diff options
| -rw-r--r-- | hostnix/mojo/flake.lock | 12 | ||||
| -rw-r--r-- | hostnix/mojo/flake.nix | 97 | ||||
| -rw-r--r-- | hostnix/mojo/modules/apps.nix | 41 | ||||
| -rw-r--r-- | hostnix/mojo/modules/obsidian.nix | 17 | ||||
| -rw-r--r-- | hostnix/mojo/modules/sunshine.nix | 18 | ||||
| -rw-r--r-- | hostnix/mojo/modules/system.nix | 29 | ||||
| -rw-r--r-- | hostnix/mojo/packages/claude-code/claude.sb (renamed from hostnix/mojo/claude.sb) | 5 | ||||
| -rw-r--r-- | hostnix/mojo/packages/claude-code/default.nix | 16 |
8 files changed, 166 insertions, 69 deletions
diff --git a/hostnix/mojo/flake.lock b/hostnix/mojo/flake.lock index 4ae7ec6..fe8e437 100644 --- a/hostnix/mojo/flake.lock +++ b/hostnix/mojo/flake.lock @@ -23,11 +23,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1773679630, - "narHash": "sha256-w1T/F8hUiEayrRda277EpXW8LxrSkeer0/4HaCGsEE4=", + "lastModified": 1782904953, + "narHash": "sha256-ESJ4VgytmAt+98YLM8466luln4HyEZ9Q36b9+Bb4P5w=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "5560a08b531df7bca64849b0c02834dd897878db", + "rev": "0921fdb3e13e40fe25fbc52b89661a9d6d32ac68", "type": "github" }, "original": { @@ -39,11 +39,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1775888245, - "narHash": "sha256-nwASzrRDD1JBEu/o8ekKYEXm/oJW6EMCzCRdrwcLe90=", + "lastModified": 1784176690, + "narHash": "sha256-RUXu+GHGkY+eShsqx8hp0BIIo51K3V1Q8AY4pPAUcDw=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "13043924aaa7375ce482ebe2494338e058282925", + "rev": "6368bc923cec55a5f78960ade0cb4dd99580e087", "type": "github" }, "original": { diff --git a/hostnix/mojo/flake.nix b/hostnix/mojo/flake.nix index 3ea5265..a61430f 100644 --- a/hostnix/mojo/flake.nix +++ b/hostnix/mojo/flake.nix @@ -8,73 +8,46 @@ nix-darwin.inputs.nixpkgs.follows = "nixpkgs"; }; - outputs = inputs@{ self, nix-darwin, nixpkgs, nixpkgs-unstable }: - let - configuration = { pkgs, ... }: { - environment.systemPackages = let - # TODO is there a better way to do this? - pkgsUnstable = import nixpkgs-unstable { - localSystem = pkgs.stdenv.system; - config.allowUnfree = true; - }; - in - [ - pkgs.direnv - pkgs.nix-direnv - - (pkgs.writeShellScriptBin "claude" '' - exec /usr/bin/sandbox-exec -f ${self}/claude.sb \ - -D TARGET_DIR=$HOME/src \ - -D TMP_DIR=/tmp \ - -D HOME_DIR=$HOME \ - -D CACHE_DIR=$HOME/.cache \ - ${pkgsUnstable.claude-code}/bin/claude \ - --allow-dangerously-skip-permissions "$@" - '') - pkgsUnstable.jujutsu - ]; - - # $ chsh -s /run/current-system/sw/bin/bash - environment.shells = [ pkgs.bashInteractive ]; - programs.bash.completion.enable = true; - - nix.settings.experimental-features = "nix-command flakes"; - - system.primaryUser = "joe"; + outputs = + inputs@{ + self, + nix-darwin, + nixpkgs, + nixpkgs-unstable, + }: + let + configuration = + { pkgs, pkgsUnstable, ... }: + { + nix.settings.experimental-features = "nix-command flakes"; - # Set Git commit hash for darwin-version. - system.configurationRevision = self.rev or self.dirtyRev or null; + # Set Git commit hash for darwin-version. + system.configurationRevision = self.rev or self.dirtyRev or null; - # Used for backwards compatibility, please read the changelog before changing. - # $ darwin-rebuild changelog - system.stateVersion = 6; + # Used for backwards compatibility, please read the changelog before changing. + # $ darwin-rebuild changelog + system.stateVersion = 6; - # The platform the configuration will be used on. - nixpkgs.hostPlatform = "aarch64-darwin"; - - nixpkgs.config.allowUnfree = true; - }; + # The platform the configuration will be used on. + nixpkgs.hostPlatform = "aarch64-darwin"; + }; - apps = { pkgs, ... }: { - homebrew = { - enable = true; - # Enable after nix-darwin 25.11 - # enableBashIntegration = true; - onActivation.cleanup = "uninstall"; - brews = [ "mas" ]; - casks = [ "linearmouse" ]; - masApps = { - "Ghostery Privacy Ad Blocker" = 6504861501; - "Kagi for Safari" = 1622835804; - "KeePassium (KeePass passwords)" = 1435127111; - Xcode = 497799835; + in + { + darwinConfigurations.mojo = nix-darwin.lib.darwinSystem { + specialArgs = { + pkgsUnstable = import nixpkgs-unstable { + system = "aarch64-darwin"; + config.allowUnfree = true; + }; }; + modules = [ + configuration + ./modules/apps.nix + ./modules/obsidian.nix + ./modules/sunshine.nix + ./modules/system.nix + ]; }; }; - in - { - darwinConfigurations.mojo = nix-darwin.lib.darwinSystem { - modules = [ configuration apps ]; - }; - }; } diff --git a/hostnix/mojo/modules/apps.nix b/hostnix/mojo/modules/apps.nix new file mode 100644 index 0000000..5c10633 --- /dev/null +++ b/hostnix/mojo/modules/apps.nix @@ -0,0 +1,41 @@ +{ pkgs, pkgsUnstable, ... }: +{ + environment.systemPackages = [ + pkgs.direnv + pkgs.fd + pkgs.fzf + pkgs.nix-direnv + pkgs.nixfmt + pkgs.ripgrep + pkgs.tmux + pkgs.tree + pkgs.uv + + (pkgsUnstable.callPackage ../packages/claude-code { }) + pkgsUnstable.jujutsu + pkgsUnstable.llama-cpp + ]; + + environment.pathsToLink = [ "/share/vim-plugins" ]; # for fzf + + homebrew = { + taps = [ "LizardByte/homebrew" ]; + + brews = [ + "mas" + "sunshine" + ]; + + casks = [ + "karabiner-elements" # modifiers, fn, reverse scroll + "linearmouse" # scroll by lines, universal back/forward + ]; + + masApps = { + "Ghostery Privacy Ad Blocker" = 6504861501; + "Kagi for Safari" = 1622835804; + "KeePassium (KeePass passwords)" = 1435127111; + Xcode = 497799835; + }; + }; +} diff --git a/hostnix/mojo/modules/obsidian.nix b/hostnix/mojo/modules/obsidian.nix new file mode 100644 index 0000000..0357b0f --- /dev/null +++ b/hostnix/mojo/modules/obsidian.nix @@ -0,0 +1,17 @@ +{ ... }: +{ + homebrew.casks = [ "obsidian" ]; + + launchd.user.agents.obsidian-auto-sync = { + script = '' + cd /Users/joe/src/Obsidian + ./.obsidian/auto-sync + ''; + serviceConfig = { + StartInterval = 300; + StandardOutPath = "/Users/joe/Library/Logs/obsidian-auto-sync.log"; + StandardErrorPath = "/Users/joe/Library/Logs/obsidian-auto-sync.log"; + RunAtLoad = false; + }; + }; +} diff --git a/hostnix/mojo/modules/sunshine.nix b/hostnix/mojo/modules/sunshine.nix new file mode 100644 index 0000000..5b02ede --- /dev/null +++ b/hostnix/mojo/modules/sunshine.nix @@ -0,0 +1,18 @@ +{ ... }: +{ + homebrew = { + taps = [ "LizardByte/homebrew" ]; + brews = [ "sunshine" ]; + }; + + launchd.user.agents.sunshine = { + serviceConfig = { + Label = "com.lizardbyte.sunshine"; + ProgramArguments = [ "/opt/homebrew/bin/sunshine" ]; + RunAtLoad = true; + KeepAlive = true; + StandardOutPath = "/tmp/sunshine.log"; + StandardErrorPath = "/tmp/sunshine.err"; + }; + }; +} diff --git a/hostnix/mojo/modules/system.nix b/hostnix/mojo/modules/system.nix new file mode 100644 index 0000000..2109311 --- /dev/null +++ b/hostnix/mojo/modules/system.nix @@ -0,0 +1,29 @@ +{ + pkgs, + pkgsUnstable, + self, + ... +}: +{ + nixpkgs.config.allowUnfree = true; + + homebrew = { + enable = true; + # Enable after nix-darwin 25.11 + # enableBashIntegration = true; + caskArgs.require_sha = true; + # Error: Refusing to uninstall /opt/homebrew/Cellar/brotli/1.2.0, [...snip...] + # because they are required by sunshine, which is currently installed. + # onActivation.cleanup = "uninstall"; + }; + + system.primaryUser = "joe"; + + security.sudo.extraConfig = '' + Defaults!/run/current-system/sw/bin/darwin-rebuild timestamp_timeout=120 + ''; + + # $ chsh -s /run/current-system/sw/bin/bash + environment.shells = [ pkgs.bashInteractive ]; + programs.bash.completion.enable = true; +} diff --git a/hostnix/mojo/claude.sb b/hostnix/mojo/packages/claude-code/claude.sb index 72797de..1117b18 100644 --- a/hostnix/mojo/claude.sb +++ b/hostnix/mojo/packages/claude-code/claude.sb @@ -293,4 +293,7 @@ ;; themselves. Otherwise it will set PATH to "" and disable colored output (allow file-read* (literal "/Users")) (allow file-read* (literal "/Users/joe")) -(allow file-read* (literal "/Users/joe/src")) +(allow file-read* (subpath "/Users/joe/src")) + +(allow file-read* (subpath (string-append (param "HOME_DIR") "/.dotfiles"))) +(deny file-read* (subpath (string-append (param "HOME_DIR") "/.dotfiles/tmp"))) diff --git a/hostnix/mojo/packages/claude-code/default.nix b/hostnix/mojo/packages/claude-code/default.nix new file mode 100644 index 0000000..a9798fd --- /dev/null +++ b/hostnix/mojo/packages/claude-code/default.nix @@ -0,0 +1,16 @@ +{ writeShellScriptBin, claude-code }: + +writeShellScriptBin "claude" '' + if [[ $HOME/ = ''${PWD%/}/* ]]; then + echo "fatal: refusing to allow access to $PWD" >&2 + exit 1 + fi + + exec /usr/bin/sandbox-exec -f ${./claude.sb} \ + -D TARGET_DIR="$(realpath "$PWD")" \ + -D TMP_DIR=/tmp \ + -D HOME_DIR="$HOME" \ + -D CACHE_DIR="$HOME/.cache" \ + ${claude-code}/bin/claude \ + --allow-dangerously-skip-permissions "$@" +'' |
