Omahub
← All plugins
B

Rotate lock

by Brad

Screen auto-rotate for Hyprland, with a bar toggle to lock it

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d22ea3a
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d22ea3a
Reviewed
1 month ago

This is a well-written, transparent plugin that does exactly what it documents: it reads orientation from monitor-sensor and applies it via hyprctl eval, with a bar toggle to lock rotation. The code is clean, uses array-based process execution (avoiding shell injection), contains no obfuscation, no network calls, and no hidden persistence beyond the documented toggle flag. The only command-string construction (hyprctl eval) uses values derived from the user's own config and integer transforms, so there is no realistic attack surface.

  • The plugin constructs a hyprctl eval command string using the configured monitor name, but this value comes from the user's own shell.json config and defaults to 'eDP-1', so it is not an injection vector.
  • The README documents a manual `rm` command for cleanup, but this is documentation only and not executed by the plugin.
  • The service runs monitor-sensor as a child process, which is expected behavior for an auto-rotate daemon and is properly cleaned up when the plugin is disabled.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bnrobinson93/omarchy-orientation --enable
Hardware #Hyprland #bar #quickshell

orientation

An Omarchy shell plugin that rotates the screen with the accelerometer, and puts a rotate lock on the bar.

Omarchy has no rotation of its own, and iio-hyprland cannot supply it: it rotates through hyprctl keyword, which Hyprland's Lua config parser rejects. This plugin reads orientation from monitor-sensor and applies it with hyprctl eval, which the Lua parser does accept.

It is two rungs of one feature:

  • a service that runs the sensor loop, and
  • a bar widget that shows whether rotation is locked, and locks it on click.

Install

omarchy plugin add https://github.com/bnrobinson93/omarchy-orientation.git
omarchy plugin enable orientation

Updates come from omarchy plugin update orientation.

It needs iio-sensor-proxy for monitor-sensor; without it the widget still tracks the lock, but nothing rotates.

Configuration

The only setting is which output rotates. It rides on the plugin's own entry in ~/.config/omarchy/shell.json — the same entry that places the widget on the bar — and hot-reloads with the rest of the shell config.

{
  "bar": {
    "layout": {
      "center": [
        { "id": "orientation", "monitor": "eDP-1" }
      ]
    }
  }
}
Key Default What it does
monitor eDP-1 The Hyprland output to rotate.

The sensor loop runs only when it can do something: rotation unlocked, monitor present in Hyprland's output list, and monitor-sensor installed. Unplug the panel or lock rotation and the process stops.

The lock

Lock state is the autorotate-off Omarchy toggle — a flag file under ~/.local/state/omarchy/toggles/, the same home Omarchy's own toggles use, so it survives a reboot and can be flipped from anywhere:

omarchy-toggle autorotate-off

The bar widget does exactly that on click. A menu row can do the same:

"trigger.toggle.auto-rotate": {
  "icon": "󰑵",
  "label": "Auto-rotate",
  "when": "test -d ~/.config/omarchy/plugins/orientation",
  "checked": "! omarchy-toggle-enabled autorotate-off",
  "action": "omarchy-toggle autorotate-off"
}

Either route flips the same flag, and the service notices and reacts — starting or stopping the sensor and sending the notification. Locking freezes the screen at its current orientation; unlocking re-syncs to wherever the machine is actually pointing, because monitor-sensor reports the current orientation as soon as it starts.

Editing plugin files in ~/.config/omarchy/plugins/orientation/ needs omarchy restart shell to take effect — the shell logs a reload on save but keeps running the code it loaded at install time. Config edits in shell.json do hot-reload.

Remove

omarchy plugin remove orientation

That disables the widget and the service, drops the entry from ~/.config/omarchy/shell.json, and deletes the plugin directory. The sensor loop stops with it, so nothing rotates afterwards — but the screen keeps whatever orientation it was last given. Put it back with:

hyprctl keyword monitor eDP-1,preferred,auto,1,transform,0

Two things live outside the plugin directory and are left alone on purpose:

rm ~/.local/state/omarchy/toggles/autorotate-off   # the lock flag, if it is set

and any trigger.toggle.auto-rotate row you added to ~/.config/omarchy/extensions/omarchy-menu.jsonc, which is your file. The row guards itself on the plugin directory existing, so it simply stops appearing.

License and dependencies

MIT — see LICENSE.

Dependency Required Why
Omarchy 4 (Quattro) with Quickshell yes the shell that hosts the plugin
Hyprland with the Lua config yes rotation is applied with hyprctl eval
iio-sensor-proxy for rotation supplies monitor-sensor; without it the lock still tracks, but nothing rotates

Nothing is vendored, nothing is compiled, and no network call is made.