Author SHA1 Message Date
moons-14 99878e741b shells: guard platform-specific pcsc tools 2026-08-06 20:38:52 +09:00
moons-14 b9a4bf72fa style: format validation workflow 2026-08-06 20:31:44 +09:00
moons-14 6d223029df style: format flake update workflow 2026-08-06 20:30:54 +09:00
moons-14 e37a0b9e41 style: format validation checks 2026-08-06 20:30:18 +09:00
moons-14 102393819d style: format registry validation 2026-08-06 20:30:01 +09:00
moons-14 26e59ad5f7 ci: capture formatter diff 2026-08-06 20:26:18 +09:00
moons-14 d191f06cc7 ci: show formatter changes on failure 2026-08-06 20:23:59 +09:00
moons-14 483d343f48 flake: add coding-agent validation workflow 2026-08-06 20:16:17 +09:00
moons-14 5ebcbb4abf labwc 2026-08-06 17:22:00 +09:00
moons-14 f8fd8a3d99 wallpaper engine 2026-08-06 17:13:02 +09:00
moons-14 16742d2fd7 window overlay 2026-08-05 06:21:26 +09:00
moons-14 15da7affaa window-overview 2026-08-05 05:53:23 +09:00
moons-14 548647fec7 window switch 2026-08-05 05:27:40 +09:00
moons-14 bcbd08c225 wallpaper vicinae 2026-08-05 05:04:22 +09:00
moons-14 a0ae83d24e feat 2026-08-05 04:37:32 +09:00
46 changed files with 2565 additions and 231 deletions
+13
View File
@@ -0,0 +1,13 @@
[mcp_servers.nixos]
command = "mcp-nixos"
startup_timeout_sec = 30
tool_timeout_sec = 60
required = false
[mcp_servers.github]
url = "https://api.githubcopilot.com/mcp/"
bearer_token_env_var = "GITHUB_PERSONAL_ACCESS_TOKEN"
http_headers = { X-MCP-Readonly = "true", X-MCP-Toolsets = "repos,pull_requests,actions" }
startup_timeout_sec = 30
tool_timeout_sec = 60
required = false
+8 -20
View File
@@ -1,27 +1,15 @@
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml
name: Check NixOS configurations
description: Build every NixOS configuration and the Registry tests
name: Build Linux checks
description: Build every x86_64-linux flake check in parallel
runs:
using: composite
steps:
- name: Build every NixOS configuration
- name: Build all Linux checks
shell: bash
run: |
set -euo pipefail
mapfile -t hosts < <(
nix eval --raw .#nixosConfigurations \
--apply 'configs: builtins.concatStringsSep "\n" (builtins.attrNames configs)'
)
installables=(.#checks.x86_64-linux.registry)
for host in "${hosts[@]}"; do
installables+=(".#nixosConfigurations.${host}.config.system.build.toplevel")
done
nix build \
--keep-going \
--no-link \
--print-build-logs \
--show-trace \
"${installables[@]}"
nix run .#nix-fast-build -- \
--flake .#checks.x86_64-linux \
--skip-cached \
--no-nom \
--no-link
+1
View File
@@ -20,3 +20,4 @@ runs:
primary-key: nix-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('flake.lock') }}
restore-prefixes-first-match: nix-${{ runner.os }}-${{ runner.arch }}-
gc-max-store-size-linux: 4G
gc-max-store-size-macos: 4G
+163 -10
View File
@@ -1,36 +1,50 @@
# Reference: https://github.com/ryoppippi/dotfiles/blob/main/.github/workflows/nix-build.yaml
name: "CI: NixOS"
name: "CI: Nix"
on:
push:
branches:
- main
paths:
- .gitignore
- AGENTS.md
- README.md
- "docs/**"
- flake.nix
- flake.lock
- ".codex/**"
- ".github/**"
- ".vscode/**"
- "flake/**"
- "hosts/**"
- "libs/**"
- "modules/**"
- "opencode.json"
- "overlays/**"
- "scripts/**"
- "shells/**"
- "skills/**"
- "tests/**"
- ".github/actions/check-nixos/**"
- ".github/actions/setup-nix/**"
- ".github/workflows/nixos.yaml"
pull_request:
paths:
- .gitignore
- AGENTS.md
- README.md
- "docs/**"
- flake.nix
- flake.lock
- ".codex/**"
- ".github/**"
- ".vscode/**"
- "flake/**"
- "hosts/**"
- "libs/**"
- "modules/**"
- "opencode.json"
- "overlays/**"
- "scripts/**"
- "shells/**"
- "skills/**"
- "tests/**"
- ".github/actions/check-nixos/**"
- ".github/actions/setup-nix/**"
- ".github/workflows/nixos.yaml"
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
@@ -38,14 +52,153 @@ concurrency:
permissions:
contents: read
jobs:
check:
name: Check all NixOS configurations
validate:
name: Plan, lint, and evaluate
runs-on: ubuntu-latest
timeout-minutes: 120
outputs:
build_linux: ${{ steps.plan.outputs.build_linux }}
build_darwin: ${{ steps.plan.outputs.build_darwin }}
nix_validation: ${{ steps.plan.outputs.nix_validation }}
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Setup Nix
uses: ./.github/actions/setup-nix
- name: Check NixOS configurations
- name: Plan validation
id: plan
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
PUSH_BASE_SHA: ${{ github.event.before }}
shell: bash
run: |
set -euo pipefail
case "${{ github.event_name }}" in
pull_request)
plan="$(nix run .#check -- plan --base "$PR_BASE_SHA" --json)"
;;
push)
plan="$(nix run .#check -- plan --base "$PUSH_BASE_SHA" --json)"
;;
*)
plan="$(nix run .#check -- plan --all-files --all-hosts --json)"
;;
esac
printf '%s\n' "$plan"
nix_validation="$(jq -r '.requiresNixValidation' <<<"$plan")"
if [[ "${{ github.event_name }}" == "pull_request" ]]; then
build_linux="$(jq -r '.nativeBuildSystems["x86_64-linux"] // false' <<<"$plan")"
build_darwin="$(jq -r '.nativeBuildSystems["aarch64-darwin"] // false' <<<"$plan")"
else
build_linux="$nix_validation"
build_darwin="$nix_validation"
fi
{
echo "nix_validation=$nix_validation"
echo "build_linux=$build_linux"
echo "build_darwin=$build_darwin"
} >> "$GITHUB_OUTPUT"
- name: Run fast checks
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
PUSH_BASE_SHA: ${{ github.event.before }}
shell: bash
run: |
set +e
set -uo pipefail
case "${{ github.event_name }}" in
pull_request)
nix run .#check -- fast --base "$PR_BASE_SHA"
;;
push)
nix run .#check -- fast --base "$PUSH_BASE_SHA"
;;
*)
nix run .#check -- fast --all-files
;;
esac
status=$?
if (( status != 0 )); then
git diff -- .
exit "$status"
fi
- name: Evaluate configurations
if: steps.plan.outputs.nix_validation == 'true' || github.event_name == 'workflow_dispatch'
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
PUSH_BASE_SHA: ${{ github.event.before }}
shell: bash
run: |
set -euo pipefail
case "${{ github.event_name }}" in
pull_request)
nix run .#check -- eval --base "$PR_BASE_SHA"
;;
push)
nix run .#check -- eval --base "$PUSH_BASE_SHA" --all-systems
;;
*)
nix run .#check -- eval --all-hosts --all-systems
;;
esac
build-linux:
name: Build Linux checks
needs: validate
if: needs.validate.outputs.build_linux == 'true'
runs-on: ubuntu-latest
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Setup Nix
uses: ./.github/actions/setup-nix
- name: Build affected Linux checks
if: github.event_name == 'pull_request'
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
shell: bash
run: |
set -euo pipefail
nix run .#check -- build --base "$PR_BASE_SHA"
- name: Build all Linux checks
if: github.event_name != 'pull_request'
uses: ./.github/actions/check-nixos
build-darwin:
name: Build Darwin checks
needs: validate
if: needs.validate.outputs.build_darwin == 'true'
runs-on: macos-15
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- name: Setup Nix
uses: ./.github/actions/setup-nix
- name: Build affected Darwin checks
if: github.event_name == 'pull_request'
env:
PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
shell: bash
run: |
set -euo pipefail
nix run .#check -- build --base "$PR_BASE_SHA"
- name: Build all Darwin checks
if: github.event_name != 'pull_request'
shell: bash
run: |
set -euo pipefail
nix run .#nix-fast-build -- \
--flake .#checks.aarch64-darwin \
--skip-cached \
--no-nom \
--no-link
+66 -5
View File
@@ -12,9 +12,11 @@ permissions:
pull-requests: write
jobs:
update:
name: Update and validate flake inputs
name: Update and check Linux
runs-on: ubuntu-latest
timeout-minutes: 120
timeout-minutes: 180
outputs:
changed: ${{ steps.update.outputs.changed }}
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
@@ -22,18 +24,76 @@ jobs:
uses: ./.github/actions/setup-nix
- name: Update flake inputs
id: update
shell: bash
run: |
set -euo pipefail
nix flake update
if git diff --quiet -- flake.lock; then
echo 'changed=false' >> "$GITHUB_OUTPUT"
else
echo 'changed=true' >> "$GITHUB_OUTPUT"
fi
- name: Check updated NixOS configurations
- name: Evaluate every flake system
if: steps.update.outputs.changed == 'true'
shell: bash
run: |
set -euo pipefail
nix flake check \
--no-build \
--all-systems \
--keep-going \
--show-trace
- name: Build Linux checks
if: steps.update.outputs.changed == 'true'
uses: ./.github/actions/check-nixos
- name: Create update pull request
- name: Upload updated lock file
if: steps.update.outputs.changed == 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: flake-lock
path: flake.lock
if-no-files-found: error
check-darwin:
name: Check Darwin
needs: update
if: needs.update.outputs.changed == 'true'
runs-on: macos-15
timeout-minutes: 180
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Download updated lock file
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: flake-lock
path: .
- name: Setup Nix
uses: ./.github/actions/setup-nix
- name: Build Darwin checks
shell: bash
run: |
set -euo pipefail
nix run .#nix-fast-build -- \
--flake .#checks.aarch64-darwin \
--skip-cached \
--no-nom \
--no-link
pull-request:
name: Create update pull request
needs:
- update
- check-darwin
if: needs.update.outputs.changed == 'true'
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Download validated lock file
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: flake-lock
path: .
- name: Create update pull request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ secrets.GITHUB_TOKEN }}
@@ -45,4 +105,5 @@ jobs:
body: |
Automated update of `flake.lock`.
The updated inputs passed the Registry tests and a build of every NixOS configuration.
The updated inputs passed all-system evaluation and native builds of
the Linux and Darwin check sets.
+7 -1
View File
@@ -1,4 +1,6 @@
/*
**/__pycache__/
*.py[cod]
!.gitignore
!README.md
@@ -6,8 +8,10 @@
!AGENTS.md
!/docs/
!.github/
!/.codex/
!/.github/
!.gitea/
!/.vscode/
!.envrc
@@ -15,7 +19,9 @@
!/flake.nix
!/flake.lock
!/opencode.json
!/scripts/
!/shells/
!/flake/
!/overlays/
+28
View File
@@ -0,0 +1,28 @@
{
"nix.enableLanguageServer": true,
"nix.serverPath": "nixd",
"nix.serverSettings": {
"nixd": {
"formatting": {
"command": ["nixfmt"]
},
"nixpkgs": {
"expr": "import (builtins.getFlake (builtins.toString ./.)).inputs.nixpkgs { }"
},
"options": {
"nixos": {
"expr": "(builtins.getFlake (builtins.toString ./.)).nixosConfigurations.galleria.options"
},
"home-manager-nixos": {
"expr": "(builtins.getFlake (builtins.toString ./.)).nixosConfigurations.galleria.options.home-manager.users.type.getSubOptions []"
},
"darwin": {
"expr": "(builtins.getFlake (builtins.toString ./.)).darwinConfigurations.m2.options"
},
"home-manager-darwin": {
"expr": "(builtins.getFlake (builtins.toString ./.)).darwinConfigurations.m2.options.home-manager.users.type.getSubOptions []"
}
}
}
}
}
+4 -1
View File
@@ -1,3 +1,6 @@
# moons14 dotfiles
My NixOS + Home Manager configurations build with flake.
My NixOS, nix-darwin, and Home Manager configurations built with flakes.
See [Coding-agent validation](docs/coding-agents.md) for the non-activating,
change-aware validation workflow used by Codex, OpenCode, and CI.
+86
View File
@@ -0,0 +1,86 @@
# Coding-agent workflow
This repository exposes deterministic validation and narrowly scoped research
tools for Codex, OpenCode, and editor agents. Live system activation is outside
this workflow.
## Validation commands
Use task-owned paths during the edit loop:
```console
nix run .#check -- plan --paths modules/applications/example/home.nix --json
nix run .#check -- fast --paths modules/applications/example/home.nix
nix run .#check -- eval --paths modules/applications/example/home.nix
nix run .#check -- build --paths modules/applications/example/home.nix
nix run .#check -- all --paths modules/applications/example/home.nix
```
For a committed pull-request range, replace `--paths ...` with
`--base <base-sha>`. `full` is reserved for CI, scheduled maintenance, or an
explicit repository-wide audit:
```console
nix run .#check -- full
```
The stages have distinct meanings:
- `plan` maps changed paths to Registry units, reverse `meta.includes`
dependencies, real hosts, and compatible build systems.
- `fast` parses changed Nix files, validates JSON, TOML, Python, and Agent Skill
frontmatter, checks whitespace, and runs configured hooks only for the
selected files.
- `eval` instantiates affected NixOS and nix-darwin configurations. Flake-wide,
validation-tool, shell, overlay, and test changes additionally evaluate every
flake system.
- `build` realizes affected configurations supported by the current platform
with no result link. Incompatible targets remain evaluation-only until a
matching runner handles them.
- `all` performs task-scoped file checks, all-system evaluation, and compatible
targeted builds.
- `full` runs all-file hooks, all-system evaluation, and every check for the
current platform through `nix-fast-build`.
The validation app constructs a filtered temporary `path:` flake from the
committed `HEAD` tree and overlays only task-owned changed paths. This isolates
unrelated worktree changes, makes new untracked Registry fragments visible to
Nix without staging them, and avoids copying ignored state such as `.direnv`.
None of these commands runs `nh os switch`, `nixos-rebuild switch`,
`darwin-rebuild switch`, `home-manager switch`, or another activation command.
The user performs activation separately.
## Agent Skills
Read `AGENTS.md` first. Use the repository skills as follows:
- `validate-nix-change` controls validation scope and evidence.
- `debug-nix-failure` classifies parse, evaluation, build, test, activation-log,
and runtime failures before proposing a correction.
- `test-nixos-service` adds a `pkgs.testers.runNixOSTest` check when a build
cannot prove service behavior.
- `update-flake-input` limits lock-file updates and validates them without
activating a host.
- `add-application-or-service` preserves Registry ownership and delegates
validation to `validate-nix-change`.
## MCP and language-server setup
The development workload installs `mcp-nixos`, `nixd`, `nix-fast-build`, and
`nix-tree`.
Project-local Codex and OpenCode configuration exposes:
- `mcp-nixos` for current NixOS, Home Manager, nix-darwin, package, and Nix
documentation queries;
- GitHub's remote MCP endpoint for Codex and OpenCode in read-only mode,
restricted to repository, pull-request, and Actions toolsets.
Set `GITHUB_PERSONAL_ACCESS_TOKEN` in the launching environment when GitHub MCP
access is needed. Do not commit the token or put it in a Nix expression because
that would expose it through source control or the Nix store.
The workspace VS Code settings use `nixd` and expose option sets for the
`galleria` NixOS configuration, its integrated Home Manager configuration, the
`m2` nix-darwin configuration, and its integrated Home Manager configuration.
+1
View File
@@ -3,5 +3,6 @@
./formatter.nix
./git-hooks.nix
./registry.nix
./validation.nix
];
}
+2
View File
@@ -34,7 +34,9 @@
];
};
actionlint.enable = true;
deadnix.enable = true;
ruff.enable = true;
statix.enable = true;
shellcheck.enable = true;
};
+37 -6
View File
@@ -25,11 +25,42 @@ let
else
{ };
configurations = dotfilesLib.hosts.mkConfigurations hostSpecs;
validationMetadata = {
schemaVersion = 1;
hosts = lib.mapAttrs (
name: spec:
let
isDarwin = lib.hasSuffix "-darwin" spec.system;
in
{
inherit (spec) system user;
kind = if isDarwin then "darwin" else "nixos";
homeManager = spec.homeManager or true;
selectedUnits = dotfilesLib.hosts.selectedUnits spec;
buildAttr =
if isDarwin then
"darwinConfigurations.${name}.system"
else
"nixosConfigurations.${name}.config.system.build.toplevel";
}
) hostSpecs;
units = lib.mapAttrs (_id: unit: {
inherit (unit) id relativePath;
directory = "modules/${lib.concatStringsSep "/" unit.relativePath}";
includes = unit.meta.includes;
fragments = builtins.attrNames (lib.filterAttrs (_: value: value != null) unit.fragments);
}) dotfilesLib.registry.units;
};
in
{
flake = {
inherit (configurations) darwinConfigurations nixosConfigurations;
lib = dotfilesLib;
lib = dotfilesLib // {
inherit validationMetadata;
};
};
perSystem =
@@ -37,10 +68,9 @@ in
let
nixosChecks =
lib.mapAttrs' (name: nixos: lib.nameValuePair "nixos-${name}" nixos.config.system.build.toplevel)
(
lib.filterAttrs (
_: nixos: nixos.pkgs.stdenv.hostPlatform.system == system
) configurations.nixosConfigurations
(lib.filterAttrs (name: _: hostSpecs.${name}.system == system) configurations.nixosConfigurations);
darwinChecks = lib.mapAttrs' (name: darwin: lib.nameValuePair "darwin-${name}" darwin.system) (
lib.filterAttrs (name: _: hostSpecs.${name}.system == system) configurations.darwinConfigurations
);
in
{
@@ -49,6 +79,7 @@ in
inherit inputs lib pkgs;
};
}
// nixosChecks;
// nixosChecks
// darwinChecks;
};
}
+51
View File
@@ -0,0 +1,51 @@
_: {
perSystem =
{ pkgs, config, ... }:
let
script = pkgs.writeText "dotfiles-check.py" (builtins.readFile ../scripts/dotfiles-check.py);
dotfilesCheck = pkgs.writeShellApplication {
name = "dotfiles-check";
runtimeInputs = [
pkgs.git
pkgs.nix
pkgs.python3
];
text = ''
exec python3 ${script} "$@"
'';
};
in
{
apps = {
check = {
type = "app";
program = "${dotfilesCheck}/bin/dotfiles-check";
};
nix-fast-build = {
type = "app";
program = "${pkgs.nix-fast-build}/bin/nix-fast-build";
};
};
packages = {
dotfiles-check = dotfilesCheck;
inherit (pkgs) nix-fast-build;
};
devShells.validation = config.pre-commit.devShell;
checks = {
validation-tool =
pkgs.runCommand "dotfiles-check-self-test"
{
nativeBuildInputs = [ dotfilesCheck ];
}
''
dotfiles-check self-test
touch "$out"
'';
dotnix-shell = config.devShells.dotnix;
};
};
}
+1
View File
@@ -104,6 +104,7 @@
"interface.cli"
"interface.labwc"
"interface.niri"
"interface.wallpaperengine"
"platform.intel-nvidia-desktop"
"security.secrets"
"security.secure-boot"
+3 -3
View File
@@ -102,8 +102,8 @@ in
(action "W-q" "Close")
(action "W-f" "ToggleMaximize")
(action "W-c" "Iconify")
(action "W-Tab" "NextWindow")
(action "W-S-Tab" "PreviousWindow")
(execute "W-Tab" "window-overview")
(execute "W-S-Tab" "window-overview --reverse")
(action "W-Up" "Lower")
(action "W-Down" "Raise")
(action "W-Left" "NextWindow")
@@ -125,7 +125,7 @@ in
(execute "W-l" "loginctl lock-session")
(execute "W-v" "vicinae vicinae://launch/clipboard/history?toggle=true")
(execute "W-j" "nani-translate-primary")
(execute "W-S-j" "normcap-translate")
(execute "W-S-j" "nani-translate-ocr")
(execute "W-C-j" "${lib.getExe' pkgs.xdg-utils "xdg-open"} naniapp://translate")
(execute "W-space" "ghostty +toggle-quick-terminal")
(execute "W-p" "wdisplays")
@@ -1,28 +1,103 @@
From: Codex <[email protected]>
Subject: [PATCH] output: remove destroyed output from ext-workspace group
Subject: [PATCH] output: detach destroyed outputs from protocol handles
The DRM backend destroys and recreates outputs when a session is paused and
resumed. Remove the output from the ext-workspace group before wlroots
finishes it, otherwise the group's output_bind listener remains attached and
wlr_output_finish() aborts.
resumed. Remove the output from the ext-workspace group and the foreign
toplevel handles before wlroots finishes it. Both protocols attach bind
listeners to the output; leaving either listener behind makes
wlr_output_finish() abort.
---
src/output.c | 3 +++
1 file changed, 3 insertions(+)
src/foreign-toplevel/foreign.c | 14 ++++++++++++++
src/output.c | 6 ++++++
include/foreign-toplevel/foreign.h | 2 ++
3 files changed, 22 insertions(+)
diff --git a/src/output.c b/src/output.c
index 2eab8ec..f19c3ff 100644
index 2eab8ec..6f6e7ef 100644
--- a/src/output.c
+++ b/src/output.c
@@ -277,6 +277,9 @@ handle_output_destroy(struct wl_listener *listener, void *data)
@@ -27,8 +27,9 @@
#include "common/macros.h"
#include "common/mem.h"
#include "common/scene-helpers.h"
#include "common/string-helpers.h"
#include "config/rcxml.h"
+#include "foreign-toplevel/foreign.h"
#include "labwc.h"
#include "layers.h"
#include "node.h"
@@ -276,7 +277,15 @@ handle_output_destroy(struct wl_listener *listener, void *data)
struct output *output = wl_container_of(listener, output, destroy);
struct seat *seat = &server.seat;
regions_evacuate_output(output);
regions_destroy(seat, &output->regions);
+ wlr_ext_workspace_group_handle_v1_output_leave(
+ server.workspaces.ext_group, output->wlr_output);
+
+ struct view *view;
+ wl_list_for_each(view, &server.views, link) {
+ foreign_toplevel_remove_output(view->foreign_toplevel, output->wlr_output);
+ }
+
if (seat->overlay.active.output == output) {
overlay_finish(seat);
}
@@ -297,7 +305,6 @@ handle_output_destroy(struct wl_listener *listener, void *data)
output->workspace_osd = NULL;
}
- struct view *view;
wl_list_for_each(view, &server.views, link) {
if (view->output == output) {
view_on_output_destroy(view);
diff --git a/include/foreign-toplevel/foreign.h b/include/foreign-toplevel/foreign.h
index 69a340a..d8ec9b4 100644
--- a/include/foreign-toplevel/foreign.h
+++ b/include/foreign-toplevel/foreign.h
@@ -3,11 +3,14 @@
#define LABWC_FOREIGN_TOPLEVEL_H
struct view;
+struct wlr_output;
struct foreign_toplevel;
struct foreign_toplevel *foreign_toplevel_create(struct view *view);
void foreign_toplevel_set_parent(struct foreign_toplevel *toplevel,
struct foreign_toplevel *parent);
+void foreign_toplevel_remove_output(struct foreign_toplevel *toplevel,
+ struct wlr_output *output);
void foreign_toplevel_destroy(struct foreign_toplevel *toplevel);
#endif /* LABWC_FOREIGN_TOPLEVEL_H */
diff --git a/src/foreign-toplevel/foreign.c b/src/foreign-toplevel/foreign.c
index 7f1ec8d..0f628a3 100644
--- a/src/foreign-toplevel/foreign.c
+++ b/src/foreign-toplevel/foreign.c
@@ -1,4 +1,5 @@
// SPDX-License-Identifier: GPL-2.0-only
#include "foreign-toplevel/foreign.h"
+#include <wlr/types/wlr_foreign_toplevel_management_v1.h>
#include <assert.h>
#include "common/mem.h"
@@ -34,6 +34,18 @@ foreign_toplevel_set_parent(struct foreign_toplevel *toplevel, struct foreign_to
parent ? &parent->wlr_toplevel : NULL);
}
+void
+foreign_toplevel_remove_output(struct foreign_toplevel *toplevel,
+ struct wlr_output *output)
+{
+ if (!toplevel || !toplevel->wlr_toplevel.handle) {
+ return;
+ }
+
+ wlr_foreign_toplevel_handle_v1_output_leave(
+ toplevel->wlr_toplevel.handle, output);
+}
+
void
foreign_toplevel_destroy(struct foreign_toplevel *toplevel)
{
--
2.51.0
@@ -61,6 +61,33 @@ let
'';
};
mkVicinaeScript =
{
name,
title,
description,
command,
mode ? "compact",
message ? null,
}:
{
name = "vicinae/scripts/wallpaper-engine/${name}";
value = {
executable = true;
text = ''
#!${lib.getExe pkgs.bash}
# @vicinae.schemaVersion 1
# @vicinae.title ${title}
# @vicinae.description ${description}
# @vicinae.mode ${mode}
# @vicinae.icon 🖼️
${lib.getExe controller} ${lib.escapeShellArg command}
${lib.optionalString (message != null) "printf '%s\\n' ${lib.escapeShellArg message}"}
'';
};
};
launcher = pkgs.writeShellApplication {
name = "linux-wallpaperengine-launcher";
runtimeInputs = [
@@ -115,6 +142,50 @@ assert lib.assertMsg (builtins.elem scaling [
pkgs.linux-wallpaperengine
];
xdg.dataFile = builtins.listToAttrs [
(mkVicinaeScript {
name = "reload";
title = "Reload Wallpaper Engine";
description = "Restart the active Wallpaper Engine background";
command = "restart";
message = "Wallpaper Engine reloaded";
})
(mkVicinaeScript {
name = "next";
title = "Next Wallpaper Engine Wallpaper";
description = "Switch to the next configured Wallpaper Engine background";
command = "next";
message = "Switched to the next Wallpaper Engine wallpaper";
})
(mkVicinaeScript {
name = "previous";
title = "Previous Wallpaper Engine Wallpaper";
description = "Switch to the previous configured Wallpaper Engine background";
command = "previous";
message = "Switched to the previous Wallpaper Engine wallpaper";
})
(mkVicinaeScript {
name = "list";
title = "List Wallpaper Engine Wallpapers";
description = "Show the configured Wallpaper Engine backgrounds";
command = "list";
mode = "fullOutput";
})
(mkVicinaeScript {
name = "current";
title = "Current Wallpaper Engine Wallpaper";
description = "Show the active Wallpaper Engine background";
command = "current";
})
(mkVicinaeScript {
name = "stop";
title = "Stop Wallpaper Engine";
description = "Stop Wallpaper Engine for this session";
command = "stop";
message = "Wallpaper Engine stopped";
})
];
systemd.user.services = lib.optionalAttrs hasWallpapers {
linux-wallpaperengine = {
Unit = {
+74 -1
View File
@@ -1,5 +1,78 @@
_: {
{ pkgs, ... }:
let
tessdataBest = pkgs.runCommand "tessdata-best-jpn-eng-chi-sim" { } ''
mkdir -p "$out"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/jpn.traineddata";
hash = "sha256-Nr35rII/WRHmJMMNBVPokLirx8MaZbPvFNqUNljEC3k=";
}
} "$out/jpn.traineddata"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/eng.traineddata";
hash = "sha256-goCu0Hgv4nJXpo6hD+fvMkyg+Nhb0v0UXRwrVgvLZro=";
}
} "$out/eng.traineddata"
ln -s ${
pkgs.fetchurl {
url = "https://github.com/tesseract-ocr/tessdata_best/raw/main/chi_sim.traineddata";
hash = "sha256-T+8tEwbI6HYW1NPkxsZ/r11EvjNCKQz48vD246p+c1s=";
}
} "$out/chi_sim.traineddata"
'';
tesseract = pkgs.tesseract5.override {
tessdata = tessdataBest;
};
naniTranslatePrimary = pkgs.writeShellApplication {
name = "nani-translate-primary";
runtimeInputs = with pkgs; [
jq
wl-clipboard
xdg-utils
];
text = ''
selected_text="$(wl-paste --primary --no-newline)" || exit 0
[ -n "$selected_text" ] || exit 0
encoded_text="$(printf '%s' "$selected_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
naniTranslateOcr = pkgs.writeShellApplication {
name = "nani-translate-ocr";
runtimeInputs = with pkgs; [
grim
jq
slurp
tesseract
xdg-utils
];
text = ''
geometry="$(slurp)" || exit 0
captured_text="$(
grim -g "$geometry" - \
| tesseract stdin stdout -l jpn+eng+chi_sim --oem 1 --psm 6
)"
[ -n "$captured_text" ] || exit 0
encoded_text="$(printf '%s' "$captured_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
programs.naniTranslateLinux.enable = true;
xdg.mimeApps.defaultApplications."x-scheme-handler/naniapp" = "nani.desktop";
home.packages = [
naniTranslatePrimary
naniTranslateOcr
];
}
+19 -17
View File
@@ -1,24 +1,8 @@
{ lib, pkgs, ... }:
let
keybindings = import ./keybindings.nix;
naniTranslatePrimary = pkgs.writeShellApplication {
name = "nani-translate-primary";
runtimeInputs = with pkgs; [
jq
wl-clipboard
xdg-utils
];
text = ''
selected_text="$(wl-paste --primary --no-newline)" || exit 0
[ -n "$selected_text" ] || exit 0
encoded_text="$(printf '%s' "$selected_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
home.packages = [ naniTranslatePrimary ];
programs.niri.settings = {
binds = keybindings // {
@@ -57,6 +41,24 @@ in
hotkey-overlay.title = "Move Window to Monitor Down";
};
"Mod+Tab" = {
repeat = false;
action.spawn = [
"window-overview"
"--hold"
];
hotkey-overlay.title = "Window Overview: Next";
};
"Mod+Shift+Tab" = {
repeat = false;
action.spawn = [
"window-overview"
"--hold"
"--reverse"
];
hotkey-overlay.title = "Window Overview: Previous";
};
"Print".action.spawn = [
"screenshot"
"region"
@@ -119,7 +121,7 @@ in
};
"Mod+Shift+J" = {
repeat = false;
action.spawn = [ "normcap-translate" ];
action.spawn = [ "nani-translate-ocr" ];
hotkey-overlay.title = "OCR and Translate with Nani";
};
"Mod+Ctrl+J" = {
+1
View File
@@ -18,6 +18,7 @@ let
(oldAttrs: {
patches = (oldAttrs.patches or [ ]) ++ [
./patches/window-switcher-labwc.patch
./patches/taskbar-overview-hook.patch
];
});
+4
View File
@@ -2,6 +2,10 @@
{
description = "Noctalia Wayland desktop shell";
includes = [
"applications.window-overview"
];
imports = {
nixos = [ inputs.noctalia.nixosModules.default ];
home = [ inputs.noctalia.homeModules.default ];
@@ -0,0 +1,43 @@
diff --git a/src/shell/bar/widgets/taskbar_widget.cpp b/src/shell/bar/widgets/taskbar_widget.cpp
--- a/src/shell/bar/widgets/taskbar_widget.cpp
+++ b/src/shell/bar/widgets/taskbar_widget.cpp
@@ -5,6 +5,7 @@
#include "compositors/workspace_backend.h"
#include "config/config_service.h"
#include "core/deferred_call.h"
+#include "core/process/process.h"
#include "i18n/i18n.h"
#include "render/core/color.h"
#include "render/core/renderer.h"
@@ -36,6 +37,18 @@
namespace {
+ [[nodiscard]] bool launchTaskbarOverview(const std::string& appId) {
+ constexpr const char* command = "noctalia-taskbar-overview";
+ if (appId.empty() || !process::commandExists(command)) {
+ return false;
+ }
+ return process::runAsync({
+ command,
+ "--app-id",
+ appId.c_str(),
+ });
+ }
+
// Integer centering; optional odd spare pixel on the end side (right/bottom).
[[nodiscard]] float centeredOffset(float extent, float content, float inset = 0.0F, bool oddSpareOnEnd = true) {
const float inner = std::max(0.0F, extent - inset * 2.0F);
@@ -373,6 +386,12 @@ void TaskbarWidget::activateOrLaunchPinned(const TaskModel& task) {
return;
}
+ const std::string overviewAppId =
+ !task.appId.empty() ? task.appId : (!task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower);
+ if (launchTaskbarOverview(overviewAppId)) {
+ return;
+ }
+
const std::string cycleKey = !task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower;
std::size_t& cursor = m_groupedAppCycleCursor[cycleKey];
if (cursor >= windows.size()) {
@@ -24,56 +24,3 @@ diff --git a/src/shell/switcher/window_switcher.cpp b/src/shell/switcher/window_
if (key.empty()) {
continue;
}
diff --git a/src/shell/bar/widgets/taskbar_widget.cpp b/src/shell/bar/widgets/taskbar_widget.cpp
--- a/src/shell/bar/widgets/taskbar_widget.cpp
+++ b/src/shell/bar/widgets/taskbar_widget.cpp
@@ -5,6 +5,7 @@
#include "compositors/workspace_backend.h"
#include "config/config_service.h"
#include "core/deferred_call.h"
+#include "core/process/process.h"
#include "i18n/i18n.h"
#include "render/core/color.h"
#include "render/core/renderer.h"
@@ -36,6 +37,18 @@
namespace {
+ [[nodiscard]] bool launchTaskbarOverview(const std::string& appId) {
+ constexpr const char* command = "noctalia-taskbar-overview";
+ if (appId.empty() || !process::commandExists(command)) {
+ return false;
+ }
+ return process::runAsync({
+ command,
+ "--app-id",
+ appId.c_str(),
+ });
+ }
+
// Integer centering; optional odd spare pixel on the end side (right/bottom).
[[nodiscard]] float centeredOffset(float extent, float content, float inset = 0.0F, bool oddSpareOnEnd = true) {
const float inner = std::max(0.0F, extent - inset * 2.0F);
@@ -373,6 +386,12 @@ void TaskbarWidget::activateOrLaunchPinned(const TaskModel& task) {
return;
}
+ const std::string overviewAppId =
+ !task.appId.empty() ? task.appId : (!task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower);
+ if (launchTaskbarOverview(overviewAppId)) {
+ return;
+ }
+
const std::string cycleKey = !task.desktopEntryId.empty() ? task.desktopEntryId : task.idLower;
std::size_t& cursor = m_groupedAppCycleCursor[cycleKey];
if (cursor >= windows.size()) {
@@ -792,6 +811,9 @@ void TaskbarWidget::create() {
}
if (data.button == BTN_LEFT) {
if (!cycleCandidates.empty()) {
+ if (cycleCandidates.size() > 1 && launchTaskbarOverview(current->appId)) {
+ return;
+ }
std::size_t& cursor = m_groupedAppCycleCursor[cycleKey];
if (cursor >= cycleCandidates.size()) {
cursor = 0;
@@ -1,44 +0,0 @@
{ pkgs, ... }:
let
normcap = pkgs.normcap.override {
tesseract4 = pkgs.tesseract4.override {
enableLanguages = [
"chi_sim"
"jpn"
"eng"
];
};
};
normcapTranslate = pkgs.writeShellApplication {
name = "normcap-translate";
runtimeInputs = [
normcap
pkgs.jq
pkgs.xdg-utils
];
text = ''
captured_text="$(
normcap \
--cli-mode \
--screenshot-handler grim \
--show-introduction False \
--update False \
--detect-codes False \
--notification False \
-l jpn eng chi_sim
)" || exit 0
[ -n "$captured_text" ] || exit 0
encoded_text="$(printf '%s' "$captured_text" | jq -sRr @uri)"
exec xdg-open "naniapp://translate?source=$encoded_text"
'';
};
in
{
home.packages = [
normcap
normcapTranslate
];
}
-7
View File
@@ -1,7 +0,0 @@
{
description = "NormCap OCR screen capture";
includes = [
"applications.nani"
];
}
+1 -1
View File
@@ -118,7 +118,7 @@ let
];
userSettings = {
"nix.enableLanguageServer" = true;
"nix.serverPath" = "nil";
"nix.serverPath" = "nixd";
"nix.serverSettings" = {
nixd = {
formatting.command = [ "nixfmt" ];
@@ -0,0 +1,7 @@
{ pkgs, ... }:
let
windowOverview = pkgs.callPackage ../package.nix { };
in
{
home.packages = [ windowOverview ];
}
@@ -0,0 +1,7 @@
{
description = "Fullscreen Wayland window overview with captured previews";
includes = [
"systems.wayland"
];
}
@@ -0,0 +1,77 @@
{
lib,
fetchCrate,
libgbm,
libglvnd,
libxkbcommon,
jq,
makeWrapper,
pkg-config,
rustPlatform,
wayland,
wl-clipboard,
}:
rustPlatform.buildRustPackage rec {
pname = "window-overview";
version = "1.5.0";
src = fetchCrate {
pname = "wlr-chooser";
inherit version;
hash = "sha256-Jb59m1z+2G5istcbC0sg9jRVcC/bQh/OY0ny9OdTsdw=";
};
patches = [
./patches/window-overview.patch
./patches/niri-backend.patch
];
cargoHash = "sha256-KBLgtS8ULrmsOf6BN5SlkVQyXB12utvr/KonnKnCTCM=";
nativeBuildInputs = [
makeWrapper
pkg-config
];
buildInputs = [
libgbm
libglvnd
libxkbcommon
wayland
];
cargoBuildFlags = [
"--bin"
"wlr-switcher"
];
postInstall = ''
mv "$out/bin/wlr-switcher" "$out/bin/.window-overview-wrapped"
makeWrapper "$out/bin/.window-overview-wrapped" "$out/bin/window-overview" \
--add-flags "--layout grid" \
--prefix PATH : "${
lib.makeBinPath [
jq
wl-clipboard
]
}" \
--prefix LD_LIBRARY_PATH : "${
lib.makeLibraryPath [
libgbm
libglvnd
]
}:/run/opengl-driver/lib"
ln -s window-overview "$out/bin/noctalia-taskbar-overview"
'';
meta = {
description = "Fullscreen Wayland window overview with captured previews";
homepage = "https://github.com/sjourdois/wlr-utils";
license = with lib.licenses; [
asl20
mit
];
mainProgram = "window-overview";
platforms = lib.platforms.linux;
};
}
@@ -0,0 +1,431 @@
--- a/src/chooser_cli.rs
+++ b/src/chooser_cli.rs
@@ -81,6 +81,7 @@
initial_cycle: None,
snapshot: false,
cycle_socket: None,
+ niri_backend: false,
};
match run_overlay(opts, t0) {
--- a/src/lib.rs
+++ b/src/lib.rs
@@ -65,7 +65,14 @@
// must connect, enumerate, and open sessions before any thumbnail appears.
let (tx, rx) = mpsc::channel();
let snapshot = opts.snapshot;
- std::thread::spawn(move || ui::capture_thread(tx, snapshot));
+ let niri_backend = opts.niri_backend;
+ std::thread::spawn(move || {
+ if niri_backend {
+ ui::niri_capture_thread(tx);
+ } else {
+ ui::capture_thread(tx, snapshot);
+ }
+ });
shell::tlog(t0, "capture-thread spawned");
let out: ui::Outcome = Arc::new(Mutex::new(None));
--- a/src/switcher_cli.rs
+++ b/src/switcher_cli.rs
@@ -88,6 +88,7 @@
let t0 = Instant::now();
let cli = Cli::parse();
i18n::init();
+ let niri_backend = std::env::var_os("NIRI_SOCKET").is_some();
if cli.doctor {
if let Err(e) = wlr_capture::doctor::report("wlr-switcher", env!("CARGO_PKG_VERSION")) {
@@ -129,32 +130,50 @@
initial_cycle: Some(!cli.reverse),
snapshot: true,
cycle_socket: Some(cycle_socket),
+ niri_backend,
};
// Pre-flight: wlr-switcher switches *windows*, which need the foreign-toplevel
// capture source (wlroots >= 0.20 / Sway >= 1.12). On older compositors connect()
// now succeeds for screen-only capture, but there are no windows to offer — so say
// so clearly and exit, instead of showing an empty dimmed overlay (issue #1).
- match wl::Client::connect() {
- Ok(client) if !client.can_capture_windows() => {
- eprintln!("{}", tr!("capture-no-window"));
- std::process::exit(2);
- }
- Ok(_) => {}
- Err(e) => {
- eprintln!("{}", tr!("error", error = format!("{e:#}")));
- std::process::exit(2);
+ if !niri_backend {
+ match wl::Client::connect() {
+ Ok(client) if !client.can_capture_windows() => {
+ eprintln!("{}", tr!("capture-no-window"));
+ std::process::exit(2);
+ }
+ Ok(_) => {}
+ Err(e) => {
+ eprintln!("{}", tr!("error", error = format!("{e:#}")));
+ std::process::exit(2);
+ }
}
}
match run_overlay(opts, t0) {
Ok(Some(sel)) => {
// Focus the picked window (outputs aren't focusable, so ignore them).
- if sel.is_window
- && let Err(e) = wl::activate_window(&sel.app_id, &sel.title, sel.dup_index)
- {
- eprintln!("{}", tr!("error", error = format!("{e:#}")));
- std::process::exit(2);
+ if sel.is_window {
+ let result: anyhow::Result<()> = if niri_backend {
+ let output = std::process::Command::new("niri")
+ .args(["msg", "action", "focus-window", "--id", &sel.identifier])
+ .output();
+ match output {
+ Ok(output) if output.status.success() => Ok(()),
+ Ok(output) => Err(anyhow::anyhow!(
+ "{}",
+ String::from_utf8_lossy(&output.stderr).trim()
+ )),
+ Err(e) => Err(e.into()),
+ }
+ } else {
+ wl::activate_window(&sel.app_id, &sel.title, sel.dup_index).map_err(Into::into)
+ };
+ if let Err(e) = result {
+ eprintln!("{}", tr!("error", error = format!("{e:#}")));
+ std::process::exit(2);
+ }
}
}
Ok(None) => std::process::exit(1), // cancelled
--- a/src/ui.rs
+++ b/src/ui.rs
@@ -6,7 +6,9 @@
use crate::tr;
use std::collections::{HashMap, HashSet};
+use std::io::Write;
use std::path::PathBuf;
+use std::process::{Command, Stdio};
use std::sync::mpsc::{Receiver, Sender};
use std::sync::{Arc, Mutex};
use std::time::{Duration, Instant};
@@ -366,6 +368,288 @@
}
}
+#[derive(Clone)]
+struct NiriWindow {
+ id: String,
+ app_id: String,
+ title: String,
+}
+
+enum ClipboardSnapshot {
+ Empty,
+ Content { mime: String, data: Vec<u8> },
+ Unavailable,
+}
+
+fn save_clipboard() -> ClipboardSnapshot {
+ let Ok(types) = Command::new("wl-paste").arg("--list-types").output() else {
+ return ClipboardSnapshot::Unavailable;
+ };
+ if !types.status.success() {
+ return ClipboardSnapshot::Empty;
+ }
+ let types = String::from_utf8_lossy(&types.stdout);
+ let offered: Vec<&str> = types.lines().filter(|line| !line.is_empty()).collect();
+ let Some(mime) = offered
+ .iter()
+ .copied()
+ .find(|mime| *mime == "text/plain;charset=utf-8")
+ .or_else(|| offered.first().copied())
+ else {
+ return ClipboardSnapshot::Empty;
+ };
+ let Ok(data) = Command::new("wl-paste")
+ .args(["--type", mime])
+ .output()
+ else {
+ return ClipboardSnapshot::Unavailable;
+ };
+ if !data.status.success() {
+ return ClipboardSnapshot::Unavailable;
+ }
+ ClipboardSnapshot::Content {
+ mime: mime.to_owned(),
+ data: data.stdout,
+ }
+}
+
+fn restore_clipboard(snapshot: ClipboardSnapshot) {
+ match snapshot {
+ ClipboardSnapshot::Empty => {
+ let _ = Command::new("wl-copy").arg("--clear").status();
+ }
+ ClipboardSnapshot::Content { mime, data } => {
+ let Ok(mut copy) = Command::new("wl-copy")
+ .args(["--type", &mime])
+ .stdin(Stdio::piped())
+ .spawn()
+ else {
+ return;
+ };
+ if let Some(mut stdin) = copy.stdin.take() {
+ let _ = stdin.write_all(&data);
+ }
+ let _ = copy.wait();
+ }
+ ClipboardSnapshot::Unavailable => {}
+ }
+}
+
+/// Decode one field emitted by jq's `@tsv` formatter. It escapes the only
+/// characters that would otherwise make the line-oriented transport ambiguous.
+fn unescape_tsv(value: &str) -> String {
+ let mut decoded = String::with_capacity(value.len());
+ let mut chars = value.chars();
+ while let Some(ch) = chars.next() {
+ if ch != '\\' {
+ decoded.push(ch);
+ continue;
+ }
+ match chars.next() {
+ Some('t') => decoded.push('\t'),
+ Some('r') => decoded.push('\r'),
+ Some('n') => decoded.push('\n'),
+ Some('\\') => decoded.push('\\'),
+ Some(other) => {
+ decoded.push('\\');
+ decoded.push(other);
+ }
+ None => decoded.push('\\'),
+ }
+ }
+ decoded
+}
+
+/// Ask niri for its toplevel list. niri does not implement the
+/// ext-image-copy-capture window protocol, so its IPC is the source of both the
+/// stable window id and the metadata used by this backend.
+fn niri_windows() -> Result<Vec<NiriWindow>, String> {
+ let response = Command::new("niri")
+ .args(["msg", "-j", "windows"])
+ .output()
+ .map_err(|e| format!("could not run niri msg: {e}"))?;
+ if !response.status.success() {
+ return Err(String::from_utf8_lossy(&response.stderr).trim().to_owned());
+ }
+
+ let mut jq = Command::new("jq")
+ .args([
+ "-r",
+ ".[] | [(.id | tostring), (.app_id // \"\"), (.title // \"\")] | @tsv",
+ ])
+ .stdin(Stdio::piped())
+ .stdout(Stdio::piped())
+ .stderr(Stdio::piped())
+ .spawn()
+ .map_err(|e| format!("could not run jq: {e}"))?;
+ jq.stdin
+ .take()
+ .ok_or_else(|| String::from("jq stdin was unavailable"))?
+ .write_all(&response.stdout)
+ .map_err(|e| format!("could not pass niri window list to jq: {e}"))?;
+ let output = jq
+ .wait_with_output()
+ .map_err(|e| format!("could not read jq output: {e}"))?;
+ if !output.status.success() {
+ return Err(String::from_utf8_lossy(&output.stderr).trim().to_owned());
+ }
+
+ let text = String::from_utf8(output.stdout)
+ .map_err(|e| format!("niri window list was not UTF-8: {e}"))?;
+ let mut windows = Vec::new();
+ for line in text.lines() {
+ let mut fields = line.splitn(3, '\t');
+ let Some(id) = fields.next() else { continue };
+ let Some(app_id) = fields.next() else { continue };
+ let Some(title) = fields.next() else { continue };
+ windows.push(NiriWindow {
+ id: id.to_owned(),
+ app_id: unescape_tsv(app_id),
+ title: unescape_tsv(title),
+ });
+ }
+ windows.sort_by(|a, b| {
+ a.app_id
+ .to_lowercase()
+ .cmp(&b.app_id.to_lowercase())
+ .then_with(|| a.title.to_lowercase().cmp(&b.title.to_lowercase()))
+ });
+ Ok(windows)
+}
+
+fn niri_window_source(w: &NiriWindow, dup_index: usize) -> Source {
+ let is_system = w.app_id.is_empty();
+ let (title, subtitle) = if is_system {
+ (w.title.clone(), String::new())
+ } else {
+ (w.app_id.clone(), w.title.clone())
+ };
+ Source {
+ key: w.id.clone(),
+ token: format!("Window: {}", w.id),
+ filter: format!("{} {}", w.app_id, w.title).to_lowercase(),
+ title,
+ subtitle,
+ is_window: true,
+ is_system,
+ app_id: w.app_id.clone(),
+ win_title: w.title.clone(),
+ dup_index,
+ }
+}
+
+/// Capture a static overview through niri's IPC. This is deliberately separate
+/// from the generic Wayland backend: niri can render any toplevel by id (even an
+/// occluded one), but does not advertise ext-image-copy-capture.
+pub fn niri_capture_thread(tx: Sender<Msg>) {
+ let windows = match niri_windows() {
+ Ok(windows) => windows,
+ Err(e) => {
+ eprintln!("niri overview backend: {e}");
+ return;
+ }
+ };
+
+ let mut dup: HashMap<(String, String), usize> = HashMap::new();
+ let mut current = Vec::with_capacity(windows.len());
+ for window in windows {
+ let e = dup
+ .entry((window.app_id.clone(), window.title.clone()))
+ .or_insert(0);
+ let source = niri_window_source(&window, *e);
+ *e += 1;
+ current.push((source, window));
+ }
+ if tx
+ .send(Msg::Sources(
+ current.iter().map(|(source, _)| source.clone()).collect(),
+ ))
+ .is_err()
+ {
+ return;
+ }
+
+ let capture_dir = wlr_capture::paths::runtime_dir().join(format!(
+ "window-overview-niri-{}",
+ std::process::id()
+ ));
+ if let Err(e) = std::fs::create_dir_all(&capture_dir) {
+ eprintln!("niri overview backend: could not create capture directory: {e}");
+ return;
+ }
+ // niri's screenshot action also sets the clipboard. Preserve the existing
+ // selection so opening the overview does not unexpectedly replace it.
+ let clipboard = save_clipboard();
+
+ for (source, window) in current {
+ if let Some(path) = icons::resolve(&window.app_id)
+ && let Some((w, h, rgba)) = icons::load(&path, 128)
+ && tx
+ .send(Msg::Icon {
+ key: source.key.clone(),
+ w: w as usize,
+ h: h as usize,
+ rgba,
+ })
+ .is_err()
+ {
+ break;
+ }
+
+ let path = capture_dir.join(format!("{}.png", window.id));
+ let command = Command::new("niri")
+ .args(["msg", "action", "screenshot-window", "--id"])
+ .arg(&window.id)
+ .args(["--write-to-disk", "true", "--show-pointer", "false", "--path"])
+ .arg(&path)
+ .output();
+ let Ok(output) = command else {
+ continue;
+ };
+ if !output.status.success() {
+ eprintln!(
+ "niri overview backend: could not capture window {}: {}",
+ window.id,
+ String::from_utf8_lossy(&output.stderr).trim()
+ );
+ continue;
+ }
+
+ // niri encodes PNGs off the compositor thread, after acknowledging the
+ // IPC action. Wait briefly for that completion without delaying the UI.
+ let mut bytes = None;
+ for _ in 0..200 {
+ match std::fs::read(&path) {
+ Ok(data) => {
+ bytes = Some(data);
+ break;
+ }
+ Err(_) => std::thread::sleep(Duration::from_millis(10)),
+ }
+ }
+ let Some(bytes) = bytes else { continue };
+ let Ok(image) = image::load_from_memory_with_format(&bytes, image::ImageFormat::Png) else {
+ continue;
+ };
+ let image = image.into_rgba8();
+ let (w, h, rgba) = thumbnail_rgba(image.width(), image.height(), image.into_raw());
+ if tx
+ .send(Msg::Thumb {
+ key: source.key,
+ w,
+ h,
+ rgba,
+ })
+ .is_err()
+ {
+ break;
+ }
+ let _ = std::fs::remove_file(path);
+ }
+ let _ = std::fs::remove_dir(capture_dir);
+ restore_clipboard(clipboard);
+}
+
/// Cheap content fingerprint of a frame (subsampled FNV-1a), to tell whether a
/// capture actually changed between rounds — used by the headless bench.
fn quick_hash(rgba: &[u8]) -> u64 {
@@ -515,11 +799,14 @@
/// Downscale a capture to a thumbnail (max side `THUMB_MAX`), never upscaling.
fn thumbnail(img: wl::CapturedImage) -> (usize, usize, Vec<u8>) {
- let (w, h) = (img.width, img.height);
+ thumbnail_rgba(img.width, img.height, img.rgba)
+}
+
+fn thumbnail_rgba(w: u32, h: u32, rgba: Vec<u8>) -> (usize, usize, Vec<u8>) {
let scale = (THUMB_MAX as f32 / w as f32)
.min(THUMB_MAX as f32 / h as f32)
.min(1.0);
- let src = match image::RgbaImage::from_raw(w, h, img.rgba) {
+ let src = match image::RgbaImage::from_raw(w, h, rgba) {
Some(s) => s,
None => return (0, 0, Vec::new()),
};
@@ -557,6 +844,9 @@
pub snapshot: bool,
/// Receives next/previous commands from repeated compositor keybind launches.
pub cycle_socket: Option<std::os::unix::net::UnixDatagram>,
+ /// Use niri's IPC for window enumeration and snapshots instead of the
+ /// ext-image-copy-capture protocol that niri does not implement.
+ pub niri_backend: bool,
}
pub struct App {
@@ -0,0 +1,336 @@
--- a/src/chooser_cli.rs
+++ b/src/chooser_cli.rs
@@ -79,0 +80,4 @@
+ app_id_filter: None,
+ initial_cycle: None,
+ snapshot: false,
+ cycle_socket: None,
--- a/src/lib.rs
+++ b/src/lib.rs
@@ -33,3 +33,3 @@
-/// Returns the held lock file (keep it alive), or `None` if another instance owns
-/// it — sway processes its own keybinding even over our exclusive keyboard grab,
-/// so re-pressing the bind would otherwise stack overlays.
+/// Returns the held lock and command socket for the first instance. Later
+/// invocations forward their requested cycle direction through the socket and
+/// return `None`, which also supports compositors that keep handling the binding.
@@ -36 +36,3 @@
-pub fn acquire_switch_lock() -> Option<std::fs::File> {
+pub fn acquire_switch_lock(
+ forward: bool,
+) -> Option<(std::fs::File, std::os::unix::net::UnixDatagram)> {
@@ -38,0 +41 @@
+ let socket_path = dir.join("wlr-switcher.sock");
@@ -45,2 +49,10 @@
- flock(&f, FlockOperation::NonBlockingLockExclusive).ok()?;
- Some(f)
+ if flock(&f, FlockOperation::NonBlockingLockExclusive).is_err() {
+ let socket = std::os::unix::net::UnixDatagram::unbound().ok()?;
+ let command = if forward { b"next" } else { b"prev" };
+ let _ = socket.send_to(command, socket_path);
+ return None;
+ }
+ let _ = std::fs::remove_file(&socket_path);
+ let socket = std::os::unix::net::UnixDatagram::bind(socket_path).ok()?;
+ socket.set_nonblocking(true).ok()?;
+ Some((f, socket))
@@ -56 +68,2 @@
- std::thread::spawn(move || ui::capture_thread(tx));
+ let snapshot = opts.snapshot;
+ std::thread::spawn(move || ui::capture_thread(tx, snapshot));
--- a/src/shell.rs
+++ b/src/shell.rs
@@ -617,0 +618,3 @@
+ Keysym::plus | Keysym::KP_Add => Key::Plus,
+ Keysym::equal => Key::Equals,
+ Keysym::minus | Keysym::KP_Subtract => Key::Minus,
--- a/src/switcher_cli.rs
+++ b/src/switcher_cli.rs
@@ -75,0 +76,6 @@
+ /// Show only windows whose Wayland app-id exactly matches this value.
+ #[arg(long)]
+ app_id: Option<String>,
+ /// Select the previous window when the overview first opens.
+ #[arg(long)]
+ reverse: bool,
@@ -96,2 +102,2 @@
- let _lock = match acquire_switch_lock() {
- Some(lock) => lock,
+ let (_lock, cycle_socket) = match acquire_switch_lock(!cli.reverse) {
+ Some(instance) => instance,
@@ -121,0 +128,4 @@
+ app_id_filter: cli.app_id,
+ initial_cycle: Some(!cli.reverse),
+ snapshot: true,
+ cycle_socket: Some(cycle_socket),
--- a/src/ui.rs
+++ b/src/ui.rs
@@ -8,0 +9 @@
+use std::path::PathBuf;
@@ -41,0 +43,32 @@
+const DEFAULT_OVERVIEW_SCALE: f32 = 0.85;
+const MIN_OVERVIEW_SCALE: f32 = 0.55;
+const MAX_OVERVIEW_SCALE: f32 = 1.0;
+
+fn overview_scale_path() -> Option<PathBuf> {
+ if let Some(path) = std::env::var_os("XDG_STATE_HOME") {
+ return Some(PathBuf::from(path).join("window-overview/scale"));
+ }
+ std::env::var_os("HOME")
+ .map(PathBuf::from)
+ .map(|path| path.join(".local/state/window-overview/scale"))
+}
+
+fn load_overview_scale() -> f32 {
+ overview_scale_path()
+ .and_then(|path| std::fs::read_to_string(path).ok())
+ .and_then(|value| value.trim().parse::<f32>().ok())
+ .unwrap_or(DEFAULT_OVERVIEW_SCALE)
+ .clamp(MIN_OVERVIEW_SCALE, MAX_OVERVIEW_SCALE)
+}
+
+fn save_overview_scale(scale: f32) {
+ let Some(path) = overview_scale_path() else {
+ return;
+ };
+ let Some(parent) = path.parent() else {
+ return;
+ };
+ if std::fs::create_dir_all(parent).is_ok() {
+ let _ = std::fs::write(path, format!("{scale:.2}\n"));
+ }
+}
@@ -177 +210 @@
-pub fn capture_thread(tx: Sender<Msg>) {
+pub fn capture_thread(tx: Sender<Msg>, snapshot: bool) {
@@ -189,0 +223 @@
+ let mut captured: HashSet<String> = HashSet::new();
@@ -236,0 +271 @@
+ captured.retain(|key| present.contains(key.as_str()));
@@ -255 +290 @@
- if sessions.contains_key(&s.key) {
+ if sessions.contains_key(&s.key) || (snapshot && captured.contains(&s.key)) {
@@ -295 +330,3 @@
- let Some(key) = by_id.get(&id) else { continue };
+ let Some(key) = by_id.get(&id).cloned() else {
+ continue;
+ };
@@ -313,0 +351,6 @@
+ if snapshot {
+ captured.insert(key.clone());
+ sessions.remove(&key);
+ by_id.remove(&id);
+ client.close_session(&id);
+ }
@@ -508,0 +552,8 @@
+ /// Exact Wayland app-id filter, used by taskbar launches.
+ pub app_id_filter: Option<String>,
+ /// Initial cycle direction. `None` leaves the first item selected.
+ pub initial_cycle: Option<bool>,
+ /// Capture each window once instead of continuously refreshing previews.
+ pub snapshot: bool,
+ /// Receives next/previous commands from repeated compositor keybind launches.
+ pub cycle_socket: Option<std::os::unix::net::UnixDatagram>,
@@ -533,0 +585,5 @@
+ app_id_filter: Option<String>,
+ initial_forward: bool,
+ overview_scale: f32,
+ cycle_socket: Option<std::os::unix::net::UnixDatagram>,
+ queued_cycles: isize,
@@ -567 +623 @@
- pending_initial_select: false,
+ pending_initial_select: opts.initial_cycle.is_some(),
@@ -571,0 +628,5 @@
+ app_id_filter: opts.app_id_filter,
+ initial_forward: opts.initial_cycle.unwrap_or(true),
+ overview_scale: load_overview_scale(),
+ cycle_socket: opts.cycle_socket,
+ queued_cycles: 0,
@@ -604 +665,4 @@
- return; // nothing to cycle yet; keep the pending initial jump
+ self.queued_cycles = self
+ .queued_cycles
+ .saturating_add(if forward { 1 } else { -1 });
+ return;
@@ -639,0 +704,12 @@
+ loop {
+ let command = self.cycle_socket.as_ref().and_then(|socket| {
+ let mut buf = [0_u8; 8];
+ socket.recv(&mut buf).ok().map(|len| (buf, len))
+ });
+ match command {
+ Some((buf, len)) if &buf[..len] == b"next" => self.cycle(true),
+ Some((buf, len)) if &buf[..len] == b"prev" => self.cycle(false),
+ Some(_) => {}
+ None => break,
+ }
+ }
@@ -698,0 +775,5 @@
+ .filter(|s| {
+ self.app_id_filter
+ .as_ref()
+ .is_none_or(|app_id| s.app_id.eq_ignore_ascii_case(app_id))
+ })
@@ -713,2 +793,0 @@
- // Exposé covers the whole screen: dim almost to opaque so the real windows
- // behind are hidden (a client can't move them; this hides them instead).
@@ -716 +795 @@
- c[3] = c[3].max(0.96);
+ c[3] = 0.5;
@@ -734 +813,5 @@
- self.selected = if n > 1 { 1 } else { 0 };
+ self.selected = if n > 1 {
+ if self.initial_forward { 1 } else { n - 1 }
+ } else {
+ 0
+ };
@@ -737,0 +821,8 @@
+ if self.queued_cycles != 0 {
+ let n = self.visible().len();
+ if n > 0 {
+ self.selected = (self.selected as isize + self.queued_cycles)
+ .rem_euclid(n as isize) as usize;
+ self.queued_cycles = 0;
+ }
+ }
@@ -745 +836 @@
- let (esc, next, prev, enter) = ctx.input(|i| {
+ let (esc, next, prev, enter, zoom_in, zoom_out, wheel_zoom) = ctx.input(|i| {
@@ -746,0 +838,8 @@
+ let wheel_zoom = i
+ .events
+ .iter()
+ .filter_map(|event| match event {
+ egui::Event::MouseWheel { delta, .. } => Some(delta.y),
+ _ => None,
+ })
+ .sum::<f32>();
@@ -755,0 +855,3 @@
+ i.key_pressed(egui::Key::Plus) || i.key_pressed(egui::Key::Equals),
+ i.key_pressed(egui::Key::Minus),
+ wheel_zoom,
@@ -771,0 +874,12 @@
+ if self.view == View::Grid && (zoom_in || zoom_out || wheel_zoom != 0.0) {
+ let delta = if zoom_in {
+ 0.05
+ } else if zoom_out {
+ -0.05
+ } else {
+ wheel_zoom.signum() * 0.05
+ };
+ self.overview_scale =
+ (self.overview_scale + delta).clamp(MIN_OVERVIEW_SCALE, MAX_OVERVIEW_SCALE);
+ save_overview_scale(self.overview_scale);
+ }
@@ -1020 +1134,5 @@
- let area = ctx.content_rect().shrink(24.0);
+ let full_area = ctx.content_rect().shrink(24.0);
+ let area = egui::Rect::from_center_size(
+ full_area.center(),
+ full_area.size() * self.overview_scale,
+ );
@@ -1048,0 +1167 @@
+ let selected = *i == self.selected;
@@ -1062,9 +1181,3 @@
- rect.size() * (0.86 + 0.14 * ease),
- );
- self.paint_expose_tile(
- ui,
- s,
- scaled,
- *i == self.selected,
- resp.hovered(),
- ease,
+ rect.size()
+ * (0.86 + 0.14 * ease)
+ * if selected { 1.04 } else { 1.0 },
@@ -1071,0 +1185 @@
+ self.paint_expose_tile(ui, s, scaled, selected, resp.hovered(), ease);
@@ -1077,0 +1192,8 @@
+ ui.painter().text(
+ egui::pos2(full_area.right(), full_area.top()),
+ egui::Align2::RIGHT_TOP,
+ format!("− {:.0}% +", self.overview_scale * 100.0),
+ egui::FontId::proportional(14.0),
+ self.theme.text_dim,
+ );
+
@@ -1107 +1229,14 @@
- let white = egui::Color32::WHITE.gamma_multiply(a);
+ let accent = if s.is_window {
+ t.window_accent
+ } else {
+ t.screen_accent
+ };
+ let content_alpha = if selected || hovered { 1.0 } else { 0.55 };
+ let white = egui::Color32::WHITE.gamma_multiply(a * content_alpha);
+ if selected {
+ p.rect_filled(
+ rect.expand(8.0),
+ radius + 8.0,
+ fade(accent).gamma_multiply(0.35),
+ );
+ }
@@ -1127,0 +1263,7 @@
+ if !selected && !hovered {
+ p.rect_filled(
+ rect,
+ radius,
+ egui::Color32::from_black_alpha(72).gamma_multiply(a),
+ );
+ }
@@ -1136 +1278,5 @@
- egui::Color32::from_black_alpha(160).gamma_multiply(a),
+ if selected {
+ fade(accent).gamma_multiply(0.9)
+ } else {
+ egui::Color32::from_black_alpha(160).gamma_multiply(a)
+ },
@@ -1175,9 +1321,22 @@
- let accent = if s.is_window {
- t.window_accent
- } else {
- t.screen_accent
- };
- let (sw, col) = if selected {
- (3.0, accent)
- } else if hovered {
- (2.0, accent)
+ if selected {
+ p.rect_stroke(
+ rect.expand(4.0),
+ radius + 4.0,
+ egui::Stroke::new(3.0, fade(egui::Color32::WHITE)),
+ egui::StrokeKind::Inside,
+ );
+ p.rect_stroke(
+ rect,
+ radius,
+ egui::Stroke::new(6.0, fade(accent)),
+ egui::StrokeKind::Inside,
+ );
+ let marker = egui::pos2(rect.right() - 18.0, rect.top() + 18.0);
+ p.circle_filled(marker, 13.0, fade(accent));
+ p.text(
+ marker,
+ egui::Align2::CENTER_CENTER,
+ "✓",
+ egui::FontId::proportional(18.0),
+ fade(egui::Color32::WHITE),
+ );
@@ -1185,8 +1344,7 @@
- (1.0, t.thumb)
- };
- p.rect_stroke(
- rect,
- radius,
- egui::Stroke::new(sw, fade(col)),
- egui::StrokeKind::Inside,
- );
+ p.rect_stroke(
+ rect,
+ radius,
+ egui::Stroke::new(if hovered { 2.0 } else { 1.0 }, fade(accent)),
+ egui::StrokeKind::Inside,
+ );
+ }
+5
View File
@@ -30,6 +30,7 @@ required on every supported host.
| `interface.linux-desktop` | NixOS with Home Manager |
| `interface.labwc` | NixOS with Home Manager |
| `interface.niri` | NixOS with Home Manager |
| `interface.wallpaperengine` | NixOS with Home Manager |
| `platform.nixos` | NixOS |
| `platform.desktop` | Physical NixOS desktop |
| `platform.intel-nvidia-desktop` | Intel/NVIDIA physical NixOS desktop |
@@ -58,6 +59,10 @@ selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload.
`interface.wallpaperengine` is an opt-in Linux desktop appearance profile. It
enables Wallpaper Engine and disables Noctalia's wallpaper surface, so hosts
without this profile retain Noctalia's configured wallpaper.
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
enables performance improvements, synced lyrics, tracker blocking, the album
color theme, and custom output-device selection while preserving user-owned
@@ -4,8 +4,6 @@
pkgs.playerctl
];
programs.noctalia.settings.wallpaper.enabled = false;
xdg.userDirs = {
enable = true;
createDirectories = true;
@@ -11,9 +11,8 @@
"applications.ghostty"
"applications.gtk"
"applications.loupe"
"applications.linux-wallpaperengine"
"applications.nautilus"
"applications.normcap"
"applications.nani"
"applications.papers"
"applications.qalculate-gtk"
"applications.resources"
@@ -0,0 +1,3 @@
{
programs.noctalia.settings.wallpaper.enabled = false;
}
@@ -0,0 +1,7 @@
{
description = "Wallpaper Engine backgrounds for Linux desktop sessions";
includes = [
"applications.linux-wallpaperengine"
];
}
@@ -3,7 +3,10 @@
home.packages = with pkgs; [
bind
bun
nil
mcp-nixos
nix-fast-build
nix-tree
nixd
python312
uv
];
+23
View File
@@ -0,0 +1,23 @@
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"nixos": {
"type": "local",
"command": ["mcp-nixos"],
"enabled": true,
"timeout": 30000
},
"github": {
"type": "remote",
"url": "https://api.githubcopilot.com/mcp/",
"enabled": true,
"oauth": false,
"headers": {
"Authorization": "Bearer {env:GITHUB_PERSONAL_ACCESS_TOKEN}",
"X-MCP-Readonly": "true",
"X-MCP-Toolsets": "repos,pull_requests,actions"
},
"timeout": 30000
}
}
}
+526
View File
@@ -0,0 +1,526 @@
#!/usr/bin/env python3
"""Change-aware, non-activating validation for this Nix dotfiles repository."""
from __future__ import annotations
import argparse
from collections import defaultdict, deque
from contextlib import contextmanager
import io
import json
import os
from pathlib import Path, PurePosixPath
import shutil
import subprocess
import sys
import tarfile
import tempfile
import tomllib
from typing import Any, Iterator, Sequence
GLOBAL_FILES = {"flake.nix", "flake.lock", "hosts/default.nix"}
GLOBAL_PREFIXES = ("flake/", "libs/", "overlays/")
FULL_EVAL_PREFIXES = GLOBAL_PREFIXES + ("scripts/", "shells/", "tests/")
FULL_BUILD_PREFIXES = GLOBAL_PREFIXES + ("scripts/", "shells/", "tests/")
DOC_SUFFIXES = (".md", ".png", ".jpg", ".jpeg", ".webp")
class ValidationError(RuntimeError):
pass
def command_text(command: Sequence[str]) -> str:
return " ".join(json.dumps(part) if any(c.isspace() for c in part) else part for part in command)
def run(
command: Sequence[str],
*,
cwd: Path,
capture: bool = False,
check: bool = True,
input_text: str | None = None,
) -> subprocess.CompletedProcess[str]:
print(f"+ {command_text(command)}", file=sys.stderr)
return subprocess.run(
list(command),
cwd=cwd,
check=check,
text=True,
input=input_text,
stdout=subprocess.PIPE if capture else None,
stderr=subprocess.PIPE if capture else None,
)
def git(root: Path, *args: str, check: bool = True) -> str:
return run(["git", *args], cwd=root, capture=True, check=check).stdout
def repo_root() -> Path:
return Path(run(["git", "rev-parse", "--show-toplevel"], cwd=Path.cwd(), capture=True).stdout.strip()).resolve()
def normalize(root: Path, raw: str) -> str:
candidate = Path(raw)
absolute = candidate.resolve() if candidate.is_absolute() else (root / candidate).resolve()
try:
return absolute.relative_to(root).as_posix()
except ValueError as error:
raise ValidationError(f"path escapes repository root: {raw}") from error
def nonempty_lines(value: str) -> list[str]:
return [line for line in value.splitlines() if line]
def tracked_paths(root: Path) -> set[str]:
return set(nonempty_lines(git(root, "ls-files")))
def untracked_paths(root: Path) -> set[str]:
return set(nonempty_lines(git(root, "ls-files", "--others", "--exclude-standard")))
def expand_paths(root: Path, raw_paths: Sequence[str], available: set[str]) -> list[str]:
result: set[str] = set()
for raw in raw_paths:
relative = normalize(root, raw)
target = root / relative
if target.is_dir():
prefix = f"{relative.rstrip('/')}/" if relative else ""
result.update(path for path in available if path.startswith(prefix))
else:
result.add(relative)
return sorted(result)
def collect_paths(root: Path, args: argparse.Namespace) -> tuple[list[str], set[str]]:
tracked = tracked_paths(root)
untracked = untracked_paths(root)
if args.paths:
paths = expand_paths(root, args.paths, tracked | untracked)
elif args.all_files:
paths = sorted(tracked)
elif args.base:
paths = nonempty_lines(
git(root, "diff", "--name-only", "--no-renames", "--diff-filter=ACMRTUXBD", f"{args.base}...HEAD", "--")
)
else:
paths = nonempty_lines(git(root, "diff", "--name-only", "--no-renames", "--diff-filter=ACMRTUXBD", "HEAD", "--"))
paths += sorted(untracked)
return sorted(set(paths)), untracked
def remove_path(path: Path) -> None:
if path.is_symlink() or path.is_file():
path.unlink()
elif path.is_dir():
shutil.rmtree(path)
@contextmanager
def flake_reference(root: Path, changed: Sequence[str]) -> Iterator[str]:
"""Create a clean HEAD snapshot and overlay only task-owned worktree paths."""
with tempfile.TemporaryDirectory(prefix="dotfiles-flake-") as temporary:
source = Path(temporary) / "source"
source.mkdir()
archive = subprocess.run(
["git", "archive", "--format=tar", "HEAD"],
cwd=root,
check=True,
stdout=subprocess.PIPE,
).stdout
with tarfile.open(fileobj=io.BytesIO(archive), mode="r:") as tar:
tar.extractall(source, filter="data")
for relative in changed:
src, dst = root / relative, source / relative
remove_path(dst)
if src.is_symlink():
dst.parent.mkdir(parents=True, exist_ok=True)
dst.symlink_to(os.readlink(src))
elif src.is_file():
dst.parent.mkdir(parents=True, exist_ok=True)
shutil.copy2(src, dst)
yield f"path:{source}"
def load_metadata(root: Path, reference: str) -> dict[str, Any]:
result = run(
["nix", "eval", "--json", "--show-trace", f"{reference}#lib.validationMetadata"],
cwd=root,
capture=True,
)
metadata = json.loads(result.stdout)
if metadata.get("schemaVersion") != 1:
raise ValidationError("unsupported validation metadata schema")
return metadata
def reverse_dependencies(units: dict[str, Any]) -> dict[str, set[str]]:
result: dict[str, set[str]] = defaultdict(set)
for unit_id, unit in units.items():
for dependency in unit.get("includes", []):
result[dependency].add(unit_id)
return result
def users_of(unit_id: str, reverse: dict[str, set[str]]) -> set[str]:
result, queue = {unit_id}, deque([unit_id])
while queue:
for dependent in reverse.get(queue.popleft(), set()):
if dependent not in result:
result.add(dependent)
queue.append(dependent)
return result
def owner_for(path: str, units: dict[str, Any]) -> str | None:
matches = []
for unit_id, unit in units.items():
directory = unit["directory"].rstrip("/")
if path == directory or path.startswith(f"{directory}/"):
matches.append((len(directory), unit_id))
return max(matches)[1] if matches else None
def path_classes(path: str, unit: dict[str, Any]) -> set[str]:
directory = unit["directory"].rstrip("/")
relative = path[len(directory) :].lstrip("/")
if relative == "nixos.nix" or relative == "home/nixos.nix":
return {"nixos"}
if relative == "darwin.nix" or relative == "home/darwin.nix":
return {"darwin"}
if relative == "meta.nix":
return {"nixos", "darwin"}
if relative in {"common.nix", "home.nix", "home/common.nix"}:
return {"nixos", "darwin"}
fragments = set(unit.get("fragments", []))
classes: set[str] = set()
if fragments & {"common", "nixos", "home", "homeCommon", "homeNixos"}:
classes.add("nixos")
if fragments & {"common", "darwin", "home", "homeCommon", "homeDarwin"}:
classes.add("darwin")
return classes or {"nixos", "darwin"}
def is_docs_only(path: str) -> bool:
return path.endswith(DOC_SUFFIXES)
def plan(metadata: dict[str, Any], paths: Sequence[str], *, all_hosts: bool = False) -> dict[str, Any]:
hosts: dict[str, Any] = metadata["hosts"]
units: dict[str, Any] = metadata["units"]
reverse = reverse_dependencies(units)
affected_units: set[str] = set()
unit_classes: dict[str, set[str]] = defaultdict(set)
affected_hosts = {"nixos": set(), "darwin": set()}
global_change = all_hosts
requires_full_eval = False
requires_full_build = False
requires_nix = False
for path in paths:
if path in GLOBAL_FILES or path.startswith(GLOBAL_PREFIXES):
global_change = True
requires_nix = True
if path.startswith(FULL_EVAL_PREFIXES) or path in GLOBAL_FILES:
requires_full_eval = True
if path.startswith(FULL_BUILD_PREFIXES) or path in {"flake.nix", "flake.lock"}:
requires_full_build = True
if path.endswith(".nix") or path == "flake.lock":
requires_nix = True
if path == "scripts/dotfiles-check.py":
requires_nix = requires_full_eval = requires_full_build = True
if path.startswith("hosts/") and path != "hosts/default.nix":
parts = PurePosixPath(path).parts
if len(parts) > 1 and parts[1] in hosts:
affected_hosts[hosts[parts[1]]["kind"]].add(parts[1])
requires_nix = True
owner = owner_for(path, units)
if owner:
classes = path_classes(path, units[owner])
for unit_id in users_of(owner, reverse):
affected_units.add(unit_id)
unit_classes[unit_id].update(classes)
requires_nix = requires_nix or not is_docs_only(path)
elif path.startswith("modules/") and not is_docs_only(path):
global_change = True
requires_nix = True
if global_change:
for name, host in hosts.items():
affected_hosts[host["kind"]].add(name)
else:
for name, host in hosts.items():
selected = set(host["selectedUnits"])
if any(unit_id in selected and host["kind"] in unit_classes[unit_id] for unit_id in affected_units):
affected_hosts[host["kind"]].add(name)
synthetic = {"nixos": set(), "darwin": set()}
for unit_id in affected_units:
for kind in unit_classes[unit_id]:
if not any(unit_id in hosts[name]["selectedUnits"] for name in affected_hosts[kind]):
synthetic[kind].add(unit_id)
systems = sorted({host["system"] for host in hosts.values()})
native_systems = {system: False for system in systems}
if requires_full_build:
native_systems = {system: requires_nix for system in systems}
else:
for kind, names in affected_hosts.items():
for name in names:
native_systems[hosts[name]["system"]] = True
for kind, unit_ids in synthetic.items():
if unit_ids:
candidates = sorted(host["system"] for host in hosts.values() if host["kind"] == kind)
if candidates:
native_systems[candidates[0]] = True
return {
"schemaVersion": 1,
"paths": sorted(paths),
"affectedUnits": sorted(affected_units),
"affectedHosts": {kind: sorted(names) for kind, names in affected_hosts.items()},
"syntheticUnits": {kind: sorted(names) for kind, names in synthetic.items()},
"requiresNixValidation": requires_nix,
"requiresFullEvaluation": requires_full_eval,
"requiresFullNativeBuild": requires_full_build,
"nativeBuildSystems": native_systems,
}
def render_plan(value: dict[str, Any], reference: str) -> None:
print(f"flake: {reference}")
print("paths:", ", ".join(value["paths"]) or "(none)")
print("units:", ", ".join(value["affectedUnits"]) or "(none)")
for kind in ("nixos", "darwin"):
print(f"{kind} hosts:", ", ".join(value["affectedHosts"][kind]) or "(none)")
print(f"{kind} synthetic:", ", ".join(value["syntheticUnits"][kind]) or "(none)")
print("full evaluation:", value["requiresFullEvaluation"])
print("full native build:", value["requiresFullNativeBuild"])
def validate_skill(path: Path) -> None:
text = path.read_text()
if not text.startswith("---\n"):
raise ValidationError(f"missing Skill frontmatter: {path}")
try:
frontmatter = text.split("---\n", 2)[1]
name = next(line.split(":", 1)[1].strip() for line in frontmatter.splitlines() if line.startswith("name:"))
except (IndexError, StopIteration) as error:
raise ValidationError(f"invalid Skill frontmatter: {path}") from error
if name != path.parent.name:
raise ValidationError(f"Skill name {name!r} does not match directory {path.parent.name!r}")
def static_checks(root: Path, paths: Sequence[str], untracked: set[str]) -> None:
for relative in paths:
path = root / relative
if not path.is_file():
continue
if relative.endswith(".nix"):
run(["nix-instantiate", "--parse", str(path)], cwd=root, capture=True)
elif relative.endswith(".json"):
json.loads(path.read_text())
elif relative.endswith(".toml"):
tomllib.loads(path.read_text())
elif relative.endswith(".py"):
compile(path.read_text(), relative, "exec")
if path.name == "SKILL.md":
validate_skill(path)
if relative in untracked:
for number, line in enumerate(path.read_text(errors="replace").splitlines(), 1):
if line.rstrip() != line:
raise ValidationError(f"trailing whitespace: {relative}:{number}")
diff_paths = [path for path in paths if path not in untracked]
if diff_paths:
run(["git", "diff", "--check", "HEAD", "--", *diff_paths], cwd=root)
def run_fast(root: Path, reference: str, paths: Sequence[str], untracked: set[str], *, all_files: bool) -> None:
static_checks(root, paths, untracked)
command = ["nix", "develop", f"{reference}#validation", "--command", "pre-commit", "run"]
command += ["--all-files"] if all_files else (["--files", *paths] if paths else [])
if paths or all_files:
run(command, cwd=root)
def selection_module_expr(unit_id: str) -> str:
quoted = json.dumps(unit_id)
return f"(flake.lib.registry.mkSelectionModule [ {quoted} ])"
def synthetic_expr(reference: str, host_name: str, host: dict[str, Any], unit_id: str, *, drv_path: bool) -> str:
selection = selection_module_expr(unit_id)
modules = [selection]
if host.get("homeManager", True):
user = json.dumps(host["user"])
modules.append(f"{{ home-manager.users.{user}.imports = [ {selection} ]; }}")
base = f"flake.{('darwinConfigurations' if host['kind'] == 'darwin' else 'nixosConfigurations')}.{json.dumps(host_name)}"
output = "extended.system" if host["kind"] == "darwin" else "extended.config.system.build.toplevel"
if drv_path:
output += ".drvPath"
return f'''let
flake = builtins.getFlake {json.dumps(reference)};
base = {base};
extended = base.extendModules {{ modules = [ {' '.join(modules)} ]; }};
in {output}'''
def representative_host(metadata: dict[str, Any], kind: str, current_system: str | None = None) -> tuple[str, dict[str, Any]] | None:
candidates = [(name, host) for name, host in metadata["hosts"].items() if host["kind"] == kind]
if current_system:
candidates = [item for item in candidates if item[1]["system"] == current_system]
return sorted(candidates)[0] if candidates else None
def host_drv_attr(reference: str, host: dict[str, Any]) -> str:
return f"{reference}#{host['buildAttr']}.drvPath"
def run_eval(
root: Path,
reference: str,
metadata: dict[str, Any],
value: dict[str, Any],
*,
all_systems: bool,
) -> None:
if all_systems or value["requiresFullEvaluation"]:
run(["nix", "flake", "check", reference, "--no-build", "--all-systems", "--keep-going", "--show-trace"], cwd=root)
return
for kind in ("nixos", "darwin"):
for name in value["affectedHosts"][kind]:
run(["nix", "eval", "--raw", "--show-trace", host_drv_attr(reference, metadata["hosts"][name])], cwd=root)
representative = representative_host(metadata, kind)
if representative:
name, host = representative
for unit_id in value["syntheticUnits"][kind]:
run(["nix", "eval", "--raw", "--impure", "--show-trace", "--expr", synthetic_expr(reference, name, host, unit_id, drv_path=True)], cwd=root)
def current_system(root: Path) -> str:
return run(["nix", "eval", "--raw", "--impure", "--expr", "builtins.currentSystem"], cwd=root, capture=True).stdout.strip()
def run_full_native(root: Path, reference: str, system: str) -> None:
run(
["nix", "run", f"{reference}#nix-fast-build", "--", "--flake", f"{reference}#checks.{system}", "--skip-cached", "--no-nom", "--no-link"],
cwd=root,
)
def run_build(root: Path, reference: str, metadata: dict[str, Any], value: dict[str, Any]) -> None:
system = current_system(root)
if value["requiresFullNativeBuild"]:
run_full_native(root, reference, system)
return
installables: list[str] = []
for kind in ("nixos", "darwin"):
for name in value["affectedHosts"][kind]:
host = metadata["hosts"][name]
if host["system"] == system:
installables.append(f"{reference}#{host['buildAttr']}")
else:
print(f"skip incompatible build: {name} ({host['system']})", file=sys.stderr)
for check in ("registry", "validation-tool"):
installables.append(f"{reference}#checks.{system}.{check}")
if installables:
run(["nix", "build", "--no-link", "--keep-going", "--print-build-logs", *sorted(set(installables))], cwd=root)
for kind in ("nixos", "darwin"):
representative = representative_host(metadata, kind, system)
if representative:
name, host = representative
for unit_id in value["syntheticUnits"][kind]:
run(["nix", "build", "--no-link", "--impure", "--expr", synthetic_expr(reference, name, host, unit_id, drv_path=False)], cwd=root)
def self_test() -> None:
metadata = {
"schemaVersion": 1,
"units": {
"applications.foo": {"directory": "modules/applications/foo", "includes": [], "fragments": ["home", "homeNixos"]},
"applications.dormant": {"directory": "modules/applications/dormant", "includes": [], "fragments": ["home"]},
"profiles.workload.dev": {"directory": "modules/profiles/workload/dev", "includes": ["applications.foo"], "fragments": ["meta"]},
},
"hosts": {
"linux": {"kind": "nixos", "system": "x86_64-linux", "user": "test", "homeManager": True, "selectedUnits": ["profiles.workload.dev"], "buildAttr": "nixosConfigurations.linux.config.system.build.toplevel"},
"mac": {"kind": "darwin", "system": "aarch64-darwin", "user": "test", "homeManager": True, "selectedUnits": ["profiles.workload.dev"], "buildAttr": "darwinConfigurations.mac.system"},
},
}
nixos = plan(metadata, ["modules/applications/foo/home/nixos.nix"])
assert nixos["affectedHosts"] == {"nixos": ["linux"], "darwin": []}
assert nixos["affectedUnits"] == ["applications.foo", "profiles.workload.dev"]
common = plan(metadata, ["modules/applications/foo/home.nix"])
assert common["affectedHosts"] == {"nixos": ["linux"], "darwin": ["mac"]}
dormant = plan(metadata, ["modules/applications/dormant/home.nix"])
assert dormant["syntheticUnits"] == {"nixos": ["applications.dormant"], "darwin": ["applications.dormant"]}
global_value = plan(metadata, ["flake.nix"])
assert global_value["requiresFullEvaluation"] and global_value["requiresFullNativeBuild"]
docs = plan(metadata, ["modules/profiles/README.md"])
assert not docs["requiresNixValidation"]
print("dotfiles-check self-test passed")
def parser() -> argparse.ArgumentParser:
result = argparse.ArgumentParser(description=__doc__)
result.add_argument("command", choices=("plan", "fast", "eval", "build", "all", "full", "self-test"))
result.add_argument("--paths", nargs="+", help="Explicit task-owned repository paths")
result.add_argument("--base", help="Compare BASE...HEAD")
result.add_argument("--all-files", action="store_true", help="Check every tracked file")
result.add_argument("--all-hosts", action="store_true", help="Validate every registered host")
result.add_argument("--all-systems", action="store_true", help="Evaluate every flake system")
result.add_argument("--json", action="store_true", help="Emit the plan as JSON")
return result
def main() -> int:
args = parser().parse_args()
if args.command == "self-test":
self_test()
return 0
selectors = sum(bool(value) for value in (args.paths, args.base, args.all_files))
if selectors > 1:
raise ValidationError("use only one of --paths, --base, or --all-files")
if args.command == "full":
if selectors or args.all_hosts or args.all_systems:
raise ValidationError("full is exhaustive and accepts no scope flags")
args.all_files = args.all_hosts = args.all_systems = True
root = repo_root()
paths, untracked = collect_paths(root, args)
with flake_reference(root, paths) as reference:
metadata = load_metadata(root, reference)
value = plan(metadata, paths, all_hosts=args.all_hosts)
if args.command == "plan":
print(json.dumps(value, ensure_ascii=False, indent=2, sort_keys=True)) if args.json else render_plan(value, reference)
return 0
if args.command in {"fast", "all", "full"}:
run_fast(root, reference, paths, untracked, all_files=args.all_files)
if args.command in {"eval", "all", "full"} and value["requiresNixValidation"]:
run_eval(root, reference, metadata, value, all_systems=args.all_systems or args.command in {"all", "full"})
if args.command in {"build", "all"} and value["requiresNixValidation"]:
run_build(root, reference, metadata, value)
if args.command == "full":
run_full_native(root, reference, current_system(root))
return 0
if __name__ == "__main__":
try:
raise SystemExit(main())
except ValidationError as error:
print(f"error: {error}", file=sys.stderr)
raise SystemExit(2) from error
except subprocess.CalledProcessError as error:
if error.stdout:
print(error.stdout, file=sys.stderr, end="")
if error.stderr:
print(error.stderr, file=sys.stderr, end="")
raise SystemExit(error.returncode) from error
+9
View File
@@ -3,15 +3,22 @@ _: {
{
pkgs,
config,
lib,
...
}:
{
devShells.dotnix = pkgs.mkShell {
packages = [
config.treefmt.build.wrapper
config.packages.dotfiles-check
pkgs.actionlint
pkgs.git
pkgs.gitleaks
pkgs.mcp-nixos
pkgs.nix-fast-build
pkgs.nix-tree
pkgs.nixd
pkgs.pre-commit
# sops-nix / age
@@ -22,6 +29,8 @@ _: {
# YubiKey for sops editing
pkgs.age-plugin-yubikey
pkgs.yubikey-manager
]
++ lib.optionals (lib.meta.availableOn pkgs.stdenv.hostPlatform pkgs.pcsc-tools) [
pkgs.pcsc-tools
];
+21 -14
View File
@@ -95,26 +95,33 @@ points cannot express the requirement.
### 4. Prove the change
Run the validation matrix in
[references/review-checklist.md](references/review-checklist.md). At minimum:
Invoke the `validate-nix-change` skill and use the task-owned files as its
explicit path set. At minimum:
1. Format the task-owned files with the repository formatter and run
`git diff --check`.
2. Inspect the complete task diff for accidental files, duplication, leaked
1. Inspect `nix run .#check -- plan --paths <task-path>... --json` and confirm
the reported units, host classes, and real hosts are correct.
2. Run `nix run .#check -- fast --paths <task-path>...` during the edit loop.
3. Inspect the complete task diff for accidental files, duplication, leaked
secrets, forced values, direct enable assignments, and unrelated rewrites.
3. Run `nix flake check`.
4. Run `pre-commit run --all-files`.
5. Evaluate every affected real host without switching it. For a
cross-platform unit or profile, evaluate both NixOS and nix-darwin even if
only one class changed. Build an affected configuration with `--no-link`
when the current platform can build it.
6. Verify selection as well as syntax: confirm that the expected package,
4. Run `nix run .#check -- all --paths <task-path>...` after the structure is
complete. This evaluates every flake system and builds affected targets for
the current platform without activation.
5. Verify selection as well as syntax: confirm that the expected package,
program, service, group, cask, or external module appears in the resulting
configuration.
6. Add a `pkgs.testers.runNixOSTest` check through the `test-nixos-service`
skill when service startup or another runtime contract cannot be proved by
evaluation and a system build.
Use `nix run .#check -- full` only for CI, scheduled maintenance, or an explicit
repository-wide audit. These commands never activate the live system. Do not
run `nh os switch`, `nixos-rebuild switch`, `darwin-rebuild switch`,
`home-manager switch`, or an equivalent activation command as validation.
If a command is unavailable, blocked by the environment, or fails for a
pre-existing reason, diagnose it and report the exact gap. Never silently skip
a required check or weaken the implementation to make a check pass.
pre-existing reason, invoke the `debug-nix-failure` skill, diagnose it, and
report the exact gap. Never silently skip a required check or weaken the
implementation to make a check pass.
### 5. Audit before completion
@@ -72,56 +72,47 @@ user-owned mutable state unless the requested policy explicitly owns it.
## Validation matrix
Run checks from the repository root and keep the exact results for the handoff.
Do not switch or activate a live system merely to validate a change.
Use the `validate-nix-change` skill and run checks from the repository root.
Keep exact results for the handoff. The validation app never switches or
activates a live system.
### Always
1. Format task-owned files. If the worktree contains unrelated user changes,
pass only task-owned paths to the configured formatter when supported.
2. Run `git diff --check`.
3. Review `git status --short`, `git diff --stat`, and the complete `git diff`.
4. Run `nix flake check`.
5. Run `pre-commit run --all-files`.
1. Run `nix run .#check -- plan --paths <task-path>... --json` and inspect the
affected units and hosts.
2. Run `nix run .#check -- fast --paths <task-path>...` during implementation.
3. Review `git status --short`, `git diff --stat`, and the complete task diff.
4. Run `nix run .#check -- all --paths <task-path>...` before handoff. It runs
all-system evaluation and compatible targeted builds without activation.
5. Reserve `nix run .#check -- full` for CI, scheduled maintenance, or an
explicit repository-wide audit.
Do not run `nh os switch`, `nixos-rebuild switch`, `darwin-rebuild switch`,
`home-manager switch`, or an equivalent activation command.
### NixOS or Home Manager on NixOS
- Evaluate each affected host's system toplevel derivation.
- Build at least one affected NixOS configuration with `--no-link` when the
current system supports it.
- Confirm that the validation plan includes each affected real NixOS host.
- Build affected NixOS configurations with `--no-link` through the validation
app when the current system supports them.
- Inspect the resulting option that proves selection: for example
`environment.systemPackages`, the user's `home.packages`,
`systemd.services`, `users.users.<name>.extraGroups`, or the upstream
`programs`/`services` option.
Typical build shape:
```sh
nix build .#nixosConfigurations.<host>.config.system.build.toplevel --no-link
```
### nix-darwin or Home Manager on Darwin
- Evaluate every affected Darwin host even when running on Linux.
- Confirm that every affected Darwin host is evaluated even when running on
Linux.
- Inspect `homebrew.casks` or `homebrew.brews` for Homebrew-backed additions.
- Evaluate the relevant Home Manager program or package option.
- Build a Darwin configuration only on a compatible Darwin builder; otherwise
report that build as an explicit runtime-validation gap.
Typical evaluation shapes:
```sh
nix eval --raw .#darwinConfigurations.<host>.system.drvPath
nix eval --json .#darwinConfigurations.<host>.config.homebrew.casks
```
Confirm the exact output attribute against the current flake before using a
command; do not paste these shapes blindly.
- Build a Darwin configuration only on a compatible Darwin runner or builder;
otherwise report the build as an explicit platform gap.
### Profiles and cross-platform changes
- Determine transitive selection through `meta.includes`, not only direct
mentions.
- Confirm transitive selection through `meta.includes`, not only direct
mentions. The validation plan computes reverse dependency closure.
- Evaluate every real host selecting the changed profile.
- Evaluate both host classes for a cross-platform profile, even if only one
current fragment changed.
@@ -134,6 +125,8 @@ command; do not paste these shapes blindly.
### Runtime-dependent behavior
Evaluation and builds cannot prove GUI appearance, credentials, network access,
hardware behavior, or successful daemon interaction. State the precise manual
post-activation check needed for those behaviors. Never describe evaluation as
hardware behavior, successful daemon interaction, or reboot state. For
reusable NixOS behavior, use the `test-nixos-service` skill and add a
`pkgs.testers.runNixOSTest` check. State the precise manual post-activation check
needed for physical hardware or external systems. Never describe evaluation as
a runtime test.
+63
View File
@@ -0,0 +1,63 @@
---
name: debug-nix-failure
description: Diagnose failures from parsing, Nix module evaluation, derivation builds, flake checks, NixOS tests, or Home Manager activation logs without changing the live system. Use when `nix run .#check`, `nix flake check`, `nix build`, CI, or a user-provided activation log fails.
---
# Debug a Nix Failure
Classify the failure before changing code. Preserve the original command,
complete error, first causal frame, and affected attribute. Never run a live
switch or activation to reproduce a validation failure.
## Identify the failing layer
- **Parse or format:** syntax location, malformed string, unmatched delimiter,
or formatter-owned rewrite.
- **Static analysis:** dead binding, suspicious expression, ShellCheck finding,
secret scan, or workflow lint.
- **Module evaluation:** missing option, wrong type, assertion, infinite
recursion, conflicting definitions, Registry selection, or unsupported host
class.
- **Derivation instantiation/build:** missing dependency, hash mismatch, patch
failure, compiler/test failure, sandbox violation, or unsupported platform.
- **NixOS test:** failed unit, timeout, command assertion, network readiness, or
reboot state.
- **Activation/runtime:** filesystem conflict, activation script, systemd unit,
hardware, credential, or external-service behavior. Diagnose only from logs
supplied by the user unless they explicitly request a non-switch inspection
command.
## Reproduce the narrowest failing operation
Start with the stage and paths reported by the validation app:
```sh
nix run .#check -- plan --paths <task-path>... --json
nix run .#check -- fast --paths <task-path>...
nix run .#check -- eval --paths <task-path>...
nix run .#check -- build --paths <task-path>...
```
For a single attribute, use `nix eval --show-trace` on its `drvPath` before a
build. For a failed derivation, retain `--print-build-logs` and inspect
`nix log <drv-path>` when the summary omits the causal lines.
## Read traces selectively
1. Find the first repository-owned frame or option path.
2. Separate the immediate failure from wrapper frames in `modules.nix`,
`lib.evalModules`, or flake-parts.
3. Inspect the option declaration and every definition contributing to it.
4. Confirm package and option names against locked inputs, not memory.
5. Check whether the failure reproduces on the base revision before calling it
task-owned.
Do not respond to a type or ownership error with import-order changes,
`lib.mkForce`, global arguments, or an overlay unless repository evidence shows
that those mechanisms are the correct owner.
## Finish with a bounded diagnosis
Report the failing layer, root cause, minimal correction, rerun command, and any
remaining platform or runtime gap. Include enough of the error to identify it,
but do not paste large unrelated logs.
+64
View File
@@ -0,0 +1,64 @@
---
name: test-nixos-service
description: Add or extend a non-activating NixOS VM or container test for service startup, sockets, timers, permissions, firewall behavior, reboot state, and inter-service dependencies. Use when evaluation and a system build cannot prove the requested runtime behavior.
---
# Test NixOS Runtime Behavior
Prefer `pkgs.testers.runNixOSTest` for reusable NixOS behavior that can be
proved without the user's physical machine. Do not activate the host
configuration and do not substitute a live `nh os switch` for a deterministic
test.
## Define the observable contract
List the runtime facts that must hold, such as:
- a systemd unit reaches `active`;
- a socket or port is listening;
- a timer triggers its service;
- a user can or cannot read a file;
- a group membership grants access;
- a firewall permits one path and blocks another;
- state survives a reboot;
- one service waits for another dependency.
Exclude behavior that requires physical GPU, fingerprint, audio, display,
Secure Boot, TPM, private credentials, or an external provider unless the test
can model it explicitly.
## Implement the smallest useful machine
Create a test under `tests/` and expose it through `checks.<system>`. Import the
owning module or Registry selection instead of copying its implementation into
the test. Use only the packages, users, files, and network peers required by the
contract.
Typical shape:
```nix
pkgs.testers.runNixOSTest {
name = "service-name";
nodes.machine = {
# Enable the owning unit or import the module under test.
};
testScript = ''
machine.start()
machine.wait_for_unit("service-name.service")
machine.succeed("systemctl is-active service-name.service")
'';
}
```
Use `wait_for_unit`, `wait_for_open_port`, `succeed`, `fail`, and explicit
reboots to express outcomes. Avoid arbitrary sleeps when a readiness condition
exists.
## Validate and report
Run the targeted test through its flake check, then run the repository
validation app for the task paths. Report the test attribute and assertions
that passed. State clearly which hardware or external behavior remains outside
the VM/container model.
+58
View File
@@ -0,0 +1,58 @@
---
name: update-flake-input
description: Update one or more pinned flake inputs with bounded lock-file changes and non-activating Linux and Darwin validation. Use for dependency refreshes, input-specific updates, automated lock-file pull requests, or diagnosing a regression introduced by flake.lock.
---
# Update a Flake Input
Keep the update scope explicit and treat `flake.lock` as generated dependency
state. Never activate a host as part of this workflow; do not run `nh os switch`,
`nixos-rebuild switch`, `darwin-rebuild switch`, `home-manager switch`, or an
equivalent command.
## Bound the update
1. Read `AGENTS.md`, inspect `git status --short`, and preserve unrelated work.
2. Record the input names and the behavior or version change being requested.
3. Prefer an input-specific update:
```sh
nix flake update <input-name>
```
Use an unrestricted `nix flake update` only when the task explicitly requests a
full refresh. Do not hand-edit lock nodes.
## Audit the lock diff
Inspect the complete `flake.lock` diff. Confirm that changed nodes are the
requested inputs or unavoidable followers and that source owners, repositories,
reference types, and hashes remain expected. Investigate unexpected node
replacement, disappearing followers, or a large transitive graph rewrite before
validation.
## Validate without activation
Run the common validation workflow against the lock file:
```sh
nix run .#check -- plan --paths flake.lock --json
nix run .#check -- fast --paths flake.lock
nix run .#check -- eval --paths flake.lock
nix run .#check -- build --paths flake.lock
```
A lock-file change requires full evaluation and the complete native check set.
Linux and Darwin builds must run on compatible runners. The scheduled update
workflow uploads the candidate lock file, builds Linux and Darwin checks, and
creates a pull request only after both pass.
When a failure appears only after the update, invoke `debug-nix-failure`, compare
the failing derivation or option with the base lock, and narrow the responsible
input before adding an override or patch.
## Report the result
List requested and transitively changed inputs, validation commands and native
platform results, any package or option migration, and remaining manual runtime
checks. Evaluation or a native build is not activation.
+128
View File
@@ -0,0 +1,128 @@
---
name: validate-nix-change
description: Plan and run efficient, non-activating validation for edits to this NixOS, nix-darwin, and Home Manager flake. Use after changing Nix modules, hosts, profiles, overlays, flake outputs, tests, scripts, CI, or agent configuration; before handing off a task; or when deciding which real hosts must be evaluated or built.
---
# Validate a Nix Change
Use the repository validation app as the source of truth for change impact and
validation commands. It derives affected hosts from Registry ownership,
`meta.includes`, host selections, fragment class, and host-local paths.
Never activate a live configuration as part of this workflow. Do not run
`nh os switch`, `nixos-rebuild switch`, `darwin-rebuild switch`,
`home-manager switch`, or an equivalent activation command. The user owns live
activation separately.
## Establish the validation scope
1. Read `AGENTS.md` and run `git status --short` before editing.
2. Preserve unrelated user changes. Track the paths owned by the current task,
including newly created untracked files.
3. Inspect the plan before expensive checks:
```sh
nix run .#check -- plan --paths <task-path>... --json
```
When validating a committed pull-request range, use:
```sh
nix run .#check -- plan --base <base-sha> --json
```
The app automatically uses a `path:` flake reference when task paths are
untracked, so newly created Registry fragments are visible to Nix without
staging them.
## Run checks in increasing cost order
### Fast edit loop
After each coherent edit, parse Nix files, validate project JSON, TOML, and
skill frontmatter, check whitespace, and run the configured hooks only for
task-owned files:
```sh
nix run .#check -- fast --paths <task-path>...
```
Do not replace this with `pre-commit run --all-files` during the edit loop.
Unrelated repository files must not become part of the task merely because an
existing check fails elsewhere.
### Evaluation
After the implementation is structurally complete, evaluate every affected
NixOS and Darwin derivation plus the supporting checks without realizing or
activating them. Flake-wide paths additionally evaluate every flake system:
```sh
nix run .#check -- eval --paths <task-path>...
```
This proves module evaluation, option types, assertions, Registry selection,
and derivation instantiation. It does not prove a successful build or runtime
behavior.
### Compatible builds
Build affected configurations for the current platform with no result link:
```sh
nix run .#check -- build --paths <task-path>...
```
The app reports incompatible targets as evaluated but skipped for native build.
A Darwin target must be built by a compatible Darwin runner or builder; a Linux
evaluation is not a Darwin build.
### Final task validation
Before handoff, run the cumulative task check. It applies file checks only to
task-owned paths, evaluates every flake system, and builds affected native
targets:
```sh
nix run .#check -- all --paths <task-path>...
```
Use `--all-hosts` only when a deliberate audit must report every registered
host as affected. Use the exhaustive command for CI, scheduled maintenance, or
an explicit repository-wide audit:
```sh
nix run .#check -- full
```
`full` runs hooks over every tracked file and builds every check for the current
platform through `nix-fast-build`.
## Add runtime tests when needed
Evaluation and builds do not prove service startup, socket behavior, firewall
rules, users and groups, permissions, reboot behavior, or network interaction.
For reusable NixOS behavior, invoke the `test-nixos-service` skill and add a
`pkgs.testers.runNixOSTest` check. Hardware, credentials, GUI appearance, and
external services may still require a precisely described manual check after
the user activates the configuration.
## Diagnose failures by layer
Invoke the `debug-nix-failure` skill when a stage fails. Fix the first failing
layer before running a more expensive one. Do not hide a pre-existing failure,
weaken an assertion, add `lib.mkForce`, or skip a required host merely to make
the task appear green.
## Report evidence precisely
Conclude with:
- task-owned paths;
- affected units and hosts reported by `plan`;
- each command run and its result;
- which targets were parsed, evaluated, built, or runtime-tested;
- any compatible-platform or manual-runtime gap.
Never describe evaluation as a build, a build as activation, or a VM test as
proof of hardware-specific behavior.