summaryrefslogtreecommitdiffstatshomepage
Commit message (Collapse)AuthorAgeFilesLines
* Track Neovim package lockfilesommerfeld2026-07-021-0/+201
|
* Drop unused Arch maintenance packagessommerfeld2026-07-022-4/+2
|
* Remove SNX Waybar integrationsommerfeld2026-07-025-80/+2
|
* Migrate VM dotfiles to chezmoisommerfeld2026-06-1918-237/+279
| | | | | | | | Move VM dotfile deployment out of Home Manager and into chezmoi with a machineRole guard. Add VM recipes for applying chezmoi state and restarting the Nix GnuPG agent. Make host-only hooks no-op on the VM and render container storage per role.
* Mirror GnuPG config on VMsommerfeld2026-06-194-17/+20
|
* Update nix lockfilesommerfeld2026-06-191-6/+6
|
* Use local gpg-agent on VMsommerfeld2026-06-195-100/+46
|
* Update blink.pairs native library setupsommerfeld2026-06-192-3/+17
|
* Update nix lockfilesommerfeld2026-06-181-6/+6
|
* Reduce Arch package surfacesommerfeld2026-06-1825-129/+409
|
* Pin blink.pairs before native loader changesommerfeld2026-06-171-4/+2
|
* Relax AI committer push checksommerfeld2026-06-172-23/+11
|
* Update Nix flake lockfilesommerfeld2026-06-171-9/+9
|
* Allow unmatched globs in zshsommerfeld2026-06-171-1/+2
|
* Update blink.pairs native setupsommerfeld2026-06-171-1/+3
|
* Update Nix flake lockfilesommerfeld2026-06-171-3/+3
|
* Add Mattermost flatpaksommerfeld2026-06-171-0/+1
|
* Disable broken Proton mail startupsommerfeld2026-06-173-4/+7
|
* Restore AUR pass secret servicesommerfeld2026-06-173-21/+7
|
* Expand sshcontrolsommerfeld2026-06-151-0/+2
|
* Update Nix flake lockfilesommerfeld2026-06-151-9/+9
|
* Use absolute editor commands under sudosommerfeld2026-06-153-8/+23
| | | | | | Resolve nvim before exporting editor and pager variables so sudo-rs env_keep does not depend on root's secure_path. Update the Waybar pacdiff action to pass an absolute DIFFPROG through sudo.
* Reduce AUR package surfacesommerfeld2026-06-159-38/+76
| | | | | | | | Move pass-secret-service, snx-rs, and Sparrow under Nix/Home Manager. Track the snx-rs system unit, pass-secret-service user unit, and pacman cache cleanup hook in the repo. Drop the mkinitcpio firmware metapackage, overdue, pacman-cleanup-hook, and the standalone btc package group.
* Add mosh work VM aliassommerfeld2026-06-151-0/+1
|
* Use unified tuicr diff viewsommerfeld2026-06-051-1/+1
|
* Limit git switch completion to local branchessommerfeld2026-06-051-0/+1
|
* Add no-hooks rebase aliassommerfeld2026-06-051-0/+1
|
* Refactor git resign aliassommerfeld2026-06-051-1/+1
|
* Update nix tools and system unitssommerfeld2026-06-054-8/+7
|
* Move more host tooling to Nixsommerfeld2026-06-0563-108/+181
|
* refactor(mail): migrate protonmail-bridge from pacman to nixsommerfeld2026-06-055-4/+26
| | | | | | | | | | | | | | | Move the ProtonMail Bridge off the AUR protonmail-bridge-core package and onto nix/host.nix, consistent with the other migrated user-leaf tools. Since the AUR package previously supplied the systemd user unit (customized via a drop-in), ship a repo-owned dot_config/systemd/user/protonmail-bridge.service instead: it runs the nix binary by absolute %h/.nix-profile/bin path with --noninteractive and folds the former drop-in's PASSWORD_STORE_DIR into the unit, so the now-redundant protonmail-bridge.service.d/override.conf is removed. Drop protonmail-bridge-core from meta/base.txt (the git send-email Perl prereqs stay). No vm.nix change: the bridge is host-only and user units are not symlinked on the headless VM.
* fix(systemd): ship poweralertd.service user unitsommerfeld2026-06-052-0/+15
| | | | | | | | | | | | poweralertd was migrated to nix (host.nix) but, like mako, the nix package does not ship a systemd user unit on the manager's search path. sway-session.target's Wants=poweralertd.service referenced a non-existent unit (previously the pacman package supplied /usr/lib/systemd/user/poweralertd.service), so battery/AC notifications never started at login. Add a repo-owned poweralertd.service (absolute nix-profile path) and register it in systemd-units/user.txt.
* fix(systemd): ship mako.service user unitsommerfeld2026-06-052-0/+18
| | | | | | | | | | | | | The nix mako package does not ship a systemd user unit on the user manager's search path, so sway-session.target's Wants=mako.service referenced a non-existent unit after the pacman->nix migration (previously the Arch mako package provided /usr/lib/systemd/user/ mako.service). mako only started on first D-Bus notification, never eagerly at session login. Add a repo-owned mako.service (Type=dbus, org.freedesktop.Notifications) using the absolute nix-profile path, matching the other sway-session units, and register it in systemd-units/user.txt.
* fix(systemd): drop StopWhenUnneeded from sway-session.targetsommerfeld2026-06-051-1/+0
| | | | | | | | | | | | | | | | | | The target reached active then was immediately garbage-collected: Reached target sway compositor session Stopped target sway compositor session Stopping swayr.../Waybar... Nothing holds a reverse dependency on sway-session.target, so the first "stop unneeded units" pass (triggered when any Wanted service transitions, e.g. a ConditionEnvironment skip during the env-import race) found it unneeded and StopWhenUnneeded=yes tore it down, cascading via PartOf/ BindsTo to every session service. Manual `systemctl --user start` worked because that starts the service directly, not the GC-prone target. StopWhenUnneeded has been latent since 030848c; the nix migration's changed startup timing exposed it. The canonical sway-session.target omits it; teardown still works via BindsTo=graphical-session.target and user-manager shutdown at logout (swaymsg exit).
* revert(systemd): drop redundant environment.d PATH filesommerfeld2026-06-051-20/+0
| | | | | | | | | | | | The absolute %h/.nix-profile/bin/<name> ExecStart paths (previous commit) fix unit startup without any PATH dependency. The remaining secondary lookups those binaries make (wl-paste -> cliphist, swayidle -> swaymsg/ playerctl) are already covered by the sway config's existing `systemctl --user import-environment PATH` (dot_config/sway/config), the established mechanism that also feeds waybar's nix-provisioned pass/python3. So environment.d/10-nix-profile-path.conf was a redundant parallel mechanism. Remove it.
* fix(systemd): use absolute %h/.nix-profile/bin paths in user unitssommerfeld2026-06-059-26/+28
| | | | | | | | | | | | | | The previous environment.d fix was insufficient: even with the nix profile on the --user manager's PATH (confirmed via `systemctl --user show-environment`), bare-name ExecStart= still fails 203/EXEC. systemd's --user manager does not resolve a bare ExecStart binary against the imported/environment.d PATH. Invoke each unit's main binary by absolute path %h/.nix-profile/bin/<name> (waybar, swayidle, swayrd, inhibridge, wl-paste, wob). %h expands to $HOME at unit load. Secondary lookups those binaries/scripts perform (cliphist, swaymsg, playerctl) still rely on PATH, which environment.d provides — so that file stays, with its comment corrected to reflect this split.
* fix(nix,meta): keep imv/wl-mirror/sparrow on pacman (OpenGL context)sommerfeld2026-06-052-19/+14
| | | | | | | | Same root cause as ghostty: imv (OpenGL), wl-mirror (EGL) and sparrow (JavaFX/OpenGL) are GL/EGL apps that can't find the system Mesa/DRI driver when built by nix on a non-NixOS host. Remove them from nix/host.nix; add imv + wl-mirror to meta/base.txt (sparrow already lives in meta/btc.txt as sparrow-wallet). Refresh the stale base.txt media comment accordingly.
* fix(nix,meta): keep ghostty on pacman to fix missing OpenGL contextsommerfeld2026-06-052-3/+11
| | | | | | | | ghostty is a GPU/OpenGL terminal. Nix-built GL apps on a non-NixOS host can't locate the system Mesa/DRI driver (FHS /usr/lib drivers don't match nix's search paths), so the nix-migrated ghostty failed to start with "missing OpenGL context". Move it back to meta/base.txt (pacman) so it links against system Mesa. Same caveat flagged for imv/wl-mirror/sparrow.
* fix(systemd): add environment.d PATH so user units find nix binariessommerfeld2026-06-051-0/+22
| | | | | | | | | | | | | | | The user-leaf tools (waybar, swayidle, swayr, mako, cliphist, inhibridge, wob, …) were migrated to the Nix home profile and their .service units reference them by bare name. The systemd user manager does not source ~/.zprofile, so its PATH lacked ~/.nix-profile/bin and every bare-name ExecStart failed with status=203/EXEC. The sway config's `systemctl --user import-environment PATH` raced with `systemctl --user start sway-session.target`; when the start won, units launched with the default PATH. environment.d is read at manager startup before any unit, closing the race deterministically. Pick up via fresh login/boot or `systemctl --user daemon-reexec`.
* fix(nix): replace nonexistent podman-docker attr with writeShellScriptBin shimsommerfeld2026-06-051-1/+5
| | | | | | | nixpkgs has no top-level `podman-docker` attribute — that's an Arch convenience pkg. NixOS exposes it via the `virtualisation.podman. dockerCompat` option but that's not reachable from home-manager. Ship a one-line writeShellScriptBin instead; same result, no module rewire.
* chore(bootstrap): drop manual paru-bin AUR build; provision subuid/subgidsommerfeld2026-06-051-51/+55
| | | | | | | | | | | | | | | | | | | | | | | | | | Two changes: 1. Eliminate the paru-bin chicken-and-egg. Old flow had to manually git-clone aur/paru-bin and run makepkg -si before just-init could call paru. Now paru ships from nixpkgs via nix/host.nix, so the bootstrap reorders to: pacman -S … nix enable nix-daemon git clone <dotfiles> just nix-switch # installs paru + chezmoi + … into ~/.nix-profile PATH=$HOME/.nix-profile/bin:$PATH just init # _chezmoi-init/apply/pkg-apply/unit-apply pkg-apply now finds paru on PATH from the nix profile, so the remaining AUR entries in meta/base.txt (arkenfox-user.js, protonmail-bridge-core, pass-secret-service-bin, zsa-udev, kernel- modules-hook, …) install correctly. chezmoi drops out of PREREQS — it comes from the nix profile too. just stays on pacman so the pre-nix-switch `just nix-switch` invocation works. 2. Add idempotent subuid/subgid provisioning. Required for rootless nix-installed podman; pacman's podman package handled this via its post-install hook, but nix-installed podman doesn't touch /etc/subuid. Range 100000-165535 is the conventional default.
* chore(meta): drop migrated packages from base.txtsommerfeld2026-06-051-73/+23
| | | | | | | | | | | | | | | | | | | | | | | | | | Remove every entry now provisioned via nix/host.nix or nix/common.nix: - Core CLIs: chezmoi, paru, qrencode, torsocks, lshw - Podman stack: podman-compose, podman-docker (rest already nix in common.nix via the previous unify commit) - Wayland session: waybar, fuzzel, wofi, mako, swayidle, swayr, inhibridge, bemoji, wob, poweralertd, ghostty - Wayland capture/clipboard: grim, slurp, wf-recorder, wtype, wl-clipboard, cliphist, imv, wl-mirror - Media control: playerctl, pulsemixer - Streaming: yt-dlp, streamlink - OCR: tesseract, tesseract-data-eng, tesseract-data-por - STT: whisper.cpp-vulkan, whisper.cpp-model-base Update the section comments to point at the nix profile for the new home of each group. Sway itself stays on pacman (login-manager session entry), as does libnotify (system shared lib), zbar (linked by other pacman pkgs), swaylock (setuid + PAM), pass-secret-service-bin (D-Bus activation), zsa-udev (udev rule), and the smartcard/font/Qt-plugin stacks. Drop whisper.cpp-vulkan from IgnorePkg in etc/pacman.conf — the package no longer exists on the system.
* fix(systemd,scripts): unhardcode /usr/bin paths for nix-migrated toolssommerfeld2026-06-0511-17/+18
| | | | | | | | | | | | | | | | | | | | | The chezmoi-owned user units and ~/.local/bin wrapper scripts called the migrated tools by absolute /usr/bin/ path. After the move to nix, those binaries live under ~/.nix-profile/bin (no /usr/bin alias). systemd user units: drop the /usr/bin/ prefix on cliphist-{text,image} (wl-paste), inhibridge, swayidle, swayrd, waybar, and the inner wob in wob.service (outer /usr/bin/sh stays, sh is system). systemd resolves bare names through the unit's inherited PATH, which includes ~/.nix-profile/bin via hm-session-vars. dictate: default_model now points at ~/.nix-profile/share/whisper-cpp-models/ggml-base.bin (overridable via $WHISPER_MODEL). Header rewritten to mention nix instead of AUR. yt-dlp / streamlink wrappers: pass $HOME/.nix-profile/bin/<tool> to _sandbox-net-parser so the bwrap-sandboxed binary is resolved explicitly (the wrappers shadow PATH lookup inside their own ~/.local/bin so re-entry would loop).
* feat(nix): migrate user-leaf tools to host profilesommerfeld2026-06-051-10/+114
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Pull every pacman/AUR entry that is (1) packaged in nixpkgs and (2) free of tight system coupling out of meta/base.txt and into nix/host.nix. System coupling = setuid, /usr/lib/systemd/system unit, udev rule, /usr/share/dbus-1/services file, /usr/share/wayland-sessions entry, shared lib other pacman pkgs link, /etc/makepkg.conf reference, system fontconfig path, PAM, Qt plugin search path, or kernel/ firmware/bootloader touchpoint. User-scope systemd units are NOT coupling — nix drops them in ~/.nix-profile/share/systemd/user/ and systemd picks them up; the chezmoi-owned unit files that referenced /usr/bin/<tool> paths are fixed in a follow-up commit. Wayland session: waybar, mako, fuzzel, wofi, swayidle, swayr, inhibridge, bemoji, wob, poweralertd, grim, slurp, wf-recorder, wtype, wl-clipboard, cliphist, imv, wl-mirror, playerctl, pulsemixer, ghostty. General CLIs: qrencode, torsocks, lshw, yt-dlp, streamlink, chezmoi, paru. GUI: sparrow. OCR: tesseract collapsed with .override { enableLanguages = [eng por] } — replaces tesseract + tesseract-data-eng + tesseract-data-por. STT: whisper-cpp.override { vulkanSupport = true; } plus an inline whisper-cpp-model-base derivation that fetches ggml-base.bin from the upstream huggingface mirror into ~/.nix-profile/share/whisper-cpp-models/.
* feat(nix): unify rootless podman across host and VMsommerfeld2026-06-054-40/+61
| | | | | | | | | | | | | | | Move the podman stack (podman, crun, conmon, netavark, aardvark-dns, slirp4netns, passt, podman-compose, podman-docker) from a vm-only block into common.nix so the Arch host and the Ubuntu remote-dev VM run the same nix-pinned versions. This drops podman-compose + podman-docker from pacman as well — they were the only podman-stack pieces still sourced from there on the host. Relocate registries.conf + policy.json into the chezmoi tree at dot_config/containers/ so both flavors share them; vm.nix now picks them up via the existing link helper. storage.conf stays inline in vm.nix because the VM needs the overlay driver while the Arch host uses the btrfs driver (root fs is btrfs there).
* chore(nix): flake.lock update (home-manager)sommerfeld2026-06-051-7/+7
| | | | | | home-manager: 7d8127d3 (master, 26.11) → b179bde2 (release-26.05) Follow-up to the release-branch pin in the previous commit.
* chore(nix): pin home-manager to release-26.05 (match nixpkgs)sommerfeld2026-06-051-1/+6
| | | | | | | | | HM master had rolled to the 26.11 development cycle while the nixos-unstable nixpkgs snapshot we follow is still on 26.05. Activation emitted the 'mismatched versions' warning at every nix-switch. Pin HM to its release-26.05 branch so the two stay in lockstep; bump the branch name when nixpkgs lib.version rolls over.
* chore(nix): flake.lock update (home-manager, tuicr)sommerfeld2026-05-291-6/+6
|
* feat(nix/common): expose run-clang-tidy missing from nixpkgs clang-toolssommerfeld2026-05-291-1/+21
| | | | | | | | | nixpkgs' clang-tools derivation symlinks scripts from clang-unwrapped only when they're executable; run-clang-tidy loses the +x bit during the multi-output split and gets skipped. Re-expose it ourselves by probing clang-unwrapped's main and python outputs (bin/ first, then the legacy share/clang/ layout) and installing the first hit at $out/bin/run-clang-tidy.
* refactor(meta/nvidia): drop linux-headers (covered by base kernels)sommerfeld2026-05-291-1/+0
| | | | | | | linux-hardened-headers and linux-lts-headers in meta/base.txt already cover every installed kernel, so 'linux-headers' here would only pull the stock 'linux' kernel back in via dependency — which we just removed.