1b15120d272b88066a4da47e71a5a9c84b83ebb3
The argv click command closed injection through the hint's value, but the sender still handed the headline and description to notify-send bare. A value beginning with a dash is parsed there as flags, and one shaped like `--hint=string:omarchy-exec-argv:[...]` is read as a hint of its own -- libnotify keys hints in a hash table, so the later of two replaces the earlier and a forged headline outranks the vector --exec built. That is reachable without any --exec in sight: omarchy-tailscale-send passes a single file's basename verbatim as the description, so a file named like the hint gives its click action to whoever chose the name. Put the headline and description behind a `--` so notify-send reads them as text, and refuse any pass-through word carrying omarchy-exec-argv -- --exec is the only thing that may build a click command. Co-Authored-By: Codex XHigh <noreply@openai.com>
Omarchy
Omarchy is a beautiful, modern & opinionated Linux distribution by DHH.
Read more at omarchy.org.
The Omarchy Manual
The manual lives in manual/, which is its authoritative source. It's
mirrored to learn.omacom.io, where
its screenshots are also hosted.
The Basics
- Getting Started
- Coming From Mac or Windows
- Navigation
- The top bar
- Themes
- Hotkeys
- Unified Clipboard & History
- Reminders
- Notices
- Text Extraction & Dictation
- Screenshots & Recording
- Toggles, idle & screensaver
- Omarchy CLI
The Applications
- Terminal
- Neovim
- AI
- Development Tools
- Shell Tools
- Shell Functions
- TUIs
- GUIs
- Browsers
- Commercial apps/services
- Web Apps
- Gaming
- Filling out PDFs
- Windows VM
- Other Packages
Configuration
- Updates
- Dotfiles
- Shell plugins
- Monitors
- Keyboard, Mouse, Trackpad
- Networking
- System sleep
- Hardware authentication
- Fonts
- Backgrounds
- Prompt
- Branding
- Common tweaks
- Extra themes
- Making your own theme
The Rest
- Mac support
- Troubleshooting
- FAQ
- System snapshots
- Security
- Omarchy on...
- Dual Boot Install
- Unattended Installs
License
Omarchy is released under the MIT License.
Languages
Shell
57.3%
QML
31.2%
JavaScript
4.1%
Python
2.9%
Go Template
2.5%
Other
2%