Updated 4 Sep 2026: Updates Omarchy 4 to current v4.0.2, replaces two dead issue sources, adds the Aug 31 security-hardening release, and refreshes operational evidence with current Quickshell crash/OOM reports. Keeps user reports explicitly anecdotal rather than treating them as measured reliability data.

Key details

  1. Omarchy 4.0.0 (Quattro) was released August 14, 2026.
  2. The default shell is one long-running Quickshell process replacing Waybar, Walker, Mako, SwayOSD, hyprlock, hypridle, swaybg and polkit-gnome.
  3. The shell exposes plugins and IPC-scriptable controls.
  4. Omarchy internals moved from a git-managed layout to system packages to separate project files from user customization.
  5. v4.0.1 shipped August 25 as a fast-follow security/fix release.
  6. v4.0.2 shipped August 31 and is currently marked the latest release.
  7. v4.0.2 adds signed Omarchy repository packages plus multiple installer, SSH, privilege, browser-policy and shell-input hardening fixes.
  8. Current 4.0.2 issue reports include a hibernate-resume Quickshell crash and one severe runaway-memory/OOM event; these are individual reports, not prevalence data.

What builders should take away

  1. Update Quattro installations to the current stable release rather than staying on 4.0.0; the follow-up releases include security hardening, not only cosmetic fixes.
  2. Treat Omarchy 4 as an architectural migration: test shell plugins, IPC integrations, lock/authentication paths and custom workstation scripts against the exact packaged Quickshell version.
  3. Prefer documented plugin/IPC surfaces over patching installed shell files so future package updates remain manageable.
  4. Keep backups and a rollback path when upgrading workstation images, especially when the shell is central to many desktop functions.
  5. For managed fleets, monitor Quickshell memory/crash behavior and verify automatic shell recovery, suspend/resume and multi-monitor workflows before broad rollout.
  6. Do not infer a general reliability rate from individual GitHub issues; use them as failure-mode examples to inform testing.

What changed

Omarchy 4.0.0 (Quattro), released August 14, 2026, re-architected the distribution around one long-running Quickshell process for the bar, launcher, menus, notifications, on-screen displays, control panels, lock screen and polkit agent, replacing Waybar, Walker, Mako, SwayOSD, hyprlock, hypridle, swaybg and polkit-gnome. The project moved internals from a git-managed layout into system packages and exposed plugin and IPC extension surfaces. Two fast-follow releases have since landed. Omarchy 4.0.2, released August 31 and currently marked latest, adds another substantial security pass: signed Omarchy repository packages, fixes for shell injection in theme/application installers, SSH and sudo hardening, safer browser policy permissions, protection against remote-image injection in shell text, and other privilege-boundary fixes. Current issue reports also show Quickshell-specific failures on 4.0.2, including a reported runaway memory allocation that exhausted RAM and swap on one Framework laptop and a separate hibernate-resume shell crash. Those are individual reports, not a measured failure rate.

Why it matters

The unified shell changes both extension ergonomics and failure concentration. Builders can customize one themed runtime through plugins and IPC instead of synchronizing many independent components, while Omarchy’s rapid security follow-ups show the project is hardening the larger privileged workstation surface created by an opinionated distribution. But because the bar, launcher, notifications, lock-related UI and other services share Quickshell, a severe shell failure can affect more of the desktop at once than a single daemon failure. The correct takeaway is not that Quickshell is unreliable; it is that a unified shell makes version pinning, rollback and observability more important.

One shell replaces a collection of desktop components

Omarchy 4’s Quickshell process owns the bar, launcher, menus, notifications, on-screen displays, control panels, lock screen and polkit agent. Waybar, Walker, Mako, SwayOSD, hyprlock, hypridle, swaybg and polkit-gnome are no longer the default architecture.

Plugins and IPC are the intended extension boundary

The long-running shell is plugin-based and exposes IPC controls, allowing users to package widgets and behaviors against one themed runtime. The project’s system-package move also separates Omarchy-owned files from user modifications more cleanly than the older git-managed arrangement.

v4.0.2 is already a substantial security follow-up

The August 31 v4.0.2 release adds additional security fixes validated by the Omarchy Security team. Release notes include signed repository packages, shell-injection fixes in theme and application installers, hardened SSH and browser-policy permissions, safer privilege paths, remote-image-injection protection and secure handling of several workstation integration surfaces. This follows the first v4.0.1 fast-fix release on August 25.

A unified shell also centralizes some failure impact

Fresh GitHub issue reports on 4.0.2 include a Quickshell SIGSEGV after hibernate/resume and one reported runaway Quickshell memory event that consumed more than 43 GB of resident memory plus swap before the kernel intervened. These are anecdotal issue reports rather than systematic reliability evidence, but they demonstrate why a shell process that owns many desktop functions deserves explicit crash/restart and rollback testing.

Why this matters beyond one distribution

Omarchy is a visible independent example of a Linux workstation treating the desktop shell as a programmable product surface. Its package separation, plugin/IPC design and rapid security response are useful implementation evidence for other projects considering a coherent shell rather than a stack of independently configured daemons.

Timeline

2026-08-14

Omarchy 4.0.0 ships Quattro

The desktop is consolidated into the new Quickshell-based programmable shell.
2026-08-25

Omarchy 4.0.1 fast-follow fixes

The first follow-up release focuses heavily on security and migration fixes.
2026-08-31

Omarchy 4.0.2 ships

A second security-heavy follow-up adds signed repository packages and multiple installer, SSH, privilege and shell hardening changes.

What to watch next

  • Whether Quickshell/plugin API behavior stabilizes across the rapid Quattro point releases.
  • Resolution and recurrence of reported memory, hibernate/resume, bar and plugin-state failures on 4.0.2.
  • Growth of third-party plugins and any stronger permission/security model for plugin execution.
  • Whether the project’s new signed package/release pipeline reduces supply-chain and workstation-upgrade risk in practice.
  • How system-package separation affects long-term user overrides and reproducible workstation builds.

Still unclear

  • Omarchy is an independent distribution and its architecture may not generalize to other Wayland desktops.
  • The plugin and IPC interfaces are new, so long-term compatibility and security practices are still emerging.
  • Current crash and OOM evidence comes from individual GitHub issue reports, not a systematic reliability study or incidence dataset.

Sources

Direct reading behind this dossier.

5 sources
The Quattro Release (v4.0.0)
Omarchy primary release notes

Defines the unified Quickshell architecture, replaced components, plugin/IPC model and upgrade/install path.

Omarchy v4.0.2
Omarchy primary release notes

Current latest stable release; documents additional security fixes, signed repository packages, installer/SSH hardening and other fast-follow improvements.

Omarchy repository
Omarchy primary repository

Inspectable source and current Quattro development surface.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment