nixos: gen 52 @ lilac — 2026-09-18 20:58 26.05.20260814.02e0898 (Yarara) -----
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
{
|
||||
"permissions": {
|
||||
"allow": [
|
||||
"Read(//home/jashton/.local/state/nix/profiles/**)",
|
||||
"Read(//nix/var/nix/profiles/**)",
|
||||
"Read(//nix/store/**)",
|
||||
"Bash(systemctl --user show-environment)",
|
||||
"Bash(nix eval *)",
|
||||
"Bash(nix-instantiate --parse /home/jashton/.dotfiles/home/jashton.nix)"
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,131 @@
|
||||
# .dotfiles
|
||||
|
||||
NixOS + Home Manager configuration for jashton's machines, built as a single flake.
|
||||
|
||||
## NixOS Flakes Structure
|
||||
|
||||
```
|
||||
.
|
||||
├── flake.nix / flake.lock Inputs + the 3 nixosConfigurations (violet, lilac, lavender)
|
||||
├── hosts/<name>/ Per-machine entrypoint + hardware.nix
|
||||
├── system/ Shared NixOS (system-level) configuration
|
||||
├── home/ Home Manager configuration for user "jashton"
|
||||
├── secrets/ + .sops.yaml sops-nix encrypted secrets
|
||||
└── ports.registry State file written by the find-open-port script
|
||||
```
|
||||
|
||||
**`flake.nix`** pins `nixpkgs` to `nixos-26.05` (plus an `nixpkgs-unstable` follower), and pulls in `home-manager`, `sops-nix`, `niri` (compositor), `wvkbd-src` (on-screen keyboard source), the DankMaterialShell trio (`dms`, `dms-plugin-registry`, `danksearch`), and `nixos-hardware`. Its `outputs` define three `nixosConfigurations`, one per host — each wires up the niri/dms-plugin-registry/sops-nix NixOS modules and a `home-manager.users.jashton` block importing `home/jashton.nix` (plus the `danksearch` home module).
|
||||
|
||||
**`hosts/`** — one directory per machine, each with `default.nix` (hostname + host-specific services/hardware tweaks, imports `../../system`) and `hardware.nix` (generated hardware scan):
|
||||
- `violet` — imports the ThinkPad-specific security module (`system/security/thinkpad.nix`), disables lid-switch suspend, has (disabled) TLP power-profile tuning, and enables `input-remapper`.
|
||||
- `lilac` — Framework laptop (Intel Core Ultra series 3, via `nixos-hardware`), fingerprint reader + Thunderbolt/bolt + Intel graphics acceleration.
|
||||
- `lavender` — minimal host, just graphics enablement.
|
||||
- Both `violet`/`lilac` open a Thunderbolt-networking point-to-point link (`thunderbolt0`, ports 4242).
|
||||
|
||||
**`system/`** — shared NixOS config imported by every host, split by concern:
|
||||
- `packages.nix` — system-wide packages, unfree allowed, plus a hand-written `unix` script (`sudo nixos-rebuild switch`, then auto-commits/pushes the dotfiles repo on success) and Steam setup.
|
||||
- `core/` — `boot.nix` (systemd-boot, `uinput` module), `audio.nix` (PipeWire/Bluetooth tuning), `env.nix` (zsh + oh-my-zsh, Nerd Font, flakes enabled, shell aliases), `locale.nix` (Denver/en_US), `power.nix` (deep sleep).
|
||||
- `security/` — `sops.nix` (age-via-SSH-host-key secrets), `sudo.nix` (passwordless `tlp` for jashton), `systemd.nix`, `thinkpad.nix` (fprintd), `users.nix` (user/group defs).
|
||||
- `network/` — NetworkManager + firewall, plus `pi-hole.nix` (a Pi-hole container run via Podman `oci-containers`).
|
||||
- `services/` — currently an empty placeholder module (compositor/greeter services are declared per-host instead, see `hosts/violet/default.nix`).
|
||||
- `virtualisation/` — Podman (with Docker compat), Waydroid, VirtualBox, libvirtd.
|
||||
|
||||
**`home/`** — Home Manager config for `jashton`:
|
||||
- `jashton.nix` — top-level user config: session vars, SSH client config (aliases for `lavender`/`violet`/`lilac`/`heliotrope`), the `lan-mouse` user service, workspace directory scaffolding (`~/dev`, `~/school`, etc.), a `custom_wvkbd` package override (builds `wvkbd` from `wvkbd-src` against the `.custom.h` files below), and a set of hand-written shell tools installed as packages: `jroot`/`jbuild`/`jrun`/`jtest`/`jclean` (Java project tooling — see below), `fkill` (interactive `pkill` by name), `find-open-port` (dev-port registry in `ports.registry`).
|
||||
- `programs/` — `default.nix` imports `alacritty.nix` (terminal theme/font), `git.nix` (identity + ignores), `nvim.nix` (full Neovim config: LSP, completion, Java/jdtls + DAP debugging — see Keybinds). `keymap.custom.h`, `layout.custom.h`, `config.custom.h` (+ `.bak` backups) are C source overrides for wvkbd's `mobintl` on-screen-keyboard layout, spliced into the `custom_wvkbd` build in `jashton.nix`.
|
||||
- `desktop/` — `default.nix` imports `niri.nix` (the niri compositor config, touch-gesture daemon, and on-screen-keyboard launcher — see Keybinds); `wvkbd.nix` is currently an empty stub.
|
||||
|
||||
**`secrets/secrets.yaml`** + **`.sops.yaml`** — sops-encrypted secrets (currently Vaultwarden client id/secret), decrypted at activation time using each host's SSH host key as the age identity.
|
||||
|
||||
## Keybinds
|
||||
|
||||
### Niri (compositor, `home/desktop/niri.nix`)
|
||||
`Mod` is niri's default modifier (Super/Windows key).
|
||||
|
||||
| Bind | Action |
|
||||
|---|---|
|
||||
| `Mod+Return` | Spawn Alacritty |
|
||||
| `Mod+Space` | Toggle DMS spotlight launcher |
|
||||
| `Mod+F` | Fullscreen focused window |
|
||||
| `Mod+V` | Toggle floating for focused window |
|
||||
| `Mod+X` | Close focused window |
|
||||
| `Mod+H` / `Mod+L` | Focus column left / right |
|
||||
| `Mod+J` / `Mod+K` | Focus window down / up |
|
||||
| `Mod+Shift+H` / `Mod+Shift+L` | Move column left / right |
|
||||
| `Mod+Shift+J` / `Mod+Shift+K` | Move column to workspace down / up |
|
||||
| `Mod+U` / `Mod+N` | Focus workspace up / down |
|
||||
| `Mod+Shift+P` | Toggle overview |
|
||||
| `Mod+P` | Toggle the on-screen keyboard (signals `wvkbd-mobintl`) |
|
||||
| `Mod+Shift+E` | Quit niri |
|
||||
| `Print` | Screenshot (interactive) |
|
||||
| `Ctrl+Print` | Screenshot whole screen |
|
||||
| `XF86AudioRaiseVolume` / `XF86AudioLowerVolume` | Volume ±5% |
|
||||
| `XF86AudioMute` | Toggle mute |
|
||||
| `XF86MonBrightnessUp` / `XF86MonBrightnessDown` | Brightness ±5 (via `dms ipc call brightness`) |
|
||||
|
||||
### Touchscreen gestures (`lisgd`, launched at niri startup, `home/desktop/niri.nix`)
|
||||
| Gesture | Action |
|
||||
|---|---|
|
||||
| 3-finger swipe left → right | Focus column left |
|
||||
| 3-finger swipe right → left | Focus column right |
|
||||
| 3-finger swipe up → down | Focus workspace up |
|
||||
| 3-finger swipe down → up | Focus workspace down |
|
||||
| 4-finger swipe down → up | Toggle DMS spotlight |
|
||||
| 1-finger swipe down → up, starting from the bottom edge | Toggle the on-screen keyboard |
|
||||
| 1-finger swipe up → down, starting from the top edge | Maximize window to edges |
|
||||
|
||||
### On-screen keyboard (custom `wvkbd-mobintl` build, `home/programs/{layout,config,keymap}.custom.h`)
|
||||
- Toggle show/hide: `Mod+P` or the bottom-edge swipe gesture above (both send `SIGRTMIN` to `wvkbd-mobintl`).
|
||||
- The "⌨" key (`NextLayer`) cycles keyboard layers: `Full ⇄ Special` in portrait, `Landscape ⇄ LandscapeSpecial` in landscape.
|
||||
- `Abc` (in the `Special` layer) returns to the base layer.
|
||||
- `Cmp` (Compose) + a letter opens that letter's accent/diacritic picker (e.g. `Cmp` then `e` → é/è/ê/ë/ē…).
|
||||
- The `q` key doubles as a shortcut into the emoji layer.
|
||||
- Alternate script layouts exist in the layout source (Cyrillic, Arabic, Persian, Greek, Georgian, Hebrew) but are not wired into the active `layers[]` cycle — only `Full`/`Special` (portrait) and `Landscape`/`LandscapeSpecial` (landscape) are reachable from the running config.
|
||||
|
||||
### Neovim (`home/programs/nvim.nix`, leader = `<Space>`)
|
||||
General:
|
||||
| Bind | Action |
|
||||
|---|---|
|
||||
| `<leader>w` | Write file |
|
||||
| `<leader>q` | Quit |
|
||||
| `<leader>wq` | Write and quit |
|
||||
| `<leader>x` | `chmod +x` the current file |
|
||||
| `Q` | Disabled (no-op) |
|
||||
| `o` / `O` | Open a line below/above, stay in normal mode |
|
||||
| `jj` (insert mode) | Escape to normal mode |
|
||||
|
||||
Completion (insert mode, nvim-cmp):
|
||||
| Bind | Action |
|
||||
|---|---|
|
||||
| `<C-Space>` | Trigger completion |
|
||||
| `<CR>` | Confirm selection |
|
||||
| `<C-n>` / `<C-p>` | Next / previous item |
|
||||
|
||||
Java LSP (buffer-local, active once `jdtls` attaches to a `.java` file):
|
||||
| Bind | Action |
|
||||
|---|---|
|
||||
| `gd` | Go to definition |
|
||||
| `gr` | Find references |
|
||||
| `K` | Hover docs |
|
||||
| `<leader>rn` | Rename symbol |
|
||||
| `<leader>ca` | Code action |
|
||||
| `<leader>f` | Format buffer |
|
||||
| `<leader>oi` | Organize imports |
|
||||
|
||||
Debugging (nvim-dap / nvim-dap-ui, global):
|
||||
| Bind | Action |
|
||||
|---|---|
|
||||
| `<leader>db` | Toggle breakpoint |
|
||||
| `<leader>dB` | Conditional breakpoint (prompts for condition) |
|
||||
| `<leader>dc` | Continue / start session (prompts for a config if none is running) |
|
||||
| `<leader>dn` | Step over |
|
||||
| `<leader>di` | Step into |
|
||||
| `<leader>du` | Step out |
|
||||
| `<leader>dr` | Toggle the debug REPL |
|
||||
| `<leader>dq` | Terminate session |
|
||||
| `<leader>de` (normal + visual) | Evaluate expression under cursor / selection |
|
||||
|
||||
### Other applications
|
||||
- **Alacritty** (`home/programs/alacritty.nix`) — only theme/font/window settings are configured; keybindings are Alacritty's unmodified defaults.
|
||||
- Everything else installed (LibreWolf, Thunderbird, Discord, VLC, Zathura, etc.) is installed via `home.packages`/`environment.systemPackages` with no keybind customization in this repo — they run with upstream defaults.
|
||||
- `input-remapper` is enabled on `violet` (`hosts/violet/default.nix`) but has no remapping profile committed in this repo.
|
||||
+14
-3
@@ -37,7 +37,7 @@ in
|
||||
GTK_IM_MODULE = "wayland"; # Forces GTK apps to use Wayland text-input protocols
|
||||
QT_IM_MODULE = "wayland"; # Forces Qt apps to use Wayland text-input protocols
|
||||
TEXT_INPUT_PRESENT = "1"; # Explicitly signals virtual keyboard capability to the shell
|
||||
JAVA_HOME = "{pkgs.jdk21}";
|
||||
JAVA_HOME = "${pkgs.jdk21}";
|
||||
};
|
||||
|
||||
home.packages = with pkgs; [
|
||||
@@ -127,17 +127,28 @@ in
|
||||
echo "jtest: no junit-platform-console-standalone jar in ~/dev/jars" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# --debug suspends the test JVM on start and waits for nvim-dap to attach
|
||||
# on :5005 (see the "Attach to jtest" config in nvim.nix), so breakpoints
|
||||
# set before running jtest --debug are hit from the very first test.
|
||||
DEBUG_ARGS=()
|
||||
if [ "''${1:-}" = "--debug" ]; then
|
||||
DEBUG_ARGS=(-agentlib:jdwp=transport=dt_socket,server=y,suspend=y,address=*:5005)
|
||||
shift
|
||||
echo "jtest: waiting for debugger to attach on 127.0.0.1:5005..." >&2
|
||||
fi
|
||||
|
||||
ROOT="$(jroot)"
|
||||
jbuild
|
||||
cd "$ROOT"
|
||||
if [ $# -eq 0 ]; then
|
||||
exec java -jar "$JUNIT" execute --class-path "bin:lib/*" --scan-class-path --details=tree
|
||||
exec java "''${DEBUG_ARGS[@]}" -jar "$JUNIT" execute --class-path "bin:lib/*" --scan-class-path --details=tree
|
||||
fi
|
||||
ARGS=""
|
||||
for pkg in "$@"; do
|
||||
ARGS="$ARGS --select-package $pkg"
|
||||
done
|
||||
exec java -jar "$JUNIT" execute --class-path "bin:lib/*" $ARGS --details=tree
|
||||
exec java "''${DEBUG_ARGS[@]}" -jar "$JUNIT" execute --class-path "bin:lib/*" $ARGS --details=tree
|
||||
'')
|
||||
|
||||
(pkgs.writeShellScriptBin "fkill" ''
|
||||
|
||||
@@ -234,6 +234,17 @@ in
|
||||
dapui.setup()
|
||||
require("nvim-dap-virtual-text").setup()
|
||||
|
||||
-- `jtest --debug` suspends the test JVM waiting on :5005; this lets
|
||||
-- <leader>dc attach to it directly from the config picker.
|
||||
dap.configurations.java = dap.configurations.java or {}
|
||||
table.insert(dap.configurations.java, {
|
||||
type = "java",
|
||||
request = "attach",
|
||||
name = "Attach to jtest (:5005)",
|
||||
hostName = "127.0.0.1",
|
||||
port = 5005,
|
||||
})
|
||||
|
||||
dap.listeners.after.event_initialized["dapui"] = function() dapui.open() end
|
||||
dap.listeners.before.event_terminated["dapui"] = function() dapui.close() end
|
||||
dap.listeners.before.event_exited["dapui"] = function() dapui.close() end
|
||||
|
||||
Reference in New Issue
Block a user