summary refs log tree commit diff
diff options
context:
space:
mode:
-rw-r--r--flake.lock852
-rwxr-xr-xflake.nix94
-rw-r--r--host/Arc/configuration.nix30
-rw-r--r--host/Arc/optional/gui/wayland.nix2
-rw-r--r--host/Arc/printing.nix (renamed from host/Rory-laptop/printing.nix)0
-rw-r--r--host/AspireTC705/configuration.nix205
-rwxr-xr-xhost/AspireTC705/hooks/post-rebuild.sh7
-rwxr-xr-xhost/AspireTC705/hooks/pre-rebuild.sh7
-rw-r--r--host/AspireTC705/optional/hardware-specific/amd.nix42
-rw-r--r--host/AspireTC705/optional/hardware-specific/nvidia.nix40
-rw-r--r--host/AspireTC705/printing.nix54
-rw-r--r--host/Rory-NTFS/configuration.nix2
-rw-r--r--host/Rory-desktop/configuration.nix45
-rw-r--r--host/Rory-desktop/optional/gui/hyprland.nix5
-rw-r--r--host/Rory-laptop/configuration.nix54
-rw-r--r--host/Rory-laptop/optional/gui/wayland.nix12
-rw-r--r--host/Rory-laptop/services/mariadb.nix (renamed from host/Rory-laptop/mariadb.nix)0
-rw-r--r--host/Rory-laptop/services/nginx.nix (renamed from host/Rory-laptop/nginx.nix)4
-rw-r--r--host/Rory-laptop/services/nginx/discord.localhost.nix (renamed from host/Rory-laptop/nginx/discord.localhost.nix)0
-rwxr-xr-xhost/Rory-laptop/services/nginx/hse.localhost.nix (renamed from host/Rory-laptop/nginx/hse.localhost.nix)0
-rw-r--r--host/Rory-laptop/services/nginx/nix-bincache.nix12
-rw-r--r--host/Rory-laptop/services/nix-bincache.nix11
-rw-r--r--host/Rory-laptop/services/ollama.nix (renamed from host/Rory-laptop/ollama.nix)0
-rw-r--r--host/Rory-laptop/services/postgres.nix (renamed from host/Rory-laptop/postgres.nix)0
-rw-r--r--host/Rory-laptop/services/printing.nix54
-rw-r--r--host/Rory-nginx/services/containers/shared.nix2
-rwxr-xr-xhost/Rory-ovh/configuration.nix40
-rw-r--r--host/Rory-ovh/services/containers/draupnir-ansible/services/draupnir.nix8
-rw-r--r--host/Rory-ovh/services/containers/draupnir-belibre/container.nix29
-rw-r--r--host/Rory-ovh/services/containers/draupnir-belibre/root.nix16
-rw-r--r--host/Rory-ovh/services/containers/draupnir-belibre/services/draupnir.nix67
-rw-r--r--host/Rory-ovh/services/containers/draupnir-fedora/services/draupnir.nix8
-rw-r--r--host/Rory-ovh/services/containers/shared.nix9
-rw-r--r--host/Rory-ovh/services/containers/spacebar/container.nix13
-rw-r--r--host/Rory-ovh/services/containers/spacebar/root.nix63
-rw-r--r--host/Rory-ovh/services/containers/spacebar/services/spacebar.nix41
-rwxr-xr-xhost/Rory-ovh/services/matrix/draupnir.nix45
-rwxr-xr-xhost/Rory-ovh/services/nginx/nginx.nix26
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/root.nix26
-rw-r--r--host/Rory-ovh/services/nginx/spacebar.chat/server/old/gateway.nix2
-rw-r--r--host/Rory-ovh/services/nginx/spacebar.chat/server/rory/admin.nix9
-rw-r--r--host/Rory-ovh/services/nginx/spacebar.chat/server/rory/gateway.nix2
-rw-r--r--host/Rory-ovh/services/nginx/spacebar.chat/server/rory/voice.nix10
-rw-r--r--host/Rory-ovh/services/prosody.nix17
-rw-r--r--host/Rory-ovh/spacebar-monitoring.nix40
-rw-r--r--host/Rory-portable/configuration.nix2
-rw-r--r--host/RoryNix/configuration.nix2
-rw-r--r--host/uISO/development.nix2
-rwxr-xr-xmodules/base-client.nix9
-rwxr-xr-xmodules/base-server.nix42
-rwxr-xr-xmodules/base.nix26
-rw-r--r--modules/monitoring/module.nix1
-rw-r--r--modules/software-templates/devenv/c-cpp.nix4
-rw-r--r--modules/software-templates/devenv/dotnet.nix4
-rw-r--r--modules/software-templates/devenv/go.nix17
-rw-r--r--modules/software-templates/devenv/java.nix4
-rw-r--r--modules/software-templates/devenv/javascript.nix4
-rw-r--r--modules/users/Arci.nix3
-rwxr-xr-xmodules/users/Rory.client.nix2
-rwxr-xr-xmodules/users/Rory.nix17
-rw-r--r--modules/users/Rory/chimmie_fedi-wallpaper.pngbin0 -> 1403953 bytes
-rw-r--r--modules/users/Rory/xenia_drawing5-1.pngbin0 -> 1480870 bytes
-rw-r--r--modules/users/Rory/xenia_drawing5-1_2160p.pngbin0 -> 4768319 bytes
-rw-r--r--modules/users/Rory/xenia_drawing5.pngbin0 -> 916370 bytes
-rw-r--r--modules/users/geba.nix199
-rwxr-xr-xmodules/users/ks.nix1
-rw-r--r--packages/overlays/matrix-synapse/patches/0001-Add-CVE-IDs-to-changelog-for-1.152.1.-19778.patch29
-rw-r--r--packages/overlays/matrix-synapse/patches/0002-nix-use-postgres-17.patch (renamed from packages/overlays/matrix-synapse/patches/0001-nix-use-postgres-17.patch)6
-rw-r--r--packages/overlays/matrix-synapse/patches/0003-nix-fix-flake.patch (renamed from packages/overlays/matrix-synapse/patches/0002-nix-fix-flake.patch)6
-rw-r--r--packages/overlays/matrix-synapse/patches/0004-nix-Update-flake.patch (renamed from packages/overlays/matrix-synapse/patches/0003-nix-Update-flake.patch)10
-rw-r--r--packages/overlays/matrix-synapse/patches/0005-nix-Temporarily-disable-go-in-flake.patch (renamed from packages/overlays/matrix-synapse/patches/0004-nix-Temporarily-disable-go-in-flake.patch)8
-rw-r--r--packages/overlays/matrix-synapse/patches/0006-Add-test-script.patch (renamed from packages/overlays/matrix-synapse/patches/0005-Add-test-script.patch)6
-rw-r--r--packages/overlays/matrix-synapse/patches/0007-Fix-gitignore-to-ignore-.venv.patch (renamed from packages/overlays/matrix-synapse/patches/0006-Fix-gitignore-to-ignore-.venv.patch)6
-rw-r--r--packages/overlays/matrix-synapse/patches/0008-Fast-auth-links.patch (renamed from packages/overlays/matrix-synapse/patches/0007-Fast-auth-links.patch)12
-rw-r--r--packages/overlays/matrix-synapse/patches/0009-Add-too-much-logging-to-room-summary-over-federation.patch (renamed from packages/overlays/matrix-synapse/patches/0008-Add-too-much-logging-to-room-summary-over-federation.patch)10
-rw-r--r--packages/overlays/matrix-synapse/patches/0010-Log-entire-room-if-accessibility-check-fails.patch (renamed from packages/overlays/matrix-synapse/patches/0009-Log-entire-room-if-accessibility-check-fails.patch)10
-rw-r--r--packages/overlays/matrix-synapse/patches/0010-Log-policy-server-rejected-events.patch31
-rw-r--r--packages/overlays/matrix-synapse/patches/0011-Use-parse_boolean-for-unredacted-content.patch8
-rw-r--r--packages/overlays/matrix-synapse/patches/0012-Expose-tombstone-in-room-admin-api.patch22
-rw-r--r--packages/overlays/matrix-synapse/patches/0013-fix-Always-recheck-messages-pagination-data-if-a-bac.patch34
-rw-r--r--packages/overlays/matrix-synapse/patches/0014-Fix-pagination-with-large-gaps-of-rejected-events.patch48
-rw-r--r--packages/overlays/matrix-synapse/patches/0015-RequestRatelimiter-expose-can_do_action.patch4
-rw-r--r--packages/overlays/matrix-synapse/patches/0016-Clarify-pre_event_ids-assert-in-event-creation-handl.patch8
-rw-r--r--packages/overlays/matrix-synapse/patches/0017-Add-bulk-send-events-endpoint.patch22
-rw-r--r--packages/overlays/matrix-synapse/patches/0018-admin-api-send-more-data.patch20
-rw-r--r--packages/overlays/matrix-synapse/patches/0019-Allow-overriding-max-background-task-count.patch10
-rwxr-xr-xprebuild.sh22
-rwxr-xr-xupdate.sh2
88 files changed, 1728 insertions, 950 deletions
diff --git a/flake.lock b/flake.lock

index e388064..37354f9 100644 --- a/flake.lock +++ b/flake.lock
@@ -20,11 +20,11 @@ ] }, "locked": { - "lastModified": 1752936381, - "narHash": "sha256-b191B12GRfvOT3odGpx5IFyGRPZbBrvCLADZfFHoJFg=", + "lastModified": 1771610171, + "narHash": "sha256-+DeInuhbm6a6PpHDNUS7pozDouq2+8xSDefoNaZLW0E=", "owner": "hyprwm", "repo": "aquamarine", - "rev": "141a991678b34e768f09b3a670c61a4c1d5d7110", + "rev": "7f9eb087703ec4acc6b288d02fa9ea3db803cd3d", "type": "github" }, "original": { @@ -57,30 +57,6 @@ "type": "github" } }, - "attic_2": { - "inputs": { - "crane": "crane_3", - "flake-compat": "flake-compat_3", - "flake-parts": "flake-parts_2", - "nix-github-actions": "nix-github-actions_2", - "nixpkgs": "nixpkgs_4", - "nixpkgs-stable": "nixpkgs-stable_2" - }, - "locked": { - "lastModified": 1752217044, - "narHash": "sha256-5TomR72rn4q+5poQcN6EnanxeXKqJSqWVAoDAFN0lUc=", - "owner": "zhaofengli", - "repo": "attic", - "rev": "24fad0622fc9404c69e83bab7738359c5be4988e", - "type": "github" - }, - "original": { - "owner": "zhaofengli", - "ref": "main", - "repo": "attic", - "type": "github" - } - }, "botcore-v4": { "inputs": { "nixpkgs": "nixpkgs" @@ -108,11 +84,11 @@ ] }, "locked": { - "lastModified": 1746960839, - "narHash": "sha256-YOov+78fsGBZGj2JQQQDozflSLJA1Wo4tRODFi2srto=", + "lastModified": 1770384065, + "narHash": "sha256-P7rjS63P9ff4fMPqFvbCjkwnfoQQ+B7qEsp4mu3l1oE=", "ref": "refs/heads/master", - "rev": "863a3817820d28d8026f6d73de304b43cb60f6fa", - "revCount": 1660, + "rev": "6de8f65769e6a42f09e20d0cad10acae8b278175", + "revCount": 1677, "type": "git", "url": "https://cgit.rory.gay/cgit-magenta.git" }, @@ -132,11 +108,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1767125279, - "narHash": "sha256-Ar3nAGDXGoQaY2hgVoXqNEEyjDV8cf2ciZB9FoJXLDw=", + "lastModified": 1772728019, + "narHash": "sha256-o0ZjV/LHo39Ors6Bi/W8+4KrlmhyboPxQ26MroFt9M4=", "owner": "famedly", "repo": "conduit", - "rev": "346913268f5fd690ae11124df3906223d3974924", + "rev": "8def22bfb8b9b23bbd47e17772f2bd80500eacf6", "type": "gitlab" }, "original": { @@ -184,65 +160,14 @@ "type": "github" } }, - "crane_3": { - "locked": { - "lastModified": 1751562746, - "narHash": "sha256-smpugNIkmDeicNz301Ll1bD7nFOty97T79m4GUMUczA=", - "owner": "ipetkov", - "repo": "crane", - "rev": "aed2020fd3dc26e1e857d4107a5a67a33ab6c1fd", - "type": "github" - }, - "original": { - "owner": "ipetkov", - "repo": "crane", - "type": "github" - } - }, - "crane_4": { - "locked": { - "lastModified": 1752946753, - "narHash": "sha256-g5uP3jIj+STUcfTJDKYopxnSijs2agRg13H0SGL5iE4=", - "owner": "ipetkov", - "repo": "crane", - "rev": "544d09fecc8c2338542c57f3f742f1a0c8c71e13", - "type": "github" - }, - "original": { - "owner": "ipetkov", - "ref": "master", - "repo": "crane", - "type": "github" - } - }, - "drasl": { - "inputs": { - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1766981813, - "narHash": "sha256-139iGyEAtKC11bgGZsRLeHWGIPomX2rP8zaLagntMpA=", - "owner": "unmojang", - "repo": "drasl", - "rev": "b73e998010e56fe5d38a923164bb41696b7b3392", - "type": "github" - }, - "original": { - "owner": "unmojang", - "repo": "drasl", - "type": "github" - } - }, "draupnirSrc": { "flake": false, "locked": { - "lastModified": 1766062654, - "narHash": "sha256-j5UEW9JpIHhFWGMEwrPE1v0hdFAw5Z4CImRYEm56I4k=", + "lastModified": 1779012439, + "narHash": "sha256-Iys8Fi9SAz1etN4HdQ82Vb7/7a+Lqi8JG4vm03MLfEo=", "owner": "the-draupnir-project", "repo": "Draupnir", - "rev": "7ef871d3c70cb3b0bab88264ad15d108798e09ed", + "rev": "5c8f6a30a1657ffe198068e87e9c5dbf58d18648", "type": "github" }, "original": { @@ -274,45 +199,6 @@ "type": "github" } }, - "fenix_2": { - "inputs": { - "nixpkgs": [ - "grapevine", - "nixpkgs" - ], - "rust-analyzer-src": "rust-analyzer-src_2" - }, - "locked": { - "lastModified": 1752993983, - "narHash": "sha256-3YKCySMNhFDdHbFiRS4QbEwk0U5l42NMD1scDtniESY=", - "owner": "nix-community", - "repo": "fenix", - "rev": "62105e0745d7450976b26dbd1497b8cbe15eb9ff", - "type": "github" - }, - "original": { - "owner": "nix-community", - "ref": "main", - "repo": "fenix", - "type": "github" - } - }, - "ffmpegSrc": { - "flake": false, - "locked": { - "lastModified": 1768241916, - "narHash": "sha256-//8am/5cxTG9S5e4H6Z8oBydcEL5P+VEmrzilljW01E=", - "ref": "refs/heads/master", - "rev": "ab66bc577681336e4a5e1d1811c251300ddeb621", - "revCount": 122452, - "type": "git", - "url": "https://git.ffmpeg.org/ffmpeg.git" - }, - "original": { - "type": "git", - "url": "https://git.ffmpeg.org/ffmpeg.git" - } - }, "flake-compat": { "flake": false, "locked": { @@ -348,15 +234,15 @@ "flake-compat_3": { "flake": false, "locked": { - "lastModified": 1747046372, - "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", - "owner": "edolstra", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", "repo": "flake-compat", - "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { - "owner": "edolstra", + "owner": "NixOS", "repo": "flake-compat", "type": "github" } @@ -364,39 +250,6 @@ "flake-compat_4": { "flake": false, "locked": { - "lastModified": 1747046372, - "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", - "type": "github" - }, - "original": { - "owner": "edolstra", - "ref": "master", - "repo": "flake-compat", - "type": "github" - } - }, - "flake-compat_5": { - "flake": false, - "locked": { - "lastModified": 1696426674, - "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", - "type": "github" - }, - "original": { - "owner": "edolstra", - "repo": "flake-compat", - "type": "github" - } - }, - "flake-compat_6": { - "flake": false, - "locked": { "lastModified": 1767039857, "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "owner": "NixOS", @@ -410,7 +263,7 @@ "type": "github" } }, - "flake-compat_7": { + "flake-compat_5": { "flake": false, "locked": { "lastModified": 1767039857, @@ -448,28 +301,6 @@ "type": "github" } }, - "flake-parts_2": { - "inputs": { - "nixpkgs-lib": [ - "grapevine", - "attic", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1751413152, - "narHash": "sha256-Tyw1RjYEsp5scoigs1384gIg6e0GoBVjms4aXFfRssQ=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "77826244401ea9de6e3bac47c2db46005e1f30b5", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, "flake-utils": { "inputs": { "systems": "systems" @@ -526,7 +357,7 @@ }, "flake-utils_4": { "inputs": { - "systems": "systems_4" + "systems": "systems_5" }, "locked": { "lastModified": 1731533236, @@ -538,53 +369,13 @@ }, "original": { "owner": "numtide", - "ref": "main", "repo": "flake-utils", "type": "github" } }, "flake-utils_5": { "inputs": { - "systems": "systems_6" - }, - "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_6": { - "inputs": { - "systems": [ - "nix-jetbrains-plugins", - "systems" - ] - }, - "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_7": { - "inputs": { - "systems": "systems_8" + "systems": "systems_7" }, "locked": { "lastModified": 1731533236, @@ -599,9 +390,9 @@ "type": "indirect" } }, - "flake-utils_8": { + "flake-utils_6": { "inputs": { - "systems": "systems_9" + "systems": "systems_8" }, "locked": { "lastModified": 1731533236, @@ -634,7 +425,7 @@ }, "git-hooks": { "inputs": { - "flake-compat": "flake-compat_7", + "flake-compat": "flake-compat_5", "gitignore": "gitignore_2", "nixpkgs": [ "nom", @@ -642,11 +433,11 @@ ] }, "locked": { - "lastModified": 1767281941, - "narHash": "sha256-6MkqajPICgugsuZ92OMoQcgSHnD6sJHwk8AxvMcIgTE=", + "lastModified": 1778507602, + "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "f0927703b7b1c8d97511c4116eb9b4ec6645a0fa", + "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", "type": "github" }, "original": { @@ -699,43 +490,16 @@ "type": "github" } }, - "grapevine": { - "inputs": { - "attic": "attic_2", - "crane": "crane_4", - "fenix": "fenix_2", - "flake-compat": "flake-compat_4", - "flake-utils": "flake-utils_4", - "nix-filter": "nix-filter_2", - "nixpkgs": "nixpkgs_5", - "rocksdb": "rocksdb" - }, - "locked": { - "host": "gitlab.computer.surgery", - "lastModified": 1767145713, - "narHash": "sha256-rH1cjS86JYQvYvvZ3w6XLtMsCbLC7Wwcywy5pr3uMLY=", - "owner": "matrix", - "repo": "grapevine-fork", - "rev": "0aae932bc949d8d9c179705a015bc0ca85ac3443", - "type": "gitlab" - }, - "original": { - "host": "gitlab.computer.surgery", - "owner": "matrix", - "repo": "grapevine-fork", - "type": "gitlab" - } - }, "home-manager": { "inputs": { - "nixpkgs": "nixpkgs_6" + "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1768248481, - "narHash": "sha256-VhJYOTDxstdxb86a7/e8bb/6GMzQEfN6cjQLsN83s48=", + "lastModified": 1779027260, + "narHash": "sha256-ZbgWWFQmSyM3HQ31nAZk2hJ7OSeNr9uRFHL8jCifY9M=", "owner": "nix-community", "repo": "home-manager", - "rev": "94597e670fbb259daaf3161d93d529986b7e7ad6", + "rev": "bcb774cfc3268120cd61808629f9aa7dad3750a2", "type": "github" }, "original": { @@ -745,27 +509,6 @@ "type": "github" } }, - "hy3": { - "inputs": { - "hyprland": [ - "hyprland" - ] - }, - "locked": { - "lastModified": 1752830283, - "narHash": "sha256-1BTJSqkj+lkIry27HuqA5UB7uRqAUvGT7LAUDQhKjU0=", - "owner": "outfoxxed", - "repo": "hy3", - "rev": "d61a2eb9b9f22c6e46edad3e8f5fbd3578961b11", - "type": "github" - }, - "original": { - "owner": "outfoxxed", - "ref": "hl0.50.0", - "repo": "hy3", - "type": "github" - } - }, "hyprcursor": { "inputs": { "hyprlang": [ @@ -782,11 +525,11 @@ ] }, "locked": { - "lastModified": 1749155331, - "narHash": "sha256-XR9fsI0zwLiFWfqi/pdS/VD+YNorKb3XIykgTg4l1nA=", + "lastModified": 1753964049, + "narHash": "sha256-lIqabfBY7z/OANxHoPeIrDJrFyYy9jAM4GQLzZ2feCM=", "owner": "hyprwm", "repo": "hyprcursor", - "rev": "45fcc10b4c282746d93ec406a740c43b48b4ef80", + "rev": "44e91d467bdad8dcf8bbd2ac7cf49972540980a5", "type": "github" }, "original": { @@ -811,11 +554,11 @@ ] }, "locked": { - "lastModified": 1752149140, - "narHash": "sha256-gbh1HL98Fdqu0jJIWN4OJQN7Kkth7+rbkFpSZLm/62A=", + "lastModified": 1770511807, + "narHash": "sha256-suKmSbSk34uPOJDTg/GbPrKEJutzK08vj0VoTvAFBCA=", "owner": "hyprwm", "repo": "hyprgraphics", - "rev": "340494a38b5ec453dfc542c6226481f736cc8a9a", + "rev": "7c75487edd43a71b61adb01cae8326d277aab683", "type": "github" }, "original": { @@ -829,35 +572,59 @@ "aquamarine": "aquamarine", "hyprcursor": "hyprcursor", "hyprgraphics": "hyprgraphics", + "hyprland-guiutils": "hyprland-guiutils", "hyprland-protocols": "hyprland-protocols", - "hyprland-qtutils": "hyprland-qtutils", "hyprlang": "hyprlang", "hyprutils": "hyprutils", "hyprwayland-scanner": "hyprwayland-scanner", - "nixpkgs": "nixpkgs_7", + "hyprwire": "hyprwire", + "nixpkgs": [ + "nixpkgs" + ], "pre-commit-hooks": "pre-commit-hooks", - "systems": "systems_5", + "systems": "systems_4", "xdph": "xdph" }, "locked": { - "lastModified": 1752961026, - "narHash": "sha256-ALp/WkfOfXMScwytTmjxpjRNmbezrgFQdEX6n3py7L8=", - "ref": "refs/tags/v0.50.1", - "rev": "4e242d086e20b32951fdc0ebcbfb4d41b5be8dcc", - "revCount": 6291, + "lastModified": 1772215399, + "narHash": "sha256-wfiduannx1mWvsGAfuMk8ipOU3AAFuJYPNV4D++dhPY=", + "ref": "refs/tags/v0.54.0", + "rev": "0002f148c9a4fe421a9d33c0faa5528cdc411e62", + "revCount": 6935, "submodules": true, "type": "git", "url": "https://github.com/hyprwm/Hyprland" }, "original": { - "ref": "refs/tags/v0.50.1", + "ref": "refs/tags/v0.54.0", "submodules": true, "type": "git", "url": "https://github.com/hyprwm/Hyprland" } }, - "hyprland-protocols": { + "hyprland-guiutils": { "inputs": { + "aquamarine": [ + "hyprland", + "aquamarine" + ], + "hyprgraphics": [ + "hyprland", + "hyprgraphics" + ], + "hyprlang": [ + "hyprland", + "hyprlang" + ], + "hyprtoolkit": "hyprtoolkit", + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "hyprwayland-scanner": [ + "hyprland", + "hyprwayland-scanner" + ], "nixpkgs": [ "hyprland", "nixpkgs" @@ -868,62 +635,48 @@ ] }, "locked": { - "lastModified": 1749046714, - "narHash": "sha256-kymV5FMnddYGI+UjwIw8ceDjdeg7ToDVjbHCvUlhn14=", + "lastModified": 1767023960, + "narHash": "sha256-R2HgtVS1G3KSIKAQ77aOZ+Q0HituOmPgXW9nBNkpp3Q=", "owner": "hyprwm", - "repo": "hyprland-protocols", - "rev": "613878cb6f459c5e323aaafe1e6f388ac8a36330", + "repo": "hyprland-guiutils", + "rev": "c2e906261142f5dd1ee0bfc44abba23e2754c660", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprland-protocols", + "repo": "hyprland-guiutils", "type": "github" } }, - "hyprland-qt-support": { + "hyprland-protocols": { "inputs": { - "hyprlang": [ - "hyprland", - "hyprland-qtutils", - "hyprlang" - ], "nixpkgs": [ "hyprland", - "hyprland-qtutils", "nixpkgs" ], "systems": [ "hyprland", - "hyprland-qtutils", "systems" ] }, "locked": { - "lastModified": 1749154592, - "narHash": "sha256-DO7z5CeT/ddSGDEnK9mAXm1qlGL47L3VAHLlLXoCjhE=", + "lastModified": 1765214753, + "narHash": "sha256-P9zdGXOzToJJgu5sVjv7oeOGPIIwrd9hAUAP3PsmBBs=", "owner": "hyprwm", - "repo": "hyprland-qt-support", - "rev": "4c8053c3c888138a30c3a6c45c2e45f5484f2074", + "repo": "hyprland-protocols", + "rev": "3f3860b869014c00e8b9e0528c7b4ddc335c21ab", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprland-qt-support", + "repo": "hyprland-protocols", "type": "github" } }, - "hyprland-qtutils": { + "hyprlang": { "inputs": { - "hyprland-qt-support": "hyprland-qt-support", - "hyprlang": [ - "hyprland", - "hyprlang" - ], "hyprutils": [ "hyprland", - "hyprland-qtutils", - "hyprlang", "hyprutils" ], "nixpkgs": [ @@ -936,45 +689,68 @@ ] }, "locked": { - "lastModified": 1750371812, - "narHash": "sha256-D868K1dVEACw17elVxRgXC6hOxY+54wIEjURztDWLk8=", + "lastModified": 1771866172, + "narHash": "sha256-fYFoXhQLrm1rD8vSFKQBOEX4OGCuJdLt1amKfHd5GAw=", "owner": "hyprwm", - "repo": "hyprland-qtutils", - "rev": "b13c7481e37856f322177010bdf75fccacd1adc8", + "repo": "hyprlang", + "rev": "0b219224910e7642eb0ed49f0db5ec3d008e3e41", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprland-qtutils", + "repo": "hyprlang", "type": "github" } }, - "hyprlang": { + "hyprtoolkit": { "inputs": { + "aquamarine": [ + "hyprland", + "hyprland-guiutils", + "aquamarine" + ], + "hyprgraphics": [ + "hyprland", + "hyprland-guiutils", + "hyprgraphics" + ], + "hyprlang": [ + "hyprland", + "hyprland-guiutils", + "hyprlang" + ], "hyprutils": [ "hyprland", + "hyprland-guiutils", "hyprutils" ], + "hyprwayland-scanner": [ + "hyprland", + "hyprland-guiutils", + "hyprwayland-scanner" + ], "nixpkgs": [ "hyprland", + "hyprland-guiutils", "nixpkgs" ], "systems": [ "hyprland", + "hyprland-guiutils", "systems" ] }, "locked": { - "lastModified": 1750371198, - "narHash": "sha256-/iuJ1paQOBoSLqHflRNNGyroqfF/yvPNurxzcCT0cAE=", + "lastModified": 1764592794, + "narHash": "sha256-7CcO+wbTJ1L1NBQHierHzheQGPWwkIQug/w+fhTAVuU=", "owner": "hyprwm", - "repo": "hyprlang", - "rev": "cee01452bca58d6cadb3224e21e370de8bc20f0b", + "repo": "hyprtoolkit", + "rev": "5cfe0743f0e608e1462972303778d8a0859ee63e", "type": "github" }, "original": { "owner": "hyprwm", - "repo": "hyprlang", + "repo": "hyprtoolkit", "type": "github" } }, @@ -990,11 +766,11 @@ ] }, "locked": { - "lastModified": 1752252310, - "narHash": "sha256-06i1pIh6wb+sDeDmWlzuPwIdaFMxLlj1J9I5B9XqSeo=", + "lastModified": 1771271487, + "narHash": "sha256-41gEiUS0Pyw3L/ge1l8MXn61cK14VAhgWB/JV8s/oNI=", "owner": "hyprwm", "repo": "hyprutils", - "rev": "bcabcbada90ed2aacb435dc09b91001819a6dc82", + "rev": "340a792e3b3d482c4ae5f66d27a9096bdee6d76d", "type": "github" }, "original": { @@ -1015,11 +791,11 @@ ] }, "locked": { - "lastModified": 1751897909, - "narHash": "sha256-FnhBENxihITZldThvbO7883PdXC/2dzW4eiNvtoV5Ao=", + "lastModified": 1770501770, + "narHash": "sha256-NWRM6+YxTRv+bT9yvlhhJ2iLae1B1pNH3mAL5wi2rlQ=", "owner": "hyprwm", "repo": "hyprwayland-scanner", - "rev": "fcca0c61f988a9d092cbb33e906775014c61579d", + "rev": "0bd8b6cde9ec27d48aad9e5b4deefb3746909d40", "type": "github" }, "original": { @@ -1028,14 +804,43 @@ "type": "github" } }, + "hyprwire": { + "inputs": { + "hyprutils": [ + "hyprland", + "hyprutils" + ], + "nixpkgs": [ + "hyprland", + "nixpkgs" + ], + "systems": [ + "hyprland", + "systems" + ] + }, + "locked": { + "lastModified": 1771606233, + "narHash": "sha256-F3PLUqQ/TwgR70U+UeOqJnihJZ2EuunzojYC4g5xHr0=", + "owner": "hyprwm", + "repo": "hyprwire", + "rev": "06c7f1f8c4194786c8400653c4efc49dc14c0f3a", + "type": "github" + }, + "original": { + "owner": "hyprwm", + "repo": "hyprwire", + "type": "github" + } + }, "lix": { "flake": false, "locked": { - "lastModified": 1768229765, - "narHash": "sha256-rcXdr5TN9aCVKVuT8eDvyV/eweI4W+5k2pBJ4m/eqbs=", - "rev": "f4314643828a013aa84a52959786e53729e58a5a", + "lastModified": 1778147108, + "narHash": "sha256-pK0oP+HYH8XVPwZ6BB0DAC4ex0gCsj0FLH5182BBgBU=", + "rev": "7831c98a4db589c84cf730db23793afe3fd90f2d", "type": "tarball", - "url": "https://git.lix.systems/api/v1/repos/lix-project/lix/archive/f4314643828a013aa84a52959786e53729e58a5a.tar.gz?rev=f4314643828a013aa84a52959786e53729e58a5a" + "url": "https://git.lix.systems/api/v1/repos/lix-project/lix/archive/7831c98a4db589c84cf730db23793afe3fd90f2d.tar.gz?rev=7831c98a4db589c84cf730db23793afe3fd90f2d" }, "original": { "type": "tarball", @@ -1044,7 +849,7 @@ }, "lix-module": { "inputs": { - "flake-utils": "flake-utils_5", + "flake-utils": "flake-utils_4", "flakey-profile": "flakey-profile", "lix": [ "lix" @@ -1054,11 +859,11 @@ ] }, "locked": { - "lastModified": 1767364176, - "narHash": "sha256-l6YdEBYQxXjD8ujqvc0tKdwWc3K8UQOi+E4Y3DKQ318=", - "rev": "1688100bba140492658d597f6b307c327f35c780", + "lastModified": 1773460763, + "narHash": "sha256-y9kC3ff89btXS8RD6pAtM50g0qtsim1I8HXBtgSqdbI=", + "rev": "5e56f5a973e24292b125dca9e9d506b0a91d6903", "type": "tarball", - "url": "https://git.lix.systems/api/v1/repos/lix-project/nixos-module/archive/1688100bba140492658d597f6b307c327f35c780.tar.gz?rev=1688100bba140492658d597f6b307c327f35c780" + "url": "https://git.lix.systems/api/v1/repos/lix-project/nixos-module/archive/5e56f5a973e24292b125dca9e9d506b0a91d6903.tar.gz?rev=5e56f5a973e24292b125dca9e9d506b0a91d6903" }, "original": { "type": "tarball", @@ -1068,11 +873,11 @@ "matrixSpecSrc": { "flake": false, "locked": { - "lastModified": 1767957591, - "narHash": "sha256-9TLrZYNgZ1uoYYE7i0dbfHpj8J1wVP3YMsOr5cFvFr8=", + "lastModified": 1778746843, + "narHash": "sha256-WqbQnI1UMpMIZe/2+Li5Dvm6DRpm6fhiX3LdZricFww=", "owner": "matrix-org", "repo": "matrix-spec", - "rev": "2cc7e13c09c4c401e4632626099954b4c1cf3296", + "rev": "905165ffd3750f6d219a4b1b1347698c9bd1601b", "type": "github" }, "original": { @@ -1085,11 +890,11 @@ "mtxclientSrc": { "flake": false, "locked": { - "lastModified": 1758395358, - "narHash": "sha256-zxpvRDKpp8sWSmf/xLgoHDWMzmdkQenZepXg+CoGtcg=", + "lastModified": 1772411127, + "narHash": "sha256-5LapoeXRiRi4tSpFvcVu4Z6+aDIz43UBoDU1Rx2y8TA=", "owner": "Nheko-reborn", "repo": "mtxclient", - "rev": "d6f10427d1c5e5b1a45f426274f8d2e8dd0b64be", + "rev": "f5766cb53c244a808b7e512c7b83b3942fb67834", "type": "github" }, "original": { @@ -1102,11 +907,11 @@ "nhekoSrc": { "flake": false, "locked": { - "lastModified": 1766771320, - "narHash": "sha256-Rxg0aRiJuFyqa0ZcZcZoJmdHr4H69oEEQF6aoqh1VZg=", + "lastModified": 1778283689, + "narHash": "sha256-Zyvfxuk77FYBYwPJykK6YBnnCLG1BeN6jJ5gcDA5Go4=", "owner": "Nheko-reborn", "repo": "nheko", - "rev": "5b065f353c93725cd96c231d078fb742b1a5aa54", + "rev": "90ff9c6f36dd9df9e0e23212c34b83ec61772bba", "type": "github" }, "original": { @@ -1131,22 +936,6 @@ "type": "github" } }, - "nix-filter_2": { - "locked": { - "lastModified": 1731533336, - "narHash": "sha256-oRam5PS1vcrr5UPgALW0eo1m/5/pls27Z/pabHNy2Ms=", - "owner": "numtide", - "repo": "nix-filter", - "rev": "f7653272fd234696ae94229839a99b73c9ab7de0", - "type": "github" - }, - "original": { - "owner": "numtide", - "ref": "main", - "repo": "nix-filter", - "type": "github" - } - }, "nix-github-actions": { "inputs": { "nixpkgs": [ @@ -1169,41 +958,18 @@ "type": "github" } }, - "nix-github-actions_2": { - "inputs": { - "nixpkgs": [ - "grapevine", - "attic", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1737420293, - "narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=", - "owner": "nix-community", - "repo": "nix-github-actions", - "rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nix-github-actions", - "type": "github" - } - }, "nix-jetbrains-plugins": { "inputs": { - "flake-compat": "flake-compat_6", - "flake-utils": "flake-utils_6", - "nixpkgs": "nixpkgs_8", - "systems": "systems_7" + "flake-compat": "flake-compat_4", + "nixpkgs": "nixpkgs_5", + "systems": "systems_6" }, "locked": { - "lastModified": 1768228750, - "narHash": "sha256-V73sd8tYumv+G7gAYrXVVj+Y8Q/bZic8usFCvKPmpv4=", + "lastModified": 1778951860, + "narHash": "sha256-aFjBC3AVLh/bsgcsoI6Z/yQmh/NABffwHJIqQOTj+Tg=", "owner": "nix-community", "repo": "nix-jetbrains-plugins", - "rev": "45f3da83dea0fa5a5f94308e0d0c0151120e9e00", + "rev": "68930eefa5e77fc6bb7977635c83a003683c2f11", "type": "github" }, "original": { @@ -1230,11 +996,11 @@ }, "nixpkgs-RoryNix": { "locked": { - "lastModified": 1768248307, - "narHash": "sha256-7Y7TXAqDXW+2p8xm85BKxkxzGO2jPI8hchkS2Vlav/A=", + "lastModified": 1779047664, + "narHash": "sha256-GGvK1crvlJa9vBwV7UBTRXB1XOFLoB3RAPsDcnqLr+E=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "7bf61c5a0f183604f2da3b412dbfec3de1d07b9a", + "rev": "195e19cca23a3f7e553b45fc26fed71ac1e39a6a", "type": "github" }, "original": { @@ -1246,11 +1012,11 @@ }, "nixpkgs-master": { "locked": { - "lastModified": 1768248307, - "narHash": "sha256-7Y7TXAqDXW+2p8xm85BKxkxzGO2jPI8hchkS2Vlav/A=", + "lastModified": 1779047664, + "narHash": "sha256-GGvK1crvlJa9vBwV7UBTRXB1XOFLoB3RAPsDcnqLr+E=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "7bf61c5a0f183604f2da3b412dbfec3de1d07b9a", + "rev": "195e19cca23a3f7e553b45fc26fed71ac1e39a6a", "type": "github" }, "original": { @@ -1260,39 +1026,39 @@ "type": "github" } }, - "nixpkgs-stable": { + "nixpkgs-override-draupnir": { "locked": { - "lastModified": 1724316499, - "narHash": "sha256-Qb9MhKBUTCfWg/wqqaxt89Xfi6qTD3XpTzQ9eXi3JmE=", + "lastModified": 1779707573, + "narHash": "sha256-wHca//T/RJVV/1S5ceiC16f/Rk0XU0aCGesWoXeiRjI=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "797f7dc49e0bc7fab4b57c021cdf68f595e47841", + "rev": "7e18ec57066eedfca6259e4d7717eae8eb619b67", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-24.05", + "ref": "master", "repo": "nixpkgs", "type": "github" } }, - "nixpkgs-stable_2": { + "nixpkgs-stable": { "locked": { - "lastModified": 1751741127, - "narHash": "sha256-t75Shs76NgxjZSgvvZZ9qOmz5zuBE8buUaYD28BMTxg=", + "lastModified": 1724316499, + "narHash": "sha256-Qb9MhKBUTCfWg/wqqaxt89Xfi6qTD3XpTzQ9eXi3JmE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "29e290002bfff26af1db6f64d070698019460302", + "rev": "797f7dc49e0bc7fab4b57c021cdf68f595e47841", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.05", + "ref": "nixos-24.05", "repo": "nixpkgs", "type": "github" } }, - "nixpkgs-stable_3": { + "nixpkgs-stable_2": { "locked": { "lastModified": 1767313136, "narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=", @@ -1308,54 +1074,6 @@ "type": "github" } }, - "nixpkgs_10": { - "locked": { - "lastModified": 1764517877, - "narHash": "sha256-pp3uT4hHijIC8JUK5MEqeAWmParJrgBVzHLNfJDZxg4=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "2d293cbfa5a793b4c50d17c05ef9e385b90edf6c", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_11": { - "locked": { - "lastModified": 1768032153, - "narHash": "sha256-6kD1MdY9fsE6FgSwdnx29hdH2UcBKs3/+JJleMShuJg=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "3146c6aa9995e7351a398e17470e15305e6e18ff", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_12": { - "locked": { - "lastModified": 1768564909, - "narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, "nixpkgs_2": { "locked": { "lastModified": 1726042813, @@ -1390,27 +1108,27 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1751949589, - "narHash": "sha256-mgFxAPLWw0Kq+C8P3dRrZrOYEQXOtKuYVlo9xvPntt8=", + "lastModified": 1778443072, + "narHash": "sha256-zi7/fsqM/kFdNuED//4WOCUtezGtKKqRNORjMvfwjnA=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9b008d60392981ad674e04016d25619281550a9d", + "rev": "da5ad661ba4e5ef59ba743f0d112cbc30e474f32", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixpkgs-unstable", + "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" } }, "nixpkgs_5": { "locked": { - "lastModified": 1752950548, - "narHash": "sha256-NS6BLD0lxOrnCiEOcvQCDVPXafX1/ek1dfJHX1nUIzc=", + "lastModified": 1778443072, + "narHash": "sha256-zi7/fsqM/kFdNuED//4WOCUtezGtKKqRNORjMvfwjnA=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "c87b95e25065c028d31a94f06a62927d18763fdf", + "rev": "da5ad661ba4e5ef59ba743f0d112cbc30e474f32", "type": "github" }, "original": { @@ -1422,11 +1140,11 @@ }, "nixpkgs_6": { "locked": { - "lastModified": 1767892417, - "narHash": "sha256-dhhvQY67aboBk8b0/u0XB6vwHdgbROZT3fJAjyNh5Ww=", + "lastModified": 1778869304, + "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba", + "rev": "d233902339c02a9c334e7e593de68855ad26c4cb", "type": "github" }, "original": { @@ -1438,11 +1156,11 @@ }, "nixpkgs_7": { "locked": { - "lastModified": 1752687322, - "narHash": "sha256-RKwfXA4OZROjBTQAl9WOZQFm7L8Bo93FQwSJpAiSRvo=", + "lastModified": 1777578337, + "narHash": "sha256-Ad49moKWeXtKBJNy2ebiTQUEgdLyvGmTeykAQ9xM+Z4=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "6e987485eb2c77e5dcc5af4e3c70843711ef9251", + "rev": "15f4ee454b1dce334612fa6843b3e05cf546efab", "type": "github" }, "original": { @@ -1454,50 +1172,50 @@ }, "nixpkgs_8": { "locked": { - "lastModified": 1767640445, - "narHash": "sha256-UWYqmD7JFBEDBHWYcqE6s6c77pWdcU/i+bwD6XxMb8A=", + "lastModified": 1775888245, + "narHash": "sha256-nwASzrRDD1JBEu/o8ekKYEXm/oJW6EMCzCRdrwcLe90=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9f0c42f8bc7151b8e7e5840fb3bd454ad850d8c5", + "rev": "13043924aaa7375ce482ebe2494338e058282925", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", + "ref": "nixpkgs-unstable", "repo": "nixpkgs", "type": "github" } }, "nixpkgs_9": { "locked": { - "lastModified": 1768127708, - "narHash": "sha256-1Sm77VfZh3mU0F5OqKABNLWxOuDeHIlcFjsXeeiPazs=", + "lastModified": 1778979197, + "narHash": "sha256-d83oRDbsJ+XrYqxqe/z5CIGRrY2B5xYC308UsQXdmus=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "ffbc9f8cbaacfb331b6017d5a5abb21a492c9a38", + "rev": "233ebfd96819ab13eff099ded59063c8bfb80d63", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", + "ref": "master", "repo": "nixpkgs", "type": "github" } }, "nom": { "inputs": { - "flake-utils": "flake-utils_7", + "flake-utils": "flake-utils_5", "git-hooks": "git-hooks", "nixpkgs": [ "nixpkgs" ] }, "locked": { - "lastModified": 1767934960, - "narHash": "sha256-37J2rFSXwcoB40BDBP4pbGOaeByzYlLs3fzAg7rtBbs=", + "lastModified": 1778817799, + "narHash": "sha256-dO9+Q2P7b9a7ivaNS9bbtkCaDi5eqZpzgIhUzc1iL/Y=", "owner": "maralorn", "repo": "nix-output-monitor", - "rev": "407f0d21bb0360a0d6fd21978be115fcc300b2d4", + "rev": "35823353dd2a4f3c30ef650839c39ee843d85679", "type": "github" }, "original": { @@ -1508,14 +1226,14 @@ }, "ooye": { "inputs": { - "nixpkgs": "nixpkgs_10" + "nixpkgs": "nixpkgs_7" }, "locked": { - "lastModified": 1765676020, - "narHash": "sha256-5t3t7h4s6Qoxp56HPNEKGnk+OTv8FNB/8hxSarCMrAY=", + "lastModified": 1777734248, + "narHash": "sha256-+jVsr0osin+zDOUrDooe3UaPJq82OEDRXq/qnqoOGUc=", "ref": "refs/heads/master", - "rev": "24128571fba0404572f594e9423f5a81aff87aa4", - "revCount": 24, + "rev": "30602e93bf809d0b9911a5c4678d830580ec1e3a", + "revCount": 26, "type": "git", "url": "https://cgit.rory.gay/nix/OOYE-module.git" }, @@ -1524,43 +1242,51 @@ "url": "https://cgit.rory.gay/nix/OOYE-module.git" } }, - "pre-commit-hooks": { + "pion-webrtc": { "inputs": { - "flake-compat": "flake-compat_5", - "gitignore": "gitignore", + "flake-utils": [ + "spacebar", + "flake-utils" + ], "nixpkgs": [ - "hyprland", + "spacebar", "nixpkgs" ] }, "locked": { - "lastModified": 1750779888, - "narHash": "sha256-wibppH3g/E2lxU43ZQHC5yA/7kIKLGxVEnsnVK1BtRg=", - "owner": "cachix", - "repo": "git-hooks.nix", - "rev": "16ec914f6fb6f599ce988427d9d94efddf25fe6d", + "lastModified": 1774417406, + "narHash": "sha256-0yXitmNAqgbCFY5xeg10P83h1ExcjLKKOtpxZ6LtmTg=", + "owner": "spacebarchat", + "repo": "pion-webrtc", + "rev": "f69636f4fb3a08c94df68c509302def0cc6cc864", "type": "github" }, "original": { - "owner": "cachix", - "repo": "git-hooks.nix", + "owner": "spacebarchat", + "repo": "pion-webrtc", "type": "github" } }, - "rocksdb": { - "flake": false, + "pre-commit-hooks": { + "inputs": { + "flake-compat": "flake-compat_3", + "gitignore": "gitignore", + "nixpkgs": [ + "hyprland", + "nixpkgs" + ] + }, "locked": { - "lastModified": 1752084860, - "narHash": "sha256-mKh6zsmxsiUix4LX+npiytmKvLbo6WNA9y4Ns/EY+bE=", - "owner": "facebook", - "repo": "rocksdb", - "rev": "410c5623195ecbe4699b9b5a5f622c7325cec6fe", + "lastModified": 1771858127, + "narHash": "sha256-Gtre9YoYl3n25tJH2AoSdjuwcqij5CPxL3U3xysYD08=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "49bbbfc218bf3856dfa631cead3b052d78248b83", "type": "github" }, "original": { - "owner": "facebook", - "ref": "v10.4.2", - "repo": "rocksdb", + "owner": "cachix", + "repo": "git-hooks.nix", "type": "github" } }, @@ -1569,13 +1295,9 @@ "botcore-v4": "botcore-v4", "cgit-magenta": "cgit-magenta", "conduit": "conduit", - "drasl": "drasl", "draupnirSrc": "draupnirSrc", - "ffmpegSrc": "ffmpegSrc", "flake-utils": "flake-utils_3", - "grapevine": "grapevine", "home-manager": "home-manager", - "hy3": "hy3", "hyprland": "hyprland", "lix": "lix", "lix-module": "lix-module", @@ -1583,10 +1305,11 @@ "mtxclientSrc": "mtxclientSrc", "nhekoSrc": "nhekoSrc", "nix-jetbrains-plugins": "nix-jetbrains-plugins", - "nixpkgs": "nixpkgs_9", + "nixpkgs": "nixpkgs_6", "nixpkgs-RoryNix": "nixpkgs-RoryNix", "nixpkgs-master": "nixpkgs-master", - "nixpkgs-stable": "nixpkgs-stable_3", + "nixpkgs-override-draupnir": "nixpkgs-override-draupnir", + "nixpkgs-stable": "nixpkgs-stable_2", "nom": "nom", "ooye": "ooye", "sops-nix": "sops-nix", @@ -1611,33 +1334,16 @@ "type": "github" } }, - "rust-analyzer-src_2": { - "flake": false, - "locked": { - "lastModified": 1752913824, - "narHash": "sha256-kRpDlijAr4p5VmcPSRw2mfhaBZ4cE3EDWzqLDIbASgA=", - "owner": "rust-lang", - "repo": "rust-analyzer", - "rev": "ed193af36937d2fd4bb14a815ec589875c5c7304", - "type": "github" - }, - "original": { - "owner": "rust-lang", - "ref": "nightly", - "repo": "rust-analyzer", - "type": "github" - } - }, "sops-nix": { "inputs": { - "nixpkgs": "nixpkgs_11" + "nixpkgs": "nixpkgs_8" }, "locked": { - "lastModified": 1768104471, - "narHash": "sha256-HdnXWQsA1EI27IJlaENUEEug58trUrh6+MT0cFiDHmY=", + "lastModified": 1777944972, + "narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=", "owner": "Mic92", "repo": "sops-nix", - "rev": "94f9cbd20f680ebb2ad6cdf39da97cbcfaedf004", + "rev": "c591bf665727040c6cc5cb409079acb22dcce33c", "type": "github" }, "original": { @@ -1648,15 +1354,16 @@ }, "spacebar": { "inputs": { - "flake-utils": "flake-utils_8", - "nixpkgs": "nixpkgs_12" + "flake-utils": "flake-utils_6", + "nixpkgs": "nixpkgs_9", + "pion-webrtc": "pion-webrtc" }, "locked": { - "lastModified": 1769063729, - "narHash": "sha256-qKl8E9Y0PNjtNMEJtPbNkdl3xtr6y7L5lTO8ezgIm4U=", + "lastModified": 1781766293, + "narHash": "sha256-IkZQ7q6sFATMxF7jDE4Zm0TJ7oLQnsGWKqMMUARjpxI=", "owner": "spacebarchat", "repo": "server", - "rev": "67318a4e9217e72b0061b0280f8ffbe9c26fc6f8", + "rev": "18dd02f151512a723918c400a2402a993e2ec10e", "type": "github" }, "original": { @@ -1728,21 +1435,6 @@ }, "systems_4": { "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_5": { - "locked": { "lastModified": 1689347949, "narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=", "owner": "nix-systems", @@ -1756,7 +1448,7 @@ "type": "github" } }, - "systems_6": { + "systems_5": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1771,7 +1463,7 @@ "type": "github" } }, - "systems_7": { + "systems_6": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1786,7 +1478,7 @@ "type": "github" } }, - "systems_8": { + "systems_7": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1801,7 +1493,7 @@ "type": "github" } }, - "systems_9": { + "systems_8": { "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -1844,11 +1536,11 @@ ] }, "locked": { - "lastModified": 1751300244, - "narHash": "sha256-PFuv1TZVYvQhha0ac53E3YgdtmLShrN0t4T6xqHl0jE=", + "lastModified": 1761431178, + "narHash": "sha256-xzjC1CV3+wpUQKNF+GnadnkeGUCJX+vgaWIZsnz9tzI=", "owner": "hyprwm", "repo": "xdg-desktop-portal-hyprland", - "rev": "6115f3fdcb2c1a57b4a80a69f3c797e47607b90a", + "rev": "4b8801228ff958d028f588f0c2b911dbf32297f9", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix
index af72a47..d82486e 100755 --- a/flake.nix +++ b/flake.nix
@@ -5,16 +5,18 @@ extra-substituters = [ # private "http://nix-bincache.rory-desktop.local" + "http://nix-bincache.rory-laptop.local" # public - "https://attic.computer.surgery/grapevine" + #"https://attic.computer.surgery/grapevine" "https://hyprland.cachix.org" "https://nix-bincache.rory.gay" ]; extra-trusted-public-keys = [ "nix-bincache.rory-desktop.local:LDcVGNQoaprWeggWcRE1N0jjEqdjOR1D0kOI3fZne24=" - "grapevine:nYiZ0Qz9nT7Y7kNC/2NdoS3+J9gwTyWxOvlwZnFgceA=" + #"grapevine:nYiZ0Qz9nT7Y7kNC/2NdoS3+J9gwTyWxOvlwZnFgceA=" "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc=" "nix-bincache.rory.gay:663PIW8xxgIImxLcsokODWI2PHFWXvzJEfjX6TaIjxQ=" + "nix-bincache.rory-laptop.local:IbXbNC8ok5YYj9HKYU/5GCec5HE/aixgW/+3sRHP2nE=" ]; }; @@ -30,10 +32,10 @@ }; # Draupnir module/package - #nixpkgs-override-synapse.url = "github:teutat3s/nixpkgs/matrix-synapse-1.136.0"; -# nixpkgs-override-draupnir.url = "github:NixOS/nixpkgs/master"; -# nixpkgs-override-draupnir.url = "github:r-ryantm/nixpkgs/auto-update/draupnir"; -# nixpkgs-override-jetbrains.url = "github:TheArcaneBrony/nixpkgs/jetbrains-2025-4"; + # nixpkgs-override-synapse.url = "github:teutat3s/nixpkgs/matrix-synapse-1.136.0"; + nixpkgs-override-draupnir.url = "github:NixOS/nixpkgs/master"; + # nixpkgs-override-draupnir.url = "github:r-ryantm/nixpkgs/auto-update/draupnir"; + # nixpkgs-override-jetbrains.url = "github:theCapypara/nixpkgs/jetbrains/update-26.1-ssl"; # Base modules home-manager.url = "github:nix-community/home-manager/master"; @@ -42,12 +44,12 @@ nix-jetbrains-plugins.url = "github:nix-community/nix-jetbrains-plugins"; # Packages - grapevine.url = "gitlab:matrix/grapevine-fork?host=gitlab.computer.surgery"; + #grapevine.url = "gitlab:matrix/grapevine-fork?host=gitlab.computer.surgery"; conduit.url = "gitlab:famedly/conduit/next"; - drasl = { - url = "github:unmojang/drasl"; - inputs.nixpkgs.follows = "nixpkgs"; - }; + #drasl = { + # url = "github:unmojang/drasl"; + # inputs.nixpkgs.follows = "nixpkgs"; + #}; # - AUR imports # aur-visual-paradigm = { # url = "git+https://aur.archlinux.org/visual-paradigm.git"; @@ -104,10 +106,10 @@ flake = false; }; - ffmpegSrc = { - url = "git+https://git.ffmpeg.org/ffmpeg.git"; - flake = false; - }; + #ffmpegSrc = { + # url = "git+https://git.ffmpeg.org/ffmpeg.git"; + # flake = false; + #}; draupnirSrc = { url = "github:the-draupnir-project/Draupnir/main"; @@ -119,11 +121,14 @@ flake = false; }; - hyprland.url = "git+https://github.com/hyprwm/Hyprland?submodules=1&ref=refs/tags/v0.50.1"; - hy3 = { - url = "github:outfoxxed/hy3?ref=hl0.50.0"; - inputs.hyprland.follows = "hyprland"; + hyprland = { + url = "git+https://github.com/hyprwm/Hyprland?submodules=1&ref=refs/tags/v0.54.0"; + inputs.nixpkgs.follows = "nixpkgs"; }; + #hy3 = { + # url = "github:outfoxxed/hy3?ref=hl0.53.3"; + # inputs.hyprland.follows = "hyprland"; + #}; }; @@ -150,8 +155,8 @@ home-manager.nixosModules.home-manager lix-module.nixosModules.default - grapevine.nixosModules.default - drasl.nixosModules.drasl + #grapevine.nixosModules.default + #drasl.nixosModules.drasl ooye.modules.default ( @@ -178,7 +183,7 @@ specialArgs = { inherit botcore-v4; inherit home-manager; - inherit grapevine; + #inherit grapevine; inherit conduit; #inherit nixpkgs-Draupnir; #inherit nixpkgs-DraupnirPkg; @@ -291,7 +296,7 @@ ./packages/overlays/lldb.nix ( - { ... }: + { pkgs, ... }: { nix = { registry.nixpkgs.flake = nixpkgs; @@ -306,7 +311,8 @@ inherit (inputs) mtxclientSrc; inherit (inputs) nhekoSrc; inherit hyprland; - inherit hy3; + inherit (inputs) nom; + inherit (inputs) nix-jetbrains-plugins; }; }; @@ -338,6 +344,29 @@ }; }; + AspireTC705 = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./host/AspireTC705/configuration.nix + ./hardware-configuration.nix + home-manager.nixosModules.home-manager + ( + { ... }: + { + nix = { + registry.nixpkgs.flake = nixpkgs; + nixPath = [ "nixpkgs=${nixpkgs.outPath}" ]; + }; + } + ) + ]; + specialArgs = { + inherit home-manager; + inherit nixpkgs-stable; + inherit (inputs) nom; + }; + }; + Rory-portable = nixpkgs.lib.nixosSystem { system = "x86_64-linux"; modules = [ @@ -458,7 +487,7 @@ inherit (oldAttrs) src; inherit patches; name = "${oldAttrs.pname}-${oldAttrs.version}"; - hash = "sha256-CKvdWo9/f8Uhi5idgRhyuZwYua6gQzoKz21XNMaXdl0="; + hash = "sha256-RwUsiS6JM5dmqquKVtyaBp67DYZys6Uecy0V6AabTk4="; }; #doInstallCheck = false; @@ -476,8 +505,19 @@ ''; }); - packages.ffmpeg-git = self.inputs.nixpkgs-master.legacyPackages.${system}.ffmpeg-full.overrideAttrs (oldAttrs: rec { - src = ffmpegSrc; + #packages.ffmpeg-git = self.inputs.nixpkgs-master.legacyPackages.${system}.ffmpeg-full.overrideAttrs (oldAttrs: rec { + # src = ffmpegSrc; + # version = "git"; + # patches = []; + #}); + + packages.openrgb-3200 = self.inputs.nixpkgs-master.legacyPackages.${system}.openrgb.overrideAttrs (oldAttrs: rec { + src = pkgs.fetchFromGitLab { + owner = "CalcProgrammer1"; + repo = "OpenRGB"; + rev = "2b7b1b4ddb3db3104a7021dbcf44a2a6b24c0f7c"; + hash = "sha256-tQt9Ej04GTYAcHeAwwvD4Idn+5FcZxRjdgMOMjvQj1E="; + }; version = "git"; patches = []; }); diff --git a/host/Arc/configuration.nix b/host/Arc/configuration.nix
index db638e1..4a7ba93 100644 --- a/host/Arc/configuration.nix +++ b/host/Arc/configuration.nix
@@ -12,13 +12,15 @@ args@{ # base imports ../../modules/base-client.nix ../../packages/vim.nix - ../../modules/users/Arci.nix + #../../modules/users/Arci.nix + ../../modules/users/geba.nix # hardware-specific imports #./optional/hardware-specific/nvidia.nix #./optional/gui/x11.nix ./optional/gui/wayland.nix + ./printing.nix ]; boot = { @@ -36,8 +38,9 @@ args@{ }; programs.noisetorch.enable = true; programs.gamemode.enable = true; - users.users.Rory.extraGroups = [ "gamemode" ]; - users.users.Arci.extraGroups = [ "gamemode" ]; + #users.users.Rory.extraGroups = [ "gamemode" ]; + #users.users.Arci.extraGroups = [ "gamemode" ]; + users.users.geba.extraGroups = [ "gamemode" ]; environment.sessionVariables = { ZSH_DISABLE_COMPFIX = "true"; @@ -61,8 +64,8 @@ args@{ services = { displayManager.gdm.enable = true; - displayManager.lightdm.enable = false; xserver = { + displayManager.lightdm.enable = false; enable = true; updateDbusEnvironment = true; xkb.layout = "us"; @@ -92,12 +95,12 @@ args@{ environment.systemPackages = with pkgs; [ eog #mpv - libreoffice + #libreoffice qt6.qtwayland #easyeffects kitty - #youtube-music + #pear-desktop jetbrains.rider dbeaver-bin vscode @@ -124,15 +127,16 @@ args@{ firefox-bin #ungoogled-chromium #needed for Rider in order to debug WASM + google-chrome unrar-wrapper #mangohud #prismlauncher #vesktop #mindustry - thunderbird + #thunderbird - blueman - ft2-clone + #blueman + #ft2-clone (callPackage ../../packages/nheko-git.nix { inherit nhekoSrc; @@ -143,7 +147,7 @@ args@{ programs.steam = { enable = false; - gamescopeSession.enable = true; + gamescopeSession.enable = false; extraCompatPackages = with pkgs; [ steam-play-none proton-ge-bin @@ -221,8 +225,8 @@ args@{ #}; # }; - virtualisation.libvirtd.enable = true; - programs.virt-manager.enable = true; + virtualisation.libvirtd.enable = false; + programs.virt-manager.enable = false; monitoring = { monitorAll = false; @@ -238,7 +242,7 @@ args@{ services.gvfs.enable = true; zramSwap = { enable = true; - memoryPercent = 200; + memoryPercent = 300; }; services.pcscd.enable = true; diff --git a/host/Arc/optional/gui/wayland.nix b/host/Arc/optional/gui/wayland.nix
index f3bc56d..639906f 100644 --- a/host/Arc/optional/gui/wayland.nix +++ b/host/Arc/optional/gui/wayland.nix
@@ -52,6 +52,8 @@ virt-viewer keepassxc networkmanagerapplet + mpv + #obs-studio ]; #environment.etc."hyprPlugins" = { diff --git a/host/Rory-laptop/printing.nix b/host/Arc/printing.nix
index 4f86347..4f86347 100644 --- a/host/Rory-laptop/printing.nix +++ b/host/Arc/printing.nix
diff --git a/host/AspireTC705/configuration.nix b/host/AspireTC705/configuration.nix new file mode 100644
index 0000000..06296a3 --- /dev/null +++ b/host/AspireTC705/configuration.nix
@@ -0,0 +1,205 @@ +args@{ + config, + pkgs, + lib, + nhekoSrc, + mtxclientSrc, + ... +}: + +{ + imports = [ + # base imports + ../../modules/base-client.nix + ../../packages/vim.nix + ../../modules/users/geba.nix + ../../modules/software-templates/eid-mw.nix + + ./printing.nix + ]; + + boot = { + kernelPackages = pkgs.linuxPackages_latest; + loader = { + grub = { + configurationLimit = 10; + enable = true; + device = "nodev"; # nodev for EFI only + # EFI + efiSupport = true; + efiInstallAsRemovable = true; + }; + }; + }; + programs.noisetorch.enable = true; + programs.gamemode.enable = true; + users.users.geba.extraGroups = [ "gamemode" ]; + + environment.sessionVariables = { + ZSH_DISABLE_COMPFIX = "true"; + }; + + networking = { + hostName = "AspireTC705"; + networkmanager.enable = true; + wireless.enable = true; + firewall = { + enable = false; + # allowedTCPPorts = [ ... ]; + # allowedUDPPorts = [ ... ]; + }; + + #useDHCP = true; # Doesn't work with NetworkManager, investigate + }; + + time.timeZone = "Europe/Brussels"; + i18n.defaultLocale = "en_US.UTF-8"; + + services = { + displayManager.gdm.enable = true; + xserver = { + displayManager.lightdm.enable = false; + enable = true; + updateDbusEnvironment = true; + xkb.layout = "us"; + }; + libinput.enable = true; + + openssh = { + enable = true; + extraConfig = '' + MaxAuthTries 32 + ''; + settings.PermitRootLogin = "yes"; + }; + pipewire = { + enable = true; + audio.enable = true; + pulse.enable = true; + wireplumber.enable = true; + jack.enable = true; + alsa.enable = true; + }; + + desktopManager.plasma6.enable = true; + }; + + services.desktopManager.gnome.enable = false; + environment.systemPackages = with pkgs; [ + anydesk + eog + libreoffice + qt6.qtwayland + + easyeffects + kitty + vscode + + # - Utilities + #inkscape-with-extensions + gimp + + # - Languages + steam-run + file-roller + + google-chrome + unrar-wrapper + keepassxc + thunderbird + + blueman + # Wrapper script to tell to Chrome/Chromium to use p11-kit-proxy to load + # security devices, so they can be used for TLS client auth. + # Each user needs to run this themselves, it does not work on a system level + # due to a bug in Chromium: + # + # https://bugs.chromium.org/p/chromium/issues/detail?id=16387 + (pkgs.writeShellScriptBin "setup-browser-eid" '' + NSSDB="''${HOME}/.pki/nssdb" + mkdir -p ''${NSSDB} + + ${pkgs.nssTools}/bin/modutil -force -dbdir sql:$NSSDB -add p11-kit-proxy \ + -libfile ${pkgs.p11-kit}/lib/p11-kit-proxy.so + '') + ]; + + programs.steam = { + enable = false; + gamescopeSession.enable = false; + extraCompatPackages = with pkgs; [ + steam-play-none + proton-ge-bin + ]; + }; + virtualisation.waydroid.enable = false; + + xdg = { + portal = { + enable = true; + extraPortals = with pkgs; [ + #xdg-desktop-portal-gtk + xdg-desktop-portal-xapp + # (callPackage ../../modules/packages/xdg-desktop-portal-gtk.nix { }) + ]; + config = { + common = { + default = [ "gtk" ]; + }; + }; + xdgOpenUsePortal = true; + }; + #sounds.enable = true; + #mime.enable = true; + #menus.enable = true; + #icons.enable = true; + #autostart.enable = true; + }; + + nixpkgs = { + config = { + allowUnfree = true; + permittedInsecurePackages = [ + "electron-25.9.0" + "olm-3.2.16" + "dotnet-sdk-wrapped-7.0.410" + "dotnet-sdk-7.0.410" + ]; + }; + }; + security = { + polkit.enable = true; + sudo.wheelNeedsPassword = false; + }; + + hardware = { + pulseaudio.enable = false; + }; + + programs.dconf.enable = true; + services.power-profiles-daemon.enable = true; + + + services.gvfs.enable = true; + zramSwap = { + enable = true; + memoryPercent = 300; + }; + services.pcscd.enable = true; + + virtualisation.vmVariant = { + users = { + mutableUsers = false; + users.Rory.password = "password"; + }; + networking.interfaces.enp34s0 = lib.mkForce { }; + }; + + system.stateVersion = "24.11"; # DO NOT EDIT! + system.activationScripts.web-eid-app = { + text = '' + mkdir -p /usr/lib/x86_64-linux-gnu + ln -sf ${pkgs.eid-mw}/lib/pkcs11/beidpkcs11.so /usr/lib/x86_64-linux-gnu/libbeidpkcs11.so.0 + ''; +}; +} diff --git a/host/AspireTC705/hooks/post-rebuild.sh b/host/AspireTC705/hooks/post-rebuild.sh new file mode 100755
index 0000000..30733ad --- /dev/null +++ b/host/AspireTC705/hooks/post-rebuild.sh
@@ -0,0 +1,7 @@ +#!/usr/bin/env sh +set -x + +git restore --staged hardware-configuration.nix +git restore --staged Ran.ca +git restore --staged modules/opensuse/ +git restore --staged opensuse/ \ No newline at end of file diff --git a/host/AspireTC705/hooks/pre-rebuild.sh b/host/AspireTC705/hooks/pre-rebuild.sh new file mode 100755
index 0000000..d4ec9d3 --- /dev/null +++ b/host/AspireTC705/hooks/pre-rebuild.sh
@@ -0,0 +1,7 @@ +#!/usr/bin/env sh +set -x + +git add -f hardware-configuration.nix +git add -f Ran.ca +git add -f modules/opensuse/ +git add -f opensuse/ \ No newline at end of file diff --git a/host/AspireTC705/optional/hardware-specific/amd.nix b/host/AspireTC705/optional/hardware-specific/amd.nix new file mode 100644
index 0000000..e4758a6 --- /dev/null +++ b/host/AspireTC705/optional/hardware-specific/amd.nix
@@ -0,0 +1,42 @@ +{ + config, + pkgs, + lib, + nhekoSrc, + mtxclientSrc, + ... +}: + +{ + imports = [ ]; + + boot.initrd.kernelModules = [ "amdgpu" ]; + + services = { + xserver = { + windowManager.i3.extraSessionCommands = '' + xrandr --output HDMI-1 --mode 3840x2160 --pos 0x0 --rotate normal --primary --output DP-1 --mode 1920x1080 --pos 3840x1080 --rotate normal --output HDMI-2 --off --output DP-2 --off + ''; + wacom.enable = true; + }; + picom.backend = "glx"; + }; + + environment.systemPackages = with pkgs; [ + rocmPackages.rocm-smi # useful to have + ]; + + hardware = { + graphics = { + enable = true; + enable32Bit = true; + extraPackages = with pkgs; [ + rocmPackages.clr.icd + #amdvlk + ]; + #extraPackages32 = with pkgs; [ driversi686Linux.amdvlk ]; + }; + }; + + systemd.tmpfiles.rules = [ "L+ /opt/rocm/hip - - - - ${pkgs.rocmPackages.clr}" ]; +} diff --git a/host/AspireTC705/optional/hardware-specific/nvidia.nix b/host/AspireTC705/optional/hardware-specific/nvidia.nix new file mode 100644
index 0000000..1f98541 --- /dev/null +++ b/host/AspireTC705/optional/hardware-specific/nvidia.nix
@@ -0,0 +1,40 @@ +{ + config, + pkgs, + lib, + nhekoSrc, + mtxclientSrc, + ... +}: + +{ + imports = [ + + ]; + + services = { + xserver = { + #videoDrivers = [ "nvidia" ]; + #windowManager.i3.extraSessionCommands = '' + # todo: restore + #''; + }; + picom.backend = "glx"; + }; + + hardware = { + graphics = { + enable = true; + }; + + nvidia = { + modesetting.enable = true; + powerManagement.enable = false; + powerManagement.finegrained = false; + open = true; + nvidiaSettings = true; + nvidiaPersistenced = true; + package = config.boot.kernelPackages.nvidiaPackages.stable; + }; + }; +} diff --git a/host/AspireTC705/printing.nix b/host/AspireTC705/printing.nix new file mode 100644
index 0000000..4f86347 --- /dev/null +++ b/host/AspireTC705/printing.nix
@@ -0,0 +1,54 @@ +{ pkgs, ... }: + +{ + imports = [ ]; + + users.users = { + Rory = { + extraGroups = [ + "lp" + "scanner" + ]; + }; + }; + + environment.systemPackages = with pkgs; [ + xsane + simple-scan + ]; + + hardware = { + sane.enable = true; + sane.extraBackends = [ + pkgs.hplipWithPlugin + pkgs.sane-airscan + ]; + }; + + programs.system-config-printer.enable = true; + + services = { + gvfs.enable = true; + saned.enable = true; + system-config-printer.enable = true; + ipp-usb.enable = true; + printing = { + enable = true; + browsing = true; + drivers = with pkgs; [ hplip ]; + }; + avahi = { + enable = true; + nssmdns4 = true; + reflector = true; + publish = { + workstation = true; + userServices = true; + hinfo = true; + enable = true; + domain = true; + addresses = true; + }; + }; + }; +} diff --git a/host/Rory-NTFS/configuration.nix b/host/Rory-NTFS/configuration.nix
index 47d4497..1e6502d 100644 --- a/host/Rory-NTFS/configuration.nix +++ b/host/Rory-NTFS/configuration.nix
@@ -104,7 +104,7 @@ feh easyeffects kitty - #youtube-music + #pear-desktop # - IDEs #jetbrains-toolbox diff --git a/host/Rory-desktop/configuration.nix b/host/Rory-desktop/configuration.nix
index 903bc60..20078d9 100644 --- a/host/Rory-desktop/configuration.nix +++ b/host/Rory-desktop/configuration.nix
@@ -19,6 +19,8 @@ args@{ ../../modules/software-templates/eid-mw.nix ../../modules/software-templates/devenv/dotnet.nix ../../modules/software-templates/devenv/javascript.nix + ../../modules/software-templates/devenv/go.nix + ../../modules/software-templates/devenv/java.nix ./services/nginx.nix ./services/postgres.nix @@ -29,7 +31,7 @@ args@{ ./optional/gui/hyprland.nix ./services/libvirt.nix -# ./services/rabbitmq.nix + # ./services/rabbitmq.nix #./services/edu/mongodb.nix #./optional/gui/x11.nix ./services/printing.nix @@ -42,7 +44,11 @@ args@{ boot = { kernelPackages = pkgs.linuxPackages_latest; - binfmt.emulatedSystems = [ "aarch64-linux" "riscv64-linux" "riscv32-linux" ]; + binfmt.emulatedSystems = [ + "aarch64-linux" + "riscv64-linux" + "riscv32-linux" + ]; loader = { grub = { configurationLimit = 10; @@ -58,7 +64,7 @@ args@{ }; # TODO: re-enable when USB is fixed - #programs.noisetorch.enable = true; + programs.noisetorch.enable = true; programs.gamemode.enable = true; users.users.Rory.extraGroups = [ "gamemode" ]; @@ -133,7 +139,7 @@ args@{ feh easyeffects kitty - youtube-music + pear-desktop dbeaver-bin #insomnia @@ -185,6 +191,8 @@ args@{ ffmpeg intiface-central wine64Packages.waylandFull + ft2-clone + luanti ]; hardware = { @@ -236,6 +244,7 @@ args@{ enableGhostscriptFonts = lib.mkForce false; }; + nix.settings.auto-optimise-store = lib.mkForce false; nixpkgs = { config = { allowUnfree = true; @@ -270,6 +279,10 @@ args@{ nginxHost = "monitoring.localhost"; nginxSsl = false; }; + + systemd.services."grafana".serviceConfig.LoadCredential = [ + "secret_key:/data/secrets/grafana-secret-key" + ]; networking.hosts."127.0.0.1" = builtins.attrNames config.services.nginx.virtualHosts; @@ -306,7 +319,29 @@ args@{ ]; }; - + services.prometheus.scrapeConfigs = [ + { + job_name = "spacebar-dev-api"; + scrape_interval = "${toString config.monitoring.prometheusScrapeInterval}s"; + static_configs = [ + { targets = [ "localhost:3001" ]; } + ]; + } + { + job_name = "spacebar-dev-gateway"; + scrape_interval = "${toString config.monitoring.prometheusScrapeInterval}s"; + static_configs = [ + { targets = [ "localhost:3002" ]; } + ]; + } + { + job_name = "spacebar-dev-cdn"; + scrape_interval = "${toString config.monitoring.prometheusScrapeInterval}s"; + static_configs = [ + { targets = [ "localhost:3003" ]; } + ]; + } + ]; console = { earlySetup = true; diff --git a/host/Rory-desktop/optional/gui/hyprland.nix b/host/Rory-desktop/optional/gui/hyprland.nix
index 22fca5b..e8b62ff 100644 --- a/host/Rory-desktop/optional/gui/hyprland.nix +++ b/host/Rory-desktop/optional/gui/hyprland.nix
@@ -8,7 +8,7 @@ { programs.hyprland = { enable = true; -# package = hyprland.packages.${pkgs.stdenv.hostPlatform.system}.hyprland; + #package = hyprland.packages.${pkgs.stdenv.hostPlatform.system}.hyprland; }; programs.hyprlock.enable = true; @@ -20,6 +20,9 @@ slurp easyeffects keepassxc + hyprpaper + hyprpolkitagent + hyprpaper ]; #environment.etc."hyprPlugins" = { diff --git a/host/Rory-laptop/configuration.nix b/host/Rory-laptop/configuration.nix
index fa392ce..0fa9bc6 100644 --- a/host/Rory-laptop/configuration.nix +++ b/host/Rory-laptop/configuration.nix
@@ -16,22 +16,26 @@ args@{ # ../../modules/environments/home.nix ../../modules/environments/nethost-Rory-desktop.nix #../../modules/software-templates/profilers.nix - ../../modules/software-templates/dotnet.client.nix - ./postgres.nix - ./nginx.nix - - #./edu/vmware.nix - #./edu/nodejs-dev.nix + ../../modules/software-templates/eid-mw.nix + ../../modules/software-templates/devenv/dotnet.nix + ../../modules/software-templates/devenv/javascript.nix + ./services/nix-bincache.nix # hardware-specific imports #./optional/hardware-specific/nvidia.nix - ./optional/hardware-specific/intel.nix + #./optional/hardware-specific/intel.nix ./optional/gui/wayland.nix + ./services/nginx.nix ]; boot = { kernelPackages = pkgs.linuxPackages_latest; + blacklistedKernelModules = [ + "nova" + "nova_core" + "nouveau" + ]; loader = { grub = { configurationLimit = 10; @@ -56,7 +60,7 @@ args@{ networking = { hostName = "Rory-laptop"; networkmanager.enable = true; - wireless.enable = false; + wireless.enable = true; firewall = { enable = false; # allowedTCPPorts = [ ... ]; @@ -121,25 +125,9 @@ args@{ feh easyeffects kitty - youtube-music + pear-desktop # - IDEs - - (jetbrains.plugins.addPlugins jetbrains.webstorm [ - jetbrains.plugins.github-copilot-fixed - #"github-copilot" - ]) - (jetbrains.plugins.addPlugins jetbrains.idea-ultimate [ - jetbrains.plugins.github-copilot-fixed - #"github-copilot" - ]) - (jetbrains.plugins.addPlugins jetbrains.clion [ - jetbrains.plugins.github-copilot-fixed - #"github-copilot" - "stringmanipulation" - "nixidea" - "visual-studio-keymap" - ]) binutils dbeaver-bin @@ -151,10 +139,10 @@ args@{ # - Languages #dotnet-sdk_8 - dotnetCorePackages.sdk_9_0 + #dotnetCorePackages.sdk_9_0 #games - osu-lazer-bin + # osu-lazer-bin # extra packages dmenu @@ -192,10 +180,10 @@ args@{ jitsi-meet-electron # nixd # broken 24/03/2025 - mullvad-vpn + # mullvad-vpn blueman ft2-clone - wxmaxima + # wxmaxima ]; environment.etc."pkcs11/modules/opensc-pkcs11".text = '' module: ${pkgs.opensc}/lib/opensc-pkcs11.so @@ -259,7 +247,7 @@ args@{ # #services.orca.enable = true; - virtualisation.waydroid.enable = true; + #virtualisation.waydroid.enable = true; xdg = { portal = { @@ -336,16 +324,16 @@ args@{ # }; virtualisation.libvirtd = { - enable = true; + enable = false; qemu = { swtpm.enable = true; - ovmf.enable = true; + #ovmf.enable = true; }; }; programs.virt-manager.enable = true; monitoring = { - monitorAll = true; + monitorAll = false; localPrometheus = true; exposePrometheus = true; localGrafana = true; diff --git a/host/Rory-laptop/optional/gui/wayland.nix b/host/Rory-laptop/optional/gui/wayland.nix
index c980a85..e90f719 100644 --- a/host/Rory-laptop/optional/gui/wayland.nix +++ b/host/Rory-laptop/optional/gui/wayland.nix
@@ -47,14 +47,14 @@ programs.hyprlock.enable = true; environment.systemPackages = with pkgs; [ wmenu - kdePackages.xwaylandvideobridge +# kdePackages.xwaylandvideobridge ]; - environment.etc."hyprPlugins" = { - text = '' - plugin = ${hy3.packages.${pkgs.stdenv.hostPlatform.system}.hy3}/lib/libhy3.so - ''; - }; +# environment.etc."hyprPlugins" = { +# text = '' +# plugin = ${hy3.packages.${pkgs.stdenv.hostPlatform.system}.hy3}/lib/libhy3.so +# ''; +# }; xdg.portal.wlr.enable = true; } diff --git a/host/Rory-laptop/mariadb.nix b/host/Rory-laptop/services/mariadb.nix
index 758cb3d..758cb3d 100644 --- a/host/Rory-laptop/mariadb.nix +++ b/host/Rory-laptop/services/mariadb.nix
diff --git a/host/Rory-laptop/nginx.nix b/host/Rory-laptop/services/nginx.nix
index c247044..720b0a8 100644 --- a/host/Rory-laptop/nginx.nix +++ b/host/Rory-laptop/services/nginx.nix
@@ -11,7 +11,7 @@ enable = true; recommendedProxySettings = true; #recommendedTlsSettings = true; - recommendedZstdSettings = true; + #recommendedZstdSettings = true; # recommendedGzipSettings = true; recommendedBrotliSettings = true; recommendedOptimisation = true; @@ -31,7 +31,7 @@ virtualHosts = { "discord.localhost" = import ./nginx/discord.localhost.nix { inherit pkgs; }; "hse.localhost" = import ./nginx/hse.localhost.nix { inherit pkgs; }; - + "nix-bincache.rory-laptop.local" = import ./nginx/nix-bincache.nix { inherit config; }; }; }; }; diff --git a/host/Rory-laptop/nginx/discord.localhost.nix b/host/Rory-laptop/services/nginx/discord.localhost.nix
index b40e13c..b40e13c 100644 --- a/host/Rory-laptop/nginx/discord.localhost.nix +++ b/host/Rory-laptop/services/nginx/discord.localhost.nix
diff --git a/host/Rory-laptop/nginx/hse.localhost.nix b/host/Rory-laptop/services/nginx/hse.localhost.nix
index c3c1731..c3c1731 100755 --- a/host/Rory-laptop/nginx/hse.localhost.nix +++ b/host/Rory-laptop/services/nginx/hse.localhost.nix
diff --git a/host/Rory-laptop/services/nginx/nix-bincache.nix b/host/Rory-laptop/services/nginx/nix-bincache.nix new file mode 100644
index 0000000..29ffc4d --- /dev/null +++ b/host/Rory-laptop/services/nginx/nix-bincache.nix
@@ -0,0 +1,12 @@ +{ config }: +{ + locations."/" = { + proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}"; + extraConfig = '' + allow 10.0.0.0/8; + allow 192.168.0.0/16; + allow 127.0.0.0/8; + deny all; + ''; + }; +} diff --git a/host/Rory-laptop/services/nix-bincache.nix b/host/Rory-laptop/services/nix-bincache.nix new file mode 100644
index 0000000..811ca63 --- /dev/null +++ b/host/Rory-laptop/services/nix-bincache.nix
@@ -0,0 +1,11 @@ +{ pkgs, ... }: + +{ + services.nix-serve = { + enable = true; + package = pkgs.nix-serve-ng; + port = 3642; + bindAddress = "127.0.0.1"; + secretKeyFile = "/data/secrets/nix-bincache-priv-key.pem"; + }; +} diff --git a/host/Rory-laptop/ollama.nix b/host/Rory-laptop/services/ollama.nix
index b1b0a7a..b1b0a7a 100644 --- a/host/Rory-laptop/ollama.nix +++ b/host/Rory-laptop/services/ollama.nix
diff --git a/host/Rory-laptop/postgres.nix b/host/Rory-laptop/services/postgres.nix
index c201b04..c201b04 100644 --- a/host/Rory-laptop/postgres.nix +++ b/host/Rory-laptop/services/postgres.nix
diff --git a/host/Rory-laptop/services/printing.nix b/host/Rory-laptop/services/printing.nix new file mode 100644
index 0000000..4f86347 --- /dev/null +++ b/host/Rory-laptop/services/printing.nix
@@ -0,0 +1,54 @@ +{ pkgs, ... }: + +{ + imports = [ ]; + + users.users = { + Rory = { + extraGroups = [ + "lp" + "scanner" + ]; + }; + }; + + environment.systemPackages = with pkgs; [ + xsane + simple-scan + ]; + + hardware = { + sane.enable = true; + sane.extraBackends = [ + pkgs.hplipWithPlugin + pkgs.sane-airscan + ]; + }; + + programs.system-config-printer.enable = true; + + services = { + gvfs.enable = true; + saned.enable = true; + system-config-printer.enable = true; + ipp-usb.enable = true; + printing = { + enable = true; + browsing = true; + drivers = with pkgs; [ hplip ]; + }; + avahi = { + enable = true; + nssmdns4 = true; + reflector = true; + publish = { + workstation = true; + userServices = true; + hinfo = true; + enable = true; + domain = true; + addresses = true; + }; + }; + }; +} diff --git a/host/Rory-nginx/services/containers/shared.nix b/host/Rory-nginx/services/containers/shared.nix
index f267ff0..c617e2b 100644 --- a/host/Rory-nginx/services/containers/shared.nix +++ b/host/Rory-nginx/services/containers/shared.nix
@@ -1,7 +1,7 @@ { pkgs, ... }: { environment.systemPackages = with pkgs; [ - neofetch + fastfetch lnav zsh git diff --git a/host/Rory-ovh/configuration.nix b/host/Rory-ovh/configuration.nix
index ac9add5..4acf6ce 100755 --- a/host/Rory-ovh/configuration.nix +++ b/host/Rory-ovh/configuration.nix
@@ -17,6 +17,7 @@ ../../modules/users/Alice.nix ./services/prometheus.nix + ./spacebar-monitoring.nix ./services/nginx/nginx.nix ./services/nix-bincache.nix @@ -27,8 +28,9 @@ ./services/matrix/ooye.nix ./services/email/root.nix ./services/drasl.nix + #./services/prosody.nix #./services/wireguard/wireguard.nix - ../../modules/software-templates/devenv/dotnet.nix + #../../modules/software-templates/devenv/dotnet.nix ]; users.groups.ocp = { }; @@ -38,6 +40,9 @@ "riscv64-linux" "riscv32-linux" ]; + boot.kernelParams = [ + "vm.nr_hugepages=48000" + ]; networking = { hostName = "Rory-ovh"; nat = { @@ -58,6 +63,9 @@ firewall.allowedTCPPorts = [ 25565 ]; + firewall.allowedUDPPorts = [ + 6000 # Spacebar voice + ]; }; systemd.network = { @@ -120,6 +128,14 @@ ; }; + containers."draupnir-belibre" = import ./services/containers/draupnir-belibre/container.nix { + inherit + pkgs + lib + draupnir + ; + }; + networking.firewall.interfaces."ve-spacebar".allowedTCPPorts = [ 5432 ]; containers."spacebar" = import ./services/containers/spacebar/container.nix { inherit @@ -129,17 +145,25 @@ ; }; + systemd.services."grafana".serviceConfig.LoadCredential = [ + "secret_key:/data/secrets/grafana-secret-key" + ]; # prevent a hang on rebuild with forgotten shells... - systemd.services."container@spacebar" = { + systemd.services."container@spacebar" = + let + mkKillShellScript = ctName: ("+-" + (pkgs.writeScript ("kill-shell-" + ctName) '' + #!/bin/sh + for pid in $(pgrep -f "nixos-container root-login ${ctName}"); do + echo "Killing shell with PID $pid" + kill -9 "$pid" + done + '')); + in + { # dependency on postgres for good measure... after = [ "postgresql.service" ]; wants = [ "postgresql.service" ]; - preStop = '' - for pid in $(pgrep -f "nixos-container root-login spacebar"); do - echo "Killing shell with PID $pid" - kill -9 "$pid" - done - ''; + serviceConfig.ExecStop = (mkKillShellScript "spacebar"); }; #containers."syntest1" = import ./services/containers/syntest1/container.nix { diff --git a/host/Rory-ovh/services/containers/draupnir-ansible/services/draupnir.nix b/host/Rory-ovh/services/containers/draupnir-ansible/services/draupnir.nix
index ef76500..93ba3f9 100644 --- a/host/Rory-ovh/services/containers/draupnir-ansible/services/draupnir.nix +++ b/host/Rory-ovh/services/containers/draupnir-ansible/services/draupnir.nix
@@ -22,7 +22,13 @@ protections = { wordlist = { - words = [ "https://postimg.cc/" ]; + words = [ + "https://postimg.cc/" + "lolitaheaven.onrender.com" + "heavenlychat-px42.onrender.com" + "heavenlydev.onrender.com" + "Adolf_hipster007" + ]; minutesBeforeTrusting = 0; }; }; diff --git a/host/Rory-ovh/services/containers/draupnir-belibre/container.nix b/host/Rory-ovh/services/containers/draupnir-belibre/container.nix new file mode 100644
index 0000000..09f5606 --- /dev/null +++ b/host/Rory-ovh/services/containers/draupnir-belibre/container.nix
@@ -0,0 +1,29 @@ +{ + draupnir, + ... +}: + +{ + privateNetwork = true; + autoStart = true; + specialArgs = { + inherit draupnir; + }; + config = + { lib, pkgs, ... }: + { + imports = [ + ../shared.nix + ./root.nix + ./services/draupnir.nix + ]; + }; + hostAddress = "192.168.100.1"; + localAddress = "192.168.100.23"; + + bindMounts."draupnir-access-token" = { + hostPath = "/data/secrets/draupnir-belibre-access-token"; + mountPoint = "/etc/draupnir-access-token"; + isReadOnly = true; + }; +} diff --git a/host/Rory-ovh/services/containers/draupnir-belibre/root.nix b/host/Rory-ovh/services/containers/draupnir-belibre/root.nix new file mode 100644
index 0000000..0ebce9e --- /dev/null +++ b/host/Rory-ovh/services/containers/draupnir-belibre/root.nix
@@ -0,0 +1,16 @@ +{ ... }: + +{ + networking.useHostResolvConf = true; + + networking.hosts = { + "192.168.100.1" = [ + "matrix.rory.gay" + "rory.gay" + ]; + }; + + networking.firewall = { + enable = true; + }; +} diff --git a/host/Rory-ovh/services/containers/draupnir-belibre/services/draupnir.nix b/host/Rory-ovh/services/containers/draupnir-belibre/services/draupnir.nix new file mode 100644
index 0000000..917958c --- /dev/null +++ b/host/Rory-ovh/services/containers/draupnir-belibre/services/draupnir.nix
@@ -0,0 +1,67 @@ +{ draupnir, ... }: + +{ + services.draupnir = { + enable = true; + package = draupnir; + secrets.accessToken = "/etc/draupnir-access-token"; + + settings = { + homeserverUrl = "https://matrix.rory.gay"; + managementRoom = "#draupnir-belibre-mgmt:rory.gay"; + recordIgnoredInvites = true; # We want to be aware of invites + autojoinOnlyIfManager = true; # ... but we don't want the bot to be invited to eg. Matrix HQ... + automaticallyRedactForReasons = [ "*" ]; # Always autoredact + fasterMembershipChecks = true; + + backgroundDelayMS = 10; # delay isn't needed, I don't mind the performance hit + pollReports = false; + + admin.enableMakeRoomAdminCommand = false; + commands.ban.defaultReasons = [ "spam" ]; + + protections = { + wordlist = { + words = [ + # The Obvious + "tranny" + "faggot" + "ywnbaw" + "nigger" + # abuse domains + "https://postimg.cc/" + "https://s.binance.com" + # Dec 2025 IRC spam + "irc.hardchats.com" + "white power" + "white pride" + "trannies" + "jews did 9/11" + "zigger" + "|| || <===" + "usurping jews" + "fag hoe" + "neo-freenode" + "thegreatbritishbookshop.co.uk" + "\"israel\"" + "die alone" + "kike" + "irc.tr0ll.us" + "irc.gangste.rs" + "irc.wepump.in" + "death to" + "irc.hackclub.com" + "irc.supernets.org" + "[supernets]" + # Known abuse + "lolitaheaven.onrender.com" + "heavenlychat-px42.onrender.com" + "heavenlydev.onrender.com" + "Adolf_hipster007" + ]; + minutesBeforeTrusting = 0; + }; + }; + }; + }; +} diff --git a/host/Rory-ovh/services/containers/draupnir-fedora/services/draupnir.nix b/host/Rory-ovh/services/containers/draupnir-fedora/services/draupnir.nix
index 0b74984..9a6d219 100644 --- a/host/Rory-ovh/services/containers/draupnir-fedora/services/draupnir.nix +++ b/host/Rory-ovh/services/containers/draupnir-fedora/services/draupnir.nix
@@ -22,7 +22,13 @@ protections = { wordlist = { - words = [ "https://postimg.cc/" ]; + words = [ + "https://postimg.cc/" + "lolitaheaven.onrender.com" + "heavenlychat-px42.onrender.com" + "heavenlydev.onrender.com" + "Adolf_hipster007" + ]; minutesBeforeTrusting = 0; }; }; diff --git a/host/Rory-ovh/services/containers/shared.nix b/host/Rory-ovh/services/containers/shared.nix
index 543e92a..d33356f 100644 --- a/host/Rory-ovh/services/containers/shared.nix +++ b/host/Rory-ovh/services/containers/shared.nix
@@ -34,9 +34,14 @@ services.resolved = { enable = lib.mkForce false; - dnssec = lib.mkForce "false"; - dnsovertls = lib.mkForce "false"; + settings = { + Resolve = { + DNSSEC = lib.mkForce "false"; + DNSOverTLS = lib.mkForce "false"; + }; + }; }; systemd.oomd.enable = false; # Kinda useless in a container, lol + system.stateVersion = "26.05"; # Required to make nix shut up about it } diff --git a/host/Rory-ovh/services/containers/spacebar/container.nix b/host/Rory-ovh/services/containers/spacebar/container.nix
index 3189236..e427abf 100644 --- a/host/Rory-ovh/services/containers/spacebar/container.nix +++ b/host/Rory-ovh/services/containers/spacebar/container.nix
@@ -21,6 +21,19 @@ hostAddress = "192.168.100.1"; localAddress = "192.168.100.22"; + forwardPorts = [ + { + containerPort = 22; + hostPort = 30022; + protocol = "tcp"; + } + { + containerPort = 6000; + hostPort = 6000; + protocol = "udp"; + } + ]; + bindMounts."spacebar-storage" = { hostPath = "/data/dedicated/spacebar-storage"; mountPoint = "/storage"; diff --git a/host/Rory-ovh/services/containers/spacebar/root.nix b/host/Rory-ovh/services/containers/spacebar/root.nix
index 28892d1..7d351c3 100644 --- a/host/Rory-ovh/services/containers/spacebar/root.nix +++ b/host/Rory-ovh/services/containers/spacebar/root.nix
@@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ lib, pkgs, ... }: { networking.useHostResolvConf = true; @@ -16,18 +16,57 @@ 3001 3002 3003 - ]; + 3004 + 3005 + 3006 + ] + ++ (lib.range 3100 3115); + allowedUDPPorts = [ 6000 ]; }; - # check that we can reach the database server before starting the service - systemd.services."spacebar-apply-migrations" = - let - address = "192.168.100.1"; - in - { - path = [ pkgs.netcat pkgs.bash ]; - serviceConfig = { - ExecStartPre = "${pkgs.bash}/bin/sh -c 'sleep 5; until ${pkgs.netcat}/bin/nc -z ${address} 5432; do echo \"Waiting for database server...\"; sleep 0.2; done'"; - }; + services.openssh = { + enable = true; + startWhenNeeded = true; + settings = { + #Banner = /. + (pkgs.writeText "ssh-banner" '' + # Welcome to spacebar.chat! + #''); }; + }; + + users.users.root = { + openssh.authorizedKeys.keys = [ + # chris + #"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMd9U0+wKjBG3Q9Qg249xJY+ybYeRV9/VMPjuwKvFBEI" + + # Rory& + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCpmQMHBFOpLfb0Y138VUK1p4FxEPSOz5FRpDK8/eOFwBmEKDjLnT4d/e/Rz2VknCTSKXLMZ4KBMYM014NW3SZR90cDAFwlkdSX638fQlEO3usfALNLWsLbzqzkufw6PKWqrybZvlpwjcacYlRItvit/GH7FLqfiT/G6BdyBErn/lmmcBxF0So0aeba2G/xf7BPPQqqaTqQgE9ml87fdFVw4zVcix823K92SQIx7PkSInpgJwqjLR8cVkL2lkvMdq6IjAEsHAiUYNbAQTUl6xhYa6+Cl8CdvCyINzCpWS3Md2rSH84dZEq0ymZ40orF9JZbHHPgSGFbrg5PUOuJ57iaCPK20z474q2APUJ7aQXiifToZKqcWHFHCj7hqWja1rEt3rQbqRPgttSg5aP3lQ3GXbR/XhdcSYln1QpPTCBxklrfN1P6hF6lWBtGhtGzOvZ5Lt1uofdsK71k5eMwYHTcBnVaMtxbYzR9ihFN6LCNvvnrj+2NvHOiYSCr+y3G4kk=" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILF2IuNu//0DP/wKMuDvBgVT3YBS2uULsipbdrhJCTM7" + #"ssh-dss AAAAB3NzaC1kc3MAAACBAMoTE3Nr79Bxg6B6SsNZh/XO4yyog7Bahg+ltICfnb9j+EXXt7mTIT5Q+8y+J3CrpRswKLK729QN/u401aqGmp/9gyAsBzpIYqxnurKjqV+6SM7PbvsGAO6YJRefpTbwz1LidUfGYu1Buv1Mg2aP6SxjM7uAz6Km9q4P6flcCegDAAAAFQDJ2BKaq0Dj0UKltXcY8SmyCb5FWQAAAIEAhHLzeD6EV26+y2zhNT+tMcm0Mc8SiJtLJCUGZqpwCkOQwJTgerxW4ri7rj/FQwpo39d7c4IMXKOh3p1g9tei8JvZ23mF7pujupqVVcRfUDJClTZkUFHwvoJSdKaPvXSWdO8E3AAkCpKYcHb3BNak8JwtC0cMRZ4LeCFfizm4WkMAAACBAJMwhnXAXgiY0rg0AZZxo2GLCm7U52u+CXx/LEd13LEYvrs8OoJCI0PjEWOKapNu0/d+iVr7aVTsfATDC/9nVRamUvMbpgGeXDetTvVRhzAy+AFQisxhu/xNM+PrRQSpiBMYQ4UTMnsrfjvTekxLoFH8hT/oDM7KhtomlbZRly2Q thearcanebrony@tab-linux-desktop" + + # samuel + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDxVritRUw3G4SMXxYpZqqkjxBUBVA+VnRcYz8ikt22iqZu0YDfILbfZ20sKF/82/VyEbzTTbTXfydlg5U248rTm93O1uXrg+H6NMqckZsqPYwQjU7+RnUDCgJUSmsTOX1Xm904NAqmjj1OLjFRO7SCJ8R5u98IagwlXzrpQ4rMOeg/HAS4Ki5nM7D0RHiar8csw2kcr3XMUCbSGmevsC+ExomHaTC1hD9r4uhZkbbyURqYGXd6hXRQCeoW3AgVRfpjDxyiYWpz9aCsWQN0iuRQeIbykfACm8Uhq42WPA+QiCifxnJSp6iSRkz1CZLxHcL/ws4sx4Xyx+JQWdBc92T/" + "ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBO2ROpMQH8QFoSP+97lGqf86ybr4OI0ohrGXCE2rAimawussEpYir2igRtF6j4Vw7rD1Jz5XeNgChW+kF4C5DNc=" + + # kino + #"ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAgEAgVEkgeVnatQ1iAsZvQuw1hj1jCAQTObaCF7M0nSf7UrSUWxs+C8s+uvg6HcJiQpRWvNaLtX1xKzAwK3wkqLXQIrOYdRTrm4TEQGdZ8QlUwGOTdpVECEiVEXuYZgiYhBoP35OeskPOcFDtYGHzsBM0ckb71xSI1S4HxmETxGlOl43JZ7SjiMYjtAEN8eqrPxcQB8R4htrxeThRypUMbO2Lc5JmnUK2fEIU3O2xHvL/vpjcBrWK/9GNoUeClWvFqasBBWOcUvPvmBEfymORJX73ELD3lPVbhIUucYQl/471O4xGALrBY6krTM4LHsNm3NG1StMlNM0LeZIy3YTHvo6dtAJJ3zYaLt9BiMpPkw2vllh35b5FSNxgJ9lU1WiM/q5TEvPsUrk5+Pi6SIEt48rejsuYwNJySmy+26ZfNJDh0Gn2S2aZJsXyrTx03t6rfuVptnOY08ZBxaOFE1lxHYOdzHL+/M1U1Z64/lkG1L7yvJtUxYAxJoxku8JenBVWQJMcKzoZDVWnrCKoKeEC8kLRjLWTDHGEq2RFOpaDBxDRYQeTFY2uQMv8F3Sbfd1FY3RF2s6wk1HB+r29skI2StN/PbQNbz57oCYAJvtsirmGoVd5BG4F335rtDENVwzYksUSEh+nKvgdUNKf7+mZg02QeKFoSJ304RLsrDsadBoF7c=" + #"ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAgEAgVEkgeVnatQ1iAsZvQuw1hj1jCAQTObaCF7M0nSf7UrSUWxs+C8s+uvg6HcJiQpRWvNaLtX1xKzAwK3wkqLXQIrOYdRTrm4TEQGdZ8QlUwGOTdpVECEiVEXuYZgiYhBoP35OeskPOcFDtYGHzsBM0ckb71xSI1S4HxmETxGlOl43JZ7SjiMYjtAEN8eqrPxcQB8R4htrxeThRypUMbO2Lc5JmnUK2fEIU3O2xHvL/vpjcBrWK/9GNoUeClWvFqasBBWOcUvPvmBEfymORJX73ELD3lPVbhIUucYQl/471O4xGALrBY6krTM4LHsNm3NG1StMlNM0LeZIy3YTHvo6dtAJJ3zYaLt9BiMpPkw2vllh35b5FSNxgJ9lU1WiM/q5TEvPsUrk5+Pi6SIEt48rejsuYwNJySmy+26ZfNJDh0Gn2S2aZJsXyrTx03t6rfuVptnOY08ZBxaOFE1lxHYOdzHL+/M1U1Z64/lkG1L7yvJtUxYAxJoxku8JenBVWQJMcKzoZDVWnrCKoKeEC8kLRjLWTDHGEq2RFOpaDBxDRYQeTFY2uQMv8F3Sbfd1FY3RF2s6wk1HB+r29skI2StN/PbQNbz57oCYAJvtsirmGoVd5BG4F335rtDENVwzYksUSEh+nKvgdUNKf7+mZg02QeKFoSJ304RLsrDsadBoF7c=" + + # maddy + #"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDOXRjGuFSnbe9zU0gd09SzfCL8JMf4EWVqbj3iAcFYsXeoMCXz5YtLl1kkOeQ3uXT1m8H/zjIRkpn2GbDpD000TBTXyBlzNOVQ23fZOvzMrYl2pX/09VFACF+tCTMxy1YsJur3ka9uwLlsmMqvSl0YZt6bN6RfEglGMEPuBfTm1EFo7MhXhUPnGUwiJ8xcsGSRH2kGmp/FSHUZL4CVWviZweULl2BcJTxqOdVZKM547SzN8/rLpu6I/4G/P8JTBiSIP4k8n5Fq6sZcDI5OOO6dk91wH9hU210kGHpwicXOoPAZzLFg4+Rz6VsXI1V8geydfm1Ci+XsQHEMs0V9IsAHPHvb8OeXBcyKtkaa4qAvIRN7ZdU4j17RVg8jHdkfdhkiNTzc6pnb9JS7xG/HU+9CW9USDaR6OFD5qSuUxLYP9qk9wYKtm+A3Yt6P+FLcuzSpjXu93vCGjJwCnuXcTP8DhoO3jVtzaixqzNMLgLCwDlalcf0lOSYEmzTs32lpPec= maddy@The" + + # cat + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILNLIRgH0j8DXd2KoGWgyRmI9hEtBE8O3UDZf+hZ5dTQ coconut@fedora" + + # puyo + #"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZDkdhQ/7/jvmOQ45O07X3UTx9tIjUVpa8uaOTzUeBj puyodead@protonmail.com" + + # cyber + #"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFnQSAqDqmi9OUgUCMWce02YxuTA0Bpgjm3y4rirrYmk cyber@cyber-pc" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFlyMSbCh8+dHKejBpZ3qZ5znqUeVOOMCru8da82Rrle cyber@cyber-pc" + + # Loan FC + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCMal04K4Gt89u13D4fOo3TMh8jgw79YeLHjn4OgEr2XCiXYd7mJeh7Osxy9Hlifl2Vf9sySjhArwsa8pkXxxh1Rdnk9csRpMx2EKGgNiLwVlqelIaNZ73uqi8ub6a7wns19NYAYl0Vy4Qvj93qOeDDVQT5MY/4BpYiku0QhYfUZuN84nwI98TnBMrBqWzVarYTSoboHaIiO+2Jxs5MSx3+xwLBGg07PpndtFr73+UJTPCHo02jqOoqzHDOY/9zKphpYVdA0+ObQtQl3KfdrIsB1UjngoQRkesl7cZenHLIpC6meSG3nWL5821rwEQSEdLY/vy6BWM6Cz07TQ6TLGurZSghSUbaEHqdeLLKqFbNw6+GxhgeFycJSUg+cakyxfxei08p6+sPn6m3tN56ZlArBkLd3ZyRM1ZPna50oUQHO/B10LCBfdZ7cXM2ErGzeJXCTdBRFtj6GxFa30nxTWsW1pS08EgkUrVyVfjN6P5w36wRC76z12U6lI40pfRqw7f3oPrN1mirThFB7v5RB/bPbnqnyHX/hLnjacMML8axeAyPoiGfnFoRC9VxUe2wn2xf4TopemsC/wzAoQzdEPxfW+tx+pB1DAl9HREw+CWDqVZCCE0SrzqPkT3sWnnKcguo76q3V1yCECzUYeqMusSFIiMdzBaAv498oRI/tjxh/w== torresefrain10@gmail.com" + ]; + }; } diff --git a/host/Rory-ovh/services/containers/spacebar/services/spacebar.nix b/host/Rory-ovh/services/containers/spacebar/services/spacebar.nix
index 807caad..7b8321b 100644 --- a/host/Rory-ovh/services/containers/spacebar/services/spacebar.nix +++ b/host/Rory-ovh/services/containers/spacebar/services/spacebar.nix
@@ -1,16 +1,21 @@ -{ spacebar, ... }: +{ spacebar, lib, ... }: let - sb = import "${spacebar}/nix/modules/default/lib.nix"; + sb = import "${spacebar}/nix/lib/mkEndpoint.nix"; in { imports = [ spacebar.nixosModules.default ]; services.spacebarchat-server = { enable = true; serverName = "spacebar.chat"; + apiEndpoint = sb.mkEndpoint "api.rory.server.spacebar.chat" 3001 true; gatewayEndpoint = sb.mkEndpoint "gateway.rory.server.spacebar.chat" 3002 true; + extraGatewayPorts = lib.range 3100 3115; cdnEndpoint = sb.mkEndpoint "cdn.rory.server.spacebar.chat" 3003 true; + adminApiEndpoint = sb.mkEndpoint "admin.rory.server.spacebar.chat" 3004 true; + webrtcEndpoint = sb.mkEndpoint "voice.rory.server.spacebar.chat" 3005 true; + cdnPath = "/storage"; cdnSignaturePath = "/run/secrets/spacebar/cdnSignature"; @@ -26,6 +31,16 @@ in ipdataApiKeyPath = "/run/secrets/spacebar/ipdataApiKey"; requestSignaturePath = "/run/secrets/spacebar/requestSignature"; + adminApi = { + enable = true; + extraConfiguration.ConnectionStrings.Spacebar = "Host=192.168.100.1; Username=spacebar; Password=spacebar; Database=spacebar; Port=5432; Include Error Detail=true; Maximum Pool Size=1000; Command Timeout=6000; Timeout=600;"; + }; + + pion-sfu = { + enable = true; + publicIp = "51.210.113.110"; + }; + settings = { security = { forwardedFor = "X-Forwarded-For"; @@ -33,7 +48,7 @@ in cdnSignUrls = true; cdnSignatureIncludeIp = true; cdnSignatureIncludeUserAgent = false; - cdnSignatureDuration = "5m"; + cdnSignatureDuration = "15m"; }; general = { frontPage = "https://spacebar.chat"; @@ -158,25 +173,29 @@ in "steam" ]; }; + register = { + blockIpDataCoThreatTypes = []; + #checkIp = false; + enableAbuseIpDb = true; + enableIpData = false; # 1500req/d, needed by gateway + }; + embeds = { + youtube = { + userAgent = "Mozilla/5.0 (compatible; Discordbot/2.0; +https://discordapp.com)"; + }; + }; }; extraEnvironment = { DATABASE = "postgres://spacebar:spacebar@192.168.100.1/spacebar"; - #WEBRTC_PORT_RANGE=60000-61000; - #PUBLIC_IP=216.230.228.60; #LOG_REQUESTS = "-200,204,304"; LOG_REQUESTS = "-"; LOG_VALIDATION_ERRORS = true; + LOG_API_ERRORS = true; #DB_LOGGING=true; #LOG_GATEWAY_TRACES=true; #LOG_PROTO_UPDATES=true; #LOG_PROTO_FRECENCY_UPDATES=true; #LOG_PROTO_SETTINGS_UPDATES=true; - #WRTC_PUBLIC_IP=webrtc.old.server.spacebar.chat; - WRTC_PUBLIC_IP = "216.230.228.19"; - WRTC_PORT_MIN = 60000; - WRTC_PORT_MAX = 65000; - WRTC_LIBRARY = "@spacebarchat/medooze-webrtc"; - #WRTC_LIBRARY=mediasoup-spacebar-wrtc; }; }; } diff --git a/host/Rory-ovh/services/matrix/draupnir.nix b/host/Rory-ovh/services/matrix/draupnir.nix
index 3eb5bcc..9a7c292 100755 --- a/host/Rory-ovh/services/matrix/draupnir.nix +++ b/host/Rory-ovh/services/matrix/draupnir.nix
@@ -1,4 +1,4 @@ -{ pkgs, draupnir, ... }: +{ config, lib, pkgs, draupnir, ... }: { services.draupnir = { @@ -30,11 +30,15 @@ protections = { wordlist = { words = [ + # The Obvious "tranny" "faggot" "ywnbaw" "nigger" + # abuse domains "https://postimg.cc/" + "https://s.binance.com" + # Dec 2025 IRC spam "irc.hardchats.com" "white power" "white pride" @@ -56,10 +60,49 @@ "irc.hackclub.com" "irc.supernets.org" "[supernets]" + "lolitaheaven.onrender.com" + "heavenlychat-px42.onrender.com" + "heavenlydev.onrender.com" + "Adolf_hipster007" ]; minutesBeforeTrusting = 0; }; }; }; }; + + systemd.services."draupnir" = { + serviceConfig = let + cfg = config.services.draupnir; + format = pkgs.formats.yaml { }; + configFile = format.generate "draupnir.yaml" cfg.settings; + in { + ExecStart = lib.mkForce ( + toString ( + [ + (lib.getExe cfg.package) + "--draupnir-config" + configFile + ] + ++ lib.optionals (cfg.secrets.accessToken != null) [ + "--access-token-path" + "%d/access_token" + ] + ++ lib.optionals (cfg.secrets.pantalaimon.password != null) [ + "--pantalaimon-password-path" + "%d/pantalaimon_password" + ] + ++ lib.optionals (cfg.secrets.web.synapseHTTPAntispam.authorization != null) [ + "--http-antispam-authorization-path" + "%d/http_antispam_authorization" + ] + ++ [ + "--max-old-space-size=32768" + "--max-semi-space-size=256" + "--prof" + ] + ) + ); + }; + }; } diff --git a/host/Rory-ovh/services/nginx/nginx.nix b/host/Rory-ovh/services/nginx/nginx.nix
index d3bbed9..2d9847b 100755 --- a/host/Rory-ovh/services/nginx/nginx.nix +++ b/host/Rory-ovh/services/nginx/nginx.nix
@@ -36,6 +36,30 @@ in access_log /var/log/nginx/access.log combined_vhosts; ''; additionalModules = with pkgs.nginxModules; [ moreheaders ]; + + upstreams."spacebar-gateway" = { + servers = { + # main + "192.168.100.22:3002" = {}; + # extraPorts + "192.168.100.22:3100" = {}; + "192.168.100.22:3101" = {}; + "192.168.100.22:3102" = {}; + "192.168.100.22:3103" = {}; + "192.168.100.22:3104" = {}; + "192.168.100.22:3105" = {}; + "192.168.100.22:3106" = {}; + "192.168.100.22:3107" = {}; + "192.168.100.22:3108" = {}; + "192.168.100.22:3109" = {}; + "192.168.100.22:3110" = {}; + "192.168.100.22:3111" = {}; + "192.168.100.22:3112" = {}; + "192.168.100.22:3113" = {}; + "192.168.100.22:3114" = {}; + "192.168.100.22:3115" = {}; + }; + }; virtualHosts = { #"boorunav.com" = serveDir { path = "/data/nginx/html_boorunav"; }; # "catgirlsaresexy.com" = serveDir { path = "/data/nginx/html_catgirlsaresexy"; }; @@ -86,8 +110,10 @@ in "ec.rory.gay" = import ./rory.gay/ec.nix { inherit config; }; #spacebar... "rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/root.nix { inherit config; }; + "admin.rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/admin.nix { inherit config; }; "api.rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/api.nix { inherit config; }; "gateway.rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/gateway.nix { inherit config; }; + "voice.rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/voice.nix { inherit config; }; "cdn.rory.server.spacebar.chat" = import ./spacebar.chat/server/rory/cdn.nix { inherit config; }; # legacy "old.server.spacebar.chat" = import ./spacebar.chat/server/rory/root.nix { inherit config; }; diff --git a/host/Rory-ovh/services/nginx/rory.gay/root.nix b/host/Rory-ovh/services/nginx/rory.gay/root.nix
index 2f491cf..a4a03b8 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/root.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/root.nix
@@ -3,7 +3,7 @@ enableACME = !config.virtualisation.isVmVariant; addSSL = !config.virtualisation.isVmVariant; root = "/data/nginx/html_rory_gay"; - extraConfig = ''autoindex on;''; + extraConfig = "autoindex on;"; locations."= /.well-known/matrix/server".extraConfig = '' more_set_headers 'Content-Type application/json'; @@ -46,4 +46,28 @@ } }'; ''; + + locations."= /.well-known/host-meta".extraConfig = '' + more_set_headers 'Content-Type application/json'; + more_set_headers 'Access-Control-Allow-Origin *'; + return 200 '<?xml version="1.0" encoding="utf-8"?> + <XRD xmlns="http://docs.oasis-open.org/ns/xri/xrd-1.0"> + <Link rel="urn:xmpp:alt-connections:websocket" + href="wss://xmpp.rory.gay/ws" /> + </XRD>'; + ''; + locations."= /.well-known/host-meta.json".extraConfig = '' + more_set_headers 'Content-Type application/json'; + more_set_headers 'Access-Control-Allow-Origin *'; + return 200 '${ + builtins.toJSON { + links = [ + { + rel = "urn:xmpp:alt-connections:websocket"; + href = "wss://xmpp.rory.gay/ws"; + } + ]; + } + }'; + ''; } diff --git a/host/Rory-ovh/services/nginx/spacebar.chat/server/old/gateway.nix b/host/Rory-ovh/services/nginx/spacebar.chat/server/old/gateway.nix
index ff95a5e..391d372 100644 --- a/host/Rory-ovh/services/nginx/spacebar.chat/server/old/gateway.nix +++ b/host/Rory-ovh/services/nginx/spacebar.chat/server/old/gateway.nix
@@ -3,7 +3,7 @@ forceSSL = true; locations = { "/" = { - proxyPass = "http://192.168.1.200:3002"; + proxyPass = "http://spacebar-gateway"; proxyWebsockets = true; extraConfig = "proxy_ssl_server_name on;" + diff --git a/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/admin.nix b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/admin.nix new file mode 100644
index 0000000..df28a55 --- /dev/null +++ b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/admin.nix
@@ -0,0 +1,9 @@ +{ config }: +{ + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; + locations."/" = { + proxyPass = "http://192.168.100.22:3004"; + extraConfig = "proxy_ssl_server_name on;" + "proxy_pass_header Authorization;"; + }; +} diff --git a/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/gateway.nix b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/gateway.nix
index 88a37da..18c66fa 100644 --- a/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/gateway.nix +++ b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/gateway.nix
@@ -3,7 +3,7 @@ enableACME = !config.virtualisation.isVmVariant; addSSL = !config.virtualisation.isVmVariant; locations."/" = { - proxyPass = "http://192.168.100.22:3002"; + proxyPass = "http://spacebar-gateway"; proxyWebsockets = true; extraConfig = "proxy_ssl_server_name on;" + "proxy_pass_header Authorization;"; }; diff --git a/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/voice.nix b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/voice.nix new file mode 100644
index 0000000..0dd40c9 --- /dev/null +++ b/host/Rory-ovh/services/nginx/spacebar.chat/server/rory/voice.nix
@@ -0,0 +1,10 @@ +{ config }: +{ + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; + locations."/" = { + proxyPass = "http://192.168.100.22:3005"; + proxyWebsockets = true; + extraConfig = "proxy_ssl_server_name on;" + "proxy_pass_header Authorization;"; + }; +} diff --git a/host/Rory-ovh/services/prosody.nix b/host/Rory-ovh/services/prosody.nix new file mode 100644
index 0000000..49fb2d0 --- /dev/null +++ b/host/Rory-ovh/services/prosody.nix
@@ -0,0 +1,17 @@ +{ lib, pkgs, ... }: +{ + services.prosody = { + enable = true; + virtualHosts."rory.gay" = { + enabled = true; + domain = "rory.gay"; + }; + admins = [ + "emma@rory.gay" + ]; + muc = [ { domain = "xmpp.rory.gay"; } ]; + httpFileShare = { + domain = "xmpp.rory.gay"; + }; + }; +} diff --git a/host/Rory-ovh/spacebar-monitoring.nix b/host/Rory-ovh/spacebar-monitoring.nix new file mode 100644
index 0000000..97176cf --- /dev/null +++ b/host/Rory-ovh/spacebar-monitoring.nix
@@ -0,0 +1,40 @@ +{ config, lib, ... }: +{ + services.prometheus.scrapeConfigs = [ + { + job_name = "spacebar-api-3001"; + scrape_interval = "1s"; + static_configs = [ + { targets = [ "192.168.100.22:3001" ]; } + ]; + } + { + job_name = "spacebar-gateway-3002"; + scrape_interval = "1s"; + static_configs = [ + { targets = [ "192.168.100.22:3002" ]; } + ]; + } + { + job_name = "spacebar-cdn-3003"; + scrape_interval = "1s"; + static_configs = [ + { targets = [ "192.168.100.22:3003" ]; } + ]; + } + { + job_name = "spacebar-webrtc-3005"; + scrape_interval = "1s"; + static_configs = [ + { targets = [ "192.168.100.22:3005" ]; } + ]; + } + ] + ++ (lib.map (port: { + job_name = "spacebar-gateway-${builtins.toString port}"; + scrape_interval = "1s"; + static_configs = [ + { targets = [ "192.168.100.22:${builtins.toString port}" ]; } + ]; + }) (lib.range 3100 3115)); +} diff --git a/host/Rory-portable/configuration.nix b/host/Rory-portable/configuration.nix
index 1982205..94d0cc2 100644 --- a/host/Rory-portable/configuration.nix +++ b/host/Rory-portable/configuration.nix
@@ -90,7 +90,7 @@ feh easyeffects kitty - #youtube-music + #pear-desktop # - IDEs #jetbrains-toolbox diff --git a/host/RoryNix/configuration.nix b/host/RoryNix/configuration.nix
index 8e3c0cc..3ba5116 100644 --- a/host/RoryNix/configuration.nix +++ b/host/RoryNix/configuration.nix
@@ -104,7 +104,7 @@ environment.systemPackages = with pkgs; [ wget - neofetch + fastfetch lnav pciutils git diff --git a/host/uISO/development.nix b/host/uISO/development.nix
index 6148c76..f1e3093 100644 --- a/host/uISO/development.nix +++ b/host/uISO/development.nix
@@ -46,6 +46,6 @@ #coreutils htop btop - neofetch + fastfetch ]; } diff --git a/modules/base-client.nix b/modules/base-client.nix
index 2a5c8e5..98418e8 100755 --- a/modules/base-client.nix +++ b/modules/base-client.nix
@@ -20,10 +20,10 @@ }; systemd = { - sleep.extraConfig = '' - AllowSuspend=no - AllowHibernation=no - ''; + sleep.settings.Sleep = { + AllowSuspend = "no"; + AllowHibernation = "no"; + }; }; environment.systemPackages = with pkgs; [ @@ -49,5 +49,4 @@ # disable all serial ports/consoles systemd.suppressedSystemUnits = [ "serial-getty@.service" ]; - } diff --git a/modules/base-server.nix b/modules/base-server.nix
index 1278d83..46f0c97 100755 --- a/modules/base-server.nix +++ b/modules/base-server.nix
@@ -27,10 +27,10 @@ }; }; - sleep.extraConfig = '' - AllowSuspend=no - AllowHibernation=no - ''; + sleep.settings.Sleep = { + AllowSuspend = "no"; + AllowHibernation = "no"; + }; }; #systemd.services.NetworkManager-wait-online.enable = false; @@ -77,38 +77,4 @@ # This shaves off half a gigabyte of disk space... hardware.enableAllFirmware = false; hardware.enableRedistributableFirmware = false; - - services = { - promtail = { - enable = true; - configuration = { - server = { - http_listen_port = 3031; - grpc_listen_port = 0; - }; - positions = { - filename = "/tmp/positions.yaml"; - }; - clients = [ { url = "https://loki.regional.seian.cloud/loki/api/v1/push"; } ]; - scrape_configs = [ - { - job_name = "journal"; - journal = { - max_age = "12h"; - labels = { - job = "systemd-journal"; - host = "${toString config.networking.hostName}"; - }; - }; - relabel_configs = [ - { - source_labels = [ "__journal__systemd_unit" ]; - target_label = "unit"; - } - ]; - } - ]; - }; - }; - }; } diff --git a/modules/base.nix b/modules/base.nix
index ae370f6..e539b15 100755 --- a/modules/base.nix +++ b/modules/base.nix
@@ -73,6 +73,7 @@ "8.8.8.8" "8.4.4.8" ]; + resolvconf.enable = false; }; environment.etc."resolv.conf" = lib.mkDefault { @@ -100,22 +101,26 @@ }; resolved = { enable = lib.mkForce false; - dnssec = lib.mkForce "false"; - dnsovertls = lib.mkForce "false"; + settings = { + Resolve = { + DNSSEC = lib.mkForce "false"; + DNSOverTLS = lib.mkForce "false"; + }; + }; }; }; systemd = { - sleep.extraConfig = '' - AllowSuspend=no - AllowHibernation=no - ''; + sleep.settings.Sleep = { + AllowSuspend = "no"; + AllowHibernation = "no"; + }; }; environment.systemPackages = with pkgs; [ #wget net-tools - neofetch + fastfetch lnav pciutils git @@ -132,7 +137,7 @@ dig cloud-utils #nix-output-monitor - nom.packages.${system}.default + nom.packages.${stdenv.hostPlatform.system}.default #expect unrar-wrapper #arch-install-scripts @@ -150,9 +155,7 @@ zsh-completions ]; - systemd.coredump.extraConfig = lib.mkDefault '' - Storage=none - ''; + systemd.coredump.settings.Coredump.Storage = lib.mkDefault "none"; nix = { settings = { experimental-features = [ @@ -183,7 +186,6 @@ }; monitoring.monitorAll = lib.mkForce false; - services.promtail.enable = lib.mkForce false; networking.useDHCP = lib.mkOverride 51 true; }; } diff --git a/modules/monitoring/module.nix b/modules/monitoring/module.nix
index f47c483..a676feb 100644 --- a/modules/monitoring/module.nix +++ b/modules/monitoring/module.nix
@@ -57,6 +57,7 @@ in protocol = "socket"; socket_mode = "0666"; }; + security.secret_key = "$__file{/run/credentials/grafana.service/secret_key}"; }; provision = { datasources.settings = { diff --git a/modules/software-templates/devenv/c-cpp.nix b/modules/software-templates/devenv/c-cpp.nix
index 579edcc..7e88303 100644 --- a/modules/software-templates/devenv/c-cpp.nix +++ b/modules/software-templates/devenv/c-cpp.nix
@@ -1,8 +1,8 @@ { pkgs, nix-jetbrains-plugins, ... }: { - environment.systemPackages = with nix-jetbrains-plugins.lib."${pkgs.stdenv.system}"; [ - (buildIdeWithPlugins pkgs.jetbrains "clion" [ + environment.systemPackages = with nix-jetbrains-plugins.lib; [ + (buildIdeWithPlugins pkgs "clion" [ "com.github.copilot" "nix-idea" # "visual-studio-keymap" diff --git a/modules/software-templates/devenv/dotnet.nix b/modules/software-templates/devenv/dotnet.nix
index d8871ef..53cbf52 100644 --- a/modules/software-templates/devenv/dotnet.nix +++ b/modules/software-templates/devenv/dotnet.nix
@@ -1,8 +1,8 @@ { pkgs, nix-jetbrains-plugins, ... }: { - environment.systemPackages = with nix-jetbrains-plugins.lib."${pkgs.stdenv.system}"; [ - (buildIdeWithPlugins pkgs.jetbrains "rider" [ + environment.systemPackages = with nix-jetbrains-plugins.lib; [ + (buildIdeWithPlugins pkgs "rider" [ "com.github.copilot" "nix-idea" # "visual-studio-keymap" diff --git a/modules/software-templates/devenv/go.nix b/modules/software-templates/devenv/go.nix new file mode 100644
index 0000000..bbce701 --- /dev/null +++ b/modules/software-templates/devenv/go.nix
@@ -0,0 +1,17 @@ +{ pkgs, nix-jetbrains-plugins, ... }: + +{ + environment.systemPackages = with nix-jetbrains-plugins.lib; [ + (buildIdeWithPlugins pkgs "goland" [ + "com.github.copilot" + "nix-idea" + # "visual-studio-keymap" + "String Manipulation" + ]) + pkgs.go + pkgs.gcc + ]; + environment.sessionVariables = { + DOTNET_CLI_TELEMETRY_OPTOUT = "1"; + }; +} diff --git a/modules/software-templates/devenv/java.nix b/modules/software-templates/devenv/java.nix
index ed1581a..a0065c6 100644 --- a/modules/software-templates/devenv/java.nix +++ b/modules/software-templates/devenv/java.nix
@@ -1,8 +1,8 @@ { pkgs, nix-jetbrains-plugins, ... }: { - environment.systemPackages = with nix-jetbrains-plugins.lib."${pkgs.stdenv.system}"; [ - (buildIdeWithPlugins pkgs.jetbrains "idea" [ + environment.systemPackages = with nix-jetbrains-plugins.lib; [ + (buildIdeWithPlugins pkgs "idea" [ "com.github.copilot" "nix-idea" # "visual-studio-keymap" diff --git a/modules/software-templates/devenv/javascript.nix b/modules/software-templates/devenv/javascript.nix
index 583f6ef..de69646 100644 --- a/modules/software-templates/devenv/javascript.nix +++ b/modules/software-templates/devenv/javascript.nix
@@ -1,8 +1,8 @@ { pkgs, nix-jetbrains-plugins, ... }: { - environment.systemPackages = with nix-jetbrains-plugins.lib."${pkgs.stdenv.system}"; [ - (buildIdeWithPlugins pkgs.jetbrains "webstorm" [ + environment.systemPackages = with nix-jetbrains-plugins.lib; [ + (buildIdeWithPlugins pkgs "webstorm" [ "com.github.copilot" "nix-idea" # "visual-studio-keymap" diff --git a/modules/users/Arci.nix b/modules/users/Arci.nix
index df7efb5..28c3c1c 100644 --- a/modules/users/Arci.nix +++ b/modules/users/Arci.nix
@@ -59,9 +59,8 @@ programs = { git = { enable = true; + signing.format = null; settings = { - user.name = "Rory&"; - user.email = "root@rory.gay"; safe.directory = "/"; }; }; diff --git a/modules/users/Rory.client.nix b/modules/users/Rory.client.nix
index ede12df..3394e16 100755 --- a/modules/users/Rory.client.nix +++ b/modules/users/Rory.client.nix
@@ -10,7 +10,7 @@ }; users.users.Rory.packages = with pkgs; [ - helvum + crosspipe vesktop pavucontrol wf-recorder diff --git a/modules/users/Rory.nix b/modules/users/Rory.nix
index c56c3ed..05745fc 100755 --- a/modules/users/Rory.nix +++ b/modules/users/Rory.nix
@@ -71,11 +71,13 @@ programs = { git = { enable = true; + signing.format = null; settings = { user.name = "Rory&"; user.email = "root@rory.gay"; safe.directory = "/"; advice.defaultBranchName = false; + signing.format = "openpgp"; }; }; zsh = { @@ -111,8 +113,7 @@ export DISABLE_AUTO_UPDATE=true COMPLETION_WAITING_DOTS="true" - ''; - initExtra = '' + # at the end? alias mv='mv -v' alias pre='npx prettier -w' alias git-commit='git commit --signoff --sign' @@ -192,12 +193,12 @@ POWERLEVEL9K_MODE = "nerdfont-complete"; POWERLEVEL9K_ICON_PADDING = "none"; POWERLEVEL9K_PROMPT_ADD_NEWLINE = "false"; - POWERLEVEL9K_LEFT_SUBSEGMENT_SEPARATOR = "\uE0B1"; - POWERLEVEL9K_RIGHT_SUBSEGMENT_SEPARATOR = "\uE0B3"; - POWERLEVEL9K_LEFT_SEGMENT_SEPARATOR = "\uE0B0"; - POWERLEVEL9K_RIGHT_SEGMENT_SEPARATOR = "\uE0B2"; - POWERLEVEL9K_LEFT_PROMPT_LAST_SEGMENT_END_SYMBOL = "\uE0B0"; - POWERLEVEL9K_RIGHT_PROMPT_FIRST_SEGMENT_START_SYMBOL = "\uE0B2"; + POWERLEVEL9K_LEFT_SUBSEGMENT_SEPARATOR = "\\uE0B1"; + POWERLEVEL9K_RIGHT_SUBSEGMENT_SEPARATOR = "\\uE0B3"; + POWERLEVEL9K_LEFT_SEGMENT_SEPARATOR = "\\uE0B0"; + POWERLEVEL9K_RIGHT_SEGMENT_SEPARATOR = "\\uE0B2"; + POWERLEVEL9K_LEFT_PROMPT_LAST_SEGMENT_END_SYMBOL = "\\uE0B0"; + POWERLEVEL9K_RIGHT_PROMPT_FIRST_SEGMENT_START_SYMBOL = "\\uE0B2"; POWERLEVEL9K_PROMPT_CHAR_OVERWRITE_STATE = true; }; }; diff --git a/modules/users/Rory/chimmie_fedi-wallpaper.png b/modules/users/Rory/chimmie_fedi-wallpaper.png new file mode 100644
index 0000000..066f8b7 --- /dev/null +++ b/modules/users/Rory/chimmie_fedi-wallpaper.png
Binary files differdiff --git a/modules/users/Rory/xenia_drawing5-1.png b/modules/users/Rory/xenia_drawing5-1.png new file mode 100644
index 0000000..5d132cf --- /dev/null +++ b/modules/users/Rory/xenia_drawing5-1.png
Binary files differdiff --git a/modules/users/Rory/xenia_drawing5-1_2160p.png b/modules/users/Rory/xenia_drawing5-1_2160p.png new file mode 100644
index 0000000..791b5da --- /dev/null +++ b/modules/users/Rory/xenia_drawing5-1_2160p.png
Binary files differdiff --git a/modules/users/Rory/xenia_drawing5.png b/modules/users/Rory/xenia_drawing5.png new file mode 100644
index 0000000..10af0ca --- /dev/null +++ b/modules/users/Rory/xenia_drawing5.png
Binary files differdiff --git a/modules/users/geba.nix b/modules/users/geba.nix new file mode 100644
index 0000000..77ee689 --- /dev/null +++ b/modules/users/geba.nix
@@ -0,0 +1,199 @@ +{ lib, pkgs, ... }: + +{ + users.users.geba = { + isNormalUser = true; + group = "users"; + extraGroups = [ + "wheel" + "libvirtd" + "ocp" + ]; + packages = with pkgs; [ + lnav + age + git + lsd + duf + (btop.override { rocmSupport = true; }) + htop + kitty.terminfo + tmux + jq + dig + + # - zsh + zsh + zsh-powerlevel10k + zsh-nix-shell + zsh-you-should-use + zsh-syntax-highlighting + zsh-completions + + wireguard-tools + ]; + openssh.authorizedKeys.keys = [ + ]; + useDefaultShell = true; + shell = pkgs.zsh; + }; + programs.zsh.enable = true; + environment.shells = with pkgs; [ zsh ]; + + home-manager.users.geba = { + home.preferXdgDirectories = true; + home.sessionVariables = { + EDITOR = "nvim"; + SYSTEMD_EDITOR = "nvim"; + GIT_EDITOR = "nvim"; + QT_QPA_PLATFORMTHEME = "xdgdesktopportal"; + GTK_USE_PORTAL = "1"; + _JAVA_AWT_WM_NONREPARENTING = "1"; + WINEDEBUG = "-all"; + CHOKIDAR_USEPOLLING = "true"; + MSBUILDLIVELOGGER = "auto"; + DOTNET_WATCH_SUPPRESS_LAUNCH_BROWSER = "1"; + DOTNET_CLI_TELEMETRY_OPTOUT = "1"; + NIXPKGS_ALLOW_UNFREE = "1"; + MOZ_USE_XINPUT2 = "1"; + }; + programs = { + git = { + enable = true; + signing.format = null; + settings = { + safe.directory = "/"; + }; + }; + zsh = { + enable = true; + #enableAutosuggestions = true; + autosuggestion.enable = true; + enableVteIntegration = true; + autocd = true; + + initExtraFirst = '' + export EDITOR=nvim + export SYSTEMD_EDITOR=$EDITOR + export GIT_EDITOR=$EDITOR + export QT_QPA_PLATFORMTHEME=xdgdesktopportal + export GTK_USE_PORTAL=1 + export _JAVA_AWT_WM_NONREPARENTING=1 + export WINEDEBUG=-all + export DOTPROFILE_LOADED='yes' + export CHOKIDAR_USEPOLLING=true + export MSBUILDLIVELOGGER=auto + export DOTNET_WATCH_SUPPRESS_LAUNCH_BROWSER=1 + export DOTNET_CLI_TELEMETRY_OPTOUT=1 + function mkkey() { + echo "Making key for $1" + ssh-keygen -t ed25519 -C "$HOST -> $1" -f ~/.ssh/id_ed25519_$1 + ( + echo "Host $1" + echo " IdentityFile ~/.ssh/id_ed25519_$1" + ) >> ~/.ssh/config + echo 'Done! Public key:' + cat ~/.ssh/id_ed25519_$1.pub + } + + export DISABLE_AUTO_UPDATE=true + COMPLETION_WAITING_DOTS="true" + ''; + initExtra = '' + alias mv='mv -v' + alias pre='npx prettier -w' + alias git-commit='git commit --signoff --sign' + alias npm='NODE_OPTIONS=--openssl-legacy-provider npm' + alias npx='NODE_OPTIONS=--openssl-legacy-provider npx' + alias yarn='NODE_OPTIONS=--openssl-legacy-provider npx -y yarn --use-yarnrc $XDG_CONFIG_HOME/yarn/config' + alias node='NODE_OPTIONS=--openssl-legacy-provider node' + # - dotnet + alias drun='dotnet watch run --no-hot-reload --property WarningLevel=0' + alias dbuild='dotnet watch build --no-hot-reload --property WarningLevel=0' + alias ls='lsd -lAhF --color=always --icon=always' + alias transfetch='neofetch --kitty ~/trans_witch.jpg' + alias gc='git-commit' + [ -f "$HOME/.profile" ] && . $HOME/.profile + ''; + #alias knconfig='cp .config ../$(date ''+%Y%m%d_%k%M%S\'').config -v; make CC=clang LLVM=1 nconfig' + oh-my-zsh = { + enable = true; + plugins = [ + "git" + "sudo" + ]; + }; + + plugins = [ + { + name = "powerlevel10k"; + src = pkgs.zsh-powerlevel10k; + file = "share/zsh-powerlevel10k/powerlevel10k.zsh-theme"; + } + { + name = "powerlevel10k-config"; + src = lib.cleanSource ./Rory; + file = "p10k.zsh"; + } + { + name = "zsh-syntax-highlighting"; + src = pkgs.zsh-syntax-highlighting; + file = "share/zsh-syntax-highlighting/zsh-syntax-highlighting.zsh"; + } + { + name = "zsh-autosuggestions"; + src = pkgs.zsh-autosuggestions; + file = "share/zsh-autosuggestions/zsh-autosuggestions.zsh"; + } + ]; + + localVariables = { + POWERLEVEL9K_LEFT_PROMPT_ELEMENTS = [ + "os_icon" + "dir" + "vcs" + "prompt_char" + ]; + POWERLEVEL9K_RIGHT_PROMPT_ELEMENTS = [ + "status" + "command_execution_time" + "background_jobs" + "direnv" + "virtualenv" + "pyenv" + "nodeenv" + "context" + "nix_shell" + "vi_mode" + "load" + "disk_usage" + "ram" + ]; + POWERLEVEL9K_MODE = "nerdfont-complete"; + POWERLEVEL9K_ICON_PADDING = "none"; + POWERLEVEL9K_PROMPT_ADD_NEWLINE = "false"; + POWERLEVEL9K_LEFT_SUBSEGMENT_SEPARATOR = "\uE0B1"; + POWERLEVEL9K_RIGHT_SUBSEGMENT_SEPARATOR = "\uE0B3"; + POWERLEVEL9K_LEFT_SEGMENT_SEPARATOR = "\uE0B0"; + POWERLEVEL9K_RIGHT_SEGMENT_SEPARATOR = "\uE0B2"; + POWERLEVEL9K_LEFT_PROMPT_LAST_SEGMENT_END_SYMBOL = "\uE0B0"; + POWERLEVEL9K_RIGHT_PROMPT_FIRST_SEGMENT_START_SYMBOL = "\uE0B2"; + POWERLEVEL9K_PROMPT_CHAR_OVERWRITE_STATE = true; + }; + }; + neovim = { + defaultEditor = true; + viAlias = true; + vimAlias = true; + vimdiffAlias = true; + coc = { + enable = true; + + }; + }; + }; + + home.stateVersion = "22.11"; + }; +} + diff --git a/modules/users/ks.nix b/modules/users/ks.nix
index d55dd1e..b0cf8df 100755 --- a/modules/users/ks.nix +++ b/modules/users/ks.nix
@@ -17,6 +17,7 @@ home-manager.users.ks = { programs.git = { enable = true; + signing.format = null; settings = { user.name = "Kinoshita Shimizu"; user.email = "ks@kinoshitaproductions.com"; diff --git a/packages/overlays/matrix-synapse/patches/0001-Add-CVE-IDs-to-changelog-for-1.152.1.-19778.patch b/packages/overlays/matrix-synapse/patches/0001-Add-CVE-IDs-to-changelog-for-1.152.1.-19778.patch new file mode 100644
index 0000000..adbc9fc --- /dev/null +++ b/packages/overlays/matrix-synapse/patches/0001-Add-CVE-IDs-to-changelog-for-1.152.1.-19778.patch
@@ -0,0 +1,29 @@ +From 16c17f3a420242e53088337d48b1fb55a86e3a8f Mon Sep 17 00:00:00 2001 +From: Denis Kasak <dkasak@termina.org.uk> +Date: Wed, 13 May 2026 17:26:16 +0200 +Subject: [PATCH 01/19] Add CVE IDs to changelog for 1.152.1. (#19778) + +Since this is just a change log update, I've removed the entire +checklist. Please tell me if this is incorrect. +--- + CHANGES.md | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/CHANGES.md b/CHANGES.md +index d9b3f8b2c1..f0488cd68c 100644 +--- a/CHANGES.md ++++ b/CHANGES.md +@@ -2,8 +2,8 @@ + + ## Security Fixes + +-- Prevent CPU starvation (Denial of Service) under worker lock contention, additionally capping the `WorkerLock` time out interval to a maximum of 60 seconds. Contributed by Famedly. ([\#19394](https://github.com/element-hq/synapse/issues/19394), ELEMENTSEC-2026-1706, [GHSA-8q93-326v-3m7g](https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g), CVE pending) +-- Prevent pagination ending when a page is full of rejected events. (ELEMENTSEC-2025-1636, [GHSA-6qf2-7x63-mm6v](https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v), CVE pending) ++- Prevent CPU starvation (Denial of Service) under worker lock contention, additionally capping the `WorkerLock` time out interval to a maximum of 60 seconds. Contributed by Famedly. ([\#19394](https://github.com/element-hq/synapse/issues/19394), ELEMENTSEC-2026-1706, [GHSA-8q93-326v-3m7g](https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g), CVE-2026-45078) ++- Prevent pagination ending when a page is full of rejected events. (ELEMENTSEC-2025-1636, [GHSA-6qf2-7x63-mm6v](https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v), CVE-2026-45076) + + + # Synapse 1.152.0 (2026-04-28) +-- +2.53.0 + diff --git a/packages/overlays/matrix-synapse/patches/0001-nix-use-postgres-17.patch b/packages/overlays/matrix-synapse/patches/0002-nix-use-postgres-17.patch
index 86bf49a..959b903 100644 --- a/packages/overlays/matrix-synapse/patches/0001-nix-use-postgres-17.patch +++ b/packages/overlays/matrix-synapse/patches/0002-nix-use-postgres-17.patch
@@ -1,7 +1,7 @@ -From 6a6679f2adc62287a94ed2bc21f0379ba8643395 Mon Sep 17 00:00:00 2001 +From e2b5f1ee0eac4b9c84e99fe9eb0d6a59103149a2 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Fri, 25 Jul 2025 08:25:28 +0200 -Subject: [PATCH 01/19] nix: use postgres 17 +Subject: [PATCH 02/19] nix: use postgres 17 Signed-off-by: Rory& <root@rory.gay> --- @@ -21,5 +21,5 @@ index 4ff6518aed..51ae12c272 100644 # On the first invocation of `devenv up`, create a database for # Synapse to store data in. -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0002-nix-fix-flake.patch b/packages/overlays/matrix-synapse/patches/0003-nix-fix-flake.patch
index 31b205f..311bc81 100644 --- a/packages/overlays/matrix-synapse/patches/0002-nix-fix-flake.patch +++ b/packages/overlays/matrix-synapse/patches/0003-nix-fix-flake.patch
@@ -1,7 +1,7 @@ -From 52073474ad787f1e1ad0a70ec5997a915cd46835 Mon Sep 17 00:00:00 2001 +From cf9633037f4927bedf4d8c89386cd8fa33984cad Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Mon, 9 Jun 2025 17:38:34 +0200 -Subject: [PATCH 02/19] nix: fix flake +Subject: [PATCH 03/19] nix: fix flake Signed-off-by: Rory& <root@rory.gay> --- @@ -186,5 +186,5 @@ index 51ae12c272..cc41490a41 100644 # over the 'synapse' database. services.postgres.initialScript = '' -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0003-nix-Update-flake.patch b/packages/overlays/matrix-synapse/patches/0004-nix-Update-flake.patch
index 10cb326..36f1e19 100644 --- a/packages/overlays/matrix-synapse/patches/0003-nix-Update-flake.patch +++ b/packages/overlays/matrix-synapse/patches/0004-nix-Update-flake.patch
@@ -1,7 +1,7 @@ -From 6431f98505a5ba3d41cfd4a16df1a746818079c2 Mon Sep 17 00:00:00 2001 +From 33cb357d30e5817bf679fc161a3a333a37579188 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Thu, 13 Nov 2025 13:57:10 +0100 -Subject: [PATCH 03/19] nix: Update flake +Subject: [PATCH 04/19] nix: Update flake Signed-off-by: Rory& <root@rory.gay> --- @@ -44,7 +44,7 @@ index 4e2f01153b..0f2de20b2b 100644 }, "original": { diff --git a/flake.nix b/flake.nix -index cc41490a41..5bde1e6c07 100644 +index cc41490a41..50ae70e989 100644 --- a/flake.nix +++ b/flake.nix @@ -82,7 +82,7 @@ @@ -52,10 +52,10 @@ index cc41490a41..5bde1e6c07 100644 # NOTE: We currently need to set the Rust version unnecessarily high # in order to work around https://github.com/matrix-org/synapse/issues/15939 - (rust-bin.stable."1.87.0".default.override { -+ (rust-bin.stable."1.88.0".default.override { ++ (rust-bin.stable."1.89.0".default.override { # Additionally install the "rust-src" extension to allow diving into the # Rust source code in an IDE (rust-analyzer will also make use of it). extensions = [ "rust-src" ]; -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0004-nix-Temporarily-disable-go-in-flake.patch b/packages/overlays/matrix-synapse/patches/0005-nix-Temporarily-disable-go-in-flake.patch
index 68a5af1..3b9e543 100644 --- a/packages/overlays/matrix-synapse/patches/0004-nix-Temporarily-disable-go-in-flake.patch +++ b/packages/overlays/matrix-synapse/patches/0005-nix-Temporarily-disable-go-in-flake.patch
@@ -1,7 +1,7 @@ -From 484d828ca40ed1d2d20d490c0a6d04c5ccfc7177 Mon Sep 17 00:00:00 2001 +From cda3b7476e27da235c8304abac8a1cf32ad2c576 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Sat, 16 Aug 2025 20:18:45 +0200 -Subject: [PATCH 04/19] nix: Temporarily disable go in flake +Subject: [PATCH 05/19] nix: Temporarily disable go in flake Signed-off-by: Rory& <root@rory.gay> --- @@ -9,7 +9,7 @@ Signed-off-by: Rory& <root@rory.gay> 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/flake.nix b/flake.nix -index 5bde1e6c07..cf7a731f51 100644 +index 50ae70e989..ef944747cb 100644 --- a/flake.nix +++ b/flake.nix @@ -151,7 +151,7 @@ @@ -22,5 +22,5 @@ index 5bde1e6c07..cf7a731f51 100644 # Postgres is needed to run Synapse with postgres support and -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0005-Add-test-script.patch b/packages/overlays/matrix-synapse/patches/0006-Add-test-script.patch
index 9ec68ee..300d132 100644 --- a/packages/overlays/matrix-synapse/patches/0005-Add-test-script.patch +++ b/packages/overlays/matrix-synapse/patches/0006-Add-test-script.patch
@@ -1,7 +1,7 @@ -From 8f90a5cc49bca091080c5dcb102c538d0ed7380e Mon Sep 17 00:00:00 2001 +From 7218323ec2954bca8af95af70cf9d8d2a064fa3c Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Thu, 13 Nov 2025 13:56:59 +0100 -Subject: [PATCH 05/19] Add test script +Subject: [PATCH 06/19] Add test script Signed-off-by: Rory& <root@rory.gay> --- @@ -18,5 +18,5 @@ index 0000000000..1ac82801b2 +#! /usr/bin/env sh +poetry run trial -j`nproc` tests -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0006-Fix-gitignore-to-ignore-.venv.patch b/packages/overlays/matrix-synapse/patches/0007-Fix-gitignore-to-ignore-.venv.patch
index 700c0c5..2ab29dd 100644 --- a/packages/overlays/matrix-synapse/patches/0006-Fix-gitignore-to-ignore-.venv.patch +++ b/packages/overlays/matrix-synapse/patches/0007-Fix-gitignore-to-ignore-.venv.patch
@@ -1,7 +1,7 @@ -From e0fa2c2646921eee904249af9f410afb65c73b37 Mon Sep 17 00:00:00 2001 +From 527765f8a34f0f4c32973b31909e67f2bcf02035 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Mon, 9 Jun 2025 17:46:10 +0200 -Subject: [PATCH 06/19] Fix gitignore to ignore .venv +Subject: [PATCH 07/19] Fix gitignore to ignore .venv Signed-off-by: Rory& <root@rory.gay> --- @@ -21,5 +21,5 @@ index e333f2320b..3aec96e75e 100644 /logs /media_store/ -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0007-Fast-auth-links.patch b/packages/overlays/matrix-synapse/patches/0008-Fast-auth-links.patch
index e092ea0..b77ad1b 100644 --- a/packages/overlays/matrix-synapse/patches/0007-Fast-auth-links.patch +++ b/packages/overlays/matrix-synapse/patches/0008-Fast-auth-links.patch
@@ -1,7 +1,7 @@ -From ad2d33f1df396c1f468c0c0502b0012e16f39342 Mon Sep 17 00:00:00 2001 +From 064fbcdd10c15eea7f695b693c7ee1ef99b6b606 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Tue, 22 Jul 2025 05:07:01 +0200 -Subject: [PATCH 07/19] Fast auth links +Subject: [PATCH 08/19] Fast auth links Signed-off-by: Rory& <root@rory.gay> --- @@ -10,10 +10,10 @@ Signed-off-by: Rory& <root@rory.gay> 2 files changed, 47 insertions(+), 4 deletions(-) diff --git a/synapse/storage/database.py b/synapse/storage/database.py -index 2d5e1d3c48..b44016d13e 100644 +index 6e38b55686..2bab1e53c5 100644 --- a/synapse/storage/database.py +++ b/synapse/storage/database.py -@@ -2591,6 +2591,49 @@ class DatabasePool: +@@ -2608,6 +2608,49 @@ class DatabasePool: return txn.fetchall() @@ -64,7 +64,7 @@ index 2d5e1d3c48..b44016d13e 100644 def make_in_list_sql_clause( database_engine: BaseDatabaseEngine, diff --git a/synapse/storage/databases/main/event_federation.py b/synapse/storage/databases/main/event_federation.py -index cc7083b605..55a0714f14 100644 +index 415926eb0a..0e34a3ffc3 100644 --- a/synapse/storage/databases/main/event_federation.py +++ b/synapse/storage/databases/main/event_federation.py @@ -47,6 +47,7 @@ from synapse.storage.database import ( @@ -97,5 +97,5 @@ index cc7083b605..55a0714f14 100644 txn.execute(sql % (clause,), args) -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0008-Add-too-much-logging-to-room-summary-over-federation.patch b/packages/overlays/matrix-synapse/patches/0009-Add-too-much-logging-to-room-summary-over-federation.patch
index 4f4d61a..ecbeb9f 100644 --- a/packages/overlays/matrix-synapse/patches/0008-Add-too-much-logging-to-room-summary-over-federation.patch +++ b/packages/overlays/matrix-synapse/patches/0009-Add-too-much-logging-to-room-summary-over-federation.patch
@@ -1,7 +1,7 @@ -From 2cd613e3c422d52693b5f50c2db2e8e1b9ae169e Mon Sep 17 00:00:00 2001 +From e0c0a852c437a5eef52041ec42edfbc6d0b913ca Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Wed, 23 Apr 2025 17:53:52 +0200 -Subject: [PATCH 08/19] Add too much logging to room summary over federation +Subject: [PATCH 09/19] Add too much logging to room summary over federation Signed-off-by: Rory& <root@rory.gay> --- @@ -9,10 +9,10 @@ Signed-off-by: Rory& <root@rory.gay> 1 file changed, 36 insertions(+), 4 deletions(-) diff --git a/synapse/handlers/room_summary.py b/synapse/handlers/room_summary.py -index 9ec0d33f11..5ea32af620 100644 +index bbcdc0877e..5a35d4d0e1 100644 --- a/synapse/handlers/room_summary.py +++ b/synapse/handlers/room_summary.py -@@ -748,23 +748,55 @@ class RoomSummaryHandler: +@@ -747,23 +747,55 @@ class RoomSummaryHandler: """ # The API doesn't return the room version so assume that a # join rule of knock is valid. @@ -73,5 +73,5 @@ index 9ec0d33f11..5ea32af620 100644 # already be in the room (if it was a child room), or there might be a # pending invite, etc. -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0009-Log-entire-room-if-accessibility-check-fails.patch b/packages/overlays/matrix-synapse/patches/0010-Log-entire-room-if-accessibility-check-fails.patch
index 991477d..1d480e4 100644 --- a/packages/overlays/matrix-synapse/patches/0009-Log-entire-room-if-accessibility-check-fails.patch +++ b/packages/overlays/matrix-synapse/patches/0010-Log-entire-room-if-accessibility-check-fails.patch
@@ -1,7 +1,7 @@ -From 067819eba568fc3acbf5be0a6e1440f59df3e32e Mon Sep 17 00:00:00 2001 +From 8f2314ceaf0d459bf11df840ce14918292f5b90d Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Wed, 23 Apr 2025 18:24:57 +0200 -Subject: [PATCH 09/19] Log entire room if accessibility check fails +Subject: [PATCH 10/19] Log entire room if accessibility check fails Signed-off-by: Rory& <root@rory.gay> --- @@ -9,10 +9,10 @@ Signed-off-by: Rory& <root@rory.gay> 1 file changed, 4 insertions(+) diff --git a/synapse/handlers/room_summary.py b/synapse/handlers/room_summary.py -index 5ea32af620..30ee91cd95 100644 +index 5a35d4d0e1..9f904af2ea 100644 --- a/synapse/handlers/room_summary.py +++ b/synapse/handlers/room_summary.py -@@ -964,6 +964,10 @@ class RoomSummaryHandler: +@@ -961,6 +961,10 @@ class RoomSummaryHandler: if not room_entry or not await self._is_remote_room_accessible( requester, room_entry.room_id, room_entry.room ): @@ -24,5 +24,5 @@ index 5ea32af620..30ee91cd95 100644 room = dict(room_entry.room) -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0010-Log-policy-server-rejected-events.patch b/packages/overlays/matrix-synapse/patches/0010-Log-policy-server-rejected-events.patch deleted file mode 100644
index 5d271c9..0000000 --- a/packages/overlays/matrix-synapse/patches/0010-Log-policy-server-rejected-events.patch +++ /dev/null
@@ -1,31 +0,0 @@ -From f085fa232b6fce515f43fa5939afb1ab1b5dc3fe Mon Sep 17 00:00:00 2001 -From: Rory& <root@rory.gay> -Date: Tue, 27 May 2025 05:21:46 +0200 -Subject: [PATCH 10/19] Log policy server rejected events - -Signed-off-by: Rory& <root@rory.gay> ---- - synapse/handlers/room_policy.py | 7 +++++++ - 1 file changed, 7 insertions(+) - -diff --git a/synapse/handlers/room_policy.py b/synapse/handlers/room_policy.py -index 0663a36714..d2216978ac 100644 ---- a/synapse/handlers/room_policy.py -+++ b/synapse/handlers/room_policy.py -@@ -111,6 +111,13 @@ class RoomPolicyHandler: - policy_server, event - ) - if recommendation != RECOMMENDATION_OK: -+ logger.info( -+ "[POLICY] Policy server %s recommended not to allow event %s in room %s: %s", -+ policy_server, -+ event.event_id, -+ event.room_id, -+ recommendation, -+ ) - return False - - return True # default allow --- -2.51.2 - diff --git a/packages/overlays/matrix-synapse/patches/0011-Use-parse_boolean-for-unredacted-content.patch b/packages/overlays/matrix-synapse/patches/0011-Use-parse_boolean-for-unredacted-content.patch
index 51e28f6..f2361c8 100644 --- a/packages/overlays/matrix-synapse/patches/0011-Use-parse_boolean-for-unredacted-content.patch +++ b/packages/overlays/matrix-synapse/patches/0011-Use-parse_boolean-for-unredacted-content.patch
@@ -1,4 +1,4 @@ -From 39f6d6db06eedce3c3833c2cb705f7758f15abe9 Mon Sep 17 00:00:00 2001 +From c4f5b54b4bc425ff0adc10ef44b1e91cd33fc969 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Tue, 27 May 2025 06:14:26 +0200 Subject: [PATCH 11/19] Use parse_boolean for unredacted content @@ -9,10 +9,10 @@ Signed-off-by: Rory& <root@rory.gay> 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/synapse/rest/client/room.py b/synapse/rest/client/room.py -index 5e7dcb0191..dac466f465 100644 +index 83664814a6..f17c1f5e26 100644 --- a/synapse/rest/client/room.py +++ b/synapse/rest/client/room.py -@@ -1023,10 +1023,9 @@ class RoomEventServlet(RestServlet): +@@ -1053,10 +1053,9 @@ class RoomEventServlet(RestServlet): requester = await self.auth.get_user_by_req(request, allow_guest=True) include_unredacted_content = self.msc2815_enabled and ( @@ -26,5 +26,5 @@ index 5e7dcb0191..dac466f465 100644 == "true" ) -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0012-Expose-tombstone-in-room-admin-api.patch b/packages/overlays/matrix-synapse/patches/0012-Expose-tombstone-in-room-admin-api.patch
index bce8aec..9c414b8 100644 --- a/packages/overlays/matrix-synapse/patches/0012-Expose-tombstone-in-room-admin-api.patch +++ b/packages/overlays/matrix-synapse/patches/0012-Expose-tombstone-in-room-admin-api.patch
@@ -1,4 +1,4 @@ -From 37a151a60fcbbf43408962121e31a9c52ea7ff3a Mon Sep 17 00:00:00 2001 +From 4a87e254861c102323b9f3bdab14b792da995069 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Tue, 27 May 2025 06:37:52 +0200 Subject: [PATCH 12/19] Expose tombstone in room admin api @@ -11,10 +11,10 @@ Signed-off-by: Rory& <root@rory.gay> 3 files changed, 40 insertions(+), 2 deletions(-) diff --git a/synapse/rest/admin/rooms.py b/synapse/rest/admin/rooms.py -index a886859ffa..e97d076a44 100644 +index 61511b9360..3ff2865b96 100644 --- a/synapse/rest/admin/rooms.py +++ b/synapse/rest/admin/rooms.py -@@ -301,6 +301,10 @@ class ListRoomRestServlet(RestServlet): +@@ -302,6 +302,10 @@ class ListRoomRestServlet(RestServlet): direction = parse_enum(request, "dir", Direction, default=Direction.FORWARDS) reverse_order = True if direction == Direction.BACKWARDS else False @@ -25,7 +25,7 @@ index a886859ffa..e97d076a44 100644 # Return list of rooms according to parameters rooms, total_rooms = await self.store.get_rooms_paginate( start, -@@ -310,6 +314,7 @@ class ListRoomRestServlet(RestServlet): +@@ -311,6 +315,7 @@ class ListRoomRestServlet(RestServlet): search_term, public_rooms, empty_rooms, @@ -34,10 +34,10 @@ index a886859ffa..e97d076a44 100644 response = { diff --git a/synapse/rest/client/room.py b/synapse/rest/client/room.py -index dac466f465..d28be2befb 100644 +index f17c1f5e26..7f3b1153f7 100644 --- a/synapse/rest/client/room.py +++ b/synapse/rest/client/room.py -@@ -1027,7 +1027,6 @@ class RoomEventServlet(RestServlet): +@@ -1057,7 +1057,6 @@ class RoomEventServlet(RestServlet): request, "fi.mau.msc2815.include_unredacted_content" ) @@ -46,10 +46,10 @@ index dac466f465..d28be2befb 100644 if include_unredacted_content and not await self.auth.is_server_admin( requester diff --git a/synapse/storage/databases/main/room.py b/synapse/storage/databases/main/room.py -index 633df07736..7623208c28 100644 +index a0c42082f0..68c2edfc14 100644 --- a/synapse/storage/databases/main/room.py +++ b/synapse/storage/databases/main/room.py -@@ -605,6 +605,7 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -779,6 +779,7 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): search_term: str | None, public_rooms: bool | None, empty_rooms: bool | None, @@ -57,7 +57,7 @@ index 633df07736..7623208c28 100644 ) -> tuple[list[dict[str, Any]], int]: """Function to retrieve a paginated list of rooms as json. -@@ -624,6 +625,7 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -798,6 +799,7 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): If true, empty rooms are queried. if false, empty rooms are excluded from the query. When it is none (the default), both empty rooms and none-empty rooms are queried. @@ -65,7 +65,7 @@ index 633df07736..7623208c28 100644 Returns: A list of room dicts and an integer representing the total number of rooms that exist given this query -@@ -792,11 +794,43 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -966,11 +968,43 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): room_count = cast(tuple[int], txn.fetchone()) return rooms, room_count[0] @@ -111,5 +111,5 @@ index 633df07736..7623208c28 100644 async def get_ratelimit_for_user(self, user_id: str) -> RatelimitOverride | None: """Check if there are any overrides for ratelimiting for the given user -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0013-fix-Always-recheck-messages-pagination-data-if-a-bac.patch b/packages/overlays/matrix-synapse/patches/0013-fix-Always-recheck-messages-pagination-data-if-a-bac.patch
index a82c2bc..e983a71 100644 --- a/packages/overlays/matrix-synapse/patches/0013-fix-Always-recheck-messages-pagination-data-if-a-bac.patch +++ b/packages/overlays/matrix-synapse/patches/0013-fix-Always-recheck-messages-pagination-data-if-a-bac.patch
@@ -1,4 +1,4 @@ -From 3d1e47c508e424851af16abe8ae2169c82bb2f85 Mon Sep 17 00:00:00 2001 +From 21cd3ad37d016c06494f0ff95c9bfd39fd92c6d4 Mon Sep 17 00:00:00 2001 From: Jason Little <j.little@famedly.com> Date: Wed, 30 Apr 2025 09:29:42 -0500 Subject: [PATCH 13/19] fix: Always recheck `/messages` pagination data if a @@ -11,7 +11,7 @@ Signed-off-by: Rory& <root@rory.gay> 2 files changed, 33 insertions(+), 36 deletions(-) diff --git a/synapse/handlers/federation.py b/synapse/handlers/federation.py -index 7808f8928b..7131a7ae3d 100644 +index b3444dd2ef..2d5612fc04 100644 --- a/synapse/handlers/federation.py +++ b/synapse/handlers/federation.py @@ -191,7 +191,7 @@ class FederationHandler: @@ -32,7 +32,7 @@ index 7808f8928b..7131a7ae3d 100644 """ # Starting the processing time here so we can include the room backfill # linearizer lock queue in the timing -@@ -306,7 +304,7 @@ class FederationHandler: +@@ -308,7 +306,7 @@ class FederationHandler: limit=1, ) if not have_later_backfill_points: @@ -41,7 +41,7 @@ index 7808f8928b..7131a7ae3d 100644 logger.debug( "_maybe_backfill_inner: all backfill points are *after* current depth. Trying again with later backfill points." -@@ -326,15 +324,15 @@ class FederationHandler: +@@ -328,15 +326,15 @@ class FederationHandler: ) # We return `False` because we're backfilling in the background and there is # no new events immediately for the caller to know about yet. @@ -60,7 +60,7 @@ index 7808f8928b..7131a7ae3d 100644 # If we're approaching an extremity we trigger a backfill, otherwise we # no-op. -@@ -353,7 +351,7 @@ class FederationHandler: +@@ -355,7 +353,7 @@ class FederationHandler: current_depth, limit, ) @@ -69,7 +69,7 @@ index 7808f8928b..7131a7ae3d 100644 # For performance's sake, we only want to paginate from a particular extremity # if we can actually see the events we'll get. Otherwise, we'd just spend a lot -@@ -421,7 +419,7 @@ class FederationHandler: +@@ -423,7 +421,7 @@ class FederationHandler: logger.debug( "_maybe_backfill_inner: found no extremities which would be visible" ) @@ -78,7 +78,7 @@ index 7808f8928b..7131a7ae3d 100644 logger.debug( "_maybe_backfill_inner: extremities_to_request %s", extremities_to_request -@@ -444,7 +442,7 @@ class FederationHandler: +@@ -446,7 +444,7 @@ class FederationHandler: ) ) @@ -87,7 +87,7 @@ index 7808f8928b..7131a7ae3d 100644 # TODO: Should we try multiple of these at a time? # Number of contacted remote homeservers that have denied our backfill -@@ -467,7 +465,7 @@ class FederationHandler: +@@ -469,7 +467,7 @@ class FederationHandler: # If this succeeded then we probably already have the # appropriate stuff. # TODO: We can probably do something more intelligent here. @@ -96,7 +96,7 @@ index 7808f8928b..7131a7ae3d 100644 except NotRetryingDestination as e: logger.info("_maybe_backfill_inner: %s", e) continue -@@ -491,7 +489,7 @@ class FederationHandler: +@@ -493,7 +491,7 @@ class FederationHandler: ) denied_count += 1 if denied_count >= max_denied_count: @@ -105,7 +105,7 @@ index 7808f8928b..7131a7ae3d 100644 continue logger.info("Failed to backfill from %s because %s", dom, e) -@@ -507,7 +505,7 @@ class FederationHandler: +@@ -509,7 +507,7 @@ class FederationHandler: ) denied_count += 1 if denied_count >= max_denied_count: @@ -114,7 +114,7 @@ index 7808f8928b..7131a7ae3d 100644 continue logger.info("Failed to backfill from %s because %s", dom, e) -@@ -519,7 +517,7 @@ class FederationHandler: +@@ -521,7 +519,7 @@ class FederationHandler: logger.exception("Failed to backfill from %s because %s", dom, e) continue @@ -123,7 +123,7 @@ index 7808f8928b..7131a7ae3d 100644 # If we have the `processing_start_time`, then we can make an # observation. We wouldn't have the `processing_start_time` in the case -@@ -531,14 +529,9 @@ class FederationHandler: +@@ -533,14 +531,9 @@ class FederationHandler: **{SERVER_NAME_LABEL: self.server_name} ).observe((processing_end_time - processing_start_time) / 1000) @@ -140,10 +140,10 @@ index 7808f8928b..7131a7ae3d 100644 async def send_invite(self, target_host: str, event: EventBase) -> EventBase: """Sends the invite to the remote server for signing. diff --git a/synapse/handlers/pagination.py b/synapse/handlers/pagination.py -index 63e5dfa70c..13aa2c97f4 100644 +index 2bc7efeb5e..6d4bde4bbe 100644 --- a/synapse/handlers/pagination.py +++ b/synapse/handlers/pagination.py -@@ -632,27 +632,31 @@ class PaginationHandler: +@@ -633,27 +633,31 @@ class PaginationHandler: or missing_too_many_events or not_enough_events_to_fill_response ): @@ -162,7 +162,7 @@ index 63e5dfa70c..13aa2c97f4 100644 - ( - events, - next_key, -- _, +- limited, - ) = await self.store.paginate_room_events_by_topological_ordering( - room_id=room_id, - from_key=from_token.room_key, @@ -179,7 +179,7 @@ index 63e5dfa70c..13aa2c97f4 100644 + ( + events, + next_key, -+ _, ++ limited, + ) = await self.store.paginate_room_events_by_topological_ordering( + room_id=room_id, + from_key=from_token.room_key, @@ -192,5 +192,5 @@ index 63e5dfa70c..13aa2c97f4 100644 # Otherwise, we can backfill in the background for eventual # consistency's sake but we don't need to block the client waiting -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0014-Fix-pagination-with-large-gaps-of-rejected-events.patch b/packages/overlays/matrix-synapse/patches/0014-Fix-pagination-with-large-gaps-of-rejected-events.patch
index 291f9c0..deb4522 100644 --- a/packages/overlays/matrix-synapse/patches/0014-Fix-pagination-with-large-gaps-of-rejected-events.patch +++ b/packages/overlays/matrix-synapse/patches/0014-Fix-pagination-with-large-gaps-of-rejected-events.patch
@@ -1,51 +1,35 @@ -From 5311dbacaa504ba702c22f03b24f527ace458a4a Mon Sep 17 00:00:00 2001 +From aa2cba639cd420a67b9528705187cd8ba21ed93d Mon Sep 17 00:00:00 2001 From: Nicolas Werner <nicolas.werner@hotmail.de> Date: Sun, 8 Jun 2025 23:14:31 +0200 Subject: [PATCH 14/19] Fix pagination with large gaps of rejected events Signed-off-by: Rory& <root@rory.gay> --- - synapse/handlers/pagination.py | 13 +++++++++++-- - 1 file changed, 11 insertions(+), 2 deletions(-) + synapse/handlers/pagination.py | 11 +++++++++++ + 1 file changed, 11 insertions(+) diff --git a/synapse/handlers/pagination.py b/synapse/handlers/pagination.py -index 13aa2c97f4..108ffcdf99 100644 +index 6d4bde4bbe..869b476d87 100644 --- a/synapse/handlers/pagination.py +++ b/synapse/handlers/pagination.py -@@ -565,7 +565,7 @@ class PaginationHandler: - ( - events, - next_key, -- _, -+ limited, - ) = await self.store.paginate_room_events_by_topological_ordering( - room_id=room_id, - from_key=from_token.room_key, -@@ -648,7 +648,7 @@ class PaginationHandler: - ( - events, - next_key, -- _, -+ limited, - ) = await self.store.paginate_room_events_by_topological_ordering( - room_id=room_id, - from_key=from_token.room_key, -@@ -671,6 +671,15 @@ class PaginationHandler: +@@ -672,6 +672,17 @@ class PaginationHandler: next_token = from_token.copy_and_replace(StreamKeyType.ROOM, next_key) + # We might have hit some internal filtering first, for example rejected + # events. Ensure we return a pagination token then. + if not events and limited: -+ return { -+ "chunk": [], -+ "start": await from_token.to_string(self.store), -+ "end": await next_token.to_string(self.store), -+ } ++ return GetMessagesResult( ++ messages_chunk=[], ++ bundled_aggregations={}, ++ state=None, ++ start_token=from_token, ++ end_token=next_token, ++ ) + - # if no events are returned from pagination, that implies - # we have reached the end of the available events. - # In that case we do not return end, to tell the client + # if no events are returned from pagination (this page is empty) + # and there aren't any more pages (not limited), + # that implies we have reached the end of the available events. -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0015-RequestRatelimiter-expose-can_do_action.patch b/packages/overlays/matrix-synapse/patches/0015-RequestRatelimiter-expose-can_do_action.patch
index c16774e..d961013 100644 --- a/packages/overlays/matrix-synapse/patches/0015-RequestRatelimiter-expose-can_do_action.patch +++ b/packages/overlays/matrix-synapse/patches/0015-RequestRatelimiter-expose-can_do_action.patch
@@ -1,4 +1,4 @@ -From 06b8ff395668f72392ae87e676fa900ed80aa562 Mon Sep 17 00:00:00 2001 +From b80719e34f34df23c90b69ca60d53d46f955d451 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Fri, 25 Jul 2025 08:26:15 +0200 Subject: [PATCH 15/19] RequestRatelimiter: expose can_do_action @@ -92,5 +92,5 @@ index d6cc3d26b5..bdc9481e4f 100644 + n_actions=n_actions, + ) -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0016-Clarify-pre_event_ids-assert-in-event-creation-handl.patch b/packages/overlays/matrix-synapse/patches/0016-Clarify-pre_event_ids-assert-in-event-creation-handl.patch
index 9a5a24a..d230cba 100644 --- a/packages/overlays/matrix-synapse/patches/0016-Clarify-pre_event_ids-assert-in-event-creation-handl.patch +++ b/packages/overlays/matrix-synapse/patches/0016-Clarify-pre_event_ids-assert-in-event-creation-handl.patch
@@ -1,4 +1,4 @@ -From 164eb03fe63eb8f07ed8e45fcb9311f5b65ccf8a Mon Sep 17 00:00:00 2001 +From e221cdbc9fa341f4f375bd4f7e5ed740446bfd68 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Sat, 16 Aug 2025 20:19:08 +0200 Subject: [PATCH 16/19] Clarify pre_event_ids assert in event creation handler @@ -9,10 +9,10 @@ Signed-off-by: Rory& <root@rory.gay> 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/synapse/handlers/message.py b/synapse/handlers/message.py -index a6499de3a8..b9dbd255ea 100644 +index 4032c7eca9..435e6b5c14 100644 --- a/synapse/handlers/message.py +++ b/synapse/handlers/message.py -@@ -1274,7 +1274,7 @@ class EventCreationHandler: +@@ -1324,7 +1324,7 @@ class EventCreationHandler: if state_event_ids is not None: # Do a quick check to make sure that prev_event_ids is present to # make the type-checking around `builder.build` happy. @@ -22,5 +22,5 @@ index a6499de3a8..b9dbd255ea 100644 temp_event = await builder.build( prev_event_ids=prev_event_ids, -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0017-Add-bulk-send-events-endpoint.patch b/packages/overlays/matrix-synapse/patches/0017-Add-bulk-send-events-endpoint.patch
index 76a2709..9ed6f9f 100644 --- a/packages/overlays/matrix-synapse/patches/0017-Add-bulk-send-events-endpoint.patch +++ b/packages/overlays/matrix-synapse/patches/0017-Add-bulk-send-events-endpoint.patch
@@ -1,4 +1,4 @@ -From a29ade42ad0e27881e2e6cbd80733e0bab24aeeb Mon Sep 17 00:00:00 2001 +From 47c6aab82a297f3e9db2df7121c16598f8711ac2 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Sat, 26 Jul 2025 09:50:56 +0200 Subject: [PATCH 17/19] Add bulk send events endpoint @@ -16,7 +16,7 @@ Signed-off-by: Rory& <root@rory.gay> 2 files changed, 114 insertions(+), 1 deletion(-) diff --git a/synapse/rest/client/capabilities.py b/synapse/rest/client/capabilities.py -index baff999ab0..5a85a415e6 100644 +index 705d74dee1..075c3de261 100644 --- a/synapse/rest/client/capabilities.py +++ b/synapse/rest/client/capabilities.py @@ -74,6 +74,9 @@ class CapabilitiesRestServlet(RestServlet): @@ -30,7 +30,7 @@ index baff999ab0..5a85a415e6 100644 } diff --git a/synapse/rest/client/room.py b/synapse/rest/client/room.py -index d28be2befb..7bcfdb68ce 100644 +index 7f3b1153f7..168415249b 100644 --- a/synapse/rest/client/room.py +++ b/synapse/rest/client/room.py @@ -23,10 +23,12 @@ @@ -46,23 +46,23 @@ index d28be2befb..7bcfdb68ce 100644 import attr from prometheus_client.core import Histogram -@@ -45,6 +47,7 @@ from synapse.api.errors import ( +@@ -51,6 +53,7 @@ from synapse.api.errors import ( UnredactedContentDeletedError, ) from synapse.api.filtering import Filter +from synapse.api.ratelimiting import RequestRatelimiter from synapse.events.utils import ( EventClientSerializer, - SerializeEventConfig, -@@ -52,6 +55,7 @@ from synapse.events.utils import ( - serialize_event, + FilteredEvent, +@@ -58,6 +61,7 @@ from synapse.events.utils import ( + format_event_for_client_v2, ) from synapse.handlers.pagination import GetMessagesResult +from synapse.events import EventBase from synapse.http.server import HttpServer from synapse.http.servlet import ( ResolveRoomIdMixin, -@@ -486,7 +490,6 @@ class RoomSendEventRestServlet(TransactionRestServlet): +@@ -514,7 +518,6 @@ class RoomSendEventRestServlet(TransactionRestServlet): txn_id, ) @@ -70,7 +70,7 @@ index d28be2befb..7bcfdb68ce 100644 def _parse_request_delay( request: SynapseRequest, max_delay: int | None, -@@ -1728,6 +1731,112 @@ class RoomSummaryRestServlet(ResolveRoomIdMixin, RestServlet): +@@ -1758,6 +1761,112 @@ class RoomSummaryRestServlet(ResolveRoomIdMixin, RestServlet): remote_room_hosts, ) @@ -183,7 +183,7 @@ index d28be2befb..7bcfdb68ce 100644 def register_servlets(hs: "HomeServer", http_server: HttpServer) -> None: RoomStateEventRestServlet(hs).register(http_server) -@@ -1737,6 +1846,7 @@ def register_servlets(hs: "HomeServer", http_server: HttpServer) -> None: +@@ -1767,6 +1876,7 @@ def register_servlets(hs: "HomeServer", http_server: HttpServer) -> None: JoinRoomAliasServlet(hs).register(http_server) RoomMembershipRestServlet(hs).register(http_server) RoomSendEventRestServlet(hs).register(http_server) @@ -192,5 +192,5 @@ index d28be2befb..7bcfdb68ce 100644 RoomStateRestServlet(hs).register(http_server) RoomRedactEventRestServlet(hs).register(http_server) -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0018-admin-api-send-more-data.patch b/packages/overlays/matrix-synapse/patches/0018-admin-api-send-more-data.patch
index fd1d70b..2969f7c 100644 --- a/packages/overlays/matrix-synapse/patches/0018-admin-api-send-more-data.patch +++ b/packages/overlays/matrix-synapse/patches/0018-admin-api-send-more-data.patch
@@ -1,4 +1,4 @@ -From 2192b7e89f700a8203afede1192e71bd1239b733 Mon Sep 17 00:00:00 2001 +From 6cb4af5641c98b0b6149e1201d8c86d72650cab4 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Mon, 27 Oct 2025 19:23:42 +0100 Subject: [PATCH 18/19] admin api - send more data @@ -11,10 +11,10 @@ Signed-off-by: Rory& <root@rory.gay> 3 files changed, 66 insertions(+), 22 deletions(-) diff --git a/synapse/rest/admin/rooms.py b/synapse/rest/admin/rooms.py -index e97d076a44..09a8a01f77 100644 +index 3ff2865b96..cad8f205e3 100644 --- a/synapse/rest/admin/rooms.py +++ b/synapse/rest/admin/rooms.py -@@ -302,7 +302,15 @@ class ListRoomRestServlet(RestServlet): +@@ -303,7 +303,15 @@ class ListRoomRestServlet(RestServlet): reverse_order = True if direction == Direction.BACKWARDS else False emma_include_tombstone = parse_boolean( @@ -31,7 +31,7 @@ index e97d076a44..09a8a01f77 100644 ) # Return list of rooms according to parameters -@@ -314,7 +322,9 @@ class ListRoomRestServlet(RestServlet): +@@ -315,7 +323,9 @@ class ListRoomRestServlet(RestServlet): search_term, public_rooms, empty_rooms, @@ -43,7 +43,7 @@ index e97d076a44..09a8a01f77 100644 response = { diff --git a/synapse/rest/client/capabilities.py b/synapse/rest/client/capabilities.py -index 5a85a415e6..3326ead0d5 100644 +index 075c3de261..c0b0a9923f 100644 --- a/synapse/rest/client/capabilities.py +++ b/synapse/rest/client/capabilities.py @@ -76,6 +76,9 @@ class CapabilitiesRestServlet(RestServlet): @@ -57,10 +57,10 @@ index 5a85a415e6..3326ead0d5 100644 } } diff --git a/synapse/storage/databases/main/room.py b/synapse/storage/databases/main/room.py -index 7623208c28..08735e1fbb 100644 +index 68c2edfc14..e427ffa78a 100644 --- a/synapse/storage/databases/main/room.py +++ b/synapse/storage/databases/main/room.py -@@ -606,6 +606,8 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -780,6 +780,8 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): public_rooms: bool | None, empty_rooms: bool | None, emma_include_tombstone: bool = False, @@ -69,7 +69,7 @@ index 7623208c28..08735e1fbb 100644 ) -> tuple[list[dict[str, Any]], int]: """Function to retrieve a paginated list of rooms as json. -@@ -626,10 +628,13 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -800,10 +802,13 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): if false, empty rooms are excluded from the query. When it is none (the default), both empty rooms and none-empty rooms are queried. emma_include_tombstone: If true, include tombstone events in the results. @@ -83,7 +83,7 @@ index 7623208c28..08735e1fbb 100644 # Filter room names by a string filter_ = [] where_args = [] -@@ -799,35 +804,61 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): +@@ -973,35 +978,61 @@ class RoomWorkerStore(CacheInvalidationWorkerStore): _get_rooms_paginate_txn, ) @@ -166,5 +166,5 @@ index 7623208c28..08735e1fbb 100644 return result -- -2.51.2 +2.53.0 diff --git a/packages/overlays/matrix-synapse/patches/0019-Allow-overriding-max-background-task-count.patch b/packages/overlays/matrix-synapse/patches/0019-Allow-overriding-max-background-task-count.patch
index 7d265fc..bc1c344 100644 --- a/packages/overlays/matrix-synapse/patches/0019-Allow-overriding-max-background-task-count.patch +++ b/packages/overlays/matrix-synapse/patches/0019-Allow-overriding-max-background-task-count.patch
@@ -1,4 +1,4 @@ -From 16e117cdf44f6709c112b388789680adbb2993bc Mon Sep 17 00:00:00 2001 +From 19d1e97075b24788daaf2895da3b46762b461ab3 Mon Sep 17 00:00:00 2001 From: Rory& <root@rory.gay> Date: Tue, 28 Oct 2025 00:01:45 +0100 Subject: [PATCH 19/19] Allow overriding max background task count @@ -19,7 +19,7 @@ index 0000000000..680342cfa2 @@ -0,0 +1 @@ +select * from scheduled_tasks where status != 'complete'; diff --git a/synapse/config/ratelimiting.py b/synapse/config/ratelimiting.py -index 78d9d61d3c..42891e3e4c 100644 +index 13c9c4dba0..a8add434d2 100644 --- a/synapse/config/ratelimiting.py +++ b/synapse/config/ratelimiting.py @@ -84,6 +84,7 @@ class RatelimitConfig(Config): @@ -31,10 +31,10 @@ index 78d9d61d3c..42891e3e4c 100644 # to the old method. if "rc_message" in config: diff --git a/synapse/util/task_scheduler.py b/synapse/util/task_scheduler.py -index 353ddb70bc..a0326473ef 100644 +index c1790fd3ae..a083e5b694 100644 --- a/synapse/util/task_scheduler.py +++ b/synapse/util/task_scheduler.py -@@ -140,6 +140,12 @@ class TaskScheduler: +@@ -142,6 +142,12 @@ class TaskScheduler: hook=lambda: {(self.server_name,): len(self._running_tasks)}, ) @@ -48,5 +48,5 @@ index 353ddb70bc..a0326473ef 100644 self, function: Callable[ -- -2.51.2 +2.53.0 diff --git a/prebuild.sh b/prebuild.sh new file mode 100755
index 0000000..b3a3e99 --- /dev/null +++ b/prebuild.sh
@@ -0,0 +1,22 @@ +#!/usr/bin/env nix-shell +#!nix-shell -i bash -p git nixos-install-tools +if [ $# -ne 1 ]; then + echo "Usage: $0 <config>" + echo "NOTE: hardware config will be generated from root!" + echo "Defined configs:" + cat flake.nix | grep '.lib.nixosSystem' | sed 's/ =.*//' | sed 's/^[ \t]*//;s/[ \t]*$//' | while read cfg; do echo " - $cfg"; done + exit 1 +fi + +CONFIG=$1 + +DERIVATION=".#nixosConfigurations.${CONFIG}.config.system.build.toplevel" +EXTRA_NIX_FLAGS="-vL --accept-flake-config --keep-going --show-trace --option allow-import-from-derivation false -j 128" +EXTRA_NIXOS_REBUILD_FLAGS="--sudo --no-reexec --offline" # legacy: --use-remote-sudo --fast + +[ -f "host/${CONFIG}/hooks/pre-rebuild.sh" ] && echo "<=== RUNNING PRE-REBUILD HOOK AT host/${CONFIG}/hooks/pre-rebuild.sh ===>" && host/${CONFIG}/hooks/pre-rebuild.sh +[ ! -f "hardware-configuration.nix" ] && echo "<=== GENERATING NEW HARDWARE CONFIG ===>" && nixos-generate-config --show-hardware-config > hardware-configuration.nix +git add -f hardware-configuration.nix +echo "<=== REBUILDING NIXOS CONFIGURATION FOR ${CONFIG} ===>" +nom build $DERIVATION $EXTRA_NIX_FLAGS && echo "<=== SWITCHING TO NEW CONFIGURATION ===>" +git rm --cached hardware-configuration.nix diff --git a/update.sh b/update.sh
index 290a208..5fe7639 100755 --- a/update.sh +++ b/update.sh
@@ -9,5 +9,5 @@ if [ -d "nixpkgs" ]; then fi echo '<=== UPDATING FLAKE INPUTS ===>' -nix flake update -vL +nix flake update --accept-flake-config -vL ./build.sh / $HOSTNAME