Files
Nomarchy/hosts/live.nix
Bernardo Magri eda8461304 feat(system): Plymouth splash, distroName, allowUnfree, offline-pin hardening
- Plymouth boot splash ported from the legacy branch (modules/nixos/
  plymouth/): logo + eased progress + LUKS entry, background tinted from
  theme-state.json via the new nomarchy.system.stateFile (wired by
  mkFlake/lib.nix; null → Tokyo Night fallback). Default on; OFF on the
  live ISO (boot-message visibility on the install medium). Pulls
  boot.initrd.systemd, which also drives the keyboard-at-LUKS feature.
- system.nixos.distroName = "Nomarchy" (os-release PRETTY_NAME,
  systemd-boot entries, ISO menu label). distroId left "nixos" (feeds
  DEFAULT_HOSTNAME + upstream isNixos checks — roadmapped).
- nixpkgs.config.allowUnfree distro-wide (here + both import-nixpkgs
  sites) — unblocks claude-code for the menu's ask-Claude module.
- systemd-boot.configurationLimit = 10 so entries don't fill the ESP.
- Live ISO: nomarchy.idle.enable = false — hypridle was suspending the
  VM mid-install (the install-hung regression); installed systems keep it.
- flake.nix offline pins (verified 0-leak via a foreign-identity
  gap-analysis probe): the repo's own standalone HM gen + inputDerivations,
  mustache-go + stdenv (stylix re-renders base16 per switch), microcode-amd/
  intel (enableRedistributableFirmware activated updateMicrocode →
  source-build cascade), buildEnv's builder.pl, findXMLCatalogs, and the
  representativeInstall mirror (xkb/initrd-systemd/microcode).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-13 07:37:32 +01:00

113 lines
4.9 KiB
Nix

# Live ISO host — boot the full Nomarchy desktop from a USB stick or QEMU
# without touching the disk. No installer yet (see roadmap); this target
# exists to test the distro end-to-end on real hardware.
{ lib, pkgs, username, nomarchySrc, ... }:
{
networking.hostName = "nomarchy-live";
isoImage.volumeID = lib.mkForce "NOMARCHY_LIVE";
isoImage.edition = lib.mkForce "live";
# The minimal-CD profile slims the image for a CONSOLE installer; this
# ISO is the desktop, so re-enable what it strips. Above all
# fontconfig (upstream forces it off at mkOverride 500): without it
# no configured family resolves — Waybar icons render as tofu and
# Ghostty silently falls back to the wrong font (seen on the
# Latitude 5410). Normal priority (100) beats the override.
fonts.fontconfig.enable = true;
# No boot splash on the install medium: the installer ISO boots its
# own initrd path (squashfs), and visibility of boot messages is
# worth more than polish here. Installed systems get the splash.
nomarchy.system.plymouth.enable = false;
xdg.icons.enable = true;
xdg.mime.enable = true;
xdg.autostart.enable = true;
documentation.enable = true;
documentation.man.enable = true;
# Do NOT touch networking.wireless here: since NixOS 26.05 the
# NetworkManager module drives its wifi backend through it
# (wireless.enable = true + dbusControlled). Force-disabling it
# kills NM's supplicant — wifi devices vanish from nmtui even
# though the driver is loaded (seen on a Latitude 5410 / AX201).
# ── Live user: no password, straight into the desktop ──────────────
users.users.${username} = {
isNormalUser = true;
initialHashedPassword = "";
extraGroups = [ "wheel" "networkmanager" "video" "render" "audio" "input" ];
};
security.sudo.wheelNeedsPassword = false;
services.getty.autologinUser = lib.mkForce username;
# Boot straight into Hyprland once; logging out lands on tuigreet.
services.greetd.settings.initial_session = {
command = "start-hyprland";
user = username;
};
# ── Hardware breadth ────────────────────────────────────────────────
# Force-loading every GPU driver in the initrd (amdgpu+radeon+nouveau+
# i915) panics most machines — only one of them can claim the GPU and
# the others explode. `availableKernelModules` lets udev load just the
# one that matches; virtio_gpu covers QEMU (tools/test-live-iso.sh).
boot.initrd.availableKernelModules = [ "amdgpu" "radeon" "nouveau" "i915" "virtio_gpu" ];
services.qemuGuest.enable = lib.mkDefault true;
# ── The Nomarchy flake on board ─────────────────────────────────────
# Read-only copy in /etc (also pins the flake source into the ISO
# closure); seeded writable into the live home so theme switching —
# state write + `home-manager switch` — works exactly like on an
# installed system. $NOMARCHY_PATH already defaults to ~/.nomarchy.
environment.etc."nomarchy".source = nomarchySrc;
systemd.services.nomarchy-seed-flake = {
description = "Seed a writable Nomarchy flake into the live user's home";
wantedBy = [ "multi-user.target" ];
serviceConfig.Type = "oneshot";
script = ''
home=/home/${username}
if [ ! -e "$home/.nomarchy" ]; then
cp -r ${nomarchySrc} "$home/.nomarchy"
chmod -R u+w "$home/.nomarchy"
chown -R ${username}:users "$home/.nomarchy"
fi
'';
};
services.getty.helpLine = lib.mkForce ''
Welcome to the Nomarchy live environment.
The graphical session autologins as '${username}' (no password).
Theme switching: nomarchy-theme-sync apply <name> (or SUPER+T)
Wallpapers: nomarchy-theme-sync bg next (or SUPER+SHIFT+T)
Install to disk: nomarchy-install
The flake lives at ~/.nomarchy.
'';
# ── Live-session desktop tweaks ─────────────────────────────────────
home-manager.users.${username} = {
# No idle lock/suspend on the install medium: an offline install
# runs 20-30 min unattended, and hypridle would blank the display
# then SUSPEND the machine mid-install (it did — the install-hung
# regression). Installed systems keep idle management.
nomarchy.idle.enable = false;
wayland.windowManager.hyprland.settings = {
# QEMU (and some panels) report a tiny "preferred" mode; ask for
# the highest resolution instead.
monitor = lib.mkForce [ ",highres,auto,1" ];
# Welcome toast once the session is up (concatenated onto the
# base exec-once list).
exec-once = [
"sh -c 'sleep 3; notify-send -a Nomarchy \"Welcome to Nomarchy\" \"SUPER+Return terminal · SUPER+T themes · install with nomarchy-install\"'"
];
};
};
system.stateVersion = "26.05";
}