hypridle locks hyprlock before every sleep -- right for suspend, but redundant for hibernate: the LUKS passphrase entered at boot already gates the resume, so the user typed a password twice. Add a nomarchy-hibernate- unlock systemd unit (WantedBy hibernate.target, After systemd-hibernate.service => runs post-resume) that dismisses hyprlock, gated on the disk being LUKS- encrypted. Suspend (and the RAM-resume phase of suspend-then-hibernate) keep locking -- they have no passphrase gate; an unencrypted hibernate keeps its lock too. idle.nix gains a pointer comment; roadmap item marked done. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
77 lines
2.2 KiB
Nix
77 lines
2.2 KiB
Nix
# hyprlock + hypridle — screen locking and idle management, themed from
|
|
# theme-state.json. One concern, one file: hypridle drives WHEN (idle
|
|
# lock, display off, suspend, lock-before-sleep), hyprlock is the
|
|
# themed lock screen itself (also behind the power menu's Lock entry).
|
|
{ config, lib, ... }:
|
|
|
|
let
|
|
cfg = config.nomarchy;
|
|
t = cfg.theme;
|
|
c = t.colors;
|
|
inherit (config.nomarchy.lib) rgb;
|
|
in
|
|
{
|
|
config = lib.mkIf cfg.idle.enable {
|
|
programs.hyprlock = {
|
|
enable = true;
|
|
settings = {
|
|
general.hide_cursor = true;
|
|
|
|
background = [{
|
|
monitor = "";
|
|
color = rgb c.base;
|
|
}];
|
|
|
|
input-field = [{
|
|
monitor = "";
|
|
size = "300, 50";
|
|
outline_thickness = t.ui.borderSize;
|
|
dots_size = 0.25;
|
|
outer_color = rgb c.accent;
|
|
inner_color = rgb c.surface;
|
|
font_color = rgb c.text;
|
|
check_color = rgb c.warn;
|
|
fail_color = rgb c.bad;
|
|
rounding = t.ui.rounding;
|
|
placeholder_text = "<i>password…</i>";
|
|
}];
|
|
|
|
label = [{
|
|
monitor = "";
|
|
text = "$TIME";
|
|
color = rgb c.text;
|
|
font_size = 64;
|
|
font_family = t.fonts.ui;
|
|
position = "0, 120";
|
|
halign = "center";
|
|
valign = "center";
|
|
}];
|
|
};
|
|
};
|
|
|
|
services.hypridle = {
|
|
enable = true;
|
|
settings = {
|
|
general = {
|
|
lock_cmd = "pidof hyprlock || hyprlock";
|
|
# Locks before every sleep. For suspend that's exactly right; on an
|
|
# encrypted hibernate the LUKS resume already gates the machine, so
|
|
# the system side dismisses this lock post-resume to avoid a double
|
|
# unlock — see nomarchy-hibernate-unlock in modules/nixos/default.nix.
|
|
before_sleep_cmd = "loginctl lock-session";
|
|
after_sleep_cmd = "hyprctl dispatch dpms on";
|
|
};
|
|
listener = [
|
|
{ timeout = 300; on-timeout = "loginctl lock-session"; }
|
|
{
|
|
timeout = 600;
|
|
on-timeout = "hyprctl dispatch dpms off";
|
|
on-resume = "hyprctl dispatch dpms on";
|
|
}
|
|
{ timeout = 1800; on-timeout = "systemctl suspend"; }
|
|
];
|
|
};
|
|
};
|
|
};
|
|
}
|