summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hostnix/mojo/flake.lock12
-rw-r--r--hostnix/mojo/flake.nix97
-rw-r--r--hostnix/mojo/modules/apps.nix41
-rw-r--r--hostnix/mojo/modules/obsidian.nix17
-rw-r--r--hostnix/mojo/modules/sunshine.nix18
-rw-r--r--hostnix/mojo/modules/system.nix29
-rw-r--r--hostnix/mojo/packages/claude-code/claude.sb (renamed from hostnix/mojo/claude.sb)5
-rw-r--r--hostnix/mojo/packages/claude-code/default.nix16
8 files changed, 166 insertions, 69 deletions
diff --git a/hostnix/mojo/flake.lock b/hostnix/mojo/flake.lock
index 4ae7ec6..fe8e437 100644
--- a/hostnix/mojo/flake.lock
+++ b/hostnix/mojo/flake.lock
@@ -23,11 +23,11 @@
},
"nixpkgs": {
"locked": {
- "lastModified": 1773679630,
- "narHash": "sha256-w1T/F8hUiEayrRda277EpXW8LxrSkeer0/4HaCGsEE4=",
+ "lastModified": 1782904953,
+ "narHash": "sha256-ESJ4VgytmAt+98YLM8466luln4HyEZ9Q36b9+Bb4P5w=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "5560a08b531df7bca64849b0c02834dd897878db",
+ "rev": "0921fdb3e13e40fe25fbc52b89661a9d6d32ac68",
"type": "github"
},
"original": {
@@ -39,11 +39,11 @@
},
"nixpkgs-unstable": {
"locked": {
- "lastModified": 1775888245,
- "narHash": "sha256-nwASzrRDD1JBEu/o8ekKYEXm/oJW6EMCzCRdrwcLe90=",
+ "lastModified": 1784176690,
+ "narHash": "sha256-RUXu+GHGkY+eShsqx8hp0BIIo51K3V1Q8AY4pPAUcDw=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "13043924aaa7375ce482ebe2494338e058282925",
+ "rev": "6368bc923cec55a5f78960ade0cb4dd99580e087",
"type": "github"
},
"original": {
diff --git a/hostnix/mojo/flake.nix b/hostnix/mojo/flake.nix
index 3ea5265..a61430f 100644
--- a/hostnix/mojo/flake.nix
+++ b/hostnix/mojo/flake.nix
@@ -8,73 +8,46 @@
nix-darwin.inputs.nixpkgs.follows = "nixpkgs";
};
- outputs = inputs@{ self, nix-darwin, nixpkgs, nixpkgs-unstable }:
- let
- configuration = { pkgs, ... }: {
- environment.systemPackages = let
- # TODO is there a better way to do this?
- pkgsUnstable = import nixpkgs-unstable {
- localSystem = pkgs.stdenv.system;
- config.allowUnfree = true;
- };
- in
- [
- pkgs.direnv
- pkgs.nix-direnv
-
- (pkgs.writeShellScriptBin "claude" ''
- exec /usr/bin/sandbox-exec -f ${self}/claude.sb \
- -D TARGET_DIR=$HOME/src \
- -D TMP_DIR=/tmp \
- -D HOME_DIR=$HOME \
- -D CACHE_DIR=$HOME/.cache \
- ${pkgsUnstable.claude-code}/bin/claude \
- --allow-dangerously-skip-permissions "$@"
- '')
- pkgsUnstable.jujutsu
- ];
-
- # $ chsh -s /run/current-system/sw/bin/bash
- environment.shells = [ pkgs.bashInteractive ];
- programs.bash.completion.enable = true;
-
- nix.settings.experimental-features = "nix-command flakes";
-
- system.primaryUser = "joe";
+ outputs =
+ inputs@{
+ self,
+ nix-darwin,
+ nixpkgs,
+ nixpkgs-unstable,
+ }:
+ let
+ configuration =
+ { pkgs, pkgsUnstable, ... }:
+ {
+ nix.settings.experimental-features = "nix-command flakes";
- # Set Git commit hash for darwin-version.
- system.configurationRevision = self.rev or self.dirtyRev or null;
+ # Set Git commit hash for darwin-version.
+ system.configurationRevision = self.rev or self.dirtyRev or null;
- # Used for backwards compatibility, please read the changelog before changing.
- # $ darwin-rebuild changelog
- system.stateVersion = 6;
+ # Used for backwards compatibility, please read the changelog before changing.
+ # $ darwin-rebuild changelog
+ system.stateVersion = 6;
- # The platform the configuration will be used on.
- nixpkgs.hostPlatform = "aarch64-darwin";
-
- nixpkgs.config.allowUnfree = true;
- };
+ # The platform the configuration will be used on.
+ nixpkgs.hostPlatform = "aarch64-darwin";
+ };
- apps = { pkgs, ... }: {
- homebrew = {
- enable = true;
- # Enable after nix-darwin 25.11
- # enableBashIntegration = true;
- onActivation.cleanup = "uninstall";
- brews = [ "mas" ];
- casks = [ "linearmouse" ];
- masApps = {
- "Ghostery Privacy Ad Blocker" = 6504861501;
- "Kagi for Safari" = 1622835804;
- "KeePassium (KeePass passwords)" = 1435127111;
- Xcode = 497799835;
+ in
+ {
+ darwinConfigurations.mojo = nix-darwin.lib.darwinSystem {
+ specialArgs = {
+ pkgsUnstable = import nixpkgs-unstable {
+ system = "aarch64-darwin";
+ config.allowUnfree = true;
+ };
};
+ modules = [
+ configuration
+ ./modules/apps.nix
+ ./modules/obsidian.nix
+ ./modules/sunshine.nix
+ ./modules/system.nix
+ ];
};
};
- in
- {
- darwinConfigurations.mojo = nix-darwin.lib.darwinSystem {
- modules = [ configuration apps ];
- };
- };
}
diff --git a/hostnix/mojo/modules/apps.nix b/hostnix/mojo/modules/apps.nix
new file mode 100644
index 0000000..5c10633
--- /dev/null
+++ b/hostnix/mojo/modules/apps.nix
@@ -0,0 +1,41 @@
+{ pkgs, pkgsUnstable, ... }:
+{
+ environment.systemPackages = [
+ pkgs.direnv
+ pkgs.fd
+ pkgs.fzf
+ pkgs.nix-direnv
+ pkgs.nixfmt
+ pkgs.ripgrep
+ pkgs.tmux
+ pkgs.tree
+ pkgs.uv
+
+ (pkgsUnstable.callPackage ../packages/claude-code { })
+ pkgsUnstable.jujutsu
+ pkgsUnstable.llama-cpp
+ ];
+
+ environment.pathsToLink = [ "/share/vim-plugins" ]; # for fzf
+
+ homebrew = {
+ taps = [ "LizardByte/homebrew" ];
+
+ brews = [
+ "mas"
+ "sunshine"
+ ];
+
+ casks = [
+ "karabiner-elements" # modifiers, fn, reverse scroll
+ "linearmouse" # scroll by lines, universal back/forward
+ ];
+
+ masApps = {
+ "Ghostery Privacy Ad Blocker" = 6504861501;
+ "Kagi for Safari" = 1622835804;
+ "KeePassium (KeePass passwords)" = 1435127111;
+ Xcode = 497799835;
+ };
+ };
+}
diff --git a/hostnix/mojo/modules/obsidian.nix b/hostnix/mojo/modules/obsidian.nix
new file mode 100644
index 0000000..0357b0f
--- /dev/null
+++ b/hostnix/mojo/modules/obsidian.nix
@@ -0,0 +1,17 @@
+{ ... }:
+{
+ homebrew.casks = [ "obsidian" ];
+
+ launchd.user.agents.obsidian-auto-sync = {
+ script = ''
+ cd /Users/joe/src/Obsidian
+ ./.obsidian/auto-sync
+ '';
+ serviceConfig = {
+ StartInterval = 300;
+ StandardOutPath = "/Users/joe/Library/Logs/obsidian-auto-sync.log";
+ StandardErrorPath = "/Users/joe/Library/Logs/obsidian-auto-sync.log";
+ RunAtLoad = false;
+ };
+ };
+}
diff --git a/hostnix/mojo/modules/sunshine.nix b/hostnix/mojo/modules/sunshine.nix
new file mode 100644
index 0000000..5b02ede
--- /dev/null
+++ b/hostnix/mojo/modules/sunshine.nix
@@ -0,0 +1,18 @@
+{ ... }:
+{
+ homebrew = {
+ taps = [ "LizardByte/homebrew" ];
+ brews = [ "sunshine" ];
+ };
+
+ launchd.user.agents.sunshine = {
+ serviceConfig = {
+ Label = "com.lizardbyte.sunshine";
+ ProgramArguments = [ "/opt/homebrew/bin/sunshine" ];
+ RunAtLoad = true;
+ KeepAlive = true;
+ StandardOutPath = "/tmp/sunshine.log";
+ StandardErrorPath = "/tmp/sunshine.err";
+ };
+ };
+}
diff --git a/hostnix/mojo/modules/system.nix b/hostnix/mojo/modules/system.nix
new file mode 100644
index 0000000..2109311
--- /dev/null
+++ b/hostnix/mojo/modules/system.nix
@@ -0,0 +1,29 @@
+{
+ pkgs,
+ pkgsUnstable,
+ self,
+ ...
+}:
+{
+ nixpkgs.config.allowUnfree = true;
+
+ homebrew = {
+ enable = true;
+ # Enable after nix-darwin 25.11
+ # enableBashIntegration = true;
+ caskArgs.require_sha = true;
+ # Error: Refusing to uninstall /opt/homebrew/Cellar/brotli/1.2.0, [...snip...]
+ # because they are required by sunshine, which is currently installed.
+ # onActivation.cleanup = "uninstall";
+ };
+
+ system.primaryUser = "joe";
+
+ security.sudo.extraConfig = ''
+ Defaults!/run/current-system/sw/bin/darwin-rebuild timestamp_timeout=120
+ '';
+
+ # $ chsh -s /run/current-system/sw/bin/bash
+ environment.shells = [ pkgs.bashInteractive ];
+ programs.bash.completion.enable = true;
+}
diff --git a/hostnix/mojo/claude.sb b/hostnix/mojo/packages/claude-code/claude.sb
index 72797de..1117b18 100644
--- a/hostnix/mojo/claude.sb
+++ b/hostnix/mojo/packages/claude-code/claude.sb
@@ -293,4 +293,7 @@
;; themselves. Otherwise it will set PATH to "" and disable colored output
(allow file-read* (literal "/Users"))
(allow file-read* (literal "/Users/joe"))
-(allow file-read* (literal "/Users/joe/src"))
+(allow file-read* (subpath "/Users/joe/src"))
+
+(allow file-read* (subpath (string-append (param "HOME_DIR") "/.dotfiles")))
+(deny file-read* (subpath (string-append (param "HOME_DIR") "/.dotfiles/tmp")))
diff --git a/hostnix/mojo/packages/claude-code/default.nix b/hostnix/mojo/packages/claude-code/default.nix
new file mode 100644
index 0000000..a9798fd
--- /dev/null
+++ b/hostnix/mojo/packages/claude-code/default.nix
@@ -0,0 +1,16 @@
+{ writeShellScriptBin, claude-code }:
+
+writeShellScriptBin "claude" ''
+ if [[ $HOME/ = ''${PWD%/}/* ]]; then
+ echo "fatal: refusing to allow access to $PWD" >&2
+ exit 1
+ fi
+
+ exec /usr/bin/sandbox-exec -f ${./claude.sb} \
+ -D TARGET_DIR="$(realpath "$PWD")" \
+ -D TMP_DIR=/tmp \
+ -D HOME_DIR="$HOME" \
+ -D CACHE_DIR="$HOME/.cache" \
+ ${claude-code}/bin/claude \
+ --allow-dangerously-skip-permissions "$@"
+''