13 Commits

Author SHA1 Message Date
Hadi f0c36f56c4 linux kernel to stable
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-21 19:02:35 +02:00
Hadi 1b2dcfc20a scroll and center
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-21 18:32:47 +02:00
Hadi af19b9f1b7 edit usbguard rules
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-21 18:32:47 +02:00
Hadi c8f02ec056 Update flake
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 14:58:16 +02:00
Hadi 3bd0a45538 add navi
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 14:52:54 +02:00
Hadi cb74a5744f Hardening: Vulnix + kernel hardening
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 14:38:47 +02:00
Hadi 4e016613cd new rules
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 14:34:38 +02:00
Hadi 688bd920de add border layout style
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 11:18:11 +02:00
Hadi b747c7c359 add grace
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 11:18:02 +02:00
Hadi 445829e365 update rules
Signed-off-by: Hadi <hadi@example.fr>
2026-08-21 10:05:20 +02:00
Hadi bb054e7e8d add nerdfonts and border
Signed-off-by: Hadi <hadi@example.fr>
2026-08-20 15:19:54 +02:00
Hadi eb7cea567c change disk id
Signed-off-by: Hadi <hadi@example.fr>
2026-08-19 15:50:28 +02:00
Hadi 8654da046c change hyprlock config
Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com>
2026-08-17 22:24:34 +02:00
18 changed files with 262 additions and 97 deletions
Generated
+24 -24
View File
@@ -363,11 +363,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786621994, "lastModified": 1787301512,
"narHash": "sha256-ygaOQQFGv3QHcNMoGBor22Dm5GouzmwYucrUfX6oTxQ=", "narHash": "sha256-VYbNaWAcwK9G+mq3jmqyCu6t4zUNUOTT8PXB3pj7XgA=",
"owner": "oxcl", "owner": "oxcl",
"repo": "nix-flake-helium-browser", "repo": "nix-flake-helium-browser",
"rev": "810640b8a7aa504d3962ec8bb857f8252aad6547", "rev": "4fe9ac832466143224203f896a3a38aa8c73b611",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -383,11 +383,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1785119570, "lastModified": 1787146702,
"narHash": "sha256-Rgs2xKnGLFWQscxUaXX07oyZeuMDOHEbqDOsgliLFGM=", "narHash": "sha256-YbRcLdU/yK4gWsQg7V8WTKZHfXL33g8+wSFUX3wyevs=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "d4fd24667c8cbef124bb70a20380cab75ec8474d", "rev": "173b7e8d40fdc8c296a9c99854314f17a3a1704c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -489,11 +489,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786249295, "lastModified": 1786852476,
"narHash": "sha256-Y2mSr+HLKYoOsjiackgilxkHXe8gkJ3z4hFFekjQX3I=", "narHash": "sha256-IM5CYtf86W4w8eUPpKcY/LpdHElmVBtJhaKnoTKxZEA=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nix-index-database", "repo": "nix-index-database",
"rev": "14d55b8069119e3b88da7aa2f6c97f86a2cd3cd6", "rev": "c7962dc97b45129df8d751bedaf37beb5a17706e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -528,11 +528,11 @@
"nixpkgs": "nixpkgs_5" "nixpkgs": "nixpkgs_5"
}, },
"locked": { "locked": {
"lastModified": 1786528975, "lastModified": 1787144466,
"narHash": "sha256-8KuasCs+mVQ7WbLONUf/QB7NZeQvovyXRyxAj4nOOzY=", "narHash": "sha256-HHfv2/HkNSKbbSyU9iD/g8lbP6r4tl33sSw1W4rXCk0=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "3e7edd9afe17e45521300e041c65de3015f4a302", "rev": "0471accf8d0a8210b31d947497d179ecc99e0021",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -589,11 +589,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1786599213, "lastModified": 1787135253,
"narHash": "sha256-yNJd40f11EzXBjSByCB7IPpeFFAdeoSKKM67dGkfFoU=", "narHash": "sha256-RD2kNWCG+Bjo6h+JVjWVNntZs2GtRoeY2xHjts/FNkA=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "0e251e24a4f24e036a084b6b4b2d2491af4167f4", "rev": "ffb3c9b700e759be2ef13237c9d8f953b32a1e46",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -666,11 +666,11 @@
}, },
"nixpkgs_6": { "nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1786535285, "lastModified": 1787204541,
"narHash": "sha256-rG5HKMAgAhMgydvKGtco6rqTxRq4EDZQCx9USLvVqYw=", "narHash": "sha256-OURZPknrTjQrlNyxPdqzyqmU/81Wes1CUP/Ft1Rv/YI=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "9f78f44a87948854445dae0b6bf82b2e87e4efb5", "rev": "5880666fd9eb563038431edb35c2d0aa595884e6",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -701,11 +701,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786700839, "lastModified": 1787315761,
"narHash": "sha256-DtB4Byceo3tyyZNsmwuM0YZSO76VaUaGMSxVjdwYQyw=", "narHash": "sha256-1ze3fFnH7GhN6P3e76Ved2OGNLU/r1Pgo59TbPi9Pg8=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nur", "repo": "nur",
"rev": "3c7c14b16718033c171babfd3020006c05d724d8", "rev": "9fd3c9b18edddb6c611fcbee9974d3b6de5443a7",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -746,11 +746,11 @@
"nixpkgs": "nixpkgs_7" "nixpkgs": "nixpkgs_7"
}, },
"locked": { "locked": {
"lastModified": 1786433999, "lastModified": 1787305329,
"narHash": "sha256-rbOp2g0UCYt+evTnCGCKBQGqSMfwX4RTXneNbeHqOAk=", "narHash": "sha256-nYA+0kCn0h0dsaApPWuSJwIlBrPchqJphnfGLzDCOFs=",
"owner": "notashelf", "owner": "notashelf",
"repo": "nvf", "repo": "nvf",
"rev": "a213644cadd5f90bf18b0c409f08f282b30e55e3", "rev": "93cb00e768908ba77f64a846f487e43e79130796",
"type": "github" "type": "github"
}, },
"original": { "original": {
+3
View File
@@ -2,6 +2,9 @@
c = config.lib.stylix.colors; c = config.lib.stylix.colors;
in { in {
home.file.".config/ilovetui/config.yaml".text = '' home.file.".config/ilovetui/config.yaml".text = ''
nerd_fonts: true
border: rounded
layout_border: full
colors: colors:
base00: "#${c.base00}" # Background base00: "#${c.base00}" # Background
base01: "#${c.base01}" # Lighter Background / Status Bars base01: "#${c.base01}" # Lighter Background / Status Bars
+5
View File
@@ -0,0 +1,5 @@
{
programs.navi = {
enable = true;
};
}
+22
View File
@@ -207,6 +207,28 @@
desc = "Dedent and keep selection"; desc = "Dedent and keep selection";
} }
# Scroll and center
{
key = "<C-d>";
mode = [
"n"
"v"
];
silent = true;
action = "<C-d>zz";
desc = "Scroll down and center";
}
{
key = "<C-u>";
mode = [
"n"
"v"
];
silent = true;
action = "<C-u>zz";
desc = "Scroll up and center";
}
# Move # Move
{ {
key = "<C-h>"; key = "<C-h>";
+128 -42
View File
@@ -1,11 +1,75 @@
{config, ...}: let {
config,
lib,
pkgs,
...
}: let
c = config.lib.stylix.colors; c = config.lib.stylix.colors;
font = config.stylix.fonts.monospace.name;
fontSize = 16;
em = fontSize * 4.0 / 3.0;
charW = em * 0.6;
lineH = em * 1.32;
round = x: builtins.floor (x + 0.5);
px = x: toString (round x);
paint = color: t: ''<span foreground="#${color}">${t}</span>'';
fromFile = name: text: ''cmd[update:0] cat ${pkgs.writeText name text}'';
inner = 42;
width = inner + 2;
valueCol = 13;
spaces = n: lib.concatStrings (lib.genList (_: " ") n);
border = paint c.base0D;
hbar = lib.concatStrings (lib.genList (_: "") inner);
row = content: border "" + content + border "";
blank = row (spaces inner);
entry = name: value: let
prompt = " ${name}:";
gap = spaces (valueCol - builtins.stringLength prompt);
tail = spaces (inner - valueCol - builtins.stringLength value);
in
row (border prompt + gap + paint c.base05 value + tail);
lines = [
(border "${hbar}")
blank
(entry "Session" "Hyprland")
(entry "Username" config.home.username)
(entry "Password" "")
blank
(border "${hbar}")
];
rowY = i: -((i + 0.5) - (builtins.length lines) / 2.0) * lineH;
colX = i: (i - width / 2.0) * charW;
frameHalfH = (builtins.length lines) * lineH / 2.0;
outsideY = frameHalfH + 1.5 * lineH;
inputH = fontSize / 0.8;
inputW = 27 * charW;
dotPad = (inputH - lineH) / 2.0;
inputX = colX (valueCol + 1) - dotPad;
passwordRow = 4;
hidden = "<span> </span>";
in { in {
stylix.targets.hyprlock.enable = false; stylix.targets.hyprlock.enable = false;
programs.hyprlock = { programs.hyprlock = {
enable = true; enable = true;
settings = { settings = {
general = {
grace = 2;
};
background = [ background = [
{ {
monitor = ""; monitor = "";
@@ -16,65 +80,87 @@ in {
label = [ label = [
{ {
monitor = ""; monitor = "";
text = ''cmd[update:0] echo "[$USER@$(hostname) ~]"''; text = ''cmd[update:1000] date +"%H:%M %A %d %B"'';
color = "rgb(${c.base0D})";
font_size = 13;
font_family = config.stylix.fonts.monospace.name;
position = "48, -48";
halign = "left";
valign = "top";
}
{
monitor = "";
text = ''cmd[update:1000] echo "$(date +'%H:%M:%S')"'';
color = "rgb(${c.base05})"; color = "rgb(${c.base05})";
font_size = 13; font_size = fontSize;
font_family = config.stylix.fonts.monospace.name; font_family = font;
position = "48, -70"; position = "0, -64";
halign = "left"; halign = "center";
valign = "top"; valign = "top";
} }
{ {
monitor = ""; monitor = "";
text = ''cmd[update:60000] echo "$(date +'%A %d %B %Y')"''; text = "Welcome";
color = "rgb(${c.base05})";
font_size = fontSize;
font_family = font;
position = "0, ${px outsideY}";
halign = "center";
valign = "center";
}
{
monitor = "";
text = fromFile "hyprlock-frame" (lib.concatStringsSep "\n" lines);
color = "rgb(${c.base05})";
font_size = fontSize;
font_family = font;
text_align = "left";
position = "0, 0";
halign = "center";
valign = "center";
}
{
monitor = "";
text = "<span> </span>$FAIL<span> </span>";
color = "rgb(${c.base08})";
font_size = fontSize;
font_family = font;
position = "0, ${px (-outsideY)}";
halign = "center";
valign = "center";
}
{
monitor = "";
text =
fromFile "hyprlock-hints"
"${paint c.base0D "Enter"} ${paint c.base04 "unlock"} ${paint c.base0D "Esc"} ${paint c.base04 "clear"}";
color = "rgb(${c.base04})"; color = "rgb(${c.base04})";
font_size = 13; font_size = fontSize;
font_family = config.stylix.fonts.monospace.name; font_family = font;
position = "48, -92"; position = "0, 40";
halign = "left"; halign = "center";
valign = "top"; valign = "bottom";
}
{
monitor = "";
text = "passwd:";
color = "rgb(${c.base0D})";
font_size = 13;
font_family = config.stylix.fonts.monospace.name;
position = "48, -141";
halign = "left";
valign = "top";
} }
]; ];
"input-field" = [ "input-field" = [
{ {
monitor = ""; monitor = "";
size = "200, 20"; size = "${px inputW}, ${px inputH}";
position = "${px (inputX + inputW / 2.0)}, ${px (rowY passwordRow)}";
halign = "center";
valign = "center";
outline_thickness = 0; outline_thickness = 0;
outer_color = "rgba(00000000)"; outer_color = "rgba(00000000)";
inner_color = "rgba(00000000)"; inner_color = "rgba(00000000)";
font_color = "rgb(${c.base05})";
fade_on_empty = false;
placeholder_text = "";
hide_input = true;
rounding = 0; rounding = 0;
check_color = "rgb(${c.base0B})"; fade_on_empty = false;
font_family = font;
font_color = "rgb(${c.base05})";
dots_text_format = "*";
dots_size = 0.8;
dots_spacing = 0.0;
dots_center = false;
swap_font_color = true;
placeholder_text = hidden;
fail_text = hidden;
check_color = "rgb(${c.base0C})";
fail_color = "rgb(${c.base08})"; fail_color = "rgb(${c.base08})";
fail_text = ''<span font_desc="${config.stylix.fonts.monospace.name} 13">auth failed</span>'';
capslock_color = "rgb(${c.base0A})"; capslock_color = "rgb(${c.base0A})";
position = "116, -138";
halign = "left";
valign = "top";
} }
]; ];
}; };
+1
View File
@@ -14,6 +14,7 @@
../../nixos/utils.nix ../../nixos/utils.nix
../../nixos/hyprland.nix ../../nixos/hyprland.nix
../../nixos/steam.nix ../../nixos/steam.nix
../../nixos/kernel-hardening.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration.. ../../home/programs/gui/helium/system.nix # I hate browser's configuration..
# CHANGEME: You should probably remove those things: # CHANGEME: You should probably remove those things:
+1
View File
@@ -25,6 +25,7 @@
../../home/programs/tui/spotatui ../../home/programs/tui/spotatui
../../home/programs/tui/elio ../../home/programs/tui/elio
../../home/programs/tui/wikiman ../../home/programs/tui/wikiman
../../home/programs/tui/navi
../../home/programs/tui/pkgs.nix ../../home/programs/tui/pkgs.nix
## GROUPS ## GROUPS
+1
View File
@@ -13,6 +13,7 @@
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly) "/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log" "/var/log"
"/var/cache/tuigreet" "/var/cache/tuigreet"
"/var/cache/vulnix"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown "/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
]; ];
+13 -20
View File
@@ -11,27 +11,20 @@
"root" "root"
]; ];
rules = '' rules = ''
allow id 1d6b:0002 serial "0000:05:00.3" name "xHCI Host Controller" hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type "" allow id 13fd:5900 name "External"
allow id 1d6b:0003 serial "0000:05:00.3" name "xHCI Host Controller" hash "d+DNGWARDtv9nEK2ZvnNOCtFernuMu5/e/oZ7kCppqQ=" parent-hash "ldMchY4Tt4GPUYo30eNGvai+Fs/EdnVY3vMyxJUq4Nk=" with-interface 09:00:00 with-connect-type "" allow id 1d6b:0003 name "xHCI Host Controller"
allow id 1d6b:0002 serial "0000:05:00.4" name "xHCI Host Controller" hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type "" allow id 1d6b:0002 name "xHCI Host Controller"
allow id 1d6b:0003 serial "0000:05:00.4" name "xHCI Host Controller" hash "UbEoCZW8HT2ldc3qDeiK+IiQlGeaBC7F63681OwmKhI=" parent-hash "tHvBfznK5rpQn+oa0PEEjHa29EAEvGyCcZixsfwA6W0=" with-interface 09:00:00 with-connect-type "" allow id 0bda:c85c name "Bluetooth Radio"
allow id 1d6b:0002 serial "0000:07:00.3" name "xHCI Host Controller" hash "pz29Oo0RhQ+5+7LgOZR4v3OlcsVv3m9kCgGsGUnoUjI=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type "" allow id 30c9:009f name "HP True Vision FHD Camera"
allow id 1d6b:0003 serial "0000:07:00.3" name "xHCI Host Controller" hash "O6iOpcl9StImWT62SrbeXacqbG6N/mTIipTRc0ipCGM=" parent-hash "DRyV2/31MYHdzkIEfbPQeb/1w4/PjOW6GqWrXkftf2I=" with-interface 09:00:00 with-connect-type "" allow id 03f0:036b name "HP USB-C Dock G5"
allow id 1d6b:0002 serial "0000:07:00.4" name "xHCI Host Controller" hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 1d6b:0003 serial "0000:07:00.4" name "xHCI Host Controller" hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" parent-hash "l2vhvC+VGVKlkBUUK/usFu8jHJ/5bWOnJG6WzRexpt4=" with-interface 09:00:00 with-connect-type ""
allow id 0bda:c85c serial "00e04c000001" name "Bluetooth Radio" hash "Q/wlToV8WQgEYHBW/UIhnSwCCusCGqAR2D5gspSCImQ=" parent-hash "4a4NgfdUaJO43rkCzmWRSeHHR/uUh5+SNsXnhosm9qs=" with-interface { e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 e0:01:01 } with-connect-type "hardwired"
allow id 30c9:009f serial "01.00.00" name "HP True Vision FHD Camera" hash "eYW5fqReJd29tfHXkEktKC63dGfDpmlRMo5uMGUWwME=" parent-hash "icotY3rI59mWiKsGxc59BGZZeBjfbuH0b4NUByj3cbQ=" with-interface { 0e:01:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 0e:02:01 fe:01:01 } with-connect-type "hardwired"
allow id 03f0:036b serial "" name "HP USB-C Dock G5" hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" parent-hash "Hp8B0Enf+ACRT2tyy0EqXj7eNsFDAnTRZadzuh/Iqd4=" via-port "7-1" with-interface { 09:00:01 09:00:02 } with-connect-type "hotplug"
allow id 03f0:066b serial "" name "HP USB-C Dock G5" hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" parent-hash "rJ3LKdvkCK3SUrCU3lV8qVbmPjA+r9Fe5106x2HlgK4=" via-port "8-1" with-interface 09:00:00 with-connect-type "hotplug"
allow id 03f0:056b serial "201604140001" name "USB Audio" hash "OxQ8HQenW3/4HSGEBOSYFS15rXDTOaNDnjMbICweHgw=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:086b serial "" name "USB2734" hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" via-port "7-1.3" with-interface { 09:00:01 09:00:02 } with-connect-type "unknown"
allow id 03f0:046b serial "11AD1D0A89EA2D08310E0B00" name "HP USB-C Dock G5" hash "DEGeuj1u4lwqrzp0UksFX7mSEY9JnGLxg7yxGbglAKE=" parent-hash "iPFGrgGz0sWgKQjWD/F8eNOhkeR728dTG8JJtkUSvuM=" with-interface { 11:00:00 ff:03:00 03:00:00 } with-connect-type "unknown"
allow id 03f0:076b serial "" name "USB5734" hash "BshoqybYo0IKgoDORYPRtbhhlmQrYAxPQb2EAm1JsWA=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" via-port "8-1.3" with-interface 09:00:00 with-connect-type "unknown"
allow id 0bda:8153 serial "000001000000" name "USB 10/100/1000 LAN" hash "utEnXKJ57kRUbPcGUaNWhEyoOEbLOYAFxvlsyC0PZkk=" parent-hash "JHDjLFApQNqijjmuKdJSWH5+1oLL7S6LQ9QHTAk5fTk=" with-interface { ff:ff:00 02:06:00 0a:00:00 0a:00:00 } with-connect-type "unknown"
allow id 046d:0ab7 serial "2046BAB04T68" name "Blue Microphones" hash "cC6AQ2e1Q/BeFeostpbf1mH2WpoUmt6bhau4NlA3niU=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 01:01:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 01:02:00 03:00:00 } with-connect-type "unknown"
allow id 13fd:5900 serial "50026B76861EE752 " name "External" hash "l/QvVV5hzZj1z6OUwB/kWl+WnH/7awrdMBoiNVx660M=" parent-hash "MSXcPAlZqkpTyZQylOhSIB8eMfST2AzVHV9EbrBGTWc=" with-interface { 08:06:50 08:06:62 } with-connect-type "unknown"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:066b name "HP USB-C Dock G5" allow id 03f0:066b name "HP USB-C Dock G5"
allow id 03f0:056b name "USB Audio"
allow id 0bda:8153 name "USB 10/100/1000 LAN"
allow id 046d:0ab7 name "Blue Microphones"
allow id 03f0:076b name "USB5734"
allow id 1532:02a1 name "Razer Ornata V3"
allow id 03f0:046b name "HP USB-C Dock G5"
allow id 03f0:086b name "USB2734"
''; '';
}; };
} }
+1 -1
View File
@@ -19,7 +19,7 @@
../../server-modules/bentopdf.nix ../../server-modules/bentopdf.nix
../../server-modules/cyberchef.nix ../../server-modules/cyberchef.nix
../../server-modules/mazanoke.nix ../../server-modules/mazanoke.nix
../../server-modules/kernel-hardening.nix ../../nixos/kernel-hardening.nix
../../server-modules/fail2ban.nix ../../server-modules/fail2ban.nix
../../server-modules/default-creds.nix ../../server-modules/default-creds.nix
../../server-modules/gitea.nix ../../server-modules/gitea.nix
+2
View File
@@ -11,6 +11,8 @@
../../nixos/users.nix ../../nixos/users.nix
../../nixos/utils.nix ../../nixos/utils.nix
../../nixos/hyprland.nix ../../nixos/hyprland.nix
../../nixos/kernel-hardening.nix
../../nixos/vulnix.nix
../../home/programs/gui/helium/system.nix # I hate browser's configuration.. ../../home/programs/gui/helium/system.nix # I hate browser's configuration..
# CHANGEME: You should probably remove those things: # CHANGEME: You should probably remove those things:
+1 -1
View File
@@ -14,7 +14,7 @@
disk = { disk = {
main = { main = {
type = "disk"; type = "disk";
device = "/dev/disk/by-id/nvme-WD_PC_SN740_SDDQNQD-256G-1201_24175M800511"; device = "/dev/disk/by-id/nvme-SK_hynix_PVC10_HFS512GEM9X173N_5MF4N00141310464Q";
content = { content = {
type = "gpt"; type = "gpt";
partitions = { partitions = {
+1
View File
@@ -24,6 +24,7 @@
../../home/programs/tui/spotatui ../../home/programs/tui/spotatui
../../home/programs/tui/elio ../../home/programs/tui/elio
../../home/programs/tui/wikiman ../../home/programs/tui/wikiman
../../home/programs/tui/navi
../../home/programs/tui/pkgs.nix ../../home/programs/tui/pkgs.nix
## GROUPS ## GROUPS
+1
View File
@@ -13,6 +13,7 @@
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly) "/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
"/var/log" "/var/log"
"/var/cache/tuigreet" "/var/cache/tuigreet"
"/var/cache/vulnix"
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown "/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
]; ];
+5 -5
View File
@@ -11,11 +11,11 @@
"root" "root"
]; ];
rules = '' rules = ''
allow id 1d6b:0002 serial "0000:00:14.0" name "xHCI Host Controller" hash "jEP/6WzviqdJ5VSeTUY8PatCNBKeaREvo2OqdplND/o=" parent-hash "rV9bfLq7c2eA4tYjVjwO4bxhm+y6GgZpl9J60L0fBkY=" with-interface 09:00:00 with-connect-type "" allow id 1d6b:0002 name "xHCI Host Controller"
allow id 1d6b:0003 serial "0000:00:14.0" name "xHCI Host Controller" hash "prM+Jby/bFHCn2lNjQdAMbgc6tse3xVx+hZwjOPHSdQ=" parent-hash "rV9bfLq7c2eA4tYjVjwO4bxhm+y6GgZpl9J60L0fBkY=" with-interface 09:00:00 with-connect-type "" allow id 0951:1666 name "DataTraveler 3.0"
allow id 17ef:6190 serial "" name "Lenovo Calliope USB Keyboard G2" hash "CfZ9R/aoXGm7BN/ojVEzKQwVoxCUtRWMuACrE7BL/5Y=" parent-hash "jEP/6WzviqdJ5VSeTUY8PatCNBKeaREvo2OqdplND/o=" via-port "1-10" with-interface { 03:01:01 03:00:00 } with-connect-type "hotplug" allow id 1d6b:0003 name "xHCI Host Controller"
allow id 0781:5581 name " SanDisk 3.2Gen1" allow id 0461:574a name "HP 125 USB Optical Mouse"
allow id 17ef:608d name "Lenovo USB Optical Mouse" allow id 0461:554a name "HP 125 Wired Keyboard"
''; '';
}; };
} }
@@ -1,4 +1,3 @@
# Kernel hardening for the server
{ {
boot.kernel.sysctl = { boot.kernel.sysctl = {
# Restrict access to kernel logs and pointers # Restrict access to kernel logs and pointers
@@ -9,6 +8,18 @@
"net.core.bpf_jit_harden" = 2; "net.core.bpf_jit_harden" = 2;
"kernel.unprivileged_bpf_disabled" = 1; "kernel.unprivileged_bpf_disabled" = 1;
# Restrict ptrace to parent processes only
"kernel.yama.ptrace_scope" = 1;
# Disable kexec (loading a new kernel at runtime)
"kernel.kexec_load_disabled" = 1;
# Disable magic SysRq key
"kernel.sysrq" = 0;
# Restrict access to /proc for non-root users
"kernel.perf_event_paranoid" = 3;
# Reverse path filtering (anti-spoofing) # Reverse path filtering (anti-spoofing)
"net.ipv4.conf.all.rp_filter" = 1; "net.ipv4.conf.all.rp_filter" = 1;
"net.ipv4.conf.default.rp_filter" = 1; "net.ipv4.conf.default.rp_filter" = 1;
@@ -29,7 +40,18 @@
# Don't send ICMP redirects # Don't send ICMP redirects
"net.ipv4.conf.all.send_redirects" = 0; "net.ipv4.conf.all.send_redirects" = 0;
# Restrict ptrace to parent processes only # Ignore bogus ICMP error responses
"kernel.yama.ptrace_scope" = 1; "net.ipv4.icmp_ignore_bogus_error_responses" = 1;
# Protect against time-wait assassination
"net.ipv4.tcp_rfc1337" = 1;
}; };
boot.kernelParams = [
"init_on_alloc=1" # zero freshly allocated kernel memory
"init_on_free=1" # zero freed kernel memory
"slab_nomerge" # don't merge slab caches of different sizes (harder heap grooming)
"page_alloc.shuffle=1" # randomize page allocator freelists
"randomize_kstack_offset=1" # randomize the kernel stack offset on syscall entry
];
} }
+1 -1
View File
@@ -10,7 +10,7 @@
}; };
}; };
tmp.cleanOnBoot = true; tmp.cleanOnBoot = true;
kernelPackages = pkgs.linuxPackages_latest; # _zen, _hardened, _rt, _rt_latest, etc. kernelPackages = pkgs.linuxPackages; # _latest, _zen, _hardened, _rt, _rt_latest, etc.
# Silent boot # Silent boot
kernelParams = [ kernelParams = [
+27
View File
@@ -0,0 +1,27 @@
# Vulnix scans the Nix store against the NVD CVE feed to find packages with
# known vulnerabilities.
{pkgs, ...}: {
environment.systemPackages = [pkgs.vulnix];
systemd.services.vulnix-scan = {
description = "Scan the system closure for known vulnerabilities (vulnix)";
serviceConfig = {
Type = "oneshot";
ExecStart = "${pkgs.vulnix}/bin/vulnix --system --cache-dir /var/cache/vulnix";
CacheDirectory = "vulnix";
# vulnix exits non-zero when it finds vulnerabilities; that's expected,
# don't let systemd treat the scan itself as a failure.
SuccessExitStatus = "1 2";
};
};
systemd.timers.vulnix-scan = {
description = "Daily vulnix scan";
wantedBy = ["timers.target"];
timerConfig = {
OnCalendar = "daily";
Persistent = true;
RandomizedDelaySec = "1h";
};
};
}