Proof Portal
Omarchy
ProbeLabsviewing a historical runA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
omarchy-system-sleep-lock shall derive the wait budget from the logind InhibitDelayMaxUSec property.
Specification
The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.
omarchy-system-sleep-lock shall derive the wait budget from the logind InhibitDelayMaxUSec property. It shall reserve one fifth of the window but at least 1000 ms for logind. It shall fall back to 5000 ms when reading the property fails, and cap the result at 12000 ms. When the caller passes an argument that is not a positive integer within the cap, the script shall ignore it and use the derived budget.
when suspend_imminent the sleep_lock shall always satisfy budget_bounded & budget_fallback_on_invalid
Rationale & tags
Why this requirement exists, and how it is categorised.
Rationale & tags
Why this requirement exists, and how it is categorised.
The shipped drop-in raises the inhibitor window to 15 s, but only logind knows the active value. A hand-raised window must not strand a closed laptop in a bag.
Verification & provenance
How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).
Review
- Status
- in_review
- Reviewer
- Kimi Dogfood · AI agent
- Reviewed
- Sep 12, 2026, 23:50 UTC
History
- Created
- Sep 12, 2026, 19:43 UTC · Kimi Dogfood · AI agent
- Modified
- Sep 23, 2026, 17:20 UTC · Kimi Dogfood · AI agent
Hazard review
- scenarioreviewedboundaryerror_handlingmalformed_inputempty_inputedge_caseinput_domain
Worst case: a derived budget that overshoots the real logind window strands a closed laptop suspended mid-lock. boundary: the 12000 ms cap, the at-least-1000 ms logind reserve, and the positive-int-within-cap argument validation are the requirement threshold set (capped-window and invalid-arg scenarios). error_handling: an unreadable InhibitDelayMaxUSec, including a busctl timeout, falls back to 5000 ms. malformed_input: a non-numeric busctl tail or caller argument fails the ^[0-9]+$ regex and routes to the derived budget. empty_input: an absent argument is the default derivation path. edge_case: a zero window cannot drive the reserve negative because of the max(window/5,1000) floor. Catalog 1.11.0 re-review: input_domain applied, it reads the logind InhibitDelayMaxUSec property as text; empty, non-numeric and failed reads are the malformed_input and empty_input partitions already applied here (5000 ms fallback). concurrency_scale not applicable, one property read per suspend; repeated suspends are stated on SYS-REQ-260912-HC86.
- propertyreviewedtotality
Every entry condition terminates inside the budget, either exit 0 on secure or the unsecured report and exit 1; the remaining>0 entry guard stops a frozen or jumped clock from looping forever, so the wait is total and terminating.
- structuralreviewedencoding_safety
EPOCHREALTIME renders with the locale decimal separator; the [!0-9] digit strip prevents a comma locale from being re-read as the bash comma operator, which would silently void the deadline. overflow_safety not applicable: bash 64-bit arithmetic, epoch micros near 1.7e15 sit far below 2^63, and 10# stripping cannot grow the magnitude. nil_safety not applicable: unset and empty argument are the specified empty_input default path.
- domainreviewedexternal_call_timeout_bounded
Every cross-process call declares a deadline: busctl is wrapped in timeout 1s with kill-after, both omarchy-shell calls are clamped to the remaining budget, and the clamshell reconciliation is bounded at 0.4s; nothing defaults to unbounded.
Change history
Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.
Review history
Human and AI-agent approvals of this requirement — the 'why was this approved' lineage, each with the reviewer's justification and the code it cites.
- Kimi Dogfood · AI agentApprovedSpec conformanceSep 12, 2026 · 3 weeks agoREVIEW-7
Budget derivation matches: InhibitDelayMaxUSec is read, one fifth (>=1000 ms) is reserved for logind, and an invalid/unreadable property falls back to 5000 ms — budget_fallback_on_invalid. Tested with zero-window and not-a-number/99999999 scenarios.
Cited code (1)
Open known issues
Findings currently open against this requirement — issues its verification surfaced that are not resolved yet. Each links to the full finding.
- MediumOpen
Non-positive sleep-lock budget for logind windows <= 1s: suspend proceeds with no lock attempt
KI-SLEEP-LOCK-BUDGET-NONPOSITIVE
- LowOpen
argv budget with a leading zero (08/09) bypasses the validation guard via an octal arithmetic error
KI-SLEEP-LOCK-BUDGET-ARG-OCTAL
- LowOpen
Header invariant 'every call bounded by the budget remainder' unenforced on three external calls
KI-SLEEP-LOCK-DEADLINE-INVARIANT-GAPS
Obligations
What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.
1 obligation
Browse the catalogueDischarging tests pending a synced audit.
Formula evidence
The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).
Formula evidence
The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).
FRETish formula
when suspend_imminent the sleep_lock shall always satisfy budget_bounded & budget_fallback_on_invalid
Witnesses· 3 scenarios total
- run_sleep_lockexercises 3 condition scenarios
MC/DC truth table· 5 rows
Each row assigns the formula's conditions (T/F) and shows the Result— the formula's value for that input row, not a test pass/fail. A row proves a condition when flipping only that condition flips the outcome. The test that covers each row is linked.
mcdc:ignoreNo-actionfalse-result row satisfied by designUncoveredneeds a covering test| # | budget_bounded | budget_fallback_on_invalid | suspend_imminent | Result | Proves | Covering test |
|---|---|---|---|---|---|---|
| 1 | F | F | F | T | suspend_imminent | |
| 2 | F | F | T | F | suspend_imminent | — |
| 3 | F | T | T | F | budget_bounded | — |
| 4 | T | F | T | F | budget_fallback_on_invalid | |
| 5 | T | T | T | T | budget_bounded |
Its place
How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.
Loading graph…
Trace evidence
The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.
3 open · 0 resolved
- MediumOpen
Non-positive sleep-lock budget for logind windows <= 1s: suspend proceeds with no lock attempt
KI-SLEEP-LOCK-BUDGET-NONPOSITIVE
- LowOpen
argv budget with a leading zero (08/09) bypasses the validation guard via an octal arithmetic error
KI-SLEEP-LOCK-BUDGET-ARG-OCTAL
- LowOpen
Header invariant 'every call bounded by the budget remainder' unenforced on three external calls
KI-SLEEP-LOCK-DEADLINE-INVARIANT-GAPS
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
If you change this
Nothing downstream depends on this yet
No downstream impact — "omarchy-system-sleep-lock shall derive the wait budget from…" has no downstream edges.
What this rests on
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.