nixos: gen 52 @ lilac — 2026-09-18 20:58 26.05.20260814.02e0898 (Yarara) -----

This commit is contained in:
2026-09-18 21:04:39 -06:00
parent a17047a67a
commit 8878543aeb
4 changed files with 168 additions and 3 deletions
+12
View File
@@ -0,0 +1,12 @@
{
"permissions": {
"allow": [
"Read(//home/jashton/.local/state/nix/profiles/**)",
"Read(//nix/var/nix/profiles/**)",
"Read(//nix/store/**)",
"Bash(systemctl --user show-environment)",
"Bash(nix eval *)",
"Bash(nix-instantiate --parse /home/jashton/.dotfiles/home/jashton.nix)"
]
}
}
+131
View File
@@ -0,0 +1,131 @@
# .dotfiles
NixOS + Home Manager configuration for jashton's machines, built as a single flake.
## NixOS Flakes Structure
```
.
├── flake.nix / flake.lock Inputs + the 3 nixosConfigurations (violet, lilac, lavender)
├── hosts/<name>/ Per-machine entrypoint + hardware.nix
├── system/ Shared NixOS (system-level) configuration
├── home/ Home Manager configuration for user "jashton"
├── secrets/ + .sops.yaml sops-nix encrypted secrets
└── ports.registry State file written by the find-open-port script
```
**`flake.nix`** pins `nixpkgs` to `nixos-26.05` (plus an `nixpkgs-unstable` follower), and pulls in `home-manager`, `sops-nix`, `niri` (compositor), `wvkbd-src` (on-screen keyboard source), the DankMaterialShell trio (`dms`, `dms-plugin-registry`, `danksearch`), and `nixos-hardware`. Its `outputs` define three `nixosConfigurations`, one per host — each wires up the niri/dms-plugin-registry/sops-nix NixOS modules and a `home-manager.users.jashton` block importing `home/jashton.nix` (plus the `danksearch` home module).
**`hosts/`** — one directory per machine, each with `default.nix` (hostname + host-specific services/hardware tweaks, imports `../../system`) and `hardware.nix` (generated hardware scan):
- `violet` — imports the ThinkPad-specific security module (`system/security/thinkpad.nix`), disables lid-switch suspend, has (disabled) TLP power-profile tuning, and enables `input-remapper`.
- `lilac` — Framework laptop (Intel Core Ultra series 3, via `nixos-hardware`), fingerprint reader + Thunderbolt/bolt + Intel graphics acceleration.
- `lavender` — minimal host, just graphics enablement.
- Both `violet`/`lilac` open a Thunderbolt-networking point-to-point link (`thunderbolt0`, ports 4242).
**`system/`** — shared NixOS config imported by every host, split by concern:
- `packages.nix` — system-wide packages, unfree allowed, plus a hand-written `unix` script (`sudo nixos-rebuild switch`, then auto-commits/pushes the dotfiles repo on success) and Steam setup.
- `core/` — `boot.nix` (systemd-boot, `uinput` module), `audio.nix` (PipeWire/Bluetooth tuning), `env.nix` (zsh + oh-my-zsh, Nerd Font, flakes enabled, shell aliases), `locale.nix` (Denver/en_US), `power.nix` (deep sleep).
- `security/` — `sops.nix` (age-via-SSH-host-key secrets), `sudo.nix` (passwordless `tlp` for jashton), `systemd.nix`, `thinkpad.nix` (fprintd), `users.nix` (user/group defs).
- `network/` — NetworkManager + firewall, plus `pi-hole.nix` (a Pi-hole container run via Podman `oci-containers`).
- `services/` — currently an empty placeholder module (compositor/greeter services are declared per-host instead, see `hosts/violet/default.nix`).
- `virtualisation/` — Podman (with Docker compat), Waydroid, VirtualBox, libvirtd.
**`home/`** — Home Manager config for `jashton`:
- `jashton.nix` — top-level user config: session vars, SSH client config (aliases for `lavender`/`violet`/`lilac`/`heliotrope`), the `lan-mouse` user service, workspace directory scaffolding (`~/dev`, `~/school`, etc.), a `custom_wvkbd` package override (builds `wvkbd` from `wvkbd-src` against the `.custom.h` files below), and a set of hand-written shell tools installed as packages: `jroot`/`jbuild`/`jrun`/`jtest`/`jclean` (Java project tooling — see below), `fkill` (interactive `pkill` by name), `find-open-port` (dev-port registry in `ports.registry`).
- `programs/` — `default.nix` imports `alacritty.nix` (terminal theme/font), `git.nix` (identity + ignores), `nvim.nix` (full Neovim config: LSP, completion, Java/jdtls + DAP debugging — see Keybinds). `keymap.custom.h`, `layout.custom.h`, `config.custom.h` (+ `.bak` backups) are C source overrides for wvkbd's `mobintl` on-screen-keyboard layout, spliced into the `custom_wvkbd` build in `jashton.nix`.
- `desktop/` — `default.nix` imports `niri.nix` (the niri compositor config, touch-gesture daemon, and on-screen-keyboard launcher — see Keybinds); `wvkbd.nix` is currently an empty stub.
**`secrets/secrets.yaml`** + **`.sops.yaml`** — sops-encrypted secrets (currently Vaultwarden client id/secret), decrypted at activation time using each host's SSH host key as the age identity.
## Keybinds
### Niri (compositor, `home/desktop/niri.nix`)
`Mod` is niri's default modifier (Super/Windows key).
| Bind | Action |
|---|---|
| `Mod+Return` | Spawn Alacritty |
| `Mod+Space` | Toggle DMS spotlight launcher |
| `Mod+F` | Fullscreen focused window |
| `Mod+V` | Toggle floating for focused window |
| `Mod+X` | Close focused window |
| `Mod+H` / `Mod+L` | Focus column left / right |
| `Mod+J` / `Mod+K` | Focus window down / up |
| `Mod+Shift+H` / `Mod+Shift+L` | Move column left / right |
| `Mod+Shift+J` / `Mod+Shift+K` | Move column to workspace down / up |
| `Mod+U` / `Mod+N` | Focus workspace up / down |
| `Mod+Shift+P` | Toggle overview |
| `Mod+P` | Toggle the on-screen keyboard (signals `wvkbd-mobintl`) |
| `Mod+Shift+E` | Quit niri |
| `Print` | Screenshot (interactive) |
| `Ctrl+Print` | Screenshot whole screen |
| `XF86AudioRaiseVolume` / `XF86AudioLowerVolume` | Volume ±5% |
| `XF86AudioMute` | Toggle mute |
| `XF86MonBrightnessUp` / `XF86MonBrightnessDown` | Brightness ±5 (via `dms ipc call brightness`) |
### Touchscreen gestures (`lisgd`, launched at niri startup, `home/desktop/niri.nix`)
| Gesture | Action |
|---|---|
| 3-finger swipe left → right | Focus column left |
| 3-finger swipe right → left | Focus column right |
| 3-finger swipe up → down | Focus workspace up |
| 3-finger swipe down → up | Focus workspace down |
| 4-finger swipe down → up | Toggle DMS spotlight |
| 1-finger swipe down → up, starting from the bottom edge | Toggle the on-screen keyboard |
| 1-finger swipe up → down, starting from the top edge | Maximize window to edges |
### On-screen keyboard (custom `wvkbd-mobintl` build, `home/programs/{layout,config,keymap}.custom.h`)
- Toggle show/hide: `Mod+P` or the bottom-edge swipe gesture above (both send `SIGRTMIN` to `wvkbd-mobintl`).
- The "⌨" key (`NextLayer`) cycles keyboard layers: `Full ⇄ Special` in portrait, `Landscape ⇄ LandscapeSpecial` in landscape.
- `Abc` (in the `Special` layer) returns to the base layer.
- `Cmp` (Compose) + a letter opens that letter's accent/diacritic picker (e.g. `Cmp` then `e` → é/è/ê/ë/ē…).
- The `q` key doubles as a shortcut into the emoji layer.
- Alternate script layouts exist in the layout source (Cyrillic, Arabic, Persian, Greek, Georgian, Hebrew) but are not wired into the active `layers[]` cycle — only `Full`/`Special` (portrait) and `Landscape`/`LandscapeSpecial` (landscape) are reachable from the running config.
### Neovim (`home/programs/nvim.nix`, leader = `<Space>`)
General:
| Bind | Action |
|---|---|
| `<leader>w` | Write file |
| `<leader>q` | Quit |
| `<leader>wq` | Write and quit |
| `<leader>x` | `chmod +x` the current file |
| `Q` | Disabled (no-op) |
| `o` / `O` | Open a line below/above, stay in normal mode |
| `jj` (insert mode) | Escape to normal mode |
Completion (insert mode, nvim-cmp):
| Bind | Action |
|---|---|
| `<C-Space>` | Trigger completion |
| `<CR>` | Confirm selection |
| `<C-n>` / `<C-p>` | Next / previous item |
Java LSP (buffer-local, active once `jdtls` attaches to a `.java` file):
| Bind | Action |
|---|---|
| `gd` | Go to definition |
| `gr` | Find references |
| `K` | Hover docs |
| `<leader>rn` | Rename symbol |
| `<leader>ca` | Code action |
| `<leader>f` | Format buffer |
| `<leader>oi` | Organize imports |
Debugging (nvim-dap / nvim-dap-ui, global):
| Bind | Action |
|---|---|
| `<leader>db` | Toggle breakpoint |
| `<leader>dB` | Conditional breakpoint (prompts for condition) |
| `<leader>dc` | Continue / start session (prompts for a config if none is running) |
| `<leader>dn` | Step over |
| `<leader>di` | Step into |
| `<leader>du` | Step out |
| `<leader>dr` | Toggle the debug REPL |
| `<leader>dq` | Terminate session |
| `<leader>de` (normal + visual) | Evaluate expression under cursor / selection |
### Other applications
- **Alacritty** (`home/programs/alacritty.nix`) — only theme/font/window settings are configured; keybindings are Alacritty's unmodified defaults.
- Everything else installed (LibreWolf, Thunderbird, Discord, VLC, Zathura, etc.) is installed via `home.packages`/`environment.systemPackages` with no keybind customization in this repo — they run with upstream defaults.
- `input-remapper` is enabled on `violet` (`hosts/violet/default.nix`) but has no remapping profile committed in this repo.
+14 -3
View File
@@ -37,7 +37,7 @@ in
GTK_IM_MODULE = "wayland"; # Forces GTK apps to use Wayland text-input protocols
QT_IM_MODULE = "wayland"; # Forces Qt apps to use Wayland text-input protocols
TEXT_INPUT_PRESENT = "1"; # Explicitly signals virtual keyboard capability to the shell
JAVA_HOME = "{pkgs.jdk21}";
JAVA_HOME = "${pkgs.jdk21}";
};
home.packages = with pkgs; [
@@ -127,17 +127,28 @@ in
echo "jtest: no junit-platform-console-standalone jar in ~/dev/jars" >&2
exit 1
fi
# --debug suspends the test JVM on start and waits for nvim-dap to attach
# on :5005 (see the "Attach to jtest" config in nvim.nix), so breakpoints
# set before running jtest --debug are hit from the very first test.
DEBUG_ARGS=()
if [ "''${1:-}" = "--debug" ]; then
DEBUG_ARGS=(-agentlib:jdwp=transport=dt_socket,server=y,suspend=y,address=*:5005)
shift
echo "jtest: waiting for debugger to attach on 127.0.0.1:5005..." >&2
fi
ROOT="$(jroot)"
jbuild
cd "$ROOT"
if [ $# -eq 0 ]; then
exec java -jar "$JUNIT" execute --class-path "bin:lib/*" --scan-class-path --details=tree
exec java "''${DEBUG_ARGS[@]}" -jar "$JUNIT" execute --class-path "bin:lib/*" --scan-class-path --details=tree
fi
ARGS=""
for pkg in "$@"; do
ARGS="$ARGS --select-package $pkg"
done
exec java -jar "$JUNIT" execute --class-path "bin:lib/*" $ARGS --details=tree
exec java "''${DEBUG_ARGS[@]}" -jar "$JUNIT" execute --class-path "bin:lib/*" $ARGS --details=tree
'')
(pkgs.writeShellScriptBin "fkill" ''
+11
View File
@@ -234,6 +234,17 @@ in
dapui.setup()
require("nvim-dap-virtual-text").setup()
-- `jtest --debug` suspends the test JVM waiting on :5005; this lets
-- <leader>dc attach to it directly from the config picker.
dap.configurations.java = dap.configurations.java or {}
table.insert(dap.configurations.java, {
type = "java",
request = "attach",
name = "Attach to jtest (:5005)",
hostName = "127.0.0.1",
port = 5005,
})
dap.listeners.after.event_initialized["dapui"] = function() dapui.open() end
dap.listeners.before.event_terminated["dapui"] = function() dapui.close() end
dap.listeners.before.event_exited["dapui"] = function() dapui.close() end