Omahub
← All plugins
F

decomposer

by Felipe Infante de Castro

Linux software for the Opal C1 webcam: GPU looks, background blur, manual focus - toggled from the bar

Security review

Review recommended · 25 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
7bc37db
Scanned
2 weeks ago
  • Shell sources dynamically generated content.

    . /dev/video11 always removes
  • Shell sources dynamically generated content.

    . /dev/video0 returns in ~14s.")
  • Shell sources dynamically generated content.

    . /dev/video0
  • medium package_manager tests/test_architecture.py:106

    System-wide Python package installation (not --user).

    pip install")):
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo cp packaging/decomposer-usb.conf /etc/tmpfiles.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/60-opal-c1.rules /etc/udev/rules.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload-rules
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm trigger --action=add --subsystem-match=usb
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/v4l2loopback.conf /etc/modprobe.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/v4l2loopback-load.conf /etc/modules-load.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n"
  • Docs external_hosts README.md:50

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/fidecastro/decomposer
  • Docs package_manager docs/SETUP.md:18

    System-wide Python package installation (not --user).

    pip install 'decomposer[gui]'
  • Docs package_manager README.md:52

    System-wide Python package installation (not --user).

    pip install -e .
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python-gobject gtk4 libadwaita gtk4-layer-shell
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/v4l2loopback.conf /etc/modprobe.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/v4l2loopback-load.conf /etc/modules-load.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/v4l2loopback.conf /etc/modprobe.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/60-opal-c1.rules /etc/udev/rules.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 0644 packaging/decomposer-usb.conf /etc/tmpfiles.d/
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemd-tmpfiles --create

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7bc37db
Reviewed
2 weeks ago

The bar widget is a simple QML button that runs the fixed command `decomposer toggle` when pressed; the plugin itself has no install-time code, network exfiltration, hidden persistence, or privileged operations. The deterministic medium findings are all false positives from documentation/comments: sudo and pip examples in SETUP.md, `. /dev/video...` fragments in docstrings, and the PNG magic bytes in a color-target generator script.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/fidecastro/decomposer --enable
Hardware #bar #ai #media
<p align="center"> <img src="docs/img/mark.png" width="140" alt="the decomposer mark"> </p> <h1 align="center">decomposer</h1> <p align="center"><em>Linux software for the Opal C1 webcam.</em></p>

The Opal C1 was the best webcam you could buy, and then its maker moved on. The software that made it special runs only on Macs, and it hasn't seen much love in years. Plug the camera into a Linux box and it pretends to be an ordinary webcam. The good parts stay locked inside.

decomposer opens them up. The looks, the manual focus, the background blur, the frame rates the sensor could always do but was never asked to. It gives the camera the second life it deserves.

<p align="center"> <img src="docs/img/desktop-2.png" width="900" alt="decomposer on an Omarchy desktop: the panel dropped from the bar, over the tiling"> </p>

It is built for Omarchy. The panel drops from the bar, follows your theme, and stays out of the way. There is also a plain command line for everything, so nothing depends on the panel being open.

How it was made

No firmware hacking. No reverse engineering of Opal's app. Two AI agents, Fable and Grok, sat with the camera and asked its endpoints questions until the answers made sense: what the USB descriptors admit to, what the hidden XLink server will say, what the sensor claims it can do and what it actually delivers. Every feature here is built on a measured answer, and the measurements are written down.

The color looks are the real Composer looks. They were extracted by photographing test charts through Opal's own app and distilling the difference into lookup tables. Zero guesswork, zero round-trip error.

What it can do

Everything is listed in docs/FEATURES.md — the two capture modes, the looks, background blur and bokeh, your own ONNX models over the feed, and the rest.

Get it running

git clone https://github.com/fidecastro/decomposer
cd decomposer && cargo build --release --manifest-path engine/Cargo.toml
python -m venv .venv && .venv/bin/pip install -e .
.venv/bin/decomposer doctor        # tells you exactly what is missing
.venv/bin/decomposer daemon        # SEND /dev/video10 + Normal /dev/video11

doctor walks the whole stack and points at what is missing. Every command that touches your system lives in docs/SETUP.md — the app never runs a privileged command, and never asks you to from inside the code.

The bar widget

The repo doubles as an Omarchy plugin: manifest.json and BarWidget.qml at the root give the bar a pixel-mark button that toggles the panel. Install it from the Omarchy plugin marketplace, or locally with decomposer install-plugin --add-to-bar. The widget runs decomposer toggle, so the app itself needs to be installed either way.

Agents and developers

Read docs/ENGINEERING.md to know more: the hard questions this camera asked back, and exactly how each one was answered. The raw lab notes live in docs/camera-notes.md.


decomposer is not affiliated with Opal. It exists because the C1 is too good a camera to leave behind.