Omahub
← All plugins
E

T2 Fan Control

by Endijs

Monitor and configure t2fanrd from the Omarchy bar

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
f7f9a51
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f7f9a51
Reviewed
1 month ago

The plugin is a fan control widget that reads sensor data and uses a privileged helper to modify /etc/t2fand.conf. The helper validates inputs, uses atomic writes, and requires admin authentication via pkexec. No malicious behavior detected.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Endijs/omarchy-t2-fan-control --enable
Hardware #bar #quickshell #system

T2 Fan Control for Omarchy

An Omarchy Shell bar widget for monitoring Apple T2 Mac thermals and editing the existing t2fanrd fan curve.

T2 Fan Control panel

It displays the hottest CPU core and every fan exposed by applesmc. One-fan Macs keep the compact hero view; two-fan models gain a small per-fan RPM list.

Requirements

  • An Apple T2 Mac with the applesmc kernel driver
  • t2fanrd installed and enabled
  • pkexec/PolicyKit for authenticated configuration changes

The widget reads fan speed and temperatures without privilege. Saving a curve uses a separately installed, root-owned helper and opens a graphical administrator prompt. The helper validates all values, preserves the original /etc/t2fand.conf, and restarts t2fanrd. If the restart fails, it restores the previous configuration automatically.

Install

omarchy plugin add https://github.com/Endijs/omarchy-t2-fan-control.git
cd ~/.config/omarchy/plugins/io.github.endijs.t2-fan-control
sudo ./contrib/install-helper.sh
omarchy plugin enable io.github.endijs.t2-fan-control --section right

The second step installs the configuration helper at /usr/local/libexec/omarchy-t2-fan-control and its PolicyKit action. Monitoring works without this step, but saving and restoring fan curves remain disabled. Plugin updates intentionally cannot replace this root-owned copy. After updating the plugin, review the changes and rerun sudo ./contrib/install-helper.sh to install the matching helper version.

For local development, place the repository at ~/.config/omarchy/plugins/io.github.endijs.t2-fan-control, then run:

omarchy plugin validate ~/.config/omarchy/plugins/io.github.endijs.t2-fan-control
omarchy-shell shell rescanPlugins
omarchy plugin enable io.github.endijs.t2-fan-control --section right

Fan curves

  • linear: even ramp between the low and high temperature
  • exponential: quieter initially, steeper near the high temperature
  • logarithmic: stronger cooling earlier in the range

always_full_speed can be used continuously for maximum cooling, at the cost of additional noise, power use, dust accumulation, and fan wear.

Remove

Before removing the plugin, open the widget and select Restore original twice to confirm. After administrator authentication, the helper restores the configuration captured before the plugin's first save and restarts t2fanrd. Then remove the plugin:

cd ~/.config/omarchy/plugins/io.github.endijs.t2-fan-control
sudo ./contrib/install-helper.sh --uninstall
omarchy plugin remove io.github.endijs.t2-fan-control

Omarchy does not run plugin uninstall hooks, so removing the plugin without restoring first leaves the current fan curve in place. If the plugin was already removed, reinstall it and use Restore original before removing it again. Remove the installed helper before deleting the plugin because Omarchy does not run uninstall hooks. Removing the plugin never removes t2fanrd.

Security

The status path is unprivileged and reads only sysfs, /etc/t2fand.conf, and the t2fanrd service state. Routine widget actions never execute the user-writable plugin checkout as root. Saving invokes pkexec with the fixed, root-owned helper at /usr/local/libexec/omarchy-t2-fan-control, and its PolicyKit action pins that exact path. Every configuration change therefore requires the desktop's normal administrator prompt, while a plugin update cannot replace the privileged executable.

The helper accepts only bounded integer temperatures, three known curve names, and a boolean full-speed value. On the first save it stores an immutable snapshot at /var/lib/omarchy-t2-fan-control/original-t2fand.conf; later saves never replace that snapshot. A successful restore deletes the snapshot so it cannot be reused after a later reinstall. Each save and restore also uses a temporary rollback copy if t2fanrd fails to restart.

License

MIT