diff --git a/fedac/nixos/configuration.nix b/fedac/nixos/configuration.nix index fe0f82a124..2eb0bcbd49 100644 --- a/fedac/nixos/configuration.nix +++ b/fedac/nixos/configuration.nix @@ -1,7 +1,7 @@ -{ config, pkgs, lib, self ? null, gitHash ? "unknown", version ? "dev", nativeSrc, ... }: +{ config, pkgs, lib, self ? null, gitHash ? "unknown", version ? "dev", nativeSrc, kidlispSrc ? null, ... }: let - ac-native = pkgs.callPackage ./packages/ac-native { inherit gitHash version nativeSrc; }; + ac-native = pkgs.callPackage ./packages/ac-native { inherit gitHash version nativeSrc kidlispSrc; }; in { imports = [ diff --git a/fedac/nixos/flake.nix b/fedac/nixos/flake.nix index dfd2ef8b27..e63ca394f5 100644 --- a/fedac/nixos/flake.nix +++ b/fedac/nixos/flake.nix @@ -21,7 +21,15 @@ } else throw "AC_NIX_NATIVE_SRC is required for fedac/nixos builds; run nix with --impure and point it at fedac/native."; - specialArgs = { inherit self gitHash version nativeSrc; }; + # KidLisp evaluator source — bundled into jslib/kidlisp-bundle.js for QuickJS. + # kidlisp.mjs imports siblings (num.mjs, …) and ../dep/@akamfoad/qr, + # so we need the aesthetic.computer tree for esbuild resolution. + acWebPath = nativeSrcPath + "/../../system/public/aesthetic.computer"; + kidlispSrc = + if nativeSrcPath != "" && builtins.pathExists (acWebPath + "/lib/kidlisp.mjs") then + builtins.path { path = acWebPath; name = "ac-web-source"; } + else null; + specialArgs = { inherit self gitHash version nativeSrc kidlispSrc; }; runtimeModules = [ ./configuration.nix ]; imageModules = runtimeModules ++ [ ./modules/image.nix ]; evalConfig = import "${nixpkgs}/nixos/lib/eval-config.nix"; @@ -41,7 +49,7 @@ # The ac-native binary as a standalone package packages.${system} = { ac-native = pkgs.callPackage ./packages/ac-native { - inherit gitHash version nativeSrc; + inherit gitHash version nativeSrc kidlispSrc; }; # Bootable raw disk image with BIOS + UEFI bootloader install. diff --git a/fedac/nixos/modules/kiosk.nix b/fedac/nixos/modules/kiosk.nix index fa53301107..45689519c5 100644 --- a/fedac/nixos/modules/kiosk.nix +++ b/fedac/nixos/modules/kiosk.nix @@ -1,7 +1,7 @@ -{ config, pkgs, lib, gitHash ? "unknown", version ? "dev", nativeSrc, ... }: +{ config, pkgs, lib, gitHash ? "unknown", version ? "dev", nativeSrc, kidlispSrc ? null, ... }: let - ac-native = pkgs.callPackage ../packages/ac-native { inherit gitHash version nativeSrc; }; + ac-native = pkgs.callPackage ../packages/ac-native { inherit gitHash version nativeSrc kidlispSrc; }; write-breadcrumb = pkgs.writeShellScript "ac-native-write-breadcrumb" '' set -u @@ -111,23 +111,26 @@ in wantedBy = [ "multi-user.target" ]; path = with pkgs; [ - coreutils systemd util-linux + coreutils gnugrep gnused gawk findutils + which psmisc # killall (psmisc), which + systemd util-linux wpa_supplicant iw dhcpcd curl dosfstools efibootmgr parted ac-native ]; environment = { - XDG_RUNTIME_DIR = "/run/user/1000"; + XDG_RUNTIME_DIR = "/run/user/0"; HOME = "/tmp/ac-home"; SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"; ALSA_PLUGIN_DIR = "${pkgs.alsa-plugins}/lib/alsa-lib"; + ALSA_CONFIG_PATH = "${pkgs.alsa-lib}/share/alsa/alsa.conf"; }; serviceConfig = { - User = "ac"; - Group = "users"; - SupplementaryGroups = [ "video" "audio" "input" "seat" ]; + # Run as root — ac-native needs full hardware access (WiFi, ALSA, + # DRM) matching the old bare-metal build where it ran as PID 1. + # Security hardening can be layered on once all features work. Type = "simple"; Restart = "on-failure"; RestartSec = 2; @@ -146,20 +149,16 @@ in # 0 = shutdown, 2 = reboot (matching current ac-native convention) SuccessExitStatus = "0 2"; ExecStopPost = "+${ac-native-stop}"; - - # Security - ProtectSystem = "strict"; - ReadWritePaths = [ "/tmp" "/mnt" "/run" ]; - PrivateTmp = false; # ac-native uses /tmp for scratch }; }; # Ensure XDG_RUNTIME_DIR exists for the ac user systemd.tmpfiles.rules = [ "d /mnt 0755 root root -" - "d /run/user/1000 0700 ac users -" - "d /tmp/ac-home 0700 ac users -" + "d /run/user/0 0700 root root -" + "d /tmp/ac-home 0700 root root -" "L+ /piece.mjs - - - - ${ac-native}/share/ac-native/piece.mjs" "L+ /pieces - - - - ${ac-native}/share/ac-native/pieces" + "L+ /jslib - - - - ${ac-native}/share/ac-native/jslib" ]; } diff --git a/fedac/nixos/packages/ac-native/default.nix b/fedac/nixos/packages/ac-native/default.nix index 54e1afc559..d0fd295391 100644 --- a/fedac/nixos/packages/ac-native/default.nix +++ b/fedac/nixos/packages/ac-native/default.nix @@ -1,8 +1,9 @@ { lib, stdenv, fetchurl, pkg-config , libdrm, alsa-lib, flite, openssl, curl , wayland, wayland-protocols, wayland-scanner -, ffmpeg +, ffmpeg, esbuild , nativeSrc +, kidlispSrc ? null , gitHash ? "unknown", version ? "dev" }: @@ -21,6 +22,7 @@ stdenv.mkDerivation { nativeBuildInputs = [ pkg-config wayland-scanner + esbuild ]; buildInputs = [ @@ -72,7 +74,7 @@ stdenv.mkDerivation { installPhase = '' runHook preInstall - mkdir -p $out/bin $out/share/ac-native/pieces + mkdir -p $out/bin $out/share/ac-native/pieces $out/share/ac-native/jslib # Binary cp build/ac-native $out/bin/ @@ -84,6 +86,14 @@ stdenv.mkDerivation { cp pieces/*.mjs $out/share/ac-native/pieces/ 2>/dev/null || true cp pieces/*.lisp $out/share/ac-native/pieces/ 2>/dev/null || true + # KidLisp bundle — ac-native loads /jslib/kidlisp-bundle.js at init. + # kidlispSrc is the aesthetic.computer web tree; entry point is lib/kidlisp.mjs. + if [ -n "${toString kidlispSrc}" ] && [ -f "${toString kidlispSrc}/lib/kidlisp.mjs" ]; then + esbuild "${toString kidlispSrc}/lib/kidlisp.mjs" --bundle --format=iife \ + --global-name=KidLispModule --platform=node \ + --outfile=$out/share/ac-native/jslib/kidlisp-bundle.js + fi + runHook postInstall '';