| Commit message (Expand) | Author | Age | Files | Lines |
| * | chore(nix): flake.lock update (home-manager, tuicr)HEADmaster | sommerfeld | 2 days | 1 | -6/+6 |
| * | feat(nix/common): expose run-clang-tidy missing from nixpkgs clang-tools | sommerfeld | 2 days | 1 | -1/+21 |
| * | refactor(meta/nvidia): drop linux-headers (covered by base kernels) | sommerfeld | 2 days | 1 | -1/+0 |
| * | feat(kernel): swap stock linux for linux-lts as fallback kernel | sommerfeld | 2 days | 5 | -33/+46 |
| * | feat(etc/resolved): forward single-label queries upstream | sommerfeld | 2 days | 1 | -0/+8 |
| * | refactor(eer): install external-editor-revived via nix on the host | sommerfeld | 2 days | 4 | -19/+38 |
| * | refactor(flatpak): route mpv and thunderbird via flatpak; drop system pkgs | sommerfeld | 2 days | 10 | -23/+29 |
| * | chore(nix): flake.lock update (tuicr) | sommerfeld | 2 days | 1 | -3/+3 |
| * | chore(thunderbird): switch flatpak app id to org.mozilla.thunderbird | sommerfeld | 2 days | 8 | -21/+21 |
| * | refactor(suspend): drop SSH session inhibit; AC rule handles it | sommerfeld | 2 days | 1 | -20/+0 |
| * | refactor(suspend): gate suspend on AC, drop bespoke zellij inhibit | sommerfeld | 2 days | 8 | -126/+33 |
| * | fix(suspend): make zellij inhibit watcher resilient to local-only sessions | sommerfeld | 2 days | 2 | -15/+59 |
| * | feat(suspend): re-enable suspend on s2idle, drop diagnostic scaffolding | sommerfeld | 2 days | 11 | -51/+36 |
| * | fix(suspend): switch hardened to s2idle, keep console alive, archive pstore | sommerfeld | 2 days | 2 | -1/+2 |
| * | fix(suspend): load intel_lpss_pci from initramfs (Arch wiki touchpad fix) | sommerfeld | 2 days | 3 | -6/+5 |
| * | feat(suspend): hardened-only init_on_free=0 + hang-detection cmdline | sommerfeld | 2 days | 4 | -2/+9 |
| * | feat(suspend): disable system suspend until hardened kernel resume issue is f... | sommerfeld | 2 days | 5 | -21/+47 |
| * | fix(suspend): only inhibit for SSH-spawned zellij sessions | sommerfeld | 2 days | 3 | -13/+37 |
| * | fix(iwd): revert MAC randomization — broke DHCP | sommerfeld | 2 days | 1 | -23/+0 |
| * | feat(suspend): hold inhibit lock while any zellij session exists | sommerfeld | 2 days | 5 | -5/+65 |
| * | feat(zsh): inhibit suspend while an SSH session is active | sommerfeld | 2 days | 1 | -0/+17 |
| * | feat(suspend): bounce snx-rs around system sleep | sommerfeld | 2 days | 2 | -0/+48 |
| * | feat(podman): switch rootless storage driver to btrfs | sommerfeld | 2 days | 4 | -4/+19 |
| * | fix(hardened): restore podman compatibility on linux-hardened | sommerfeld | 2 days | 2 | -0/+8 |
| * | docs(bootstrap): also suggest fallback UKI EFI entries | sommerfeld | 2 days | 1 | -1/+7 |
| * | Revert "refactor(boot): drop linux-hardened-fallback UKI" | sommerfeld | 2 days | 1 | -1/+4 |
| * | refactor(boot): drop linux-hardened-fallback UKI | sommerfeld | 2 days | 1 | -4/+1 |
| * | docs(bootstrap): mention optional linux-hardened EFI entry | sommerfeld | 2 days | 1 | -0/+4 |
| * | feat(sandbox): bwrap wrappers for mpv, yt-dlp, streamlink | sommerfeld | 2 days | 5 | -0/+75 |
| * | feat(boot): add linux-hardened as parallel UKI | sommerfeld | 2 days | 2 | -0/+21 |
| * | feat(iwd): per-SSID MAC randomisation | sommerfeld | 2 days | 1 | -0/+23 |
| * | feat(polkit): restrict systemd + udisks system actions to active local sessions | sommerfeld | 2 days | 2 | -0/+26 |
| * | feat(sysctl): kernel info-disclosure + ICMP/IPv6 RA hardening | sommerfeld | 2 days | 1 | -1/+39 |
| * | chore(nix): flake.lock update (home-manager, nixpkgs, tuicr) | sommerfeld | 2 days | 1 | -9/+9 |
| * | fix(nix): tuicr switched to packages.${system}.default schema | sommerfeld | 2 days | 1 | -3/+1 |
| * | fix(nftables): waydroid DHCP/DNS ingress, drop manual NAT table | sommerfeld | 9 days | 1 | -19/+9 |
| * | fix(sway): disable shortcut inhibitor for waydroid windows | sommerfeld | 9 days | 1 | -0/+1 |
| * | fix(nftables): add MASQUERADE for waydroid0 | sommerfeld | 9 days | 1 | -3/+19 |
| * | Revert "fix(sysctl): enable net.ipv4.ip_forward for NAT bridges" | sommerfeld | 9 days | 1 | -5/+0 |
| * | fix(sysctl): enable net.ipv4.ip_forward for NAT bridges | sommerfeld | 9 days | 1 | -0/+5 |
| * | fix(net): positive-match physical NICs into bond0 | sommerfeld | 9 days | 1 | -14/+9 |
| * | fix(net): keep waydroid0 out of bond0, allow it through nftables | sommerfeld | 9 days | 2 | -2/+10 |
| * | feat(tuicr): side-by-side diff, mouse, space leader | sommerfeld | 10 days | 1 | -0/+3 |
| * | feat(tuicr): configure gruvbox-dark theme | sommerfeld | 10 days | 2 | -0/+4 |
| * | fix(ssh): make agent.sock symlink concurrent-connection-safe | sommerfeld | 10 days | 2 | -13/+32 |
| * | feat(zsh): recover Arch site-functions + HELPDIR after removing system zsh | sommerfeld | 10 days | 1 | -3/+18 |
| * | fix(nix,zsh): tuicr flake schema + restore XDG_DATA_DIRS | sommerfeld | 10 days | 3 | -2/+132 |
| * | fix(sway): propagate PATH / GPG env into systemd --user + dbus | sommerfeld | 10 days | 1 | -2/+11 |
| * | fix(ssh): stabilise forwarded ssh-agent socket across reconnects | sommerfeld | 10 days | 2 | -3/+40 |
| * | docs(rules): document nix/vm.nix symlink invariant | sommerfeld | 10 days | 1 | -0/+11 |