Proof Portal

Project overview

Omarchy

ProbeLabsviewing a historical run

A proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.

Viewing historical run 7e54103Oct 3, 2026, 12:13 AMquattro-proofBack to current
Back to findings
Known issueKI-MENU-OPEN-LEAVES-CONFIRM

A menu summon leaves a pending uninstall question on top of the new prompt

OpenOpenLow

Low-severity issue, currently open.

What this means for you

Plain-language impact — what this issue could mean for your users and your system, before any of the technical detail.

If something summons the menu while an uninstall question is open, the question stays on top of the new prompt. The dialog preselects Uninstall, so the Enter you meant for the prompt uninstalls the app. Omarchy deletes your own, web-app and TUI launchers with no further prompt; for a package, it opens the uninstall terminal. The prompt's caller gets a cancel, so the action behind it never runs.

Technical description

Every summon enters through open(), which calls openDmenu(), or openRoute() and then openExistingMenu(). These replace the mode, rows and request files while opened stays true, and none of them clears deleteConfirmOpen or deleteTarget (anchor CNF1). Only onOpenedChanged clears them, when the menu closes. The keyCatcher still sends every key to the dialog, which preselects Uninstall. Enter then runs confirmDelete(): cancel() finishes the new request with no selection, and appLibrary.remove() uninstalls the app.

Affected requirements

The requirement(s) this issue violates — click through to the spec.

Severity, explained

Why this is rated the way it is — and the scoring signals behind the rating (each ⓘ explains the term).

LowRated severity — the impact if this issue is exploited or hit.
why this rating
Risk-rated
risk area
Correctness
Security classification
Not a security surface
CVE surface
None

How it's proven

The reproducer — an actual test that drives the real code and shows the issue happening. Run it yourself, or peek the test and the source it covers.

Known issue reproducedprofileknown_issue_reproducerprovesSW-REQ-260922-8CQ4
Reproducer test
Run it yourself
pocs/menu-qml-static.sh
Covers (2)
Last run Oct 3, 2026, 12:06 AM

Reproduction steps

Technical steps for your engineers to confirm the issue by hand.

pocs/menu-qml-static.sh

What protects you, and the fix

What limits your exposure today, and the planned remediation.

What protects you now

It takes an unanswered uninstall question plus a summon, such as a script prompt that appears while you are in the Apps menu. Answering the question with Escape or Cancel, or closing the menu, clears it.

The fix

Call cancelDelete() in open(), where every summon enters, when a question is pending. PR #14054 does this.

Blast radius

If you touch this issue, what else may need re-checking — the requirements it affects and the code and tests that hang off them. Historical view: authored trace links only — automatically derived links aren't reconstructible for past runs.

Tracing blast radius…

Touch this finding and you re-check 1 requirements · 1 code files · 1 tests.

Requirements (1)
Code files (1)
  • Menu.qml
Tests (1)
  • menu-compositor-test.sh

Per-requirement evidence

For each requirement this finding touches: the implementing code, verifying tests, and proof obligations that discharge it.

Implementing code (6)
  • shell/plugins/menu/Menu.qml
    Keys.onPressed
  • shell/plugins/menu/Menu.qml
    cancelDelete
  • shell/plugins/menu/Menu.qml
    confirmDelete
  • shell/plugins/menu/Menu.qml
    onCanceled
  • shell/plugins/menu/Menu.qml
    onConfirmed
  • shell/plugins/menu/Menu.qml
    requestDeleteSelected
Tests & evidence (1)
  • test/shell.d/menu-compositor-test.sh

Evidence trail

The raw evidence manifests behind this finding — superseded by the resolved reproducer above, kept here for traceability.

  • pocs/menu-qml-static.sh
  • proof/evidence/ki-menu-open-leaves-confirm.yaml

Change history

Every recorded revision of this finding's source file — when it was added, edited, or re-classified, with the diff for each change.

Discussions

Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.

Sign in to discuss this with the proof team.Sign in