Compare commits
419
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
57a3171f94 | ||
|
|
c1403be257 | ||
|
|
b4cccbd4bc | ||
|
|
1543ae0852 | ||
|
|
a4cf1d1085 | ||
|
|
d5bd9cd77a | ||
|
|
b2217f8051 | ||
|
|
08920bcfd1 | ||
|
|
320cbf535b | ||
|
|
deadc7204c | ||
|
|
a1fa429e94 | ||
|
|
d8a6661f78 | ||
|
|
5138eaf896 | ||
|
|
e636bf1664 | ||
|
|
ee9c7b96c9 | ||
|
|
cd7cf09aa3 | ||
|
|
ee20edc445 | ||
|
|
bb9c29c193 | ||
|
|
08278afff6 | ||
|
|
aabb2037ed | ||
|
|
0bddd7a5ed | ||
|
|
9f8122dd2b | ||
|
|
818b88b75f | ||
|
|
d0d0978f34 | ||
|
|
ace757665e | ||
|
|
d9ffa378a6 | ||
|
|
b317d77bbf | ||
|
|
f73cbf1f65 | ||
|
|
958c16ba9a | ||
|
|
4bcdd687ca | ||
|
|
3f0f0ece39 | ||
|
|
57ff7cbd20 | ||
|
|
6a771120d6 | ||
|
|
f8531f95fe | ||
|
|
7c3d11b160 | ||
|
|
8073b91aa3 | ||
|
|
ae3e2b18d3 | ||
|
|
82325d90a1 | ||
|
|
56c666e108 | ||
|
|
3fe4b4fb3c | ||
|
|
426b6e8f02 | ||
|
|
905fe60936 | ||
|
|
4ec530e8b5 | ||
|
|
1e107a7b92 | ||
|
|
09b3575c2d | ||
|
|
8c62fba085 | ||
|
|
d0e2383e3f | ||
|
|
b1737791a9 | ||
|
|
1e2d8fbb37 | ||
|
|
3510d049d3 | ||
|
|
8f6396c0dc | ||
|
|
a0a51c56f0 | ||
|
|
06648f4902 | ||
|
|
ec2e2c72e7 | ||
|
|
5176e2f4b4 | ||
|
|
df49e56fd6 | ||
|
|
2fec379474 | ||
|
|
c1d952849a | ||
|
|
2fa8900609 | ||
|
|
da529ac9e4 | ||
|
|
52d0615161 | ||
|
|
e6efc7c131 | ||
|
|
3bfa436c19 | ||
|
|
72a7e97c84 | ||
|
|
6a7fdcd583 | ||
|
|
ebe39ab3fa | ||
|
|
aff4c008ce | ||
|
|
6d789c5a41 | ||
|
|
6c5a56295d | ||
|
|
a43b4091db | ||
|
|
e0ffd55e7a | ||
|
|
c68f5d1387 | ||
|
|
ca6f8609c3 | ||
|
|
8c29e146dd | ||
|
|
24531016d8 | ||
|
|
65cfcebaa2 | ||
|
|
3479b795aa | ||
|
|
cbe4a600d4 | ||
|
|
c65c24c87c | ||
|
|
a3fd89f1bb | ||
|
|
36815b4852 | ||
|
|
7c952d9a52 | ||
|
|
fdbfb1dc1b | ||
|
|
0d7874ef7e | ||
|
|
53dd29f381 | ||
|
|
131e68e07e | ||
|
|
0fc4e7ac67 | ||
|
|
05a5979906 | ||
|
|
8b720b9662 | ||
|
|
6d323f4ffd | ||
|
|
7b1d394e7d | ||
|
|
48124872b6 | ||
|
|
9f48ffaca1 | ||
|
|
3ab1648f50 | ||
|
|
e5e7b6e878 | ||
|
|
c31afa6e76 | ||
|
|
8cecf9c5c5 | ||
|
|
f0c8e1f6fe | ||
|
|
d70b24c2a8 | ||
|
|
0b53d57d3a | ||
|
|
c2b36207f2 | ||
|
|
eb05ef6d65 | ||
|
|
adc6bed3ad | ||
|
|
c496b15409 | ||
|
|
5fb45ece61 | ||
|
|
bfe00257dc | ||
|
|
9b628e171b | ||
|
|
a58dd30d2b | ||
|
|
8393ede275 | ||
|
|
7e22bf538a | ||
|
|
000ec99b5a | ||
|
|
e95de00a47 | ||
|
|
36fed93cf5 | ||
|
|
3bda9f6b14 | ||
|
|
c00da4e0a4 | ||
|
|
e9bf5c5232 | ||
|
|
973db96394 | ||
|
|
31e3a75444 | ||
|
|
454d8d95c6 | ||
|
|
7d5e904fb2 | ||
|
|
5125a3cd41 | ||
|
|
e2b82ebd0f | ||
|
|
7451154694 | ||
|
|
54802bec7c | ||
|
|
b8c7ac0302 | ||
|
|
89abe5ba46 | ||
|
|
69921864a7 | ||
|
|
682de76b1e | ||
|
|
c3c8c9f2a5 | ||
|
|
fc4e3dbe40 | ||
|
|
7cd9aac79e | ||
|
|
a4ecab1763 | ||
|
|
c3211fcd0c | ||
|
|
1204e79a1e | ||
|
|
9a9ab01072 | ||
|
|
a9f953b682 | ||
|
|
c48e963a55 | ||
|
|
49eedd3d2a | ||
|
|
25381509d5 | ||
|
|
5206a9fd30 | ||
|
|
7be9c1b136 | ||
|
|
5eb53f6003 | ||
|
|
3c7396a09c | ||
|
|
d55543d033 | ||
|
|
ebd0bfc11f | ||
|
|
ac7999d72d | ||
|
|
830b3f0b50 | ||
|
|
55106a887e | ||
|
|
15f067638e | ||
|
|
d7c9b35913 | ||
|
|
eaacfa1101 | ||
|
|
349b2c66a9 | ||
|
|
165ff3069d | ||
|
|
f910ac37b6 | ||
|
|
8df64f8196 | ||
|
|
3a0a38a1e7 | ||
|
|
7d6644bdb6 | ||
|
|
7220b01d67 | ||
|
|
f5ad8e3e76 | ||
|
|
585cd058e8 | ||
|
|
6f24595362 | ||
|
|
f0b44d6854 | ||
|
|
23acc59c99 | ||
|
|
66911b7d16 | ||
|
|
423929a533 | ||
|
|
e04a388232 | ||
|
|
a79b28f2fa | ||
|
|
b866fbb28b | ||
|
|
425c929e20 | ||
|
|
8828770125 | ||
|
|
44c5d10416 | ||
|
|
5875113d74 | ||
|
|
7f9694a4be | ||
|
|
1dd19f19e4 | ||
|
|
bffbd4a6c4 | ||
|
|
f2457a22c8 | ||
|
|
caa59bf50a | ||
|
|
04a3412801 | ||
|
|
ff139e8183 | ||
|
|
be2d7d6535 | ||
|
|
1f9cca7781 | ||
|
|
21d733a51f | ||
|
|
0d71cbf88d | ||
|
|
82566dd254 | ||
|
|
a991859d1f | ||
|
|
9d5b27bc93 | ||
|
|
2d257c09a1 | ||
|
|
04b04f4b9d | ||
|
|
f67a4856c3 | ||
|
|
2f140d6ac8 | ||
|
|
0721726e21 | ||
|
|
300af6fcc5 | ||
|
|
72c88d5928 | ||
|
|
e2da3338ab | ||
|
|
63c31af37a | ||
|
|
19346808c4 | ||
|
|
daf8e22831 | ||
|
|
9753a8706b | ||
|
|
fb27326bbc | ||
|
|
fa6120c32f | ||
|
|
f6b29e4af8 | ||
|
|
d46a07214f | ||
|
|
b07a4c8be5 | ||
|
|
7c284a6504 | ||
|
|
44a7d0e687 | ||
|
|
a9939228f6 | ||
|
|
9f609d1d9f | ||
|
|
0d3dcc55f3 | ||
|
|
cd6a8a796d | ||
|
|
e0a7c37735 | ||
|
|
5374405a01 | ||
|
|
acd6aa5a90 | ||
|
|
7347f72507 | ||
|
|
30845beee0 | ||
|
|
33220d4791 | ||
|
|
acf6b46011 | ||
|
|
93562b65cf | ||
|
|
0e3b855456 | ||
|
|
e09c1aefe4 | ||
|
|
e2676937fa | ||
|
|
0b5fee1285 | ||
|
|
9ed53ae9ab | ||
|
|
d23a9c26f3 | ||
|
|
b9b927dd1f | ||
|
|
24952f03f9 | ||
|
|
58f268e065 | ||
|
|
a4cc54778d | ||
|
|
0c0f423db8 | ||
|
|
8e251e4534 | ||
|
|
b9e580c113 | ||
|
|
a0e4dd2af9 | ||
|
|
7e5c6f7e21 | ||
|
|
af62c4d176 | ||
|
|
051283a895 | ||
|
|
516dbe1fa4 | ||
|
|
40d2a159cc | ||
|
|
2ca294741f | ||
|
|
0abf012666 | ||
|
|
bed70a84af | ||
|
|
2892da83ea | ||
|
|
f47b8062cb | ||
|
|
7877cba5f5 | ||
|
|
c449918bfb | ||
|
|
52ee8c57c2 | ||
|
|
8817b00b00 | ||
|
|
14737a9676 | ||
|
|
b6fff20c69 | ||
|
|
d693997a32 | ||
|
|
f0fbf2dbe7 | ||
|
|
f2753a4ca6 | ||
|
|
f88be00227 | ||
|
|
d642c98560 | ||
|
|
4cabc9c286 | ||
|
|
846444354b | ||
|
|
6cb36e8327 | ||
|
|
c36b57f219 | ||
|
|
24c2d2bab7 | ||
|
|
760a11c870 | ||
|
|
0e83fc6e76 | ||
|
|
a6d73d0904 | ||
|
|
4515dacafb | ||
|
|
9603417da1 | ||
|
|
43975d782b | ||
|
|
751a96bc1f | ||
|
|
113883e37d | ||
|
|
73d59580d0 | ||
|
|
1b8d711826 | ||
|
|
b8939c4fe4 | ||
|
|
a175c68f3f | ||
|
|
eaff8219d6 | ||
|
|
e7bd2f8f2f | ||
|
|
53d0f0ed11 | ||
|
|
75a7fb885d | ||
|
|
516590cf12 | ||
|
|
feb64b5364 | ||
|
|
2c77fdbfba | ||
|
|
a5af2a5b22 | ||
|
|
75f8e4dbc5 | ||
|
|
ce5a3b9db9 | ||
|
|
000c40f4fe | ||
|
|
bb81755a36 | ||
|
|
2c563bd049 | ||
|
|
ebb88c3428 | ||
|
|
fe728cfb5a | ||
|
|
e9f41de2a8 | ||
|
|
2d9b633169 | ||
|
|
5417dfd58c | ||
|
|
95eac71bf5 | ||
|
|
7b4a4951dc | ||
|
|
9951b44d5b | ||
|
|
9175b4bb5f | ||
|
|
814b503899 | ||
|
|
4d8a451649 | ||
|
|
2fb6b09b67 | ||
|
|
feecfd97cd | ||
|
|
e2361f4496 | ||
|
|
9ddb2e6ca7 | ||
|
|
d97323bc60 | ||
|
|
adf5c88ba1 | ||
|
|
df599ea8f1 | ||
|
|
991bb2f6d4 | ||
|
|
d06cf700ee | ||
|
|
4a0bddd498 | ||
|
|
fdc512d107 | ||
|
|
5d6e0851b6 | ||
|
|
7386d8878e | ||
|
|
665cc04a60 | ||
|
|
31631ea68f | ||
|
|
b1db30ce36 | ||
|
|
1d9f622484 | ||
|
|
727119f8c7 | ||
|
|
42be12b510 | ||
|
|
59efa72d69 | ||
|
|
11ea44f3e2 | ||
|
|
47f263077e | ||
|
|
bde9fa6f64 | ||
|
|
c9c2d40f71 | ||
|
|
6ab392f626 | ||
|
|
e21d07988b | ||
|
|
02ba211ea1 | ||
|
|
678b22642a | ||
|
|
7206892913 | ||
|
|
5926058aec | ||
|
|
731910af01 | ||
|
|
cd445c5465 | ||
|
|
d677e3e844 | ||
|
|
42e16f31c6 | ||
|
|
e3bde1588b | ||
|
|
f4e2805e19 | ||
|
|
aba0c60eba | ||
|
|
57c93ffe6c | ||
|
|
147ed950e3 | ||
|
|
7cca8f95f7 | ||
|
|
0176a5082b | ||
|
|
fc9367a9ec | ||
|
|
a6746213b1 | ||
|
|
a36049dac5 | ||
|
|
0b6f96a6b9 | ||
|
|
c31b6e8a03 | ||
|
|
3f4351d233 | ||
|
|
30b6672aee | ||
|
|
a2e44a84be | ||
|
|
00a8cb30fa | ||
|
|
03877755e9 | ||
|
|
fb2bc03f92 | ||
|
|
8a94b5b99b | ||
|
|
adc989f7ec | ||
|
|
c796587d2e | ||
|
|
e182d8dff6 | ||
|
|
d634e28f67 | ||
|
|
0824c13801 | ||
|
|
da3311397a | ||
|
|
3f6f512406 | ||
|
|
9b9c9a57b6 | ||
|
|
8f227c405e | ||
|
|
1f7ed1c7fe | ||
|
|
ae406c0457 | ||
|
|
7c72c013b1 | ||
|
|
5084b33265 | ||
|
|
dc1c716ded | ||
|
|
80eddf2bf7 | ||
|
|
e84e84a256 | ||
|
|
bd1d46766a | ||
|
|
320bf025d2 | ||
|
|
6b81859ed0 | ||
|
|
2df9e48110 | ||
|
|
3cd3a79f9b | ||
|
|
962eb3f1c0 | ||
|
|
5b0cffeec2 | ||
|
|
49b807fa7c | ||
|
|
f1cf8c4f5a | ||
|
|
349a74c66c | ||
|
|
cc9c8408bb | ||
|
|
f43dac477e | ||
|
|
5c12a6f4a1 | ||
|
|
3509925a86 | ||
|
|
2733527a58 | ||
|
|
5bc4677c03 | ||
|
|
6715348399 | ||
|
|
67e7728c9a | ||
|
|
4bff4bc8ae | ||
|
|
ff80eacd0f | ||
|
|
0e87d3d391 | ||
|
|
2119dd10f6 | ||
|
|
1e16e2a9c2 | ||
|
|
62ba0a2242 | ||
|
|
65cc1fa8e3 | ||
|
|
46d0fa4ded | ||
|
|
3cdacf160b | ||
|
|
9525191e9f | ||
|
|
74a58bfb3f | ||
|
|
87b61d6666 | ||
|
|
b5b7888793 | ||
|
|
4d0ae6980d | ||
|
|
c3954c51c4 | ||
|
|
3d95b01351 | ||
|
|
02232f71c5 | ||
|
|
5665d6c05e | ||
|
|
94adbd6259 | ||
|
|
e1976612f0 | ||
|
|
87131f51f8 | ||
|
|
3924b55553 | ||
|
|
09414c7e2d | ||
|
|
8abb2e7244 | ||
|
|
2fe899db70 | ||
|
|
ca1f666b6d | ||
|
|
c738b81ff5 | ||
|
|
97c05365cf | ||
|
|
4075a3c23a | ||
|
|
f959b8878b | ||
|
|
ff1d6384df | ||
|
|
47174f3868 | ||
|
|
fe2fc038fd | ||
|
|
c5b7b604ca | ||
|
|
8f4f3d8d2d | ||
|
|
1c21c9410e | ||
|
|
b721000dc6 | ||
|
|
ed6c4aabea | ||
|
|
303a8143a4 |
@@ -0,0 +1,2 @@
|
||||
# nixpkgs: format with `nixfmt`
|
||||
dc1c716ded39758062ed7e6bc410ad274119de9f
|
||||
+43
-34
@@ -1,13 +1,13 @@
|
||||
name: "Test"
|
||||
on:
|
||||
pull_request:
|
||||
merge_group:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
|
||||
env:
|
||||
NIXPKGS_BRANCH: nixpkgs-unstable
|
||||
NIX_DARWIN_BRANCH: master
|
||||
NIX_VERSION: 2.24.11
|
||||
|
||||
jobs:
|
||||
@@ -19,7 +19,7 @@ jobs:
|
||||
# TODO: Change them once the repository configuration is updated.
|
||||
|
||||
test-stable:
|
||||
runs-on: macos-13
|
||||
runs-on: macos-14
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Install Nix
|
||||
@@ -29,7 +29,7 @@ jobs:
|
||||
- run: nix flake check --override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
|
||||
install-against-stable:
|
||||
runs-on: macos-13
|
||||
runs-on: macos-14
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
@@ -40,48 +40,55 @@ jobs:
|
||||
nix_path: nixpkgs=channel:${{ env.NIXPKGS_BRANCH }}
|
||||
- name: Install channels
|
||||
run: |
|
||||
nix-channel --add https://github.com/LnL7/nix-darwin/archive/${{ env.NIX_DARWIN_BRANCH }}.tar.gz darwin
|
||||
nix-channel --add https://nixos.org/channels/${{ env.NIXPKGS_BRANCH }} nixpkgs
|
||||
nix-channel --update
|
||||
sudo nix-channel --add https://nixos.org/channels/${{ env.NIXPKGS_BRANCH }} nixpkgs
|
||||
sudo nix-channel --update
|
||||
- name: Install nix-darwin
|
||||
run: |
|
||||
export NIX_PATH=$HOME/.nix-defexpr/channels
|
||||
|
||||
mkdir -p ~/.config/nix-darwin
|
||||
cp modules/examples/simple.nix ~/.config/nix-darwin/configuration.nix
|
||||
sudo mkdir -p /etc/nix-darwin
|
||||
sudo cp modules/examples/simple.nix /etc/nix-darwin/configuration.nix
|
||||
|
||||
nixConfHash=$(shasum -a 256 /etc/nix/nix.conf | cut -d ' ' -f 1)
|
||||
/usr/bin/sed -i.bak \
|
||||
"s/# programs.fish.enable = true;/nix.settings.access-tokens = [ \"github.com=\${{ secrets.GITHUB_TOKEN }}\" ]; environment.etc.\"nix\/nix.conf\".knownSha256Hashes = [ \"$nixConfHash\" ];/" \
|
||||
~/.config/nix-darwin/configuration.nix
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
"s/# programs.fish.enable = true;/ \
|
||||
imports = [ \
|
||||
({ options, ... }: { \
|
||||
nix.settings.access-tokens = [ \"github.com=\${{ secrets.GITHUB_TOKEN }}\" ]; \
|
||||
environment.etc.\"nix\/nix.conf\".knownSha256Hashes = [ \"$nixConfHash\" ]; \
|
||||
nix.nixPath = \
|
||||
[ { darwin = \"${PWD////\/}\"; } ] \
|
||||
++ options.nix.nixPath.default; \
|
||||
}) \
|
||||
]; \
|
||||
/" \
|
||||
/etc/nix-darwin/configuration.nix
|
||||
|
||||
nix run .#darwin-rebuild \
|
||||
-- switch \
|
||||
-I darwin-config=$HOME/.config/nix-darwin/configuration.nix
|
||||
sudo nix run .#darwin-rebuild -- switch \
|
||||
-I darwin=. \
|
||||
-I darwin-config=/etc/nix-darwin/configuration.nix
|
||||
- name: Switch to new configuration
|
||||
run: |
|
||||
. /etc/bashrc
|
||||
|
||||
/usr/bin/sed -i.bak \
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
"s/pkgs.vim/pkgs.hello/" \
|
||||
~/.config/nix-darwin/configuration.nix
|
||||
/etc/nix-darwin/configuration.nix
|
||||
|
||||
darwin-rebuild switch -I darwin=.
|
||||
sudo darwin-rebuild switch
|
||||
|
||||
hello
|
||||
- name: Test uninstallation of nix-darwin
|
||||
run: |
|
||||
# We need to specify `--extra-experimental-features` because `experimental-features` is set by
|
||||
# `cachix/install-nix-action` but not by our default config above
|
||||
nix run .#darwin-uninstaller \
|
||||
sudo nix run .#darwin-uninstaller \
|
||||
--extra-experimental-features "nix-command flakes" \
|
||||
--override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
nix run .#darwin-uninstaller.tests.uninstaller \
|
||||
sudo nix run .#darwin-uninstaller.tests.uninstaller \
|
||||
--extra-experimental-features "nix-command flakes" \
|
||||
--override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
|
||||
install-flake:
|
||||
runs-on: macos-13
|
||||
runs-on: macos-14
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
@@ -91,36 +98,38 @@ jobs:
|
||||
install_url: https://releases.nixos.org/nix/nix-${{ env.NIX_VERSION }}/install
|
||||
- name: Install nix-darwin
|
||||
run: |
|
||||
mkdir -p ~/.config/nix-darwin
|
||||
sudo mkdir -p /etc/nix-darwin
|
||||
darwin=$(pwd)
|
||||
pushd ~/.config/nix-darwin
|
||||
nix flake init -t $darwin
|
||||
pushd /etc/nix-darwin
|
||||
sudo nix flake init -t $darwin
|
||||
nixConfHash=$(shasum -a 256 /etc/nix/nix.conf | cut -d ' ' -f 1)
|
||||
/usr/bin/sed -i.bak \
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
"s/# programs.fish.enable = true;/nix.settings.access-tokens = [ \"github.com=\${{ secrets.GITHUB_TOKEN }}\" ]; environment.etc.\"nix\/nix.conf\".knownSha256Hashes = [ \"$nixConfHash\" ];/" \
|
||||
flake.nix
|
||||
/usr/bin/sed -i.bak \
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
's/darwinConfigurations."simple"/darwinConfigurations."'$(scutil --get LocalHostName)'"/g' \
|
||||
flake.nix
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
's/nixpkgs.hostPlatform = "aarch64-darwin";/nixpkgs.hostPlatform = "'$(nix eval --expr builtins.currentSystem --impure --raw)'";/' \
|
||||
flake.nix
|
||||
popd
|
||||
nix run .#darwin-rebuild -- \
|
||||
switch --flake ~/.config/nix-darwin#simple \
|
||||
sudo nix run .#darwin-rebuild -- switch \
|
||||
--override-input nix-darwin . \
|
||||
--override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
- name: Switch to new configuration
|
||||
run: |
|
||||
. /etc/bashrc
|
||||
|
||||
/usr/bin/sed -i.bak \
|
||||
sudo /usr/bin/sed -i.bak \
|
||||
"s/pkgs.vim/pkgs.hello/" \
|
||||
~/.config/nix-darwin/flake.nix
|
||||
/etc/nix-darwin/flake.nix
|
||||
|
||||
darwin-rebuild switch --flake ~/.config/nix-darwin#simple \
|
||||
sudo darwin-rebuild switch \
|
||||
--override-input nix-darwin . \
|
||||
--override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
|
||||
hello
|
||||
- name: Test uninstallation of nix-darwin
|
||||
run: |
|
||||
nix run .#darwin-uninstaller --override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
nix run .#darwin-uninstaller.tests.uninstaller --override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
sudo nix run .#darwin-uninstaller --override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
sudo nix run .#darwin-uninstaller.tests.uninstaller --override-input nixpkgs nixpkgs/${{ env.NIXPKGS_BRANCH }}
|
||||
|
||||
@@ -1,35 +0,0 @@
|
||||
name: Update manual
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
|
||||
jobs:
|
||||
update-manual:
|
||||
runs-on: macos-13
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
# So that we fetch all branches, since we need to checkout the `gh-pages` branch later.
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@v30
|
||||
|
||||
- name: Build manual
|
||||
run: |
|
||||
nix build .#manualHTML
|
||||
|
||||
- name: Push update to manual
|
||||
run: |
|
||||
git checkout gh-pages
|
||||
rm -rf manual
|
||||
cp -R result/share/doc/darwin manual
|
||||
rm result
|
||||
git checkout master -- README.md
|
||||
git config user.name github-actions
|
||||
git config user.email github-actions@github.com
|
||||
git add --all
|
||||
git commit -m "Update manual"
|
||||
git push
|
||||
@@ -0,0 +1,45 @@
|
||||
name: Update website
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
|
||||
permissions: {}
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build
|
||||
runs-on: macos-14
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@02a151ada4993995686f9ed4f1be7cfbb229e56f
|
||||
- name: Build website
|
||||
run: nix build .#website -o _site
|
||||
- name: Upload website
|
||||
id: deployment
|
||||
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa
|
||||
|
||||
# See: <https://github.com/actions/deploy-pages?tab=readme-ov-file#usage>
|
||||
deploy:
|
||||
name: Deploy
|
||||
needs: build
|
||||
permissions:
|
||||
pages: write
|
||||
id-token: write
|
||||
environment:
|
||||
name: github-pages
|
||||
url: ${{ steps.deployment.outputs.page_url }}
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Deploy to GitHub Pages
|
||||
id: deployment
|
||||
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e
|
||||
@@ -1,2 +1,3 @@
|
||||
.DS_Store
|
||||
*.swp
|
||||
result*
|
||||
|
||||
@@ -1,3 +1,90 @@
|
||||
2026-05-16
|
||||
- The reversed split-window key bindings previously generated by
|
||||
`programs.tmux.enableSensible` are no longer emitted when
|
||||
`system.stateVersion` is 7 or later, so tmux uses its conventional
|
||||
behavior: `%` splits the current pane horizontally and `"` splits it
|
||||
vertically.
|
||||
|
||||
Existing configurations with `system.stateVersion` 6 or earlier keep
|
||||
the previous reversed bindings. You can explicitly choose either
|
||||
behavior with `programs.tmux.reverseSplitBindings`.
|
||||
|
||||
2026-02-10
|
||||
- Major changes to `homebrew` module
|
||||
|
||||
`homebrew.brewPrefix` was renamed to `homebrew.prefix`, and its semantics
|
||||
changed: the old option pointed to the bin directory (e.g.,
|
||||
`/opt/homebrew/bin`), while the new option points to the Homebrew prefix
|
||||
(e.g., `/opt/homebrew`), matching `brew --prefix`.
|
||||
|
||||
`homebrew.whalebrews` was removed. Whalebrew support was removed from
|
||||
Homebrew Bundle in Homebrew 4.7.0 (Nov 2025), so `whalebrew` entries in a
|
||||
Brewfile now cause `brew bundle` to fail.
|
||||
|
||||
`homebrew.global.lockfiles` and `homebrew.global.noLock` no longer have any
|
||||
effect. Homebrew Bundle removed lockfile support in Homebrew 4.4.0 (Oct 2024).
|
||||
|
||||
`homebrew.onActivation.cleanup` now supports a `"check"` mode, which checks
|
||||
for unlisted packages and aborts activation if any are found, without
|
||||
removing them.
|
||||
|
||||
Shell integration options were added: `homebrew.enableBashIntegration`,
|
||||
`homebrew.enableFishIntegration`, and `homebrew.enableZshIntegration`.
|
||||
|
||||
New Brewfile entry types were added: `homebrew.goPackages`,
|
||||
`homebrew.cargoPackages`, and `homebrew.vscode`.
|
||||
|
||||
New options were added for brews: `postinstall`, `link = "overwrite"`, and
|
||||
`restart_service = "always"`. The `postinstall` option was also added for
|
||||
casks.
|
||||
|
||||
2025-01-30
|
||||
- Previously, some nix-darwin options applied to the user running
|
||||
`darwin-rebuild`. As part of a long‐term migration to make
|
||||
nix-darwin focus on system‐wide activation and support first‐class
|
||||
multi‐user setups, all system activation now runs as `root`, and
|
||||
these options instead apply to the `system.primaryUser` user.
|
||||
|
||||
You will get an evaluation error if you are using any options to
|
||||
which this applies.
|
||||
|
||||
To continue using these options, set `system.primaryUser` to the name
|
||||
of the user you have been using to run `darwin-rebuild`. In the long
|
||||
run, this setting will be deprecated and removed after all the
|
||||
functionality it is relevant for has been adjusted to allow
|
||||
specifying the relevant user separately, moved under the
|
||||
`users.users.*` namespace, or migrated to Home Manager.
|
||||
|
||||
Accordingly, `darwin-rebuild` must now be run as root, the
|
||||
`system.activationScripts.{extraUserActivation,preUserActivation,
|
||||
postUserActivation}` settings have been removed, and all activation
|
||||
scripts are now executed as `root` – be careful if you override any
|
||||
of them.
|
||||
|
||||
If you run into any unexpected issues with the migration, please
|
||||
open an issue at <https://github.com/nix-darwin/nix-darwin/issues/new>
|
||||
and include as much information as possible.
|
||||
|
||||
2025-01-29
|
||||
- There is now a `nix.enable` toggle to disable management of the Nix
|
||||
installation. Nix installation management has been made more
|
||||
opinionated as a consequence; nix-darwin now only supports managing a
|
||||
multi‐user daemon installation of Nix, and unconditionally takes
|
||||
ownership of the nix-daemon launchd daemon and the `_nixbld*` build
|
||||
users when Nix installation management is enabled.
|
||||
|
||||
If the new constraints do not work with your setup, you can disable
|
||||
the `nix.enable` option to opt out of Nix installation management
|
||||
entirely; see the option documentation for caveats.
|
||||
|
||||
2025-01-18
|
||||
- The default configuration path for all new installations
|
||||
is `/etc/nix-darwin`. This was already the undocumented
|
||||
default for `darwin-rebuild switch` when using flakes. This
|
||||
is implemented by setting `environment.darwinConfig` to
|
||||
`"/etc/nix-darwin/configuration.nix"` by default when
|
||||
`system.stateVersion` ≥ 6.
|
||||
|
||||
2024-09-10
|
||||
- The default Nix build user group ID is now set to 350 when
|
||||
`system.stateVersion` ≥ 5, to reflect the default for new Nix
|
||||
@@ -69,7 +156,7 @@
|
||||
|
||||
`nix.daemonIONice` was renamed to `nix.daemonIOLowPriority`, and
|
||||
`nix.daemonNiceLevel` was removed in favor a new option
|
||||
`nix.nix.daemonProcessType`.
|
||||
`nix.daemonProcessType`.
|
||||
|
||||
2021-01-16
|
||||
- Added `homebrew` module, to manage formulas installed by Homebrew via `brew bundle`.
|
||||
@@ -189,7 +276,7 @@
|
||||
|
||||
Use a channel for nix-darwin or configure nix.nixPath
|
||||
|
||||
sudo nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
|
||||
sudo nix-channel --add https://github.com/nix-darwin/nix-darwin/archive/master.tar.gz darwin
|
||||
sudo nix-channel --update
|
||||
|
||||
nix.nixPath =
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
[<img src="https://daiderd.com/nix-darwin/images/nix-darwin.png" width="200px" alt="logo" />](https://github.com/LnL7/nix-darwin)
|
||||
[<img src="https://github.com/user-attachments/assets/0e1a77ac-6739-4153-bd24-abd3a5e143f5" width="200px" alt="logo" />](https://github.com/nix-darwin/nix-darwin)
|
||||
|
||||
# nix-darwin
|
||||
|
||||
[](https://github.com/LnL7/nix-darwin/actions/workflows/test.yml)
|
||||
[](https://github.com/nix-darwin/nix-darwin/actions/workflows/test.yml)
|
||||
|
||||
Nix modules for darwin, `/etc/nixos/configuration.nix` for macOS.
|
||||
|
||||
@@ -11,14 +11,11 @@ nix-darwin is built up around [Nixpkgs](https://github.com/NixOS/nixpkgs), quite
|
||||
|
||||
## Prerequisites
|
||||
|
||||
The only prerequisite is a Nix implementation, both Nix and Lix are supported.
|
||||
|
||||
As the official Nix installer does not include an automated uninstaller, and manual uninstallation on macOS is a complex process, we recommend using one of the following installers instead:
|
||||
|
||||
- The [Nix installer from Determinate Systems](https://github.com/DeterminateSystems/nix-installer?tab=readme-ov-file#determinate-nix-installer) is only recommended for use with flake-based setups. **Make sure you use it without the `--determinate` flag**. The `--determinate` flag installs the Determinate Nix distribution which does not work out of the box with nix-darwin.
|
||||
* The [Lix installer](https://lix.systems/install/#on-any-other-linuxmacos-system) supports both flake-based and channel-based setups.
|
||||
The only prerequisite is a Nix implementation; both Nix and Lix are supported.
|
||||
|
||||
As the official Nix installer does not include an automated uninstaller, and manual uninstallation on macOS is a complex process, we recommend using the [Lix installer](https://lix.systems/install/#on-any-other-linuxmacos-system), which supports both flake-based and channel-based setups.
|
||||
|
||||
The installer you use doesn't affect which Nix interpreter your system will use later on. nix-darwin manages the Nix installation by default and will default to upstream Nix. If you wish to use Lix instead of Nix, set `nix.package = pkgs.lix` in your configuration.
|
||||
|
||||
## Getting started
|
||||
|
||||
@@ -33,21 +30,22 @@ Despite being an experimental feature in Nix currently, nix-darwin recommends th
|
||||
<summary>Getting started from scratch</summary>
|
||||
<p></p>
|
||||
|
||||
If you don't have an existing `configuration.nix`, you can run the following commands to generate a basic `flake.nix` inside `~/.config/nix-darwin`:
|
||||
If you don't have an existing `configuration.nix`, you can run the following commands to generate a basic `flake.nix` inside `/etc/nix-darwin`:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/.config/nix-darwin
|
||||
cd ~/.config/nix-darwin
|
||||
sudo mkdir -p /etc/nix-darwin
|
||||
sudo chown $(id -nu):$(id -ng) /etc/nix-darwin
|
||||
cd /etc/nix-darwin
|
||||
|
||||
# To use Nixpkgs unstable:
|
||||
nix flake init -t nix-darwin/master
|
||||
# To use Nixpkgs 24.11:
|
||||
nix flake init -t nix-darwin/nix-darwin-24.11
|
||||
# To use Nixpkgs 26.05:
|
||||
nix flake init -t nix-darwin/nix-darwin-26.05
|
||||
|
||||
sed -i '' "s/simple/$(scutil --get LocalHostName)/" flake.nix
|
||||
```
|
||||
|
||||
Make sure to change `nixpkgs.hostPlatform` to `aarch64-darwin` if you are using Apple Silicon.
|
||||
Make sure to check if `nixpkgs.hostPlatform` is set to either `x86_64-darwin` for Intel or `aarch64-darwin` for Apple Silicon.
|
||||
|
||||
</details>
|
||||
|
||||
@@ -62,10 +60,10 @@ Add the following to `flake.nix` in the same folder as `configuration.nix`:
|
||||
description = "John's darwin system";
|
||||
|
||||
inputs = {
|
||||
# Use `github:NixOS/nixpkgs/nixpkgs-24.11-darwin` to use Nixpkgs 24.11.
|
||||
# Use `github:NixOS/nixpkgs/nixpkgs-26.05-darwin` to use Nixpkgs 26.05.
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
# Use `github:LnL7/nix-darwin/nix-darwin-24.11` to use Nixpkgs 24.11.
|
||||
nix-darwin.url = "github:LnL7/nix-darwin/master";
|
||||
# Use `github:nix-darwin/nix-darwin/nix-darwin-26.05` to use Nixpkgs 26.05.
|
||||
nix-darwin.url = "github:nix-darwin/nix-darwin/master";
|
||||
nix-darwin.inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
@@ -88,7 +86,10 @@ Make sure to set `nixpkgs.hostPlatform` in your `configuration.nix` to either `x
|
||||
Unlike NixOS, `nix-darwin` does not have an installer, you can just run `darwin-rebuild switch` to install nix-darwin. As `darwin-rebuild` won't be installed in your `PATH` yet, you can use the following command:
|
||||
|
||||
```bash
|
||||
nix run nix-darwin -- switch --flake ~/.config/nix-darwin
|
||||
# To use Nixpkgs unstable:
|
||||
sudo nix run nix-darwin/master#darwin-rebuild -- switch
|
||||
# To use Nixpkgs 26.05:
|
||||
sudo nix run nix-darwin/nix-darwin-26.05#darwin-rebuild -- switch
|
||||
```
|
||||
|
||||
### Step 3. Using `nix-darwin`
|
||||
@@ -96,7 +97,7 @@ nix run nix-darwin -- switch --flake ~/.config/nix-darwin
|
||||
After installing, you can run `darwin-rebuild` to apply changes to your system:
|
||||
|
||||
```bash
|
||||
darwin-rebuild switch --flake ~/.config/nix-darwin
|
||||
sudo darwin-rebuild switch
|
||||
```
|
||||
|
||||
#### Using flake inputs
|
||||
@@ -124,15 +125,15 @@ nix-darwin.lib.darwinSystem {
|
||||
|
||||
### Step 1. Creating `configuration.nix`
|
||||
|
||||
Copy the [simple](./modules/examples/simple.nix) example to `~/.config/nix-darwin/configuration.nix`.
|
||||
Copy the [simple](./modules/examples/simple.nix) example to `/etc/nix-darwin/configuration.nix`.
|
||||
|
||||
### Step 2. Adding `nix-darwin` channel
|
||||
|
||||
```bash
|
||||
# If you use Nixpkgs unstable (the default):
|
||||
sudo nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
|
||||
# If you use Nixpkgs 24.11:
|
||||
sudo nix-channel --add https://github.com/LnL7/nix-darwin/archive/nix-darwin-24.11.tar.gz darwin
|
||||
sudo nix-channel --add https://github.com/nix-darwin/nix-darwin/archive/master.tar.gz darwin
|
||||
# If you use Nixpkgs 26.05:
|
||||
sudo nix-channel --add https://github.com/nix-darwin/nix-darwin/archive/nix-darwin-26.05.tar.gz darwin
|
||||
|
||||
sudo nix-channel --update
|
||||
```
|
||||
@@ -142,12 +143,8 @@ sudo nix-channel --update
|
||||
To install `nix-darwin`, you can just run `darwin-rebuild switch` to install nix-darwin. As `darwin-rebuild` won't be installed in your `PATH` yet, you can use the following command:
|
||||
|
||||
```bash
|
||||
# If you use Nixpkgs unstable (the default):
|
||||
nix-build https://github.com/LnL7/nix-darwin/archive/master.tar.gz -A darwin-rebuild
|
||||
# If you use Nixpkgs 24.11:
|
||||
nix-build https://github.com/LnL7/nix-darwin/archive/nix-darwin-24.11.tar.gz -A darwin-rebuild
|
||||
|
||||
./result/bin/darwin-rebuild switch -I darwin-config=$HOME/.config/nix-darwin/configuration.nix
|
||||
nix-build '<darwin>' -A darwin-rebuild
|
||||
sudo ./result/bin/darwin-rebuild switch -I darwin-config=/etc/nix-darwin/configuration.nix
|
||||
```
|
||||
|
||||
### Step 4. Using `nix-darwin`
|
||||
@@ -155,7 +152,7 @@ nix-build https://github.com/LnL7/nix-darwin/archive/nix-darwin-24.11.tar.gz -A
|
||||
After installing, you can run `darwin-rebuild` to apply changes to your system:
|
||||
|
||||
```bash
|
||||
darwin-rebuild switch
|
||||
sudo darwin-rebuild switch
|
||||
```
|
||||
|
||||
### Step 5. Updating `nix-darwin`
|
||||
@@ -169,22 +166,24 @@ sudo nix-channel --update
|
||||
|
||||
## Documentation
|
||||
|
||||
`darwin-help` will open up a local copy of the reference documentation, it can also be found online [here](https://daiderd.com/nix-darwin/manual/index.html).
|
||||
The reference documentation is available:
|
||||
|
||||
The documentation is also available as manpages by running `man 5 configuration.nix`.
|
||||
* Online: [nix-darwin reference](https://nix-darwin.github.io/nix-darwin/manual/index.html)
|
||||
* Locally in your browser via the `darwin-help` command
|
||||
* As a manual page via `man 5 configuration.nix`
|
||||
|
||||
## Uninstalling
|
||||
|
||||
To run the latest version of the uninstaller, you can run the following command:
|
||||
|
||||
```
|
||||
nix --extra-experimental-features "nix-command flakes" run nix-darwin#darwin-uninstaller
|
||||
sudo nix --extra-experimental-features "nix-command flakes" run nix-darwin#darwin-uninstaller
|
||||
```
|
||||
|
||||
If that command doesn't work for you, you can try the locally installed uninstaller:
|
||||
|
||||
```
|
||||
darwin-uninstaller
|
||||
sudo darwin-uninstaller
|
||||
```
|
||||
|
||||
## Tests
|
||||
@@ -210,7 +209,7 @@ flag can also be used to override darwin-config or nixpkgs, for more
|
||||
information on the `-I` flag look at the nix-build [manpage](https://nixos.org/manual/nix/stable/command-ref/nix-build.html).
|
||||
|
||||
```bash
|
||||
darwin-rebuild switch -I darwin=.
|
||||
sudo darwin-rebuild switch -I darwin=.
|
||||
```
|
||||
|
||||
If you're adding a module, please add yourself to `meta.maintainers`, for example
|
||||
@@ -226,6 +225,6 @@ If you're adding a module, please add yourself to `meta.maintainers`, for exampl
|
||||
The `or` operator takes care of graceful degradation when `lib` from Nixpkgs
|
||||
goes out of sync.
|
||||
|
||||
Also feel free to contact me if you have questions,
|
||||
- Matrix - @daiderd:matrix.org, you can find me in [#macos:nixos.org](https://matrix.to/#/#macos:nixos.org)
|
||||
- @LnL7 on twitter
|
||||
Feel free to contact us on Matrix if you have questions:
|
||||
* **User support:** [#macos:nixos.org](https://matrix.to/#/#macos:nixos.org)
|
||||
* **Development discussion:** [#nix-darwin-dev:nixos.org](https://matrix.to/#/#nix-darwin-dev:nixos.org)
|
||||
|
||||
@@ -0,0 +1,82 @@
|
||||
|
||||
# Nix
|
||||
if [ -e '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh' ]; then
|
||||
. '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh'
|
||||
fi
|
||||
# End Nix
|
||||
|
||||
|
||||
# System-wide profile for interactive zsh(1) shells.
|
||||
|
||||
# Setup user specific overrides for this in ~/.zshrc. See zshbuiltins(1)
|
||||
# and zshoptions(1) for more details.
|
||||
|
||||
# Correctly display UTF-8 with combining characters. We'll assume UTF-8 if the
|
||||
# locale(1) binary is missing entirely.
|
||||
if [[ ! -x /usr/bin/locale ]] || [[ "$(locale LC_CTYPE)" == "UTF-8" ]]; then
|
||||
setopt COMBINING_CHARS
|
||||
fi
|
||||
|
||||
# Disable the log builtin, so we don't conflict with /usr/bin/log
|
||||
disable log
|
||||
|
||||
# Save command history
|
||||
HISTFILE=${ZDOTDIR:-$HOME}/.zsh_history
|
||||
HISTSIZE=2000
|
||||
SAVEHIST=1000
|
||||
|
||||
# Beep on error
|
||||
setopt BEEP
|
||||
|
||||
# Use keycodes (generated via zkbd) if present, otherwise fallback on
|
||||
# values from terminfo
|
||||
if [[ -r ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR} ]] ; then
|
||||
source ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR}
|
||||
else
|
||||
typeset -g -A key
|
||||
|
||||
[[ -n "$terminfo[kf1]" ]] && key[F1]=$terminfo[kf1]
|
||||
[[ -n "$terminfo[kf2]" ]] && key[F2]=$terminfo[kf2]
|
||||
[[ -n "$terminfo[kf3]" ]] && key[F3]=$terminfo[kf3]
|
||||
[[ -n "$terminfo[kf4]" ]] && key[F4]=$terminfo[kf4]
|
||||
[[ -n "$terminfo[kf5]" ]] && key[F5]=$terminfo[kf5]
|
||||
[[ -n "$terminfo[kf6]" ]] && key[F6]=$terminfo[kf6]
|
||||
[[ -n "$terminfo[kf7]" ]] && key[F7]=$terminfo[kf7]
|
||||
[[ -n "$terminfo[kf8]" ]] && key[F8]=$terminfo[kf8]
|
||||
[[ -n "$terminfo[kf9]" ]] && key[F9]=$terminfo[kf9]
|
||||
[[ -n "$terminfo[kf10]" ]] && key[F10]=$terminfo[kf10]
|
||||
[[ -n "$terminfo[kf11]" ]] && key[F11]=$terminfo[kf11]
|
||||
[[ -n "$terminfo[kf12]" ]] && key[F12]=$terminfo[kf12]
|
||||
[[ -n "$terminfo[kf13]" ]] && key[F13]=$terminfo[kf13]
|
||||
[[ -n "$terminfo[kf14]" ]] && key[F14]=$terminfo[kf14]
|
||||
[[ -n "$terminfo[kf15]" ]] && key[F15]=$terminfo[kf15]
|
||||
[[ -n "$terminfo[kf16]" ]] && key[F16]=$terminfo[kf16]
|
||||
[[ -n "$terminfo[kf17]" ]] && key[F17]=$terminfo[kf17]
|
||||
[[ -n "$terminfo[kf18]" ]] && key[F18]=$terminfo[kf18]
|
||||
[[ -n "$terminfo[kf19]" ]] && key[F19]=$terminfo[kf19]
|
||||
[[ -n "$terminfo[kf20]" ]] && key[F20]=$terminfo[kf20]
|
||||
[[ -n "$terminfo[kbs]" ]] && key[Backspace]=$terminfo[kbs]
|
||||
[[ -n "$terminfo[kich1]" ]] && key[Insert]=$terminfo[kich1]
|
||||
[[ -n "$terminfo[kdch1]" ]] && key[Delete]=$terminfo[kdch1]
|
||||
[[ -n "$terminfo[khome]" ]] && key[Home]=$terminfo[khome]
|
||||
[[ -n "$terminfo[kend]" ]] && key[End]=$terminfo[kend]
|
||||
[[ -n "$terminfo[kpp]" ]] && key[PageUp]=$terminfo[kpp]
|
||||
[[ -n "$terminfo[knp]" ]] && key[PageDown]=$terminfo[knp]
|
||||
[[ -n "$terminfo[kcuu1]" ]] && key[Up]=$terminfo[kcuu1]
|
||||
[[ -n "$terminfo[kcub1]" ]] && key[Left]=$terminfo[kcub1]
|
||||
[[ -n "$terminfo[kcud1]" ]] && key[Down]=$terminfo[kcud1]
|
||||
[[ -n "$terminfo[kcuf1]" ]] && key[Right]=$terminfo[kcuf1]
|
||||
fi
|
||||
|
||||
# Default key bindings
|
||||
[[ -n ${key[Delete]} ]] && bindkey "${key[Delete]}" delete-char
|
||||
[[ -n ${key[Home]} ]] && bindkey "${key[Home]}" beginning-of-line
|
||||
[[ -n ${key[End]} ]] && bindkey "${key[End]}" end-of-line
|
||||
[[ -n ${key[Up]} ]] && bindkey "${key[Up]}" up-line-or-search
|
||||
[[ -n ${key[Down]} ]] && bindkey "${key[Down]}" down-line-or-search
|
||||
|
||||
# Default prompt
|
||||
PS1="%n@%m %1~ %# "
|
||||
|
||||
# Useful support for interacting with Terminal.app or other terminal programs
|
||||
[ -r "/etc/zshrc_$TERM_PROGRAM" ] && . "/etc/zshrc_$TERM_PROGRAM"
|
||||
@@ -0,0 +1,3 @@
|
||||
# Written by https://github.com/DeterminateSystems/nix-installer.
|
||||
# The contents below are based on options specified at installation time.
|
||||
|
||||
@@ -0,0 +1,74 @@
|
||||
# System-wide profile for interactive zsh(1) shells.
|
||||
|
||||
# Setup user specific overrides for this in ~/.zshrc. See zshbuiltins(1)
|
||||
# and zshoptions(1) for more details.
|
||||
|
||||
# Correctly display UTF-8 with combining characters. We'll assume UTF-8 if the
|
||||
# locale(1) binary is missing entirely.
|
||||
if [[ ! -x /usr/bin/locale ]] || [[ "$(locale LC_CTYPE)" == "UTF-8" ]]; then
|
||||
setopt COMBINING_CHARS
|
||||
fi
|
||||
|
||||
# Disable the log builtin, so we don't conflict with /usr/bin/log
|
||||
disable log
|
||||
|
||||
# Save command history
|
||||
HISTFILE=${ZDOTDIR:-$HOME}/.zsh_history
|
||||
HISTSIZE=2000
|
||||
SAVEHIST=1000
|
||||
|
||||
# Beep on error
|
||||
setopt BEEP
|
||||
|
||||
# Use keycodes (generated via zkbd) if present, otherwise fallback on
|
||||
# values from terminfo
|
||||
if [[ -r ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR} ]] ; then
|
||||
source ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR}
|
||||
else
|
||||
typeset -g -A key
|
||||
|
||||
[[ -n "$terminfo[kf1]" ]] && key[F1]=$terminfo[kf1]
|
||||
[[ -n "$terminfo[kf2]" ]] && key[F2]=$terminfo[kf2]
|
||||
[[ -n "$terminfo[kf3]" ]] && key[F3]=$terminfo[kf3]
|
||||
[[ -n "$terminfo[kf4]" ]] && key[F4]=$terminfo[kf4]
|
||||
[[ -n "$terminfo[kf5]" ]] && key[F5]=$terminfo[kf5]
|
||||
[[ -n "$terminfo[kf6]" ]] && key[F6]=$terminfo[kf6]
|
||||
[[ -n "$terminfo[kf7]" ]] && key[F7]=$terminfo[kf7]
|
||||
[[ -n "$terminfo[kf8]" ]] && key[F8]=$terminfo[kf8]
|
||||
[[ -n "$terminfo[kf9]" ]] && key[F9]=$terminfo[kf9]
|
||||
[[ -n "$terminfo[kf10]" ]] && key[F10]=$terminfo[kf10]
|
||||
[[ -n "$terminfo[kf11]" ]] && key[F11]=$terminfo[kf11]
|
||||
[[ -n "$terminfo[kf12]" ]] && key[F12]=$terminfo[kf12]
|
||||
[[ -n "$terminfo[kf13]" ]] && key[F13]=$terminfo[kf13]
|
||||
[[ -n "$terminfo[kf14]" ]] && key[F14]=$terminfo[kf14]
|
||||
[[ -n "$terminfo[kf15]" ]] && key[F15]=$terminfo[kf15]
|
||||
[[ -n "$terminfo[kf16]" ]] && key[F16]=$terminfo[kf16]
|
||||
[[ -n "$terminfo[kf17]" ]] && key[F17]=$terminfo[kf17]
|
||||
[[ -n "$terminfo[kf18]" ]] && key[F18]=$terminfo[kf18]
|
||||
[[ -n "$terminfo[kf19]" ]] && key[F19]=$terminfo[kf19]
|
||||
[[ -n "$terminfo[kf20]" ]] && key[F20]=$terminfo[kf20]
|
||||
[[ -n "$terminfo[kbs]" ]] && key[Backspace]=$terminfo[kbs]
|
||||
[[ -n "$terminfo[kich1]" ]] && key[Insert]=$terminfo[kich1]
|
||||
[[ -n "$terminfo[kdch1]" ]] && key[Delete]=$terminfo[kdch1]
|
||||
[[ -n "$terminfo[khome]" ]] && key[Home]=$terminfo[khome]
|
||||
[[ -n "$terminfo[kend]" ]] && key[End]=$terminfo[kend]
|
||||
[[ -n "$terminfo[kpp]" ]] && key[PageUp]=$terminfo[kpp]
|
||||
[[ -n "$terminfo[knp]" ]] && key[PageDown]=$terminfo[knp]
|
||||
[[ -n "$terminfo[kcuu1]" ]] && key[Up]=$terminfo[kcuu1]
|
||||
[[ -n "$terminfo[kcub1]" ]] && key[Left]=$terminfo[kcub1]
|
||||
[[ -n "$terminfo[kcud1]" ]] && key[Down]=$terminfo[kcud1]
|
||||
[[ -n "$terminfo[kcuf1]" ]] && key[Right]=$terminfo[kcuf1]
|
||||
fi
|
||||
|
||||
# Default key bindings
|
||||
[[ -n ${key[Delete]} ]] && bindkey "${key[Delete]}" delete-char
|
||||
[[ -n ${key[Home]} ]] && bindkey "${key[Home]}" beginning-of-line
|
||||
[[ -n ${key[End]} ]] && bindkey "${key[End]}" end-of-line
|
||||
[[ -n ${key[Up]} ]] && bindkey "${key[Up]}" up-line-or-search
|
||||
[[ -n ${key[Down]} ]] && bindkey "${key[Down]}" down-line-or-search
|
||||
|
||||
# Default prompt
|
||||
PS1="%n@%m %1~ %# "
|
||||
|
||||
# Useful support for interacting with Terminal.app or other terminal programs
|
||||
[ -r "/etc/zshrc_$TERM_PROGRAM" ] && . "/etc/zshrc_$TERM_PROGRAM"
|
||||
@@ -0,0 +1,7 @@
|
||||
|
||||
# Set up Nix only on SSH connections
|
||||
# See: https://github.com/DeterminateSystems/nix-installer/pull/714
|
||||
if [ -e '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh' ] && [ -n "${SSH_CONNECTION:-}" ] && [ "${SHLVL:-0}" -eq 1 ]; then
|
||||
. '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh'
|
||||
fi
|
||||
# End Nix
|
||||
@@ -0,0 +1,14 @@
|
||||
|
||||
# Generated by https://github.com/DeterminateSystems/nix-installer.
|
||||
# See `/nix/nix-installer --version` for the version details.
|
||||
|
||||
!include nix.custom.conf
|
||||
|
||||
experimental-features = nix-command flakes
|
||||
always-allow-substitutes = true
|
||||
extra-trusted-substituters = https://cache.flakehub.com
|
||||
extra-trusted-public-keys = cache.flakehub.com-3:hJuILl5sVK4iKm86JzgdXW12Y2Hwd5G07qKtHTOcDCM= cache.flakehub.com-4:Asi8qIv291s0aYLyH6IOnr5Kf6+OF14WVjkE6t3xMio= cache.flakehub.com-5:zB96CRlL7tiPtzA9/WKyPkp3A2vqxqgdgyTVNGShPDU= cache.flakehub.com-6:W4EGFwAGgBj3he7c5fNh9NkOXw0PUVaxygCVKeuvaqU= cache.flakehub.com-7:mvxJ2DZVHn/kRxlIaxYNMuDG1OvMckZu32um1TadOR8= cache.flakehub.com-8:moO+OVS0mnTjBTcOUh2kYLQEd59ExzyoW1QgQ8XAARQ= cache.flakehub.com-9:wChaSeTI6TeCuV/Sg2513ZIM9i0qJaYsF+lZCXg0J6o= cache.flakehub.com-10:2GqeNlIp6AKp4EF2MVbE1kBOp9iBSyo0UPR9KoR0o1Y=
|
||||
bash-prompt-prefix = (nix:$name)\040
|
||||
max-jobs = auto
|
||||
extra-nix-path = nixpkgs=flake:nixpkgs
|
||||
upgrade-nix-store-path-url = https://install.determinate.systems/nix-upgrade/stable/universal
|
||||
@@ -0,0 +1,4 @@
|
||||
|
||||
# Written by https://github.com/DeterminateSystems/nix-installer.
|
||||
# The contents below are based on options specified at installation time.
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
# Generated by https://github.com/DeterminateSystems/nix-installer.
|
||||
# See `/nix/nix-installer --version` for the version details.
|
||||
|
||||
extra-experimental-features = nix-command flakes
|
||||
always-allow-substitutes = true
|
||||
extra-trusted-substituters = https://cache.flakehub.com
|
||||
extra-trusted-public-keys = cache.flakehub.com-3:hJuILl5sVK4iKm86JzgdXW12Y2Hwd5G07qKtHTOcDCM= cache.flakehub.com-4:Asi8qIv291s0aYLyH6IOnr5Kf6+OF14WVjkE6t3xMio= cache.flakehub.com-5:zB96CRlL7tiPtzA9/WKyPkp3A2vqxqgdgyTVNGShPDU= cache.flakehub.com-6:W4EGFwAGgBj3he7c5fNh9NkOXw0PUVaxygCVKeuvaqU= cache.flakehub.com-7:mvxJ2DZVHn/kRxlIaxYNMuDG1OvMckZu32um1TadOR8= cache.flakehub.com-8:moO+OVS0mnTjBTcOUh2kYLQEd59ExzyoW1QgQ8XAARQ= cache.flakehub.com-9:wChaSeTI6TeCuV/Sg2513ZIM9i0qJaYsF+lZCXg0J6o= cache.flakehub.com-10:2GqeNlIp6AKp4EF2MVbE1kBOp9iBSyo0UPR9KoR0o1Y=
|
||||
bash-prompt-prefix = (nix:$name)\040
|
||||
max-jobs = auto
|
||||
extra-nix-path = nixpkgs=flake:nixpkgs
|
||||
upgrade-nix-store-path-url = https://install.determinate.systems/nix-upgrade/stable/universal
|
||||
|
||||
!include nix.custom.conf
|
||||
@@ -0,0 +1,3 @@
|
||||
# Written by https://github.com/NixOS/nix-installer
|
||||
# The contents below are based on options specified at installation time.
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
# Generated by https://github.com/NixOS/nix-installer
|
||||
# See `/nix/nix-installer --version` for the version details.
|
||||
|
||||
extra-experimental-features = nix-command flakes
|
||||
always-allow-substitutes = true
|
||||
bash-prompt-prefix = (nix:$name)\040
|
||||
max-jobs = auto
|
||||
extra-nix-path = nixpkgs=flake:nixpkgs
|
||||
|
||||
!include nix.custom.conf
|
||||
@@ -0,0 +1,11 @@
|
||||
# Generated by https://install.lix.systems/.
|
||||
# See `/nix/lix-installer --version` for the version details.
|
||||
|
||||
extra-experimental-features = nix-command
|
||||
always-allow-substitutes = true
|
||||
extra-trusted-substituters = https://cache.lix.systems
|
||||
extra-trusted-public-keys = cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o=
|
||||
bash-prompt-prefix = (nix:$name)\040
|
||||
max-jobs = auto
|
||||
|
||||
!include nix.custom.conf
|
||||
@@ -0,0 +1,3 @@
|
||||
# Written by https://install.lix.systems/.
|
||||
# The contents below are based on options specified at installation time.
|
||||
|
||||
@@ -0,0 +1,81 @@
|
||||
# System-wide profile for interactive zsh(1) shells.
|
||||
|
||||
# Setup user specific overrides for this in ~/.zshrc. See zshbuiltins(1)
|
||||
# and zshoptions(1) for more details.
|
||||
|
||||
# Correctly display UTF-8 with combining characters. We'll assume UTF-8 if the
|
||||
# locale(1) binary is missing entirely.
|
||||
if [[ ! -x /usr/bin/locale ]] || [[ "$(locale LC_CTYPE)" == "UTF-8" ]]; then
|
||||
setopt COMBINING_CHARS
|
||||
fi
|
||||
|
||||
# Disable the log builtin, so we don't conflict with /usr/bin/log
|
||||
disable log
|
||||
|
||||
# Save command history
|
||||
HISTFILE=${ZDOTDIR:-$HOME}/.zsh_history
|
||||
HISTSIZE=2000
|
||||
SAVEHIST=1000
|
||||
|
||||
# Beep on error
|
||||
setopt BEEP
|
||||
|
||||
# Use keycodes (generated via zkbd) if present, otherwise fallback on
|
||||
# values from terminfo
|
||||
if [[ -r ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR} ]] ; then
|
||||
source ${ZDOTDIR:-$HOME}/.zkbd/${TERM}-${VENDOR}
|
||||
else
|
||||
typeset -g -A key
|
||||
|
||||
[[ -n "$terminfo[kf1]" ]] && key[F1]=$terminfo[kf1]
|
||||
[[ -n "$terminfo[kf2]" ]] && key[F2]=$terminfo[kf2]
|
||||
[[ -n "$terminfo[kf3]" ]] && key[F3]=$terminfo[kf3]
|
||||
[[ -n "$terminfo[kf4]" ]] && key[F4]=$terminfo[kf4]
|
||||
[[ -n "$terminfo[kf5]" ]] && key[F5]=$terminfo[kf5]
|
||||
[[ -n "$terminfo[kf6]" ]] && key[F6]=$terminfo[kf6]
|
||||
[[ -n "$terminfo[kf7]" ]] && key[F7]=$terminfo[kf7]
|
||||
[[ -n "$terminfo[kf8]" ]] && key[F8]=$terminfo[kf8]
|
||||
[[ -n "$terminfo[kf9]" ]] && key[F9]=$terminfo[kf9]
|
||||
[[ -n "$terminfo[kf10]" ]] && key[F10]=$terminfo[kf10]
|
||||
[[ -n "$terminfo[kf11]" ]] && key[F11]=$terminfo[kf11]
|
||||
[[ -n "$terminfo[kf12]" ]] && key[F12]=$terminfo[kf12]
|
||||
[[ -n "$terminfo[kf13]" ]] && key[F13]=$terminfo[kf13]
|
||||
[[ -n "$terminfo[kf14]" ]] && key[F14]=$terminfo[kf14]
|
||||
[[ -n "$terminfo[kf15]" ]] && key[F15]=$terminfo[kf15]
|
||||
[[ -n "$terminfo[kf16]" ]] && key[F16]=$terminfo[kf16]
|
||||
[[ -n "$terminfo[kf17]" ]] && key[F17]=$terminfo[kf17]
|
||||
[[ -n "$terminfo[kf18]" ]] && key[F18]=$terminfo[kf18]
|
||||
[[ -n "$terminfo[kf19]" ]] && key[F19]=$terminfo[kf19]
|
||||
[[ -n "$terminfo[kf20]" ]] && key[F20]=$terminfo[kf20]
|
||||
[[ -n "$terminfo[kbs]" ]] && key[Backspace]=$terminfo[kbs]
|
||||
[[ -n "$terminfo[kich1]" ]] && key[Insert]=$terminfo[kich1]
|
||||
[[ -n "$terminfo[kdch1]" ]] && key[Delete]=$terminfo[kdch1]
|
||||
[[ -n "$terminfo[khome]" ]] && key[Home]=$terminfo[khome]
|
||||
[[ -n "$terminfo[kend]" ]] && key[End]=$terminfo[kend]
|
||||
[[ -n "$terminfo[kpp]" ]] && key[PageUp]=$terminfo[kpp]
|
||||
[[ -n "$terminfo[knp]" ]] && key[PageDown]=$terminfo[knp]
|
||||
[[ -n "$terminfo[kcuu1]" ]] && key[Up]=$terminfo[kcuu1]
|
||||
[[ -n "$terminfo[kcub1]" ]] && key[Left]=$terminfo[kcub1]
|
||||
[[ -n "$terminfo[kcud1]" ]] && key[Down]=$terminfo[kcud1]
|
||||
[[ -n "$terminfo[kcuf1]" ]] && key[Right]=$terminfo[kcuf1]
|
||||
fi
|
||||
|
||||
# Default key bindings
|
||||
[[ -n ${key[Delete]} ]] && bindkey "${key[Delete]}" delete-char
|
||||
[[ -n ${key[Home]} ]] && bindkey "${key[Home]}" beginning-of-line
|
||||
[[ -n ${key[End]} ]] && bindkey "${key[End]}" end-of-line
|
||||
[[ -n ${key[Up]} ]] && bindkey "${key[Up]}" up-line-or-search
|
||||
[[ -n ${key[Down]} ]] && bindkey "${key[Down]}" down-line-or-search
|
||||
|
||||
# Default prompt
|
||||
PS1="%n@%m %1~ %# "
|
||||
|
||||
# Useful support for interacting with Terminal.app or other terminal programs
|
||||
[ -r "/etc/zshrc_$TERM_PROGRAM" ] && . "/etc/zshrc_$TERM_PROGRAM"
|
||||
|
||||
# Nix
|
||||
if [ -e '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh' ]; then
|
||||
. '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh'
|
||||
fi
|
||||
# End Nix
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
# Generated by https://install.lix.systems/.
|
||||
# See `/nix/lix-installer --version` for the version details.
|
||||
|
||||
extra-experimental-features = nix-command flakes
|
||||
always-allow-substitutes = true
|
||||
extra-trusted-substituters = https://cache.lix.systems
|
||||
extra-trusted-public-keys = cache.lix.systems:aBnZUw8zA7H35Cz2RyKFVs3H4PlGTLawyY5KRbvJR8o=
|
||||
bash-prompt-prefix = (nix:$name)\040
|
||||
max-jobs = auto
|
||||
extra-nix-path = nixpkgs=flake:nixpkgs
|
||||
|
||||
!include nix.custom.conf
|
||||
@@ -0,0 +1,12 @@
|
||||
# System-wide profile for interactive zsh(1) login shells.
|
||||
|
||||
# Setup user specific overrides for this in ~/.zprofile. See zshbuiltins(1)
|
||||
# and zshoptions(1) for more details.
|
||||
|
||||
if [ -z "$LANG" ]; then
|
||||
export LANG=C.UTF-8
|
||||
fi
|
||||
|
||||
if [ -x /usr/libexec/path_helper ]; then
|
||||
eval `/usr/libexec/path_helper -s`
|
||||
fi
|
||||
@@ -30,7 +30,7 @@ let
|
||||
declarations = map
|
||||
(decl:
|
||||
if lib.hasPrefix (toString prefix) (toString decl) then
|
||||
gitHubDeclaration "LnL7" "nix-darwin" revision
|
||||
gitHubDeclaration "nix-darwin" "nix-darwin" revision
|
||||
(lib.removePrefix "/"
|
||||
(lib.removePrefix (toString prefix) (toString decl)))
|
||||
# TODO: handle this in a better way (may require upstream
|
||||
@@ -53,7 +53,7 @@ in rec {
|
||||
substitute \
|
||||
${optionsDoc.optionsJSON}/nix-support/hydra-build-products \
|
||||
$out/nix-support/hydra-build-products \
|
||||
--replace \
|
||||
--replace-fail \
|
||||
'${optionsDoc.optionsJSON}/share/doc/nixos' \
|
||||
"$out/share/doc/darwin"
|
||||
'';
|
||||
@@ -74,8 +74,8 @@ in rec {
|
||||
cp -r ${pkgs.documentation-highlighter} $dst/highlightjs
|
||||
|
||||
substitute ${./manual.md} manual.md \
|
||||
--replace '@DARWIN_VERSION@' "${version}" \
|
||||
--replace \
|
||||
--replace-fail '@DARWIN_VERSION@' "${version}" \
|
||||
--replace-fail \
|
||||
'@DARWIN_OPTIONS_JSON@' \
|
||||
${optionsJSON}/share/doc/darwin/options.json
|
||||
|
||||
@@ -94,8 +94,7 @@ in rec {
|
||||
--stylesheet highlightjs/mono-blue.css \
|
||||
--script ./highlightjs/highlight.pack.js \
|
||||
--script ./highlightjs/loader.js \
|
||||
--toc-depth 1 \
|
||||
--chunk-toc-depth 1 \
|
||||
--sidebar-depth 1 \
|
||||
./manual.md \
|
||||
$dst/index.html
|
||||
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<title>nix-darwin</title>
|
||||
<script>
|
||||
window.location.replace("https://github.com/nix-darwin/nix-darwin#readme");
|
||||
</script>
|
||||
<noscript>
|
||||
<meta
|
||||
http-equiv="refresh"
|
||||
content="0; url=https://github.com/nix-darwin/nix-darwin#readme">
|
||||
</noscript>
|
||||
</head>
|
||||
<body>
|
||||
<h1>nix-darwin</h1>
|
||||
<p>
|
||||
nix-darwin is a declarative configuration system for macOS, based
|
||||
on Nix. See the
|
||||
<a href="https://github.com/nix-darwin/nix-darwin#readme">GitHub
|
||||
repository</a> for more information.
|
||||
</p>
|
||||
</body>
|
||||
</html>
|
||||
+12
-14
@@ -37,7 +37,7 @@ assert enableNixpkgsReleaseCheck -> checkRelease lib || throw ''
|
||||
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/NIXPKGS-BRANCH";
|
||||
nix-darwin.url = "github:LnL7/nix-darwin/NIX-DARWIN-BRANCH";
|
||||
nix-darwin.url = "github:nix-darwin/nix-darwin/NIX-DARWIN-BRANCH";
|
||||
nix-darwin.inputs.nixpkgs.follows = "nixpkgs";
|
||||
# …
|
||||
};
|
||||
@@ -46,7 +46,7 @@ assert enableNixpkgsReleaseCheck -> checkRelease lib || throw ''
|
||||
|
||||
$ sudo nix-channel --list
|
||||
nixpkgs https://nixos.org/channels/NIXPKGS-BRANCH
|
||||
darwin https://github.com/LnL7/nix-darwin/archive/NIX-DARWIN-BRANCH.tar.gz
|
||||
darwin https://github.com/nix-darwin/nix-darwin/archive/NIX-DARWIN-BRANCH.tar.gz
|
||||
…
|
||||
$ nix-channel --list
|
||||
…
|
||||
@@ -58,12 +58,12 @@ assert enableNixpkgsReleaseCheck -> checkRelease lib || throw ''
|
||||
You can then fix your channels like this:
|
||||
|
||||
$ sudo nix-channel --add https://nixos.org/channels/NIXPKGS-BRANCH nixpkgs
|
||||
$ sudo nix-channel --add https://github.com/LnL7/nix-darwin/archive/NIX-DARWIN-BRANCH.tar.gz darwin
|
||||
$ sudo nix-channel --add https://github.com/nix-darwin/nix-darwin/archive/NIX-DARWIN-BRANCH.tar.gz darwin
|
||||
$ sudo nix-channel --update
|
||||
|
||||
After that, activating your system again should work correctly. If it
|
||||
doesn’t, please open an issue at
|
||||
<https://github.com/LnL7/nix-darwin/issues/new> and include as much
|
||||
<https://github.com/nix-darwin/nix-darwin/issues/new> and include as much
|
||||
information as possible.
|
||||
'';
|
||||
|
||||
@@ -77,17 +77,15 @@ let
|
||||
};
|
||||
};
|
||||
|
||||
eval = lib.evalModules (builtins.removeAttrs args [ "lib" ] // {
|
||||
eval = lib.evalModules (builtins.removeAttrs args [ "lib" "enableNixpkgsReleaseCheck" ] // {
|
||||
class = "darwin";
|
||||
modules = modules ++ [ argsModule ] ++ baseModules;
|
||||
specialArgs = { modulesPath = builtins.toString ./modules; } // specialArgs;
|
||||
});
|
||||
in
|
||||
|
||||
{
|
||||
inherit (eval._module.args) pkgs;
|
||||
inherit (eval) options config;
|
||||
inherit (eval) _module;
|
||||
|
||||
system = eval.config.system.build.toplevel;
|
||||
}
|
||||
|
||||
withExtraAttrs = configuration: configuration // {
|
||||
inherit (configuration._module.args) pkgs;
|
||||
system = configuration.config.system.build.toplevel;
|
||||
extendModules = args: withExtraAttrs (configuration.extendModules args);
|
||||
};
|
||||
in withExtraAttrs eval
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
{
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
{
|
||||
options.flake.darwinConfigurations = lib.mkOption {
|
||||
type = lib.types.lazyAttrsOf lib.types.raw;
|
||||
default = { };
|
||||
description = "Darwin system configurations";
|
||||
};
|
||||
}
|
||||
Generated
+3
-3
@@ -2,11 +2,11 @@
|
||||
"nodes": {
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1736241350,
|
||||
"narHash": "sha256-CHd7yhaDigUuJyDeX0SADbTM9FXfiWaeNyY34FL1wQU=",
|
||||
"lastModified": 1783279667,
|
||||
"narHash": "sha256-/NAkDSsve+GNM0Bt6tleJdCGfsTlK89nPjkVOzZMo0s=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "8c9fd3e564728e90829ee7dbac6edc972971cd0f",
|
||||
"rev": "f205b5574fd0cb7da5b702a2da51507b7f4fdd1b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -56,6 +56,8 @@
|
||||
darwin-uninstaller = prev.callPackage ./pkgs/darwin-uninstaller { };
|
||||
};
|
||||
|
||||
flakeModules.default = ./flake-module.nix;
|
||||
|
||||
darwinModules.hydra = ./modules/examples/hydra.nix;
|
||||
darwinModules.lnl = ./modules/examples/lnl.nix;
|
||||
darwinModules.simple = ./modules/examples/simple.nix;
|
||||
@@ -78,6 +80,13 @@
|
||||
default = self.packages.${system}.darwin-rebuild;
|
||||
|
||||
inherit (pkgs) darwin-option darwin-rebuild darwin-version darwin-uninstaller;
|
||||
|
||||
# TODO: Include manuals for active release branches in the website.
|
||||
# (This may involve moving it to a separate repository.)
|
||||
website = pkgs.linkFarm "nix-darwin-website" {
|
||||
"index.html" = ./doc/website/index.html;
|
||||
manual = "${self.packages.${system}.manualHTML}/share/doc/darwin";
|
||||
};
|
||||
})));
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,149 @@
|
||||
# This module defines the packages that appear in
|
||||
# /run/current-system/sw.
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
|
||||
makeDrvBinPath = lib.concatMapStringsSep ":" (p: if lib.isDerivation p then "${p}/bin" else p);
|
||||
|
||||
defaultPackageNames = [ ];
|
||||
defaultPackages = map (
|
||||
n:
|
||||
let
|
||||
pkg = pkgs.${n};
|
||||
in
|
||||
lib.setPrio ((pkg.meta.priority or lib.meta.defaultPriority) + 3) pkg
|
||||
) defaultPackageNames;
|
||||
defaultPackagesText = "[ ${lib.concatMapStringsSep " " (n: "pkgs.${n}") defaultPackageNames} ]";
|
||||
|
||||
in
|
||||
|
||||
{
|
||||
imports = [
|
||||
(lib.mkRenamedOptionModule ["environment" "postBuild"] ["environment" "extraSetup"])
|
||||
];
|
||||
|
||||
options = {
|
||||
|
||||
environment = {
|
||||
systemPath = lib.mkOption {
|
||||
type = lib.types.listOf (lib.types.either lib.types.path lib.types.str);
|
||||
description = "The set of paths that are added to PATH.";
|
||||
apply = x: if lib.isList x then makeDrvBinPath x else x;
|
||||
};
|
||||
|
||||
systemPackages = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.package;
|
||||
default = [ ];
|
||||
example = lib.literalExpression "[ pkgs.firefox pkgs.thunderbird ]";
|
||||
description = ''
|
||||
The set of packages that appear in
|
||||
/run/current-system/sw. These packages are
|
||||
automatically available to all users, and are
|
||||
automatically updated every time you rebuild the system
|
||||
configuration. (The latter is the main difference with
|
||||
installing them in the default profile,
|
||||
{file}`/nix/var/nix/profiles/default`.
|
||||
'';
|
||||
};
|
||||
|
||||
defaultPackages = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.package;
|
||||
default = defaultPackages;
|
||||
defaultText = lib.literalMD ''
|
||||
these packages, with their `meta.priority` numerically increased
|
||||
(thus lowering their installation priority):
|
||||
|
||||
${defaultPackagesText}
|
||||
'';
|
||||
example = [ ];
|
||||
description = ''
|
||||
Set of default packages that aren't strictly necessary
|
||||
for a running system, entries can be removed for a more
|
||||
minimal NixOS installation.
|
||||
|
||||
Like with systemPackages, packages are installed to
|
||||
{file}`/run/current-system/sw`. They are
|
||||
automatically available to all users, and are
|
||||
automatically updated every time you rebuild the system
|
||||
configuration.
|
||||
'';
|
||||
};
|
||||
|
||||
pathsToLink = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
# According to https://github.com/NixOS/nixpkgs/blob/2795c506fe8fb7b03c36ccb51f75b6df0ab2553f/nixos/modules/config/system-path.nix#L108-L109
|
||||
# `/lib` needs to be added to make NSS modules work, however currently we don't add it
|
||||
# and it's unclear whether the comment applies on macOS as well.
|
||||
default = [ ];
|
||||
example = [ "/share/doc" ];
|
||||
description = "List of directories to be symlinked in {file}`/run/current-system/sw`.";
|
||||
};
|
||||
|
||||
extraOutputsToInstall = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
example = [
|
||||
"dev"
|
||||
"info"
|
||||
];
|
||||
description = ''
|
||||
Entries listed here will be appended to the `meta.outputsToInstall` attribute for each package in `environment.systemPackages`, and the files from the corresponding derivation outputs symlinked into {file}`/run/current-system/sw`.
|
||||
|
||||
For example, this can be used to install the `dev` and `info` outputs for all packages in the system environment, if they are available.
|
||||
|
||||
To use specific outputs instead of configuring them globally, select the corresponding attribute on the package derivation, e.g. `libxml2.dev` or `coreutils.info`.
|
||||
'';
|
||||
};
|
||||
|
||||
extraSetup = lib.mkOption {
|
||||
type = lib.types.lines;
|
||||
default = "";
|
||||
description = "Shell fragments to be run after the system environment has been created. This should only be used for things that need to modify the internals of the environment, e.g. generating MIME caches. The environment being built can be accessed at $out.";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
system = {
|
||||
|
||||
path = lib.mkOption {
|
||||
internal = true;
|
||||
description = ''
|
||||
The packages you want in the system environment.
|
||||
'';
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
config = {
|
||||
|
||||
environment.systemPackages = config.environment.defaultPackages;
|
||||
|
||||
environment.pathsToLink = [
|
||||
"/bin"
|
||||
"/share/locale"
|
||||
];
|
||||
|
||||
system.path = pkgs.buildEnv {
|
||||
name = "system-path";
|
||||
paths = config.environment.systemPackages;
|
||||
inherit (config.environment) pathsToLink extraOutputsToInstall;
|
||||
ignoreCollisions = true;
|
||||
# !!! Hacky, should modularise.
|
||||
# outputs TODO: note that the tools will often not be linked by default
|
||||
postBuild = ''
|
||||
# Remove wrapped binaries, they shouldn't be accessible via PATH.
|
||||
find $out/bin -maxdepth 1 -name ".*-wrapped" -type l -delete
|
||||
|
||||
${config.environment.extraSetup}
|
||||
'';
|
||||
};
|
||||
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
# This module manages the terminfo database
|
||||
# and its integration in the system.
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
{
|
||||
|
||||
options = {
|
||||
environment.enableAllTerminfo = lib.mkOption {
|
||||
default = false;
|
||||
type = lib.types.bool;
|
||||
description = ''
|
||||
Whether to install all terminfo outputs
|
||||
'';
|
||||
};
|
||||
|
||||
security.sudo.keepTerminfo = lib.mkOption {
|
||||
default = true;
|
||||
type = lib.types.bool;
|
||||
description = ''
|
||||
Whether to preserve the `TERMINFO` and `TERMINFO_DIRS`
|
||||
environment variables, for `root` and the `admin` group.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
|
||||
# This should not contain packages that are broken or can't build, since it
|
||||
# will break this expression
|
||||
#
|
||||
# can be generated with:
|
||||
# lib.attrNames (lib.filterAttrs
|
||||
# (_: drv: (builtins.tryEval (
|
||||
# lib.isDerivation drv && drv ? terminfo && drv.meta.available && !drv.meta.broken && !drv.meta.unsupported)).value)
|
||||
# pkgs)
|
||||
environment.systemPackages = lib.mkIf config.environment.enableAllTerminfo (
|
||||
map (x: x.terminfo) (
|
||||
with pkgs.pkgsBuildBuild;
|
||||
[
|
||||
alacritty
|
||||
alacritty-graphics
|
||||
ghostty-bin
|
||||
kitty
|
||||
mtm
|
||||
rio
|
||||
rxvt-unicode-unwrapped
|
||||
rxvt-unicode-unwrapped-emoji
|
||||
st
|
||||
tmux
|
||||
wezterm
|
||||
]
|
||||
)
|
||||
);
|
||||
|
||||
environment.pathsToLink = [
|
||||
"/share/terminfo"
|
||||
];
|
||||
|
||||
environment.etc.terminfo = {
|
||||
source = "${config.system.path}/share/terminfo";
|
||||
};
|
||||
|
||||
# TODO: use `environment.profileRelativeSessionVariables`
|
||||
environment.variables = {
|
||||
TERMINFO_DIRS = map (path: path + "/share/terminfo") config.environment.profiles ++ [ "/usr/share/terminfo" ];
|
||||
};
|
||||
|
||||
environment.extraInit = ''
|
||||
# reset TERM with new TERMINFO available (if any)
|
||||
export TERM=$TERM
|
||||
'';
|
||||
|
||||
security =
|
||||
let
|
||||
extraConfig = ''
|
||||
|
||||
# Keep terminfo database for root and %admin.
|
||||
Defaults:root,%admin env_keep+=TERMINFO_DIRS
|
||||
Defaults:root,%admin env_keep+=TERMINFO
|
||||
'';
|
||||
in
|
||||
lib.mkIf config.security.sudo.keepTerminfo {
|
||||
sudo = { inherit extraConfig; };
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,4 +1,4 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
{ options, config, lib, pkgs, ... }:
|
||||
|
||||
with lib;
|
||||
|
||||
@@ -11,13 +11,10 @@ let
|
||||
aliasCommands =
|
||||
mapAttrsToList (n: v: ''alias ${n}=${escapeShellArg v}'')
|
||||
(filterAttrs (k: v: v != null) cfg.shellAliases);
|
||||
|
||||
makeDrvBinPath = concatMapStringsSep ":" (p: if isDerivation p then "${p}/bin" else p);
|
||||
in
|
||||
|
||||
{
|
||||
imports = [
|
||||
(mkRenamedOptionModule ["environment" "postBuild"] ["environment" "extraSetup"])
|
||||
(mkRemovedOptionModule [ "environment" "loginShell" ] ''
|
||||
This option was only used to change the default command in tmux.
|
||||
|
||||
@@ -26,49 +23,30 @@ in
|
||||
];
|
||||
|
||||
options = {
|
||||
environment.systemPackages = mkOption {
|
||||
type = types.listOf types.package;
|
||||
default = [];
|
||||
example = literalExpression "[ pkgs.curl pkgs.vim ]";
|
||||
description = ''
|
||||
The set of packages that appear in
|
||||
/run/current-system/sw. These packages are
|
||||
automatically available to all users, and are
|
||||
automatically updated every time you rebuild the system
|
||||
configuration. (The latter is the main difference with
|
||||
installing them in the default profile,
|
||||
{file}`/nix/var/nix/profiles/default`.
|
||||
'';
|
||||
};
|
||||
|
||||
environment.systemPath = mkOption {
|
||||
type = types.listOf (types.either types.path types.str);
|
||||
description = "The set of paths that are added to PATH.";
|
||||
apply = x: if isList x then makeDrvBinPath x else x;
|
||||
};
|
||||
|
||||
environment.profiles = mkOption {
|
||||
type = types.listOf types.str;
|
||||
description = "A list of profiles used to setup the global environment.";
|
||||
};
|
||||
|
||||
environment.extraOutputsToInstall = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
example = [ "doc" "info" "devdoc" ];
|
||||
description = "List of additional package outputs to be symlinked into {file}`/run/current-system/sw`.";
|
||||
};
|
||||
|
||||
environment.pathsToLink = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
example = [ "/share/doc" ];
|
||||
description = "List of directories to be symlinked in {file}`/run/current-system/sw`.";
|
||||
};
|
||||
|
||||
environment.darwinConfig = mkOption {
|
||||
type = types.either types.path types.str;
|
||||
default = "$HOME/.nixpkgs/darwin-configuration.nix";
|
||||
type = types.nullOr (types.either types.path types.str);
|
||||
default =
|
||||
if config.nixpkgs.flake.setNixPath then
|
||||
# Don’t set this for flake‐based systems.
|
||||
null
|
||||
else if config.system.stateVersion >= 6 then
|
||||
"/etc/nix-darwin/configuration.nix"
|
||||
else
|
||||
"${config.system.primaryUserHome}/.nixpkgs/darwin-configuration.nix";
|
||||
defaultText = literalExpression ''
|
||||
if config.nixpkgs.flake.setNixPath then
|
||||
# Don’t set this for flake‐based systems.
|
||||
null
|
||||
else if config.system.stateVersion >= 6 then
|
||||
"/etc/nix-darwin/configuration.nix"
|
||||
else
|
||||
"''${config.system.primaryUserHome}/.nixpkgs/darwin-configuration.nix"
|
||||
'';
|
||||
description = ''
|
||||
The path of the darwin configuration.nix used to configure the system,
|
||||
this updates the default darwin-config entry in NIX_PATH. Since this
|
||||
@@ -110,7 +88,7 @@ in
|
||||
description = ''
|
||||
Shell script code called during global environment initialisation
|
||||
after all variables and profileVariables have been set.
|
||||
This code is asumed to be shell-independent, which means you should
|
||||
This code is assumed to be shell-independent, which means you should
|
||||
stick to pure sh without sh word split.
|
||||
'';
|
||||
};
|
||||
@@ -144,24 +122,23 @@ in
|
||||
'';
|
||||
type = types.lines;
|
||||
};
|
||||
|
||||
environment.extraSetup = mkOption {
|
||||
type = types.lines;
|
||||
default = "";
|
||||
description = ''
|
||||
Shell fragments to be run after the system environment has been created.
|
||||
This should only be used for things that need to modify the internals
|
||||
of the environment, e.g. generating MIME caches.
|
||||
The environment being built can be accessed at $out.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
|
||||
# This is horrible, sorry.
|
||||
system.requiresPrimaryUser = mkIf (
|
||||
config.nix.enable
|
||||
&& !config.nixpkgs.flake.setNixPath
|
||||
&& config.system.stateVersion < 6
|
||||
&& options.environment.darwinConfig.highestPrio == (mkOptionDefault {}).priority
|
||||
) [
|
||||
"environment.darwinConfig"
|
||||
];
|
||||
|
||||
environment.systemPath = mkMerge [
|
||||
[ (makeBinPath cfg.profiles) ]
|
||||
(mkOrder 1200 [ "/usr/local/bin:/usr/bin:/usr/sbin:/bin:/sbin" ])
|
||||
(mkOrder 1200 [ "/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin" ])
|
||||
];
|
||||
|
||||
# Use user, default and system profiles.
|
||||
@@ -170,16 +147,7 @@ in
|
||||
[ "/run/current-system/sw" "/nix/var/nix/profiles/default" ]
|
||||
];
|
||||
|
||||
environment.pathsToLink = [
|
||||
"/bin"
|
||||
"/share/locale"
|
||||
"/share/terminfo"
|
||||
];
|
||||
|
||||
environment.extraInit = ''
|
||||
# reset TERM with new TERMINFO available (if any)
|
||||
export TERM=$TERM
|
||||
|
||||
export NIX_USER_PROFILE_DIR="/nix/var/nix/profiles/per-user/$USER"
|
||||
export NIX_PROFILES="${concatStringsSep " " (reverseList cfg.profiles)}"
|
||||
'';
|
||||
@@ -188,19 +156,10 @@ in
|
||||
{
|
||||
XDG_CONFIG_DIRS = map (path: path + "/etc/xdg") cfg.profiles;
|
||||
XDG_DATA_DIRS = map (path: path + "/share") cfg.profiles;
|
||||
TERMINFO_DIRS = map (path: path + "/share/terminfo") cfg.profiles ++ [ "/usr/share/terminfo" ];
|
||||
EDITOR = mkDefault "nano";
|
||||
PAGER = mkDefault "less -R";
|
||||
};
|
||||
|
||||
system.path = pkgs.buildEnv {
|
||||
name = "system-path";
|
||||
paths = cfg.systemPackages;
|
||||
postBuild = cfg.extraSetup;
|
||||
ignoreCollisions = true;
|
||||
inherit (cfg) pathsToLink extraOutputsToInstall;
|
||||
};
|
||||
|
||||
system.build.setEnvironment = pkgs.writeText "set-environment" ''
|
||||
# Prevent this file from being sourced by child shells.
|
||||
export __NIX_DARWIN_SET_ENVIRONMENT_DONE=1
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
nix-darwin.url = "github:LnL7/nix-darwin/master";
|
||||
nix-darwin.url = "github:nix-darwin/nix-darwin/master";
|
||||
nix-darwin.inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
@@ -27,7 +27,7 @@
|
||||
|
||||
# Used for backwards compatibility, please read the changelog before changing.
|
||||
# $ darwin-rebuild changelog
|
||||
system.stateVersion = 5;
|
||||
system.stateVersion = 6;
|
||||
|
||||
# The platform the configuration will be used on.
|
||||
nixpkgs.hostPlatform = "aarch64-darwin";
|
||||
|
||||
@@ -43,5 +43,5 @@ in
|
||||
echo "ok"
|
||||
'';
|
||||
|
||||
system.stateVersion = 5;
|
||||
system.stateVersion = 6;
|
||||
}
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
{ config, lib, inputs, pkgs, ... }:
|
||||
|
||||
{
|
||||
system.primaryUser = "lnl";
|
||||
|
||||
system.defaults.NSGlobalDomain.AppleKeyboardUIMode = 3;
|
||||
system.defaults.NSGlobalDomain.ApplePressAndHoldEnabled = false;
|
||||
system.defaults.NSGlobalDomain.InitialKeyRepeat = 10;
|
||||
@@ -48,8 +50,6 @@
|
||||
pkgs.jq
|
||||
pkgs.ripgrep
|
||||
pkgs.shellcheck
|
||||
|
||||
pkgs.qes
|
||||
];
|
||||
|
||||
services.yabai.enable = true;
|
||||
@@ -199,7 +199,7 @@
|
||||
programs.zsh.enableFzfGit = true;
|
||||
programs.zsh.enableFzfHistory = true;
|
||||
|
||||
programs.zsh.variables.cfg = "$HOME/.config/nixpkgs/darwin/configuration.nix";
|
||||
programs.zsh.variables.cfg = "/etc/nix-darwin/configuration.nix";
|
||||
programs.zsh.variables.darwin = "$HOME/.nix-defexpr/darwin";
|
||||
programs.zsh.variables.nixpkgs = "$HOME/.nix-defexpr/nixpkgs";
|
||||
|
||||
@@ -319,8 +319,7 @@
|
||||
# path = /etc/per-user/lnl/gitconfig
|
||||
# environment.etc."per-user/lnl/gitconfig".text = builtins.readFile "${inputs.dotfiles}/git/gitconfig";
|
||||
|
||||
nix.configureBuildUsers = true;
|
||||
nix.nrBuildUsers = 32;
|
||||
|
||||
system.stateVersion = 5;
|
||||
system.stateVersion = 6;
|
||||
}
|
||||
|
||||
@@ -7,13 +7,10 @@
|
||||
[ pkgs.vim
|
||||
];
|
||||
|
||||
# Use custom location for configuration.nix.
|
||||
environment.darwinConfig = "$HOME/.config/nix-darwin/configuration.nix";
|
||||
|
||||
# Enable alternative shell support in nix-darwin.
|
||||
# programs.fish.enable = true;
|
||||
|
||||
# Used for backwards compatibility, please read the changelog before changing.
|
||||
# $ darwin-rebuild changelog
|
||||
system.stateVersion = 5;
|
||||
system.stateVersion = 6;
|
||||
}
|
||||
|
||||
+370
-125
@@ -12,7 +12,7 @@ let
|
||||
|
||||
mkBrewfileSectionString = heading: entries: optionalString (entries != [ ]) ''
|
||||
# ${heading}
|
||||
${concatMapStringsSep "\n" (v: v.brewfileLine or v) entries}
|
||||
${concatStringsSep "\n" (unique (map (v: v.brewfileLine or v) entries))}
|
||||
|
||||
'';
|
||||
|
||||
@@ -28,9 +28,23 @@ let
|
||||
mkBrewfileLineOptionsListString = attrs:
|
||||
concatStringsSep ", " (mapAttrsToList (n: v: "${n}: ${v}") attrs);
|
||||
|
||||
# Renders a Brewfile option that can be either a bool or a Ruby symbol (e.g. `:overwrite`).
|
||||
mkBrewfileLineBoolOrSymbolString = name: config: sCfg:
|
||||
optionalString (hasAttr name sCfg) (
|
||||
", ${name}: " + (
|
||||
if isBool config.${name} then sCfg.${name}
|
||||
else ":${config.${name}}"
|
||||
)
|
||||
);
|
||||
|
||||
|
||||
# Option and submodule helper functions ----------------------------------------------------------
|
||||
|
||||
mkShellIntegrationOption = shell: mkEnableOption ''
|
||||
Homebrew ${shell} shell integration, which sets up Homebrew's environment
|
||||
and shell completions
|
||||
'';
|
||||
|
||||
mkNullOrBoolOption = args: mkOption (args // {
|
||||
type = types.nullOr types.bool;
|
||||
default = null;
|
||||
@@ -54,37 +68,44 @@ let
|
||||
# Submodules -------------------------------------------------------------------------------------
|
||||
# Option values and descriptions of Brewfile entries are sourced/derived from:
|
||||
# * `brew` manpage: https://docs.brew.sh/Manpage
|
||||
# * `brew bundle` source files (at https://github.com/Homebrew/homebrew-bundle/tree/9fffe077f1a5a722ed5bd26a87ed622e8cb64e0c):
|
||||
# * lib/bundle/dsl.rb
|
||||
# * lib/bundle/{brew,cask,tap}_installer.rb
|
||||
# * spec/bundle/{brew,cask,tap}_installer_spec.rb
|
||||
# * `brew bundle` source files (at https://github.com/Homebrew/brew/tree/master/Library/Homebrew/bundle):
|
||||
# * dsl.rb
|
||||
# * {brew,cask,tap}_installer.rb
|
||||
# * ../test/bundle/{brew,cask,tap}_installer_spec.rb
|
||||
|
||||
onActivationOptions = { config, ... }: {
|
||||
options = {
|
||||
cleanup = mkOption {
|
||||
type = types.enum [ "none" "uninstall" "zap" ];
|
||||
type = types.enum [ "none" "check" "uninstall" "zap" ];
|
||||
default = "none";
|
||||
example = "uninstall";
|
||||
description = ''
|
||||
This option manages what happens to formulae installed by Homebrew, that aren't present in
|
||||
This option manages what happens to packages installed by Homebrew that aren't present in
|
||||
the Brewfile generated by this module, during {command}`nix-darwin` system
|
||||
activation.
|
||||
|
||||
When set to `"none"` (the default), formulae not present in the generated
|
||||
When set to `"none"` (the default), packages not present in the generated
|
||||
Brewfile are left installed.
|
||||
|
||||
When set to `"check"`, {command}`nix-darwin` verifies during system activation that no
|
||||
Homebrew packages (taps, formulae, casks, etc.) are installed that aren't present in the
|
||||
generated Brewfile. If extra packages are found, activation fails with a list of them.
|
||||
Note that when this check fails during {command}`darwin-rebuild switch`, the entire
|
||||
system activation is aborted and no other configuration changes will be applied until
|
||||
the issue is resolved.
|
||||
|
||||
When set to `"uninstall"`, {command}`nix-darwin` invokes
|
||||
{command}`brew bundle [install]` with the {command}`--cleanup` flag. This
|
||||
uninstalls all formulae not listed in generated Brewfile, i.e.,
|
||||
{command}`brew uninstall` is run for those formulae.
|
||||
uninstalls all packages not listed in the generated Brewfile, i.e.,
|
||||
{command}`brew uninstall` is run for those packages.
|
||||
|
||||
When set to `"zap"`, {command}`nix-darwin` invokes
|
||||
{command}`brew bundle [install]` with the {command}`--cleanup --zap`
|
||||
flags. This uninstalls all formulae not listed in the generated Brewfile, and if the
|
||||
formula is a cask, removes all files associated with that cask. In other words,
|
||||
{command}`brew uninstall --zap` is run for all those formulae.
|
||||
flags. This uninstalls all packages not listed in the generated Brewfile, and if the
|
||||
package is a cask, removes all files associated with that cask. In other words,
|
||||
{command}`brew uninstall --zap` is run for all those packages.
|
||||
|
||||
If you plan on exclusively using {command}`nix-darwin` to manage formulae
|
||||
If you plan on exclusively using {command}`nix-darwin` to manage packages
|
||||
installed by Homebrew, you probably want to set this option to
|
||||
`"uninstall"` or `"zap"`.
|
||||
'';
|
||||
@@ -97,7 +118,7 @@ let
|
||||
{command}`nix-darwin` system activation. The default is `false`
|
||||
so that repeated invocations of {command}`darwin-rebuild switch` are idempotent.
|
||||
|
||||
Note that Homebrew auto-updates when it's been more then 5 minutes since it last updated.
|
||||
Note that Homebrew auto-updates when it's been more than 5 minutes since it last updated.
|
||||
|
||||
Although auto-updating is disabled by default during system activation, note that Homebrew
|
||||
will auto-update when you manually invoke certain Homebrew commands. To modify this
|
||||
@@ -121,6 +142,26 @@ let
|
||||
activation.
|
||||
'';
|
||||
};
|
||||
extraEnv = mkOption {
|
||||
type = types.attrsOf types.str;
|
||||
default = { };
|
||||
example = {
|
||||
HOMEBREW_NO_ENV_HINTS = "1";
|
||||
HOMEBREW_NO_ANALYTICS = "1";
|
||||
};
|
||||
description = ''
|
||||
Extra environment variables to set when {command}`nix-darwin` invokes
|
||||
{command}`brew bundle [install]` during system checks and activation.
|
||||
|
||||
Useful for setting Homebrew's `HOMEBREW_NO_*` variables (e.g.,
|
||||
`HOMEBREW_NO_ENV_HINTS`, `HOMEBREW_NO_ANALYTICS`, `HOMEBREW_NO_UPDATE_REPORT_NEW`)
|
||||
that aren't inherited from the user's shell environment because activation runs
|
||||
under sudo.
|
||||
|
||||
Each entry is prepended to the {command}`brew bundle` invocation in the form
|
||||
`KEY=VALUE`, alongside `HOMEBREW_NO_AUTO_UPDATE=1` when applicable.
|
||||
'';
|
||||
};
|
||||
extraFlags = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [ ];
|
||||
@@ -131,17 +172,31 @@ let
|
||||
'';
|
||||
};
|
||||
|
||||
brewBundleCmd = mkInternalOption { type = types.str; };
|
||||
brewBundleCmd = mkInternalOption { type = types.functionTo types.str; };
|
||||
};
|
||||
|
||||
config = {
|
||||
brewBundleCmd = concatStringsSep " " (
|
||||
optional (!config.autoUpdate) "HOMEBREW_NO_AUTO_UPDATE=1"
|
||||
++ [ "brew bundle --file='${brewfileFile}' --no-lock" ]
|
||||
++ optional (!config.upgrade) "--no-upgrade"
|
||||
++ optional (config.cleanup == "uninstall") "--cleanup"
|
||||
++ optional (config.cleanup == "zap") "--cleanup --zap"
|
||||
++ config.extraFlags
|
||||
brewBundleCmd = { onlyCheck }: concatStringsSep " " (
|
||||
[
|
||||
''PATH="${cfg.prefix}/bin:${lib.makeBinPath [ pkgs.mas ]}:$PATH"''
|
||||
"sudo"
|
||||
"--preserve-env=PATH"
|
||||
"--user=${escapeShellArg cfg.user}"
|
||||
"--set-home"
|
||||
"env"
|
||||
]
|
||||
++ optional (onlyCheck || !config.autoUpdate) "HOMEBREW_NO_AUTO_UPDATE=1"
|
||||
++ mapAttrsToList (k: v: "${k}=${escapeShellArg v}") config.extraEnv
|
||||
++ [ "brew bundle --file='${brewfileFile}'" ]
|
||||
++ (
|
||||
if onlyCheck then
|
||||
[ "cleanup 2>&1" ]
|
||||
else
|
||||
optional (!config.upgrade) "--no-upgrade"
|
||||
++ optional (config.cleanup == "uninstall") "--force-cleanup"
|
||||
++ optional (config.cleanup == "zap") "--zap --force-cleanup"
|
||||
++ config.extraFlags
|
||||
)
|
||||
);
|
||||
};
|
||||
};
|
||||
@@ -155,14 +210,6 @@ let
|
||||
Whether to enable Homebrew to automatically use the Brewfile that this module generates in
|
||||
the Nix store, when you manually invoke {command}`brew bundle`.
|
||||
|
||||
Enabling this option will change the default value of
|
||||
[](#opt-homebrew.global.lockfiles) to `false` since, with
|
||||
this option enabled, {command}`brew bundle [install]` will default to using the
|
||||
Brewfile that this module generates in the Nix store, unless you explicitly point it at
|
||||
another Brewfile using the `--file` flag. As a result, it will try to
|
||||
write the lockfile in the Nix store, and complain that it can't (though the command will
|
||||
run successfully regardless).
|
||||
|
||||
Implementation note: when enabled, this option sets the
|
||||
`HOMEBREW_BUNDLE_FILE` environment variable to the path of the Brewfile
|
||||
that this module generates in the Nix store, by adding it to
|
||||
@@ -178,7 +225,7 @@ let
|
||||
{command}`brew tap`, and {command}`brew bundle [install]`.
|
||||
|
||||
Note that Homebrew auto-updates when you manually invoke commands like the ones mentioned
|
||||
above if it's been more then 5 minutes since it last updated.
|
||||
above if it's been more than 5 minutes since it last updated.
|
||||
|
||||
You may want to consider disabling this option if you have
|
||||
[](#opt-homebrew.onActivation.upgrade) enabled, and
|
||||
@@ -191,31 +238,13 @@ let
|
||||
[](#opt-environment.variables).
|
||||
'';
|
||||
};
|
||||
lockfiles = mkOption {
|
||||
type = types.bool;
|
||||
default = !config.brewfile;
|
||||
defaultText = literalExpression "!config.homebrew.global.brewfile";
|
||||
description = ''
|
||||
Whether to enable Homebrew to generate lockfiles when you manually invoke
|
||||
{command}`brew bundle [install]`.
|
||||
|
||||
This option will default to `false` if
|
||||
[](#opt-homebrew.global.brewfile) is enabled since, with that option enabled,
|
||||
{command}`brew bundle [install]` will default to using the Brewfile that this
|
||||
module generates in the Nix store, unless you explicitly point it at another Brewfile
|
||||
using the `--file` flag. As a result, it will try to write the
|
||||
lockfile in the Nix store, and complain that it can't (though the command will run
|
||||
successfully regardless).
|
||||
|
||||
Implementation note: when disabled, this option sets the
|
||||
`HOMEBREW_BUNDLE_NO_LOCK` environment variable, by adding it to
|
||||
[](#opt-environment.variables).
|
||||
'';
|
||||
};
|
||||
|
||||
# The `noLock` option was replaced by `lockfiles`. Due to `homebrew.global` being a submodule,
|
||||
# we can't use `mkRemovedOptionModule`, so we leave this option definition here, and trigger
|
||||
# and error message with an assertion below if it's set by the user.
|
||||
# `noLock` was the original option; `lockfiles` replaced it (with inverted semantics).
|
||||
# Both are now dead: Homebrew Bundle removed lockfile support in Homebrew 4.4.0
|
||||
# (Oct 2024), so the `HOMEBREW_BUNDLE_NO_LOCK` env var and `--no-lock` CLI flag are
|
||||
# ignored. We keep both definitions with null defaults to detect explicit user
|
||||
# configuration and emit a warning below. We can't use `mkRemovedOptionModule` because
|
||||
# `homebrew.global` is a submodule.
|
||||
lockfiles = mkOption { visible = false; default = null; };
|
||||
noLock = mkOption { visible = false; default = null; };
|
||||
|
||||
homebrewEnvironmentVariables = mkInternalOption { type = types.attrs; };
|
||||
@@ -225,7 +254,6 @@ let
|
||||
homebrewEnvironmentVariables = {
|
||||
HOMEBREW_BUNDLE_FILE = mkIf config.brewfile "${brewfileFile}";
|
||||
HOMEBREW_NO_AUTO_UPDATE = mkIf (!config.autoUpdate) "1";
|
||||
HOMEBREW_BUNDLE_NO_LOCK = mkIf (!config.lockfiles) "1";
|
||||
};
|
||||
};
|
||||
};
|
||||
@@ -234,7 +262,7 @@ let
|
||||
options = {
|
||||
name = mkOption {
|
||||
type = types.str;
|
||||
example = "homebrew/cask-fonts";
|
||||
example = "apple/apple";
|
||||
description = ''
|
||||
When {option}`clone_target` is unspecified, this is the name of a formula
|
||||
repository to tap from GitHub using HTTPS. For example, `"user/repo"`
|
||||
@@ -253,6 +281,25 @@ let
|
||||
description = ''
|
||||
Whether to auto-update the tap even if it is not hosted on GitHub. By default, only taps
|
||||
hosted on GitHub are auto-updated (for performance reasons).
|
||||
|
||||
Note: Homebrew Bundle accepts this option in Brewfile syntax but may silently ignore it
|
||||
during installation. See [the Homebrew Bundle source](https://github.com/Homebrew/brew/tree/master/Library/Homebrew/bundle)
|
||||
for current behavior.
|
||||
'';
|
||||
};
|
||||
trusted = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
example = true;
|
||||
description = ''
|
||||
Whether to trust this tap during {command}`nix-darwin` system activation, by adding the
|
||||
`trusted: true` option to its {command}`brew bundle` Brewfile entry.
|
||||
|
||||
Homebrew 6.0.0 enabled `HOMEBREW_REQUIRE_TAP_TRUST` by default, which refuses to
|
||||
load formulae/casks from non-official taps that haven't been trusted, aborting activation.
|
||||
Set this to `true` for non-official taps you control so their formulae and casks are
|
||||
installed during activation. Official taps are always trusted, so this has no effect only
|
||||
them.
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -268,7 +315,8 @@ let
|
||||
"tap ${sCfg.name}"
|
||||
+ optionalString (sCfg ? clone_target) ", ${sCfg.clone_target}"
|
||||
+ optionalString (sCfg ? force_auto_update)
|
||||
", force_auto_update: ${sCfg.force_auto_update}";
|
||||
", force_auto_update: ${sCfg.force_auto_update}"
|
||||
+ optionalString config.trusted ", trusted: true";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -385,19 +433,34 @@ let
|
||||
};
|
||||
require_sha = mkNullOrBoolOption {
|
||||
description = ''
|
||||
Whether to require cask(s) to have a checksum.
|
||||
Whether to require casks to have a checksum.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
no_quarantine = mkNullOrBoolOption {
|
||||
description = "Whether to disable quarantining of downloads.";
|
||||
description = ''
|
||||
Whether to disable quarantining of downloads.
|
||||
|
||||
Note: this option is deprecated in Homebrew and may be removed in a
|
||||
future release. See [Homebrew/brew#20755](https://github.com/Homebrew/brew/issues/20755).
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
no_binaries = mkNullOrBoolOption {
|
||||
description = "Whether to disable linking of helper executables.";
|
||||
description = ''
|
||||
Whether to disable linking of helper executables.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
ignore_dependencies = mkNullOrBoolOption {
|
||||
description = "Ignore casks dependencies in case you manage them extrenally";
|
||||
description = ''
|
||||
Whether to ignore cask dependencies, e.g., when you manage them externally.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
|
||||
brewfileLine = mkInternalOption { type = types.nullOr types.str; };
|
||||
@@ -424,7 +487,7 @@ let
|
||||
type = with types; nullOr (listOf str);
|
||||
default = null;
|
||||
description = ''
|
||||
Arguments flags to pass to {command}`brew install`. Values should not include the
|
||||
Argument flags to pass to {command}`brew install`. Values should not include the
|
||||
leading `"--"`.
|
||||
'';
|
||||
};
|
||||
@@ -437,12 +500,14 @@ let
|
||||
'';
|
||||
};
|
||||
restart_service = mkOption {
|
||||
type = with types; nullOr (either bool (enum [ "changed" ]));
|
||||
type = with types; nullOr (either bool (enum [ "changed" "always" ]));
|
||||
default = null;
|
||||
description = ''
|
||||
Whether to run {command}`brew services restart` for the formula and register it to
|
||||
launch at login (or boot). If set to `"changed"`, the service will only
|
||||
be restarted on version changes.
|
||||
be restarted when the formula is newly installed or upgraded. If set to
|
||||
`"always"`, the service will be restarted on every {command}`brew bundle`
|
||||
run, even if nothing changed.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
@@ -450,17 +515,53 @@ let
|
||||
start_service = mkNullOrBoolOption {
|
||||
description = ''
|
||||
Whether to run {command}`brew services start` for the formula and register it to
|
||||
launch at login (or boot).
|
||||
launch at login (or boot). Unlike {option}`restart_service`, this only starts
|
||||
the service if it is not currently running, without restarting an already-running
|
||||
service.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
link = mkNullOrBoolOption {
|
||||
link = mkOption {
|
||||
type = with types; nullOr (either bool (enum [ "overwrite" ]));
|
||||
default = null;
|
||||
description = ''
|
||||
Whether to link the formula to the Homebrew prefix. When this option is
|
||||
`null`, Homebrew will use it's default behavior which is to link the
|
||||
formula if it's currently unlinked and not keg-only, and to unlink the formula if it's
|
||||
currently linked and keg-only.
|
||||
Whether to link the formula to the Homebrew prefix. When set to `"overwrite"`,
|
||||
existing symlinks will be overwritten ({command}`brew link --overwrite`). When this
|
||||
option is `null`, Homebrew will use its default behavior, which is to link the formula
|
||||
if it's currently unlinked and not keg-only, and to unlink the formula if it's currently
|
||||
linked and keg-only.
|
||||
'';
|
||||
};
|
||||
postinstall = mkNullOrStrOption {
|
||||
description = ''
|
||||
A shell command to run after the formula is installed or upgraded. The command is passed
|
||||
to the system shell and only executes when the formula actually changed (was freshly
|
||||
installed or upgraded), not on every {command}`brew bundle` run.
|
||||
'';
|
||||
};
|
||||
# `version_file` is intentionally not exposed: it writes the installed version to a file
|
||||
# path relative to the `brew bundle` working directory, which is not meaningful during
|
||||
# nix-darwin system activation.
|
||||
trusted = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
example = false;
|
||||
description = ''
|
||||
Whether to trust this formula during {command}`nix-darwin` system activation, by adding the
|
||||
`trusted: true` option to its {command}`brew bundle` Brewfile entry.
|
||||
|
||||
Homebrew 6.0.0 enabled `HOMEBREW_REQUIRE_TAP_TRUST` by default, which refuses to
|
||||
load formulae from non-official taps that haven't been trusted, aborting activation. Set
|
||||
this to `true` for a formula from a non-official tap you control so it is installed during
|
||||
activation.
|
||||
|
||||
This only takes effect when {option}`name` is a fully-qualified name (`user/repo/formula`),
|
||||
since only fully-qualified names map to a tap and can be trusted (and installed) on their
|
||||
own. When {option}`name` is a plain formula name, it is resolved through your tapped
|
||||
repositories, so trust must instead come from the containing tap being marked as trusted
|
||||
(see [](#opt-homebrew.taps)). Official taps are always trusted, so this has no effect on
|
||||
them.
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -470,20 +571,15 @@ let
|
||||
config =
|
||||
let
|
||||
sCfg = mkProcessedSubmodConfig config;
|
||||
sCfgSubset = removeAttrs sCfg [ "name" "restart_service" ];
|
||||
sCfgSubset = removeAttrs sCfg [ "name" "restart_service" "link" "trusted" ];
|
||||
in
|
||||
{
|
||||
brewfileLine =
|
||||
"brew ${sCfg.name}"
|
||||
+ optionalString (sCfgSubset != { }) ", ${mkBrewfileLineOptionsListString sCfgSubset}"
|
||||
# We need to handle the `restart_service` option seperately since it can be either a bool
|
||||
# or `:changed` in the Brewfile.
|
||||
+ optionalString (sCfg ? restart_service) (
|
||||
", restart_service: " + (
|
||||
if isBool config.restart_service then sCfg.restart_service
|
||||
else ":${config.restart_service}"
|
||||
)
|
||||
);
|
||||
+ mkBrewfileLineBoolOrSymbolString "link" config sCfg
|
||||
+ mkBrewfileLineBoolOrSymbolString "restart_service" config sCfg
|
||||
+ optionalString config.trusted ", trusted: true";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -502,12 +598,42 @@ let
|
||||
[](#opt-homebrew.caskArgs) for the available options.
|
||||
'';
|
||||
};
|
||||
greedy = mkNullOrBoolOption {
|
||||
greedy = mkOption {
|
||||
type = types.nullOr types.bool;
|
||||
default = cfg.greedyCasks;
|
||||
description = ''
|
||||
Whether to always upgrade this cask regardless of whether it's unversioned or it updates
|
||||
itself.
|
||||
'';
|
||||
};
|
||||
postinstall = mkNullOrStrOption {
|
||||
description = ''
|
||||
A shell command to run after the cask is installed or upgraded. The command is passed to
|
||||
the system shell and only executes when the cask was actually installed or upgraded, not
|
||||
on every {command}`brew bundle` run.
|
||||
'';
|
||||
};
|
||||
trusted = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
example = false;
|
||||
description = ''
|
||||
Whether to trust this cask during {command}`nix-darwin` system activation, by adding the
|
||||
`trusted: true` option to its {command}`brew bundle` Brewfile entry.
|
||||
|
||||
Homebrew 6.0.0 enabled `HOMEBREW_REQUIRE_TAP_TRUST` by default, which refuses to
|
||||
load casks from non-official taps that haven't been trusted, silently skipping them. Set
|
||||
this to `true` for a cask from a non-official tap you control so it is installed during
|
||||
activation.
|
||||
|
||||
This only takes effect when {option}`name` is a fully-qualified name (`user/repo/cask`),
|
||||
since only fully-qualified names map to a tap and can be trusted (and installed) on their
|
||||
own. When {option}`name` is a plain cask name, it is resolved through your tapped
|
||||
repositories, so trust must instead come from the containing tap being marked as trusted
|
||||
(see [](#opt-homebrew.taps)). Official taps are always trusted, so this has no effect on
|
||||
them.
|
||||
'';
|
||||
};
|
||||
|
||||
brewfileLine = mkInternalOption { type = types.nullOr types.str; };
|
||||
};
|
||||
@@ -515,12 +641,13 @@ let
|
||||
config =
|
||||
let
|
||||
sCfg = mkProcessedSubmodConfig config;
|
||||
sCfgSubset = removeAttrs sCfg [ "name" ];
|
||||
sCfgSubset = removeAttrs sCfg [ "name" "trusted" ];
|
||||
in
|
||||
{
|
||||
brewfileLine =
|
||||
"cask ${sCfg.name}"
|
||||
+ optionalString (sCfgSubset != { }) ", ${mkBrewfileLineOptionsListString sCfgSubset}";
|
||||
+ optionalString (sCfgSubset != { }) ", ${mkBrewfileLineOptionsListString sCfgSubset}"
|
||||
+ optionalString config.trusted ", trusted: true";
|
||||
};
|
||||
};
|
||||
in
|
||||
@@ -531,21 +658,26 @@ in
|
||||
imports = [
|
||||
(mkRenamedOptionModule [ "homebrew" "autoUpdate" ] [ "homebrew" "onActivation" "autoUpdate" ])
|
||||
(mkRenamedOptionModule [ "homebrew" "cleanup" ] [ "homebrew" "onActivation" "cleanup" ])
|
||||
(mkRemovedOptionModule [ "homebrew" "brewPrefix" ] "`homebrew.brewPrefix` has been renamed to `homebrew.prefix` and its semantics changed: the old option pointed to the bin directory (e.g., `/opt/homebrew/bin`), while the new option points to the Homebrew prefix (e.g., `/opt/homebrew`), matching `brew --prefix`. Please replace `homebrew.brewPrefix` with `homebrew.prefix`, removing the trailing `/bin` if present.")
|
||||
(mkRemovedOptionModule [ "homebrew" "whalebrews" ] "Whalebrew support was removed from Homebrew Bundle in Homebrew 4.7.0 (Nov 2025). `whalebrew` entries in a Brewfile now cause `brew bundle` to fail. Please manage Whalebrew images directly using the `whalebrew` CLI.")
|
||||
];
|
||||
|
||||
options.homebrew = {
|
||||
enable = mkEnableOption ''
|
||||
{command}`nix-darwin` to manage installing/updating/upgrading Homebrew taps, formulae,
|
||||
and casks, as well as Mac App Store apps and Docker containers, using Homebrew Bundle.
|
||||
casks, Mac App Store apps, Visual Studio Code extensions, Go packages, and Cargo
|
||||
crates using Homebrew Bundle.
|
||||
|
||||
Note that enabling this option does not install Homebrew, see the Homebrew
|
||||
[website](https://brew.sh) for installation instructions.
|
||||
|
||||
Use the [](#opt-homebrew.brews), [](#opt-homebrew.casks),
|
||||
[](#opt-homebrew.masApps), and [](#opt-homebrew.whalebrews) options
|
||||
to list the Homebrew formulae, casks, Mac App Store apps, and Docker containers you'd like to
|
||||
install. Use the [](#opt-homebrew.taps) option, to make additional formula
|
||||
repositories available to Homebrew. This module uses those options (along with the
|
||||
[](#opt-homebrew.masApps), [](#opt-homebrew.vscode),
|
||||
[](#opt-homebrew.goPackages), and [](#opt-homebrew.cargoPackages) options to list
|
||||
the Homebrew formulae, casks, Mac App Store apps, Visual Studio Code extensions,
|
||||
Go packages, and Cargo crates you'd like to install. Use the
|
||||
[](#opt-homebrew.taps) option, to make additional formula repositories available to
|
||||
Homebrew. This module uses those options (along with the
|
||||
[](#opt-homebrew.caskArgs) options) to generate a Brewfile that
|
||||
{command}`nix-darwin` passes to the {command}`brew bundle` command during
|
||||
system activation.
|
||||
@@ -559,20 +691,38 @@ in
|
||||
This module also provides a few options for modifying how Homebrew commands behave when
|
||||
you manually invoke them, under [](#opt-homebrew.global)'';
|
||||
|
||||
brewPrefix = mkOption {
|
||||
user = mkOption {
|
||||
type = types.str;
|
||||
default = if pkgs.stdenv.hostPlatform.isAarch64 then "/opt/homebrew/bin" else "/usr/local/bin";
|
||||
defaultText = literalExpression ''
|
||||
if pkgs.stdenv.hostPlatform.isAarch64 then "/opt/homebrew/bin"
|
||||
else "/usr/local/bin"
|
||||
'';
|
||||
default = config.system.primaryUser;
|
||||
defaultText = literalExpression "config.system.primaryUser";
|
||||
description = ''
|
||||
The path prefix where the {command}`brew` executable is located. This will be set to
|
||||
the correct value based on your system's platform, and should only need to be changed if you
|
||||
manually installed Homebrew in a non-standard location.
|
||||
The user that owns the Homebrew installation. In most cases
|
||||
this should be the normal user account that you installed
|
||||
Homebrew as.
|
||||
'';
|
||||
};
|
||||
|
||||
prefix = mkOption {
|
||||
type = types.str;
|
||||
default = if pkgs.stdenv.hostPlatform.isAarch64 then "/opt/homebrew" else "/usr/local";
|
||||
defaultText = literalExpression ''
|
||||
if pkgs.stdenv.hostPlatform.isAarch64 then "/opt/homebrew"
|
||||
else "/usr/local"
|
||||
'';
|
||||
description = ''
|
||||
The Homebrew prefix directory, i.e., the value that {command}`brew --prefix` returns.
|
||||
The default is automatically set based on your system's platform, and should only need
|
||||
to be changed if you manually installed Homebrew in a non-standard location.
|
||||
'';
|
||||
};
|
||||
|
||||
# These default to `false` (unlike direnv, which defaults to `true`) because existing users
|
||||
# likely already have `brew shellenv` in their dotfiles, and enabling by default would cause
|
||||
# duplicate evaluation.
|
||||
enableBashIntegration = mkShellIntegrationOption "Bash";
|
||||
enableFishIntegration = mkShellIntegrationOption "Fish";
|
||||
enableZshIntegration = mkShellIntegrationOption "Zsh";
|
||||
|
||||
onActivation = mkOption {
|
||||
type = types.submodule onActivationOptions;
|
||||
default = { };
|
||||
@@ -594,10 +744,10 @@ in
|
||||
type = with types; listOf (coercedTo str (name: { inherit name; }) (submodule tapOptions));
|
||||
default = [ ];
|
||||
example = literalExpression ''
|
||||
# Adapted examples from https://github.com/Homebrew/homebrew-bundle#usage
|
||||
# Adapted from https://docs.brew.sh/Brew-Bundle-and-Brewfile
|
||||
[
|
||||
# `brew tap`
|
||||
"homebrew/cask"
|
||||
"apple/apple"
|
||||
|
||||
# `brew tap` with custom Git URL and arguments
|
||||
{
|
||||
@@ -631,11 +781,20 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
greedyCasks = mkNullOrBoolOption {
|
||||
description = ''
|
||||
Whether to always upgrade casks listed in [](#opt-homebrew.casks) regardless
|
||||
of whether it's unversioned or it updates itself.
|
||||
|
||||
Homebrew's default is `false`.
|
||||
'';
|
||||
};
|
||||
|
||||
brews = mkOption {
|
||||
type = with types; listOf (coercedTo str (name: { inherit name; }) (submodule brewOptions));
|
||||
default = [ ];
|
||||
example = literalExpression ''
|
||||
# Adapted examples from https://github.com/Homebrew/homebrew-bundle#usage
|
||||
# Adapted from https://docs.brew.sh/Brew-Bundle-and-Brewfile
|
||||
[
|
||||
# `brew install`
|
||||
"imagemagick"
|
||||
@@ -654,6 +813,12 @@ in
|
||||
link = true;
|
||||
conflicts_with = [ "mysql" ];
|
||||
}
|
||||
|
||||
# `brew install`, run a post-install command on version changes
|
||||
{
|
||||
name = "postgresql@16";
|
||||
postinstall = "\''${HOMEBREW_PREFIX}/opt/postgresql@16/bin/postgres -D \''${HOMEBREW_PREFIX}/var/postgresql@16";
|
||||
}
|
||||
]
|
||||
'';
|
||||
description = ''
|
||||
@@ -669,7 +834,7 @@ in
|
||||
type = with types; listOf (coercedTo str (name: { inherit name; }) (submodule caskOptions));
|
||||
default = [ ];
|
||||
example = literalExpression ''
|
||||
# Adapted examples from https://github.com/Homebrew/homebrew-bundle#usage
|
||||
# Adapted from https://docs.brew.sh/Brew-Bundle-and-Brewfile
|
||||
[
|
||||
# `brew install --cask`
|
||||
"google-chrome"
|
||||
@@ -685,6 +850,12 @@ in
|
||||
name = "opera";
|
||||
greedy = true;
|
||||
}
|
||||
|
||||
# `brew install --cask`, run a post-install command on install or upgrade
|
||||
{
|
||||
name = "google-cloud-sdk";
|
||||
postinstall = "\''${HOMEBREW_PREFIX}/bin/gcloud components update";
|
||||
}
|
||||
]
|
||||
'';
|
||||
description = ''
|
||||
@@ -708,9 +879,6 @@ in
|
||||
description = ''
|
||||
Applications to install from Mac App Store using {command}`mas`.
|
||||
|
||||
When this option is used, `"mas"` is automatically added to
|
||||
[](#opt-homebrew.brews).
|
||||
|
||||
Note that you need to be signed into the Mac App Store for {command}`mas` to
|
||||
successfully install and upgrade applications, and that unfortunately apps removed from this
|
||||
option will not be uninstalled automatically even if
|
||||
@@ -722,21 +890,47 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
whalebrews = mkOption {
|
||||
vscode = mkOption {
|
||||
type = with types; listOf str;
|
||||
default = [ ];
|
||||
example = [ "whalebrew/wget" ];
|
||||
example = [ "golang.go" ];
|
||||
description = ''
|
||||
List of Docker images to install using {command}`whalebrew`.
|
||||
List of Visual Studio Code extensions to install using Homebrew Bundle.
|
||||
|
||||
When this option is used, `"whalebrew"` is automatically added to
|
||||
[](#opt-homebrew.brews).
|
||||
A compatible editor (Visual Studio Code, VSCodium, Cursor, or VS Code Insiders)
|
||||
must be available. If none is found, Homebrew will attempt to install
|
||||
`visual-studio-code` automatically.
|
||||
|
||||
For more information on {command}`whalebrew` see:
|
||||
[github.com/whalebrew/whalebrew](https://github.com/whalebrew/whalebrew).
|
||||
For more information on {command}`code` see:
|
||||
[VSCode Extension Marketplace](https://code.visualstudio.com/docs/editor/extension-marketplace).
|
||||
'';
|
||||
};
|
||||
|
||||
goPackages = mkOption {
|
||||
type = with types; listOf str;
|
||||
default = [ ];
|
||||
example = [ "github.com/charmbracelet/crush" ];
|
||||
description = ''
|
||||
List of Go packages to install using {command}`go install`.
|
||||
|
||||
Homebrew will automatically install the {command}`go` formula if it is not already
|
||||
installed.
|
||||
'';
|
||||
};
|
||||
|
||||
cargoPackages = mkOption {
|
||||
type = with types; listOf str;
|
||||
default = [ ];
|
||||
example = [ "ripgrep" ];
|
||||
description = ''
|
||||
List of Rust packages to install using {command}`cargo install`.
|
||||
|
||||
Homebrew will automatically install the {command}`rust` formula if it is not already
|
||||
installed.
|
||||
'';
|
||||
};
|
||||
|
||||
|
||||
extraConfig = mkOption {
|
||||
type = types.lines;
|
||||
default = "";
|
||||
@@ -749,7 +943,7 @@ in
|
||||
|
||||
brewfile = mkInternalOption {
|
||||
type = types.str;
|
||||
description = "String reprensentation of the generated Brewfile useful for debugging.";
|
||||
description = "String representation of the generated Brewfile useful for debugging.";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -758,18 +952,15 @@ in
|
||||
|
||||
config = {
|
||||
|
||||
assertions = [
|
||||
# See comment above `homebrew.global.noLock` option declaration for why this is required.
|
||||
{ assertion = cfg.global.noLock == null; message = "The option `homebrew.global.noLock' was removed, use `homebrew.global.lockfiles' in it's place."; }
|
||||
];
|
||||
|
||||
warnings = [
|
||||
(mkIf (options.homebrew.autoUpdate.isDefined || options.homebrew.cleanup.isDefined) "The `homebrew' module no longer upgrades outdated formulae and apps by default during `nix-darwin' system activation. To enable upgrading, set `homebrew.onActivation.upgrade = true'.")
|
||||
(mkIf (cfg.global.noLock != null || cfg.global.lockfiles != null) "The options `homebrew.global.noLock' and `homebrew.global.lockfiles' have been deprecated. Homebrew Bundle removed lockfile support in Homebrew 4.4.0 (Oct 2024), so these options no longer have any effect. Please remove them from your configuration.")
|
||||
(mkIf (hasSuffix "/bin" cfg.prefix) "`homebrew.prefix` should be the Homebrew prefix directory (e.g., `/opt/homebrew`), not the bin directory. The value should match what `brew --prefix` returns. Did you mean to remove the trailing `/bin`?")
|
||||
];
|
||||
|
||||
homebrew.brews =
|
||||
optional (cfg.masApps != { }) "mas"
|
||||
++ optional (cfg.whalebrews != [ ]) "whalebrew";
|
||||
system.requiresPrimaryUser = mkIf (cfg.enable && options.homebrew.user.highestPrio == (mkOptionDefault {}).priority) [
|
||||
"homebrew.enable"
|
||||
];
|
||||
|
||||
homebrew.brewfile =
|
||||
"# Created by `nix-darwin`'s `homebrew` module\n\n"
|
||||
@@ -780,19 +971,73 @@ in
|
||||
+ mkBrewfileSectionString "Casks" cfg.casks
|
||||
+ mkBrewfileSectionString "Mac App Store apps"
|
||||
(mapAttrsToList (n: id: ''mas "${n}", id: ${toString id}'') cfg.masApps)
|
||||
+ mkBrewfileSectionString "Docker containers" (map (v: ''whalebrew "${v}"'') cfg.whalebrews)
|
||||
+ mkBrewfileSectionString "Visual Studio Code extensions" (map (v: ''vscode "${v}"'') cfg.vscode)
|
||||
+ mkBrewfileSectionString "Go packages" (map (v: ''go "${v}"'') cfg.goPackages)
|
||||
+ mkBrewfileSectionString "Cargo packages" (map (v: ''cargo "${v}"'') cfg.cargoPackages)
|
||||
+ optionalString (cfg.extraConfig != "") ("# Extra config\n" + cfg.extraConfig);
|
||||
|
||||
environment.variables = mkIf cfg.enable cfg.global.homebrewEnvironmentVariables;
|
||||
|
||||
programs = mkIf cfg.enable {
|
||||
bash.interactiveShellInit = mkIf cfg.enableBashIntegration ''
|
||||
eval "$(${cfg.prefix}/bin/brew shellenv bash)"
|
||||
if [[ -r "${cfg.prefix}/etc/profile.d/bash_completion.sh" ]]; then
|
||||
source "${cfg.prefix}/etc/profile.d/bash_completion.sh"
|
||||
else
|
||||
for COMPLETION in "${cfg.prefix}/etc/bash_completion.d/"*; do
|
||||
[[ -r "$COMPLETION" ]] && source "$COMPLETION"
|
||||
done
|
||||
fi
|
||||
'';
|
||||
|
||||
zsh.interactiveShellInit = mkIf cfg.enableZshIntegration ''
|
||||
eval "$(${cfg.prefix}/bin/brew shellenv zsh)"
|
||||
'';
|
||||
|
||||
fish.interactiveShellInit = mkIf cfg.enableFishIntegration ''
|
||||
eval (${cfg.prefix}/bin/brew shellenv fish)
|
||||
if test -d "${cfg.prefix}/share/fish/completions"
|
||||
set -p fish_complete_path "${cfg.prefix}/share/fish/completions"
|
||||
end
|
||||
if test -d "${cfg.prefix}/share/fish/vendor_completions.d"
|
||||
set -p fish_complete_path "${cfg.prefix}/share/fish/vendor_completions.d"
|
||||
end
|
||||
'';
|
||||
};
|
||||
|
||||
system.checks.text = mkIf (cfg.enable && cfg.onActivation.cleanup == "check") ''
|
||||
if [ -f "${cfg.prefix}/bin/brew" ]; then
|
||||
homebrewCleanupExitCode=0
|
||||
homebrewCleanupResult=$(${cfg.onActivation.brewBundleCmd { onlyCheck = true; }}) || homebrewCleanupExitCode=$?
|
||||
if [ "$homebrewCleanupExitCode" -eq 1 ]; then
|
||||
printf >&2 '\e[1;31merror: found Homebrew packages not listed in the Brewfile, aborting activation\e[0m\n'
|
||||
printf >&2 '%s\n' "$homebrewCleanupResult"
|
||||
printf >&2 '\n'
|
||||
printf >&2 'To fix this, either:\n'
|
||||
printf >&2 ' - Add the listed packages to your nix-darwin Homebrew configuration\n'
|
||||
printf >&2 ' - Remove them by running: brew bundle cleanup --force\n'
|
||||
printf >&2 ' - Set homebrew.onActivation.cleanup to "uninstall" or "zap"\n'
|
||||
exit 2
|
||||
elif [ "$homebrewCleanupExitCode" -ne 0 ]; then
|
||||
printf >&2 '\e[1;31merror: brew bundle cleanup failed, aborting activation\e[0m\n'
|
||||
printf >&2 '%s\n' "$homebrewCleanupResult"
|
||||
exit 2
|
||||
fi
|
||||
fi
|
||||
'';
|
||||
|
||||
system.activationScripts.homebrew.text = mkIf cfg.enable ''
|
||||
# Homebrew Bundle
|
||||
echo >&2 "Homebrew bundle..."
|
||||
if [ -f "${cfg.brewPrefix}/brew" ]; then
|
||||
PATH="${cfg.brewPrefix}":$PATH ${cfg.onActivation.brewBundleCmd}
|
||||
if [ -f "${cfg.prefix}/bin/brew" ]; then
|
||||
${cfg.onActivation.brewBundleCmd { onlyCheck = false; }}
|
||||
else
|
||||
echo -e "\e[1;31merror: Homebrew is not installed, skipping...\e[0m" >&2
|
||||
fi
|
||||
'';
|
||||
};
|
||||
|
||||
meta.maintainers = [
|
||||
lib.maintainers.malo or "malo"
|
||||
];
|
||||
}
|
||||
|
||||
@@ -9,7 +9,7 @@ let
|
||||
|
||||
toEnvironmentText = name: value: {
|
||||
name = "${value.serviceConfig.Label}.plist";
|
||||
value.text = generators.toPlist { } value.serviceConfig;
|
||||
value.text = generators.toPlist { escape = true; } value.serviceConfig;
|
||||
};
|
||||
|
||||
launchdConfig = import ./launchd.nix;
|
||||
@@ -90,7 +90,7 @@ let
|
||||
serviceConfig.ProgramArguments = mkIf (config.command != "") [
|
||||
"/bin/sh"
|
||||
"-c"
|
||||
"/bin/wait4path /nix/store && exec ${config.command}"
|
||||
"/bin/wait4path /nix/store && exec ${config.command}"
|
||||
];
|
||||
serviceConfig.EnvironmentVariables = mkIf (env != {}) env;
|
||||
};
|
||||
@@ -170,7 +170,16 @@ in
|
||||
|
||||
launchd.user.agents = mkOption {
|
||||
default = {};
|
||||
type = types.attrsOf (types.submodule serviceOptions);
|
||||
type = types.attrsOf (types.submodule [
|
||||
serviceOptions
|
||||
({ name, ... }: {
|
||||
options.managedBy = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
internal = true;
|
||||
default = lib.showOption [ "launchd" "user" "agents" name ];
|
||||
};
|
||||
})
|
||||
]);
|
||||
description = ''
|
||||
Definition of per-user launchd agents.
|
||||
|
||||
@@ -187,6 +196,18 @@ in
|
||||
|
||||
config = {
|
||||
|
||||
system.requiresPrimaryUser =
|
||||
lib.map (
|
||||
name:
|
||||
lib.showOption [
|
||||
"launchd"
|
||||
"user"
|
||||
"envVariables"
|
||||
name
|
||||
]
|
||||
) (attrNames cfg.user.envVariables)
|
||||
++ lib.map ({ managedBy, ... }: managedBy) (attrValues cfg.user.agents);
|
||||
|
||||
environment.launchAgents = mapAttrs' toEnvironmentText cfg.agents;
|
||||
environment.launchDaemons = mapAttrs' toEnvironmentText cfg.daemons;
|
||||
|
||||
|
||||
@@ -120,6 +120,18 @@ in
|
||||
This key maps to the second argument of `execvp(3)`. This key is required in the absence of the Program
|
||||
key. Please note: many people are confused by this key. Please read `execvp(3)` very carefully!
|
||||
'';
|
||||
# TODO: Remove this some time after 25.11.
|
||||
apply =
|
||||
val:
|
||||
if (builtins.isNull val) then
|
||||
val
|
||||
else
|
||||
(map (
|
||||
item:
|
||||
lib.warnIf (lib.hasInfix "&" item)
|
||||
"A value for `ProgramArguments` contains the literal string `&`. This is no longer necessary and will lead to double-escaping, as nix-darwin now automatically escapes special characters."
|
||||
item
|
||||
) val);
|
||||
};
|
||||
|
||||
EnableGlobbing = mkOption {
|
||||
|
||||
@@ -39,11 +39,13 @@ in
|
||||
ids.uids = {
|
||||
nixbld = lib.mkDefault 350;
|
||||
_prometheus-node-exporter = 534;
|
||||
_dnscrypt-proxy = 535;
|
||||
};
|
||||
|
||||
ids.gids = {
|
||||
nixbld = lib.mkDefault (if config.system.stateVersion < 5 then 30000 else 350);
|
||||
_prometheus-node-exporter = 534;
|
||||
_dnscrypt-proxy = 535;
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
+12
-1
@@ -1,5 +1,7 @@
|
||||
[
|
||||
./alias.nix
|
||||
./config/system-path.nix
|
||||
./config/terminfo.nix
|
||||
./documentation
|
||||
./meta.nix
|
||||
./misc/ids.nix
|
||||
@@ -10,6 +12,7 @@
|
||||
./security/sudo.nix
|
||||
./system
|
||||
./system/base.nix
|
||||
./system/primary-user.nix
|
||||
./system/checks.nix
|
||||
./system/activation-scripts.nix
|
||||
./system/applications.nix
|
||||
@@ -23,6 +26,7 @@
|
||||
./system/defaults/dock.nix
|
||||
./system/defaults/finder.nix
|
||||
./system/defaults/hitoolbox.nix
|
||||
./system/defaults/iCal.nix
|
||||
./system/defaults/screencapture.nix
|
||||
./system/defaults/screensaver.nix
|
||||
./system/defaults/alf.nix
|
||||
@@ -45,6 +49,7 @@
|
||||
./system/version.nix
|
||||
./time
|
||||
./networking
|
||||
./networking/applicationFirewall.nix
|
||||
./nix
|
||||
./nix/linux-builder.nix
|
||||
./nix/nix-darwin.nix
|
||||
@@ -62,6 +67,7 @@
|
||||
./services/chunkwm.nix
|
||||
./services/cachix-agent.nix
|
||||
./services/dnsmasq.nix
|
||||
./services/dnscrypt-proxy.nix
|
||||
./services/emacs.nix
|
||||
./services/eternal-terminal.nix
|
||||
./services/github-runner
|
||||
@@ -98,14 +104,19 @@
|
||||
./services/yabai
|
||||
./services/nextdns
|
||||
./services/jankyborders
|
||||
./programs/_1password.nix
|
||||
./programs/_1password-gui.nix
|
||||
./programs/arqbackup.nix
|
||||
./programs/bash
|
||||
./programs/devenv.nix
|
||||
./programs/direnv.nix
|
||||
./programs/fish.nix
|
||||
./programs/gnupg.nix
|
||||
./programs/man.nix
|
||||
./programs/mas.nix
|
||||
./programs/info
|
||||
./programs/nix-index
|
||||
./programs/ssh
|
||||
./programs/ssh.nix
|
||||
./programs/tmux.nix
|
||||
./programs/vim.nix
|
||||
./programs/zsh
|
||||
|
||||
@@ -0,0 +1,73 @@
|
||||
{ config, lib, ... }:
|
||||
let
|
||||
cfg = config.networking.applicationFirewall;
|
||||
|
||||
socketfilterfw =
|
||||
option: value:
|
||||
lib.concatStringsSep " " [
|
||||
"/usr/libexec/ApplicationFirewall/socketfilterfw"
|
||||
"--${option}"
|
||||
(if value then "on" else "off")
|
||||
];
|
||||
in
|
||||
{
|
||||
meta.maintainers = [
|
||||
(lib.maintainers.prince213 or "prince213")
|
||||
(lib.maintainers.ryanccn or "ryanccn")
|
||||
];
|
||||
|
||||
options.networking.applicationFirewall = {
|
||||
enable = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
example = true;
|
||||
description = "Whether to enable application firewall.";
|
||||
};
|
||||
|
||||
blockAllIncoming = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
example = true;
|
||||
description = "Whether to block all incoming connections.";
|
||||
};
|
||||
|
||||
allowSigned = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
example = true;
|
||||
description = "Whether to allow built-in software to receive incoming connections.";
|
||||
};
|
||||
|
||||
allowSignedApp = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
example = true;
|
||||
description = "Whether to allow downloaded signed software to receive incoming connections.";
|
||||
};
|
||||
|
||||
enableStealthMode = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
example = true;
|
||||
description = "Whether to enable stealth mode.";
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
system.activationScripts.networking.text = ''
|
||||
echo "configuring application firewall..." >&2
|
||||
|
||||
${lib.optionalString (cfg.enable != null) (socketfilterfw "setglobalstate" cfg.enable)}
|
||||
${lib.optionalString (cfg.blockAllIncoming != null) (
|
||||
socketfilterfw "setblockall" cfg.blockAllIncoming
|
||||
)}
|
||||
${lib.optionalString (cfg.allowSigned != null) (socketfilterfw "setallowsigned" cfg.allowSigned)}
|
||||
${lib.optionalString (cfg.allowSignedApp != null) (
|
||||
socketfilterfw "setallowsignedapp" cfg.allowSignedApp
|
||||
)}
|
||||
${lib.optionalString (cfg.enableStealthMode != null) (
|
||||
socketfilterfw "setstealthmode" cfg.enableStealthMode
|
||||
)}
|
||||
'';
|
||||
};
|
||||
}
|
||||
@@ -18,6 +18,9 @@ let
|
||||
*${lib.escapeShellArg srv}*)
|
||||
networksetup -setdnsservers ${lib.escapeShellArgs ([ srv ] ++ (emptyList cfg.dns))}
|
||||
networksetup -setsearchdomains ${lib.escapeShellArgs ([ srv ] ++ (emptyList cfg.search))}
|
||||
${optionalString (cfg.dhcpClientId != null) ''
|
||||
networksetup -setdhcp ${lib.escapeShellArgs [ srv cfg.dhcpClientId ]}
|
||||
''}
|
||||
;;
|
||||
esac
|
||||
'') cfg.knownNetworkServices}
|
||||
@@ -71,6 +74,56 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
networking.domain = mkOption {
|
||||
default = null;
|
||||
example = "home.arpa";
|
||||
type = types.nullOr types.str;
|
||||
description = ''
|
||||
The domain. It can be left empty if it is auto-detected through DHCP.
|
||||
'';
|
||||
};
|
||||
|
||||
networking.fqdn = mkOption {
|
||||
type = types.str;
|
||||
default =
|
||||
if (cfg.hostName != "" && cfg.domain != null) then
|
||||
"${cfg.hostName}.${cfg.domain}"
|
||||
else
|
||||
throw ''
|
||||
The FQDN is required but cannot be determined from `networking.hostName`
|
||||
and `networking.domain`. Please ensure these options are set properly or
|
||||
set `networking.fqdn` directly.
|
||||
'';
|
||||
defaultText = literalExpression ''"''${networking.hostName}.''${networking.domain}"'';
|
||||
description = ''
|
||||
The fully qualified domain name (FQDN) of this host. By default, it is
|
||||
the result of combining `networking.hostName` and `networking.domain.`
|
||||
|
||||
Using this option will result in an evaluation error if the hostname is empty or
|
||||
no domain is specified.
|
||||
|
||||
Modules that accept a mere `networking.hostName` but prefer a fully qualified
|
||||
domain name may use `networking.fqdnOrHostName` instead.
|
||||
'';
|
||||
};
|
||||
|
||||
networking.fqdnOrHostName = mkOption {
|
||||
readOnly = true;
|
||||
type = types.str;
|
||||
default = if cfg.domain == null then cfg.hostName else cfg.fqdn;
|
||||
defaultText = literalExpression ''
|
||||
if cfg.domain == null then cfg.hostName else cfg.fqdn
|
||||
'';
|
||||
description = ''
|
||||
Either the fully qualified domain name (FQDN), or just the host name if
|
||||
it does not exists.
|
||||
|
||||
This is a convenience option for modules to read instead of `fqdn` when
|
||||
a mere `hostName` is also an acceptable value; this option does not
|
||||
throw an error when `domain` is unset.
|
||||
'';
|
||||
};
|
||||
|
||||
networking.knownNetworkServices = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
@@ -83,6 +136,21 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
networking.dhcpClientId = mkOption {
|
||||
type = types.nullOr types.str;
|
||||
default = null;
|
||||
example = "my-client-id";
|
||||
description = ''
|
||||
The DHCP client identifier to use when requesting an IP address from a DHCP server.
|
||||
|
||||
If this option is set, it will be used by the system when requesting an IP address.
|
||||
If not set, no changes will be made.
|
||||
|
||||
Set to the string "empty" to clear any previously configured client ID
|
||||
and restore the system default behavior.
|
||||
'';
|
||||
};
|
||||
|
||||
networking.dns = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
@@ -112,13 +180,13 @@ in
|
||||
warnings = [
|
||||
(mkIf (cfg.knownNetworkServices == [] && cfg.dns != []) "networking.knownNetworkServices is empty, dns servers will not be configured.")
|
||||
(mkIf (cfg.knownNetworkServices == [] && cfg.search != []) "networking.knownNetworkServices is empty, dns searchdomains will not be configured.")
|
||||
(mkIf (cfg.knownNetworkServices == [] && cfg.dhcpClientId != null) "networking.knownNetworkServices is empty, dhcp client ID will not be configured.")
|
||||
];
|
||||
|
||||
system.activationScripts.networking.text = ''
|
||||
echo "configuring networking..." >&2
|
||||
|
||||
${optionalString (cfg.computerName != null) ''
|
||||
# shellcheck disable=SC1112
|
||||
scutil --set ComputerName ${escapeShellArg cfg.computerName}
|
||||
''}
|
||||
${optionalString (cfg.hostName != null) ''
|
||||
@@ -133,6 +201,11 @@ in
|
||||
${optionalString (cfg.wakeOnLan.enable != null) ''
|
||||
systemsetup -setWakeOnNetworkAccess '${onOff cfg.wakeOnLan.enable}' &> /dev/null
|
||||
''}
|
||||
|
||||
if [ -e /etc/hosts.before-nix-darwin ]; then
|
||||
echo "restoring /etc/hosts..." >&2
|
||||
sudo mv /etc/hosts{.before-nix-darwin,}
|
||||
fi
|
||||
'';
|
||||
|
||||
};
|
||||
|
||||
+175
-66
@@ -12,6 +12,8 @@ let
|
||||
|
||||
isNixAtLeast = versionAtLeast (getVersion nixPackage);
|
||||
|
||||
configureBuildUsers = !(config.nix.settings.auto-allocate-uids or false);
|
||||
|
||||
makeNixBuildUser = nr: {
|
||||
name = "_nixbld${toString nr}";
|
||||
value = {
|
||||
@@ -49,13 +51,16 @@ let
|
||||
|
||||
mkKeyValuePairs = attrs: concatStringsSep "\n" (mapAttrsToList mkKeyValue attrs);
|
||||
|
||||
isExtra = key: hasPrefix "extra-" key;
|
||||
|
||||
in
|
||||
pkgs.writeTextFile {
|
||||
name = "nix.conf";
|
||||
text = ''
|
||||
# WARNING: this file is generated from the nix.* options in
|
||||
# your nix-darwin configuration. Do not edit it!
|
||||
${mkKeyValuePairs cfg.settings}
|
||||
${mkKeyValuePairs (filterAttrs (key: value: !(isExtra key)) cfg.settings)}
|
||||
${mkKeyValuePairs (filterAttrs (key: value: isExtra key) cfg.settings)}
|
||||
${cfg.extraOptions}
|
||||
'';
|
||||
checkPhase =
|
||||
@@ -134,6 +139,34 @@ let
|
||||
namedPaths ++ searchPaths;
|
||||
};
|
||||
|
||||
handleUnmanaged = managedConfig: mkMerge [
|
||||
(mkIf cfg.enable managedConfig)
|
||||
(mkIf (!cfg.enable) {
|
||||
system.activationScripts.nix-daemon.text = ''
|
||||
# Restore unmanaged Nix daemon if present
|
||||
unmanagedNixProfile=/nix/var/nix/profiles/default
|
||||
if [[
|
||||
-e /run/current-system/Library/LaunchDaemons/org.nixos.nix-daemon.plist
|
||||
&& -e $unmanagedNixProfile/Library/LaunchDaemons/org.nixos.nix-daemon.plist
|
||||
]]; then
|
||||
printf >&2 'restoring unmanaged Nix daemon...\n'
|
||||
cp \
|
||||
"$unmanagedNixProfile/Library/LaunchDaemons/org.nixos.nix-daemon.plist" \
|
||||
/Library/LaunchDaemons
|
||||
launchctl load -w /Library/LaunchDaemons/org.nixos.nix-daemon.plist
|
||||
fi
|
||||
'';
|
||||
})
|
||||
];
|
||||
|
||||
managedDefault = name: default: {
|
||||
default = if cfg.enable then default else throw ''
|
||||
${name}: accessed when `nix.enable` is off; this is a bug in
|
||||
nix-darwin or a third‐party module
|
||||
'';
|
||||
defaultText = default;
|
||||
};
|
||||
|
||||
in
|
||||
|
||||
{
|
||||
@@ -144,7 +177,6 @@ in
|
||||
in
|
||||
[
|
||||
# Only ever in NixOS
|
||||
(mkRemovedOptionModule [ "nix" "enable" ] "No `nix-darwin` equivalent to this NixOS option.")
|
||||
(mkRemovedOptionModule [ "nix" "daemonCPUSchedPolicy" ] (altOption "nix.daemonProcessType"))
|
||||
(mkRemovedOptionModule [ "nix" "daemonIOSchedClass" ] (altOption "nix.daemonProcessType"))
|
||||
(mkRemovedOptionModule [ "nix" "daemonIOSchedPriority" ] (altOption "nix.daemonIOLowPriority"))
|
||||
@@ -157,6 +189,14 @@ in
|
||||
(mkRenamedOptionModule [ "users" "nix" "nrBuildUsers" ] [ "nix" "nrBuildUsers" ])
|
||||
(mkRenamedOptionModule [ "nix" "daemonIONice" ] [ "nix" "daemonIOLowPriority" ])
|
||||
(mkRemovedOptionModule [ "nix" "daemonNiceLevel" ] (consider "nix.daemonProcessType"))
|
||||
(mkRemovedOptionModule [ "nix" "useDaemon" ] ''
|
||||
nix-darwin now only supports managing multi‐user daemon
|
||||
installations of Nix.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "nix" "configureBuildUsers" ] ''
|
||||
nix-darwin now manages build users unconditionally when
|
||||
`nix.enable` is on.
|
||||
'')
|
||||
] ++ mapAttrsToList (oldConf: newConf: mkRenamedOptionModule [ "nix" oldConf ] [ "nix" "settings" newConf ]) legacyConfMappings;
|
||||
|
||||
###### interface
|
||||
@@ -165,29 +205,43 @@ in
|
||||
|
||||
nix = {
|
||||
|
||||
enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Whether to enable Nix.
|
||||
|
||||
Disabling this will stop nix-darwin from managing the
|
||||
installed version of Nix, the nix-daemon launchd daemon, and
|
||||
the settings in {file}`/etc/nix/nix.conf`.
|
||||
|
||||
This allows you to use nix-darwin without it taking over your
|
||||
system installation of Nix. Some nix-darwin functionality
|
||||
that relies on managing the Nix installation, like the
|
||||
`nix.*` options to adjust Nix settings or configure a Linux
|
||||
builder, will be unavailable. You will also have to upgrade
|
||||
Nix yourself, as nix-darwin will no longer do so.
|
||||
|
||||
::: {.warning}
|
||||
If you have already removed your global system installation
|
||||
of Nix, this will break nix-darwin and you will have to
|
||||
reinstall Nix to fix it.
|
||||
:::
|
||||
'';
|
||||
};
|
||||
|
||||
package = mkOption {
|
||||
type = types.package;
|
||||
default = pkgs.nix;
|
||||
inherit (managedDefault "nix.package" pkgs.nix) default;
|
||||
defaultText = literalExpression "pkgs.nix";
|
||||
description = ''
|
||||
This option specifies the Nix package instance to use throughout the system.
|
||||
'';
|
||||
};
|
||||
|
||||
# Not in NixOS module
|
||||
useDaemon = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
If set, Nix will use the daemon to perform operations.
|
||||
Use this instead of services.nix-daemon.enable if you don't want the
|
||||
daemon service to be managed for you.
|
||||
'';
|
||||
};
|
||||
|
||||
distributedBuilds = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
inherit (managedDefault "nix.distributedBuilds" false) default defaultText;
|
||||
description = ''
|
||||
Whether to distribute builds to the machines listed in
|
||||
{option}`nix.buildMachines`.
|
||||
@@ -197,7 +251,7 @@ in
|
||||
# Not in NixOS module
|
||||
daemonProcessType = mkOption {
|
||||
type = types.enum [ "Background" "Standard" "Adaptive" "Interactive" ];
|
||||
default = "Standard";
|
||||
inherit (managedDefault "nix.daemonProcessType" "Standard") default defaultText;
|
||||
description = ''
|
||||
Nix daemon process resource limits class. These limits propagate to
|
||||
build processes. `Standard` is the default process type
|
||||
@@ -212,7 +266,7 @@ in
|
||||
# Not in NixOS module
|
||||
daemonIOLowPriority = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
inherit (managedDefault "nix.daemonIOLowPriority" false) default defaultText;
|
||||
description = ''
|
||||
Whether the Nix daemon process should considered to be low priority when
|
||||
doing file system I/O.
|
||||
@@ -340,7 +394,7 @@ in
|
||||
};
|
||||
};
|
||||
});
|
||||
default = [ ];
|
||||
inherit (managedDefault "nix.buildMachines" [ ]) default defaultText;
|
||||
description = ''
|
||||
This option lists the machines to be used if distributed builds are
|
||||
enabled (see {option}`nix.distributedBuilds`).
|
||||
@@ -354,21 +408,13 @@ in
|
||||
envVars = mkOption {
|
||||
type = types.attrs;
|
||||
internal = true;
|
||||
default = { };
|
||||
inherit (managedDefault "nix.envVars" { }) default defaultText;
|
||||
description = "Environment variables used by Nix.";
|
||||
};
|
||||
|
||||
# Not in NixOS module
|
||||
configureBuildUsers = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Enable configuration for nixbld group and users.
|
||||
'';
|
||||
};
|
||||
|
||||
nrBuildUsers = mkOption {
|
||||
type = types.int;
|
||||
inherit (managedDefault "nix.nrBuildUsers" 0) default defaultText;
|
||||
description = ''
|
||||
Number of `nixbld` user accounts created to
|
||||
perform secure concurrent builds. If you receive an error
|
||||
@@ -396,11 +442,16 @@ in
|
||||
# Definition differs substantially from NixOS module
|
||||
nixPath = mkOption {
|
||||
type = nixPathType;
|
||||
default = lib.optionals cfg.channel.enable [
|
||||
# Include default path <darwin-config>.
|
||||
{ darwin-config = "${config.environment.darwinConfig}"; }
|
||||
"/nix/var/nix/profiles/per-user/root/channels"
|
||||
];
|
||||
inherit (managedDefault "nix.nixPath" (
|
||||
lib.optionals cfg.channel.enable (
|
||||
lib.optionals (config.environment.darwinConfig != null) [
|
||||
# Include default path <darwin-config>.
|
||||
{ darwin-config = "${config.environment.darwinConfig}"; }
|
||||
] ++ [
|
||||
"/nix/var/nix/profiles/per-user/root/channels"
|
||||
]
|
||||
)
|
||||
)) default;
|
||||
|
||||
defaultText = lib.literalExpression ''
|
||||
lib.optionals cfg.channel.enable [
|
||||
@@ -422,7 +473,7 @@ in
|
||||
|
||||
checkConfig = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
inherit (managedDefault "nix.checkConfig" true) default defaultText;
|
||||
description = ''
|
||||
If enabled (the default), checks for data type mismatches and that Nix
|
||||
can parse the generated nix.conf.
|
||||
@@ -483,7 +534,7 @@ in
|
||||
};
|
||||
}
|
||||
));
|
||||
default = { };
|
||||
inherit (managedDefault "nix.registry" { }) default defaultText;
|
||||
description = ''
|
||||
A system-wide flake registry.
|
||||
'';
|
||||
@@ -491,7 +542,7 @@ in
|
||||
|
||||
extraOptions = mkOption {
|
||||
type = types.lines;
|
||||
default = "";
|
||||
inherit (managedDefault "nix.extraOptions" "") default defaultText;
|
||||
example = ''
|
||||
keep-outputs = true
|
||||
keep-derivations = true
|
||||
@@ -660,7 +711,7 @@ in
|
||||
};
|
||||
};
|
||||
};
|
||||
default = { };
|
||||
inherit (managedDefault "nix.settings" { }) default defaultText;
|
||||
description = ''
|
||||
Configuration for Nix, see
|
||||
<https://nixos.org/manual/nix/stable/#sec-conf-file>
|
||||
@@ -678,7 +729,7 @@ in
|
||||
|
||||
###### implementation
|
||||
|
||||
config = {
|
||||
config = handleUnmanaged {
|
||||
environment.systemPackages =
|
||||
[
|
||||
nixPackage
|
||||
@@ -702,8 +753,13 @@ in
|
||||
"5d23e6d7015756c6f300f8cd558ec4d9234ca61deefd4f2478e91a49760b0747" # DeterminateSystems Nix installer 0.16.0
|
||||
"e4974acb79c56148cb8e92137fa4f2de9b7356e897b332fc4e6769e8c0b83e18" # DeterminateSystems Nix installer 0.20.0
|
||||
"966d22ef5bb9b56d481e8e0d5f7ca2deaf4d24c0f0fc969b2eeaa7ae0aa42907" # DeterminateSystems Nix installer 0.22.0
|
||||
"53712b4335030e2dbfb46bb235f8cffcac83fea404bd32dc99417ac89e2dd7c5" # DeterminateSystems Nix installer 0.33.0
|
||||
"6bb8d6b0dd16b44ee793a9b8382dac76c926e4c16ffb8ddd2bb4884d1ca3f811" # DeterminateSystems Nix installer 0.34.0
|
||||
"24797ac05542ff8b52910efc77870faa5f9e3275097227ea4e50c430a5f72916" # lix-installer 0.17.1 with flakes
|
||||
"b027b5cad320b5b8123d9d0db9f815c3f3921596c26dc3c471457098e4d3cc40" # lix-installer 0.17.1 without flakes
|
||||
"74ee0ae5ad21a1b101617685fd3d001f74a9466d9d763d92eb75b99cc740db91" # experimental official Nix installer 2.33.3
|
||||
"daa9d824601c088f52de3da176e14328ba41e7be3eb450fdf8b93c86f236f722" # lix-installer 3.95.0 (47bc300) with flakes
|
||||
"7659f39ef9ab9cdf50f8e6ae3476cbf3f27be6485500d1f225d45574d943a9f7" # lix-installer 3.95.0 (47bc300) without flakes
|
||||
];
|
||||
|
||||
environment.etc."nix/registry.json".text = builtins.toJSON {
|
||||
@@ -757,13 +813,16 @@ in
|
||||
|
||||
# Not in NixOS module
|
||||
{ assertion = elem "nixbld" config.users.knownGroups -> elem "nixbld" createdGroups; message = "refusing to delete group nixbld in users.knownGroups, this would break nix"; }
|
||||
{ assertion = elem "_nixbld1" config.users.knownGroups -> elem "_nixbld1" createdUsers; message = "refusing to delete user _nixbld1 in users.knownUsers, this would break nix"; }
|
||||
{ assertion = elem "_nixbld1" config.users.knownUsers -> elem "_nixbld1" createdUsers; message = "refusing to delete user _nixbld1 in users.knownUsers, this would break nix"; }
|
||||
{ assertion = config.users.groups ? "nixbld" -> config.users.groups.nixbld.members != []; message = "refusing to remove all members from nixbld group, this would break nix"; }
|
||||
|
||||
{
|
||||
# Should be fixed in Lix by https://gerrit.lix.systems/c/lix/+/2100
|
||||
# Should be fixed in Lix by https://gerrit.lix.systems/c/lix/+/2100, Nix by https://github.com/NixOS/nix/commit/d888846b68dd5fad998b84c5cb6246b1b63398cd
|
||||
# Lix 2.92.0 will set `VERSION_SUFFIX` to `""`; `lib.versionAtLeast "" "pre20241107"` will return `true`.
|
||||
assertion = cfg.settings.auto-optimise-store -> (cfg.package.pname == "lix" && (isNixAtLeast "2.92.0" && versionAtLeast (strings.removePrefix "-" cfg.package.VERSION_SUFFIX) "pre20241107"));
|
||||
assertion = cfg.settings.auto-optimise-store -> (
|
||||
(cfg.package.pname == "lix" && (isNixAtLeast "2.92.0" && versionAtLeast (strings.removePrefix "-" cfg.package.VERSION_SUFFIX) "pre20241107"))
|
||||
|| (cfg.package.pname == "nix" && ((isNixAtLeast "2.31.3" && !isNixAtLeast "2.32") || isNixAtLeast "2.32.5" || isNixAtLeast "2.33"))
|
||||
);
|
||||
message = "`nix.settings.auto-optimise-store` is known to corrupt the Nix Store, please use `nix.optimise.automatic` instead.";
|
||||
}
|
||||
];
|
||||
@@ -775,29 +834,26 @@ in
|
||||
|
||||
# Not in NixOS module
|
||||
nix.nixPath = mkIf (config.system.stateVersion < 2) (mkDefault [
|
||||
"darwin=$HOME/.nix-defexpr/darwin"
|
||||
"darwin-config=$HOME/.nixpkgs/darwin-configuration.nix"
|
||||
"darwin=${config.system.primaryUserHome}/.nix-defexpr/darwin"
|
||||
"darwin-config=${config.system.primaryUserHome}/.nixpkgs/darwin-configuration.nix"
|
||||
"/nix/var/nix/profiles/per-user/root/channels"
|
||||
]);
|
||||
|
||||
system.requiresPrimaryUser = mkIf (
|
||||
config.system.stateVersion < 2
|
||||
&& options.nix.nixPath.highestPrio == (mkDefault {}).priority
|
||||
) [
|
||||
"nix.nixPath"
|
||||
];
|
||||
|
||||
# Set up the environment variables for running Nix.
|
||||
environment.variables = cfg.envVars // { NIX_PATH = cfg.nixPath; };
|
||||
|
||||
environment.extraInit = mkMerge [
|
||||
(mkIf cfg.channel.enable ''
|
||||
if [ -e "$HOME/.nix-defexpr/channels" ]; then
|
||||
export NIX_PATH="$HOME/.nix-defexpr/channels''${NIX_PATH:+:$NIX_PATH}"
|
||||
fi
|
||||
'')
|
||||
# Not in NixOS module
|
||||
''
|
||||
# Set up secure multi-user builds: non-root users build through the
|
||||
# Nix daemon.
|
||||
if [ ! -w /nix/var/nix/db ]; then
|
||||
export NIX_REMOTE=daemon
|
||||
fi
|
||||
''
|
||||
];
|
||||
environment.extraInit = mkIf cfg.channel.enable ''
|
||||
if [ -e "$HOME/.nix-defexpr/channels" ]; then
|
||||
export NIX_PATH="$HOME/.nix-defexpr/channels''${NIX_PATH:+:$NIX_PATH}"
|
||||
fi
|
||||
'';
|
||||
|
||||
environment.extraSetup = mkIf (!cfg.channel.enable) ''
|
||||
rm --force $out/bin/nix-channel
|
||||
@@ -805,10 +861,10 @@ in
|
||||
|
||||
nix.nrBuildUsers = mkDefault (max 32 (if cfg.settings.max-jobs == "auto" then 0 else cfg.settings.max-jobs));
|
||||
|
||||
users.users = mkIf cfg.configureBuildUsers nixbldUsers;
|
||||
users.users = mkIf configureBuildUsers nixbldUsers;
|
||||
|
||||
# Not in NixOS module
|
||||
users.groups.nixbld = mkIf cfg.configureBuildUsers {
|
||||
users.groups.nixbld = mkIf configureBuildUsers {
|
||||
description = "Nix build group for nix-daemon";
|
||||
gid = config.ids.gids.nixbld;
|
||||
members = attrNames nixbldUsers;
|
||||
@@ -816,14 +872,66 @@ in
|
||||
users.knownUsers =
|
||||
let nixbldUserNames = attrNames nixbldUsers;
|
||||
in
|
||||
mkIf cfg.configureBuildUsers (mkMerge [
|
||||
mkMerge [
|
||||
nixbldUserNames
|
||||
(map (removePrefix "_") nixbldUserNames) # delete old style nixbld users
|
||||
]);
|
||||
users.knownGroups = mkIf cfg.configureBuildUsers [ "nixbld" ];
|
||||
];
|
||||
users.knownGroups = [ "nixbld" ];
|
||||
|
||||
# The Determinate Systems installer puts user‐specified settings in
|
||||
# `/etc/nix/nix.custom.conf` since v0.33.0. Supplement the
|
||||
# `/etc/nix/nix.conf` hash check so that we don’t accidentally
|
||||
# clobber user configuration.
|
||||
#
|
||||
# TODO: Maybe this could use a more general file placement mechanism
|
||||
# to express that we want it deleted and know only one hash?
|
||||
system.activationScripts.checks.text = mkAfter ''
|
||||
nixCustomConfKnownSha256Hashes=(
|
||||
# DetSys v0.33.0
|
||||
6787fade1cf934f82db554e78e1fc788705c2c5257fddf9b59bdd963ca6fec63
|
||||
# DetSys v0.34.0
|
||||
3bd68ef979a42070a44f8d82c205cfd8e8cca425d91253ec2c10a88179bb34aa
|
||||
# Nix 2.33.3
|
||||
71f7fdc9f6c9e55ca0f2e6f85137037d660b3224a34d59305e8530ca292bc734
|
||||
# Lix 2.95.1
|
||||
a6dee4985bf207d3bec6a3cee28aefb33e60f5d0a91d8c20bbd71b9dadb2e601
|
||||
)
|
||||
if [[ -e /etc/nix/nix.custom.conf ]]; then
|
||||
nixCustomConfSha256Output=$(shasum -a 256 /etc/nix/nix.custom.conf)
|
||||
nixCustomConfSha256Hash=''${nixCustomConfSha256Output%% *}
|
||||
nixCustomConfIsKnown=
|
||||
for nixCustomConfKnownSha256Hash
|
||||
in "''${nixCustomConfKnownSha256Hashes[@]}"
|
||||
do
|
||||
if
|
||||
[[ $nixCustomConfSha256Hash == "$nixCustomConfKnownSha256Hash" ]]
|
||||
then
|
||||
nixCustomConfIsKnown=1
|
||||
break
|
||||
fi
|
||||
done
|
||||
if [[ ! $nixCustomConfIsKnown ]]; then
|
||||
printf >&2 '\e[1;31merror: custom settings in `/etc/nix/nix.custom.conf`, aborting activation\e[0m\n'
|
||||
printf >&2 'You will need to migrate these to nix-darwin `nix.*` settings if you\n'
|
||||
printf >&2 'wish to keep them. Check the manual for the appropriate settings and\n'
|
||||
printf >&2 'add them to your system configuration, then run:\n'
|
||||
printf >&2 '\n'
|
||||
printf >&2 ' $ sudo mv /etc/nix/nix.custom.conf{,.before-nix-darwin}\n'
|
||||
printf >&2 '\n'
|
||||
printf >&2 'and activate your system again.\n'
|
||||
exit 2
|
||||
fi
|
||||
fi
|
||||
'';
|
||||
|
||||
# Unrelated to use in NixOS module
|
||||
system.activationScripts.nix-daemon.text = mkIf cfg.useDaemon ''
|
||||
system.activationScripts.nix-daemon.text = ''
|
||||
# Follow up on the `/etc/nix/nix.custom.conf` check.
|
||||
# TODO: Use a more generalized file placement mechanism for this.
|
||||
if [[ -e /etc/nix/nix.custom.conf ]]; then
|
||||
mv /etc/nix/nix.custom.conf{,.before-nix-darwin}
|
||||
fi
|
||||
|
||||
if ! diff /etc/nix/nix.conf /run/current-system/etc/nix/nix.conf &> /dev/null || ! diff /etc/nix/machines /run/current-system/etc/nix/machines &> /dev/null; then
|
||||
echo "reloading nix-daemon..." >&2
|
||||
launchctl kill HUP system/org.nixos.nix-daemon
|
||||
@@ -840,6 +948,9 @@ in
|
||||
trusted-users = [ "root" ];
|
||||
substituters = mkAfter [ "https://cache.nixos.org/" ];
|
||||
|
||||
# Not in NixOS module
|
||||
build-users-group = "nixbld";
|
||||
|
||||
# Not implemented yet
|
||||
# system-features = mkDefault (
|
||||
# [ "nixos-test" "benchmark" "big-parallel" "kvm" ] ++
|
||||
@@ -855,8 +966,6 @@ in
|
||||
|
||||
(mkIf (isNixAtLeast "2.3pre") { sandbox-fallback = false; })
|
||||
|
||||
# Not in NixOS module
|
||||
(mkIf cfg.useDaemon { build-users-group = "nixbld"; })
|
||||
];
|
||||
|
||||
};
|
||||
|
||||
@@ -144,7 +144,7 @@ in
|
||||
|
||||
workingDirectory = mkOption {
|
||||
type = types.str;
|
||||
default = "/var/lib/darwin-builder";
|
||||
default = "/var/lib/linux-builder";
|
||||
description = ''
|
||||
The working directory of the Linux builder daemon process.
|
||||
'';
|
||||
@@ -159,57 +159,76 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
system.activationScripts.preActivation.text = ''
|
||||
mkdir -p ${cfg.workingDirectory}
|
||||
'';
|
||||
config = mkMerge [
|
||||
(mkIf (!cfg.enable) {
|
||||
system.activationScripts.preActivation.text = ''
|
||||
rm -rf ${cfg.workingDirectory}
|
||||
'';
|
||||
})
|
||||
(mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`nix.linux-builder.enable` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
|
||||
launchd.daemons.linux-builder = {
|
||||
environment = {
|
||||
inherit (config.environment.variables) NIX_SSL_CERT_FILE;
|
||||
};
|
||||
system.activationScripts.preActivation.text = ''
|
||||
# Migrate if using the old working directory
|
||||
if [ -e /var/lib/darwin-builder ] && [ ! -e ${cfg.workingDirectory} ]; then
|
||||
mv /var/lib/darwin-builder ${cfg.workingDirectory}
|
||||
fi
|
||||
|
||||
# create-builder uses TMPDIR to share files with the builder, notably certs.
|
||||
# macOS will clean up files in /tmp automatically that haven't been accessed in 3+ days.
|
||||
# If we let it use /tmp, leaving the computer asleep for 3 days makes the certs vanish.
|
||||
# So we'll use /run/org.nixos.linux-builder instead and clean it up ourselves.
|
||||
script = ''
|
||||
export TMPDIR=/run/org.nixos.linux-builder USE_TMPDIR=1
|
||||
rm -rf $TMPDIR
|
||||
mkdir -p $TMPDIR
|
||||
trap "rm -rf $TMPDIR" EXIT
|
||||
${lib.optionalString cfg.ephemeral ''
|
||||
rm -f ${cfg.workingDirectory}/${cfg.package.nixosConfig.networking.hostName}.qcow2
|
||||
''}
|
||||
${cfg.package}/bin/create-builder
|
||||
mkdir -p ${cfg.workingDirectory}
|
||||
'';
|
||||
|
||||
serviceConfig = {
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
WorkingDirectory = cfg.workingDirectory;
|
||||
launchd.daemons.linux-builder = {
|
||||
environment = {
|
||||
inherit (config.environment.variables) NIX_SSL_CERT_FILE;
|
||||
};
|
||||
|
||||
# create-builder uses TMPDIR to share files with the builder, notably certs.
|
||||
# macOS will clean up files in /tmp automatically that haven't been accessed in 3+ days.
|
||||
# If we let it use /tmp, leaving the computer asleep for 3 days makes the certs vanish.
|
||||
# So we'll use /run/org.nixos.linux-builder instead and clean it up ourselves.
|
||||
script = ''
|
||||
export TMPDIR=/run/org.nixos.linux-builder USE_TMPDIR=1
|
||||
rm -rf $TMPDIR
|
||||
mkdir -p $TMPDIR
|
||||
trap "rm -rf $TMPDIR" EXIT
|
||||
${lib.optionalString cfg.ephemeral ''
|
||||
rm -f ${cfg.workingDirectory}/${cfg.package.nixosConfig.networking.hostName}.qcow2
|
||||
''}
|
||||
${cfg.package}/bin/create-builder
|
||||
'';
|
||||
|
||||
serviceConfig = {
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
WorkingDirectory = cfg.workingDirectory;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
environment.etc."ssh/ssh_config.d/100-linux-builder.conf".text = ''
|
||||
Host linux-builder
|
||||
User builder
|
||||
Hostname localhost
|
||||
HostKeyAlias linux-builder
|
||||
Port 31022
|
||||
IdentityFile /etc/nix/builder_ed25519
|
||||
'';
|
||||
environment.etc."ssh/ssh_config.d/100-linux-builder.conf".text = ''
|
||||
Host linux-builder
|
||||
User builder
|
||||
Hostname localhost
|
||||
HostKeyAlias linux-builder
|
||||
Port 31022
|
||||
IdentityFile /etc/nix/builder_ed25519
|
||||
'';
|
||||
|
||||
nix.distributedBuilds = true;
|
||||
nix.distributedBuilds = true;
|
||||
|
||||
nix.buildMachines = [{
|
||||
hostName = "linux-builder";
|
||||
sshUser = "builder";
|
||||
sshKey = "/etc/nix/builder_ed25519";
|
||||
publicHostKey = "c3NoLWVkMjU1MTkgQUFBQUMzTnphQzFsWkRJMU5URTVBQUFBSUpCV2N4Yi9CbGFxdDFhdU90RStGOFFVV3JVb3RpQzVxQkorVXVFV2RWQ2Igcm9vdEBuaXhvcwo=";
|
||||
inherit (cfg) mandatoryFeatures maxJobs protocol speedFactor supportedFeatures systems;
|
||||
}];
|
||||
nix.buildMachines = [{
|
||||
hostName = "linux-builder";
|
||||
sshUser = "builder";
|
||||
sshKey = "/etc/nix/builder_ed25519";
|
||||
publicHostKey = "c3NoLWVkMjU1MTkgQUFBQUMzTnphQzFsWkRJMU5URTVBQUFBSUpCV2N4Yi9CbGFxdDFhdU90RStGOFFVV3JVb3RpQzVxQkorVXVFV2RWQ2Igcm9vdEBuaXhvcwo=";
|
||||
inherit (cfg) mandatoryFeatures maxJobs protocol speedFactor supportedFeatures systems;
|
||||
}];
|
||||
|
||||
nix.settings.builders-use-substitutes = true;
|
||||
};
|
||||
nix.settings.builders-use-substitutes = true;
|
||||
})
|
||||
];
|
||||
}
|
||||
|
||||
+28
-22
@@ -4,44 +4,50 @@ let
|
||||
nix-tools = pkgs.callPackage ../../pkgs/nix-tools {
|
||||
inherit (config.system) profile;
|
||||
inherit (config.environment) systemPath;
|
||||
nixPackage = config.nix.package;
|
||||
nixPath = lib.optionalString config.nix.enable (lib.concatStringsSep ":" config.nix.nixPath);
|
||||
nixPackage = if config.nix.enable then config.nix.package else null;
|
||||
};
|
||||
|
||||
darwin-uninstaller = pkgs.callPackage ../../pkgs/darwin-uninstaller { };
|
||||
|
||||
inherit (nix-tools) darwin-option darwin-rebuild darwin-version;
|
||||
mkToolModule = { name, package ? nix-tools.${name} }: { config, ... }: {
|
||||
options.system.tools.${name}.enable = lib.mkEnableOption "${name} script" // {
|
||||
default = config.system.tools.enable;
|
||||
};
|
||||
|
||||
config = lib.mkIf config.system.tools.${name}.enable {
|
||||
environment.systemPackages = [ package ];
|
||||
};
|
||||
};
|
||||
in
|
||||
|
||||
{
|
||||
options.system = {
|
||||
disableInstallerTools = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
internal = true;
|
||||
default = false;
|
||||
description = ''
|
||||
Disable darwin-rebuild and darwin-option. This is useful to shrink
|
||||
systems which are not expected to rebuild or reconfigure themselves.
|
||||
Use at your own risk!
|
||||
'';
|
||||
};
|
||||
|
||||
includeUninstaller = lib.mkOption {
|
||||
tools.enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
internal = true;
|
||||
default = true;
|
||||
description = ''
|
||||
Disable internal tools, such as darwin-rebuild and darwin-option. This
|
||||
is useful to shrink systems which are not expected to rebuild or
|
||||
reconfigure themselves. Use at your own risk!
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
environment.systemPackages =
|
||||
[ darwin-version ]
|
||||
++ lib.optionals (!config.system.disableInstallerTools) [
|
||||
darwin-option
|
||||
darwin-rebuild
|
||||
] ++ lib.optional config.system.includeUninstaller darwin-uninstaller;
|
||||
imports = [
|
||||
(lib.mkRenamedOptionModule [ "system" "includeUninstaller" ] [ "system" "tools" "darwin-uninstaller" "enable" ])
|
||||
(lib.mkRemovedOptionModule [ "system" "disableInstallerTools" ] "Please use system.tools.enable instead")
|
||||
|
||||
(mkToolModule { name = "darwin-option"; })
|
||||
(mkToolModule { name = "darwin-rebuild"; })
|
||||
(mkToolModule { name = "darwin-version"; })
|
||||
(mkToolModule { name = "darwin-uninstaller"; package = darwin-uninstaller; })
|
||||
];
|
||||
|
||||
config = {
|
||||
system.build = {
|
||||
inherit darwin-option darwin-rebuild darwin-version;
|
||||
inherit (nix-tools) darwin-option darwin-rebuild darwin-version;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -37,8 +37,8 @@ in
|
||||
setNixPath = mkOption {
|
||||
type = types.bool;
|
||||
|
||||
default = cfg.source != null;
|
||||
defaultText = "config.nixpkgs.flake.source != null";
|
||||
default = config.nix.enable && cfg.source != null;
|
||||
defaultText = literalExpression ''config.nix.enable && nixpkgs.flake.source != null'';
|
||||
|
||||
description = ''
|
||||
Whether to set {env}`NIX_PATH` to include `nixpkgs=flake:nixpkgs` such that `<nixpkgs>`
|
||||
@@ -57,8 +57,8 @@ in
|
||||
setFlakeRegistry = mkOption {
|
||||
type = types.bool;
|
||||
|
||||
default = cfg.source != null;
|
||||
defaultText = "config.nixpkgs.flake.source != null";
|
||||
default = config.nix.enable && cfg.source != null;
|
||||
defaultText = literalExpression ''config.nix.enable && config.nixpkgs.flake.source != null'';
|
||||
|
||||
description = ''
|
||||
Whether to pin nixpkgs in the system-wide flake registry (`/etc/nix/registry.json`) to the
|
||||
@@ -85,6 +85,18 @@ in
|
||||
be set, since it is implemented in terms of indirection through the flake registry.
|
||||
'';
|
||||
}
|
||||
|
||||
# TODO: Upstream these to NixOS.
|
||||
|
||||
{
|
||||
assertion = cfg.setNixPath -> config.nix.enable;
|
||||
message = ''`nixpkgs.flake.setNixPath` requires `nix.enable`'';
|
||||
}
|
||||
|
||||
{
|
||||
assertion = cfg.setFlakeRegistry -> config.nix.enable;
|
||||
message = ''`nixpkgs.flake.setFlakeRegistry` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
}
|
||||
(mkIf cfg.setFlakeRegistry {
|
||||
|
||||
+136
-112
@@ -1,89 +1,99 @@
|
||||
{ config, options, lib, pkgs, ... }:
|
||||
|
||||
with lib;
|
||||
{
|
||||
config,
|
||||
options,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.nixpkgs;
|
||||
opt = options.nixpkgs;
|
||||
|
||||
isConfig = x:
|
||||
builtins.isAttrs x || lib.isFunction x;
|
||||
isConfig = x: builtins.isAttrs x || lib.isFunction x;
|
||||
|
||||
optCall = f: x:
|
||||
if lib.isFunction f
|
||||
then f x
|
||||
else f;
|
||||
optCall = f: x: if lib.isFunction f then f x else f;
|
||||
|
||||
mergeConfig = lhs_: rhs_:
|
||||
mergeConfig =
|
||||
lhs_: rhs_:
|
||||
let
|
||||
lhs = optCall lhs_ { inherit pkgs; };
|
||||
rhs = optCall rhs_ { inherit pkgs; };
|
||||
lhs = optCall lhs_ { inherit lib pkgs; };
|
||||
rhs = optCall rhs_ { inherit lib pkgs; };
|
||||
in
|
||||
recursiveUpdate lhs rhs //
|
||||
optionalAttrs (lhs ? packageOverrides) {
|
||||
packageOverrides = pkgs:
|
||||
optCall lhs.packageOverrides pkgs //
|
||||
optCall (attrByPath [ "packageOverrides" ] { } rhs) pkgs;
|
||||
} //
|
||||
optionalAttrs (lhs ? perlPackageOverrides) {
|
||||
perlPackageOverrides = pkgs:
|
||||
optCall lhs.perlPackageOverrides pkgs //
|
||||
optCall (attrByPath [ "perlPackageOverrides" ] { } rhs) pkgs;
|
||||
lib.recursiveUpdate lhs rhs
|
||||
// lib.optionalAttrs (lhs ? allowUnfreePackages) {
|
||||
allowUnfreePackages = lhs.allowUnfreePackages ++ (lib.attrByPath [ "allowUnfreePackages" ] [ ] rhs);
|
||||
}
|
||||
// lib.optionalAttrs (lhs ? packageOverrides) {
|
||||
packageOverrides =
|
||||
pkgs:
|
||||
optCall lhs.packageOverrides pkgs // optCall (lib.attrByPath [ "packageOverrides" ] { } rhs) pkgs;
|
||||
}
|
||||
// lib.optionalAttrs (lhs ? perlPackageOverrides) {
|
||||
perlPackageOverrides =
|
||||
pkgs:
|
||||
optCall lhs.perlPackageOverrides pkgs
|
||||
// optCall (lib.attrByPath [ "perlPackageOverrides" ] { } rhs) pkgs;
|
||||
};
|
||||
|
||||
configType = mkOptionType {
|
||||
configType = lib.mkOptionType {
|
||||
name = "nixpkgs-config";
|
||||
description = "nixpkgs config";
|
||||
check = x:
|
||||
let traceXIfNot = c:
|
||||
if c x then true
|
||||
else lib.traceSeqN 1 x false;
|
||||
in traceXIfNot isConfig;
|
||||
merge = args: foldr (def: mergeConfig def.value) {};
|
||||
check =
|
||||
x:
|
||||
let
|
||||
traceXIfNot = c: if c x then true else lib.traceSeqN 1 x false;
|
||||
in
|
||||
traceXIfNot isConfig;
|
||||
merge = args: lib.foldr (def: mergeConfig def.value) { };
|
||||
};
|
||||
|
||||
overlayType = mkOptionType {
|
||||
overlayType = lib.mkOptionType {
|
||||
name = "nixpkgs-overlay";
|
||||
description = "nixpkgs overlay";
|
||||
check = lib.isFunction;
|
||||
merge = lib.mergeOneOption;
|
||||
};
|
||||
|
||||
pkgsType = types.pkgs // {
|
||||
pkgsType = lib.types.pkgs // {
|
||||
# This type is only used by itself, so let's elaborate the description a bit
|
||||
# for the purpose of documentation.
|
||||
description = "An evaluation of Nixpkgs; the top level attribute set of packages";
|
||||
};
|
||||
|
||||
hasBuildPlatform = opt.buildPlatform.highestPrio < (mkOptionDefault {}).priority;
|
||||
hasBuildPlatform = opt.buildPlatform.highestPrio < (lib.mkOptionDefault { }).priority;
|
||||
hasHostPlatform = opt.hostPlatform.isDefined;
|
||||
hasPlatform = hasHostPlatform || hasBuildPlatform;
|
||||
|
||||
# Context for messages
|
||||
hostPlatformLine = optionalString hasHostPlatform "${showOptionWithDefLocs opt.hostPlatform}";
|
||||
buildPlatformLine = optionalString hasBuildPlatform "${showOptionWithDefLocs opt.buildPlatform}";
|
||||
hostPlatformLine = lib.optionalString hasHostPlatform "${lib.showOptionWithDefLocs opt.hostPlatform}";
|
||||
buildPlatformLine = lib.optionalString hasBuildPlatform "${lib.showOptionWithDefLocs opt.buildPlatform}";
|
||||
|
||||
legacyOptionsDefined =
|
||||
optional (opt.system.highestPrio < (mkDefault {}).priority) opt.system
|
||||
;
|
||||
legacyOptionsDefined = lib.optional (
|
||||
opt.system.highestPrio < (lib.mkDefault { }).priority
|
||||
) opt.system;
|
||||
|
||||
defaultPkgs =
|
||||
if opt.hostPlatform.isDefined
|
||||
then
|
||||
let isCross = cfg.buildPlatform != cfg.hostPlatform;
|
||||
systemArgs =
|
||||
if isCross
|
||||
then {
|
||||
if opt.hostPlatform.isDefined then
|
||||
let
|
||||
isCross = cfg.buildPlatform != cfg.hostPlatform;
|
||||
systemArgs =
|
||||
if isCross then
|
||||
{
|
||||
localSystem = cfg.buildPlatform;
|
||||
crossSystem = cfg.hostPlatform;
|
||||
}
|
||||
else {
|
||||
else
|
||||
{
|
||||
localSystem = cfg.hostPlatform;
|
||||
};
|
||||
in
|
||||
import cfg.source ({
|
||||
inherit (cfg) config overlays;
|
||||
} // systemArgs)
|
||||
import cfg.source (
|
||||
{
|
||||
inherit (cfg) config overlays;
|
||||
}
|
||||
// systemArgs
|
||||
)
|
||||
else
|
||||
import cfg.source {
|
||||
inherit (cfg) config overlays;
|
||||
@@ -96,9 +106,9 @@ in
|
||||
|
||||
{
|
||||
options.nixpkgs = {
|
||||
pkgs = mkOption {
|
||||
pkgs = lib.mkOption {
|
||||
type = pkgsType;
|
||||
example = literalExpression "import <nixpkgs> {}";
|
||||
example = lib.literalExpression "import <nixpkgs> {}";
|
||||
description = ''
|
||||
If set, the pkgs argument to all nix-darwin modules is the value of
|
||||
this option, extended with `nixpkgs.overlays`, if
|
||||
@@ -120,53 +130,48 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
config = mkOption {
|
||||
default = {};
|
||||
example = literalExpression
|
||||
''
|
||||
{ allowBroken = true; allowUnfree = true; }
|
||||
'';
|
||||
config = lib.mkOption {
|
||||
default = { };
|
||||
example = lib.literalExpression ''
|
||||
{ allowBroken = true; allowUnfree = true; }
|
||||
'';
|
||||
type = configType;
|
||||
description = ''
|
||||
The configuration of the Nix Packages collection. (For
|
||||
details, see the Nixpkgs documentation.) It allows you to set
|
||||
package configuration options.
|
||||
Global configuration for Nixpkgs.
|
||||
The complete list of [Nixpkgs configuration options](https://nixos.org/manual/nixpkgs/unstable/#sec-config-options-reference) is in the [Nixpkgs manual section on global configuration](https://nixos.org/manual/nixpkgs/unstable/#chap-packageconfig).
|
||||
|
||||
Ignored when `nixpkgs.pkgs` is set.
|
||||
Ignored when {option}`nixpkgs.pkgs` is set.
|
||||
'';
|
||||
};
|
||||
|
||||
overlays = mkOption {
|
||||
default = [];
|
||||
example = literalExpression
|
||||
''
|
||||
[
|
||||
(self: super: {
|
||||
openssh = super.openssh.override {
|
||||
hpnSupport = true;
|
||||
kerberos = self.libkrb5;
|
||||
};
|
||||
})
|
||||
]
|
||||
'';
|
||||
type = types.listOf overlayType;
|
||||
overlays = lib.mkOption {
|
||||
default = [ ];
|
||||
example = lib.literalExpression ''
|
||||
[
|
||||
(self: super: {
|
||||
openssh = super.openssh.override {
|
||||
hpnSupport = true;
|
||||
kerberos = self.libkrb5;
|
||||
};
|
||||
})
|
||||
]
|
||||
'';
|
||||
type = lib.types.listOf overlayType;
|
||||
description = ''
|
||||
List of overlays to use with the Nix Packages collection.
|
||||
(For details, see the Nixpkgs documentation.) It allows
|
||||
you to override packages globally. Each function in the list
|
||||
takes as an argument the *original* Nixpkgs.
|
||||
The first argument should be used for finding dependencies, and
|
||||
the second should be used for overriding recipes.
|
||||
List of overlays to apply to Nixpkgs.
|
||||
This option allows modifying the Nixpkgs package set accessed through the `pkgs` module argument.
|
||||
|
||||
If `nixpkgs.pkgs` is set, overlays specified here
|
||||
will be applied after the overlays that were already present
|
||||
in `nixpkgs.pkgs`.
|
||||
For details, see the [Overlays chapter in the Nixpkgs manual](https://nixos.org/manual/nixpkgs/stable/#chap-overlays).
|
||||
|
||||
If the {option}`nixpkgs.pkgs` option is set, overlays specified using `nixpkgs.overlays` will be applied after the overlays that were already included in `nixpkgs.pkgs`.
|
||||
'';
|
||||
};
|
||||
|
||||
hostPlatform = mkOption {
|
||||
type = types.either types.str types.attrs; # TODO utilize lib.systems.parsedPlatform
|
||||
example = { system = "aarch64-darwin"; config = "aarch64-apple-darwin"; };
|
||||
hostPlatform = lib.mkOption {
|
||||
type = lib.types.either lib.types.str lib.types.attrs; # TODO utilize lib.systems.parsedPlatform
|
||||
example = {
|
||||
system = "aarch64-darwin";
|
||||
};
|
||||
# Make sure that the final value has all fields for sake of other modules
|
||||
# referring to this. TODO make `lib.systems` itself use the module system.
|
||||
apply = lib.systems.elaborate;
|
||||
@@ -179,15 +184,24 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
buildPlatform = mkOption {
|
||||
type = types.either types.str types.attrs; # TODO utilize lib.systems.parsedPlatform
|
||||
buildPlatform = lib.mkOption {
|
||||
type = lib.types.either lib.types.str lib.types.attrs; # TODO utilize lib.systems.parsedPlatform
|
||||
default = cfg.hostPlatform;
|
||||
example = { system = "x86_64-darwin"; config = "x86_64-apple-darwin"; };
|
||||
example = {
|
||||
system = "x86_64-darwin";
|
||||
};
|
||||
# Make sure that the final value has all fields for sake of other modules
|
||||
# referring to this.
|
||||
apply = lib.systems.elaborate;
|
||||
defaultText = literalExpression
|
||||
''config.nixpkgs.hostPlatform'';
|
||||
apply =
|
||||
inputBuildPlatform:
|
||||
let
|
||||
elaborated = lib.systems.elaborate inputBuildPlatform;
|
||||
in
|
||||
if lib.systems.equals elaborated cfg.hostPlatform then
|
||||
cfg.hostPlatform # make identical, so that `==` equality works; see https://github.com/NixOS/nixpkgs/issues/278001
|
||||
else
|
||||
elaborated;
|
||||
defaultText = lib.literalExpression ''config.nixpkgs.hostPlatform'';
|
||||
description = ''
|
||||
Specifies the platform on which nix-darwin should be built.
|
||||
By default, nix-darwin is built on the system where it runs, but you can
|
||||
@@ -202,12 +216,11 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
system = mkOption {
|
||||
type = types.str;
|
||||
system = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
example = "x86_64-darwin";
|
||||
default =
|
||||
if opt.hostPlatform.isDefined
|
||||
then
|
||||
if opt.hostPlatform.isDefined then
|
||||
throw ''
|
||||
Neither ${opt.system} nor any other option in nixpkgs.* is meant
|
||||
to be read by modules and configurations.
|
||||
@@ -232,9 +245,9 @@ in
|
||||
|
||||
# nix-darwin only
|
||||
|
||||
source = mkOption {
|
||||
type = types.path;
|
||||
defaultText = literalMD ''
|
||||
source = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
defaultText = lib.literalMD ''
|
||||
`<nixpkgs>` or nix-darwin's `nixpkgs` flake input
|
||||
'';
|
||||
description = ''
|
||||
@@ -247,8 +260,8 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
constructedByUs = mkOption {
|
||||
type = types.bool;
|
||||
constructedByUs = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
internal = true;
|
||||
description = ''
|
||||
Whether `pkgs` was constructed by this module. This is false when any of
|
||||
@@ -266,40 +279,51 @@ in
|
||||
# which is somewhat costly for Nixpkgs. With an explicit priority, we only
|
||||
# evaluate the wrapper to find out that the priority is lower, and then we
|
||||
# don't need to evaluate `finalPkgs`.
|
||||
lib.mkOverride lib.modules.defaultOverridePriority
|
||||
finalPkgs.__splicedPackages;
|
||||
lib.mkOverride lib.modules.defaultOverridePriority finalPkgs.__splicedPackages;
|
||||
};
|
||||
|
||||
nixpkgs.constructedByUs =
|
||||
# We set it with default priority and it can not be merged, so if the
|
||||
# pkgs module argument has that priority, it's from us.
|
||||
(lib.modules.mergeAttrDefinitionsWithPrio options._module.args).pkgs.highestPrio
|
||||
== lib.modules.defaultOverridePriority
|
||||
== lib.modules.defaultOverridePriority
|
||||
# Although, if nixpkgs.pkgs is set, we did forward it, but we did not construct it.
|
||||
&& !opt.pkgs.isDefined;
|
||||
&& !opt.pkgs.isDefined;
|
||||
|
||||
assertions = [
|
||||
(
|
||||
let
|
||||
pkgsSystem = finalPkgs.stdenv.targetPlatform.system;
|
||||
in {
|
||||
in
|
||||
{
|
||||
assertion = cfg.constructedByUs -> !hasPlatform -> cfg.system == pkgsSystem;
|
||||
message = "The nix-darwin nixpkgs.pkgs option was set to a Nixpkgs invocation that compiles to target system ${pkgsSystem} but nix-darwin was configured for system ${darwinExpectedSystem} via nix-darwin option nixpkgs.system. The nix-darwin system settings must match the Nixpkgs target system.";
|
||||
message = "The nix-darwin nixpkgs.pkgs option was set to a Nixpkgs invocation that compiles to target system ${pkgsSystem} but nix-darwin was configured for system ${config.nixpkgs.system} via nix-darwin option nixpkgs.system. The nix-darwin system settings must match the Nixpkgs target system.";
|
||||
}
|
||||
)
|
||||
{
|
||||
assertion = cfg.constructedByUs -> hasPlatform -> legacyOptionsDefined == [];
|
||||
assertion = cfg.constructedByUs -> hasPlatform -> legacyOptionsDefined == [ ];
|
||||
message = ''
|
||||
Your system configures nixpkgs with the platform parameter${optionalString hasBuildPlatform "s"}:
|
||||
${hostPlatformLine
|
||||
}${buildPlatformLine
|
||||
}
|
||||
Your system configures nixpkgs with the platform parameter${lib.optionalString hasBuildPlatform "s"}:
|
||||
${hostPlatformLine}${buildPlatformLine}
|
||||
However, it also defines the legacy options:
|
||||
${concatMapStrings showOptionWithDefLocs legacyOptionsDefined}
|
||||
${lib.concatMapStrings lib.showOptionWithDefLocs legacyOptionsDefined}
|
||||
For a future proof system configuration, we recommend to remove
|
||||
the legacy definitions.
|
||||
'';
|
||||
}
|
||||
{
|
||||
assertion = opt.pkgs.isDefined -> cfg.config == { };
|
||||
message = ''
|
||||
Your system configures nixpkgs with an externally created instance.
|
||||
`nixpkgs.config` options should be passed when creating the instance instead.
|
||||
|
||||
Current value:
|
||||
${lib.generators.toPretty { multiline = true; } cfg.config}
|
||||
|
||||
Defined in:
|
||||
${lib.concatMapStringsSep "\n" (file: " - ${file}") opt.config.files}
|
||||
'';
|
||||
}
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs._1password-gui;
|
||||
in
|
||||
{
|
||||
options = {
|
||||
programs._1password-gui = {
|
||||
enable = lib.mkEnableOption "the 1Password GUI application";
|
||||
|
||||
package = lib.mkPackageOption pkgs "1Password GUI" {
|
||||
default = [ "_1password-gui" ];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
# Based on https://github.com/reckenrode/nixos-configs/blob/22b8357fc6ffbd0df5ce50dc417c23a807a268a2/modules/by-name/1p/1password/darwin-module.nix
|
||||
system.activationScripts.applications.text = lib.mkAfter ''
|
||||
install -o root -g wheel -m0555 -d "/Applications/1Password.app"
|
||||
|
||||
rsyncFlags=(
|
||||
# mtime is standardized in the nix store, which would leave only file size to distinguish files.
|
||||
# Thus we need checksums, despite the speed penalty.
|
||||
--checksum
|
||||
# Converts all symlinks pointing outside of the copied tree (thus unsafe) into real files and directories.
|
||||
# This neatly converts all the symlinks pointing to application bundles in the nix store into
|
||||
# real directories, without breaking any relative symlinks inside of application bundles.
|
||||
# This is good enough, because the make-symlinks-relative.sh setup hook converts all $out internal
|
||||
# symlinks to relative ones.
|
||||
--copy-unsafe-links
|
||||
--archive
|
||||
--delete
|
||||
--chmod=-w
|
||||
--no-group
|
||||
--no-owner
|
||||
)
|
||||
|
||||
${lib.getExe pkgs.rsync} "''${rsyncFlags[@]}" \
|
||||
${cfg.package}/Applications/1Password.app/ /Applications/1Password.app
|
||||
'';
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs._1password;
|
||||
in
|
||||
{
|
||||
options = {
|
||||
programs._1password = {
|
||||
enable = lib.mkEnableOption "the 1Password CLI tool";
|
||||
|
||||
package = lib.mkPackageOption pkgs "1Password CLI" {
|
||||
default = [ "_1password-cli" ];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
# Integration with the 1Password GUI will only work if the CLI at `/usr/local/bin/op`
|
||||
# Based on https://github.com/reckenrode/nixos-configs/blob/22b8357fc6ffbd0df5ce50dc417c23a807a268a2/modules/by-name/1p/1password/darwin-module.nix
|
||||
system.activationScripts.applications.text = lib.mkAfter ''
|
||||
install -o root -g wheel -m0555 -D \
|
||||
${lib.getExe cfg.package} /usr/local/bin/op
|
||||
'';
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs.arqbackup;
|
||||
in
|
||||
{
|
||||
options = {
|
||||
programs.arqbackup = {
|
||||
enable = lib.mkEnableOption "Arq backup";
|
||||
|
||||
# If `arq` is not available then we set `default` to `null` to prevent
|
||||
# eval from breaking while `arq` hasn't been merged yet. Only if a user
|
||||
# enables the module will they be required to set this option.
|
||||
package = lib.mkPackageOption pkgs "arq" (lib.optionalAttrs (!pkgs ? arq) { default = null; });
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
launchd.daemons.arqagent = {
|
||||
command = "${cfg.package}/Applications/Arq.app/Contents/Resources/ArqAgent.app/Contents/MacOS/ArqAgent";
|
||||
serviceConfig.Label = "com.haystacksoftware.arqagent";
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive = true;
|
||||
};
|
||||
|
||||
launchd.user.agents.ArqMonitor = {
|
||||
command = "${cfg.package}/Applications/Arq.app/Contents/Resources/ArqMonitor.app/Contents/MacOS/ArqMonitor";
|
||||
serviceConfig.Label = "com.haystacksoftware.ArqMonitor";
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "programs.arqbackup.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,53 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs.devenv;
|
||||
|
||||
hook = shell: "${lib.getExe cfg.package} hook ${shell}";
|
||||
in
|
||||
{
|
||||
meta.maintainers = [
|
||||
lib.maintainers.domenkozar or "domenkozar"
|
||||
lib.maintainers.sandydoo or "sandydoo"
|
||||
lib.maintainers.anish or "anish"
|
||||
];
|
||||
|
||||
options.programs.devenv = {
|
||||
enable = lib.mkEnableOption "devenv, fast, declarative, reproducible and composable developer environments";
|
||||
|
||||
package = lib.mkPackageOption pkgs "devenv" { };
|
||||
|
||||
enableBashIntegration = lib.mkEnableOption "auto-activation of devenv environments in Bash" // {
|
||||
default = true;
|
||||
};
|
||||
|
||||
enableFishIntegration = lib.mkEnableOption "auto-activation of devenv environments in Fish" // {
|
||||
default = true;
|
||||
};
|
||||
|
||||
enableZshIntegration = lib.mkEnableOption "auto-activation of devenv environments in Zsh" // {
|
||||
default = true;
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
programs.bash.interactiveShellInit = lib.mkIf cfg.enableBashIntegration ''
|
||||
eval "$(${hook "bash"})"
|
||||
'';
|
||||
|
||||
programs.fish.interactiveShellInit = lib.mkIf cfg.enableFishIntegration ''
|
||||
${hook "fish"} | source
|
||||
'';
|
||||
|
||||
programs.zsh.interactiveShellInit = lib.mkIf cfg.enableZshIntegration ''
|
||||
eval "$(${hook "zsh"})"
|
||||
'';
|
||||
};
|
||||
}
|
||||
+69
-23
@@ -5,12 +5,19 @@
|
||||
...
|
||||
}: let
|
||||
cfg = config.programs.direnv;
|
||||
enabledOption =
|
||||
x:
|
||||
lib.mkEnableOption x
|
||||
// {
|
||||
default = true;
|
||||
example = false;
|
||||
};
|
||||
format = pkgs.formats.toml {};
|
||||
in {
|
||||
meta.maintainers = [
|
||||
lib.maintainers.mattpolzin or "mattpolzin"
|
||||
];
|
||||
options.programs.direnv = {
|
||||
|
||||
enable = lib.mkEnableOption ''
|
||||
direnv integration. Takes care of both installation and
|
||||
setting up the sourcing of the shell. Additionally enables nix-direnv
|
||||
@@ -19,6 +26,22 @@ in {
|
||||
|
||||
package = lib.mkPackageOption pkgs "direnv" {};
|
||||
|
||||
finalPackage = lib.mkOption {
|
||||
type = lib.types.package;
|
||||
readOnly = true;
|
||||
description = "The wrapped direnv package.";
|
||||
};
|
||||
|
||||
enableBashIntegration = enabledOption ''
|
||||
Bash integration
|
||||
'';
|
||||
enableZshIntegration = enabledOption ''
|
||||
Zsh integration
|
||||
'';
|
||||
enableFishIntegration = enabledOption ''
|
||||
Fish integration
|
||||
'';
|
||||
|
||||
direnvrcExtra = lib.mkOption {
|
||||
type = lib.types.lines;
|
||||
default = "";
|
||||
@@ -54,53 +77,76 @@ in {
|
||||
|
||||
package = lib.mkPackageOption pkgs "nix-direnv" {};
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
inherit (format) type;
|
||||
default = {};
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
global = {
|
||||
log_format = "-";
|
||||
log_filter = "^$";
|
||||
};
|
||||
}
|
||||
'';
|
||||
description = ''
|
||||
Direnv configuration. Refer to {manpage}`direnv.toml(1)`.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
|
||||
programs = {
|
||||
zsh.interactiveShellInit = ''
|
||||
direnv = {
|
||||
finalPackage = pkgs.symlinkJoin {
|
||||
inherit (cfg.package) name;
|
||||
paths = [cfg.package];
|
||||
# direnv has a fish library which automatically sources direnv for some reason
|
||||
postBuild = ''
|
||||
rm -rf "$out/share/fish"
|
||||
'';
|
||||
meta.mainProgram = "direnv";
|
||||
};
|
||||
settings = lib.mkIf cfg.silent {
|
||||
global = {
|
||||
log_format = lib.mkDefault "-";
|
||||
log_filter = lib.mkDefault "^$";
|
||||
};
|
||||
};
|
||||
};
|
||||
zsh.interactiveShellInit = lib.mkIf cfg.enableZshIntegration ''
|
||||
if ${lib.boolToString cfg.loadInNixShell} || printenv PATH | grep -vqc '/nix/store'; then
|
||||
eval "$(${lib.getExe cfg.package} hook zsh)"
|
||||
eval "$(${lib.getExe cfg.finalPackage} hook zsh)"
|
||||
fi
|
||||
'';
|
||||
|
||||
#$NIX_GCROOT for "nix develop" https://github.com/NixOS/nix/blob/6db66ebfc55769edd0c6bc70fcbd76246d4d26e0/src/nix/develop.cc#L530
|
||||
#$IN_NIX_SHELL for "nix-shell"
|
||||
bash.interactiveShellInit = ''
|
||||
bash.interactiveShellInit = lib.mkIf cfg.enableBashIntegration ''
|
||||
if ${lib.boolToString cfg.loadInNixShell} || [ -z "$IN_NIX_SHELL$NIX_GCROOT$(printenv PATH | grep '/nix/store')" ] ; then
|
||||
eval "$(${lib.getExe cfg.package} hook bash)"
|
||||
eval "$(${lib.getExe cfg.finalPackage} hook bash)"
|
||||
fi
|
||||
'';
|
||||
|
||||
fish.interactiveShellInit = ''
|
||||
fish.interactiveShellInit = lib.mkIf cfg.enableFishIntegration ''
|
||||
if ${lib.boolToString cfg.loadInNixShell};
|
||||
or printenv PATH | grep -vqc '/nix/store';
|
||||
${lib.getExe cfg.package} hook fish | source
|
||||
${lib.getExe cfg.finalPackage} hook fish | source
|
||||
end
|
||||
'';
|
||||
};
|
||||
|
||||
environment = {
|
||||
systemPackages =
|
||||
if cfg.loadInNixShell then [cfg.package]
|
||||
else [
|
||||
#direnv has a fish library which sources direnv for some reason
|
||||
(cfg.package.overrideAttrs (old: {
|
||||
installPhase =
|
||||
(old.installPhase or "")
|
||||
+ ''
|
||||
rm -rf $out/share/fish
|
||||
'';
|
||||
}))
|
||||
];
|
||||
|
||||
systemPackages = [
|
||||
cfg.finalPackage
|
||||
];
|
||||
variables = {
|
||||
DIRENV_CONFIG = "/etc/direnv";
|
||||
DIRENV_LOG_FORMAT = lib.mkIf cfg.silent "";
|
||||
};
|
||||
|
||||
etc = {
|
||||
"direnv/direnv.toml".source = lib.mkIf (cfg.settings != {}) (
|
||||
format.generate "direnv.toml" cfg.settings
|
||||
);
|
||||
"direnv/direnvrc".text = ''
|
||||
${lib.optionalString cfg.nix-direnv.enable ''
|
||||
#Load nix-direnv
|
||||
|
||||
@@ -8,6 +8,10 @@ let
|
||||
|
||||
cfg = config.programs.fish;
|
||||
|
||||
fishAbbrs = concatStringsSep "\n" (
|
||||
mapAttrsToList (k: v: "abbr -a ${k} -- ${escapeShellArg v}") cfg.shellAbbrs
|
||||
);
|
||||
|
||||
fishAliases = concatStringsSep "\n" (
|
||||
mapAttrsToList (k: v: "alias ${k} ${escapeShellArg v}")
|
||||
(filterAttrs (k: v: v != null) cfg.shellAliases)
|
||||
@@ -101,6 +105,18 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
shellAbbrs = mkOption {
|
||||
default = {};
|
||||
example = {
|
||||
gco = "git checkout";
|
||||
npu = "nix-prefetch-url";
|
||||
};
|
||||
description = ''
|
||||
Set of fish abbreviations.
|
||||
'';
|
||||
type = with types; attrsOf str;
|
||||
};
|
||||
|
||||
shellAliases = mkOption {
|
||||
default = config.environment.shellAliases;
|
||||
description = ''
|
||||
@@ -217,6 +233,7 @@ in
|
||||
# if we haven't sourced the interactive config, do it
|
||||
status --is-interactive; and not set -q __fish_nix_darwin_interactive_config_sourced
|
||||
and begin
|
||||
${fishAbbrs}
|
||||
${fishAliases}
|
||||
|
||||
${sourceEnv "interactiveShellInit"}
|
||||
|
||||
@@ -1,8 +1,19 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
with lib;
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
inherit (lib)
|
||||
getExe'
|
||||
mkIf
|
||||
mkOption
|
||||
mkPackageOption
|
||||
optionalString
|
||||
types
|
||||
;
|
||||
|
||||
cfg = config.programs.gnupg;
|
||||
|
||||
@@ -10,6 +21,8 @@ in
|
||||
|
||||
{
|
||||
options.programs.gnupg = {
|
||||
package = mkPackageOption pkgs "gnupg" { };
|
||||
|
||||
agent.enable = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -29,9 +42,12 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.agent.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
launchd.user.agents.gnupg-agent.serviceConfig = {
|
||||
ProgramArguments = [
|
||||
"${pkgs.gnupg}/bin/gpg-connect-agent" "/bye"
|
||||
(getExe' cfg.package "gpg-connect-agent")
|
||||
"/bye"
|
||||
];
|
||||
RunAtLoad = cfg.agent.enableSSHSupport;
|
||||
KeepAlive.SuccessfulExit = false;
|
||||
@@ -40,12 +56,13 @@ in
|
||||
environment.extraInit = ''
|
||||
# Bind gpg-agent to this TTY if gpg commands are used.
|
||||
export GPG_TTY=$(tty)
|
||||
'' + (optionalString cfg.agent.enableSSHSupport ''
|
||||
''
|
||||
+ (optionalString cfg.agent.enableSSHSupport ''
|
||||
# SSH agent protocol doesn't support changing TTYs, so bind the agent
|
||||
# to every new TTY.
|
||||
${pkgs.gnupg}/bin/gpg-connect-agent --quiet updatestartuptty /bye > /dev/null 2>&1
|
||||
${getExe' cfg.package "gpg-connect-agent"} --quiet updatestartuptty /bye > /dev/null 2>&1
|
||||
|
||||
export SSH_AUTH_SOCK=$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)
|
||||
export SSH_AUTH_SOCK=$(${getExe' cfg.package "gpgconf"} --list-dirs agent-ssh-socket)
|
||||
'');
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,209 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
options,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
inherit (lib)
|
||||
attrValues
|
||||
concatStringsSep
|
||||
escapeShellArg
|
||||
getExe
|
||||
literalExpression
|
||||
mapAttrsToList
|
||||
mkEnableOption
|
||||
mkIf
|
||||
mkOption
|
||||
mkOptionDefault
|
||||
mkPackageOption
|
||||
optionalString
|
||||
types
|
||||
;
|
||||
|
||||
cfg = config.programs.mas;
|
||||
|
||||
apps = mapAttrsToList (name: id: { inherit name id; }) cfg.packages;
|
||||
|
||||
desiredIds = map (app: toString app.id) apps;
|
||||
homebrewIds = map toString (attrValues config.homebrew.masApps);
|
||||
|
||||
hasWork = cfg.update || cfg.packages != { } || cfg.cleanup || homebrewIds != [ ];
|
||||
|
||||
activationScript =
|
||||
if hasWork then
|
||||
''
|
||||
echo >&2 "setting up App Store apps (mas)..."
|
||||
|
||||
runAsUser() {
|
||||
sudo \
|
||||
--preserve-env=PATH \
|
||||
--set-home \
|
||||
--user=${escapeShellArg cfg.user} \
|
||||
"$@"
|
||||
}
|
||||
|
||||
listStatus=0
|
||||
listOutput=$(
|
||||
runAsUser ${getExe cfg.package} list 2>&1
|
||||
) || listStatus=$?
|
||||
|
||||
if (( listStatus != 0 )); then
|
||||
echo >&2 "warning: mas list failed (exit ''${listStatus}):"
|
||||
echo >&2 "''${listOutput}"
|
||||
if echo "''${listOutput}" | grep -qi "not signed in"; then
|
||||
echo >&2 "login required; skipping App Store installs/updates/cleanup"
|
||||
exit 0
|
||||
fi
|
||||
fi
|
||||
|
||||
# Only emit cleanup-only shell variables when cleanup is enabled; otherwise shellcheck
|
||||
# treats them as unused and fails the activation script build.
|
||||
installedIds=()
|
||||
${if cfg.cleanup then
|
||||
''
|
||||
# Parse mas list output: "ID AppName (version)"
|
||||
declare -A installedApps
|
||||
while IFS= read -r line; do
|
||||
[[ -z "$line" ]] && continue
|
||||
line="''${line#"''${line%%[![:space:]]*}"}"
|
||||
id="''${line%% *}"
|
||||
rest="''${line#"$id"}"
|
||||
rest="''${rest#"''${rest%%[![:space:]]*}"}"
|
||||
name="''${rest% (*}"
|
||||
name="''${name%"''${name##*[![:space:]]}"}"
|
||||
[[ -n "$id" ]] && {
|
||||
installedIds+=( "$id" )
|
||||
installedApps["$id"]="$name"
|
||||
}
|
||||
done <<<"$listOutput"
|
||||
''
|
||||
else
|
||||
''
|
||||
while IFS= read -r line; do
|
||||
[[ -z "$line" ]] && continue
|
||||
line="''${line#"''${line%%[![:space:]]*}"}"
|
||||
id="''${line%% *}"
|
||||
[[ -n "$id" ]] && installedIds+=( "$id" )
|
||||
done <<<"$listOutput"
|
||||
''}
|
||||
|
||||
${optionalString cfg.update ''
|
||||
runAsUser ${getExe cfg.package} update || true
|
||||
''}
|
||||
|
||||
desiredIds=(
|
||||
${concatStringsSep "\n " desiredIds}
|
||||
)
|
||||
|
||||
is_installed() {
|
||||
local needle=$1
|
||||
for id in "''${installedIds[@]}"; do
|
||||
if [[ "$id" == "$needle" ]]; then
|
||||
return 0
|
||||
fi
|
||||
done
|
||||
return 1
|
||||
}
|
||||
|
||||
${optionalString (cfg.packages != { }) ''
|
||||
for appId in "''${desiredIds[@]}"; do
|
||||
if is_installed "$appId"; then
|
||||
continue
|
||||
fi
|
||||
runAsUser ${getExe cfg.package} install "$appId" || true
|
||||
done
|
||||
''}
|
||||
|
||||
${optionalString cfg.cleanup ''
|
||||
homebrewIds=(
|
||||
${concatStringsSep "\n " homebrewIds}
|
||||
)
|
||||
|
||||
keepIds=( "''${desiredIds[@]}" "''${homebrewIds[@]}" )
|
||||
|
||||
for installedId in "''${installedIds[@]}"; do
|
||||
keep=false
|
||||
for keepId in "''${keepIds[@]}"; do
|
||||
if [[ "$installedId" == "$keepId" ]]; then
|
||||
keep=true
|
||||
break
|
||||
fi
|
||||
done
|
||||
|
||||
if ! $keep; then
|
||||
appName="''${installedApps[$installedId]:-$installedId}"
|
||||
echo >&2 "removing $appName from App Store"
|
||||
runAsUser ${getExe cfg.package} uninstall "$installedId" || true
|
||||
fi
|
||||
done
|
||||
''}
|
||||
''
|
||||
else
|
||||
"";
|
||||
in
|
||||
{
|
||||
options.programs.mas = {
|
||||
enable = mkEnableOption "managing Mac App Store apps with mas";
|
||||
|
||||
user = mkOption {
|
||||
type = types.str;
|
||||
default = config.system.primaryUser;
|
||||
defaultText = literalExpression "config.system.primaryUser";
|
||||
description = ''
|
||||
The user account that runs {command}`mas`. This user must be signed into the Mac App Store
|
||||
for installs or updates to succeed.
|
||||
'';
|
||||
};
|
||||
|
||||
package = mkPackageOption pkgs "mas" { };
|
||||
|
||||
packages = mkOption {
|
||||
type = types.attrsOf types.ints.positive;
|
||||
default = { };
|
||||
example = literalExpression ''
|
||||
{
|
||||
Xcode = 497799835;
|
||||
"1Password for Safari" = 1569813296;
|
||||
}
|
||||
'';
|
||||
description = ''
|
||||
Applications to install from the Mac App Store. Attribute names are only for readability;
|
||||
values must be the numeric identifiers used by {command}`mas`.
|
||||
'';
|
||||
};
|
||||
|
||||
update = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Whether to run {command}`mas update` during system activation in addition to installing the
|
||||
configured apps.
|
||||
'';
|
||||
};
|
||||
|
||||
cleanup = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Whether to uninstall Mac App Store apps that are currently installed but not listed in
|
||||
{option}`programs.mas.packages`. Apps listed in {option}`homebrew.masApps` are also preserved.
|
||||
This runs before install/update; any app id not in either set will be removed.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
system.requiresPrimaryUser =
|
||||
mkIf (cfg.enable && options.programs.mas.user.highestPrio == (mkOptionDefault { }).priority)
|
||||
[
|
||||
"programs.mas.enable"
|
||||
];
|
||||
|
||||
environment.systemPackages = mkIf cfg.enable [ cfg.package ];
|
||||
|
||||
system.activationScripts.mas.text = mkIf cfg.enable activationScript;
|
||||
};
|
||||
}
|
||||
@@ -1,14 +1,12 @@
|
||||
{ config, lib, ... }:
|
||||
|
||||
with lib;
|
||||
|
||||
let
|
||||
cfg = config.programs.ssh;
|
||||
|
||||
knownHosts = map (h: getAttr h cfg.knownHosts) (attrNames cfg.knownHosts);
|
||||
knownHosts = builtins.attrValues cfg.knownHosts;
|
||||
|
||||
host =
|
||||
{ name, ... }:
|
||||
{ name, config, ... }:
|
||||
{
|
||||
options = {
|
||||
certAuthority = lib.mkOption {
|
||||
@@ -19,17 +17,30 @@ let
|
||||
individual host's key.
|
||||
'';
|
||||
};
|
||||
hostNames = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
hostNames = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ name ] ++ config.extraHostNames;
|
||||
description = ''
|
||||
A list of host names and/or IP numbers used for accessing
|
||||
the host's ssh service.
|
||||
The set of system-wide known SSH hosts. To make simple setups more
|
||||
convenient the name of an attribute in this set is used as a host name
|
||||
for the entry. This behaviour can be disabled by setting
|
||||
`hostNames` explicitly. You can use
|
||||
`extraHostNames` to add additional host names without
|
||||
disabling this default.
|
||||
'';
|
||||
};
|
||||
publicKey = mkOption {
|
||||
extraHostNames = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [];
|
||||
description = ''
|
||||
A list of additional host names and/or IP numbers used for
|
||||
accessing the host's ssh service. This list is ignored if
|
||||
`hostNames` is set explicitly.
|
||||
'';
|
||||
};
|
||||
publicKey = lib.mkOption {
|
||||
default = null;
|
||||
type = types.nullOr types.str;
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
example = "ecdsa-sha2-nistp521 AAAAE2VjZHN...UEPg==";
|
||||
description = ''
|
||||
The public key data for the host. You can fetch a public key
|
||||
@@ -38,9 +49,9 @@ let
|
||||
the key type and the key itself.
|
||||
'';
|
||||
};
|
||||
publicKeyFile = mkOption {
|
||||
publicKeyFile = lib.mkOption {
|
||||
default = null;
|
||||
type = types.nullOr types.path;
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
description = ''
|
||||
The path to the public key file for the host. The public
|
||||
key file is read at build time and saved in the Nix store.
|
||||
@@ -51,16 +62,13 @@ let
|
||||
'';
|
||||
};
|
||||
};
|
||||
config = {
|
||||
hostNames = mkDefault [ name ];
|
||||
};
|
||||
};
|
||||
# Taken from: https://github.com/NixOS/nixpkgs/blob/f4aa6afa5f934ece2d1eb3157e392d056be01617/nixos/modules/services/networking/ssh/sshd.nix#L46-L93
|
||||
userOptions = {
|
||||
|
||||
options.openssh.authorizedKeys = {
|
||||
keys = mkOption {
|
||||
type = types.listOf types.str;
|
||||
keys = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [];
|
||||
description = ''
|
||||
A list of verbatim OpenSSH public keys that should be added to the
|
||||
@@ -73,8 +81,8 @@ let
|
||||
'';
|
||||
};
|
||||
|
||||
keyFiles = mkOption {
|
||||
type = types.listOf types.path;
|
||||
keyFiles = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.path;
|
||||
default = [];
|
||||
description = ''
|
||||
A list of files each containing one OpenSSH public key that should be
|
||||
@@ -89,29 +97,29 @@ let
|
||||
};
|
||||
|
||||
authKeysFiles = let
|
||||
mkAuthKeyFile = u: nameValuePair "ssh/nix_authorized_keys.d/${u.name}" {
|
||||
mkAuthKeyFile = u: lib.nameValuePair "ssh/nix_authorized_keys.d/${u.name}" {
|
||||
text = ''
|
||||
${concatStringsSep "\n" u.openssh.authorizedKeys.keys}
|
||||
${concatMapStrings (f: readFile f + "\n") u.openssh.authorizedKeys.keyFiles}
|
||||
${builtins.concatStringsSep "\n" u.openssh.authorizedKeys.keys}
|
||||
${lib.concatMapStrings (f: builtins.readFile f + "\n") u.openssh.authorizedKeys.keyFiles}
|
||||
'';
|
||||
};
|
||||
usersWithKeys = attrValues (flip filterAttrs config.users.users (n: u:
|
||||
length u.openssh.authorizedKeys.keys != 0 || length u.openssh.authorizedKeys.keyFiles != 0
|
||||
usersWithKeys = builtins.attrValues (lib.flip lib.filterAttrs config.users.users (n: u:
|
||||
lib.length u.openssh.authorizedKeys.keys != 0 || lib.length u.openssh.authorizedKeys.keyFiles != 0
|
||||
));
|
||||
in listToAttrs (map mkAuthKeyFile usersWithKeys);
|
||||
in lib.listToAttrs (map mkAuthKeyFile usersWithKeys);
|
||||
|
||||
oldAuthorizedKeysHash = "5a5dc1e20e8abc162ad1cc0259bfd1dbb77981013d87625f97d9bd215175fc0a";
|
||||
in
|
||||
|
||||
{
|
||||
imports = [
|
||||
(mkRemovedOptionModule [ "services" "openssh" "authorizedKeysFiles" ] "No `nix-darwin` equivalent to this NixOS option.")
|
||||
(lib.mkRemovedOptionModule [ "services" "openssh" "authorizedKeysFiles" ] "No `nix-darwin` equivalent to this NixOS option.")
|
||||
];
|
||||
|
||||
options = {
|
||||
|
||||
users.users = mkOption {
|
||||
type = with types; attrsOf (submodule userOptions);
|
||||
users.users = lib.mkOption {
|
||||
type = with lib.types; attrsOf (submodule userOptions);
|
||||
};
|
||||
|
||||
programs.ssh.extraConfig = lib.mkOption {
|
||||
@@ -123,41 +131,47 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
programs.ssh.knownHosts = mkOption {
|
||||
programs.ssh.knownHosts = lib.mkOption {
|
||||
default = {};
|
||||
type = types.attrsOf (types.submodule host);
|
||||
type = lib.types.attrsOf (lib.types.submodule host);
|
||||
description = ''
|
||||
The set of system-wide known SSH hosts.
|
||||
The set of system-wide known SSH hosts. To make simple setups more
|
||||
convenient the name of an attribute in this set is used as a host name
|
||||
for the entry. This behaviour can be disabled by setting
|
||||
`hostNames` explicitly. You can use
|
||||
`extraHostNames` to add additional host names without
|
||||
disabling this default.
|
||||
'';
|
||||
example = literalExpression ''
|
||||
[
|
||||
{
|
||||
hostNames = [ "myhost" "myhost.mydomain.com" "10.10.1.4" ];
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
myhost = {
|
||||
extraHostNames = [ "myhost.mydomain.com" "10.10.1.4" ];
|
||||
publicKeyFile = ./pubkeys/myhost_ssh_host_dsa_key.pub;
|
||||
}
|
||||
{
|
||||
hostNames = [ "myhost2" ];
|
||||
};
|
||||
"myhost2.net".publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILIRuJ8p1Fi+m6WkHV0KWnRfpM1WxoW8XAS+XvsSKsTK";
|
||||
"myhost2.net/dsa" = {
|
||||
hostNames = [ "myhost2.net" ];
|
||||
publicKeyFile = ./pubkeys/myhost2_ssh_host_dsa_key.pub;
|
||||
}
|
||||
]
|
||||
};
|
||||
}
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
|
||||
assertions = flip mapAttrsToList cfg.knownHosts (name: data: {
|
||||
assertions = lib.flip lib.mapAttrsToList cfg.knownHosts (name: data: {
|
||||
assertion = (data.publicKey == null && data.publicKeyFile != null) ||
|
||||
(data.publicKey != null && data.publicKeyFile == null);
|
||||
message = "knownHost ${name} must contain either a publicKey or publicKeyFile";
|
||||
});
|
||||
|
||||
environment.etc = authKeysFiles //
|
||||
{ "ssh/ssh_known_hosts" = mkIf (builtins.length knownHosts > 0) {
|
||||
text = (flip (concatMapStringsSep "\n") knownHosts
|
||||
{ "ssh/ssh_known_hosts" = lib.mkIf (builtins.length knownHosts > 0) {
|
||||
text = (lib.flip (lib.concatMapStringsSep "\n") knownHosts
|
||||
(h: assert h.hostNames != [];
|
||||
lib.optionalString h.certAuthority "@cert-authority " + concatStringsSep "," h.hostNames + " "
|
||||
+ (if h.publicKey != null then h.publicKey else readFile h.publicKeyFile)
|
||||
lib.optionalString h.certAuthority "@cert-authority " + builtins.concatStringsSep "," h.hostNames + " "
|
||||
+ (if h.publicKey != null then h.publicKey else builtins.readFile h.publicKeyFile)
|
||||
)) + "\n";
|
||||
};
|
||||
"ssh/ssh_config.d/100-nix-darwin.conf".text = config.programs.ssh.extraConfig;
|
||||
@@ -57,6 +57,17 @@ in
|
||||
description = "Enable sensible configuration options for tmux.";
|
||||
};
|
||||
|
||||
programs.tmux.reverseSplitBindings = mkOption {
|
||||
type = types.bool;
|
||||
default = config.system.stateVersion <= 6 && cfg.enableSensible;
|
||||
defaultText = literalExpression "config.system.stateVersion <= 6 && config.programs.tmux.enableSensible";
|
||||
example = true;
|
||||
description = ''
|
||||
Whether to reverse the `%` and `"` split-window key bindings
|
||||
emitted by the tmux module.
|
||||
'';
|
||||
};
|
||||
|
||||
programs.tmux.enableMouse = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -127,8 +138,6 @@ in
|
||||
set -s escape-time 0
|
||||
|
||||
bind c new-window -c '#{pane_current_path}'
|
||||
bind % split-window -v -c '#{pane_current_path}'
|
||||
bind '"' split-window -h -c '#{pane_current_path}'
|
||||
|
||||
# TODO: make these interactive
|
||||
bind C new-session
|
||||
@@ -138,6 +147,11 @@ in
|
||||
# set -g utf8 on
|
||||
'';
|
||||
|
||||
programs.tmux.tmuxOptions.splitBindings.text = mkIf cfg.reverseSplitBindings ''
|
||||
bind % split-window -v -c '#{pane_current_path}'
|
||||
bind '"' split-window -h -c '#{pane_current_path}'
|
||||
'';
|
||||
|
||||
programs.tmux.tmuxOptions.mouse.text = mkIf cfg.enableMouse ''
|
||||
set -g mouse on
|
||||
setw -g mouse on
|
||||
|
||||
@@ -77,7 +77,7 @@ in
|
||||
config = mkIf cfg.enable {
|
||||
|
||||
environment.systemPackages =
|
||||
[ # Include vim_configurable package.
|
||||
[ # Include vim-full package.
|
||||
cfg.package
|
||||
];
|
||||
|
||||
@@ -92,7 +92,7 @@ in
|
||||
endif
|
||||
'';
|
||||
|
||||
programs.vim.package = pkgs.vim_configurable.customize {
|
||||
programs.vim.package = pkgs.vim-full.customize {
|
||||
name = "vim";
|
||||
vimrcConfig.customRC = config.environment.etc."vimrc".text;
|
||||
vimrcConfig.vam = {
|
||||
|
||||
@@ -59,6 +59,18 @@ in
|
||||
description = "Shell script code used to initialise the zsh prompt.";
|
||||
};
|
||||
|
||||
programs.zsh.histSize = mkOption {
|
||||
type = types.int;
|
||||
default = 2000;
|
||||
description = "Change history size.";
|
||||
};
|
||||
|
||||
programs.zsh.histFile = mkOption {
|
||||
type = types.str;
|
||||
default = "$HOME/.zsh_history";
|
||||
description = "Change history file.";
|
||||
};
|
||||
|
||||
programs.zsh.enableCompletion = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
@@ -102,6 +114,12 @@ in
|
||||
description = "Enable fzf keybinding for Ctrl-r history search.";
|
||||
};
|
||||
|
||||
programs.zsh.enableAutosuggestions = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = "Enable zsh-autosuggestions.";
|
||||
};
|
||||
|
||||
programs.zsh.enableSyntaxHighlighting = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -123,6 +141,7 @@ in
|
||||
[ # Include zsh package
|
||||
pkgs.zsh
|
||||
] ++ optional cfg.enableCompletion pkgs.nix-zsh-completions
|
||||
++ optional cfg.enableAutosuggestions pkgs.zsh-autosuggestions
|
||||
++ optional cfg.enableSyntaxHighlighting pkgs.zsh-syntax-highlighting
|
||||
++ optional cfg.enableFastSyntaxHighlighting pkgs.zsh-fast-syntax-highlighting;
|
||||
|
||||
@@ -182,10 +201,11 @@ in
|
||||
if [ -n "$__ETC_ZSHRC_SOURCED" -o -n "$NOSYSZSHRC" ]; then return; fi
|
||||
__ETC_ZSHRC_SOURCED=1
|
||||
|
||||
# history defaults
|
||||
SAVEHIST=2000
|
||||
HISTSIZE=2000
|
||||
HISTFILE=$HOME/.zsh_history
|
||||
# Setup command line history.
|
||||
# Don't export these, otherwise other shells (bash) will try to use same HISTFILE.
|
||||
SAVEHIST=${builtins.toString cfg.histSize}
|
||||
HISTSIZE=${builtins.toString cfg.histSize}
|
||||
HISTFILE=${cfg.histFile}
|
||||
|
||||
setopt HIST_IGNORE_DUPS SHARE_HISTORY HIST_FCNTL_LOCK
|
||||
|
||||
@@ -199,12 +219,16 @@ in
|
||||
${optionalString cfg.enableGlobalCompInit "autoload -U compinit && compinit"}
|
||||
${optionalString cfg.enableBashCompletion "autoload -U bashcompinit && bashcompinit"}
|
||||
|
||||
${optionalString cfg.enableAutosuggestions
|
||||
"source ${pkgs.zsh-autosuggestions}/share/zsh-autosuggestions/zsh-autosuggestions.zsh"
|
||||
}
|
||||
|
||||
${optionalString cfg.enableSyntaxHighlighting
|
||||
"source ${pkgs.zsh-syntax-highlighting}/share/zsh-syntax-highlighting/zsh-syntax-highlighting.zsh"
|
||||
}
|
||||
|
||||
${optionalString cfg.enableFastSyntaxHighlighting
|
||||
"source ${pkgs.zsh-fast-syntax-highlighting}/share/zsh/site-functions/fast-syntax-highlighting.plugin.zsh"
|
||||
"source ${pkgs.zsh-fast-syntax-highlighting}/share/zsh/plugins/fast-syntax-highlighting/fast-syntax-highlighting.plugin.zsh"
|
||||
}
|
||||
|
||||
${optionalString cfg.enableFzfCompletion "source ${fzfCompletion}"}
|
||||
@@ -220,18 +244,23 @@ in
|
||||
environment.etc."zprofile".knownSha256Hashes = [
|
||||
"db8422f92d8cff684e418f2dcffbb98c10fe544b5e8cd588b2009c7fa89559c5"
|
||||
"0235d3c1b6cf21e7043fbc98e239ee4bc648048aafaf6be1a94a576300584ef2" # macOS
|
||||
"f320016e2cf13573731fbee34f9fe97ba867dd2a31f24893d3120154e9306e92" # macOS 26b1 and higher
|
||||
];
|
||||
|
||||
environment.etc."zshrc".knownSha256Hashes = [
|
||||
"19a2d673ffd47b8bed71c5218ff6617dfc5e8533b240b9ba79142a45f8823c23"
|
||||
"fb5827cb4712b7e7932d438067ec4852c8955a9ff0f55e282473684623ebdfa1" # macOS
|
||||
"4d1ab5704f9d167a042fecac0d056c8a79a8ebd71e032d3489536c8db9ffe3e0" # macOS 26b1 and higher
|
||||
"c5a00c072c920f46216454978c44df044b2ec6d03409dc492c7bdcd92c94a110" # official Nix installer
|
||||
"40b0d8751adae5b0100a4f863be5b75613a49f62706427e92604f7e04d2e2261" # official Nix installer
|
||||
"bf76c5ed8e65e616f4329eccf662ee91be33b8bfd33713ce9946f2fe94fea7fa" # official Nix installer (macOS 26b1 and higher)
|
||||
"2af1b563e389d11b76a651b446e858116d7a20370d9120a7e9f78991f3e5f336" # DeterminateSystems installer
|
||||
"27274e44b88a1174787f9a3d437d3387edc4f9aaaf40356054130797f5dc7912" # DeterminateSystems installer (macOS 26b1 and higher)
|
||||
];
|
||||
|
||||
environment.etc."zshenv".knownSha256Hashes = [
|
||||
"d07015be6875f134976fce84c6c7a77b512079c1c5f9594dfa65c70b7968b65f" # DeterminateSystems installer
|
||||
"4e8f7cb9b699511f4ba5f9d5f8de1c9f5efb5c607de88faf5f58b8b9cb38edbf" # experimental official Nix installer 2.33.3
|
||||
];
|
||||
|
||||
};
|
||||
|
||||
+88
-51
@@ -1,69 +1,106 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
with lib;
|
||||
|
||||
let
|
||||
cfg = config.security.pam;
|
||||
|
||||
# Implementation Notes
|
||||
#
|
||||
# We don't use `environment.etc` because this would require that the user manually delete
|
||||
# `/etc/pam.d/sudo` which seems unwise given that applying the nix-darwin configuration requires
|
||||
# sudo. We also can't use `system.patchs` since it only runs once, and so won't patch in the
|
||||
# changes again after OS updates (which remove modifications to this file).
|
||||
#
|
||||
# As such, we resort to line addition/deletion in place using `sed`. We add a comment to the
|
||||
# added line that includes the name of the option, to make it easier to identify the line that
|
||||
# should be deleted when the option is disabled.
|
||||
mkSudoTouchIdAuthScript = isEnabled:
|
||||
let
|
||||
file = "/etc/pam.d/sudo";
|
||||
option = "security.pam.enableSudoTouchIdAuth";
|
||||
sed = "${pkgs.gnused}/bin/sed";
|
||||
in ''
|
||||
${if isEnabled then ''
|
||||
# Enable sudo Touch ID authentication, if not already enabled
|
||||
if ! grep 'pam_tid.so' ${file} > /dev/null; then
|
||||
${sed} -i '2i\
|
||||
auth sufficient pam_tid.so # nix-darwin: ${option}
|
||||
' ${file}
|
||||
fi
|
||||
'' else ''
|
||||
# Disable sudo Touch ID authentication, if added by nix-darwin
|
||||
if grep '${option}' ${file} > /dev/null; then
|
||||
${sed} -i '/${option}/d' ${file}
|
||||
fi
|
||||
''}
|
||||
'';
|
||||
cfg = config.security.pam.services.sudo_local;
|
||||
in
|
||||
|
||||
{
|
||||
imports = [
|
||||
(lib.mkRemovedOptionModule [ "security" "pam" "enableSudoTouchIdAuth" ] ''
|
||||
This option has been renamed to `security.pam.services.sudo_local.touchIdAuth` for consistency with NixOS.
|
||||
'')
|
||||
];
|
||||
|
||||
options = {
|
||||
security.pam.enableSudoTouchIdAuth = mkEnableOption "" // {
|
||||
description = ''
|
||||
Enable sudo authentication with Touch ID.
|
||||
security.pam.services.sudo_local = {
|
||||
enable = lib.mkEnableOption "managing {file}`/etc/pam.d/sudo_local` with nix-darwin" // {
|
||||
default = true;
|
||||
example = false;
|
||||
};
|
||||
|
||||
When enabled, this option adds the following line to
|
||||
{file}`/etc/pam.d/sudo`:
|
||||
text = lib.mkOption {
|
||||
type = lib.types.lines;
|
||||
default = "";
|
||||
description = ''
|
||||
Contents of {file}`/etc/pam.d/sudo_local`
|
||||
'';
|
||||
};
|
||||
|
||||
```
|
||||
auth sufficient pam_tid.so
|
||||
```
|
||||
touchIdAuth = lib.mkEnableOption "" // {
|
||||
description = ''
|
||||
Whether to enable Touch ID with sudo.
|
||||
|
||||
::: {.note}
|
||||
macOS resets this file when doing a system update. As such, sudo
|
||||
authentication with Touch ID won't work after a system update
|
||||
until the nix-darwin configuration is reapplied.
|
||||
:::
|
||||
'';
|
||||
This will also allow your Apple Watch to be used for sudo. If this doesn't work,
|
||||
you can go into `System Settings > Touch ID & Password` and toggle the switch for
|
||||
your Apple Watch.
|
||||
'';
|
||||
};
|
||||
|
||||
watchIdAuth = lib.mkEnableOption "" // {
|
||||
description = ''
|
||||
Use Apple Watch for sudo authentication, for devices without Touch ID or
|
||||
laptops with lids closed, consider using this.
|
||||
|
||||
When enabled, you can use your Apple Watch to authenticate sudo commands.
|
||||
If this doesn't work, you can go into `System Settings > Touch ID & Password`
|
||||
and toggle the switch for your Apple Watch.
|
||||
'';
|
||||
};
|
||||
|
||||
reattach = lib.mkEnableOption "" // {
|
||||
description = ''
|
||||
Whether to enable reattaching a program to the user's bootstrap session.
|
||||
|
||||
This fixes Touch ID for sudo not working inside tmux and screen.
|
||||
|
||||
This allows programs like tmux and screen that run in the background to
|
||||
survive across user sessions to work with PAM services that are tied to the
|
||||
bootstrap session.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = {
|
||||
system.activationScripts.pam.text = ''
|
||||
security.pam.services.sudo_local.text = lib.concatLines (
|
||||
(lib.optional cfg.reattach "auth optional ${pkgs.pam-reattach}/lib/pam/pam_reattach.so")
|
||||
++ (lib.optional cfg.touchIdAuth "auth sufficient pam_tid.so")
|
||||
++ (lib.optional cfg.watchIdAuth "auth sufficient ${pkgs.pam-watchid}/lib/pam_watchid.so")
|
||||
);
|
||||
|
||||
environment.etc."pam.d/sudo_local" = {
|
||||
inherit (cfg) enable text;
|
||||
};
|
||||
|
||||
system.activationScripts.pam.text =
|
||||
let
|
||||
file = "/etc/pam.d/sudo";
|
||||
marker = "security.pam.services.sudo_local";
|
||||
deprecatedOption = "security.pam.enableSudoTouchIdAuth";
|
||||
sed = lib.getExe pkgs.gnused;
|
||||
in
|
||||
''
|
||||
# PAM settings
|
||||
echo >&2 "setting up pam..."
|
||||
${mkSudoTouchIdAuthScript cfg.enableSudoTouchIdAuth}
|
||||
|
||||
# REMOVEME when macOS 13 no longer supported as macOS automatically
|
||||
# nukes this file on system upgrade
|
||||
# Always clear out older implementation if it is present
|
||||
if grep '${deprecatedOption}' ${file} > /dev/null; then
|
||||
${sed} -i '/${deprecatedOption}/d' ${file}
|
||||
fi
|
||||
|
||||
${if cfg.enable then ''
|
||||
# REMOVEME when macOS 13 no longer supported
|
||||
# `sudo_local` is automatically included after macOS 14
|
||||
if ! grep 'sudo_local' ${file} > /dev/null; then
|
||||
${sed} -i '2iauth include sudo_local # nix-darwin: ${marker}' ${file}
|
||||
fi
|
||||
'' else ''
|
||||
# Remove include line if we added it
|
||||
if grep '${marker}' ${file} > /dev/null; then
|
||||
${sed} -i '/${marker}/d' ${file}
|
||||
fi
|
||||
''}
|
||||
'';
|
||||
};
|
||||
}
|
||||
|
||||
@@ -1,5 +1,35 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
let
|
||||
activationPath =
|
||||
lib.makeBinPath (
|
||||
[
|
||||
pkgs.gnugrep
|
||||
pkgs.coreutils
|
||||
] ++ lib.optionals config.nix.enable [ config.nix.package ]
|
||||
)
|
||||
+ lib.optionalString (!config.nix.enable) ''
|
||||
$(
|
||||
# If `nix.enable` is off, there might be an unmanaged Nix
|
||||
# installation (say in `/nix/var/nix/profiles/default`) that
|
||||
# activation scripts (such as Home Manager) want to find on the
|
||||
# `$PATH`. Search for it directly to avoid polluting the
|
||||
# activation script environment with everything on the
|
||||
# `environment.systemPath`.
|
||||
if nixEnvPath=$(
|
||||
PATH="${config.environment.systemPath}" command -v nix-env
|
||||
); then
|
||||
printf ':'
|
||||
${lib.getExe' pkgs.coreutils "dirname"} -- "$(
|
||||
${lib.getExe' pkgs.coreutils "readlink"} \
|
||||
--canonicalize-missing \
|
||||
-- "$nixEnvPath"
|
||||
)"
|
||||
fi
|
||||
)''
|
||||
+ ":/usr/bin:/bin:/usr/sbin:/sbin";
|
||||
in
|
||||
|
||||
{
|
||||
imports = [
|
||||
(lib.mkRemovedOptionModule [ "services" "activate-system" "enable" ] "The `activate-system` service is now always enabled as it is necessary for a working `nix-darwin` setup.")
|
||||
@@ -10,7 +40,17 @@
|
||||
script = ''
|
||||
set -e
|
||||
set -o pipefail
|
||||
export PATH="${pkgs.gnugrep}/bin:${pkgs.coreutils}/bin:@out@/sw/bin:/usr/bin:/bin:/usr/sbin:/sbin"
|
||||
|
||||
PATH="${activationPath}"
|
||||
|
||||
export PATH
|
||||
export USER=root
|
||||
export LOGNAME=root
|
||||
export HOME=~root
|
||||
export MAIL=/var/mail/root
|
||||
export SHELL=$BASH
|
||||
export LANG=C
|
||||
export LC_CTYPE=UTF-8
|
||||
|
||||
systemConfig=$(cat ${config.system.profile}/systemConfig)
|
||||
|
||||
@@ -21,14 +61,15 @@
|
||||
ln -sfn $(cat ${config.system.profile}/systemConfig) /run/current-system
|
||||
|
||||
# Prevent the current configuration from being garbage-collected.
|
||||
ln -sfn /run/current-system /nix/var/nix/gcroots/current-system
|
||||
if [[ -d /nix/var/nix/gcroots ]]; then
|
||||
ln -sfn /run/current-system /nix/var/nix/gcroots/current-system
|
||||
fi
|
||||
|
||||
${config.system.activationScripts.etcChecks.text}
|
||||
${config.system.activationScripts.checks.text}
|
||||
${config.system.activationScripts.etc.text}
|
||||
${config.system.activationScripts.keyboard.text}
|
||||
'';
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive.SuccessfulExit = false;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -199,6 +199,7 @@ in
|
||||
type = enum [
|
||||
"qwerty"
|
||||
"dvorak"
|
||||
"colemak"
|
||||
];
|
||||
default = "qwerty";
|
||||
description = "Keymapping preset.";
|
||||
@@ -253,6 +254,7 @@ in
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
};
|
||||
managedBy = "services.aerospace.enable";
|
||||
};
|
||||
}
|
||||
);
|
||||
|
||||
@@ -55,7 +55,7 @@ in
|
||||
|
||||
default = [];
|
||||
description = ''
|
||||
List of AutoSSH sessions to start as systemd services. Each service is
|
||||
List of AutoSSH sessions to start as launchd daemon. Each daemon is
|
||||
named 'autossh-{session.name}'.
|
||||
'';
|
||||
|
||||
@@ -78,7 +78,7 @@ in
|
||||
config = mkIf (cfg.sessions != []) {
|
||||
|
||||
launchd.daemons =
|
||||
lib.fold ( s : acc : acc //
|
||||
lib.foldr ( s : acc : acc //
|
||||
{
|
||||
"autossh-${s.name}" =
|
||||
let
|
||||
|
||||
@@ -227,14 +227,21 @@ in
|
||||
{ path = cfg.runtimePackages ++ [ cfg.package pkgs.coreutils pkgs.darwin.DarwinTools ];
|
||||
environment = {
|
||||
HOME = cfg.dataDir;
|
||||
NIX_REMOTE = "daemon";
|
||||
inherit (config.environment.variables) NIX_SSL_CERT_FILE;
|
||||
} // (if config.nix.useDaemon then { NIX_REMOTE = "daemon"; } else {});
|
||||
};
|
||||
|
||||
## NB: maximum care is taken so that secrets (ssh keys and the CI token)
|
||||
## don't end up in the Nix store.
|
||||
script = let
|
||||
sshDir = "${cfg.dataDir}/.ssh";
|
||||
tagStr = lib.concatStringsSep "," (lib.mapAttrsToList (name: value: "${name}=${value}") cfg.tags);
|
||||
tagStr =
|
||||
name: value:
|
||||
if lib.isList value then
|
||||
lib.concatStringsSep "," (builtins.map (v: "${name}=${v}") value)
|
||||
else
|
||||
"${name}=${value}";
|
||||
tagsStr = lib.concatStringsSep "," (lib.mapAttrsToList tagStr cfg.tags);
|
||||
in
|
||||
optionalString (cfg.privateSshKeyPath != null) ''
|
||||
mkdir -m 0700 "${sshDir}"
|
||||
@@ -244,7 +251,7 @@ in
|
||||
token="$(cat ${toString cfg.tokenPath})"
|
||||
name="${cfg.name}"
|
||||
shell="${cfg.shell}"
|
||||
tags="${tagStr}"
|
||||
tags="${tagsStr}"
|
||||
build-path="${cfg.dataDir}/builds"
|
||||
hooks-path="${cfg.hooksPath}"
|
||||
${cfg.extraConfig}
|
||||
|
||||
@@ -51,6 +51,14 @@ in {
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# TODO: Upstream this to NixOS.
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`services.cachix-agent.enable` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
|
||||
launchd.daemons.cachix-agent = {
|
||||
script = ''
|
||||
. ${cfg.credentialsFile}
|
||||
|
||||
@@ -126,6 +126,7 @@ in
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.ProcessType = "Interactive";
|
||||
managedBy = "services.chunkwm.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -0,0 +1,81 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
|
||||
cfg = config.services.dnscrypt-proxy;
|
||||
|
||||
format = pkgs.formats.toml { };
|
||||
|
||||
configFile = format.generate "dnscrypt-proxy.toml" cfg.settings;
|
||||
|
||||
in
|
||||
|
||||
{
|
||||
options.services.dnscrypt-proxy = {
|
||||
|
||||
enable = lib.mkEnableOption "the dnscrypt-proxy service.";
|
||||
|
||||
package = lib.mkPackageOption pkgs "dnscrypt-proxy" { };
|
||||
|
||||
settings = lib.mkOption {
|
||||
description = ''
|
||||
Attrset that is converted and passed as TOML config file.
|
||||
For available params, see: <https://github.com/DNSCrypt/dnscrypt-proxy/blob/${pkgs.dnscrypt-proxy.version}/dnscrypt-proxy/example-dnscrypt-proxy.toml>
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
sources.public-resolvers = {
|
||||
urls = [ "https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md" ];
|
||||
cache_file = "public-resolvers.md";
|
||||
minisign_key = "RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3";
|
||||
refresh_delay = 72;
|
||||
};
|
||||
}
|
||||
'';
|
||||
type = format.type;
|
||||
default = { };
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
users.users._dnscrypt-proxy = {
|
||||
uid = config.ids.uids._dnscrypt-proxy;
|
||||
gid = config.ids.gids._dnscrypt-proxy;
|
||||
home = "/var/lib/dnscrypt-proxy";
|
||||
createHome = true;
|
||||
shell = "/usr/bin/false";
|
||||
description = "System user for dnscrypt-proxy";
|
||||
};
|
||||
|
||||
users.groups._dnscrypt-proxy = {
|
||||
gid = config.ids.gids._dnscrypt-proxy;
|
||||
description = "System group for dnscrypt-proxy";
|
||||
};
|
||||
|
||||
users.knownUsers = [ "_dnscrypt-proxy" ];
|
||||
users.knownGroups = [ "_dnscrypt-proxy" ];
|
||||
|
||||
launchd.daemons.dnscrypt-proxy = {
|
||||
script = ''
|
||||
${lib.getExe' cfg.package "dnscrypt-proxy"} -config ${configFile}
|
||||
'';
|
||||
serviceConfig =
|
||||
let
|
||||
logPath = config.users.users._dnscrypt-proxy.home + "/dnscrypt-proxy.log";
|
||||
in
|
||||
{
|
||||
RunAtLoad = true;
|
||||
KeepAlive = true;
|
||||
StandardOutPath = logPath;
|
||||
StandardErrorPath = logPath;
|
||||
GroupName = "_dnscrypt-proxy";
|
||||
UserName = "_dnscrypt-proxy";
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -42,18 +42,42 @@ in
|
||||
{ localhost = "127.0.0.1"; }
|
||||
'';
|
||||
};
|
||||
|
||||
services.dnsmasq.servers = mkOption {
|
||||
type = types.listOf types.str;
|
||||
default = [];
|
||||
description = ''
|
||||
List of upstream DNS servers to forward queries to.
|
||||
If empty, dnsmasq will use the servers from /etc/resolv.conf.
|
||||
Each entry can be:
|
||||
- An IP address (e.g., "1.2.3.4")
|
||||
- A domain-specific server (e.g., "/example.com/1.2.3.4")
|
||||
- A server with port (e.g., "1.2.3.4#5353")
|
||||
See dnsmasq(8) man page for --server option for full syntax.
|
||||
'';
|
||||
example = literalExpression ''
|
||||
[
|
||||
"8.8.8.8"
|
||||
"8.8.4.4"
|
||||
"/internal.example.com/192.168.1.1"
|
||||
]
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
launchd.daemons.dnsmasq = {
|
||||
serviceConfig.ProgramArguments = [
|
||||
"${cfg.package}/bin/dnsmasq"
|
||||
"--listen-address=${cfg.bind}"
|
||||
"--port=${toString cfg.port}"
|
||||
"--keep-in-foreground"
|
||||
] ++ (mapA (domain: addr: "--address=/${domain}/${addr}") cfg.addresses);
|
||||
command = let
|
||||
args = [
|
||||
"--listen-address=${cfg.bind}"
|
||||
"--port=${toString cfg.port}"
|
||||
"--keep-in-foreground"
|
||||
] ++ (mapA (domain: addr: "--address=/${domain}/${addr}") cfg.addresses)
|
||||
++ (map (server: "--server=${server}") cfg.servers);
|
||||
in
|
||||
"${cfg.package}/bin/dnsmasq ${concatStringsSep " " args}";
|
||||
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = true;
|
||||
|
||||
@@ -49,6 +49,7 @@ in {
|
||||
RunAtLoad = true;
|
||||
KeepAlive = true;
|
||||
};
|
||||
managedBy = "services.emacs.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -262,8 +262,8 @@ in
|
||||
};
|
||||
|
||||
nodeRuntimes = mkOption {
|
||||
type = with types; nonEmptyListOf (enum [ "node20" ]);
|
||||
default = [ "node20" ];
|
||||
type = with types; nonEmptyListOf (enum [ "node20" "node24" ]);
|
||||
default = [ "node24" ];
|
||||
description = ''
|
||||
List of Node.js runtimes the runner should support.
|
||||
'';
|
||||
|
||||
@@ -2,17 +2,22 @@
|
||||
|
||||
let
|
||||
inherit (lib) any attrValues boolToString concatStringsSep escapeShellArg
|
||||
flatten flip getExe getExe' hasAttr hasPrefix mapAttrsToList mapAttrs' mkBefore
|
||||
mkDefault mkIf mkMerge nameValuePair optionalAttrs optionalString replaceStrings;
|
||||
flatten flip getExe getExe' hasPrefix mapAttrsToList mapAttrs' mkBefore
|
||||
mkDefault mkIf mkMerge nameValuePair optionalString replaceStrings;
|
||||
|
||||
mkSvcName = name: "github-runner-${name}";
|
||||
mkStateDir = cfg: "/var/lib/github-runners/${cfg.name}";
|
||||
mkLogDir = cfg: "/var/log/github-runners/${cfg.name}";
|
||||
mkWorkDir = cfg: if (cfg.workDir != null) then cfg.workDir else "/var/lib/github-runners/_work/${cfg.name}";
|
||||
mkWorkDir = cfg: if (cfg.workDir != null) then cfg.workDir else "/private/var/lib/github-runners/_work/${cfg.name}";
|
||||
in
|
||||
{
|
||||
config.assertions = flatten (
|
||||
flip mapAttrsToList config.services.github-runners (name: cfg: map (mkIf cfg.enable) [
|
||||
# TODO: Upstream this to NixOS.
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`services.github-runners.${name}.enable` requires `nix.enable`'';
|
||||
}
|
||||
{
|
||||
assertion = (cfg.user == null && cfg.group == null) || (cfg.user != null);
|
||||
message = "`services.github-runners.${name}`: Either set `user` and `group` to `null` to have nix-darwin manage them or set at least `user` explicitly";
|
||||
@@ -22,7 +27,7 @@ in
|
||||
message = "`services.github-runners.${name}`: The `extraLabels` option is mandatory if `noDefaultLabels` is set";
|
||||
}
|
||||
{
|
||||
assertion = cfg.workDir == null || !(hasPrefix "/run/" cfg.workDir || hasPrefix "/var/run/" cfg.workDir || hasPrefix "/private/var/run/");
|
||||
assertion = cfg.workDir == null || !(hasPrefix "/run/" cfg.workDir || hasPrefix "/var/run/" cfg.workDir || hasPrefix "/private/var/run/" cfg.workDir);
|
||||
message = "`services.github-runners.${name}`: `workDir` being inside /run is not supported";
|
||||
}
|
||||
])
|
||||
@@ -49,32 +54,29 @@ in
|
||||
in
|
||||
{
|
||||
launchd = mkIf cfg.enable {
|
||||
text = mkBefore (''
|
||||
text = mkBefore ''
|
||||
echo >&2 "setting up GitHub Runner '${cfg.name}'..."
|
||||
|
||||
(
|
||||
umask -S u=rwx,g=rx,o= > /dev/null
|
||||
# shellcheck disable=SC2174
|
||||
${getExe' pkgs.coreutils "mkdir"} -p -m u=rwx,g=rx,o= ${escapeShellArg (mkStateDir cfg)}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkStateDir cfg)}
|
||||
|
||||
${getExe' pkgs.coreutils "mkdir"} -p ${escapeShellArg (mkStateDir cfg)}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkStateDir cfg)}
|
||||
# shellcheck disable=SC2174
|
||||
${getExe' pkgs.coreutils "mkdir"} -p -m u=rwx,g=rx,o= ${escapeShellArg (mkLogDir cfg)}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkLogDir cfg)}
|
||||
|
||||
${getExe' pkgs.coreutils "mkdir"} -p ${escapeShellArg (mkLogDir cfg)}
|
||||
# launchd will fail to start the service if the outer direction doesn't have sufficient permissions
|
||||
${getExe' pkgs.coreutils "chmod"} o+rx ${escapeShellArg (mkLogDir { name = ""; })}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkLogDir cfg)}
|
||||
|
||||
${optionalString (cfg.workDir == null) ''
|
||||
${getExe' pkgs.coreutils "mkdir"} -p ${escapeShellArg (mkWorkDir cfg)}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkWorkDir cfg)}
|
||||
''}
|
||||
)
|
||||
'');
|
||||
${optionalString (cfg.workDir == null) ''
|
||||
# shellcheck disable=SC2174
|
||||
${getExe' pkgs.coreutils "mkdir"} -p -m u=rwx,g=rx,o= ${escapeShellArg (mkWorkDir cfg)}
|
||||
${getExe' pkgs.coreutils "chown"} ${user}:${group} ${escapeShellArg (mkWorkDir cfg)}
|
||||
''}
|
||||
'';
|
||||
};
|
||||
}));
|
||||
|
||||
config.launchd.daemons = flip mapAttrs' config.services.github-runners (name: cfg:
|
||||
let
|
||||
package = cfg.package.override (old: optionalAttrs (hasAttr "nodeRuntimes" old) { inherit (cfg) nodeRuntimes; });
|
||||
package = cfg.package.override { inherit (cfg) nodeRuntimes; };
|
||||
stateDir = mkStateDir cfg;
|
||||
logDir = mkLogDir cfg;
|
||||
workDir = mkWorkDir cfg;
|
||||
|
||||
@@ -19,6 +19,7 @@ let
|
||||
# make config file readable by service
|
||||
chown -R --reference=$HOME $(dirname ${configPath})
|
||||
'' else ''
|
||||
set -e
|
||||
export CONFIG_FILE=${configPath}
|
||||
|
||||
mkdir -p $(dirname ${configPath})
|
||||
@@ -92,8 +93,8 @@ let
|
||||
done
|
||||
|
||||
# update global options
|
||||
remarshal --if toml --of json ${configPath} \
|
||||
| jq -cM ${escapeShellArg (concatStringsSep " | " [
|
||||
tomlq -t \
|
||||
${escapeShellArg (concatStringsSep " | " [
|
||||
".check_interval = ${toJSON cfg.checkInterval}"
|
||||
".concurrent = ${toJSON cfg.concurrent}"
|
||||
".sentry_dsn = ${toJSON cfg.sentryDSN}"
|
||||
@@ -103,9 +104,9 @@ let
|
||||
".session_server.session_timeout = ${toJSON cfg.sessionServer.sessionTimeout}"
|
||||
"del(.[] | nulls)"
|
||||
"del(.session_server[] | nulls)"
|
||||
])} \
|
||||
| remarshal --if json --of toml \
|
||||
| sponge ${configPath}
|
||||
])} ${configPath} \
|
||||
> config.toml.new
|
||||
mv config.toml.new ${configPath}
|
||||
|
||||
# make config file readable by service
|
||||
chown -R --reference=$HOME $(dirname ${configPath})
|
||||
@@ -551,14 +552,15 @@ in
|
||||
launchd.daemons.gitlab-runner = {
|
||||
environment = { #config.networking.proxy.envVars // {
|
||||
HOME = "${config.users.users.gitlab-runner.home}";
|
||||
NIX_REMOTE = "daemon";
|
||||
NIX_SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
} // (if config.nix.useDaemon then { NIX_REMOTE = "daemon"; } else {});
|
||||
};
|
||||
path = with pkgs; [
|
||||
bash
|
||||
gawk
|
||||
jq
|
||||
moreutils
|
||||
remarshal
|
||||
yq
|
||||
# util-linux
|
||||
cfg.package
|
||||
coreutils
|
||||
|
||||
@@ -22,6 +22,14 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# TODO: Upstream this to NixOS.
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`services.hercules-ci-agent.enable` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
|
||||
launchd.daemons.hercules-ci-agent = {
|
||||
script = "exec ${cfg.package}/bin/hercules-ci-agent --config ${cfg.tomlFile}";
|
||||
|
||||
@@ -74,7 +82,7 @@ in
|
||||
darwin.label = config.system.darwinLabel;
|
||||
darwin.revision = config.system.darwinRevision;
|
||||
darwin.version = config.system.darwinVersion;
|
||||
darwin.nix.daemon = config.nix.useDaemon;
|
||||
darwin.nix.daemon = true;
|
||||
darwin.nix.sandbox = config.nix.settings.sandbox;
|
||||
};
|
||||
};
|
||||
|
||||
@@ -64,6 +64,7 @@ in
|
||||
StandardErrorPath = cfg.logFile;
|
||||
EnvironmentVariables = {} // (optionalAttrs (cfg.ipfsPath != null) { IPFS_PATH = cfg.ipfsPath; });
|
||||
};
|
||||
managedBy = "services.ipfs.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -22,7 +22,7 @@ in {
|
||||
];
|
||||
|
||||
options.services.jankyborders = {
|
||||
enable = mkEnableOption "Enable the jankyborders service.";
|
||||
enable = mkEnableOption "the jankyborders service.";
|
||||
|
||||
package = mkPackageOption pkgs "jankyborders" {};
|
||||
|
||||
@@ -162,6 +162,7 @@ in {
|
||||
++ (optionalArg "order" cfg.order);
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = true;
|
||||
managedBy = "services.jankyborders.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -84,6 +84,7 @@ in
|
||||
"${parentAppDir}/.Karabiner-VirtualHIDDevice-Manager.app/Contents/MacOS/Karabiner-VirtualHIDDevice-Manager" "activate"
|
||||
];
|
||||
serviceConfig.RunAtLoad = true;
|
||||
managedBy = "services.karabiner-elements.enable";
|
||||
};
|
||||
|
||||
# We need this to run every reboot as /run gets nuked so we can't put this
|
||||
@@ -101,10 +102,11 @@ in
|
||||
launchd.user.agents.karabiner_session_monitor = {
|
||||
serviceConfig.ProgramArguments = [
|
||||
"/bin/sh" "-c"
|
||||
"/bin/wait4path /run/wrappers/bin && /run/wrappers/bin/karabiner_session_monitor"
|
||||
"/bin/wait4path /run/wrappers/bin && /run/wrappers/bin/karabiner_session_monitor"
|
||||
];
|
||||
serviceConfig.Label = "org.pqrs.karabiner.karabiner_session_monitor";
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "services.karabiner-elements.enable";
|
||||
};
|
||||
|
||||
environment.userLaunchAgents."org.pqrs.karabiner.agent.karabiner_grabber.plist".source = "${cfg.package}/Library/LaunchAgents/org.pqrs.karabiner.agent.karabiner_grabber.plist";
|
||||
|
||||
@@ -33,7 +33,7 @@ in
|
||||
services.khd.i3Keybindings = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = "Wether to configure i3 style keybindings for kwm.";
|
||||
description = "Whether to configure i3 style keybindings for kwm.";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -57,6 +57,8 @@ in
|
||||
SockType = "dgram";
|
||||
SockFamily = "IPv4";
|
||||
};
|
||||
|
||||
managedBy = "services.khd.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -47,6 +47,7 @@ in
|
||||
SockType = "dgram";
|
||||
SockFamily = "IPv4";
|
||||
};
|
||||
managedBy = "services.kwm.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -29,7 +29,16 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# TODO: Upstream this to NixOS.
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`services.lorri.enable` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
|
||||
environment.systemPackages = [ pkgs.lorri ];
|
||||
|
||||
launchd.user.agents.lorri = {
|
||||
command = with pkgs; "${lorri}/bin/lorri daemon";
|
||||
path = with pkgs; [ config.nix.package git gnutar gzip ];
|
||||
@@ -41,6 +50,7 @@ in
|
||||
StandardErrorPath = cfg.logFile;
|
||||
EnvironmentVariables = { NIX_PATH = "nixpkgs=" + toString pkgs.path; };
|
||||
};
|
||||
managedBy = "services.lorri.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
@@ -56,6 +56,7 @@ in {
|
||||
serviceConfig.StartInterval = cfg.startInterval;
|
||||
serviceConfig.StandardErrorPath = "/var/log/offlineimap.log";
|
||||
serviceConfig.StandardOutPath = "/var/log/offlineimap.log";
|
||||
managedBy = "services.offlineimap.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -29,6 +29,12 @@ in {
|
||||
default = "/var/log/netdata";
|
||||
description = "Log directory for Netdata";
|
||||
};
|
||||
|
||||
cacheDir = mkOption {
|
||||
type = types.path;
|
||||
default = "/var/cache/netdata";
|
||||
description = "Cache directory for Netdata";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -50,6 +56,7 @@ in {
|
||||
|
||||
system.activationScripts.preActivation.text = ''
|
||||
mkdir -p ${cfg.workDir}
|
||||
mkdir -p ${cfg.cacheDir}
|
||||
'';
|
||||
};
|
||||
}
|
||||
|
||||
@@ -7,8 +7,8 @@
|
||||
|
||||
let
|
||||
inherit (lib)
|
||||
escapeShellArg
|
||||
concatStringsSep
|
||||
escapeShellArgs
|
||||
getExe
|
||||
mkEnableOption
|
||||
mkIf
|
||||
@@ -104,7 +104,8 @@ in {
|
||||
]
|
||||
++ (map (collector: "--collector.${collector}") cfg.enabledCollectors)
|
||||
++ (map (collector: "--no-collector.${collector}") cfg.disabledCollectors)
|
||||
) + escapeShellArgs cfg.extraFlags;
|
||||
++ (map escapeShellArg cfg.extraFlags)
|
||||
);
|
||||
serviceConfig = let
|
||||
logPath = config.users.users._prometheus-node-exporter.home
|
||||
+ "/prometheus-node-exporter.log";
|
||||
|
||||
@@ -66,6 +66,9 @@ in {
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
};
|
||||
|
||||
# https://github.com/influxdata/telegraf/issues/17607
|
||||
environment.HOME = "/var/root";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -41,6 +41,7 @@ in
|
||||
serviceConfig.Program = "${cfg.package}/bin/mopidy";
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "services.mopidy.enable";
|
||||
};
|
||||
})
|
||||
(mkIf cfg.mediakeys.enable {
|
||||
@@ -48,6 +49,7 @@ in
|
||||
serviceConfig.Program = "${cfg.package}/bin/mpdkeys";
|
||||
serviceConfig.RunAtLoad = true;
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "services.mopidy.mediakeys.enable";
|
||||
};
|
||||
})
|
||||
];
|
||||
|
||||
@@ -30,8 +30,7 @@ in {
|
||||
|
||||
launchd.daemons.nextdns = {
|
||||
path = [ nextdns ];
|
||||
serviceConfig.ProgramArguments =
|
||||
[ "${pkgs.nextdns}/bin/nextdns" "run" ] ++ cfg.arguments;
|
||||
command = concatStringsSep " " (["${pkgs.nextdns}/bin/nextdns run"] ++ cfg.arguments);
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = true;
|
||||
};
|
||||
|
||||
@@ -3,17 +3,18 @@
|
||||
let
|
||||
cfg = config.services.nix-daemon;
|
||||
|
||||
inherit (lib) mkDefault mkIf mkMerge mkOption types;
|
||||
inherit (lib) mkRemovedOptionModule mkDefault mkIf mkMerge mkOption types;
|
||||
in
|
||||
|
||||
{
|
||||
options = {
|
||||
services.nix-daemon.enable = mkOption {
|
||||
type = types.bool;
|
||||
default = true;
|
||||
description = "Whether to enable the nix-daemon service.";
|
||||
};
|
||||
imports = [
|
||||
(mkRemovedOptionModule [ "services" "nix-daemon" "enable" ] ''
|
||||
nix-darwin now manages nix-daemon unconditionally when
|
||||
`nix.enable` is on.
|
||||
'')
|
||||
];
|
||||
|
||||
options = {
|
||||
services.nix-daemon.enableSocketListener = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -39,9 +40,7 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
|
||||
nix.useDaemon = true;
|
||||
config = mkIf config.nix.enable {
|
||||
|
||||
launchd.daemons.nix-daemon = {
|
||||
command = lib.getExe' config.nix.package "nix-daemon";
|
||||
|
||||
@@ -14,6 +14,7 @@ in
|
||||
(mkRemovedOptionModule [ "nix" "gc" "dates" ] "Use `nix.gc.interval` instead.")
|
||||
(mkRemovedOptionModule [ "nix" "gc" "randomizedDelaySec" ] "No `nix-darwin` equivalent to this NixOS option.")
|
||||
(mkRemovedOptionModule [ "nix" "gc" "persistent" ] "No `nix-darwin` equivalent to this NixOS option.")
|
||||
(mkRemovedOptionModule [ "nix" "gc" "user" ] "The garbage collection service now always runs as `root`.")
|
||||
];
|
||||
|
||||
###### interface
|
||||
@@ -28,13 +29,6 @@ in
|
||||
description = "Automatically run the garbage collector at a specific time.";
|
||||
};
|
||||
|
||||
# Not in NixOS module
|
||||
user = mkOption {
|
||||
type = types.nullOr types.str;
|
||||
default = null;
|
||||
description = "User that runs the garbage collector.";
|
||||
};
|
||||
|
||||
interval = mkOption {
|
||||
type = launchdTypes.StartCalendarInterval;
|
||||
default = [{ Weekday = 7; Hour = 3; Minute = 15; }];
|
||||
@@ -62,15 +56,18 @@ in
|
||||
|
||||
###### implementation
|
||||
|
||||
config = mkIf cfg.automatic {
|
||||
config = {
|
||||
assertions = [
|
||||
{
|
||||
assertion = cfg.automatic -> config.nix.enable;
|
||||
message = ''nix.gc.automatic requires nix.enable'';
|
||||
}
|
||||
];
|
||||
|
||||
launchd.daemons.nix-gc = {
|
||||
launchd.daemons.nix-gc = mkIf cfg.automatic {
|
||||
command = "${config.nix.package}/bin/nix-collect-garbage ${cfg.options}";
|
||||
environment.NIX_REMOTE = optionalString config.nix.useDaemon "daemon";
|
||||
serviceConfig.RunAtLoad = false;
|
||||
serviceConfig.StartCalendarInterval = cfg.interval;
|
||||
serviceConfig.UserName = cfg.user;
|
||||
};
|
||||
|
||||
};
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@ in
|
||||
{
|
||||
imports = [
|
||||
(mkRemovedOptionModule [ "nix" "optimise" "dates" ] "Use `nix.optimise.interval` instead.")
|
||||
(mkRemovedOptionModule [ "nix" "optimise" "user" ] "The store optimisation service now always runs as `root`.")
|
||||
];
|
||||
|
||||
###### interface
|
||||
@@ -34,13 +35,6 @@ in
|
||||
description = "Automatically run the nix store optimiser at a specific time.";
|
||||
};
|
||||
|
||||
# Not in NixOS module
|
||||
user = mkOption {
|
||||
type = types.nullOr types.str;
|
||||
default = null;
|
||||
description = "User that runs the store optimisation.";
|
||||
};
|
||||
|
||||
interval = mkOption {
|
||||
type = launchdTypes.StartCalendarInterval;
|
||||
default = [{ Weekday = 7; Hour = 4; Minute = 15; }];
|
||||
@@ -58,17 +52,20 @@ in
|
||||
|
||||
###### implementation
|
||||
|
||||
config = mkIf cfg.automatic {
|
||||
config = {
|
||||
assertions = [
|
||||
{
|
||||
assertion = cfg.automatic -> config.nix.enable;
|
||||
message = ''nix.optimise.automatic requires nix.enable'';
|
||||
}
|
||||
];
|
||||
|
||||
launchd.daemons.nix-optimise = {
|
||||
environment.NIX_REMOTE = optionalString config.nix.useDaemon "daemon";
|
||||
launchd.daemons.nix-optimise = mkIf cfg.automatic {
|
||||
command = "${lib.getExe' config.nix.package "nix-store"} --optimise";
|
||||
serviceConfig = {
|
||||
RunAtLoad = false;
|
||||
StartCalendarInterval = cfg.interval;
|
||||
UserName = cfg.user;
|
||||
};
|
||||
};
|
||||
|
||||
};
|
||||
}
|
||||
|
||||
@@ -46,6 +46,13 @@ in
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.nix.enable;
|
||||
message = ''`services.ofborg.enable` requires `nix.enable`'';
|
||||
}
|
||||
];
|
||||
|
||||
warnings = mkIf (isDerivation cfg.configFile) [
|
||||
"services.ofborg.configFile is a derivation, credentials will be world readable"
|
||||
];
|
||||
|
||||
@@ -1,18 +1,110 @@
|
||||
{ config, lib, ... }:
|
||||
{ config, lib, pkgs, ... }:
|
||||
|
||||
let
|
||||
cfg = config.services.openssh;
|
||||
|
||||
hostKeyOpts = {
|
||||
options = {
|
||||
type = lib.mkOption {
|
||||
type = lib.types.enum [ "dsa" "ecdsa" "ed25519" "rsa" ];
|
||||
description = ''
|
||||
Key type passed to `ssh-keygen -t`.
|
||||
'';
|
||||
};
|
||||
|
||||
path = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = ''
|
||||
Path to the private key file.
|
||||
'';
|
||||
};
|
||||
|
||||
bits = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.int;
|
||||
default = null;
|
||||
description = ''
|
||||
Key size in bits. If `null`, `ssh-keygen` uses the default
|
||||
for the given key type (RSA=3072, ECDSA=256, ED25519=fixed).
|
||||
'';
|
||||
};
|
||||
|
||||
comment = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
description = ''
|
||||
Comment for the key, passed to `ssh-keygen -C`.
|
||||
|
||||
Defaults to an empty string to match Apple's built-in host key
|
||||
generation and avoid leaking the hostname.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
hostKeysConfig = lib.concatMapStringsSep "\n"
|
||||
(k: "HostKey ${k.path}")
|
||||
cfg.hostKeys;
|
||||
|
||||
keygenScript = lib.concatMapStrings (k:
|
||||
let
|
||||
escapedPath = lib.escapeShellArg k.path;
|
||||
in ''
|
||||
if ! [[ -s ${escapedPath} ]]; then
|
||||
if ! [[ -L ${escapedPath} ]]; then
|
||||
rm -f ${escapedPath}
|
||||
fi
|
||||
|
||||
keygenArgs=(
|
||||
-t ${lib.escapeShellArg k.type}
|
||||
${lib.optionalString (k.bits != null) "-b ${toString k.bits}"}
|
||||
-C ${lib.escapeShellArg k.comment}
|
||||
-f ${escapedPath}
|
||||
-N ""
|
||||
)
|
||||
|
||||
mkdir -p "$(dirname ${escapedPath})"
|
||||
chmod 0755 "$(dirname ${escapedPath})"
|
||||
${lib.getExe' pkgs.openssh "ssh-keygen"} "''${keygenArgs[@]}"
|
||||
fi
|
||||
'') cfg.hostKeys;
|
||||
in
|
||||
{
|
||||
options = {
|
||||
services.openssh.enable = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
description = ''
|
||||
Whether to enable Apple's built-in OpenSSH server.
|
||||
services.openssh = {
|
||||
enable = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
description = ''
|
||||
Whether to enable Apple's built-in OpenSSH server.
|
||||
|
||||
The default is null which means let macOS manage the OpenSSH server.
|
||||
'';
|
||||
The default is null which means let macOS manage the OpenSSH server.
|
||||
'';
|
||||
};
|
||||
|
||||
extraConfig = lib.mkOption {
|
||||
type = lib.types.lines;
|
||||
default = "";
|
||||
description = ''
|
||||
Extra configuration text loaded in {file}`sshd_config`.
|
||||
See {manpage}`sshd_config(5)` for help.
|
||||
'';
|
||||
};
|
||||
|
||||
hostKeys = lib.mkOption {
|
||||
type = lib.types.listOf (lib.types.submodule hostKeyOpts);
|
||||
default = [
|
||||
{ type = "rsa"; path = "/etc/ssh/ssh_host_rsa_key"; }
|
||||
{ type = "ecdsa"; path = "/etc/ssh/ssh_host_ecdsa_key"; }
|
||||
{ type = "ed25519"; path = "/etc/ssh/ssh_host_ed25519_key"; }
|
||||
];
|
||||
description = ''
|
||||
SSH host key declarations. Each entry specifies a key type and path.
|
||||
`HostKey` directives are written to the sshd configuration for each
|
||||
entry.
|
||||
|
||||
The default matches the keys that macOS automatically generates.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -29,5 +121,13 @@ in
|
||||
launchctl disable system/com.openssh.sshd
|
||||
fi
|
||||
'');
|
||||
|
||||
environment.etc."ssh/sshd_config.d/099-host-keys.conf" = lib.mkIf (cfg.hostKeys != []) {
|
||||
text = hostKeysConfig;
|
||||
};
|
||||
|
||||
environment.etc."ssh/sshd_config.d/100-nix-darwin.conf".text = cfg.extraConfig;
|
||||
|
||||
system.activationScripts.openssh.text = lib.mkIf (cfg.hostKeys != []) keygenScript;
|
||||
};
|
||||
}
|
||||
|
||||
@@ -363,6 +363,7 @@ in
|
||||
serviceConfig.EnvironmentVariables = {
|
||||
PGDATA = cfg.dataDir;
|
||||
};
|
||||
managedBy = "services.postgresql.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -61,6 +61,7 @@ in
|
||||
${cfg.package}/bin/privoxy /etc/privoxy-config
|
||||
'';
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "services.privoxy.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -67,6 +67,7 @@ in
|
||||
launchd.user.agents.redis = {
|
||||
command = "${cfg.package}/bin/redis-server /etc/redis.conf";
|
||||
serviceConfig.KeepAlive = true;
|
||||
managedBy = "services.redis.enable";
|
||||
};
|
||||
|
||||
environment.etc."redis.conf".text = ''
|
||||
|
||||
@@ -54,6 +54,7 @@ in
|
||||
++ optionals (cfg.config != "") [ "--config" "${configFile}" ];
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = true;
|
||||
managedBy = "services.sketchybar.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -40,6 +40,8 @@ in
|
||||
++ optionals (cfg.skhdConfig != "") [ "-c" "/etc/skhdrc" ];
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.ProcessType = "Interactive";
|
||||
|
||||
managedBy = "services.skhd.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -22,11 +22,12 @@ in
|
||||
services.spacebar.enable = mkOption {
|
||||
type = bool;
|
||||
default = false;
|
||||
description = "Whether to enable the spacebar spacebar.";
|
||||
description = "Whether to enable the spacebar.";
|
||||
};
|
||||
|
||||
services.spacebar.package = mkOption {
|
||||
type = path;
|
||||
default = pkgs.spacebar;
|
||||
description = "The spacebar package to use.";
|
||||
};
|
||||
|
||||
@@ -69,6 +70,8 @@ in
|
||||
serviceConfig.EnvironmentVariables = {
|
||||
PATH = "${cfg.package}/bin:${config.environment.systemPath}";
|
||||
};
|
||||
|
||||
managedBy = "services.spacebar.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -58,6 +58,7 @@ in
|
||||
RunAtLoad = true;
|
||||
ThrottleInterval = 30;
|
||||
};
|
||||
managedBy = "services.spotifyd.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -66,6 +66,7 @@ in
|
||||
command = "${cfg.package}/bin/synapse --config ${configFile}";
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = true;
|
||||
managedBy = "services.synapse-bt.enable";
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
@@ -130,6 +130,7 @@ in
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = cfg.client.autoStart;
|
||||
serviceConfig.ProcessType = "Interactive";
|
||||
managedBy = "services.synergy.client.enable";
|
||||
};
|
||||
})
|
||||
|
||||
@@ -145,6 +146,7 @@ in
|
||||
serviceConfig.KeepAlive = true;
|
||||
serviceConfig.RunAtLoad = cfg.server.autoStart;
|
||||
serviceConfig.ProcessType = "Interactive";
|
||||
managedBy = "services.synergy.server.enable";
|
||||
};
|
||||
})
|
||||
];
|
||||
|
||||
@@ -42,6 +42,7 @@ in {
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
};
|
||||
managedBy = "services.trezord.enable";
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -83,7 +83,7 @@ let
|
||||
preDown = mkOption {
|
||||
type = with types; coercedTo (listOf str) (concatStringsSep "\n") lines;
|
||||
default = "";
|
||||
description = "List of commadns to run before interface shutdown.";
|
||||
description = "List of commands to run before interface shutdown.";
|
||||
};
|
||||
|
||||
preUp = mkOption {
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user