diff options
| -rw-r--r-- | flake.lock | 68 | ||||
| -rw-r--r-- | flake.nix | 92 | ||||
| -rw-r--r-- | lib/depot-tools.nix | 84 | ||||
| -rw-r--r-- | machines/radon/pxeboot.nix | 1 | ||||
| -rw-r--r-- | machines/t1/default.nix | 6 | ||||
| -rw-r--r-- | machines/t480/default.nix | 38 | ||||
| -rw-r--r-- | mod/code/cses/.envrc | 1 | ||||
| -rw-r--r-- | mod/misc/cv/default.nix | 6 | ||||
| -rw-r--r-- | mod/nix/readTree/default.nix | 326 | ||||
| -rw-r--r-- | mod/tools/typst/default.nix | 34 | ||||
| -rw-r--r-- | mod/tools/typst/main.typ | 1 | ||||
| -rw-r--r-- | mod/tools/typst/packages/tmu/template.typ | 37 | ||||
| -rw-r--r-- | mod/tools/typst/packages/tmu/typst.toml | 7 | ||||
| -rw-r--r-- | mod/web/blog/default.nix | 30 | ||||
| -rw-r--r-- | mod/web/resistors/default.nix | 12 | ||||
| -rw-r--r-- | modules/dns.nix (renamed from machines/xnet/net/dns.nix) | 0 | ||||
| -rw-r--r-- | modules/users.nix (renamed from mod/users/kle/default.nix) | 20 | ||||
| -rw-r--r-- | modules/xnet/README (renamed from machines/xnet/README) | 0 | ||||
| -rw-r--r-- | modules/xnet/default.nix (renamed from machines/xnet/default.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/desktop/default.nix (renamed from machines/xnet/desktop/default.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/disk.nix (renamed from machines/xnet/disk.nix) | 3 | ||||
| -rw-r--r-- | modules/xnet/gitserver/default.nix (renamed from machines/xnet/gitserver/default.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/gitserver/gitweb.nix (renamed from machines/xnet/gitserver/gitweb.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/monitoring/22604_rev2.json (renamed from machines/xnet/monitoring/22604_rev2.json) | 0 | ||||
| -rw-r--r-- | modules/xnet/monitoring/default.nix (renamed from machines/xnet/monitoring/default.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/monitoring/grafana.nix (renamed from machines/xnet/monitoring/grafana.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/net/default.nix (renamed from machines/xnet/net/default.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/net/dns.nix | 38 | ||||
| -rw-r--r-- | modules/xnet/net/sshd.nix (renamed from machines/xnet/net/sshd.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/nginx.nix (renamed from machines/xnet/nginx.nix) | 0 | ||||
| -rw-r--r-- | modules/xnet/persist.nix (renamed from machines/xnet/persist.nix) | 0 | ||||
| -rw-r--r-- | packages/blog/.gitignore (renamed from mod/web/blog/.gitignore) | 0 | ||||
| -rw-r--r-- | packages/blog/config.toml (renamed from mod/web/blog/config.toml) | 0 | ||||
| -rw-r--r-- | packages/blog/content/posts/_index.md (renamed from mod/web/blog/content/posts/_index.md) | 0 | ||||
| -rw-r--r-- | packages/blog/content/posts/deterministic-hostnames.md (renamed from mod/web/blog/content/posts/deterministic-hostnames.md) | 0 | ||||
| -rw-r--r-- | packages/blog/content/posts/nohup.md (renamed from mod/web/blog/content/posts/nohup.md) | 0 | ||||
| -rw-r--r-- | packages/blog/content/posts/stateless-compute-networks.md (renamed from mod/web/blog/content/posts/stateless-compute-networks.md) | 0 | ||||
| -rw-r--r-- | packages/blog/content/posts/vim-compilers.md (renamed from mod/web/blog/content/posts/vim-compilers.md) | 0 | ||||
| -rw-r--r-- | packages/blog/default.nix | 21 | ||||
| -rw-r--r-- | packages/blog/templates/404.html (renamed from mod/web/blog/templates/404.html) | 0 | ||||
| -rw-r--r-- | packages/blog/templates/base.html (renamed from mod/web/blog/templates/base.html) | 0 | ||||
| -rw-r--r-- | packages/blog/templates/index.html (renamed from mod/web/blog/templates/index.html) | 0 | ||||
| -rw-r--r-- | packages/blog/templates/post.html (renamed from mod/web/blog/templates/post.html) | 0 | ||||
| -rw-r--r-- | packages/cses/default.nix (renamed from mod/code/cses/default.nix) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1068.cpp (renamed from mod/code/cses/problems/1068.cpp) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1069.cpp (renamed from mod/code/cses/problems/1069.cpp) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1070.cpp (renamed from mod/code/cses/problems/1070.cpp) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1071.cpp (renamed from mod/code/cses/problems/1071.cpp) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1083.cpp (renamed from mod/code/cses/problems/1083.cpp) | 0 | ||||
| -rw-r--r-- | packages/cses/problems/1094.cpp (renamed from mod/code/cses/problems/1094.cpp) | 0 | ||||
| -rw-r--r-- | packages/cv/cv.typ (renamed from mod/misc/cv/cv.typ) | 0 | ||||
| -rw-r--r-- | packages/cv/default.nix | 5 | ||||
| -rw-r--r-- | packages/perf-flamegraph.nix (renamed from mod/tools/perf-flamegraph.nix) | 0 | ||||
| -rw-r--r-- | packages/resistors/default.nix | 7 | ||||
| -rw-r--r-- | packages/resistors/index.html (renamed from mod/web/resistors/index.html) | 0 | ||||
| -rw-r--r-- | packages/resistors/styles.css (renamed from mod/web/resistors/styles.css) | 0 |
56 files changed, 215 insertions, 622 deletions
@@ -1,28 +1,5 @@ { "nodes": { - "agenix": { - "inputs": { - "darwin": [], - "home-manager": "home-manager", - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1703089996, - "narHash": "sha256-ipqShkBmHKC9ft1ZAsA6aeKps32k7+XZSPwfxeHLsAU=", - "owner": "ryantm", - "repo": "agenix", - "rev": "564595d0ad4be7277e07fa63b5a991b3c645655d", - "type": "github" - }, - "original": { - "owner": "ryantm", - "ref": "0.15.0", - "repo": "agenix", - "type": "github" - } - }, "disko": { "inputs": { "nixpkgs": [ @@ -44,27 +21,6 @@ "type": "github" } }, - "home-manager": { - "inputs": { - "nixpkgs": [ - "agenix", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1682203081, - "narHash": "sha256-kRL4ejWDhi0zph/FpebFYhzqlOBrk0Pl3dzGEKSAlEw=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "32d3e39c491e2f91152c84f8ad8b003420eab0a1", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "home-manager", - "type": "github" - } - }, "naersk": { "inputs": { "nixpkgs": [ @@ -119,32 +75,10 @@ }, "root": { "inputs": { - "agenix": "agenix", "disko": "disko", "naersk": "naersk", "nixos-hardware": "nixos-hardware", - "nixpkgs": "nixpkgs", - "sops-nix": "sops-nix" - } - }, - "sops-nix": { - "inputs": { - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1732186149, - "narHash": "sha256-N9JGWe/T8BC0Tss2Cv30plvZUYoiRmykP7ZdY2on2b0=", - "owner": "Mic92", - "repo": "sops-nix", - "rev": "53c853fb1a7e4f25f68805ee25c83d5de18dc699", - "type": "github" - }, - "original": { - "owner": "Mic92", - "repo": "sops-nix", - "type": "github" + "nixpkgs": "nixpkgs" } } }, @@ -1,19 +1,11 @@ { description = "Personal monorepo"; - inputs = { nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; disko.url = "github:nix-community/disko/v1.6.1"; disko.inputs.nixpkgs.follows = "nixpkgs"; - sops-nix.url = "github:Mic92/sops-nix"; - sops-nix.inputs.nixpkgs.follows = "nixpkgs"; - - agenix.url = "github:ryantm/agenix/0.15.0"; - agenix.inputs.nixpkgs.follows = "nixpkgs"; - agenix.inputs.darwin.follows = ""; - nixos-hardware.url = "github:nixos/nixos-hardware/master"; # Rust projects @@ -25,70 +17,71 @@ let inherit (builtins) attrNames - filter listToAttrs map readDir ; + inherit (nixpkgs) lib; + inherit (nixpkgs.lib) + mapAttrs nixosSystem ; - readTree = import ./mod/nix/readTree { }; + systems = [ "x86_64-linux" "aarch64-linux" ]; - # Recursively converts subdirectories under ./mod into an attrset - # that can be passed to other parts of the depot. - readDepot = depotArgs: readTree { - args = depotArgs; - path = ./mod; - }; + inherit (import ./lib/depot-tools.nix { inherit inputs systems lib; }) + importDir + eachSystem + systemArgs + ; - # Named arguments to be made available to any nix expression in - # the depot module. - depot = readTree.fix (self: readDepot { - depot = self; + packages = eachSystem ( + { newScope, ... }: + mapAttrs (pname: { path, ... }: newScope { inherit pname; } path { }) + (importDir ./packages) + ); + publisherArgs = { + flake = self; inherit inputs; + }; - # x86_64-linux is hardcoded as the package arch only for the - # mod directory. This workaround keeps the flake pure, - # at the expense of only supporting one system. This can - # be circumvented by retrieving the system during evaluation, - # but flakes disallow this by design. - # - # This monorepo currently depends on functionality from flakes, - # but this may change in the future, perhaps shifting to an - # impure base with certain packages exposed from the flake in a - # pure way. - # - # In practice, this means that any configuration or package - # exposed from the depot flake that makes use of internal - # derivations is limited to x86_64-linux. For now this is fine, - # but ideally any architecture supported by nix should be - # allowed to evaluate projects hosted here. - pkgs = nixpkgs.legacyPackages."x86_64-linux"; + expectsPublisherArgs = + module: + builtins.isFunction module + && builtins.all (arg: builtins.elem arg (builtins.attrNames publisherArgs)) ( + builtins.attrNames (builtins.functionArgs module) + ); - # Expose lib attribute to modules. - lib = nixpkgs.lib; - }); + injectPublisherArgs = + modulePath: + let + module = import modulePath; + in + if expectsPublisherArgs module then + lib.setDefaultModuleLocation modulePath (module publisherArgs) + else + modulePath; - machines = filter (m: m != "xnet") - (attrNames (readDir ./machines)); + nixosModules = mapAttrs (_: moduleDir: injectPublisherArgs moduleDir) + (mapAttrs (_: { path, ... }: path) (importDir ./modules)); in { - inherit depot; - - nixosModules.xnet.imports = - [ ./machines/xnet inputs.disko.nixosModules.disko ]; + inherit packages nixosModules; nixosConfigurations = listToAttrs ( map (name: { inherit name; - value = nixosSystem { + value = nixosSystem rec { system = "x86_64-linux"; - specialArgs = { inherit inputs depot; }; + specialArgs = { + inherit inputs; + inherit (self) outputs; + inherit (systemArgs.${system}) flake perSystem; + }; modules = [ # Machine's specific configuration ./machines/${name} @@ -108,6 +101,7 @@ ]; }; }) - machines); + (attrNames (readDir ./machines)) + ); }; } diff --git a/lib/depot-tools.nix b/lib/depot-tools.nix new file mode 100644 index 0000000..448055a --- /dev/null +++ b/lib/depot-tools.nix @@ -0,0 +1,84 @@ +{ inputs +, systems +, nixpkgs ? inputs.nixpkgs +, ... +}: + +let + inherit (builtins) + match + head + readDir + ; + + inherit (nixpkgs.lib) + callPackageWith + filterAttrs + genAttrs + makeScope + mapAttrs + mapAttrs' + ; + + importDir = + path: + let + entries = readDir path; + + # Get paths to directories + onlyDirs = filterAttrs (_name: type: type == "directory") entries; + dirPaths = mapAttrs + (name: type: { + path = path + "/${name}"; + inherit type; + }) + onlyDirs; + + # Get paths to nix files, where the name is the basename of the file without the .nix extension + nixPaths = removeAttrs + (mapAttrs' + ( + name: type: + let + nixName = match "(.*)\\.nix" name; + in + { + name = if type == "directory" || nixName == null then "__junk" else (head nixName); + value = { + path = path + "/${name}"; + type = type; + }; + } + ) + entries) [ "__junk" ]; + in + dirPaths // nixPaths; + + # Memoize the args per system + systemArgs = genAttrs systems ( + system: + let + # Resolve the packages for each input. + perSystem = mapAttrs + (_: flake: flake.legacyPackages.${system} or { } // flake.packages.${system} or { }) + inputs; + + # Handle nixpkgs specially. + pkgs = + if (nixpkgs.config or { }) == { } && (nixpkgs.overlays or [ ]) == [ ] then + perSystem.nixpkgs + else + import inputs.nixpkgs { + inherit system; + config = nixpkgs.config or { }; + overlays = nixpkgs.overlays or [ ]; + }; + + flake = inputs.self; + in + makeScope callPackageWith (_: { inherit inputs perSystem flake pkgs system; }) + ); + + eachSystem = f: genAttrs systems (system: f systemArgs.${system}); +in +{ inherit importDir systemArgs eachSystem; } diff --git a/machines/radon/pxeboot.nix b/machines/radon/pxeboot.nix index 4d897c3..4655990 100644 --- a/machines/radon/pxeboot.nix +++ b/machines/radon/pxeboot.nix @@ -24,6 +24,7 @@ let users.users.root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP7T2uWJFUu8aFZZgQusGKyEMocb2pKbHLDad2eIJus9" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEOw8YEbHsKy38JHp9W1wcxxZgWCDgnabOXccZUN5ddd" ]; }) ]; diff --git a/machines/t1/default.nix b/machines/t1/default.nix index f565fc6..7f375a1 100644 --- a/machines/t1/default.nix +++ b/machines/t1/default.nix @@ -1,4 +1,4 @@ -{ inputs, depot, pkgs, ... }: +{ inputs, flake, pkgs, perSystem, ... }: let inherit (inputs.nixos-hardware.nixosModules) @@ -6,7 +6,7 @@ let common-gpu-amd ; - inherit (depot.users) kle; + inherit (import flake.outputs.nixosModules.users { inherit perSystem pkgs; }) kle; in { imports = [ @@ -16,7 +16,7 @@ in system.stateVersion = "24.11"; - users.users.kle = kle.nixos; + users.users.kle = kle; xnet = { desktop.enable = true; diff --git a/machines/t480/default.nix b/machines/t480/default.nix index e726670..24b6bc6 100644 --- a/machines/t480/default.nix +++ b/machines/t480/default.nix @@ -1,12 +1,10 @@ -{ inputs, depot, ... }: +{ inputs, flake, perSystem, pkgs, ... }: let inherit (inputs.nixos-hardware.nixosModules) lenovo-thinkpad-t480 ; - inherit (depot.users) - kle - ; + inherit (import flake.outputs.nixosModules.users { inherit perSystem pkgs; }) kle; in { imports = [ @@ -23,16 +21,15 @@ in }; }; - users.users.kle = kle.nixos; + users.users.kle = kle; networking = { hostName = "t480"; useDHCP = false; dhcpcd.enable = false; - nameservers = [ "127.0.0.1" ]; networkmanager = { enable = true; - dns = "none"; + # dns = "none"; wifi.powersave = true; }; }; @@ -40,32 +37,5 @@ in programs.nm-applet.enable = true; services.fwupd.enable = true; - services.unbound = { - enable = true; - settings.server = { - interface = [ "127.0.0.1" ]; - port = 53; - access-control = [ "127.0.0.1 allow" ]; - harden-glue = true; - harden-dnssec-stripped = true; - use-caps-for-id = false; - prefetch = true; - edns-buffer-size = 1232; - hide-identity = true; - hide-version = true; - }; - - settings.forward-zone = [ - { - name = "."; - forward-tls-upstream = true; - forward-addr = [ - "9.9.9.9#dns.quad9.net" - "149.112.112.112#dns.quad9.net" - ]; - } - ]; - }; - xnet.persist = [ "/etc/NetworkManager/system-connections" ]; } diff --git a/mod/code/cses/.envrc b/mod/code/cses/.envrc deleted file mode 100644 index 1d953f4..0000000 --- a/mod/code/cses/.envrc +++ /dev/null @@ -1 +0,0 @@ -use nix diff --git a/mod/misc/cv/default.nix b/mod/misc/cv/default.nix deleted file mode 100644 index b663475..0000000 --- a/mod/misc/cv/default.nix +++ /dev/null @@ -1,6 +0,0 @@ -{ pkgs, ... }: - -pkgs.runCommand "cv" { } '' - mkdir -p $out/share - ${pkgs.typst}/bin/typst compile ${./cv.typ} $out/share/cv.pdf -'' diff --git a/mod/nix/readTree/default.nix b/mod/nix/readTree/default.nix deleted file mode 100644 index 4a745ce..0000000 --- a/mod/nix/readTree/default.nix +++ /dev/null @@ -1,326 +0,0 @@ -# Copyright (c) 2019 Vincent Ambo -# Copyright (c) 2020-2021 The TVL Authors -# SPDX-License-Identifier: MIT -# -# Provides a function to automatically read a filesystem structure -# into a Nix attribute set. -# -# Called with an attribute set taking the following arguments: -# -# path: Path to a directory from which to start reading the tree. -# -# args: Argument set to pass to each imported file. -# -# filter: Function to filter `args` based on the tree location. This should -# be a function of the form `args -> location -> args`, where the -# location is a list of strings representing the path components of -# the current readTree target. Optional. -{ ... }: - -let - inherit (builtins) - attrNames - concatMap - concatStringsSep - elem - elemAt - filter - hasAttr - head - isAttrs - listToAttrs - map - match - readDir - substring; - - argsWithPath = args: parts: - let meta.locatedAt = parts; - in meta // (if isAttrs args then args else args meta); - - readDirVisible = path: - let - children = readDir path; - # skip hidden files, except for those that contain special instructions to readTree - isVisible = f: f == ".skip-subtree" || f == ".skip-tree" || (substring 0 1 f) != "."; - names = filter isVisible (attrNames children); - in - listToAttrs (map - (name: { - inherit name; - value = children.${name}; - }) - names); - - # Create a mark containing the location of this attribute and - # a list of all child attribute names added by readTree. - marker = parts: children: { - __readTree = parts; - __readTreeChildren = builtins.attrNames children; - }; - - # Create a label from a target's tree location. - mkLabel = target: - let label = concatStringsSep "/" target.__readTree; - in if target ? __subtarget - then "${label}:${target.__subtarget}" - else label; - - # Merge two attribute sets, but place attributes in `passthru` via - # `overrideAttrs` for derivation targets that support it. - merge = a: b: - if a ? overrideAttrs - then - a.overrideAttrs - (prev: { - passthru = (prev.passthru or { }) // b; - }) - else a // b; - - # Import a file and enforce our calling convention - importFile = args: scopedArgs: path: parts: filter: - let - importedFile = - if scopedArgs != { } && builtins ? scopedImport # For tvix - then builtins.scopedImport scopedArgs path - else import path; - pathType = builtins.typeOf importedFile; - in - if pathType != "lambda" - then throw "readTree: trying to import ${toString path}, but it’s a ${pathType}, you need to make it a function like { depot, pkgs, ... }" - else importedFile (filter parts (argsWithPath args parts)); - - nixFileName = file: - let res = match "(.*)\\.nix" file; - in if res == null then null else head res; - - # Internal implementation of readTree, which handles things like the - # skipping of trees and subtrees. - # - # This method returns an attribute sets with either of two shapes: - # - # { ok = ...; } # a tree was read successfully - # { skip = true; } # a tree was skipped - # - # The higher-level `readTree` method assembles the final attribute - # set out of these results at the top-level, and the internal - # `children` implementation unwraps and processes nested trees. - readTreeImpl = { args, initPath, rootDir, parts, argsFilter, scopedArgs }: - let - dir = readDirVisible initPath; - - # Determine whether any part of this tree should be skipped. - # - # Adding a `.skip-subtree` file will still allow the import of - # the current node's "default.nix" file, but stop recursion - # there. - # - # Adding a `.skip-tree` file will completely ignore the folder - # in which this file is located. - skipTree = hasAttr ".skip-tree" dir; - skipSubtree = skipTree || hasAttr ".skip-subtree" dir; - - joinChild = c: initPath + ("/" + c); - - self = - if rootDir - then { __readTree = [ ]; } - else importFile args scopedArgs initPath parts argsFilter; - - # Import subdirectories of the current one, unless any skip - # instructions exist. - # - # This file can optionally contain information on why the tree - # should be ignored, but its content is not inspected by - # readTree - filterDir = f: dir."${f}" == "directory"; - filteredChildren = map - (c: { - name = c; - value = readTreeImpl { - inherit argsFilter scopedArgs; - args = args; - initPath = (joinChild c); - rootDir = false; - parts = (parts ++ [ c ]); - }; - }) - (filter filterDir (attrNames dir)); - - # Remove skipped children from the final set, and unwrap the - # result set. - children = - if skipSubtree then [ ] - else map ({ name, value }: { inherit name; value = value.ok; }) (filter (child: child.value ? ok) filteredChildren); - - # Import Nix files - nixFiles = - if skipSubtree then [ ] - else filter (f: f != null) (map nixFileName (attrNames dir)); - nixChildren = map - (c: - let - p = joinChild (c + ".nix"); - childParts = parts ++ [ c ]; - imported = importFile args scopedArgs p childParts argsFilter; - in - { - name = c; - value = - if isAttrs imported - then merge imported (marker childParts { }) - else imported; - }) - nixFiles; - - nodeValue = if dir ? "default.nix" then self else { }; - - allChildren = listToAttrs ( - if dir ? "default.nix" - then children - else nixChildren ++ children - ); - - in - if skipTree - then { skip = true; } - else { - ok = - if isAttrs nodeValue - then merge nodeValue (allChildren // (marker parts allChildren)) - else nodeValue; - }; - - # Top-level implementation of readTree itself. - readTree = args: - let - tree = readTreeImpl args; - in - if tree ? skip - then throw "Top-level folder has a .skip-tree marker and could not be read by readTree!" - else tree.ok; - - # Helper function to fetch subtargets from a target. This is a - # temporary helper to warn on the use of the `meta.targets` - # attribute, which is deprecated in favour of `meta.ci.targets`. - subtargets = node: - let targets = (node.meta.targets or [ ]) ++ (node.meta.ci.targets or [ ]); - in if node ? meta.targets then - builtins.trace '' - [1;31mWarning: The meta.targets attribute is deprecated. - - Please move the subtargets of //${mkLabel node} to the - meta.ci.targets attribute. - [0m - '' - targets else targets; - - # Function which can be used to find all readTree targets within an - # attribute set. - # - # This function will gather physical targets, that is targets which - # correspond directly to a location in the repository, as well as - # subtargets (specified in the meta.ci.targets attribute of a node). - # - # This can be used to discover targets for inclusion in CI - # pipelines. - # - # Called with the arguments: - # - # eligible: Function to determine whether the given derivation - # should be included in the build. - gather = eligible: node: - if node ? __readTree then - # Include the node itself if it is eligible. - (if eligible node then [ node ] else [ ]) - # Include eligible children of the node - ++ concatMap (gather eligible) (map (attr: node."${attr}") node.__readTreeChildren) - # Include specified sub-targets of the node - ++ filter eligible (map - (k: (node."${k}" or { }) // { - # Keep the same tree location, but explicitly mark this - # node as a subtarget. - __readTree = node.__readTree; - __readTreeChildren = [ ]; - __subtarget = k; - }) - (subtargets node)) - else [ ]; - - # Determine whether a given value is a derivation. - # Copied from nixpkgs/lib for cases where lib is not available yet. - isDerivation = x: isAttrs x && x ? type && x.type == "derivation"; -in -{ - inherit gather mkLabel; - - __functor = _: - { path - , args - , filter ? (_parts: x: x) - , scopedArgs ? { } - }: - readTree { - inherit args scopedArgs; - argsFilter = filter; - initPath = path; - rootDir = true; - parts = [ ]; - }; - - # In addition to readTree itself, some functionality is exposed that - # is useful for users of readTree. - - # Create a readTree filter disallowing access to the specified - # top-level folder in the repository, except for specific exceptions - # specified by their (full) paths. - # - # Called with the arguments: - # - # folder: Name of the restricted top-level folder (e.g. 'experimental') - # - # exceptions: List of readTree parts (e.g. [ [ "services" "some-app" ] ]), - # which should be able to access the restricted folder. - # - # reason: Textual explanation for the restriction (included in errors) - restrictFolder = { folder, exceptions ? [ ], reason }: parts: args: - if (elemAt parts 0) == folder || elem parts exceptions - then args - else args // { - depot = args.depot // { - "${folder}" = throw '' - Access to targets under //${folder} is not permitted from - other repository paths. Specific exceptions are configured - at the top-level. - - ${reason} - At location: ${builtins.concatStringsSep "." parts} - ''; - }; - }; - - # This definition of fix is identical to <nixpkgs>.lib.fix, but is - # provided here for cases where readTree is used before nixpkgs can - # be imported. - # - # It is often required to create the args attribute set. - fix = f: let x = f x; in x; - - # Takes an attribute set and adds a meta.ci.targets attribute to it - # which contains all direct children of the attribute set which are - # derivations. - # - # Type: attrs -> attrs - drvTargets = attrs: - attrs // { - # preserve .meta from original attrs - meta = (attrs.meta or { }) // { - # preserve .meta.ci (except .targets) from original attrs - ci = (attrs.meta.ci or { }) // { - targets = builtins.filter - (x: isDerivation attrs."${x}") - (builtins.attrNames attrs); - }; - }; - }; -} diff --git a/mod/tools/typst/default.nix b/mod/tools/typst/default.nix deleted file mode 100644 index 1871cc6..0000000 --- a/mod/tools/typst/default.nix +++ /dev/null @@ -1,34 +0,0 @@ -{ pkgs, ... }: -let - version = "0.0.0"; - - depotPackages = pkgs.stdenvNoCC.mkDerivation { - pname = "depot-typst-packages"; - inherit version; - src = ./packages; - phases = [ "installPhase" ]; - - installPhase = '' - for pkg in $src/*; do - name=$(basename $pkg) - mkdir -p $out/share/typst/packages/depot/$name/${version} - cp -rv $pkg/* $out/share/typst/packages/depot/$name/${version}/ - done - ''; - }; -in -{ - inherit depotPackages; - - writeEnv = pkgs.mkShellNoCC { - packages = [ - pkgs.typst - pkgs.typstyle - pkgs.tinymist - depotPackages - ]; - - shellHook = "export TYPST_PACKAGE_PATH=${depotPackages}/share/typst"; - # shellHook = "alias typst='XDG_DATA_HOME=${depotPackages}/share typst'"; - }; -} diff --git a/mod/tools/typst/main.typ b/mod/tools/typst/main.typ deleted file mode 100644 index c6be2b4..0000000 --- a/mod/tools/typst/main.typ +++ /dev/null @@ -1 +0,0 @@ -#import "@depot/tmu:0.0.0": * diff --git a/mod/tools/typst/packages/tmu/template.typ b/mod/tools/typst/packages/tmu/template.typ deleted file mode 100644 index 721e7b6..0000000 --- a/mod/tools/typst/packages/tmu/template.typ +++ /dev/null @@ -1,37 +0,0 @@ -#let report( - title: [], - course: [], - semester: [], - authors: (), - doc, -) = { - set page( - paper: "us-letter", - margin: 1.5in, - numbering: "1", - header: align(horizon, strong(course + h(1fr) + semester)), - ) - - set align(center) - text(18pt, strong(title)) - linebreak() - text(12pt, "Toronto Metropolitan University") - - v(24pt) - - grid( - columns: (1fr,) * calc.min(authors.len(), 4), - row-gutter: 12pt, - ..authors.map(a => [ - #a.name \ - #a.id \ - #link("mailto:" + a.email) - ]) - ) - - set align(left) - set par(justify: true) - v(24pt) - - doc -} diff --git a/mod/tools/typst/packages/tmu/typst.toml b/mod/tools/typst/packages/tmu/typst.toml deleted file mode 100644 index caf96d7..0000000 --- a/mod/tools/typst/packages/tmu/typst.toml +++ /dev/null @@ -1,7 +0,0 @@ -[package] -name = "tmu" -version = "0.0.0" -entrypoint = "template.typ" -authors = ["Kleidi Bujari"] -license = "MIT" -description = "TMU engineering report template" diff --git a/mod/web/blog/default.nix b/mod/web/blog/default.nix deleted file mode 100644 index 1f91a68..0000000 --- a/mod/web/blog/default.nix +++ /dev/null @@ -1,30 +0,0 @@ -{ pkgs, depot, ... }: -let - inherit (pkgs) - symlinkJoin - ; - - posts = pkgs.stdenvNoCC.mkDerivation { - pname = "4kb.net"; - version = "1.0"; - src = ./.; - - nativeBuildInputs = with pkgs; [ - zola - ]; - - buildPhase = "zola build"; - installPhase = '' - mkdir -p $out - cp -r public/* $out/ - ''; - }; - -in -symlinkJoin { - name = "site"; - paths = [ - posts - depot.misc.cv - ]; -} diff --git a/mod/web/resistors/default.nix b/mod/web/resistors/default.nix deleted file mode 100644 index 5fca68b..0000000 --- a/mod/web/resistors/default.nix +++ /dev/null @@ -1,12 +0,0 @@ -{ pkgs, ... }: - -pkgs.stdenvNoCC.mkDerivation { - pname = "resistors"; - version = "0.0"; - src = ./.; - - buildInputs = [ pkgs.nodePackages.prettier ]; - - phases = [ "installPhase" ]; - installPhase = "mkdir -p $out; cp -r $src/*.{css,html} $out/"; -} diff --git a/machines/xnet/net/dns.nix b/modules/dns.nix index 0632fa9..0632fa9 100644 --- a/machines/xnet/net/dns.nix +++ b/modules/dns.nix diff --git a/mod/users/kle/default.nix b/modules/users.nix index fca1ec7..f9f7df3 100644 --- a/mod/users/kle/default.nix +++ b/modules/users.nix @@ -1,29 +1,19 @@ -{ pkgs, depot, ... }: +{ pkgs, perSystem, ... }: let inherit (builtins) - attrValues - ; + attrValues; - inherit (depot.tools) + inherit (perSystem.self) perf-flamegraph ; - - gitKeys = builtins.fetchurl { - url = "https://github.com/kbujari.keys"; - sha256 = "1kskbiyqvjz1wsmcrgh9v0iryf33y70zk503z0m96wmzdjllmc94"; - }; - keys = { t480 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEOw8YEbHsKy38JHp9W1wcxxZgWCDgnabOXccZUN5ddd"; t1 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP7T2uWJFUu8aFZZgQusGKyEMocb2pKbHLDad2eIJus9"; }; in { - inherit keys; - inherit gitKeys; - - nixos = { + kle = { initialHashedPassword = "$6$R4dDhaftX.vapGMd$.An36hlp3DXfkIC7bPZ0MDPo6Zvpk8JRrhy2LES.lZZj6JDa74oJkcMW3DCsIySvLJxOPXSShos0TpgJ/w0fH/"; isNormalUser = true; shell = pkgs.fish; @@ -33,9 +23,11 @@ in packages = with pkgs; [ btop curl + emacs fzf guvcview jq + jujutsu lynx neovim perf-flamegraph diff --git a/machines/xnet/README b/modules/xnet/README index ab1c28c..ab1c28c 100644 --- a/machines/xnet/README +++ b/modules/xnet/README diff --git a/machines/xnet/default.nix b/modules/xnet/default.nix index 9d224cf..9d224cf 100644 --- a/machines/xnet/default.nix +++ b/modules/xnet/default.nix diff --git a/machines/xnet/desktop/default.nix b/modules/xnet/desktop/default.nix index 995381f..995381f 100644 --- a/machines/xnet/desktop/default.nix +++ b/modules/xnet/desktop/default.nix diff --git a/machines/xnet/disk.nix b/modules/xnet/disk.nix index 26b6909..82e9c87 100644 --- a/machines/xnet/disk.nix +++ b/modules/xnet/disk.nix @@ -1,4 +1,4 @@ -{ config, lib, modulesPath, ... }: +{ config, lib, modulesPath, inputs, ... }: let cfg = config.xnet.disk; commonOpts = { @@ -16,6 +16,7 @@ in { imports = [ (modulesPath + "/installer/scan/not-detected.nix") + inputs.disko.nixosModules.default ]; options.xnet.disk = { diff --git a/machines/xnet/gitserver/default.nix b/modules/xnet/gitserver/default.nix index 2152ebd..2152ebd 100644 --- a/machines/xnet/gitserver/default.nix +++ b/modules/xnet/gitserver/default.nix diff --git a/machines/xnet/gitserver/gitweb.nix b/modules/xnet/gitserver/gitweb.nix index da9a5ee..da9a5ee 100644 --- a/machines/xnet/gitserver/gitweb.nix +++ b/modules/xnet/gitserver/gitweb.nix diff --git a/machines/xnet/monitoring/22604_rev2.json b/modules/xnet/monitoring/22604_rev2.json index 0adeb22..0adeb22 100644 --- a/machines/xnet/monitoring/22604_rev2.json +++ b/modules/xnet/monitoring/22604_rev2.json diff --git a/machines/xnet/monitoring/default.nix b/modules/xnet/monitoring/default.nix index eed4963..eed4963 100644 --- a/machines/xnet/monitoring/default.nix +++ b/modules/xnet/monitoring/default.nix diff --git a/machines/xnet/monitoring/grafana.nix b/modules/xnet/monitoring/grafana.nix index e95318d..e95318d 100644 --- a/machines/xnet/monitoring/grafana.nix +++ b/modules/xnet/monitoring/grafana.nix diff --git a/machines/xnet/net/default.nix b/modules/xnet/net/default.nix index 7242855..7242855 100644 --- a/machines/xnet/net/default.nix +++ b/modules/xnet/net/default.nix diff --git a/modules/xnet/net/dns.nix b/modules/xnet/net/dns.nix new file mode 100644 index 0000000..0632fa9 --- /dev/null +++ b/modules/xnet/net/dns.nix @@ -0,0 +1,38 @@ +{ lib, ... }: +let + inherit (lib) + mkDefault + ; + + quad9 = [ + "9.9.9.9#dns.quad9.net" + "149.112.112.112#dns.quad9.net" + "2620:fe::fe#dns.quad9.net" + "2620:fe::9#dns.quad9.net" + ]; + + cloudflare = [ + "1.1.1.1#one.one.one.one" + "1.0.0.1#one.one.one.one" + "2606:4700:4700::1111#one.one.one.one" + "2606:4700:4700::1001#one.one.one.one" + ]; +in +{ + + networking.nameservers = mkDefault quad9; + + services.resolved = { + enable = true; + llmnr = "false"; + dnssec = "false"; + dnsovertls = mkDefault "opportunistic"; + fallbackDns = quad9 ++ cloudflare; + extraConfig = '' + MulticastDNS=yes + ''; + }; + + # Allow mDNS resolution + networking.firewall.allowedTCPPorts = [ 5353 ]; +} diff --git a/machines/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix index 9d7976e..9d7976e 100644 --- a/machines/xnet/net/sshd.nix +++ b/modules/xnet/net/sshd.nix diff --git a/machines/xnet/nginx.nix b/modules/xnet/nginx.nix index eadd794..eadd794 100644 --- a/machines/xnet/nginx.nix +++ b/modules/xnet/nginx.nix diff --git a/machines/xnet/persist.nix b/modules/xnet/persist.nix index 10eb883..10eb883 100644 --- a/machines/xnet/persist.nix +++ b/modules/xnet/persist.nix diff --git a/mod/web/blog/.gitignore b/packages/blog/.gitignore index decc3f8..decc3f8 100644 --- a/mod/web/blog/.gitignore +++ b/packages/blog/.gitignore diff --git a/mod/web/blog/config.toml b/packages/blog/config.toml index 69c389b..69c389b 100644 --- a/mod/web/blog/config.toml +++ b/packages/blog/config.toml diff --git a/mod/web/blog/content/posts/_index.md b/packages/blog/content/posts/_index.md index 9efc62e..9efc62e 100644 --- a/mod/web/blog/content/posts/_index.md +++ b/packages/blog/content/posts/_index.md diff --git a/mod/web/blog/content/posts/deterministic-hostnames.md b/packages/blog/content/posts/deterministic-hostnames.md index 43dc7d8..43dc7d8 100644 --- a/mod/web/blog/content/posts/deterministic-hostnames.md +++ b/packages/blog/content/posts/deterministic-hostnames.md diff --git a/mod/web/blog/content/posts/nohup.md b/packages/blog/content/posts/nohup.md index 64f7983..64f7983 100644 --- a/mod/web/blog/content/posts/nohup.md +++ b/packages/blog/content/posts/nohup.md diff --git a/mod/web/blog/content/posts/stateless-compute-networks.md b/packages/blog/content/posts/stateless-compute-networks.md index bac9e5d..bac9e5d 100644 --- a/mod/web/blog/content/posts/stateless-compute-networks.md +++ b/packages/blog/content/posts/stateless-compute-networks.md diff --git a/mod/web/blog/content/posts/vim-compilers.md b/packages/blog/content/posts/vim-compilers.md index f735228..f735228 100644 --- a/mod/web/blog/content/posts/vim-compilers.md +++ b/packages/blog/content/posts/vim-compilers.md diff --git a/packages/blog/default.nix b/packages/blog/default.nix new file mode 100644 index 0000000..204388f --- /dev/null +++ b/packages/blog/default.nix @@ -0,0 +1,21 @@ +{ pkgs, perSystem, ... }: +let + inherit (perSystem.self) + cv + ; +in +pkgs.stdenvNoCC.mkDerivation { + name = "4kb.net"; + src = ./.; + + nativeBuildInputs = with pkgs; [ + zola + ]; + + buildPhase = "zola build"; + installPhase = '' + mkdir -p $out/share + cp -r public/* $out/ + cp ${cv} $out/share/cv.pdf + ''; +} diff --git a/mod/web/blog/templates/404.html b/packages/blog/templates/404.html index a4669df..a4669df 100644 --- a/mod/web/blog/templates/404.html +++ b/packages/blog/templates/404.html diff --git a/mod/web/blog/templates/base.html b/packages/blog/templates/base.html index 5a91df5..5a91df5 100644 --- a/mod/web/blog/templates/base.html +++ b/packages/blog/templates/base.html diff --git a/mod/web/blog/templates/index.html b/packages/blog/templates/index.html index 6e8a2af..6e8a2af 100644 --- a/mod/web/blog/templates/index.html +++ b/packages/blog/templates/index.html diff --git a/mod/web/blog/templates/post.html b/packages/blog/templates/post.html index b819520..b819520 100644 --- a/mod/web/blog/templates/post.html +++ b/packages/blog/templates/post.html diff --git a/mod/code/cses/default.nix b/packages/cses/default.nix index 6538eb8..6538eb8 100644 --- a/mod/code/cses/default.nix +++ b/packages/cses/default.nix diff --git a/mod/code/cses/problems/1068.cpp b/packages/cses/problems/1068.cpp index 8d05936..8d05936 100644 --- a/mod/code/cses/problems/1068.cpp +++ b/packages/cses/problems/1068.cpp diff --git a/mod/code/cses/problems/1069.cpp b/packages/cses/problems/1069.cpp index 232d2f7..232d2f7 100644 --- a/mod/code/cses/problems/1069.cpp +++ b/packages/cses/problems/1069.cpp diff --git a/mod/code/cses/problems/1070.cpp b/packages/cses/problems/1070.cpp index 131a644..131a644 100644 --- a/mod/code/cses/problems/1070.cpp +++ b/packages/cses/problems/1070.cpp diff --git a/mod/code/cses/problems/1071.cpp b/packages/cses/problems/1071.cpp index 778cc86..778cc86 100644 --- a/mod/code/cses/problems/1071.cpp +++ b/packages/cses/problems/1071.cpp diff --git a/mod/code/cses/problems/1083.cpp b/packages/cses/problems/1083.cpp index a3cd253..a3cd253 100644 --- a/mod/code/cses/problems/1083.cpp +++ b/packages/cses/problems/1083.cpp diff --git a/mod/code/cses/problems/1094.cpp b/packages/cses/problems/1094.cpp index 56f3886..56f3886 100644 --- a/mod/code/cses/problems/1094.cpp +++ b/packages/cses/problems/1094.cpp diff --git a/mod/misc/cv/cv.typ b/packages/cv/cv.typ index 7d43763..7d43763 100644 --- a/mod/misc/cv/cv.typ +++ b/packages/cv/cv.typ diff --git a/packages/cv/default.nix b/packages/cv/default.nix new file mode 100644 index 0000000..9de6903 --- /dev/null +++ b/packages/cv/default.nix @@ -0,0 +1,5 @@ +{ pkgs, ... }: + +pkgs.runCommand "cv" { } '' + ${pkgs.typst}/bin/typst compile --format pdf ${./cv.typ} $out +'' diff --git a/mod/tools/perf-flamegraph.nix b/packages/perf-flamegraph.nix index b472b74..b472b74 100644 --- a/mod/tools/perf-flamegraph.nix +++ b/packages/perf-flamegraph.nix diff --git a/packages/resistors/default.nix b/packages/resistors/default.nix new file mode 100644 index 0000000..6a038ea --- /dev/null +++ b/packages/resistors/default.nix @@ -0,0 +1,7 @@ +{ pkgs, ... }: + +pkgs.runCommandNoCC "resisto-rs" { } '' + mkdir -p $out + cp ${./index.html} $out/index.html + cp ${./styles.css} $out/styles.css +'' diff --git a/mod/web/resistors/index.html b/packages/resistors/index.html index 0683f49..0683f49 100644 --- a/mod/web/resistors/index.html +++ b/packages/resistors/index.html diff --git a/mod/web/resistors/styles.css b/packages/resistors/styles.css index e2823e4..e2823e4 100644 --- a/mod/web/resistors/styles.css +++ b/packages/resistors/styles.css |
