Omahub
← All plugins
P

Sandman

by Pierre Berube

Set lid-close actions and when your screen rests, locks, sleeps, and hibernates.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
a186c4d
Scanned
1 week ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:32

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -D -o root -g root -m 0755 \
  • Docs sudo README.md:87

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /etc/systemd/sleep.conf.d/90-sandman.conf
  • Docs sudo README.md:88

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /usr/local/libexec/sandman-configure-hibernate

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a186c4d
Reviewed
1 week ago

Sandman is a transparent idle/lid management plugin. The deterministic scan's sudo findings are in README install/uninstall instructions, not in code executed by the plugin; the actual QML and Python code is straightforward, validates inputs, and only writes its own config files plus a systemd sleep drop-in through a root-owned helper. No obfuscation, credential theft, hidden persistence, or destructive behavior was found.

  • The privileged helper is installed manually with sudo from the user-owned plugin checkout; users should verify the helper file before installing it as root.
  • The plugin can suspend/hibernate the system and modify /etc/systemd/sleep.conf.d/90-sandman.conf when the helper is installed; these actions are user-initiated and documented.
  • It rewrites ~/.config/hypr/bindings.lua and ~/.config/omarchy/shell.json, but uses atomic writes and preserves unrelated configuration.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/lgse/sandman --enable
System #bar #power-management #system

Sandman

Set when your screen rests, locks, and sleeps from the Omarchy Quattro bar.

Sandman screensaver, auto-lock, and sleep settings

On laptops, Sandman also shows lid-close actions:

Sandman laptop lid-close actions

Sandman provides six simple controls:

  • Lid close — keeps the system default or does nothing, turns off the laptop display, suspends, or hibernates when the lid closes.
  • Screen saver — starts the screen saver after the selected period of inactivity.
  • Displays off — turns the displays off (DPMS) after the selected period of inactivity while respecting idle inhibitors.
  • Auto-lock — locks the session after the selected period of inactivity.
  • Sleep — suspends the computer after the selected period of inactivity while respecting idle inhibitors.
  • Hibernate after sleep — wakes a suspended computer after the selected delay and hibernates it.

Each setting offers presets, Off, and a custom hours-and-minutes timeout. Omarchy requires positive screen-saver and lock values, so Sandman simulates Off with safe seven-day timeouts while displaying and persisting Off as 0.

Install

omarchy plugin add https://github.com/lgse/sandman.git --enable

Install the privileged helper from the user-owned plugin checkout, then restart the shell if it is already running:

sudo install -D -o root -g root -m 0755 \
  ~/.config/omarchy/plugins/lgse.sandman/sandman-configure-hibernate \
  /usr/local/libexec/sandman-configure-hibernate
omarchy restart shell

If needed, add it to the bar explicitly:

omarchy bar plugin add lgse.sandman --section right

Usage

Click the Zzz icon in the bar and choose a lid-close action or a timeout for each idle stage. Presets apply immediately; Custom accepts hours and minutes and applies on confirmation for screen saver, displays off, auto-lock, sleep, and hibernate-after-sleep. Existing values that do not match a preset—including Omarchy's 2½-minute screen-saver default—open as Custom. Changes survive shell reloads and reboots.

The lid controls appear only when UPower reports a laptop lid. System default leaves logind in charge. The other actions use a low-level lid-switch inhibitor while Sandman is running, then handle the event without changing system-wide logind configuration. For managed lid actions, Sandman also installs a small managed block in ~/.config/hypr/bindings.lua that replaces Omarchy's default switch:on:Lid Switch binding. Omarchy's default binding locks immediately on lid close, before Sandman can apply Do nothing or Display off, so Sandman unbinds it and keeps only Omarchy's clamshell monitor reconciliation. Selecting System default removes Sandman's managed Hyprland block again. Display off targets the internal eDP/LVDS/DSI output and turns it back on when the lid opens. Hibernate is selectable only when logind reports that it is available.

Sandman stores its state in ~/.config/omarchy/sandman.json. The effective screen-saver and auto-lock values remain in Omarchy's standard ~/.config/omarchy/shell.json; lid actions and the displays-off, sleep, and hibernate-after-sleep timers are handled by Sandman itself and are not written there. Changing the hibernate delay asks for administrator authorization because systemd's RTC wake timer is configured system-wide.

How displays off works

Sandman uses Quickshell's idle monitor with inhibitor support and turns the displays off through Hyprland's dpms dispatcher. Applications holding an idle inhibitor can prevent the timer from firing, and any key press or mouse movement turns the displays back on.

How sleep and hibernate work

Sandman uses Quickshell's idle monitor with inhibitor support and requests suspend through systemctl suspend. Applications holding an idle inhibitor can prevent the timer from firing, and system-level sleep inhibitors can reject the suspend request.

When Hibernate after sleep is enabled, Sandman instead requests systemctl suspend-then-hibernate. systemd sets an RTC wake alarm, wakes after the chosen delay, and hibernates. Sandman stores the delay in /etc/systemd/sleep.conf.d/90-sandman.conf; changing or disabling it requires administrator authorization. The option is available only when logind reports that suspend-then-hibernate is supported. When it is unavailable, Sandman disables the positive timeout choices and reports any prerequisite it can detect, including missing disk-backed swap, missing kernel hibernation support, missing resume discovery, or restrictive kernel lockdown. Off remains available so an old setting can always be cleared.

Requirements

  • Omarchy Quattro
  • Python 3
  • systemd
  • UPower
  • GLib (gdbus)
  • Polkit (pkexec), to change the systemd hibernate delay

The helper is deliberately separate from sandman.py, because the latter is loaded from the user-owned plugin directory and must never be executed as root.

Validate

npm test
omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" BarWidget.qml Panel.qml Service.qml LidService.qml

Remove

omarchy plugin remove lgse.sandman
rm -f ~/.config/omarchy/sandman.json
sudo rm -f /etc/systemd/sleep.conf.d/90-sandman.conf
sudo rm -f /usr/local/libexec/sandman-configure-hibernate

Removing Sandman does not revert the screen-saver and lock timeouts already written to shell.json. If Sandman is removed while a managed lid action is selected, remove the managed block between -- BEGIN Sandman lid action override and -- END Sandman lid action override from ~/.config/hypr/bindings.lua, or reinstall Sandman and select System default before removing it.

This matters if either setting was left Off. Off is stored in shell.json as a seven-day timeout, so removing Sandman while auto-lock is Off leaves a machine that effectively never locks, with no Sandman UI left to notice it. Set anything you want back on before removing, or restore Omarchy's defaults afterwards:

python3 - <<'PY'
import json, pathlib
path = pathlib.Path.home() / ".config/omarchy/shell.json"
config = json.loads(path.read_text())
config.setdefault("idle", {}).update({"screensaver": 150, "lock": 300})
path.write_text(json.dumps(config, indent=2) + "\n")
PY

License

MIT