Omawall
Omawall is an Omarchy 4 (Quattro) shell plugin for viewing and managing the UFW firewall without leaving the desktop bar.
Features
- Shows whether UFW is active and how many user rules are configured.
- Lists numbered IPv4 and IPv6 rules with actions, direction, source, and comments.
- Adds allow, deny, reject, and TCP rate-limit rules.
- Supports incoming and outgoing rules, TCP/UDP/any protocol, numeric ports and port ranges, IP/CIDR restrictions, and comments.
- Deletes rules with confirmation and stale-rule protection.
- Enables or disables UFW with an explicit confirmation step.
- Displays UFW's incoming, outgoing, routed, and logging state without changing Omarchy's defaults or Docker-specific configuration.
Preview

Requirements
- Omarchy 4 (Quattro) with the current
omarchy-shellplugin API - UFW (
ufwis included with Omarchy) pkexecand a working Polkit authentication agent- Python 3.10 or newer
Install
omarchy plugin add https://github.com/sahzudin/omawall.git --enable
The widget defaults to the right side of the bar. Move it at any time:
omarchy bar move io.github.sahzudin.omawall --section right
Left-click the shield to open Omawall. Right-click it to refresh the status.
Update
omarchy plugin update io.github.sahzudin.omawall --yes
Remove
omarchy plugin remove io.github.sahzudin.omawall --yes
Removal deletes the plugin checkout and its bar entry. It does not change UFW, delete firewall rules, disable the firewall, or remove any system package.
Security model
Omarchy shell plugins and omawallctl.py always run as the signed-in user. The
helper validates each request, then asks Polkit to execute the root-owned
/usr/bin/ufw binary. No file in the user-writable plugin directory is ever
executed with elevated privileges. The helper:
- invokes
pkexec /usr/bin/ufwwith an argument array, never through a shell; - accepts only known actions, directions, and protocols;
- validates ports, IP addresses/networks, and comment length;
- verifies a numbered rule still matches the selected rule immediately before deletion, avoiding deletion of a different rule after a stale UI refresh;
- reads UFW's output under a byte cap, a rule-count cap, and a timeout, so a stuck or endlessly chatty command cannot grow the helper or the shell;
- never edits
/etc/ufwfiles directly.
UFW's output is treated as untrusted input on the way back. Rule fields,
comments, defaults, and error text are stripped of control characters and
length-capped, and every panel Text item pins textFormat: Text.PlainText, so
a markup-shaped rule comment is shown literally instead of being rendered as
rich text that could load remote or local resources.
Omawall deliberately does not reset UFW, change default policies, or edit
before.rules, after.rules, application profiles, or ufw-docker rules.
Please report suspected vulnerabilities privately through the repository's GitHub Security Advisory form. See SECURITY.md.
Development
Run the helper tests and validate the manifest:
python -m unittest discover -s tests -v
omarchy plugin validate .
For a local development copy, copy this repository to
~/.config/omarchy/plugins/io.github.sahzudin.omawall, rescan plugins, and
enable it with omarchy plugin enable io.github.sahzudin.omawall.
License
MIT