Omahub
← All plugins
T

Sonos

by tbye

Route system audio to a Sonos speaker and control volume on the local household.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
2daf69d
Scanned
1 month ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed pipewire-zeroconf"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo ufw allow from 192.168.0.0/16 to any port 6001:6010 proto udp comment 'sonos-raop'"
  • Docs sudo README.md:68

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo ufw allow from 192.168.0.0/16 to any port 6001:6010 proto udp comment 'sonos-raop'

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2daf69d
Reviewed
1 month ago

The plugin is a well-structured Sonos audio router with careful input sanitization and bounded network operations. The deterministic scan flagged sudo commands, but those appear only in documentation and as printed suggestions in install.sh, not executed by the plugin. No malicious or destructive behavior was found.

  • The install script prints a sudo pacman command as a suggestion but does not execute it; the actual package install uses omarchy pkg add.
  • The README includes a sudo ufw command, but it is documentation only and not run by the plugin.
  • The plugin writes a PipeWire config and symlinks a CLI into ~/.local/bin, which is expected behavior and reversible via uninstall.sh.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tbye/tbye.sonos --enable
System #bar #quickshell #system

tbye.sonos

Omarchy bar widget that sends this computer's audio to a Sonos speaker and controls volume on every speaker in the household.

Click the wireless-speaker icon (just left of the volume control). Pick This computer or any room. Each Sonos row has its own volume slider.

System audio is routed over AirPlay (PipeWire RAOP). Volume uses the same UPnP calls as the Sonos app, so you can turn any speaker up or down even when it is not the current output. Switching to a room reads that speaker's current volume first and applies it to the AirPlay sink, so playback does not jump to 100%. While a room is the current output, the system volume and that speaker stay in sync — volume keys, the audio panel, and the Sonos slider all drive the same level.

This is a bar-widget. The details panel is part of that widget; the plugin does not start a second Quickshell process.

Install

Needs Omarchy, Python 3 (standard library only), Sonos speakers on the same LAN with AirPlay enabled, and pipewire-zeroconf.

omarchy plugin add https://github.com/tbye/tbye.sonos.git --enable
omarchy bar move tbye.sonos --before omarchy.audio

AirPlay output needs PipeWire RAOP discovery. Omarchy never runs plugin install hooks, so that half is a separate user-level script:

~/.config/omarchy/plugins/tbye.sonos/scripts/install.sh

install.sh may install the pipewire-zeroconf package (omarchy pkg add; if that is unavailable it prints a pacman command). It writes a user PipeWire drop-in tagged managed-by: tbye.sonos and links omarchy-sonos into ~/.local/bin. It does not move, replace, or symlink the plugin checkout — Omarchy rejects plugin folders that contain symlinks.

Usage

  • Left-click the bar icon: open the picker
  • Click a speaker name: send system audio there
  • Drag the slider under a name: set that speaker's volume
  • Right-click the bar icon: switch back to this computer
  • Scroll-wheel on the icon: volume of the current output
  • Volume keys / the system audio panel: same level on the current Sonos room
  • Escape closes the panel

AirPlay to Sonos has about 1.5 seconds of latency. Fine for music; not great for games or video unless you can delay the picture to match.

Configure

omarchy bar move tbye.sonos --before omarchy.audio

If speakers appear in the list but play stays on the laptop, open UDP 6001–6010 from your LAN (AirPlay timing/control). That is a firewall change, not something the plugin runs for you:

sudo ufw allow from 192.168.0.0/16 to any port 6001:6010 proto udp comment 'sonos-raop'

CLI

omarchy-sonos list
omarchy-sonos status
omarchy-sonos set-output local
omarchy-sonos set-output RINCON_...
omarchy-sonos volume RINCON_... 25
omarchy-sonos mute RINCON_... toggle

list prints JSON with rooms, volume, mute, and whether the matching AirPlay sink is ready.

Remove

Omarchy does not run uninstall hooks. Remove session extras first, then the plugin:

~/.config/omarchy/plugins/tbye.sonos/scripts/uninstall.sh
omarchy plugin remove tbye.sonos

uninstall.sh removes the RAOP drop-in, the omarchy-sonos CLI link, ~/.local/state/omarchy-sonos, and leftover tbye.sonos.bak.* copies from older installers. It does not remove pipewire-zeroconf.

How it works

  1. Discovery and volume — sonosctl.py finds the household through a Sonos GetZoneGroupState query (seeded from Avahi _sonos._tcp) and talks RenderingControl SOAP for volume/mute. Invisible stereo-pair partners and surround satellites that share a room name are folded into that room; a distinctly named Sub still gets its own slider. Avahi/SOAP payloads are byte-capped, topology is capped at 32 rooms, names are stripped of markup, and a lookup is aborted after 8 seconds so a LAN responder cannot retain the helper or the shared shell.
  2. Output switching — PipeWire RAOP creates a sink per AirPlay receiver. The widget matches sinks by the speaker's MAC (Sonos-<MAC> in the sink name) so a room like "Basement" is not confused with an Apple TV of the same name. Selecting a room calls omarchy-audio-output-set-default after setting the sink volume to the speaker's current level.

State lives in ~/.local/state/omarchy-sonos/, not in the plugin directory, so saving it does not reload Omarchy shell. The helper byte-caps that file, opens it without following a symlink, and writes through an exclusive temporary name so a planted entry cannot retain the shared shell or overwrite another path.

Issues, support and feedback welcome

Please create an issue if there's anything I can help you with.

tbye.sonos is in no way affiliated with Sonos. Sonos and related marks are property of their owners.