feat(cli): nomarchy-pull / nomarchy-rebuild / nomarchy-home
Some checks failed
Check / eval (push) Has been cancelled

Split lifecycle into three clear commands (user pick):
  nomarchy-pull     git pull (if checkout) + flake.lock update
  nomarchy-rebuild  system switch on current lock (snap + nvd)
  nomarchy-home     Home Manager switch

Full upgrade: pull && rebuild && home. Legacy sys-update / sys-rebuild /
home-update remain as wrappers. nixos-rebuild-snap uses NOMARCHY_PATH.

V0: flake check --no-build green.
This commit is contained in:
2026-07-10 13:32:50 +01:00
parent 910f357f08
commit 3d5cb21302
9 changed files with 127 additions and 101 deletions

View File

@@ -223,8 +223,8 @@ in
compares the flake's locked inputs (nixpkgs, the Nomarchy input, )
against upstream and when Flatpak is enabled counts Flatpak
updates, surfacing a Waybar indicator + a notification when something
is available. It never changes anything; you still run sys-update /
home-update / flatpak update yourself'' // { default = config.nomarchy.settings.updates.enable or false; };
is available. It never changes anything; you still run nomarchy-pull /
nomarchy-rebuild / nomarchy-home / flatpak update yourself'' // { default = config.nomarchy.settings.updates.enable or false; };
interval = lib.mkOption {
type = lib.types.str;

View File

@@ -798,7 +798,7 @@ ${themeRows}
fi
fi
nomarchy-theme-sync --quiet set settings.fingerprint.pam "$new" --no-switch
notify-send "Fingerprint" "Use for login: $new applies on next sys-rebuild."
notify-send "Fingerprint" "Use for login: $new applies on next nomarchy-rebuild."
;;
esac ;;
@@ -843,7 +843,7 @@ ${themeRows}
printf 'Enter to close.'; read -r _" ;;
*Snapshots*) exec "$0" snapshot ;;
*"older generation"*)
notify-send "System rollback" "Reboot and pick an older NixOS generation in the boot menu (the last 10 are kept). Make it stick: revert the change in ~/.nomarchy, then sys-rebuild. Details: docs/RECOVERY.md §3." ;;
notify-send "System rollback" "Reboot and pick an older NixOS generation in the boot menu (the last 10 are kept). Make it stick: revert the change in ~/.nomarchy, then nomarchy-rebuild. Details: docs/RECOVERY.md §3." ;;
esac ;;
tools)

View File

@@ -69,11 +69,11 @@ in
gpl = "git pull";
gf = "git fetch --all --prune";
# Nix — the flake/store verbs (system/home rebuilds already have the
# sys-update / home-update commands, so they're not re-aliased here).
# Nix — store/flake verbs. Lifecycle is nomarchy-pull /
# nomarchy-rebuild / nomarchy-home (full names on PATH, not aliases).
ns = "nix shell"; # ns nixpkgs#ripgrep
nr = "nix run"; # nr nixpkgs#cowsay
nfu = "nix flake update";
nfu = "nix flake update"; # prefer nomarchy-pull day-to-day
nfc = "nix flake check";
nsearch = "nix search nixpkgs";
ngc = "nix-collect-garbage -d"; # user generations; sudo for system roots

View File

@@ -1,7 +1,7 @@
# Update awareness (opt-in, nomarchy.updates.enable) — a passive background
# check that surfaces a Waybar indicator + a notification when updates are
# available, without ever changing anything (you still run sys-update /
# home-update / flatpak update). It counts:
# available, without ever changing anything (you still run nomarchy-pull /
# nomarchy-rebuild / nomarchy-home / flatpak update). It counts:
# • flake inputs whose locked rev is behind upstream (nixpkgs, the Nomarchy
# input, home-manager …) — via `git ls-remote` on each branch-tracking
# github/git input in flake.lock; offline → skipped, never a false alarm.
@@ -83,7 +83,7 @@ let
msg="$nix flake input(s)"
[ "$fp" -gt 0 ] && msg="$msg · $fp Flatpak(s)"
${pkgs.libnotify}/bin/notify-send -a Nomarchy "Updates available" \
"$msg click the bar icon, or run sys-update."
"$msg click the bar icon, or: nomarchy-pull && nomarchy-rebuild && nomarchy-home"
fi
refresh_bar ;;
status)
@@ -91,7 +91,7 @@ let
[ "$total" -gt 0 ] 2>/dev/null || exit 0 # up to date / unchecked hide
nix=$("$JQ" -r '.nix // 0' "$state"); fp=$("$JQ" -r '.flatpak // 0' "$state")
tip="Updates available"
[ "$nix" -gt 0 ] && tip="$tip\n $nix flake input(s) sys-update"
[ "$nix" -gt 0 ] && tip="$tip\n $nix flake input(s) nomarchy-pull && nomarchy-rebuild && nomarchy-home"
[ "$fp" -gt 0 ] && tip="$tip\n $fp Flatpak(s) flatpak update"
printf '{"text":"󰚰 %d","tooltip":"%s","class":"available"}\n' "$total" "$tip" ;;
upgrade)
@@ -99,9 +99,13 @@ let
nix=$("$JQ" -r '.nix // 0' "$state" 2>/dev/null || echo 0)
fp=$("$JQ" -r '.flatpak // 0' "$state" 2>/dev/null || echo 0)
echo "Pending: $nix flake input(s), $fp Flatpak(s)."
if [ "$nix" -gt 0 ] && command -v sys-update >/dev/null 2>&1; then
read -rp "Run sys-update (flake update + system rebuild)? [y/N] " a
[ "$a" = y ] && sys-update
if [ "$nix" -gt 0 ] && command -v nomarchy-pull >/dev/null 2>&1; then
read -rp "Run nomarchy-pull && nomarchy-rebuild && nomarchy-home? [y/N] " a
if [ "$a" = y ]; then
nomarchy-pull
nomarchy-rebuild
command -v nomarchy-home >/dev/null 2>&1 && nomarchy-home
fi
fi
if [ "$fp" -gt 0 ] && command -v flatpak >/dev/null 2>&1; then
read -rp "Run flatpak update? [y/N] " a

View File

@@ -54,9 +54,9 @@ in
${distroName} a NixOS desktop, themed from one JSON.
sys-update update inputs + rebuild the system
sys-rebuild rebuild the system, no input update
home-update apply home/theme changes (no sudo)
nomarchy-pull git pull + flake input update (no rebuild)
nomarchy-rebuild rebuild the system (current lock)
nomarchy-home rebuild the desktop / Home Manager
nomarchy-theme-sync apply <theme> switch the whole palette
nomarchy-doctor read-only health check
SUPER+? keybindings cheatsheet
@@ -333,25 +333,63 @@ in
nomarchy-control-center # TUI control center
nomarchy-detect-hw # post-install hardware re-probe (HARDWARE.md §8)
# Friendly wrappers for the two rebuild paths (README §3). Run as
# your user: `nix flake update` must NOT run as root (libgit2
# refuses the user-owned flake repo) — sudo happens inside, only
# for the system switch.
(pkgs.writeShellScriptBin "sys-update" ''
# Day-to-day lifecycle (README §3). Always run as your user —
# `nix flake update` / git must not run as root (libgit2 refuses a
# user-owned flake); sudo is only for the system switch.
#
# nomarchy-pull git pull (if checkout) + flake.lock update
# nomarchy-rebuild system switch against the *current* lock
# nomarchy-home Home Manager switch (desktop layer)
#
# Full distro upgrade: nomarchy-pull && nomarchy-rebuild && nomarchy-home
# Config-only system: nomarchy-rebuild
# Theme/desktop only: nomarchy-home
#
# Legacy names (sys-update / sys-rebuild / home-update) stay as
# thin wrappers so old docs and muscle memory keep working.
(pkgs.writeShellScriptBin "nomarchy-pull" ''
set -euo pipefail
if [ "$(id -u)" -eq 0 ]; then
echo "sys-update: run as your normal user (it sudos the rebuild itself)" >&2
echo "nomarchy-pull: run as your normal user" >&2
exit 1
fi
flake="''${NOMARCHY_PATH:-$HOME/.nomarchy}"
echo "sys-update: updating flake inputs in $flake"
if [ ! -d "$flake" ]; then
echo "nomarchy-pull: flake path not found: $flake" >&2
echo " Set NOMARCHY_PATH or clone/symlink your flake to ~/.nomarchy." >&2
exit 1
fi
# 1) Your checkout (system.nix / home.nix / local edits).
if [ -d "$flake/.git" ]; then
echo "nomarchy-pull: git pull --ff-only in $flake"
git -C "$flake" pull --ff-only
else
echo "nomarchy-pull: $flake is not a git checkout skipping git pull"
fi
# 2) Flake inputs (nixpkgs, nomarchy, home-manager, ).
echo "nomarchy-pull: nix flake update in $flake"
nix flake update --flake "$flake"
echo "nomarchy-pull: done next: nomarchy-rebuild then nomarchy-home"
'')
(pkgs.writeShellScriptBin "nomarchy-rebuild" ''
set -euo pipefail
if [ "$(id -u)" -eq 0 ]; then
echo "nomarchy-rebuild: run as your normal user (it sudos the rebuild itself)" >&2
exit 1
fi
flake="''${NOMARCHY_PATH:-$HOME/.nomarchy}"
if [ ! -d "$flake" ]; then
echo "nomarchy-rebuild: flake path not found: $flake" >&2
exit 1
fi
before=$(readlink -f /run/current-system)
log=$(mktemp)
trap 'rm -f "$log"' EXIT
set +e
# Snapshot-first when snapper is on; pass flake path through sudo
# (nixos-rebuild-snap used to hardcode /etc/nixos).
if command -v nixos-rebuild-snap >/dev/null 2>&1; then
sudo nixos-rebuild-snap "$@" 2>&1 | tee "$log"
sudo env NOMARCHY_PATH="$flake" nixos-rebuild-snap "$@" 2>&1 | tee "$log"
else
sudo nixos-rebuild switch --flake "$flake#default" "$@" 2>&1 | tee "$log"
fi
@@ -359,71 +397,32 @@ in
set -e
if [ "$rc" -ne 0 ]; then
echo
echo "sys-update: rebuild FAILED (exit $rc). Last lines:"
echo "nomarchy-rebuild: FAILED (exit $rc). Last lines:"
tail -n 40 "$log" || true
echo
echo "Diagnose: nomarchy-doctor"
echo "Recovery: docs/RECOVERY.md (boot menu generations / snapper)"
exit "$rc"
fi
# What did that update actually change? Package-level diff of the
# old vs new generation (the informative half of "informative +
# rock-stable"); never fails the run.
after=$(readlink -f /run/current-system)
if [ "$before" = "$after" ]; then
echo "sys-update: no changes the system is identical."
echo "nomarchy-rebuild: no changes the system is identical."
else
echo "sys-update: what changed:"
echo "nomarchy-rebuild: what changed:"
${pkgs.nvd}/bin/nvd diff "$before" "$after" || true
fi
'')
# The no-update twin (hardware-QA request): rebuild the system
# against the CURRENT lock — config changes only, no `nix flake
# update` — mirroring how home-update never touches the lock.
# Same snapshot-first path when available.
(pkgs.writeShellScriptBin "sys-rebuild" ''
(pkgs.writeShellScriptBin "nomarchy-home" ''
set -euo pipefail
if [ "$(id -u)" -eq 0 ]; then
echo "sys-rebuild: run as your normal user (it sudos the rebuild itself)" >&2
echo "nomarchy-home: run as your normal user" >&2
exit 1
fi
flake="''${NOMARCHY_PATH:-$HOME/.nomarchy}"
before=$(readlink -f /run/current-system)
log=$(mktemp)
trap 'rm -f "$log"' EXIT
set +e
if command -v nixos-rebuild-snap >/dev/null 2>&1; then
sudo nixos-rebuild-snap "$@" 2>&1 | tee "$log"
else
sudo nixos-rebuild switch --flake "$flake#default" "$@" 2>&1 | tee "$log"
fi
rc=''${PIPESTATUS[0]}
set -e
if [ "$rc" -ne 0 ]; then
echo
echo "sys-rebuild: rebuild FAILED (exit $rc). Last lines:"
tail -n 40 "$log" || true
echo
echo "Diagnose: nomarchy-doctor"
echo "Recovery: docs/RECOVERY.md (boot menu generations / snapper)"
exit "$rc"
fi
# Same what-changed diff as sys-update (the twins stay twins).
after=$(readlink -f /run/current-system)
if [ "$before" = "$after" ]; then
echo "sys-rebuild: no changes the system is identical."
else
echo "sys-rebuild: what changed:"
${pkgs.nvd}/bin/nvd diff "$before" "$after" || true
fi
'')
(pkgs.writeShellScriptBin "home-update" ''
set -euo pipefail
if [ "$(id -u)" -eq 0 ]; then
echo "home-update: run as your normal user" >&2
if [ ! -d "$flake" ]; then
echo "nomarchy-home: flake path not found: $flake" >&2
exit 1
fi
flake="''${NOMARCHY_PATH:-$HOME/.nomarchy}"
log=$(mktemp)
trap 'rm -f "$log"' EXIT
set +e
@@ -432,13 +431,25 @@ in
set -e
if [ "$rc" -ne 0 ]; then
echo
echo "home-update: switch FAILED (exit $rc). Last lines:"
echo "nomarchy-home: FAILED (exit $rc). Last lines:"
tail -n 40 "$log" || true
echo
echo "Diagnose: nomarchy-doctor"
echo "Recovery: home-manager generations (or docs/RECOVERY.md)"
exit "$rc"
fi
echo "nomarchy-home: desktop applied."
'')
# Legacy aliases — same behaviour, old names.
(pkgs.writeShellScriptBin "sys-update" ''
# Was: flake update + system rebuild. Now the two explicit steps.
nomarchy-pull && nomarchy-rebuild "$@"
'')
(pkgs.writeShellScriptBin "sys-rebuild" ''
exec nomarchy-rebuild "$@"
'')
(pkgs.writeShellScriptBin "home-update" ''
exec nomarchy-home "$@"
'')
git
@@ -461,12 +472,15 @@ in
echo "This script must be run as root (use sudo)" >&2
exit 1
fi
# Prefer the path nomarchy-rebuild passes through sudo; fall back
# for hand invocations.
flake="''${NOMARCHY_PATH:-/etc/nixos}"
echo "Creating pre-rebuild snapshot..."
${pkgs.snapper}/bin/snapper -c root create \
-d "Pre-rebuild $(date +'%Y-%m-%d %H:%M:%S')" \
--cleanup-algorithm number
echo "Rebuilding..."
nixos-rebuild switch --flake /etc/nixos#default "$@"
echo "Rebuilding $flake#default ..."
nixos-rebuild switch --flake "$flake#default" "$@"
'')
# The desktop snapshot manager (browse / diff / restore / rollback over
# snapper, elevating via polkit) — the primary `nomarchy-menu snapshot`