Compare commits

..
89 Commits
Author SHA1 Message Date
samw 89328c7160 25.11 -> 26.05 2026-09-13 04:29:30 +01:00
samw b9365a827d add fd 2026-09-13 04:27:33 +01:00
samw 571202560a fmt 2026-09-13 04:27:33 +01:00
samw 275f56dd55 goodbye zinc, hello gallium 2026-09-13 04:27:33 +01:00
samw 344f52c05b ssh: connection sharing thing 2026-07-02 11:13:49 +01:00
samw a6a4f5660b git: unpushed alias 2026-07-02 11:13:49 +01:00
samw edcb288716 flake: add kallax 2026-06-07 16:00:37 +01:00
samw 327962567f macs: add smerge to path 2026-04-05 17:13:50 +01:00
samw 5e5bacfd14 wezterm: enable 2026-03-26 18:23:57 +00:00
samw 433c96eca4 me: add gallium ssh key 2026-03-15 16:58:52 +00:00
samw 746b05f91c macs: only source brew if exists 2026-03-15 16:58:39 +00:00
samw ad60d86c53 ssh: squish warning 2026-02-27 18:22:24 +00:00
samw ac362b6667 macs: squish home manager warning (again?) 2026-02-05 01:04:38 +00:00
samw 072ff7acdc hx: fix rust-analyzer, remove basedpyright (it's in upstream) 2025-12-29 17:53:25 +01:00
samw edefea64ee helix: show hidden files, rendering tweaks 2025-12-16 14:37:22 +00:00
samw 1ede986cc1 fzf: show hidden 2025-12-16 14:37:22 +00:00
samw aebb5dcd08 fmt 2025-12-05 16:34:49 +00:00
samw 7a1df05022 vscode: updates for 25.11 2025-12-05 16:34:45 +00:00
samw 97d3c6f0af iterm: ok whatever 2025-12-05 16:29:06 +00:00
samw c4953a227a git: add mergiraf 2025-12-05 16:29:06 +00:00
samw 84d4741d98 various updates 2025-12-05 16:29:06 +00:00
samw 924177bd4c use nixos-x rather than release-x, pin unstable 2025-12-05 16:26:08 +00:00
samw b15ba6c14c direnv: increase warning time 2025-12-05 16:16:40 +00:00
samw d90384b2de starship: add direnv 2025-12-05 15:55:32 +00:00
samw 31b30027ce update to 25.11 2025-12-05 15:54:38 +00:00
samw 7c56f42779 nix: use nixfmt-rfc-style 2025-12-05 15:48:11 +00:00
samw ef681a3ba8 squash 2025-12-05 15:44:22 +00:00
samw cee2d8e6bc fix warnings 2025-12-05 15:44:12 +00:00
samw b3fedf3584 fzf: get files from fd to respect gitignore when ctrl-ting 2025-12-05 15:43:35 +00:00
samw 1e8b5ebb0d phosphorus: add 2025-12-05 15:42:39 +00:00
samw f89e0bcec7 helix: add and configure 2025-12-05 15:41:53 +00:00
samw 6e55465310 25.11 updates, hope it works on 2505 lol 2025-10-07 17:26:18 +01:00
samw 9d1d445fbc add helix 2025-10-07 16:45:31 +01:00
samw 38715744d0 update to 25.05 2025-08-29 20:29:45 +01:00
samw c12f8e2d07 vim: fix trouble 2025-05-13 01:02:40 +01:00
samw 78f926a1a1 flake: 24.05->24.11 2025-05-13 00:57:14 +01:00
samw 5b373b9a57 tpmssh: fix socket 2024-10-05 16:45:57 +01:00
samw 700b56d41a fix 2024-09-28 23:19:25 +01:00
samw 665403ee0f maybe don't clobber sessionvariables 2024-09-28 20:06:13 +01:00
samw c0978d2186 add tpmssh 2024-09-28 19:57:44 +01:00
samw b3b9941c9b remove boron 2024-09-28 19:19:59 +01:00
samw 8fd2a4fb6e shell: shorten/expand homemanager/nixos-rebuild aliases 2024-09-26 13:33:21 +01:00
samw cc24d247b1 vim: replace pylsp with basedpyright 2024-09-25 21:41:59 +01:00
samw c38a6da542 gpg: fix pinentry 2024-09-22 14:32:13 +01:00
samw 36ae4c738d update to 24.05 2024-06-08 22:42:24 +01:00
samw 7f90b53891 zsh: squash warning 2024-04-24 23:12:13 +01:00
samw 58e331678d flake: update 2024-04-24 23:10:02 +01:00
samw 9f821584d5 add nix shell alias 2024-04-24 22:56:53 +01:00
samw 786d7d1b06 update to 23.11 2024-03-30 21:25:55 +00:00
samw c5c4e59f04 s/exa/eza 2024-03-30 21:23:53 +00:00
samw 007d0203bc git: add lfs 2023-11-27 19:09:30 +00:00
samw eb0ee2cdce flake: update nixpkgs 2023-10-03 17:49:51 +01:00
samw 39c4a76673 gpg: disable agent on darwin 2023-10-03 17:48:06 +01:00
samw 7eaf129278 zsh: make fzf respect gitignore 2023-10-03 10:48:58 +01:00
samw 57ca6b2305 pkgs: add dig/whois 2023-08-25 17:05:16 +01:00
samw a2cab93005 gpg: ssh support 2023-08-25 17:05:16 +01:00
samw 604cf1b75d Fine iterm have your changes dammit 2023-08-18 13:07:08 +02:00
samw 2941017589 friendship ended with rnix, now nil is my best friend 2023-08-18 13:07:08 +02:00
samw 6b46199500 gpg: enable agent 2023-07-17 01:32:22 +01:00
samw 0fbb31defe gpg: enable ccid on not-darwin 2023-07-17 01:03:11 +01:00
samw a44510a299 git: add tea cli 2023-07-15 15:02:11 +01:00
samw 94453d9b7f flake: update inputs to fix vscode breakage 2023-06-16 12:41:27 +01:00
samw cf1a0cbee2 update to 23.05 2023-06-03 19:38:11 +08:00
samw b0ae82d147 vim: add open on *hub plugin 2023-06-03 19:25:26 +08:00
samw b4dedbbea3 Fix EDITOR=nvim on nixos 23.05 2023-05-28 20:58:01 +08:00
samw 7cff2f9d50 vscode: auto color scheme, rulers, ssh 2023-04-21 14:42:58 +01:00
samw 780b0969ed vim: switch snippy for vsnip 2023-04-17 14:25:34 +01:00
samw 098307eac9 nvim: make tabs look nicer 2023-04-07 00:58:14 +01:00
samw e8d7c460db nvim: configure lsp completion snippets 2023-04-07 00:57:41 +01:00
samw 9c620bd13d flake: update nixpkgs 2023-03-06 11:53:39 +00:00
samw ca7b30470f nix: pin nixpkgs in registry to flake nixpkgs 2023-02-28 22:02:05 +00:00
samw 17988ec069 vim: add nvim-go, update nixpkgs 2023-02-21 18:17:56 +00:00
samw f3533d8033 me: remove boron pubkey 2023-02-10 15:36:29 +00:00
samw a0b452def4 Allow unfree, fix weird nix error when using home in nixos config 2023-01-07 13:47:13 +00:00
samw 1529fda04d flake: update inputs 2023-01-05 01:21:00 +00:00
samw 6f688efc96 zsh: add dr alias 2023-01-05 01:19:16 +00:00
samw 2231683ffc vim: add html5 plugin, update nixpkgs 2022-12-27 01:23:32 +00:00
samw 9017475528 vim: Add rustopendocs command 2022-12-16 21:14:20 +00:00
samw 96396f67a7 flake: Add luroy 2022-12-16 19:41:35 +00:00
samw 91c2171da3 vim: disable completions in comments
also fancy borders
2022-12-16 16:26:34 +00:00
samw 74b11aead4 vim: Add lsp completion 2022-12-15 18:42:05 +00:00
samw 9d17d0b0be Remove zbar workaround 2022-12-15 17:34:53 +00:00
samw d173f84fc0 Update to 22.11, remove ykman workaround 2022-12-15 17:34:53 +00:00
samw 8eef537cba zsh: Ignore dupes in history 2022-12-12 01:01:30 +00:00
samw 8e435df3e2 zsh: autocd 2022-12-11 21:15:43 +00:00
samw b9820b9a5e git: add git-open 2022-11-19 22:37:14 +00:00
samw 6c85de5bcd vsc: Add nix/editorconfig exts 2022-11-19 22:37:09 +00:00
samw d2d59eefa0 vim: Tweak textwidth, fix python autoindent 2022-11-19 22:36:31 +00:00
samw 7ac16e425a Remove rust (in favour of individual direnvs) 2022-11-19 22:36:31 +00:00
26 changed files with 2610 additions and 721 deletions
Generated
+49 -18
View File
@@ -2,19 +2,16 @@
"nodes": {
"devshell": {
"inputs": {
"flake-utils": [
"flake-utils"
],
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1654858401,
"narHash": "sha256-53bw34DtVJ2bnF6WEwy6Tym+qY0pNEiEwARUlvmTZjs=",
"lastModified": 1764011051,
"narHash": "sha256-M7SZyPZiqZUR/EiiBJnmyUbOi5oE/03tCeFrTiUZchI=",
"owner": "numtide",
"repo": "devshell",
"rev": "f55e05c6d3bbe9acc7363bc8fc739518b2f02976",
"rev": "17ed8d9744ebe70424659b0ef74ad6d41fc87071",
"type": "github"
},
"original": {
@@ -24,12 +21,15 @@
}
},
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1653893745,
"narHash": "sha256-0jntwV3Z8//YwuOjzhV2sgJJPt+HY6KhU7VZUL0fKZQ=",
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "1ed9fb1935d260de5fe1c2f7ee0ebaae17ed2fa1",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
@@ -45,32 +45,47 @@
]
},
"locked": {
"lastModified": 1654113405,
"narHash": "sha256-VpK+0QaWG2JRgB00lw77N9TjkE3ec0iMYIX1TzGpxa4=",
"lastModified": 1789267039,
"narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "ac2287df5a2d6f0a44bbcbd11701dbbf6ec43675",
"rev": "ec172013fa62135f58fb58dd17ae9651e8f39727",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "release-22.05",
"ref": "release-26.05",
"repo": "home-manager",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1662874738,
"narHash": "sha256-kG29aU9f5UTWhPf/QEh5LanDmqqbbcErWYAcPptC/Cg=",
"lastModified": 1789114715,
"narHash": "sha256-ugpsyk3NM2s87vXfUiIIiibbJ4Pp0JPS5p/3mfs+q+c=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "dd1f4d982445a7d1b1869baa42f8f0f9bc606714",
"rev": "21a67dc470149f337cecafbe965d8d252a390518",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1764951420,
"narHash": "sha256-oLJXP0fb5hyUvHGKAWdtjhl1/4ivxXy3HsuMMTTxrd8=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "0b784f7c32b9bbab8a599ccc6b4acc58f42d6f4f",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-22.05",
"repo": "nixpkgs",
"type": "github"
}
@@ -80,7 +95,23 @@
"devshell": "devshell",
"flake-utils": "flake-utils",
"home-manager": "home-manager",
"nixpkgs": "nixpkgs"
"nixpkgs": "nixpkgs",
"nixpkgs-unstable": "nixpkgs-unstable"
}
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
}
},
+106 -30
View File
@@ -2,85 +2,161 @@
description = "Samw's home environment, as managed by nix/home-manager.";
inputs = {
# Nixpkgs
nixpkgs = {url = "github:nixos/nixpkgs/nixos-22.05";};
nixpkgs = {
# N.B. we use the nixos-x branch as this is updated *after* successful hydra builds
# rather than release-x. See https://wiki.nixos.org/wiki/Channel_branches
url = "github:nixos/nixpkgs/nixos-26.05";
};
nixpkgs-unstable = {
url = "github:nixos/nixpkgs";
};
# Other modules
home-manager = {
url = "github:nix-community/home-manager/release-22.05";
url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
flake-utils.url = "github:numtide/flake-utils";
devshell = {
url = "github:numtide/devshell";
inputs.flake-utils.follows = "flake-utils";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs: let
outputs =
inputs:
let
overlays = [
# Add our own local packages
(final: prev: rec {
(final: prev: {
# Make my local packages available as pkgs.mypkgs.<foo>
mypkgs = prev.callPackage ./pkgs { };
# Directly override yubikey-manager
yubikey-manager = mypkgs.yubikey-manager;
})
# more up to date ssh-tpm-agent. Can probably ditch this post-24.05
(final: prev: {
ssh-tpm-agent = (import inputs.nixpkgs-unstable { system = prev.system; }).ssh-tpm-agent;
})
];
in (rec {
in
(
rec {
profiles = import ./home/profiles.nix;
lib = {
mkHome = {
mkHome =
{
profiles,
system,
username ? "samw",
}:
inputs.home-manager.lib.homeManagerConfiguration {
inherit username system;
stateVersion = "21.11";
pkgs = (
import inputs.nixpkgs {
inherit system;
config.allowUnfree = true; # Yes I know it's bad for me
}
);
modules = [
{
home = {
inherit username;
homeDirectory =
if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin
then "/Users/${username}"
else "/home/${username}";
# In home-manager 22.11 configuration/extraModules go away and are replaced
# by a single "modules". So let's get ready for that.
configuration = {...}: {};
if (inputs.nixpkgs.lib.systems.elaborate system).isDarwin then
"/Users/${username}"
else
"/home/${username}";
stateVersion = "21.11";
};
}
]
++ profiles
++ [
{ nixpkgs.overlays = overlays; }
# See comment in home/default.nix.
(
{ pkgs, ... }:
{
nix = {
enable = true;
package = pkgs.nix;
settings.experimental-features = "nix-command flakes";
settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel)
# Pin the nixpkgs registry to our locked nixpkgs. This means that we
# get the same packages via e.g. nix shell as we have at the system
# level, so less duplication overall and no more fetching that 30MB src
# every time you run nix shell.
registry.nixpkgs.flake = inputs.nixpkgs;
registry.nixpkgs-unstable.to = {
owner = "nixos";
repo = "nixpkgs";
type = "github";
};
};
}
)
];
extraSpecialArgs = { inherit system; };
extraModules = profiles ++ [{nixpkgs.overlays = overlays;}];
};
};
# Standalone home-manager configurations
homeConfigurations = {
boron = lib.mkHome {
gallium = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [default dev dev-gui sensitive mac docker aws];
username = "samuel.willcocks";
profiles = with profiles; [
default
dev
dev-gui
sensitive
mac
];
};
zinc = lib.mkHome {
luroy = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [
default
dev
];
};
kallax = lib.mkHome {
system = "x86_64-linux";
profiles = with profiles; [default dev];
};
phosphorus = lib.mkHome {
system = "aarch64-darwin";
profiles = with profiles; [default dev dev-gui sensitive mac];
profiles = with profiles; [
default
dev
sensitive
mac
];
};
};
}
# Per-system things
// (inputs.flake-utils.lib.eachDefaultSystem (system: let
// (inputs.flake-utils.lib.eachDefaultSystem (
system:
let
pkgs = import inputs.nixpkgs {
inherit system;
overlays = overlays ++ [inputs.devshell.overlay];
overlays = overlays ++ [ inputs.devshell.overlays.default ];
};
platform = pkgs.lib.systems.elaborate system;
in {
in
{
# Flake interface to my local packages.
# - `callPackage` puts some junk in mypkgs (`override` and
# `overrideDerivation`) so we filter out anything that isn't a derivation
# - We also filter out any packages that aren't supported on the current
# platform.
packages = with pkgs.lib; (filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs);
formatter = pkgs.alejandra;
packages =
with pkgs.lib;
(filterAttrs (_: v: (isDerivation v && meta.availableOn platform v)) pkgs.mypkgs);
formatter = pkgs.nixfmt-tree;
# A devshell with useful utils
devShells.default = pkgs.devshell.mkShell {
packages = [
inputs.home-manager.defaultPackage.${system}
inputs.home-manager.packages.${system}.default
];
};
})));
}
))
);
}
+4 -1
View File
@@ -1 +1,4 @@
{pkgs, ...}: {home.packages = with pkgs; [awscli2];}
{ pkgs, ... }:
{
home.packages = with pkgs; [ awscli2 ];
}
File diff suppressed because it is too large Load Diff
+45 -21
View File
@@ -1,43 +1,53 @@
{
pkgs,
lib,
...
}: let
}:
let
packages = pkgs.callPackage ./packages.nix { };
in {
in
{
home.packages = packages.all;
home.sessionVariables = {
"PATH" = "$HOME/.local/bin:$PATH";
"EDITOR" = "vim";
"WORDCHARS" = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery
EDITOR = "vim"; # is overriden to nvim in vim.nix if needed
WORDCHARS = "\${WORDCHARS//[\\/.=]/}"; # ctrl-w on paths without make angery
};
/*
# For some reason this doesn't play nice when using home manager config from inside
# a nixos configuration.
nix = {
enable = true;
package = pkgs.nix;
settings.experimental-features = "nix-command flakes";
settings.max-jobs = "auto"; # Gotta go fast (build derivations in parallel)
};
*/
programs = {
home-manager.enable = true;
# Shell and env-y stuff
zsh = {
enable = true;
autocd = true;
history = rec {
extended = true;
size = 100000;
save = size;
ignoreDups = true;
};
shellAliases = {
g = "git";
cat = "bat";
ip = "ip --color=auto";
hmswitch = ''home-manager switch --flake ".#$(hostname -s)"'';
nrswitch = "nixos-rebuild --use-remote-sudo switch --flake '.#'";
ns = "nix shell nixpkgs#";
hm = ''home-manager --flake ".#$(hostname -s)"'';
hms = ''home-manager --flake ".#$(hostname -s)" switch'';
nr = "nixos-rebuild --sudo --flake '.#'";
nrs = "nixos-rebuild --sudo --flake '.#' switch";
da = "direnv allow .";
dr = "direnv reload";
};
# Extra .zshrc stuff
initExtra = ''
initContent = ''
# zstyle ':completion:*' menu select # fancy interactive autocomplete
zstyle ':completion:*' matcher-list 'm:{a-z}={A-Za-z}' # tabcomplete lower to upper case
@@ -47,7 +57,7 @@ in {
# Don't honk at me constantly
unsetopt beep
'';
enableSyntaxHighlighting = true;
syntaxHighlighting.enable = true;
plugins = [
{
name = "fzf-tab";
@@ -60,42 +70,56 @@ in {
];
};
exa = {
enable = true;
enableAliases = true;
};
eza.enable = true;
starship = {
enable = true;
settings = {
add_newline = false;
format = "$username$hostname$shlvl$directory$git_branch$git_commit$git_state$git_metrics$git_status$hg_branch$docker_context$golang$kotlin$nodejs$python$rust$terraform$nix_shell$memory_usage$aws$gcloud$openstack$azure$env_var$crystal$custom$sudo$cmd_duration$line_break$jobs$status$shell$character";
direnv.disabled = false;
format = "$all";
username.format = "[$user]($style) ";
hostname.format = "[$hostname]($style) ";
directory = {truncation_length = -1;};
directory = {
truncation_length = -1;
};
git_branch.format = "[$symbol$branch]($style) ";
python.format = "[py \${pyenv_prefix}(\${version} )(\\($virtualenv\\) )]($style)";
nodejs.format = "[js ($version )]($style)";
nix_shell.format = "[nix $state( \\($name\\))]($style) ";
python.symbol = "py ";
nodejs.symbol = "js ";
nix_shell.symbol = "nix ";
rust.symbol = "rs ";
direnv.symbol = "de ";
};
};
direnv = {
enable = true;
nix-direnv.enable = true;
config.global.warn_timeout = "30s";
};
fzf = {
enable = true;
defaultCommand = "${pkgs.ripgrep}/bin/rg --files";
# Include hidden files/folders (-H) but exclude .git
defaultCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
fileWidgetCommand = "${pkgs.fd}/bin/fd -H --type f -E .git";
};
ssh = {
enable = true;
enableDefaultConfig = false;
package = pkgs.openssh; # Use modern ssh
includes = [ "~/.ssh/config.local" ];
settings."Host *" = {
user = "samw";
serverAliveInterval = 30;
serverAliveCountMax = 10;
matchBlocks."*".user = "samw";
compression = true;
controlMaster = "autoask";
controlPath = "~/.ssh/master-%r@%n:%p";
# Close socket once last connection closes
controlPersist = "no";
};
};
};
}
+7 -1
View File
@@ -1 +1,7 @@
{pkgs, ...}: {home.packages = with pkgs; [docker colima];}
{ pkgs, ... }:
{
home.packages = with pkgs; [
docker
colima
];
}
+27 -13
View File
@@ -1,16 +1,24 @@
{...}: {
programs.git = {
enable = true;
userName = "Sam Willcocks";
userEmail = "sam@wlcx.cc";
delta = {
{ pkgs, ... }:
{
home.packages = with pkgs; [
git-open
tea
];
programs.delta = {
# Better diffs
enable = true;
options = {line-numbers = true;};
enableGitIntegration = true;
options = {
line-numbers = true;
};
aliases = {
};
programs.git = {
enable = true;
lfs.enable = true;
settings = {
user.name = "Sam Willcocks";
user.email = "sam@wlcx.cc";
alias = {
a = "add";
ap = "add -p";
br = "branch";
@@ -33,14 +41,20 @@
st = "status";
sw = "switch";
swc = "switch --create";
unp = "log --branches --not --remotes --no-walk --decorate --oneline";
gone = ''
! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
gone = ''! git fetch -p && git for-each-ref --format '%(refname:short) %(upstream:track)' awk '$2 == "[gone]" {print $1}' | xargs -r git branch -D'';
};
extraConfig = {
branch.sort = "-committerdate";
push.default = "current";
init.defaultBranch = "main";
merge = {
conflictStyle = "diff3";
mergiraf = {
name = "mergiraf";
driver = "${pkgs.mergiraf}/bin/mergiraf merge --git %O %A %B -s %S -x %X -y %Y -p %P -l %L";
};
};
};
includes = [
# Always include local gitconfig if it's there
+10 -2
View File
@@ -1,4 +1,5 @@
{pkgs, ...}: {
{ pkgs, lib, ... }:
{
programs.gpg = {
enable = true;
mutableKeys = false;
@@ -19,6 +20,13 @@
];
# make yubikey work on macos? lolgpg
# https://github.com/NixOS/nixpkgs/issues/155629
scdaemonSettings = {disable-ccid = true;};
scdaemonSettings = (lib.optionalAttrs pkgs.stdenv.isDarwin { disable-ccid = true; });
};
# Shouldn't have an effect on macos, on linux we need to specify a pinentry
services.gpg-agent = {
enable = !pkgs.stdenv.isDarwin;
enableSshSupport = true;
pinentry.package = pkgs.pinentry-all;
};
}
+45
View File
@@ -0,0 +1,45 @@
{ ... }:
{
programs.helix = {
enable = true;
settings = {
theme = "monokai_pro";
editor = {
"soft-wrap".enable = true;
"file-picker".hidden = false; # Show hidden files (yes it's counter-intuitive)
gutters = [
"diagnostics"
"line-numbers"
"spacer"
"diff"
];
whitespace.render = {
space = "none";
tab = "all";
nbsp = "all";
nnbsp = "all";
newline = "none";
};
};
};
languages = {
language-server.rust-analyzer.config = {
# Don't get lost in .direnv etc and chew 100% cpu forever
files.excludeDirs = [
".git"
".cargo"
".direnv"
];
};
language = [
{
name = "python";
language-servers = [
"ty"
"basedpyright"
];
}
];
};
};
}
+8 -4
View File
@@ -2,15 +2,16 @@
vim.o.number = true
vim.o.relativenumber = true -- number + relativenumber == hybrid
vim.o.mouse = "nvi" -- mouse mode in normal, visual and insert
vim.o.textwidth = 88 -- A vaguely sensible default textwidth
vim.o.colorcolumn = "+0" -- Mark the textwidth
vim.o.textwidth = 88 -- a vaguely sensible default textwidth
vim.o.formatoptions = "cqj" -- the default, but minus `t` which autowraps text.
vim.o.colorcolumn = "+0" -- mark the textwidth
vim.o.shiftwidth = 4
vim.o.tabstop = 4
vim.o.softtabstop = 4
vim.o.expandtab = true
vim.o.expandtab = true -- owo expands ur tab
vim.o.list = true
vim.o.listchars = "trail:·" -- show trailing spaces
vim.o.listchars = "trail:·,tab:␉·" -- show trailing spaces
-- Colors
vim.cmd "colorscheme gruvbox"
@@ -19,3 +20,6 @@ vim.o.termguicolors = true
-- Keybinds
vim.api.nvim_set_keymap('n','<C-P>', '<cmd> FZF<CR>', { noremap=true })
-- Language-specific
vim.g.pyindent_open_paren = "shiftwidth()" -- Don't double indent after ( you villain.
+22 -7
View File
@@ -1,15 +1,30 @@
{
pkgs,
lib,
...
}: {
}:
{
# Mac specific packages.
# TODO: have this in a central packages place rather than here
home.packages = with pkgs; [pngpaste mypkgs.qrclip];
home.packages = with pkgs; [
pngpaste
mypkgs.qrclip
];
home.sessionPath = [
"/Applications/Sublime Merge.app/Contents/SharedSupport/bin"
];
# Use secretive for SSH agent
programs.ssh.matchBlocks.all = lib.mkIf pkgs.stdenv.isDarwin {
host = "*";
extraOptions."IdentityAgent" = "~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
programs.ssh.settings."Host *".IdentityAgent = "~/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
programs.zsh.sessionVariables = {
SSH_AUTH_SOCK = "$HOME/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh";
# Make connection muxing permission work.
# Openssh by default will only use SSH_ASKPASS if it sees DISPLAY/WAYLAND_DISPLAY, so we have to force it
SSH_ASKPASS_REQUIRE = "force";
# A nice applescript permission dialog
SSH_ASKPASS = (pkgs.fetchurl {
url = "https://raw.githubusercontent.com/theseal/ssh-askpass/refs/heads/master/ssh-askpass";
hash= "sha256-bQUuGS3Mb+i4Kt+1mDP203s2W1jlRcpl/7uXA7TUZ+o=";
executable = true;
});
};
programs.zsh.initExtra = "eval $(/opt/homebrew/bin/brew shellenv)";
programs.zsh.initContent = "[ -e /opt/homebrew/bin/brew ] && eval $(/opt/homebrew/bin/brew shellenv)";
}
+20 -3
View File
@@ -1,9 +1,11 @@
{ pkgs }:
with pkgs; rec {
with pkgs;
rec {
# The stuff you want installed everywhere. The necessities.
base = [
bat # cat replacement, aliased to cat in home-manager
file
fd
git
htop
lsof
@@ -12,13 +14,28 @@ with pkgs; rec {
unzip
vim
wget
helix
];
# Networking shit
net = [iperf3 nmap socat tcpdump];
net = [
dig
iperf3
mtr
nmap
socat
tcpdump
];
# development tools
dev = [jq nixfmt gh glab hexyl];
dev = [
jq
nixfmt-rfc-style
gh
glab
hexyl
attic-client
];
all = base ++ net ++ dev;
}
+5 -2
View File
@@ -1,8 +1,11 @@
{pkgs, ...}: {
{ pkgs, ... }:
{
home.packages = with pkgs; [ yubikey-manager ];
programs.password-store = {
enable = true;
settings = {PASSWORD_STORE_DIR = "$HOME/.password-store";};
settings = {
PASSWORD_STORE_DIR = "$HOME/.password-store";
};
package = pkgs.pass.withExtensions (exts: [ exts.pass-otp ]);
};
programs.zsh.shellAliases = {
+45 -5
View File
@@ -2,16 +2,48 @@
# The basics that you'll want everywhere
default = ./default.nix;
# A machine for development
dev = {...}: {
imports = [./git.nix ./rust.nix ./vim.nix ./vim-dev];
dev =
{ ... }:
{
imports = [
./git.nix
./vim.nix
./vim-dev
./helix.nix
];
};
# A machine for dev with a GUI
# TODO: detect this automatically somehow?
dev-gui = {...}: {
dev-gui =
{ ... }:
{
imports = [ ./vscode.nix ];
programs.wezterm = {
enable = true;
extraConfig = ''
return {
color_scheme = "GruvboxDarkHard",
keys = {
{
key = 'd',
mods = 'SUPER',
action = wezterm.action.SplitVertical{domain='CurrentPaneDomain'},
},
{
key = 'D',
mods = 'SUPER | SHIFT',
action = wezterm.action.SplitHorizontal{domain='CurrentPaneDomain'},
},
},
}
'';
};
};
tpmssh = ./tpmssh.nix;
# Sensitive stuff
sensitive = {...}: {
sensitive =
{ ... }:
{
imports = [
./passwords.nix
./gpg.nix
@@ -24,5 +56,13 @@
# A machine you want to do aws stuff on
aws = ./aws.nix;
# A server
server = {...}: {imports = [./default.nix ./git.nix ./vim.nix];};
server =
{ ... }:
{
imports = [
./default.nix
./git.nix
./vim.nix
];
};
}
-1
View File
@@ -1 +0,0 @@
{pkgs, ...}: {home.packages = [pkgs.rustup pkgs.rust-analyzer];}
+43
View File
@@ -0,0 +1,43 @@
# Enable tpm-ssh-agent in a systemd user service
{ pkgs, config, ... }:
{
home.packages = [ pkgs.ssh-tpm-agent ];
home.sessionVariables = {
SSH_AUTH_SOCK = "$(${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent --print-socket)";
};
systemd.user.sockets.ssh-tpm-agent = {
Install.WantedBy = [ "sockets.target" ];
Socket = {
ListenStream = "%t/ssh-tpm-agent.sock";
SocketMode = "0600";
Service = "ssh-tpm-agent.service";
};
};
systemd.user.services.ssh-tpm-agent = {
Unit = {
Requires = [ "ssh-tpm-agent.socket" ];
ConditionEnvironment = "!SSH_AGENT_PID";
};
Service = {
Environment = ''
SSH_AUTH_SOCK="%t/ssh-tpm-agent.sock"
'';
ExecStart = "${
pkgs.writeShellScriptBin "start-ssh-tpm-agent" (
if config.services.gpg-agent.enableSshSupport then
''
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent -A $(${config.programs.gpg.package}/bin/gpgconf --list-dirs agent-ssh-socket)
''
else
''
${pkgs.ssh-tpm-agent}/bin/ssh-tpm-agent
''
)
}/bin/start-ssh-tpm-agent";
PassEnvironment = "SSH_AGENT_PID";
SuccessExitStatus = 2;
Type = "simple";
};
};
}
+19 -14
View File
@@ -3,24 +3,26 @@
lib,
system,
...
}: let
vim-vue-plugin = pkgs.vimUtils.buildVimPlugin {
name = "vim-vue-plugin";
src = pkgs.fetchFromGitHub {
owner = "leafOfTree";
repo = "vim-vue-plugin";
rev = "b2bb4dd8f6d97909c48bc33937177d4068921a10";
sha256 = "eBfMxt5AaSCHzU7PFp7eWZhGY8l3EqeMLrU0ntB6eLA=";
};
};
in {
programs.neovim.plugins = with pkgs.vimPlugins;
}:
{
home.packages = with pkgs; [
nil
nixd
];
programs.neovim.plugins =
with pkgs.vimPlugins;
[
# More fancy shit
nvim-treesitter
# Language stuff
nvim-lspconfig
trouble-nvim
# Language server/completions
nvim-lspconfig
nvim-cmp
cmp-nvim-lsp
cmp-vsnip
vim-vsnip
# Language specific
go-nvim
rust-vim
vim-terraform
vim-protobuf
@@ -29,6 +31,9 @@ in {
dhall-vim
kotlin-vim
Jenkinsfile-vim-syntax
html5-vim
# Useful stuff
vim-gh-line
]
# delve is unsupported on aarch64-linux and golangci-lint is broken on darwin
# (see https://github.com/NixOS/nixpkgs/issues/168984).
+76 -17
View File
@@ -9,37 +9,93 @@ local on_attach = function(client, bufnr)
vim.api.nvim_buf_set_keymap(bufnr, 'n', '<space>f', '<cmd>lua vim.lsp.buf.formatting()<CR>', opts)
end
-- Enable Language LSPs
-- Completion
local cmp = require'cmp'
cmp.setup({
-- Use snippy for completion
snippet = {
expand = function(args)
vim.fn["vsnip#anonymous"](args.body)
end,
},
-- Disable completions if we're in a comment
enabled = function()
if require"cmp.config.context".in_treesitter_capture("comment")==true or require"cmp.config.context".in_syntax_group("Comment") then
return false
else
return true
end
end,
window = {
completion = cmp.config.window.bordered(),
documentation = cmp.config.window.bordered(),
},
mapping = cmp.mapping.preset.insert({
['<C-Space>'] = cmp.mapping.complete(),
['<C-e>'] = cmp.mapping.abort(),
['<CR>'] = cmp.mapping.confirm({ select = true }),
}),
sources = cmp.config.sources({
{ name = 'nvim_lsp' },
}),
}, {
{ name = 'buffer' },
})
-- Language servers
local capabilities = require('cmp_nvim_lsp').default_capabilities()
require'lspconfig'.gopls.setup{
on_attach = on_attach,
capabilities = capabilities,
}
require'lspconfig'.pylsp.setup{
require'lspconfig'.basedpyright.setup{}
require'lspconfig'.nil_ls.setup{
on_attach = on_attach,
handlers = {
["textDocument/publishDiagnostics"] = vim.lsp.with(
vim.lsp.diagnostic.on_publish_diagnostics, {
-- Disable virtual_text
virtual_text = false
capabilities = capabilities,
}
),
}
}
require'lspconfig'.rnix.setup{
on_attach = on_attach
require'lspconfig'.nixd.setup{
on_attach = on_attach,
capabilities = capabilities,
}
require'lspconfig'.rust_analyzer.setup{
on_attach = on_attach
on_attach = on_attach,
capabilities = capabilities,
commands = {
RustOpenDocs = {
function()
vim.lsp.buf_request(vim.api.nvim_get_current_buf(), 'experimental/externalDocs', vim.lsp.util.make_position_params(), function(err, url)
if err then
error(tostring(err))
else
vim.fn['netrw#BrowseX'](url, 0)
end
end)
end,
description = 'Open documentation for the symbol under the cursor in default browser',
},
},
settings = {
["rust-analyzer"] = {
procMacro = {
enable = false,
},
},
},
}
require'lspconfig'.dhall_lsp_server.setup{
on_attach = on_attach
on_attach = on_attach,
capabilities = capabilities,
}
require'lspconfig'.eslint.setup{
on_attach = on_attach
on_attach = on_attach,
capabilities = capabilities,
}
-- Configure volar (vuejs language server stuff) in "takeover" mode
require'lspconfig'.volar.setup{
on_attach = on_attach,
capabilities = capabilities,
filetypes = {'typescript', 'javascript', 'javascriptreact', 'typescriptreact', 'vue', 'json'},
on_attach = on_attach
}
--[[ If we didn't have takeover mode enabled above, we'd want this
require'lspconfig'.tsserver.setup{
@@ -47,9 +103,12 @@ require'lspconfig'.tsserver.setup{
}
]]--
-- Other language plugins
require('go').setup()
-- Diags with Trouble
require('trouble').setup {
icons = false,
icons = {},
signs = {
error = "E",
warning = "W",
+14 -9
View File
@@ -1,33 +1,38 @@
# This module sets up a "full" neovim install with plugins and unicorns. It
# also makes neovim the default editor and aliases vim to nvim.
# Vim with some niceties. If you're spending any time in vim you'll want this.
# For a full-fat vim with all the bells and whistles, see vim-dev
{
pkgs,
lib,
strings,
...
}: {
home.sessionVariables = {"EDITOR" = "nvim";};
home.packages = with pkgs; [rnix-lsp ripgrep];
}:
{
home.sessionVariables.EDITOR = lib.mkForce "nvim";
home.packages = with pkgs; [ ripgrep ];
programs.neovim = {
enable = true;
viAlias = true;
vimAlias = true;
# defaults changed from true in 26.05
withRuby = false;
withPython3 = false;
plugins = with pkgs.vimPlugins; [
# Basic stuff
vim-sensible
vim-noctu # 16color colorscheme
gruvbox-nvim
fzfWrapper # The basic "built in" fzf stuff
fzf-wrapper # The basic "built in" fzf stuff
fzf-vim # The fancier opt in fzf stuff
# The only language plugin you always need... because if it's running nixos you
# *will* be editing nix files!
vim-nix
# Git stuff
fugitive
vim-fugitive
vim-gitgutter
# More stuff idk
emmet-vim
vim-sleuth # guess whitespace settings from file
vim-sleuth # guess whitespace settings from file
];
extraConfig = ''
lua <<EOF
+15 -7
View File
@@ -1,16 +1,24 @@
{pkgs, ...}: {
programs.vscode = {
{ pkgs, ... }:
{
programs.vscodium = {
enable = true;
package = pkgs.vscodium;
mutableExtensionsDir = false;
extensions = with pkgs.vscode-extensions; [
matklad.rust-analyzer
profiles.default.extensions = with pkgs.vscode-extensions; [
rust-lang.rust-analyzer
jdinhlife.gruvbox
jnoortheen.nix-ide
editorconfig.editorconfig
];
userSettings = {
profiles.default.userSettings = {
"update.mode" = "none";
"workbench.colorTheme" = "Gruvbox Dark Hard";
"window.autoDetectColorScheme" = true;
"workbench.preferredDarkColorTheme" = "Gruvbox Dark Hard";
"workbench.preferredLightColorTheme" = "Gruvbox Light Hard";
"files.trimTrailingWhitespace" = true;
"emmet.includeLanguages"."django-html" = "html";
# Don't try to write to the nix-managed .ssh/config
"remote.SSH.configFile" = "~/.ssh/config.local";
"editor.rulers" = [ 90 ];
};
};
}
+1 -1
View File
@@ -5,6 +5,6 @@
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMvrgrLnE+AQBOBRiBoTFkbWaYTvqaBzIp4OfDiXUij"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDQdGzwYiallvWXIHgSAf2GOwMJKA8bxPmwyuO+vsd1HwB65hMRPCpKS+FNLIpkrADNnuhGS3xGCGSSuQ+zAu/g= zinc-se-main@secretive.zinc.local"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNLrJyUXmiFWb9vhlTWZLYr64IsKut+c9TGqq3/uwPDeF4X0Qb2jzxqXfQcDSztjR09JHbC8BOqfpYYT9LHahIo= YubiKey #13340583 PIV Slot 9a"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBG97EFzrTE5jI0P5CP5/y/thCzGNHt74u2mpXpdrB25URrn3ABDJcbmO/tGtNR8uhM3n/kUpr6Ax27orjmIOQtA= boron-se-main@secretive.boron.local"
"ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBC/kJYueV9cBlyPsYhC0Q2HQR+E6MswwUF6hwXrkbb4JPNn9bD2PM2GjXQe0rz6KWPr4LYkbGTo9zbRQg3d2MTE= gallium-se-main@secretive.gallium.local"
];
}
+2 -3
View File
@@ -1,6 +1,5 @@
# TODO: auto import everything
{pkgs, ...}: {
{ pkgs, ... }:
{
qrclip = pkgs.callPackage ./qrclip { };
zbar = pkgs.callPackage ./zbar {};
yubikey-manager = pkgs.callPackage ./yubikey-manager {};
}
+6 -3
View File
@@ -2,11 +2,14 @@
pkgs,
lib,
stdenv,
}: let
zbar = pkgs.mypkgs.zbar.override {enableVideo = false;};
}:
let
zbar = pkgs.zbar.override { enableVideo = false; };
in
(pkgs.writeShellScriptBin "qrclip" ''
set -eo pipefail
${pkgs.pngpaste}/bin/pngpaste - | ${zbar}/bin/zbarimg --raw -q1 -
'')
// {meta.platforms = lib.platforms.darwin;}
// {
meta.platforms = lib.platforms.darwin;
}
-78
View File
@@ -1,78 +0,0 @@
{
python3Packages,
fetchFromGitHub,
lib,
yubikey-personalization,
libu2f-host,
libusb1,
procps,
}:
python3Packages.buildPythonPackage rec {
pname = "yubikey-manager";
version = "4.0.8";
format = "pyproject";
src = fetchFromGitHub {
repo = "yubikey-manager";
rev = version;
owner = "Yubico";
sha256 = "sha256-OszXOu/NhoX4WutsT4Z1LsY54KTOWRKt13yDo2fzDbA=";
};
patches = [./lol.patch];
doCheck = false;
postPatch = ''
substituteInPlace pyproject.toml \
--replace 'cryptography = "^2.1 || ^3.0"' 'cryptography = "*"'
substituteInPlace "ykman/pcsc/__init__.py" \
--replace 'pkill' '${procps}/bin/pkill'
'';
nativeBuildInputs = with python3Packages; [poetry-core];
propagatedBuildInputs = with python3Packages;
[
click
cryptography
pyscard
pyusb
six
fido2
]
++ [
libu2f-host
libusb1
yubikey-personalization
];
makeWrapperArgs = [
"--prefix"
"LD_LIBRARY_PATH"
":"
(lib.makeLibraryPath [libu2f-host libusb1 yubikey-personalization])
];
postInstall = ''
mkdir -p "$out/man/man1"
cp man/ykman.1 "$out/man/man1"
mkdir -p $out/share/bash-completion/completions
_YKMAN_COMPLETE=source $out/bin/ykman > $out/share/bash-completion/completions/ykman || :
mkdir -p $out/share/zsh/site-functions/
_YKMAN_COMPLETE=source_zsh "$out/bin/ykman" > "$out/share/zsh/site-functions/_ykman" || :
substituteInPlace "$out/share/zsh/site-functions/_ykman" \
--replace 'compdef _ykman_completion ykman;' '_ykman_completion "$@"'
'';
checkInputs = with python3Packages; [pytestCheckHook makefun];
meta = with lib; {
homepage = "https://developers.yubico.com/yubikey-manager";
description = "Command line tool for configuring any YubiKey over all USB transports";
license = licenses.bsd2;
platforms = platforms.unix;
maintainers = with maintainers; [benley lassulus pinpox];
};
}
-12
View File
@@ -1,12 +0,0 @@
diff --git a/pyproject.toml b/pyproject.toml
index 7544201..9caa5c6 100644
--- a/pyproject.toml
+++ b/pyproject.toml
@@ -30,7 +30,6 @@ packages = [
python = "^3.6"
dataclasses = {version = "^0.8", python = "<3.7"}
cryptography = ">=2.1, <39"
-pyOpenSSL = {version = ">=0.15.1", optional = true}
pyscard = "^1.9 || ^2.0"
fido2 = ">=0.9, <1.0"
click = "^6.0 || ^7.0 || ^8.0"
-94
View File
@@ -1,94 +0,0 @@
{
stdenv,
lib,
fetchFromGitHub,
imagemagickBig,
pkg-config,
libX11,
libv4l,
libiconv,
qtbase ? null,
darwin,
qtx11extras ? null,
wrapQtAppsHook ? null,
wrapGAppsHook,
gtk3,
xmlto,
docbook_xsl,
autoreconfHook,
dbus,
enableVideo ? stdenv.isLinux,
# The implementation is buggy and produces an error like
# Name Error (Connection ":1.4380" is not allowed to own the service "org.linuxtv.Zbar" due to security policies in the configuration file)
# for every scanned code.
# see https://github.com/mchehab/zbar/issues/104
enableDbus ? false,
libintl,
}:
stdenv.mkDerivation rec {
pname = "zbar";
version = "0.23.90";
outputs = ["out" "lib" "dev" "doc" "man"];
src = fetchFromGitHub {
owner = "mchehab";
repo = "zbar";
rev = version;
sha256 = "sha256-FvV7TMc4JbOiRjWLka0IhtpGGqGm5fis7h870OmJw2U=";
};
nativeBuildInputs =
[pkg-config xmlto autoreconfHook docbook_xsl] ++ lib.optionals enableVideo [wrapQtAppsHook wrapGAppsHook];
buildInputs =
[imagemagickBig libX11 libintl]
++ lib.optionals enableDbus [dbus]
++ lib.optionals enableVideo [libv4l gtk3 qtbase qtx11extras]
++ lib.optionals stdenv.isDarwin [libiconv darwin.apple_sdk.frameworks.Foundation];
# Disable assertions which include -dev QtBase file paths.
NIX_CFLAGS_COMPILE = "-DQT_NO_DEBUG";
configureFlags =
["--without-python"]
++ (
if enableDbus
then ["--with-dbusconfdir=${placeholder "out"}/share"]
else ["--without-dbus"]
)
++ (
if enableVideo
then ["--with-gtk=gtk3"]
else [
"--disable-video"
"--without-gtk"
"--without-qt"
]
);
dontWrapQtApps = true;
dontWrapGApps = true;
postFixup = lib.optionalString enableVideo ''
wrapGApp "$out/bin/zbarcam-gtk"
wrapQtApp "$out/bin/zbarcam-qt"
'';
enableParallelBuilding = true;
meta = with lib; {
description = "Bar code reader";
longDescription = ''
ZBar is an open source software suite for reading bar codes from various
sources, such as video streams, image files and raw intensity sensors. It
supports many popular symbologies (types of bar codes) including
EAN-13/UPC-A, UPC-E, EAN-8, Code 128, Code 39, Interleaved 2 of 5 and QR
Code.
'';
maintainers = with maintainers; [delroth raskin];
platforms = platforms.unix;
license = licenses.lgpl21;
homepage = "https://github.com/mchehab/zbar";
};
}