Quattro 4.0.3: Hermes/OpenClaw OOB + security pass

Omarchy v4.0.3 landed September 8 with a twin headline: Hermes and OpenClaw out of the box, plus another security pass validated by the Omarchy Security team. This is not a rehash of the Quattro / 4.0.2 week-in-review — that covered the Quickshell rewrite, signed packages, SSH defaults, and the Docker-group footgun. 4.0.3 is the next patch: more coding agents in the install path, and lockdowns aimed at plugin auth, sudo expiry, and remote Kitty sockets.

Hermes, OpenClaw, and a thicker agent menu

OpenClaw installs from Install > AI, exposes a Control UI as a desktop app, and can become your default coding agent via the terminal interface. Omarchy owns onboarding and the local user gateway; uninstall prompts before wiping agent data. Hermes gets the same treatment — one install wired into desktop, terminal, and the default-agent launcher, with Omarchy skills linked into Hermes and prompted sessions using the native interactive UI.

The menu keeps filling: T3 Code with Omarchy theme support, Perplexity as a desktop AI app, Cursor CLI and Muse Code as default coding-agent options. For operators who already treat local agents as LAN neighbors to SSH sessions, this is packaging discipline — agents as first-class installables with removal hygiene — not another “paste this curl into root” weekend.

Security pass: plugins, sudo, Kitty, Broadcom

The security deltas are the part EtherNinja cares about most. Plugin access to authentication services is restricted — the right move when a Quickshell-era plugin catalogue explodes and agents write QML for fun. Temporary passwordless sudo now requires an expiry setup, which closes the classic “I enabled NOPASSWD for a script and forgot” hole. Kitty remote control is limited to local sockets, cutting a common remote-control overreach if something on the box tries to drive the terminal from elsewhere.

Also in the harden list: mise command-wrapper input handling, locate indexing defaults, ownership on installed sleep hooks, and lock-screen authentication command lookup. Compatibility side: fingerprint-reader setup improvements, Panther Lake kernel bump to 7.2.3, and Broadcom Wi-Fi switched to the DKMS driver after Arch dropped the prebuilt module — the kind of “wifi died after update” landmine that hits travel laptops hard.

Fresh vs the prior week-in-review: that piece covered Quattro’s Quickshell rewrite, 4.0.2’s signed packages and SSH/CUPS lockdowns, gaming framing, and Ollama/LM Studio in the path. 4.0.3’s delta is Hermes/OpenClaw OOB integration, a wider default-agent roster (Cursor CLI, Muse, T3 Code), and the auth/sudo/Kitty/DKMS cluster — treat it as the next security+agents patch, not a second summary of Quattro launch week.

Upgrade path

Existing machines: Update > Omarchy. Fresh metal: ISO at omarchy-4.0.3.iso (SHA256 03d60bc74306dca51f96e1a84b690871d8d606826b260edd0208962da8507d14). If you find issues, use the responsible disclosure path on omarchy.org/security — don’t dump half-baked PoCs into Discord.

Bottom line for netsec folks: 4.0.3 thickens the agent surface and simultaneously shrinks the privilege and remote-control blast radius. Install the agents you trust, expiry your sudo, and treat plugin auth restrictions as a feature — not friction.

Leave a comment

Published discussion only. Your email is not shown.

This site uses Akismet to reduce spam. Learn how your comment data is processed.