Compare commits

...
Author SHA1 Message Date
aaron 1b9b584729 feature(gpg): add more signing-keys to the config to enable my laptop as well 2026-09-05 15:44:42 +02:00
aaron d9d6877714 feature(gpg): move git from gpg-signing to ssh-signing 2026-09-05 15:33:05 +02:00
aaron 6704ec389c Merge pull request 'chore(update): update flake file' (#73) from chore/update into main
Reviewed-on: #73
2026-08-31 13:52:26 +02:00
aaron aca9e5d7cc chore(update): update flake file 2026-08-30 18:46:17 +02:00
aaron 2c8fbf008d Merge pull request 'chore(update): update flake file' (#72) from chore/update into main
Reviewed-on: #72
2026-08-20 20:53:12 +02:00
aaron c4f1be8a38 chore(update): update flake file 2026-08-20 20:52:22 +02:00
aaron 6df7fcacbb Merge pull request 'fix: ship a numbered udev rule file for vial since otherwise it gets overwritten by systemd's udev file' (#71) from feature/vial into main
Reviewed-on: #71
2026-08-09 14:45:34 +02:00
aaron bc11b464a8 fix: ship a numbered udev rule file for vial since otherwise it gets overwritten by systemd's udev file 2026-08-09 14:45:08 +02:00
aaron 0ac9b45286 Merge pull request 'feature(udev): add support for vial.rocks configurable devices and add the native app as well' (#69) from feature/lily58 into main
Reviewed-on: #69
2026-08-09 14:27:03 +02:00
aaron 55e12b2226 Merge pull request 'feature/appimage' (#70) from feature/bitbox02 into main
Reviewed-on: #70
2026-08-09 14:26:54 +02:00
aaron eab8f4974e feature(appimage): add appimage squashfs support for my nixos 2026-08-09 14:13:52 +02:00
aaron 0b1190a257 feature(appimage): add appimage squashfs support for my nixos 2026-08-09 14:13:06 +02:00
aaron 62954a67b5 feature(udev): add support for vial.rocks configurable devices and add the native app as well 2026-08-09 13:49:46 +02:00
aaron 37d44b64c1 Merge pull request 'chore(flake): update flake file' (#68) from chore/update into main
Reviewed-on: #68
2026-08-06 16:50:04 +02:00
aaron cb5dd91550 chore(flake): update flake file 2026-08-06 16:38:59 +02:00
aaron fb04de1d23 Merge pull request 'feature(tmux): make tmux forward csi-u sequences thus enabling shift-enter in opencode' (#66) from feature/tmux into main
Reviewed-on: #66
2026-07-29 10:46:47 +02:00
aaron f41387e451 feature(tmux): make tmux forward csi-u sequences thus enabling shift-enter in opencode 2026-07-29 10:44:42 +02:00
aaron 2ae9d451f5 Merge pull request 'refactor(tmux): tidy up my old tmux config, use unicode for the seperators and backport augmentations from my at-work-config' (#65) from feature/tmux into main
Reviewed-on: #65
2026-07-29 10:34:05 +02:00
aaron 3feb6d2367 refactor(tmux): tidy up my old tmux config, use unicode for the seperators and backport augmentations from my at-work-config 2026-07-29 10:30:33 +02:00
aaron 41fbb67fc9 Merge pull request 'fix(sleep): revert s2sleep as it introduces crashes after the wake-up of the system' (#64) from fix/sleep into main
Reviewed-on: #64
2026-07-23 17:10:08 +02:00
aaron 274c39b213 Merge pull request 'refactor(sleep): move the s2 sleep change to argon only since s2idle would cost more battery on a laptop that s3 deep sleep' (#63) from fix/sleep into main
Reviewed-on: #63
2026-07-23 15:08:41 +02:00
aaron a2e9ad6035 Merge pull request 'fix(sleep): change sleep mode from s3 deep to s2 idle sleep to prevent issues woth radeon RDNA4 cards' (#62) from fix/sleep into main
Reviewed-on: #62
2026-07-23 14:56:59 +02:00
9 changed files with 193 additions and 42 deletions
Generated
+16 -15
View File
@@ -8,11 +8,11 @@
]
},
"locked": {
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"lastModified": 1787559586,
"narHash": "sha256-onL0VLf9vPllmT0H/OlURIU5r5t5WIEl7t4tVNKT0Nw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"rev": "9d0d87172c374f89da73c1cfe6d81ae62feac1f1",
"type": "github"
},
"original": {
@@ -28,11 +28,11 @@
]
},
"locked": {
"lastModified": 1784546264,
"narHash": "sha256-jxVr5EHMYAOkFvS2k0abIvt6NqyshyWmiHHzV17sT2g=",
"lastModified": 1787797243,
"narHash": "sha256-8+Q7NOB7RPajRjA4pbCDLzqH+MTjnG9x6LUPLfL2joA=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "e3dea8e4792b09a6c0eb5836b0284ad05b1acba0",
"rev": "99c9ec63390f1d8c14d95d9e8b17cc29cfbd4e11",
"type": "github"
},
"original": {
@@ -43,11 +43,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1784497964,
"narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=",
"lastModified": 1787900134,
"narHash": "sha256-VYXO0XZlgj06dxJZRhrD3WoSsvq/c7+/Akyoa22pefw=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163",
"rev": "83199d0d373dd3ac2b9a1996b1d0263f76ab7a4c",
"type": "github"
},
"original": {
@@ -66,11 +66,11 @@
"systems": "systems"
},
"locked": {
"lastModified": 1784057377,
"narHash": "sha256-yycNej5//EsRbV10moBoh+/63vXEwZD1ZFEiRm6C9rQ=",
"lastModified": 1787862710,
"narHash": "sha256-dL1Tv7LekaTWUJxHRckjbupWczDdc3QOgRuVCM+WAvQ=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "07180a087e4a00720dc0731cbcd8dec796974381",
"rev": "8c096abcf376137527c134da4ee210332b08ccc0",
"type": "github"
},
"original": {
@@ -86,11 +86,11 @@
]
},
"locked": {
"lastModified": 1784556533,
"narHash": "sha256-tlcP2x7d+ldS3BypTcInqrsOhi6BPuSSTeubfBMmm8Y=",
"lastModified": 1788099672,
"narHash": "sha256-t4Rw5OeULK/WA2Jh9ja615sCs2AmvahkAUx/ymdf2YQ=",
"owner": "noctalia-dev",
"repo": "noctalia-shell",
"rev": "815635cf7dc810616c9e6ecf4b9b4f4c54e69905",
"rev": "d891007c022a3a1d4484495fe8b350a00deafae9",
"type": "github"
},
"original": {
@@ -108,6 +108,7 @@
}
},
"systems": {
"flake": false,
"locked": {
"lastModified": 1774449309,
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
+2
View File
@@ -2,6 +2,7 @@
{
imports = [
../../modules/nixos/appimage.nix
../../modules/nixos/astro.nix
../../modules/nixos/audio.nix
../../modules/nixos/bootloader.nix
@@ -25,6 +26,7 @@
../../modules/nixos/steam.nix
../../modules/nixos/thunar.nix
../../modules/nixos/users.nix
../../modules/nixos/vial.nix
];
# set hostname
+2
View File
@@ -2,6 +2,7 @@
{
imports = [
../../modules/nixos/appimage.nix
../../modules/nixos/astro.nix
../../modules/nixos/audio.nix
../../modules/nixos/bootloader.nix
@@ -21,6 +22,7 @@
../../modules/nixos/settings.nix
../../modules/nixos/steam.nix
../../modules/nixos/users.nix
../../modules/nixos/vial.nix
];
# set hostname
+24 -3
View File
@@ -1,17 +1,38 @@
{ config, pkgs, inputs, ... }:
{ config, lib, pkgs, inputs, ... }:
let
email = "aaron@0x29a.ch";
# public half of every machine's ~/.ssh/id_ed25519, each one verified as a
# signing key in gitea. the key a host signs with is picked up from the key
# file itself, this list only tells the local git which machines to trust
signingKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGDkhvvTUcBSQdtXjX+Mw2Bp8HHhtiBm8aJi4ZxiBgZR aaron@neon"
];
in
{
# gitea verifies signatures against the account keys, this teaches the local
# git the same trust so `git log --show-signature` resolves as well
xdg.configFile."git/allowed_signers".text =
lib.concatMapStrings (key: "${email} ${key}\n") signingKeys;
programs.git = {
enable = true;
settings = {
push = { autoSetupRemote = true; };
user = {
name = "aaron";
email = "aaron@0x29a.ch";
email = email;
};
gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers";
};
signing = {
key = "7A830180A05DAC59CDE43B0677D2F5DB48184456";
format = "ssh";
# point at the *public* key so ssh-keygen signs through the ssh agent
# instead of reading the passphrase protected private key from disk
key = "${config.home.homeDirectory}/.ssh/id_ed25519.pub";
signer = "${pkgs.openssh}/bin/ssh-keygen";
signByDefault = true;
};
};
+84 -21
View File
@@ -1,60 +1,123 @@
{ config, pkgs, inputs, ... }:
let
# Powerline separators, U+E0B0..U+E0B3.
#
# Written as escapes rather than literal glyphs. These are Private Use Area
# codepoints: they render only with a patched font, they survive copy/paste
# badly, and when they get stripped the loss is invisible, the config still
# parses, the status bar just quietly loses its separators. Nix has no \u
# escape of its own, but fromJSON does.
sep = builtins.fromJSON ''
{
"right": "\ue0b0",
"rightThin": "\ue0b1",
"left": "\ue0b2",
"leftThin": "\ue0b3"
}
'';
in
{
programs.tmux = {
# defaults
enable = true;
prefix = "C-a";
keyMode = "vi";
mouse = true;
terminal = "screen-256color";
# tmux-256color gives truecolor, italics and undercurl in nvim.
terminal = "tmux-256color";
# Default is 500ms. Causes lag you feel when leaving insert mode in nvim,
# because tmux is waiting to see whether Esc starts an escape sequence.
escapeTime = 10;
# nvim autoread / :checktime react to focus.
focusEvents = true;
# History limit.
historyLimit = 50000;
# Window numbers matching the number row.
baseIndex = 1;
extraConfig = ''
# Status keys
set -g status-keys vi
# Tell tmux the outer terminal can do 24-bit colour (tmux >= 3.2).
set -sa terminal-features ",*:RGB"
# Shift+Enter / extended keys
# These make tmux forward CSI-u sequences unconditionally.
# Needs tmux >= 3.5 for the format option,
set -s extended-keys always
set -s extended-keys-format csi-u
set -as terminal-features '*:extkeys'
# Status bar options
set -g status-interval 1
set -g status on
set -g status-interval 5
set -g status-justify left
# Clock mode
setw -g clock-mode-colour cyan
# Colors
set -g status-bg black
set -g status-fg white
# Key bindings
# Reload configuration
bind r source-file ~/.config/tmux/tmux.conf
# Panel split and selection
bind r source-file ~/.config/tmux/tmux.conf \; display-message "tmux.conf reloaded"
# Panel split and selection, new panes/windows inherit the cwd
unbind %
unbind '"'
bind v split-window -v
bind c split-window -h
bind i new-window
bind b previous-window
bind n next-window
bind v split-window -v -c "#{pane_current_path}"
bind c split-window -h -c "#{pane_current_path}"
bind i new-window -c "#{pane_current_path}"
bind -r b previous-window
bind -r n next-window
# Move around panes with hjkl
bind h select-pane -L
bind j select-pane -D
bind k select-pane -U
bind l select-pane -R
# Resize panes
bind H resize-pane -L 5
bind J resize-pane -D 5
bind K resize-pane -U 5
bind L resize-pane -R 5
bind -r H resize-pane -L 5
bind -r J resize-pane -D 5
bind -r K resize-pane -U 5
bind -r L resize-pane -R 5
# Wayland clipboard integration
# Copy selection to both clipboard (Ctrl+V / Shift+Insert) and primary (middle-click)
bind -T copy-mode-vi v send-keys -X begin-selection
bind -T copy-mode-vi C-v send-keys -X rectangle-toggle
bind -T copy-mode-vi y send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
bind -T copy-mode-vi Enter send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
bind -T copy-mode-vi MouseDragEnd1Pane send-keys -X copy-pipe-and-cancel "wl-copy && wl-copy --primary"
# Uncomment if you want yanks to also travel over SSH via OSC52.
# Locally redundant with wl-copy above.
#set -g set-clipboard on
# Kill commands
bind q kill-window
bind Q kill-session
bind q confirm-before -p "kill window #W? (y/n)" kill-window
bind Q confirm-before -p "kill session #S? (y/n)" kill-session
# Bars
# This is the nord-tmux status line. #{prefix_highlight} came from that
# theme's tmux-prefix-highlight integration -- a plugin you never loaded,
# so the token expanded to nothing. tmux can do it natively. Commas inside
# #{?...} are argument separators and have to be escaped as #, hence the
# look of the style spec.
set -g status-left-length 24
set -g status-left "#[fg=black,bg=blue,bold] #{=20:session_name} #[fg=blue,bg=black,nobold,noitalics,nounderscore]"
set -g status-right "#{prefix_highlight}#[fg=brightblack,bg=black,nobold,noitalics,nounderscore]#[fg=white,bg=brightblack] %Y-%m-%d #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]#[fg=white,bg=brightblack] %H:%M #[fg=cyan,bg=brightblack,nobold,noitalics,nounderscore]#[fg=black,bg=cyan,bold] #H "
set -g status-left "#[fg=black,bg=blue,bold] #{=20:session_name} #[fg=blue,bg=black,nobold,noitalics,nounderscore]${sep.right}"
set -g status-right "#{?client_prefix,#[fg=black#,bg=yellow#,bold] ^A ,}#[fg=brightblack,bg=black,nobold,noitalics,nounderscore]${sep.left}#[fg=white,bg=brightblack] %Y-%m-%d #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]${sep.leftThin}#[fg=white,bg=brightblack] %H:%M #[fg=cyan,bg=brightblack,nobold,noitalics,nounderscore]${sep.left}#[fg=black,bg=cyan,bold] #H "
# Windows
set -g window-status-format "#[fg=black,bg=brightblack,nobold,noitalics,nounderscore] #[fg=white,bg=brightblack]#I #[fg=white,bg=brightblack,nobold,noitalics,nounderscore] #[fg=white,bg=brightblack]#W #F #[fg=brightblack,bg=black,nobold,noitalics,nounderscore]"
set -g window-status-current-format "#[fg=black,bg=cyan,nobold,noitalics,nounderscore] #[fg=black,bg=cyan]#I #[fg=black,bg=cyan,nobold,noitalics,nounderscore] #[fg=black,bg=cyan]#W #F #[fg=cyan,bg=black,nobold,noitalics,nounderscore]"
set -g window-status-format "#[fg=black,bg=brightblack,nobold,noitalics,nounderscore]${sep.right} #[fg=white,bg=brightblack]#I #[fg=white,bg=brightblack,nobold,noitalics,nounderscore]${sep.rightThin} #[fg=white,bg=brightblack]#W #F #[fg=brightblack,bg=black,nobold,noitalics,nounderscore]${sep.right}"
set -g window-status-current-format "#[fg=black,bg=cyan,nobold,noitalics,nounderscore]${sep.right} #[fg=black,bg=cyan]#I #[fg=black,bg=cyan,nobold,noitalics,nounderscore]${sep.rightThin} #[fg=black,bg=cyan]#W #F #[fg=cyan,bg=black,nobold,noitalics,nounderscore]${sep.right}"
set -g window-status-separator ""
'';
};
+19
View File
@@ -0,0 +1,19 @@
{ config, lib, pkgs, ... }:
{
# AppImages ship a squashfs payload that the bundled runtime mounts through
# libfuse.so.2 at startup. nix-ld resolves the ELF interpreter but not that
# dlopen, so running one directly dies with "dlopen(): error loading
# libfuse.so.2". appimage-run sidesteps the mount entirely: it unpacks the
# image and runs the payload inside an FHS sandbox, which the bundled Qt and
# electron style binaries need anyway.
#
# Used for the BitBox02 wallet AppImage, downloaded fresh from
# https://bitbox.swiss/download/ rather than installed from nixpkgs.
programs.appimage = {
enable = true;
# register AppImages with binfmt_misc so ./Something.AppImage runs as-is,
# no appimage-run prefix to remember.
binfmt = true;
};
}
+18 -2
View File
@@ -4,12 +4,28 @@
# enable gnupg agent
programs.gnupg.agent = {
enable = true;
enableSSHSupport = true;
pinentryPackage = pkgs.pinentry-curses;
# a graphical pinentry never grabs the tty, so a passphrase prompt can no
# longer take over a terminal that a coding agent is driving
pinentryPackage = pkgs.pinentry-qt;
settings = {
# keep the key unlocked for a full working day instead of 10 minutes,
# so signing commits asks at most once per session
default-cache-ttl = 86400;
max-cache-ttl = 86400;
# fail an unattended signature instead of blocking on a prompt forever
pinentry-timeout = 120;
};
};
environment.systemPackages = with pkgs; [
gnupg
pinentry-qt
# fallback for sessions without a display, switch pinentryPackage to use it
pinentry-curses
# prime the passphrase cache on demand, e.g. before an agent session
(writeShellScriptBin "gpg-unlock" ''
echo | ${config.programs.gnupg.package}/bin/gpg --clearsign --output /dev/null
echo "gpg key unlocked"
'')
];
}
+1
View File
@@ -35,6 +35,7 @@
tree
unzip
usbutils
vial
vim
wget
which
+26
View File
@@ -0,0 +1,26 @@
{ config, lib, pkgs, ... }:
{
# Vial-capable keyboards (lily58 pro r2g) expose a second, non-keyboard raw
# HID interface that vial.rocks drives over WebHID. Its /dev/hidraw* node is
# root-only by default, so neither chromium nor the native app can open it.
#
# This has to ship as a numbered rules file rather than via
# services.udev.extraRules: extraRules lands in 99-local.rules, but the
# builtin that turns TAG+="uaccess" into an actual ACL is invoked from
# systemd's 73-seat-late.rules. A tag set at 99 is set too late to be seen,
# so the device ends up correctly tagged and still unreadable. 60- sorts
# safely ahead of 73.
services.udev.packages = [
(pkgs.writeTextFile {
name = "vial-udev-rules";
destination = "/lib/udev/rules.d/60-vial.rules";
# Vial firmware advertises itself through a magic USB serial, so this
# matches any vial board rather than just the lily58. uaccess hands the
# device to whoever owns the active seat, no group membership needed.
text = ''
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", TAG+="uaccess"
'';
})
];
}