diff options
Diffstat (limited to '')
| -rw-r--r-- | chaski/configuration.nix | 3 | ||||
| -rw-r--r-- | chaski/services/tracktrain.nix | 148 | ||||
| -rw-r--r-- | common/common.nix | 2 | ||||
| -rw-r--r-- | common/desktop.nix | 19 | ||||
| -rw-r--r-- | flora/services/akkoma.nix | 28 | ||||
| -rw-r--r-- | flora/services/blog.nix | 6 | ||||
| -rw-r--r-- | flora/services/cgit.nix | 8 | ||||
| -rw-r--r-- | flora/services/mail.nix | 6 | ||||
| -rw-r--r-- | flora/services/monit.nix | 16 | ||||
| -rw-r--r-- | home/home-minimal.nix | 1 | ||||
| -rw-r--r-- | home/home.nix | 88 | ||||
| -rw-r--r-- | home/newsboat-public.nix | 16 | ||||
| -rw-r--r-- | home/packages-minimal.nix | 6 | ||||
| -rw-r--r-- | home/packages.nix | 10 | ||||
| -rw-r--r-- | ilex/configuration.nix | 4 | ||||
| -rw-r--r-- | inputs.nix | 2 | ||||
| -rw-r--r-- | npins/default.nix | 158 | ||||
| -rw-r--r-- | npins/sources.json | 136 | ||||
| -rw-r--r-- | pkgs/default.nix | 11 | ||||
| -rw-r--r-- | pkgs/hikari.nix | 31 | ||||
| -rw-r--r-- | pkgs/overlay.nix | 55 | ||||
| -rw-r--r-- | pkgs/patches/element-css.patch | 28 | ||||
| -rw-r--r-- | pkgs/plover/default.nix | 5 | ||||
| -rw-r--r-- | pkgs/plover/plover-dev.nix | 73 | ||||
| -rw-r--r-- | pkgs/plover/plover-stroke.nix | 39 | ||||
| -rw-r--r-- | pkgs/plover/plover.nix | 96 | ||||
| -rw-r--r-- | pkgs/plover/rtf_tokenize.nix | 33 | ||||
| -rw-r--r-- | secrets/chaski.yaml | 15 |
28 files changed, 526 insertions, 517 deletions
diff --git a/chaski/configuration.nix b/chaski/configuration.nix index 0271e0f..94b89df 100644 --- a/chaski/configuration.nix +++ b/chaski/configuration.nix @@ -12,7 +12,8 @@ ./services/chat.nix ./services/bahnhof-name.nix ./services/conduit.nix - ./services/headscale.nix + # ./services/headscale.nix + ./services/tracktrain.nix ]; sops.defaultSopsFile = ../secrets/chaski.yaml; diff --git a/chaski/services/tracktrain.nix b/chaski/services/tracktrain.nix new file mode 100644 index 0000000..85e98fc --- /dev/null +++ b/chaski/services/tracktrain.nix @@ -0,0 +1,148 @@ +{ config, lib, pkgs, inputs, ... }: + +let + tracktrain-config = '' + dbstring: "dbname=tracktrain user=tracktrain" + gtfs: ${pkgs.copyPathToStore ./gtfs.zip} + assets: ${pkgs.tracktrain}/assets + + warp: + port: 4000 + ''; +in +{ + sops.secrets = { + "tracktrain/env" = {}; + "nginx/tracktrain-auth" = { + owner = "nginx"; + }; + }; + + services.nginx.recommendedProxySettings = true; + services.nginx.virtualHosts."tracktrain.stuebinm.eu" = { + serverAliases = [ "tracktrain.ilztalbahn.eu" ]; + locations."/" = { + proxyPass = "http://192.168.42.41:4000"; + proxyWebsockets = true; + basicAuthFile = "/run/secrets/nginx/tracktrain-auth"; + }; + locations."/api" = { + proxyPass = "http://192.168.42.41:4000"; + proxyWebsockets = true; + extraConfig = '' + add_header 'Access-Control-Allow-Origin' '*' always; + ''; + }; + locations."/api/gtfs/".extraConfig = '' + rewrite /gtfs/(.*) /api/v1/gtfs/$1; + ''; + locations."/metrics/" = { + proxyPass = "http://localhost:2342"; + proxyWebsockets = true; + extraConfig = '' + rewrite ^/metrics/(.*) /$1 break; + ''; + }; + enableACME = true; + forceSSL = true; + }; + + + # services.prometheus = { + # enable = true; + # port = 9001; + # scrapeConfigs = [ { + # job_name = "tracktrain"; + # static_configs = [{ + # targets = [ "192.168.42.41:4000" ]; + # }]; + # } ]; + # }; + + # services.grafana = { + # enable = true; + # settings.server = { + # serve_from_sub_path = true; + # domain = "tracktrain.ilztalbahn.eu"; + # root_url = "%(protocol)s://%(domain)s:/metrics/"; + # http_port = 2342; + # http_addr = "0.0.0.0"; + # }; + + # provision = { + # enable = true; + # datasources.settings.datasources = [ { + # url = "http://localhost:9001"; + # type = "prometheus"; + # name = "prometheus"; + # } ]; + # }; + # }; + + networking.firewall.allowedTCPPorts = [ 443 ]; + + containers.tracktrain = { + autoStart = true; + privateNetwork = true; + hostAddress6 = "fd00::42:40"; + localAddress6 = "fd00::42:41"; + hostAddress = "192.168.42.40"; + localAddress = "192.168.42.41"; + + config = { config, ... }: { + + systemd.services.tracktrain = { + enable = true; + + description = "tracks trains, hopefully"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" ]; + serviceConfig = { + Type = "simple"; + # EnvironmentFile = "/secrets/env"; + DynamicUser = true; + }; + path = [ pkgs.wget pkgs.ntfy-sh ]; + script = '' + cd /tmp + ln -sf ${pkgs.writeText "config.yaml" tracktrain-config} "config.yaml" + sleep 3 + ${pkgs.tracktrain}/bin/tracktrain +RTS -T + ''; + }; + + systemd.services.postgresql.wantedBy = [ "tracktrain.service" ]; + + services.postgresql = { + enable = true; + ensureDatabases = [ "tracktrain" ]; + ensureUsers = [ { + name = "tracktrain"; + ensureDBOwnership = true; + } ]; + authentication = '' + local all all trust + ''; + }; + + networking.firewall.enable = false; + system.stateVersion = "25.11"; + + services.coredns = { + enable = true; + config = '' + .:53 { + forward . 1.1.1.1 + } + ''; + }; + }; + }; + + networking.nat = { + enable = true; + internalInterfaces = [ "ve-tracktrain" ]; + externalInterface = "ens3"; + }; + +} diff --git a/common/common.nix b/common/common.nix index 02fec64..e10fbf1 100644 --- a/common/common.nix +++ b/common/common.nix @@ -37,7 +37,7 @@ documentation = { dev.enable = true; - man.generateCaches = true; + man.cache.enable = true; nixos.includeAllModules = true; nixos.options.warningsAreErrors = false; }; diff --git a/common/desktop.nix b/common/desktop.nix index 9341b83..cfe636c 100644 --- a/common/desktop.nix +++ b/common/desktop.nix @@ -21,7 +21,7 @@ users.defaultUserShell = pkgs.fish; users.users.stuebinm = { isNormalUser = true; - extraGroups = [ "docker" "wheel" "networking" "video" "wireshark" ]; + extraGroups = [ "docker" "wheel" "networking" "video" "wireshark" "dialout" ]; home = "/home/stuebinm"; hashedPassword = "$6$IULsCnY7HjDHAJWs$05DYuwXsfWWKj6m3KTWCPp5k9HuQikIamNBzn2GihMG8oeEf5c8YkXlwuO6uTnX8ZFmyAQdhXfO5yYNEM/YTm0"; useDefaultShell = true; @@ -42,26 +42,25 @@ }; # graphics and stuff - programs.light.enable = true; programs.slock.enable = true; environment.systemPackages = with pkgs; [ - hikari fuzzel apply-config + fuzzel apply-config ]; - security.pam.services.hikari-unlocker.text = '' - auth include login - ''; + # security.pam.services.hikari-unlocker.text = '' + # auth include login + # ''; services.davfs2.enable = true; services.greetd = { enable = true; settings = { - default_session = { - command = "${pkgs.tuigreet}/bin/tuigreet -tr --asterisks --cmd 'hikari -c ~/hikari.conf'"; - user = "stuebinm"; - }; + # default_session = { + # command = "${pkgs.tuigreet}/bin/tuigreet -tr --asterisks --cmd 'hikari -c ~/hikari.conf'"; + # user = "stuebinm"; + # }; # terminal.vt = 2; }; }; diff --git a/flora/services/akkoma.nix b/flora/services/akkoma.nix index 6864a29..d7e7b49 100644 --- a/flora/services/akkoma.nix +++ b/flora/services/akkoma.nix @@ -114,7 +114,7 @@ in database = "pleroma"; socket_dir = "/run/postgresql"; pool_size = 10; - # prepare = ":named"; + prepare = mkAtom ":named"; show_sensitive_data_on_connection_error = true; parameters = { plan_cache_mode = "force_custom_plan"; }; }; @@ -166,16 +166,16 @@ in } ]; settings = { - max_connections = 20; - shared_buffers = "256MB"; - effective_cache_size = "768MB"; - maintenance_work_mem = "64MB"; + max_connections = 300; + shared_buffers = "768MB"; + effective_cache_size = "2304MB"; + maintenance_work_mem = "192MB"; checkpoint_completion_target = 0.9; - wal_buffers = "7864kB"; + wal_buffers = "16MB"; default_statistics_target = 100; random_page_cost = 1.1; effective_io_concurrency = 200; - work_mem = "6553kB"; + work_mem = "4MB"; huge_pages = "off"; min_wal_size = "2GB"; max_wal_size = "8GB"; @@ -203,8 +203,18 @@ in networking.firewall.allowedTCPPorts = [ 4000 ]; - environment.etc."resolv.conf".text = - "nameserver 1.1.1.1"; + # environment.etc."resolv.conf".text = + # "nameserver 1.1.1.1"; + # + # TODO: Possibly? + # services.coredns = { + # enable = true; + # config = '' + # .:53 { + # forward . 1.1.1.1 + # } + # ''; + # }; }; }; diff --git a/flora/services/blog.nix b/flora/services/blog.nix index e77cc7c..89436df 100644 --- a/flora/services/blog.nix +++ b/flora/services/blog.nix @@ -6,7 +6,7 @@ let src = pkgs.fetchgit { url = "https://stuebinm.eu/git/forks/lux"; rev = "refs/heads/master"; - sha256 = "sha256-L2y5SEGOaoWl+jQGP3TmpQQLojjkRAjiRjbwhGKOg14="; + hash = "sha256-ooRgRhs50D6TEFVpL9QfsCUKX/R7dUoETIorJoS9FNY="; }; buildInputs = [ pkgs.mdbook ]; buildPhase = '' @@ -27,8 +27,8 @@ let ''; installPhase = '' mkdir -p $out - mv gtfs-book-html $out/gtfs - mv gtfs-realtime-book-html $out/gtfs-realtime + mv /build/gtfs-book-html $out/gtfs + mv /build/gtfs-realtime-book-html $out/gtfs-realtime cp -r ${lux.outPath} $out/lux ''; }; diff --git a/flora/services/cgit.nix b/flora/services/cgit.nix index b846ad4..5ee8103 100644 --- a/flora/services/cgit.nix +++ b/flora/services/cgit.nix @@ -2,7 +2,13 @@ let cgitconf = '' - source-filter=${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py + source-filter=${pkgs.writeScript ''highlighter'' '' + if [[ $1 == *.thy ]]; then + ${pkgs.isabelle-utils}/bin/isabelle2unicode | ${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py "$1" + else + ${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py "$1" + fi + ''} about-filter=${pkgs.cgit}/lib/cgit/filters/about-formatting.sh cache-size=1000 logo=/git/cgit.png diff --git a/flora/services/mail.nix b/flora/services/mail.nix index 0ee8418..4705e25 100644 --- a/flora/services/mail.nix +++ b/flora/services/mail.nix @@ -12,15 +12,11 @@ # A list of all login accounts. To create the password hashes, use # nix run nixpkgs.apacheHttpd -c htpasswd -nbB "" "super secret password" | cut -d: -f2 - loginAccounts = { + accounts = { "hello@stuebinm.eu" = { hashedPasswordFile = "/run/secrets/mail/hashedPassword"; aliases = ["postmaster@stuebinm.eu" "abuse@stuebinm.eu"]; }; }; - - # Use Let's Encrypt certificates. Note that this needs to set up a stripped - # down nginx and opens port 80. - certificateScheme = "acme-nginx"; }; } diff --git a/flora/services/monit.nix b/flora/services/monit.nix index cc5f3c4..e67f424 100644 --- a/flora/services/monit.nix +++ b/flora/services/monit.nix @@ -30,11 +30,23 @@ if failed port 443 with protocol https then alert - check host nobelium with address colorspace.club + check host erpu.eu with address erpu.eu if failed port 443 with protocol https then alert - check host billy with address preprint.books.exposed + check host erpu-zulip with address zulip.erpu.eu + if failed port 443 with protocol https + then alert + + check host erpu-authentik with address login.erpu.eu + if failed port 443 with protocol https + then alert + + check host erpu-nextcloud with address nextcloud.erpu.eu + if failed port 443 with protocol https + then alert + + check host erpu-hedgedoc with address pad.erpu.eu if failed port 443 with protocol https then alert ''; diff --git a/home/home-minimal.nix b/home/home-minimal.nix index 98ba513..32075d8 100644 --- a/home/home-minimal.nix +++ b/home/home-minimal.nix @@ -156,6 +156,7 @@ alias = { search = "!git log --format='tformat:%h %cs %s' --no-show-signature | fzf --multi --preview 'git show {+1}|bat -p -lpatch --color=always' | cut -f1 -d\" \" | wl-copy -n && wl-paste"; where = "!fish -c git-where"; + changes = "!git log --format=format: --name-only --since='1 year ago' | sort | uniq -c | sort -nr | head -20"; }; merge.mergiraf = { diff --git a/home/home.nix b/home/home.nix index 15df8de..6d1a061 100644 --- a/home/home.nix +++ b/home/home.nix @@ -69,20 +69,6 @@ userName = "stuebinm@ilztalbahn.eu"; passwordCommand = "secret-tool lookup mail ilztalbahn"; }; - accounts.preprint = { - address = "admin@books.exposed"; - imap.host = "books.exposed"; - mbsync = { - enable = true; - create = "maildir"; - }; - msmtp.enable = true; - mu.enable = true; - realName = "terru"; - smtp.host = "books.exposed"; - userName = "admin@books.exposed"; - passwordCommand = "secret-tool lookup mail preprint"; - }; }; programs.bash = { @@ -194,6 +180,8 @@ programs.neovim = { enable = true; viAlias = true; + withRuby = false; + withPython3 = false; plugins = with pkgs; [ (vimPlugins.nvim-treesitter.withPlugins (plugins: [ tree-sitter-grammars.tree-sitter-nix ])) @@ -302,58 +290,63 @@ programs.ssh = { # forwardAgent = true; enable = true; + enableDefaultConfig = true; extraConfig = '' SetEnv TERM=xterm-256color ''; - matchBlocks = let + settings = let keydir = config.home.homeDirectory + "/.ssh"; - hetznerlogin = match: {user = "root"; identityFile = keydir + "/hetzner.pub";} // match; - vpslogin = hostname: hetznerlogin {inherit hostname;}; + hetznerlogin = match: { User = "root"; IdentityFile = keydir + "/hetzner.pub";} // match; + vpslogin = hostname: hetznerlogin { inherit hostname; }; in { "flora" = vpslogin "flora.stuebinm.eu"; "chaski" = vpslogin "chaski.stuebinm.eu"; - "cgit" = vpslogin "flora.stuebinm.eu" // {user = "git";}; + "cgit" = vpslogin "flora.stuebinm.eu" // {User = "git";}; "mate" = { - hostname = "192.168.69.174"; - user = "root"; - identityFile = keydir + "/hetzner.pub"; + Hostname = "192.168.69.174"; + User = "root"; + IdentityFile = keydir + "/hetzner.pub"; }; "c3voc" = { - hostname = "git.c3voc.de"; - user = "git"; - identityFile = keydir + "/id_surltesh-echer"; + Hostname = "git.c3voc.de"; + User = "git"; + IdentityFile = keydir + "/id_surltesh-echer"; }; "encoder* mixer* atem* minion*" = { # hostname = "%h.lan.c3voc.de"; - user = "voc"; - extraOptions.StrictHostKeyChecking = "no"; + User = "voc"; + StrictHostKeyChecking = "no"; }; "nobelium" = { - hostname = "no.colorspace.club"; - user = "root"; - identityFile = keydir + "/id_ed25519"; + Hostname = "no.colorspace.club"; + User = "root"; + IdentityFile = keydir + "/id_ed25519"; }; "colorspace-git" = { - hostname = "no.colorspace.club"; - user = "git"; - identityFile = keydir + "/id_ed25519"; + Hostname = "no.colorspace.club"; + User = "git"; + IdentityFile = keydir + "/id_ed25519"; }; "git.infra4future.de" = { - hostname = "git.infra4future.de"; - user = "gitea"; - identityFile = keydir + "/id_ed25519"; - addressFamily = "inet"; + Hostname = "git.infra4future.de"; + User = "gitea"; + IdentityFile = keydir + "/id_ed25519"; + AddressFamily = "inet"; }; "namauh" = { - hostname = "10.11.99.1"; - user = "root"; - identityFile = keydir + "/id_ed25519"; + Hostname = "10.11.99.1"; + User = "root"; + IdentityFile = keydir + "/id_ed25519"; }; "billy" = { - hostname = "billy.books.exposed"; - user = "root"; - identityFile = keydir + "/id_ed25519"; + Hostname = "billy.books.exposed"; + User = "root"; + IdentityFile = keydir + "/id_ed25519"; + }; + "regiolis" = { + Hostname = "regiolis.erpu.eu"; + User = "terru"; }; }; }; @@ -371,17 +364,6 @@ }; - services.mako = { - enable = true; - settings = { - background-color = "#74389eb0"; - border-color = "#c27cb6ff"; - default-timeout = 5000; # milliseconds - padding = "10"; - output = "DP-9"; - }; - }; - services.mpd = { enable = true; musicDirectory = "${config.home.homeDirectory}/music"; diff --git a/home/newsboat-public.nix b/home/newsboat-public.nix index 7da942b..1f82e0c 100644 --- a/home/newsboat-public.nix +++ b/home/newsboat-public.nix @@ -4,7 +4,6 @@ with import ./newsboat-lib.nix; # news (ntag "https://thinkmods.store/blogs/news.atom" "tech") (ntag "http://feeds.feedburner.com/Blendernation" "blender") - (ntag "https://puri.sm/feed/" "tech") (ntag "https://events.ccc.de/feed" "chaos") (ntag "https://this-week-in-rust.org/rss.xml" "prog") (ntag "https://weekly.nixos.org/feeds/all.rss.xml" "prog") @@ -14,7 +13,6 @@ with import ./newsboat-lib.nix; (ntag "https://ctxt.es/es/?tpl=87" "es") (ntag "https://warnung.bund.de/api31/mowas/rss/092620000000.rss" "bund") (jtag "https://madeinchinajournal.com/feed/" "pol") - (jtag "https://decorrespondent.nl/feed/v1/publications" "pol") (jtag "https://solar.lowtechmagazine.com/feeds/all-en.atom.xml" "tech") (btag "https://www.omgubuntu.co.uk/feed" "tech") (ntag "https://liputenpo.org/feed" "tok") @@ -78,8 +76,6 @@ with import ./newsboat-lib.nix; (btag "https://www.haskellforall.com/feeds/posts/default" "comp") (btag "http://conal.net/blog/feed" "comp") (btag "https://michael.stapelberg.ch/posts/tags/distri/feed.xml" "comp") - (btag "https://mattermost.com/blog/category/releases/feed/" "security") - (btag "https://mattermost.com/security-updates/feed/" "security") (btag "https://ionathan.ch/feed.xml" "comp") (btag "https://wingolog.org/feed/atom" "comp") (btag "https://os.phil-opp.com/rss.xml" "comp") @@ -223,6 +219,15 @@ with import ./newsboat-lib.nix; (btag "https://blog.aada.cat/index.xml" "friends") (btag "https://jonworth.eu/feed/" "trains") (btag "https://vulpinecitrus.info/blog/atom.xml" "comp") + (btag "https://www.jonmsterling.com/019X/atom.xml" "maths") + (btag "https://www.scottsmitelli.com/index.xml" "comp") + (btag "https://asta.boserup.eu/forest/fragments/atom.xml" "friends") + (btag "https://www.typography.com/rss/blog" "type") + (btag "https://rdnlsmith.com/index.xml" "comp") + (btag "https://blog.glyphdrawing.club/feed.xml" "type") + (btag "https://shadycharacters.co.uk/feed.xml" "type") + (btag "https://compilercrim.es/rss.xml" "comp") + (btag "https://www.math.columbia.edu/~woit/wordpress/atom.xml" "physics") # paper (btag "http://arxiv.org/rss/cs.PL" "paper") @@ -232,7 +237,6 @@ with import ./newsboat-lib.nix; # videos (vtag "https://media.ccc.de/updates.rdf" "chaos") # Media.CCC.de (ytag "UC9rxWtgVUFls4LocQhXoNJA" "tech") # Software Circus - (ytag "UCXuqSBlHAE6Xw-yeJA0Tunw" "tech") # Linus Tech Tips (ytag "UCBa659QWEk1AI4Tg--mrJ2A" "stuff") # Tom Scott (ytag "UCtGG8ucQgEJPeUPhJZ4M4jA" "stuff") # Rare Earth (ytag "UC9GwQ_SGeq7Nrn4NQfwVoRA" "climate") # Students for Future @@ -299,12 +303,12 @@ with import ./newsboat-lib.nix; (podcast "https://feeds.soundcloud.com/users/soundcloud:users:237055046/sounds.rss") (podcast "https://fernostwaerts.de/feed/mp3/") (podcast "https://allesgesagt.podigee.io/feed/mp3") - (podcast "https://logbuch-netzpolitik.de/feed") (podcast "https://feeds.feedburner.com/SrslyWrong") (podcast "https://efforg.libsyn.com/rss") (podcast "https://feed.podbean.com/lingfieldnotes/feed.xml") (podcast "https://dasklima.podigee.io/feed/mp3") (podcast "https://www.haecksen.org/podcast/rss") + (podcast "https://aboutlogic.podigee.io/feed/mp3") (music "https://feeds.soundcloud.com/users/soundcloud%3Ausers%3A39508706/sounds.rss") diff --git a/home/packages-minimal.nix b/home/packages-minimal.nix index 20eb6df..baf15e4 100644 --- a/home/packages-minimal.nix +++ b/home/packages-minimal.nix @@ -19,10 +19,8 @@ git-annex git-bug git-appraise mergiraf # other things gauche - # html, js & co - jq html-tidy nodePackages.stylelint nodePackages.js-beautify zola - lowdown + jq ijq lowdown # nix things - nixfmt-rfc-style deploy-rs.deploy-rs + nixfmt deploy-rs.deploy-rs ]; } diff --git a/home/packages.nix b/home/packages.nix index 236b5b6..10c4a3c 100644 --- a/home/packages.nix +++ b/home/packages.nix @@ -8,11 +8,11 @@ in emacs-pgtk emacs-all-the-icons-fonts julia-mono - river-classic swaybg swaylock - plover-dev + river-classic swaybg swaylock dunst + plover # internet apps & clients firefox keepassxc mumble lynx offpunk - openconnect telegram-desktop monolith magic-wormhole-rs + openconnect monolith magic-wormhole-rs dino # graphics & audio audacity blender darktable ffmpeg-full @@ -29,7 +29,7 @@ in almanac libnotify grim slurp (zbar.override { enableVideo = false; withXorg = false; }) wl-clipboard showrt kijetesantakaluotokieni mpc dufs progress hledger - wineWowPackages.full sops xdg-utils exiftool + wineWow64Packages.full sops xdg-utils exiftool mercurial darcs git-annex-remote-remarkable2 # git-who rlwrap inputs.ocaml-forester.legacyPackages.${system}.forester @@ -52,7 +52,7 @@ in (agda.withPackages (p: [ p.standard-library p.cubical p.agda-categories ])) # html, js & co - jq ijq html-tidy nodePackages.stylelint nodePackages.js-beautify zola + html-tidy # nodePackages.stylelint nodePackages.js-beautify libxml2 fq htmlq # rust rust-bin.stable.latest.minimal rust-analyzer rustfmt diff --git a/ilex/configuration.nix b/ilex/configuration.nix index d648adc..fd746a7 100644 --- a/ilex/configuration.nix +++ b/ilex/configuration.nix @@ -23,7 +23,7 @@ networking.firewall.allowedUDPPorts = [ 9100 9103 ]; boot.kernelPackages = - pkgs.linuxKernel.packageAliases.linux_latest; + pkgs.linuxKernel.packageAliases.linux_default; hardware.graphics.enable32Bit = true; hardware.bluetooth.enable = true; @@ -92,4 +92,6 @@ USB_EXCLUDE_AUDIO = 1; }; }; + + security.pam.services.swaylock = {}; } @@ -28,7 +28,7 @@ let inherit system; overlays = [ (import sources.rust-overlay) - deploy-rs.overlay + deploy-rs.overlays.default (import ./pkgs/overlay.nix { inherit inputs; }) lix-overlay ]; diff --git a/npins/default.nix b/npins/default.nix index 8955703..b7f402e 100644 --- a/npins/default.nix +++ b/npins/default.nix @@ -9,8 +9,15 @@ */ # Generated by npins. Do not modify; will be overwritten regularly let - data = builtins.fromJSON (builtins.readFile ./sources.json); - version = data.version; + # Backwards-compatibly make something that previously didn't take any arguments take some + # The function must return an attrset, and will unfortunately be eagerly evaluated + # Same thing, but it catches eval errors on the default argument so that one may still call it with other arguments + mkFunctor = + fn: + let + e = builtins.tryEval (fn { }); + in + (if e.success then e.value else { error = fn { }; }) // { __functor = _self: fn; }; # https://github.com/NixOS/nixpkgs/blob/0258808f5744ca980b9a1f24fe0b1e6f0fecee9c/lib/lists.nix#L295 range = @@ -21,7 +28,6 @@ let # https://github.com/NixOS/nixpkgs/blob/0258808f5744ca980b9a1f24fe0b1e6f0fecee9c/lib/strings.nix#L269 stringAsChars = f: s: concatStrings (map f (stringToCharacters s)); - concatMapStrings = f: list: concatStrings (map f list); concatStrings = builtins.concatStringsSep ""; # If the environment variable NPINS_OVERRIDE_${name} is set, then use @@ -48,19 +54,62 @@ let mkSource = name: spec: + { + pkgs ? null, + }: assert spec ? type; let + # Unify across builtin and pkgs fetchers. + # `fetchGit` requires a wrapper because of slight API differences. + fetchers = + if pkgs == null then + { + inherit (builtins) fetchTarball fetchurl; + # Frustratingly, due to flakes and `fetchTree`, `fetchGit` + # has a different signature than the other builtin + # fetchers + fetchGit = args: (builtins.fetchGit args).outPath; + } + else + { + fetchTarball = + { + url, + sha256, + }: + pkgs.fetchzip { + inherit url sha256; + extension = "tar"; + }; + inherit (pkgs) fetchurl; + fetchGit = + { + url, + submodules, + rev, + name, + narHash, + }: + pkgs.fetchgit { + inherit url rev name; + fetchSubmodules = submodules; + hash = narHash; + }; + }; + path = if spec.type == "Git" then - mkGitSource spec + mkGitSource fetchers spec else if spec.type == "GitRelease" then - mkGitSource spec + mkGitSource fetchers spec else if spec.type == "PyPi" then - mkPyPiSource spec + mkPyPiSource fetchers spec else if spec.type == "Channel" then - mkChannelSource spec + mkChannelSource fetchers spec else if spec.type == "Tarball" then - mkTarballSource spec + mkTarballSource fetchers spec + else if spec.type == "Container" then + mkContainerSource pkgs spec else builtins.throw "Unknown source type ${spec.type}"; in @@ -68,21 +117,25 @@ let mkGitSource = { + fetchTarball, + fetchGit, + ... + }: + { repository, revision, url ? null, submodules, hash, - branch ? null, ... }: assert repository ? type; # At the moment, either it is a plain git repository (which has an url), or it is a GitHub/GitLab repository # In the latter case, there we will always be an url to the tarball if url != null && !submodules then - builtins.fetchTarball { + fetchTarball { inherit url; - sha256 = hash; # FIXME: check nix version & use SRI hashes + sha256 = hash; } else let @@ -93,6 +146,8 @@ let "https://github.com/${repository.owner}/${repository.repo}.git" else if repository.type == "GitLab" then "${repository.server}/${repository.repo_path}.git" + else if repository.type == "Forgejo" then + "${repository.server}/${repository.owner}/${repository.repo}.git" else throw "Unrecognized repository type ${repository.type}"; urlToName = @@ -107,42 +162,91 @@ let "${if matched == null then "source" else builtins.head matched}${appendShort}"; name = urlToName url revision; in - builtins.fetchGit ({ + fetchGit { rev = revision; - inherit name; - # hash = hash; - inherit url submodules; - } // (if branch != null then { - ref = "refs/heads/${branch}"; - } else {})); + narHash = hash; + + inherit name submodules url; + }; mkPyPiSource = - { url, hash, ... }: - builtins.fetchurl { + { fetchurl, ... }: + { + url, + hash, + ... + }: + fetchurl { inherit url; sha256 = hash; }; mkChannelSource = - { url, hash, ... }: - builtins.fetchTarball { + { fetchTarball, ... }: + { + url, + hash, + ... + }: + fetchTarball { inherit url; sha256 = hash; }; mkTarballSource = + { fetchTarball, ... }: { url, locked_url ? url, hash, ... }: - builtins.fetchTarball { + fetchTarball { url = locked_url; sha256 = hash; }; + + mkContainerSource = + pkgs: + { + image_name, + image_tag, + image_digest, + hash, + ... + }: + if pkgs == null then + builtins.throw "container sources require passing in a Nixpkgs value: https://github.com/andir/npins/blob/master/README.md#using-the-nixpkgs-fetchers" + else + pkgs.dockerTools.pullImage { + imageName = image_name; + imageDigest = image_digest; + finalImageTag = image_tag; + hash = hash; + }; in -if version == 5 then - builtins.mapAttrs mkSource data.pins -else - throw "Unsupported format version ${toString version} in sources.json. Try running `npins upgrade`" +mkFunctor ( + { + input ? ./sources.json, + }: + let + data = + if builtins.isPath input then + # while `readFile` will throw an error anyways if the path doesn't exist, + # we still need to check beforehand because *our* error can be caught but not the one from the builtin + # See: <https://git.lix.systems/lix-project/lix/issues/1098> + if builtins.pathExists input then + builtins.fromJSON (builtins.readFile input) + else + throw "Input path ${toString input} does not exist" + else if builtins.isAttrs input then + input + else + throw "Unsupported input type ${builtins.typeOf input}, must be a path or an attrset"; + version = data.version; + in + if version == 7 then + builtins.mapAttrs (name: spec: mkFunctor (mkSource name spec)) data.pins + else + throw "Unsupported format version ${toString version} in sources.json. Try running `npins upgrade`" +) diff --git a/npins/sources.json b/npins/sources.json index 3a74c0a..8540f90 100644 --- a/npins/sources.json +++ b/npins/sources.json @@ -9,9 +9,9 @@ }, "branch": "main", "submodules": false, - "revision": "aa8519ec107d7cfa29b03005c9176708e1269965", - "url": "https://github.com/ai-robots-txt/ai.robots.txt/archive/aa8519ec107d7cfa29b03005c9176708e1269965.tar.gz", - "hash": "01injirgqzzhd7sqarhlf54b994b70c7f8g88xrkqsy4gs0vzx9v" + "revision": "0e111dcc24cbcdf4e609edde70f9f9184eac8b02", + "url": "https://github.com/ai-robots-txt/ai.robots.txt/archive/0e111dcc24cbcdf4e609edde70f9f9184eac8b02.tar.gz", + "hash": "sha256-JBN4kvpilklvgpI7mWsWc7+2ww16ZYdoiqJT4gZFePg=" }, "almanac": { "type": "Git", @@ -23,7 +23,7 @@ "submodules": false, "revision": "cdd82b013777324f146c4961b866154a9287110b", "url": null, - "hash": "0804k1zcnyhfdgjxmpgyg9l537j6p4ajrjgzz9svxka6acc1l85h" + "hash": "sha256-sCAaGFNGzb51+v/JLBW5Rp5RaHr+3drlaw56y36YBCA=" }, "bahnhof-name": { "type": "Git", @@ -33,9 +33,9 @@ }, "branch": "rnv", "submodules": false, - "revision": "83031c010be0ed73f45ba5975d16cb05a1638ff1", + "revision": "250be698ace92026668f08ada962e6e517717d92", "url": null, - "hash": "19kfjrndg5xvspwqljgsiyadi4fjnq99zfpr9k6bnx3z2g2m1rk8" + "hash": "sha256-tN7pdV5CrMcSW3+8iifKS2of3BUcJL77f4HB3xw+y6A=" }, "blog": { "type": "Git", @@ -45,9 +45,9 @@ }, "branch": "main", "submodules": false, - "revision": "61d865b1cb837f059bcd0b215d6f83ae33393e32", + "revision": "9758e92c4786f28d59a4b4bee90410142095097d", "url": null, - "hash": "0076rfb3fzb8j9mbi0xlv1fx8l0v9rvba6gfn6xydds75ahmf0bj" + "hash": "sha256-mr2Pn7cXM4qr0XuXcHYCdWWoORo8QtsVGv/r0KgDltA=" }, "deploy-rs": { "type": "Git", @@ -59,7 +59,7 @@ "submodules": false, "revision": "9001480e03ab8c957716e2bf164bbde605472399", "url": null, - "hash": "1iiplqa731ldha728xk2fi36n87p20hnzf35g21jli1dlknw388f" + "hash": "sha256-DqHB7aQtRCqDeGW4byEQ9yBrRnRidiSOgo2GcRSmN8Y=" }, "flake-compat": { "type": "GitRelease", @@ -75,7 +75,7 @@ "version": "v1.1.0", "revision": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", "url": "https://api.github.com/repos/edolstra/flake-compat/tarball/v1.1.0", - "hash": "19d2z6xsvpxm184m41qrpi1bplilwipgnzv9jy17fgw421785q1m" + "hash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=" }, "flake-utils": { "type": "GitRelease", @@ -91,7 +91,7 @@ "version": "v1.0.0", "revision": "04c1b180862888302ddfb2e3ad9eaa63afc60cf8", "url": "https://api.github.com/repos/numtide/flake-utils/tarball/v1.0.0", - "hash": "0hynd4rbkbplxzl2a8wb3r8z0h17z2alhhdsam78g3vgzpzg0d43" + "hash": "sha256-gzTw/v1vj4dOVbpBSJX4J0DwUR6LIyXo7/SuuTJp1kM=" }, "gtfsBooks": { "type": "Git", @@ -101,9 +101,9 @@ }, "branch": "main", "submodules": false, - "revision": "2a9d4fcf48b872aef1343f71dfddf44946fd8eb5", + "revision": "51ac2f45a806496e384a2a58b8a8604afb687759", "url": null, - "hash": "077xjxaisjqcnqwjpq8cfg34y27cv5aidvzwv4d5736rz9v96bak" + "hash": "sha256-q7VOIz2j+1Q9bChwpFme5F+D2l62bckixabUNQeJOjs=" }, "home-manager": { "type": "Git", @@ -112,11 +112,11 @@ "owner": "nix-community", "repo": "home-manager" }, - "branch": "release-25.11", + "branch": "release-26.05", "submodules": false, - "revision": "0d782ee42c86b196acff08acfbf41bb7d13eed5b", - "url": "https://github.com/nix-community/home-manager/archive/0d782ee42c86b196acff08acfbf41bb7d13eed5b.tar.gz", - "hash": "1kqxy6r4ahnbazmpa4pncdp62najdikdaw8hvrv8nl6qxvbmf9fy" + "revision": "ec172013fa62135f58fb58dd17ae9651e8f39727", + "url": "https://github.com/nix-community/home-manager/archive/ec172013fa62135f58fb58dd17ae9651e8f39727.tar.gz", + "hash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=" }, "isabelle-utils": { "type": "Git", @@ -128,7 +128,7 @@ "submodules": false, "revision": "a44e60333135d9c10b1a0579693ea4c7a655fb05", "url": null, - "hash": "1rksv96izbzcpg74lbix9lw3rxjcy1hs1f4kd8xf4nzclq439931" + "hash": "sha256-YaQ0CKbsW+I6apO4oGHwTPY8OE09LkrOu+yvH03aeuY=" }, "lix": { "type": "Git", @@ -138,9 +138,9 @@ }, "branch": "main", "submodules": false, - "revision": "95ac829cf361035d8d8ee46eb3540d21f7bac842", + "revision": "f04a78f6871e0ccf8404b3cdcd68bbd63f16a2c1", "url": null, - "hash": "0ncnlyyhbrk24xvjzv3wlab50qx3pqqfsrp06a5088rq355kpilc" + "hash": "sha256-rI6ESsiP8BOMz7P2FZYblrMv4sMwkCqM34bKepsMzO8=" }, "lix-nixos-module": { "type": "Git", @@ -150,9 +150,9 @@ }, "branch": "main", "submodules": false, - "revision": "1688100bba140492658d597f6b307c327f35c780", + "revision": "c5b8d8576206ddce31b86e336476c2f9b8361085", "url": null, - "hash": "0pyzj0rdq62fz2i06ldwf9ridp195p6vvsp8yb1pii8h2q81v9lp" + "hash": "sha256-Ikdf593tWTFMkKhtScxE+t2fV+Myh8n4JeYU/0Xc8H8=" }, "mirage-opam-overlays": { "type": "Git", @@ -163,9 +163,9 @@ }, "branch": "main", "submodules": false, - "revision": "eddcd1bc7e035392596b603d23dde67a88e6f6bc", - "url": "https://github.com/dune-universe/mirage-opam-overlays/archive/eddcd1bc7e035392596b603d23dde67a88e6f6bc.tar.gz", - "hash": "09cwhnnmphicm4j6figds2ckagbnypdmcqmbgcszjn6zzll5fymx" + "revision": "5ae850a5cb00d570dc7c1c2d7c2995c1b50e674f", + "url": "https://github.com/dune-universe/mirage-opam-overlays/archive/5ae850a5cb00d570dc7c1c2d7c2995c1b50e674f.tar.gz", + "hash": "sha256-2Kovi4lacyRIz9lZrc9pFvinVhLxopDGzlIZXOEMe18=" }, "nixos-mailserver": { "type": "Git", @@ -174,11 +174,11 @@ "repo_path": "simple-nixos-mailserver/nixos-mailserver", "server": "https://gitlab.com/" }, - "branch": "nixos-25.11", + "branch": "nixos-26.05", "submodules": false, - "revision": "23f0a53ca6e58e61e1ea2b86791c69b79c91656d", - "url": "https://gitlab.com/api/v4/projects/simple-nixos-mailserver%2Fnixos-mailserver/repository/archive.tar.gz?sha=23f0a53ca6e58e61e1ea2b86791c69b79c91656d", - "hash": "0pqc7bay9v360x2b7irqaz4ly63gp4z859cgg5c04imknv0pwjqw" + "revision": "d357b9f048c5532ec81b0e0034c0b8463d5ddd46", + "url": "https://gitlab.com/api/v4/projects/simple-nixos-mailserver%2Fnixos-mailserver/repository/archive.tar.gz?sha=d357b9f048c5532ec81b0e0034c0b8463d5ddd46", + "hash": "sha256-falBPi+PJtMx0vwII8L24wjDGXNZMwRiVXsw8WTXLEo=" }, "nixpkgs": { "type": "Git", @@ -187,11 +187,11 @@ "owner": "NixOS", "repo": "nixpkgs" }, - "branch": "nixos-25.11", + "branch": "nixos-26.05", "submodules": false, - "revision": "23d72dabcb3b12469f57b37170fcbc1789bd7457", - "url": "https://github.com/NixOS/nixpkgs/archive/23d72dabcb3b12469f57b37170fcbc1789bd7457.tar.gz", - "hash": "0dhpsdghgajfkbq8d00p9x4nbnzgl4wmkz7h77zvgc3h40ylk4yg" + "revision": "c3eea5b2156db11c7eeeada3dc737711255b253e", + "url": "https://github.com/NixOS/nixpkgs/archive/c3eea5b2156db11c7eeeada3dc737711255b253e.tar.gz", + "hash": "sha256-vdhpDJ3Lr24lkZ+fDCjmBRRtw9/vcSzkqGJOJyF5h2U=" }, "nixpkgs-unstable": { "type": "Git", @@ -202,9 +202,9 @@ }, "branch": "nixpkgs-unstable", "submodules": false, - "revision": "fef9403a3e4d31b0a23f0bacebbec52c248fbb51", - "url": "https://github.com/NixOS/nixpkgs/archive/fef9403a3e4d31b0a23f0bacebbec52c248fbb51.tar.gz", - "hash": "1fzknmnvbfj8bxkw7bqcyjvxy3v2vz11vkp3r8nwihmrf6wnlpd4" + "revision": "c7def046b9a883d46974757852106483d741586f", + "url": "https://github.com/NixOS/nixpkgs/archive/c7def046b9a883d46974757852106483d741586f.tar.gz", + "hash": "sha256-6RSEDHIWQtesQKWSu5qRai8L2h4KgCgMEfJHstW99G4=" }, "ntfy-matrix-bot": { "type": "Git", @@ -216,7 +216,7 @@ "submodules": false, "revision": "c4bedb1756c96db3f7d01feedc6587f7b0c3dc0f", "url": null, - "hash": "1kq34zk7k6rg9k8frvx51hl1ldqqbfgvhm9f827b5a4c0rx28dah" + "hash": "sha256-UDUkegaMqLKOQC5VuJ9bGDcaKAyl7+zQTC+beeYnA88=" }, "ocaml-forester": { "type": "GitRelease", @@ -231,7 +231,7 @@ "version": "5.0", "revision": "5ceee0e7d20febc0552caad0f71aa01750574d43", "url": null, - "hash": "1ajajlg1yksk666mp5xf0ipy0c2r4pz650mrcprm45rf76xxjmj9" + "hash": "sha256-SVbZuzkuF1LzZbmCYv4lWTDgbwSul1uNMVNPHx6VSqo=" }, "opam-nix": { "type": "Git", @@ -242,9 +242,9 @@ }, "branch": "main", "submodules": false, - "revision": "1f373ef8c4cc1237a74c681b47bbdbdf7ab185a6", - "url": "https://github.com/tweag/opam-nix/archive/1f373ef8c4cc1237a74c681b47bbdbdf7ab185a6.tar.gz", - "hash": "1n1xzxrzypxr7wr3ij0yf13fsrx6xac9jd3m06pk4d2icpq0lmrv" + "revision": "edd1b7bc8574f2242b759b0c4def186af2ab4a70", + "url": "https://github.com/tweag/opam-nix/archive/edd1b7bc8574f2242b759b0c4def186af2ab4a70.tar.gz", + "hash": "sha256-lY9ceaXFru4OWlp6wyJTYaJbXyB4yPvmAOgHiI73pDI=" }, "opam-overlays": { "type": "Git", @@ -255,9 +255,9 @@ }, "branch": "master", "submodules": false, - "revision": "12731a6f86d7c452a94c72106fa9d3327988582d", - "url": "https://github.com/dune-universe/opam-overlays/archive/12731a6f86d7c452a94c72106fa9d3327988582d.tar.gz", - "hash": "0zhgcn5j5aygxqkzsfdsfafw17pr9f2fcs7175kiwyrfj2wzsdmn" + "revision": "d3aca134ac032e7522e95a18f1ef72c63f45459b", + "url": "https://github.com/dune-universe/opam-overlays/archive/d3aca134ac032e7522e95a18f1ef72c63f45459b.tar.gz", + "hash": "sha256-Do6VnAFQm+LTUfpQsHwnP0Efp2AOqhwPMjBU7vQFSDY=" }, "opam-repository": { "type": "GitRelease", @@ -273,7 +273,7 @@ "version": "1.2.0", "revision": "62aabc825803c9dbf126488219524e68d74cd41c", "url": "https://api.github.com/repos/ocaml/opam-repository/tarball/1.2.0", - "hash": "1rk665nzczykyxxs7c7kp2hgy49sn3alvcw15n7gsxm9qyxw0agz" + "hash": "sha256-/ynAu8epdv2OLYGzTdWwOhH/oLjzsKN799N/9m0xZuY=" }, "opam2json": { "type": "GitRelease", @@ -286,10 +286,10 @@ "version_upper_bound": null, "release_prefix": null, "submodules": false, - "version": "v0.4", - "revision": "562752a30aaff8985890ef5a2049a82247fc4b0f", - "url": "https://api.github.com/repos/tweag/opam2json/tarball/v0.4", - "hash": "00z4iqyl1x27nhkn89y771jl0iyqi2kfk8mq55nh0m798xnxz5g6" + "version": "v0.5", + "revision": "03f27d131c97327ed7db91c6dc903101bec08fec", + "url": "https://api.github.com/repos/tweag/opam2json/tarball/v0.5", + "hash": "sha256-rBGN9TERADPXiehNe1/9emO6QqYPrTwSoMdB+BVEWpM=" }, "playground": { "type": "Git", @@ -301,7 +301,7 @@ "submodules": false, "revision": "19144f12772063b1c6f00ad186dabbf53ea25985", "url": null, - "hash": "1ss0n237f0dmw0akw2q0qp8nvnijcg35f9qgy3i27m4ib3gl4ybk" + "hash": "sha256-c3lC31iR1CPi8A8nV8ZjMtpt0cUACz4V4LUBd4awQOs=" }, "rust-overlay": { "type": "Git", @@ -312,9 +312,9 @@ }, "branch": "master", "submodules": false, - "revision": "11a396520bf911e4ed01e78e11633d3fc63b350e", - "url": "https://github.com/oxalica/rust-overlay/archive/11a396520bf911e4ed01e78e11633d3fc63b350e.tar.gz", - "hash": "1wxy14xdw29z144vmp90iai8k5zq3ppq5p1bvbvnnbbg9kx5z4mf" + "revision": "89e99bf0778a8f2cd18c9360c3f19c1ee47fc739", + "url": "https://github.com/oxalica/rust-overlay/archive/89e99bf0778a8f2cd18c9360c3f19c1ee47fc739.tar.gz", + "hash": "sha256-Aggle++fTyAifBy+QBPxjM+obO5iepKW/8MDxQtgGvI=" }, "showrt": { "type": "Git", @@ -326,7 +326,7 @@ "submodules": false, "revision": "7de36af3c6ffcc25832a6ff2303ba6c4c1101de5", "url": null, - "hash": "09shk9b3969gmbmh8mavgss6f90zb51rsfby5n1d924agxzl93d6" + "hash": "sha256-po1Ef3+KiNSCLX45nUNZHyRntH5bVQTrqi+ZNFaaUCc=" }, "sops-nix": { "type": "Git", @@ -337,21 +337,33 @@ }, "branch": "master", "submodules": false, - "revision": "d6e0e666048a5395d6ea4283143b7c9ac704720d", - "url": "https://github.com/Mic92/sops-nix/archive/d6e0e666048a5395d6ea4283143b7c9ac704720d.tar.gz", - "hash": "0f2l5w6af84skfmy051s5727n2wc3bq2fvdjf34jkliyi7jdgfy5" + "revision": "13616fff713a9f94055c66f15687ebdc17a335df", + "url": "https://github.com/Mic92/sops-nix/archive/13616fff713a9f94055c66f15687ebdc17a335df.tar.gz", + "hash": "sha256-4GuMPW90JSxXWDPUB9M+1m7fYbe3H0apOd86/zBQ2Kw=" + }, + "tracktrain": { + "type": "Git", + "repository": { + "type": "Git", + "url": "https://stuebinm.eu/git/tracktrain" + }, + "branch": "main", + "submodules": false, + "revision": "dbb5c4b6b882cd99981eb854386586854a23fdec", + "url": null, + "hash": "sha256-M7aZHfKKo91ZcuQWcBkg2fkn8a7NYDuUTZJfotdkLeY=" }, "traveltext": { "type": "Git", "repository": { "type": "Git", - "url": "https://stuebinm.eu/git/traveltext" + "url": "ssh://cgit/~/public/traveltext" }, "branch": "main", "submodules": false, - "revision": "d876202506621eb76012c12cbb0e91fd2bb0ada0", + "revision": "3a3fe4e9d140dff030d06e45fd6981d14cf97d16", "url": null, - "hash": "0886l3r4fnnd6pc699n9l7kzh1y00y6bbdalab90gjqccviwv9cd" + "hash": "sha256-qDQgZOWBM123WRNs5ddBT6ohQyNKEat3ilWTfEQ6cf8=" }, "uplcg": { "type": "Git", @@ -363,8 +375,8 @@ "submodules": false, "revision": "b61c0b191578d6ed39a6038cca7b436764a1f9f1", "url": null, - "hash": "0675z5gvw0chx3hrr7bpiqxiwcykxhgw8qws17yazi071i8jgl29" + "hash": "sha256-SdAnUQwHxK/8CZpjxB/s0zMeO453nZzh6JABvl/55Rg=" } }, - "version": 5 + "version": 7 } diff --git a/pkgs/default.nix b/pkgs/default.nix index ce35fc2..5563b52 100644 --- a/pkgs/default.nix +++ b/pkgs/default.nix @@ -2,12 +2,11 @@ { inherit (nixpkgs) - galmon-core galmon-full almanac rustex - kijetesantakaluotokieni showrt isabelle-utils isabat - travelynx crs-tracker crs-php bahnhof-name matrix-to - hikari_unstable heartwood radicle-interface radicle-tui - inweb nomsring bookwyrm mollysocket git-annex-remote-remarkable2 - ntfy-matrix-bot transport_validator mergiraf git-who plover plover-dev; + galmon-core galmon-full almanac rustex kijetesantakaluotokieni showrt + isabelle-utils isabat travelynx crs-tracker crs-php bahnhof-name matrix-to + hikari heartwood radicle-interface radicle-tui inweb nomsring bookwyrm + mollysocket git-annex-remote-remarkable2 ntfy-matrix-bot transport_validator + mergiraf git-who plover plover-dev tracktrain; pkgs = nixpkgs; } diff --git a/pkgs/hikari.nix b/pkgs/hikari.nix index afbc335..e096b5a 100644 --- a/pkgs/hikari.nix +++ b/pkgs/hikari.nix @@ -1,8 +1,8 @@ -{ lib, stdenv, fetchzip -, pkg-config, bmake +{ lib, stdenv, fetchgit +, pkg-config , cairo, glib, libevdev, libinput, libxkbcommon, linux-pam, pango, pixman , libucl, wayland, wayland-protocols, wayland-scanner, wlroots, mesa -, libdrm, libgbm +, libdrm, libgbm, ninja, libxcb-wm, meson , features ? { gammacontrol = true; layershell = true; @@ -13,14 +13,15 @@ stdenv.mkDerivation rec { pname = "hikari"; - version = "2.3.3"; + version = "3.0.0"; - src = fetchzip { - url = "https://hikari.acmelabs.space/releases/${pname}-${version}.tar.gz"; - sha256 = "sha256-5Ug0U3ESC5F/gj7bahnLYkeY/weSCj0QASwdFuWwdMI="; + src = fetchgit { + url = "https://codeberg.org/thomasadam/hikari"; + rev = version; + hash = "sha256-gcD0VYIqGoArvRcDpS0BYGDwuxVJZYQpuvv0is6dozM="; }; - nativeBuildInputs = [ pkg-config bmake ]; + nativeBuildInputs = [ pkg-config meson ninja ]; buildInputs = [ cairo @@ -28,6 +29,7 @@ stdenv.mkDerivation rec { libevdev libinput libxkbcommon + libxcb-wm libdrm libgbm linux-pam @@ -41,22 +43,9 @@ stdenv.mkDerivation rec { wlroots ]; - patches = [ ./patches/hikari-gtk4.patch ]; - enableParallelBuilding = true; - makeFlags = with lib; [ "PREFIX=$(out)" "DEBUG=YES" ] - ++ optional stdenv.isLinux "WITH_POSIX_C_SOURCE=YES" - ++ mapAttrsToList (feat: enabled: - optionalString enabled "WITH_${toUpper feat}=YES" - ) features; - postPatch = '' - # Can't suid in nix store - # Run hikari as root (it will drop privileges as early as possible), or create - # a systemd unit to give it the necessary permissions/capabilities. - substituteInPlace Makefile --replace '4555' '555' - sed -i 's@<drm_fourcc.h>@<libdrm/drm_fourcc.h>@' src/*.c ''; diff --git a/pkgs/overlay.nix b/pkgs/overlay.nix index f76496e..c539517 100644 --- a/pkgs/overlay.nix +++ b/pkgs/overlay.nix @@ -27,25 +27,6 @@ in }) { }; - #### taken from nixpkgs PRs - - - plover = self.python3Packages.callPackage ./plover/plover.nix { - inherit (self.libsForQt5) wrapQtAppsHook; - pyqt = self.python3Packages.pyqt5; - }; - - plover-dev = self.python3Packages.callPackage ./plover/plover-dev.nix { - inherit (self.qt6) wrapQtAppsHook qtbase; - pyqt = self.python3Packages.pyside6; - }; - - plover-stroke = self.python3Packages.callPackage ./plover/plover-stroke.nix { }; - - - rtf-tokenize = self.python3Packages.callPackage ./plover/rtf_tokenize.nix { }; - - #### packages which are actually in use somewhere #### @@ -59,7 +40,7 @@ in ]; }); - akkoma = (self.callPackage ./akkoma {}).overrideAttrs { + akkoma = (super.akkoma).overrideAttrs { patches = [ ./patches/akkoma-toki-pona.patch ]; }; @@ -172,14 +153,18 @@ in }; in '' ln -sf ${TwemojiMozilla-colr} \ - res/fonts/Twemoji_Mozilla/TwemojiMozilla-colr.woff2 + apps/web/res/fonts/Twemoji_Mozilla/TwemojiMozilla-colr.woff2 ln -sf ${TwemojiMozilla-sbix} \ - res/fonts/Twemoji_Mozilla/TwemojiMozilla-sbix.woff2 - substituteInPlace src/stores/room-list/ListLayout.ts \ - --replace "TILE_HEIGHT_PX = 44" "TILE_HEIGHT_PX = 32" + apps/web/res/fonts/Twemoji_Mozilla/TwemojiMozilla-sbix.woff2 + # substituteInPlace apps/web/src/stores/room-list/ListLayout.ts \ + # --replace "TILE_HEIGHT_PX = 44" "TILE_HEIGHT_PX = 32" ''; }; + tracktrain = self.callPackage (inputs.tracktrain {}) { + #compiler = "default"; + }; + bahnhof-name = let haskellPkgs = self.haskellPackages.override (old: { @@ -234,9 +219,9 @@ in }) {}; }; }); - pkg = { mkDerivation, base, bytestring, cassava, containers + pkg = { mkDerivation, base, bytestring, cassava, containers, dns , fuzzyfind, fuzzyset, http-client, http-client-rustls, http-types - , lib, stm, text, time, vector, wai, wai-extra, warp + , lib, network, stm, text, time, vector, wai, wai-extra, warp }: mkDerivation { pname = "bahnhof-name"; @@ -245,10 +230,11 @@ in isLibrary = false; isExecutable = true; executableHaskellDepends = [ - base bytestring cassava containers fuzzyfind fuzzyset http-client - http-client-rustls http-types stm text time vector wai wai-extra - warp + base bytestring cassava containers dns fuzzyfind fuzzyset + http-client http-client-rustls http-types network stm text time + vector wai wai-extra warp ]; + description = "Serve information on German railway stations"; jailbreak = true; mainProgram = "bahnhof-name"; license = lib.licenses.eupl12; @@ -265,13 +251,6 @@ in #### sporadically maintained / updated #### - hikari_unstable = (unstable.hikari.overrideAttrs (old: { - src = /home/stuebinm/clones/hikari; - buildInputs = old.buildInputs ++ [ self.pandoc self.xorg.xcbutilwm.dev ]; #self.libdrm self.libdrm.dev ]; - makeFlags = with self.lib; - [ "PREFIX=$(out)" "WITH_POSIX_C_SOURCE=YES" - "WITH_GAMMACONTROL=YES" "WITH_LAYERSHELL=YES" "WITH_SCREENCOPY=YES" ]; - })).override { wlroots = unstable.wlroots_0_16; stdenv = self.clangStdenv; }; twelf = super.twelf.overrideAttrs (old: { src = self.fetchFromGitHub { owner = "k4rtik"; @@ -305,9 +284,7 @@ in }; - hikari = self.callPackage ./hikari.nix { wlroots = self.wlroots_0_15; }; - - wlroots_0_15 = self.callPackage ./wlroots_0_15.nix {}; + hikari = self.callPackage ./hikari.nix { }; travelynx = self.callPackage ./travelynx.nix {}; diff --git a/pkgs/patches/element-css.patch b/pkgs/patches/element-css.patch index 4123bab..94621ff 100644 --- a/pkgs/patches/element-css.patch +++ b/pkgs/patches/element-css.patch @@ -2,8 +2,8 @@ diff --git a/res/css/dings.custom.css b/res/css/dings.custom.css new file mode 100644 index 000000000..48ae3414f --- /dev/null -+++ b/res/css/dings.custom.css -@@ -0,0 +1,104 @@ ++++ b/apps/web/res/css/dings.custom.css +@@ -0,0 +1,120 @@ + +.mx_RoomTile .mx_RoomTile_titleContainer .mx_RoomTile_title { + font-size: 11pt !important; @@ -108,10 +108,26 @@ index 000000000..48ae3414f + --MBody-border-radius: 2px !important; +} + ++[class*="roomListItem"] { ++ min-height: 35px; ++ color: white; ++} ++[class*="selected"]>div { ++ background-color: darkred ++} ++[class*="selected"]>div::before { ++ background-color: unset ++} ++[class*="stickyRow"] [class*="container"] { ++ border-color: darkred; ++ border-bottom: 3px solid darkred; ++ border-radius: 0; ++ color: white; ++} diff --git a/src/vector/index.html b/src/vector/index.html index f5213701c..50e0729d9 100644 ---- a/src/vector/index.html -+++ b/src/vector/index.html +--- a/apps/web/src/vector/index.html ++++ b/apps/web/src/vector/index.html @@ -48,6 +48,7 @@ <link rel="stylesheet" href="<%= file %>"> <% } @@ -122,8 +138,8 @@ index f5213701c..50e0729d9 100644 let path = tag.attributes && tag.attributes.href; diff --git a/webpack.config.js b/webpack.config.js index d7dc5ffa0..00f751ed8 100644 ---- a/webpack.config.js -+++ b/webpack.config.js +--- a/apps/web/webpack.config.ts ++++ b/apps/web/webpack.config.ts @@ -365,6 +365,24 @@ module.exports = (env, argv) => { }, }, diff --git a/pkgs/plover/default.nix b/pkgs/plover/default.nix deleted file mode 100644 index 865d469..0000000 --- a/pkgs/plover/default.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ config, lib, pkgs, ... }: - -{ - -} diff --git a/pkgs/plover/plover-dev.nix b/pkgs/plover/plover-dev.nix deleted file mode 100644 index c39ee14..0000000 --- a/pkgs/plover/plover-dev.nix +++ /dev/null @@ -1,73 +0,0 @@ -{ - lib, - fetchFromGitHub, - writeShellScriptBin, - plover, - python3Packages, - pkginfo, - packaging, - psutil, - pygments, - readme-renderer, - requests-cache, - requests-futures, - # Qt - pyqt, - qtbase, - wrapQtAppsHook, -}: - -(plover.override { - inherit wrapQtAppsHook pyqt; -}).overridePythonAttrs - (oldAttrs: rec { - version = "5.0.0.dev2"; - - src = fetchFromGitHub { - owner = "openstenoproject"; - repo = "plover"; - tag = "v${version}"; - hash = "sha256-PZwxVrdQPhgbj+YmWZIUETngeJGs6IQty0hY43tLQO0="; - }; - - pyproject = true; - - # pythonRelaxDeps seemingly doesn't work here - postPatch = oldAttrs.postPatch + '' - sed -i /PySide6-Essentials/d pyproject.toml - - substituteInPlace pyproject.toml \ - --replace-fail "setuptools>=79.0.0" "setuptools" - ''; - - build-system = oldAttrs.build-system ++ [ - # Replacement for missing pyside6-essentials tools, - # workaround for https://github.com/NixOS/nixpkgs/issues/277849. - # Ideally this would be solved in pyside6 itself but I spent four - # hours trying to untangle its build system before giving up. If - # anyone wants to spend the time fixing it feel free to request - # me (@Pandapip1) as a reviewer. - (writeShellScriptBin "pyside6-uic" '' - exec ${qtbase}/libexec/uic -g python "$@" - '') - (writeShellScriptBin "pyside6-rcc" '' - exec ${qtbase}/libexec/rcc -g python "$@" - '') - ]; - - dependencies = - oldAttrs.dependencies - ++ [ - packaging - pkginfo - psutil - pygments - qtbase - readme-renderer - requests-cache - requests-futures - ] - ++ readme-renderer.optional-dependencies.md; - - meta.description = oldAttrs.meta.description + " (Development version)"; - }) diff --git a/pkgs/plover/plover-stroke.nix b/pkgs/plover/plover-stroke.nix deleted file mode 100644 index 62da352..0000000 --- a/pkgs/plover/plover-stroke.nix +++ /dev/null @@ -1,39 +0,0 @@ -{ - lib, - buildPythonPackage, - fetchFromGitHub, - setuptools, - pytestCheckHook, - pytest-qt, - pyside6, -}: - -buildPythonPackage rec { - pname = "plover-stroke"; - version = "1.1.0"; - pyproject = true; - - src = fetchFromGitHub { - owner = "openstenoproject"; - repo = "plover_stroke"; - tag = version; - hash = "sha256-A75OMzmEn0VmDAvmQCp6/7uptxzwWJTwsih3kWlYioA="; - }; - - build-system = [ setuptools ]; - - nativeCheckInputs = [ - pytestCheckHook - pytest-qt - pyside6 - ]; - - pythonImportsCheck = [ "plover_stroke" ]; - - meta = { - description = "Helper class for working with steno strokes"; - homepage = "https://github.com/openstenoproject/plover_stroke"; - license = lib.licenses.gpl2Plus; # https://github.com/openstenoproject/plover_stroke/issues/4 - maintainers = with lib.maintainers; [ pandapip1 ]; - }; -} diff --git a/pkgs/plover/plover.nix b/pkgs/plover/plover.nix deleted file mode 100644 index 17c106c..0000000 --- a/pkgs/plover/plover.nix +++ /dev/null @@ -1,96 +0,0 @@ -{ - lib, - config, - stdenv, - plover, - buildPythonPackage, - fetchFromGitHub, - fetchpatch, - versionCheckHook, - appdirs, - babel, - evdev, - mock, - pyserial, - pytestCheckHook, - pytest-qt, - plover-stroke, - rtf-tokenize, - setuptools, - wcwidth, - wheel, - xlib, - # Qt dependencies - pyqt, - wrapQtAppsHook, -}: - -buildPythonPackage rec { - pname = "plover"; - version = "4.0.2"; - pyproject = true; - - src = fetchFromGitHub { - owner = "openstenoproject"; - repo = "plover"; - tag = "v${version}"; - hash = "sha256-VpQT25bl8yPG4J9IwLkhSkBt31Y8BgPJdwa88WlreA8="; - }; - - postPatch = '' - sed -i 's/,<77//g' pyproject.toml # pythonRelaxDepsHook doesn't work for this for some reason - ''; - - build-system = [ - babel - setuptools - pyqt - wheel - ]; - dependencies = [ - appdirs - evdev - pyqt - pyserial - plover-stroke - rtf-tokenize - setuptools - wcwidth - xlib - ]; - nativeBuildInputs = [ - wrapQtAppsHook - ]; - - nativeCheckInputs = [ - pytestCheckHook - versionCheckHook - pytest-qt - mock - ]; - - # Segfaults?! - disabledTestPaths = [ "test/gui_qt/test_dictionaries_widget.py" ]; - - preFixup = '' - makeWrapperArgs+=("''${qtWrapperArgs[@]}") - ''; - - dontWrapQtApps = true; - - pythonImportsCheck = [ "plover" ]; - - meta = { - description = "OpenSteno Plover stenography software"; - homepage = "https://www.openstenoproject.org/plover/"; - mainProgram = "plover"; - maintainers = with lib.maintainers; [ - twey - kovirobi - pandapip1 - ]; - license = lib.licenses.gpl2Plus; - platforms = lib.platforms.unix; - broken = stdenv.hostPlatform.isDarwin; - }; -} diff --git a/pkgs/plover/rtf_tokenize.nix b/pkgs/plover/rtf_tokenize.nix deleted file mode 100644 index 805845f..0000000 --- a/pkgs/plover/rtf_tokenize.nix +++ /dev/null @@ -1,33 +0,0 @@ -{ - lib, - buildPythonPackage, - fetchFromGitHub, - setuptools, - pytestCheckHook, -}: - -buildPythonPackage rec { - pname = "rtf-tokenize"; - version = "1.0.0"; - pyproject = true; - - src = fetchFromGitHub { - owner = "openstenoproject"; - repo = "rtf_tokenize"; - tag = version; - hash = "sha256-zwD2sRYTY1Kmm/Ag2hps9VRdUyQoi4zKtDPR+F52t9A="; - }; - - build-system = [ setuptools ]; - - nativeCheckInputs = [ pytestCheckHook ]; - - pythonImportsCheck = [ "rtf_tokenize" ]; - - meta = { - description = "Simple RTF tokenizer package for Python"; - homepage = "https://github.com/openstenoproject/rtf_tokenize"; - license = lib.licenses.gpl2Plus; # https://github.com/openstenoproject/rtf_tokenize/issues/1 - maintainers = with lib.maintainers; [ pandapip1 ]; - }; -} diff --git a/secrets/chaski.yaml b/secrets/chaski.yaml index 7f07b2c..31c18b3 100644 --- a/secrets/chaski.yaml +++ b/secrets/chaski.yaml @@ -1,10 +1,10 @@ ntfy-matrix-bot: env: ENC[AES256_GCM,data:mk/7fcdfsq+BOB8QK7LzVhYMDmMLw0cB0qq3p2IGWQAJtodqlqQMJukVF0jpoJLB/9GMcCweloVikus9K23/lcUPMZFHCdpMRR94puGROub8RF+v6XvegC741utlsLWGnS+Z/U8atHoI2rptdh4OV9lwELFYMpwDC/2IhxnhIyqWbAKnuWGdJcNVAKF6QxI0gY854xKoxRNXs3BrctoubSbBSyarjQiFgpk=,iv:jip5eTFPyBa199/SZhfezMY+Og8i1rh+2dmfVzBRPpo=,tag:xyLR34PqtJI63M5qnMvemQ==,type:str] +tracktrain: + env: "" +nginx: + tracktrain-auth: ENC[AES256_GCM,data:VlcsqohpTdTJ56DtKfjkGZD671jW5LBLWhcKfBQAmYq0RBtiBTzM0oZTYGl7quUZPuIAB0bM8alEcGsPQep8wAre,iv:+I0PQr4LwjwC2xTJDXpr7UxqTAhDCk3JvMlsmaOK6L8=,tag:LzjbqFruDNWGFm03yft79A==,type:str] sops: - kms: [] - gcp_kms: [] - azure_kv: [] - hc_vault: [] age: - recipient: age18wkr3kjalalzrq9l05q32gnlaqr7t6rqqzde307m83rs9fp4xcfsdtj9gt enc: | @@ -24,8 +24,7 @@ sops: aFF6Nkowc3kxckFGNWRqSUxYdXZOd0kKsoRAtnnhIkaPACXgaGzMNW6uAG4pAg4d DdgcTPKdAEv0uAqAmndsll+vWE1C0FaUwe37/jmBfAKrXpN7GwVa4g== -----END AGE ENCRYPTED FILE----- - lastmodified: "2024-03-27T22:32:40Z" - mac: ENC[AES256_GCM,data:MJTMrHLh9rL7p1Y+e4if51ZYvfYWDV25eJvJ3unZwIAahF5GoOav4rb1hU1hLObZFhtlyjgHe/VGP2D+QsDARJOop0kGiybnfHqz7Vh7KIWhjDwsxaBPkxMUovxrEhxnwHR8+zKqNs+Vcl06ZaJ2F6U0rJRqyxO2CK5aSnuqDtE=,iv:qDsnPrVlnwnmWFJYxgCBCvg1/qgFl1IOC3QEifXaEbs=,tag:/oVJDam2l7pD+g2tIBAakg==,type:str] - pgp: [] + lastmodified: "2026-03-29T21:30:26Z" + mac: ENC[AES256_GCM,data:4zial4AotTlj7/EifC6A9SptDM0HjdBJcINRUPGv0FT8QjinfQD8kQTlRh6LOr+2jfcNkoll5Inxt4Aibl0FpYjiaiML2T2RZXb3e12JE7gcE1ndNBWMbS2DRF2DWPrQywoW2a6IzI3oAC9dZxrFBVkx8mPYGWBtxifmYCBqPfU=,iv:9OBOAR+HS/hDwEh7DK+Vc6s+pwFWDlduq1sxb9aXkvk=,tag:hCFbxL8pFivX7QCDQ6QmYg==,type:str] unencrypted_suffix: _unencrypted - version: 3.8.1 + version: 3.12.1 |
