This commit is contained in:
2026-07-14 19:28:47 +09:00
parent c5c56fde83
commit b5c49ffa79
9 changed files with 106 additions and 19 deletions
+1
View File
@@ -31,6 +31,7 @@
./slack.nix ./slack.nix
./ssh ./ssh
./swayidle.nix ./swayidle.nix
./swaylock
./tailscale.nix ./tailscale.nix
./vicinae.nix ./vicinae.nix
./vim ./vim
+3 -5
View File
@@ -123,12 +123,10 @@ in
}; };
"Mod+L" = { "Mod+L" = {
action.spawn = [ action.spawn = [
"noctalia" (lib.getExe' pkgs.systemd "loginctl")
"msg" "lock-session"
"session"
"lock"
]; ];
hotkey-overlay.title = "Lock the Screen: noctalia"; hotkey-overlay.title = "Lock the Screen";
}; };
"Mod+V" = { "Mod+V" = {
action.spawn = [ action.spawn = [
+4
View File
@@ -54,6 +54,10 @@ in
}; };
}; };
desktop_widgets.enabled = false; desktop_widgets.enabled = false;
lockscreen = {
enabled = false;
fingerprint = false;
};
widget = { widget = {
cpu = { cpu = {
type = "sysmon"; type = "sysmon";
+4 -13
View File
@@ -2,25 +2,18 @@
pkgs, pkgs,
lib, lib,
config, config,
inputs,
... ...
}: }:
let let
cfg = config.my.applications.swayidle; cfg = config.my.applications.swayidle;
noctaliaPkg = inputs.noctalia.packages.${pkgs.stdenv.hostPlatform.system}.default;
noctalia = lib.getExe noctaliaPkg;
brightnessctl = lib.getExe pkgs.brightnessctl; brightnessctl = lib.getExe pkgs.brightnessctl;
niri = lib.getExe pkgs.niri; niri = lib.getExe pkgs.niri;
rm = "${pkgs.coreutils}/bin/rm"; rm = "${pkgs.coreutils}/bin/rm";
systemctl = lib.getExe' pkgs.systemd "systemctl";
brightnessState = "$XDG_RUNTIME_DIR/swayidle-brightness"; brightnessState = "$XDG_RUNTIME_DIR/swayidle-brightness";
noctaliaMsg = command: "${noctalia} msg ${command}";
lockCmd = noctaliaMsg "session lock";
# AC 接続中は何もしない。 # AC 接続中は何もしない。
# つまり、以下のアイドル処理をバッテリー駆動時のみにする。 # つまり、以下のアイドル処理をバッテリー駆動時のみにする。
skipIfOnAC = '' skipIfOnAC = ''
@@ -49,10 +42,10 @@ let
fi fi
''; '';
lockAndSuspend = pkgs.writeShellScript "swayidle-lock-and-suspend" '' suspendOnBattery = pkgs.writeShellScript "swayidle-suspend-on-battery" ''
${skipIfOnAC} ${skipIfOnAC}
${noctaliaMsg "session lock-and-suspend"} exec ${systemctl} suspend
''; '';
afterResume = pkgs.writeShellScript "swayidle-after-resume" '' afterResume = pkgs.writeShellScript "swayidle-after-resume" ''
@@ -83,13 +76,11 @@ in
} }
{ {
timeout = 360; timeout = 360;
command = "${lockAndSuspend}"; command = "${suspendOnBattery}";
} }
]; ];
events = { events = {
lock = lockCmd;
before-sleep = lockCmd;
after-resume = "${afterResume}"; after-resume = "${afterResume}";
}; };
}; };
+23
View File
@@ -0,0 +1,23 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock;
in
{
imports = [
./home.nix
./system.nix
];
options.my.applications.swaylock = {
enable = lib.mkEnableOption "swaylock screen locker";
};
config = lib.mkIf cfg.enable {
my.applications.swaylock.system.enable = lib.mkDefault true;
my.applications.swaylock.homeManager.enable = lib.mkDefault true;
};
}
+48
View File
@@ -0,0 +1,48 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock;
hmCfg = config.my.applications.swaylock.homeManager;
in
{
options.my.applications.swaylock.homeManager = {
enable = lib.mkEnableOption "swaylock home-manager configuration";
};
config.home-manager.sharedModules = [
(
{ lib, pkgs, ... }:
{
config = lib.mkIf (cfg.enable && hmCfg.enable) {
home.packages = with pkgs; [
swaylock # Wayland screen locker using ext-session-lock-v1
];
# systemd-lock-handler holds a sleep inhibitor until this service is
# ready. swaylock forks only after the compositor confirms the lock.
systemd.user.services.swaylock = {
Unit = {
Description = "Screen locker for Wayland";
Documentation = [ "man:swaylock(1)" ];
OnSuccess = [ "unlock.target" ];
PartOf = [ "lock.target" ];
Before = [ "lock.target" ];
};
Service = {
Type = "forking";
ExecStart = "${lib.getExe pkgs.swaylock} -f";
Restart = "on-failure";
RestartSec = 0;
};
Install.WantedBy = [ "lock.target" ];
};
};
}
)
];
}
+21
View File
@@ -0,0 +1,21 @@
{
lib,
config,
...
}:
let
cfg = config.my.applications.swaylock.system;
in
{
options.my.applications.swaylock.system = {
enable = lib.mkEnableOption "swaylock system configuration";
};
config = lib.mkIf cfg.enable {
services.systemd-lock-handler.enable = true;
# Screen unlocking deliberately uses passwords only. Fingerprints remain
# available to explicitly enabled PAM services such as sudo and polkit.
security.pam.services.swaylock.fprintAuth = false;
};
}
+1
View File
@@ -20,6 +20,7 @@ in
ly.enable = true; ly.enable = true;
noctalia.enable = true; noctalia.enable = true;
swayidle.enable = true; swayidle.enable = true;
swaylock.enable = true;
vicinae.enable = true; vicinae.enable = true;
}; };
my.system = { my.system = {
+1 -1
View File
@@ -19,7 +19,7 @@ in
security.pam.services.polkit-1.fprintAuth = true; security.pam.services.polkit-1.fprintAuth = true;
security.pam.services = { security.pam.services = {
login.fprintAuth = true; login.fprintAuth = false;
sudo.fprintAuth = true; sudo.fprintAuth = true;
greetd.fprintAuth = lib.mkForce false; greetd.fprintAuth = lib.mkForce false;
ly.fprintAuth = lib.mkForce false; ly.fprintAuth = lib.mkForce false;