Omahub
← All plugins
O

VLANs

by Omar-sv88

List, connect, create, and delete 802.1Q VLAN connections (via NetworkManager)

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4474229
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Potentially dangerous behavior flagged

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

High
AI risk level
High
Recommendation
avoid
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4474229
Reviewed
1 month ago

The plugin's VLAN listing script executes a shell command that embeds connection names in double quotes without escaping, allowing command injection if a connection name contains shell metacharacters. This could lead to arbitrary code execution when the widget refreshes. The deterministic scan missed this because it is a logic flaw in the shell script construction.

  • Command injection in listScript: connection names are interpolated into a bash -c script without proper escaping, allowing arbitrary command execution if a connection name contains double quotes or other shell metacharacters.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Omar-sv88/omarchy-vlans --enable
Hardware #bar #system

VLANs

A NetworkManager VLAN manager for the Omarchy bar. The stock omarchy.network widget only covers Wi-Fi and DNS; this fills the gap for 802.1Q VLANs — list, connect, disconnect, create, and delete them without leaving the bar.

Install

omarchy plugin add https://github.com/Omar-sv88/omarchy-vlans.git --enable

Update

omarchy plugin update io.github.omar-sv88.vlans

Remove

omarchy plugin remove io.github.omar-sv88.vlans

Add --yes to either command to skip the confirmation prompt.

Features

  • Lists every VLAN connection NetworkManager knows about, with parent interface, VLAN ID, IP mode, and live status
  • A switch per VLAN to connect/disconnect it
  • New VLAN form: parent interface picker (auto-detected Ethernet/Wi-Fi devices), VLAN ID (1-4094), optional name, DHCP or manual IP/gateway, autoconnect toggle
  • Delete with a confirmation dialog
  • Auto-refreshes every 15s while the panel is open, plus a manual Refresh button

How it works

This is a Quickshell plugin loaded by the long-running omarchy-shell process, using the same manifest.json + bar-widget contract as Omarchy's first-party bar widgets (Network, Bluetooth, Audio, ...).

  • manifest.json declares the plugin (id: io.github.omar-sv88.vlans, kind: bar-widget) and points at Panel.qml as the entry point.
  • Panel.qml is the QML UI: the bar icon/toggle switch, the popup panel, and the nmcli Process calls that back every action.
  • Model.js holds the pure parsing/validation logic (VLAN ID range, CIDR validation, the read-only listing script, nmcli connection add argv construction) with no QML dependencies, so it's unit-testable with plain Node.

All VLAN operations run through nmcli directly as your user — no sudo required. NetworkManager already permits the active session to manage its own connections, the same way the stock Network widget connects to Wi-Fi without prompting for a password.

Requirements

  • NetworkManager (nmcli) with the 8021q kernel module (present on any modern Linux install; loads automatically when a VLAN connection activates)

License

MIT — see LICENSE.