Compare commits

..
44 Commits
Author SHA1 Message Date
Lumpiasty bbc498b857 update nixos 2026-09-11 01:23:10 +02:00
Lumpiasty 6ed62f94db gate homebrew improt by darwin check to fix building on linux 2026-09-11 01:22:57 +02:00
Lumpiasty 93df208274 Move macbook config under hosts 2026-09-06 01:42:18 +02:00
Lumpiasty 9bccabf712 install steam using brew on macos 2026-09-06 01:40:40 +02:00
Lumpiasty 129b9ae365 Install steam from brew on macos 2026-09-06 01:40:04 +02:00
Lumpiasty 7ed37b3b75 update nixos 2026-09-06 00:53:48 +02:00
Lumpiasty ba0c0d55ce Patch ntfsplus kernel module to support nowindows_names 2026-09-06 00:16:05 +02:00
Lumpiasty cbf9cc29ca remove reference to non-existant config.lumpiastyHome.linux 2026-09-05 00:33:39 +02:00
Lumpiasty f9d95837f5 fix applications in spotlight 2026-09-03 22:14:17 +02:00
Lumpiasty cddf1860d2 fix ssh controlpath on macos 2026-09-03 21:41:39 +02:00
Lumpiasty 8298f90315 resolve evaluation issues on nix-darwin 2026-09-03 21:41:39 +02:00
Lumpiasty 930c7b6018 Separate out linux specific home-manager stuff 2026-09-03 21:41:39 +02:00
Lumpiasty 99df214e10 mark macbook as pc 2026-09-03 21:41:39 +02:00
Lumpiasty d90315fe68 remove redundant easyeffects package 2026-09-03 21:41:39 +02:00
Lumpiasty 936ef1a7e0 remove librewolf overlay 2026-09-03 21:27:48 +02:00
Lumpiasty dcb32fe35d remove conflicting username and add home location 2026-08-31 01:15:16 +02:00
Lumpiasty 7e2a3d894d import home config alongside home-manager modules 2026-08-31 01:09:36 +02:00
Lumpiasty 461323c58f comment out flatpak options in home-manager 2026-08-31 00:59:12 +02:00
Lumpiasty 814daf2bfe guard import of plasma-manager options by enablePlasma 2026-08-31 00:56:30 +02:00
Lumpiasty bfecd4fadf Enable home manager on darwin 2026-08-31 00:50:44 +02:00
Lumpiasty 4e8aea6a24 Refactor options.nix as separate file 2026-08-31 00:43:07 +02:00
Lumpiasty a4d8971a77 first building revision of nix-darwin 2026-08-28 02:01:57 +02:00
Lumpiasty c97f728a01 parametrize ventoy-qt5 version in permittedInsecurePackages 2026-08-25 00:01:31 +02:00
Lumpiasty cc39b11599 update nixos 2026-08-24 23:53:10 +02:00
Lumpiasty bfa8f5c118 update nixos 2026-08-24 23:49:59 +02:00
Lumpiasty fc7a88814a nixos update 2026-08-09 23:19:49 +02:00
Lumpiasty d07be06293 add user to cdrom group 2026-07-25 19:38:49 +02:00
Lumpiasty dd446c742e Remove ntfsplus module 2026-07-25 19:35:02 +02:00
Lumpiasty be49c9858d remove python-lsp-server 2026-07-25 19:24:46 +02:00
Lumpiasty 26370a3d19 remove patool workaround 2026-07-25 18:45:57 +02:00
Lumpiasty 0e8cd39223 update networkmanager to 1.58.0 2026-07-25 18:44:11 +02:00
Lumpiasty 7b02a1d7f6 remove kde gear 2026-07-25 18:38:55 +02:00
Lumpiasty bc72ae3d99 remove oh-my-pi 2026-07-25 18:34:46 +02:00
Lumpiasty bb6388a338 update upstream renamed package 2026-07-25 18:30:23 +02:00
Lumpiasty ab184e2005 update nixos 2026-07-25 18:16:31 +02:00
Lumpiasty 42f554b371 exclude kdev-python due to build failure 2026-07-20 01:56:22 +02:00
Lumpiasty 1a75b67cc8 exclude calligra due to build failure 2026-07-20 01:52:49 +02:00
Lumpiasty b7fa5d89c5 remove workaround for fixed openldap issue 2026-07-20 01:44:18 +02:00
Lumpiasty 3dbd5ca53b work around build failure of python.patool 2026-07-20 01:43:31 +02:00
Lumpiasty e572b6af0d disable optimised easyeffects binaries on acer 2026-07-20 01:02:04 +02:00
Lumpiasty ca8b285c17 comment out caveman 2026-07-20 00:31:32 +02:00
Lumpiasty 504ff35644 update nixos 2026-07-20 00:25:46 +02:00
Lumpiasty 1c59901eb1 update NetworkManager to 1.58-rc1 2026-07-05 16:24:39 +02:00
Lumpiasty b49bbadd4f use native networkmanager option for enabling clat 2026-07-05 16:14:05 +02:00
42 changed files with 586 additions and 1155 deletions
Generated
+94 -158
View File
@@ -31,11 +31,11 @@
"treefmt-nix": "treefmt-nix" "treefmt-nix": "treefmt-nix"
}, },
"locked": { "locked": {
"lastModified": 1782772816, "lastModified": 1784665499,
"narHash": "sha256-s9BuFv0mRuZx9C1MF8qPHRdcAK14ONi0A5m6E2wqOoM=", "narHash": "sha256-9BMxlTxCCDAeoNLtb1a/st7udtTIJep+wpUzquA29VU=",
"owner": "nix-community", "owner": "nix-community",
"repo": "bun2nix", "repo": "bun2nix",
"rev": "5a39d717029e94163ac223aee8d5c9946cafed1c", "rev": "0f2a1f0b6f42cebe3b149bf62d38754c5e0e9729",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -44,38 +44,6 @@
"type": "github" "type": "github"
} }
}, },
"cachyos-kernel": {
"flake": false,
"locked": {
"lastModified": 1783173044,
"narHash": "sha256-IzB6XWH8zyBhR3zS2eCKwtVOLipOpVSwN8Lnpgn+5k0=",
"owner": "CachyOS",
"repo": "linux-cachyos",
"rev": "d96a067ff30ed47ff1743d60a569b4badd2d7670",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "linux-cachyos",
"type": "github"
}
},
"cachyos-kernel-patches": {
"flake": false,
"locked": {
"lastModified": 1782814529,
"narHash": "sha256-YGYe7cy8vUFguQzdCt6FP1B/viF53cJdFZhNJ8Rpp5Y=",
"owner": "CachyOS",
"repo": "kernel-patches",
"rev": "f98908d8b5cacc4c24a6039ffd9f41f6a0de4ba2",
"type": "github"
},
"original": {
"owner": "CachyOS",
"repo": "kernel-patches",
"type": "github"
}
},
"cf": { "cf": {
"locked": { "locked": {
"lastModified": 1756852014, "lastModified": 1756852014,
@@ -93,17 +61,17 @@
}, },
"claude-code": { "claude-code": {
"inputs": { "inputs": {
"flake-utils": "flake-utils",
"nixpkgs": [ "nixpkgs": [
"nixpkgs" "nixpkgs"
] ],
"systems": "systems_2"
}, },
"locked": { "locked": {
"lastModified": 1783124463, "lastModified": 1789074092,
"narHash": "sha256-rIawyN3+D9uqGmoYpTLZ2D6PYEp8xPykto8Uu+ER830=", "narHash": "sha256-QCXTUbd4FuwOHO7LgJws78YTRcco4xgR8RoYgKLvd9w=",
"owner": "sadjow", "owner": "sadjow",
"repo": "claude-code-nix", "repo": "claude-code-nix",
"rev": "9b05ec91a00ee8edea17b9279d55a5c1f084d754", "rev": "1f88b393ac054378c393f914dc83d08a6ef5daeb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -198,24 +166,6 @@
"nixpkgs" "nixpkgs"
] ]
}, },
"locked": {
"lastModified": 1777988971,
"narHash": "sha256-qIoWPDs+0/8JecyYgE3gpKQxW/4bLW/gp45vow9ioCQ=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "0678d8986be1661af6bb555f3489f2fdfc31f6ff",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-parts_2": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": { "locked": {
"lastModified": 1782949081, "lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=", "narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
@@ -230,25 +180,25 @@
"type": "github" "type": "github"
} }
}, },
"flake-utils": { "flake-parts_2": {
"inputs": { "inputs": {
"systems": "systems_2" "nixpkgs-lib": "nixpkgs-lib"
}, },
"locked": { "locked": {
"lastModified": 1731533236, "lastModified": 1788450739,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "flake-parts",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "flake-parts",
"type": "github" "type": "github"
} }
}, },
"flake-utils_2": { "flake-utils": {
"locked": { "locked": {
"lastModified": 1634851050, "lastModified": 1634851050,
"narHash": "sha256-N83GlSGPJJdcqhUxSCS/WwW5pksYf3VP1M13cDRTSVA=", "narHash": "sha256-N83GlSGPJJdcqhUxSCS/WwW5pksYf3VP1M13cDRTSVA=",
@@ -292,11 +242,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783134515, "lastModified": 1789071706,
"narHash": "sha256-qMoZazubXlXUD9k/syJ/aiWC4X4g73mwVmZ7Z4+rdpM=", "narHash": "sha256-S+oyh2YSP9V5bSjWbbK0N7GxdxxMwgBfUOtUdVcAWc4=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "b885baad531fa3d3beae2ba9a0712d22974d8016", "rev": "150f9ce4ddd41544ea42eb9d6043a75bd615fa24",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -306,6 +256,26 @@
"type": "github" "type": "github"
} }
}, },
"homebrew": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1785271058,
"narHash": "sha256-xVisL04Gt6LsGa1cGCLHhTED7iEykgl7krPyzAm2ZQg=",
"owner": "koalalorenzo",
"repo": "home-manager-brew",
"rev": "795f9aed8ddce24b3cae3b75598e6861e7d72d10",
"type": "github"
},
"original": {
"owner": "koalalorenzo",
"repo": "home-manager-brew",
"type": "github"
}
},
"lanzaboote": { "lanzaboote": {
"inputs": { "inputs": {
"crane": "crane", "crane": "crane",
@@ -330,36 +300,18 @@
"type": "github" "type": "github"
} }
}, },
"linux-ntfs": {
"flake": false,
"locked": {
"lastModified": 1782084613,
"narHash": "sha256-Z2tjz2/OFd0LBAxDbwAMnqre3uCsJxQ0oatoh4PU+Fk=",
"owner": "namjaejeon",
"repo": "linux-ntfs",
"rev": "640b7dde5def187d41042ec29a66fcbc46cdcc3a",
"type": "github"
},
"original": {
"owner": "namjaejeon",
"repo": "linux-ntfs",
"type": "github"
}
},
"nix-cachyos-kernel": { "nix-cachyos-kernel": {
"inputs": { "inputs": {
"cachyos-kernel": "cachyos-kernel",
"cachyos-kernel-patches": "cachyos-kernel-patches",
"flake-compat": "flake-compat_2", "flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_2", "flake-parts": "flake-parts_2",
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
}, },
"locked": { "locked": {
"lastModified": 1783190258, "lastModified": 1789070668,
"narHash": "sha256-55yKik8EoFm4istFFri5OzXxwk3ik4erB4Tn2BoOlQc=", "narHash": "sha256-Zel41jsQnKlZQHBFndBoRCJ3WfJCXknV2jL0GJbLy9k=",
"owner": "xddxdd", "owner": "xddxdd",
"repo": "nix-cachyos-kernel", "repo": "nix-cachyos-kernel",
"rev": "02b8219a7dc6dd9db5660718382555ef25fce02c", "rev": "b8538a38adfd2a443aa0f8f3d506c29161f71f5f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -368,6 +320,27 @@
"type": "github" "type": "github"
} }
}, },
"nix-darwin": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1786845137,
"narHash": "sha256-oQFip+v0luP8NIxJzmiW4Wu8bILsbFWom5l0zonl8hQ=",
"owner": "nix-darwin",
"repo": "nix-darwin",
"rev": "4cff07de74b50e64bdd68cd4e722ab5b6b35ee48",
"type": "github"
},
"original": {
"owner": "nix-darwin",
"ref": "master",
"repo": "nix-darwin",
"type": "github"
}
},
"nix-flatpak": { "nix-flatpak": {
"locked": { "locked": {
"lastModified": 1767983141, "lastModified": 1767983141,
@@ -391,11 +364,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1783183418, "lastModified": 1789063032,
"narHash": "sha256-buWqgFRFRhcWcHrKh/4C4Sq75B9OkEWzWQ5WRMnT6LQ=", "narHash": "sha256-QHJcFCNEf7gqOzwClCIyAnU24Q2OUQS9WJTduZgnkxs=",
"owner": "sudosubin", "owner": "sudosubin",
"repo": "nix-skills", "repo": "nix-skills",
"rev": "49bae75a07cb80d0e602ab3b4edc1e7a74ad84b4", "rev": "f3305681ea01e147fc65fa16d55df81fab28c6f7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -434,11 +407,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1782562157, "lastModified": 1788942796,
"narHash": "sha256-a7+T6QSeowynwZ1ZJJbP8T8ntAytvrui8kFGJmIZt2c=", "narHash": "sha256-CLoJCCRi9sogsyGXYn8rOCWBLKAntfKUB9Rli/YXgEY=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "a9cf7546a938c737b079e738de73934a13de9784", "rev": "83bbc895120516d6e86885a188c04beced6535d9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -450,11 +423,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1783176197, "lastModified": 1789034407,
"narHash": "sha256-pCpbAkZsk6IYSeYUPyDRdkF1y0wSn9fxKyQxhUxt5nQ=", "narHash": "sha256-7X4GZ0KK5qHF9lppR9IlfXShYGcxxw1Kcjj8m5+19H0=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "c148c8dc4d8befea368b3ce7b5fb5cf71dfba198", "rev": "3824e02a19d7dccf95c30aa1cab8c857323d2201",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -464,29 +437,13 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs-2605": {
"locked": {
"lastModified": 1783148766,
"narHash": "sha256-uslt2pqShTIXDdAHRHv2QkYLsVdY8Oqwz0EA48/RSM8=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a50de1b7d8a586adc18d2395c19de7d6058e6030",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-lib": { "nixpkgs-lib": {
"locked": { "locked": {
"lastModified": 1782614948, "lastModified": 1788057806,
"narHash": "sha256-ePjCwr1sNm9NYUqywL7QfK3JnlS015msC+eBu2zKlp8=", "narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixpkgs.lib", "repo": "nixpkgs.lib",
"rev": "db3f255737b94216eb71cce308e2912cf6bc2d7c", "rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -513,11 +470,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1782959384, "lastModified": 1789006805,
"narHash": "sha256-xnJJk+ct+D2+wdRxj1wk36w5zV9RVESwRqcklPdt3fM=", "narHash": "sha256-xB8mKMOx1IA9vTDNLmJZ6n4wCMq/cuWBBOzGCRnqxrU=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "65179426c83bb3f6bc14898b42ea1c6f01d374b0", "rev": "8ce4ef6cb6f871616146b9fe26d2a5ae594e94fe",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -542,31 +499,10 @@
"type": "indirect" "type": "indirect"
} }
}, },
"ntfsplus": {
"inputs": {
"linux-ntfs": "linux-ntfs",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1774317576,
"narHash": "sha256-HSDFaDLvfS/NqJlXbHh9135DEpqH6JrNuWqbu3YPcTg=",
"owner": "cmspam",
"repo": "ntfsplus-flake",
"rev": "e22d1bcbac31b4e6484d32c503396e8184650215",
"type": "github"
},
"original": {
"owner": "cmspam",
"repo": "ntfsplus-flake",
"type": "github"
}
},
"peerix": { "peerix": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_3", "flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_2", "flake-utils": "flake-utils",
"nixpkgs": "nixpkgs_3" "nixpkgs": "nixpkgs_3"
}, },
"locked": { "locked": {
@@ -593,11 +529,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1775856943, "lastModified": 1785762349,
"narHash": "sha256-b7Mp7P+q2Md5AGt4rjHfMcBykzMumFTen10ST++AuTU=", "narHash": "sha256-jZhZkzAwc7f3exzcTDJWP2WCAchCv0iNC3UF/QsahdQ=",
"owner": "nix-community", "owner": "nix-community",
"repo": "plasma-manager", "repo": "plasma-manager",
"rev": "a524a6160e6df89f7673ba293cf7d78b559eb1a5", "rev": "a19a2a029fa180911bd89c554dca1616e10f4c1d",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -635,16 +571,16 @@
"bun2nix": "bun2nix", "bun2nix": "bun2nix",
"claude-code": "claude-code", "claude-code": "claude-code",
"home-manager": "home-manager", "home-manager": "home-manager",
"homebrew": "homebrew",
"lanzaboote": "lanzaboote", "lanzaboote": "lanzaboote",
"nix-cachyos-kernel": "nix-cachyos-kernel", "nix-cachyos-kernel": "nix-cachyos-kernel",
"nix-darwin": "nix-darwin",
"nix-flatpak": "nix-flatpak", "nix-flatpak": "nix-flatpak",
"nix-skills": "nix-skills", "nix-skills": "nix-skills",
"nix-sweep": "nix-sweep", "nix-sweep": "nix-sweep",
"nixos-hardware": "nixos-hardware", "nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs_2", "nixpkgs": "nixpkgs_2",
"nixpkgs-2605": "nixpkgs-2605",
"nixpkgs-linuxeol": "nixpkgs-linuxeol", "nixpkgs-linuxeol": "nixpkgs-linuxeol",
"ntfsplus": "ntfsplus",
"peerix": "peerix", "peerix": "peerix",
"plasma-manager": "plasma-manager" "plasma-manager": "plasma-manager"
} }
@@ -672,16 +608,16 @@
}, },
"systems": { "systems": {
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1776166891,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", "narHash": "sha256-bI8yrEGjrohR5hkQox7UrxDH7XqrYMwI8SL/LrJ1+S8=",
"owner": "nix-systems", "owner": "nix-systems",
"repo": "default", "repo": "triplet",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", "rev": "6de7bc09397911ce03636afbcf6118745ab2cda0",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-systems", "owner": "nix-systems",
"repo": "default", "repo": "triplet",
"type": "github" "type": "github"
} }
}, },
@@ -708,11 +644,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1775636079, "lastModified": 1784369104,
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", "narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=",
"owner": "numtide", "owner": "numtide",
"repo": "treefmt-nix", "repo": "treefmt-nix",
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", "rev": "df3c0640565d04a0261253cdd89fce78ec50168a",
"type": "github" "type": "github"
}, },
"original": { "original": {
+32 -6
View File
@@ -14,7 +14,6 @@
inputs = { inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-2605.url = "github:NixOS/nixpkgs/nixos-26.05";
nixpkgs-linuxeol.url = "github:NixOS/nixpkgs/162f04bf3dd222187388bc990a8678170d594419"; nixpkgs-linuxeol.url = "github:NixOS/nixpkgs/162f04bf3dd222187388bc990a8678170d594419";
nixos-hardware = { nixos-hardware = {
url = "github:NixOS/nixos-hardware/master"; url = "github:NixOS/nixos-hardware/master";
@@ -49,10 +48,6 @@
url = "github:Lumpiasty/acer-wmi-ext/main"; url = "github:Lumpiasty/acer-wmi-ext/main";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
ntfsplus = {
url = "github:cmspam/ntfsplus-flake";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-skills = { nix-skills = {
url = "github:sudosubin/nix-skills"; url = "github:sudosubin/nix-skills";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
@@ -62,9 +57,17 @@
url = "github:nix-community/bun2nix"; url = "github:nix-community/bun2nix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
nix-darwin = {
url = "github:nix-darwin/nix-darwin/master";
inputs.nixpkgs.follows = "nixpkgs";
};
homebrew = {
url = "github:koalalorenzo/home-manager-brew";
inputs.nixpkgs.follows = "nixpkgs";
};
}; };
outputs = { self, nixos-hardware, ... }@inputs: outputs = { self, nixos-hardware, nix-darwin, ... }@inputs:
{ {
nixosConfigurations = nixosConfigurations =
let let
@@ -75,5 +78,28 @@
acer = mkNixosSystem {} hosts/acer.nix; acer = mkNixosSystem {} hosts/acer.nix;
gaming-pc = mkNixosSystem {} hosts/gaming-pc.nix; gaming-pc = mkNixosSystem {} hosts/gaming-pc.nix;
}; };
darwinConfigurations."MacBook-Pro-Macbook" = nix-darwin.lib.darwinSystem {
modules = [
((import ./hosts/macbook.nix) self)
inputs.home-manager.darwinModules.home-manager
{
home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true;
home-manager.verbose = true;
home-manager.users.macbookpro = { ... }: {
imports = [
./home-modules
./users/user/home.nix
inputs.homebrew.homeManagerModules.default
];
lumpiastyHome.macos = true;
};
nixpkgs.overlays = [
inputs.claude-code.overlays.default
inputs.nix-skills.overlays.default
] ++ (import ./overlays/pkgs.nix { bun2nix = inputs.bun2nix; });
}
];
};
}; };
} }
+10 -2
View File
@@ -1,12 +1,20 @@
{ flake, pkgs, lib, ... }: { flake, pkgs, lib, osConfig ? null, ... }:
{ {
options.lumpiastyHome.macos = lib.mkEnableOption "Macos specific things";
imports = [ imports = [
./gpg.nix ./gpg.nix
./pc.nix ./pc.nix
./dev.nix ./dev.nix
./gaming.nix ./gaming.nix
./plasma.nix
./fhsBash.nix ./fhsBash.nix
./linux.nix
] ++ lib.optionals (osConfig ? system.defaults) [
# Can't use config.lumpiastyHome.macos here — imports are evaluated before config,
# causing infinite recursion. osConfig ? system.defaults detects nix-darwin.
./macos.nix
] ++ lib.optionals (osConfig.lumpiasty.enablePlasma) [
./plasma.nix
]; ];
} }
+2 -8
View File
@@ -62,8 +62,6 @@
}; };
home.packages = with pkgs; [ home.packages = with pkgs; [
python312
python312Packages.python-lsp-server
nil nil
kubectl kubectl
kubectx kubectx
@@ -75,18 +73,14 @@
docker docker
docker-buildx docker-buildx
proton-vpn proton-vpn
wl-clipboard
devenv devenv
dig dig
whois whois
mtr mtr
traceroute
nodejs_24 nodejs_24
codex codex
claude-code claude-code
oh-my-pi
winbox4 winbox4
amdgpu_top
dua dua
]; ];
@@ -123,7 +117,7 @@
User = "root"; User = "root";
ControlMaster = "auto"; ControlMaster = "auto";
ControlPersist = "3600"; ControlPersist = "3600";
ControlPath = "/run/user/%i/ssh-socket-%r@%h:%p"; ControlPath = lib.mkIf config.lumpiastyHome.linux "/run/user/%i/ssh-socket-%r@%h:%p";
ServerAliveInterval = 20; ServerAliveInterval = 20;
}; };
@@ -165,7 +159,7 @@
'' ''
); );
skills = with pkgs.skills; { skills = with pkgs.skills; {
caveman = majiayu000."claude-skill-registry".caveman + "/"; # caveman = majiayu000."claude-skill-registry".caveman + "/";
}; };
}; };
}; };
+3 -2
View File
@@ -7,7 +7,7 @@
services.gpg-agent = { services.gpg-agent = {
enable = true; enable = true;
enableSshSupport = true; enableSshSupport = true;
pinentry.package = pkgs.pinentry-qt; pinentry.package = lib.mkIf config.lumpiastyHome.linux pkgs.pinentry-qt;
extraConfig = '' extraConfig = ''
listen-backlog 256 listen-backlog 256
''; '';
@@ -15,7 +15,8 @@
programs.gpg.enable = true; programs.gpg.enable = true;
programs.git.signing = { programs.git.signing =
lib.mkIf config.lumpiastyHome.linux { # TODO: on macos too
format = "openpgp"; format = "openpgp";
key = "EA287B39E5F69945"; key = "EA287B39E5F69945";
signByDefault = true; signByDefault = true;
+29
View File
@@ -0,0 +1,29 @@
{ config, lib, pkgs, osConfig, ... }:
{
options.lumpiastyHome.linux = lib.mkEnableOption "Linux specific things";
config = lib.mkIf config.lumpiastyHome.linux {
services.easyeffects.enable = true;
systemd.user.services.easyeffects.Service = lib.mkIf osConfig.lumpiasty.audioRt.cpuPartitioning {
# Move easyeffects into audio.slice (defined in modules/desktop/audio-rt.nix)
# which has AllowedCPUs=<audioCpus> — pins all DSP work to the reserved cores.
Slice = "audio.slice";
};
programs.chromium.enable = true;
programs.chromium.package = pkgs.ungoogled-chromium;
home.packages = with pkgs; (lib.optionals config.lumpiastyHome.dev [
wl-clipboard
traceroute
amdgpu_top
] ++ lib.optionals config.lumpiastyHome.linux [
pass-wayland
libreoffice-qt-stable
vlc
gimp
ventoy-full-qt
teamspeak6-client
]);
};
}
+33
View File
@@ -0,0 +1,33 @@
{ config, lib, pkgs, osConfig, ... }:
let
brewPath = config.homebrew.brewPath;
in {
config = lib.mkIf config.lumpiastyHome.macos {
targets.darwin.copyApps.enable = true;
targets.darwin.linkApps.enable = false;
homebrew = {
enable = true;
brewInstall = true;
update = true;
upgrade = true;
cleanup = true;
casks = [
"steam"
];
};
home.activation.homebrewInstall = lib.mkForce (
lib.hm.dag.entryAfter ["installPackages" "linkGeneration" "createGpgHomedir"] (
if config.homebrew.brewInstall then ''
if [ ! -f "${brewPath}" ]; then
echo "Homebrew not found (${brewPath}), installing..."
export PATH="${pkgs.curl}/bin:${pkgs.bash}/bin:${pkgs.coreutils}/bin:${pkgs.gnugrep}/bin:${pkgs.gnused}/bin:$PATH"
${pkgs.bash}/bin/bash -c "$(${pkgs.curl}/bin/curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
fi
'' else ""
)
);
};
}
+7 -23
View File
@@ -8,38 +8,22 @@
vesktop vesktop
# Manual update, not yet in nixpkgs as for now # Manual update, not yet in nixpkgs as for now
spotify spotify
pass-wayland
teamspeak6-client
easyeffects
libreoffice-qt6-fresh
vlc
inkscape inkscape
qtpass qtpass
signal-desktop signal-desktop
transmission_4-qt6 transmission_4-qt
thunderbird thunderbird
pwgen pwgen
siyuan siyuan
gimp
ventoy-full-qt
]; ];
programs.librewolf.enable = true; programs.librewolf.enable = true;
services.easyeffects.enable = true;
systemd.user.services.easyeffects.Service = lib.mkIf osConfig.lumpiasty.audioRt.cpuPartitioning {
# Move easyeffects into audio.slice (defined in modules/desktop/audio-rt.nix)
# which has AllowedCPUs=<audioCpus> — pins all DSP work to the reserved cores.
Slice = "audio.slice";
};
programs.chromium.enable = true; # services.flatpak.remotes = [{
programs.chromium.package = pkgs.ungoogled-chromium; # name = "flathub"; location = "https://dl.flathub.org/repo/flathub.flatpakrepo";
# }];
services.flatpak.remotes = [{ # services.flatpak.packages = [
name = "flathub"; location = "https://dl.flathub.org/repo/flathub.flatpakrepo"; # # "org.onlyoffice.desktopeditors"
}]; # ];
services.flatpak.packages = [
# "org.onlyoffice.desktopeditors"
];
# Vesktop settings # Vesktop settings
# Nope, TODO # Nope, TODO
+1
View File
@@ -75,6 +75,7 @@ rec {
enable = true; enable = true;
cpuPartitioning = false; cpuPartitioning = false;
performanceGovernor = false; performanceGovernor = false;
optimisedBinaries = false;
}; };
sshd = true; sshd = true;
users.user = true; users.user = true;
-2
View File
@@ -102,8 +102,6 @@
}; };
}; };
# Use ntfs-plus instead driver
services.ntfsplus.enable = true;
# Force disable ntfs-3g driver # Force disable ntfs-3g driver
boot.supportedFilesystems.ntfs = lib.mkForce false; boot.supportedFilesystems.ntfs = lib.mkForce false;
+36
View File
@@ -0,0 +1,36 @@
self: { pkgs, ... }: {
imports = [ ../modules/options.nix ];
# List packages installed in system profile. To search by name, run:
# $ nix-env -qaP | grep wget
environment.systemPackages = with pkgs; [
vim
curl
git
];
# Necessary for using flakes on this system.
nix.settings.experimental-features = "nix-command flakes";
# Enable alternative shell support in nix-darwin.
# programs.fish.enable = true;
# Set Git commit hash for darwin-version.
system.configurationRevision = self.rev or self.dirtyRev or null;
# Used for backwards compatibility, please read the changelog before changing.
# $ darwin-rebuild changelog
system.stateVersion = 6;
# The platform the configuration will be used on.
nixpkgs.hostPlatform = "aarch64-darwin";
users.users.macbookpro = {
home = "/Users/macbookpro";
};
lumpiasty.pc = true;
# Allow unfree packages
nixpkgs.config.allowUnfree = true;
}
+1
View File
@@ -9,5 +9,6 @@ lib.mkIf condition (
../home-modules ../home-modules
home home
]; ];
lumpiastyHome.linux = true;
} }
) )
-6
View File
@@ -1,7 +1,6 @@
{ {
self, self,
nixpkgs, nixpkgs,
nixpkgs-2605,
home-manager, home-manager,
nix-flatpak, nix-flatpak,
plasma-manager, plasma-manager,
@@ -10,7 +9,6 @@
nix-sweep, nix-sweep,
peerix, peerix,
acer-wmi-ext, acer-wmi-ext,
ntfsplus,
nix-skills, nix-skills,
nixpkgs-linuxeol, nixpkgs-linuxeol,
bun2nix, bun2nix,
@@ -26,14 +24,10 @@ nixpkgs.lib.nixosSystem {
inherit plasma-manager; inherit plasma-manager;
inherit acer-wmi-ext; inherit acer-wmi-ext;
inherit nixpkgs-linuxeol; inherit nixpkgs-linuxeol;
inherit ntfsplus;
}; };
modules = [ modules = [
{ {
nixpkgs.overlays = [ nixpkgs.overlays = [
(final: prev: {
librewolf = nixpkgs-2605.legacyPackages.${prev.system}.librewolf;
})
claude-code.overlays.default claude-code.overlays.default
acer-wmi-ext.overlays.default acer-wmi-ext.overlays.default
nix-skills.overlays.default nix-skills.overlays.default
+3 -2
View File
@@ -2,13 +2,13 @@
{ {
imports = [ imports = [
./options.nix
hardware/intel-cpu.nix hardware/intel-cpu.nix
hardware/amd-cpu.nix hardware/amd-cpu.nix
hardware/no-mitigations.nix hardware/no-mitigations.nix
hardware/acer-undervolt.nix hardware/acer-undervolt.nix
system/ntfsplus.nix
system/roles.nix
system/nixpkgs.nix system/nixpkgs.nix
system/location.nix system/location.nix
system/shell.nix system/shell.nix
@@ -18,6 +18,7 @@
system/ipv6-mostly.nix system/ipv6-mostly.nix
system/nix.nix system/nix.nix
system/zfs.nix system/zfs.nix
system/ntfsplus.nix
desktop/plasma.nix desktop/plasma.nix
desktop/touchpad.nix desktop/touchpad.nix
+2 -66
View File
@@ -38,72 +38,7 @@ let
in in
{ { config = lib.mkMerge [
options.lumpiasty.audioRt = {
enable = lib.mkEnableOption "Audio RT scheduling and CPU isolation";
audioCpus = lib.mkOption {
type = lib.types.str;
default = "12-15";
description = "CPU list reserved for audio services (systemd cpuset syntax).";
};
nonAudioCpus = lib.mkOption {
type = lib.types.str;
default = "0-11";
description = "CPU list for everything else.";
};
# ------ Individual optimization toggles ------
cpuPartitioning = lib.mkOption {
type = lib.types.bool;
default = cfg.enable;
description = ''
Cgroup-based CPU partitioning via dedicated audio.slice and
restricted app/session/background slices.
'';
};
rtLimits = lib.mkOption {
type = lib.types.bool;
default = cfg.enable;
description = ''
Raise rlimits (RTPRIO=95, MEMLOCK=infinity) for the audio group
so PipeWire's module-rt can set SCHED_FIFO 88 directly instead
of going through RTKit's priority-10 ceiling.
'';
};
performanceGovernor = lib.mkOption {
type = lib.types.bool;
default = cfg.enable;
description = ''
Keep cpufreq governor `performance` on the audio cores so they
stay boosted regardless of measured utilization.
'';
};
ananicy = lib.mkOption {
type = lib.types.bool;
default = cfg.enable;
description = ''
Run ananicy-cpp with a rule that pins easyeffects to nice -12 so
its non-RT DSP threads get scheduler preference under load.
'';
};
optimisedBinaries = lib.mkOption {
type = lib.types.bool;
default = cfg.enable;
description = ''
Rebuild easyeffects and its DSP dependencies with -march=znver4 -O3
(and LTO for cmake builds, target-cpu for rust builds).
'';
};
};
config = lib.mkMerge [
# --- Optimised binary builds --------------------------------------------- # --- Optimised binary builds ---------------------------------------------
(lib.mkIf (cfg.enable && cfg.optimisedBinaries) { (lib.mkIf (cfg.enable && cfg.optimisedBinaries) {
@@ -223,6 +158,7 @@ in
services.ananicy = { services.ananicy = {
enable = true; enable = true;
package = pkgs.ananicy-cpp; package = pkgs.ananicy-cpp;
rulesProvider = pkgs.ananicy-cpp;
extraRules = [ extraRules = [
{ name = "easyeffects"; type = "Audio"; nice = -12; } { name = "easyeffects"; type = "Audio"; nice = -12; }
]; ];
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.enableGnome = lib.mkEnableOption "Enable Gnome desktop";
config = lib.mkIf config.lumpiasty.enableGnome { config = lib.mkIf config.lumpiasty.enableGnome {
# Enable the X11 windowing system. # Enable the X11 windowing system.
services.xserver.enable = true; services.xserver.enable = true;
+1 -30
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.enablePlasma = lib.mkEnableOption "Enable Plasma6 desktop";
config = lib.mkIf config.lumpiasty.enablePlasma { config = lib.mkIf config.lumpiasty.enablePlasma {
# Enable the X11 windowing system. # Enable the X11 windowing system.
services.xserver.enable = true; services.xserver.enable = true;
@@ -33,34 +31,7 @@
# Use wayland in electron apps # Use wayland in electron apps
environment.sessionVariables.NIXOS_OZONE_WL = "1"; environment.sessionVariables.NIXOS_OZONE_WL = "1";
environment.systemPackages = environment.systemPackages = [
(lib.pipe (builtins.attrValues pkgs.kdePackages.gear) [
(builtins.filter (pkg: !pkg.meta.broken))
# Exclude neochat and itinerary due to known vulnerabilities
(builtins.filter (pkg: pkg.pname != "neochat"))
(builtins.filter (pkg: pkg.pname != "itinerary"))
# Exclude angelfish due to build failure
(builtins.filter (pkg: pkg.pname != "angelfish"))
# Exclude step due to build failure
(builtins.filter (pkg: pkg.pname != "step"))
# Exclude plasma-vault due to build failure
(builtins.filter (pkg: pkg.pname != "plasma-vault"))
# Exclude kalzium due to build failure
(builtins.filter (pkg: pkg.pname != "kalzium"))
# Exclude audiocd-kio due to build failure
(builtins.filter (pkg: pkg.pname != "audiocd-kio"))
# Exclude audiotube due to build failure
(builtins.filter (pkg: pkg.pname != "audiotube"))
# Exclude plasma-mobile
(builtins.filter (pkg: pkg.pname != "plasma-mobile"))
]) ++ [
# Printing support in Plasma settings # Printing support in Plasma settings
pkgs.system-config-printer pkgs.system-config-printer
]; ];
-2
View File
@@ -2,8 +2,6 @@
{ {
options.lumpiasty.enablePulseaudio = lib.mkEnableOption "Enable Plasma6 desktop";
config = lib.mkIf config.lumpiasty.enablePulseaudio { config = lib.mkIf config.lumpiasty.enablePulseaudio {
# Enable sound with pipewire. Dont forget after 24.05 # Enable sound with pipewire. Dont forget after 24.05
services.pulseaudio.enable = false; services.pulseaudio.enable = false;
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.enableTailscale = lib.mkEnableOption "Enable Tailscale VPN";
config = lib.mkIf config.lumpiasty.enableTailscale { config = lib.mkIf config.lumpiasty.enableTailscale {
services.tailscale = { services.tailscale = {
enable = true; enable = true;
+3 -174
View File
@@ -1,177 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { ... }:
# Touch pad configuration interface # Touch pad configuration interface.
# Options are declared in ./options.nix; config is applied by home-modules/plasma.nix.
let
scrollMethods = {
twoFingers = "twoFingers";
touchPadEdges = "touchPadEdges";
};
rightClickMethods = {
bottomRight = "bottomRight";
twoFingers = "twoFingers";
};
accelerationProfiles = {
none = "none";
default = "default";
};
in
{ {
# Copy of https://github.com/nix-community/plasma-manager/blob/trunk/modules/input.nix#L69
options.lumpiasty.touchPad = {
enable = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable the touchpad.
'';
};
name = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "PNP0C50:00 0911:5288 Touchpad";
description = ''
The name of the touchpad.
This can be found by looking at the `Name` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
vendorId = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "0911";
description = ''
The vendor ID of the touchpad.
This can be found by looking at the `Vendor` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
productId = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "5288";
description = ''
The product ID of the touchpad.
This can be found by looking at the `Product` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
disableWhileTyping = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to disable the touchpad while typing.
'';
};
leftHanded = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = false;
description = ''
Whether to swap the left and right buttons.
'';
};
middleButtonEmulation = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = false;
description = ''
Whether to enable middle mouse click emulation by pressing the left and right buttons at the same time.
Activating this increases the click latency by 50ms.
'';
};
pointerSpeed = lib.mkOption {
type = with lib.types; nullOr (numbers.between (-1) 1);
default = null;
example = "0";
description = ''
How fast the pointer moves.
'';
};
accelerationProfile = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames accelerationProfiles));
default = null;
example = "none";
description = "Set the touchpad acceleration profile.";
apply = profile: if (profile == null) then null else accelerationProfiles."${profile}";
};
naturalScroll = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable natural scrolling for the touchpad.
'';
};
tapToClick = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable tap-to-click for the touchpad.
'';
};
tapAndDrag = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable tap-and-drag for the touchpad.
'';
};
tapDragLock = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable the tap-and-drag lock for the touchpad.
'';
};
scrollMethod = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames scrollMethods));
default = null;
example = "touchPadEdges";
description = ''
Configure how scrolling is performed on the touchpad.
'';
apply = method: if (method == null) then null else scrollMethods."${method}";
};
scrollSpeed = lib.mkOption {
type = with lib.types; nullOr (numbers.between 0.1 20);
default = null;
example = 0.1;
description = ''
Configure the scrolling speed of the touchpad. Lower is slower.
If unset, KDE Plasma will default to 0.3.
'';
};
rightClickMethod = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames rightClickMethods));
default = null;
example = "twoFingers";
description = ''
Configure how right-clicking is performed on the touchpad.
'';
apply = method: if (method == null) then null else rightClickMethods."${method}";
};
twoFingerTap = lib.mkOption {
type =
with lib.types;
nullOr (enum [
"rightClick"
"middleClick"
]);
default = null;
example = "twoFingers";
description = ''
Configure what a two-finger tap maps to on the touchpad.
'';
apply = v: if (v == null) then null else (v == "middleClick");
};
};
} }
-2
View File
@@ -18,8 +18,6 @@
# persist values across boot / resume. # persist values across boot / resume.
{ {
options.lumpiasty.acerUndervolt = lib.mkEnableOption "ryzenadj + ryzen_smu tooling for Acer 8845HS";
config = lib.mkIf config.lumpiasty.acerUndervolt { config = lib.mkIf config.lumpiasty.acerUndervolt {
boot.kernelModules = [ "ryzen_smu" ]; boot.kernelModules = [ "ryzen_smu" ];
boot.extraModulePackages = [ config.boot.kernelPackages.ryzen-smu ]; boot.extraModulePackages = [ config.boot.kernelPackages.ryzen-smu ];
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.amdCpu = lib.mkEnableOption "Enable amd CPU";
config = lib.mkIf config.lumpiasty.amdCpu { config = lib.mkIf config.lumpiasty.amdCpu {
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = true; hardware.cpu.amd.updateMicrocode = true;
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.intelCpu = lib.mkEnableOption "Enable intel CPU";
config = lib.mkIf config.lumpiasty.intelCpu { config = lib.mkIf config.lumpiasty.intelCpu {
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
# hardware.cpu.intel.updateMicrocode = true; # hardware.cpu.intel.updateMicrocode = true;
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.noMitigations = lib.mkEnableOption "Disable mitigations";
config = lib.mkIf config.lumpiasty.noMitigations { config = lib.mkIf config.lumpiasty.noMitigations {
boot.kernelParams = [ boot.kernelParams = [
"mitigations=off" "mitigations=off"
+258
View File
@@ -0,0 +1,258 @@
{ config, lib, ... }:
let
scrollMethods = {
twoFingers = "twoFingers";
touchPadEdges = "touchPadEdges";
};
rightClickMethods = {
bottomRight = "bottomRight";
twoFingers = "twoFingers";
};
accelerationProfiles = {
none = "none";
default = "default";
};
in
{
options.lumpiasty = {
pc = lib.mkEnableOption "Enable options specific to personal computers";
laptop = lib.mkEnableOption "Enable options specific to laptops";
intelCpu = lib.mkEnableOption "Enable intel CPU";
amdCpu = lib.mkEnableOption "Enable amd CPU";
noMitigations = lib.mkEnableOption "Disable mitigations";
acerUndervolt = lib.mkEnableOption "ryzenadj + ryzen_smu tooling for Acer 8845HS";
enablePlasma = lib.mkEnableOption "Enable Plasma6 desktop";
enableGnome = lib.mkEnableOption "Enable Gnome desktop";
enablePulseaudio = lib.mkEnableOption "Enable Pulseaudio/Pipewire";
enableTailscale = lib.mkEnableOption "Enable Tailscale VPN";
sshd = lib.mkEnableOption "Enable OpenSSH server";
gaming = lib.mkEnableOption "Enable options specific to gaming computers";
scx = lib.mkEnableOption "Enable sched-ext";
ipv6Mostly = lib.mkEnableOption "Enable IPv6-mostly (RFC 8925 + CLAT/464XLAT) support in NetworkManager";
users = {
user = lib.mkEnableOption "Create user \"user\"";
drugi = lib.mkEnableOption "Create user \"drugi\"";
};
touchPad = {
enable = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable the touchpad.
'';
};
name = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "PNP0C50:00 0911:5288 Touchpad";
description = ''
The name of the touchpad.
This can be found by looking at the `Name` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
vendorId = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "0911";
description = ''
The vendor ID of the touchpad.
This can be found by looking at the `Vendor` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
productId = lib.mkOption {
type = with lib.types; nullOr str;
default = null;
example = "5288";
description = ''
The product ID of the touchpad.
This can be found by looking at the `Product` attribute in the section in
the `/proc/bus/input/devices` path belonging to the touchpad.
'';
};
disableWhileTyping = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to disable the touchpad while typing.
'';
};
leftHanded = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = false;
description = ''
Whether to swap the left and right buttons.
'';
};
middleButtonEmulation = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = false;
description = ''
Whether to enable middle mouse click emulation by pressing the left and right buttons at the same time.
Activating this increases the click latency by 50ms.
'';
};
pointerSpeed = lib.mkOption {
type = with lib.types; nullOr (numbers.between (-1) 1);
default = null;
example = "0";
description = ''
How fast the pointer moves.
'';
};
accelerationProfile = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames accelerationProfiles));
default = null;
example = "none";
description = "Set the touchpad acceleration profile.";
apply = profile: if (profile == null) then null else accelerationProfiles."${profile}";
};
naturalScroll = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable natural scrolling for the touchpad.
'';
};
tapToClick = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable tap-to-click for the touchpad.
'';
};
tapAndDrag = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable tap-and-drag for the touchpad.
'';
};
tapDragLock = lib.mkOption {
type = with lib.types; nullOr bool;
default = null;
example = true;
description = ''
Whether to enable the tap-and-drag lock for the touchpad.
'';
};
scrollMethod = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames scrollMethods));
default = null;
example = "touchPadEdges";
description = ''
Configure how scrolling is performed on the touchpad.
'';
apply = method: if (method == null) then null else scrollMethods."${method}";
};
scrollSpeed = lib.mkOption {
type = with lib.types; nullOr (numbers.between 0.1 20);
default = null;
example = 0.1;
description = ''
Configure the scrolling speed of the touchpad. Lower is slower.
If unset, KDE Plasma will default to 0.3.
'';
};
rightClickMethod = lib.mkOption {
type = with lib.types; nullOr (enum (builtins.attrNames rightClickMethods));
default = null;
example = "twoFingers";
description = ''
Configure how right-clicking is performed on the touchpad.
'';
apply = method: if (method == null) then null else rightClickMethods."${method}";
};
twoFingerTap = lib.mkOption {
type =
with lib.types;
nullOr (enum [
"rightClick"
"middleClick"
]);
default = null;
example = "twoFingers";
description = ''
Configure what a two-finger tap maps to on the touchpad.
'';
apply = v: if (v == null) then null else (v == "middleClick");
};
};
audioRt = {
enable = lib.mkEnableOption "Audio RT scheduling and CPU isolation";
audioCpus = lib.mkOption {
type = lib.types.str;
default = "12-15";
description = "CPU list reserved for audio services (systemd cpuset syntax).";
};
nonAudioCpus = lib.mkOption {
type = lib.types.str;
default = "0-11";
description = "CPU list for everything else.";
};
cpuPartitioning = lib.mkOption {
type = lib.types.bool;
default = config.lumpiasty.audioRt.enable;
description = ''
Cgroup-based CPU partitioning via dedicated audio.slice and
restricted app/session/background slices.
'';
};
rtLimits = lib.mkOption {
type = lib.types.bool;
default = config.lumpiasty.audioRt.enable;
description = ''
Raise rlimits (RTPRIO=95, MEMLOCK=infinity) for the audio group
so PipeWire's module-rt can set SCHED_FIFO 88 directly instead
of going through RTKit's priority-10 ceiling.
'';
};
performanceGovernor = lib.mkOption {
type = lib.types.bool;
default = config.lumpiasty.audioRt.enable;
description = ''
Keep cpufreq governor `performance` on the audio cores so they
stay boosted regardless of measured utilization.
'';
};
ananicy = lib.mkOption {
type = lib.types.bool;
default = config.lumpiasty.audioRt.enable;
description = ''
Run ananicy-cpp with a rule that pins easyeffects to nice -12 so
its non-RT DSP threads get scheduler preference under load.
'';
};
optimisedBinaries = lib.mkOption {
type = lib.types.bool;
default = config.lumpiasty.audioRt.enable;
description = ''
Rebuild easyeffects and its DSP dependencies with -march=znver4 -O3
(and LTO for cmake builds, target-cpu for rust builds).
'';
};
};
};
}
-3
View File
@@ -1,8 +1,5 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.gaming = lib.mkEnableOption "Enable options specific to gaming computers";
options.lumpiasty.scx = lib.mkEnableOption "Enable sched-ext";
config = lib.mkIf config.lumpiasty.gaming { config = lib.mkIf config.lumpiasty.gaming {
# https://github.com/NixOS/nixpkgs/blob/10e687235226880ed5e9f33f1ffa71fe60f2638a/nixos/modules/programs/steam.nix # https://github.com/NixOS/nixpkgs/blob/10e687235226880ed5e9f33f1ffa71fe60f2638a/nixos/modules/programs/steam.nix
hardware.graphics = { hardware.graphics = {
+4 -8
View File
@@ -6,22 +6,18 @@
# defaults, mirroring the Fedora 45 change: # defaults, mirroring the Fedora 45 change:
# https://fedoraproject.org/wiki/Changes/IPv6-Mostly_Support_In_NetworkManager # https://fedoraproject.org/wiki/Changes/IPv6-Mostly_Support_In_NetworkManager
{ {
options.lumpiasty.ipv6Mostly = lib.mkEnableOption "Enable IPv6-mostly (RFC 8925 + CLAT/464XLAT) support in NetworkManager";
config = lib.mkIf config.lumpiasty.ipv6Mostly { config = lib.mkIf config.lumpiasty.ipv6Mostly {
# Use the patched NM build with CLAT support, without replacing pkgs.networkmanager # Use the patched NM build with CLAT support, without replacing pkgs.networkmanager
# globally (which would cascade rebuilds across the entire system closure). # globally (which would cascade rebuilds across the entire system closure).
networking.networkmanager.package = pkgs.networkmanager-clat; networking.networkmanager.package = pkgs.networkmanager-clat;
# Drop a conf.d snippet that sets connection-level defaults. # Drop a conf.d snippet that sets connection-level defaults.
# NM reads /etc/NetworkManager/conf.d/*.conf in addition to NetworkManager.conf. networking.networkmanager.settings.connection = {
environment.etc."NetworkManager/conf.d/99-ipv6-mostly.conf".text = ''
# IPv6-mostly: automatically enable CLAT (464XLAT) and DHCPv4 option 108 # IPv6-mostly: automatically enable CLAT (464XLAT) and DHCPv4 option 108
# when the network advertises PREF64 and/or option 108 (RFC 8925). # when the network advertises PREF64 and/or option 108 (RFC 8925).
# On networks without these, behaviour is unchanged (native IPv4 proceeds). # On networks without these, behaviour is unchanged (native IPv4 proceeds).
[connection-defaults] "ipv4.clat" = "auto";
ipv4.clat=auto "ipv4.dhcp-ipv6-only-preferred" = "auto";
ipv4.dhcp-ipv6-only-preferred=auto };
'';
}; };
} }
+1 -1
View File
@@ -6,6 +6,6 @@
nixpkgs.config.permittedInsecurePackages = [ nixpkgs.config.permittedInsecurePackages = [
# Ventoy has some blobs making it insecure # Ventoy has some blobs making it insecure
"ventoy-qt5-1.1.12" "ventoy-qt5-${pkgs.ventoy.version}"
]; ];
} }
@@ -1,16 +1,6 @@
From 8b5c5d23c1218a996a1d6780ca56853454813418 Mon Sep 17 00:00:00 2001 diff --git a/fs/ntfs/super.c b/fs/ntfs/super.c
From: Lumpiasty <arek.dzski@gmail.com> --- a/fs/ntfs/super.c
Date: Thu, 7 May 2026 01:50:05 +0200 +++ b/fs/ntfs/super.c
Subject: [PATCH 1/2] fix windows_names option
---
super.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/super.c b/super.c
index 875fb5a..49ad898 100644
--- a/super.c
+++ b/super.c
@@ -91,7 +91,7 @@ static const struct fs_parameter_spec ntfs_parameters[] = { @@ -91,7 +91,7 @@ static const struct fs_parameter_spec ntfs_parameters[] = {
fsparam_flag("sys_immutable", Opt_sys_immutable), fsparam_flag("sys_immutable", Opt_sys_immutable),
fsparam_flag("nohidden", Opt_nohidden), fsparam_flag("nohidden", Opt_nohidden),
@@ -20,6 +10,4 @@ index 875fb5a..49ad898 100644
fsparam_flag("acl", Opt_acl), fsparam_flag("acl", Opt_acl),
fsparam_flag("discard", Opt_discard), fsparam_flag("discard", Opt_discard),
fsparam_flag("sparse", Opt_sparse), fsparam_flag("sparse", Opt_sparse),
--
2.53.0
@@ -1,16 +1,6 @@
From 7fbf82056e26d99bfa4d5aab87ce287cd8c8cbef Mon Sep 17 00:00:00 2001 diff --git a/fs/ntfs/namei.c b/fs/ntfs/namei.c
From: Lumpiasty <arek.dzski@gmail.com> --- a/fs/ntfs/namei.c
Date: Thu, 7 May 2026 01:56:33 +0200 +++ b/fs/ntfs/namei.c
Subject: [PATCH 2/2] gate bad character check by windows_names
---
namei.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/namei.c b/namei.c
index 9e937d1..7369943 100644
--- a/namei.c
+++ b/namei.c
@@ -61,12 +61,12 @@ static int ntfs_check_bad_windows_name(struct ntfs_volume *vol, @@ -61,12 +61,12 @@ static int ntfs_check_bad_windows_name(struct ntfs_volume *vol,
const __le16 *wc, const __le16 *wc,
unsigned int wc_len) unsigned int wc_len)
@@ -27,6 +17,4 @@ index 9e937d1..7369943 100644
/* Check for trailing space or dot. */ /* Check for trailing space or dot. */
if (wc_len > 0 && if (wc_len > 0 &&
(wc[wc_len - 1] == cpu_to_le16(' ') || (wc[wc_len - 1] == cpu_to_le16(' ') ||
--
2.53.0
+5 -70
View File
@@ -1,78 +1,13 @@
{ config, pkgs, lib, ntfsplus, ... }: { config, lib, pkgs, ... }:
# Builds and loads the ntfsplus kernel driver (github:namjaejeon/linux-ntfs),
# a maintained out-of-tree NTFS driver for Linux 6.1+.
#
# The upstream driver is used as-is, with two local patches applied on top
# (see ntfsplus-patches/). This avoids maintaining a fork that would need
# rebasing on every upstream update — patches are plain files that apply
# cleanly regardless of upstream churn.
#
# The ntfsplus flake's nixosModule is NOT used directly. It builds the kernel
# module as a `let` binding inside the module closure — not exposed as a
# package in its flake outputs — so there is nothing in pkgs to override.
# Replicating the module here is the only way to substitute a patched source.
#
# The ntfsplus flake (github:cmspam/ntfsplus-flake) is reused only for:
# - its linux-ntfs source input (ntfsplus.inputs.linux-ntfs)
# - its bundled Makefile (${ntfsplus}/Makefile)
# The flake ships its own Makefile because the upstream repo's Makefile
# has an ifneq KERNELRELEASE guard that breaks the out-of-tree nix build.
#
# The derivation is built inside this module (not via an overlay) so that
# config.boot.kernelPackages.kernel resolves to whatever kernel the host
# declares, with no extra indirection or per-host maintenance.
#
# ntfsplus is passed in via specialArgs in lib/mkNixosSystem.nix.
let {
cfg = config.services.ntfsplus; boot.extraModulePackages = [
((pkgs.callPackage ../../pkgs/ntfs/package.nix { kernel = config.boot.kernelPackages.kernel; }).overrideAttrs {
patchedSrc = pkgs.applyPatches {
name = "linux-ntfs-patched";
src = ntfsplus.inputs.linux-ntfs;
patches = [ patches = [
# fsparam_flag → fsparam_bool so windows_names=0/1 is accepted as a
# mount option rather than being treated as a bare flag.
./ntfsplus-patches/0001-fix-windows_names-option.patch ./ntfsplus-patches/0001-fix-windows_names-option.patch
# Gate the bad-character check behind NVolCheckWindowsNames so that
# the check only runs when windows_names is actually enabled.
./ntfsplus-patches/0002-gate-bad-character-check-by-windows_names.patch ./ntfsplus-patches/0002-gate-bad-character-check-by-windows_names.patch
]; ];
}; })
ntfsplus-mod = pkgs.stdenv.mkDerivation {
pname = "ntfsplus-module";
version = ntfsplus.inputs.linux-ntfs.shortRev or ntfsplus.inputs.linux-ntfs.rev;
src = patchedSrc;
nativeBuildInputs = config.boot.kernelPackages.kernel.moduleBuildDependencies;
preBuild = "cp ${ntfsplus}/Makefile Makefile";
makeFlags = [
"KDIR=${config.boot.kernelPackages.kernel.dev}/lib/modules/${config.boot.kernelPackages.kernel.modDirVersion}/build"
"KVERSION=${config.boot.kernelPackages.kernel.modDirVersion}"
"CONFIG_NTFS_FS_POSIX_ACL=y"
]; ];
installPhase = ''
mkdir -p $out/lib/modules/${config.boot.kernelPackages.kernel.modDirVersion}/extra
cp ntfs.ko $out/lib/modules/${config.boot.kernelPackages.kernel.modDirVersion}/extra/
'';
};
in
{
options.services.ntfsplus = {
enable = lib.mkEnableOption "ntfsplus kernel driver and utilities";
};
config = lib.mkIf cfg.enable {
boot.extraModulePackages = [ ntfsplus-mod ];
boot.kernelModules = [ "ntfs" ];
boot.extraModprobeConfig = ''
alias fs-ntfs ntfs
alias ntfsplus ntfs
'';
services.udev.extraRules = ''
SUBSYSTEM=="block", ENV{ID_FS_TYPE}=="ntfs", ENV{ID_FS_TYPE}="ntfs"
'';
environment.systemPackages = [ pkgs.ntfsprogs-plus ];
};
} }
-6
View File
@@ -1,6 +0,0 @@
{config, lib, pkgs, modulesPath, ... }:
{
options.lumpiasty.pc = lib.mkEnableOption "Enable options specific to personal computers";
options.lumpiasty.laptop = lib.mkEnableOption "Enable options specific to laptops";
}
-2
View File
@@ -1,8 +1,6 @@
{ config, lib, pkgs, modulesPath, ... }: { config, lib, pkgs, modulesPath, ... }:
{ {
options.lumpiasty.sshd = lib.mkEnableOption "Enable intel CPU";
config = lib.mkIf config.lumpiasty.sshd { config = lib.mkIf config.lumpiasty.sshd {
services.openssh = { services.openssh = {
enable = true; enable = true;
+1 -7
View File
@@ -10,12 +10,6 @@ let
mkUser = import ../../lib/mkUser.nix { inherit lib; }; mkUser = import ../../lib/mkUser.nix { inherit lib; };
in in
{ {
options.lumpiasty.users = {
user = lib.mkEnableOption "Create user \"user\"";
drugi = lib.mkEnableOption "Create user \"drugi\"";
};
config = { config = {
# Install system-wide docker because rootless causes issues with binfmt # Install system-wide docker because rootless causes issues with binfmt
virtualisation.docker.enable = config.lumpiasty.pc; virtualisation.docker.enable = config.lumpiasty.pc;
@@ -69,7 +63,7 @@ in
users.users.user = lib.mkMerge [ users.users.user = lib.mkMerge [
(mkUser cfg.user ../../users/user/config.nix) (mkUser cfg.user ../../users/user/config.nix)
{ {
extraGroups = lib.mkIf config.lumpiasty.pc [ "docker" "libvirtd" ]; extraGroups = lib.mkIf config.lumpiasty.pc [ "docker" "libvirtd" "cdrom" ];
} }
]; ];
home-manager.users.user = mkHome cfg.user ../../users/user/home.nix; home-manager.users.user = mkHome cfg.user ../../users/user/home.nix;
+2 -8
View File
@@ -3,20 +3,14 @@
[ [
bun2nix.overlays.default bun2nix.overlays.default
(final: prev: { (final: prev: {
oh-my-pi = final.callPackage ../pkgs/oh-my-pi { inherit (final) bun2nix; };
opencode-claude-auth = prev.callPackage ../pkgs/opencode-claude-auth { }; opencode-claude-auth = prev.callPackage ../pkgs/opencode-claude-auth { };
opencode-antigravity-auth = final.callPackage ../pkgs/opencode-antigravity-auth { inherit (final) bun2nix; }; opencode-antigravity-auth = final.callPackage ../pkgs/opencode-antigravity-auth { inherit (final) bun2nix; };
# Build failure 08.05.2026
# https://github.com/NixOS/nixpkgs/issues/513245#issuecomment-4320293674
openldap = prev.openldap.overrideAttrs {
doCheck = !prev.stdenv.hostPlatform.isi686;
};
# NetworkManager 1.57.4-dev: adds ipv4.clat (CLAT/464XLAT) needed for IPv6-mostly. # NetworkManager 1.57.4-dev: adds ipv4.clat (CLAT/464XLAT) needed for IPv6-mostly.
# Used via networking.networkmanager.package — does not replace pkgs.networkmanager globally. # Used via networking.networkmanager.package — does not replace pkgs.networkmanager globally.
# Remove once nixpkgs ships networkmanager >= 1.58 stable. # Remove once nixpkgs ships networkmanager >= 1.58 stable.
networkmanager-clat = assert final.lib.assertMsg networkmanager-clat = assert final.lib.assertMsg
(final.lib.versionOlder prev.networkmanager.version "1.58") (final.lib.versionOlder prev.networkmanager.version "1.59")
"nixpkgs now ships NetworkManager ${prev.networkmanager.version} >= 1.58 remove the override in overlays/pkgs.nix and pkgs/networkmanager-dev/"; "nixpkgs now ships NetworkManager ${prev.networkmanager.version} >= 1.59 remove the override in overlays/pkgs.nix and pkgs/networkmanager-dev/ if the patches are no longer needed";
prev.callPackage ../pkgs/networkmanager-dev/package.nix { }; prev.callPackage ../pkgs/networkmanager-dev/package.nix { };
}) })
] ]
@@ -1,16 +0,0 @@
diff --git a/meson.build b/meson.build
index 61c025b9d7..d2ae60da34 100644
--- a/meson.build
+++ b/meson.build
@@ -1025,9 +1025,9 @@ meson.add_install_script(
join_paths('tools', 'meson-post-install.sh'),
nm_datadir,
nm_bindir,
- nm_pkgconfdir,
+ nm_prefix + nm_pkgconfdir,
nm_pkglibdir,
- nm_pkgstatedir,
+ nm_prefix + nm_pkgstatedir,
nm_mandir,
nm_sysconfdir,
enable_docs ? '1' : '0',
-48
View File
@@ -1,48 +0,0 @@
diff --git a/data/84-nm-drivers.rules b/data/84-nm-drivers.rules
index 148acade5c..6395fbfbe5 100644
--- a/data/84-nm-drivers.rules
+++ b/data/84-nm-drivers.rules
@@ -7,6 +7,6 @@ ACTION!="add|change|move", GOTO="nm_drivers_end"
# Determine ID_NET_DRIVER if there's no ID_NET_DRIVER or DRIVERS (old udev?)
ENV{ID_NET_DRIVER}=="?*", GOTO="nm_drivers_end"
DRIVERS=="?*", GOTO="nm_drivers_end"
-PROGRAM="/bin/sh -c '/usr/sbin/ethtool -i $$1 |/usr/bin/sed -n s/^driver:\ //p' -- $env{INTERFACE}", ENV{ID_NET_DRIVER}="%c"
+PROGRAM="@runtimeShell@ -c '@ethtool@/bin/ethtool -i $$1 |@gnused@/bin/sed -n s/^driver:\ //p' -- $env{INTERFACE}", ENV{ID_NET_DRIVER}="%c"
LABEL="nm_drivers_end"
diff --git a/src/libnmc-base/nm-vpn-helpers.c b/src/libnmc-base/nm-vpn-helpers.c
index cbe76f5f1c..6ec684f9fe 100644
--- a/src/libnmc-base/nm-vpn-helpers.c
+++ b/src/libnmc-base/nm-vpn-helpers.c
@@ -284,15 +284,6 @@ nm_vpn_openconnect_authenticate_helper(NMSettingVpn *s_vpn, GPtrArray *secrets,
const char *const *iter;
const char *path;
const char *opt;
- const char *const DEFAULT_PATHS[] = {
- "/sbin/",
- "/usr/sbin/",
- "/usr/local/sbin/",
- "/bin/",
- "/usr/bin/",
- "/usr/local/bin/",
- NULL,
- };
const char *oc_argv[(12 + 2 * G_N_ELEMENTS(oc_property_args))];
const char *gw;
int port;
@@ -311,13 +302,8 @@ nm_vpn_openconnect_authenticate_helper(NMSettingVpn *s_vpn, GPtrArray *secrets,
port = extract_url_port(gw);
- path = nm_utils_file_search_in_paths("openconnect",
- "/usr/sbin/openconnect",
- DEFAULT_PATHS,
- G_FILE_TEST_IS_EXECUTABLE,
- NULL,
- NULL,
- error);
+ path = g_find_program_in_path("openconnect");
+
if (!path)
return FALSE;
+3 -229
View File
@@ -2,240 +2,14 @@
# Required for IPv6-mostly / RFC 8925 + RFC 6877 on NixOS until 1.58 stable lands in nixpkgs. # Required for IPv6-mostly / RFC 8925 + RFC 6877 on NixOS until 1.58 stable lands in nixpkgs.
# Remove this override once nixpkgs ships networkmanager >= 1.58. # Remove this override once nixpkgs ships networkmanager >= 1.58.
{ {
lib, networkmanager
stdenv,
fetchurl,
replaceVars,
gettext,
pkg-config,
dbus,
gitUpdater,
libuuid,
polkit,
gnutls,
ppp,
dhcpcd,
iptables,
nftables,
python3,
vala,
libgcrypt,
dnsmasq,
bluez5,
readline,
libselinux,
audit,
gobject-introspection,
perl,
modemmanager,
openresolv,
libndp,
newt,
ethtool,
gnused,
iputils,
kmod,
jansson,
elfutils,
gtk-doc,
libxslt,
docbook_xsl,
docbook_xml_dtd_412,
docbook_xml_dtd_42,
docbook_xml_dtd_43,
curl,
meson,
mesonEmulatorHook,
ninja,
bpftools,
llvmPackages,
libbpf,
libnvme,
libpsl,
mobile-broadband-provider-info,
runtimeShell,
buildPackages,
nixosTests,
systemd,
udev,
udevCheckHook,
withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd,
withNbft ? false,
}: }:
let networkmanager.overrideAttrs (old: {
pythonForDocs = python3.pythonOnBuildForHost.withPackages (pkgs: with pkgs; [ pygobject3 ]); patches = old.patches ++ [
in
stdenv.mkDerivation (finalAttrs: {
pname = "networkmanager";
version = "1.57.4-dev";
src = fetchurl {
# Use the stable release tarball (not the git archive) — GitLab git archives are not content-stable.
url = "https://gitlab.freedesktop.org/api/v4/projects/411/packages/generic/NetworkManager/${finalAttrs.version}/NetworkManager-${finalAttrs.version}.tar.xz";
hash = "sha256-ThYPO/0YsmFSc2Qol1ZAoQb1qdtjPRg+rvxpUzKe0sA=";
};
outputs = [
"out"
"dev"
"devdoc"
"man"
"doc"
];
mesonFlags = [
"--sysconfdir=/etc"
"--localstatedir=/var"
(lib.mesonOption "systemdsystemunitdir" (
if withSystemd then "${placeholder "out"}/etc/systemd/system" else "no"
))
"-Dudev_dir=${placeholder "out"}/lib/udev"
"-Ddbus_conf_dir=${placeholder "out"}/share/dbus-1/system.d"
"-Dkernel_firmware_dir=/run/current-system/firmware"
"-Dmodprobe=${kmod}/bin/modprobe"
(lib.mesonOption "session_tracking" (if withSystemd then "systemd" else "no"))
(lib.mesonBool "systemd_journal" withSystemd)
"-Dlibaudit=yes-disabled-by-default"
"-Dpolkit_agent_helper_1=/run/wrappers/bin/polkit-agent-helper-1"
"-Diwd=true"
"-Dpppd=${ppp}/bin/pppd"
"-Diptables=${iptables}/bin/iptables"
"-Dnft=${nftables}/bin/nft"
"-Dmodem_manager=true"
"-Dnmtui=true"
"-Ddnsmasq=${dnsmasq}/bin/dnsmasq"
"-Dqt=false"
(lib.mesonBool "nbft" withNbft)
"-Dresolvconf=${openresolv}/bin/resolvconf"
"-Ddhcpcd=${dhcpcd}/bin/dhcpcd"
"-Ddocs=${lib.boolToString (stdenv.buildPlatform == stdenv.hostPlatform)}"
"-Dman=${lib.boolToString (stdenv.buildPlatform == stdenv.hostPlatform)}"
"-Dtests=no"
"-Dcrypto=gnutls"
"-Dmobile_broadband_provider_info_database=${mobile-broadband-provider-info}/share/mobile-broadband-provider-info/serviceproviders.xml"
];
patches = [
(replaceVars ./fix-paths.patch {
inherit
ethtool
gnused
;
inherit runtimeShell;
})
./fix-install-paths.patch
# CLAT prefix selection ignores RFC 6724 rule 3 (avoid deprecated addresses): # CLAT prefix selection ignores RFC 6724 rule 3 (avoid deprecated addresses):
# a deprecated prefix (preferred lifetime 0) can win the selection and break # a deprecated prefix (preferred lifetime 0) can win the selection and break
# CLAT with an unroutable source address. Report upstream, then drop this. # CLAT with an unroutable source address. Report upstream, then drop this.
./clat-skip-deprecated-prefixes.patch ./clat-skip-deprecated-prefixes.patch
]; ];
buildInputs = [
(if withSystemd then systemd else udev)
libselinux
audit
libpsl
libuuid
polkit
ppp
libndp
curl
mobile-broadband-provider-info
bluez5
dnsmasq
modemmanager
readline
newt
jansson
dbus
libbpf
]
++ lib.optionals withNbft [
libnvme
];
propagatedBuildInputs = [
gnutls
libgcrypt
];
# Disable hardening flags that break clang -target bpf (CLAT BPF compilation).
# Same workaround as nixpkgs systemd package.
hardeningDisable = [ "zerocallusedregs" "shadowstack" "pacret" ];
nativeBuildInputs = [
meson
ninja
gettext
pkg-config
# BPF compiler for CLAT/464XLAT — must use buildPackages to avoid splicing issues
bpftools
buildPackages.llvmPackages.clang
buildPackages.llvmPackages.libllvm
vala
gobject-introspection
perl
elfutils
gtk-doc
libxslt
docbook_xsl
docbook_xml_dtd_412
docbook_xml_dtd_42
docbook_xml_dtd_43
pythonForDocs
udevCheckHook
]
++ lib.optionals (!stdenv.buildPlatform.canExecute stdenv.hostPlatform) [
mesonEmulatorHook
];
doCheck = false;
postPatch = ''
patchShebangs ./tools
patchShebangs libnm/generate-setting-docs.py
# TODO: submit upstream
substituteInPlace meson.build \
--replace "'vala', req" "'vala', native: false, req"
''
+ lib.optionalString withSystemd ''
substituteInPlace data/NetworkManager.service.in \
--replace-fail /usr/bin/busctl ${systemd}/bin/busctl
'';
preBuild = ''
mkdir -p ${placeholder "out"}/lib
ln -s $PWD/src/libnm-client-impl/libnm.so.0 ${placeholder "out"}/lib/libnm.so.0
'';
postFixup = lib.optionalString (stdenv.buildPlatform != stdenv.hostPlatform) ''
cp -r ${buildPackages.networkmanager.devdoc} $devdoc
cp -r ${buildPackages.networkmanager.man} $man
'';
doInstallCheck = true;
passthru = {
tests = {
inherit (nixosTests.networking) networkmanager;
};
};
meta = {
homepage = "https://networkmanager.dev";
description = "Network configuration and management tool (1.57.4-dev with CLAT/ipv6-mostly support)";
license = lib.licenses.gpl2Plus;
maintainers = with lib.maintainers; [ obadz ];
teams = [ lib.teams.freedesktop ];
platforms = lib.platforms.linux;
badPlatforms = [
lib.systems.inspect.platformPatterns.isStatic
];
};
}) })
+38
View File
@@ -0,0 +1,38 @@
{ pkgs
, lib
, kernel ? pkgs.linuxPackages_latest.kernel
}:
pkgs.stdenv.mkDerivation {
pname = "ntfs-kernel-module";
inherit (kernel) src version postPatch nativeBuildInputs;
kernel_dev = kernel.dev;
kernelVersion = kernel.modDirVersion;
modulePath = "fs/ntfs";
buildPhase = ''
BUILT_KERNEL=$kernel_dev/lib/modules/$kernelVersion/build
cp $BUILT_KERNEL/Module.symvers .
cp $BUILT_KERNEL/.config .
cp $kernel_dev/vmlinux .
make "-j$NIX_BUILD_CORES" modules_prepare
make "-j$NIX_BUILD_CORES" M=$modulePath modules
'';
installPhase = ''
make \
INSTALL_MOD_PATH="$out" \
XZ="xz -T$NIX_BUILD_CORES" \
M="$modulePath" \
modules_install
'';
meta = {
description = "NTFS kernel module";
license = lib.licenses.gpl3;
};
}
-221
View File
@@ -1,221 +0,0 @@
{ bun2nix, fetchFromGitHub, fetchurl, fetchzip, runCommand, python3, pkgs, stdenv, ... }:
# NOTE: This derivation works around two open bun2nix bugs. Remove the
# workarounds and simplify once they are fixed upstream.
#
# Bug 1 — missing .npm manifest cache files
# https://github.com/nix-community/bun2nix/issues/77
#
# bun's install cache requires two kinds of entries per package:
# - the extracted package directory (e.g. handlebars@4.7.9@@@1/)
# - a hashed .npm manifest file (e.g. 02dd05ab1686ff3a.npm)
# bun2nix only provides the former. bun therefore fetches the manifest from
# the registry during the "Resolving" phase, which fails in the Nix sandbox.
#
# Workaround: pass --offline to bun install. This tells bun to skip manifest
# fetches and trust the lockfile for resolution instead.
#
# Bug 2 — catalog: specifiers still trigger network resolution with --offline
# https://github.com/nix-community/bun2nix/issues/77 (same thread)
#
# bun2nix's bunResolveCatalogRefs rewrites "catalog:" specifiers in
# package.json to the version *range* from the catalog table (e.g. "^1.3.14")
# rather than the exact pinned version from bun.lock's packages section.
# Even with --offline, bun reads the catalog table from bun.lock and tries to
# resolve those ranges, hitting the network.
#
# Workaround: the Python script below pre-processes the source before the
# build. It pins every dep in every workspace package.json to the exact
# version from bun.lock's packages section (so no ranges remain for bun to
# resolve), and strips the catalog/catalogs keys from bun.lock entirely.
#
# bun.lock is JSONC (trailing-comma JSON) so we parse it with Python's stdlib
# json after stripping trailing commas with a regex.
#
# Additionally, oh-my-pi's bun.lock was generated with bun >=1.3.14 which uses
# a different Wyhash seed for cache keys than nixpkgs's bun 1.3.13. Bumping bun
# globally breaks other packages (e.g. opencode), so instead we patch the
# generated wrapper script in postInstall to reference bun 1.3.14 directly.
# Hashes from https://github.com/NixOS/nixpkgs/pull/519796
let
version = "15.2.1";
# bun 1.3.14 — needed for correct cache key hashes; scoped to this package.
bun_1_3_14 = pkgs.bun.overrideAttrs (_: {
version = "1.3.14";
src =
let
sources = {
"aarch64-darwin" = fetchurl {
url = "https://github.com/oven-sh/bun/releases/download/bun-v1.3.14/bun-darwin-aarch64.zip";
hash = "sha256-2LliIYKK1vl6x6wKt+lYcjQa92MAHogD6CZ2UsJlJiA=";
};
"aarch64-linux" = fetchurl {
url = "https://github.com/oven-sh/bun/releases/download/bun-v1.3.14/bun-linux-aarch64.zip";
hash = "sha256-on/7Y6gxA3WDbg1vZorhf6jY0YuIw3yCHGUzGXOhmjs=";
};
"x86_64-darwin" = fetchurl {
url = "https://github.com/oven-sh/bun/releases/download/bun-v1.3.14/bun-darwin-x64-baseline.zip";
hash = "sha256-PjWtb1OXGpg0v55nhuKt9ytfGSHMmpxf3gc9KXKUQHY=";
};
"x86_64-linux" = fetchurl {
url = "https://github.com/oven-sh/bun/releases/download/bun-v1.3.14/bun-linux-x64.zip";
hash = "sha256-lR7iruhV8IWVruxiJSJqKY0/6oOj3NZGXAnLzN9+hI8=";
};
};
in
sources.${stdenv.hostPlatform.system} or (throw "bun 1.3.14 not available for ${stdenv.hostPlatform.system}");
});
src = fetchFromGitHub {
owner = "can1357";
repo = "oh-my-pi";
rev = "v${version}";
hash = "sha256-fztQJrhDG5ZbTlgqoHA96eCgwYm5WIna3mAPlCDWYLM=";
};
# The workspace source for @oh-my-pi/pi-natives has no pre-built .node
# binaries — those only exist in the npm tarball. Fetch it so we can copy
# the platform binaries into packages/natives/native/ before the build.
piNativesTarball = fetchzip {
url = "https://registry.npmjs.org/@oh-my-pi/pi-natives/-/pi-natives-${version}.tgz";
hash = "sha256-mEEnvTNxWFVSs1An61K83sSjUJ5bz4yrluwZvz1+6fg=";
stripRoot = false;
};
srcWithBunNix = runCommand "oh-my-pi-src" {
nativeBuildInputs = [ bun2nix bun_1_3_14 python3 ];
} ''
cp -r ${src} $out
chmod -R u+w $out
# Copy pre-built .node binaries from the npm tarball into the workspace
# source so the runtime can load the native addon without building Rust.
cp ${piNativesTarball}/package/native/*.node $out/packages/natives/native/
bun2nix --lock-file $out/bun.lock --output-file $out/bun.nix
python3 - "$out" << 'EOF'
import sys, re, json, os
root = sys.argv[1]
lock_path = os.path.join(root, "bun.lock")
raw = open(lock_path).read()
lock = json.loads(re.sub(r',(\s*[}\]])', r'\1', raw))
packages = lock.get("packages", {})
catalog = lock.get("catalog", {})
catalogs = lock.get("catalogs", {})
# Build name -> exact resolved version from the packages section.
resolved = {}
for name, entry in packages.items():
if isinstance(entry, list) and entry and isinstance(entry[0], str):
spec = entry[0]
if spec.startswith(name + "@"):
resolved[name] = spec[len(name) + 1:]
def pin(name, spec):
"""Pin a dep specifier to its exact resolved version from bun.lock."""
if not isinstance(spec, str):
return spec
# catalog: specifiers resolve via catalog table then pinned version.
if spec.startswith("catalog:"):
cname = spec[len("catalog:"):]
table = catalog if cname == "" else catalogs.get(cname, {})
rv = resolved.get(name)
cv = table.get(name)
if isinstance(rv, str) and rv.startswith("workspace:"):
return "workspace:*"
if isinstance(rv, str):
return rv
if isinstance(cv, str):
return cv
return spec
# Any npm version range pin to exact resolved version.
if not spec.startswith(("workspace:", "file:", "link:", "git", "http", "/")):
rv = resolved.get(name)
if isinstance(rv, str) and rv.startswith("workspace:"):
return "workspace:*"
if isinstance(rv, str):
return rv
return spec
sections = ["dependencies", "devDependencies", "peerDependencies", "optionalDependencies"]
def rewrite(holder):
for sec in sections:
deps = holder.get(sec)
if isinstance(deps, dict):
for name in list(deps):
deps[name] = pin(name, deps[name])
# Rewrite bun.lock workspaces and drop the catalog tables.
for ws in lock.get("workspaces", {}).values():
rewrite(ws)
lock.pop("catalog", None)
lock.pop("catalogs", None)
open(lock_path, "w").write(json.dumps(lock, indent=2) + "\n")
# Rewrite each workspace package.json (root "" included).
for ws_dir in lock.get("workspaces", {}):
pkg_path = os.path.join(root, ws_dir, "package.json")
if not os.path.exists(pkg_path):
continue
pkg = json.loads(open(pkg_path).read())
rewrite(pkg)
open(pkg_path, "w").write(json.dumps(pkg, indent=2) + "\n")
EOF
'';
in
(bun2nix.writeBunApplication {
pname = "omp";
inherit version;
src = srcWithBunNix;
# oh-my-pi requires bun >=1.3.14 at runtime. writeBunApplication prepends
# pkgs.bun (1.3.13) to PATH in the startup script, so we use an absolute
# path to bun 1.3.14 instead of relying on PATH resolution.
#
# writeBunApplication's installPhase does `cd $out/share/$pname` before
# exec, so $PWD is always the store path. OLDPWD is set by bash's cd to the
# user's original directory. We cd back so omp's process.cwd() is correct,
# and use an absolute path to the entry point so bun resolves modules from
# the store regardless of cwd.
# At this point the wrapper has already done `cd $out/share/omp`, so $PWD
# is the store package dir and OLDPWD is the user's original directory.
# Capture the store dir, cd back to the user's dir so omp's process.cwd()
# is correct, then exec bun with an absolute path so module resolution
# still works from the store.
startScript = ''
_omp_pkg="$PWD"
cd "''${OLDPWD:-$PWD}"
exec ${bun_1_3_14}/bin/bun run "$_omp_pkg/packages/coding-agent/src/cli.ts" "$@"
'';
dontUseBunBuild = true;
dontUseBunCheck = true;
# --offline: workaround for Bug 1 above (missing .npm manifest cache files).
bunInstallFlags = [ "--offline" "--linker=isolated" "--ignore-scripts" ];
# Generate the docs index embedded into the binary at build time.
# The prepack script reads docs/**/*.md and emits docs-index.generated.ts.
postBunNodeModulesInstallPhase = ''
${bun_1_3_14}/bin/bun run packages/coding-agent/scripts/generate-docs-index.ts
'';
bunDeps = bun2nix.fetchBunDeps {
bunNix = "${srcWithBunNix}/bun.nix";
};
meta = {
description = "AI coding agent for the terminal batteries included";
homepage = "https://omp.sh";
mainProgram = "omp";
};
})
-2
View File
@@ -18,8 +18,6 @@
kubernetes-helm kubernetes-helm
xonsh xonsh
gnumake gnumake
python312
python312Packages.python-lsp-server
nil nil
docker docker
docker-buildx docker-buildx
+2 -2
View File
@@ -1,14 +1,14 @@
{ config, pkgs, osConfig, ... }: { config, pkgs, osConfig, ... }:
{ {
home.username = "user"; # home.username = "user";
lumpiastyHome = { lumpiastyHome = {
gpg = osConfig.lumpiasty.pc; gpg = osConfig.lumpiasty.pc;
enablePcApps = osConfig.lumpiasty.pc; enablePcApps = osConfig.lumpiasty.pc;
dev = osConfig.lumpiasty.pc; dev = osConfig.lumpiasty.pc;
gaming = osConfig.lumpiasty.gaming; gaming = osConfig.lumpiasty.gaming;
fhs = osConfig.lumpiasty.pc; fhs = osConfig.lumpiasty.pc && config.lumpiastyHome.linux;
}; };
home.stateVersion = "24.05"; home.stateVersion = "24.05";