This commit is contained in:
2026-07-14 19:28:47 +09:00
parent c5c56fde83
commit b5c49ffa79
9 changed files with 106 additions and 19 deletions
+1
View File
@@ -31,6 +31,7 @@
./slack.nix
./ssh
./swayidle.nix
./swaylock
./tailscale.nix
./vicinae.nix
./vim
+3 -5
View File
@@ -123,12 +123,10 @@ in
};
"Mod+L" = {
action.spawn = [
"noctalia"
"msg"
"session"
"lock"
(lib.getExe' pkgs.systemd "loginctl")
"lock-session"
];
hotkey-overlay.title = "Lock the Screen: noctalia";
hotkey-overlay.title = "Lock the Screen";
};
"Mod+V" = {
action.spawn = [
+4
View File
@@ -54,6 +54,10 @@ in
};
};
desktop_widgets.enabled = false;
lockscreen = {
enabled = false;
fingerprint = false;
};
widget = {
cpu = {
type = "sysmon";
+4 -13
View File
@@ -2,25 +2,18 @@
pkgs,
lib,
config,
inputs,
...
}:
let
cfg = config.my.applications.swayidle;
noctaliaPkg = inputs.noctalia.packages.${pkgs.stdenv.hostPlatform.system}.default;
noctalia = lib.getExe noctaliaPkg;
brightnessctl = lib.getExe pkgs.brightnessctl;
niri = lib.getExe pkgs.niri;
rm = "${pkgs.coreutils}/bin/rm";
systemctl = lib.getExe' pkgs.systemd "systemctl";
brightnessState = "$XDG_RUNTIME_DIR/swayidle-brightness";
noctaliaMsg = command: "${noctalia} msg ${command}";
lockCmd = noctaliaMsg "session lock";
# AC 接続中は何もしない。
# つまり、以下のアイドル処理をバッテリー駆動時のみにする。
skipIfOnAC = ''
@@ -49,10 +42,10 @@ let
fi
'';
lockAndSuspend = pkgs.writeShellScript "swayidle-lock-and-suspend" ''
suspendOnBattery = pkgs.writeShellScript "swayidle-suspend-on-battery" ''
${skipIfOnAC}
${noctaliaMsg "session lock-and-suspend"}
exec ${systemctl} suspend
'';
afterResume = pkgs.writeShellScript "swayidle-after-resume" ''
@@ -83,13 +76,11 @@ in
}
{
timeout = 360;
command = "${lockAndSuspend}";
command = "${suspendOnBattery}";
}
];
events = {
lock = lockCmd;
before-sleep = lockCmd;
after-resume = "${afterResume}";
};
};
+23
View File
@@ -0,0 +1,23 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock;
in
{
imports = [
./home.nix
./system.nix
];
options.my.applications.swaylock = {
enable = lib.mkEnableOption "swaylock screen locker";
};
config = lib.mkIf cfg.enable {
my.applications.swaylock.system.enable = lib.mkDefault true;
my.applications.swaylock.homeManager.enable = lib.mkDefault true;
};
}
+48
View File
@@ -0,0 +1,48 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock;
hmCfg = config.my.applications.swaylock.homeManager;
in
{
options.my.applications.swaylock.homeManager = {
enable = lib.mkEnableOption "swaylock home-manager configuration";
};
config.home-manager.sharedModules = [
(
{ lib, pkgs, ... }:
{
config = lib.mkIf (cfg.enable && hmCfg.enable) {
home.packages = with pkgs; [
swaylock # Wayland screen locker using ext-session-lock-v1
];
# systemd-lock-handler holds a sleep inhibitor until this service is
# ready. swaylock forks only after the compositor confirms the lock.
systemd.user.services.swaylock = {
Unit = {
Description = "Screen locker for Wayland";
Documentation = [ "man:swaylock(1)" ];
OnSuccess = [ "unlock.target" ];
PartOf = [ "lock.target" ];
Before = [ "lock.target" ];
};
Service = {
Type = "forking";
ExecStart = "${lib.getExe pkgs.swaylock} -f";
Restart = "on-failure";
RestartSec = 0;
};
Install.WantedBy = [ "lock.target" ];
};
};
}
)
];
}
+21
View File
@@ -0,0 +1,21 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock.system;
in
{
options.my.applications.swaylock.system = {
enable = lib.mkEnableOption "swaylock system configuration";
};
config = lib.mkIf cfg.enable {
services.systemd-lock-handler.enable = true;
# Screen unlocking deliberately uses passwords only. Fingerprints remain
# available to explicitly enabled PAM services such as sudo and polkit.
security.pam.services.swaylock.fprintAuth = false;
};
}
+1
View File
@@ -20,6 +20,7 @@ in
ly.enable = true;
noctalia.enable = true;
swayidle.enable = true;
swaylock.enable = true;
vicinae.enable = true;
};
my.system = {
+1 -1
View File
@@ -19,7 +19,7 @@ in
security.pam.services.polkit-1.fprintAuth = true;
security.pam.services = {
login.fprintAuth = true;
login.fprintAuth = false;
sudo.fprintAuth = true;
greetd.fprintAuth = lib.mkForce false;
ly.fprintAuth = lib.mkForce false;