Proof Portal
Omarchy
ProbeLabsviewing a historical runA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
String-blind trailing-comma strip silently mutated in-string commas in menu labels and actions
This defect has been fixed and verified.
Description
The issue as recorded.
MenuModel.js stripJsonc used the string-blind regex /,(\s*[}\]])/g to strip JSONC trailing commas. The regex matched zero-width whitespace and never tracked string literals. It deleted in-string commas before a closer even though those commas were data. JSON.parse accepted the stripped text, so the corruption stayed silent. Mode (a) corrupted display labels; mode (b) mutated action commands such as "mv f{.bak,}" brace expansions. omarchy-menu runs action strings with full user privileges, so mutated commands executed without warning.
Affected requirements
The requirement(s) this issue violates — click through to the spec.
Severity, explained
Why this is rated the way it is — and the scoring signals behind the rating (each ⓘ explains the term).
- risk area
- Config Behavior
Where it is
The code this defect touches — peek any of these files inline to see the exact spot.
Root cause
What actually went wrong underneath — how it is classified, and the coverage gap that let it slip through.
No requirement modeled the comma-drop decision. Its two conditions (comma_in_string, next_char_closes_json) had no exercising test. No test partition held a comma plus closer inside a string literal. 3T3F could not catch this class because the corrupted text still parsed.
Disposition: Covered by a requirement
Proof it's fixed
The tests, tightened requirements and new obligations that prove this defect is gone — and can't quietly return.
Covered by a requirement.
- Malformed Input on SW-REQ-260927-66FW
Blast radius
If you touch this issue, what else may need re-checking — the requirements it affects and the code and tests that hang off them. Historical view: authored trace links only — automatically derived links aren't reconstructible for past runs.
Touch this finding and you re-check 10 requirements · 2 code files · 2 tests.
- Menu.qml
- MenuModel.js
- menu-test.sh
- menu-pointer-lifecycle-test.sh
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Change history
Every recorded revision of this finding's source file — when it was added, edited, or re-classified, with the diff for each change.
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.