| Age | Commit message (Collapse) | Author |
|
/usr/bin/git is an xcode-select shim that needs to stat
/Library/Developer/CommandLineTools to find the real git binary; the
sandbox denied that path by default, breaking git entirely.
Separately, when TARGET_DIR is a subdirectory of a larger repo, the
real .git/.jj directories live above TARGET_DIR and were unwritable,
breaking commits from within the subdirectory. default.nix now
resolves the real git/jj dirs at launch and passes them through as
GIT_DIR/JJ_DIR sandbox params.
|
|
|
|
|
|
|
|
|
|
Sometimes seems to work with uninstall, but generally doesn't.
|
|
|
|
git-daemon-export-ok is a very simply access control for
git-http-backend. We explicitly disable it.
See https://github.com/NixOS/nixpkgs/commit/8b6fc43e100d053ed4e7fd28f4f1edf04f0d5374
|
|
n8n has trouble building and just seems to be unnecessary trouble. FWIW
it seems like we could improve our configuration by using the more
standard services.n8n.environment
|
|
There appear to be some issues:
- Remap Super/Alt on client
- Mouse pointer disappears
- Scroll not working
- Letterboxing
|
|
Also install fd and rg so those vim fzf commands work
|
|
Perhaps less secure but we're running this command a whole lot.
|
|
Every activation fails with trying to uninstall sunshine's dependencies,
for some reason.
|
|
|
|
Give access to .dotfiles, fix ~/src subdirectories, and check that we
don't allow access to everything.
|
|
|
|
|
|
Cannot use nix-darwin because of https://github.com/nix-darwin/nix-darwin/issues/1041
Anyway since it uses kernel extensions, etc, this might be better via
the cask.
Since Karabiner-Elements creates a virtual device, it should be
configured before LinearMouse. Unlike LinearMouse, reverse scrolling
works with iPad continuity too
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Rollback nixpkgs for https://github.com/NixOS/nixpkgs/issues/507531
|
|
From https://github.com/neko-kai/claude-code-sandbox
|
|
|
|
|
|
|
|
|
|
Some other minor adjustments to entity naming, fan, and grow light.
|
|
Use a disposable domain until thinking more about authentication.
|
|
|
|
|
|
$ nix flake update --override-input nixpkgs github:NixOS/nixpkgs/ea156c6c3a5b67b0120f92f664853914a58d3b05
Avoid cgit issue until fix lands on stable:
https://github.com/NixOS/nixpkgs/pull/477185
|
|
|
|
- More reliable smart plug on panel light
- SAD lamp timer
|
|
Replaces unmaintained header authentication behind oauth2-proxy.
Add OIDC client for Home Assistant:
- Callback URLs: https://ha.mou.fo/auth/oidc/callback
- Public Client
To link OIDC credentials with the existing joe user, temporarily set:
auth_oidc.features.automatic_user_linking = true;
See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users
Must login through either:
- https://ha.mou.fo/auth/oidc/welcome
- https://ha.mou.fo/auth/oidc/redirect
Injecting directly into the landing login page is pending
https://github.com/christiaangoossens/hass-oidc-auth/issues/19
|
|
Much simpler to configure and use.
|
|
|
|
|
|
The auth_header Home Assistant custom component has been removed. For
now we use the last package from:
https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
|
|
NixOS 25.11 contains Nix 2.30 which now builds to /nix/var/nix/builds,
which is not space constrained like the previous default of /tmp. To
perform the upgrade to NixOS 25.11, we first must unset our build-dir
from a world writable directory.
See https://github.com/nixos/nix/issues/13701
|
|
|
|
|
|
Getting the right permissions set on the socket is quite awkward.
Perhaps listening on a port would have been preferable. systemd socket
activation would require us to support file descriptor handoff (which
would need to be changed in Nitro).
|
|
|
|
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi
anyway, so remove it. It may be possible to use Broadcom open source
drivers for our BCM4360, but these may only support newer hardware.
Also use allowUnfreePredicate to explicitly whitelist packages.
|
|
|