Compare commits
34
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1b9b584729
|
||
|
|
d9d6877714
|
||
|
|
6704ec389c | ||
|
|
aca9e5d7cc
|
||
|
|
2c8fbf008d | ||
|
|
c4f1be8a38
|
||
|
|
6df7fcacbb | ||
|
|
bc11b464a8
|
||
|
|
0ac9b45286 | ||
|
|
55e12b2226 | ||
|
|
eab8f4974e
|
||
|
|
0b1190a257
|
||
|
|
62954a67b5
|
||
|
|
37d44b64c1 | ||
|
|
cb5dd91550
|
||
|
|
fb04de1d23 | ||
|
|
f41387e451
|
||
|
|
2ae9d451f5 | ||
|
|
3feb6d2367
|
||
|
|
41fbb67fc9 | ||
|
|
b15968b004
|
||
|
|
274c39b213 | ||
|
|
2a3c439993
|
||
|
|
a2e9ad6035 | ||
|
|
6fdde12804
|
||
|
|
32291e63bb | ||
|
|
0e681ec0e2
|
||
|
|
0ce944b327 | ||
|
|
046a17374b
|
||
|
|
626015db9f | ||
|
|
dfc2a1ca3a
|
||
|
|
e41d02abcc
|
||
|
|
ec79afe982
|
||
|
|
536d4df5e4 |
Generated
+16
-15
@@ -8,11 +8,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1778716662,
|
||||
"narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
|
||||
"lastModified": 1787559586,
|
||||
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
|
||||
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -28,11 +28,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782159472,
|
||||
"narHash": "sha256-S+/v+BWz9c8IbGhRM8L4UUVC5j2oZuAHj1b5XlkBjyw=",
|
||||
"lastModified": 1787797243,
|
||||
"narHash": "sha256-8+Q7NOB7RPajRjA4pbCDLzqH+MTjnG9x6LUPLfL2joA=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "351959fcdbe5cadec1c3434d7abd14dff31af2d5",
|
||||
"rev": "99c9ec63390f1d8c14d95d9e8b17cc29cfbd4e11",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -43,11 +43,11 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1781577229,
|
||||
"narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
|
||||
"lastModified": 1787900134,
|
||||
"narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
|
||||
"rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -66,11 +66,11 @@
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782160744,
|
||||
"narHash": "sha256-cHC0CeygNx5y07oTyNo6Gkc0k3fD964MRvwQerlImPY=",
|
||||
"lastModified": 1787862710,
|
||||
"narHash": "sha256-dL1Tv7LekaTWUJxHRckjbupWczDdc3QOgRuVCM+WAvQ=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixvim",
|
||||
"rev": "f60bf47332d1564a175ad4b517a83ff0c288f2e7",
|
||||
"rev": "8c096abcf376137527c134da4ee210332b08ccc0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -86,11 +86,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782159196,
|
||||
"narHash": "sha256-+2SNFxlnmetcPCIfai0gv89mgnXFQr3kMwLDKUyn0ZE=",
|
||||
"lastModified": 1788099672,
|
||||
"narHash": "sha256-t4Rw5OeULK/WA2Jh9ja615sCs2AmvahkAUx/ymdf2YQ=",
|
||||
"owner": "noctalia-dev",
|
||||
"repo": "noctalia-shell",
|
||||
"rev": "a5a5ea605ac68599d29669030d39173f1e1a0c17",
|
||||
"rev": "d891007c022a3a1d4484495fe8b350a00deafae9",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -108,6 +108,7 @@
|
||||
}
|
||||
},
|
||||
"systems": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1774449309,
|
||||
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
{
|
||||
imports = [
|
||||
../../modules/nixos/appimage.nix
|
||||
../../modules/nixos/astro.nix
|
||||
../../modules/nixos/audio.nix
|
||||
../../modules/nixos/bootloader.nix
|
||||
@@ -25,6 +26,7 @@
|
||||
../../modules/nixos/steam.nix
|
||||
../../modules/nixos/thunar.nix
|
||||
../../modules/nixos/users.nix
|
||||
../../modules/nixos/vial.nix
|
||||
];
|
||||
|
||||
# set hostname
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
{
|
||||
imports = [
|
||||
../../modules/nixos/appimage.nix
|
||||
../../modules/nixos/astro.nix
|
||||
../../modules/nixos/audio.nix
|
||||
../../modules/nixos/bootloader.nix
|
||||
@@ -21,6 +22,7 @@
|
||||
../../modules/nixos/settings.nix
|
||||
../../modules/nixos/steam.nix
|
||||
../../modules/nixos/users.nix
|
||||
../../modules/nixos/vial.nix
|
||||
];
|
||||
|
||||
# set hostname
|
||||
|
||||
@@ -1,17 +1,38 @@
|
||||
{ config, pkgs, inputs, ... }:
|
||||
{ config, lib, pkgs, inputs, ... }:
|
||||
|
||||
let
|
||||
email = "aaron@0x29a.ch";
|
||||
|
||||
# public half of every machine's ~/.ssh/id_ed25519, each one verified as a
|
||||
# signing key in gitea. the key a host signs with is picked up from the key
|
||||
# file itself, this list only tells the local git which machines to trust
|
||||
signingKeys = [
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon"
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGDkhvvTUcBSQdtXjX+Mw2Bp8HHhtiBm8aJi4ZxiBgZR aaron@neon"
|
||||
];
|
||||
in
|
||||
{
|
||||
# gitea verifies signatures against the account keys, this teaches the local
|
||||
# git the same trust so `git log --show-signature` resolves as well
|
||||
xdg.configFile."git/allowed_signers".text =
|
||||
lib.concatMapStrings (key: "${email} ${key}\n") signingKeys;
|
||||
|
||||
programs.git = {
|
||||
enable = true;
|
||||
settings = {
|
||||
push = { autoSetupRemote = true; };
|
||||
user = {
|
||||
name = "aaron";
|
||||
email = "aaron@0x29a.ch";
|
||||
email = email;
|
||||
};
|
||||
gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers";
|
||||
};
|
||||
signing = {
|
||||
key = "7A830180A05DAC59CDE43B0677D2F5DB48184456";
|
||||
format = "ssh";
|
||||
# point at the *public* key so ssh-keygen signs through the ssh agent
|
||||
# instead of reading the passphrase protected private key from disk
|
||||
key = "${config.home.homeDirectory}/.ssh/id_ed25519.pub";
|
||||
signer = "${pkgs.openssh}/bin/ssh-keygen";
|
||||
signByDefault = true;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -1,60 +1,123 @@
|
||||
{ config, pkgs, inputs, ... }:
|
||||
|
||||
let
|
||||
# Powerline separators, U+E0B0..U+E0B3.
|
||||
#
|
||||
# Written as escapes rather than literal glyphs. These are Private Use Area
|
||||
# codepoints: they render only with a patched font, they survive copy/paste
|
||||
# badly, and when they get stripped the loss is invisible, the config still
|
||||
# parses, the status bar just quietly loses its separators. Nix has no \u
|
||||
# escape of its own, but fromJSON does.
|
||||
sep = builtins.fromJSON ''
|
||||
{
|
||||
"right": "\ue0b0",
|
||||
"rightThin": "\ue0b1",
|
||||
"left": "\ue0b2",
|
||||
"leftThin": "\ue0b3"
|
||||
}
|
||||
'';
|
||||
in
|
||||
{
|
||||
programs.tmux = {
|
||||
# defaults
|
||||
enable = true;
|
||||
prefix = "C-a";
|
||||
keyMode = "vi";
|
||||
mouse = true;
|
||||
terminal = "screen-256color";
|
||||
|
||||
# tmux-256color gives truecolor, italics and undercurl in nvim.
|
||||
terminal = "tmux-256color";
|
||||
|
||||
# Default is 500ms. Causes lag you feel when leaving insert mode in nvim,
|
||||
# because tmux is waiting to see whether Esc starts an escape sequence.
|
||||
escapeTime = 10;
|
||||
|
||||
# nvim autoread / :checktime react to focus.
|
||||
focusEvents = true;
|
||||
|
||||
# History limit.
|
||||
historyLimit = 50000;
|
||||
|
||||
# Window numbers matching the number row.
|
||||
baseIndex = 1;
|
||||
|
||||
extraConfig = ''
|
||||
# Status keys
|
||||
set -g status-keys vi
|
||||
|
||||
# Tell tmux the outer terminal can do 24-bit colour (tmux >= 3.2).
|
||||
set -sa terminal-features ",*:RGB"
|
||||
|
||||
# Shift+Enter / extended keys
|
||||
# These make tmux forward CSI-u sequences unconditionally.
|
||||
# Needs tmux >= 3.5 for the format option,
|
||||
set -s extended-keys always
|
||||
set -s extended-keys-format csi-u
|
||||
set -as terminal-features '*:extkeys'
|
||||
|
||||
# Status bar options
|
||||
set -g status-interval 1
|
||||
set -g status on
|
||||
set -g status-interval 5
|
||||
set -g status-justify left
|
||||
|
||||
# Clock mode
|
||||
setw -g clock-mode-colour cyan
|
||||
|
||||
# Colors
|
||||
set -g status-bg black
|
||||
set -g status-fg white
|
||||
|
||||
# Key bindings
|
||||
# Reload configuration
|
||||
bind r source-file ~/.config/tmux/tmux.conf
|
||||
# Panel split and selection
|
||||
bind r source-file ~/.config/tmux/tmux.conf \; display-message "tmux.conf reloaded"
|
||||
|
||||
# Panel split and selection, new panes/windows inherit the cwd
|
||||
unbind %
|
||||
unbind '"'
|
||||
bind v split-window -v
|
||||
bind c split-window -h
|
||||
bind i new-window
|
||||
bind b previous-window
|
||||
bind n next-window
|
||||
bind v split-window -v -c "#{pane_current_path}"
|
||||
bind c split-window -h -c "#{pane_current_path}"
|
||||
bind i new-window -c "#{pane_current_path}"
|
||||
bind -r b previous-window
|
||||
bind -r n next-window
|
||||
|
||||
# Move around panes with hjkl
|
||||
bind h select-pane -L
|
||||
bind j select-pane -D
|
||||
bind k select-pane -U
|
||||
bind l select-pane -R
|
||||
|
||||
# Resize panes
|
||||
bind H resize-pane -L 5
|
||||
bind J resize-pane -D 5
|
||||
bind K resize-pane -U 5
|
||||
bind L resize-pane -R 5
|
||||
bind -r H resize-pane -L 5
|
||||
bind -r J resize-pane -D 5
|
||||
bind -r K resize-pane -U 5
|
||||
bind -r L resize-pane -R 5
|
||||
|
||||
# Wayland clipboard integration
|
||||
# Copy selection to both clipboard (Ctrl+V / Shift+Insert) and primary (middle-click)
|
||||
bind -T copy-mode-vi v send-keys -X begin-selection
|
||||
bind -T copy-mode-vi C-v send-keys -X rectangle-toggle
|
||||
bind -T copy-mode-vi y send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
|
||||
bind -T copy-mode-vi Enter send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
|
||||
bind -T copy-mode-vi MouseDragEnd1Pane send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
|
||||
# Uncomment if you want yanks to also travel over SSH via OSC52.
|
||||
# Locally redundant with wl-copy above.
|
||||
#set -g set-clipboard on
|
||||
|
||||
# Kill commands
|
||||
bind q kill-window
|
||||
bind Q kill-session
|
||||
bind q confirm-before -p "kill window #W? (y/n)" kill-window
|
||||
bind Q confirm-before -p "kill session #S? (y/n)" kill-session
|
||||
|
||||
# Bars
|
||||
# This is the nord-tmux status line. #{prefix_highlight} came from that
|
||||
# theme's tmux-prefix-highlight integration -- a plugin you never loaded,
|
||||
# so the token expanded to nothing. tmux can do it natively. Commas inside
|
||||
# #{?...} are argument separators and have to be escaped as #, hence the
|
||||
# look of the style spec.
|
||||
set -g status-left-length 24
|
||||
set -g status-left "#[fg=black,bg=blue,bold] #{=20:session_name} #[fg=blue,bg=black,nobold,noitalics,nounderscore]"
|
||||
set -g status-right "#{prefix_highlight}#[fg=brightblack,bg=black,nobold,noitalics,nounderscore]#[fg=white,bg=brightblack] %Y-%m-%d #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]#[fg=white,bg=brightblack] %H:%M #[fg=cyan,bg=brightblack,nobold,noitalics,nounderscore]#[fg=black,bg=cyan,bold] #H "
|
||||
set -g status-left "#[fg=black,bg=blue,bold] #{=20:session_name} #[fg=blue,bg=black,nobold,noitalics,nounderscore]${sep.right}"
|
||||
set -g status-right "#{?client_prefix,#[fg=black#,bg=yellow#,bold] ^A ,}#[fg=brightblack,bg=black,nobold,noitalics,nounderscore]${sep.left}#[fg=white,bg=brightblack] %Y-%m-%d #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]${sep.leftThin}#[fg=white,bg=brightblack] %H:%M #[fg=cyan,bg=brightblack,nobold,noitalics,nounderscore]${sep.left}#[fg=black,bg=cyan,bold] #H "
|
||||
|
||||
# Windows
|
||||
set -g window-status-format "#[fg=black,bg=brightblack,nobold,noitalics,nounderscore] #[fg=white,bg=brightblack]#I #[fg=white,bg=brightblack,nobold,noitalics,nounderscore] #[fg=white,bg=brightblack]#W #F #[fg=brightblack,bg=black,nobold,noitalics,nounderscore]"
|
||||
set -g window-status-current-format "#[fg=black,bg=cyan,nobold,noitalics,nounderscore] #[fg=black,bg=cyan]#I #[fg=black,bg=cyan,nobold,noitalics,nounderscore] #[fg=black,bg=cyan]#W #F #[fg=cyan,bg=black,nobold,noitalics,nounderscore]"
|
||||
set -g window-status-format "#[fg=black,bg=brightblack,nobold,noitalics,nounderscore]${sep.right} #[fg=white,bg=brightblack]#I #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]${sep.rightThin} #[fg=white,bg=brightblack]#W #F #[fg=brightblack,bg=black,nobold,noitalics,nounderscore]${sep.right}"
|
||||
set -g window-status-current-format "#[fg=black,bg=cyan,nobold,noitalics,nounderscore]${sep.right} #[fg=black,bg=cyan]#I #[fg=black,bg=cyan,nobold,noitalics,nounderscore]${sep.rightThin} #[fg=black,bg=cyan]#W #F #[fg=cyan,bg=black,nobold,noitalics,nounderscore]${sep.right}"
|
||||
set -g window-status-separator ""
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
{
|
||||
# AppImages ship a squashfs payload that the bundled runtime mounts through
|
||||
# libfuse.so.2 at startup. nix-ld resolves the ELF interpreter but not that
|
||||
# dlopen, so running one directly dies with "dlopen(): error loading
|
||||
# libfuse.so.2". appimage-run sidesteps the mount entirely: it unpacks the
|
||||
# image and runs the payload inside an FHS sandbox, which the bundled Qt and
|
||||
# electron style binaries need anyway.
|
||||
#
|
||||
# Used for the BitBox02 wallet AppImage, downloaded fresh from
|
||||
# https://bitbox.swiss/download/ rather than installed from nixpkgs.
|
||||
programs.appimage = {
|
||||
enable = true;
|
||||
# register AppImages with binfmt_misc so ./Something.AppImage runs as-is,
|
||||
# no appimage-run prefix to remember.
|
||||
binfmt = true;
|
||||
};
|
||||
}
|
||||
+18
-2
@@ -4,12 +4,28 @@
|
||||
# enable gnupg agent
|
||||
programs.gnupg.agent = {
|
||||
enable = true;
|
||||
enableSSHSupport = true;
|
||||
pinentryPackage = pkgs.pinentry-curses;
|
||||
# a graphical pinentry never grabs the tty, so a passphrase prompt can no
|
||||
# longer take over a terminal that a coding agent is driving
|
||||
pinentryPackage = pkgs.pinentry-qt;
|
||||
settings = {
|
||||
# keep the key unlocked for a full working day instead of 10 minutes,
|
||||
# so signing commits asks at most once per session
|
||||
default-cache-ttl = 86400;
|
||||
max-cache-ttl = 86400;
|
||||
# fail an unattended signature instead of blocking on a prompt forever
|
||||
pinentry-timeout = 120;
|
||||
};
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
gnupg
|
||||
pinentry-qt
|
||||
# fallback for sessions without a display, switch pinentryPackage to use it
|
||||
pinentry-curses
|
||||
# prime the passphrase cache on demand, e.g. before an agent session
|
||||
(writeShellScriptBin "gpg-unlock" ''
|
||||
echo | ${config.programs.gnupg.package}/bin/gpg --clearsign --output /dev/null
|
||||
echo "gpg key unlocked"
|
||||
'')
|
||||
];
|
||||
}
|
||||
|
||||
@@ -4,6 +4,7 @@
|
||||
# system packages
|
||||
environment.systemPackages = with pkgs; [
|
||||
btop
|
||||
cifs-utils
|
||||
cowsay
|
||||
dnsutils
|
||||
ethtool
|
||||
@@ -20,6 +21,7 @@
|
||||
ltrace
|
||||
mtr
|
||||
neovim
|
||||
nfs-utils
|
||||
nh
|
||||
nix-output-monitor
|
||||
nmap
|
||||
@@ -33,10 +35,11 @@
|
||||
tree
|
||||
unzip
|
||||
usbutils
|
||||
vial
|
||||
vim
|
||||
wl-clipboard
|
||||
wget
|
||||
which
|
||||
wl-clipboard
|
||||
xz
|
||||
zip
|
||||
zstd
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
{
|
||||
# Vial-capable keyboards (lily58 pro r2g) expose a second, non-keyboard raw
|
||||
# HID interface that vial.rocks drives over WebHID. Its /dev/hidraw* node is
|
||||
# root-only by default, so neither chromium nor the native app can open it.
|
||||
#
|
||||
# This has to ship as a numbered rules file rather than via
|
||||
# services.udev.extraRules: extraRules lands in 99-local.rules, but the
|
||||
# builtin that turns TAG+="uaccess" into an actual ACL is invoked from
|
||||
# systemd's 73-seat-late.rules. A tag set at 99 is set too late to be seen,
|
||||
# so the device ends up correctly tagged and still unreadable. 60- sorts
|
||||
# safely ahead of 73.
|
||||
services.udev.packages = [
|
||||
(pkgs.writeTextFile {
|
||||
name = "vial-udev-rules";
|
||||
destination = "/lib/udev/rules.d/60-vial.rules";
|
||||
# Vial firmware advertises itself through a magic USB serial, so this
|
||||
# matches any vial board rather than just the lily58. uaccess hands the
|
||||
# device to whoever owns the active seat, no group membership needed.
|
||||
text = ''
|
||||
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", TAG+="uaccess"
|
||||
'';
|
||||
})
|
||||
];
|
||||
}
|
||||
Reference in New Issue
Block a user