Proof Portal

Project overview

Omarchy

ProbeLabsviewing a historical run

A proof layer — requirements, tests and verified fixes — for two of Omarchy's subsystems: the application menu (launcher scripts, QML model, JSONC config, search and selection) and the lock screen (lock scripts, QML, PAM authentication). Scope is deliberately limited to those components of omacom/omarchy; the rest of the distribution is not covered.

Viewing historical run 329e23fOct 2, 2026, 04:58 AMpr/6525Back to current
All requirements
RequirementSYS-REQ-260922-X6Z5SystemReview

A script-driven select/input prompt delivers the picked value to the caller (glyph stripped, subtext kept as the stable key); cancellation reaches the caller as no-selection.

This requirement changed after its last recorded review, so approval is stale. Automated checks pass and 3/3 obligations are satisfied.
PriorityshallTypeguaranteeCategoryfunctionalComponentmenuAssuranceCFindingsLowworst open

Specification

The requirement exactly as authored — its complete prose text and, where present, the formal FRETish sentence it compiles to.

Description

A script-driven select/input prompt delivers the picked value to the caller (glyph stripped, subtext kept as the stable key); cancellation reaches the caller as no-selection.

FRETish formula
when picker_active & selection_made the dmenu_protocol shall eventually satisfy picker_answer_returned
View full formal model

Rationale & tags

Why this requirement exists, and how it is categorised.

Scripts block on the answer file; a lost answer or a glyph leaking into the result breaks every caller.

Verification & provenance

How this requirement was checked: the review trail, edit history, and the machine-analysis status terms (each ⓘ explains what it means).

Assurance levelC
Formalizationvalid
Realizabilityrealizable
Vacuitychecked_ok
Strategyfretish

Review

Status
in_review
Reviewer
Kimi Zero Warnings · AI agent
Reviewed
Sep 27, 2026, 21:25 UTC

History

Created
Sep 22, 2026, 13:33 UTC · Kimi Dogfood · AI agent
Modified
Oct 1, 2026, 21:23 UTC · Claude Baseline Pass · AI agent

Hazard review

Reviewed Oct 1, 2026, 21:26 UTCby agent:claude-baseline-passcatalog v1.11.0
  • scenarioreviewederror_handlingmalformed_inputinput_domainconcurrency_scale

    Worst case graded above (peer death after summon hangs the synchronous caller - medium, tracked at the children under the KI). error_handling: cancellation reaches the caller as a clean no-selection (exit 1) rather than an error, so cancel is a protocol answer, not a failure; the answer file empty-vs-absent distinction is the no-selection contract. malformed_input: the picked value is delivered glyph-stripped with subtext preserved as the stable key, so decorative drift in labels cannot corrupt the payload; unknown/empty payloads are refused by the payload-shape child rather than passed through. boundary: single-select and multi-select modes answer through one delivery path so the caller needs no mode-specific wait logic. Catalog 1.11.0 re-review: input_domain applied, input_domain is on its obligation checklist and covered by SW-REQ-260922-Q6ZS (stdin lines as options). concurrency_scale applied, select and input prompts can be summoned while another request is active; the stranded-caller defect is KI-MENU-REQUEST-LIFECYCLE (omacom/omarchy#9057).

  • propertyrevieweddeterminism

    determinism: the same pick answers the same payload - glyph stripping and key extraction are pure string functions of the chosen row; delivery order (exit code, answer file content) is fixed by the protocol, not by timing. idempotency: rewriting the answer file with the same pick converges; a second pick overwrites the first, which is the documented last-writer contract.

  • structuralnot applicable

    payload is a stripped string written to a file: no memory/pointer/format surface; encoding is preserved byte-wise by the shell write path, and the shape guard on the caller side is dispositioned under scenario.malformed_input.

  • domainreviewed

    external_call_timeout_bounded evaluated: the wait-on-answer-file poll inside the dmenu flow is exactly the KI-MENU-SELECT-POLL-DEADLOCK mechanism, and it is deferred at the children that carry the poll (9ABD and Q6ZS under the KI, with reproducer); the parent adds no duplicate deferral - decomposition keeps the debt row where the fix will land, and obligation_decomposition stays honest because both children carry the class. cancel-as-answer means the protocol never relies on a timeout for its normal path. No trust boundary: the answer travels from the user own picker surface to their own script through a mode-600 file in the session tmpdir.

Change history

Every recorded revision of this requirement's source file — newest first, each with its commit message and the diff for that change.

Open known issues

Findings currently open against this requirement — issues its verification surfaced that are not resolved yet. Each links to the full finding.

Obligations

What this requirement must witness to be considered satisfied — the required evidence, and the tests that discharge each one.

2 obligations · 2 discharged

Browse the catalogue

Evidence tagged via <REQ> is witnessed by a requirement that satisfies this one — normal for stakeholder / aggregate requirements, which are proven through the requirements that refine them.

Discharged

Behavior when operations fail or dependencies are unavailable.

If it were violatedMedium

the summoned picker surface dies after a successful select IPC and before writing the answer file: the synchronous caller waits on a file that will never appear - the reproduced poll-deadlock class; the bound is owned at the dmenu children (9ABD/Q6ZS) as a KI-tracked deferral on KI-MENU-SELECT-POLL-DEADLOCK, so the parent records the decision rather than duplicating the debt row

Discharging evidence2/2 required witnessed
Discharged

A parser, reader, or configuration loader states its accepted input domain at the byte level and what happens for each partition of it.

Discharging evidence1/1 required witnessed

Formula evidence

The formal formula behind this requirement, the variables it is written over, and the tests that exercise it (each term is explained inline).

FRETish formula

when picker_active & selection_made the dmenu_protocol shall eventually satisfy picker_answer_returned

Witnesses· 3 scenarios total

  • menu-dmenu-test.sh:1
    exercises 3 condition scenarios

MC/DC truth table· 4 rows

Each row assigns the formula's conditions (T/F) and shows the Result— the formula's value for that input row, not a test pass/fail. A row proves a condition when flipping only that condition flips the outcome. The test that covers each row is linked.

Covereda test exercises this rowExempteda reviewed mcdc:ignoreNo-actionfalse-result row satisfied by designUncoveredneeds a covering test
#picker_activepicker_answer_returnedselection_madeResultProvesCovering test
1FFTTpicker_active
2TFFTselection_made
3TFTFpicker_active—
4TTTTpicker_answer_returned

Its place

How this requirement connects — what proves it, what it affects, and what it rests on. Authored links only here; automatically derived links come from the audit index.

Loading graph…

Trace evidence

The concrete artifacts linked to this requirement — implementing code, verifying tests, documents, and the findings raised against it.

Impact

Blast radius — authored trace links only (automatically derived links come from the audit index and aren't shown here).

Discussions

Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.

Sign in to discuss this with the proof team.Sign in