Compare commits

...
5 Commits
Author SHA1 Message Date
Lumpiasty b52d07c778 chore: add cachyos binary cache 2026-06-20 00:51:43 +02:00
Lumpiasty 5b2b451002 Use librewolf from nixpkgs 26.05 2026-06-20 00:48:01 +02:00
Lumpiasty a6af72b1ae feat: use cachyos kernel on acer host 2026-06-19 22:10:32 +02:00
Lumpiasty e02099e022 update nixos 2026-06-19 19:00:53 +02:00
Lumpiasty 4ab575a73b add antigravity provider for opencode 2026-06-19 18:06:47 +02:00
9 changed files with 297 additions and 44 deletions
Generated
+155 -18
View File
@@ -44,6 +44,38 @@
"type": "github"
}
},
"cachyos-kernel": {
"flake": false,
"locked": {
"lastModified": 1781883168,
"narHash": "sha256-raAojJGk0aWdscfFn/9ikZ6V5oUuAZcAz5kjAZ2QN3E=",
"owner": "CachyOS",
"repo": "linux-cachyos",
"rev": "daed450e9b1a4fadfef68fb4fa5e2f3391fedb34",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "linux-cachyos",
"type": "github"
}
},
"cachyos-kernel-patches": {
"flake": false,
"locked": {
"lastModified": 1781879636,
"narHash": "sha256-vNTtJIee7GrrUY93UwQ/x2yFkwI4IpHPiyc3kXfVflo=",
"owner": "CachyOS",
"repo": "kernel-patches",
"rev": "5e818fcbf2eb8de573c9270295ce9f5215973303",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "kernel-patches",
"type": "github"
}
},
"cf": {
"locked": {
"lastModified": 1756852014,
@@ -67,11 +99,11 @@
]
},
"locked": {
"lastModified": 1780258891,
"narHash": "sha256-KURy7kHE9TZG2wrQX0xaKScWp3JqEx7cYxboCJO/KPU=",
"lastModified": 1781833989,
"narHash": "sha256-zLuv4n6C5ceFaLwYKV2uh8zK7Z6fFXx7FD398pi2GVU=",
"owner": "sadjow",
"repo": "claude-code-nix",
"rev": "e65e7eca7efe776d0bf5f53e317d33b3ff973623",
"rev": "a94e5e841e4992e8e173aba973cb9c41ec575bb8",
"type": "github"
},
"original": {
@@ -128,6 +160,22 @@
}
},
"flake-compat_2": {
"flake": false,
"locked": {
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "NixOS",
"repo": "flake-compat",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1627913399,
@@ -164,6 +212,24 @@
"type": "github"
}
},
"flake-parts_2": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
"lastModified": 1778716662,
"narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems_2"
@@ -226,11 +292,11 @@
]
},
"locked": {
"lastModified": 1780099287,
"narHash": "sha256-efIPwVGtIWIjWcznhaop6XN6HxnOL8800hF6CBNvlqQ=",
"lastModified": 1781884383,
"narHash": "sha256-i27BvWCxpdunZVCpeO1WrGLw2chG8LlMiuD6FSYezjo=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "7d8127d308c3fb9664f7e643eec944be74ebb37d",
"rev": "e061b008856927dacf7adfcd44343f353413cbd8",
"type": "github"
},
"original": {
@@ -280,6 +346,28 @@
"type": "github"
}
},
"nix-cachyos-kernel": {
"inputs": {
"cachyos-kernel": "cachyos-kernel",
"cachyos-kernel-patches": "cachyos-kernel-patches",
"flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_2",
"nixpkgs": "nixpkgs"
},
"locked": {
"lastModified": 1781896647,
"narHash": "sha256-xlHqfEa3ZwgD477tn3wF1DEv7KgppmDaSLss44dbjmQ=",
"owner": "xddxdd",
"repo": "nix-cachyos-kernel",
"rev": "8bf6af7fd57d129ec00d06e399e01cb6f97a97e8",
"type": "github"
},
"original": {
"owner": "xddxdd",
"repo": "nix-cachyos-kernel",
"type": "github"
}
},
"nix-flatpak": {
"locked": {
"lastModified": 1767983141,
@@ -303,11 +391,11 @@
]
},
"locked": {
"lastModified": 1780319273,
"narHash": "sha256-U+H0zgXVtFMz1mwVTvn5ATOweYU9LpFsbwpUT3TT4SM=",
"lastModified": 1781885060,
"narHash": "sha256-Sx6m0ylfHIRmowEuzphgZ3McRamg5GHs8cdJcwO29Fc=",
"owner": "sudosubin",
"repo": "nix-skills",
"rev": "97a2deb0d9194b9dbe9725b1b076f2ee854e3973",
"rev": "d486392e9e2b9b3d537694e6dd7599f0de3c083e",
"type": "github"
},
"original": {
@@ -346,11 +434,11 @@
]
},
"locked": {
"lastModified": 1780310866,
"narHash": "sha256-fPBRVf6A5xlACYcOI59shGrjURuvwu0lRsDoSCEXt/I=",
"lastModified": 1781622756,
"narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=",
"owner": "NixOS",
"repo": "nixos-hardware",
"rev": "4ed851c979641e28597a05086332d75cdc9e395f",
"rev": "08018c72174a4df5657f8d94178ac69fb9c243e5",
"type": "github"
},
"original": {
@@ -362,20 +450,51 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1779560665,
"narHash": "sha256-tpyBcxPpcQb8ukyNF7DoCwfSY3VPsxHoYwj00Cayv5o=",
"lastModified": 1781836206,
"narHash": "sha256-BGjXqZOcLbkjwt8smyUskR8hNl7piTg8ccpQdSTw09s=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "64c08a7ca051951c8eae34e3e3cb1e202fe36786",
"rev": "d4fea6b6bfce7b55c6df36fb973205b89d7fe761",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"ref": "nixos-unstable-small",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-2605": {
"locked": {
"lastModified": 1781216227,
"narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-lib": {
"locked": {
"lastModified": 1777168982,
"narHash": "sha256-GOkGPcboWE9BmGCRMLX3worL4EMnsnG8MyKmXNeYuhQ=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "f5901329dade4a6ea039af1433fb087bd9c1fe14",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgs-linuxeol": {
"locked": {
"lastModified": 1776914381,
@@ -392,6 +511,22 @@
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1781577229,
"narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"ntfsplus": {
"inputs": {
"linux-ntfs": "linux-ntfs",
@@ -415,7 +550,7 @@
},
"peerix": {
"inputs": {
"flake-compat": "flake-compat_2",
"flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixpkgs"
@@ -488,11 +623,13 @@
"claude-code": "claude-code",
"home-manager": "home-manager",
"lanzaboote": "lanzaboote",
"nix-cachyos-kernel": "nix-cachyos-kernel",
"nix-flatpak": "nix-flatpak",
"nix-skills": "nix-skills",
"nix-sweep": "nix-sweep",
"nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs",
"nixpkgs": "nixpkgs_2",
"nixpkgs-2605": "nixpkgs-2605",
"nixpkgs-linuxeol": "nixpkgs-linuxeol",
"ntfsplus": "ntfsplus",
"peerix": "peerix",
+2
View File
@@ -3,6 +3,7 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-2605.url = "github:NixOS/nixpkgs/nixos-26.05";
nixpkgs-linuxeol.url = "github:NixOS/nixpkgs/162f04bf3dd222187388bc990a8678170d594419";
nixos-hardware = {
url = "github:NixOS/nixos-hardware/master";
@@ -46,6 +47,7 @@
url = "github:sudosubin/nix-skills";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-cachyos-kernel.url = "github:xddxdd/nix-cachyos-kernel";
bun2nix = {
url = "github:nix-community/bun2nix";
inputs.nixpkgs.follows = "nixpkgs";
+13 -12
View File
@@ -34,13 +34,6 @@
programs.vscodium = {
enable = true;
package = assert pkgs.vscodium.version == "1.116.02821"; (pkgs.vscodium.overrideAttrs rec {
version = "1.121.03429";
src = pkgs.fetchurl {
url = "https://github.com/VSCodium/vscodium/releases/download/${version}/VSCodium-linux-x64-${version}.tar.gz";
hash = "sha256-LJsGc11MH6zlcJNfSWjTWPn2Jp9dkjeBPQuCXH1woUM=";
};
});
profiles.default.extensions = with pkgs; [
vscode-extensions.mkhl.direnv
vscode-extensions.jnoortheen.nix-ide
@@ -94,15 +87,23 @@
dua
];
# Inject the opencode-claude-auth plugin into the user's opencode.json without
# overwriting it — replaces any stale store path for this plugin and adds if absent.
home.activation.opencodeClaudeAuth = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
# Inject opencode auth plugins into the user's opencode.json without
# overwriting it — replaces any stale store path for each plugin and adds if absent.
# NOTE: opencode-antigravity-auth authenticates against Google's Antigravity
# backend (where consumer AI Pro/Ultra quota moved after the June 18 2026
# Gemini CLI/Code Assist OAuth shutdown). Using it violates Google's ToS and
# may get the Google account banned — accepted risk, see the plugin README.
home.activation.opencodePlugins = lib.hm.dag.entryAfter [ "writeBoundary" ] ''
cfg="$HOME/.config/opencode/opencode.json"
mkdir -p "$(dirname "$cfg")"
[ -f "$cfg" ] || echo '{}' > "$cfg"
tmp=$(mktemp)
${pkgs.jq}/bin/jq --arg path "file://${pkgs.opencode-claude-auth}" '
.plugin = ((.plugin // []) | map(select(test("opencode-claude-auth") | not)) + [$path])
${pkgs.jq}/bin/jq \
--arg claude "file://${pkgs.opencode-claude-auth}" \
--arg antigravity "file://${pkgs.opencode-antigravity-auth}" '
.plugin = ((.plugin // [])
| map(select((test("opencode-claude-auth") or test("opencode-gemini-auth") or test("opencode-antigravity-auth")) | not))
+ [$claude, $antigravity])
' "$cfg" > "$tmp" && mv "$tmp" "$cfg"
'';
+8 -4
View File
@@ -1,4 +1,4 @@
{ lib, pkgs, nixpkgs-linuxeol, ... }:
{ config, lib, pkgs, nixpkgs-linuxeol, ... }:
rec {
# Identity
@@ -23,8 +23,8 @@ rec {
# Kernel
# boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usb_storage" "sd_mod" "rtsx_pci_sdmmc" ];
boot.kernelPackages = pkgs.linuxKernel.packages.linux_7_0;
boot.zfs.package = pkgs.zfs_2_4;
boot.kernelPackages = pkgs.cachyosKernels.linuxPackages-cachyos-latest;
boot.zfs.package = config.boot.kernelPackages.zfs_cachyos;
# Swap
swapDevices = [
@@ -71,7 +71,11 @@ rec {
amdCpu = true;
noMitigations = false;
enablePulseaudio = true;
audioRt.enable = true;
audioRt = {
enable = true;
cpuPartitioning = false;
performanceGovernor = false;
};
sshd = true;
users.user = true;
# users.drugi = true;
+14 -2
View File
@@ -1,6 +1,7 @@
{
self,
nixpkgs,
nixpkgs-2605,
home-manager,
nix-flatpak,
plasma-manager,
@@ -13,6 +14,7 @@
nix-skills,
nixpkgs-linuxeol,
bun2nix,
nix-cachyos-kernel,
...
}:
hardwareConfig: hostConfig:
@@ -29,13 +31,23 @@ nixpkgs.lib.nixosSystem {
modules = [
{
nixpkgs.overlays = [
(final: prev: {
librewolf = nixpkgs-2605.legacyPackages.${prev.system}.librewolf;
})
claude-code.overlays.default
acer-wmi-ext.overlays.default
nix-skills.overlays.default
nix-cachyos-kernel.overlays.pinned
] ++ (import ../overlays/pkgs.nix { inherit bun2nix; });
nix.settings = {
substituters = [ "https://claude-code.cachix.org" ];
trusted-public-keys = [ "claude-code.cachix.org-1:YeXf2aNu7UTX8Vwrze0za1WEDS+4DuI2kVeWEE4fsRk=" ];
substituters = [
"https://claude-code.cachix.org"
"https://attic.xuyh0120.win/lantian"
];
trusted-public-keys = [
"claude-code.cachix.org-1:YeXf2aNu7UTX8Vwrze0za1WEDS+4DuI2kVeWEE4fsRk="
"lantian:EeAUQ+W+6r7EtwnmYjeVwx5kOGEBpjlBfPlzGlTNvHc="
];
};
}
lanzaboote.nixosModules.lanzaboote
+7 -7
View File
@@ -139,10 +139,10 @@ in
{ domain = "@audio"; type = "-"; item = "memlock"; value = "unlimited"; }
{ domain = "@audio"; type = "-"; item = "nice"; value = "-20"; }
];
systemd.user.extraConfig = ''
DefaultLimitRTPRIO=95
DefaultLimitMEMLOCK=infinity
'';
systemd.user.settings.Manager = {
DefaultLimitRTPRIO = 95;
DefaultLimitMEMLOCK = "infinity";
};
})
# --- CPU partitioning (cgroup-based) ------------------------------------
@@ -159,9 +159,9 @@ in
# so cores get clamped at minimum frequency.
# - No rcu_nocbs= : microsecond-scale jitter is irrelevant at 21ms quantum.
(lib.mkIf (cfg.enable && cfg.cpuPartitioning) {
systemd.user.extraConfig = ''
CPUAffinity=${cfg.nonAudioCpus}
'';
systemd.user.settings.Manager = {
CPUAffinity = cfg.nonAudioCpus;
};
systemd.settings.Manager.CPUAffinity = cfg.nonAudioCpus;
# Delegate the cpuset controller to user managers so user-level slices
+1 -1
View File
@@ -4,8 +4,8 @@
# Allow unfree packages
nixpkgs.config.allowUnfree = true;
# Ventoy has some blobs making it insecure
nixpkgs.config.permittedInsecurePackages = [
# Ventoy has some blobs making it insecure
"ventoy-qt5-1.1.12"
];
}
+1
View File
@@ -5,6 +5,7 @@
(final: prev: {
oh-my-pi = final.callPackage ../pkgs/oh-my-pi { inherit (final) bun2nix; };
opencode-claude-auth = prev.callPackage ../pkgs/opencode-claude-auth { };
opencode-antigravity-auth = final.callPackage ../pkgs/opencode-antigravity-auth { inherit (final) bun2nix; };
# Build failure 08.05.2026
# https://github.com/NixOS/nixpkgs/issues/513245#issuecomment-4320293674
openldap = prev.openldap.overrideAttrs {
@@ -0,0 +1,96 @@
{ stdenv, fetchurl, runCommand, bun, bun2nix }:
# opencode-antigravity-auth ships only `dist/` in its npm tarball and relies on
# runtime `dependencies` (@opencode-ai/plugin, @openauthjs/openauth, zod, ...).
# opencode loads it via a file:// path and does NOT install those deps, so the
# tarball-only approach fails at load time with "Cannot find module
# '@opencode-ai/plugin'". We therefore vendor node_modules with bun2nix.
#
# bun.lock and bun.nix are generated on the fly rather than committed.
#
# The tarball ships no lockfile, so we synthesize one with `bun install
# --lockfile-only`. Resolving npm version ranges (e.g. "^4.1.4") into exact
# versions requires registry access, and Nix only permits network inside a
# fixed-output derivation — hence `lockfileHash` below. This is the single
# unavoidable hash for the dep graph: it pins the resolved lockfile, which in
# turn (via bun2nix -> fetchBunDeps) pins every transitive dependency, each
# fetched as its own hash-checked FOD. bun.nix itself stays uncommitted and
# is derived deterministically from the pinned lockfile.
#
# Bump `version`, `hash`, and `lockfileHash` together. To refresh lockfileHash,
# set it to lib.fakeHash, build, and copy the "got:" value from the error.
let
version = "1.6.0";
src = fetchurl {
url = "https://registry.npmjs.org/opencode-antigravity-auth/-/opencode-antigravity-auth-${version}.tgz";
hash = "sha256-bLoDjJHuHczxKbslyZSm4zKg5FhdRLdUteKXFmqVlHQ=";
};
# Fixed-output derivation: network-enabled, produces only the resolved
# bun.lock. Determinism is enforced by lockfileHash.
bunLock = stdenv.mkDerivation {
name = "opencode-antigravity-auth-bun.lock";
inherit src;
sourceRoot = "package";
nativeBuildInputs = [ bun ];
buildPhase = ''
export HOME="$TMPDIR"
bun install --lockfile-only --no-progress
'';
installPhase = "cp bun.lock $out";
outputHashMode = "flat";
outputHashAlgo = "sha256";
outputHash = "sha256-H+m181VozFyEEQVrOZTienj15Bgn1UXTG/G/B9gy1UE=";
};
# Derive a source tree containing the resolved bun.lock and a bun.nix
# generated from it. Fully offline — no network needed here.
srcWithBunNix = runCommand "opencode-antigravity-auth-src" {
nativeBuildInputs = [ bun2nix ];
} ''
mkdir -p $out
# The npm tarball unpacks to a top-level `package/` directory.
tar xzf ${src} --strip-components=1 -C $out
chmod -R u+w $out
cp ${bunLock} $out/bun.lock
bun2nix --lock-file $out/bun.lock --output-file $out/bun.nix
'';
in
stdenv.mkDerivation {
pname = "opencode-antigravity-auth";
inherit version;
src = srcWithBunNix;
nativeBuildInputs = [ bun2nix.hook ];
# The bun cache (symlink farm) built from the generated bun.nix. The hook
# copies this into a writable BUN_INSTALL_CACHE_DIR and runs `bun install
# --offline` against it to materialize node_modules with no network.
bunDeps = bun2nix.fetchBunDeps {
bunNix = "${srcWithBunNix}/bun.nix";
};
# This is a plugin (a library directory), not an app: skip bun build/check.
dontUseBunBuild = true;
dontUseBunCheck = true;
dontRunLifecycleScripts = true;
installPhase = ''
runHook preInstall
mkdir -p $out
cp -r dist package.json node_modules $out/
[ -f README.md ] && cp README.md $out/ || true
[ -f LICENSE ] && cp LICENSE $out/ || true
runHook postInstall
'';
dontFixup = true;
}