sys/cli

本文件是NixOS的CLI配置。 主要包含两部分内容:

  • 系统环境管理(root的环境)
  • 系统配置
{ pkgs, lib, ... }:

{

系统环境管理(root的环境)

  imports = [
    ./build-machines.nix
  ];

  # List packages installed in system profile. To search, run:
  # $ nix search wget
  environment.systemPackages = with pkgs; [
    git
    file
    wget
    fzf
    perf
  ];

  # neovim
  programs.neovim.enable = true;
  programs.neovim.defaultEditor = true;
  programs.neovim.viAlias = true;
  programs.neovim.vimAlias = true;

  # ssh
  services.openssh = {
    enable = true;
    settings = {
      X11Forwarding = true;
      PasswordAuthentication = false;
    };
  };

系统配置

启用NTFS文件系统的支持。 如此就可以在NixOS/Windows双系统的电脑上挂在Windows的分区啦。

  boot.supportedFilesystems = [ "ntfs" ];

配置binfmt,让非本地指令集的用户程序可以正常运行。 比如在x86_64-linux上运行aarch64-linux的用户程序。 注意:不能在配和本地一样的binfmt,比如不能在x86_64-linux的机器上配置x86_64-linux的binfmt。 不然会出现奇怪的嵌套?你执行任何一条命令(x86_64-linux)都需要去调用qemu-x86_64, 但qemu-x86_64本事也是x86_64-linux的,所以会死循环? 我做了个实验:在x86_64-linux的NixOS中启用x86_64-linux的binfmt。 任何程序都执行不了了,连关机都不行,只能强制重启。 不过好在NixOS可以回滚,轻松复原实验前的环境。 下面的filterAttrs就是用来保证不配置本地的binfmt。

  boot.binfmt = {
    emulatedSystems = lib.remove builtins.currentSystem [
      "x86_64-linux"
      "aarch64-linux"
      "riscv64-linux"
    ];
    preferStaticEmulators = true;
  };

启用docdev。 在home-manager中装devdoc似乎有问题,得在NixOS中装才行。 之后有空再来详细研究。

  # Make sure devdoc outputs are installed.
  documentation.dev.enable = true;
  # Make sure legacy path is installed as well.
  environment.pathsToLink = [ "/share/gtk-doc" ];

  nix.settings.trusted-users = ["root" "xieby1"];

  zramSwap.enable = true;

  boot.kernelPackages = pkgs.linuxPackages_xanmod;

  networking.firewall.enable = false;

  # The following are mkDefault when desktopManager.gnome.enable is true
  networking.networkmanager.enable = true;

允许本机活跃用户(wheel组)免密修改NetworkManager连接配置。 否则连接新WiFi或修改密码时会写入system连接,触发polkit的 settings.modify.system 认证(dms自带polkit agent,会弹出密码框; 忽略则连接不会被持久化)。 仅放宽 settings.modify.*,且限定 active && local(本机活跃会话)

  • wheel,与NM默认对扫描/连接给出的 allow_active=yes 信任级别一致。
  security.polkit.extraConfig = ''
    polkit.addRule(function(action, subject) {
      if (subject.active && subject.local && subject.isInGroup("wheel") &&
          action.id.indexOf("org.freedesktop.NetworkManager.settings.modify.") === 0) {
        return polkit.Result.YES;
      }
    });
  '';
  # Podman user Quadlets wait for the system network-online.target via
  # podman-user-wait-network-online.service; pull it in at boot so the user
  # wait service does not time out while polling an inactive passive target.
  systemd.targets.network-online.wantedBy = [ "multi-user.target" ];
  hardware.bluetooth.enable = true;
  services.upower.enable = true;
  # TODO: remove, currently home-manager switch needs
  programs.dconf.enable = true;
}