Proof Portal
Omarchy
ProbeLabsviewing a historical runA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
The user shall lock the session on demand.
Specification
The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.
The user shall lock the session on demand. The system shall lock the session before suspend. The session shall unlock only after a successful password or fingerprint authentication.
Rationale & tags
Why this requirement exists, and how it is categorised.
Rationale & tags
Why this requirement exists, and how it is categorised.
A session left unlocked exposes the user's data. Suspend without a secure lock is the highest-risk case because the machine sleeps unattended.
Verification & provenance
How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).
Review
- Status
- in_review
- Reviewer
- Kimi Dogfood · AI agent
- Reviewed
- Sep 12, 2026, 23:50 UTC
History
- Created
- Sep 12, 2026, 19:42 UTC · Kimi Dogfood · AI agent
- Modified
- Sep 23, 2026, 17:08 UTC · Kimi Dogfood · AI agent
Change history
Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.
Obligations
What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.
3 obligations · 2 discharged · 1 not yet witnessed
Browse the catalogueEvidence tagged via <REQ> is witnessed by a requirement that satisfies this one — normal for stakeholder / aggregate requirements, which are proven through the requirements that refine them.
Happy-path behavior with valid inputs.
- nominalrecommendedpresentCovered by 1 test
Behavior when operations fail or dependencies are unavailable.
- negativerequiredpresentCovered by 1 test
Behavior at limits, thresholds, and edge-of-range values.
Acceptance criteria
Stakeholder conditions for satisfaction, traced to the derived requirements and evidence that discharge them.
Acceptance criteria
Stakeholder conditions for satisfaction, traced to the derived requirements and evidence that discharge them.
Stakeholder-authored conditions defining when the requirement is satisfied, traced to derived requirements / evidence.
- AC-001verify: test
Locking the session (omarchy system lock or sleep path) results in a session the compositor reports as locked, or a visible failure.
Derived requirementsNo acceptance-test witness found
Its place
How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.
Loading graph…
Trace evidence
The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.
No findings affect this requirement
Nothing was flagged against this requirement in the pinned run.
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
If you change this
Requirements (20)
- The system shall report the compositor session-lock state…lock · SYS
- While an Omarchy update runs, the system shall hold an…lock · SYS
- When suspend is imminent, the system shall request the…lock · SYS
- The system shall install the PAM password stack for the…lock · SYS
- When the user locks the session, the system shall engage…lock · SYS
- omarchy-hyprland-session-locked shall exit 0 when any…lock · SW
- When the stranded-lock probe exits 0, the shell lock…lock · SW
- omarchy-update-lock held shall exit 0 only when…lock · SW
- omarchy-update-lock run shall open the update lock file on…lock · SW
- omarchy-system-sleep-lock shall derive the wait budget from…lock · SW
- omarchy-system-sleep-lock shall request the session lock…lock · SW
- When the budget expires before the session reports secure,…lock · SW
- When omarchy-apply-lock runs with EUID 0, it shall replace…lock · SW
- omarchy-apply-lock shall test fingerprint enrollment by…lock · SW
- When the target user has no enrolled fingerprint or…lock · SW
- When a fingerprint sensor is configured, the lock view…lock · SW
- When the lock IPC handler receives a lock request and…lock · SW
- When the user locks the session and the ttfx screensaver is…lock · SW
- While the session is locked and the idle blank timer…lock · SW
- When the entered password text is wider than the password…lock · SW
Files to re-check (7)
- omarchy-hyprland-session-lockedbin/omarchy-hyprland-session-locked
- Service.qmlshell/plugins/lock/Service.qml
- omarchy-update-lockbin/omarchy-update-lock
- omarchy-system-sleep-lockbin/omarchy-system-sleep-lock
- omarchy-apply-lockbin/omarchy-apply-lock
- omarchy-system-lockbin/omarchy-system-lock
- LockView.qmlshell/plugins/lock/LockView.qml
Tests to re-run (10)
- sleep-lock-test.shtest/shell.d/sleep-lock-test.sh
- hyprland-session-locked-test.shtest/shell.d/hyprland-session-locked-test.sh
- lock-stranded-recovery-test.shtest/shell.d/lock-stranded-recovery-test.sh
- update-lock-test.shtest/shell.d/update-lock-test.sh
- apply-lock-test.shtest/shell.d/apply-lock-test.sh
- system-lock-test.shtest/shell.d/system-lock-test.sh
- lock-fingerprint-indicator-test.shtest/shell.d/lock-fingerprint-indicator-test.sh
- lock-missing-pam-test.shtest/shell.d/lock-missing-pam-test.sh
- lock-blank-fingerprint-test.shtest/shell.d/lock-blank-fingerprint-test.sh
- lock-password-overflow-test.shtest/shell.d/lock-password-overflow-test.sh
What this rests on
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.