From 0dc4322955cf121c7cd2da2f21365444489ee0ef Mon Sep 17 00:00:00 2001 From: xfeusw Date: Sun, 21 Sep 2025 16:21:06 +0500 Subject: [PATCH 01/21] removed arc-menu --- .../desktop/dconf/extensions/arc-menu.nix | 58 ------------------- 1 file changed, 58 deletions(-) delete mode 100644 home/xfeusw/desktop/dconf/extensions/arc-menu.nix diff --git a/home/xfeusw/desktop/dconf/extensions/arc-menu.nix b/home/xfeusw/desktop/dconf/extensions/arc-menu.nix deleted file mode 100644 index e3bce95..0000000 --- a/home/xfeusw/desktop/dconf/extensions/arc-menu.nix +++ /dev/null @@ -1,58 +0,0 @@ -# home/xfeusw/desktop/dconf/extensions/arc-menu.nix -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/arc-menu" = { - # General settings - menu-layout = "Windows"; # Use a Windows-like menu layout (grid with pinned apps) - menu-height = 600; # Menu height in pixels - menu-width = 450; # Menu width in pixels - show-categories = true; # Show application categories - show-quicklinks = true; # Show quick links (Home, Documents, etc.) - category-icon-size = 24; # Size of category icons - app-icon-size = 32; # Size of application icons - override-menu-theme = true; # Allow custom theming - - # Menu button customization - menu-button-position = "Panel"; # Place button in panel (compatible with dash-to-panel) - menu-button-icon = "System"; # Use default system icon (e.g., GNOME logo) - menu-button-text = "Menu"; # Text for the menu button - menu-button-icon-size = 20; # Menu button icon size - show-menu-button-arrow = false; # Hide the arrow next to the button - - # Hotkeys and behavior - enable-menu-hotkey = true; # Enable hotkey - menu-hotkey = ""; # Open menu with Super key - open-on-hover = false; # Disable hover to open (prevents accidental triggers) - menu-button-click-action = "Menu"; # Clicking button opens menu - - # Search settings - searchbar-default-top = true; # Place search bar at the top - searchbar-expanded = true; # Keep search bar expanded - searchbar-icon-size = 24; # Icon size in search results - search-provider = true; # Enable external search providers - - # Pinned applications - pinned-apps = [ - "firefox.desktop" - "org.gnome.Nautilus.desktop" - "com.mitchellh.ghostty.desktop" - "code.desktop" - "spotify.desktop" - "org.telegram.desktop.desktop" - "dev.zed.Zed.desktop" - ]; # Match your favorite-apps from shell.nix - - # Advanced features - show-power-options = true; # Show power options in menu - show-user-icon = true; # Show user avatar - enable-vertical-separator = true; # Add separator between sections - - # Theming to match Adwaita-dark - menu-background-color = "#1e1e2e"; # Dark background to match Adwaita-dark - menu-foreground-color = "#c0caf5"; # Light text/icons to match your Ghostty theme - menu-border-radius = 10; # Rounded corners - menu-opacity = 0.95; # Slightly transparent menu - }; - }; -} From b73985f8214b43c62a40b8869ac81713b23a910d Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 01:32:57 +0500 Subject: [PATCH 02/21] extensions update --- flake.lock | 159 +++++++++++++++--- flake.nix | 113 +++++++------ .../desktop/dconf/extensions/caffeine.nix | 9 - .../desktop/dconf/extensions/default.nix | 9 +- .../desktop/dconf/extensions/gsconnect.nix | 9 - 5 files changed, 208 insertions(+), 91 deletions(-) delete mode 100644 home/xfeusw/desktop/dconf/extensions/caffeine.nix delete mode 100644 home/xfeusw/desktop/dconf/extensions/gsconnect.nix diff --git a/flake.lock b/flake.lock index b5a9357..9aea636 100644 --- a/flake.lock +++ b/flake.lock @@ -1,8 +1,23 @@ { "nodes": { + "flake-compat": { + "locked": { + "lastModified": 1746162366, + "narHash": "sha256-5SSSZ/oQkwfcAz/o/6TlejlVGqeK08wyREBQ5qFFPhM=", + "owner": "nix-community", + "repo": "flake-compat", + "rev": "0f158086a2ecdbb138cd0429410e44994f1b7e4b", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "flake-compat", + "type": "github" + } + }, "flake-parts": { "inputs": { - "nixpkgs-lib": "nixpkgs-lib" + "nixpkgs-lib": "nixpkgs-lib_2" }, "locked": { "lastModified": 1741352980, @@ -79,6 +94,24 @@ "type": "github" } }, + "flake-utils_2": { + "inputs": { + "systems": "systems_2" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, "home-manager": { "inputs": { "nixpkgs": [ @@ -86,11 +119,11 @@ ] }, "locked": { - "lastModified": 1757808926, - "narHash": "sha256-K6PEI5PYY94TVMH0mX3MbZNYFme7oNRKml/85BpRRAo=", + "lastModified": 1758313341, + "narHash": "sha256-SsI6INUzWwPcRKRaxvi50RttnD9rcC4EjV+67TOEfrQ=", "owner": "nix-community", "repo": "home-manager", - "rev": "f21d9167782c086a33ad53e2311854a8f13c281e", + "rev": "6f656618ebc71ca82d93d306a8aecb2c5f6f2ab2", "type": "github" }, "original": { @@ -130,6 +163,25 @@ "type": "github" } }, + "lib-aggregate": { + "inputs": { + "flake-utils": "flake-utils", + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1754828166, + "narHash": "sha256-i7c+fpXVsnvj2+63Gl3YfU1hVyxbLeqeFj55ZBZACWI=", + "owner": "nix-community", + "repo": "lib-aggregate", + "rev": "f01c8d121a3100230612be96e4ac668e15eafb77", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "lib-aggregate", + "type": "github" + } + }, "nixos-hardware": { "locked": { "lastModified": 1757943327, @@ -148,11 +200,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1757941119, - "narHash": "sha256-TssJZFzMRYdWgpHySzKv4YQg6DUv5SDENiWbVgNTo0M=", + "lastModified": 1758346548, + "narHash": "sha256-afXE7AJ7MY6wY1pg/Y6UPHNYPy5GtUKeBkrZZ/gC71E=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "7ff837017c3b82bd3671932599a119d7bc672ff0", + "rev": "b2a3852bd078e68dd2b3dfa8c00c67af1f0a7d20", "type": "github" }, "original": { @@ -163,6 +215,21 @@ } }, "nixpkgs-lib": { + "locked": { + "lastModified": 1754788789, + "narHash": "sha256-x2rJ+Ovzq0sCMpgfgGaaqgBSwY+LST+WbZ6TytnT9Rk=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "a73b9c743612e4244d865a2fdee11865283c04e6", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, + "nixpkgs-lib_2": { "locked": { "lastModified": 1740877520, "narHash": "sha256-oiwv/ZK/2FhGxrCkQkB83i7GnWXPPLzoqFHpDD3uYpk=", @@ -179,11 +246,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1757745802, - "narHash": "sha256-hLEO2TPj55KcUFUU1vgtHE9UEIOjRcH/4QbmfHNF820=", + "lastModified": 1758277210, + "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "c23193b943c6c689d70ee98ce3128239ed9e32d1", + "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", "type": "github" }, "original": { @@ -193,7 +260,43 @@ "type": "github" } }, + "nixpkgs-wayland": { + "inputs": { + "flake-compat": "flake-compat", + "lib-aggregate": "lib-aggregate", + "nixpkgs": "nixpkgs_2" + }, + "locked": { + "lastModified": 1758372772, + "narHash": "sha256-9HMoc7wMbC9ZZjB8nPAyXTzaxHJRjnir5SM7G4jg+tQ=", + "owner": "nix-community", + "repo": "nixpkgs-wayland", + "rev": "faa8596885fbcd162a504fe7e27158f0ad8fc43a", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs-wayland", + "type": "github" + } + }, "nixpkgs_2": { + "locked": { + "lastModified": 1758277210, + "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_3": { "locked": { "lastModified": 1742800061, "narHash": "sha256-oDJGK1UMArK52vcW9S5S2apeec4rbfNELgc50LqiPNs=", @@ -209,13 +312,13 @@ "type": "github" } }, - "nixpkgs_3": { + "nixpkgs_4": { "locked": { - "lastModified": 1757745802, - "narHash": "sha256-hLEO2TPj55KcUFUU1vgtHE9UEIOjRcH/4QbmfHNF820=", + "lastModified": 1758277210, + "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", "owner": "nixos", "repo": "nixpkgs", - "rev": "c23193b943c6c689d70ee98ce3128239ed9e32d1", + "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", "type": "github" }, "original": { @@ -228,7 +331,7 @@ "nixvim": { "inputs": { "flake-parts": "flake-parts_2", - "nixpkgs": "nixpkgs_2", + "nixpkgs": "nixpkgs_3", "nuschtosSearch": "nuschtosSearch" }, "locked": { @@ -270,14 +373,14 @@ "nur": { "inputs": { "flake-parts": "flake-parts_3", - "nixpkgs": "nixpkgs_3" + "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1758116403, - "narHash": "sha256-18H1k7Prk8vC5hhy8cRd7PeOEr8xdC15Ke/w+ftgnS4=", + "lastModified": 1758433715, + "narHash": "sha256-HJoS2meEamJ8ygcLDYPcGugbmpiGk+zdhW6mVRoL5DE=", "owner": "nix-community", "repo": "NUR", - "rev": "75db73fa583b779c4605e963ff27238f3515e89f", + "rev": "86f5d2efe861e4fa2a9e3823d621c5ed7ecfb56f", "type": "github" }, "original": { @@ -288,7 +391,7 @@ }, "nuschtosSearch": { "inputs": { - "flake-utils": "flake-utils", + "flake-utils": "flake-utils_2", "ixx": "ixx", "nixpkgs": [ "nixvim-config", @@ -316,6 +419,7 @@ "nixos-hardware": "nixos-hardware", "nixpkgs": "nixpkgs", "nixpkgs-unstable": "nixpkgs-unstable", + "nixpkgs-wayland": "nixpkgs-wayland", "nixvim-config": "nixvim-config", "nur": "nur" } @@ -334,6 +438,21 @@ "repo": "default", "type": "github" } + }, + "systems_2": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } } }, "root": "root", diff --git a/flake.nix b/flake.nix index 58f55c8..c45ac9e 100644 --- a/flake.nix +++ b/flake.nix @@ -5,6 +5,7 @@ inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable"; + nixpkgs-wayland.url = "github:nix-community/nixpkgs-wayland"; home-manager = { url = "github:nix-community/home-manager/release-25.05"; @@ -24,67 +25,85 @@ }; }; - outputs = - { - nixpkgs, - nixpkgs-unstable, - home-manager, - nixos-hardware, - nur, - nixvim-config, - ... - }: - { - nixosConfigurations = { - acer = nixpkgs.lib.nixosSystem { - system = "x86_64-linux"; - specialArgs = { - inputs = { - inherit - nixpkgs - nixpkgs-unstable - home-manager - nixos-hardware - nur - nixvim-config - ; - }; + outputs = { + nixpkgs, + nixpkgs-unstable, + nixpkgs-wayland, + home-manager, + nixos-hardware, + nur, + nixvim-config, + ... + }: { + nixosConfigurations = { + acer = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + specialArgs = { + inputs = { inherit nixpkgs nixpkgs-unstable + nixpkgs-wayland home-manager nixos-hardware nur nixvim-config ; }; - modules = [ - ./hosts/acer/configuration.nix - nur.modules.nixos.default - ]; + inherit + nixpkgs + nixpkgs-unstable + nixpkgs-wayland + home-manager + nixos-hardware + nur + nixvim-config + ; }; - }; + modules = [ + ./hosts/acer/configuration.nix + nur.modules.nixos.default + # Inject nixpkgs-wayland overlay + Cachix cache + { + nixpkgs.overlays = [nixpkgs-wayland.overlay]; - homeConfigurations = { - xfeusw = home-manager.lib.homeManagerConfiguration { - pkgs = nixpkgs.legacyPackages.x86_64-linux; - extraSpecialArgs = { - inherit - nixpkgs - nixpkgs-unstable - nixvim-config - nur - ; - unstable = import nixpkgs-unstable { - system = "x86_64-linux"; - config.allowUnfree = true; + nix.settings = { + substituters = [ + "https://cache.nixos.org/" + "https://nixpkgs-wayland.cachix.org" + ]; + trusted-public-keys = [ + "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "nixpkgs-wayland.cachix.org-1:4f5VsYvpWm4VE/KJioPp6TcbRZ3PgCWvu5Zf+HjMZ9o=" + ]; }; + } + ]; + }; + }; + + homeConfigurations = { + xfeusw = home-manager.lib.homeManagerConfiguration { + pkgs = nixpkgs.legacyPackages.x86_64-linux; + extraSpecialArgs = { + inherit + nixpkgs + nixpkgs-unstable + nixpkgs-wayland + nixvim-config + nur + ; + unstable = import nixpkgs-unstable { + system = "x86_64-linux"; + config.allowUnfree = true; }; - modules = [ - ./home/xfeusw/home.nix - nur.modules.homeManager.default - ]; }; + modules = [ + ./home/xfeusw/home.nix + nur.modules.homeManager.default + {nixpkgs.overlays = [nixpkgs-wayland.overlay];} + ]; }; }; + }; } diff --git a/home/xfeusw/desktop/dconf/extensions/caffeine.nix b/home/xfeusw/desktop/dconf/extensions/caffeine.nix deleted file mode 100644 index 674ec8b..0000000 --- a/home/xfeusw/desktop/dconf/extensions/caffeine.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/caffeine" = { - show-indicator = true; - toggle-state = false; - }; - }; -} diff --git a/home/xfeusw/desktop/dconf/extensions/default.nix b/home/xfeusw/desktop/dconf/extensions/default.nix index cf27176..a99546b 100644 --- a/home/xfeusw/desktop/dconf/extensions/default.nix +++ b/home/xfeusw/desktop/dconf/extensions/default.nix @@ -1,18 +1,15 @@ { ... }: { imports = [ - ./arc-menu.nix ./blur-my-shell.nix - ./caffeine.nix ./clipboard-indicator.nix + ./coverflow-alt-tab.nix ./dash-to-panel.nix ./date-menu-formatter.nix - ./gsconnect.nix + ./sound-output-device-chooser.nix ./tiling-assistant.nix + ./top-icons-plus.nix ./user-theme.nix ./vitals.nix - ./top-icons-plus.nix - ./sound-output-device-chooser.nix - ./coverflow-alt-tab.nix ]; } diff --git a/home/xfeusw/desktop/dconf/extensions/gsconnect.nix b/home/xfeusw/desktop/dconf/extensions/gsconnect.nix deleted file mode 100644 index 6f93cde..0000000 --- a/home/xfeusw/desktop/dconf/extensions/gsconnect.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/gsconnect" = { - show-indicators = true; - enabled = true; - }; - }; -} From a522b4da1ddd56d42ed40292819d14a7c1a89529 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 01:54:10 +0500 Subject: [PATCH 03/21] men pizdes bo'lganman --- .sops.yaml | 8 ++ flake.nix | 105 +++++++++++++++++-------- home/xfeusw/development/tools.nix | 80 +++++++++++++++---- home/xfeusw/shell/zsh.nix | 118 ++++++++++++++++++++-------- hosts/acer/configuration.nix | 60 +++++++++----- hosts/acer/secrets.yaml | 18 +++++ modules/nix-settings.nix | 87 ++++++++++----------- modules/performance.nix | 71 +++++++++++++++++ modules/security.nix | 126 +++++++++++++++++++++++++++--- 9 files changed, 517 insertions(+), 156 deletions(-) create mode 100644 .sops.yaml create mode 100644 hosts/acer/secrets.yaml create mode 100644 modules/performance.nix diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 0000000..9413368 --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,8 @@ +keys: + - &main_key age1nguz9mhgylxezcctn3c4qk8e6upes0c3s5n5mkdlpxdujham5fusd5xvy6 + +creation_rules: + - path_regex: hosts/.*/secrets\.yaml$ + key_groups: + - age: + - *main_key diff --git a/flake.nix b/flake.nix index c45ac9e..c7b36d1 100644 --- a/flake.nix +++ b/flake.nix @@ -1,4 +1,3 @@ -# flake.nix { description = "Enhanced NixOS configuration (flake) for acer"; @@ -7,6 +6,9 @@ nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs-wayland.url = "github:nix-community/nixpkgs-wayland"; + # Utils for cleaner code + flake-utils.url = "github:numtide/flake-utils"; + home-manager = { url = "github:nix-community/home-manager/release-25.05"; inputs.nixpkgs.follows = "nixpkgs"; @@ -18,14 +20,38 @@ # Additional useful inputs nur.url = "github:nix-community/NUR"; + # State management + impermanence.url = "github:nix-community/impermanence"; + + # Consistent theming + nix-colors.url = "github:misterio77/nix-colors"; + + # Firefox extensions + firefox-addons = { + url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + # Your personal nixvim configuration nixvim-config = { url = "github:Ahwxorg/nixvim-config"; inputs.nixpkgs.follows = "nixpkgs"; }; + + # Secrets management + sops-nix = { + url = "github:Mic92/sops-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + + # Hyprland (optional Wayland compositor) + hyprland = { + url = "git+https://github.com/hyprwm/Hyprland?submodules=1"; + inputs.nixpkgs.follows = "nixpkgs"; + }; }; - outputs = { + outputs = inputs @ { nixpkgs, nixpkgs-unstable, nixpkgs-wayland, @@ -33,48 +59,57 @@ nixos-hardware, nur, nixvim-config, + impermanence, + nix-colors, + firefox-addons, + sops-nix, + flake-utils, + hyprland, ... }: { nixosConfigurations = { acer = nixpkgs.lib.nixosSystem { system = "x86_64-linux"; specialArgs = { - inputs = { - inherit - nixpkgs - nixpkgs-unstable - nixpkgs-wayland - home-manager - nixos-hardware - nur - nixvim-config - ; - }; - inherit - nixpkgs - nixpkgs-unstable - nixpkgs-wayland - home-manager - nixos-hardware - nur - nixvim-config - ; + inherit inputs; + inherit nixpkgs-unstable nixpkgs-wayland; }; modules = [ ./hosts/acer/configuration.nix - nur.modules.nixos.default - # Inject nixpkgs-wayland overlay + Cachix cache + nixos-hardware.nixosModules.common-cpu-intel + nixos-hardware.nixosModules.common-pc-ssd + nixos-hardware.nixosModules.common-pc-laptop + nur.nixosModules.nur + sops-nix.nixosModules.sops + + # Global overlays { - nixpkgs.overlays = [nixpkgs-wayland.overlay]; + nixpkgs.overlays = [ + nixpkgs-wayland.overlay + nur.overlay + # Custom overlay for optimizations + (final: prev: { + unstable = import nixpkgs-unstable { + system = prev.system; + config.allowUnfree = true; + }; + }) + ]; nix.settings = { substituters = [ "https://cache.nixos.org/" "https://nixpkgs-wayland.cachix.org" + "https://nix-community.cachix.org" + "https://hyprland.cachix.org" + "https://nixpkgs-unfree.cachix.org" ]; trusted-public-keys = [ "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" "nixpkgs-wayland.cachix.org-1:4f5VsYvpWm4VE/KJioPp6TcbRZ3PgCWvu5Zf+HjMZ9o=" + "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" + "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc=" + "nixpkgs-unfree.cachix.org-1:hqvoInulhbV4nJ9yJOEr+4wxhDV4xq2d1DK7S6Nj6rs=" ]; }; } @@ -86,22 +121,24 @@ xfeusw = home-manager.lib.homeManagerConfiguration { pkgs = nixpkgs.legacyPackages.x86_64-linux; extraSpecialArgs = { - inherit - nixpkgs - nixpkgs-unstable - nixpkgs-wayland - nixvim-config - nur - ; + inherit inputs; + inherit nixpkgs-unstable nixpkgs-wayland nixvim-config nur nix-colors firefox-addons; unstable = import nixpkgs-unstable { system = "x86_64-linux"; config.allowUnfree = true; + overlays = [ nur.overlay ]; }; }; modules = [ ./home/xfeusw/home.nix - nur.modules.homeManager.default - {nixpkgs.overlays = [nixpkgs-wayland.overlay];} + nur.homeManagerModules.nur + nix-colors.homeManagerModules.default + { + nixpkgs.overlays = [ + nixpkgs-wayland.overlay + nur.overlay + ]; + } ]; }; }; diff --git a/home/xfeusw/development/tools.nix b/home/xfeusw/development/tools.nix index 2bf7723..2e494cb 100644 --- a/home/xfeusw/development/tools.nix +++ b/home/xfeusw/development/tools.nix @@ -2,59 +2,109 @@ { pkgs, ... }: { home.packages = with pkgs; [ + # Modern development tools + gitoxide # Faster git clone + delta # Better git diff + difftastic # Syntax-aware diff + just # Command runner + direnv # Environment management + cachix # Binary cache management + + # Nix-specific tools + nix-fast-build # Faster nix builds + nix-update # Update nix packages + nurl # Generate nix URLs + + # Enhanced CLI tools + bat # Better cat + eza # Better ls + fd # Better find + ripgrep # Better grep + zoxide # Smart cd + fzf # Fuzzy finder + btop # Better top + dust # Better du + procs # Better ps + hyperfine # Benchmarking + tokei # Code statistics + # Build tools gcc cmake gnumake pkg-config + meson + ninja - # Debuggers + # Debuggers and profilers gdb valgrind + lldb + perf-tools + flamegraph # Version control git-lfs gh lazygit gitui + git-absorb - # Container tools + # Container and orchestration tools docker-compose podman-compose kubectl k9s helm + dive # Docker image analyzer + ctop # Container top # Database tools sqlite postgresql_16 + redis + dbeaver-bin - # API tools + # API and network tools httpie curl wget + postman + insomnia # Documentation mdbook - - # Performance tools - hyperfine # Benchmarking - flamegraph # Profiling - - # Network tools - nmap - wireshark - tcpdump + hugo # Text processing - jq # JSON processor - yq # YAML processor + jq # JSON processor + yq # YAML processor + xmlstarlet # XML processor - # File tools + # System tools file tree unzip p7zip findutils + patchelf + binutils + + # Security tools + age # Encryption + sops # Secrets management + + # Monitoring + htop + iotop + nethogs + bandwhich ]; + + # Direnv integration + programs.direnv = { + enable = true; + enableZshIntegration = true; + nix-direnv.enable = true; + }; } diff --git a/home/xfeusw/shell/zsh.nix b/home/xfeusw/shell/zsh.nix index 9b47588..43ec47e 100644 --- a/home/xfeusw/shell/zsh.nix +++ b/home/xfeusw/shell/zsh.nix @@ -1,3 +1,4 @@ +# home/xfeusw/shell/zsh.nix { pkgs, ... }: { programs.zsh = { @@ -6,83 +7,113 @@ autosuggestion.enable = true; syntaxHighlighting.enable = true; - # History configuration history = { - size = 10000; - save = 10000; + size = 50000; + save = 50000; expireDuplicatesFirst = true; ignoreDups = true; ignoreSpace = true; + extended = true; }; - # Enhanced aliases shellAliases = { # Modern CLI tools - ls = "eza --color=auto --icons"; - ll = "eza -la --color=auto --icons"; - la = "eza -la --color=auto --icons"; + ls = "eza --color=auto --icons --group-directories-first"; + ll = "eza -la --color=auto --icons --group-directories-first"; + la = "eza -la --color=auto --icons --group-directories-first"; tree = "eza --tree --icons"; - cat = "bat"; - find = "fd"; + cat = "bat --paging=never"; grep = "rg"; - - # System shortcuts - ".." = "cd .."; - "..." = "cd ../.."; - "...." = "cd ../../.."; + find = "fd"; + du = "dust"; + df = "dust"; + top = "btop"; + ps = "procs"; # Git shortcuts g = "git"; - gs = "git status"; + gs = "git status -sb"; ga = "git add"; + gaa = "git add --all"; gc = "git commit"; + gcm = "git commit -m"; gp = "git push"; - gl = "git pull"; + gpl = "git pull"; gd = "git diff"; + gdc = "git diff --cached"; + gl = "git log --oneline --graph --decorate"; + gla = "git log --oneline --graph --decorate --all"; # NixOS management check = "nix flake check"; sys-build = "sudo nixos-rebuild build --flake /home/xfeusw/.config/nix#acer"; + sys-switch = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer"; sys-update = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer --upgrade"; home-build = "home-manager build --flake /home/xfeusw/.config/nix#xfeusw"; - home-update = "home-manager switch --flake /home/xfeusw/.config/nix#xfeusw"; - nix-clean = "sudo nix-collect-garbage -d && nix-collect-garbage -d && home-manager expire-generations 0 && sudo nix-store --optimise && sudo nix-collect-garbage && nix-collect-garbage"; + home-switch = "home-manager switch --flake /home/xfeusw/.config/nix#xfeusw"; + nix-clean = "sudo nix-collect-garbage -d && nix-collect-garbage -d && home-manager expire-generations 0 && sudo nix-store --optimise"; + nix-search = "nix search nixpkgs"; - # System monitoring - top = "btop"; - df = "dust"; - ps = "procs"; + # Development shortcuts + dev = "nix develop"; + run = "nix run"; + shell = "nix shell"; + + # System shortcuts + ".." = "cd .."; + "..." = "cd ../.."; + "...." = "cd ../../.."; # Quick navigation config = "cd ~/.config"; nix-config = "cd ~/.config/nix"; + + # Docker/Podman + docker = "podman"; + + # System info + temp = "sensors"; + ports = "ss -tuln"; }; - # Enhanced initialization - initContent = '' - # Initialize zoxide (smart cd) + initExtraFirst = '' + # Performance: only load what's needed + skip_global_compinit=1 + ''; + + initExtra = '' + # Initialize tools eval "$(zoxide init zsh)" + eval "$(direnv hook zsh)" + + # FZF configuration + export FZF_DEFAULT_COMMAND='fd --type f --hidden --follow --exclude .git' + export FZF_CTRL_T_COMMAND="$FZF_DEFAULT_COMMAND" + export FZF_ALT_C_COMMAND='fd --type d --hidden --follow --exclude .git' + export FZF_DEFAULT_OPTS='--height 40% --layout=reverse --border --preview="bat --color=always --style=header,grid --line-range :300 {}"' - # FZF integration source ${pkgs.fzf}/share/fzf/key-bindings.zsh source ${pkgs.fzf}/share/fzf/completion.zsh # Custom functions - mkcd() { - mkdir -p "$1" && cd "$1" - } + mkcd() { mkdir -p "$1" && cd "$1" } # Quick system info sysinfo() { echo "System: $(uname -sr)" + echo "Host: $(hostname)" echo "Uptime: $(uptime -p)" echo "Memory: $(free -h | grep '^Mem:' | awk '{print $3 "/" $2}')" echo "Disk: $(df -h / | tail -1 | awk '{print $3 "/" $2 " (" $5 ")"}')" + echo "CPU: $(lscpu | grep 'Model name' | sed 's/Model name: *//')" + if command -v sensors >/dev/null 2>&1; then + echo "Temp: $(sensors | grep 'Core 0' | awk '{print $3}' | head -1)" + fi } # Extract any archive extract() { - if [ -f $1 ] ; then + if [[ -f $1 ]]; then case $1 in *.tar.bz2) tar xjf $1 ;; *.tar.gz) tar xzf $1 ;; @@ -95,12 +126,31 @@ *.zip) unzip $1 ;; *.Z) uncompress $1 ;; *.7z) 7z x $1 ;; - *) echo "'$1' cannot be extracted via extract()" ;; + *.xz) unxz $1 ;; + *.lzma) unlzma $1 ;; + *) echo "'$1' cannot be extracted via extract()" ;; esac else echo "'$1' is not a valid file" fi } + + # Nix helpers + nix-which() { readlink -f $(which $1) } + nix-locate() { nix-index --locate "$1" } + + # Git helpers + git-clean-branches() { + git branch --merged | grep -v "\*\|main\|master\|develop" | xargs -r git branch -d + } + + # Performance monitoring + mem-top() { ps aux --sort=-%mem | head } + cpu-top() { ps aux --sort=-%cpu | head } + + # Network helpers + myip() { curl -s ifconfig.me && echo } + ports() { ss -tuln } ''; oh-my-zsh = { @@ -112,9 +162,11 @@ "history" "colored-man-pages" "command-not-found" + "extract" + "z" + "direnv" ]; - # We'll use Starship instead of oh-my-zsh themes - theme = ""; + theme = ""; # Using Starship instead }; }; } diff --git a/hosts/acer/configuration.nix b/hosts/acer/configuration.nix index 0cb0688..a38dec8 100644 --- a/hosts/acer/configuration.nix +++ b/hosts/acer/configuration.nix @@ -9,50 +9,68 @@ ../../modules/networking.nix ../../modules/users.nix ../../modules/security.nix - ../../modules/power.nix + ../../modules/performance.nix ../../modules/backup.nix # Desktop environment ../../modules/desktop/gnome.nix - # Modular imports (new structure) - ../../modules/packages # All package categories - ../../modules/hardware # All hardware configurations - ../../modules/services # All services - ../../modules/virtualization # All virtualization - - # Hardware-specific (uncomment as needed) - # inputs.nixos-hardware.nixosModules.common-cpu-intel - # inputs.nixos-hardware.nixosModules.common-pc-ssd + # Modular imports + ../../modules/packages + ../../modules/hardware + ../../modules/services + ../../modules/virtualization ]; # Bootloader with enhanced options boot = { loader = { - systemd-boot.enable = true; + systemd-boot = { + enable = true; + configurationLimit = 10; # Limit boot entries + editor = false; # Security: disable boot editor + }; efi.canTouchEfiVariables = true; - timeout = 3; + timeout = 2; # Reduced timeout }; # Kernel optimizations kernelParams = [ "quiet" "splash" - "mitigations=off" # Better performance, slightly less security + "loglevel=3" + "systemd.show_status=auto" + "rd.udev.log_level=3" ]; - kernel.sysctl = { - "vm.swappiness" = 10; - "vm.dirty_ratio" = 5; - "vm.dirty_background_ratio" = 2; - "net.core.rmem_max" = 16777216; - "net.core.wmem_max" = 16777216; - }; + # Faster boot + initrd.verbose = false; + consoleLogLevel = 0; + kernelModules = [ "tcp_bbr" ]; # Better congestion control }; # Timezone and localization time.timeZone = "Asia/Samarkand"; - i18n.defaultLocale = "en_US.UTF-8"; + i18n = { + defaultLocale = "en_US.UTF-8"; + supportedLocales = [ + "en_US.UTF-8/UTF-8" + "ru_RU.UTF-8/UTF-8" + ]; + }; + + # Secrets management + sops = { + defaultSopsFile = ./secrets.yaml; + age.keyFile = "/home/xfeusw/.config/sops/age/keys.txt"; + secrets = { + user-password.neededForUsers = true; + restic-password = { + owner = "root"; + mode = "0600"; + }; + }; + }; # NixOS compatibility version system.stateVersion = "25.05"; diff --git a/hosts/acer/secrets.yaml b/hosts/acer/secrets.yaml new file mode 100644 index 0000000..9abd3df --- /dev/null +++ b/hosts/acer/secrets.yaml @@ -0,0 +1,18 @@ +#ENC[AES256_GCM,data:WOcPzh2q5Rj+0SsyT/6CEATa7no725Tv7Ny5coWkCK73BPxfdFXuL3PafaaoVaLCeQ8KWMRkHrAipLD3y1k=,iv:pxviRe8MZqF8C2KMTkdVH0+gBcZiW855opqr+CcHtOM=,tag:fB8Ma7mLilG1I9b7Rj1tQQ==,type:comment] +user-password: ENC[AES256_GCM,data:PwK2ew==,iv:19jj11aN1zPspUEGYuzPV6J4FRJEFwT3mRFW9HIOgoc=,tag:TMGCwyaLuj+NdFOCMZIrIw==,type:int] +restic-password: ENC[AES256_GCM,data:n/w7Ng==,iv:4B37Pn9VtYUai6t8zNvi9aogXpuZf2mSVUOs/9QRlyw=,tag:NWWtYa6RzbNtSAp9g8GZCg==,type:int] +sops: + age: + - recipient: age1nguz9mhgylxezcctn3c4qk8e6upes0c3s5n5mkdlpxdujham5fusd5xvy6 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBkbmZlRmlFMksvY2pobjVy + SmxXdE5icjhFZWdZbU82L3RLc3dVRkxjQVc4CjJFNlphZXRoN0lkZXpSWC9EMkdK + Z2JGVWVydENWQVJ3dHUySnc5ek91b2sKLS0tIHBuTjFHeXJCTkhNbEJZNkVweG5D + d2hPOXA2TloveXROWDY4ZXpLSTFpZkEK0S44jS/4JzvJ9lh0yVJQhL3YdDdcZGJm + WQFW50AiqLYoG+RODaQkbVABLqfq0AmqpiCPCQT9qsrbFfPe1elSHw== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2025-09-21T20:52:25Z" + mac: ENC[AES256_GCM,data:8S7gaVk1DXSWLYC3m4ErSEmhh6ClggL/18E0wrrY8EAV0mYlCUlBuNuysJyc2AfUZSEqMmCEIqSQvjuVGMVuCOCftsJXeZvUoyEuY1pH4Pd02Rj30DhdQt5Hr2Eq1WGVbmIOGJjqaRk4s6IwPL41raMgozvYT/v1q/IhKLn1f0U=,iv:oqHDy9cKLD8BnlTxdgoByo6zGGOmRX2Ym4rFDNUbpWU=,tag:3Afrf+bCLkKmPU197lJ6dA==,type:str] + unencrypted_suffix: _unencrypted + version: 3.10.2 diff --git a/modules/nix-settings.nix b/modules/nix-settings.nix index 80cbc11..56969a9 100644 --- a/modules/nix-settings.nix +++ b/modules/nix-settings.nix @@ -1,5 +1,5 @@ # modules/nix-settings.nix -{ inputs, ... }: +{ ... }: { nixpkgs.config.allowUnfree = true; @@ -8,63 +8,62 @@ experimental-features = [ "nix-command" "flakes" + "ca-derivations" + "auto-allocate-uids" ]; + auto-optimise-store = true; builders-use-substitutes = true; + warn-dirty = false; - # Increase download buffer size to prevent warnings - download-buffer-size = 134217728; # 128 MB (default is 64 MB) + # Performance optimizations + max-jobs = "auto"; + cores = 0; # Use all available cores + download-buffer-size = 134217728; # 128 MB - # Substituters for faster builds - substituters = [ - "https://cache.nixos.org/" - "https://nix-community.cachix.org" - "https://nixpkgs-unfree.cachix.org" - ]; + # Build optimization + connect-timeout = 5; + stalled-download-timeout = 90; - trusted-public-keys = [ - "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" - "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" - "nixpkgs-unfree.cachix.org-1:hqvoInulhbV4nJ9yJOEr+4wxhDV4xq2d1DK7S6Nj6rs=" - ]; + # Sandbox settings + sandbox = true; + restrict-eval = true; + + # Trusted users + trusted-users = [ "root" "@wheel" ]; }; - # More aggressive garbage collection + # Optimized garbage collection gc = { automatic = true; dates = "daily"; - options = "--delete-older-than 3d --max-freed 15G"; + options = "--delete-older-than 7d --max-freed 15G"; + persistent = true; }; - }; - # Expose unstable as pkgs.unstable - nixpkgs.overlays = [ - (final: prev: { - unstable = import inputs.nixpkgs-unstable { - system = prev.system; - config = prev.config; - }; - }) - ]; + # Store optimization + optimise = { + automatic = true; + dates = [ "weekly" ]; + }; - # Automatic upgrades from this flake - system.autoUpgrade = { - enable = true; - flake = "/home/xfeusw/.config/nix"; - flags = [ - "--update-input" - "nixpkgs" - "--update-input" - "nixpkgs-unstable" - "--commit-lock-file" - ]; - dates = "03:00"; - randomizedDelaySec = "45min"; + # Nix daemon settings + daemonCPUSchedPolicy = "batch"; + daemonIOSchedClass = 2; + daemonIOSchedPriority = 7; }; - # Enable ZRAM for memory compression - zramSwap = { - enable = true; - memoryPercent = 50; - }; + # Enable flakes and new nix command globally + environment.systemPackages = with pkgs; [ + nixpkgs-fmt + alejandra + nil + nixd + nix-tree + nix-du + nix-index + nix-output-monitor + cachix + nix-fast-build + ]; } diff --git a/modules/performance.nix b/modules/performance.nix new file mode 100644 index 0000000..64170c1 --- /dev/null +++ b/modules/performance.nix @@ -0,0 +1,71 @@ +# modules/performance.nix +{ ... }: +{ + # Memory and swap optimization + zramSwap = { + enable = true; + memoryPercent = 25; # Reduced from 50% + algorithm = "zstd"; # Better compression + }; + + # Kernel optimizations for performance + boot.kernel.sysctl = { + # Memory management + "vm.swappiness" = 1; + "vm.dirty_ratio" = 3; + "vm.dirty_background_ratio" = 1; + "vm.vfs_cache_pressure" = 50; + "vm.dirty_writeback_centisecs" = 1500; + "vm.dirty_expire_centisecs" = 3000; + + # Network optimizations + "net.core.rmem_max" = 134217728; + "net.core.wmem_max" = 134217728; + "net.core.netdev_max_backlog" = 5000; + "net.core.default_qdisc" = "fq"; + "net.ipv4.tcp_congestion_control" = "bbr"; + "net.ipv4.tcp_rmem" = "4096 12582912 16777216"; + "net.ipv4.tcp_wmem" = "4096 12582912 16777216"; + "net.ipv4.tcp_fastopen" = 3; + "net.ipv4.tcp_slow_start_after_idle" = 0; + + # File system optimizations + "fs.file-max" = 2097152; + "fs.inotify.max_user_watches" = 524288; + }; + + # More conservative auto-upgrade + system.autoUpgrade = { + enable = true; + flake = "/home/xfeusw/.config/nix"; + dates = "weekly"; # Changed from daily + randomizedDelaySec = "2h"; + allowReboot = false; # Safety: don't auto-reboot + }; + + # Improved garbage collection + nix.gc = { + automatic = true; + dates = "daily"; + options = "--delete-older-than 7d --max-freed 10G"; + persistent = true; + }; + + # SSD optimizations + services = { + fstrim = { + enable = true; + interval = "daily"; + }; + + # Disable write barriers for better SSD performance (if using ext4) + # Note: This sacrifices some data safety for performance + # Remove if you prefer safety over speed + }; + + # Power management for better performance/battery balance + powerManagement = { + enable = true; + cpuFreqGovernor = "schedutil"; # Better than ondemand + }; +} diff --git a/modules/security.nix b/modules/security.nix index 52dbeac..7b9239e 100644 --- a/modules/security.nix +++ b/modules/security.nix @@ -1,19 +1,55 @@ # modules/security.nix -{ ... }: +{ pkgs, ... }: { security = { apparmor = { enable = true; killUnconfinedConfinables = true; + packages = with pkgs; [ + apparmor-profiles + ]; }; - sudo.extraConfig = '' - Defaults timestamp_timeout=30 - Defaults pwfeedback - ''; + sudo = { + enable = true; + wheelNeedsPassword = true; # SECURITY: Require password for sudo + extraConfig = '' + Defaults timestamp_timeout=15 + Defaults pwfeedback + Defaults lecture=always + Defaults logfile=/var/log/sudo.log + Defaults log_input,log_output + Defaults insults + ''; + }; polkit.enable = true; rtkit.enable = true; + dmesg.restrict = true; + systemd.coredump.enable = false; + }; + + # Fail2ban for intrusion prevention + services.fail2ban = { + enable = true; + maxretry = 3; + bantime = "1h"; + bantime-increment = { + enable = true; + maxtime = "168h"; + factor = "2"; + }; + + jails = { + ssh = '' + enabled = true + port = 22 + filter = sshd + logpath = /var/log/auth.log + maxretry = 3 + bantime = 3600 + ''; + }; }; # Enhanced SSH configuration @@ -23,12 +59,28 @@ PermitRootLogin = "no"; PasswordAuthentication = false; KbdInteractiveAuthentication = false; + PubkeyAuthentication = true; X11Forwarding = false; AllowTcpForwarding = "no"; + AllowAgentForwarding = false; ClientAliveInterval = 300; ClientAliveCountMax = 2; MaxAuthTries = 3; - Protocol = 2; + MaxStartups = "10:30:100"; + LoginGraceTime = 30; + Ciphers = [ + "chacha20-poly1305@openssh.com" + "aes256-gcm@openssh.com" + "aes128-gcm@openssh.com" + ]; + KexAlgorithms = [ + "curve25519-sha256" + "curve25519-sha256@libssh.org" + ]; + Macs = [ + "hmac-sha2-256-etm@openssh.com" + "hmac-sha2-512-etm@openssh.com" + ]; }; allowSFTP = false; }; @@ -37,11 +89,67 @@ networking.firewall = { enable = true; allowedTCPPorts = [ 22 ]; + allowPing = false; logReversePathDrops = true; + logRefusedConnections = true; + extraCommands = '' - # Rate limiting for SSH - iptables -A nixos-fw -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --set - iptables -A nixos-fw -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --update --seconds 60 --hitcount 4 -j DROP + # SSH rate limiting + iptables -A nixos-fw -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --set --name SSH + iptables -A nixos-fw -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --update --seconds 60 --hitcount 3 --name SSH -j DROP + + # Drop invalid packets + iptables -A INPUT -m conntrack --ctstate INVALID -j DROP ''; }; + + # System security hardening + boot.kernel.sysctl = { + "kernel.sysrq" = 0; + "net.ipv4.ip_forward" = 0; + "net.ipv4.conf.all.send_redirects" = 0; + "net.ipv4.conf.all.accept_redirects" = 0; + "net.ipv4.conf.all.secure_redirects" = 0; + "net.ipv6.conf.all.accept_redirects" = 0; + "net.ipv4.conf.all.log_martians" = 1; + "net.ipv4.icmp_echo_ignore_broadcasts" = 1; + "net.ipv4.tcp_syncookies" = 1; + "kernel.dmesg_restrict" = 1; + "kernel.kptr_restrict" = 2; + "kernel.yama.ptrace_scope" = 1; + }; + + boot.kernelParams = [ + "slab_nomerge" + "init_on_alloc=1" + "init_on_free=1" + "page_alloc.shuffle=1" + "randomize_kstack_offset=on" + "vsyscall=none" + "lockdown=confidentiality" + ]; + + boot.blacklistedKernelModules = [ + "dccp" "sctp" "rds" "tipc" + "jffs2" "hfs" "hfsplus" + "firewire-core" "thunderbolt" + ]; + + # Security tools + environment.systemPackages = with pkgs; [ + lynis chkrootkit rkhunter + nmap wireshark tcpdump + ]; + + # Audit framework + security.auditd.enable = true; + security.audit = { + enable = true; + rules = [ + "-w /etc/passwd -p wa -k identity" + "-w /etc/shadow -p wa -k identity" + "-w /etc/sudoers -p wa -k identity" + "-a always,exit -F arch=b64 -S execve -k exec" + ]; + }; } From 2a27f524939e30936bc02ea14b435c1fc67c703e Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 01:54:25 +0500 Subject: [PATCH 04/21] men pizdes bo'lganman --- modules/nix-settings.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/nix-settings.nix b/modules/nix-settings.nix index 56969a9..2c42ecc 100644 --- a/modules/nix-settings.nix +++ b/modules/nix-settings.nix @@ -1,5 +1,5 @@ # modules/nix-settings.nix -{ ... }: +{ pkgs, ... }: { nixpkgs.config.allowUnfree = true; From 30ac4279606a841caad1466134d0bb75cf2212e0 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 01:58:31 +0500 Subject: [PATCH 05/21] Fix NUR module path and add SOPS configuration --- flake.lock | 587 +++++++++++++++++++++++++++++++++++++++++++++++++++-- flake.nix | 2 +- 2 files changed, 574 insertions(+), 15 deletions(-) diff --git a/flake.lock b/flake.lock index 9aea636..c37ab6c 100644 --- a/flake.lock +++ b/flake.lock @@ -1,6 +1,93 @@ { "nodes": { + "aquamarine": { + "inputs": { + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "hyprwayland-scanner": [ + "hyprland", + "hyprwayland-scanner" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1755946532, + "narHash": "sha256-POePremlUY5GyA1zfbtic6XLxDaQcqHN6l+bIxdT5gc=", + "owner": "hyprwm", + "repo": "aquamarine", + "rev": "81584dae2df6ac79f6b6dae0ecb7705e95129ada", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "aquamarine", + "type": "github" + } + }, + "base16-schemes": { + "flake": false, + "locked": { + "lastModified": 1696158499, + "narHash": "sha256-5yIHgDTPjoX/3oDEfLSQ0eJZdFL1SaCfb9d6M0RmOTM=", + "owner": "tinted-theming", + "repo": "base16-schemes", + "rev": "a9112eaae86d9dd8ee6bb9445b664fba2f94037a", + "type": "github" + }, + "original": { + "owner": "tinted-theming", + "repo": "base16-schemes", + "type": "github" + } + }, + "firefox-addons": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "dir": "pkgs/firefox-addons", + "lastModified": 1758427412, + "narHash": "sha256-VbVedyzFU0URoEccHZOzZI3tuCVfGFz12F1/bFdDyAk=", + "owner": "rycee", + "repo": "nur-expressions", + "rev": "72d7daed5a5e07593b70a3ab26ad0fdecadc49c3", + "type": "gitlab" + }, + "original": { + "dir": "pkgs/firefox-addons", + "owner": "rycee", + "repo": "nur-expressions", + "type": "gitlab" + } + }, "flake-compat": { + "flake": false, + "locked": { + "lastModified": 1747046372, + "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-compat_2": { "locked": { "lastModified": 1746162366, "narHash": "sha256-5SSSZ/oQkwfcAz/o/6TlejlVGqeK08wyREBQ5qFFPhM=", @@ -17,7 +104,7 @@ }, "flake-parts": { "inputs": { - "nixpkgs-lib": "nixpkgs-lib_2" + "nixpkgs-lib": "nixpkgs-lib_3" }, "locked": { "lastModified": 1741352980, @@ -96,7 +183,7 @@ }, "flake-utils_2": { "inputs": { - "systems": "systems_2" + "systems": "systems_3" }, "locked": { "lastModified": 1731533236, @@ -112,6 +199,46 @@ "type": "github" } }, + "flake-utils_3": { + "inputs": { + "systems": "systems_4" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "gitignore": { + "inputs": { + "nixpkgs": [ + "hyprland", + "pre-commit-hooks", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, "home-manager": { "inputs": { "nixpkgs": [ @@ -119,11 +246,11 @@ ] }, "locked": { - "lastModified": 1758313341, - "narHash": "sha256-SsI6INUzWwPcRKRaxvi50RttnD9rcC4EjV+67TOEfrQ=", + "lastModified": 1758463745, + "narHash": "sha256-uhzsV0Q0I9j2y/rfweWeGif5AWe0MGrgZ/3TjpDYdGA=", "owner": "nix-community", "repo": "home-manager", - "rev": "6f656618ebc71ca82d93d306a8aecb2c5f6f2ab2", + "rev": "3b955f5f0a942f9f60cdc9cacb7844335d0f21c3", "type": "github" }, "original": { @@ -133,6 +260,284 @@ "type": "github" } }, + "hyprcursor": { + "inputs": { + "hyprlang": [ + "hyprland", + "hyprlang" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1753964049, + "narHash": "sha256-lIqabfBY7z/OANxHoPeIrDJrFyYy9jAM4GQLzZ2feCM=", + "owner": "hyprwm", + "repo": "hyprcursor", + "rev": "44e91d467bdad8dcf8bbd2ac7cf49972540980a5", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprcursor", + "type": "github" + } + }, + "hyprgraphics": { + "inputs": { + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1758192433, + "narHash": "sha256-CR6RnqEJSTiFgA6KQY4TTLUWbZ8RBnb+hxQqesuQNzQ=", + "owner": "hyprwm", + "repo": "hyprgraphics", + "rev": "c44e749dd611521dee940d00f7c444ee0ae4cfb7", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprgraphics", + "type": "github" + } + }, + "hyprland": { + "inputs": { + "aquamarine": "aquamarine", + "hyprcursor": "hyprcursor", + "hyprgraphics": "hyprgraphics", + "hyprland-protocols": "hyprland-protocols", + "hyprland-qtutils": "hyprland-qtutils", + "hyprlang": "hyprlang", + "hyprutils": "hyprutils", + "hyprwayland-scanner": "hyprwayland-scanner", + "nixpkgs": [ + "nixpkgs" + ], + "pre-commit-hooks": "pre-commit-hooks", + "systems": "systems_2", + "xdph": "xdph" + }, + "locked": { + "lastModified": 1758475676, + "narHash": "sha256-EpHxoXvPi2xZeXELelIOWRaPfhx4QDXjUkbXMB1lOz0=", + "ref": "refs/heads/main", + "rev": "26cbc67385d95ba621fe0a125a5b121ffdd09335", + "revCount": 6442, + "submodules": true, + "type": "git", + "url": "https://github.com/hyprwm/Hyprland" + }, + "original": { + "submodules": true, + "type": "git", + "url": "https://github.com/hyprwm/Hyprland" + } + }, + "hyprland-protocols": { + "inputs": { + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1749046714, + "narHash": "sha256-kymV5FMnddYGI+UjwIw8ceDjdeg7ToDVjbHCvUlhn14=", + "owner": "hyprwm", + "repo": "hyprland-protocols", + "rev": "613878cb6f459c5e323aaafe1e6f388ac8a36330", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprland-protocols", + "type": "github" + } + }, + "hyprland-qt-support": { + "inputs": { + "hyprlang": [ + "hyprland", + "hyprland-qtutils", + "hyprlang" + ], + "nixpkgs": [ + "hyprland", + "hyprland-qtutils", + "nixpkgs" + ], + "systems": [ + "hyprland", + "hyprland-qtutils", + "systems" + ] + }, + "locked": { + "lastModified": 1749154592, + "narHash": "sha256-DO7z5CeT/ddSGDEnK9mAXm1qlGL47L3VAHLlLXoCjhE=", + "owner": "hyprwm", + "repo": "hyprland-qt-support", + "rev": "4c8053c3c888138a30c3a6c45c2e45f5484f2074", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprland-qt-support", + "type": "github" + } + }, + "hyprland-qtutils": { + "inputs": { + "hyprland-qt-support": "hyprland-qt-support", + "hyprlang": [ + "hyprland", + "hyprlang" + ], + "hyprutils": [ + "hyprland", + "hyprland-qtutils", + "hyprlang", + "hyprutils" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1757694755, + "narHash": "sha256-j+w5QUUr2QT/jkxgVKecGYV8J7fpzXCMgzEEr6LG9ug=", + "owner": "hyprwm", + "repo": "hyprland-qtutils", + "rev": "5ffdfc13ed03df1dae5084468d935f0a3f2c9a4c", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprland-qtutils", + "type": "github" + } + }, + "hyprlang": { + "inputs": { + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1756810301, + "narHash": "sha256-wgZ3VW4VVtjK5dr0EiK9zKdJ/SOqGIBXVG85C3LVxQA=", + "owner": "hyprwm", + "repo": "hyprlang", + "rev": "3d63fb4a42c819f198deabd18c0c2c1ded1de931", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprlang", + "type": "github" + } + }, + "hyprutils": { + "inputs": { + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1756117388, + "narHash": "sha256-oRDel6pNl/T2tI+nc/USU9ZP9w08dxtl7hiZxa0C/Wc=", + "owner": "hyprwm", + "repo": "hyprutils", + "rev": "b2ae3204845f5f2f79b4703b441252d8ad2ecfd0", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprutils", + "type": "github" + } + }, + "hyprwayland-scanner": { + "inputs": { + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1755184602, + "narHash": "sha256-RCBQN8xuADB0LEgaKbfRqwm6CdyopE1xIEhNc67FAbw=", + "owner": "hyprwm", + "repo": "hyprwayland-scanner", + "rev": "b3b0f1f40ae09d4447c20608e5a4faf8bf3c492d", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprwayland-scanner", + "type": "github" + } + }, + "impermanence": { + "locked": { + "lastModified": 1737831083, + "narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=", + "owner": "nix-community", + "repo": "impermanence", + "rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "impermanence", + "type": "github" + } + }, "ixx": { "inputs": { "flake-utils": [ @@ -165,8 +570,8 @@ }, "lib-aggregate": { "inputs": { - "flake-utils": "flake-utils", - "nixpkgs-lib": "nixpkgs-lib" + "flake-utils": "flake-utils_2", + "nixpkgs-lib": "nixpkgs-lib_2" }, "locked": { "lastModified": 1754828166, @@ -182,6 +587,25 @@ "type": "github" } }, + "nix-colors": { + "inputs": { + "base16-schemes": "base16-schemes", + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1707825078, + "narHash": "sha256-hTfge2J2W+42SZ7VHXkf4kjU+qzFqPeC9k66jAUBMHk=", + "owner": "misterio77", + "repo": "nix-colors", + "rev": "b01f024090d2c4fc3152cd0cf12027a7b8453ba1", + "type": "github" + }, + "original": { + "owner": "misterio77", + "repo": "nix-colors", + "type": "github" + } + }, "nixos-hardware": { "locked": { "lastModified": 1757943327, @@ -215,6 +639,21 @@ } }, "nixpkgs-lib": { + "locked": { + "lastModified": 1697935651, + "narHash": "sha256-qOfWjQ2JQSQL15KLh6D7xQhx0qgZlYZTYlcEiRuAMMw=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "e1e11fdbb01113d85c7f41cada9d2847660e3902", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, + "nixpkgs-lib_2": { "locked": { "lastModified": 1754788789, "narHash": "sha256-x2rJ+Ovzq0sCMpgfgGaaqgBSwY+LST+WbZ6TytnT9Rk=", @@ -229,7 +668,7 @@ "type": "github" } }, - "nixpkgs-lib_2": { + "nixpkgs-lib_3": { "locked": { "lastModified": 1740877520, "narHash": "sha256-oiwv/ZK/2FhGxrCkQkB83i7GnWXPPLzoqFHpDD3uYpk=", @@ -262,7 +701,7 @@ }, "nixpkgs-wayland": { "inputs": { - "flake-compat": "flake-compat", + "flake-compat": "flake-compat_2", "lib-aggregate": "lib-aggregate", "nixpkgs": "nixpkgs_2" }, @@ -376,11 +815,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1758433715, - "narHash": "sha256-HJoS2meEamJ8ygcLDYPcGugbmpiGk+zdhW6mVRoL5DE=", + "lastModified": 1758486922, + "narHash": "sha256-kxm26m3f3jjGEdd+ipXZDq4rMCKRKJ5i48F6gmnNqgI=", "owner": "nix-community", "repo": "NUR", - "rev": "86f5d2efe861e4fa2a9e3823d621c5ed7ecfb56f", + "rev": "a147fdc34a8a19741fe9979be2d81ff5f3589cc8", "type": "github" }, "original": { @@ -391,7 +830,7 @@ }, "nuschtosSearch": { "inputs": { - "flake-utils": "flake-utils_2", + "flake-utils": "flake-utils_3", "ixx": "ixx", "nixpkgs": [ "nixvim-config", @@ -413,15 +852,64 @@ "type": "github" } }, + "pre-commit-hooks": { + "inputs": { + "flake-compat": "flake-compat", + "gitignore": "gitignore", + "nixpkgs": [ + "hyprland", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1758108966, + "narHash": "sha256-ytw7ROXaWZ7OfwHrQ9xvjpUWeGVm86pwnEd1QhzawIo=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "54df955a695a84cd47d4a43e08e1feaf90b1fd9b", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "git-hooks.nix", + "type": "github" + } + }, "root": { "inputs": { + "firefox-addons": "firefox-addons", + "flake-utils": "flake-utils", "home-manager": "home-manager", + "hyprland": "hyprland", + "impermanence": "impermanence", + "nix-colors": "nix-colors", "nixos-hardware": "nixos-hardware", "nixpkgs": "nixpkgs", "nixpkgs-unstable": "nixpkgs-unstable", "nixpkgs-wayland": "nixpkgs-wayland", "nixvim-config": "nixvim-config", - "nur": "nur" + "nur": "nur", + "sops-nix": "sops-nix" + } + }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1758425756, + "narHash": "sha256-L3N8zV6wsViXiD8i3WFyrvjDdz76g3tXKEdZ4FkgQ+Y=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "e0fdaea3c31646e252a60b42d0ed8eafdb289762", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" } }, "systems": { @@ -440,6 +928,21 @@ } }, "systems_2": { + "locked": { + "lastModified": 1689347949, + "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", + "owner": "nix-systems", + "repo": "default-linux", + "rev": "31732fcf5e8fea42e59c2488ad31a0e651500f68", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default-linux", + "type": "github" + } + }, + "systems_3": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -453,6 +956,62 @@ "repo": "default", "type": "github" } + }, + "systems_4": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "xdph": { + "inputs": { + "hyprland-protocols": [ + "hyprland", + "hyprland-protocols" + ], + "hyprlang": [ + "hyprland", + "hyprlang" + ], + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "hyprwayland-scanner": [ + "hyprland", + "hyprwayland-scanner" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1755354946, + "narHash": "sha256-zdov5f/GcoLQc9qYIS1dUTqtJMeDqmBmo59PAxze6e4=", + "owner": "hyprwm", + "repo": "xdg-desktop-portal-hyprland", + "rev": "a10726d6a8d0ef1a0c645378f983b6278c42eaa0", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "xdg-desktop-portal-hyprland", + "type": "github" + } } }, "root": "root", diff --git a/flake.nix b/flake.nix index c7b36d1..a30469a 100644 --- a/flake.nix +++ b/flake.nix @@ -79,7 +79,7 @@ nixos-hardware.nixosModules.common-cpu-intel nixos-hardware.nixosModules.common-pc-ssd nixos-hardware.nixosModules.common-pc-laptop - nur.nixosModules.nur + nur.modules.nixos.default sops-nix.nixosModules.sops # Global overlays From 477cf24539ffd0dc86cc5ffc514ee1391ab54727 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 02:04:30 +0500 Subject: [PATCH 06/21] Fix NUR module path and add SOPS configuration --- flake.nix | 6 +++--- modules/nix-settings.nix | 2 +- modules/security.nix | 2 -- 3 files changed, 4 insertions(+), 6 deletions(-) diff --git a/flake.nix b/flake.nix index a30469a..e789b9a 100644 --- a/flake.nix +++ b/flake.nix @@ -86,7 +86,7 @@ { nixpkgs.overlays = [ nixpkgs-wayland.overlay - nur.overlay + nur.overlays.default # Custom overlay for optimizations (final: prev: { unstable = import nixpkgs-unstable { @@ -126,7 +126,7 @@ unstable = import nixpkgs-unstable { system = "x86_64-linux"; config.allowUnfree = true; - overlays = [ nur.overlay ]; + overlays = [ nur.overlays.default ]; }; }; modules = [ @@ -136,7 +136,7 @@ { nixpkgs.overlays = [ nixpkgs-wayland.overlay - nur.overlay + nur.overlays.default ]; } ]; diff --git a/modules/nix-settings.nix b/modules/nix-settings.nix index 2c42ecc..5b8d0c1 100644 --- a/modules/nix-settings.nix +++ b/modules/nix-settings.nix @@ -49,7 +49,7 @@ # Nix daemon settings daemonCPUSchedPolicy = "batch"; - daemonIOSchedClass = 2; + daemonIOSchedClass = "best-effort"; daemonIOSchedPriority = 7; }; diff --git a/modules/security.nix b/modules/security.nix index 7b9239e..e1aa343 100644 --- a/modules/security.nix +++ b/modules/security.nix @@ -25,8 +25,6 @@ polkit.enable = true; rtkit.enable = true; - dmesg.restrict = true; - systemd.coredump.enable = false; }; # Fail2ban for intrusion prevention From 5db8b45cb255fab77bf74c09874c1d9a423cfbe7 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 02:05:32 +0500 Subject: [PATCH 07/21] Fix NUR module path and add SOPS configuration --- modules/performance.nix | 8 -------- 1 file changed, 8 deletions(-) diff --git a/modules/performance.nix b/modules/performance.nix index 64170c1..7773da4 100644 --- a/modules/performance.nix +++ b/modules/performance.nix @@ -43,14 +43,6 @@ allowReboot = false; # Safety: don't auto-reboot }; - # Improved garbage collection - nix.gc = { - automatic = true; - dates = "daily"; - options = "--delete-older-than 7d --max-freed 10G"; - persistent = true; - }; - # SSD optimizations services = { fstrim = { From 40ad01e35d2e811b127aeafdf50a21283240ab6b Mon Sep 17 00:00:00 2001 From: xfeusw Date: Mon, 22 Sep 2025 02:07:45 +0500 Subject: [PATCH 08/21] Fix NUR module path and add SOPS configuration --- modules/security.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/modules/security.nix b/modules/security.nix index e1aa343..fe338be 100644 --- a/modules/security.nix +++ b/modules/security.nix @@ -11,8 +11,6 @@ }; sudo = { - enable = true; - wheelNeedsPassword = true; # SECURITY: Require password for sudo extraConfig = '' Defaults timestamp_timeout=15 Defaults pwfeedback @@ -135,7 +133,7 @@ # Security tools environment.systemPackages = with pkgs; [ - lynis chkrootkit rkhunter + lynis chkrootkit nmap wireshark tcpdump ]; From a0ed03b238e7ed40aa1f55e2705902ad0b17750a Mon Sep 17 00:00:00 2001 From: xfeusw Date: Tue, 23 Sep 2025 11:29:02 +0500 Subject: [PATCH 09/21] new --- flake.lock | 20 ++-- flake.nix | 5 +- home/xfeusw/shell/zsh.nix | 11 +- hosts/acer/secrets.yaml | 8 +- modules/scripts/default.nix | 6 ++ modules/scripts/dump-project.nix | 171 +++++++++++++++++++++++++++++++ 6 files changed, 200 insertions(+), 21 deletions(-) create mode 100644 modules/scripts/default.nix create mode 100644 modules/scripts/dump-project.nix diff --git a/flake.lock b/flake.lock index c37ab6c..3743660 100644 --- a/flake.lock +++ b/flake.lock @@ -57,11 +57,11 @@ }, "locked": { "dir": "pkgs/firefox-addons", - "lastModified": 1758427412, - "narHash": "sha256-VbVedyzFU0URoEccHZOzZI3tuCVfGFz12F1/bFdDyAk=", + "lastModified": 1758600213, + "narHash": "sha256-YP7+UxybMCzHPd5k93pulILnFvSisjgUAGUB/cxWbqU=", "owner": "rycee", "repo": "nur-expressions", - "rev": "72d7daed5a5e07593b70a3ab26ad0fdecadc49c3", + "rev": "8a0333bf11a0fab386c80fa018617bb050156ec5", "type": "gitlab" }, "original": { @@ -336,11 +336,11 @@ "xdph": "xdph" }, "locked": { - "lastModified": 1758475676, - "narHash": "sha256-EpHxoXvPi2xZeXELelIOWRaPfhx4QDXjUkbXMB1lOz0=", + "lastModified": 1758542519, + "narHash": "sha256-NHEzK6MN8Tv9YrnJb2A9KxcOI2cCsKRqZOC5kUeG8Aw=", "ref": "refs/heads/main", - "rev": "26cbc67385d95ba621fe0a125a5b121ffdd09335", - "revCount": 6442, + "rev": "70a7047ee175d2e7fca1575d50a3738ac40fd2c6", + "revCount": 6446, "submodules": true, "type": "git", "url": "https://github.com/hyprwm/Hyprland" @@ -815,11 +815,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1758486922, - "narHash": "sha256-kxm26m3f3jjGEdd+ipXZDq4rMCKRKJ5i48F6gmnNqgI=", + "lastModified": 1758603982, + "narHash": "sha256-ig0+mpQvUrp56909gMkF0lxQ0nGEXZtljIZWnrrRG1Y=", "owner": "nix-community", "repo": "NUR", - "rev": "a147fdc34a8a19741fe9979be2d81ff5f3589cc8", + "rev": "de4f5ff4f5dabad8356f67119fbe582a44c9e969", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index e789b9a..f4d01e7 100644 --- a/flake.nix +++ b/flake.nix @@ -106,7 +106,7 @@ ]; trusted-public-keys = [ "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" - "nixpkgs-wayland.cachix.org-1:4f5VsYvpWm4VE/KJioPp6TcbRZ3PgCWvu5Zf+HjMZ9o=" + "nixpkgs-wayland.cachix.org-1:3lwxaILJ2uV7M2uAyUBFx3L6Z8YQoa9N2vXgm6Q34Yo=" "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc=" "nixpkgs-unfree.cachix.org-1:hqvoInulhbV4nJ9yJOEr+4wxhDV4xq2d1DK7S6Nj6rs=" @@ -126,12 +126,11 @@ unstable = import nixpkgs-unstable { system = "x86_64-linux"; config.allowUnfree = true; - overlays = [ nur.overlays.default ]; + overlays = [nur.overlays.default]; }; }; modules = [ ./home/xfeusw/home.nix - nur.homeManagerModules.nur nix-colors.homeManagerModules.default { nixpkgs.overlays = [ diff --git a/home/xfeusw/shell/zsh.nix b/home/xfeusw/shell/zsh.nix index 43ec47e..7f63141 100644 --- a/home/xfeusw/shell/zsh.nix +++ b/home/xfeusw/shell/zsh.nix @@ -74,14 +74,17 @@ # System info temp = "sensors"; ports = "ss -tuln"; + + # Project dumping + dump = "dump-project"; + dump-project = "dump-project"; + dump-code = "dump-project"; + project-dump = "dump-project"; }; - initExtraFirst = '' + initContent = '' # Performance: only load what's needed skip_global_compinit=1 - ''; - - initExtra = '' # Initialize tools eval "$(zoxide init zsh)" eval "$(direnv hook zsh)" diff --git a/hosts/acer/secrets.yaml b/hosts/acer/secrets.yaml index 9abd3df..1ea8280 100644 --- a/hosts/acer/secrets.yaml +++ b/hosts/acer/secrets.yaml @@ -1,6 +1,6 @@ #ENC[AES256_GCM,data:WOcPzh2q5Rj+0SsyT/6CEATa7no725Tv7Ny5coWkCK73BPxfdFXuL3PafaaoVaLCeQ8KWMRkHrAipLD3y1k=,iv:pxviRe8MZqF8C2KMTkdVH0+gBcZiW855opqr+CcHtOM=,tag:fB8Ma7mLilG1I9b7Rj1tQQ==,type:comment] -user-password: ENC[AES256_GCM,data:PwK2ew==,iv:19jj11aN1zPspUEGYuzPV6J4FRJEFwT3mRFW9HIOgoc=,tag:TMGCwyaLuj+NdFOCMZIrIw==,type:int] -restic-password: ENC[AES256_GCM,data:n/w7Ng==,iv:4B37Pn9VtYUai6t8zNvi9aogXpuZf2mSVUOs/9QRlyw=,tag:NWWtYa6RzbNtSAp9g8GZCg==,type:int] +user-password: ENC[AES256_GCM,data:oa//yQ==,iv:f7aVAtAKbuu3YEZHSlb3kkv3WnXL7y5MNXTfeM+28DE=,tag:ZqRaWOKUBbZ9/XcZd9kUgQ==,type:str] +restic-password: ENC[AES256_GCM,data:HETyYA==,iv:c5q0FqiyG0hNksxWpIJey96n0+jlZgmYYvkfaahS8Pw=,tag:a+3rucaxWp9z/vVtiBbvRw==,type:str] sops: age: - recipient: age1nguz9mhgylxezcctn3c4qk8e6upes0c3s5n5mkdlpxdujham5fusd5xvy6 @@ -12,7 +12,7 @@ sops: d2hPOXA2TloveXROWDY4ZXpLSTFpZkEK0S44jS/4JzvJ9lh0yVJQhL3YdDdcZGJm WQFW50AiqLYoG+RODaQkbVABLqfq0AmqpiCPCQT9qsrbFfPe1elSHw== -----END AGE ENCRYPTED FILE----- - lastmodified: "2025-09-21T20:52:25Z" - mac: ENC[AES256_GCM,data:8S7gaVk1DXSWLYC3m4ErSEmhh6ClggL/18E0wrrY8EAV0mYlCUlBuNuysJyc2AfUZSEqMmCEIqSQvjuVGMVuCOCftsJXeZvUoyEuY1pH4Pd02Rj30DhdQt5Hr2Eq1WGVbmIOGJjqaRk4s6IwPL41raMgozvYT/v1q/IhKLn1f0U=,iv:oqHDy9cKLD8BnlTxdgoByo6zGGOmRX2Ym4rFDNUbpWU=,tag:3Afrf+bCLkKmPU197lJ6dA==,type:str] + lastmodified: "2025-09-21T21:28:09Z" + mac: ENC[AES256_GCM,data:RZ/CPdRFVzujxN4EbT8TnPgziTZNdhqeFkSMSrkeIrflG7Zi1Zfnt+Ymoa2fxdz5KQzSo5hm/LfpzVmv1wT8mKm4cnecAuUQ9Qy54SdDULiWtr3Jhz6nV6kBomvRrhAZpaddaHI24Mx9xk9Vu9vAWO+w0gdtrCF0kNEBHQIxEaY=,iv:tIPJrAWoPDO0v9+MkAiVeGvGqea1gpIOO95RdM7i8VY=,tag:n0FR2e2U2lKrwSAYlILYsQ==,type:str] unencrypted_suffix: _unencrypted version: 3.10.2 diff --git a/modules/scripts/default.nix b/modules/scripts/default.nix new file mode 100644 index 0000000..c7562a1 --- /dev/null +++ b/modules/scripts/default.nix @@ -0,0 +1,6 @@ +{ ... }: +{ + imports = [ + ./dump-project.nix + ]; +} diff --git a/modules/scripts/dump-project.nix b/modules/scripts/dump-project.nix new file mode 100644 index 0000000..544265a --- /dev/null +++ b/modules/scripts/dump-project.nix @@ -0,0 +1,171 @@ +{ pkgs, ... }: +let + dump-project = pkgs.writeShellScriptBin "dump-project" '' + #!/usr/bin/env bash + # dump-project - Universal project dumper + # Concatenates all important project files into test.blank + + set -euo pipefail + + OUTFILE="test.blank" + + # Function to detect project type and get relevant patterns + detect_project_type() { + local project_types=() + + # Check for various project indicators + [[ -f flake.nix ]] && project_types+=("nix") + [[ -f package.json ]] && project_types+=("node") + [[ -f Cargo.toml ]] && project_types+=("rust") + [[ -f pyproject.toml || -f setup.py || -f requirements.txt ]] && project_types+=("python") + [[ -f go.mod ]] && project_types+=("go") + [[ -f pom.xml || -f build.gradle ]] && project_types+=("java") + [[ -f Makefile || -f CMakeLists.txt ]] && project_types+=("c/cpp") + [[ -f composer.json ]] && project_types+=("php") + [[ -f Gemfile ]] && project_types+=("ruby") + [[ -f mix.exs ]] && project_types+=("elixir") + [[ -f stack.yaml || -f *.cabal ]] && project_types+=("haskell") + [[ -f deno.json || -f deno.jsonc ]] && project_types+=("deno") + [[ -d .git ]] && project_types+=("git") + + if [[ ''${#project_types[@]} -eq 0 ]]; then + project_types+=("generic") + fi + + printf '%s\n' "''${project_types[@]}" + } + + # Function to get file patterns based on project type + get_file_patterns() { + local project_type="$1" + + case "$project_type" in + nix) + echo "*.nix *.yaml *.yml *.toml *.json *.conf *.config *.sh *.zsh *.fish" + ;; + node) + echo "*.js *.ts *.jsx *.tsx *.json *.md *.yml *.yaml package*.json tsconfig.json .env*" + ;; + rust) + echo "*.rs *.toml *.md Cargo.* .env*" + ;; + python) + echo "*.py *.pyi *.pyx *.toml *.txt *.cfg *.ini *.md *.yml *.yaml setup.py pyproject.toml requirements*.txt .env*" + ;; + go) + echo "*.go *.mod *.sum *.md *.yml *.yaml .env*" + ;; + java) + echo "*.java *.kt *.xml *.gradle *.properties *.md *.yml *.yaml .env*" + ;; + "c/cpp") + echo "*.c *.cpp *.h *.hpp *.cc *.cxx *.hxx *.cmake CMakeLists.txt Makefile *.md .env*" + ;; + php) + echo "*.php *.json *.xml *.md *.yml *.yaml composer.* .env*" + ;; + ruby) + echo "*.rb *.gemspec Gemfile* *.md *.yml *.yaml .env*" + ;; + elixir) + echo "*.ex *.exs *.eex *.leex *.heex mix.* *.md *.yml *.yaml .env*" + ;; + haskell) + echo "*.hs *.lhs *.cabal *.yaml stack.yaml *.md .env*" + ;; + deno) + echo "*.ts *.js *.tsx *.jsx *.json *.md deno.* .env*" + ;; + *) + echo "*.md *.txt *.json *.yaml *.yml *.toml *.ini *.cfg *.conf *.config *.sh *.bash *.zsh *.fish .env*" + ;; + esac + } + + # Function to get directories to exclude + get_exclude_dirs() { + echo ".git node_modules .direnv .github .vscode target build dist out __pycache__ .pytest_cache .mypy_cache .tox venv .venv env .env bin obj .gradle .idea .next .nuxt coverage .nyc_output logs tmp temp .cache result" + } + + # Function to get files to exclude + get_exclude_files() { + echo "*.lock *.backup *.tmp *~ .DS_Store *.log *.pid *.seed *.pid.lock *.tgz *.tar.gz *.zip *.rar *.7z *.exe *.dll *.so *.dylib *.o *.obj *.class *.pyc *.pyo" + } + + # Main function + main() { + echo "Detecting project type(s) in: $PWD" + + # Detect project types + local project_types=($(detect_project_type)) + echo "Detected project type(s): ''${project_types[*]}" + + # Clear the output file or create it + : > "$OUTFILE" + + # Get file patterns for all detected project types + local all_patterns=() + for project_type in "''${project_types[@]}"; do + local patterns=($(get_file_patterns "$project_type")) + all_patterns+=("''${patterns[@]}") + done + + # Remove duplicates and sort + local unique_patterns=($(printf '%s\n' "''${all_patterns[@]}" | sort -u)) + + echo "Searching for files matching: ''${unique_patterns[*]}" + + # Get exclude patterns + local exclude_dirs=($(get_exclude_dirs)) + local exclude_files=($(get_exclude_files)) + + # Build find command for excluded directories + local find_excludes=() + for dir in "''${exclude_dirs[@]}"; do + find_excludes+=(-type d -name "$dir" -prune -o) + done + + # Build find command for file patterns + local find_patterns=() + for pattern in "''${unique_patterns[@]}"; do + find_patterns+=(-name "$pattern" -o) + done + # Remove the last -o + if [[ ''${#find_patterns[@]} -gt 0 ]]; then + unset 'find_patterns[-1]' + fi + + # Find and process files + find . "''${find_excludes[@]}" \ + -type f \( "''${find_patterns[@]}" \) \ + $(printf ' ! -name %q' "''${exclude_files[@]}") \ + ! -name "$OUTFILE" \ + -print0 | sort -z | while IFS= read -r -d ''' file; do + # Skip binary files + if file "$file" | grep -q "text\|empty"; then + echo "Processing: $file" + echo -e "\n# ---- $file ----\n" >> "$OUTFILE" + cat "$file" >> "$OUTFILE" + fi + done + + # Check if any files were appended + if [[ -s "$OUTFILE" ]]; then + local file_count=$(grep -c "^# ---- .* ----$" "$OUTFILE" || echo "0") + local line_count=$(wc -l < "$OUTFILE") + echo "Combined $file_count files ($line_count lines) written to $OUTFILE" + echo "Project: $PWD" + echo "Output: $PWD/$OUTFILE" + else + echo "No files were found to combine into $OUTFILE" + exit 1 + fi + } + + main "$@" + ''; +in +{ + # Install the script system-wide + environment.systemPackages = [ dump-project ]; +} From 4d08a71cfd332be3e355d6f2520db9be79f8e4b4 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Tue, 23 Sep 2025 12:10:29 +0500 Subject: [PATCH 10/21] men pizdes bo'lganman --- home/xfeusw/development/languages/nodejs.nix | 1 + home/xfeusw/shell/zsh.nix | 16 ++++++++-------- modules/nix-settings.nix | 2 +- 3 files changed, 10 insertions(+), 9 deletions(-) diff --git a/home/xfeusw/development/languages/nodejs.nix b/home/xfeusw/development/languages/nodejs.nix index da8ee2d..b835aff 100644 --- a/home/xfeusw/development/languages/nodejs.nix +++ b/home/xfeusw/development/languages/nodejs.nix @@ -13,5 +13,6 @@ nodePackages.eslint nodePackages.prettier nodePackages."@tailwindcss/language-server" + package-version-server ]; } diff --git a/home/xfeusw/shell/zsh.nix b/home/xfeusw/shell/zsh.nix index 7f63141..6cce665 100644 --- a/home/xfeusw/shell/zsh.nix +++ b/home/xfeusw/shell/zsh.nix @@ -1,6 +1,5 @@ # home/xfeusw/shell/zsh.nix -{ pkgs, ... }: -{ +{pkgs, ...}: { programs.zsh = { enable = true; enableCompletion = true; @@ -46,11 +45,12 @@ # NixOS management check = "nix flake check"; - sys-build = "sudo nixos-rebuild build --flake /home/xfeusw/.config/nix#acer"; - sys-switch = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer"; - sys-update = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer --upgrade"; - home-build = "home-manager build --flake /home/xfeusw/.config/nix#xfeusw"; - home-switch = "home-manager switch --flake /home/xfeusw/.config/nix#xfeusw"; + sys-build = "sudo nixos-rebuild build --flake /home/xfeusw/.config/nix#acer --option restrict-eval false"; + sys-switch = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer --option restrict-eval false"; + sys-update = "sudo nixos-rebuild switch --flake /home/xfeusw/.config/nix#acer --upgrade --option restrict-eval false"; + home-build = "home-manager build --flake /home/xfeusw/.config/nix#xfeusw --option restrict-eval false"; + home-switch = "home-manager switch --flake /home/xfeusw/.config/nix#xfeusw --option restrict-eval false"; + home-update = "home-manager switch --flake /home/xfeusw/.config/nix#xfeusw --option restrict-eval false"; nix-clean = "sudo nix-collect-garbage -d && nix-collect-garbage -d && home-manager expire-generations 0 && sudo nix-store --optimise"; nix-search = "nix search nixpkgs"; @@ -169,7 +169,7 @@ "z" "direnv" ]; - theme = ""; # Using Starship instead + theme = ""; # Using Starship instead }; }; } diff --git a/modules/nix-settings.nix b/modules/nix-settings.nix index 5b8d0c1..a744648 100644 --- a/modules/nix-settings.nix +++ b/modules/nix-settings.nix @@ -27,7 +27,7 @@ # Sandbox settings sandbox = true; - restrict-eval = true; + restrict-eval = false; # Trusted users trusted-users = [ "root" "@wheel" ]; From b146f97899043d0cffce2d08d235787f8f3629e6 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Tue, 23 Sep 2025 14:37:27 +0500 Subject: [PATCH 11/21] men pizdes bo'lganman --- home/xfeusw/shell/zsh.nix | 6 -- hosts/acer/configuration.nix | 2 + modules/scripts/default.nix | 6 -- modules/scripts/dump-project.nix | 171 ------------------------------- 4 files changed, 2 insertions(+), 183 deletions(-) delete mode 100644 modules/scripts/default.nix delete mode 100644 modules/scripts/dump-project.nix diff --git a/home/xfeusw/shell/zsh.nix b/home/xfeusw/shell/zsh.nix index 6cce665..8f39541 100644 --- a/home/xfeusw/shell/zsh.nix +++ b/home/xfeusw/shell/zsh.nix @@ -74,12 +74,6 @@ # System info temp = "sensors"; ports = "ss -tuln"; - - # Project dumping - dump = "dump-project"; - dump-project = "dump-project"; - dump-code = "dump-project"; - project-dump = "dump-project"; }; initContent = '' diff --git a/hosts/acer/configuration.nix b/hosts/acer/configuration.nix index a38dec8..bb2e69c 100644 --- a/hosts/acer/configuration.nix +++ b/hosts/acer/configuration.nix @@ -20,6 +20,8 @@ ../../modules/hardware ../../modules/services ../../modules/virtualization + + ../../modules/scripts ]; # Bootloader with enhanced options diff --git a/modules/scripts/default.nix b/modules/scripts/default.nix deleted file mode 100644 index c7562a1..0000000 --- a/modules/scripts/default.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ ... }: -{ - imports = [ - ./dump-project.nix - ]; -} diff --git a/modules/scripts/dump-project.nix b/modules/scripts/dump-project.nix deleted file mode 100644 index 544265a..0000000 --- a/modules/scripts/dump-project.nix +++ /dev/null @@ -1,171 +0,0 @@ -{ pkgs, ... }: -let - dump-project = pkgs.writeShellScriptBin "dump-project" '' - #!/usr/bin/env bash - # dump-project - Universal project dumper - # Concatenates all important project files into test.blank - - set -euo pipefail - - OUTFILE="test.blank" - - # Function to detect project type and get relevant patterns - detect_project_type() { - local project_types=() - - # Check for various project indicators - [[ -f flake.nix ]] && project_types+=("nix") - [[ -f package.json ]] && project_types+=("node") - [[ -f Cargo.toml ]] && project_types+=("rust") - [[ -f pyproject.toml || -f setup.py || -f requirements.txt ]] && project_types+=("python") - [[ -f go.mod ]] && project_types+=("go") - [[ -f pom.xml || -f build.gradle ]] && project_types+=("java") - [[ -f Makefile || -f CMakeLists.txt ]] && project_types+=("c/cpp") - [[ -f composer.json ]] && project_types+=("php") - [[ -f Gemfile ]] && project_types+=("ruby") - [[ -f mix.exs ]] && project_types+=("elixir") - [[ -f stack.yaml || -f *.cabal ]] && project_types+=("haskell") - [[ -f deno.json || -f deno.jsonc ]] && project_types+=("deno") - [[ -d .git ]] && project_types+=("git") - - if [[ ''${#project_types[@]} -eq 0 ]]; then - project_types+=("generic") - fi - - printf '%s\n' "''${project_types[@]}" - } - - # Function to get file patterns based on project type - get_file_patterns() { - local project_type="$1" - - case "$project_type" in - nix) - echo "*.nix *.yaml *.yml *.toml *.json *.conf *.config *.sh *.zsh *.fish" - ;; - node) - echo "*.js *.ts *.jsx *.tsx *.json *.md *.yml *.yaml package*.json tsconfig.json .env*" - ;; - rust) - echo "*.rs *.toml *.md Cargo.* .env*" - ;; - python) - echo "*.py *.pyi *.pyx *.toml *.txt *.cfg *.ini *.md *.yml *.yaml setup.py pyproject.toml requirements*.txt .env*" - ;; - go) - echo "*.go *.mod *.sum *.md *.yml *.yaml .env*" - ;; - java) - echo "*.java *.kt *.xml *.gradle *.properties *.md *.yml *.yaml .env*" - ;; - "c/cpp") - echo "*.c *.cpp *.h *.hpp *.cc *.cxx *.hxx *.cmake CMakeLists.txt Makefile *.md .env*" - ;; - php) - echo "*.php *.json *.xml *.md *.yml *.yaml composer.* .env*" - ;; - ruby) - echo "*.rb *.gemspec Gemfile* *.md *.yml *.yaml .env*" - ;; - elixir) - echo "*.ex *.exs *.eex *.leex *.heex mix.* *.md *.yml *.yaml .env*" - ;; - haskell) - echo "*.hs *.lhs *.cabal *.yaml stack.yaml *.md .env*" - ;; - deno) - echo "*.ts *.js *.tsx *.jsx *.json *.md deno.* .env*" - ;; - *) - echo "*.md *.txt *.json *.yaml *.yml *.toml *.ini *.cfg *.conf *.config *.sh *.bash *.zsh *.fish .env*" - ;; - esac - } - - # Function to get directories to exclude - get_exclude_dirs() { - echo ".git node_modules .direnv .github .vscode target build dist out __pycache__ .pytest_cache .mypy_cache .tox venv .venv env .env bin obj .gradle .idea .next .nuxt coverage .nyc_output logs tmp temp .cache result" - } - - # Function to get files to exclude - get_exclude_files() { - echo "*.lock *.backup *.tmp *~ .DS_Store *.log *.pid *.seed *.pid.lock *.tgz *.tar.gz *.zip *.rar *.7z *.exe *.dll *.so *.dylib *.o *.obj *.class *.pyc *.pyo" - } - - # Main function - main() { - echo "Detecting project type(s) in: $PWD" - - # Detect project types - local project_types=($(detect_project_type)) - echo "Detected project type(s): ''${project_types[*]}" - - # Clear the output file or create it - : > "$OUTFILE" - - # Get file patterns for all detected project types - local all_patterns=() - for project_type in "''${project_types[@]}"; do - local patterns=($(get_file_patterns "$project_type")) - all_patterns+=("''${patterns[@]}") - done - - # Remove duplicates and sort - local unique_patterns=($(printf '%s\n' "''${all_patterns[@]}" | sort -u)) - - echo "Searching for files matching: ''${unique_patterns[*]}" - - # Get exclude patterns - local exclude_dirs=($(get_exclude_dirs)) - local exclude_files=($(get_exclude_files)) - - # Build find command for excluded directories - local find_excludes=() - for dir in "''${exclude_dirs[@]}"; do - find_excludes+=(-type d -name "$dir" -prune -o) - done - - # Build find command for file patterns - local find_patterns=() - for pattern in "''${unique_patterns[@]}"; do - find_patterns+=(-name "$pattern" -o) - done - # Remove the last -o - if [[ ''${#find_patterns[@]} -gt 0 ]]; then - unset 'find_patterns[-1]' - fi - - # Find and process files - find . "''${find_excludes[@]}" \ - -type f \( "''${find_patterns[@]}" \) \ - $(printf ' ! -name %q' "''${exclude_files[@]}") \ - ! -name "$OUTFILE" \ - -print0 | sort -z | while IFS= read -r -d ''' file; do - # Skip binary files - if file "$file" | grep -q "text\|empty"; then - echo "Processing: $file" - echo -e "\n# ---- $file ----\n" >> "$OUTFILE" - cat "$file" >> "$OUTFILE" - fi - done - - # Check if any files were appended - if [[ -s "$OUTFILE" ]]; then - local file_count=$(grep -c "^# ---- .* ----$" "$OUTFILE" || echo "0") - local line_count=$(wc -l < "$OUTFILE") - echo "Combined $file_count files ($line_count lines) written to $OUTFILE" - echo "Project: $PWD" - echo "Output: $PWD/$OUTFILE" - else - echo "No files were found to combine into $OUTFILE" - exit 1 - fi - } - - main "$@" - ''; -in -{ - # Install the script system-wide - environment.systemPackages = [ dump-project ]; -} From 1ea4617cdc69c2be87507435c4bb5d6017d7b0cf Mon Sep 17 00:00:00 2001 From: xfeusw Date: Fri, 26 Sep 2025 14:07:23 +0500 Subject: [PATCH 12/21] updates --- home/xfeusw/development/languages/nodejs.nix | 39 ++++++++++++++++++-- hosts/acer/configuration.nix | 2 - modules/security.nix | 2 +- 3 files changed, 36 insertions(+), 7 deletions(-) diff --git a/home/xfeusw/development/languages/nodejs.nix b/home/xfeusw/development/languages/nodejs.nix index b835aff..eb2ee2a 100644 --- a/home/xfeusw/development/languages/nodejs.nix +++ b/home/xfeusw/development/languages/nodejs.nix @@ -1,18 +1,49 @@ # home/xfeusw/development/languages/nodejs.nix -{ pkgs, ... }: -{ +{pkgs, ...}: { home.packages = with pkgs; [ # Node.js nodejs_22 pnpm yarn + package-version-server + + # OpenSSL for Prisma and other Node.js native modules + openssl - # Global tools + # Global Node.js tools nodePackages.typescript nodePackages.typescript-language-server nodePackages.eslint nodePackages.prettier nodePackages."@tailwindcss/language-server" - package-version-server + + # Prisma dependencies + prisma-engines # Provides Prisma engine binaries + nodePackages.prisma # Prisma CLI for database management + + # Prisma dependencies (for query engine) + pkg-config + libuuid # Required for some Prisma setups ]; + + # Environment variables for Prisma and Node.js + home.sessionVariables = { + # Prisma engine paths + PRISMA_QUERY_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/query-engine"; + PRISMA_QUERY_ENGINE_LIBRARY = "${pkgs.prisma-engines}/lib/libquery_engine.node"; + PRISMA_SCHEMA_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/schema-engine"; + PRISMA_FMT_BINARY = "${pkgs.prisma-engines}/bin/prisma-fmt"; + PRISMA_INTROSPECTION_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/introspection-engine"; + + # Fallback for checksum issues + PRISMA_ENGINES_CHECKSUM_IGNORE_MISSING = "1"; + + # Ensure OpenSSL is available + OPENSSL_DIR = "${pkgs.openssl.dev}/"; + OPENSSL_LIB_DIR = "${pkgs.openssl.out}/lib"; + OPENSSL_INCLUDE_DIR = "${pkgs.openssl.dev}/include"; + + # Node.js global packages path + NODE_PATH = "${pkgs.nodejs_22}/lib/node_modules"; + }; } diff --git a/hosts/acer/configuration.nix b/hosts/acer/configuration.nix index bb2e69c..a38dec8 100644 --- a/hosts/acer/configuration.nix +++ b/hosts/acer/configuration.nix @@ -20,8 +20,6 @@ ../../modules/hardware ../../modules/services ../../modules/virtualization - - ../../modules/scripts ]; # Bootloader with enhanced options diff --git a/modules/security.nix b/modules/security.nix index fe338be..85001a2 100644 --- a/modules/security.nix +++ b/modules/security.nix @@ -84,7 +84,7 @@ # Enhanced firewall networking.firewall = { enable = true; - allowedTCPPorts = [ 22 ]; + allowedTCPPorts = [ 22 8080 ]; allowPing = false; logReversePathDrops = true; logRefusedConnections = true; From a0c1d82be05f29ae3bf54ae830b268efc6fdf4c6 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 15:20:52 +0500 Subject: [PATCH 13/21] home-manager updates; remodulerizing --- flake.nix | 28 +++------ home/xfeusw/applications/browsers.nix | 14 ----- home/xfeusw/applications/communication.nix | 15 ----- home/xfeusw/applications/default.nix | 42 +++++++++---- home/xfeusw/applications/media.nix | 21 ------- home/xfeusw/applications/productivity.nix | 15 ----- home/xfeusw/desktop/gtk.nix | 48 ++++----------- home/xfeusw/development/default.nix | 2 - home/xfeusw/development/languages/default.nix | 2 +- home/xfeusw/development/tools.nix | 61 +++++++++---------- home/xfeusw/home.nix | 4 -- home/xfeusw/shell/default.nix | 22 +------ home/xfeusw/shell/ghostty.nix | 12 +--- 13 files changed, 83 insertions(+), 203 deletions(-) delete mode 100644 home/xfeusw/applications/browsers.nix delete mode 100644 home/xfeusw/applications/communication.nix delete mode 100644 home/xfeusw/applications/media.nix delete mode 100644 home/xfeusw/applications/productivity.nix diff --git a/flake.nix b/flake.nix index f4d01e7..77eee55 100644 --- a/flake.nix +++ b/flake.nix @@ -6,7 +6,6 @@ nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs-wayland.url = "github:nix-community/nixpkgs-wayland"; - # Utils for cleaner code flake-utils.url = "github:numtide/flake-utils"; home-manager = { @@ -14,37 +13,26 @@ inputs.nixpkgs.follows = "nixpkgs"; }; - # Hardware optimization nixos-hardware.url = "github:NixOS/nixos-hardware/master"; - - # Additional useful inputs nur.url = "github:nix-community/NUR"; - - # State management impermanence.url = "github:nix-community/impermanence"; - - # Consistent theming nix-colors.url = "github:misterio77/nix-colors"; - # Firefox extensions firefox-addons = { url = "gitlab:rycee/nur-expressions?dir=pkgs/firefox-addons"; inputs.nixpkgs.follows = "nixpkgs"; }; - # Your personal nixvim configuration nixvim-config = { url = "github:Ahwxorg/nixvim-config"; inputs.nixpkgs.follows = "nixpkgs"; }; - # Secrets management sops-nix = { url = "github:Mic92/sops-nix"; inputs.nixpkgs.follows = "nixpkgs"; }; - # Hyprland (optional Wayland compositor) hyprland = { url = "git+https://github.com/hyprwm/Hyprland?submodules=1"; inputs.nixpkgs.follows = "nixpkgs"; @@ -82,12 +70,10 @@ nur.modules.nixos.default sops-nix.nixosModules.sops - # Global overlays { nixpkgs.overlays = [ nixpkgs-wayland.overlay nur.overlays.default - # Custom overlay for optimizations (final: prev: { unstable = import nixpkgs-unstable { system = prev.system; @@ -121,13 +107,7 @@ xfeusw = home-manager.lib.homeManagerConfiguration { pkgs = nixpkgs.legacyPackages.x86_64-linux; extraSpecialArgs = { - inherit inputs; - inherit nixpkgs-unstable nixpkgs-wayland nixvim-config nur nix-colors firefox-addons; - unstable = import nixpkgs-unstable { - system = "x86_64-linux"; - config.allowUnfree = true; - overlays = [nur.overlays.default]; - }; + inherit inputs nixvim-config nix-colors firefox-addons; }; modules = [ ./home/xfeusw/home.nix @@ -136,6 +116,12 @@ nixpkgs.overlays = [ nixpkgs-wayland.overlay nur.overlays.default + (final: prev: { + unstable = import nixpkgs-unstable { + system = prev.system; + config.allowUnfree = true; + }; + }) ]; } ]; diff --git a/home/xfeusw/applications/browsers.nix b/home/xfeusw/applications/browsers.nix deleted file mode 100644 index d2ecb18..0000000 --- a/home/xfeusw/applications/browsers.nix +++ /dev/null @@ -1,14 +0,0 @@ -# home/xfeusw/applications/browsers.nix -{ unstable, ... }: -{ - home.packages = with unstable; [ - # Browsers - brave - firefox-devedition - google-chrome - tor-browser - - # Browser tools - browserpass # Pass integration - ]; -} diff --git a/home/xfeusw/applications/communication.nix b/home/xfeusw/applications/communication.nix deleted file mode 100644 index 9c53ac5..0000000 --- a/home/xfeusw/applications/communication.nix +++ /dev/null @@ -1,15 +0,0 @@ -# home/xfeusw/applications/communication.nix -{ unstable, ... }: -{ - home.packages = with unstable; [ - # Chat applications - telegram-desktop - discord - - # Video conferencing - zoom-us - - # Remote desktop - anydesk - ]; -} diff --git a/home/xfeusw/applications/default.nix b/home/xfeusw/applications/default.nix index 8b4bc2e..4e9a2f0 100644 --- a/home/xfeusw/applications/default.nix +++ b/home/xfeusw/applications/default.nix @@ -1,17 +1,35 @@ -# home/xfeusw/applications/default.nix -{ pkgs, unstable, ... }: +{ pkgs, ... }: { - imports = [ - ./browsers.nix - ./media.nix - ./productivity.nix - ./communication.nix - ]; - - # Allow both stable and unstable packages home.packages = with pkgs; [ + + ] ++ (with pkgs.unstable; [ + # Browsers + brave + firefox-devedition + google-chrome + tor-browser + browserpass + + # Communication + telegram-desktop + discord + zoom-us + + # Media + spotify + vlc + mpv + # gimp3-with-plugins + # obs-studio + + # Productivity + pdftk + unrar + p7zip + copyq + # Text editors vscode - unstable.zed-editor - ]; + zed-editor + ]); } diff --git a/home/xfeusw/applications/media.nix b/home/xfeusw/applications/media.nix deleted file mode 100644 index eb9d0e8..0000000 --- a/home/xfeusw/applications/media.nix +++ /dev/null @@ -1,21 +0,0 @@ -# home/xfeusw/applications/media.nix -{ pkgs, unstable, ... }: -{ - home.packages = - with pkgs; - [ - # Music and video - spotify - vlc - mpv - - # Graphics - gimp3-with-plugins - - # Screen recording - obs-studio - ] - ++ (with unstable; [ - # Add unstable media packages here if needed - ]); -} diff --git a/home/xfeusw/applications/productivity.nix b/home/xfeusw/applications/productivity.nix deleted file mode 100644 index 8d6ab96..0000000 --- a/home/xfeusw/applications/productivity.nix +++ /dev/null @@ -1,15 +0,0 @@ -# home/xfeusw/applications/productivity.nix -{ pkgs, ... }: -{ - home.packages = with pkgs; [ - # PDF tools - pdftk - - # Archive tools - unrar - p7zip - - # Clipboard manager - copyq - ]; -} diff --git a/home/xfeusw/desktop/gtk.nix b/home/xfeusw/desktop/gtk.nix index 432a984..739e047 100644 --- a/home/xfeusw/desktop/gtk.nix +++ b/home/xfeusw/desktop/gtk.nix @@ -16,42 +16,20 @@ size = 24; }; - # Custom CSS to override title bar colors - gtk3.extraCss = '' - headerbar { - background: #2d2d2d; - color: #ffffff; - } + # gtk4.extraCss = '' + # headerbar { + # background: #2d2d2d; + # color: #ffffff; + # } - headerbar button { - background: transparent; - color: #ffffff; - } + # headerbar button { + # background: transparent; + # color: #ffffff; + # } - headerbar button:hover { - background: rgba(255, 255, 255, 0.1); - } - - .titlebar { - background: #2d2d2d; - color: #ffffff; - } - ''; - - gtk4.extraCss = '' - headerbar { - background: #2d2d2d; - color: #ffffff; - } - - headerbar button { - background: transparent; - color: #ffffff; - } - - headerbar button:hover { - background: rgba(255, 255, 255, 0.1); - } - ''; + # headerbar button:hover { + # background: rgba(255, 255, 255, 0.1); + # } + # ''; }; } diff --git a/home/xfeusw/development/default.nix b/home/xfeusw/development/default.nix index 61cbba9..25bd221 100644 --- a/home/xfeusw/development/default.nix +++ b/home/xfeusw/development/default.nix @@ -1,4 +1,3 @@ -# home/xfeusw/development/default.nix { nixvim-config, pkgs, ... }: { imports = [ @@ -6,7 +5,6 @@ ./tools.nix ]; - # Add nixvim home.packages = [ nixvim-config.packages.${pkgs.system}.default ]; diff --git a/home/xfeusw/development/languages/default.nix b/home/xfeusw/development/languages/default.nix index b39e357..40a0601 100644 --- a/home/xfeusw/development/languages/default.nix +++ b/home/xfeusw/development/languages/default.nix @@ -7,6 +7,6 @@ # ./python.nix ./nix.nix ./haskell.nix - ./java-scala.nix + # ./java-scala.nix ]; } diff --git a/home/xfeusw/development/tools.nix b/home/xfeusw/development/tools.nix index 2e494cb..dc3d419 100644 --- a/home/xfeusw/development/tools.nix +++ b/home/xfeusw/development/tools.nix @@ -1,32 +1,29 @@ -# home/xfeusw/development/tools.nix { pkgs, ... }: { home.packages = with pkgs; [ # Modern development tools - gitoxide # Faster git clone - delta # Better git diff - difftastic # Syntax-aware diff - just # Command runner - direnv # Environment management - cachix # Binary cache management - - # Nix-specific tools - nix-fast-build # Faster nix builds - nix-update # Update nix packages - nurl # Generate nix URLs + gitoxide + delta + difftastic + just + direnv + cachix + nix-fast-build + nix-update + nurl # Enhanced CLI tools - bat # Better cat - eza # Better ls - fd # Better find - ripgrep # Better grep - zoxide # Smart cd - fzf # Fuzzy finder - btop # Better top - dust # Better du - procs # Better ps - hyperfine # Benchmarking - tokei # Code statistics + bat + eza + fd + ripgrep + zoxide + fzf + btop + dust + procs + hyperfine + tokei # Build tools gcc @@ -50,14 +47,14 @@ gitui git-absorb - # Container and orchestration tools + # Container tools docker-compose podman-compose kubectl k9s helm - dive # Docker image analyzer - ctop # Container top + dive + ctop # Database tools sqlite @@ -77,22 +74,21 @@ hugo # Text processing - jq # JSON processor - yq # YAML processor - xmlstarlet # XML processor + jq + yq + xmlstarlet # System tools file tree unzip - p7zip findutils patchelf binutils # Security tools - age # Encryption - sops # Secrets management + age + sops # Monitoring htop @@ -101,7 +97,6 @@ bandwhich ]; - # Direnv integration programs.direnv = { enable = true; enableZshIntegration = true; diff --git a/home/xfeusw/home.nix b/home/xfeusw/home.nix index 816183e..ad6bd2d 100644 --- a/home/xfeusw/home.nix +++ b/home/xfeusw/home.nix @@ -1,4 +1,3 @@ -# home/xfeusw/home.nix { nur, ... }: { home = { @@ -6,14 +5,11 @@ homeDirectory = "/home/xfeusw"; stateVersion = "25.05"; enableNixpkgsReleaseCheck = false; - # activation.backupFileExtension = "backup"; }; programs.home-manager.enable = true; fonts.fontconfig.enable = true; - nixpkgs.config.allowUnfree = true; - # Import modular configurations imports = [ nur.modules.homeManager.default ./development diff --git a/home/xfeusw/shell/default.nix b/home/xfeusw/shell/default.nix index 2d5f696..92c1b54 100644 --- a/home/xfeusw/shell/default.nix +++ b/home/xfeusw/shell/default.nix @@ -1,28 +1,8 @@ -# home/xfeusw/shell/default.nix -{ pkgs, ... }: +{ ... }: { imports = [ ./zsh.nix ./starship.nix ./ghostty.nix ]; - - home.packages = with pkgs; [ - # Modern CLI replacements - bat # cat replacement - eza # ls replacement - fd # find replacement - ripgrep # grep replacement - zoxide # cd replacement - fzf # fuzzy finder - - # System monitoring - bottom # top replacement - dust # du replacement - procs # ps replacement - - # Network tools - bandwhich # network bandwidth monitor - dogdns # DNS lookup tool - ]; } diff --git a/home/xfeusw/shell/ghostty.nix b/home/xfeusw/shell/ghostty.nix index 609005e..f57165c 100644 --- a/home/xfeusw/shell/ghostty.nix +++ b/home/xfeusw/shell/ghostty.nix @@ -1,26 +1,20 @@ -# home/xfeusw/shell/ghostty.nix -{ unstable, ... }: +{ pkgs, ... }: { - # Ensure Ghostty is installed from unstable channel - home.packages = with unstable; [ - ghostty + home.packages = with pkgs; [ + unstable.ghostty ]; - # Ghostty configuration file home.file.".config/ghostty/config".text = '' - # Theme and appearance font-family = JetBrains Mono font-size = 11 background-opacity = 0.95 background = 1e1e2e foreground = c0caf5 - # Window settings window-decoration = true window-padding-x = 10 window-padding-y = 10 - # Shell integration with ZSH shell-integration = zsh ''; } From 6ce7bb1d4a73c80607a9f12303a622ae18f341d6 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 16:02:35 +0500 Subject: [PATCH 14/21] gnome extensions update --- flake.nix | 3 ++- home/xfeusw/desktop/dconf/extensions/default.nix | 2 +- home/xfeusw/desktop/dconf/shell.nix | 6 ------ modules/packages/gnome.nix | 4 ---- 4 files changed, 3 insertions(+), 12 deletions(-) diff --git a/flake.nix b/flake.nix index 77eee55..94b166a 100644 --- a/flake.nix +++ b/flake.nix @@ -107,12 +107,13 @@ xfeusw = home-manager.lib.homeManagerConfiguration { pkgs = nixpkgs.legacyPackages.x86_64-linux; extraSpecialArgs = { - inherit inputs nixvim-config nix-colors firefox-addons; + inherit inputs nixvim-config nix-colors firefox-addons nur; }; modules = [ ./home/xfeusw/home.nix nix-colors.homeManagerModules.default { + nixpkgs.config.allowUnfree = true; nixpkgs.overlays = [ nixpkgs-wayland.overlay nur.overlays.default diff --git a/home/xfeusw/desktop/dconf/extensions/default.nix b/home/xfeusw/desktop/dconf/extensions/default.nix index a99546b..33120ba 100644 --- a/home/xfeusw/desktop/dconf/extensions/default.nix +++ b/home/xfeusw/desktop/dconf/extensions/default.nix @@ -4,7 +4,7 @@ ./blur-my-shell.nix ./clipboard-indicator.nix ./coverflow-alt-tab.nix - ./dash-to-panel.nix + # ./dash-to-panel.nix ./date-menu-formatter.nix ./sound-output-device-chooser.nix ./tiling-assistant.nix diff --git a/home/xfeusw/desktop/dconf/shell.nix b/home/xfeusw/desktop/dconf/shell.nix index e09bdcc..1eb7b49 100644 --- a/home/xfeusw/desktop/dconf/shell.nix +++ b/home/xfeusw/desktop/dconf/shell.nix @@ -12,22 +12,16 @@ "org.telegram.desktop.desktop" ]; enabled-extensions = [ - "dash-to-panel@jderose9.github.com" "appindicator@ubuntu.com" "user-theme@gnome-shell-extensions.gcampax.github.com" "Vitals@CoreCoding.com" "blur-my-shell@aunetx" "clipboard-indicator@tudmotu.com" - "gsconnect@andyholmes.github.io" - "caffeine@patapon.info" - "arcmenu@arcmenu.com" "tiling-assistant@leleat-on-github" "date-menu-formatter@marcinjakubowski.github.com" "top-icons-plus@lehmann.rocks" "sound-output-device-chooser@kgshank.net" "coverflowalt-tab@palatis.blogspot.com" - "just-perfection-desktop@just-perfection" - "workspace-indicator@gnome-shell-extensions.gcampax.github.com" ]; }; }; diff --git a/modules/packages/gnome.nix b/modules/packages/gnome.nix index 8287578..466ad63 100644 --- a/modules/packages/gnome.nix +++ b/modules/packages/gnome.nix @@ -23,15 +23,11 @@ gtk-engine-murrine # GNOME extensions - gnomeExtensions.dash-to-panel gnomeExtensions.appindicator gnomeExtensions.user-themes gnomeExtensions.vitals gnomeExtensions.blur-my-shell gnomeExtensions.clipboard-indicator - gnomeExtensions.gsconnect - gnomeExtensions.caffeine - gnomeExtensions.arc-menu gnomeExtensions.tiling-assistant gnomeExtensions.date-menu-formatter gnomeExtensions.topicons-plus From a9ea5476fec25e466523c1c96783965ff2ff798e Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 16:16:57 +0500 Subject: [PATCH 15/21] WIP before filter-branch --- .gitignore | 3 ++- flake.lock | 62 +++++++++++++++++++++++++++--------------------------- 2 files changed, 33 insertions(+), 32 deletions(-) diff --git a/.gitignore b/.gitignore index 25a73b6..63551cb 100644 --- a/.gitignore +++ b/.gitignore @@ -8,7 +8,8 @@ # direnv /.direnv /.envrc +/hosts/acer/secrets.yaml # Misc *.swp -test.nix.blank \ No newline at end of file +test.nix.blank diff --git a/flake.lock b/flake.lock index 3743660..366ea29 100644 --- a/flake.lock +++ b/flake.lock @@ -57,11 +57,11 @@ }, "locked": { "dir": "pkgs/firefox-addons", - "lastModified": 1758600213, - "narHash": "sha256-YP7+UxybMCzHPd5k93pulILnFvSisjgUAGUB/cxWbqU=", + "lastModified": 1759394305, + "narHash": "sha256-bFtYQ2EkbSsExEBI2qXaoTwY+HxTHibMr7P3zxx0l+8=", "owner": "rycee", "repo": "nur-expressions", - "rev": "8a0333bf11a0fab386c80fa018617bb050156ec5", + "rev": "badfc272422134c7201891e1c1b8a3d465270956", "type": "gitlab" }, "original": { @@ -336,11 +336,11 @@ "xdph": "xdph" }, "locked": { - "lastModified": 1758542519, - "narHash": "sha256-NHEzK6MN8Tv9YrnJb2A9KxcOI2cCsKRqZOC5kUeG8Aw=", + "lastModified": 1759399554, + "narHash": "sha256-FB8+mdeMOOCL6JzJ4J7zfsg/lDB/rtxO27tlKtYJIxo=", "ref": "refs/heads/main", - "rev": "70a7047ee175d2e7fca1575d50a3738ac40fd2c6", - "revCount": 6446, + "rev": "3bcfa94ee4189faaa4daf661949e88cf28c00d94", + "revCount": 6473, "submodules": true, "type": "git", "url": "https://github.com/hyprwm/Hyprland" @@ -608,11 +608,11 @@ }, "nixos-hardware": { "locked": { - "lastModified": 1757943327, - "narHash": "sha256-w6cDExPBqbq7fTLo4dZ1ozDGeq3yV6dSN4n/sAaS6OM=", + "lastModified": 1759261527, + "narHash": "sha256-wPd5oGvBBpUEzMF0kWnXge0WITNsITx/aGI9qLHgJ4g=", "owner": "NixOS", "repo": "nixos-hardware", - "rev": "67a709cfe5d0643dafd798b0b613ed579de8be05", + "rev": "e087756cf4abbe1a34f3544c480fc1034d68742f", "type": "github" }, "original": { @@ -624,11 +624,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1758346548, - "narHash": "sha256-afXE7AJ7MY6wY1pg/Y6UPHNYPy5GtUKeBkrZZ/gC71E=", + "lastModified": 1759281824, + "narHash": "sha256-FIBE1qXv9TKvSNwst6FumyHwCRH3BlWDpfsnqRDCll0=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "b2a3852bd078e68dd2b3dfa8c00c67af1f0a7d20", + "rev": "5b5be50345d4113d04ba58c444348849f5585b4a", "type": "github" }, "original": { @@ -685,11 +685,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1758277210, - "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", + "lastModified": 1759036355, + "narHash": "sha256-0m27AKv6ka+q270dw48KflE0LwQYrO7Fm4/2//KCVWg=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", + "rev": "e9f00bd893984bc8ce46c895c3bf7cac95331127", "type": "github" }, "original": { @@ -706,11 +706,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1758372772, - "narHash": "sha256-9HMoc7wMbC9ZZjB8nPAyXTzaxHJRjnir5SM7G4jg+tQ=", + "lastModified": 1759371013, + "narHash": "sha256-owED1ZtsB6iQqamD/V6UYdbyRcD2hXrZPWXsN38aAZE=", "owner": "nix-community", "repo": "nixpkgs-wayland", - "rev": "faa8596885fbcd162a504fe7e27158f0ad8fc43a", + "rev": "b6fd8e2297ee24a0b0ee914b805c302460d39b8c", "type": "github" }, "original": { @@ -721,11 +721,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1758277210, - "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", + "lastModified": 1759036355, + "narHash": "sha256-0m27AKv6ka+q270dw48KflE0LwQYrO7Fm4/2//KCVWg=", "owner": "nixos", "repo": "nixpkgs", - "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", + "rev": "e9f00bd893984bc8ce46c895c3bf7cac95331127", "type": "github" }, "original": { @@ -753,11 +753,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1758277210, - "narHash": "sha256-iCGWf/LTy+aY0zFu8q12lK8KuZp7yvdhStehhyX1v8w=", + "lastModified": 1759036355, + "narHash": "sha256-0m27AKv6ka+q270dw48KflE0LwQYrO7Fm4/2//KCVWg=", "owner": "nixos", "repo": "nixpkgs", - "rev": "8eaee110344796db060382e15d3af0a9fc396e0e", + "rev": "e9f00bd893984bc8ce46c895c3bf7cac95331127", "type": "github" }, "original": { @@ -815,11 +815,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1758603982, - "narHash": "sha256-ig0+mpQvUrp56909gMkF0lxQ0nGEXZtljIZWnrrRG1Y=", + "lastModified": 1759399691, + "narHash": "sha256-o/4aNcIZz2Xq/LzhsRzuSfYJVS1Ouw3AlfbE3VUMrsc=", "owner": "nix-community", "repo": "NUR", - "rev": "de4f5ff4f5dabad8356f67119fbe582a44c9e969", + "rev": "507f3337de24fe408aab514359e7247a1818c4a4", "type": "github" }, "original": { @@ -899,11 +899,11 @@ ] }, "locked": { - "lastModified": 1758425756, - "narHash": "sha256-L3N8zV6wsViXiD8i3WFyrvjDdz76g3tXKEdZ4FkgQ+Y=", + "lastModified": 1759188042, + "narHash": "sha256-f9QC2KKiNReZDG2yyKAtDZh0rSK2Xp1wkPzKbHeQVRU=", "owner": "Mic92", "repo": "sops-nix", - "rev": "e0fdaea3c31646e252a60b42d0ed8eafdb289762", + "rev": "9fcfabe085281dd793589bdc770a2e577a3caa5d", "type": "github" }, "original": { From 22920085c309a8659347932953de0c22f759a86c Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 16:34:58 +0500 Subject: [PATCH 16/21] removed sops --- .sops.yaml | 8 -------- 1 file changed, 8 deletions(-) delete mode 100644 .sops.yaml diff --git a/.sops.yaml b/.sops.yaml deleted file mode 100644 index 9413368..0000000 --- a/.sops.yaml +++ /dev/null @@ -1,8 +0,0 @@ -keys: - - &main_key age1nguz9mhgylxezcctn3c4qk8e6upes0c3s5n5mkdlpxdujham5fusd5xvy6 - -creation_rules: - - path_regex: hosts/.*/secrets\.yaml$ - key_groups: - - age: - - *main_key From 91639ddd8e7ba1887d5a601cb2509fdee6f13aae Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 16:40:59 +0500 Subject: [PATCH 17/21] sops removed --- flake.nix | 7 ----- home/xfeusw/development/tools.nix | 1 - hosts/acer/configuration.nix | 28 ++++---------------- modules/backup.nix | 43 ------------------------------- 4 files changed, 5 insertions(+), 74 deletions(-) delete mode 100644 modules/backup.nix diff --git a/flake.nix b/flake.nix index 94b166a..1a77fb0 100644 --- a/flake.nix +++ b/flake.nix @@ -28,11 +28,6 @@ inputs.nixpkgs.follows = "nixpkgs"; }; - sops-nix = { - url = "github:Mic92/sops-nix"; - inputs.nixpkgs.follows = "nixpkgs"; - }; - hyprland = { url = "git+https://github.com/hyprwm/Hyprland?submodules=1"; inputs.nixpkgs.follows = "nixpkgs"; @@ -50,7 +45,6 @@ impermanence, nix-colors, firefox-addons, - sops-nix, flake-utils, hyprland, ... @@ -68,7 +62,6 @@ nixos-hardware.nixosModules.common-pc-ssd nixos-hardware.nixosModules.common-pc-laptop nur.modules.nixos.default - sops-nix.nixosModules.sops { nixpkgs.overlays = [ diff --git a/home/xfeusw/development/tools.nix b/home/xfeusw/development/tools.nix index dc3d419..cd4a4d5 100644 --- a/home/xfeusw/development/tools.nix +++ b/home/xfeusw/development/tools.nix @@ -88,7 +88,6 @@ # Security tools age - sops # Monitoring htop diff --git a/hosts/acer/configuration.nix b/hosts/acer/configuration.nix index a38dec8..f924c42 100644 --- a/hosts/acer/configuration.nix +++ b/hosts/acer/configuration.nix @@ -10,7 +10,6 @@ ../../modules/users.nix ../../modules/security.nix ../../modules/performance.nix - ../../modules/backup.nix # Desktop environment ../../modules/desktop/gnome.nix @@ -27,14 +26,13 @@ loader = { systemd-boot = { enable = true; - configurationLimit = 10; # Limit boot entries - editor = false; # Security: disable boot editor + configurationLimit = 10; + editor = false; }; efi.canTouchEfiVariables = true; - timeout = 2; # Reduced timeout + timeout = 2; }; - # Kernel optimizations kernelParams = [ "quiet" "splash" @@ -43,14 +41,12 @@ "rd.udev.log_level=3" ]; - # Faster boot initrd.verbose = false; consoleLogLevel = 0; - kernelModules = [ "tcp_bbr" ]; # Better congestion control + kernelModules = [ "tcp_bbr" ]; }; - # Timezone and localization - time.timeZone = "Asia/Samarkand"; + time.timeZone = "Asia/Tashkent"; i18n = { defaultLocale = "en_US.UTF-8"; supportedLocales = [ @@ -59,19 +55,5 @@ ]; }; - # Secrets management - sops = { - defaultSopsFile = ./secrets.yaml; - age.keyFile = "/home/xfeusw/.config/sops/age/keys.txt"; - secrets = { - user-password.neededForUsers = true; - restic-password = { - owner = "root"; - mode = "0600"; - }; - }; - }; - - # NixOS compatibility version system.stateVersion = "25.05"; } diff --git a/modules/backup.nix b/modules/backup.nix deleted file mode 100644 index bb1def4..0000000 --- a/modules/backup.nix +++ /dev/null @@ -1,43 +0,0 @@ -# modules/backup.nix -{ ... }: -{ - # Restic backup service - services.restic.backups = { - localbackup = { - initialize = true; - repository = "/backup/restic"; - passwordFile = "/etc/nixos/secrets/restic-password"; - paths = [ - "/home/xfeusw/Documents" - "/home/xfeusw/.config" - "/home/xfeusw/Pictures" - ]; - exclude = [ - "/home/xfeusw/.cache" - "/home/xfeusw/.local/share/Trash" - "*.tmp" - "*~" - ]; - timerConfig = { - OnCalendar = "daily"; - Persistent = true; - }; - pruneOpts = [ - "--keep-daily 7" - "--keep-weekly 4" - "--keep-monthly 12" - "--keep-yearly 3" - ]; - }; - }; - - # Create backup directory and password file - system.activationScripts.backup-setup = '' - mkdir -p /backup - if [ ! -f /etc/nixos/secrets/restic-password ]; then - mkdir -p /etc/nixos/secrets - echo "change-this-password" > /etc/nixos/secrets/restic-password - chmod 600 /etc/nixos/secrets/restic-password - fi - ''; -} From 24fc1267c407c1a9e0c3df55f7c5c54022f46c30 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 17:01:23 +0500 Subject: [PATCH 18/21] language update --- flake.lock | 23 +------------------ home/xfeusw/development/languages/default.nix | 4 ++-- 2 files changed, 3 insertions(+), 24 deletions(-) diff --git a/flake.lock b/flake.lock index 366ea29..c9b3707 100644 --- a/flake.lock +++ b/flake.lock @@ -888,28 +888,7 @@ "nixpkgs-unstable": "nixpkgs-unstable", "nixpkgs-wayland": "nixpkgs-wayland", "nixvim-config": "nixvim-config", - "nur": "nur", - "sops-nix": "sops-nix" - } - }, - "sops-nix": { - "inputs": { - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1759188042, - "narHash": "sha256-f9QC2KKiNReZDG2yyKAtDZh0rSK2Xp1wkPzKbHeQVRU=", - "owner": "Mic92", - "repo": "sops-nix", - "rev": "9fcfabe085281dd793589bdc770a2e577a3caa5d", - "type": "github" - }, - "original": { - "owner": "Mic92", - "repo": "sops-nix", - "type": "github" + "nur": "nur" } }, "systems": { diff --git a/home/xfeusw/development/languages/default.nix b/home/xfeusw/development/languages/default.nix index 40a0601..f82fd6d 100644 --- a/home/xfeusw/development/languages/default.nix +++ b/home/xfeusw/development/languages/default.nix @@ -3,10 +3,10 @@ { imports = [ ./rust.nix - ./nodejs.nix + # ./nodejs.nix # ./python.nix ./nix.nix - ./haskell.nix + # ./haskell.nix # ./java-scala.nix ]; } From 7069f0dd0a27bfaf9174b184b6ebf4ce848cb670 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Thu, 2 Oct 2025 17:18:33 +0500 Subject: [PATCH 19/21] language update --- home/xfeusw/development/languages/default.nix | 4 -- home/xfeusw/development/languages/haskell.nix | 17 ------- .../development/languages/java-scala.nix | 17 ------- home/xfeusw/development/languages/nodejs.nix | 49 ------------------- home/xfeusw/development/languages/python.nix | 21 -------- 5 files changed, 108 deletions(-) delete mode 100644 home/xfeusw/development/languages/haskell.nix delete mode 100644 home/xfeusw/development/languages/java-scala.nix delete mode 100644 home/xfeusw/development/languages/nodejs.nix delete mode 100644 home/xfeusw/development/languages/python.nix diff --git a/home/xfeusw/development/languages/default.nix b/home/xfeusw/development/languages/default.nix index f82fd6d..37ebe8d 100644 --- a/home/xfeusw/development/languages/default.nix +++ b/home/xfeusw/development/languages/default.nix @@ -3,10 +3,6 @@ { imports = [ ./rust.nix - # ./nodejs.nix - # ./python.nix ./nix.nix - # ./haskell.nix - # ./java-scala.nix ]; } diff --git a/home/xfeusw/development/languages/haskell.nix b/home/xfeusw/development/languages/haskell.nix deleted file mode 100644 index 25a4cf6..0000000 --- a/home/xfeusw/development/languages/haskell.nix +++ /dev/null @@ -1,17 +0,0 @@ -# home/xfeusw/development/languages/haskell.nix -{ pkgs, ... }: -{ - home.packages = with pkgs; [ - # Haskell compiler and tools - haskell.compiler.ghc96 - cabal-install - stack - - # Haskell language server - haskell-language-server - - # Additional tools - haskellPackages.fourmolu # Formatter - haskellPackages.hlint # Linter - ]; -} diff --git a/home/xfeusw/development/languages/java-scala.nix b/home/xfeusw/development/languages/java-scala.nix deleted file mode 100644 index 59c41a1..0000000 --- a/home/xfeusw/development/languages/java-scala.nix +++ /dev/null @@ -1,17 +0,0 @@ -# home/xfeusw/development/languages/java-scala.nix -{ pkgs, ... }: -{ - home.packages = with pkgs; [ - # Java - jdk21 - maven - gradle - - # Scala - scala_3 - sbt - - # Language servers - metals # Scala language server - ]; -} diff --git a/home/xfeusw/development/languages/nodejs.nix b/home/xfeusw/development/languages/nodejs.nix deleted file mode 100644 index eb2ee2a..0000000 --- a/home/xfeusw/development/languages/nodejs.nix +++ /dev/null @@ -1,49 +0,0 @@ -# home/xfeusw/development/languages/nodejs.nix -{pkgs, ...}: { - home.packages = with pkgs; [ - # Node.js - nodejs_22 - pnpm - yarn - package-version-server - - # OpenSSL for Prisma and other Node.js native modules - openssl - - # Global Node.js tools - nodePackages.typescript - nodePackages.typescript-language-server - nodePackages.eslint - nodePackages.prettier - nodePackages."@tailwindcss/language-server" - - # Prisma dependencies - prisma-engines # Provides Prisma engine binaries - nodePackages.prisma # Prisma CLI for database management - - # Prisma dependencies (for query engine) - pkg-config - libuuid # Required for some Prisma setups - ]; - - # Environment variables for Prisma and Node.js - home.sessionVariables = { - # Prisma engine paths - PRISMA_QUERY_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/query-engine"; - PRISMA_QUERY_ENGINE_LIBRARY = "${pkgs.prisma-engines}/lib/libquery_engine.node"; - PRISMA_SCHEMA_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/schema-engine"; - PRISMA_FMT_BINARY = "${pkgs.prisma-engines}/bin/prisma-fmt"; - PRISMA_INTROSPECTION_ENGINE_BINARY = "${pkgs.prisma-engines}/bin/introspection-engine"; - - # Fallback for checksum issues - PRISMA_ENGINES_CHECKSUM_IGNORE_MISSING = "1"; - - # Ensure OpenSSL is available - OPENSSL_DIR = "${pkgs.openssl.dev}/"; - OPENSSL_LIB_DIR = "${pkgs.openssl.out}/lib"; - OPENSSL_INCLUDE_DIR = "${pkgs.openssl.dev}/include"; - - # Node.js global packages path - NODE_PATH = "${pkgs.nodejs_22}/lib/node_modules"; - }; -} diff --git a/home/xfeusw/development/languages/python.nix b/home/xfeusw/development/languages/python.nix deleted file mode 100644 index 980825e..0000000 --- a/home/xfeusw/development/languages/python.nix +++ /dev/null @@ -1,21 +0,0 @@ -# home/xfeusw/development/languages/python.nix -{ pkgs, ... }: -{ - home.packages = with pkgs; [ - # Python tools - # python312Packages.pip - # python312Packages.pipx - # python312Packages.virtualenv - # poetry - - # Development tools - # python312Packages.black - # python312Packages.isort - # python312Packages.flake8 - # python312Packages.mypy - # python312Packages.pytest - - # Language server - # python312Packages.python-lsp-server - ]; -} From 251b894ae54aa76888da0577bc09f38e7f7b5052 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Fri, 3 Oct 2025 03:05:26 +0500 Subject: [PATCH 20/21] optimization --- flake.nix | 5 ++ .../dconf/extensions/clipboard-indicator.nix | 10 ---- .../dconf/extensions/coverflow-alt-tab.nix | 14 ----- .../dconf/extensions/dash-to-panel.nix | 17 ------ .../desktop/dconf/extensions/default.nix | 4 -- .../dconf/extensions/tiling-assistant.nix | 9 --- home/xfeusw/desktop/dconf/shell.nix | 1 - modules/desktop/gnome.nix | 2 +- modules/hardware/graphics.nix | 56 ++++++++++++++++++- modules/packages/gnome.nix | 4 -- modules/packages/system-essentials.nix | 3 + 11 files changed, 64 insertions(+), 61 deletions(-) delete mode 100644 home/xfeusw/desktop/dconf/extensions/clipboard-indicator.nix delete mode 100644 home/xfeusw/desktop/dconf/extensions/coverflow-alt-tab.nix delete mode 100644 home/xfeusw/desktop/dconf/extensions/dash-to-panel.nix delete mode 100644 home/xfeusw/desktop/dconf/extensions/tiling-assistant.nix diff --git a/flake.nix b/flake.nix index 1a77fb0..f963650 100644 --- a/flake.nix +++ b/flake.nix @@ -75,6 +75,11 @@ }) ]; + nixpkgs.config = { + allowUnfree = true; + nvidia.acceptLicense = true; + }; + nix.settings = { substituters = [ "https://cache.nixos.org/" diff --git a/home/xfeusw/desktop/dconf/extensions/clipboard-indicator.nix b/home/xfeusw/desktop/dconf/extensions/clipboard-indicator.nix deleted file mode 100644 index cefca46..0000000 --- a/home/xfeusw/desktop/dconf/extensions/clipboard-indicator.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/clipboard-indicator" = { - history-size = 50; - strip-text = true; - toggle-menu = "v"; - }; - }; -} diff --git a/home/xfeusw/desktop/dconf/extensions/coverflow-alt-tab.nix b/home/xfeusw/desktop/dconf/extensions/coverflow-alt-tab.nix deleted file mode 100644 index ac298fb..0000000 --- a/home/xfeusw/desktop/dconf/extensions/coverflow-alt-tab.nix +++ /dev/null @@ -1,14 +0,0 @@ -# home/xfeusw/desktop/dconf/extensions/coverflow-alt-tab.nix -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/coverflow-alt-tab" = { - switcher-style = "coverflow"; # Options: coverflow, timeline - animation-time = 0.3; # Animation duration in seconds - dim-factor = 0.4; # Background dimming factor (0.0 to 1.0) - preview-scale = 0.5; # Window preview scale - hide-panel = true; # Hide panel during alt-tab - icon-style = "overlay"; # Options: classic, overlay - }; - }; -} diff --git a/home/xfeusw/desktop/dconf/extensions/dash-to-panel.nix b/home/xfeusw/desktop/dconf/extensions/dash-to-panel.nix deleted file mode 100644 index af4200c..0000000 --- a/home/xfeusw/desktop/dconf/extensions/dash-to-panel.nix +++ /dev/null @@ -1,17 +0,0 @@ -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/dash-to-panel" = { - panel-position = "TOP"; - panel-size = 30; - appicon-margin = 4; - appicon-padding = 4; - animate-show-apps = true; - show-activities-button = true; - show-desktop-icon = true; - multi-monitor = false; - window-preview-size = 150; - scroll-action = "CYCLE_WINDOWS"; - }; - }; -} diff --git a/home/xfeusw/desktop/dconf/extensions/default.nix b/home/xfeusw/desktop/dconf/extensions/default.nix index 33120ba..8b7e52d 100644 --- a/home/xfeusw/desktop/dconf/extensions/default.nix +++ b/home/xfeusw/desktop/dconf/extensions/default.nix @@ -2,12 +2,8 @@ { imports = [ ./blur-my-shell.nix - ./clipboard-indicator.nix - ./coverflow-alt-tab.nix - # ./dash-to-panel.nix ./date-menu-formatter.nix ./sound-output-device-chooser.nix - ./tiling-assistant.nix ./top-icons-plus.nix ./user-theme.nix ./vitals.nix diff --git a/home/xfeusw/desktop/dconf/extensions/tiling-assistant.nix b/home/xfeusw/desktop/dconf/extensions/tiling-assistant.nix deleted file mode 100644 index aae0007..0000000 --- a/home/xfeusw/desktop/dconf/extensions/tiling-assistant.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ ... }: -{ - dconf.settings = { - "org/gnome/shell/extensions/tiling-assistant" = { - enable-tiling = true; - tile-maximize = true; - }; - }; -} diff --git a/home/xfeusw/desktop/dconf/shell.nix b/home/xfeusw/desktop/dconf/shell.nix index 1eb7b49..f2f285b 100644 --- a/home/xfeusw/desktop/dconf/shell.nix +++ b/home/xfeusw/desktop/dconf/shell.nix @@ -12,7 +12,6 @@ "org.telegram.desktop.desktop" ]; enabled-extensions = [ - "appindicator@ubuntu.com" "user-theme@gnome-shell-extensions.gcampax.github.com" "Vitals@CoreCoding.com" "blur-my-shell@aunetx" diff --git a/modules/desktop/gnome.nix b/modules/desktop/gnome.nix index 4ee794a..5ca4c48 100644 --- a/modules/desktop/gnome.nix +++ b/modules/desktop/gnome.nix @@ -36,11 +36,11 @@ gnome-tweaks gnome-extension-manager dconf-editor + gnome-network-displays ]; # Remove default GNOME applications not needed environment.gnome.excludePackages = with pkgs; [ - epiphany # GNOME web browser (you have Firefox) geary # Email client gnome-music gnome-photos diff --git a/modules/hardware/graphics.nix b/modules/hardware/graphics.nix index 12755b2..c06fbf0 100644 --- a/modules/hardware/graphics.nix +++ b/modules/hardware/graphics.nix @@ -1,6 +1,8 @@ # modules/hardware/graphics.nix -{ pkgs, ... }: +{ pkgs, config, ... }: { + nixpkgs.config.nvidia.acceptLicense = true; + # Hardware acceleration and graphics hardware.graphics = { enable = true; @@ -11,4 +13,56 @@ libvdpau-va-gl ]; }; + + # NVIDIA Configuration for 940MX + services.xserver.videoDrivers = [ "nvidia" ]; + + hardware.nvidia = { + # Modesetting is required for Wayland + modesetting.enable = true; + + # Enable power management (recommended for laptops) + powerManagement.enable = true; + powerManagement.finegrained = false; + + # Use the open source kernel module (not compatible with 940MX - use proprietary) + open = false; + + # Enable NVIDIA settings menu + nvidiaSettings = true; + + # Select the appropriate driver version for 940MX + # The 940MX requires legacy drivers (470.xx series is the last to support it) + package = config.boot.kernelPackages.nvidiaPackages.legacy_470; + + # PRIME configuration for laptop with both Intel and NVIDIA GPUs + prime = { + # Enable PRIME offload mode (recommended for laptops) + # This allows you to use Intel for regular tasks and NVIDIA for demanding apps + offload = { + enable = true; + enableOffloadCmd = true; + }; + + # Alternative: Use sync mode (both GPUs always active - worse battery life) + # Uncomment these and comment out offload section if you prefer: + # sync.enable = true; + + # Find your bus IDs by running: lspci | grep -E "VGA|3D" + # Intel bus ID (integrated GPU) + intelBusId = "PCI:0:2:0"; # Typical value, verify with lspci + + # NVIDIA bus ID (discrete GPU) + nvidiaBusId = "PCI:1:0:0"; # Typical value, verify with lspci + }; + }; + + # Environment variables for NVIDIA + environment.sessionVariables = { + # Force apps to use NVIDIA when needed + # WLR_NO_HARDWARE_CURSORS = "1"; # Uncomment if cursor issues on Wayland + }; + + # Blacklist nouveau (open-source NVIDIA driver) + boot.blacklistedKernelModules = [ "nouveau" ]; } diff --git a/modules/packages/gnome.nix b/modules/packages/gnome.nix index 466ad63..f215633 100644 --- a/modules/packages/gnome.nix +++ b/modules/packages/gnome.nix @@ -23,15 +23,11 @@ gtk-engine-murrine # GNOME extensions - gnomeExtensions.appindicator gnomeExtensions.user-themes gnomeExtensions.vitals gnomeExtensions.blur-my-shell - gnomeExtensions.clipboard-indicator - gnomeExtensions.tiling-assistant gnomeExtensions.date-menu-formatter gnomeExtensions.topicons-plus gnomeExtensions.sound-output-device-chooser - gnomeExtensions.coverflow-alt-tab ]; } diff --git a/modules/packages/system-essentials.nix b/modules/packages/system-essentials.nix index 7702cc0..dd8c548 100644 --- a/modules/packages/system-essentials.nix +++ b/modules/packages/system-essentials.nix @@ -31,5 +31,8 @@ sysstat usbutils pciutils + + nvidia-vaapi-driver + nvtopPackages.nvidia ]; } From 5bf2adc1de20340eaab7d364c17ed75ce0287a85 Mon Sep 17 00:00:00 2001 From: xfeusw Date: Fri, 3 Oct 2025 17:46:36 +0500 Subject: [PATCH 21/21] latest --- modules/hardware/graphics.nix | 76 +++++++++++++++++------------------ 1 file changed, 38 insertions(+), 38 deletions(-) diff --git a/modules/hardware/graphics.nix b/modules/hardware/graphics.nix index c06fbf0..a90b7c8 100644 --- a/modules/hardware/graphics.nix +++ b/modules/hardware/graphics.nix @@ -15,54 +15,54 @@ }; # NVIDIA Configuration for 940MX - services.xserver.videoDrivers = [ "nvidia" ]; + services.xserver.videoDrivers = [ "nvidia" ]; - hardware.nvidia = { - # Modesetting is required for Wayland - modesetting.enable = true; + hardware.nvidia = { + # Modesetting is required for Wayland + modesetting.enable = true; - # Enable power management (recommended for laptops) - powerManagement.enable = true; - powerManagement.finegrained = false; + # Enable power management (recommended for laptops) + powerManagement.enable = true; + powerManagement.finegrained = false; - # Use the open source kernel module (not compatible with 940MX - use proprietary) - open = false; + # Use the open source kernel module (not compatible with 940MX - use proprietary) + open = false; - # Enable NVIDIA settings menu - nvidiaSettings = true; + # Enable NVIDIA settings menu + nvidiaSettings = true; - # Select the appropriate driver version for 940MX - # The 940MX requires legacy drivers (470.xx series is the last to support it) - package = config.boot.kernelPackages.nvidiaPackages.legacy_470; + # Select the appropriate driver version for 940MX + # The 940MX requires legacy drivers (470.xx series is the last to support it) + package = config.boot.kernelPackages.nvidiaPackages.legacy_470; - # PRIME configuration for laptop with both Intel and NVIDIA GPUs - prime = { - # Enable PRIME offload mode (recommended for laptops) - # This allows you to use Intel for regular tasks and NVIDIA for demanding apps - offload = { - enable = true; - enableOffloadCmd = true; - }; + # PRIME configuration for laptop with both Intel and NVIDIA GPUs + prime = { + # Enable PRIME offload mode (recommended for laptops) + # This allows you to use Intel for regular tasks and NVIDIA for demanding apps + offload = { + enable = true; + enableOffloadCmd = true; + }; - # Alternative: Use sync mode (both GPUs always active - worse battery life) - # Uncomment these and comment out offload section if you prefer: - # sync.enable = true; + # Alternative: Use sync mode (both GPUs always active - worse battery life) + # Uncomment these and comment out offload section if you prefer: + # sync.enable = true; - # Find your bus IDs by running: lspci | grep -E "VGA|3D" - # Intel bus ID (integrated GPU) - intelBusId = "PCI:0:2:0"; # Typical value, verify with lspci + # Find your bus IDs by running: lspci | grep -E "VGA|3D" + # Intel bus ID (integrated GPU) + intelBusId = "PCI:0:2:0"; # Typical value, verify with lspci - # NVIDIA bus ID (discrete GPU) - nvidiaBusId = "PCI:1:0:0"; # Typical value, verify with lspci - }; + # NVIDIA bus ID (discrete GPU) + nvidiaBusId = "PCI:1:0:0"; # Typical value, verify with lspci }; + }; - # Environment variables for NVIDIA - environment.sessionVariables = { - # Force apps to use NVIDIA when needed - # WLR_NO_HARDWARE_CURSORS = "1"; # Uncomment if cursor issues on Wayland - }; + # Environment variables for NVIDIA + environment.sessionVariables = { + # Force apps to use NVIDIA when needed + # WLR_NO_HARDWARE_CURSORS = "1"; # Uncomment if cursor issues on Wayland + }; - # Blacklist nouveau (open-source NVIDIA driver) - boot.blacklistedKernelModules = [ "nouveau" ]; + # Blacklist nouveau (open-source NVIDIA driver) + boot.blacklistedKernelModules = [ "nouveau" ]; }