Omahub
← All plugins
V

Sony Headphones

by Vyom Jain

Capability-driven controls and battery status for Sony Sound Connect headphones.

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
f6144b3
Scanned
1 month ago
  • Bundles a systemd unit file.

    [Unit]
  • medium external_hosts scripts/fetch-fmt.sh:17

    Downloads or connects to an external HTTP(S) host.

    git clone --filter=blob:none --no-checkout "https://github.com/fmtlib/fmt.git" "$destination"
  • Docs external_hosts …/releases/v0.2.2.md:33

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/VyomJain6904/sony-headphones-linux.git
  • Docs external_hosts README.md:55

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/VyomJain6904/sony-headphones-linux.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f6144b3
Reviewed
1 month ago

The Omarchy widget itself is plain QML/JS with no network access, obfuscation, credential handling, or destructive behavior; it only reads a local status file and invokes a separately installed CLI. The deterministic scan's high rating comes from the bundled systemd user service and dependency-fetch scripts, which are documented, pinned, and not part of the widget's runtime install path. No hidden persistence, data exfiltration, or harmful install-time activity was found.

  • The widget executes whatever `sony-headphonesctl` resolves to on PATH, so users should install the trusted native companion from the pinned AUR/source build and avoid untrusted PATH overrides.
  • The repository contains source-build scripts that fetch pinned upstream dependencies over HTTPS; these are transparent and checksum-verified, but a full source install should still be reviewed as a native package, not as part of the Omarchy plugin itself.
  • The bundled systemd user service is a legitimate companion daemon service, only enabled when the user explicitly runs the installer or AUR package; it is not installed or activated by the Omarchy plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/VyomJain6904/sony-headphones-linux --enable
Widgets #quickshell #media

Sony Headphones for Linux

A native Linux service and command-line controller for Sony headphones that use the Sony | Sound Connect protocol. It publishes live state as JSON and accepts commands through a private Unix socket, so it can be used by any desktop, status bar, script, or automation tool. An optional Omarchy Quattro widget provides a graphical frontend.

Hardware alpha: the complete control path is tested on a WH-1000XM5 running firmware 2.5.1 over MDR v2. Other models may work when they report supported protocol capabilities, but they are not claimed as tested. See the compatibility matrix.

Omarchy dark theme Omarchy light theme
Sony Headphones panel using a dark theme Sony Headphones panel using a light theme

Features

  • Main, left, right, and case battery levels when reported by the device
  • Noise cancellation, ambient sound level, and focus on voice
  • Speak-to-Chat, DSEE, writable equalizer presets, and connection priority
  • Headphone volume normalized to 0–100
  • Capability-gated controls: unsupported features are not displayed
  • On-demand RFCOMM control so Sony's phone app can reconnect after the panel closes
  • Live Omarchy colors, spacing, controls, and dark/light theme changes

The panel intentionally omits playback controls. Playback commands remain in the version-1 CLI schema for compatibility.

Install on Arch or Omarchy

The AUR package owns only the native daemon, CLI, user service, documentation, and licenses. Omarchy owns the optional QML plugin checkout.

Install the native companion from the AUR:

yay -S sony-headphones-linux
systemctl --user enable --now sony-headphones.service

Install the optional Omarchy widget separately:

omarchy plugin add https://github.com/VyomJain6904/sony-headphones-linux.git
omarchy plugin enable io.github.vyomjain6904.sony-headphones --section right

Confirm the native service is healthy:

systemctl --user status sony-headphones.service
sony-headphonesctl status

The AUR package is a source build. makepkg verifies checksums for the application, libmdr, and fmt sources before building, and CMake is disconnected from dependency downloads during compilation.

Install from source

Install the build dependencies listed in Development, then run:

git clone https://github.com/VyomJain6904/sony-headphones-linux.git
cd sony-headphones-linux
./scripts/build.sh
./scripts/install.sh
systemctl --user enable --now sony-headphones.service

install.sh writes only to ~/.local/bin and ~/.config/systemd/user. It does not install or enable the Omarchy widget. Before writing, it rejects unrelated, modified, linked, or foreign-checkout destinations and records the installed hashes in a private checkout-bound receipt.

For a deterministic build without Bluetooth/libmdr:

./scripts/build.sh --without-libmdr
./build/native/sony-headphonesd --mock

Use the CLI

sony-headphonesctl status
sony-headphonesctl noise off|anc|ambient
sony-headphonesctl ambient-level 1..20
sony-headphonesctl focus-on-voice on|off
sony-headphonesctl speak-to-chat on|off
sony-headphonesctl dsee on|off
sony-headphonesctl eq-preset <reported-preset>
sony-headphonesctl connection quality|stable
sony-headphonesctl volume 0..100

The daemon atomically publishes state at:

${XDG_STATE_HOME:-$HOME/.local/state}/sony-headphones/status.json

See the integration guide for Waybar, Polybar, eww, AGS, i3status-rust, Conky, KDE Plasma, GNOME Shell, keybindings, and custom Quickshell configurations.

Update

Update AUR and Omarchy components independently:

yay -Syu sony-headphones-linux
systemctl --user restart sony-headphones.service
omarchy plugin update io.github.vyomjain6904.sony-headphones

For a receipt-backed source installation, pull the repository, rebuild, reinstall, and restart the service:

git pull --ff-only
./scripts/build.sh
./scripts/install.sh
systemctl --user restart sony-headphones.service

Existing v0.2.2 source installs predate ownership receipts. Immediately after the first git pull, run ./scripts/install.sh once before rebuilding; it adopts the old installation only when all three files are byte-identical to the existing build. Then use the normal build/install sequence above. A conflict stops without changing files or the service; inspect, back up, and resolve that path manually rather than forcing installation.

Uninstall

For an AUR installation:

systemctl --user disable --now sony-headphones.service
yay -Rns sony-headphones-linux
omarchy plugin remove io.github.vyomjain6904.sony-headphones

For a source installation, run the tracked uninstaller from its checkout:

./scripts/uninstall.sh
omarchy plugin remove io.github.vyomjain6904.sony-headphones

The source uninstaller validates the receipt and every recorded hash before disabling the service. It removes only unchanged artifacts installed by the same checkout; a missing receipt, symlink, unrelated file, or modified owned file stops removal. The native uninstaller and package removal preserve private state. Delete it only when the last status and error information is no longer wanted:

rm -r -- "$HOME/.local/state/sony-headphones"

The Omarchy command is optional in every removal path and should be omitted when the widget was not installed.

Dependencies

Runtime:

  • Linux, BlueZ, D-Bus, and libbluetooth
  • Omarchy Quattro/Quickshell only for the optional widget

Full source builds require CMake 3.31 or newer, a C++20 compiler, Git, pkg-config, jq, D-Bus and BlueZ development headers, and Node.js for the JavaScript model test. The runtime contains no Python, Electron, telemetry, or network client.

Safety and limitations

The daemon and CLI run as an unprivileged user. Their state and socket directories are private, and the public state omits the Bluetooth address. Installing an AUR package uses the normal package-manager privileges required to write under /usr; the running service itself does not require root, setuid, or a broad D-Bus policy.

The project does not implement firmware flashing, 360 Reality Audio, Sony account/cloud functions, location tracking, factory reset, or a second Quickshell process. Read SECURITY.md before using real-device write commands.

Documentation

License and affiliation

MIT licensed. This project is independent, unofficial, and is not affiliated with or endorsed by Sony. Sony, Sony | Sound Connect, and product names are trademarks of their respective owners.