pam_unix rejects empty passwords by default, so if hypridle locked the live session there was nothing the user could type to unlock it. Set allowNullPassword on the hyprlock PAM service so a bare Enter dismisses the locker, matching the empty live account passwords. Scoped to the live host so installed systems still reject empty unlocks. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
105 lines
3.9 KiB
Nix
105 lines
3.9 KiB
Nix
{ config, pkgs, inputs, lib, ... }:
|
|
|
|
{
|
|
# Live-ISO defaults. The install.sh keymap step calls `hyprctl keyword
|
|
# input:kb_layout` at runtime so the user's pick takes effect during the
|
|
# install, and writes the chosen value into the *installed* system.
|
|
console.keyMap = lib.mkDefault "us";
|
|
i18n.defaultLocale = lib.mkDefault "en_US.UTF-8";
|
|
services.xserver.xkb.layout = lib.mkDefault "us";
|
|
|
|
# ISO Branding
|
|
isoImage.volumeID = lib.mkForce "NOMARCHY_LIVE";
|
|
isoImage.edition = lib.mkForce "graphical";
|
|
|
|
# Home Manager activation for the nixos live user is provided by the
|
|
# home-manager.nixosModules.home-manager module wired up in flake.nix.
|
|
|
|
environment.systemPackages = with pkgs; [
|
|
git
|
|
gum
|
|
alacritty
|
|
parted
|
|
btrfs-progs
|
|
cryptsetup
|
|
mkpasswd
|
|
inputs.disko.packages.${pkgs.stdenv.hostPlatform.system}.disko
|
|
(pkgs.makeDesktopItem {
|
|
name = "install-nomarchy";
|
|
desktopName = "Install Nomarchy";
|
|
exec = "alacritty -e sudo /etc/install.sh";
|
|
terminal = false;
|
|
categories = [ "System" ];
|
|
})
|
|
];
|
|
|
|
# Ensure the live environment user has the necessary groups for graphical acceleration and audio
|
|
users.users.nixos.extraGroups = [ "wheel" "video" "render" "audio" "networkmanager" ];
|
|
|
|
# Graphics support for live environment.
|
|
#
|
|
# Force-loading every GPU driver in the initrd (amdgpu+radeon+nouveau+i915)
|
|
# panics most machines — only one of them can claim the GPU and the others
|
|
# explode. List them under `availableKernelModules` instead so udev only
|
|
# loads the one that matches the present hardware. We still force the AMD
|
|
# pair when Plymouth needs KMS early; `virtio_gpu` is auto-loaded when
|
|
# we're booted in QEMU via nomarchy-test-live-iso.
|
|
boot.initrd.availableKernelModules = [
|
|
"amdgpu" "radeon" "nouveau" "i915" "virtio_gpu"
|
|
];
|
|
services.xserver.videoDrivers = [ "amdgpu" "radeon" "nouveau" "modesetting" "fbdev" "virtio" ];
|
|
|
|
environment.etc."install.sh" = {
|
|
source = ../installer/install.sh;
|
|
mode = "0755";
|
|
};
|
|
|
|
environment.etc."hardware-db.sh" = {
|
|
source = ../installer/hardware-db.sh;
|
|
mode = "0644";
|
|
};
|
|
|
|
environment.etc."disko-config.nix" = {
|
|
source = ../installer/disko-config.nix;
|
|
};
|
|
|
|
environment.etc."nomarchy".source = inputs.self;
|
|
|
|
# Embed the git revision the ISO was built from so install.sh can pin the
|
|
# generated flake to the exact same commit. `inputs.self.rev` exists only
|
|
# when the flake is built from a clean git tree; from a dirty worktree we
|
|
# fall back to dirtyRev (which won't be resolvable by `git+https`, so the
|
|
# installer treats it as "unpinned"). Empty file = unpinned.
|
|
environment.etc."nomarchy-rev".text =
|
|
if inputs.self ? rev then inputs.self.rev
|
|
else "";
|
|
|
|
# Auto-login to the graphical session
|
|
services.displayManager.autoLogin.enable = true;
|
|
services.displayManager.autoLogin.user = "nixos";
|
|
|
|
# Allow passwordless sudo for the live user
|
|
security.sudo.wheelNeedsPassword = false;
|
|
|
|
# The live accounts have empty passwords, but pam_unix rejects an empty
|
|
# password by default — which leaves hyprlock unsolvable if the idle
|
|
# timer locks the session (nothing you can type unlocks it). Allow null
|
|
# passwords for the locker so it can be dismissed with a bare Enter.
|
|
# Live-ISO only: installed systems must never accept empty unlocks.
|
|
security.pam.services.hyprlock.allowNullPassword = true;
|
|
|
|
# Override the upstream installer helpLine (says "NixOS", points nowhere
|
|
# useful for us). Shown on every TTY before login and again as the MOTD.
|
|
services.getty.helpLine = lib.mkForce ''
|
|
|
|
Welcome to the Nomarchy live environment.
|
|
|
|
To install Nomarchy: sudo /etc/install.sh
|
|
To preview the install: sudo /etc/install.sh --dry-run
|
|
To resume an interrupted run: sudo /etc/install.sh --resume
|
|
|
|
The graphical session autologins as 'nixos' (no password).
|
|
The 'nixos' and 'root' accounts have empty passwords.
|
|
'';
|
|
}
|