{ config, lib, pkgs, ... }: { # Vial-capable keyboards (lily58 pro r2g) expose a second, non-keyboard raw # HID interface that vial.rocks drives over WebHID. Its /dev/hidraw* node is # root-only by default, so neither chromium nor the native app can open it. # # This has to ship as a numbered rules file rather than via # services.udev.extraRules: extraRules lands in 99-local.rules, but the # builtin that turns TAG+="uaccess" into an actual ACL is invoked from # systemd's 73-seat-late.rules. A tag set at 99 is set too late to be seen, # so the device ends up correctly tagged and still unreadable. 60- sorts # safely ahead of 73. services.udev.packages = [ (pkgs.writeTextFile { name = "vial-udev-rules"; destination = "/lib/udev/rules.d/60-vial.rules"; # Vial firmware advertises itself through a magic USB serial, so this # matches any vial board rather than just the lily58. uaccess hands the # device to whoever owns the active seat, no group membership needed. text = '' KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{serial}=="*vial:f64c2b3c*", TAG+="uaccess" ''; }) ]; }