Omahub
← All plugins
R

oSystemd

by Ricky Banks

Manage systemd units from the Omarchy bar. List, inspect, start/stop, enable/disable, mask, and view unit files and journals. Supports user and system scope; system mutations invoke systemctl directly.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
32a5a40
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
32a5a40
Reviewed
1 month ago

The plugin is a systemd management UI that invokes systemctl directly, with no obfuscation or hidden behavior. The deterministic scan flagged a test fixture containing a systemd unit file, which is not executable code and poses no risk. The polkit documentation explicitly warns against dangerous configurations, and the code appears to follow safe practices.

  • The plugin can perform system-scope mutations (start/stop/enable/mask) via systemctl, which may require elevated privileges; this is expected functionality but users should be aware of the implications.
  • The polkit README mentions a previous dangerous .pkla file; ensure it is not included in the repository or installed by the plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rickycbanks/osystemd --enable
System #system

oSystemd

Manage systemd units from the Omarchy bar.

List, search, filter, inspect, start/stop, enable/disable, mask, and view unit files and journals — all from a compact bar widget and a rich panel UI.

Features

  • List & Search — View all units with real-time filtering by name or description.
  • Type & State Filters — Chip-based toggles for service, timer, socket, mount, and more; filter by active/inactive/failed state.
  • Status Inspection — Key fields at a glance: PID, load state, fragment path, activation timestamp.
  • Mutations — Start, stop, restart, enable, disable, mask, unmask with confirmation-aware UI.
  • Unloaded Units Section — View unit files installed on disk but not currently loaded by systemd (e.g., D-Bus-activated services like fprintd). Start, enable, disable, or mask them from the same panel.
  • Unit File Viewer — Monospace rendering of unit file contents via systemctl cat.
  • Journal Peek — Tail recent journal lines for any unit without leaving the panel.
  • Scope Toggle — Switch between user and system scope instantly; system mutations invoke systemctl directly (a polkit agent may prompt for authentication).
  • Bar Indicator — Traffic-light dot with tooltip; pulses on failures, shows count badge.
  • Persistent Settings — Type filters, state filters, refresh interval, and pinned units survive restarts via settings.json.

Install

omarchy plugin add https://github.com/rickycbanks/osystemd.git

Then restart omarchy-shell (or wait for the shell to auto-detect the new plugin).

Remove

omarchy-plugin-remove io.github.rickycbanks.osystemd

Polkit Setup

System-scope mutations invoke systemctl directly. If your user has the appropriate privileges, the action succeeds. Otherwise a polkit authentication agent in your session may prompt for a password.

Ensure a polkit agent (e.g. polkit-gnome or Omarchy's built-in Quickshell.Services.Polkit agent) is running. For details and important security notes about previous pkexec-based elevation, see polkit/README.md.

Configuration

Settings are stored as JSON at:

~/.local/state/quickshell/by-shell/<shell>/plugins/io.github.rickycbanks.osystemd/settings.json
Field Type Default Description
scope string "user" "user" or "system"
refreshIntervalMs int 30000 Auto-refresh interval in milliseconds
journalLines int 100 Number of journal lines to fetch
typeFilter list<string> (all) Unit types to show
stateFilter list<string> (active, inactive, failed) Unit states to show
pinned list<string> [] Unit names pinned to the top of the list

Release

Releases are tag-driven. Version is defined in manifest.json and units.py (__version__).

  1. Bump manifest.json and units.py to the target version (e.g. 1.1.0), update tests/README as needed, and merge via PR.
  2. After the version bump is merged, create and push the tag: git tag v1.1.0 && git push origin v1.1.0.
  3. Pushing a vX.Y.Z tag triggers .github/workflows/release.yml: it checks out without persistent credentials, validates the v-stripped tag equals manifest.json (and helper) version, runs python -m unittest discover -s tests -v, and creates a GitHub Release from the already-pushed tag with generated notes (gh release create --verify-tag).

Do not create or push the tag until the version-bump PR is approved and merged. The workflow requires contents: write only and uses GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} solely for the release step; tag data is passed via environment variables.

Screenshots

[<img alt="Cups.Service" src="assets/quickview.png" />]

[<img alt="alt text" src="assets/actions.png" />]

Credits

License

MIT