14 Commits

Author SHA1 Message Date
Tom Alexander
c2619b4344 Update packages. 2026-09-07 17:42:46 -04:00
Tom Alexander
f2bde9ffea Disable installing documentation. 2026-09-07 15:41:38 -04:00
Tom Alexander
0d6001d655 Add parted to debugging role on kubernetes.
This is to support expanding the storage.
2026-09-07 13:24:39 -04:00
Tom Alexander
a0e8a74906 Update packages. 2026-09-05 19:07:41 -04:00
Tom Alexander
e719948a3e Switch to quad9 for DNS.
Mullvad is shutting down their public DNS.

ref: https://mullvad.net/en/blog/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead
2026-09-05 09:46:36 -04:00
Tom Alexander
3f281f1980 Clean up nix_builder directories at the start of a build. 2026-09-03 22:21:07 -04:00
Tom Alexander
6ed4aa08f6 Add a role for mitmproxy. 2026-08-29 09:40:21 -04:00
Tom Alexander
9bfa21368b Update to Linux 7.2.
This is to pull in the drivers for the mt7927 wireless chipset in my desktop. Normally, I would keep the rest of my machines on LTS but since Linux 7 significantly changed the kernel preemption, maintaining two configs would be more trouble than it is worth.
2026-08-29 06:50:47 -04:00
Tom Alexander
4eb7749967 Update persist directory for the latest firefox. 2026-08-29 06:50:45 -04:00
Tom Alexander
d0504bf98f Update rpcs3. 2026-08-28 09:02:47 -04:00
Tom Alexander
f1d6ae3f1b Merge branch 'update' into nix 2026-08-28 06:55:11 -04:00
Tom Alexander
85815fddfd Update deprecated podman settings. 2026-08-28 06:53:56 -04:00
Tom Alexander
5680e566bc Update packages. 2026-08-28 06:53:56 -04:00
Tom Alexander
3bbaeaf2af Install Arial font with rpcs3. 2026-08-26 17:16:22 -04:00
18 changed files with 107 additions and 93 deletions

View File

@@ -64,6 +64,7 @@ in
./roles/media ./roles/media
./roles/memtest86 ./roles/memtest86
./roles/minimal_base ./roles/minimal_base
./roles/mitmproxy
./roles/network ./roles/network
./roles/nix_index ./roles/nix_index
./roles/nix_repl ./roles/nix_repl
@@ -247,31 +248,31 @@ in
glew = (final.glew.override { enableEGL = false; }); glew = (final.glew.override { enableEGL = false; });
}; };
}) })
(disableTests "onetbb") # oneTBB tests hang forever on machines with a single core (like my build virtual machine) https://github.com/uxlfoundation/oneTBB/issues/1557
(disableTests "aws-c-common") # aws-c-common tests time out on my build virtual machine but run fine on my laptop.
(disableOptimizations "onnxruntime") # QuantizeLinearOpTest test failing.
(final: prev: { (final: prev: {
fwupd = prev.fwupd.overrideAttrs ( rpcs3 = prev.rpcs3.overrideAttrs (
finalAttrs: prevAttrs: { finalAttrs: prevAttrs: {
version = "2.1.5"; version = "0.0.42-19843";
src = final.fetchFromGitHub { src = final.fetchFromGitHub {
owner = "fwupd"; owner = "RPCS3";
repo = "fwupd"; repo = "rpcs3";
tag = finalAttrs.version; rev = "6567a5a2f8ab47a89db395d6b47a7b59b23d6960";
hash = "sha256-DzQ+N99ZmFRqZc2rN6PSqmoIMXUyrE8Kkn+KnT/AWPc="; postCheckout = ''
cd $out/3rdparty
git submodule update --init \
fusion/fusion asmjit/asmjit yaml-cpp/yaml-cpp SoundTouch/soundtouch stblib/stb \
feralinteractive/feralinteractive wolfssl/wolfssl
'';
hash = "sha256-a1c1+Ui7XyHFTGEZAgRuJasCzQqr2PZNTlwaDUWVb18=";
}; };
patches = [ ];
} }
); );
}) })
(disableTests "onetbb") # oneTBB tests hang forever on machines with a single core (like my build virtual machine) https://github.com/uxlfoundation/oneTBB/issues/1557
(disableTests "aws-c-common") # aws-c-common tests time out on my build virtual machine but run fine on my laptop.
# Works but probably sets python2's scipy to be python3:
#
# (final: prev: {
# pythonPackagesExtensions = prev.pythonPackagesExtensions ++ [
# (python-final: python-prev: {
# scipy = final.unoptimized.python3Packages.scipy;
# })
# ];
# })
]; ];
# This option defines the first version of NixOS you have installed on this particular machine, # This option defines the first version of NixOS you have installed on this particular machine,

View File

@@ -22,11 +22,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1780894562, "lastModified": 1781152676,
"narHash": "sha256-c3430xwxwhHipl3jigUGMMBfpaMylDqytW/kdmB3ZGs=", "narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "disko",
"rev": "24fed06cac83bcc44ac8efbb57cab1a82fa0bedc", "rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -170,11 +170,11 @@
"rust-overlay": "rust-overlay_2" "rust-overlay": "rust-overlay_2"
}, },
"locked": { "locked": {
"lastModified": 1786250497, "lastModified": 1788488145,
"narHash": "sha256-OPhVT5n9OyPDZA3mIO6D5jVVvp/QmG8nT5Trb0gouSs=", "narHash": "sha256-s1UY+kbLtb+5ye4GnE/HKh0idUQ0iiIkMMtGI7cDRHk=",
"ref": "refs/heads/main", "ref": "refs/heads/main",
"rev": "0a270dcbdd51baa2895634a3baee29373db8337a", "rev": "8b28dfb583e094f52fd6ab70c709cc1981d8853d",
"revCount": 42, "revCount": 46,
"type": "git", "type": "git",
"url": "https://code.fizz.buzz/talexander/nix_builder.git" "url": "https://code.fizz.buzz/talexander/nix_builder.git"
}, },
@@ -185,11 +185,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1780749050, "lastModified": 1788752844,
"narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=", "narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "a799d3e3886da994fa307f817a6bc705ae538eeb", "rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -199,22 +199,6 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs-google": {
"locked": {
"lastModified": 1779893571,
"narHash": "sha256-wiwMyVCtmjRjlFCe2zaumCE6LRV9GzzN0ZH25NQkbAU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "45f6cfaa4605b706c870e75bd74bdb5e97eee11e",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "45f6cfaa4605b706c870e75bd74bdb5e97eee11e",
"type": "github"
}
},
"nixpkgs-stable": { "nixpkgs-stable": {
"locked": { "locked": {
"lastModified": 1730741070, "lastModified": 1730741070,
@@ -264,8 +248,7 @@
"impermanence": "impermanence", "impermanence": "impermanence",
"lanzaboote": "lanzaboote", "lanzaboote": "lanzaboote",
"nix_builder": "nix_builder", "nix_builder": "nix_builder",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs"
"nixpkgs-google": "nixpkgs-google"
} }
}, },
"rust-overlay": { "rust-overlay": {

View File

@@ -20,7 +20,6 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-google.url = "github:NixOS/nixpkgs/45f6cfaa4605b706c870e75bd74bdb5e97eee11e";
lanzaboote = { lanzaboote = {
url = "github:nix-community/lanzaboote/v0.4.2"; url = "github:nix-community/lanzaboote/v0.4.2";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
@@ -39,7 +38,6 @@
{ {
self, self,
nixpkgs, nixpkgs,
nixpkgs-google,
disko, disko,
impermanence, impermanence,
lanzaboote, lanzaboote,
@@ -99,9 +97,6 @@
hostPlatform.gcc.arch = "default"; hostPlatform.gcc.arch = "default";
hostPlatform.gcc.tune = "default"; hostPlatform.gcc.tune = "default";
}; };
google = import nixpkgs-google {
system = prev.stdenv.hostPlatform.system;
};
}) })
]; ];
}; };

View File

@@ -118,6 +118,7 @@
me.lvfs.enable = true; me.lvfs.enable = true;
me.media.enable = true; me.media.enable = true;
me.memtest.enable = true; me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true; me.network.enable = true;
me.nix_index.enable = true; me.nix_index.enable = true;
me.nix_repl.enable = true; me.nix_repl.enable = true;

View File

@@ -111,6 +111,7 @@
me.lvfs.enable = true; me.lvfs.enable = true;
me.media.enable = true; me.media.enable = true;
me.memtest.enable = true; me.memtest.enable = true;
me.mitmproxy.enable = true;
me.network.enable = true; me.network.enable = true;
me.nix_index.enable = true; me.nix_index.enable = true;
me.nix_repl.enable = true; me.nix_repl.enable = true;

View File

@@ -72,5 +72,9 @@ in
git_fix_author git_fix_author
rsync_clone rsync_clone
]; ];
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
}; };
} }

View File

@@ -20,7 +20,7 @@
config = lib.mkIf (config.me.firefox.enable && config.me.graphical) { config = lib.mkIf (config.me.firefox.enable && config.me.graphical) {
programs.firefox = { programs.firefox = {
enable = true; enable = true;
package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { pipewireSupport = true; }) { }); package = (pkgs.wrapFirefox (pkgs.firefox-unwrapped.override { withPipewire = true; }) { });
languagePacks = [ "en-US" ]; languagePacks = [ "en-US" ];
preferences = { preferences = {
# "identity.sync.tokenserver.uri": "https://ffsync.fizz.buzz/token/1.0/sync/1.5"; # "identity.sync.tokenserver.uri": "https://ffsync.fizz.buzz/token/1.0/sync/1.5";
@@ -134,7 +134,7 @@
users.talexander = { users.talexander = {
directories = [ directories = [
{ {
directory = ".mozilla"; directory = ".config/mozilla";
user = "talexander"; user = "talexander";
group = "talexander"; group = "talexander";
mode = "0700"; mode = "0700";

View File

@@ -18,7 +18,7 @@
}; };
config = lib.mkIf config.me.gcloud.enable { config = lib.mkIf config.me.gcloud.enable {
environment.systemPackages = with pkgs.google; [ environment.systemPackages = with pkgs; [
(google-cloud-sdk.withExtraComponents [ google-cloud-sdk.components.gke-gcloud-auth-plugin ]) (google-cloud-sdk.withExtraComponents [ google-cloud-sdk.components.gke-gcloud-auth-plugin ])
]; ];

View File

@@ -100,6 +100,7 @@
IFS=$'\n\t' IFS=$'\n\t'
DIR="$( cd "$( dirname "''${BASH_SOURCE[0]}" )" && pwd )" DIR="$( cd "$( dirname "''${BASH_SOURCE[0]}" )" && pwd )"
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder clean --config ${./files/nix_builder.toml}
NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder build --config ${./files/nix_builder.toml} ${builtins.concatStringsSep " " build_flags} NIX_REMOTE='local?root=/.disk/root' RUST_BACKTRACE=1 RUST_LOG=nix_builder=DEBUG ${nix_builder.packages.x86_64-linux.default}/bin/nix-builder build --config ${./files/nix_builder.toml} ${builtins.concatStringsSep " " build_flags}
''; '';
restartIfChanged = false; restartIfChanged = false;

View File

@@ -14,30 +14,12 @@ let
full = { full = {
PREEMPT_DYNAMIC = yes; PREEMPT_DYNAMIC = yes;
PREEMPT = yes; PREEMPT = yes;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no; PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
}; };
lazy = { lazy = {
PREEMPT_DYNAMIC = yes; PREEMPT_DYNAMIC = yes;
PREEMPT = no; PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = yes; PREEMPT_LAZY = yes;
PREEMPT_NONE = no;
};
voluntary = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = yes;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = no;
};
none = {
PREEMPT_DYNAMIC = no;
PREEMPT = no;
PREEMPT_VOLUNTARY = lib.mkForce no;
PREEMPT_LAZY = lib.mkForce no;
PREEMPT_NONE = yes;
}; };
}; };
tick_hz = tick_hz =
@@ -99,16 +81,14 @@ let
TRANSPARENT_HUGEPAGE_MADVISE = yes; TRANSPARENT_HUGEPAGE_MADVISE = yes;
}; };
}; };
common_config = common_config = with lib.kernel; {
with lib.kernel;
{
# Google's BBRv3 TCP congestion Control # Google's BBRv3 TCP congestion Control
TCP_CONG_BBR = yes; TCP_CONG_BBR = yes;
DEFAULT_BBR = yes; DEFAULT_BBR = yes;
}; };
flavors = { flavors = {
server = lib.mkMerge [ server = lib.mkMerge [
preemption_type.none preemption_type.lazy
tick_hz."300" tick_hz."300"
performance_governor.default performance_governor.default
tick_rate.tickless tick_rate.tickless
@@ -142,7 +122,8 @@ in
kernel.version = lib.mkOption { kernel.version = lib.mkOption {
type = lib.types.str; type = lib.types.str;
default = "linux"; # LTS # default = "linux"; # LTS
default = "linux_7_2"; # LTS
example = "linux_6_18"; example = "linux_6_18";
description = "What version of the kernl should we use."; description = "What version of the kernl should we use.";
}; };

View File

@@ -25,8 +25,8 @@
nixpkgs.overlays = [ nixpkgs.overlays = [
(final: prev: { (final: prev: {
tex = ( tex = (
pkgs.texlive.combine { pkgs.texliveSmall.withPackages (
inherit (pkgs.texlive) ps: with ps; [
scheme-basic scheme-basic
dvisvgm dvisvgm
dvipng # for preview and export as html in org-mode dvipng # for preview and export as html in org-mode
@@ -44,8 +44,8 @@
upquote # emacs org-mode pdf export upquote # emacs org-mode pdf export
lineno # emacs org-mode pdf export lineno # emacs org-mode pdf export
beamer # emacs org-mode presentation pdf export beamer # emacs org-mode presentation pdf export
; ]
} )
); );
}) })
]; ];

View File

@@ -0,0 +1,25 @@
{
config,
lib,
pkgs,
...
}:
{
imports = [ ];
options.me = {
mitmproxy.enable = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
description = "Whether we want to install mitmproxy.";
};
};
config = lib.mkIf config.me.mitmproxy.enable {
environment.systemPackages = with pkgs; [
mitmproxy
];
};
}

View File

@@ -6,6 +6,8 @@
}: }:
# Alternative DNS servers: # Alternative DNS servers:
# "194.242.2.2#doh.mullvad.net"
# "2a07:e340::2#doh.mullvad.net"
# "1.0.0.1#cloudflare-dns.com" # "1.0.0.1#cloudflare-dns.com"
# "1.1.1.1#cloudflare-dns.com" # "1.1.1.1#cloudflare-dns.com"
# "2606:4700:4700::1001#cloudflare-dns.com" # "2606:4700:4700::1001#cloudflare-dns.com"
@@ -14,6 +16,10 @@
# "8.8.8.8#dns.google" # "8.8.8.8#dns.google"
# "2001:4860:4860::8844#dns.google" # "2001:4860:4860::8844#dns.google"
# "2001:4860:4860::8888#dns.google" # "2001:4860:4860::8888#dns.google"
# "9.9.9.10#dns10.quad9.net"
# "149.112.112.10#dns10.quad9.net"
# "2620:fe::10#dns10.quad9.net"
# "2620:fe::fe:10#dns10.quad9.net"
let let
patchScriptBin = patchScriptBin =
@@ -39,8 +45,10 @@ in
networking.dhcpcd.enable = lib.mkDefault false; networking.dhcpcd.enable = lib.mkDefault false;
networking.useDHCP = lib.mkDefault false; networking.useDHCP = lib.mkDefault false;
networking.nameservers = [ networking.nameservers = [
"194.242.2.2#doh.mullvad.net" "9.9.9.10#dns10.quad9.net"
"2a07:e340::2#doh.mullvad.net" "149.112.112.10#dns10.quad9.net"
"2620:fe::10#dns10.quad9.net"
"2620:fe::fe:10#dns10.quad9.net"
]; ];
services.resolved = { services.resolved = {
enable = true; enable = true;

View File

@@ -34,7 +34,9 @@
# Write config files in /etc/containers # Write config files in /etc/containers
virtualisation.containers.enable = true; virtualisation.containers.enable = true;
# By default this includes "quay.io" which leads to prompting for which registry to download from. # By default this includes "quay.io" which leads to prompting for which registry to download from.
virtualisation.containers.registries.search = [ "docker.io" ]; virtualisation.containers.registries.settings = {
unqualified-search-registries = [ "docker.io" ];
};
virtualisation = { virtualisation = {
podman = { podman = {
enable = true; enable = true;

View File

@@ -38,7 +38,7 @@ in
}; };
}; };
Miscellaneous = { Miscellaneous = {
"Pause emulation on RPCS3 focus loss" = true; "Pause emulation on RPCS3 focus loss" = false;
"Start games in fullscreen mode" = true; "Start games in fullscreen mode" = true;
"Pause Emulation During Home Menu" = false; # true makes the home menu slow "Pause Emulation During Home Menu" = false; # true makes the home menu slow
}; };
@@ -53,7 +53,10 @@ in
rpcs3 rpcs3
]; ];
allowedUnfree = [ "rpcs3" ]; allowedUnfree = [
"rpcs3"
"corefonts"
];
security.pam.loginLimits = [ security.pam.loginLimits = [
{ {
@@ -70,6 +73,10 @@ in
} }
]; ];
fonts.packages = with pkgs; [
corefonts # Needed for Arial, otherwise launching games fails.
];
me.install.user.talexander.file = { me.install.user.talexander.file = {
".config/rpcs3/config.yml" = lib.mkIf (config.me.rpcs3.config != null) { ".config/rpcs3/config.yml" = lib.mkIf (config.me.rpcs3.config != null) {
source = rpcs3_config_yaml; source = rpcs3_config_yaml;

View File

@@ -64,6 +64,10 @@
}; };
nix.settings.auto-optimise-store = !config.me.buildingPortable; nix.settings.auto-optimise-store = !config.me.buildingPortable;
# Disable installing documentation.
documentation.doc.enable = false;
documentation.nixos.enable = false;
environment.persistence."/persist" = lib.mkIf (config.me.mountPersistence) { environment.persistence."/persist" = lib.mkIf (config.me.mountPersistence) {
hideMounts = true; hideMounts = true;
directories = [ directories = [

View File

@@ -164,11 +164,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1784120854, "lastModified": 1788752844,
"narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=", "narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46", "rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github" "type": "github"
}, },
"original": { "original": {

View File

@@ -25,6 +25,7 @@
gptfdisk # cgdisk gptfdisk # cgdisk
arp-scan # To find devices on the network arp-scan # To find devices on the network
ldns # for drill ldns # for drill
parted
]; ];
# This can make debugging easier by rejecting packets instead of dropping them: # This can make debugging easier by rejecting packets instead of dropping them: