Extend the clamshell gate to /etc/pam.d/sudo, not just polkit-1. When the
lid is shut the reader is unreachable, so a terminal sudo would block on
"Place your finger" until pam_fprintd timed out before letting you type the
password. The same pam_exec gate (success=1 skips fingerprint when the lid
is closed) now runs ahead of pam_fprintd in the sudo stack as well.
setup and removal share one gate definition across sudo and polkit; the
migration now gates both stacks on existing installs.
Resolves the clamshell case in #856 and supersedes #6003.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add a first-run notification, alongside the keybindings/Wi-Fi toasts, that
invites anyone with a fingerprint sensor to enable it. Clicking launches
omarchy-setup-security-fingerprint in a floating terminal.
Detection lives in a new omarchy-hw-fingerprint helper that reads sysfs
(device product descriptor plus a fingerprint-vendor allowlist), so it
works before fprintd/usbutils are installed and without nagging machines
that have no reader. The setup script reuses the same helper as an early
gate, bailing before installing any packages when no reader is found
(replacing the old post-install fprintd-list probe).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bring the fingerprint affordance to the Quickshell lock screen and polkit
dialog, matching what hyprlock did on master.
Lock screen: render the md-fingerprint glyph inside the password field's
right edge when a sensor is enrolled, reserving space so long passwords
never run under it.
Polkit dialog: show one method at a time. When a sensor is enrolled and
the reader is reachable, the dialog is just the centered fingerprint icon
(square card); the moment PAM asks for a password it switches to the
password field. Detects pam_fprintd anywhere in the auth stack now that a
gate can precede it.
Lid awareness: a closed lid means the reader is unreachable, so both
surfaces fall back to the password. polkit gets a pam_exec clamshell gate
(auth [success=1 default=ignore] before pam_fprintd) so a shut lid drops
straight to the password prompt instead of blocking on the reader for the
pam_fprintd timeout; the lock screen hides the icon and skips scanning.
The gate points at the fixed /usr/bin path the package always provides so
it survives switching between package installs and dev-link. A migration
adds the gate for existing fingerprint setups.
New helper omarchy-hw-laptop-closed (pure lid state); omarchy-hw-clamshell
now composes it with the external-monitor check.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bring back per-theme Plymouth unlock theming, dropped when walker +
elephant were removed. Selection now uses the same image carousel as
the theme and background switchers instead of a name list.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Prefer the site's own apple-touch-icon (typically 180-512px) over
Google's favicon service, which often serves an upscaled 16-32px
favicon. Validate downloads are actual images so an HTML error page
never gets saved as an icon.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Spawning quickshell directly from omarchy-restart-shell leaked transient
environment variables from the calling terminal, SSH connection, or
development tool into the fresh shell. Dispatch the launch through
Hyprland instead so it inherits the canonical session environment, same
as autostart.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
omarchy bar transparent now accepts toggle, flipping the current value
in one jq update (absent counts as opaque, matching the shell).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A freshly-started hyprsunset applies its default temperature at the end
of boot, silently overriding a set sent while it was still starting.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
With quickshell-git, qs kill blocks until the instance has fully
exited, so restarting no longer needs to resolve pids and wait for them
to die. Kill in a loop until none remain - each call takes the oldest,
and duplicates from stale sessions are the reason this script exists.
The timeout bounds a wedged shell that can't process the quit message:
its kill would otherwise report success after Qt's 30s wait gives up,
re-killing the same undead instance forever. The test mock now kills
real processes synchronously to match.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
qs parses -n before the ipc subcommand as its top-level --no-duplicate
launch flag and silently ignores it, so IPC still went to the oldest
matching instance - exactly the stale one left behind around a restart.
The --newest flag belongs to the ipc subcommand: qs ipc -n. Verified
against two live instances; the test now pins the flag position.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Same treatment as Stay Awake: the indicator polled the toggle CLI over
a Process with a timer to paper over the race after clicking, and the
CLI ended by asking the shell to refresh every indicator over IPC. A new
omarchy.nightlight service owns hyprsunset instead - it probes the
temperature on startup, applies changes itself for in-shell toggles, and
answers on the nightlight IPC target. The indicator becomes a plain
binding. The CLI still drives hyprctl directly so keybindings, the menu,
and ssh work without the shell, but now just nudges the service to
re-probe since hyprsunset has no state file to watch.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The indicator polled omarchy-toggle-idle over a Process and re-ran it on
a timer to toggle, while the CLI called back into the shell over IPC to
apply and refresh the state it had just changed. Now the indicator binds
straight to the idle service's stayAwake property and flips it in
process. The CLI only touches the state file, which the service already
watches, so toggling from keybindings and scripts still reaches the
shell without any reentrant IPC.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Hyprland only takes scales where the mode divides into whole logical
pixels (in 1/120 steps), so picking 3x on a 1280x800 QEMU display threw
a red error overlay and silently kept the old scale. Round the request
up to the nearest clean divisor instead, so 3x becomes 3.2x.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Hyprland 0.56.0 emits invalid JSON from `hyprctl -j binds`: the new
allow_input_capture field was added to the format template at slot 16
but its argument at position 8, shifting every value from
has_description onward and landing unquoted strings in numeric slots.
The jq parse failure emptied the keybindings menu down to the two
static web-app entries — and the empty result got cached under a
stable key, permanently.
Parse the plain-format output instead, which is unaffected (and also
immune to the older quotes-in-args JSON breakage), refuse to cache a
record set with zero dynamic binds, and bump the cache version so
poisoned caches invalidate.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds named reboot and shutdown OSD icons, and gives the touchscreen
toggle a proper gesture-tap glyph instead of the restart arrow it
was accidentally using.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Transient systemd timers default to AccuracySec=1min, so the 2s
reboot/shutdown could fire up to a minute late.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
One knob for apparent text size, anchored to the 12px shell default: it sets
the shell font base-size (~/.config/omarchy/shell.toml), GNOME/GTK's
text-scaling-factor (12px -> 1.0), and the terminal font point size
(12px -> 9pt) in lockstep. Accepts 9-20px; reset returns all three to
default. Terminals live-reload where they can (alacritty/kitty/ghostty);
foot gets a single restart nudge that replaces itself instead of stacking.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Suppression was enabled only after cleanup_legacy_user_paths had already
moved ~/.local/share/omarchy aside, so the live session could auto-reload
during the swap window and pop "source= globbing error: found no match"
for every legacy hyprland.conf source line. Enable suppression as the
first step of the upgrade sequence instead; the EXIT trap still restores
it if the upgrade dies early.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Extract run_as_user_omarchy and run_as_user_wayland_session helpers to
replace ten hand-rolled run_as_user env blocks
- Declare the retired user-unit list once instead of three times
- Use git ls-files --others to find user-added theme backgrounds instead
of diffing against the tracked list by hand
- Stop rewriting the SDDM 10-theme/10-wayland confs the omarchy package
already installs, and drop the duplicate [Theme] section from
99-omarchy-login.conf
- Drop the legacy-path rewrite in the theme hyprland.conf shim; the user
transition already rewrote those references
- Remove dead code: the unreachable channel re-validation, the declare -F
guard in cleanup_on_exit, and the unset block at the end of the
user-transition script
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The user-transition script is fed to bash on stdin, so the browser-close
gum confirm read the script itself: it auto-declined and swallowed the
remaining script text, leaving bash to fail on a mid-construct syntax
error. The outer confirm and reboot prompts had the same exposure when
the script runs via curl | bash. Read all three from /dev/tty.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The Copy URL shortcut repair checked the outer script's yes variable,
which never reached the user-transition heredoc's bash process, so the
upgrade died with "yes: unbound variable" under set -u whenever a
browser was running with the old extension id in its Preferences.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gum_env.lua is fed into the compositor environment via hl.env at login,
but that environment is captured once and is not refreshed on a theme
switch. Terminals launched through uwsm-app inherit the caller's
environment (scopes don't read systemctl --user set-environment), so a
floating terminal would show the login-time theme's gum colors.
Extract the export logic into a sourced omarchy-restart-gum helper and
source it from the presentation terminal launcher so gum widgets match
the active theme.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The reconciliation poll (added in "Fix clamshell display recovery") is a
backstop for lid transitions the Hyprland switch binds can miss across
suspend/resume. But the internal panel is only ever disabled while the
laptop is docked — lid shut with an external monitor active — so the poll
has nothing to reconcile when undocked. Running it 24/7 on every laptop
wakes the CPU every 2s for no reason, which is exactly the case where
battery matters most.
Start the poll when an external monitor is present and stop it when the
last one goes away (driven by the socat monitor-add/remove watch), gated
on omarchy-hw-laptop. Undocked laptops and desktops now never poll; a
docked laptop keeps the 2s recovery poll. Switch the event reader from a
pipe to process substitution so it runs in the main shell and can manage
the poll's lifetime.
Desktop verified: no poll runs even with external monitors attached. The
docked-laptop start/stop path needs a check on real laptop hardware.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
omarchy-hyprland-monitor-watch ran poll_clamshell_state() every 2s for
the whole session, and each pass forks omarchy-hyprland-monitor-clamshell
plus its hyprctl/jq/monitor-* children. Clamshell (lid) handling can only
ever apply to a machine with a lid, so on desktops and VMs this was pure
churn — the single largest remaining source of idle process wakeups
(~3 forks/sec on an otherwise idle desktop).
Gate the poll behind a new omarchy-hw-laptop helper (lid button, or a
laptop DMI chassis type as a fallback). The event-driven socat watch on
Hyprland monitor add/remove is unchanged, so monitor hotplug still
reconciles everywhere; only the periodic lid poll is now laptop-only.
Verified on a desktop: steady-state omarchy-hyprland-* forks drop from
~3/sec to zero, socat watch still present.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The indicators widget broadcast a refresh every 2s, fanning out to four
status subprocesses (nightlight, idle, reminder, screen-recording), and
NightLight/StayAwake each ran an additional 5s poll. On an idle desktop
this was the dominant source of process churn (~33 of ~53 forks/sec in a
VM). The state-changing commands already push `omarchy.indicators
refresh` over IPC, so the polling was redundant.
Drop the 2s broadcast and the two 5s timers; indicators now refresh at
startup and on the IPC push. Also fix three callers that pushed to the
wrong target `Indicators` instead of `omarchy.indicators` (screen
recording, notification silencing, and the omarchy-shell help example) —
those pushes silently failed and only appeared to work because the poll
masked them.
Idle fork rate drops ~53/s to ~20/s.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The tree is wholly package-owned, but files can land there unowned
(in-place extension work, script-written files), and pacman then aborts
the entire upgrade on the file conflict — as happened when copy-url's
service worker was renamed to background-2.js. The conflict check runs
before any hooks or scriptlets, so the package itself can't recover;
the update command has to allow the overwrite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The lock service arms a 5s blank timer whenever the screen locks, and
input at the lock screen re-arms it. Closing the lid sprays pointer
noise over the lock surface, so the timer was routinely armed right
before suspend, froze mid-countdown, and fired moments after resume --
blanking the freshly woken unlock screen under the user.
Guard the timer with a wall-clock check: if far more time elapsed than
the interval, the countdown slept through a suspend, so take a fresh
run-up instead of blanking. This also blanks the lock screen 5s after
an untouched resume.
Two accomplices made the flash worse and hid the real bug:
- The clamshell watcher's 2s poll fired an unconditional global DPMS
enable whenever no external monitor was active, relighting any blank
within 2 seconds (lock-screen blanking never stuck on undocked
laptops) and racing the resume modeset. Recovery now only wakes
displays when it actually re-enables one.
- Every keystroke at the lock screen dispatched a redundant DPMS
enable via omarchy-system-wake, forcing extra modesets in the
fragile just-resumed DRM state. Brightness "on" now skips the
dispatch when every active display is already lit.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The stable Brave Origin's process is named plain "brave" (the wrapper
execs /opt/brave-origin-bin/brave), so pgrep -x brave-origin never
matches, and pgrep -f brave-origin also matches the installer's own
floating terminal - which made omarchy-install-browser launch a
headless browser and hang on first install.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Brave now publishes brave-origin-bin on AUR, so use it instead of
brave-origin-beta-bin. The stable wrapper also parses flags files
correctly, so Brave Origin can use the normal chromium flags like
the other Chromium-based browsers.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
With initial workspace tracking disabled, windows naturally open on the active workspace. Remove the explicit Hyprland workspace dispatch and let shell actions, shell restarts, and presentation terminals launch directly.
omarchy-restart-shell now kills by config dir via quickshell kill and
relaunches with --no-duplicate, polling kill until every instance is
gone since kill returns without waiting and -n silently exits if one
remains. The locked-session refusal reads Hyprland monitor state alone,
which covers a hung shell holding the lock; the redundant shell IPC
probe, availability guards, and omarchy-shell path indirection are gone.
Shell IPC calls now time out (2s default, OMARCHY_SHELL_IPC_TIMEOUT to
override) so probing an unresponsive shell fails fast instead of
hanging the caller.
omarchy-hyprland-launch checks dispatch output for "ok" rather than the
exit code, which is 0 even on Lua errors, so a failed dispatch falls
through to the bash -lc fallback instead of silently launching nothing.
The Quattro upgrade cutover delegates to omarchy-restart-shell instead
of carrying its own copy of the lock check, pkill, and readiness loop.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Restore the key translation the awk parser used to do (C-M-S-Left →
CTRL + ALT + SHIFT + LEFT, PPage → PAGE UP, etc) as a display pass over
the tmux list-keys output, along with the PREFIX header line and the
COPY MODE table label.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>