Omahub
← All plugins
D

BarDisplay

by Deoxizn

Show or hide the bar per display. Lists every monitor with a toggle.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
3da0148
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3da0148
Reviewed
1 month ago

The plugin is a bar widget that toggles bar visibility per monitor. It writes only user-owned config files on the normal path, and its optional admin patch is well-guarded with path allowlists, symlink checks, and backups. The deterministic scan found no issues, and the code is transparent and non-malicious.

  • The plugin can run a script with root privileges via pkexec to patch a system file, but it is guarded by path allowlisting, symlink refusal, and backup validation, and requires explicit user action.
  • The patch script modifies the active bar's QML file, which could theoretically break the bar if the patch anchors change, but it is idempotent and restores backups on failure.
  • The service runs `hyprctl monitors -j` and `omarchy restart shell`, which are standard system commands with no destructive behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Deoxizn/BarDisplay --enable
Appearance #bar

BarDisplay

Show or hide the Omarchy bar per display.

A bar-widget button + a popup that lists every monitor with a toggle, its resolution and refresh rate. Turning a display off hides the bar there; the bar always stays visible on at least one display. Works with the Shibumi bar and the default Omarchy bar.

<p align="center"> <img src="preview.png" alt="BarDisplay: monitor list popup with per-display toggles, resolution and refresh rate" /> </p>

Install

omarchy plugin add https://github.com/Deoxizn/BarDisplay.git --enable

omarchy plugin add clones the repo, validates it, and enables the widget in the right section of the bar. Or drop the widget into bar.layout.right in ~/.config/omarchy/shell.json manually. The shell hot-reloads plugins and the bar.

Updating

omarchy plugin update dev.deoxizn.bardisplay

omarchy plugin update fetches the latest version, shows the diff, and asks before applying it. Run it without an id to update every installed git-managed plugin.

How it works

  • A headless service owns the state. The set of displays the bar appears on is stored in ~/.config/omarchy/shell.json under bar.monitors; an empty list means "every display" (the default, so nothing changes out of the box).
  • Toggling a display writes bar.monitors and pushes the list straight into the running bar, so panels appear/disappear without a restart.
  • Bar plugins have no native per-display toggle, so the service also runs scripts/ensure-bar-support.sh against the active bar's QML. That patch is idempotent (skips when already applied), backs the file up first, and refuses to touch the bar if its structure changed after an update — so it can't break the bar, it just re-applies the support when an update wipes it.
  • The default Omarchy bar lives in root-owned /usr/share/omarchy, so patching it needs a one-time admin grant. The panel shows an Apply button that runs the same script through pkexec; the support re-applies itself after updates (the panel will ask again).
  • System bars are not watched by Omarchy's plugin watcher (that only hot-reloads bars under ~/.config/omarchy/plugins), so the running built-in bar cannot read a freshly patched file. After a successful admin patch the panel confirms it (a desktop toast plus an 8-second countdown with a Cancel in the popup, in case pkexec's dialog stole the focus) and auto-restarts the shell via omarchy restart shell (Omarchy's own crash-free restart — not Quickshell.reload, which can crash quickshell-git). If the restart ever fails the panel keeps a manual Restart button.
  • The widget and its popup live in one Panel.qml entry point (like Omabench). The KeyboardPanel is a direct child of the widget root, which the Shibumi host relies on to anchor the popup to the visible bar edge and size it to the real content — don't wrap it in a Loader or inner Item.
  • Physical resolution and refresh rates come from hyprctl monitors -j (Hyprland), fetched once by the service at startup. Quickshell screens only report logical (scale-divided) pixels, so the physical width/height would otherwise read wrong on scaled displays.

Uninstall

omarchy plugin remove dev.deoxizn.bardisplay

Remove the widget from bar.layout in shell.json, and if you want to revert the bar itself, restore the backup the support script keeps next to the patched file (Bar.qml.bardisplay.bak).

Security

BarDisplay never modifies system files on the normal code path:

  • Shibumi bar: has native barMonitors support; the plugin only writes bar.monitors to ~/.config/omarchy/shell.json (user-owned).
  • Stock Omarchy bar: lives at /usr/share/omarchy/shell/plugins/bar/Bar.qml (root-owned). The one-time admin patch via pkexec is guarded by:
    • Symlink refusal — the script refuses to operate on symlinks for both the bar file and its backup.
    • Path allowlist — the elevated script only accepts the exact stock bar path (/usr/share/omarchy/shell/plugins/bar/Bar.qml); any other path is rejected.
    • Backup validation — the backup is verified to be a regular file in the same directory as the bar file.
    • TOCTOU re-check — the bar file is re-verified as a regular file immediately before the write, after the backup is created.
    • Self-healing on update — if the stock bar is updated and the patch is wiped, the service detects it and re-applies (the user is asked again).

Known issues

  • A one-time shell crash after the first install is a quickshell-git bug, not a BarDisplay problem. Quickshell.reload tears the IPC handler registry down in a way that can use-after-free (IpcHandler::updateRegistration, FileView) when a new engine generation is created — the reason Omarchy ships with Quickshell's own reloading disabled and reloads at the plugin level instead. BarDisplay used to call Quickshell.reload(false) to make the patched bar pick up its support; that reload was what crashed, so it has been removed in favor of Omarchy's plugin watcher, which re-creates user-owned bars the moment the patch writes their QML. For the built-in (system) bar — which the watcher does not cover — the service instead restarts the shell with Omarchy's own omarchy restart shell after a successful admin patch.
  • The bar patch is applied at shell startup from values computed fresh from the loaded manifests. Relying on QML bindings that read nested members of a property var (like manifest.__sourceDir) reads stale inside the host's change handlers and silently skips the patch; sourceDirFor() / activeBarFileFor() / supportScriptFor() avoid that.