# Security policy ## Supported versions Security fixes are provided for the latest release on the default branch. ## Reporting a vulnerability Please do not open a public issue for a suspected vulnerability. Use GitHub's **Security → Report a vulnerability** form for this repository so details can be reviewed privately. Include the affected Omawall version, Omarchy version, UFW version, the action that exposes the problem, and a minimal reproduction when possible. Please do not include passwords, private keys, public IP addresses, or complete firewall configurations. ## Privileged boundary The QML interface and plugin-owned `omawallctl.py` helper always run as the desktop user. After validating structured arguments, the helper launches `pkexec /usr/bin/ufw ...`, so the only code Polkit executes as root is the root-owned UFW binary. No mutable file from the plugin directory is passed to `pkexec`, and no command is invoked through a shell. ## Untrusted UFW output Everything UFW prints is treated as untrusted input, because rule comments and addresses can be written by anything that has already configured the firewall. - `omawallctl.py` reads UFW under a timeout, a 256 KiB output cap, and a 512-rule cap, and stops draining a pipe once the cap is reached rather than buffering without end. - `Model.js` strips control characters and length-caps every field, default, and error string before the panel sees it. - Every `Text` item in `Panel.qml` sets `textFormat: Text.PlainText`. QML's default `AutoText` would render markup-shaped values as rich text, which can trigger resource loads from inside the shell process. A test enforces that each `Text` item keeps this property.