diff --git a/modules/hjem-ctp/default.nix b/modules/hjem-ctp/default.nix index a144fa6..33b749e 100644 --- a/modules/hjem-ctp/default.nix +++ b/modules/hjem-ctp/default.nix @@ -19,7 +19,6 @@ in ./eza.nix ./fcitx5.nix ./fish.nix - ./fuzzel.nix ./vencord.nix ./wleave.nix ]; diff --git a/modules/hjem-ctp/eza.nix b/modules/hjem-ctp/eza.nix index 1b2194c..26e4534 100644 --- a/modules/hjem-ctp/eza.nix +++ b/modules/hjem-ctp/eza.nix @@ -1,5 +1,4 @@ - -# Catppuccin theme for Fuzzel +# Catppuccin theme for Eza { config, ctp-lib, @@ -8,7 +7,7 @@ ... }: let - cfg = config.ctp.fuzzel; + cfg = config.ctp.eza; src = pkgs.fetchFromGitHub { owner = "catppuccin"; diff --git a/modules/hjem-ctp/fuzzel.nix b/modules/hjem-ctp/fuzzel.nix deleted file mode 100644 index 29ea936..0000000 --- a/modules/hjem-ctp/fuzzel.nix +++ /dev/null @@ -1,26 +0,0 @@ -# Catppuccin theme for Fuzzel -{ - config, - ctp-lib, - lib, - pkgs, - ... -}: -let - cfg = config.ctp.fuzzel; - - src = pkgs.fetchFromGitHub { - owner = "catppuccin"; - repo = "fuzzel"; - rev = "0af0e26901b60ada4b20522df739f032797b07c3"; - hash = "sha256-XpItMGsYq4XvLT+7OJ9YRILfd/9RG1GMuO6J4hSGepg="; - }; -in -{ - options.ctp.fuzzel = ctp-lib.mkCatppuccinOptions "Fuzzel" { withAccent = true; }; - - config = lib.mkIf cfg.enable { - rum.programs.fuzzel.settings.main.include = - "${src}/themes/catppuccin-${cfg.flavor}/${cfg.accent}.ini"; - }; -} diff --git a/modules/hjem-ext/default.nix b/modules/hjem-ext/default.nix index f3be158..5390081 100644 --- a/modules/hjem-ext/default.nix +++ b/modules/hjem-ext/default.nix @@ -6,5 +6,6 @@ ./programs/swaylock.nix ./programs/swayosd.nix ./programs/vesktop.nix + ./programs/vicinae.nix ]; } diff --git a/modules/hjem-ext/programs/jujutsu.nix b/modules/hjem-ext/programs/jujutsu.nix index 781940b..a831d8c 100644 --- a/modules/hjem-ext/programs/jujutsu.nix +++ b/modules/hjem-ext/programs/jujutsu.nix @@ -12,7 +12,6 @@ in options.ext.programs.jujutsu = { enable = lib.mkEnableOption "Jujutsu"; package = lib.mkPackageOption pkgs "jujutsu" { }; - settings = lib.mkOption { type = lib.types.submodule { freeformType = format.type; @@ -23,8 +22,9 @@ in config = lib.mkIf cfg.enable { packages = [ cfg.package ]; - xdg.config.files."jj/config.toml".source = lib.mkIf (cfg.settings != { }) ( - format.generate "jj-config.toml" cfg.settings - ); + xdg.config.files."jj/config.toml" = lib.mkIf (cfg.settings != { }) { + generator = format.generate "jj-config.toml"; + value = cfg.settings; + }; }; } diff --git a/modules/hjem-ext/programs/vesktop.nix b/modules/hjem-ext/programs/vesktop.nix index aa4c29f..c32e1f0 100644 --- a/modules/hjem-ext/programs/vesktop.nix +++ b/modules/hjem-ext/programs/vesktop.nix @@ -65,14 +65,20 @@ in ]) ]; - xdg.config.files = { - "vesktop/settings.json".source = format.generate "vesktop-settings.json" cfg.settings; - } - // lib.optionalAttrs cfg.vencord.enable { - "vesktop/settings/settings.json".source = - format.generate "vencord-settings.json" cfg.vencord.settings; - - "vesktop/settings/quickCss.css".text = cfg.vencord.css; - }; + xdg.config.files = lib.mkMerge [ + { + "vesktop/settings.json" = lib.mkIf (cfg.settings != { }) { + generator = format.generate "vesktop-settings.json"; + value = cfg.settings; + }; + } + (lib.mkIf cfg.vencord.enable { + "vesktop/settings/settings.json" = lib.mkIf (cfg.vencord.settings != { }) { + generator = format.generate "vencord-settings.json"; + value = cfg.vencord.settings; + }; + "vesktop/settings/quickCss.css".text = lib.mkIf (cfg.vencord.css != "") cfg.vencord.css; + }) + ]; }; } diff --git a/modules/hjem-ext/programs/vicinae.nix b/modules/hjem-ext/programs/vicinae.nix new file mode 100644 index 0000000..56b64da --- /dev/null +++ b/modules/hjem-ext/programs/vicinae.nix @@ -0,0 +1,32 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.ext.programs.vicinae; + format = pkgs.formats.json { }; +in +{ + options.ext.programs.vicinae = { + enable = lib.mkEnableOption "Vicinae"; + package = lib.mkPackageOption pkgs "vicinae" { }; + + settings = lib.mkOption { + inherit (format) type; + description = '' + Configuration written to {file}`$XDG_CONFIG_HOME/vicinae/vicinae.json`. + ''; + default = { }; + }; + }; + + config = lib.mkIf cfg.enable { + packages = [ cfg.package ]; + xdg.config.files."vicinae/vicinae.json" = { + generator = format.generate "vicinae.json"; + value = cfg.settings; + }; + }; +} diff --git a/modules/nixos/hysteria.nix b/modules/nixos/hysteria.nix new file mode 100644 index 0000000..0b52b49 --- /dev/null +++ b/modules/nixos/hysteria.nix @@ -0,0 +1,96 @@ +# Copied from https://github.com/NixOS/nixpkgs/pull/307601 +{ + config, + lib, + pkgs, + utils, + ... +}: +let + cfg = config.services.hysteria; + settingsFormat = pkgs.formats.json { }; +in +{ + options.services.hysteria = { + enable = lib.mkEnableOption "Hysteria, a powerful, lightning fast and censorship resistant proxy"; + + package = lib.mkPackageOption pkgs "hysteria" { }; + + mode = lib.mkOption { + type = lib.types.enum [ + "server" + "client" + ]; + default = "server"; + description = "Whether to use Hysteria as a client or a server."; + }; + + settings = lib.mkOption { + type = lib.types.submodule { freeformType = settingsFormat.type; }; + default = { }; + description = '' + The Hysteria configuration, see https://hysteria.network/ for documentation. + + Options containing secret data should be set to an attribute set + containing the attribute `_secret` - a string pointing to a file + containing the value the option should be set to. + ''; + }; + }; + config = lib.mkIf cfg.enable { + systemd.services.hysteria = { + description = "Hysteria daemon, a powerful, lightning fast and censorship resistant proxy."; + documentation = [ "https://hysteria.network/" ]; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + preStart = utils.genJqSecretsReplacementSnippet cfg.settings "/var/lib/hysteria/config.json"; + serviceConfig = { + ExecStart = lib.concatStringsSep " " [ + (lib.getExe cfg.package) + cfg.mode + "--disable-update-check" + "--config /var/lib/hysteria/config.json" + ]; + + StateDirectory = "hysteria"; + WorkingDirectory = "/var/lib/hysteria"; + + ### Hardening + AmbientCapabilities = [ + "CAP_NET_ADMIN" + "CAP_NET_BIND_SERVICE" + "CAP_NET_RAW" + ]; + CapabilityBoundingSet = [ + "CAP_NET_ADMIN" + "CAP_NET_BIND_SERVICE" + "CAP_NET_RAW" + ]; + NoNewPrivileges = true; + PrivateMounts = true; + PrivateTmp = true; + ProcSubset = "pid"; + ProtectClock = true; + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + ProtectSystem = "strict"; + RestrictRealtime = true; + RestrictSUIDSGID = true; + RestrictNamespaces = true; + SystemCallArchitectures = "native"; + SystemCallFilter = "@system-service"; + UMask = "0077"; + + # More perf + CPUSchedulingPolicy = "rr"; + CPUSchedulingPriority = 99; + }; + }; + }; +} diff --git a/overlay.nix b/overlay.nix index f537a11..6915aaa 100644 --- a/overlay.nix +++ b/overlay.nix @@ -1,13 +1,13 @@ # May lord have mercy on my soul -_: prev: { +final: prev: { jujutsu = prev.jujutsu.overrideAttrs { patches = (prev.patches or [ ]) ++ [ # HACK: I am so sick and tired of not being able to push to Nixpkgs # because some edgy fucking idiot thought that it's a good idea to not # specify an email address in a commit - # + # # See https://github.com/NixOS/nixpkgs/pull/453871 - # See https://github.com/jj-vcs/jj/issues/5723 + # See https://github.com/jj-vcs/jj/issues/5723 (prev.fetchpatch2 { url = "https://github.com/pluiedev/jj/commit/daa88d4dd485ed0c188023d2af8f811fd4db4a14.patch"; hash = "sha256-F8fp+LXQwuFVVVnYHJAEaQ9dFr6z9tdCkmcKDC39mM8="; @@ -15,4 +15,13 @@ _: prev: { ]; doCheck = false; }; + + # TODO: Remove when nixpkgs#473189 is available in unstable + vicinae = final.runCommand "vicinae-patched" { } '' + mkdir -p $out + cp -r ${prev.vicinae}/* $out + substituteInPlace $out/share/systemd/user/vicinae.service \ + --replace-fail "/bin/kill" "${final.lib.getExe' final.coreutils "kill"}" \ + --replace-fail "vicinae" "$out/bin/vicinae" + ''; } diff --git a/systems/common.nix b/systems/common.nix index 30614b3..9e7e302 100644 --- a/systems/common.nix +++ b/systems/common.nix @@ -71,14 +71,5 @@ algorithm = "zstd"; }; - system = { - # thanks to @getchoo - autoUpgrade = { - enable = true; - flake = "git+https://tangled.sh/@pluie.me/flake#${config.networking.hostName}"; - flags = [ "--refresh" ]; - }; - - configurationRevision = inputs.self.rev or inputs.self.dirtyRev or "unknown-dirty"; - }; + system.configurationRevision = inputs.self.rev or inputs.self.dirtyRev or "unknown-dirty"; } diff --git a/systems/focaccia/default.nix b/systems/focaccia/default.nix index f4c1725..707d53f 100644 --- a/systems/focaccia/default.nix +++ b/systems/focaccia/default.nix @@ -1,15 +1,32 @@ { + lib, + utils, ... }: +let + settings = { + + }; +in { imports = [ ../common.nix ./hardware-configuration.nix ./networking.nix + ../../modules/nixos/hysteria.nix ]; - networking.hostName = "focaccia"; - networking.domain = ""; + networking = { + hostName = "focaccia"; + domain = "pluie.me"; + firewall = { + allowedUDPPorts = [ 53 ]; + allowedTCPPorts = [ + 80 + 443 + ]; + }; + }; users.users.leah = { enable = true; @@ -26,9 +43,9 @@ }; services.openssh = { - enable = true; - ports = [ 42069 ]; - settings.PermitRootLogin = "prohibit-password"; + enable = true; + ports = [ 42069 ]; + settings.PermitRootLogin = "prohibit-password"; }; programs.mosh = { @@ -39,4 +56,31 @@ users.users.root.openssh.authorizedKeys.keys = [ ''ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKbsavGX9rGRx5R+7ovLn+r7D/w3zkbqCik4bS31moSz'' ]; + + boot.kernel.sysctl = { + "net.core.rmem_max" = 16777216; + "net.core.wmem_max" = 16777216; + }; + + services.hysteria = { + enable = true; + settings = { + listen = ":53"; + acme = { + domains = [ "focaccia.pluie.me" ]; + email = "srv@acc.pluie.me"; + }; + auth = { + type = "password"; + password._secret = "/var/lib/hysteria/passwd"; + }; + masquerade = { + type = "proxy"; + proxy = { + url = "https://news.ycombinator.com/"; + rewriteHost = true; + }; + }; + }; + }; } diff --git a/systems/laptop.nix b/systems/laptop.nix index 6a7d0be..21f0248 100644 --- a/systems/laptop.nix +++ b/systems/laptop.nix @@ -15,7 +15,7 @@ nix.settings.extra-platforms = [ "aarch64-linux" ]; boot = { - kernelPackages = pkgs.linuxPackages_xanmod_latest; + kernelPackages = pkgs.linuxPackages_xanmod; loader = { limine = { diff --git a/users/leah/appearance.nix b/users/leah/appearance.nix index 551a3a4..1d04fff 100644 --- a/users/leah/appearance.nix +++ b/users/leah/appearance.nix @@ -39,6 +39,7 @@ in ]; ext.programs.moor.settings.style = "catppuccin-${flavor}"; + ext.programs.vicinae.settings.theme = "catppuccin-${flavor}"; }; programs.vivid = { diff --git a/users/leah/presets/niri/config.kdl b/users/leah/presets/niri/config.kdl index 7e55b1a..7a12b91 100644 --- a/users/leah/presets/niri/config.kdl +++ b/users/leah/presets/niri/config.kdl @@ -131,10 +131,12 @@ layer-rule { place-within-backdrop true } -// Fuzzel +// Fuzzel/Vicinae layer-rule { match namespace="launcher" + match namespace="vicinae" baba-is-float true + shadow { on } @@ -154,9 +156,10 @@ window-rule { } } +// Allow terminal background to be transparent window-rule { match app-id="com.mitchellh.ghostty" - // Allow terminal background to be transparent + match title=r#"^Vicinae"# draw-border-with-background false } @@ -175,7 +178,7 @@ binds { // Suggested binds for running programs: terminal, app launcher, screen locker. Mod+T repeat=false { spawn "ghostty" "+new-window"; } - Super+D repeat=false { spawn "bash" "-c" "pkill fuzzel || fuzzel"; } + Super+D repeat=false { spawn "vicinae" "toggle"; } Super+Alt+L { spawn "swaylock"; } XF86AudioRaiseVolume allow-when-locked=true { spawn "swayosd-client" "--output-volume=raise"; } @@ -355,6 +358,7 @@ window-rule { window-rule { match at-startup=true app-id="steam" match app-id=r#"^steam_app_"# + open-on-workspace "gaming" } window-rule { @@ -363,3 +367,14 @@ window-rule { // Never allow notifications steal focus open-focused false } + +debug { + // Some apps are very naughty with xdg-activation. + // Then again, the protocol isn't really well-designed in the first place. + // + // Hall of Shame: + // - Telegram + // - Discord + // - 1Password + honor-xdg-activation-with-invalid-serial +} diff --git a/users/leah/presets/niri/default.nix b/users/leah/presets/niri/default.nix index c7692db..7e5801b 100644 --- a/users/leah/presets/niri/default.nix +++ b/users/leah/presets/niri/default.nix @@ -71,31 +71,19 @@ }; }; - rum.programs.fuzzel = { + ext.programs.vicinae = { enable = true; - - settings.main = { - font = "Sans:size=14"; - use-bold = true; - show-actions = true; - match-counter = true; - - # Make Fuzzel take on-demand focus - keyboard-focus = "on-demand"; - - lines = 8; - width = 35; - y-margin = 8; - horizontal-pad = 20; - vertical-pad = 16; - inner-pad = 8; - anchor = "bottom"; - layer = "top"; - }; - - settings.border = { - radius = 8; - width = 2; + settings = { + closeOnFocusLoss = false; + considerPreedit = true; + font.size = 12; + keybinding = "default"; + popToRootOnClose = true; + window = { + csd = true; + opacity = 0.85; + rounding = 16; + }; }; }; }; diff --git a/users/leah/presets/niri/swayosd/default.nix b/users/leah/presets/niri/swayosd/default.nix index d280c6e..60f56de 100644 --- a/users/leah/presets/niri/swayosd/default.nix +++ b/users/leah/presets/niri/swayosd/default.nix @@ -27,8 +27,12 @@ in systemd.services.swayosd-server = { after = [ "graphical-session.target" ]; wantedBy = [ "graphical-session.target" ]; - serviceConfig.ExecStart = lib.getExe' swayosd "swayosd-server"; restartTriggers = [ swayosd ]; + serviceConfig = { + ExecStart = lib.getExe' swayosd "swayosd-server"; + Restart = "always"; + RestartSec = 60; + }; }; }; } diff --git a/users/leah/presets/niri/waybar/default.nix b/users/leah/presets/niri/waybar/default.nix index db19474..0a65668 100644 --- a/users/leah/presets/niri/waybar/default.nix +++ b/users/leah/presets/niri/waybar/default.nix @@ -5,7 +5,6 @@ let jsonFormat = pkgs.formats.json { }; config = import ./config.nix args; - configFile = jsonFormat.generate "waybar-config.jsonc" config; in { hjem.users.leah = { @@ -14,7 +13,7 @@ in xdg.config.files = { "waybar/style.css".source = ./style.css; - "waybar/config.jsonc".source = configFile; + "waybar/config.jsonc".source = jsonFormat.generate "waybar-config.jsonc" config; }; }; } diff --git a/users/leah/programs/default.nix b/users/leah/programs/default.nix index 43c7a1e..cdd5519 100644 --- a/users/leah/programs/default.nix +++ b/users/leah/programs/default.nix @@ -1,4 +1,5 @@ { + config, inputs, pkgs, lib, @@ -40,6 +41,11 @@ papers wechat + (pkgs.makeAutostartItem { + name = "throne"; + inherit (config.programs.throne) package; + }) + # Command-line apps just nix-output-monitor