Proof Portal
Omarchy
ProbeLabsviewing a historical runA proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.
When the done file exists but the selection file is empty (cancel), the script prints nothing and exits 1.
Specification
The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.
When the done file exists but the selection file is empty (cancel), the script prints nothing and exits 1.
when empty_selection the dmenu_protocol shall eventually satisfy exit_one_on_empty
Rationale & tags
Why this requirement exists, and how it is categorised.
Rationale & tags
Why this requirement exists, and how it is categorised.
bin/omarchy-menu-select lines 95-98.
Verification & provenance
How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).
Review
- Status
- in_review
- Reviewer
- Kimi Zero Warnings · AI agent
- Reviewed
- Sep 27, 2026, 21:25 UTC
History
- Created
- Sep 22, 2026, 13:34 UTC · Kimi Dogfood · AI agent
- Modified
- Sep 30, 2026, 07:13 UTC · Leonid Bugaev
Hazard review
- scenarioreviewedboundaryerror_handlingedge_case
Worst case: a cancel masquerades as success - exit 0 with empty output would make callers such as confirmation prompts proceed on an answer nobody gave; the -s partition is the whole guard, sending an empty selection file to the unconditional exit 1 arm with nothing on stdout. boundary: selection-file empty versus non-empty is the exact partition this contract names, and done-file-present-but-selection-absent is the cancel encoding it must resolve. edge_case: the selection file vanishing between the -s test and cat fails under set -e to the same observable (nonzero, silent), and a whitespace-only answer counts as non-empty by -s and is passed through verbatim - the caller-side trim is out of this contract. The done-file wait feeding this arm carries the same unbounded poll already tracked on Q6ZS; the identical loop in bin/omarchy-menu-input is that KI's second site and is deferred, not suppressed.
- propertyreviewedtotality
Every (done-file, selection-file) combination the protocol can produce resolves to exactly one defined ending - content printed with exit 0, or silence with exit 1 - with no combination leaving the script printing a partial answer or exiting zero on a cancel.
- structuralnot applicable
A -s file test, cat, and two mktemp'd fixed paths with an EXIT trap; no parsing of file contents, no arithmetic, no encoding transform - the selection bytes pass through verbatim.
- domainnot applicable
Same-user local files at mktemp paths plus the omarchy-shell IPC summon owned by the protocol sibling (Q6ZS/C8HX); no network egress, crypto, or privilege surface in the answer-reading arm this requirement governs.
Change history
Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.
Review history
Human and AI-agent approvals of this requirement — the 'why was this approved' lineage, each with the reviewer's justification and the code it cites.
- Kimi Zero Warnings · AI agentApprovedSpec conformanceSep 27, 2026 · 5 days agoREVIEW-42
Read omarchy-menu-select and omarchy-menu-input. When the done file exists but the selection file is empty (a cancel), the script takes the unconditional exit-1 arm and prints nothing — the dmenu stub test at menu-dmenu-test.sh:91 observes status 1 with empty stdout. The empty_selection condition models the empty-selection-file test exactly. Formula conforms to the code.
Cited code (1)
Open known issues
Findings currently open against this requirement — issues its verification surfaced that are not resolved yet. Each links to the full finding.
Obligations
What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.
1 obligation · 1 deferred
Browse the catalogueSecond site of the tracked poll deadlock: bin/omarchy-menu-input polls the same done_file with no deadline and no peer-liveness probe (while [[ ! -e $done_file ]]; sleep 0.05), so a menu that dies after a successful summon hangs every synchronous caller, exactly the reproduced defect class on omarchy-menu-select; the empty-selection arm under review sits downstream of that wait
Discharging tests pending a synced audit.
Formula evidence
The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).
Formula evidence
The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).
FRETish formula
when empty_selection the dmenu_protocol shall eventually satisfy exit_one_on_empty
Witnesses· 2 scenarios total
- menu-dmenu-test.sh:1exercises 2 condition scenarios
MC/DC truth table· 3 rows
Each row assigns the formula's conditions (T/F) and shows the Result— the formula's value for that input row, not a test pass/fail. A row proves a condition when flipping only that condition flips the outcome. The test that covers each row is linked.
mcdc:ignoreNo-actionfalse-result row satisfied by designUncoveredneeds a covering test| # | empty_selection | exit_one_on_empty | Result | Proves | Covering test |
|---|---|---|---|---|---|
| 1 | F | F | T | empty_selection | |
| 2 | T | F | F | empty_selection | — |
| 3 | T | T | T | exit_one_on_empty |
Its place
How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.
Loading graph…
Trace evidence
The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
Impact
Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).
If you change this
Nothing downstream depends on this yet
No downstream impact — "When the done file exists but the selection file is empty…" has no downstream edges.
What this rests on
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.