Proof Portal

Project overview

Omarchy

ProbeLabsviewing a historical run

A proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.

Viewing historical run 7916138Sep 29, 2026, 09:44 AMpr/13255Back to current
All requirements
RequirementSW-REQ-260922-3T3FSoftwareDraft

Unparseable input (after stripping), non-object JSON, and non-object entries yield an empty or skipped item set; no exception escapes the parser.

All automated checks pass and 3/3 obligations are satisfied. Human review is still pending.
PriorityshallTypeguaranteeCategoryfunctionalComponentmenuAssuranceCFindingsnone open

Specification

The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.

Description

Unparseable input (after stripping), non-object JSON, and non-object entries yield an empty or skipped item set; no exception escapes the parser. Trailing-comma stripping is string-aware — commas inside string literals are preserved verbatim, and only a comma outside any string whose next non-whitespace character is } or ] is dropped (trailing_comma_dropped = !comma_in_string && next_char_closes_json).

FRETish formula
when json_invalid the menu_model shall eventually satisfy empty_item_set & !parse_error_raised
View full formal model

Rationale & tags

Why this requirement exists, and how it is categorised.

MenuModel.js parseMenuJsonc and stripJsonc; a crashing parser would take the whole menu down on a user edit, and the pre-fix string-blind comma regex silently corrupted labels containing comma+whitespace+} or ] (e.g. "x, ]y") while the parse still succeeded.

Verification & provenance

How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).

Assurance levelC
Formalizationvalid
Realizabilityrealizable
Vacuitychecked_ok
Strategyfretish

Review

Status
pending

History

Created
Sep 22, 2026, 13:34 UTC · Kimi Dogfood · AI agent
Modified
Sep 23, 2026, 17:20 UTC · Kimi Dogfood · AI agent

Hazard review

Reviewed Sep 27, 2026, 19:20 UTCby agent:kimi-fix-jsonc-refreshcatalog v1.10.0
  • scenarioreviewedmalformed_inputerror_handling

    Delta-touched by the fix branch (description/rationale now name string-aware comma semantics). malformed_input: unparseable-after-strip input still routes to the unconditional catch returning [] (verified by direct execution 2026-09-27: unterminated string -> parse fail -> empty set, no exception escapes). error_handling: the failure mode is silent empty menu by design; the NEW malformed-input subclass this branch removes is the one where parse SUCCEEDED on corrupted text (comma-in-string), which no error path could ever catch - correctly handled by 66FW's prevention, not by error handling here.

  • propertyrevieweddeterminism
  • domainnot applicable

    No domain workload tags; local config parser.

  • structuralnot applicable

    GC'd JavaScript; no C-family structural hazard surface.

Change history

Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.

Review history

Human and AI-agent approvals of this requirement — the 'why was this approved' lineage, each with the reviewer's justification and the code it cites.

  1. Kimi Fix Jsonc Refresh · AI agentApprovedSpec conformanceSep 27, 2026 · 5 days agoREVIEW-22

    Delta-touch conformance for the fix branch: agent-25 extended the description and rationale to name the string-aware trailing-comma semantics (trailing_comma_dropped = !comma_in_string && next_char_closes_json) and the pre-fix silent-corruption behavior. Verified against MenuModel.js: the stripJsonc scanner (lines 1-35) drops a comma iff it is outside every string literal and the next non-whitespace byte is } or ], and parseMenuJsonc still routes any post-strip parse failure to the catch that returns [] with no exception escaping (fretish: json_invalid -> eventually empty_item_set & !parse_error_raised unchanged and still honored; unterminated-string case verified by direct execution this campaign). The added prose is descriptive, not normative; the normative equivalence lives in SW-REQ-260927-66FW. Status left at draft per quattro baseline convention (all menu SW specs are draft there); the changed-requirements gate is satisfied via 66FW promotion.

    Cited code (4)

Obligations

What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.

2 obligations · 2 discharged

Browse the catalogue
Discharged

Behavior at limits, thresholds, and edge-of-range values.

Discharging evidence1/1 required witnessed
  • nominalrequiredpresent
    Covered by 1 test
  • negativerecommendedpresent
    Covered by 1 test
Discharged

Behavior when operations fail or dependencies are unavailable.

Discharging evidence2/2 required witnessed
  • negativerequiredpresent
    Covered by 1 test
  • nominalrequiredpresent
    Covered by 1 test

Formula evidence

The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).

FRETish formula

when json_invalid the menu_model shall eventually satisfy empty_item_set & !parse_error_raised

Witnesses· 2 scenarios total

  • menu-test.sh:1
    exercises 2 condition scenarios

MC/DC truth table· 4 rows

Each row assigns the formula's conditions (T/F) and shows the Result— the formula's value for that input row, not a test pass/fail. A row proves a condition when flipping only that condition flips the outcome. The test that covers each row is linked.

Covereda test exercises this rowExempteda reviewed mcdc:ignoreNo-actionfalse-result row satisfied by designUncoveredneeds a covering test
#empty_item_setjson_invalidparse_error_raisedResultProvesCovering test
1FFFTjson_invalid
2FTFFempty_item_set—
3TTFTempty_item_set
4TTTFparse_error_raised—

Its place

How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.

Loading graph…

Trace evidence

The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.

0 open · 1 resolved

No open findings

Everything flagged against this requirement has been resolved.

Impact

Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).

If you change this

Requirements
0
Files
2
Tests
1
At-risk contracts
0

Files to re-check (2)

  • Menu.qmlshell/plugins/menu/Menu.qml
  • MenuModel.jsshell/plugins/menu/MenuModel.js

Tests to re-run (1)

  • menu-test.shtest/shell.d/menu-test.sh

What this rests on

Discussions

Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.

Sign in to discuss this with the proof team.Sign in