Proof Portal
Omarchy
ProbeLabsviewing a historical runA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
String-blind trailing-comma strip silently mutated in-string commas in menu labels and actions
This defect has been fixed and verified.
Description
The issue as recorded.
MenuModel.js stripJsonc used the string-blind regex /,(\s*[}\]])/g to strip JSONC trailing commas. Because \s* matches zero characters and the regex never tracked string literals, a comma inside a string value followed by } or ] (with any amount of whitespace, including none) was deleted even though it was data. JSON.parse accepts the stripped text, so nothing ever surfaced an error: the corruption was silent. Two observed failure modes. Mode (a) display corruption: a label "x, ]y" rendered as "x ]y". Mode (b) command mutation, the realistic payload: an action "mv f{.bak,}" became "mv f{.bak}" (brace expansion destroyed; mv then targets a literal filename) and "awk '{print $1, }'" became "awk '{print $1 }'" (output format silently changed for downstream pipelines). omarchy-menu executes action strings with the invoking user's full privileges, so a mutated command runs mutated with no warning. The defect did not escalate privilege - the user authors the config - but it violated the explicit-configuration contract invisibly. Reproduced old-vs-new on 2026-09-27 (research-delta doc); fixed on this branch by the string-aware single-pass scanner.
Affected requirements
The requirement(s) this issue violates — click through to the spec.
Severity, explained
Why this is rated the way it is — and the scoring signals behind the rating (each ⓘ explains the term).
- risk area
- Config Behavior
Where it is
The code this defect touches — peek any of these files inline to see the exact spot.
Root cause
What actually went wrong underneath — how it is classified, and the coverage gap that let it slip through.
No requirement modeled the comma-drop decision, so its two conditions (comma_in_string, next_char_closes_json) were unexercised variables and no test partition held a comma+closer inside a string literal. The 3T3F parse-robustness requirement could never catch this class because the corrupted text still parsed successfully.
Disposition: Covered by a requirement
Proof it's fixed
The tests, tightened requirements and new obligations that prove this defect is gone — and can't quietly return.
Covered by a requirement.
- Malformed Input on SW-REQ-260927-66FW
Blast radius
If you touch this issue, what else may need re-checking — the requirements it affects and the code and tests that hang off them. Historical view: authored trace links only — automatically derived links aren't reconstructible for past runs.
Touch this finding and you re-check 6 requirements · 2 code files · 1 tests.
- Menu.qml
- MenuModel.js
- menu-test.sh
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Change history
Every recorded revision of this finding's source file — when it was added, edited, or re-classified, with the diff for each change.
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.