diff --git a/modules/nixos/boot/default.nix b/modules/nixos/boot/default.nix index 648eee8a..19e81c03 100644 --- a/modules/nixos/boot/default.nix +++ b/modules/nixos/boot/default.nix @@ -4,6 +4,7 @@ ./generic.nix # generic boot configuration ./loader.nix # which system loader are we using ./secure-boot.nix # pretty much what it looks like + ./tmpfs.nix # configs to allow you to run on tmpfs # keep-sorted end ]; } diff --git a/modules/nixos/boot/generic.nix b/modules/nixos/boot/generic.nix index ad717d2c..ffba9373 100644 --- a/modules/nixos/boot/generic.nix +++ b/modules/nixos/boot/generic.nix @@ -1,211 +1,104 @@ -{ - lib, - pkgs, - config, - ... -}: +{ lib, config, ... }: let inherit (lib.modules) mkIf mkForce mkMerge mkDefault - mkOverride - ; - inherit (lib.lists) optionals; - inherit (lib.options) mkOption mkEnableOption; - inherit (lib.types) - str - raw ; + inherit (lib.options) mkEnableOption; cfg = config.garden.system.boot; in { options.garden.system.boot = { - enableKernelTweaks = mkEnableOption "security and performance related kernel parameters"; - recommendedLoaderConfig = mkEnableOption "tweaks for common bootloader configs per my liking"; - loadRecommendedModules = mkEnableOption "kernel modules that accommodate for most use cases"; - tmpOnTmpfs = - mkEnableOption "`/tmp` living on tmpfs. false means it will be cleared manually on each reboot" - // { + initrd = { + enableTweaks = mkEnableOption "quality of life tweaks for the initrd stage" // { default = true; }; - kernel = mkOption { - type = raw; - default = pkgs.linuxPackages_latest; - defaultText = "pkgs.linuxPackages_latest"; - description = "The kernel to use for the system."; + optimizeCompressor = + mkEnableOption '' + initrd compression algorithm optimizations for size. + Enabling this option will force initrd to use zstd (default) with + level 19 and -T0 (STDIN). This will reduce thee initrd size greatly + at the cost of compression speed. + Not recommended for low-end hardware. + '' + // { + default = config.garden.profiles.workstation.enable; + defaultText = "config.garden.profiles.workstation.enable"; + }; }; - - initrd = { - enableTweaks = mkEnableOption "quality of life tweaks for the initrd stage"; - optimizeCompressor = mkEnableOption '' - initrd compression algorithm optimizations for size. - Enabling this option will force initrd to use zstd (default) with - level 19 and -T0 (STDIN). This will reduce thee initrd size greatly - at the cost of compression speed. - Not recommended for low-end hardware. - ''; - }; - - extraModprobeConfig = mkOption { - type = str; - default = "options hid_apple fnmode=1"; - description = "Extra modprobe config that will be passed to system modprobe config."; - }; - - silentBoot = mkEnableOption '' - almost entirely silent boot process through `quiet` kernel parameter - ''; }; - config = { - boot = { - consoleLogLevel = 3; - - # we set the kernel to be defaulted to the one set by our settings - # we happen to default this to the latest kernel sooo: - # always use the latest kernel, love the unstablity - kernelPackages = mkOverride 500 cfg.kernel; - - extraModprobeConfig = mkDefault cfg.extraModprobeConfig; - - # whether to enable support for Linux MD RAID arrays - # as of 23.11>, this throws a warning if neither MAILADDR nor PROGRAM are set - swraid.enable = mkDefault false; - - # shared config between bootloaders - # they are set unless system.boot.loader != none - loader = { - # if set to 0, space needs to be held to get the boot menu to appear - timeout = mkForce 2; - - # copy boot files to /boot so that /nix/store is not required to boot - # it takes up more space but it makes my messups a bit safer - generationsDir.copyKernels = true; - - # we need to allow installation to modify EFI variables - efi.canTouchEfiVariables = true; - }; - - # increase the map count, this is important for applications that require a lot of memory mappings - # such as games and emulators - kernel.sysctl."vm.max_map_count" = 2147483642; - - # if you have a lack of ram, you should avoid tmpfs to prevent hangups while compiling - tmp = { - # /tmp on tmpfs, lets it live on your ram - useTmpfs = cfg.tmpOnTmpfs; + config.boot = { + consoleLogLevel = 3; - # If not using tmpfs, which is naturally purged on reboot, we must clean - # we have to clean /tmp - cleanOnBoot = mkDefault (!config.boot.tmp.useTmpfs); + extraModprobeConfig = mkDefault "options hid_apple fnmode=1"; - # this defaults to 50% of your ram - # but i want to build code sooo - # tmpfsSize = mkDefault "75%"; + # whether to enable support for Linux MD RAID arrays + # as of 23.11>, this throws a warning if neither MAILADDR nor PROGRAM are set + swraid.enable = mkDefault false; - # enable huge pages on tmpfs for better performance - tmpfsHugeMemoryPages = "within_size"; - }; - - # initrd and kernel tweaks - # read what each parameter or module does before doing so, it will defo break something otherwise - initrd = mkMerge [ - (mkIf cfg.initrd.enableTweaks { - # Verbosity of the initrd - # disabling verbosity removes only the mandatory messages generated by the NixOS - verbose = false; - - # enable systemd in initrd (experimental) - systemd.enable = true; - - kernelModules = [ - "nvme" - "xhci_pci" - "ahci" - "btrfs" - "sd_mod" - "dm_mod" - ]; - - availableKernelModules = [ - "vmd" - "usbhid" - "sd_mod" - "sr_mod" - "dm_mod" - "uas" - "usb_storage" - "rtsx_usb_sdmmc" - "rtsx_pci_sdmmc" # Realtek SD card interface (btw i hate realtek) - "ata_piix" - "virtio_pci" - "virtio_scsi" - "ehci_pci" - ]; - }) - - (mkIf cfg.initrd.optimizeCompressor { - compressor = "zstd"; - compressorArgs = [ - "-19" - "-T0" - ]; - }) - ]; - - # https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html - kernelParams = - optionals cfg.enableKernelTweaks [ - # https://en.wikipedia.org/wiki/Kernel_page-table_isolation - # auto means kernel will automatically decide the pti state - "pti=auto" # on || off - - # disable the intel_idle (it stinks anyway) driver and use acpi_idle instead - "idle=nomwait" - - # enable IOMMU for devices used in passthrough and provide better host performance - "iommu=pt" + # shared config between bootloaders + # they are set unless system.boot.loader != none + loader = { + # if set to 0, space needs to be held to get the boot menu to appear + timeout = mkForce 2; - # disable usb autosuspend - "usbcore.autosuspend=-1" + # copy boot files to /boot so that /nix/store is not required to boot + # it takes up more space but it makes my messups a bit safer + generationsDir.copyKernels = true; - # isables resume and restores original swap space - "noresume" - - # allow systemd to set and save the backlight state - "acpi_backlight=native" - - # prevent the kernel from blanking plymouth out of the fb - "fbcon=nodefer" - - # disable boot logo - "logo.nologo" - - # disable the cursor in vt to get a black screen during intermissions - "vt.global_cursor_default=0" - ] - ++ optionals cfg.silentBoot [ - # tell the kernel to not be verbose, the voices are too loud - "quiet" - - # kernel log message level - "loglevel=3" # 1: system is unusable | 3: error condition | 7: very verbose + # we need to allow installation to modify EFI variables + efi.canTouchEfiVariables = true; + }; - # udev log message level - "udev.log_level=3" + # initrd and kernel tweaks + # read what each parameter or module does before doing so, it will defo break something otherwise + initrd = mkMerge [ + (mkIf cfg.initrd.enableTweaks { + # Verbosity of the initrd + # disabling verbosity removes only the mandatory messages generated by the NixOS + verbose = false; + + # enable systemd in initrd (experimental) + systemd.enable = true; + + kernelModules = [ + "nvme" + "xhci_pci" + "ahci" + "btrfs" + "sd_mod" + "dm_mod" + ]; - # lower the udev log level to show only errors or worse - "rd.udev.log_level=3" + availableKernelModules = [ + "vmd" + "usbhid" + "sd_mod" + "sr_mod" + "dm_mod" + "uas" + "usb_storage" + "rtsx_usb_sdmmc" + "rtsx_pci_sdmmc" # Realtek SD card interface (btw i hate realtek) + "ata_piix" + "virtio_pci" + "virtio_scsi" + "ehci_pci" + ]; + }) - # disable systemd status messages - # rd prefix means systemd-udev will be used instead of initrd - "systemd.show_status=auto" - "rd.systemd.show_status=auto" + (mkIf cfg.initrd.optimizeCompressor { + compressor = "zstd"; + compressorArgs = [ + "-19" + "-T0" ]; - }; + }) + ]; }; } diff --git a/modules/nixos/boot/tmpfs.nix b/modules/nixos/boot/tmpfs.nix new file mode 100644 index 00000000..acc9684b --- /dev/null +++ b/modules/nixos/boot/tmpfs.nix @@ -0,0 +1,32 @@ +{ lib, config, ... }: +let + inherit (lib) mkEnableOption mkDefault; + + cfg = config.garden.system.boot; +in +{ + options.garden.system.boot = { + tmpOnTmpfs = + mkEnableOption "`/tmp` living on tmpfs. false means it will be cleared manually on each reboot" + // { + default = true; + }; + }; + + # if you have a lack of ram, you should avoid tmpfs to prevent hangups while compiling + config.boot.tmp = { + # /tmp on tmpfs, lets it live on your ram + useTmpfs = cfg.tmpOnTmpfs; + + # If not using tmpfs, which is naturally purged on reboot, we must clean + # we have to clean /tmp + cleanOnBoot = mkDefault (!config.boot.tmp.useTmpfs); + + # this defaults to 50% of your ram + # but i want to build code sooo + # tmpfsSize = mkDefault "75%"; + + # enable huge pages on tmpfs for better performance + tmpfsHugeMemoryPages = "within_size"; + }; +} diff --git a/modules/nixos/hardware/cloud/hetzner/garden.nix b/modules/nixos/hardware/cloud/hetzner/garden.nix index 7d770b65..54ca9475 100644 --- a/modules/nixos/hardware/cloud/hetzner/garden.nix +++ b/modules/nixos/hardware/cloud/hetzner/garden.nix @@ -16,13 +16,17 @@ in bluetooth = false; }; - system.boot = { - loader = "grub"; - grub.device = "/dev/sda"; - enableKernelTweaks = true; - initrd.enableTweaks = true; - loadRecommendedModules = true; - tmpOnTmpfs = false; + system = { + boot = { + loader = "grub"; + grub.device = "/dev/sda"; + initrd.enableTweaks = true; + tmpOnTmpfs = false; + }; + + kernel = { + tweaks.enable = true; + }; }; }; }; diff --git a/modules/nixos/kernel/default.nix b/modules/nixos/kernel/default.nix index 353d5076..1e38f351 100644 --- a/modules/nixos/kernel/default.nix +++ b/modules/nixos/kernel/default.nix @@ -3,6 +3,7 @@ # keep-sorted start ./blacklisted-modules.nix ./misc.nix + ./package.nix ./params.nix ./sysctl.nix ./sysfs.nix diff --git a/modules/nixos/kernel/package.nix b/modules/nixos/kernel/package.nix new file mode 100644 index 00000000..1a59aa46 --- /dev/null +++ b/modules/nixos/kernel/package.nix @@ -0,0 +1,30 @@ +{ + lib, + pkgs, + config, + ... +}: +let + inherit (lib.types) raw; + inherit (lib.options) mkOption; + inherit (lib.modules) mkOverride; + + cfg = config.garden.system.kernel; +in +{ + options.garden.system.kernel = { + packages = mkOption { + type = raw; + default = pkgs.linuxPackages_latest; + defaultText = "pkgs.linuxPackages_latest"; + description = "The kernel to use for the system."; + }; + }; + + config = { + # we set the kernel to be defaulted to the one set by our settings + # we happen to default this to the latest kernel sooo: + # always use the latest kernel, love the unstablity + boot.kernelPackages = mkOverride 500 cfg.packages; + }; +} diff --git a/modules/nixos/kernel/params.nix b/modules/nixos/kernel/params.nix index 3659f193..76172349 100644 --- a/modules/nixos/kernel/params.nix +++ b/modules/nixos/kernel/params.nix @@ -1,6 +1,23 @@ +# the holy handbook to kernel parameters +# +{ lib, config, ... }: +let + inherit (lib) mkEnableOption optionals; + cfg = config.garden.system; +in { - # https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html - boot.kernelParams = [ + options.garden.system = { + boot.silent = mkEnableOption '' + almost entirely silent boot process through `quiet` kernel parameter + ''; + + kernel.tweaks.enable = mkEnableOption "security and performance related kernel parameters" // { + default = config.garden.profiles.workstation.enable; + defaultText = "config.garden.profiles.workstation.enable"; + }; + }; + + config.boot.kernelParams = [ # NixOS produces many wakeups per second, which is bad for battery life. # This kernel parameter disables the timer tick on the last 4 cores "nohz_full=4-7" @@ -47,5 +64,52 @@ # prevent the kernel from blanking plymouth out of the fb "fbcon=nodefer" + ] + ++ optionals cfg.kernel.tweaks.enable [ + # https://en.wikipedia.org/wiki/Kernel_page-table_isolation + # auto means kernel will automatically decide the pti state + "pti=auto" # on || off + + # disable the intel_idle (it stinks anyway) driver and use acpi_idle instead + "idle=nomwait" + + # enable IOMMU for devices used in passthrough and provide better host performance + "iommu=pt" + + # disable usb autosuspend + "usbcore.autosuspend=-1" + + # isables resume and restores original swap space + "noresume" + + # allow systemd to set and save the backlight state + "acpi_backlight=native" + + # prevent the kernel from blanking plymouth out of the fb + "fbcon=nodefer" + + # disable boot logo + "logo.nologo" + + # disable the cursor in vt to get a black screen during intermissions + "vt.global_cursor_default=0" + ] + ++ optionals cfg.boot.silent [ + # tell the kernel to not be verbose, the voices are too loud + "quiet" + + # kernel log message level + "loglevel=3" # 1: system is unusable | 3: error condition | 7: very verbose + + # udev log message level + "udev.log_level=3" + + # lower the udev log level to show only errors or worse + "rd.udev.log_level=3" + + # disable systemd status messages + # rd prefix means systemd-udev will be used instead of initrd + "systemd.show_status=auto" + "rd.systemd.show_status=auto" ]; } diff --git a/modules/nixos/kernel/sysctl.nix b/modules/nixos/kernel/sysctl.nix index 06f69337..fc21d8c4 100644 --- a/modules/nixos/kernel/sysctl.nix +++ b/modules/nixos/kernel/sysctl.nix @@ -99,5 +99,9 @@ # unless the user ID of the follower matches the symlink, or the # directory owner matches the symlink "fs.protected_symlinks" = 1; + + # increase the map count, this is important for applications that require a lot of memory mappings + # such as games and emulators + "vm.max_map_count" = 2147483642; }; } diff --git a/systems/amaterasu/default.nix b/systems/amaterasu/default.nix index 56206bd5..14d53232 100644 --- a/systems/amaterasu/default.nix +++ b/systems/amaterasu/default.nix @@ -31,13 +31,6 @@ boot = { loader = "systemd-boot"; secureBoot = true; - enableKernelTweaks = true; - loadRecommendedModules = true; - - initrd = { - enableTweaks = true; - optimizeCompressor = true; - }; }; bluetooth.enable = true; diff --git a/systems/athena/default.nix b/systems/athena/default.nix index 03b9fd21..69683afd 100644 --- a/systems/athena/default.nix +++ b/systems/athena/default.nix @@ -23,9 +23,6 @@ system.boot = { loader = "systemd-boot"; secureBoot = false; - loadRecommendedModules = true; - enableKernelTweaks = true; - initrd.enableTweaks = true; }; services = { diff --git a/systems/valkyrie/default.nix b/systems/valkyrie/default.nix index 10fc5439..8b073b76 100644 --- a/systems/valkyrie/default.nix +++ b/systems/valkyrie/default.nix @@ -21,17 +21,9 @@ boot = { loader = "none"; secureBoot = false; - enableKernelTweaks = true; - loadRecommendedModules = true; - - initrd = { - enableTweaks = true; - optimizeCompressor = true; - }; }; emulation.enable = true; - bluetooth.enable = false; }; };