Compare commits

..
1 Commits
Author SHA1 Message Date
soraefir be9cb5ccc0 async podman from rebuild 2026-06-21 17:58:53 +02:00
36 changed files with 174 additions and 375 deletions
Generated
+55 -52
View File
@@ -23,11 +23,11 @@
]
},
"locked": {
"lastModified": 1786845137,
"narHash": "sha256-oQFip+v0luP8NIxJzmiW4Wu8bILsbFWom5l0zonl8hQ=",
"lastModified": 1779036909,
"narHash": "sha256-zXcwYQGCT6pzinK+1dBB2ekTVtfxGZAapb3Evdcu4fY=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "4cff07de74b50e64bdd68cd4e722ab5b6b35ee48",
"rev": "56c666e108467d87d13508936aade6d567f2a501",
"type": "github"
},
"original": {
@@ -74,21 +74,21 @@
"type": "github"
}
},
"flake-parts_2": {
"flake-utils": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib_2"
"systems": "systems"
},
"locked": {
"lastModified": 1772408722,
"narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3",
"lastModified": 1681202837,
"narHash": "sha256-H+Rh19JDwRtpVPAWp64F+rlEtxUWBAQW28eAi3SRSzg=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "cfacdce06f30d2b68473a46042957675eebb3401",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
@@ -97,11 +97,11 @@
"nixpkgs": "nixpkgs"
},
"locked": {
"lastModified": 1787144466,
"narHash": "sha256-HHfv2/HkNSKbbSyU9iD/g8lbP6r4tl33sSw1W4rXCk0=",
"lastModified": 1780065812,
"narHash": "sha256-SCSLUKBmwlSLGQ8Xbr8PjRFtiHNk0l9ktqkcmqdBkfE=",
"owner": "nixos",
"repo": "nixos-hardware",
"rev": "0471accf8d0a8210b31d947497d179ecc99e0021",
"rev": "b76b5639c0593e0aeb0b5879ad62d4b30596c144",
"type": "github"
},
"original": {
@@ -117,11 +117,11 @@
]
},
"locked": {
"lastModified": 1787146702,
"narHash": "sha256-YbRcLdU/yK4gWsQg7V8WTKZHfXL33g8+wSFUX3wyevs=",
"lastModified": 1779726825,
"narHash": "sha256-RUkMrREjKDQrA+dA9+xZviGAxM5W1aVdyOr/bSYpHrE=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "173b7e8d40fdc8c296a9c99854314f17a3a1704c",
"rev": "b179bde238977f7d4454fc770b1a727eaf55111c",
"type": "github"
},
"original": {
@@ -152,11 +152,11 @@
},
"nixUnstable": {
"locked": {
"lastModified": 1787111413,
"narHash": "sha256-sFosWtq21eHGJRnTc/hvf4M1obRgLEUMNm/IzllkHMA=",
"lastModified": 1780030872,
"narHash": "sha256-u6WU/yd/o8iYQrHX3RAwO1hYa3LkoSL+WNQD0rJfJZQ=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "afe3d8ac4395617bdcdac9f188ac8717a062e014",
"rev": "e9a7635a57597d9754eccebdfc7045e6c8600e6b",
"type": "github"
},
"original": {
@@ -174,11 +174,11 @@
]
},
"locked": {
"lastModified": 1784642409,
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=",
"lastModified": 1780169171,
"narHash": "sha256-3HBYDfBgZ+ph52HS6Ks/bMMwuh2uONIT72sZ1CtLE/s=",
"owner": "nix-community",
"repo": "nixos-wsl",
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e",
"rev": "998b2821c30b2938637230916904ceb8757c79e8",
"type": "github"
},
"original": {
@@ -215,28 +215,13 @@
"type": "github"
}
},
"nixpkgs-lib_2": {
"locked": {
"lastModified": 1772328832,
"narHash": "sha256-e+/T/pmEkLP6BHhYjx6GmwP5ivonQQn0bJdH9YrRB+Q=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "c185c7a5e5dd8f9add5b2f8ebeff00888b070742",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1787101114,
"narHash": "sha256-gwrPcFf/rDjHPaVflbDZ040ZDmBTRj/7+s8ZmE2SaIM=",
"lastModified": 1780203844,
"narHash": "sha256-K5sT4jTpGs15ADhviMKNBH38REpPf5Q6mM1+N6cArVE=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "b18a4b905f8d028dc4476412e6d6891728695379",
"rev": "b51242d7d43689db2f3be91bd05d5b24fbb469c4",
"type": "github"
},
"original": {
@@ -254,11 +239,11 @@
]
},
"locked": {
"lastModified": 1787161289,
"narHash": "sha256-CVTJnlo3KGv9XDT7594byKZAT2cZAMQUVvY4/1plK8M=",
"lastModified": 1780265777,
"narHash": "sha256-t/KORFHEv8Jn2vFmVfv4Zffekv+MUogI2KgtxuCcEmQ=",
"owner": "nix-community",
"repo": "nur",
"rev": "512f014a5717fd8181e971f7a0d12901e35521d3",
"rev": "39917b7f68263188707925ffe26c9df6ef4e7d64",
"type": "github"
},
"original": {
@@ -288,11 +273,11 @@
]
},
"locked": {
"lastModified": 1786629091,
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=",
"lastModified": 1777944972,
"narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f",
"rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
"type": "github"
},
"original": {
@@ -301,16 +286,34 @@
"type": "github"
}
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"vscode-server": {
"inputs": {
"flake-parts": "flake-parts_2"
"flake-utils": "flake-utils",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784312229,
"narHash": "sha256-2uHCSUw341o3my1R0U0YCfbnMEazylxb58evWsjGL50=",
"lastModified": 1770124655,
"narHash": "sha256-yHmd2B13EtBUPLJ+x0EaBwNkQr9LTne1arLVxT6hSnY=",
"owner": "nix-community",
"repo": "nixos-vscode-server",
"rev": "2f984dfbe7e5271b5c413d3e734374cc1306c921",
"rev": "92ce71c3ba5a94f854e02d57b14af4997ab54ef0",
"type": "github"
},
"original": {
+1 -1
View File
@@ -32,7 +32,7 @@
vscode-server = {
url = "github:nix-community/nixos-vscode-server";
# inputs.nixpkgs.follows = "nixpkgs";
inputs.nixpkgs.follows = "nixpkgs";
};
};
+1 -1
View File
@@ -28,7 +28,7 @@ let
logoColor1 = p.base07;
logoColor2 = p.base07;
# ─────────────────────────────────────────────────────────────────────────
in lib.mkIf config.syscfg.make.gui {
in {
home.packages = with pkgs; [ fastfetch ];
xdg.configFile."neofetch/config.conf".source = ./config.conf;
xdg.configFile."fastfetch/logo.txt".source = ./logo.txt;
+2 -2
View File
@@ -1,5 +1,5 @@
{ config, lib, ... }: {
programs.kitty = lib.mkIf config.syscfg.make.gui {
{ config, ... }: {
programs.kitty = {
enable = true;
settings = {
foreground = "#${config.colorScheme.palette.base07}";
+3 -3
View File
@@ -1,16 +1,16 @@
{ config, lib, pkgs, ... }: {
{ pkgs, ... }: {
home.packages = with pkgs; [
ripgrep
unzip
socat
appimage-run
cbonsai
pipes-rs
cmatrix
#cava
sl
] ++ lib.optionals (config.syscfg.make.gui || config.syscfg.make.develop) [
pkgs.appimage-run
];
}
@@ -1,22 +1,18 @@
{ lib, config, pkgs, ... }:
let
exts = with pkgs.vscode-extensions; [
bbenoist.nix
esbenp.prettier-vscode
anthropic.claude-code
# openai.codex
];
in {
{ lib, config, pkgs, ... }: {
config = lib.mkIf (config.syscfg.make.develop) {
programs.vscodium = {
enable = true;
profiles.default.extensions = exts;
};
programs.antigravity = {
enable = true;
profiles.default.extensions = exts;
#profiles.default = {
profiles.default.extensions = with pkgs.vscode-extensions; [
bbenoist.nix
esbenp.prettier-vscode
golang.go
ms-python.vscode-pylance
ms-vscode.cpptools
dbaeumer.vscode-eslint
];
#};
};
};
}
+1 -2
View File
@@ -4,9 +4,8 @@
programs.imv.enable = true;
programs.obs-studio.enable = true;
services.jellyfin-mpv-shim.enable = true;
home.packages = with pkgs; [ krita gimp darktable ];
home.packages = with pkgs; [ jellyfin-mpv-shim krita gimp darktable ];
};
}
+3 -34
View File
@@ -1,17 +1,18 @@
{ lib, config, pkgs, ... }:
let
configuredMpv = config.programs.mpv.finalPackage;
shimWatchdog = pkgs.custom.jellyfin-mpv-shim-watchdog;
in{
config = lib.mkIf (config.syscfg.make.gui) {
programs.mpv = {
enable = true;
scripts = with pkgs.mpvScripts; [ mpris ];
scripts = with pkgs.mpvScripts; [ mpris modernz ];
config = {
hwdec ="auto";
profile ="high-quality";
ytdl-format = "bestvideo+bestaudio";
osc ="no";
};
bindings =
@@ -82,37 +83,5 @@ in{
};
programs.yt-dlp.enable = true;
# The upstream jellyfin-mpv-shim service has no Restart and no network
# ordering: it happily starts while offline (silently dead) and never
# recovers a connection dropped by a network blip. Gate its start on the
# network being up, and let a watchdog notice the "up but not connected"
# state that systemd can't see. See pkgs.custom.jellyfin-mpv-shim-watchdog.
systemd.user.services.jellyfin-mpv-shim.Service = {
ExecStartPre = "${shimWatchdog}/bin/jellyfin-mpv-shim-watchdog wait-online";
TimeoutStartSec = "infinity"; # stay in start-pre until the network is back
Restart = "on-failure";
RestartSec = 5;
};
systemd.user.services.jellyfin-mpv-shim-watchdog = {
Unit = {
Description = "Restart jellyfin-mpv-shim when it is up but not connected";
After = [ "jellyfin-mpv-shim.service" ];
};
Service = {
Type = "oneshot";
ExecStart = "${shimWatchdog}/bin/jellyfin-mpv-shim-watchdog check";
};
};
systemd.user.timers.jellyfin-mpv-shim-watchdog = {
Unit.Description = "Periodic health check for jellyfin-mpv-shim";
Timer = {
OnActiveSec = "60s";
OnUnitActiveSec = "60s";
};
Install.WantedBy = [ "timers.target" ];
};
};
}
+1 -1
View File
@@ -5,7 +5,7 @@
home.packages = with pkgs;
[
# custom.simc
instawow
unstable.instawow
];
# templates buggy currently
@@ -6,15 +6,13 @@ PANEL="$1"
exec 9>"/tmp/eww_panel_toggle.lock"
flock -n 9 || exit 0
# Every eww call must run with fd 9 closed (9>&-): `eww open` daemonizes and
# would inherit the fd, holding the flock forever and wedging all later toggles.
CURRENT=$(eww get active-panel 2>/dev/null 9>&- | tr -d '"')
CURRENT=$(eww get active-panel 2>/dev/null | tr -d '"')
if [ "$CURRENT" = "$PANEL" ]; then
eww update active-panel="" 9>&-
eww close popup 2>/dev/null 9>&-
eww update active-panel=""
eww close popup 2>/dev/null
else
eww update active-panel="$PANEL" 9>&-
eww close popup 2>/dev/null 9>&-
eww-open-on-current-screen popup 9>&-
eww update active-panel="$PANEL"
eww close popup 2>/dev/null
eww-open-on-current-screen popup
fi
+1 -49
View File
@@ -1,23 +1,9 @@
{ lib, config, pkgs, ... }:
let
ensureDaemon = pkgs.custom.eww-ensure-daemon;
ewwCleanStart = pkgs.writeShellScript "eww-clean-start" ''
uid="$(${pkgs.coreutils}/bin/id -u)"
runtime_dir="''${XDG_RUNTIME_DIR:-/run/user/$uid}"
${pkgs.procps}/bin/pkill -TERM -x -u "$uid" eww >/dev/null 2>&1 || true
${pkgs.coreutils}/bin/sleep 0.2
${pkgs.procps}/bin/pkill -KILL -x -u "$uid" eww >/dev/null 2>&1 || true
${pkgs.coreutils}/bin/rm -f "$runtime_dir"/eww-server_*
'';
openOnCurrentScreen = pkgs.writeShellScriptBin "eww-open-on-current-screen" ''
window="$1"
shift
${ensureDaemon}/bin/eww-ensure-daemon || exit 1
screen="$(hyprctl monitors -j | ${lib.getExe pkgs.jq} -r '.[] | select(.focused == true) | .name' | head -n1)"
if [ -n "$screen" ]; then
@@ -27,21 +13,6 @@ let
exec ${lib.getExe pkgs.eww} open "$window" "$@"
'';
# Escape hatch: tears down every eww process (including orphaned daemons that
# own unreachable surfaces), clears the stale socket, and brings back a single
# daemon with the bar. `pkill -x` matches the process name exactly so it can
# never match a wrapper script or a shell that merely mentions eww.
ewwReset = pkgs.writeShellScriptBin "eww-reset" ''
${pkgs.systemd}/bin/systemctl --user stop eww.service >/dev/null 2>&1 || true
${pkgs.procps}/bin/pkill -x -u "$(id -u)" eww >/dev/null 2>&1 || true
sleep 1
${pkgs.procps}/bin/pkill -9 -x -u "$(id -u)" eww >/dev/null 2>&1 || true
rm -f "''${XDG_RUNTIME_DIR:-/run/user/$(id -u)}"/eww-server_*
${ensureDaemon}/bin/eww-ensure-daemon || exit 1
exec ${lib.getExe pkgs.eww} open bar --screen 0
'';
# Wraps a static script file with a bash launcher that prepends Nix store
# bin dirs to PATH — keeps the source files unchanged.
mkScript = name: src: inputs: pkgs.writeShellScriptBin name ''
@@ -72,26 +43,7 @@ let
in {
config = lib.mkIf (config.usercfg.wm == "Wayland") {
home.packages = [ pkgs.eww openOnCurrentScreen ensureDaemon ewwReset ];
# One explicitly-managed daemon, so no client ever races to spawn a rival.
# ExecStartPre clears a socket left behind by an unclean exit, which would
# otherwise make the fresh daemon look reachable to clients before it binds.
systemd.user.services.eww = {
Unit = {
Description = "eww daemon";
PartOf = [ "graphical-session.target" ];
After = [ "graphical-session.target" ];
};
Service = {
Type = "simple";
ExecStartPre = "${ewwCleanStart}";
ExecStart = "${lib.getExe pkgs.eww} daemon --no-daemonize";
Restart = "always";
RestartSec = 1;
};
Install.WantedBy = [ "graphical-session.target" ];
};
home.packages = [ pkgs.eww openOnCurrentScreen ];
xdg.configFile = lib.mkMerge [
{
+54 -30
View File
@@ -1,12 +1,7 @@
{ config, lib, pkgs, ... }:
let
# Close the bar if it's already open (wrong screen), then open on the target screen.
# Must go through eww-ensure-daemon: this runs on every monitor hotplug, and a
# bare `eww open` against a busy/dead socket spawns a second daemon, leaving the
# first one's bar and popups on screen with no way to close them.
moveOrOpenBar = screen: "${pkgs.writeShellScript "kanshi-eww-bar-${toString screen}" ''
${pkgs.custom.eww-ensure-daemon}/bin/eww-ensure-daemon || exit 1
if ${pkgs.eww}/bin/eww active-windows 2>/dev/null | grep -qx "bar"; then
${pkgs.eww}/bin/eww close bar
fi
@@ -23,7 +18,7 @@ let
aocT = "AOC 24E1W1 GNSKCHA086899";
aocB = "AOC 24E1W1 GNSKBHA080346";
lgM = "LG Electronics LG ULTRAGEAR+ 511NTDVGC194";
valinorM = "Lenovo Group Limited *";
in {
config = lib.mkIf (config.usercfg.wm == "Wayland") {
@@ -47,9 +42,17 @@ in {
mode = "1920x1080@60.000";
};}
{output = baseOutput//{
criteria = "Lenovo Group Limited *";
criteria = "LG UNKNOWN_TBD";
mode = "1920x1080@144.000";
};}
{output = baseOutput//{
criteria = "LG Display 0x060A Unknown";
mode = "1920x1080@60.020";
};}
{output = baseOutput//{
criteria = "CEX CX133 0x00000001";
mode = "2560x1600@59.972";
};}
{output = baseOutput//{
criteria = "AOC 16G3 1DDP7HA000348";
mode = "1920x1080@144.000";
@@ -96,7 +99,7 @@ in {
];
};}
{profile = {
name = "tower_01";
name = "tower_0";
outputs = [
{
criteria = "AOC 24E1W1 GNSKCHA086899";
@@ -131,33 +134,54 @@ in {
];
};}
{profile = {
name = "valinor00";
name = "tower_1";
outputs = [
{
criteria = "Lenovo Group Limited *";
criteria = "AOC 24E1W1 GNSKCHA086899";
position = "0,0";
}
{
criteria = "AOC 24E1W1 GNSKBHA080346";
position = "0,0";
}
{
criteria = "LG UNKNOWN_TBD";
position = "0,0";
}
];
exec = [
"${pkgs.writeShellScript "kanshi-hyprland-init" ''
#!/usr/bin/env bash
${pkgs.hyprland}/bin/hyprctl eval '
hl.workspace_rule({ workspace = "1", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "2", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "3", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "4", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "5", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "6", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "7", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "8", monitor = "eDP-1", default = true })
hl.workspace_rule({ workspace = "9", monitor = "eDP-1", default = true })
'
${pkgs.hyprland}/bin/hyprctl eval 'hl.dispatch(hl.dsp.focus({ monitor = "eDP-1" })); hl.dispatch(hl.dsp.focus({ workspace = "1" }));'
''}"
"${pkgs.awww}/bin/awww restore"
(moveOrOpenBar 0)
];
};}
{profile = {
name = "laptop_0";
outputs = [{
criteria = "LG Display 0x060A Unknown";
position = "0,0";
}];
};}
{profile = {
name = "laptop_1";
outputs = [
{
criteria = "CEX CX133 0x00000001";
position = "0,0";
}
{
criteria = "LG Display 0x060A Unknown";
position = "2560,0";
}
];
};}
{profile = {
name = "laptop_2";
outputs = [
{
criteria = "AOC 16G3 1DDP7HA000348";
position = "0,0";
}
{
criteria = "LG Display 0x060A Unknown";
position = "1920,0";
}
];
};}
];
};
+2 -5
View File
@@ -24,17 +24,14 @@
startupScript = pkgs.writeShellScriptBin "hyprland-start" ''
# Wait for the managed daemon rather than letting `eww open` spawn its own:
# at login the socket may not be bound yet, and a self-spawned client daemon
# would orphan the service's one, leaving unclosable windows behind.
(${pkgs.custom.eww-ensure-daemon}/bin/eww-ensure-daemon \
&& ${pkgs.eww}/bin/eww open bar --screen 0) &
${pkgs.eww}/bin/eww open bar &
${pkgs.awww}/bin/awww-daemon &
${pkgs.awww}/bin/awww restore &
sleep 2
keepassxc &
firefox &
jellyfin-mpv-shim &
easyeffects --gapplication-service &
sleep 2
+1
View File
@@ -109,6 +109,7 @@
telegram-desktop &
nextcloud &
jellyfin-mpv-shim &
#flameshot &
sleep 2
+1 -1
View File
@@ -1,5 +1,5 @@
{ config, lib, ... }: {
imports = [ ./dbus ./docs ./fonts ./hw ./locale ./network ./nix ./security ./xdg ];
imports = [ ./dbus ./fonts ./hw ./locale ./network ./nix ./security ./xdg ];
services.journald.extraConfig = ''
SystemMaxUse=512M
-14
View File
@@ -1,14 +0,0 @@
{ config, lib, ... }:
let
cfg = config.syscfg.make;
withDocs = cfg.gui || cfg.develop || cfg.serverExtras;
in
{
documentation = lib.mkIf (!withDocs) {
enable = false;
man.enable = false;
info.enable = false;
doc.enable = false;
nixos.enable = false;
};
}
+2 -2
View File
@@ -1,6 +1,6 @@
{ config, lib, pkgs, ... }: {
{ pkgs, ... }: {
fonts = lib.mkIf (config.syscfg.make.gui || config.syscfg.make.serverExtras) {
fonts = {
enableDefaultPackages = false;
fontDir.enable = true;
+3 -3
View File
@@ -1,5 +1,5 @@
{ config, lib, ... }: {
services.fwupd.enable = lib.mkDefault (config.syscfg.make.gui || config.syscfg.make.power);
{ lib, ... }: {
services.fwupd.enable = true;
hardware.enableAllFirmware = false;
services.power-profiles-daemon.enable = lib.mkDefault config.syscfg.make.gui;
services.power-profiles-daemon.enable = lib.mkDefault true;
}
+3 -6
View File
@@ -1,9 +1,6 @@
{ config, lib, pkgs, ... }:
let
hasNfsFileSystems = lib.any (fs: fs.fsType == "nfs" || fs.fsType == "nfs4") (lib.attrValues config.fileSystems);
in {
{ pkgs, ... }: {
services.fstrim.enable = true; # Improves SSD life
services.gvfs.enable = config.syscfg.make.gui; # User Mounted FS
services.gvfs.enable = true; # User Mounted FS
environment.systemPackages = lib.optionals hasNfsFileSystems [ pkgs.nfs-utils ];
environment.systemPackages = with pkgs; [ nfs-utils ];
}
+3 -3
View File
@@ -1,4 +1,4 @@
{ config, ... }: {
hardware.graphics.enable = config.syscfg.make.gui || config.syscfg.make.serverExtras || config.syscfg.make.game;
hardware.graphics.enable32Bit = config.syscfg.make.game;
{ ... }: {
hardware.graphics.enable = true;
hardware.graphics.enable32Bit = true;
}
+2 -4
View File
@@ -1,4 +1,4 @@
{ config, inputs, lib, pkgs, ... }: {
{ inputs, pkgs, ... }: {
nixpkgs.config = {
permittedInsecurePackages = [ ];
allowUnfree = true;
@@ -33,9 +33,7 @@
];
};
};
programs.nix-ld = lib.mkIf (
config.syscfg.make.gui || config.syscfg.make.develop || config.syscfg.make.serverExtras
) {
programs.nix-ld = {
enable = true;
libraries = with pkgs; [
libx11 libxcb libxi libxext libxkbfile xcbutilcursor
@@ -1,12 +1,10 @@
{ config, lib, pkgs, ... }: {
config = lib.mkIf config.syscfg.make.gui {
security.polkit.enable = true;
security.pam.services.hyprlock = { #swaylock
text = ''
auth include login
'';
};
environment.systemPackages = [ pkgs.polkit_gnome ];
{ pkgs, ... }: {
security.polkit.enable = true;
security.pam.services.hyprlock = { #swaylock
text = ''
auth include login
'';
};
environment.systemPackages = with pkgs; [ polkit_gnome ];
}
-1
View File
@@ -3,7 +3,6 @@
config = lib.mkIf (config.syscfg.make.develop) {
programs.wireshark.enable = true;
programs.dconf.enable = true;
environment.systemPackages = with pkgs; [ wget dconf wireshark mtr android-tools ];
};
+2 -2
View File
@@ -1,5 +1,5 @@
{ config, lib, pkgs, ... }: {
{ pkgs, ... }: {
imports = [ ./debug ./develop ./telegraf ];
environment.systemPackages = lib.optionals config.syscfg.make.gui [ pkgs.engrampa ];
environment.systemPackages = with pkgs; [ pkgs.engrampa ];
}
+6
View File
@@ -63,6 +63,12 @@ in {
startAt = "weekly";
};
}
// builtins.listToAttrs (
map (name: {
name = "podman-${name}";
value.serviceConfig.Type = lib.mkForce "exec";
}) (builtins.attrNames config.virtualisation.oci-containers.containers)
)
// mkNamedUnits (e: {
name = "${e.name}-vm";
value = {
-3
View File
@@ -3,9 +3,7 @@ let
listNames = config.syscfg.server.db;
containerNames = lib.concatMap (app: app.requires.secrets) (builtins.attrValues config.syscfg.server.loadedContainers);
allApps = lib.unique (listNames ++ containerNames);
needsServerSops = config.syscfg.server.loadedContainers != {} || allApps != [];
in{
config = lib.mkIf needsServerSops {
sops.secrets = {
CUSTOM = {
mode = "0444";
@@ -15,5 +13,4 @@ in{
mode = "0444";
sopsFile = ./server.yaml;
}));
};
}
+1 -2
View File
@@ -2,9 +2,8 @@
with lib; {
cli = mkOption { type = types.bool; default = true; };
gui = mkOption { type = types.bool; default = false; };
serverExtras = mkOption { type = types.bool; default = false; };
virt = mkOption { type = types.bool; default = false; };
power = mkOption { type = types.bool; default = false; };
game = mkOption { type = types.bool; default = false; };
develop = mkOption { type = types.bool; default = false; };
}
}
-4
View File
@@ -5,8 +5,4 @@
repalette = pkgs.callPackage ./repalette { };
vosk = pkgs.callPackage ./vosk { };
eww-ensure-daemon = pkgs.callPackage ./eww-ensure-daemon { };
jellyfin-mpv-shim-watchdog = pkgs.callPackage ./jellyfin-mpv-shim-watchdog { };
}
-58
View File
@@ -1,58 +0,0 @@
{ lib
, writeShellScriptBin
, coreutils
, eww
, procps
, systemd
, util-linux
}:
# `eww open` silently becomes a NEW daemon when it can't reach the socket,
# rebinding the same socket path and orphaning the previous daemon. The old
# daemon keeps rendering its layer-shell surfaces but no longer answers any
# `eww close` — that is the "zombie panel I can't close" / "bar opened twice".
# Every open path must go through here first, so the socket is always live and
# owned by the managed user service before a client touches it.
writeShellScriptBin "eww-ensure-daemon" ''
eww=${lib.getExe eww}
uid="$(${coreutils}/bin/id -u)"
runtime_dir="''${XDG_RUNTIME_DIR:-/run/user/$uid}"
lock_file="$runtime_dir/eww-ensure-daemon.lock"
service_active() {
${systemd}/bin/systemctl --user is-active --quiet eww.service
}
daemon_healthy() {
"$eww" ping >/dev/null 2>&1 && service_active
}
wait_for_ping() {
i=0
while [ "$i" -lt 100 ]; do
daemon_healthy && return 0
${coreutils}/bin/sleep 0.1
i=$((i + 1))
done
return 1
}
daemon_healthy && exit 0
${coreutils}/bin/mkdir -p "$runtime_dir"
(
${util-linux}/bin/flock -x 9
daemon_healthy && exit 0
${systemd}/bin/systemctl --user stop eww.service >/dev/null 2>&1 || true
${procps}/bin/pkill -TERM -x -u "$uid" eww >/dev/null 2>&1 || true
${coreutils}/bin/sleep 0.2
${procps}/bin/pkill -KILL -x -u "$uid" eww >/dev/null 2>&1 || true
${coreutils}/bin/rm -f "$runtime_dir"/eww-server_*
${systemd}/bin/systemctl --user reset-failed eww.service >/dev/null 2>&1 || true
${systemd}/bin/systemctl --user start eww.service >/dev/null 2>&1 || true
wait_for_ping
) 9>"$lock_file"
''
@@ -1,51 +0,0 @@
{ writeShellScriptBin
, coreutils
, findutils
, gnugrep
, iproute2
, systemd
}:
# jellyfin-mpv-shim keeps a persistent socket to the Jellyfin server. When the
# machine drops off the network that socket dies, but the process stays alive
# and the unit stays "active" — running yet deaf to cast requests, the "up but
# not working, restart it by hand" case. systemd can't see this: nothing
# crashes and the shim speaks no health protocol, so we probe the real thing —
# is its MainPID still holding a live (established, non-loopback) connection?
#
# check (default) one tick, run by a 60s timer: restart if online but
# not connected, rate-limited to one restart per 5 min
# wait-online block until a real address exists; used as ExecStartPre so the
# unit only starts once online
writeShellScriptBin "jellyfin-mpv-shim-watchdog" ''
set -u
service="jellyfin-mpv-shim.service"
stamp="''${XDG_RUNTIME_DIR:-/run/user/$(${coreutils}/bin/id -u)}/jellyfin-mpv-shim-watchdog.stamp"
# A global-scope address on a non-loopback interface true for a LAN IP too,
# so this needs no server URL and works whether Jellyfin is local or remote.
network_up() { ${iproute2}/bin/ip -o addr show scope global up 2>/dev/null | ${gnugrep}/bin/grep -q .; }
if [ "''${1:-check}" = wait-online ]; then
while ! network_up; do ${coreutils}/bin/sleep 5; done
exit 0
fi
# Healthy: MainPID owns an established socket to something other than loopback.
pid="$(${systemd}/bin/systemctl --user show -p MainPID --value "$service" 2>/dev/null)"
if [ "''${pid:-0}" != 0 ] && ${iproute2}/bin/ss -tnpH state established 2>/dev/null \
| ${gnugrep}/bin/grep "pid=$pid," \
| ${gnugrep}/bin/grep -qv -e '127\.0\.0\.1' -e '\[::1\]'; then
exit 0
fi
# Not connected: only worth restarting once the network is actually back...
network_up || exit 0
# ...and not if we already restarted within the last 5 minutes.
[ -e "$stamp" ] && [ -n "$(${findutils}/bin/find "$stamp" -mmin -5 2>/dev/null)" ] && exit 0
: > "$stamp"
echo "jellyfin-mpv-shim-watchdog: online but no live connection -> restarting $service"
${systemd}/bin/systemctl --user restart "$service"
''
+1 -1
View File
@@ -38,7 +38,7 @@ pkgs.mkShell {
#CUSTOM (custom...)
]) ++ (with pkgs.llvmPackages; [
libcxxClang
]) ++ (with pkgs.python3Packages; [
]) ++ (with pkgs.python313Packages; [
pip pandas numpy matplotlib typer pillow reportlab python-barcode pypdf markdown requests
])
;
-5
View File
@@ -17,9 +17,4 @@
10.10.1.2 avalon.helcel.net
'';
swapDevices = [ {
device = "/swapfile";
size = 2 * 1024; # Size in megabytes (4 GB)
} ];
}
-2
View File
@@ -5,12 +5,10 @@
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
boot.loader.systemd-boot.enable = lib.mkForce false;
boot.loader.efi.canTouchEfiVariables = lib.mkForce false;
boot.loader.grub = {
enable = true;
device = "/dev/sda";
efiSupport = true;
efiInstallAsRemovable = true;
};
boot.initrd.availableKernelModules =