Skip to content

security: harden shell status execution - #222

Merged
tcballard merged 2 commits into
mainfrom
codex/plugin-runtime-hardening
Sep 4, 2026
Merged

tcballard merged 2 commits into
mainfrom
codex/plugin-runtime-hardening

Conversation

@tcballard

@tcballard tcballard commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Summary

  • execute root-owned absolute paths for timeout, omachat-ctl, and legacy jq
  • mark dynamic QML text as plain text
  • pin the reviewed runtime contract to Omarchy 4.0.1, Quickshell 0.3.1, and Qt 6.11.2
  • document the 64 KiB output contract and require revalidation after runtime changes
  • declare coreutils as a package dependency
  • bump the plugin manifest version to 0.0.2

Supply-chain boundary

The Quattro widget targets the plugin API and Quickshell/Qt builds supplied by Omarchy v4.0.1. It does not claim compatibility with floating standalone Quickshell builds.

Validation

Not run in this session. Run the repository's full gate and live Omarchy v4.0.1 plugin validation before merge.

@tcballard
tcballard force-pushed the codex/anchor-deadlines branch from f1e056d to 3fe5fab Compare September 4, 2026 07:39
@tcballard
tcballard changed the base branch from codex/anchor-deadlines to main September 4, 2026 07:46
@tcballard
tcballard force-pushed the codex/plugin-runtime-hardening branch from d4fbb78 to 709e85e Compare September 4, 2026 07:46
@tcballard
tcballard merged commit 87c3bcb into main Sep 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant