# A root-capable desktop is not a named web operation.

The Sunday 30 August 2026 [rough.day](https://rough.day/) tech edition ranked “Omarchy desktop environment allows any user process to escalate to root” as item one. The live source is the 0xcc.io post [Omarchy: Any User Process Can Escalate to Root](https://0xcc.io/posts/omarchy-root-creds/). [Wrench](https://wrench.rip/) does not treat that host privilege grant as its job. It names a provider operation a session can call on purpose, attests whether the current contract can run it, and stays on provider capabilities rather than desktop root.

This news take uses the live 0xcc.io post fetched for this draft, the Sunday 30 August 2026 [rough.day](https://rough.day/) tech edition, the [rough.day selection notes](https://rough.day/info), and the public v0.16.7 pages for the [Wrench home](https://wrench.rip/), [provider capability attestation](https://wrench.rip/provider-capabilities/), [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/), [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/), and [rumour sourced take](https://wrench.rip/rumour-is-the-exploit/). Operation counts are the current release attestation, substituted at site build time. This page does not reprint the post or any privilege-escalation procedure.

## Sunday ranked a desktop privilege grant, not a Wrench contract

[rough.day](https://rough.day/) considers reporting from the previous 24 hours, groups related coverage, and publishes up to six stories per category when the day supports that many. Its [selection notes](https://rough.day/info) say the tech edition favors demonstrated impact and durable change over product promotion. The Sunday 30 August 2026 tech list placed the Omarchy privilege report at rank one, with 0xcc.io as the source host.

The ranked title is the edition’s headline. The live post title is “Omarchy: Any User Process Can Escalate to Root.” This page names both. It does not reprint the edition summary or the post’s reconstruction notes.

[Hraness](https://hraness.com/) publishes Wrench and this site. The edition is an independent ranking of a public desktop-security report. It is not a Wrench release note, and a ranked story does not add a provider operation.

## Session-wide root is a host story, not a named web job

The post says Omarchy’s default desktop left every process in the user session able to obtain host root, without a password, `sudo`, or a privilege prompt. The author reported the configuration privately. The project later removed that default and published 4.0.1. This page keeps that bound. It does not describe how a process obtained root, and it does not treat the patched default as a Wrench capability.

The object under test is the desktop session. A Linux environment that grants host root to ordinary user processes is making a local privilege decision. That is a different object from the [provider capability attestation](https://wrench.rip/provider-capabilities/), which names operations a session can call on purpose.

Wrench’s product is the outbound contract, not the workstation’s root boundary. The [Wrench home](https://wrench.rip/) states that each authenticated operation is typed, bounded, and tied to one account and transport. The caller brings the model and interface. Wrench supplies the local capability and custody layer. It is not an AI agent, planner, or approval shell. It does not decide which desktop processes may become root.

## Attestation names the operation a caller chose

The current release attests 327 operations across 23 bundled public adapters. 139 are `observed`. 188 remain `capture-required`. Those figures are the same release-bound counts published on the [provider capability attestation](https://wrench.rip/provider-capabilities/). This page does not add a provider, invent an Omarchy operation, or treat a reservation as ready. Telegram is absent from those manifests. Wrench does not install a Telegram Bot API substitute or claim Telegram contact access.

`observed` means the current contract can plan and execute after local doctor and auth checks pass. `capture-required` is an inert reservation. The attestation page says a missing or `capture-required` operation stays unavailable rather than falling back to general browser control. A desktop that can escalate a user process to root does not mark a Wrench reservation `observed`, and a patched host default does not invent one.

## Desktop root, guest machines, device policy, and rumour answer different questions

The [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/) asks whether a guest machine can stand in for attestation. The [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/) asks whether a rooted-phone check can stand in for a named web job. The [rumour sourced take](https://wrench.rip/rumour-is-the-exploit/) asks whether a search direction can stand in for that same job. This page asks whether a desktop that lets any user process escalate to root can stand in for named, attested web operations. The pages refuse different substitutes.

| Decision | Omarchy session-wide root grant | Wrench attested operation |
| --- | --- | --- |
| What is named | A desktop session whose ordinary processes can become host root | A named outbound outcome such as `messaging.list` |
| What is attested | Local privilege on the workstation, not an outbound contract | Exact provider, transport, account realm, contract version, implementation, input, and risk |
| Failed check | Any process in the user session could obtain host root | The operation stops. A `capture-required` reservation stays inert |
| Missing proof | A later patched default is still not a named web operation | The reservation cannot plan or execute, and Wrench does not invent a browser fallback |
| Job of the layer | Choose which desktop processes may become root | Name the operation a caller chose and attest whether it is available |

A session that can escalate to root still does not name `messaging.list` or mark a reservation `observed`. The post is evidence that a desktop default can grant host privilege. It is not a Wrench capability grant.

Read the VM page for containment. Read the PayPal page for device policy. Read the rumour page for agentic search. Read this page for why a root-capable desktop is not an attested operation. The pages do not reprint one another.

## Read the edition and the post, then the current contract

Start with [Omarchy: Any User Process Can Escalate to Root](https://0xcc.io/posts/omarchy-root-creds/). Keep the Sunday 30 August 2026 ranking on [rough.day](https://rough.day/) and the [selection notes](https://rough.day/info) as the edition record. [hraness.com](https://hraness.com/) is the publisher of Wrench. Then read the [provider capability attestation](https://wrench.rip/provider-capabilities/) for every current operation and completeness mark, the [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/) when the question is a guest machine rather than desktop root, the [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/) when the question is a rooted-phone check rather than a host privilege grant, and the [rumour sourced take](https://wrench.rip/rumour-is-the-exploit/) when the question is a search direction rather than a desktop default.
