sys/cli
本文件是NixOS的CLI配置。 主要包含两部分内容:
- 系统环境管理(root的环境)
- 系统配置
{ pkgs, lib, ... }:
{
系统环境管理(root的环境)
imports = [
./build-machines.nix
];
# List packages installed in system profile. To search, run:
# $ nix search wget
environment.systemPackages = with pkgs; [
git
file
wget
fzf
perf
];
# neovim
programs.neovim.enable = true;
programs.neovim.defaultEditor = true;
programs.neovim.viAlias = true;
programs.neovim.vimAlias = true;
# ssh
services.openssh = {
enable = true;
settings = {
X11Forwarding = true;
PasswordAuthentication = false;
};
};
系统配置
启用NTFS文件系统的支持。 如此就可以在NixOS/Windows双系统的电脑上挂在Windows的分区啦。
boot.supportedFilesystems = [ "ntfs" ];
配置binfmt,让非本地指令集的用户程序可以正常运行。
比如在x86_64-linux上运行aarch64-linux的用户程序。
注意:不能在配和本地一样的binfmt,比如不能在x86_64-linux的机器上配置x86_64-linux的binfmt。
不然会出现奇怪的嵌套?你执行任何一条命令(x86_64-linux)都需要去调用qemu-x86_64,
但qemu-x86_64本事也是x86_64-linux的,所以会死循环?
我做了个实验:在x86_64-linux的NixOS中启用x86_64-linux的binfmt。
任何程序都执行不了了,连关机都不行,只能强制重启。
不过好在NixOS可以回滚,轻松复原实验前的环境。
下面的filterAttrs就是用来保证不配置本地的binfmt。
boot.binfmt = {
emulatedSystems = lib.remove builtins.currentSystem [
"x86_64-linux"
"aarch64-linux"
"riscv64-linux"
];
preferStaticEmulators = true;
};
启用docdev。 在home-manager中装devdoc似乎有问题,得在NixOS中装才行。 之后有空再来详细研究。
# Make sure devdoc outputs are installed.
documentation.dev.enable = true;
# Make sure legacy path is installed as well.
environment.pathsToLink = [ "/share/gtk-doc" ];
nix.settings.trusted-users = ["root" "xieby1"];
zramSwap.enable = true;
boot.kernelPackages = pkgs.linuxPackages_xanmod;
networking.firewall.enable = false;
# The following are mkDefault when desktopManager.gnome.enable is true
networking.networkmanager.enable = true;
允许本机活跃用户(wheel组)免密修改NetworkManager连接配置。
否则连接新WiFi或修改密码时会写入system连接,触发polkit的
settings.modify.system 认证(dms自带polkit agent,会弹出密码框;
忽略则连接不会被持久化)。
仅放宽 settings.modify.*,且限定 active && local(本机活跃会话)
wheel,与NM默认对扫描/连接给出的allow_active=yes信任级别一致。
security.polkit.extraConfig = ''
polkit.addRule(function(action, subject) {
if (subject.active && subject.local && subject.isInGroup("wheel") &&
action.id.indexOf("org.freedesktop.NetworkManager.settings.modify.") === 0) {
return polkit.Result.YES;
}
});
'';
# Podman user Quadlets wait for the system network-online.target via
# podman-user-wait-network-online.service; pull it in at boot so the user
# wait service does not time out while polling an inactive passive target.
systemd.targets.network-online.wantedBy = [ "multi-user.target" ];
hardware.bluetooth.enable = true;
services.upower.enable = true;
# TODO: remove, currently home-manager switch needs
programs.dconf.enable = true;
}