Some checks failed
Check / eval (push) Failing after 2m45s
Bernardo promoted the PROPOSED item live: with fingerprint PAM on, sudo/login should accept whichever factor comes first instead of pam_fprintd's wait-for-the-reader-then-password. Stock PAM cannot express parallel factors (linux-pam#301), so this packages pam-fprint-grosshack v0.3.0 (pkgs/, pinned from GitLab — the field-standard fprintd fork), source-reviewed before packaging: every failure path (no reader, no prints, fprintd absent/hung, timeout, password typed) returns PAM_AUTHINFO_UNAVAIL and falls through; a typed password is only ferried via PAM_AUTHTOK to the stock `auth sufficient pam_unix.so … try_first_pass` rule — the module never validates passwords itself, so it cannot lock out password login. New option nomarchy.hardware.fingerprint.parallel, default TRUE (the better UX is what opting into fingerprint PAM buys; false = stock sequential). Wiring swaps the modulePath of stock fprintd's rule slot (mkForce) so the sufficient-before-pam_unix ordering is inherited, not recomputed. README + downstream template rows added. Verified: V2 — checks.hardware-toggles extended to three nodes, green: parallel node asserts the grosshack auth line precedes pam_unix in /etc/pam.d/sudo and that with NO reader a correct password still passes sudo while a wrong one fails (the lockout-safety invariant); seqpam node gets stock pam_fprintd and no grosshack; nopam gets neither. flake check + option-docs + template-sot green. V3 pending (HARDWARE-QUEUE, AMD dev box): the real type-or-touch race, fprintd-stopped fallback, hyprlock/greeter after a fingerprint win. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
101 lines
5.9 KiB
Nix
101 lines
5.9 KiB
Nix
# Your machine: bootloader, hostname, users, services.
|
||
# The distro itself comes from nomarchy.nixosModules.nomarchy — override
|
||
# any of its defaults here with plain NixOS options (they use mkDefault),
|
||
# or via the nomarchy.system.* toggles.
|
||
#
|
||
# Source of truth for install and flake-init: nomarchy-install copies this
|
||
# file and only patches placeholders + the __NOMARCHY_INSTALLER__ region.
|
||
{ pkgs, username, ... }:
|
||
|
||
{
|
||
boot.loader.systemd-boot.enable = true;
|
||
boot.loader.efi.canTouchEfiVariables = true;
|
||
|
||
networking.hostName = "my-nomarchy";
|
||
time.timeZone = "UTC";
|
||
i18n.defaultLocale = "en_US.UTF-8";
|
||
|
||
# One keyboard layout everywhere: xkb is the source of truth; the distro
|
||
# defaults (console.useXkbConfig + systemd initrd) derive the virtual
|
||
# console and the LUKS passphrase prompt from it. Match home.nix
|
||
# nomarchy.keyboard.*.
|
||
services.xserver.xkb.layout = "us";
|
||
services.xserver.xkb.variant = "";
|
||
|
||
# Your login user — `username` flows in from flake.nix automatically.
|
||
# The installer adds initialHashedPassword here; flake-init: set a password
|
||
# (or users.mutableUsers) before first boot if needed.
|
||
users.users.${username} = {
|
||
isNormalUser = true;
|
||
extraGroups = [ "wheel" "networkmanager" "video" "input" ];
|
||
};
|
||
|
||
# __NOMARCHY_INSTALLER_BEGIN__
|
||
# Installer fills this region (power, hardware, snapper, resume, autoLogin).
|
||
# Flake-init: leave empty and use the commented catalog below, or enable
|
||
# snapper when on BTRFS with a /.snapshots subvolume:
|
||
# nomarchy.system.snapper.enable = true;
|
||
# __NOMARCHY_INSTALLER_END__
|
||
|
||
# ── Overrides (uncomment to change) ─────────────────────────────────
|
||
# nomarchy.system.greeter.enable = false; # bring your own login manager
|
||
# environment.systemPackages = [ pkgs.htop ];
|
||
|
||
# ── Opt-in features — uncomment and tweak to enable ─────────────────
|
||
# nomarchy.system.power = { # active power management (laptops)
|
||
# enable = true;
|
||
# backend = "ppd"; # "ppd" (default) or "tlp"
|
||
# laptop = true; # required by batteryChargeLimit
|
||
# batteryChargeLimit = 80; # cap charging for longevity
|
||
# thermal.enable = true; # thermald (Intel CPUs)
|
||
# };
|
||
#
|
||
# nomarchy.system.autoTimezone.enable = true; # clock follows your location
|
||
# # (geoclue); travelling updates the
|
||
# # time on its own. Unsets time.timeZone
|
||
# # above. Easier toggled from System menu.
|
||
#
|
||
# nomarchy.hardware = { # enablement above nixos-hardware (installer-detected)
|
||
# intel.enable = true; # GuC/HuC firmware; installer sets this on Intel
|
||
# intel.computeRuntime = true; # OpenCL/oneVPL GPU compute (opt-in)
|
||
# amd.enable = true; # amd-pstate + radeonsi VA-API; installer-set on AMD
|
||
# amd.rocm.enable = true; # ROCm GPU compute (multi-GB, opt-in)
|
||
# amd.rocm.gfxOverride = "11.0.0"; # HSA override for an unlisted iGPU
|
||
# fingerprint.enable = true; # fprintd; installer-set when a reader is detected
|
||
# fingerprint.pam = true; # use the fingerprint for login + sudo
|
||
# fingerprint.parallel = false; # sequential prompt instead of password-or-finger
|
||
# npu.enable = true; # on-die NPU driver (experimental; userspace runtime BYO)
|
||
# latestKernel = true; # newest kernel for very-new hardware (drivers not yet in the default)
|
||
# camera.hideIrSensor = true; # dual-sensor webcam: hide the IR node so apps get the color cam
|
||
# # (installer-set when a paired RGB+IR webcam is detected)
|
||
# i2c.enable = true; # /dev/i2c-* (RGB, sensors); ddcci is distro-default for external brightness
|
||
# i2c.ddcci = true; # already mkDefault true — set false to opt out
|
||
# };
|
||
#
|
||
# nomarchy.services.tailscale.enable = true; # mesh VPN — connect from System › VPN
|
||
# # (login user is operator, no sudo)
|
||
# nomarchy.services.syncthing.enable = true; # file sync — GUI at http://127.0.0.1:8384
|
||
# nomarchy.services.podman.enable = true; # rootless containers (docker → podman)
|
||
# nomarchy.services.flatpak.enable = true; # Flatpak + the Flathub remote
|
||
# nomarchy.services.pika.enable = true; # Pika Backup (GUI Borg backups)
|
||
# nomarchy.services.steam.enable = true; # Steam (32-bit libs, controllers, ports)
|
||
# nomarchy.services.libvirt.enable = true; # libvirt/KVM + virt-manager GUI
|
||
# nomarchy.services.obs.enable = true; # OBS Studio + v4l2loopback virtual camera
|
||
# nomarchy.services.docker.enable = true; # Docker rootful (not alongside podman)
|
||
# nomarchy.services.kdeconnect.enable = true;# KDE Connect phone integration (opens ports)
|
||
# nomarchy.services.gamemode.enable = true; # Feral GameMode performance daemon
|
||
# nomarchy.services.adb.enable = true; # Android adb/fastboot tools
|
||
# nomarchy.services.wireshark.enable = true; # Wireshark GUI (wireshark group, no root)
|
||
# nomarchy.services.ollama.enable = true; # local LLM runtime (127.0.0.1:11434)
|
||
# nomarchy.services.printing.enable = true; # CUPS + Avahi network printer discovery
|
||
# nomarchy.services.openrgb.enable = true; # RGB peripheral/motherboard lighting daemon
|
||
# nomarchy.services.restic = { # scheduled (daily) restic backup
|
||
# enable = true;
|
||
# repository = "/mnt/backup/restic"; # path or URL (sftp:/b2:/…)
|
||
# passwordFile = "/etc/nomarchy/restic-password"; # absolute path, NOT in the flake
|
||
# paths = [ "/home" ];
|
||
# };
|
||
|
||
system.stateVersion = "26.05";
|
||
}
|