summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--flake.lock68
-rw-r--r--flake.nix92
-rw-r--r--lib/depot-tools.nix84
-rw-r--r--machines/radon/pxeboot.nix1
-rw-r--r--machines/t1/default.nix6
-rw-r--r--machines/t480/default.nix38
-rw-r--r--mod/code/cses/.envrc1
-rw-r--r--mod/misc/cv/default.nix6
-rw-r--r--mod/nix/readTree/default.nix326
-rw-r--r--mod/tools/typst/default.nix34
-rw-r--r--mod/tools/typst/main.typ1
-rw-r--r--mod/tools/typst/packages/tmu/template.typ37
-rw-r--r--mod/tools/typst/packages/tmu/typst.toml7
-rw-r--r--mod/web/blog/default.nix30
-rw-r--r--mod/web/resistors/default.nix12
-rw-r--r--modules/dns.nix (renamed from machines/xnet/net/dns.nix)0
-rw-r--r--modules/users.nix (renamed from mod/users/kle/default.nix)20
-rw-r--r--modules/xnet/README (renamed from machines/xnet/README)0
-rw-r--r--modules/xnet/default.nix (renamed from machines/xnet/default.nix)0
-rw-r--r--modules/xnet/desktop/default.nix (renamed from machines/xnet/desktop/default.nix)0
-rw-r--r--modules/xnet/disk.nix (renamed from machines/xnet/disk.nix)3
-rw-r--r--modules/xnet/gitserver/default.nix (renamed from machines/xnet/gitserver/default.nix)0
-rw-r--r--modules/xnet/gitserver/gitweb.nix (renamed from machines/xnet/gitserver/gitweb.nix)0
-rw-r--r--modules/xnet/monitoring/22604_rev2.json (renamed from machines/xnet/monitoring/22604_rev2.json)0
-rw-r--r--modules/xnet/monitoring/default.nix (renamed from machines/xnet/monitoring/default.nix)0
-rw-r--r--modules/xnet/monitoring/grafana.nix (renamed from machines/xnet/monitoring/grafana.nix)0
-rw-r--r--modules/xnet/net/default.nix (renamed from machines/xnet/net/default.nix)0
-rw-r--r--modules/xnet/net/dns.nix38
-rw-r--r--modules/xnet/net/sshd.nix (renamed from machines/xnet/net/sshd.nix)0
-rw-r--r--modules/xnet/nginx.nix (renamed from machines/xnet/nginx.nix)0
-rw-r--r--modules/xnet/persist.nix (renamed from machines/xnet/persist.nix)0
-rw-r--r--packages/blog/.gitignore (renamed from mod/web/blog/.gitignore)0
-rw-r--r--packages/blog/config.toml (renamed from mod/web/blog/config.toml)0
-rw-r--r--packages/blog/content/posts/_index.md (renamed from mod/web/blog/content/posts/_index.md)0
-rw-r--r--packages/blog/content/posts/deterministic-hostnames.md (renamed from mod/web/blog/content/posts/deterministic-hostnames.md)0
-rw-r--r--packages/blog/content/posts/nohup.md (renamed from mod/web/blog/content/posts/nohup.md)0
-rw-r--r--packages/blog/content/posts/stateless-compute-networks.md (renamed from mod/web/blog/content/posts/stateless-compute-networks.md)0
-rw-r--r--packages/blog/content/posts/vim-compilers.md (renamed from mod/web/blog/content/posts/vim-compilers.md)0
-rw-r--r--packages/blog/default.nix21
-rw-r--r--packages/blog/templates/404.html (renamed from mod/web/blog/templates/404.html)0
-rw-r--r--packages/blog/templates/base.html (renamed from mod/web/blog/templates/base.html)0
-rw-r--r--packages/blog/templates/index.html (renamed from mod/web/blog/templates/index.html)0
-rw-r--r--packages/blog/templates/post.html (renamed from mod/web/blog/templates/post.html)0
-rw-r--r--packages/cses/default.nix (renamed from mod/code/cses/default.nix)0
-rw-r--r--packages/cses/problems/1068.cpp (renamed from mod/code/cses/problems/1068.cpp)0
-rw-r--r--packages/cses/problems/1069.cpp (renamed from mod/code/cses/problems/1069.cpp)0
-rw-r--r--packages/cses/problems/1070.cpp (renamed from mod/code/cses/problems/1070.cpp)0
-rw-r--r--packages/cses/problems/1071.cpp (renamed from mod/code/cses/problems/1071.cpp)0
-rw-r--r--packages/cses/problems/1083.cpp (renamed from mod/code/cses/problems/1083.cpp)0
-rw-r--r--packages/cses/problems/1094.cpp (renamed from mod/code/cses/problems/1094.cpp)0
-rw-r--r--packages/cv/cv.typ (renamed from mod/misc/cv/cv.typ)0
-rw-r--r--packages/cv/default.nix5
-rw-r--r--packages/perf-flamegraph.nix (renamed from mod/tools/perf-flamegraph.nix)0
-rw-r--r--packages/resistors/default.nix7
-rw-r--r--packages/resistors/index.html (renamed from mod/web/resistors/index.html)0
-rw-r--r--packages/resistors/styles.css (renamed from mod/web/resistors/styles.css)0
56 files changed, 215 insertions, 622 deletions
diff --git a/flake.lock b/flake.lock
index ea444a3..b40bfe5 100644
--- a/flake.lock
+++ b/flake.lock
@@ -1,28 +1,5 @@
{
"nodes": {
- "agenix": {
- "inputs": {
- "darwin": [],
- "home-manager": "home-manager",
- "nixpkgs": [
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1703089996,
- "narHash": "sha256-ipqShkBmHKC9ft1ZAsA6aeKps32k7+XZSPwfxeHLsAU=",
- "owner": "ryantm",
- "repo": "agenix",
- "rev": "564595d0ad4be7277e07fa63b5a991b3c645655d",
- "type": "github"
- },
- "original": {
- "owner": "ryantm",
- "ref": "0.15.0",
- "repo": "agenix",
- "type": "github"
- }
- },
"disko": {
"inputs": {
"nixpkgs": [
@@ -44,27 +21,6 @@
"type": "github"
}
},
- "home-manager": {
- "inputs": {
- "nixpkgs": [
- "agenix",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1682203081,
- "narHash": "sha256-kRL4ejWDhi0zph/FpebFYhzqlOBrk0Pl3dzGEKSAlEw=",
- "owner": "nix-community",
- "repo": "home-manager",
- "rev": "32d3e39c491e2f91152c84f8ad8b003420eab0a1",
- "type": "github"
- },
- "original": {
- "owner": "nix-community",
- "repo": "home-manager",
- "type": "github"
- }
- },
"naersk": {
"inputs": {
"nixpkgs": [
@@ -119,32 +75,10 @@
},
"root": {
"inputs": {
- "agenix": "agenix",
"disko": "disko",
"naersk": "naersk",
"nixos-hardware": "nixos-hardware",
- "nixpkgs": "nixpkgs",
- "sops-nix": "sops-nix"
- }
- },
- "sops-nix": {
- "inputs": {
- "nixpkgs": [
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1732186149,
- "narHash": "sha256-N9JGWe/T8BC0Tss2Cv30plvZUYoiRmykP7ZdY2on2b0=",
- "owner": "Mic92",
- "repo": "sops-nix",
- "rev": "53c853fb1a7e4f25f68805ee25c83d5de18dc699",
- "type": "github"
- },
- "original": {
- "owner": "Mic92",
- "repo": "sops-nix",
- "type": "github"
+ "nixpkgs": "nixpkgs"
}
}
},
diff --git a/flake.nix b/flake.nix
index 771e38a..605017b 100644
--- a/flake.nix
+++ b/flake.nix
@@ -1,19 +1,11 @@
{
description = "Personal monorepo";
-
inputs = {
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
disko.url = "github:nix-community/disko/v1.6.1";
disko.inputs.nixpkgs.follows = "nixpkgs";
- sops-nix.url = "github:Mic92/sops-nix";
- sops-nix.inputs.nixpkgs.follows = "nixpkgs";
-
- agenix.url = "github:ryantm/agenix/0.15.0";
- agenix.inputs.nixpkgs.follows = "nixpkgs";
- agenix.inputs.darwin.follows = "";
-
nixos-hardware.url = "github:nixos/nixos-hardware/master";
# Rust projects
@@ -25,70 +17,71 @@
let
inherit (builtins)
attrNames
- filter
listToAttrs
map
readDir
;
+ inherit (nixpkgs) lib;
+
inherit (nixpkgs.lib)
+ mapAttrs
nixosSystem
;
- readTree = import ./mod/nix/readTree { };
+ systems = [ "x86_64-linux" "aarch64-linux" ];
- # Recursively converts subdirectories under ./mod into an attrset
- # that can be passed to other parts of the depot.
- readDepot = depotArgs: readTree {
- args = depotArgs;
- path = ./mod;
- };
+ inherit (import ./lib/depot-tools.nix { inherit inputs systems lib; })
+ importDir
+ eachSystem
+ systemArgs
+ ;
- # Named arguments to be made available to any nix expression in
- # the depot module.
- depot = readTree.fix (self: readDepot {
- depot = self;
+ packages = eachSystem (
+ { newScope, ... }:
+ mapAttrs (pname: { path, ... }: newScope { inherit pname; } path { })
+ (importDir ./packages)
+ );
+ publisherArgs = {
+ flake = self;
inherit inputs;
+ };
- # x86_64-linux is hardcoded as the package arch only for the
- # mod directory. This workaround keeps the flake pure,
- # at the expense of only supporting one system. This can
- # be circumvented by retrieving the system during evaluation,
- # but flakes disallow this by design.
- #
- # This monorepo currently depends on functionality from flakes,
- # but this may change in the future, perhaps shifting to an
- # impure base with certain packages exposed from the flake in a
- # pure way.
- #
- # In practice, this means that any configuration or package
- # exposed from the depot flake that makes use of internal
- # derivations is limited to x86_64-linux. For now this is fine,
- # but ideally any architecture supported by nix should be
- # allowed to evaluate projects hosted here.
- pkgs = nixpkgs.legacyPackages."x86_64-linux";
+ expectsPublisherArgs =
+ module:
+ builtins.isFunction module
+ && builtins.all (arg: builtins.elem arg (builtins.attrNames publisherArgs)) (
+ builtins.attrNames (builtins.functionArgs module)
+ );
- # Expose lib attribute to modules.
- lib = nixpkgs.lib;
- });
+ injectPublisherArgs =
+ modulePath:
+ let
+ module = import modulePath;
+ in
+ if expectsPublisherArgs module then
+ lib.setDefaultModuleLocation modulePath (module publisherArgs)
+ else
+ modulePath;
- machines = filter (m: m != "xnet")
- (attrNames (readDir ./machines));
+ nixosModules = mapAttrs (_: moduleDir: injectPublisherArgs moduleDir)
+ (mapAttrs (_: { path, ... }: path) (importDir ./modules));
in
{
- inherit depot;
-
- nixosModules.xnet.imports =
- [ ./machines/xnet inputs.disko.nixosModules.disko ];
+ inherit packages nixosModules;
nixosConfigurations = listToAttrs (
map
(name: {
inherit name;
- value = nixosSystem {
+ value = nixosSystem rec {
system = "x86_64-linux";
- specialArgs = { inherit inputs depot; };
+ specialArgs = {
+ inherit inputs;
+ inherit (self) outputs;
+ inherit (systemArgs.${system}) flake perSystem;
+ };
modules = [
# Machine's specific configuration
./machines/${name}
@@ -108,6 +101,7 @@
];
};
})
- machines);
+ (attrNames (readDir ./machines))
+ );
};
}
diff --git a/lib/depot-tools.nix b/lib/depot-tools.nix
new file mode 100644
index 0000000..448055a
--- /dev/null
+++ b/lib/depot-tools.nix
@@ -0,0 +1,84 @@
+{ inputs
+, systems
+, nixpkgs ? inputs.nixpkgs
+, ...
+}:
+
+let
+ inherit (builtins)
+ match
+ head
+ readDir
+ ;
+
+ inherit (nixpkgs.lib)
+ callPackageWith
+ filterAttrs
+ genAttrs
+ makeScope
+ mapAttrs
+ mapAttrs'
+ ;
+
+ importDir =
+ path:
+ let
+ entries = readDir path;
+
+ # Get paths to directories
+ onlyDirs = filterAttrs (_name: type: type == "directory") entries;
+ dirPaths = mapAttrs
+ (name: type: {
+ path = path + "/${name}";
+ inherit type;
+ })
+ onlyDirs;
+
+ # Get paths to nix files, where the name is the basename of the file without the .nix extension
+ nixPaths = removeAttrs
+ (mapAttrs'
+ (
+ name: type:
+ let
+ nixName = match "(.*)\\.nix" name;
+ in
+ {
+ name = if type == "directory" || nixName == null then "__junk" else (head nixName);
+ value = {
+ path = path + "/${name}";
+ type = type;
+ };
+ }
+ )
+ entries) [ "__junk" ];
+ in
+ dirPaths // nixPaths;
+
+ # Memoize the args per system
+ systemArgs = genAttrs systems (
+ system:
+ let
+ # Resolve the packages for each input.
+ perSystem = mapAttrs
+ (_: flake: flake.legacyPackages.${system} or { } // flake.packages.${system} or { })
+ inputs;
+
+ # Handle nixpkgs specially.
+ pkgs =
+ if (nixpkgs.config or { }) == { } && (nixpkgs.overlays or [ ]) == [ ] then
+ perSystem.nixpkgs
+ else
+ import inputs.nixpkgs {
+ inherit system;
+ config = nixpkgs.config or { };
+ overlays = nixpkgs.overlays or [ ];
+ };
+
+ flake = inputs.self;
+ in
+ makeScope callPackageWith (_: { inherit inputs perSystem flake pkgs system; })
+ );
+
+ eachSystem = f: genAttrs systems (system: f systemArgs.${system});
+in
+{ inherit importDir systemArgs eachSystem; }
diff --git a/machines/radon/pxeboot.nix b/machines/radon/pxeboot.nix
index 4d897c3..4655990 100644
--- a/machines/radon/pxeboot.nix
+++ b/machines/radon/pxeboot.nix
@@ -24,6 +24,7 @@ let
users.users.root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP7T2uWJFUu8aFZZgQusGKyEMocb2pKbHLDad2eIJus9"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEOw8YEbHsKy38JHp9W1wcxxZgWCDgnabOXccZUN5ddd"
];
})
];
diff --git a/machines/t1/default.nix b/machines/t1/default.nix
index f565fc6..7f375a1 100644
--- a/machines/t1/default.nix
+++ b/machines/t1/default.nix
@@ -1,4 +1,4 @@
-{ inputs, depot, pkgs, ... }:
+{ inputs, flake, pkgs, perSystem, ... }:
let
inherit (inputs.nixos-hardware.nixosModules)
@@ -6,7 +6,7 @@ let
common-gpu-amd
;
- inherit (depot.users) kle;
+ inherit (import flake.outputs.nixosModules.users { inherit perSystem pkgs; }) kle;
in
{
imports = [
@@ -16,7 +16,7 @@ in
system.stateVersion = "24.11";
- users.users.kle = kle.nixos;
+ users.users.kle = kle;
xnet = {
desktop.enable = true;
diff --git a/machines/t480/default.nix b/machines/t480/default.nix
index e726670..24b6bc6 100644
--- a/machines/t480/default.nix
+++ b/machines/t480/default.nix
@@ -1,12 +1,10 @@
-{ inputs, depot, ... }:
+{ inputs, flake, perSystem, pkgs, ... }:
let
inherit (inputs.nixos-hardware.nixosModules)
lenovo-thinkpad-t480
;
- inherit (depot.users)
- kle
- ;
+ inherit (import flake.outputs.nixosModules.users { inherit perSystem pkgs; }) kle;
in
{
imports = [
@@ -23,16 +21,15 @@ in
};
};
- users.users.kle = kle.nixos;
+ users.users.kle = kle;
networking = {
hostName = "t480";
useDHCP = false;
dhcpcd.enable = false;
- nameservers = [ "127.0.0.1" ];
networkmanager = {
enable = true;
- dns = "none";
+ # dns = "none";
wifi.powersave = true;
};
};
@@ -40,32 +37,5 @@ in
programs.nm-applet.enable = true;
services.fwupd.enable = true;
- services.unbound = {
- enable = true;
- settings.server = {
- interface = [ "127.0.0.1" ];
- port = 53;
- access-control = [ "127.0.0.1 allow" ];
- harden-glue = true;
- harden-dnssec-stripped = true;
- use-caps-for-id = false;
- prefetch = true;
- edns-buffer-size = 1232;
- hide-identity = true;
- hide-version = true;
- };
-
- settings.forward-zone = [
- {
- name = ".";
- forward-tls-upstream = true;
- forward-addr = [
- "9.9.9.9#dns.quad9.net"
- "149.112.112.112#dns.quad9.net"
- ];
- }
- ];
- };
-
xnet.persist = [ "/etc/NetworkManager/system-connections" ];
}
diff --git a/mod/code/cses/.envrc b/mod/code/cses/.envrc
deleted file mode 100644
index 1d953f4..0000000
--- a/mod/code/cses/.envrc
+++ /dev/null
@@ -1 +0,0 @@
-use nix
diff --git a/mod/misc/cv/default.nix b/mod/misc/cv/default.nix
deleted file mode 100644
index b663475..0000000
--- a/mod/misc/cv/default.nix
+++ /dev/null
@@ -1,6 +0,0 @@
-{ pkgs, ... }:
-
-pkgs.runCommand "cv" { } ''
- mkdir -p $out/share
- ${pkgs.typst}/bin/typst compile ${./cv.typ} $out/share/cv.pdf
-''
diff --git a/mod/nix/readTree/default.nix b/mod/nix/readTree/default.nix
deleted file mode 100644
index 4a745ce..0000000
--- a/mod/nix/readTree/default.nix
+++ /dev/null
@@ -1,326 +0,0 @@
-# Copyright (c) 2019 Vincent Ambo
-# Copyright (c) 2020-2021 The TVL Authors
-# SPDX-License-Identifier: MIT
-#
-# Provides a function to automatically read a filesystem structure
-# into a Nix attribute set.
-#
-# Called with an attribute set taking the following arguments:
-#
-# path: Path to a directory from which to start reading the tree.
-#
-# args: Argument set to pass to each imported file.
-#
-# filter: Function to filter `args` based on the tree location. This should
-# be a function of the form `args -> location -> args`, where the
-# location is a list of strings representing the path components of
-# the current readTree target. Optional.
-{ ... }:
-
-let
- inherit (builtins)
- attrNames
- concatMap
- concatStringsSep
- elem
- elemAt
- filter
- hasAttr
- head
- isAttrs
- listToAttrs
- map
- match
- readDir
- substring;
-
- argsWithPath = args: parts:
- let meta.locatedAt = parts;
- in meta // (if isAttrs args then args else args meta);
-
- readDirVisible = path:
- let
- children = readDir path;
- # skip hidden files, except for those that contain special instructions to readTree
- isVisible = f: f == ".skip-subtree" || f == ".skip-tree" || (substring 0 1 f) != ".";
- names = filter isVisible (attrNames children);
- in
- listToAttrs (map
- (name: {
- inherit name;
- value = children.${name};
- })
- names);
-
- # Create a mark containing the location of this attribute and
- # a list of all child attribute names added by readTree.
- marker = parts: children: {
- __readTree = parts;
- __readTreeChildren = builtins.attrNames children;
- };
-
- # Create a label from a target's tree location.
- mkLabel = target:
- let label = concatStringsSep "/" target.__readTree;
- in if target ? __subtarget
- then "${label}:${target.__subtarget}"
- else label;
-
- # Merge two attribute sets, but place attributes in `passthru` via
- # `overrideAttrs` for derivation targets that support it.
- merge = a: b:
- if a ? overrideAttrs
- then
- a.overrideAttrs
- (prev: {
- passthru = (prev.passthru or { }) // b;
- })
- else a // b;
-
- # Import a file and enforce our calling convention
- importFile = args: scopedArgs: path: parts: filter:
- let
- importedFile =
- if scopedArgs != { } && builtins ? scopedImport # For tvix
- then builtins.scopedImport scopedArgs path
- else import path;
- pathType = builtins.typeOf importedFile;
- in
- if pathType != "lambda"
- then throw "readTree: trying to import ${toString path}, but it’s a ${pathType}, you need to make it a function like { depot, pkgs, ... }"
- else importedFile (filter parts (argsWithPath args parts));
-
- nixFileName = file:
- let res = match "(.*)\\.nix" file;
- in if res == null then null else head res;
-
- # Internal implementation of readTree, which handles things like the
- # skipping of trees and subtrees.
- #
- # This method returns an attribute sets with either of two shapes:
- #
- # { ok = ...; } # a tree was read successfully
- # { skip = true; } # a tree was skipped
- #
- # The higher-level `readTree` method assembles the final attribute
- # set out of these results at the top-level, and the internal
- # `children` implementation unwraps and processes nested trees.
- readTreeImpl = { args, initPath, rootDir, parts, argsFilter, scopedArgs }:
- let
- dir = readDirVisible initPath;
-
- # Determine whether any part of this tree should be skipped.
- #
- # Adding a `.skip-subtree` file will still allow the import of
- # the current node's "default.nix" file, but stop recursion
- # there.
- #
- # Adding a `.skip-tree` file will completely ignore the folder
- # in which this file is located.
- skipTree = hasAttr ".skip-tree" dir;
- skipSubtree = skipTree || hasAttr ".skip-subtree" dir;
-
- joinChild = c: initPath + ("/" + c);
-
- self =
- if rootDir
- then { __readTree = [ ]; }
- else importFile args scopedArgs initPath parts argsFilter;
-
- # Import subdirectories of the current one, unless any skip
- # instructions exist.
- #
- # This file can optionally contain information on why the tree
- # should be ignored, but its content is not inspected by
- # readTree
- filterDir = f: dir."${f}" == "directory";
- filteredChildren = map
- (c: {
- name = c;
- value = readTreeImpl {
- inherit argsFilter scopedArgs;
- args = args;
- initPath = (joinChild c);
- rootDir = false;
- parts = (parts ++ [ c ]);
- };
- })
- (filter filterDir (attrNames dir));
-
- # Remove skipped children from the final set, and unwrap the
- # result set.
- children =
- if skipSubtree then [ ]
- else map ({ name, value }: { inherit name; value = value.ok; }) (filter (child: child.value ? ok) filteredChildren);
-
- # Import Nix files
- nixFiles =
- if skipSubtree then [ ]
- else filter (f: f != null) (map nixFileName (attrNames dir));
- nixChildren = map
- (c:
- let
- p = joinChild (c + ".nix");
- childParts = parts ++ [ c ];
- imported = importFile args scopedArgs p childParts argsFilter;
- in
- {
- name = c;
- value =
- if isAttrs imported
- then merge imported (marker childParts { })
- else imported;
- })
- nixFiles;
-
- nodeValue = if dir ? "default.nix" then self else { };
-
- allChildren = listToAttrs (
- if dir ? "default.nix"
- then children
- else nixChildren ++ children
- );
-
- in
- if skipTree
- then { skip = true; }
- else {
- ok =
- if isAttrs nodeValue
- then merge nodeValue (allChildren // (marker parts allChildren))
- else nodeValue;
- };
-
- # Top-level implementation of readTree itself.
- readTree = args:
- let
- tree = readTreeImpl args;
- in
- if tree ? skip
- then throw "Top-level folder has a .skip-tree marker and could not be read by readTree!"
- else tree.ok;
-
- # Helper function to fetch subtargets from a target. This is a
- # temporary helper to warn on the use of the `meta.targets`
- # attribute, which is deprecated in favour of `meta.ci.targets`.
- subtargets = node:
- let targets = (node.meta.targets or [ ]) ++ (node.meta.ci.targets or [ ]);
- in if node ? meta.targets then
- builtins.trace ''
- Warning: The meta.targets attribute is deprecated.
-
- Please move the subtargets of //${mkLabel node} to the
- meta.ci.targets attribute.
- 
- ''
- targets else targets;
-
- # Function which can be used to find all readTree targets within an
- # attribute set.
- #
- # This function will gather physical targets, that is targets which
- # correspond directly to a location in the repository, as well as
- # subtargets (specified in the meta.ci.targets attribute of a node).
- #
- # This can be used to discover targets for inclusion in CI
- # pipelines.
- #
- # Called with the arguments:
- #
- # eligible: Function to determine whether the given derivation
- # should be included in the build.
- gather = eligible: node:
- if node ? __readTree then
- # Include the node itself if it is eligible.
- (if eligible node then [ node ] else [ ])
- # Include eligible children of the node
- ++ concatMap (gather eligible) (map (attr: node."${attr}") node.__readTreeChildren)
- # Include specified sub-targets of the node
- ++ filter eligible (map
- (k: (node."${k}" or { }) // {
- # Keep the same tree location, but explicitly mark this
- # node as a subtarget.
- __readTree = node.__readTree;
- __readTreeChildren = [ ];
- __subtarget = k;
- })
- (subtargets node))
- else [ ];
-
- # Determine whether a given value is a derivation.
- # Copied from nixpkgs/lib for cases where lib is not available yet.
- isDerivation = x: isAttrs x && x ? type && x.type == "derivation";
-in
-{
- inherit gather mkLabel;
-
- __functor = _:
- { path
- , args
- , filter ? (_parts: x: x)
- , scopedArgs ? { }
- }:
- readTree {
- inherit args scopedArgs;
- argsFilter = filter;
- initPath = path;
- rootDir = true;
- parts = [ ];
- };
-
- # In addition to readTree itself, some functionality is exposed that
- # is useful for users of readTree.
-
- # Create a readTree filter disallowing access to the specified
- # top-level folder in the repository, except for specific exceptions
- # specified by their (full) paths.
- #
- # Called with the arguments:
- #
- # folder: Name of the restricted top-level folder (e.g. 'experimental')
- #
- # exceptions: List of readTree parts (e.g. [ [ "services" "some-app" ] ]),
- # which should be able to access the restricted folder.
- #
- # reason: Textual explanation for the restriction (included in errors)
- restrictFolder = { folder, exceptions ? [ ], reason }: parts: args:
- if (elemAt parts 0) == folder || elem parts exceptions
- then args
- else args // {
- depot = args.depot // {
- "${folder}" = throw ''
- Access to targets under //${folder} is not permitted from
- other repository paths. Specific exceptions are configured
- at the top-level.
-
- ${reason}
- At location: ${builtins.concatStringsSep "." parts}
- '';
- };
- };
-
- # This definition of fix is identical to <nixpkgs>.lib.fix, but is
- # provided here for cases where readTree is used before nixpkgs can
- # be imported.
- #
- # It is often required to create the args attribute set.
- fix = f: let x = f x; in x;
-
- # Takes an attribute set and adds a meta.ci.targets attribute to it
- # which contains all direct children of the attribute set which are
- # derivations.
- #
- # Type: attrs -> attrs
- drvTargets = attrs:
- attrs // {
- # preserve .meta from original attrs
- meta = (attrs.meta or { }) // {
- # preserve .meta.ci (except .targets) from original attrs
- ci = (attrs.meta.ci or { }) // {
- targets = builtins.filter
- (x: isDerivation attrs."${x}")
- (builtins.attrNames attrs);
- };
- };
- };
-}
diff --git a/mod/tools/typst/default.nix b/mod/tools/typst/default.nix
deleted file mode 100644
index 1871cc6..0000000
--- a/mod/tools/typst/default.nix
+++ /dev/null
@@ -1,34 +0,0 @@
-{ pkgs, ... }:
-let
- version = "0.0.0";
-
- depotPackages = pkgs.stdenvNoCC.mkDerivation {
- pname = "depot-typst-packages";
- inherit version;
- src = ./packages;
- phases = [ "installPhase" ];
-
- installPhase = ''
- for pkg in $src/*; do
- name=$(basename $pkg)
- mkdir -p $out/share/typst/packages/depot/$name/${version}
- cp -rv $pkg/* $out/share/typst/packages/depot/$name/${version}/
- done
- '';
- };
-in
-{
- inherit depotPackages;
-
- writeEnv = pkgs.mkShellNoCC {
- packages = [
- pkgs.typst
- pkgs.typstyle
- pkgs.tinymist
- depotPackages
- ];
-
- shellHook = "export TYPST_PACKAGE_PATH=${depotPackages}/share/typst";
- # shellHook = "alias typst='XDG_DATA_HOME=${depotPackages}/share typst'";
- };
-}
diff --git a/mod/tools/typst/main.typ b/mod/tools/typst/main.typ
deleted file mode 100644
index c6be2b4..0000000
--- a/mod/tools/typst/main.typ
+++ /dev/null
@@ -1 +0,0 @@
-#import "@depot/tmu:0.0.0": *
diff --git a/mod/tools/typst/packages/tmu/template.typ b/mod/tools/typst/packages/tmu/template.typ
deleted file mode 100644
index 721e7b6..0000000
--- a/mod/tools/typst/packages/tmu/template.typ
+++ /dev/null
@@ -1,37 +0,0 @@
-#let report(
- title: [],
- course: [],
- semester: [],
- authors: (),
- doc,
-) = {
- set page(
- paper: "us-letter",
- margin: 1.5in,
- numbering: "1",
- header: align(horizon, strong(course + h(1fr) + semester)),
- )
-
- set align(center)
- text(18pt, strong(title))
- linebreak()
- text(12pt, "Toronto Metropolitan University")
-
- v(24pt)
-
- grid(
- columns: (1fr,) * calc.min(authors.len(), 4),
- row-gutter: 12pt,
- ..authors.map(a => [
- #a.name \
- #a.id \
- #link("mailto:" + a.email)
- ])
- )
-
- set align(left)
- set par(justify: true)
- v(24pt)
-
- doc
-}
diff --git a/mod/tools/typst/packages/tmu/typst.toml b/mod/tools/typst/packages/tmu/typst.toml
deleted file mode 100644
index caf96d7..0000000
--- a/mod/tools/typst/packages/tmu/typst.toml
+++ /dev/null
@@ -1,7 +0,0 @@
-[package]
-name = "tmu"
-version = "0.0.0"
-entrypoint = "template.typ"
-authors = ["Kleidi Bujari"]
-license = "MIT"
-description = "TMU engineering report template"
diff --git a/mod/web/blog/default.nix b/mod/web/blog/default.nix
deleted file mode 100644
index 1f91a68..0000000
--- a/mod/web/blog/default.nix
+++ /dev/null
@@ -1,30 +0,0 @@
-{ pkgs, depot, ... }:
-let
- inherit (pkgs)
- symlinkJoin
- ;
-
- posts = pkgs.stdenvNoCC.mkDerivation {
- pname = "4kb.net";
- version = "1.0";
- src = ./.;
-
- nativeBuildInputs = with pkgs; [
- zola
- ];
-
- buildPhase = "zola build";
- installPhase = ''
- mkdir -p $out
- cp -r public/* $out/
- '';
- };
-
-in
-symlinkJoin {
- name = "site";
- paths = [
- posts
- depot.misc.cv
- ];
-}
diff --git a/mod/web/resistors/default.nix b/mod/web/resistors/default.nix
deleted file mode 100644
index 5fca68b..0000000
--- a/mod/web/resistors/default.nix
+++ /dev/null
@@ -1,12 +0,0 @@
-{ pkgs, ... }:
-
-pkgs.stdenvNoCC.mkDerivation {
- pname = "resistors";
- version = "0.0";
- src = ./.;
-
- buildInputs = [ pkgs.nodePackages.prettier ];
-
- phases = [ "installPhase" ];
- installPhase = "mkdir -p $out; cp -r $src/*.{css,html} $out/";
-}
diff --git a/machines/xnet/net/dns.nix b/modules/dns.nix
index 0632fa9..0632fa9 100644
--- a/machines/xnet/net/dns.nix
+++ b/modules/dns.nix
diff --git a/mod/users/kle/default.nix b/modules/users.nix
index fca1ec7..f9f7df3 100644
--- a/mod/users/kle/default.nix
+++ b/modules/users.nix
@@ -1,29 +1,19 @@
-{ pkgs, depot, ... }:
+{ pkgs, perSystem, ... }:
let
inherit (builtins)
- attrValues
- ;
+ attrValues;
- inherit (depot.tools)
+ inherit (perSystem.self)
perf-flamegraph
;
-
- gitKeys = builtins.fetchurl {
- url = "https://github.com/kbujari.keys";
- sha256 = "1kskbiyqvjz1wsmcrgh9v0iryf33y70zk503z0m96wmzdjllmc94";
- };
-
keys = {
t480 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEOw8YEbHsKy38JHp9W1wcxxZgWCDgnabOXccZUN5ddd";
t1 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP7T2uWJFUu8aFZZgQusGKyEMocb2pKbHLDad2eIJus9";
};
in
{
- inherit keys;
- inherit gitKeys;
-
- nixos = {
+ kle = {
initialHashedPassword = "$6$R4dDhaftX.vapGMd$.An36hlp3DXfkIC7bPZ0MDPo6Zvpk8JRrhy2LES.lZZj6JDa74oJkcMW3DCsIySvLJxOPXSShos0TpgJ/w0fH/";
isNormalUser = true;
shell = pkgs.fish;
@@ -33,9 +23,11 @@ in
packages = with pkgs; [
btop
curl
+ emacs
fzf
guvcview
jq
+ jujutsu
lynx
neovim
perf-flamegraph
diff --git a/machines/xnet/README b/modules/xnet/README
index ab1c28c..ab1c28c 100644
--- a/machines/xnet/README
+++ b/modules/xnet/README
diff --git a/machines/xnet/default.nix b/modules/xnet/default.nix
index 9d224cf..9d224cf 100644
--- a/machines/xnet/default.nix
+++ b/modules/xnet/default.nix
diff --git a/machines/xnet/desktop/default.nix b/modules/xnet/desktop/default.nix
index 995381f..995381f 100644
--- a/machines/xnet/desktop/default.nix
+++ b/modules/xnet/desktop/default.nix
diff --git a/machines/xnet/disk.nix b/modules/xnet/disk.nix
index 26b6909..82e9c87 100644
--- a/machines/xnet/disk.nix
+++ b/modules/xnet/disk.nix
@@ -1,4 +1,4 @@
-{ config, lib, modulesPath, ... }:
+{ config, lib, modulesPath, inputs, ... }:
let
cfg = config.xnet.disk;
commonOpts = {
@@ -16,6 +16,7 @@ in
{
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
+ inputs.disko.nixosModules.default
];
options.xnet.disk = {
diff --git a/machines/xnet/gitserver/default.nix b/modules/xnet/gitserver/default.nix
index 2152ebd..2152ebd 100644
--- a/machines/xnet/gitserver/default.nix
+++ b/modules/xnet/gitserver/default.nix
diff --git a/machines/xnet/gitserver/gitweb.nix b/modules/xnet/gitserver/gitweb.nix
index da9a5ee..da9a5ee 100644
--- a/machines/xnet/gitserver/gitweb.nix
+++ b/modules/xnet/gitserver/gitweb.nix
diff --git a/machines/xnet/monitoring/22604_rev2.json b/modules/xnet/monitoring/22604_rev2.json
index 0adeb22..0adeb22 100644
--- a/machines/xnet/monitoring/22604_rev2.json
+++ b/modules/xnet/monitoring/22604_rev2.json
diff --git a/machines/xnet/monitoring/default.nix b/modules/xnet/monitoring/default.nix
index eed4963..eed4963 100644
--- a/machines/xnet/monitoring/default.nix
+++ b/modules/xnet/monitoring/default.nix
diff --git a/machines/xnet/monitoring/grafana.nix b/modules/xnet/monitoring/grafana.nix
index e95318d..e95318d 100644
--- a/machines/xnet/monitoring/grafana.nix
+++ b/modules/xnet/monitoring/grafana.nix
diff --git a/machines/xnet/net/default.nix b/modules/xnet/net/default.nix
index 7242855..7242855 100644
--- a/machines/xnet/net/default.nix
+++ b/modules/xnet/net/default.nix
diff --git a/modules/xnet/net/dns.nix b/modules/xnet/net/dns.nix
new file mode 100644
index 0000000..0632fa9
--- /dev/null
+++ b/modules/xnet/net/dns.nix
@@ -0,0 +1,38 @@
+{ lib, ... }:
+let
+ inherit (lib)
+ mkDefault
+ ;
+
+ quad9 = [
+ "9.9.9.9#dns.quad9.net"
+ "149.112.112.112#dns.quad9.net"
+ "2620:fe::fe#dns.quad9.net"
+ "2620:fe::9#dns.quad9.net"
+ ];
+
+ cloudflare = [
+ "1.1.1.1#one.one.one.one"
+ "1.0.0.1#one.one.one.one"
+ "2606:4700:4700::1111#one.one.one.one"
+ "2606:4700:4700::1001#one.one.one.one"
+ ];
+in
+{
+
+ networking.nameservers = mkDefault quad9;
+
+ services.resolved = {
+ enable = true;
+ llmnr = "false";
+ dnssec = "false";
+ dnsovertls = mkDefault "opportunistic";
+ fallbackDns = quad9 ++ cloudflare;
+ extraConfig = ''
+ MulticastDNS=yes
+ '';
+ };
+
+ # Allow mDNS resolution
+ networking.firewall.allowedTCPPorts = [ 5353 ];
+}
diff --git a/machines/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix
index 9d7976e..9d7976e 100644
--- a/machines/xnet/net/sshd.nix
+++ b/modules/xnet/net/sshd.nix
diff --git a/machines/xnet/nginx.nix b/modules/xnet/nginx.nix
index eadd794..eadd794 100644
--- a/machines/xnet/nginx.nix
+++ b/modules/xnet/nginx.nix
diff --git a/machines/xnet/persist.nix b/modules/xnet/persist.nix
index 10eb883..10eb883 100644
--- a/machines/xnet/persist.nix
+++ b/modules/xnet/persist.nix
diff --git a/mod/web/blog/.gitignore b/packages/blog/.gitignore
index decc3f8..decc3f8 100644
--- a/mod/web/blog/.gitignore
+++ b/packages/blog/.gitignore
diff --git a/mod/web/blog/config.toml b/packages/blog/config.toml
index 69c389b..69c389b 100644
--- a/mod/web/blog/config.toml
+++ b/packages/blog/config.toml
diff --git a/mod/web/blog/content/posts/_index.md b/packages/blog/content/posts/_index.md
index 9efc62e..9efc62e 100644
--- a/mod/web/blog/content/posts/_index.md
+++ b/packages/blog/content/posts/_index.md
diff --git a/mod/web/blog/content/posts/deterministic-hostnames.md b/packages/blog/content/posts/deterministic-hostnames.md
index 43dc7d8..43dc7d8 100644
--- a/mod/web/blog/content/posts/deterministic-hostnames.md
+++ b/packages/blog/content/posts/deterministic-hostnames.md
diff --git a/mod/web/blog/content/posts/nohup.md b/packages/blog/content/posts/nohup.md
index 64f7983..64f7983 100644
--- a/mod/web/blog/content/posts/nohup.md
+++ b/packages/blog/content/posts/nohup.md
diff --git a/mod/web/blog/content/posts/stateless-compute-networks.md b/packages/blog/content/posts/stateless-compute-networks.md
index bac9e5d..bac9e5d 100644
--- a/mod/web/blog/content/posts/stateless-compute-networks.md
+++ b/packages/blog/content/posts/stateless-compute-networks.md
diff --git a/mod/web/blog/content/posts/vim-compilers.md b/packages/blog/content/posts/vim-compilers.md
index f735228..f735228 100644
--- a/mod/web/blog/content/posts/vim-compilers.md
+++ b/packages/blog/content/posts/vim-compilers.md
diff --git a/packages/blog/default.nix b/packages/blog/default.nix
new file mode 100644
index 0000000..204388f
--- /dev/null
+++ b/packages/blog/default.nix
@@ -0,0 +1,21 @@
+{ pkgs, perSystem, ... }:
+let
+ inherit (perSystem.self)
+ cv
+ ;
+in
+pkgs.stdenvNoCC.mkDerivation {
+ name = "4kb.net";
+ src = ./.;
+
+ nativeBuildInputs = with pkgs; [
+ zola
+ ];
+
+ buildPhase = "zola build";
+ installPhase = ''
+ mkdir -p $out/share
+ cp -r public/* $out/
+ cp ${cv} $out/share/cv.pdf
+ '';
+}
diff --git a/mod/web/blog/templates/404.html b/packages/blog/templates/404.html
index a4669df..a4669df 100644
--- a/mod/web/blog/templates/404.html
+++ b/packages/blog/templates/404.html
diff --git a/mod/web/blog/templates/base.html b/packages/blog/templates/base.html
index 5a91df5..5a91df5 100644
--- a/mod/web/blog/templates/base.html
+++ b/packages/blog/templates/base.html
diff --git a/mod/web/blog/templates/index.html b/packages/blog/templates/index.html
index 6e8a2af..6e8a2af 100644
--- a/mod/web/blog/templates/index.html
+++ b/packages/blog/templates/index.html
diff --git a/mod/web/blog/templates/post.html b/packages/blog/templates/post.html
index b819520..b819520 100644
--- a/mod/web/blog/templates/post.html
+++ b/packages/blog/templates/post.html
diff --git a/mod/code/cses/default.nix b/packages/cses/default.nix
index 6538eb8..6538eb8 100644
--- a/mod/code/cses/default.nix
+++ b/packages/cses/default.nix
diff --git a/mod/code/cses/problems/1068.cpp b/packages/cses/problems/1068.cpp
index 8d05936..8d05936 100644
--- a/mod/code/cses/problems/1068.cpp
+++ b/packages/cses/problems/1068.cpp
diff --git a/mod/code/cses/problems/1069.cpp b/packages/cses/problems/1069.cpp
index 232d2f7..232d2f7 100644
--- a/mod/code/cses/problems/1069.cpp
+++ b/packages/cses/problems/1069.cpp
diff --git a/mod/code/cses/problems/1070.cpp b/packages/cses/problems/1070.cpp
index 131a644..131a644 100644
--- a/mod/code/cses/problems/1070.cpp
+++ b/packages/cses/problems/1070.cpp
diff --git a/mod/code/cses/problems/1071.cpp b/packages/cses/problems/1071.cpp
index 778cc86..778cc86 100644
--- a/mod/code/cses/problems/1071.cpp
+++ b/packages/cses/problems/1071.cpp
diff --git a/mod/code/cses/problems/1083.cpp b/packages/cses/problems/1083.cpp
index a3cd253..a3cd253 100644
--- a/mod/code/cses/problems/1083.cpp
+++ b/packages/cses/problems/1083.cpp
diff --git a/mod/code/cses/problems/1094.cpp b/packages/cses/problems/1094.cpp
index 56f3886..56f3886 100644
--- a/mod/code/cses/problems/1094.cpp
+++ b/packages/cses/problems/1094.cpp
diff --git a/mod/misc/cv/cv.typ b/packages/cv/cv.typ
index 7d43763..7d43763 100644
--- a/mod/misc/cv/cv.typ
+++ b/packages/cv/cv.typ
diff --git a/packages/cv/default.nix b/packages/cv/default.nix
new file mode 100644
index 0000000..9de6903
--- /dev/null
+++ b/packages/cv/default.nix
@@ -0,0 +1,5 @@
+{ pkgs, ... }:
+
+pkgs.runCommand "cv" { } ''
+ ${pkgs.typst}/bin/typst compile --format pdf ${./cv.typ} $out
+''
diff --git a/mod/tools/perf-flamegraph.nix b/packages/perf-flamegraph.nix
index b472b74..b472b74 100644
--- a/mod/tools/perf-flamegraph.nix
+++ b/packages/perf-flamegraph.nix
diff --git a/packages/resistors/default.nix b/packages/resistors/default.nix
new file mode 100644
index 0000000..6a038ea
--- /dev/null
+++ b/packages/resistors/default.nix
@@ -0,0 +1,7 @@
+{ pkgs, ... }:
+
+pkgs.runCommandNoCC "resisto-rs" { } ''
+ mkdir -p $out
+ cp ${./index.html} $out/index.html
+ cp ${./styles.css} $out/styles.css
+''
diff --git a/mod/web/resistors/index.html b/packages/resistors/index.html
index 0683f49..0683f49 100644
--- a/mod/web/resistors/index.html
+++ b/packages/resistors/index.html
diff --git a/mod/web/resistors/styles.css b/packages/resistors/styles.css
index e2823e4..e2823e4 100644
--- a/mod/web/resistors/styles.css
+++ b/packages/resistors/styles.css