Proof Portal
Omarchy
ProbeLabs73 findings · 87 requirementsA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
A menu summon leaves a pending uninstall question on top of the new prompt
Low-severity issue, currently open.
What this means for you
Plain-language impact — what this issue could mean for your users and your system, before any of the technical detail.
If something summons the menu while an uninstall question is open, the question stays on top of the new prompt. The dialog preselects Uninstall, so the Enter you meant for the prompt uninstalls the app. Omarchy deletes your own, web-app and TUI launchers with no further prompt; for a package, it opens the uninstall terminal. The prompt's caller gets a cancel, so the action behind it never runs.
Technical description
Every summon enters through open(), which calls openDmenu(), or openRoute() and then openExistingMenu(). These replace the mode, rows and request files while opened stays true, and none of them clears deleteConfirmOpen or deleteTarget (anchor CNF1). Only onOpenedChanged clears them, when the menu closes. The keyCatcher still sends every key to the dialog, which preselects Uninstall. Enter then runs confirmDelete(): cancel() finishes the new request with no selection, and appLibrary.remove() uninstalls the app.
Affected requirements
The requirement(s) this issue violates — click through to the spec.
Severity, explained
Why this is rated the way it is — and the scoring signals behind the rating (each ⓘ explains the term).
- why this rating
- Risk-rated
- risk area
- Correctness
- CVE surface
- None
How it's proven
The reproducer — an actual test that drives the real code and shows the issue happening. Run it yourself, or peek the test and the source it covers.
pocs/menu-qml-static.sh
Reproduction steps
Technical steps for your engineers to confirm the issue by hand.
pocs/menu-qml-static.sh
What protects you, and the fix
What limits your exposure today, and the planned remediation.
What protects you now
It takes an unanswered uninstall question plus a summon, such as a script prompt that appears while you are in the Apps menu. Answering the question with Escape or Cancel, or closing the menu, clears it.
The fix
Call cancelDelete() in open(), where every summon enters, when a question is pending. PR #14054 does this.
Blast radius
If you touch this issue, what else may need re-checking — the requirements it affects and the code and tests that hang off them. Historical view: authored trace links only — automatically derived links aren't reconstructible for past runs.
Touch this finding and you re-check 1 requirements · 1 code files · 1 tests.
- Menu.qml
- menu-compositor-test.sh
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Per-requirement evidence
For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.
Evidence trail
The raw evidence manifests behind this finding — superseded by the resolved reproducer above, kept here for traceability.
Evidence trail
The raw evidence manifests behind this finding — superseded by the resolved reproducer above, kept here for traceability.
- pocs/menu-qml-static.sh
- proof/evidence/ki-menu-open-leaves-confirm.yaml
Change history
Every recorded revision of this finding's source file — when it was added, edited, or re-classified, with the diff for each change.
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.