PATH with /usr/share/omarchy/bin:/usr/local/bin:/usr/bin:/bin before it runs any optional command.
Rationale: Install and upgrade callers can start this helper as root. An inherited PATH lets a user-writable directory supply root-executed commands.
Strategy: fretish
SW-REQ-260912-FAWV review shall Guarantee DAL-C
FRETish: when suspend_imminent the sleep_lock shall always satisfy budget_bounded & budget_fallback_on_invalid
Description: omarchy-system-sleep-lock shall derive the wait budget from the logind InhibitDelayMaxUSec property. It shall reserve one fifth of the window but at least 1000 ms for logind. It shall fall back to 5000 ms when reading the property fails, and cap the result at 12000 ms. When the caller passes an argument that is not a positive integer within the cap, the script shall ignore it and use the derived budget.
Rationale: The shipped drop-in raises the inhibitor window to 15 s, but only logind knows the active value. A hand-raised window must not strand a closed laptop in a bag.
Strategy: fretish
SW-REQ-260912-FVHS review shall Guarantee DAL-C
FRETish: when update_run_requested & lock_unavailable the update_lock shall always satisfy run_refused_with_diagnostic
Description: omarchy-update-lock run shall open the update lock file on a dedicated file descriptor. It shall print a diagnostic and exit 1 when flock cannot take the lock. It shall export the descriptor to the executed command.
Rationale: The executed update must hold the lock for its whole lifetime, so the script exports the descriptor rather than releasing it after acquisition.
Strategy: fretish
SW-REQ-260912-GGGS review shall Guarantee DAL-C
FRETish: when suspend_imminent the sleep_lock shall always satisfy lock_requested_before_clamshell_sync
Description: omarchy-system-sleep-lock shall request the session lock before it calls the clamshell reconciliation helper.
Rationale: A stuck Hyprland IPC call during a lid transition must not consume the lock window before Quickshell has begun securing the session.
Strategy: fretish
SW-REQ-260912-H2YF review shall Guarantee DAL-C
FRETish: when budget_expired_without_secure the sleep_lock shall eventually satisfy unsecured_reported & exit_failure
Description: When the budget expires before the session reports secure, omarchy-system-sleep-lock shall print an unsecured-suspend diagnostic on stderr. It shall then send a critical notification and exit 1. When the session reports secure within the budget, the script shall exit 0.
Rationale: logind suspends whether or not the wait succeeded. The notification on the unlock screen is the only way anyone finds out the session slept exposed.
Strategy: fretish
SW-REQ-260912-J8SX review shall Guarantee DAL-C
FRETish: when lock_requested & !password_pam_configured the lock_service shall always satisfy lock_denied_missing_pam
Description: When the lock IPC handler receives a lock request and /etc/pam.d/omarchy-lock-password is missing, the lock service shall answer missing-pam. It shall not engage the session lock.
Rationale: A lock engaged without a password PAM stack can never authenticate. Refusing the lock is the only outcome that cannot strand the user.
Strategy: fretish
SW-REQ-260912-MXQG review shall Guarantee DAL-C
FRETish: when user_lock_requested & ttfx_running the system_lock shall eventually satisfy ttfx_signalled & ttfx_wait_bounded
Description: When the user locks the session and the ttfx screensaver is running, omarchy-system-lock shall send SIGTERM to ttfx. The script shall wait up to 1 s for ttfx to exit before it finishes.
Rationale: ttfx handles SIGTERM asynchronously. Closing its terminal before it exits can leave a stuck full-screen process above the lock screen.
Strategy: fretish
SW-REQ-260912-ND55 review shall Guarantee DAL-C
FRETish: when idle_timeout_expired the lock_service shall always satisfy (blank_displays | password_auth_in_flight | timer_rearmed_after_suspend)
Description: When the idle blank timer expires during a locked session, the lock service shall blank the displays only when no password authentication is in flight. The armed fingerprint PAM shall not hold the display lit. When wall-clock time shows the timer froze through a suspend, the service shall re-arm the timer instead of blanking.
Rationale: A countdown frozen by suspend fires right after resume and would blank the freshly woken unlock screen under the user. The fingerprint PAM stays armed for the whole lock, so gating on the combined authenticating state would keep the panel lit until unlock.
Strategy: fretish
SW-REQ-260912-S154 review shall Guarantee DAL-C
FRETish: when fingerprint_enrollment_queried the apply_lock shall always satisfy fprintd_absolute_path_only
Description: omarchy-apply-lock shall test fingerprint enrollment by invoking /usr/bin/fprintd-list for the target user. The helper shall not resolve fprintd-list through PATH.
Rationale: A PATH-resolved fprintd-list would run attacker-controlled code as root during install or upgrade.
Strategy: fretish
SW-REQ-260912-WBS3 review shall Guarantee DAL-C
FRETish: when password_text_overflows the lock_view shall always satisfy dots_scaled_within_field
Description: When entered password text exceeds the field width, the lock view shall scale the password dots so the row stays inside the field. The lock view shall report the edited text to the service without an edit-feedback loop.
Rationale: An unbounded dot row lets a long password overflow the field and leak its length beyond the field edge.
Strategy: fretish
SW-REQ-260912-WJYM review shall Guarantee DAL-C
FRETish: when stranded_lock_detected & password_pam_configured the lock_service shall eventually satisfy stranded_lock_recovered_once & recovery_logged
Description: When the stranded-lock probe exits 0, the service holds no lock, and password PAM exists, the lock service shall take the session lock once. It shall log a lock-stranded recovery event.
Rationale: ext-session-lock outlives its client. Without recovery, a shell restart leaves an orphan lock that only the Hyprland failsafe covers and nobody can unlock.
Strategy: fretish
SW-REQ-260912-Y0WT review shall Guarantee DAL-C
FRETish: when fingerprint_not_enrolled the apply_lock shall always satisfy fingerprint_pam_removed
Description: When the target user has no enrolled fingerprint or /usr/bin/fprintd-list is not executable, omarchy-apply-lock shall remove /etc/pam.d/omarchy-lock-fingerprint. When an enrolled fingerprint exists, the helper shall install the PAM fingerprint stack.
Rationale: A stale fingerprint PAM stack without an enrolled finger would offer an authentication path that can never succeed and can shadow the password path.
Strategy: fretish

5.2 menu

Requirements: 55 total (55 guarantees, 0 assumptions, 0 constraints, 0 derived)

Functional Requirements

SW-REQ-260922-0W96 review shall Guarantee DAL-C
FRETish: when lua_binds_present the keybindings_menu shall eventually satisfy lua_binds_dispatchable
Description: Binds Hyprland reports as dispatcher __lua are shown with resolved keys from the source-derived cache and remain dispatchable.
Rationale: bin/omarchy-menu-keybindings lines 4-9 and the LUA_BIND_*_MAP population.
Strategy: fretish
SW-REQ-260922-2JZT review shall Guarantee DAL-C
FRETish: when plain_substitution_form the guard_pipeline shall eventually satisfy only_plain_form_substituted
Description: The rewrite touches only the plain $(reader) form, mapping it to the captured slot. command -v reader, VAR=x reader, and every other form runs the real command.
Rationale: MenuModel.js substituteGuardReaders lines 462-467 and the comment at 437-442.
Strategy: fretish
SW-REQ-260922-3JG5 review shall Guarantee DAL-C
FRETish: when all_rows_disabled the menu_navigation shall eventually satisfy no_cursor_parked
Description: When no row is selectable, the menu shows no cursor at all rather than parking one on a row Enter cannot run. The cursor returns the moment a row becomes selectable.
Rationale: Menu.qml settleCursor lines 547-551 and nextSelectable line 541.
Strategy: fretish
SW-REQ-260922-3T3F review shall Guarantee DAL-C
FRETish: when json_invalid the menu_model shall eventually satisfy empty_item_set & !parse_error_raised
Description: Unparseable input (after stripping), non-object JSON, and non-object entries yield an empty or skipped item set; no exception escapes the parser.
Rationale: MenuModel.js parseMenuJsonc. A crashing parser would take the whole menu down on a user edit. Upstream e332dc97 rejects scalar and null roots only; for..in walks a top-level JSON array root and renders phantom rows (KI-MENU-JSONC-ARRAY-ROOT, omacom/omarchy#13492).
Strategy: fretish
SW-REQ-260922-3VTN review shall Guarantee DAL-C
FRETish: when no_active_request the dmenu_protocol shall eventually satisfy menu_closes_silently
Description: finishRequest with no active request or no done file just closes the menu. It creates or truncates no files.
Rationale: Menu.qml finishRequest lines 118-121.
Strategy: fretish
SW-REQ-260922-4079 review shall Guarantee DAL-C
FRETish: when batch_killed the guard_pipeline shall eventually satisfy last_complete_set_kept & pending_reeval_runs
Description: The menu discards a guard batch that exits nonzero or by signal, keeping the last complete result set in effect. An evaluation that stood aside runs once the process exits.
Rationale: Menu.qml guardProc.onExited lines 1027-1063; a half-read batch would silently un-hide rows whose when: went unanswered.
Strategy: fretish
SW-REQ-260922-43HQ review shall Guarantee DAL-C
FRETish: when dirs_unchanged the image_selector shall eventually satisfy cached_rows_reused
Description: When the fast signature (directory path + mtime per image dir) matches, the script serves cached rows without rescanning image files.
Rationale: bin/omarchy-menu-images lines 116-123 (fast signature v3 compare at line 124).
Strategy: fretish
SW-REQ-260922-46HY review shall Guarantee DAL-C
FRETish: when entry_shape_declared the menu_model shall eventually satisfy kind_and_parent_inferred
Description: An entry with action is an action, with target a link, otherwise a menu. An undeclared parent derives from the dotted id (or root). Root's parent is empty.
Rationale: MenuModel.js normalizeItem lines 13-40.
Strategy: fretish
SW-REQ-260922-4EWA review shall Guarantee DAL-C
FRETish: when same_named_plugins the plugin_picker shall eventually satisfy pick_resolves_by_id
Description: Every picker row carries the plugin id as tab subtext. This tells same-named plugins apart on screen. The pick resolves to the id, which the verb command receives.
Rationale: bin/omarchy-menu-plugin lines 25-37 and 45.
Strategy: fretish
SW-REQ-260922-4VAV review shall Guarantee DAL-C
FRETish: when timezone_pick_cancelled the timezone_script shall eventually satisfy timezone_not_set
Description: Cancelling the timezone picker exits 1 before any timedatectl set-timezone invocation.
Rationale: bin/omarchy-menu-timezone line 7.
Strategy: fretish
SW-REQ-260922-50RE review shall Guarantee DAL-C
FRETish: when menu_open_called the menu_lifecycle shall eventually satisfy lifecycle_answered
Description: open(payload) dispatches on mode: select/input open the dmenu flow, anything else opens the resolved route. close() cancels. refresh() reloads both JSONC files and returns ok. ping() returns ok.
Rationale: Menu.qml open/close/refresh/ping lines 21-44 and openExistingMenu/openDmenu lines 837-881; this is the plugin lifecycle the dispatcher IPC reaches.
Strategy: fretish
SW-REQ-260922-74BZ review shall Guarantee DAL-C
FRETish: when route_input & !exact_id_match & !alias_match the menu_router shall eventually satisfy route_is_literal_input
Description: A route matching no id and no alias resolves to the literal input. A misspelling still attempts to open that id without a rewrite.
Rationale: MenuModel.js resolveRoute line 190; menu-test.sh pins 'no-such-route'.
Strategy: fretish
SW-REQ-260922-7NPE review shall Guarantee DAL-C
FRETish: when user_entry_overrides the menu_model shall eventually satisfy per_key_override_applied & root_injected
Description: A user entry overrides the default per key while keeping the row's original order slot. The model injects a root item with label Go when no source declares one.
Rationale: MenuModel.js mergeMenuSources lines 66-96; menu-test.sh pins override order.
Strategy: fretish
SW-REQ-260922-8CQ4 review shall Guarantee DAL-C
FRETish: when delete_key_on_app the menu_actions shall eventually satisfy uninstall_confirmed_flow
Description: Delete with the cursor on an app row opens an uninstall confirmation naming the app. Confirming removes the app through the shared app library and closes the menu. Cancelling closes the dialog and returns focus without removing anything. Non-app rows ignore the key.
Rationale: Menu.qml requestDeleteSelected/cancelDelete/confirmDelete lines 789-813 and Keys.onPressed line 1129.
Strategy: fretish
SW-REQ-260922-8ERH review shall Guarantee DAL-C
FRETish: when share_clipboard the share_script shall eventually satisfy clipboard_saved_to_temp & send_detached
Description: Clipboard mode writes the clipboard to a temp .txt file and sends all files through systemd-run --user --quiet --collect localsend. System cleanup owns the temp file so LocalSend can read it.
Rationale: bin/omarchy-menu-share lines 15-19 and 42-46.
Strategy: fretish
SW-REQ-260922-9ABD review shall Guarantee DAL-C
FRETish: when empty_selection the dmenu_protocol shall eventually satisfy exit_one_on_empty
Description: When the done file exists but the selection file is empty (cancel), the script prints nothing and exits 1.
Rationale: bin/omarchy-menu-select lines 95-98.
Strategy: fretish
SW-REQ-260922-9DMS review shall Guarantee DAL-C
FRETish: when keycode_binding the keybindings_menu shall eventually satisfy symbol_resolved
Description: A code:N binding shows the keysym resolved from the compiled keymap, or the built-in fallback table when xkbcli cannot resolve it; GRAVE displays as ~.
Rationale: bin/omarchy-menu-keybindings parse_keycodes lines 13-46.
Strategy: fretish
SW-REQ-260922-B757 review shall Guarantee DAL-C
FRETish: when rows_overflow the menu_layout shall eventually satisfy fold_signals_more
Description: When the rows do not fit, the list height ends mid-row: the clipped peek row tells the eye there is more below the fold. The height never lands exactly on a row boundary, and the card never exceeds 70 percent of panel height.
Rationale: Menu.qml foldedListHeight lines 167-179, availableRowsHeight lines 154-162, rowListHeight/dmenuRowListHeight lines 181-216; comments at 150-166 state the intent.
Strategy: fretish
SW-REQ-260922-B839 review shall Guarantee DAL-C
FRETish: when no_options_given the dmenu_protocol shall eventually satisfy usage_error_exit_one
Description: With no prompt, or no options from arguments or stdin, a usage diagnostic prints to stderr and the script exits 1.
Rationale: bin/omarchy-menu-select lines 17-20 and 65-68.
Strategy: fretish
SW-REQ-260922-C8HX review shall Guarantee DAL-C
FRETish: when finish_requested & prompt_dismissed the dmenu_protocol shall eventually satisfy done_only_written
Description: finishRequest with a null selection (Escape/cancel) creates only the done file, so the caller observes the cancel as an empty selection.
Rationale: Menu.qml finishRequest lines 129-133 and cancel lines 831-835.
Strategy: fretish
SW-REQ-260922-CYB9 review shall Guarantee DAL-C
FRETish: when route_input & !exact_id_match & alias_match the menu_router shall eventually satisfy route_is_alias_target
Description: Absent an exact id, a route equal to a declared alias resolves to the id of the item declaring the alias. Alias comparison lowercases and maps underscores to dashes.
Rationale: MenuModel.js resolveRoute lines 181-189; normalization at line 178 and 186.
Strategy: fretish
SW-REQ-260922-DE93 review shall Guarantee DAL-C
FRETish: when submenu_entered the menu_navigation shall eventually satisfy back_retraces_path
Description: Drilling in pushes the previous menu on the navigation stack. Backspace/Left pops it, or falls back to the parent menu when the stack is empty. Entering a menu clears the filter.
Rationale: Menu.qml setActiveMenu lines 729-742 and goBack lines 744-757.
Strategy: fretish
SW-REQ-260922-DQ9P review shall Guarantee DAL-C
FRETish: when query_terms_given the menu_search shall eventually satisfy all_terms_matched & row_hidden_from_results
Description: A row matches only when every query term appears in its name text (label, leaf id, aliases) or as a whole word in its description. Invisible and disabled rows never match.
Rationale: MenuModel.js matchesQuery lines 323-339; Menu.qml matchesQuery line 510-512 excludes disabled rows from search.
Strategy: fretish
SW-REQ-260922-E4J2 review shall Guarantee DAL-C
FRETish: when jsonc_has_comments_or_commas the menu_model shall eventually satisfy items_parsed
Description: The parser strips full-line // comments and trailing commas before JSON parsing, so the authored JSONC parses to its declared entries.
Rationale: MenuModel.js stripJsonc lines 1-5 and parseMenuJsonc lines 42-64.
Strategy: fretish
SW-REQ-260922-EFNR review shall Guarantee DAL-C
FRETish: when provider_reran the menu_model shall eventually satisfy previous_batch_replaced
Description: swapProviderRows drops exactly the rows carrying the re-run provider's providerMenu and appends the new batch, leaving static children and other providers' rows untouched.
Rationale: MenuModel.js swapProviderRows lines 140-165; a just-disabled plugin disappears from the Enable list on the next run.
Strategy: fretish
SW-REQ-260922-FGZQ review shall Guarantee DAL-C
FRETish: when finish_requested the dmenu_protocol shall eventually satisfy selection_and_done_written
Description: finishRequest with a selection writes the value to the selection file and creates the done file, shell-quoted, and only then closes.
Rationale: Menu.qml finishRequest lines 117-135.
Strategy: fretish
SW-REQ-260922-HR29 review shall Guarantee DAL-C
FRETish: when paths_given the file_picker shall eventually satisfy listing_shape
Description: The listing matches the requested formats case-insensitively, prunes dotfiles and dot-directories, and sorts rows by modification time descending. The script rejects a nonexistent path on stderr with exit 1.
Rationale: bin/omarchy-menu-file lines 28-48.
Strategy: fretish
SW-REQ-260922-JREH review shall Guarantee DAL-C
FRETish: when chooser_failed the share_script shall eventually satisfy critical_notification_exit_one
Description: A file chooser exit status above 1 sends a critical 'Could not share' notification and exits 1; an empty pick exits 0 silently.
Rationale: bin/omarchy-menu-share lines 28-38; command substitution preserves the chooser's real exit status.
Strategy: fretish
SW-REQ-260922-JRW1 review shall Guarantee DAL-C
FRETish: when guard_results_applied the menu_view shall eventually satisfy rows_hidden_or_marked_per_results
Description: Applied guard results drive the view. A row hides when its when: is false. A static submenu or link hides when no descendant is visible, while provider-backed menus stay visible. A checked:true or disabled:true row earns the check-mark label. A disabled row dims and skips the cursor.
Rationale: MenuModel.js isVisible lines 255-272, isDisabled lines 277-280, labelFor lines 284-288; menu-test.sh pins each arm.
Strategy: fretish
SW-REQ-260922-KRBH review shall Guarantee DAL-C
FRETish: when picker_verb_given the plugin_picker shall eventually satisfy verb_filter_applied
Description: enable offers disabled plugins; disable offers enabled canDisable plugins; clone offers first-party plugins no installed clone points back at; remove offers non-first-party plugins.
Rationale: bin/omarchy-menu-plugin lines 12-21; menu-plugin-test.sh pins each filter.
Strategy: fretish
SW-REQ-260922-MH9B review shall Guarantee DAL-C
FRETish: when signature_mismatch the image_selector shall eventually satisfy rows_rebuilt_and_cached
Description: When the fast signature differs, the script rebuilds rows from a full per-file scan and rewrites the rows cache plus signatures.
Rationale: bin/omarchy-menu-images lines 125-141 (full scan) and the cache write path.
Strategy: fretish
SW-REQ-260922-MP00 review shall Guarantee DAL-C
FRETish: when answer_file_written the dmenu_protocol shall eventually satisfy selection_printed
Description: Once the done file exists, the script prints a non-empty selection file to stdout.
Rationale: bin/omarchy-menu-select lines 91-97; same protocol in omarchy-menu-input lines 50-56.
Strategy: fretish
SW-REQ-260922-MQ37 review shall Guarantee DAL-C
FRETish: when guards_declared the guard_pipeline shall eventually satisfy one_line_per_guard
Description: The generated guard script holds exactly one if-line per declared when, checked, or disabled, each echoing <id>:<w|c|d>:<0|1>; items with no guard get none.
Rationale: MenuModel.js guardScript lines 478-491 and guardLine lines 469-472.
Strategy: fretish
SW-REQ-260922-N3RM review shall Guarantee DAL-C
FRETish: when resolved_kind_action the menu_router shall eventually satisfy action_runs_directly & menu_not_opened
Description: When a route resolves to an action item with a non-empty action, the action runs directly and no menu opens.
Rationale: Menu.qml openRoute lines 895-905; opening an action as a submenu would show an empty list.
Strategy: fretish
SW-REQ-260922-NM45 review shall Guarantee DAL-C
FRETish: when dmenu_option_picked the dmenu_protocol shall eventually satisfy glyph_stripped & subtext_returned
Description: A dmenu option may lead with a glyph TAB and trail a subtext TAB. The picker shows the glyph but never returns it. A subtext-bearing pick returns 'label TAB subtext' as the stable key.
Rationale: bin/omarchy-menu-select header lines 9-13; Menu.qml activateIndex lines 766-769.
Strategy: fretish
SW-REQ-260922-PRNV review shall Guarantee DAL-C
FRETish: when route_input & exact_id_match the menu_router shall eventually satisfy route_is_exact_id
Description: An exact id match wins over every alias. App rows are never routable, so an installed app's keywords cannot shadow a menu route (htop ships Keywords=system).
Rationale: MenuModel.js resolveRoute lines 177-191.
Strategy: fretish
SW-REQ-260922-Q6ZS review shall Guarantee DAL-C
FRETish: when select_invoked the dmenu_protocol shall eventually satisfy payload_shape_correct
Description: The select payload carries mode=select, prompt, options, selectionFile, and doneFile, plus integer width/maxHeight only when given. Options come from arguments or, with none and non-terminal stdin, from stdin lines.
Rationale: bin/omarchy-menu-select lines 29-87.
Strategy: fretish
SW-REQ-260922-QMWP review shall Guarantee DAL-C
FRETish: when nothing_actionable the plugin_picker shall eventually satisfy notification_and_exit_zero
Description: When no plugin matches the verb, the script sends a 'No plugin to <verb>' notification and exits 0 instead of opening an empty list.
Rationale: bin/omarchy-menu-plugin line 31.
Strategy: fretish
SW-REQ-260922-RGCV review shall Guarantee DAL-C
FRETish: when pkg_presence_asked the guard_pipeline shall eventually satisfy shadow_matches_pacman
Description: The prelude's omarchy-pkg-present/missing shadows agree with pacman -Q everywhere. This covers provides resolution, version constraints deferred to pacman, and the no-argument case (present true of nothing, missing not).
Rationale: MenuModel.js guardHelpers lines 422-435; pacman -Qi continuation-line parsing at lines 418-421.
Strategy: fretish
SW-REQ-260922-SJ7P review shall Guarantee DAL-C
FRETish: when match_quality_varies the menu_search shall eventually satisfy better_match_ranks_first
Description: Scores tier exact label, whole-word app name, label prefix, label substring, name text, then description. Menus and links promote by 2, apps demote by 5 within a tier. Final order breaks ties by depth then declaration order.
Rationale: MenuModel.js searchScore lines 341-363.
Strategy: fretish
SW-REQ-260922-SNZG review shall Guarantee DAL-C
FRETish: when verb_unknown the menu_dispatcher shall eventually satisfy diagnostic_printed & exit_two
Description: An unknown verb prints 'omarchy-menu: unknown verb' naming the verb to stderr and exits 2.
Rationale: bin/omarchy-menu lines 48-51; exit 2 keeps misuse distinct from runtime failure.
Strategy: fretish
SW-REQ-260922-SWFT review shall Guarantee DAL-C
FRETish: when timezone_picked the timezone_script shall eventually satisfy timezone_set_and_refreshed
Description: The script applies a picked timezone with sudo timedatectl set-timezone, refreshes the clock plugin, and sends a confirmation notification naming the new timezone.
Rationale: bin/omarchy-menu-timezone lines 8-10.
Strategy: fretish
SW-REQ-260922-T257 review shall Guarantee DAL-C
FRETish: when verb_known the menu_dispatcher shall eventually satisfy ipc_call_executed
Description: toggle, summon, close, refresh, and ping each exec the matching omarchy-shell IPC call. toggle and summon pass the route as a JSON payload. help prints usage and exits 0.
Rationale: bin/omarchy-menu lines 19-47.
Strategy: fretish
SW-REQ-260922-TKDP review shall Guarantee DAL-C
FRETish: when matches_span_menus the menu_search shall eventually satisfy sections_divided
Description: Search lists current-menu matches before deeper (drilldown) matches, with a divider section exactly when both groups are non-empty.
Rationale: Menu.qml rebuildDisplay lines 621-648.
Strategy: fretish
SW-REQ-260922-W17G review shall Guarantee DAL-C
FRETish: when reader_value_reused the guard_pipeline shall eventually satisfy reader_read_once
Description: A value command shared by several guards (e.g. omarchy-default-browser across seven rows) runs once per batch, captured eagerly before any guard line.
Rationale: MenuModel.js guardPrelude lines 443-456; a lazy memo would die in the $() subshell.
Strategy: fretish
SW-REQ-260922-XW52 review shall Guarantee DAL-C
FRETish: when resolved_kind_link the menu_router shall eventually satisfy link_target_followed
Description: When a route resolves to a link item, the menu opens at the link's target.
Rationale: Menu.qml openRoute lines 906-908.
Strategy: fretish
SW-REQ-260922-Y58B review shall Guarantee DAL-C
FRETish: when no_guards_declared the guard_pipeline shall eventually satisfy empty_guard_script
Description: When no item declares a guard, the guard script is empty and no guard process runs.
Rationale: MenuModel.js guardScript line 490; menu-guards-test.sh pins the empty case.
Strategy: fretish
SW-REQ-260922-Z48F review shall Guarantee DAL-C
FRETish: when cursor_moves the menu_navigation shall eventually satisfy disabled_rows_skipped
Description: Cursor movement lands on the next selectable row in the direction of travel, wrapping at the list ends. Movement steps over disabled rows.
Rationale: Menu.qml nextSelectable lines 530-542 and select lines 706-717.
Strategy: fretish
SW-REQ-260922-Z680 review shall Guarantee DAL-C
FRETish: when orphan_id_present | provider_reran the menu_model shall eventually satisfy orphans_dropped & id_listed_once & inputs_not_mutated
Description: mergeAppRows and swapProviderRows return fresh maps that drop orphan ids and the replaced batch. They list a duplicated incoming id once and never write into their input maps.
Rationale: MenuModel.js lines 98-165; the in-place write they replace was occasionally dropped by the QML engine and compounded into duplicate launcher rows.
Strategy: fretish
SW-REQ-260928-8VJQ review shall Guarantee DAL-C
FRETish: when action_is_bare_summon the menu_model shall eventually satisfy in_process_summon_equivalent
Description: A menu action may exactly match the bare-summon grammar: omarchy-shell shell summon <id>, plus an optional single-quoted payload. The payload carries no embedded quote and the id draws from [A-Za-z0-9._-]+. Such an action executes in-process via shell.summon(id, payload) instead of spawning bash. An absent payload defaults to an empty object literal, matching the bin/omarchy-shell argv default exactly. Any action outside that grammar falls back to the unchanged execDetached bash path. The fast path must preserve semantics: same plugin id, same payload bytes, same default.
Rationale: Upstream c231097d (#13435) added MenuModel.summonAction and the execAction fast path. bin/omarchy-shell:51 defaults a missing payload to '{}', exactly like match[2] || '{}'. The regex grammar is a strict subset of bash word-splitting here: the id charset excludes metacharacters, and the payload admits no embedded quote. A 10/10 edge battery on 2026-09-28 confirmed the equivalence. Exotic inputs fall back to bash.
Strategy: fretish
SW-REQ-260929-B8N9 review shall Guarantee DAL-C
FRETish: when item_requested the menu_model shall eventually satisfy item_by_id_resolved
Description: The merged item tree is addressable by id. An id present in the tree yields its item, and any other id yields null. Menu state then falls back to the root menu instead of a dangling entry.
Rationale: Menu.qml item lines 233-235; the by-id accessor over the merged tree used by guard evaluation, navigation fallbacks, and route/state lookups.
Strategy: fretish
SW-REQ-260929-DXFJ review shall Guarantee DAL-C
FRETish: when menu_interacted the menu_presentation shall eventually satisfy card_top_frozen
Description: After the first filter keystroke or submenu move, the card top edge and the maximum rows height freeze at their current values. The card then grows and shrinks downward instead of re-centering on every resize. Closing the menu clears the freeze, so the next open centers again.
Rationale: Menu.qml panel.freezeCardTop lines 1147-1152 and onShownChanged line 1163; presentation stability of the presented menu session, reset by the close lifecycle.
Strategy: fretish
SW-REQ-260929-REJT review shall Guarantee DAL-C
FRETish: when media_rejected the image_selector shall eventually satisfy rejection_marker_recorded
Description: A converter that refuses a video records an empty .failed marker keyed by the file content hash. Timeouts and kills write no marker, so a later open retries. A standing marker withholds the video row and keeps the rows uncached. Still images never produce markers, and a failed lazy generation leaves nothing behind.
Rationale: bin/omarchy-menu-images generate_thumbnail writes the marker, thumbnail_for hands it back, and is_video_path gates marker eligibility. Authored with SW-REQ-260929-THMB to resolve the family_under_modeled finding on the shared target.
Strategy: fretish
SW-REQ-260929-T378 review shall Guarantee DAL-C
FRETish: when pointer_moves_over_rows the menu_pointer shall eventually satisfy gated_row_selection
Description: Row selection follows the pointer only after it genuinely moves past the gate threshold. It never lands on a non-selectable row. Keyboard navigation, filtering, menu transitions, the delete dialog, and opening the menu disarm the gate. Synthetic hover churn under a stationary pointer therefore cannot move the selection.
Rationale: Menu.qml disarmPointer line 978 and selectFromPointer lines 982-987 via PointerMoveGate; pointer-driven selection is a distinct trigger from keyboard traversal (Z48F) and must not fight it.
Strategy: fretish
SW-REQ-260929-THMB review shall Guarantee DAL-C
FRETish: when thumbnail_missing the image_selector shall eventually satisfy thumbnail_generated
Description: The pipeline detects video paths by extension and dispatches each media file to a format-appropriate converter. Videos go to ffmpegthumbnailer under a timeout; still images go to single-threaded vipsthumbnail. A lazy open generates stills inside the menu process and queues videos for the fan-out. The queued fan-out fills every core with still images and gives videos one lane per four cores. A content-hash lock serializes the generators per file; the generator reaps an aged legacy directory lock and leaves a fresh one to its owner. The finished thumbnail lands at the content-hash cache path and its row serves it.
Rationale: bin/omarchy-menu-images is_video_path, generate_thumbnail, thumbnail_for, and drain_pending_thumbnails carry the thumbnail pipeline between the directory scan and the row cache. Authored with SW-REQ-260929-REJT to resolve the family_under_modeled finding on the shared target.
Strategy: fretish

6. Verification Status Matrix

Req ID Assurance Formalization Realizability Consistency Vacuity Code Coverage Documented Review
STK-REQ-260912-XJ5D C none Unchecked Unchecked — — in_review
STK-REQ-260922-XTNR C none Unchecked Unchecked — — in_review
SW-REQ-260912-0Y70 C valid Unchecked Unchecked — — in_review
SW-REQ-260912-41VV C valid Unchecked Unchecked — — in_review
SW-REQ-260912-EH0K C valid Unchecked Unchecked — — in_review
SW-REQ-260912-EKJP C valid Unchecked Unchecked — — in_review
SW-REQ-260912-FAWV C valid Unchecked Unchecked — — in_review
SW-REQ-260912-FVHS C valid Unchecked Unchecked — — in_review
SW-REQ-260912-GGGS C valid Unchecked Unchecked — — in_review
SW-REQ-260912-H2YF C valid Unchecked Unchecked — — in_review
SW-REQ-260912-J8SX C valid Unchecked Unchecked — — in_review
SW-REQ-260912-MXQG C valid Unchecked Unchecked — — in_review
SW-REQ-260912-ND55 C valid Unchecked Unchecked — — in_review
SW-REQ-260912-S154 C valid Unchecked Unchecked — — in_review
SW-REQ-260912-WBS3 C valid Unchecked Unchecked — — in_review
SW-REQ-260912-WJYM C valid Unchecked Unchecked — — in_review
SW-REQ-260912-Y0WT C valid Unchecked Unchecked — — in_review
SW-REQ-260922-0W96 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-2JZT C valid Unchecked Unchecked — — in_review
SW-REQ-260922-3JG5 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-3T3F C valid Unchecked Unchecked — — in_review
SW-REQ-260922-3VTN C valid Unchecked Unchecked — — in_review
SW-REQ-260922-4079 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-43HQ C valid Unchecked Unchecked — — in_review
SW-REQ-260922-46HY C valid Unchecked Unchecked — — in_review
SW-REQ-260922-4EWA C valid Unchecked Unchecked — — in_review
SW-REQ-260922-4VAV C valid Unchecked Unchecked — — in_review
SW-REQ-260922-50RE C valid Unchecked Unchecked — — in_review
SW-REQ-260922-74BZ C valid Unchecked Unchecked — — in_review
SW-REQ-260922-7NPE C valid Unchecked Unchecked — — in_review
SW-REQ-260922-8CQ4 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-8ERH C valid Unchecked Unchecked — — in_review
SW-REQ-260922-9ABD C valid Unchecked Unchecked — — in_review
SW-REQ-260922-9DMS C valid Unchecked Unchecked — — in_review
SW-REQ-260922-B757 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-B839 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-C8HX C valid Unchecked Unchecked — — in_review
SW-REQ-260922-CYB9 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-DE93 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-DQ9P C valid Unchecked Unchecked — — in_review
SW-REQ-260922-E4J2 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-EFNR C valid Unchecked Unchecked — — in_review
SW-REQ-260922-FGZQ C valid Unchecked Unchecked — — in_review
SW-REQ-260922-HR29 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-JREH C valid Unchecked Unchecked — — in_review
SW-REQ-260922-JRW1 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-KRBH C valid Unchecked Unchecked — — in_review
SW-REQ-260922-MH9B C valid Unchecked Unchecked — — in_review
SW-REQ-260922-MP00 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-MQ37 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-N3RM C valid Unchecked Unchecked — — in_review
SW-REQ-260922-NM45 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-PRNV C valid Unchecked Unchecked — — in_review
SW-REQ-260922-Q6ZS C valid Unchecked Unchecked — — in_review
SW-REQ-260922-QMWP C valid Unchecked Unchecked — — in_review
SW-REQ-260922-RGCV C valid Unchecked Unchecked — — in_review
SW-REQ-260922-SJ7P C valid Unchecked Unchecked — — in_review
SW-REQ-260922-SNZG C valid Unchecked Unchecked — — in_review
SW-REQ-260922-SWFT C valid Unchecked Unchecked — — in_review
SW-REQ-260922-T257 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-TKDP C valid Unchecked Unchecked — — in_review
SW-REQ-260922-W17G C valid Unchecked Unchecked — — in_review
SW-REQ-260922-XW52 C valid Unchecked Unchecked — — in_review
SW-REQ-260922-Y58B C valid Unchecked Unchecked — — in_review
SW-REQ-260922-Z48F C valid Unchecked Unchecked — — in_review
SW-REQ-260922-Z680 C valid Unchecked Unchecked — — in_review
SW-REQ-260928-8VJQ C valid Unchecked Unchecked — — in_review
SW-REQ-260929-B8N9 C valid Unchecked Unchecked — — in_review
SW-REQ-260929-DXFJ C valid Unchecked Unchecked — — in_review
SW-REQ-260929-REJT C valid Unchecked Unchecked — — in_review
SW-REQ-260929-T378 C valid Unchecked Unchecked — — in_review
SW-REQ-260929-THMB C valid Unchecked Unchecked — — in_review
SYS-REQ-260912-FRG0 C valid Unchecked Unchecked — — in_review
SYS-REQ-260912-H8A5 C valid Unchecked Unchecked — — in_review
SYS-REQ-260912-HC86 C valid Unchecked Unchecked — — in_review
SYS-REQ-260912-JW2J C valid Unchecked Unchecked — — in_review
SYS-REQ-260912-T0XP C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-0M8A C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-47T8 C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-6642 C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-J0AN C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-P708 C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-PPDW C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-R8DQ C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-V7W6 C valid Unchecked Unchecked — — in_review
SYS-REQ-260922-X6Z5 C valid Unchecked Unchecked — — in_review
SYS-REQ-260927-WC89 C valid Unchecked Unchecked — — in_review

7. Traceability

7.1 Coverage Summary (Per-Component Heat Map)

This table shows test coverage for each component's guarantee requirements. Color-coded: green = 80%+, amber = 40-79%, red = <40%.

Component Total Reqs Guarantees Tested Test Coverage Code Coverage Documented Gaps Suspect
lock 21 21 0 0% — 0% 21 0
menu 66 66 0 0% — 0% 66 0

Note: Test coverage reflects FLIP/MC-DC verified_by links. Assumptions and constraints are verified through consistency checking and integration analysis, not through FLIP test fixtures. Parent (satisfies) links apply only to cross-component integration requirements. Implementation (implemented_by) links to source code are optional traceability.

7.1b Cross-Level Traceability

Per-level coverage showing upward and downward traceability across the specification hierarchy.

Level Spec Prefix Total Reqs Upward Traces Downward Traces Coverage
L0 specs/stakeholder STK-REQ 2 0 2 100%
L1 specs/system SYS-REQ 15 15 15 100%
L2 specs/software SW-REQ 70 70 0 100%

Cross-Level Link Summary

From LevelFrom SpecTo LevelTo SpecLinks
L1 specs/system L0 specs/stakeholder 15
L2 specs/software L1 specs/system 71

7.2 Traceability Gaps

This section highlights requirements with missing traceability links. Requirements that are fully traced are omitted — only gaps are shown. If this section is empty, all requirements are fully traced.

STK-REQ-260912-XJ5D recommended guarantee — missing test link
guarantee requirement missing verified_by trace
STK-REQ-260922-XTNR recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-0Y70 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-41VV recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-EH0K recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-EKJP recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-FAWV recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-FVHS recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-GGGS recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-H2YF recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-J8SX recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-MXQG recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-ND55 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-S154 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-WBS3 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-WJYM recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260912-Y0WT recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-0W96 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-2JZT recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-3JG5 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-3T3F recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-3VTN recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-4079 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-43HQ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-46HY recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-4EWA recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-4VAV recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-50RE recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-74BZ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-7NPE recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-8CQ4 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-8ERH recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-9ABD recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-9DMS recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-B757 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-B839 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-C8HX recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-CYB9 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-DE93 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-DQ9P recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-E4J2 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-EFNR recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-FGZQ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-HR29 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-JREH recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-JRW1 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-KRBH recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-MH9B recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-MP00 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-MQ37 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-N3RM recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-NM45 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-PRNV recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-Q6ZS recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-QMWP recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-RGCV recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-SJ7P recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-SNZG recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-SWFT recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-T257 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-TKDP recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-W17G recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-XW52 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-Y58B recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-Z48F recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260922-Z680 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260928-8VJQ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260929-B8N9 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260929-DXFJ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260929-REJT recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260929-T378 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SW-REQ-260929-THMB recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260912-FRG0 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260912-H8A5 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260912-HC86 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260912-JW2J recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260912-T0XP recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-0M8A recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-47T8 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-6642 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-J0AN recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-P708 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-PPDW recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-R8DQ recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-V7W6 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260922-X6Z5 recommended guarantee — missing test link
guarantee requirement missing verified_by trace
SYS-REQ-260927-WC89 recommended guarantee — missing test link
guarantee requirement missing verified_by trace

8. Gap Analysis Summary

87
Total Requirements
98%
Parent Traceability
0%
Test Traceability
0%
Implementation Traceability

Identified Gaps (Missing Links Only)

Only requirements missing expected links are shown below. This gap-focused view highlights what needs action rather than listing all links.

Req IDTypeMissingSeverityMessage
STK-REQ-260912-XJ5D guarantee test guarantee requirement missing verified_by trace
STK-REQ-260922-XTNR guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-0Y70 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-41VV guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-EH0K guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-EKJP guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-FAWV guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-FVHS guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-GGGS guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-H2YF guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-J8SX guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-MXQG guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-ND55 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-S154 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-WBS3 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-WJYM guarantee test guarantee requirement missing verified_by trace
SW-REQ-260912-Y0WT guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-0W96 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-2JZT guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-3JG5 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-3T3F guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-3VTN guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-4079 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-43HQ guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-46HY guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-4EWA guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-4VAV guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-50RE guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-74BZ guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-7NPE guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-8CQ4 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-8ERH guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-9ABD guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-9DMS guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-B757 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-B839 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-C8HX guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-CYB9 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-DE93 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-DQ9P guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-E4J2 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-EFNR guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-FGZQ guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-HR29 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-JREH guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-JRW1 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-KRBH guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-MH9B guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-MP00 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-MQ37 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-N3RM guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-NM45 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-PRNV guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-Q6ZS guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-QMWP guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-RGCV guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-SJ7P guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-SNZG guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-SWFT guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-T257 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-TKDP guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-W17G guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-XW52 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-Y58B guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-Z48F guarantee test guarantee requirement missing verified_by trace
SW-REQ-260922-Z680 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260928-8VJQ guarantee test guarantee requirement missing verified_by trace
SW-REQ-260929-B8N9 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260929-DXFJ guarantee test guarantee requirement missing verified_by trace
SW-REQ-260929-REJT guarantee test guarantee requirement missing verified_by trace
SW-REQ-260929-T378 guarantee test guarantee requirement missing verified_by trace
SW-REQ-260929-THMB guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260912-FRG0 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260912-H8A5 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260912-HC86 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260912-JW2J guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260912-T0XP guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-0M8A guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-47T8 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-6642 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-J0AN guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-P708 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-PPDW guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-R8DQ guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-V7W6 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260922-X6Z5 guarantee test guarantee requirement missing verified_by trace
SYS-REQ-260927-WC89 guarantee test guarantee requirement missing verified_by trace

9. Appendices

9.1 Variable Definitions

lock

NameTypeDirectionDescriptionUnits
user_lock_requested bool input The user invoked the session lock entry point.
session_lock_engaged bool output The shell lock plugin engaged the ext-session-lock.
keyboard_layout_default bool output The keyboard layout was reset to the first layout.
screensaver_stopped bool output The ttfx screensaver was signalled and waited out.
suspend_imminent bool input logind signalled PrepareForSleep and the delay inhibitor is held.
lock_requested_first bool output The session lock was requested before clamshell reconciliation.
session_secure bool output The compositor reports the session lock as secure.
unsecured_suspend_reported bool output An unsecured suspend was diagnosed on stderr and notified as critical.
lock_auth_config_run bool input omarchy-apply-lock was invoked to configure lock authentication.
password_pam_installed bool output The PAM password stack for the lock screen is installed.
fingerprint_pam_installed bool output The PAM fingerprint stack is installed.
fingerprint_pam_removed bool output /etc/pam.d/omarchy-lock-fingerprint is removed.
lock_state_queried bool input A caller asked for the compositor session-lock state.
lock_state_reported bool output The lock state is reported as exit 0 locked, 1 unlocked, or 2 undetermined.
stranded_lock_recovered bool output A stranded compositor lock is reclaimed by the shell.
update_run_requested bool input A caller asked omarchy-update-lock to run a command under the update lock.
update_lock_exclusive bool output Only one update holds the update lock at a time.
held_state_reported bool output The held subcommand reports whether the caller holds the update lock.
user_lock_requested bool input The user invoked the session lock entry point.
ttfx_running bool input The ttfx screensaver process is running.
ttfx_signalled bool output SIGTERM was delivered to ttfx.
ttfx_wait_bounded bool output The wait for ttfx exit is bounded at 1 s.
suspend_imminent bool input logind signalled PrepareForSleep and the delay inhibitor is held.
lock_requested_before_clamshell_sync bool output The lock IPC request precedes the clamshell helper call.
budget_bounded bool output The wait budget is derived from logind InhibitDelayMaxUSec, reserves a fifth or at least 1000 ms, and is capped at 12000 ms.
budget_fallback_on_invalid bool output A missing or invalid budget argument falls back to the derived budget.
budget_expired_without_secure bool input The wait budget expired before the session reported secure.
unsecured_reported bool output The unsecured-suspend diagnostic and critical notification were emitted.
exit_failure bool output The script exits with status 1.
running_as_root bool input The helper runs with EUID 0.
trusted_path_only bool output PATH is replaced with trusted system directories before optional commands run.
fingerprint_enrollment_queried bool input The helper tests whether the target user has an enrolled fingerprint.
fprintd_absolute_path_only bool output fprintd-list is invoked only as /usr/bin/fprintd-list.
fingerprint_not_enrolled bool input No enrolled fingerprint exists or /usr/bin/fprintd-list is not executable.
fingerprint_pam_removed bool output /etc/pam.d/omarchy-lock-fingerprint is removed.
lock_state_queried bool input A caller asked for the compositor session-lock state.
exit_zero_on_lock bool output Exit 0 when any monitor lists LOCK in solitaryBlockedBy.
exit_one_on_answerable_unlocked bool output Exit 1 when no monitor shows LOCK and a monitor is not blocked by WORKSPACE.
exit_two_on_undetermined bool output Exit 2 when hyprctl fails or no monitor answer is determined.
stranded_lock_detected bool input The stranded-lock probe found a lock this shell did not take.
stranded_lock_recovered_once bool output The service takes the stranded lock exactly once.
recovery_logged bool output A lock-stranded recovery event is written to the journal log.
password_pam_configured bool input /etc/pam.d/omarchy-lock-password loaded successfully.
lock_requested bool input The lock IPC handler received a lock request.
lock_denied_missing_pam bool output The lock request is answered missing-pam and no session lock engages.
idle_timeout_expired bool input The idle blank timer expired.
blank_displays bool output The displays are blanked behind the lock.
password_auth_in_flight bool input A password authentication is in progress.
timer_rearmed_after_suspend bool output The blank timer is re-armed because wall-clock time shows a suspend gap.
password_text_overflows bool input The entered password dot row is wider than the password field.
dots_scaled_within_field bool output The password dots are scaled so the row stays inside the field.
update_run_requested bool input A caller asked omarchy-update-lock to run a command under the update lock.
lock_unavailable bool input Another process holds the update lock.
run_refused_with_diagnostic bool output The run is refused with a diagnostic and exit 1 when the lock is taken.
held_state_queried bool input A caller asked whether it holds the update lock.
held_true_only_for_owning_fd bool output held exits 0 only for the descriptor that owns the lock.
fingerprint_sensor_configured bool input A fingerprint sensor is enrolled and its PAM stack is installed.
fingerprint_indicator_tracks_sensor bool output The lock view shows the fingerprint indicator exactly when a sensor is configured.

menu

NameTypeDirectionDescriptionUnits
menu_invoked bool input A keybind or CLI invocation asked for the menu.
menu_presented bool output The menu card is visible with rows for the active route.
route_given bool input The caller passed a route string (item id or alias).
routed_to_intended_item bool output The menu opens at the item the route denotes.
menu_sources_loaded bool input The default and user JSONC menu sources were (re)loaded.
item_tree_merged bool output One ordered item tree exists with user overrides applied.
provider_rows_arrive bool input A provider (apps, fonts, power-profiles) delivered a new row batch.
dynamic_rows_swapped bool output The provider's rows replaced its previous batch atomically.
guards_evaluated bool input The guard batch ran for the current item set.
system_state_reflected bool output Row visibility, checkmarks, and dimming match the guard results.
search_entered bool input The user typed a filter query.
matching_rows_ranked bool output Visible matching rows are ranked by match quality.
selection_made bool input The user activated a row or answered a prompt.
action_executed_or_submenu_opened bool output A leaf action ran or the target submenu opened.
picker_active bool input The menu is answering a script's select/input prompt.
picker_answer_returned bool output The picked value was delivered to the calling script.
action_script_invoked bool input A menu action script (share, timezone, picker, images, keybindings, file) was invoked.
intended_side_effect bool output The script performed its documented side effect or refusal.
lock_row_activated bool input The user activated the menu's Lock row.
system_lock_invoked bool output The menu invoked the lock component's omarchy-system-lock entry point.
verb_known bool input The verb is one of toggle, summon, close, refresh, ping, or help.
ipc_call_executed bool output The matching omarchy-shell IPC call was exec'd with the route payload.
verb_unknown bool input The verb matches none of the known verbs.
diagnostic_printed bool output An unknown-verb diagnostic naming the verb is written to stderr.
exit_two bool output The script exits with status 2.
route_input bool input A non-empty route string was supplied.
exact_id_match bool input The normalized route equals an existing item id.
alias_match bool input The normalized route equals an alias of a non-app item.
route_is_exact_id bool output The route resolves to the exact id, ahead of any alias.
route_is_alias_target bool output The route resolves to the id of the item declaring the alias.
route_is_literal_input bool output The route resolves to the literal input string.
resolved_kind_action bool input The resolved item is an action with a non-empty action.
action_runs_directly bool output The action executes without opening the menu.
menu_not_opened bool output No menu card opens for the invocation.
resolved_kind_link bool input The resolved item is a link with a non-empty target.
link_target_followed bool output The menu opens at the link target.
jsonc_has_comments_or_commas bool input The JSONC source carries // comments or trailing commas.
items_parsed bool output The item set parses to the declared entries.
json_invalid bool input The source is not parseable JSON after stripping.
empty_item_set bool output The parse yields an empty item set.
parse_error_raised bool output A parse exception escapes to the caller.
entry_shape_declared bool input An entry carries action, target, or neither.
kind_and_parent_inferred bool output Kind is action/target/menu by shape; parent derives from the dotted id; root's parent is empty.
user_entry_overrides bool input The user source re-declares an id from the default source.
per_key_override_applied bool output Only the re-declared keys change; the row keeps its original order slot.
root_injected bool output A root item exists even when no source declares it.
orphan_id_present bool input itemOrder lists an id with no item behind it.
orphans_dropped bool output Orphan ids and previous app rows are absent from the merged result.
id_listed_once bool output The id appears exactly once in the merged order.
inputs_not_mutated bool output The merge writes no key into the maps it was handed.
provider_reran bool input The provider for a submenu produced a new batch.
previous_batch_replaced bool output Rows from the provider's previous batch are gone; other items are untouched.
guards_declared bool input Items declare when, checked, or disabled expressions.
one_line_per_guard bool output The guard script holds exactly one tagged if-line per declared guard.
no_guards_declared bool input No item declares any guard expression.
empty_guard_script bool output The guard script is empty.
reader_value_reused bool input Several guards read the same value command.
reader_read_once bool output The value command runs once per batch, captured before any guard.
pkg_presence_asked bool input A guard asks omarchy-pkg-present or omarchy-pkg-missing.
shadow_matches_pacman bool output The prelude's answer equals pacman -Q, including provides and the no-argument case.
plain_substitution_form bool input A guard reads a value as plain $(reader).
only_plain_form_substituted bool output Only the plain $(reader) form is substituted; every other form runs the real command.
batch_killed bool input The guard batch exited nonzero or by signal.
last_complete_set_kept bool output The previous complete guard results stay in effect.
pending_reeval_runs bool output An evaluation that stood aside runs after the in-flight batch exits.
query_terms_given bool input The user typed one or more query terms.
all_terms_matched bool output Every term matches the name text or a whole description word.
row_hidden_from_results bool output Invisible and disabled rows are absent from search results.
match_quality_varies bool input Rows match by exact label, prefix, substring, name text, or description.
better_match_ranks_first bool output Exact beats prefix beats substring beats name beats description; apps demote within a tier; ties break by depth then order.
matches_span_menus bool input Matches exist both in the active menu and in deeper submenus.
sections_divided bool output Current-menu rows list before drilldown rows with a divider between.
cursor_moves bool input The user moves the cursor up or down.
disabled_rows_skipped bool output The cursor lands on the next selectable row in the direction of travel, wrapping at the ends.
all_rows_disabled bool input Every row in the list is disabled.
no_cursor_parked bool output No cursor is shown (selectedIndex reset, cursor inactive).
submenu_entered bool input The user drilled into a submenu.
back_retraces_path bool output Back pops the navigation stack, or falls back to the parent menu; the filter clears.
dmenu_option_picked bool input The user picked a dmenu option.
glyph_stripped bool output The leading glyph is shown but never returned.
subtext_returned bool output A subtext-bearing option returns label TAB subtext.
select_invoked bool input omarchy-menu-select was called with a prompt and options.
payload_shape_correct bool output The summon payload carries mode, prompt, options, selectionFile, doneFile, and integer width/maxHeight when given.
no_options_given bool input No options were passed and stdin is not a terminal with zero lines.
usage_error_exit_one bool output A usage diagnostic prints to stderr and the script exits 1.
answer_file_written bool input The menu wrote the selection and done files.
selection_printed bool output The selection content is printed to stdout.
empty_selection bool input The selection file is empty at done time.
exit_one_on_empty bool output The script exits 1 without printing.
finish_requested bool input The QML side finishes an active request with a selection or null.
selection_and_done_written bool output The selection file holds the value and the done file is created.
done_only_written bool output Only the done file is created (cancellation).
no_active_request bool input finishRequest runs with no active request or no done file.
menu_closes_silently bool output The menu closes without touching any file.
picker_verb_given bool input omarchy-menu-plugin was called with enable, disable, clone, or remove.
verb_filter_applied bool output Only plugins matching the verb's rule are offered.
same_named_plugins bool input Two offered plugins share a display name.
pick_resolves_by_id bool output The pick acts on the row's id, not its name.
nothing_actionable bool input No plugin matches the verb's rule.
notification_and_exit_zero bool output A 'No plugin to <verb>' notification is sent and the script exits 0.
share_clipboard bool input omarchy-menu-share runs in clipboard mode.
clipboard_saved_to_temp bool output The clipboard is written to a temp .txt file that outlives the script.
chooser_failed bool input The file chooser exited with status above 1.
critical_notification_exit_one bool output A critical notification is sent and the script exits 1.
send_detached bool output LocalSend runs detached via systemd-run --user.
timezone_pick_cancelled bool input The timezone picker was cancelled.
timezone_not_set bool output timedatectl set-timezone is not invoked.
timezone_picked bool input A timezone was picked.
timezone_set_and_refreshed bool output The timezone is set, the clock plugin refreshes, and a confirmation notification is sent.
dirs_unchanged bool input The image directories' fast signature (path + mtime) matches the cache.
cached_rows_reused bool output Cached rows are used without rescanning image files.
signature_mismatch bool input The fast signature differs from the cache.
rows_rebuilt_and_cached bool output Rows are rebuilt from a full scan and the cache is rewritten.
lua_binds_present bool input Hyprland reports Lua binds as dispatcher __lua.
lua_binds_dispatchable bool output Lua binds appear with resolved keys and can be dispatched.
keycode_binding bool input A binding is reported as an XKB keycode (code:N).
symbol_resolved bool output The key shows as a symbol from the compiled keymap, or the built-in fallback; GRAVE shows as ~.
paths_given bool input omarchy-menu-file was given label, colon-separated paths, and formats.
listing_shape bool output Files match the formats, dotfiles and dot-directories are pruned, and rows sort by mtime descending.
prompt_dismissed bool input The user cancelled the prompt without picking (mirrors the system-layer variable).
guard_results_applied bool input The batched guard results (when/checked/disabled per id) landed in the view state.
rows_hidden_or_marked_per_results bool output Rows hide on when:false, static submenus with no visible descendant hide, provider menus stay, checked/disabled rows earn the check mark, disabled rows dim.
menu_open_called bool input The host called open(payloadJson) after summon.
lifecycle_answered bool output Payload mode dispatched (select/input/route), close cancels, refresh reloads both JSONC sources and answers ok, ping answers ok.
rows_overflow bool input The row list is taller than the height available to it.
fold_signals_more bool output The list height ends mid-row with a peek of the next row, capped at 70 percent of panel height, never exactly on a row boundary.
delete_key_on_app bool input The user pressed Delete with the cursor on an app row.
uninstall_confirmed_flow bool output A confirmation dialog opens; confirm removes the app through the app library, cancel restores focus without removing.
action_is_bare_summon bool input The action string matches the bare-summon grammar 'omarchy-shell shell summon <id> ['<payload>']' (id [A-Za-z0-9._-]+, payload single-quoted, no embedded quote).
in_process_summon_equivalent bool output The action runs in-process via shell.summon(id, payload) with bash-equivalent argv semantics (payload defaults to '{}' exactly as bin/omarchy-shell line 51 does for the 3-arg form); non-matching actions keep the unchanged execDetached bash path.
item_requested bool input A caller asks the item model for an item by id (guard evaluation, navigation fallback, or route/state lookup).
item_by_id_resolved bool output The by-id accessor answers with the id item when present and null otherwise; the answer is never a dangling entry.
menu_interacted bool input The user interacts with the open menu: the first filter keystroke or a submenu move.
card_top_frozen bool output The card top edge and max rows height hold at their interaction-time values; closing the menu clears the freeze.
pointer_moves_over_rows bool input The pointer genuinely moves past the PointerMoveGate threshold over the row list.
gated_row_selection bool output Pointer-driven selection ends in the gate-honored outcome: it lands on the hovered row only when the gate moved and the row is selectable, otherwise selection holds.
thumbnail_missing bool input A scanned media file has no thumbnail at its content-hash cache path.
thumbnail_generated bool output The thumbnail is generated by the format-appropriate converter and lands at the file content-hash cache path.
media_rejected bool input The converter refuses a video: it exits non-zero without a timeout or kill, or a .failed marker already stands for the file content hash.
rejection_marker_recorded bool output The rejection stands recorded and honored: the .failed marker keyed by the video hash exists, the video offers no row, and the rows stay uncached.