Commit Graph

2323 Commits

Author SHA1 Message Date
Gavin John
b76bf041c7 nixos/immersed: openPorts -> openFirewall
The PR that added this is only a few hours old (https://github.com/NixOS/nixpkgs/pull/399766) and hasn't had the chance to enter an unstable released, which is why I haven't added a rename flag.
2026-07-05 01:13:47 -04:00
Ryan Hendrickson
6edbf1a6a0 immersed: add option to open firewall ports and libraries for hardware encoding support (#399766) 2026-07-04 21:29:37 -04:00
Daniel Thwaites
3bc78b00e8 treewide: largely remove danth from maintainers
I have not used most of these in a while, so have no interest in
maintaining them any more.
2026-07-04 18:56:47 +01:00
aaravrav
3b93c07201 nixos/moonlight-qt: add module 2026-07-04 12:55:55 +05:30
Maximilian Bosch
0be9f9b2fa captive-browser: 0-unstable-2021-08-01 -> 0-unstable-2025-11-05 (#538118) 2026-07-04 06:32:09 +00:00
Maximilian Bosch
6b6b3a6cd8 nixos/captive-browser: update default arguments passed to Chromium
Closes #533452

Taken from https://github.com/pacoorozco/captive-browser/blob/9f75ef3/config_examples/captive-browser-linux-networkmanager.toml
2026-07-03 19:18:51 +02:00
Gavin John
f8225c39df nixos/comma: init
Fixes https://github.com/NixOS/nixpkgs/issues/426379
2026-07-03 10:58:40 -04:00
Maximilian Bosch
900ed1808d nixos/captive-browser: drop setcap wrapper
Linux 5.7 is not supported on NixOS anymore, so this is dead-code.
2026-07-03 15:09:24 +02:00
Sandro
20a8da7e87 nixos/foot: only modify the prompt when running inside foot (#534737) 2026-06-29 22:31:52 +00:00
nixpkgs-ci[bot]
7ac2687f5f Merge master into staging-next 2026-06-25 00:45:19 +00:00
r-vdp
1260b0727b nixos/fish: extract completion generator from the fish binary
fish no longer installs share/fish/tools/ and instead embeds the
script in the binary. Extract it via `status get-file` and replace
the patch that stripped the autogenerated header with an inline sed
plus a test that fails the build if the upstream header format
changes.
2026-06-24 17:20:00 +02:00
Steven Allen
32bf61c51e nixos/foot: only modify the prompt when running inside foot
Without this, these integration scripts will mess with the prompt even
when not running a shell inside of foot. This can break:

1. Terminals that don't understand these sequences (e.g., gnome-terminal
and likely other vte based terminals).
2. Anything that tries to parse the prompt (Emacs packages like
bash-completion).

This patch relies on the TERM variable (against upstream's
recommendation [1]) because:

1. Only Fish [2] has built-in support for querying things like
XTVERSION. Querying terminal features manually is non-trivial and
requires writing to STDOUT, which I'd like to avoid.

2. Even in Fish, this XTVERSION may only be queried after the first
prompt has been displayed ([2]), which is too late.

This patch does not explicitly check if the terminal is interactive as
the modified files are only sourced by interactive shells anyway.

[1]: https://codeberg.org/dnkl/foot#programmatically-checking-if-running-in-foot
[2]: https://fishshell.com/docs/current/cmds/status.html#status-terminal

fixes #374613
2026-06-23 13:49:26 -07:00
nixpkgs-ci[bot]
7d340b597d Merge master into staging-nixos 2026-06-22 13:55:09 +00:00
Janne Heß
b3c092d3c3 nixos/vscode: system-wide policies option (#496195) 2026-06-22 09:00:13 +00:00
Martin Weinelt
28c1501947 nixos/appimage: enable fuse 2026-06-20 17:29:41 +02:00
Martin Weinelt
ef352e5401 nixos/fuse: disable by default
This change disables the fuse module by default and shifts the
obligation to enable it to consumers.
2026-06-20 17:29:40 +02:00
Mio
3ef4f90536 nixos/sniffnet: install package when enabled 2026-06-18 09:27:47 +10:00
Sandro
814d98f490 nixos/clash-verge: relax checkReversePath in TUN mode (#517118) 2026-06-16 21:04:38 +00:00
André Silva
184d1b4c0f nixos/uwsm: set restartIfChanged = false on session units 2026-06-16 11:19:57 +01:00
Yt
f3785405f6 libsoup_2_4: drop (#529295) 2026-06-15 23:27:32 +00:00
nixpkgs-ci[bot]
07846d183a Merge master into staging-nixos 2026-06-13 00:51:06 +00:00
NotAShelf
bb070e800e nixos/hyprland: migrate Systemd user settings to RFC 42-style attrs
Signed-off-by: NotAShelf <raf@notashelf.dev>
Change-Id: I6f9330373d89a24ccc191104bdeaa7236a6a6964
2026-06-12 22:12:35 +03:00
Martin Weinelt
7a3819ed28 nixos/gamemode: opt into pkexec 2026-06-12 00:50:44 +02:00
Martin Weinelt
581de9713c nixos/throne: opt into pkexec
https://github.com/throneproj/Throne/blob/4.3.7/src/ui/mainwindow.cpp#L843-L847
2026-06-11 20:31:23 +02:00
Peder Bergebakken Sundt
9550204ab3 clash-verge-rev: 2.4.7 -> 2.5.1 (#523235) 2026-06-10 22:34:53 +00:00
sternenseemann
01e7815238 nixos/foot: fix zsh duplicate precmd functions (#523065) 2026-06-10 04:34:27 +00:00
Pascal Bach
c172c09112 jai-jail: init at 0.3 (#504873) 2026-06-09 07:30:18 +00:00
whispers
14d99f9d24 mouse-actions-gui: drop
mouse-actions-gui is reliant on Tauri v1, which pulls in webkitgtk 4.0
and libsoup 2.4. The former has already been dropped, and the latter's
is imminent. It has been marked broken in Nixpkgs since October 2025.
2026-06-07 18:51:13 -04:00
Mitchell Pleune
1b9b855569 nixos/iotop: optionally enable delayacct tracking in kernel
Since Linux commit e4042ad492357fa995921376462b04a025dd53b6 (May 2021)
this is disabled by default as it is "not used much."
2026-06-06 09:42:25 +02:00
agentelement
af7dd49a51 nixos/jai-jail: init jai-jail 2026-06-05 14:41:12 -07:00
Samuel Ainsworth
7ce9753bd8 nixos/niri: pin defaultSession so GDM 50 stops bouncing to gnome-session
GDM 50 falls back to launching `gnome-session` as the user session
command when the AccountsService record has `Session=` empty and
`services.displayManager.defaultSession` is unset. On a Niri-only
machine the spawn fails with ENOENT and the user is bounced back to
the greeter — an indefinite login loop after a fresh install or after
the AccountsService record gets reset.

GDM 49 hit the same fallback path but happened to find gnome-session
on PATH; the user's first session pick then got stashed in
AccountsService and subsequent logins worked. GDM 50's tighter
environment removed the accidental save.

Setting `services.displayManager.defaultSession = lib.mkDefault "niri"`
inside `programs.niri` makes a Niri-only install boot straight into
the compositor. Users running multiple session packages can still
override via a plain assignment.

Refs https://github.com/NixOS/nixpkgs/issues/523332
2026-06-05 14:17:17 -04:00
Yaksis
16bb18b666 nixos/clash-verge: relax checkReversePath in TUN mode 2026-06-02 10:37:36 +08:00
r-vdp
1ac3c5dc99 nixos/shadow: use file capabilities for newuidmap/newgidmap
Writing a multi-line /proc/<pid>/[ug]id_map only requires
CAP_SETUID/CAP_SETGID over the parent user namespace, not full root.
shadow's own --with-fcaps install mode (70971457b761) sets exactly
cap_setuid+ep / cap_setgid+ep, and Arch, Fedora and Debian have shipped
these binaries with file capabilities instead of setuid for years.

The setuid variant already drops to the same single capability before
the uid_map write (see lib/idmapping.c), so the privilege at the point
attacker-controlled data reaches the kernel is unchanged. The reduction
is in the startup window: with file capabilities the process never has
euid 0 and never holds the full capability set during NSS lookups,
/etc/subuid parsing and /proc/<pid> opening.

The only functional difference is that mapping host uid 0 into a child
namespace additionally needs CAP_SETFCAP, which the setuid path got
implicitly. NixOS never puts uid 0 into auto-allocated subuid ranges,
and granting it manually is a deliberate root-equivalent configuration;
the release notes document the override for that case.

nixosTests.{shadow,podman,docker-rootless} pass; the latter two
exercise newuidmap/newgidmap via rootless containers.

Supersedes #461172.

Co-authored-by: Rasheeq Azad <rasheeqhere@gmail.com>
2026-06-01 00:18:28 +03:00
Atemu
73e30c74f6 nixos/steam: remove unnecessary bwrap wrapper (#524488) 2026-05-29 14:11:24 +00:00
erop
12b7b2fac9 nixos/steam: remove unnecessary bwrap wrapper 2026-05-28 16:05:14 +02:00
K900
feb74edee5 gamescope: feature option enableWsi (#523394) 2026-05-27 17:40:10 +00:00
Malix - Alix Brunet
08d29d4cac gamescope: feature option enableWsi 2026-05-27 19:33:33 +02:00
Toma
1630215fe2 throne: 1.0.13 -> 1.1.2 (#489883) 2026-05-26 18:38:34 +00:00
Martin Weinelt
0e2dde1883 nixos/lix: load tun kmod for pasta (#524016) 2026-05-25 22:41:17 +00:00
Martin Weinelt
34fbf0285a nixos/lix: load tun kmod for pasta
With kernel lockdown the tun kmod is not necessarily available in stage2,
but Lix dependes on it through pasta.

nix-daemon[682677]: remote pid 682659 is user build (trusted)
nix-daemon[682711]: Failed to open() /dev/net/tun: No such device
nix-daemon[682702]: Failed to set up tap device in namespace
2026-05-25 23:45:07 +02:00
Ramses
ac76bfd72f command-not-found: don't require lib.mkForce to set dbPath (#517324) 2026-05-25 20:54:18 +00:00
Sandro
9623bda6bb zsh: unbreak nixos module build for dynamic dhcp hostname (#485244) 2026-05-25 13:35:39 +00:00
Kira Bruneau
fd27832e66 nixos/gamemode: add package option (#523641) 2026-05-24 23:07:41 +00:00
Niclas Metschke
f8a843dd36 nixos/gamemode: add package option 2026-05-24 17:01:12 +02:00
isabel
7766073f61 termite: remove broken package with no live upstream (#522784) 2026-05-23 20:17:00 +00:00
HHR2020
3fd7307e91 nixos/clash-verge: add StateDirectory for clash-verge-service
ProtectSystem=strict makes /var read-only, so the persistent state
fallback path needs a StateDirectory to be writable.

21e661fa14/src/core/paths.rs (L94)
2026-05-23 17:51:00 +08:00
Fernando Rodrigues
12404c0e20 nixos/starship: fix '$' escaping for bash and zsh (#523057) 2026-05-22 16:47:59 +00:00
Colin Hooper
64a6456f52 nixos/foot: fix zsh prompt marker precmd function being overwritten by the end pipe marker precmd function 2026-05-22 16:20:20 +01:00
Colin Hooper
24b80c45f2 nixos/starship: fix '$' escaping for bash and zsh 2026-05-22 15:28:21 +01:00
Emil Thorsoe
654a07279a termite: remove broken package with no live upstream
Also remove from enableAllTerminfo list.

Since vte: 0.82.3 → 0.84.0 custom patches applied to vte in termite are
broken. The package has been without upstream for 5 years for now.

18de7682e9
https://github.com/NixOS/nixpkgs/issues/122929
2026-05-22 15:29:27 +03:00