Omahub
← All plugins
S

Omawall

by Sahzudin Mahmic

View and manage the Omarchy UFW firewall from the bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
877784f
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
877784f
Reviewed
1 month ago

No dangerous or malicious behavior found. The plugin runs an unprivileged Python helper that invokes /usr/bin/ufw through pkexec with validated argument lists, and firewall changes require explicit user confirmation and a Polkit prompt. The deterministic scan's low-severity 'obfuscation' finding is a test-only escape sequence exercising output-cap handling, not hidden or obfuscated shipping code.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sahzudin/omawall --enable
System #bar #system #security

Omawall

Omawall is an Omarchy 4 (Quattro) shell plugin for viewing and managing the UFW firewall without leaving the desktop bar.

Features

  • Shows whether UFW is active and how many user rules are configured.
  • Lists numbered IPv4 and IPv6 rules with actions, direction, source, and comments.
  • Adds allow, deny, reject, and TCP rate-limit rules.
  • Supports incoming and outgoing rules, TCP/UDP/any protocol, numeric ports and port ranges, IP/CIDR restrictions, and comments.
  • Deletes rules with confirmation and stale-rule protection.
  • Enables or disables UFW with an explicit confirmation step.
  • Displays UFW's incoming, outgoing, routed, and logging state without changing Omarchy's defaults or Docker-specific configuration.

Preview

Omawall firewall management panel

Requirements

  • Omarchy 4 (Quattro) with the current omarchy-shell plugin API
  • UFW (ufw is included with Omarchy)
  • pkexec and a working Polkit authentication agent
  • Python 3.10 or newer

Install

omarchy plugin add https://github.com/sahzudin/omawall.git --enable

The widget defaults to the right side of the bar. Move it at any time:

omarchy bar move io.github.sahzudin.omawall --section right

Left-click the shield to open Omawall. Right-click it to refresh the status.

Update

omarchy plugin update io.github.sahzudin.omawall --yes

Remove

omarchy plugin remove io.github.sahzudin.omawall --yes

Removal deletes the plugin checkout and its bar entry. It does not change UFW, delete firewall rules, disable the firewall, or remove any system package.

Security model

Omarchy shell plugins and omawallctl.py always run as the signed-in user. The helper validates each request, then asks Polkit to execute the root-owned /usr/bin/ufw binary. No file in the user-writable plugin directory is ever executed with elevated privileges. The helper:

  • invokes pkexec /usr/bin/ufw with an argument array, never through a shell;
  • accepts only known actions, directions, and protocols;
  • validates ports, IP addresses/networks, and comment length;
  • verifies a numbered rule still matches the selected rule immediately before deletion, avoiding deletion of a different rule after a stale UI refresh;
  • reads UFW's output under a byte cap, a rule-count cap, and a timeout, so a stuck or endlessly chatty command cannot grow the helper or the shell;
  • never edits /etc/ufw files directly.

UFW's output is treated as untrusted input on the way back. Rule fields, comments, defaults, and error text are stripped of control characters and length-capped, and every panel Text item pins textFormat: Text.PlainText, so a markup-shaped rule comment is shown literally instead of being rendered as rich text that could load remote or local resources.

Omawall deliberately does not reset UFW, change default policies, or edit before.rules, after.rules, application profiles, or ufw-docker rules.

Please report suspected vulnerabilities privately through the repository's GitHub Security Advisory form. See SECURITY.md.

Development

Run the helper tests and validate the manifest:

python -m unittest discover -s tests -v
omarchy plugin validate .

For a local development copy, copy this repository to ~/.config/omarchy/plugins/io.github.sahzudin.omawall, rescan plugins, and enable it with omarchy plugin enable io.github.sahzudin.omawall.

License

MIT