Omarchy Week in Review: Quattro, Agents, and Security Defaults

Omarchy’s Quattro week kept landing punches. Between the Quickshell rewrite still echoing from mid-August, an agentic desktop that puts Ollama and LM Studio in the install path, foundation money upstream, a security sprint that closed a long-standing Docker-group footgun, and a loud gaming frame from NAG, this is the update cycle Linux workstation people should actually read. Here’s the EtherNinja cut — packets, privilege, and what to do next.

Quattro, Quickshell, and 4.0.2

Omarchy 4.0.0 (Quattro) wasn’t a theme refresh. It replaced a pile of desktop glue with a Quickshell-centered shell, pushed more of the stack into Arch packages, and bet the workstation on agents as first-class citizens. Phoronix covered the release; the practical takeaway is simpler: your tiling desktop now has a stronger opinion about panels, widgets, and agent hooks. If you customized Hyprland Lua heavily, expect migration friction — Quattro is a system move, not a quiet patch Tuesday.

Six days after 4.0.1, v4.0.2 landed another security pass: signed packages from the Omarchy repo, hardened SSH (password auth off by default on fresh hardening paths), CUPS and display-manager asset lockdowns, tighter web-app URL and desktop-entry handling, and closed unprivileged input/SSH escalation paths. The Omarchy Review’s 4.0.2 write-up is a clean checklist. Verified SHA256 on the release notes: 2ef8e624aa1bec7e277e28056b8535a6c9373ba48d7ede3f1a01cb6d2373cfb8. Fresh installs should grab the current omarchy-4.0.2.iso; existing Quattro boxes should run Update > Omarchy, then log out/in so group and SSH migrations stick.

Gaming frame

NAG’s coverage quotes DHH’s “best damn OS for gamers” push and notes Omarchy already ships Steam, RetroArch, Heroic, Lutris, Battle.net (incl. GE-Proton paths), Moonlight, Xbox Cloud Gaming, and GeForce Now in the install story — plus early native Wayland titles like BonkCity targeting Omarchy directly. Anti-cheat and Game Pass remain industry problems, not distro magic. Still: when a Hyprland workstation starts getting indie native builds and a gaming narrative in the same cycle as Quattro, netops people should notice the audience widening past ricers and Rails shops.

Agentic desktop: Ollama and LM Studio in the path

Quattro’s other headline is agents on the metal. Omarchy’s install and menu path treat local model runtimes as neighbors to coding agents — Ollama, LM Studio, and friends sit next to the same hotkeys and crash-hand-off story. AI Socratic framed it as betting the Linux desktop on agents. Private inference on your LAN is no longer a weekend science project bolted onto a ricing setup; it’s part of the default narrative. Same week the wider industry accelerates local stacks (more in our AI week note), Omarchy wires the desktop so an agent can live beside your SSH sessions without living only in a browser tab.

Omacom Foundation: patrons, spend, and upstream

Momentum isn’t only code. Quattro crossed 200,000 ISO downloads in about 18 days. On the money side, 1Password and 37signals became Distinguished Corporate Patrons, the foundation announced crossing $13M with Distinguished Patrons joining Founding and corporate backers, and it committed to be the exclusive multi-year Hyprland sponsor (Hyprperks going free; personal donations still welcome). First full-time hire: kernel developer Krzysztof Wilczyński to lead Omarchy Kernel work (PCI/endpoint background, performance/compat/security focus). Token patronage followed — ~$1.95M in lab tokens (Meta Founding Token Patron; Anthropic, OpenAI, and Fireworks as Distinguished Token Patrons). Then open patronage tiers plus another roughly +$510k (OpenRouter tokens, Four Technologies corporate pledge, ~$60k from open patrons) pushed total pledges into the mid-$15M range, with an explicit spend-down plan rather than a vault. Opinionated Arch desktops used to die when one maintainer got busy. Foundation capacity explains how Quattro could land security sprints days after disclosure — and why upstream Hyprland/Quickshell/kernel work suddenly has payroll behind it.

Docker group = root, then the fix

The sharpest operational story: Omarchy’s default install historically put the user in the docker group. On Linux, that membership is effectively root — the socket talks to a privileged daemon. Researcher write-up at 0xcc.io made the exposure plain. v4.0.1 stopped auto-adding users to the Docker group and made sudoless Docker opt-in, alongside safer agent launch defaults, FIDO2 staging paths, plugin/git transport guards, USB-name-as-Lua traps, and more. If you installed before that change, don’t assume the menu update alone remade your session. Check id, confirm whether docker still appears, and treat “convenient container access” as a conscious privilege decision.

Lua and config gotchas

Quickshell and Hyprland Lua are powerful; they’re also injection surfaces if untrusted strings become code. Several 4.0.1/4.0.2 fixes stop device names, theme installers, and shell text paths from becoming executable config. If you maintain custom plugins or theme overlays, read the release notes before you update — then diff your overrides.

What to do

Update to the current Quattro line (4.0.2). Verify Docker group membership and SSH password-auth posture. Treat sudoless Docker as a conscious risk with a documented blast radius. Keep agents and local models — but keep least privilege next to them. EtherNinja will keep tracking Omarchy the same way we track anything else that sits on Arch and touches your trust boundary: clean notes, real links, no hype.

Leave a comment

Published discussion only. Your email is not shown.

This site uses Akismet to reduce spam. Learn how your comment data is processed.