diff --git a/hosts/x1g13/default.nix b/hosts/x1g13/default.nix index be9db17..481a888 100644 --- a/hosts/x1g13/default.nix +++ b/hosts/x1g13/default.nix @@ -7,8 +7,4 @@ boot.initrd.luks.devices.cryptroot.device = "/dev/disk/by-partuuid/311d0f9c-f35f-42e6-b6fc-a4d67dd21b2e"; - - my.applications.git.homeManager = { - signingKey = "~/.ssh/id_ed25519_sk_rk.pub"; - }; } diff --git a/modules/applications/1password.nix b/modules/applications/1password.nix index 073558e..b47ea8a 100644 --- a/modules/applications/1password.nix +++ b/modules/applications/1password.nix @@ -17,5 +17,10 @@ in enable = true; polkitPolicyOwners = [ "moons" ]; }; + + programs.ssh.startAgent = lib.mkForce false; + programs.gnupg.agent.enableSSHSupport = lib.mkForce false; + + services.gnome.gcr-ssh-agent.enable = lib.mkForce false; }; } diff --git a/modules/applications/git/default.nix b/modules/applications/git/default.nix index 6d7bbf9..8064501 100644 --- a/modules/applications/git/default.nix +++ b/modules/applications/git/default.nix @@ -14,15 +14,17 @@ in options.my.applications.git = { enable = lib.mkEnableOption "git version control"; + userName = lib.mkOption { - type = lib.types.str; - default = "moons-14"; - description = "Git user name"; + type = lib.types.singleLineStr; + default = "moons"; + description = "Default Git user.name."; }; + userEmail = lib.mkOption { - type = lib.types.str; + type = lib.types.singleLineStr; default = "moons@moons14.com"; - description = "Git user email"; + description = "Default Git user.email."; }; }; diff --git a/modules/applications/git/home.nix b/modules/applications/git/home.nix index 9791d65..9ba7fc0 100644 --- a/modules/applications/git/home.nix +++ b/modules/applications/git/home.nix @@ -1,4 +1,5 @@ { + pkgs, lib, config, ... @@ -6,15 +7,48 @@ let cfg = config.my.applications.git; hmCfg = config.my.applications.git.homeManager; + + signingKeyPath = ".ssh/1password-git-signing.pub"; + signingKeyFile = "~/${signingKeyPath}"; + + gitSshSign = pkgs.writeShellScript "git-ssh-sign" '' + one_password_sock="$HOME/.1password/agent.sock" + + if { [ -n "''${SSH_CONNECTION:-}" ] || [ -n "''${SSH_CLIENT:-}" ]; } \ + && [ -n "''${SSH_AUTH_SOCK:-}" ] \ + && [ -S "$SSH_AUTH_SOCK" ]; then + exec ${pkgs.openssh}/bin/ssh-keygen "$@" + fi + + if [ -S "$one_password_sock" ]; then + export SSH_AUTH_SOCK="$one_password_sock" + exec ${pkgs.openssh}/bin/ssh-keygen "$@" + fi + + if [ -n "''${SSH_AUTH_SOCK:-}" ] && [ -S "$SSH_AUTH_SOCK" ]; then + exec ${pkgs.openssh}/bin/ssh-keygen "$@" + fi + + echo "git ssh signing failed: no forwarded SSH agent or 1Password agent socket found" >&2 + echo "expected: forwarded SSH_AUTH_SOCK or $one_password_sock" >&2 + exit 1 + ''; in { options.my.applications.git.homeManager = { enable = lib.mkEnableOption "git home-manager configuration"; + signingPublicKey = lib.mkOption { + type = lib.types.nullOr lib.types.singleLineStr; + default = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq 1password-git-signing"; + example = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPLwReAiwhXoO34S2+MrvqUhi8IWp4IzUq4OSp3niJdq 1password-git-signing"; + description = "SSH public key copied from the 1Password SSH key item used for Git signing."; + }; + signingKey = lib.mkOption { - type = lib.types.nullOr lib.types.str; - default = "~/.ssh/id_ed25519_sk_rk.pub"; - example = "~/.ssh/id_ed25519.pub"; + type = lib.types.str; + default = signingKeyFile; + readOnly = true; description = "SSH public key path used for Git commit and tag signing."; }; }; @@ -22,13 +56,15 @@ in config = lib.mkIf hmCfg.enable { assertions = [ { - assertion = hmCfg.signingKey != null; - message = "my.applications.git.homeManager.signingKey must be set per host."; + assertion = hmCfg.signingPublicKey != null && hmCfg.signingPublicKey != ""; + message = "my.applications.git.homeManager.signingPublicKey must be set to the public key copied from 1Password."; } ]; home-manager.sharedModules = [ { + home.file.${signingKeyPath}.text = hmCfg.signingPublicKey + "\n"; + programs.git = { enable = true; @@ -44,7 +80,7 @@ in signByDefault = true; }; - settings = { + extraConfig = { user.name = cfg.userName; user.email = cfg.userEmail; @@ -55,6 +91,8 @@ in log.date = "iso"; merge.conflictStyle = "diff3"; + gpg.ssh.program = "${gitSshSign}"; + alias = { br = "branch --sort=-committerdate"; co = "checkout"; diff --git a/modules/applications/niri/home.nix b/modules/applications/niri/home.nix index 2759325..c6a2d14 100644 --- a/modules/applications/niri/home.nix +++ b/modules/applications/niri/home.nix @@ -48,6 +48,11 @@ in spawn-at-startup = [ { command = [ "noctalia-shell" ]; } + { + command = [ + "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1" + ]; + } ]; cursor.size = 16; diff --git a/modules/applications/niri/system.nix b/modules/applications/niri/system.nix index cb51762..1057953 100644 --- a/modules/applications/niri/system.nix +++ b/modules/applications/niri/system.nix @@ -18,6 +18,7 @@ in environment.systemPackages = with pkgs; [ wdisplays # Wayland display configuration GUI wlr-randr # Wayland output management CLI + polkit_gnome # Polkit authentication agent for GNOME ]; }; } diff --git a/modules/applications/ssh/default.nix b/modules/applications/ssh/default.nix index 0a5c0fd..7f99dcd 100644 --- a/modules/applications/ssh/default.nix +++ b/modules/applications/ssh/default.nix @@ -14,33 +14,6 @@ in options.my.applications.ssh = { enable = lib.mkEnableOption "OpenSSH client"; - - defaultIdentityFile = lib.mkOption { - type = lib.types.str; - default = "~/.ssh/id_ed25519"; - description = "Default SSH identity file"; - }; - - addKeysToAgent = lib.mkOption { - type = lib.types.str; - default = "no"; - description = "Add keys to SSH agent"; - }; - - matchBlocks = lib.mkOption { - type = lib.types.attrs; - default = { }; - description = "SSH match blocks"; - }; - - githubIdentityFiles = lib.mkOption { - type = lib.types.listOf lib.types.str; - default = [ - "~/.ssh/id_ed25519_sk_rk" - "~/.ssh/id_ed25519" - ]; - description = "SSH identity files for GitHub (tried in order)"; - }; }; config = lib.mkIf cfg.enable { diff --git a/modules/applications/ssh/home.nix b/modules/applications/ssh/home.nix index 17186e9..98a30fe 100644 --- a/modules/applications/ssh/home.nix +++ b/modules/applications/ssh/home.nix @@ -5,12 +5,17 @@ ... }: let - cfg = config.my.applications.ssh; hmCfg = config.my.applications.ssh.homeManager; in { options.my.applications.ssh.homeManager = { enable = lib.mkEnableOption "SSH home-manager configuration"; + + matchBlocks = lib.mkOption { + type = lib.types.attrs; + default = { }; + description = "SSH match blocks"; + }; }; config.home-manager.sharedModules = [ @@ -22,30 +27,31 @@ in systemd.user.sockets.gcr-ssh-agent.Install.WantedBy = lib.mkForce [ ]; - services.ssh-agent.enable = true; - - home.sessionVariables = { - SSH_AUTH_SOCK = "\${XDG_RUNTIME_DIR}/ssh-agent"; - }; + services.ssh-agent.enable = lib.mkForce false; programs.ssh = { enable = true; enableDefaultConfig = false; - settings = cfg.matchBlocks // { + settings = hmCfg.matchBlocks // { "github.com" = { - IdentityFile = cfg.githubIdentityFiles; - AddKeysToAgent = cfg.addKeysToAgent; + HostName = "github.com"; + User = "git"; + AddKeysToAgent = "no"; }; "*" = { - IdentityFile = cfg.defaultIdentityFile; - AddKeysToAgent = cfg.addKeysToAgent; + AddKeysToAgent = "no"; SetEnv = { TERM = "xterm-256color"; }; }; }; + + extraConfig = '' + Match exec "test -S %d/.1password/agent.sock" + IdentityAgent %d/.1password/agent.sock + ''; }; }; } diff --git a/modules/system/fingerprint.nix b/modules/system/fingerprint.nix index 28749ab..2671243 100644 --- a/modules/system/fingerprint.nix +++ b/modules/system/fingerprint.nix @@ -14,6 +14,10 @@ in config = lib.mkIf cfg.enable { services.fprintd.enable = true; + security.polkit.enable = true; + + security.pam.services.polkit-1.fprintAuth = true; + security.pam.services = { login.fprintAuth = true; sudo.fprintAuth = true;