Proof Portal

Project overview

Omarchy

ProbeLabsviewing a historical run

A proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.

Viewing historical run 5ee801eOct 2, 2026, 04:35 AMpr/13012Back to current
All requirements
RequirementSTK-REQ-260912-XJ5DStakeholderReview

The user shall lock the session on demand.

This requirement changed after its last recorded review, so approval is stale. Automated checks pass and 1/1 obligations are satisfied.
PriorityshallTypeguaranteeCategoryfunctionalComponentlockAssuranceCFindingsnone open

Specification

The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.

Description

The user shall lock the session on demand. The system shall lock the session before suspend. The session shall unlock only after a successful password or fingerprint authentication.

Rationale & tags

Why this requirement exists, and how it is categorised.

A session left unlocked exposes the user's data. Suspend without a secure lock is the highest-risk case because the machine sleeps unattended.

Verification & provenance

How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).

Assurance levelC
Formalizationnone
Strategyinformal

Review

Status
in_review
Reviewer
Kimi Dogfood · AI agent
Reviewed
Sep 12, 2026, 23:50 UTC

History

Created
Sep 12, 2026, 19:42 UTC · Kimi Dogfood · AI agent
Modified
Sep 28, 2026, 02:32 UTC · Kimi Zero Warnings · AI agent

Hazard review

Reviewed Oct 1, 2026, 21:26 UTCby agent:claude-baseline-passcatalog v1.11.0
  • scenarioreviewednominalerror_handlingboundaryconcurrency_scale

    Story-level partitions that decompose through the SYS layer: nominal (lock on demand results in a compositor-reported locked session) through T0XP and WC89, error_handling (suspends that beat the lock are reported, missing PAM refuses to lock) through HC86, H2YF, FRG0, and J8SX, boundary (lock-before-suspend deadlines, enrollment-driven PAM provisioning, exclusive update lock) through HC86, FAWV, JW2J, and H8A5. Unlock only after successful authentication is witnessed by the AC-001 acceptance test. Catalog 1.11.0 re-review: input_domain not applicable, it reads no external text input. concurrency_scale applied, the user can lock on demand while a suspend also requests the lock; both paths must leave one engaged lock.

  • propertynot applicable

    Story-level intent; no algebraic property is stated at this level, and the at-most-once and bounded-wait properties are recorded on the SYS and SW children that specify them.

  • structuralnot applicable

    Stakeholder story with no implementation at this level; structural surfaces are recorded on the children.

  • domainnot applicable

    Stakeholder story over local session state; no HTTP, crypto, transport, or multi-tenant workload exists anywhere in the decomposition.

Change history

Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.

Obligations

What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.

3 obligations · 2 discharged · 1 not yet witnessed

Browse the catalogue

Evidence tagged via <REQ> is witnessed by a requirement that satisfies this one — normal for stakeholder / aggregate requirements, which are proven through the requirements that refine them.

Discharged

Happy-path behavior with valid inputs.

Discharging evidence0/0 required witnessed
  • nominalrecommendedpresent
    Covered by 2 tests
    via SYS-REQ-260912-T0XP
Discharged

Behavior when operations fail or dependencies are unavailable.

Discharging evidence1/1 required witnessed
Not yet witnessed

Behavior at limits, thresholds, and edge-of-range values.

Discharging evidence0/0 required witnessed

    Acceptance criteria

    Stakeholder conditions for satisfaction, traced to the derived requirements and evidence that discharge them.

    Stakeholder-authored conditions defining when the requirement is satisfied, traced to derived requirements / evidence.

    Its place

    How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.

    Loading graph…

    Trace evidence

    The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.

    No findings affect this requirement

    Nothing was flagged against this requirement in the pinned run.

    Impact

    Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).

    If you change this

    Requirements
    22
    Files
    8
    Tests
    13
    At-risk contracts
    0

    Requirements (22)

    Files to re-check (8)

    • omarchy-hyprland-session-lockedbin/omarchy-hyprland-session-locked
    • Service.qmlshell/plugins/lock/Service.qml
    • omarchy-update-lockbin/omarchy-update-lock
    • omarchy-system-sleep-lockbin/omarchy-system-sleep-lock
    • omarchy-apply-lockbin/omarchy-apply-lock
    • omarchy-system-lockbin/omarchy-system-lock
    • LockView.qmlshell/plugins/lock/LockView.qml
    • Menu.qmlshell/plugins/menu/Menu.qml

    Tests to re-run (13)

    • lock-acceptance-test.shtest/shell.d/lock-acceptance-test.sh
    • sleep-lock-test.shtest/shell.d/sleep-lock-test.sh
    • hyprland-session-locked-test.shtest/shell.d/hyprland-session-locked-test.sh
    • lock-stranded-recovery-test.shtest/shell.d/lock-stranded-recovery-test.sh
    • update-lock-test.shtest/shell.d/update-lock-test.sh
    • apply-lock-test.shtest/shell.d/apply-lock-test.sh
    • system-lock-test.shtest/shell.d/system-lock-test.sh
    • menumodel-replay.test.mjstest/node/menumodel-replay.test.mjs
    • menu-test.shtest/shell.d/menu-test.sh
    • lock-fingerprint-indicator-test.shtest/shell.d/lock-fingerprint-indicator-test.sh
    • lock-missing-pam-test.shtest/shell.d/lock-missing-pam-test.sh
    • lock-blank-fingerprint-test.shtest/shell.d/lock-blank-fingerprint-test.sh
    • lock-password-overflow-test.shtest/shell.d/lock-password-overflow-test.sh

    What this rests on

    Discussions

    Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.

    Sign in to discuss this with the proof team.Sign in