Commit Graph
6344 Commits
Author SHA1 Message Date
Mehmet Ince 70047956fa Harden lock authentication command lookup
Keep the target user's local bin on user-scoped upgrade paths while giving privileged lock and firewall helpers only root-owned search directories. Pin the lock helper's root PATH and fprintd-list executable, with regression coverage for each defense independently.

Reported-by: Rooke Poole <rookpool97@gmail.com>
2026-09-04 19:43:03 +01:00
David Heinemeier HanssonandClaude Fable 5 493067741e Give foot its own touchpad scroll factor (#9793)
foot only applies scrollback.multiplier to discrete wheel clicks, so
precise touchpad scrolling ignores it and crawls at the group's 1.5
factor. Split foot out at 2.0 to match how the other terminals feel.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-04 17:59:32 +02:00
Spencer Bull f99d33a8dd Merge pull request #9663 from spencerbull/fix/hermes-prompt-probe
Fix the Hermes CLI readiness probe, and tear the CLI down on uninstall
2026-09-02 15:21:45 -05:00
Spencer BullandClaude Opus 5 21470fd1ea Say how to finish a failed teardown, and record the probe's real history
A failed --remove told the user to run it again, but that advice could
never work: rm -f has usually taken the marked stub by the time the
failure is judged, and a rerun that finds nothing it owns succeeds
without touching the mise environment it was asked to finish removing.
Spell out the three commands that complete the job by hand instead.

Also correct the story the probe comment told: chat never lost
--oneshot in v0.20 -- no released Hermes defined it there. It lived at
the top level until v0.21 added chat's own, so the old probe was keyed
to a flag no release ever carried under chat, and every install read
as not ready. Recorded straight so a future hermes-desktop bump to
v0.21+, which would make the old probe pass on the desktop path alone,
cannot read as the fix.

Findings from omarchybot's review (Opus 5, with Codex at xhigh).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-02 09:40:44 -05:00
d3d23fddde Honor keepLoaded for services during plugin hot-reload (#9485)
* Honor keepLoaded for services during plugin hot-reload

Plugin reload destroyed every service, including omarchy.lock, which drops the ext-session-lock client while Hyprland still holds the lock and surfaces the crashed-lockscreen fallback.

* Prove keepLoaded service survival with a fixture service

A fresh lock service also reports an empty lastEventAt, so comparing it
across the rescan passed whether or not the instance survived. A fixture
keepLoaded service whose in-memory marker is set before the rescan and
read back after can only pass when the same instance is still mounted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Drop kept services whose plugin no longer declares a service

The _syncServices cleanup only asked whether the plugin was still
installed and enabled, so a kept service whose plugin dropped its
service kind or entry point kept running as a zombie until shell
restart. Apply the same eligibility checks used at creation, and hand
kept instances the refreshed manifest after a rescan.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Cover omarchy.media in keepLoaded expectations; note kept services reload on restart

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-02 12:33:44 +02:00
46cfc4ada5 Judge the CLI teardown by what is left, and match flags as definitions
Two review follow-ups. The probe counted any mention of --tui/--query in
the help as support -- Hermes already writes "With --tui:" into --dev's
description, so a release that dropped the option while keeping the
prose would still read as ready. A flag now counts only when followed by
a shape argparse prints after a definition: the usage bracket, the gap
before same-line help text, an uppercase metavar, or the line end. Not
probed by parsing a real invocation on purpose -- a release that ignores
unknown arguments would turn the probe into a live session.

And the teardown trusted its commands: a stub rm that failed aborted
Remove Hermes under set -e before any ~/.hermes handling, while mise
failures vanished into || true. --remove now attempts every step, then
judges by what is left -- the marked stub still present, or mise still
resolving the tool -- and Remove Hermes tolerates the failure until the
runtime is handled, then carries it in its exit code.

Findings from the same codex review at xhigh, verified and proven by
mutation before landing.

Co-Authored-By: Codex <noreply@openai.com>
Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-02 01:01:13 -05:00
c462aad9ee Prove ownership before --remove touches mise
The teardown removed the Omarchy tool spec from mise unconditionally,
so removing Hermes Desktop could destroy a mise environment the user
had built against the same spec while sparing their wrapper -- the very
command the removal claims to preserve, broken behind its back. The
whole teardown now turns on the marked stub, as replacement already
does; the desktop takeover keeps its own bargain, where a second Hermes
goes whoever built it and the app still provides the command after.

Also close the probe over underscores -- _ continues a flag name just
as - does, so --tui_mode no longer answers for --tui -- and pin the
gaps review found in the tests: each flag must match on its own (either
grep could be deleted before without a failure), a foreign wrapper's
mise environment must survive --remove, and Remove Hermes must tear
down the CLI in the interrupted-install case, not only after the app's
runtime landed.

Findings from an independent codex review at xhigh, each verified
against the source and proven by mutation before landing.

Co-Authored-By: Codex <noreply@openai.com>
Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 23:32:35 -05:00
Spencer BullandClaude 36d52254a7 Tear down the mise Hermes CLI on Remove Hermes
Remove Hermes dropped the desktop package and its ~/.hermes runtime but
never touched the mise CLI, on the assumption the install-time handoff
had already removed it. A CLI the app never superseded -- an interrupted
install, or the terminal CLI from before the app existed -- was left
stranded on PATH after uninstall.

Add a --remove mode to omarchy-install-hermes-cli that performs the same
teardown the desktop takeover already does (mise rm -g + mise uninstall,
and the marked stub), and call it from omarchy-remove-ai-hermes. The tool
spec and ownership marker stay defined in one place, so the takeover and
teardown paths cannot drift. Scoped to what Omarchy owns: a Hermes the
user installed themselves is left alone.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 22:51:03 -05:00
Ryan Hughes 7eca64e268 Merge pull request #8859 from tobi/feat/network-captive-portal
Show captive portal status and sign-in action in network panel
2026-09-01 23:39:43 -04:00
Spencer BullandClaude f7078b9136 Match Hermes flag probe at a boundary, cover the mise path
Review follow-up on the readiness probe. The two greps were fixed-string
substring matches, so a future release listing only --tui-theme or
--query-log while dropping the bare --tui/--query omarchy-agent passes
would read as ready -- the same false verdict inverted. Anchor both to a
flag boundary.

Add a regression case pinning that a substring-only help is rejected,
and one exercising --check through a mise-installed hermes in both
capability directions: the desktop and foreign cases only covered their
own wrappers, and the mise path is what a machine without the app runs.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-09-01 15:53:52 -05:00
Spencer Bull f08840d6cc Probe Hermes readiness by the flags omarchy-agent passes
Hermes v0.20 removed chat's --oneshot flag, which hermes_prompt_ready
used as its capability marker. A fully bootstrapped Hermes Desktop
install then read as not ready: --check failed forever, the default
agent flow looped back into the installer, and --now dead-ended with
"Launch Hermes Desktop once to finish installing it" on a machine
where it already had.

Probe for --tui and --query instead: the flags omarchy-agent actually
passes to seed an interactive session, rather than one that merely
shipped alongside them.
2026-09-01 14:25:37 -05:00
Spencer Bull b71dcad96e Merge pull request #7469 from omacom/hermes-agent
Add Hermes as a desktop app and a coding agent
2026-09-01 11:11:57 -05:00
David Heinemeier Hansson 4d017913d0 Update the tagline to Beautiful, Fun & Agentic (#9584)
Matches omarchy.org, the X header, and the ISO. The README and the agent skill carry their lowercase variants.
2026-09-01 11:54:15 +02:00
Ryan Hughes b686ed892d Merge pull request #9267 from omacom/fix/close-password-only-sshd
Disable sshd entirely when no usable key is authorized
2026-08-30 18:46:35 -04:00
Ryan HughesandClaude Fable 5 5c03dc8c09 Disable sshd entirely when no usable key is authorized
The old setup command enabled sshd before importing a key, so an aborted
run left a password-only server exposed. Skipping that machine kept the
hole Omarchy opened; close it instead by disabling sshd. Omarchy is a
desktop distro, so the console remains, and the warning explains how to
set up key-based access or deliberately re-enable password logins.

With the stakes flipped from skip to disable, "no usable key" must not
false-positive: follow an authorized_keys symlink to its key (dotfiles
setups have working key auth), and treat an unreadable file as
unverifiable rather than keyless.

Amends the unreleased 1788124236 migration in place; no released install
has run it, so every machine still gets the new behavior in one pass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-30 18:45:05 -04:00
Ryan Hughes 3c2a24b248 Merge pull request #9255 from omacom/security/migrate-existing-sshd-hardening-v4-0-2
Harden existing key-based SSH setups
2026-08-30 18:38:00 -04:00
Ryan HughesandClaude Fable 5 986962bb64 Keep the sshd hardening migration from locking users out
Validate authorized_keys line by line with the question sshd actually
asks: ssh-keygen -lf on the whole file also fingerprints a private key
copied there by mistake, which sshd cannot use, so the migration would
have disabled the only working login path.

Tighten ~/.ssh and authorized_keys the way omarchy-setup-security-sshd
does, and back off from a group-writable home directory: StrictModes
makes sshd ignore the key either way, with the same lockout.

Complete with a notice instead of failing on conditions the migration
cannot repair (a broken or pre-Include sshd_config, an overriding admin
rule, a failed reload of a valid config), so those machines keep passwords
as they were without blocking every migration queued behind this one.
Only missing privileges stay pending, since a terminal rerun fixes that.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-30 18:36:26 -04:00
Ryan Hughes a93ee6a433 Merge pull request #9263 from omacom/fix/shell-test-host-assumptions
Fix test failures caused by host assumptions
2026-08-30 18:27:24 -04:00
acrogenesis ca4f596a14 Harden existing key-based SSH setups 2026-08-30 18:07:59 -04:00
Ryan Hughes 279f4d6b95 Give the sshd acceptance exercise a terminal for sudo
Without a terminal sudo keys its cached credential on the parent
process of each call, so the timestamp validated by sudo -S -v in the
test shell never reached omarchy-setup-security-sshd's own sudo calls
when omarchy-iso-test drove the suite over ssh with no pty, and the
exercise died with 'a terminal is required'. Run it under script(1)
and validate the password on that pseudo-terminal first, so every sudo
underneath shares the terminal-keyed credential.
2026-08-30 18:06:33 -04:00
Ryan Hughes 243fe1c9d9 Shadow the git URL checker instead of thinning PATH
The missing-checker case dropped $ROOT/bin from PATH to make
omarchy-git-url-check unfindable, but installed machines carry the
packaged checker in /usr/bin, so it was always found and the test
failed on every 4.x machine. Shadow it with a stub that reports
command-not-found so the scenario holds regardless of the host.
2026-08-30 17:48:34 -04:00
Ryan Hughes bae189861f Copy the Windows VM helper before the test hides /home
The mount-boundary test tmpfs-mounts over /home before sourcing
$ROOT/bin/omarchy-windows-vm, so a checkout living under /home vanished
mid-test and set -e aborted with no output. Take a mount-safe copy of
the helper into the test tmpdir before the mounts land.
2026-08-30 17:48:34 -04:00
Ryan Hughes 981274b20a Merge pull request #9249 from omacom/fix/acceptance-installed-tree-default
Default the acceptance suite's OMARCHY_PATH to the installed tree alone
2026-08-30 16:58:09 -04:00
Ryan Hughes fe1325202b Default the acceptance suite's OMARCHY_PATH to the installed tree alone
The suite verifies the finished product: VM runs never use a dev-linked
tree, so the session-environment lookup and own-checkout fallback were
needless indirection. /usr/share/omarchy is the default; a caller testing
a different tree passes OMARCHY_PATH itself.
2026-08-30 16:58:04 -04:00
Ryan Hughes 432b5e3e24 Merge pull request #9240 from omacom/fix/acceptance-security-coverage
Fix the bar visibility toggle and make the acceptance suite cover 4.0.2 security hardening
2026-08-30 16:40:42 -04:00
Ryan Hughes 99ec17acfa Cover the 4.0.2 security hardening in the acceptance suite
Assert the closed session-to-root paths on an installed system — no blanket
input-group membership, no shipped asdcontrol sudoers grant — and exercise
omarchy-setup-security-sshd unattended end to end: sshd up, key authorized,
password and keyboard-interactive authentication off in the effective
config, SSH port rate limited in the firewall.

The sshd section mutates the machine, so it requires the explicit
OMARCHY_ACCEPTANCE_SUDO_PASSWORD opt-in that omarchy-iso-test passes for
its throwaway VMs; elsewhere it skips.
2026-08-30 16:30:51 -04:00
Ryan Hughes 9ca8f90e91 Capture OCR screenshots at 2x scale
Tesseract routinely drops small caption text at native resolution — the
weather panel's detail labels fail the WIND assertion with the text plainly
on screen. Let the compositor upscale the capture instead.
2026-08-30 16:30:51 -04:00
Ryan Hughes d3a5e69162 Fail the package audit when the manifest is missing
Reading a nonexistent manifest produced an empty package list, so the audit
reported every package installed after checking none of them.
2026-08-30 16:30:51 -04:00
Ryan Hughes d6130394fa Default the suite's OMARCHY_PATH to the running session's tree
Run over SSH with no OMARCHY_PATH, the acceptance runner defaulted it to
its own root — wrong in both sync modes omarchy-iso-test uses. With only
test/ synced, the root has no shell or install manifests: omarchy-shell
refuses every call and the package audit passes vacuously against an empty
manifest. With a full tree synced, the path disagrees with the config path
the session shell was started from, and since qs matches instances by that
path, every omarchy-shell call reads as "not running".

The suite acts on the running session, so ask the user manager for the
session's own OMARCHY_PATH first, then fall back to this checkout, then to
the installed tree.
2026-08-30 16:30:45 -04:00
Ryan Hughes 7aceb388e7 Merge pull request #9226 from omacom/security/add-security-policy
Add security policy
2026-08-30 16:15:41 -04:00
Ryan Hughes e1fc502286 Nudge the bar over IPC when toggling visibility
The shell notices the bar-off flag through a FileView watch on the toggles
directory, and that watch can permanently stop delivering events after flag
changes land in quick succession — the bar then stays parked off screen
until the shell restarts. Have omarchy-toggle-bar nudge the bar's probe
over IPC after flipping the flag, so the toggle no longer depends on the
watch staying alive. The watch remains for other writers of the flag.
2026-08-30 16:10:57 -04:00
Ryan Hughes e68994680a Merge pull request #9232 from omacom/fix/menu-acceptance-style-navigation
Fix Style submenu navigation in the menu acceptance test
2026-08-30 15:32:49 -04:00
Ryan Hughes 55a3906f4c Step past the restored Unlock entry to reach Menu Bar in the menu test
The Style submenu grew its Unlock entry back (d411c90a) the same day the
menu acceptance test was written, so the blind Down-key walk landed on
Font and picked a font instead of opening the Menu Bar submenu — the bar
position assertion then timed out on every run.
2026-08-30 15:31:13 -04:00
acrogenesis f8d7fae7a8 Match website security guidance 2026-08-30 13:26:18 -06:00
acrogenesis 3def390764 Add security policy 2026-08-30 13:19:11 -06:00
Ryan Hughes a24064c720 Merge pull request #9225 from omacom/fix/sshd-hardening-verification-case
Match sshd -T keywords case-insensitively when verifying SSH hardening
2026-08-30 15:13:52 -04:00
Ryan Hughes 71d7ac81ae Match sshd -T keywords case-insensitively when verifying hardening
OpenSSH 10.x prints configuration keywords in CamelCase in its sshd -T
dump, where 9.x printed them lowercase. The case-sensitive grep in
omarchy-setup-security-sshd therefore never matched on OpenSSH 10.x, so
the hardening drop-in was always judged ineffective and removed, leaving
password authentication enabled.
2026-08-30 15:03:06 -04:00
Ryan Hughes 4271b880c3 Merge pull request #9214 from omacom/rc-channel-pacman
Point the rc channel at the rc package repository
2026-08-30 13:54:07 -04:00
Ryan Hughes 884ca49340 Point the rc channel at the rc package repository
pacman-rc.conf shipped with [omarchy] on pkgs.omarchy.org/edge — a
leftover from when release candidates published there. Candidates now
publish to a dedicated rc channel, so a machine switched to rc with
omarchy-refresh-pacman was pairing the rc Arch mirror with edge omarchy
packages, and omarchy-version-channel could not name the rc repository
at all (an rc install reported 'rc / unknown').

Point the conf at pkgs.omarchy.org/rc, teach omarchy-version-channel
the rc repository, and repoint existing rc-channel machines with a
migration. The migration only rewrites the shipped pairing (rc mirror +
edge [omarchy]); an administrator's deliberate combination is kept.
2026-08-30 13:52:06 -04:00
Ryan Hughes 21b27c5aed Merge pull request #9200 from omacom/security/v4-0-2-input-asdcontrol-sshd
[4.0.2] Close unprivileged input and SSH escalation paths
2026-08-30 13:03:09 -04:00
Ryan HughesandDavid Heinemeier Hansson df819a6f98 Close three paths from an unprivileged session to root
Apply the Omabot patch on Quattro, verify effective SSH hardening, prevent stored provisioning state from restoring the blanket input-group grant, and stop Omarchy from shipping asdcontrol authorization that belongs to the package.

Co-authored-by: David Heinemeier Hansson <david@hey.com>
2026-08-30 12:54:08 -04:00
Ryan Hughes 943d2fcbe9 Merge pull request #9002 from acrogenesis/remove-legacy-installer-privileged-files
Repair legacy paths and privileged files left by retired installers
2026-08-30 12:07:18 -04:00
Ryan Hughes 58c399de30 Revert "Drop unrelated privileged heredoc scanner"
This reverts commit 4c23077f80.
2026-08-30 11:54:31 -04:00
Ryan Hughes 15f26cbe1b Remove redundant migration command preflight 2026-08-30 11:49:54 -04:00
Ryan Hughes 4c23077f80 Drop unrelated privileged heredoc scanner 2026-08-30 11:49:50 -04:00
Ryan Hughes 40d0c9bbdf Require Quattro migrations to complete 2026-08-30 11:36:22 -04:00
Ryan Hughes 8add7b49de Repair legacy XCompose and vulnerable power paths 2026-08-30 11:36:22 -04:00
625c4a1603 Quote install-app and install-font names like install-and-launch (#7843)
* Quote install-app and install-font names like install-and-launch

* Quote the package list too, not just the display name

The display name was quoted but omarchy-pkg-add's own arguments were still interpolated into the bash -c string raw, so `omarchy install app Vim 'vim; id'` ran id. The list has to reach the helper as several words, so it cannot be quoted whole: it is split the way the unquoted expansion split it and each word is quoted on its own. Reading with -d '' keeps a newline-separated list intact instead of dropping every package after the first, which plain read -a would. install-font's package is singular and is quoted whole, and install-and-launch carried the same flaw.

Reported by acrogenesis in review of #7843.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>

* Test that install-font skips font-set when pkg-add fails

The hostile-package case was asserting the family still got set, which only held because the mock always exits 0. pacman would reject that name and the && chain would skip font-set.

* Keep the installers working when errexit is inherited

read -d '' always ends at EOF rather than on its delimiter, so it reports failure on every input. Under an inherited errexit the installers exited there and built no command at all.

Reported by Codex XHigh in review of #7843.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>

---------

Co-authored-by: David Heinemeier Hansson <david@hey.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Codex XHigh <noreply@openai.com>
2026-08-30 14:22:58 +02:00
David Heinemeier Hansson a041e9a7f3 Merge pull request #8611 from smfworks/feat/hermes-skill-symlinks
Link Omarchy agent skills into Hermes
2026-08-30 12:53:21 +02:00
David Heinemeier Hansson 2541eeee3d Merge quattro into hermes-agent
Catches the branch up on 94 commits so what lands here is reviewed against
current quattro, and so #8611 contributes its own five files rather than
dragging a partial catch-up in behind it.
2026-08-30 11:58:37 +02:00