Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
49 lines
3.4 KiB
Markdown
49 lines
3.4 KiB
Markdown
# ThinkPad T400 — install notes
|
|
|
|
Flake host: `lyrathorpe-t400`. Files: `configuration.nix`, the `boot-*.nix`
|
|
variants, and `hardware-configuration.nix`.
|
|
|
|
## Hardware configuration
|
|
|
|
`hardware-configuration.nix` here is a hand-written **placeholder**. On the real
|
|
machine, run `nixos-generate-config`, replace the file, and commit it. It assumes
|
|
by-label partitions — root `nixos` (ext4) and `swap` — so either label them at
|
|
install time or swap in the generated UUIDs.
|
|
|
|
## Bootloader — import the module matching the flashed firmware
|
|
|
|
`configuration.nix` imports exactly one boot module. Default is `boot-bios.nix`;
|
|
switch by commenting it out and uncommenting the relevant alternative.
|
|
|
|
| Firmware | Module | Notes |
|
|
| ---------------------------------------------------- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
|
| Stock Lenovo BIOS, or coreboot + **SeaBIOS** payload | `boot-bios.nix` | GRUB on the MBR. Set `device` to the real install disk (`/dev/sda` by default). MBR/legacy layout. |
|
|
| coreboot + **GRUB** payload | `boot-coreboot-grub.nix` | GRUB is config-only (`device = "nodev"`); NixOS does **not** write to a disk. Your coreboot `grub.cfg` (in the flash chip) must `search` for and `configfile` the on-disk `/boot/grub/grub.cfg`, or chainload the disk's GRUB. |
|
|
| coreboot + **Tianocore/edk2 (UEFI)** payload | `boot-coreboot-uefi.nix` | systemd-boot. `canTouchEfiVariables = true` (coreboot honours NVRAM writes). The module **declares its own ESP** (`/boot` vfat, label `ESP`) — when you regenerate `hardware-configuration.nix`, do **not** let it also define `/boot`. Create + label an `ESP` vfat partition (GPT). |
|
|
|
|
## Graphics
|
|
|
|
This unit has the optional **discrete ATI Mobility Radeon HD 3470 (RV620)**. The
|
|
open `radeon` KMS driver is loaded in the initrd for early modesetting; firmware
|
|
comes from `enableRedistributableFirmware`.
|
|
|
|
The T400 has switchable graphics (discrete ATI + Intel GMA 4500MHD). Select
|
|
**Discrete** in the firmware's graphics setting so only the ATI is live. If you
|
|
run **Integrated** instead, the Intel `i915` driver takes over with no config
|
|
change and `radeon` stays idle.
|
|
|
|
## Login
|
|
|
|
Graphical login via a Wayland greeter — `greetd` running ReGreet inside the
|
|
`cage` kiosk compositor — configured centrally in `lyrathorpe/swaywm.nix` for
|
|
every Sway host (gated on `features.swayDesktop.enable`). The greeter is forced
|
|
to the Dvorak layout to match the console and Sway session. Set the user
|
|
password (`passwd lyrathorpe`) after install, or the greeter cannot
|
|
authenticate. Requires working radeon/i915 KMS (see Graphics).
|
|
|
|
## Apply
|
|
|
|
```sh
|
|
sudo nixos-rebuild switch --flake .#lyrathorpe-t400
|
|
```
|