Files
Nomarchy/templates/downstream/home.nix
Bernardo Magri e2de9062d8
All checks were successful
Check / eval (push) Successful in 2m59s
feat(idle): unlock by fingerprint, and say so — hyprlock never used the PAM flag
Bernardo tested the lock screen after turning `fingerprint.pam` on: sudo took
a finger, hyprlock did nothing. The PAM stack was not the problem — grosshack
sits in /etc/pam.d/hyprlock at order 11400 exactly like sudo's. hyprlock just
never asks it: its PAM conversation runs only on submit, so a module that
wants to prompt *while* polling the reader never gets a turn. hyprlock has its
own fprintd-over-D-Bus backend instead, behind `auth:fingerprint:enabled`,
which nothing in the distro ever set. So `fingerprint.pam = true` promised
"login + sudo" and silently skipped the surface you meet most often.

The second half is the one worth having: enabling the backend alone yields a
reader that works while the field still reads "password…". $FPRINTPROMPT is
the ONLY slot hyprlock renders the ready/scanning/failed messages into, and
ours hardcoded the placeholder — proven on hardware, where a test config with
the backend on unlocked by finger and said nothing whatsoever. A feature that
works and cannot be discovered fails VISION's "discoverable without reading
the README" either way, so the placeholder now carries $FPRINTPROMPT and the
messages mirror sudo's "Enter Password or Place finger".

New `nomarchy.idle.fingerprint` (default false), mirroring
`nomarchy.hardware.fingerprint.pam` the way `nomarchy.keyboard.layout` mirrors
`services.xserver.xkb.layout`: hyprlock is configured in standalone Home
Manager, which has no `osConfig` to derive the NixOS side from. Opt-in rather
than implied, because with no reader hyprlock advertises a scan that cannot
happen. Documented in the template (SoT for opt-in comments) and README —
option-docs caught the missing row, which is the check doing its job.

Verified V2: nix flake check --no-build; checks.option-docs passes (failed
first with "undocumented option", as it should). V3 pending: Bernardo applies
it and confirms the field reads "password… or scan finger" and both factors
work — the mechanism itself is already proven on his reader via a test config.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 12:58:53 +01:00

205 lines
9.8 KiB
Nix
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Your user environment. The Nomarchy desktop (Hyprland, Waybar,
# Ghostty, theming engine, Stylix) comes from homeModules.nomarchy;
# tune it via the nomarchy.* options, add your own packages and
# programs below.
#
# Source of truth for install and flake-init: nomarchy-install copies this
# file and only patches keyboard layout/variant.
{ pkgs, ... }:
{
# Session keyboard — match services.xserver.xkb.* in system.nix (console
# + LUKS prompt follow xkb via the distro module). Installer patches these.
nomarchy.keyboard.layout = "us";
nomarchy.keyboard.variant = "";
# ── Overrides (the desktop is on by default; tweak or opt out) ──────
# nomarchy.terminal = "kitty"; # swap the default terminal
# nomarchy.waybar.enable = false; # bring your own bar
# nomarchy.stylix.enable = false; # opt out of GTK/Qt theming
# nomarchy.dockAudio.enable = false; # keep audio put when docking
# nomarchy.idle.fingerprint = true; # unlock the lock screen by finger too, and
# # say so on the field. Set it alongside
# # nomarchy.hardware.fingerprint.pam in
# # system.nix — hyprlock is configured here
# # and cannot read the NixOS side, and it
# # does not take a finger through PAM at all.
#
# Icon pack: Papirus ships by default (auto Dark/Light by theme mode) and
# is the ONLY icon pack in your closure. To use another, set the `icons`
# field in your theme-state.json to a theme name from a known pack — only
# that pack is then added (no bloat otherwise). Known packs: Papirus,
# Tela, Qogir, Reversal, Numix (see modules/home/theme.nix `iconPacks`).
# e.g. theme-state.json: "icons": "Tela-dark"
# ── Opt-in features — uncomment and tweak to enable ─────────────────
# nomarchy.nightlight = { # scheduled blue-light filter (hyprsunset)
# enable = true; # declarative opt-in (or just enable it from
# # the menu: System Night light)
# temperature = 4000; # night warmth in K — lower is warmer
# sunset = "20:00";
# sunrise = "07:00";
# latitude = "52.52"; # geo mode: set BOTH lat/long and sunrise/
# longitude = "13.40"; # sunset follow your location (wlsunset);
# # the fixed times above are then ignored
# };
#
# nomarchy.updates = { # passive update-awareness indicator + notification
# enable = true;
# interval = "daily"; # how often to check (systemd OnCalendar)
# flatpak = true; # also count Flatpak updates when flatpak is on
# };
#
# nomarchy.monitors = [ # declarative per-output layout, hotplug-applied
# { name = "eDP-1"; position = "0x0"; }
# { name = "HDMI-A-1"; position = "auto-right"; }
# ]; # names from `hyprctl devices`
#
# nomarchy.launchOrFocus = [ # SUPER+<key> focuses the app's window,
# { key = "B"; class = "firefox"; } # or launches it if none is open;
# { key = "O"; class = "obsidian"; }# rows appear in the SUPER+? cheatsheet
# ]; # (class from `hyprctl clients`)
#
# nomarchy.displayProfiles = { # named layouts for the SAME outputs —
# docked = { # switch: System Display Profiles
# monitors = [
# { name = "eDP-1"; resolution = "disable"; }
# { name = "DP-3"; position = "0x0"; }
# { name = "DP-4"; position = "auto-right"; }
# ];
# workspaces = { "1" = "DP-3"; "9" = "DP-4"; }; # optional ws→output pins
# };
# undocked = [ { name = "eDP-1"; position = "0x0"; } ]; # bare list = monitors only
# }; # applied instantly + remembered in the
# # flake state (settings.displayProfile);
# # the menu's Auto-switch row makes dock/
# # undock pick the matching profile
#
# nomarchy.keyboard.devices = { # a specific keyboard's own layout
# "keychron-keychron-k2" = { layout = "de"; };
# };
#
# nomarchy.keyboard.layouts = [ "de" "fr" ]; # optional: put these first in the
# # new-keyboard picker (all installed XKB
# # layouts are searchable without this)
#
# services.nextcloud-client = { # Nextcloud sync client (upstream Home Manager
# enable = true; # module — installs the client and starts it
# startInBackground = true; # with the graphical session; tray icon only,
# }; # no window). Re-comment to remove the app
# # AND its background service.
# ── Application suite ───────────────────────────────────────────────
# A starter complete-workstation set, installed for your user — yours to
# curate. Delete a line to slim the machine; uncomment a suggestion (or
# add your own) to extend it. The desktop itself — terminal, editor
# keybinds, theming — comes from the modules; these are the heavier
# standalone apps the distro doesn't impose by default.
#
# Apps that need system setup beyond a package (Steam's 32-bit stack,
# a daemon, group membership, a kernel module) are NOT here — they're
# opt-in service toggles in system.nix instead (nomarchy.services.* —
# steam, libvirt, obs, docker, gamemode, kdeconnect, adb, wireshark,
# ollama, printing).
home.packages = with pkgs; [
libreoffice-fresh # office suite (documents, sheets, slides)
vscode # code editor (unfree; allowUnfree is on)
(chromium.override { enableWideVine = true; })
# web browser with Widevine DRM (Netflix, Spotify web…);
# unfree CDM — mime defaults → chromium-browser.desktop
gimp # raster image editor
inkscape # vector graphics
mpv # media player
amberol # music player (local library; streaming → spotify below)
# pwvucontrol + calcurse ship with the Waybar module (volume right-click / clock)
# ── More apps — uncomment to add ─────────────────────────────────
# Web browsers (chromium ships above — swap/delete freely)
# firefox
# ungoogled-chromium
# brave # (unfree)
# google-chrome # (unfree)
# Communication
# signal-desktop
# telegram-desktop
# element-desktop # Matrix
# vesktop # Discord (themeable client)
# slack # (unfree)
# zoom-us # (unfree)
# teams-for-linux # community client (no official Linux app)
# thunderbird # email
# Office & documents
# onlyoffice-desktopeditors # stronger MS-Office fidelity
# kdePackages.okular # heavier PDF viewer (zathura ships by default)
# xournalpp # PDF annotation
# pdfarranger
# calibre # ebook library
# texliveFull # full LaTeX toolchain — multi-GB (texliveMedium is lighter)
# Notes / research
# logseq
# obsidian # (unfree)
# joplin-desktop
# anki-bin # flashcards
# zotero # reference manager
# Code & data
# zed-editor
# lazygit
# dbeaver-bin # database GUI
# bruno # API client
# distrobox # containerized dev shells
# Graphics & design
# krita # digital painting
# blender # 3D
# darktable # RAW photo
# Audio / video
# audacity
# shotcut # video editor
# kdePackages.kdenlive # video editor (pulls in KDE libs)
# handbrake # transcoder
# Webcam tuning (rarely needed — the distro's IR-hide covers the
# common dual-sensor problem; these are for genuine tuning cases)
# cameractrls # GUI for exposure/focus/zoom, saves per-camera presets
# v4l-utils # v4l2-ctl CLI: list formats, poke controls directly
# Media
# vlc
# spotify # (unfree)
# newsflash # RSS reader
# Gaming (Steam + GameMode are service toggles in system.nix)
# lutris
# heroic # Epic/GOG launcher
# bottles # Wine prefixes
# prismlauncher # Minecraft
# protonup-qt # Proton-GE manager
# mangohud # in-game overlay
# Files, sync & torrents
# nextcloud-client # bare app — services.nextcloud-client above
# # also autostarts it with the session
# localsend # AirDrop-like transfer
# qbittorrent
# Security
# keepassxc
# bitwarden-desktop
# System
# gnome-disk-utility
# gparted
# baobab # disk usage
# wireguard-tools # WireGuard CLI (NetworkManager imports .conf tunnels natively)
# Local AI (Ollama is a service toggle in system.nix)
# lmstudio # (unfree; large closure)
# alpaca # GTK Ollama UI
];
}