Kernel-level ad, tracker, and telemetry sinkhole plugin engineered for Omarchy Linux.
Author: Ozan Ozdil (ozdil)
License: MIT
Plugin ID: ozdil.omablock
- Zero Latency (< 0.1ms): Leverages atomic, kernel-level DNS sinkhole routing (
0.0.0.0) without middleman proxy overhead or battery drain. - Military-Grade HANCORE Defense: Deep integration of self-defense features including Self-Integrity Verification (SHA-256 binary hashing) and
prctl(PR_SET_DUMPABLE, 0)anti-tamper. - Advanced Kernel Blackout: Panic Blackout mode and Zero-Trust egress lockdown (drops non-loopback DNS 53/853 with TCP RST/ICMP admin-prohibited) for immediate threat containment.
- AI-Powered Threat Detection: Integrated IDN Homograph and Punycode spoofing radar via advanced DGA Classification engine to stop zero-day phishing typosquatting.
- 79,500+ Curated Rules: Pre-bundled offline database with one-click online synchronization against StevenBlack Unified and EasyPrivacy upstream blocklists.
- Fine-Grained Category Filtering:
- Commercial Ads: DoubleClick, PageAd, Criteo, Taboola, Outbrain, popups, and video advertising networks.
- Telemetry and Surveillance: Operating system, analytics, and third-party tracking beacons.
- Malware and Phishing: Known command-and-control endpoints, cryptominers, and malicious domains.
- Social Network Trackers: Third-party pixel trackers, audience measurement, and social widgets.
- Live Shield Verification: In-panel live resolution diagnostics to verify protection in real time.
- Custom Allow and Deny Lists: Instantly whitelist or blacklist specific domains with zero DNS downtime.
- Hardware Armor Control: Toggle USB access instantly through UI directly integrated with system state files.
- Monochrome Design: Native Omarchy UI styling adhering strictly to typography standards and color palette rules.
- OmaBlock Shield Bridge (Chrome / Chromium): Native Manifest V3 extension bridging the kernel-level DNS sinkhole with browser-level declarative rules and deep cosmetic DOM filtering for first-party advertising elements.
- Hardened Rust Engine: Strict regex sanitization, safe atomic file replacement, bounded memory limits, and zeroize-secured memory buffers.
+---------------------------------------------------------+
| Omarchy Wayland Bar |
| [ OmaBlock ] |
+---------------------------+-----------------------------+
| QML IPC / Click
v
+---------------------------------------------------------+
| OmaBlock Control Center (QML) |
| - Hero Toggle (ON/OFF) - Realtime Metrics |
| - Category Matrix - Self-Diagnostic Test |
| - Whitelist/Blacklist Chips - Update / Flush |
+---------------------------+-----------------------------+
| CLI / Stdio JSON
v
+---------------------------------------------------------+
| omablock-engine (Rust Native) |
| - Pre-bundled ~80k categorized rules |
| - Category filter & Whitelist arithmetic |
| - Live latency benchmarking (<0.1ms) |
| - Background updater (curl + deduplication) |
+---------------------------+-----------------------------+
| Polkit helper (/usr/bin)
v
+---------------------------------------------------------+
| omablock-hosts-sync & /etc/hosts Sinkhole |
| - Atomic replacement via os.replace |
| - DNS cache purge via resolvectl flush-caches |
| - 0.0.0.0 sinkhole for instantaneous connection drop |
+---------------------------+-----------------------------+
| System Sinkhole
v
+---------------------------------------------------------+
| OmaBlock Shield Bridge (Chrome / Chromium) |
| - Manifest V3 DeclarativeNetRequest ruleset |
| - Cosmetic DOM Injection & first-party ad removal |
| - Zero-latency synchronization with system shield |
+---------------------------------------------------------+
- cargo and rustc (Rust toolchain, for building from source)
- systemd-resolved (resolvectl, for flushing local DNS cache)
Under the Omarchy Linux Security Standards (AGENTS.md Rule 5.3), precompiled binaries are strictly forbidden from Git repositories to guarantee user system integrity. Therefore, the native engine must be compiled from source on your local machine after adding the plugin.
omarchy plugin add https://github.com/ozdil/omarchy-omablock.gitNavigate to the plugin directory and run the user-space build script:
cd ~/.config/omarchy/plugins/ozdil.omablock
./build.shThis builds omablock-engine from source and places user executables in ~/.local/bin.
To enable system-wide /etc/hosts and Polkit integration without raw password prompts, install the package via Arch package manager:
cd ~/.config/omarchy/plugins/ozdil.omablock
makepkg -siIf not automatically added, place ozdil.omablock into bar.layout.right in ~/.config/omarchy/shell.json:
{
"id": "ozdil.omablock"
}omarchy-restart-shellTo cleanly remove OmaBlock:
cd ~/.config/omarchy/plugins/ozdil.omablock
./uninstall.sh
sudo pacman -R omarchy-omablock 2>/dev/null || true
omarchy plugin remove ozdil.omablockOmaBlock provides standalone CLI commands:
# View full status in JSON
omablock --status
# Toggle protection
omablock --toggle
omablock --enable
omablock --disable
# Toggle individual categories
omablock --toggle-category ads
omablock --toggle-category telemetry
omablock --toggle-category malware
omablock --toggle-category social
# Manage Whitelist
omablock --whitelist-add adservice.google.com
omablock --whitelist-remove adservice.google.com
# Manage Blacklist
omablock --blacklist-add annoying-site.com
omablock --blacklist-remove annoying-site.com
# Run real-time resolution test
omablock --test
# Sync latest rules from cloud blocklists
omablock --update
# Flush system DNS resolver cache
omablock --flushOmaBlock complies strictly with the Omarchy Linux Security Standards (AGENTS.md):
- Safe File Synchronization: Hosts file modifications are performed atomically via staging files, ensuring no partial writes or DNS downtime.
- Subprocess Isolation: Process executions run in isolated process groups (
cmd.process_group(0)) with monotonic deadlines and 64 KiB buffer caps. - Input Sanitization: Domain inputs are strictly validated against domain name standards to prevent configuration poisoning.
- Plain Text UI: All dynamic text rendered in QML components utilizes
textFormat: Text.PlainTextto prevent script and markup injection.
If you find OmaBlock useful and want to support independent Linux security tools:
MIT License. See LICENSE for details.

