* Give built-in plugins an honest on/off state Every built-in reported itself enabled no matter what. A bar widget said "enabled" while sitting nowhere near the bar, and disabling a built-in service silently did nothing, because enabled meant "listed in plugins[]" and a built-in never is. Nothing surfaced that, since the only caller listing plugins was the CLI. For a widget, on and off is its place in the bar, so listPlugins reports layout membership -- what enable/disable actually toggles. For everything else built in, loading by default is the right behaviour to keep, so switching one off is recorded the other way round, in disabledPlugins[]. shell.json still carries only the deviation from the defaults: the key is dropped the moment nothing is switched off, leaving a config that never disabled anything byte-identical. isEnabled still answers a separate question -- whether the component loads at all -- and deliberately does not follow a widget out of the bar. omarchy.menu is both a widget and the menu itself, so tying the two together would let taking its button off the bar lock the menu out of the shell, with no way back that isn't the CLI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Manage plugins from Setup > Plugins Plugins were CLI-only. Setup > Plugins now offers Enable, Disable, Add, and Remove, each list living in the menu itself so picking a row acts on it. Enable and Disable cover the built-ins as well as anything installed -- the bar widgets you can put in the bar, the services and overlays you can switch off. Remove is limited to plugins the user installed, since a built-in has no checkout to delete, and stays hidden until there is one. Whole-bar replacements are left out; those are chosen under Style. Enabling a bar widget asks for a section first, because enabling alone drops it on the right and the only way to move it was a follow-up bar plugin move. The CLI asks the same question after its own add, so both paths place a widget the same way. Add and Remove run in a terminal: one needs a git URL and shows the trust warning before cloning, the other deletes a checkout and prints where it backed it up. Providers grew two hooks for this. placementFor turns a row into a submenu instead of an action, and volatile re-runs the enumeration when its submenu is entered -- picking from these lists is what changes them, and rows a provider no longer returns now drop out instead of lingering forever. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Trim the plugin menu after review Menu.qml carried its own shellQuote while already importing Util and calling Util.shellQuote a few lines up; two copies of the same escaping is one place for a future fix to miss. isDisabled walked the array by hand to compare values it writes itself, and dropDisabled was an eight-line helper with one caller. Two bugs came out of the same pass. A whole-bar replacement belongs under Style rather than these lists, but the exclusion sat in the shared row builder, so a third-party bar could be installed and never removed -- Remove would show an empty list under a guard that said something was there. The exclusion now sits on the two lists that mean it. Rows are keyed by id, and distinct plugin ids can slugify alike: acme.foo, acme_foo and acme-foo all give acme-foo. The merge keeps the first row per id, so the rest simply vanished from the list with nothing to say why. Row ids are now made distinct before merging. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Pick a plugin the way we pick a theme Setup > Plugins listed plugins as menu rows, which needed three providers, a placement submenu, a volatile-refresh hook and a row-swap in the merge. Only Font and Apps are built that way. Theme, Background, Unlock, Timezone and Keybindings all pipe a list into omarchy-menu-select instead, which is one action string and a small script -- so that is what these use now. The trade is search: a plugin name is no longer findable from the root prompt. Neither is a theme name or a timezone, and Enable Plugin still is, so the loss sits where the rest of the menu already puts it. Two pieces of the row machinery stay, because they are worth having for the lists that remain. A volatile provider re-runs when its submenu is entered, so a font installed since the shell started now shows up without restarting it, and rows a provider stops returning drop out. Row ids are still made distinct before merging: Fira Code and Fira-Code both slug to fira-code, and a repeated id was silently dropped. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Let a picked option carry an icon Moving the plugin lists onto omarchy-menu-select cost them their glyphs: the select mode has always hardcoded an empty icon, which is why Timezone and Keybindings have none either. An option may now lead with one, as "<glyph><TAB><label>". The menu shows the glyph, filters on the label, and hands the label back, so a caller never strips a glyph off its own selection and a list of plain strings behaves exactly as before. The plugin picker uses it for the puzzle glyph on each plugin and the align glyphs on the sections, which also regain the capitals they lost when the section names were passed through raw. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Switch bars by enabling one A bar option was kept out of Enable and Disable on the grounds that picking which bar to run belongs under Style -- but nothing under Style ever offered it, so an installed bar could be added and removed and never actually put to use. The menu was guarding a door to a room that was never built. Enabling one is the switch. setEnabled already assigns bar.id for a bar option, so a bar has always replaced the one before it; only the picker's filter stood in the way. Dropping it costs nothing else, because enabled for a bar option means active: the bar in use is the one row absent from Enable, every other installed bar is one pick away, and the built-in is just another entry, so going back to it is enabling Bar. Disable keeps the exclusion. That is the one verb a bar cannot answer -- there is no off, only a successor -- and offering it would have listed the built-in bar on a stock system, where turning it off deletes a bar.id that was never set and nothing happens. A bar carries the bar glyph rather than the puzzle one, so a row that replaces the whole bar does not read like one more widget to switch on, and enable now says "Now using X as the bar" instead of "Enabled X", which understated a whole-bar swap in both the enable and the freshly-added path. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Refuse a plugin that declares a kind it cannot load A kind is a promise to supply something to load, and the shell reads that something from a fixed key: entryPoints.bar to draw a bar, entryPoints.menu to open a menu. Nothing checked the promise. A manifest could claim kinds ["bar"] with no bar entry point, pass validation, install, and enable -- and then the bar would fall back to the built-in and the widget would be skipped, leaving a plugin that does nothing, explained only by a console.warn nobody reads. Our own plugins have been held to this table by plugins-test.sh all along. This holds third-party ones to the same table, at add and update time, where there is still someone to tell. A kind outside the table is left alone rather than guessed at, so a shell that learns a new kind does not need this list updated first. The cost is that a misspelled kind still installs quietly. omarchy-plugin-validate had no tests; it has some now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Act on the plugin whose row was picked The picker showed a name and then looked that name up again across every plugin, filtered set or not, taking the first match. Two plugins can share a name: cloning one keeps the name it was cloned from, so the documented `omarchy plugin clone omarchy.clock local.clock` leaves two plugins called Clock. Enable listed the clone -- the built-in was already enabled, so only the clone was eligible -- and then enabled omarchy.clock, moving the built-in widget instead. Remove listed the clone and tried to delete a built-in that has no checkout to delete. A row now carries its id alongside its label, and the id is read back off the row that was picked instead of being derived from the name a second time. Where a name is not unique among the rows on offer, the label carries the id too, so two rows that would both say Clock can be told apart at all -- which they could not before, whichever one the pick resolved to. The verb prompt only ever sees the first two fields, so the menu shows what it always did. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Never ask a bar where to sit in the bar A manifest may declare both bar and bar-widget, and validation accepts it. The picker saw bar-widget, asked for a section, and passed it to enable. setEnabled takes bar as the dominant kind: it writes bar.id and returns, adding nothing to any layout, so the move that followed had no widget to find and failed -- after the bar had already been switched. A partial success with an error on the way out. Bar wins ahead of bar-widget now, in the picker and in the placement prompt `plugin add --enable` asks, so a bar is enabled without a placement it cannot use. The CLI refuses a placement on a bar outright, before the bar is switched rather than after, since `omarchy plugin enable <bar> --section left` could reach the same half-applied state without going through either. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Only replacement, no off * Add default placement for bar widgets * Simplify plugin menu actions * Document plugin placement behavior * Allow dropping widgets in empty bar space * Treat plugin dependencies as runtime invariants * Reject duplicate plugin ids on add --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
288 lines
12 KiB
Markdown
288 lines
12 KiB
Markdown
# Omarchy shell
|
|
|
|
`omarchy-shell` is a single long-running [Quickshell](https://quickshell.org/)
|
|
instance that hosts the Omarchy desktop. Hyprland autostart launches one shell
|
|
per graphical session; everything else — the bar, background switcher, panels,
|
|
and overlays — runs **inside** the shell as a plugin.
|
|
|
|
Hosting everything inside one shell means:
|
|
|
|
- shared services and singletons live once, not once per process
|
|
- summoning a panel is an IPC call into a process that is already running,
|
|
not a fresh `quickshell -p ...` cold start
|
|
- third-party plugins can be loaded from disk without changing any source
|
|
code in Omarchy itself
|
|
|
|
The runtime layout:
|
|
|
|
```
|
|
shell/
|
|
shell.qml entry point (ShellRoot)
|
|
services/
|
|
PluginRegistry.qml discovers, validates plugins, looks up enabled state in shell.json
|
|
BarWidgetRegistry.qml unified registry for bar widgets (1p + 3p)
|
|
plugins/
|
|
bar/ first-party plugins (see plugins/README.md)
|
|
image-picker/
|
|
menu/
|
|
notifications/
|
|
panels/
|
|
audio/
|
|
bluetooth/
|
|
monitor/
|
|
network/
|
|
power/
|
|
weather/
|
|
model-usage/
|
|
services/
|
|
battery/
|
|
idle/
|
|
osd/
|
|
polkit/
|
|
```
|
|
|
|
The plugin discovery path is documented in [plugins/README.md](plugins/README.md).
|
|
|
|
## Plugin manifest
|
|
|
|
Every plugin ships a `manifest.json` describing what it is and how the
|
|
shell should load it. Minimal example:
|
|
|
|
```json
|
|
{
|
|
"schemaVersion": 1,
|
|
"id": "my.org.cool-clock",
|
|
"name": "Cool clock",
|
|
"version": "1.0.0",
|
|
"author": "You",
|
|
"description": "A clock that does cool things",
|
|
"kinds": ["bar-widget"],
|
|
"entryPoints": { "barWidget": "Widget.qml" },
|
|
"barWidget": {
|
|
"displayName": "Cool clock",
|
|
"category": "Time",
|
|
"allowMultiple": false,
|
|
"defaultSection": "left",
|
|
"defaults": { "format": "HH:mm" },
|
|
"schema": [
|
|
{ "key": "format", "type": "string", "label": "Format" }
|
|
]
|
|
}
|
|
}
|
|
```
|
|
|
|
Supported `kinds`:
|
|
|
|
| Kind | What it is |
|
|
|--------------|--------------------------------------------------------------|
|
|
| `bar-widget` | A component that the active bar can drop into a section |
|
|
| `panel` | A persistent or summoned floating window (e.g. OSD) |
|
|
| `overlay` | A fullscreen overlay (e.g. background switcher) |
|
|
| `menu` | A summoned menu surface |
|
|
| `service` | A headless singleton, no UI |
|
|
| `bar` | A full bar option that can replace the built-in `omarchy.bar` |
|
|
|
|
Only one `bar` plugin is active at a time. Missing or invalid selections fall
|
|
back to the built-in `omarchy.bar`, so users always have a safe path home.
|
|
Panels, overlays, and menus are loaded when summoned. Plugins that need
|
|
to outlive a single summon can set `keepLoaded: true` (e.g. the image
|
|
picker keeps its overlay window mounted between summons). First-party
|
|
services are loaded at startup.
|
|
|
|
The full schema lives in `services/PluginRegistry.qml`.
|
|
|
|
## Installing a third-party plugin
|
|
|
|
A plugin is a **git repo** with a `manifest.json` at its root. Adding one
|
|
clones it straight into `~/.config/omarchy/plugins/<id>/` (named by the
|
|
manifest id); updating is a fast-forward pull of that checkout.
|
|
|
|
```bash
|
|
omarchy plugin add https://github.com/acme/omarchy-weather.git
|
|
omarchy plugin update acme.weather # fetches, shows a diff, fast-forwards
|
|
omarchy plugin update --all
|
|
omarchy plugin remove acme.weather
|
|
```
|
|
|
|
> ⚠️ **Plugins run as unsandboxed code inside `omarchy-shell`.** Adding warns
|
|
> you before cloning, plugins land disabled so you can review the code before
|
|
> enabling, and updates show a diff of the changes before touching anything.
|
|
> Only add repos whose code you are willing to run.
|
|
|
|
Each command is **interactive** when run bare in a terminal (gum pickers,
|
|
confirmation, a diff to review) and fully **non-interactive** when given
|
|
arguments. Pass `--yes` to skip every prompt — this is the path for scripts and
|
|
AI agents:
|
|
|
|
```bash
|
|
omarchy plugin add https://github.com/acme/omarchy-weather.git --enable --yes
|
|
omarchy plugin update --all --yes
|
|
```
|
|
|
|
The installer never runs plugin code, install hooks, or sudo — it only clones
|
|
files, validates the manifest, and toggles enabled state over shell IPC. Since
|
|
an installed plugin is a plain git checkout, anything beyond add/update
|
|
(pinning a ref, switching branches) is ordinary git in the plugin directory.
|
|
|
|
### Installing by hand
|
|
|
|
You can still drop a plugin in without git:
|
|
|
|
1. Put it in `~/.config/omarchy/plugins/<plugin-id>/` with a `manifest.json`
|
|
plus the QML referenced from its `entryPoints`.
|
|
2. `omarchy plugin rescan`.
|
|
3. `omarchy plugin enable <id>`. Bar widgets start in
|
|
`barWidget.defaultSection`, or in the center when it is omitted, and can be
|
|
moved with `omarchy bar plugin move`; a full bar replaces the one in use.
|
|
|
|
The lower-level IPC equivalents remain available via `omarchy-shell shell rescanPlugins`,
|
|
`omarchy-shell shell setPluginEnabled <id> true`, and `omarchy-shell shell listPlugins`.
|
|
The `omarchy plugin` command wraps those calls and can also edit the persisted
|
|
bar layout in `shell.json`.
|
|
|
|
To hack on an existing widget safely, clone it into a user plugin instead of
|
|
editing the built-in source. Third-party ids must be namespaced and may not use
|
|
the reserved `omarchy.*` prefix.
|
|
|
|
```bash
|
|
omarchy plugin clone omarchy.clock local.clock --replace
|
|
omarchy plugin clone # interactive source/name picker
|
|
omarchy plugin edit local.clock # cd into the plugin directory
|
|
```
|
|
|
|
First-party plugins under `shell/plugins/` are discovered the same way and load
|
|
by default. Disabling a non-widget records it in `disabledPlugins[]`; disabling
|
|
a widget removes it from the bar layout while leaving its component available
|
|
to add again. A full bar has no off state and is replaced by enabling another.
|
|
|
|
## IPC contract
|
|
|
|
The shell exposes a single `shell` IPC target plus whatever extra targets
|
|
individual plugins register (e.g. the bar's `bar` target for refresh
|
|
hooks, the image picker's `image-selector` target). `omarchy-menu` uses the
|
|
shell target to summon the first-party `omarchy.menu` plugin instead of
|
|
running a separate Quickshell instance.
|
|
|
|
| Method | Returns | Effect |
|
|
|------------------------------------------|---------|-------------------------------------------------------|
|
|
| `ping` | `ok` | health check |
|
|
| `summon <id> <payloadJson>` | `ok` / `unknown` | load + open a panel/overlay plugin |
|
|
| `hide <id>` | — | close a previously-summoned plugin |
|
|
| `toggle <id> <payloadJson>` | — | summon if closed, hide if open |
|
|
| `call <id> <method> <arg>` | string | call a method on an already-loaded plugin |
|
|
| `rescanPlugins` | — | re-walk plugin dirs and hot-reload plugin code |
|
|
| `reloadConfig` | `ok` | reload `~/.config/omarchy/shell.json` |
|
|
| `setPluginEnabled <id> <enabled>` | `ok` / `unknown` | flip the persisted enabled bit (see note) |
|
|
| `listPlugins` | JSON | every discovered plugin, sorted by name |
|
|
|
|
Direct invocation:
|
|
|
|
```
|
|
quickshell ipc -p $OMARCHY_PATH/shell call shell ping
|
|
```
|
|
|
|
Hyprland autostart launches the shell directly with `quickshell -p
|
|
$OMARCHY_PATH/shell`. Use `omarchy-restart-shell` to stop every running
|
|
instance of that config and launch one fresh shell process.
|
|
|
|
A convenience wrapper, [`omarchy-shell`](../bin/omarchy-shell), forwards IPC
|
|
calls to the running shell. It does not start the shell.
|
|
|
|
```
|
|
omarchy-shell shell ping
|
|
omarchy-shell shell toggle omarchy.menu '{"menu":"root"}'
|
|
omarchy-shell shell listPlugins
|
|
omarchy-shell shell rescanPlugins
|
|
```
|
|
|
|
**Note on `setPluginEnabled`:** the `enabled` argument is a string. Only the
|
|
literal `"true"` enables the plugin; every other value (including `"True"`,
|
|
`"1"`, `"yes"`, or omitted) disables it. This keeps the IPC surface
|
|
type-stable across QML's `string`-only IPC arguments.
|
|
|
|
## Persisted state
|
|
|
|
There is one user config file. Everything that distinguishes your
|
|
customization from the shipped defaults lives in it.
|
|
|
|
| Path | Owner | Purpose |
|
|
|-----------------------------------|----------------|--------------------------------------------------------|
|
|
| `~/.config/omarchy/shell.json` | the shell | full layout + per-entry settings + enabled plugin list |
|
|
| `~/.config/omarchy/plugins/<id>/` | user | drop-in third-party plugin source files |
|
|
|
|
The `config/omarchy/shell.json` default config describes the
|
|
fresh-install state. When the user has no `shell.json`, the shell uses
|
|
the defaults verbatim. Once the user customizes anything, `shell.json`
|
|
becomes the authoritative file — we do **not** deep-merge defaults back in.
|
|
|
|
### shell.json shape
|
|
|
|
```json
|
|
{
|
|
"version": 1,
|
|
"idle": {
|
|
"screensaver": 150,
|
|
"lock": 300
|
|
},
|
|
"bar": {
|
|
"id": "omarchy.bar",
|
|
"position": "top",
|
|
"transparent": false,
|
|
"centerAnchor": "omarchy.clock",
|
|
"layout": {
|
|
"left": [ { "id": "omarchy.menu" }, { "id": "omarchy.workspaces" } ],
|
|
"center": [ { "id": "omarchy.clock", "format": "HH:mm" } ],
|
|
"right": [
|
|
{ "id": "omarchy.audio" }
|
|
]
|
|
}
|
|
},
|
|
"plugins": []
|
|
}
|
|
```
|
|
|
|
### Storage rules
|
|
|
|
1. **The active bar option is `bar.id`.** Omit it or set it to `omarchy.bar`
|
|
to use the built-in bar. Set it to another plugin id whose manifest declares
|
|
`kind: "bar"` to replace the full bar.
|
|
2. **Every plugin instance is one entry.** Either in `bar.layout.<section>`
|
|
for bar widgets, or in `plugins[]` for panels, overlays, services,
|
|
menus, and anything else non-bar.
|
|
3. **Settings are inline on the entry.** No `config:` sub-object, no
|
|
separate per-plugin settings file, no merge layers. The fields on each
|
|
entry are the values the plugin sees.
|
|
4. **Built-in widget ids are namespaced.** Use ids such as `omarchy.clock`,
|
|
`omarchy.audio`, and `omarchy.network`. The migration rewrites older ids
|
|
like `Clock` and `AudioPanel` forward.
|
|
5. **Third-party enabled ⇔ present.** A third-party plugin is enabled iff
|
|
its id appears somewhere in shell.json. For full bar options, that means
|
|
`bar.id`; for bar widgets, `omarchy bar plugin` adds/removes layout entries;
|
|
other plugin kinds are enabled with the shell IPC. First-party non-bar
|
|
plugins are always enabled.
|
|
6. **Multiple instances** are allowed when a manifest sets
|
|
`allowMultiple: true`. Each instance is independent — e.g. two clock
|
|
widgets in different timezones are just two `{"id":"omarchy.clock", "timezone": ...}`
|
|
entries with their own values.
|
|
7. **Idle timings are top-level.** `idle.screensaver` and `idle.lock`
|
|
are seconds since user idle began, so the default lock fires at 300s
|
|
even if the 150s screensaver starts first.
|
|
8. **`version: 1` is required** at the top level. The shell will fall back
|
|
to defaults rather than load an unknown version.
|
|
|
|
## Implementation history
|
|
|
|
Built up in phases on this branch:
|
|
|
|
- Phase 1 — `omarchy-shell phase 1: host the existing bar in a single shell`
|
|
- Phase 2 — `omarchy-shell phase 2: plugin registry and bar widget registry`
|
|
- Phase 3 — `omarchy-shell phase 3: fold bar-settings into the shell as a panel plugin`
|
|
- Phase 4 — `omarchy-shell phase 4: absorb background-switcher as a plugin`
|
|
- Phase 5 — `omarchy-shell phase 5: docs, cleanup, and migration crumbs`
|
|
- Phase 6 — `omarchy-shell phase 6: reviewer cleanup (path traversal, collision, races)`
|
|
- Phase 7 — `omarchy-shell phase 7: replace socket with IpcHandler, rename to image-picker`
|
|
- Phase 8a — `omarchy-shell phase 8a: unified shell.json with inline plugin settings`
|
|
|
|
Shared services and Pipewire/UPower/Hyprland consolidation are explicitly
|
|
out of scope here and deferred to a follow-up after a review pass.
|