-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
-
44
-
45
-
46
-
47
-
48
-
49
-
50
-
51
-
52
-
53
-
54
-
55
-
56
-
57
-
58
-
59
-
60
-
61
-
62
-
63
-
64
-
65
-
66
-
67
-
68
-
69
-
70
-
71
-
72
-
73
-
74
-
75
-
76
-
77
-
78
-
79
-
80
-
81
-
82
-
83
-
84
-
85
-
86
-
87
-
88
-
89
-
90
-
91
-
92
-
93
-
94
-
95
-
96
-
97
-
98
-
99
-
100
-
101
-
102
-
103
-
104
-
105
-
106
-
107
-
108
-
109
-
110
-
111
-
112
-
113
-
114
-
115
-
116
-
117
-
118
-
119
-
120
-
121
-
122
-
123
-
124
-
125
-
126
-
127
-
128
-
129
-
130
-
131
-
132
-
133
-
134
-
135
-
136
-
137
-
138
-
139
-
140
-
141
-
142
-
143
-
144
-
145
-
146
-
147
-
148
-
149
-
150
-
151
-
152
-
153
-
154
-
155
-
156
-
157
-
158
-
159
-
160
-
161
-
162
-
163
-
164
-
165
-
166
-
167
-
168
-
169
-
170
-
171
-
172
-
173
-
174
-
175
-
176
-
177
-
178
-
179
-
180
-
181
-
182
-
183
-
184
-
185
-
186
-
187
-
188
-
189
-
190
-
191
-
192
-
193
-
194
-
195
-
196
-
197
-
198
-
199
-
200
-
201
-
202
-
203
-
204
-
205
-
206
-
207
-
208
-
209
-
210
-
211
-
212
-
213
-
214
-
215
-
216
-
217
-
218
-
219
-
220
-
221
-
222
-
223
-
224
-
225
-
226
-
227
-
228
-
229
-
230
-
231
-
232
-
233
-
234
-
235
-
236
-
237
-
238
-
239
-
240
-
241
-
242
-
243
-
244
-
245
-
246
-
247
-
248
-
249
-
250
-
251
-
252
-
253
-
254
-
255
-
256
-
257
-
258
-
259
-
260
-
261
-
262
-
263
-
264
-
265
-
266
-
267
-
268
-
269
-
270
-
271
-
272
-
273
-
274
-
275
-
276
-
277
-
278
-
279
-
280
-
281
-
282
-
283
-
284
-
285
-
286
-
287
-
288
-
289
-
290
-
291
-
292
{
config,
lib,
pkgs,
...
}:
let
fcitx5-lean = pkgs.callPackage (pkgs.fetchgit {
url = "https://git.unnamed.website/fcitx5-lean";
rev = "09f4c75509da34ee9438eabac41174a1fbe249ae";
hash = "sha256-5mbdh8oOBIIDAaBb9gfTigmX38rBefLKclGPJeCI9nQ=";
}) { };
in
{
# BAD NIX STORE STOP BEING 100GB
# Don't run the optimiser automatically though, since it doesn't save that much space and messes up generation build dates
# There's also auto-optimise-store but it apparently has performance issues
nix.gc = {
automatic = true;
dates = "weekly";
options = "--delete-older-than 7d";
};
# For NeoChat ugh
nixpkgs.config.permittedInsecurePackages = [ "olm-3.2.16" ];
hardware = {
# Auto screen rotation in tablet mode, auto brightness, and other goodies
sensor.iio.enable = true;
bluetooth.enable = true;
};
boot.loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
};
# NixOS is a disk destroyer
# I NEED ZSTD
fileSystems."/".options = [ "compress=zstd" ];
# Need to manually run this command due to KDE Connect and MIT network wonkiness:
# nmcli connection modify "MIT SECURE" +ipv4.routes "10.29.0.0/16 10.29.208.1"
networking.networkmanager.enable = true;
programs = {
firefox = {
enable = true;
# Probably want to stick with Firefox for now instead of LibreWolf which can only be configured with home-manager
# Only put settings here that are hard to change in the GUI
preferences = {
# Show title bar for KDE consistency
"browser.tabs.inTitlebar" = 0;
# INFINITE HISTORY
"places.history.expiration.max_pages" = 2147483647;
# KDE file picker
"widget.use-xdg-desktop-portal.file-picker" = 1;
};
};
# Disable Akonadi and other evil things
# KMail can and will hurt you
kde-pim.enable = false;
kdeconnect.enable = true;
# I'm lazy
# gitui is kinda buggy so use lazygit instead
lazygit.enable = true;
# So I can use my computer like a normal person
nix-ld.enable = true;
# Enable KDE partition manager so I don't have to clown around in fdisk
partition-manager.enable = true;
ssh = {
# Use KWallet to store SSH password
enableAskPassword = true;
startAgent = true;
};
thunderbird = {
enable = true;
preferences = {
# Show title bar for KDE consistency
"mail.tabs.drawInTitlebar" = false;
# KDE file picker
"widget.use-xdg-desktop-portal.file-picker" = 1;
};
};
};
# Enable Podman because I'm weak and need my Ubuntu help I need it I really need it
virtualisation.podman.enable = true;
environment = {
systemPackages = with pkgs; [
# Math and programming
# BLAZINGLY FAST FEARLESS CONCURRENCY
cargo
clippy
# Unfortunately
(coq.withPackages (
ps: with ps; [
coq # This is needed because coq-hammer expects coq-core, not rocq-core
coq-hammer
stdlib
vsrocq-language-server
]
))
# For the Dafny VSCode extension, dotnet must be in $PATH
# Use Dafny and Z3 from the extension rather than nixpkgs to match the exact version that 6.S057 uses
dotnet-runtime
# For installing Lean beta versions
# Also, lean4 from nixpkgs is often outdated and doesn't work with the mathlib binary cache
# TODO: Updating gcc breaks toolchains
elan
# For Lean FFI stuff
gcc
gnumake
# Unfortunately
# python3 in nixpkgs often lags behind the latest stable release, so hardcode the version here
python314
rust-analyzer
rustc
rustfmt
# 100x faster than pip!
uv
# Patch for XDG support
# https://discourse.nixos.org/t/can-i-install-vscodium-and-tweak-its-product-json/54481/3
(vscodium.overrideAttrs (old: {
postInstall = (old.postInstall or "") + ''
substituteInPlace $out/lib/vscode/resources/app/product.json --replace-fail .vscode-oss .local/share/VSCodium
'';
}))
# Apps
deja-dup
kdePackages.neochat
kdePackages.plasma-keyboard
kdePackages.tokodon
keepassxc
kile
krita
(mpv.override {
scripts = with pkgs.mpvScripts; [
mpris
visualizer
];
})
rnote
# Utilities and other random junk
# For biblatex
biber
ffmpeg
fusee-nano
hunspellDicts.en-us-large
ripgrep
sqlite
# Compared to texliveBasic, this includes some useful packages like setspace and subfigure
(texliveSmall.withPackages (ps: with ps; [ biblatex ]))
# Better man pages
tlrc
typst
typstyle
# Faster than imagemagick
vips
];
variables = {
# For Dafny
DOTNET_SYSTEM_GLOBALIZATION_INVARIANT = 1;
# Lean toolchains are huge so put them outside of ~ so they don't end up in backups or snapshots
ELAN_HOME = "/opt/elan";
# Make Electron apps use Wayland
# This seems necessary for VSCodium in particular
NIXOS_OZONE_WL = "1";
# For LuaLaTeX
TEXMFVAR = "$HOME/.cache/texmf-var";
# Make VSCodium use XDG
VSCODE_CLI_DATA_DIR = "$HOME/.local/share/VSCodium";
};
};
# Use simplified Chinese glyphs instead of Japanese such as for 门
# https://wiki.archlinux.org/title/Localization/Simplified_Chinese#Chinese_characters_displayed_as_variant_(Japanese)_glyphs
# My previous solution was to install wqy_microhei which only has Chinese glyphs but it's no longer maintained
# Also NixOS installs Noto Sans CJK by default now
# https://github.com/NixOS/nixpkgs/pull/521738/
fonts.fontconfig.defaultFonts = {
sansSerif = [
"Noto Sans"
"Noto Sans CJK SC"
];
serif = [
"Noto Serif"
"Noto Serif CJK SC"
];
monospace = [
"Hack" # Looks nicer than Noto Sans Mono and is what KDE uses by default
"Noto Sans Mono CJK SC"
];
};
i18n.inputMethod = {
enable = true;
type = "fcitx5";
fcitx5 = {
addons = with pkgs; [
kdePackages.fcitx5-chinese-addons
fcitx5-lean
];
waylandFrontend = true;
};
};
# KDE! YAY!
services.desktopManager.plasma6.enable = true;
# PLM
services.displayManager = {
autoLogin.user = "a";
plasma-login-manager.enable = true;
};
# Give PLM permission to read LUKS password for autologin
systemd.services.plasmalogin.serviceConfig.KeyringMode = "inherit";
# PAM is evil dark magic
security.pam.services.plasmalogin-autologin.rules.auth = {
systemd_loadkey = {
order = 0;
control = "optional";
modulePath = "${pkgs.systemd}/lib/security/pam_systemd_loadkey.so";
};
# The default /etc/pam.d/plasmalogin-autologin doesn't invoke pam_kwallet5.so
# Thus we need to manually do it with auth include plasmalogin
plasmalogin = {
order = 1;
control = "include";
modulePath = "plasmalogin";
};
};
# Fingerprint authentication
services.fprintd.enable = true;
# Don't enable fprintd for everything, otherwise plasmalogin takes 30 seconds to log in
# Also, pam_kwallet5.so needs my password which obviously doesn't work with fingerprint login
# https://github.com/NixOS/nixpkgs/issues/239770#issuecomment-1868402338
security.pam.services.login.fprintAuth = false;
# fprintd is buggy if running during sleep so kill it first
# This is an fprintd bug so Plasma updates probably won't fix it
systemd.services.kill-fprintd = {
wantedBy = [ "sleep.target" ];
before = [ "sleep.target" ];
serviceConfig.ExecStart = "${pkgs.killall}/bin/killall fprintd";
};
# My hardware is pretty well supported wow what a surprise
services.fwupd.enable = true;
# Sometimes apps in nixpkgs are broken or buggy or outdated so let's have an alternative available
# Yes I'm an evil Nix pragmatist rather than a Nix purist
services.flatpak.enable = true;
services.ollama = {
enable = true;
package = pkgs.ollama-vulkan;
};
# It sync things I guess
services.syncthing = {
enable = true;
user = "a";
group = "users";
openDefaultPorts = true;
# The default when running Syncthing normally
configDir = "/home/a/.local/state/syncthing";
};
# THE ONLY CORRECT BACKUP METHOD
services.btrbk.instances.btrbk.settings = {
timestamp_format = "short";
snapshot_dir = "/.snapshots";
snapshot_preserve = "3d 3w 3m *y";
snapshot_preserve_min = "latest";
volume."/".subvolume = "/home";
};
# Wait for internet connectivity if we just booted up
# network-online.target only waits for nm-online -s -q which doesn't necessarily mean the network is up
systemd.services.btrbk-btrbk.serviceConfig.ExecStartPre = "${pkgs.networkmanager}/bin/nm-online -q";
# Add SSH key to agent during desktop login
systemd.user.services.ssh-add = {
wantedBy = [ "graphical-session.target" ];
after = [ "plasma-kwallet-pam.service" ];
serviceConfig.ExecStart = "${pkgs.openssh}/bin/ssh-add";
};
}