diff --git a/modules/ryan-config/base-system.scm b/modules/ryan-config/base-system.scm new file mode 100644 index 0000000..ce4b5ab --- /dev/null +++ b/modules/ryan-config/base-system.scm @@ -0,0 +1,186 @@ +(use-modules (gnu) (nongnu packages linux)) +(use-modules (gnu system setuid)) +(use-modules (gnu packages admin)) +(use-modules (guix packages)) +(use-modules (gnu packages shells)) +(use-modules (guix build-system trivial)) +(use-modules (guix licenses)) +(use-modules (gnu packages tls)) +(use-modules (srfi srfi-1)) +(use-modules (ryan-packages freedesktop)) +(use-modules (ryan-packages wm)) +(use-package-modules security-token) +(use-service-modules cups desktop networking xorg ssh nix sound security-token docker virtualization) + +; Define package that installs my root ca public keys +(define my-ca-certs + (package + (name "my-ca-certs") + (version "1") + (source (local-file "./CACerts" + #:recursive? #t)) + (build-system trivial-build-system) + (license mpl2.0) + (home-page "https://rschanz.org") + (arguments + `(#:modules + ((guix build utils)) + #:builder + (begin + (use-modules (guix build utils) + (srfi srfi-1) + (srfi srfi-26) + (ice-9 ftw)) + (let* ((ca-certificates (assoc-ref %build-inputs "source")) + (crt-suffix ".crt") + (is-certificate? (cut string-suffix? crt-suffix <>)) + (certificates (filter is-certificate? + (scandir ca-certificates))) + (out (assoc-ref %outputs "out")) + (certificate-directory (string-append out "/etc/ssl/certs")) + (openssl (string-append (assoc-ref %build-inputs "openssl") "/bin/openssl"))) + (mkdir-p certificate-directory) + (for-each + (lambda (cert) + (invoke + openssl "x509" + "-in" (string-append ca-certificates "/" cert) + "-outform" "PEM" + "-out" (string-append certificate-directory "/" cert ".pem"))) + certificates) + #t)))) + (native-inputs + (list openssl)) + (synopsis "My CA Certs") + (description synopsis))) + +; Re-define the base packages to remove sudo +(define %my-base-packages + (remove (lambda (package) + (member (package-name package) + (list "sudo" "nano"))) + %base-packages )) + +(define %backlight-udev-rule + (udev-rule + "90-backlight.rules" + (string-append "ACTION==\"add\", SUBSYSTEM==\"backlight\", " + "RUN+=\"/run/current-system/profile/bin/chgrp video /sys/class/backlight/%k/brightness\"" + "\n" + "ACTION==\"add\", SUBSYSTEM==\"backlight\", " + "RUN+=\"/run/current-system/profile/bin/chmod g+w /sys/class/backlight/%k/brightness\""))) + +(operating-system + (kernel linux) + (firmware (list linux-firmware)) + (locale "en_US.utf8") + (timezone "America/New_York") + (keyboard-layout (keyboard-layout "us")) + (host-name "ThisWillChange") + + ;; The list of user accounts ('root' is implicit). + (users (cons* (user-account + (name "ryan") + (comment "Ryan") + (group "users") + ;(shell (file-append zsh "/bin/zsh")) + (home-directory "/home/ryan") + (supplementary-groups '("wheel" "netdev" "audio" "video" "lp" "plugdev" "docker" "libvirt" "kvm"))) + %base-user-accounts)) + + ;; Packages installed system-wide. Users can also install packages + ;; under their own account: use 'guix search KEYWORD' to search + ;; for packages and 'guix install PACKAGE' to install a package. + (packages (append (map specification->package (list "sway" + "swaybg" + "swayidle" + ;"swaylock-effects" + "fuzzel" + "alacritty" + "pinentry-qt" + "adwaita-icon-theme" + "hicolor-icon-theme" + "git" + "nss-certs" + "waybar" + "gnupg" + "light" + "mako" + "grim" + "slurp" + "wl-clipboard" + "bluez" + "blueman" + "ldacbt" + "libfreeaptx" + "libfdk" + "opendoas" + ;"xdg-desktop-portal-wlr" + "xdg-desktop-portal" + "pipewire" + "docker" + "libvirt" + "virt-manager" + "wireplumber" + "zsh")) + (list my-ca-certs xdg-desktop-portal-wlr-new swaylock-effects-new) + %my-base-packages )) + + ;; Below is the list of system services. To search for available + ;; services, run 'guix system search KEYWORD' in a terminal. + (services + (append (list + + ;; To configure OpenSSH, pass an 'openssh-configuration' + ;; record as a second argument to 'service' below. + (service openssh-service-type) + (service pcscd-service-type) + (service docker-service-type) + (service nix-service-type) + (service libvirt-service-type + (libvirt-configuration + (unix-sock-group "libvirt"))) + (service bluetooth-service-type) + (udev-rules-service 'fido2 libfido2 #:groups '("plugdev"))) + + ;; This is the default list of services we + ;; are appending to. + (modify-services %desktop-services + (guix-service-type config => + (guix-configuration + (inherit config) + (substitute-urls + (append (list "https://substitutes.nonguix.org") + %default-substitute-urls)) + (authorized-keys + (cons* (plain-file "non-guix.pub" + "(public-key + (ecc + (curve Ed25519) + (q #C1FD53E5D4CE971933EC50C9F307AE2171A2D3B52C804642A7A35F84F3A4EA98#) + ) + )" ) %default-authorized-guix-keys)))) + (udev-service-type config => + (udev-configuration + (inherit config) + (rules (cons %backlight-udev-rule + (udev-configuration-rules config))))) + (delete pulseaudio-service-type) + (delete gdm-service-type) + (delete xorg-server-service-type) + (delete alsa-service-type) ))) + (setuid-programs + (append (list (file-like->setuid-program + (file-append + ;(specification->package "swaylock-effects") + swaylock-effects-new + "/bin/swaylock")) + (file-like->setuid-program + (file-append + (specification->package "opendoas") + "/bin/doas"))) + (delete sudo %setuid-programs))) + (bootloader (bootloader-configuration + (bootloader grub-efi-bootloader) + (targets (list "/boot/efi")) + (keyboard-layout keyboard-layout))))))))