The r8169 NIC drops carrier on S3 resume, and systemd-networkd reacts by reconfiguring enp130s0: it dropped the static address/default route and deleted foreign routing policy rules (mihomo's 9000-9010 and Tailscale's 5210-5270). clash's TUN then lost its outbound interface and networking stayed broken until clash was restarted.
- IgnoreCarrierLoss=10s keeps the static address/route across the short carrier loss.
- ManageForeignRoutingPolicyRules=false stops networkd from deleting the TUN/VPN ip rules during the reconfiguration.
The lock listener ignores inhibitors but had no playback condition, so it locked the screen at its timeout even during active media playback (screen-off already skipped via playerctl). Add the same playerctl condition to the lock listener.
niri already owns the org.freedesktop.ScreenSaver interface and feeds its inhibitors into the compositor idle notifier, so hypridle's own registration always fails with 'Another service is already providing...'. Set ignore_dbus_inhibit = true so hypridle no longer tries to claim it; D-Bus inhibits are still handled by niri.
Replace the static hypridle.conf with services.hypridle.settings and add required timeout options so each host tunes its own values:
- idols-ai (PC): 15 min keyboard, 20 min screen-off, 30 min lock.
- 12kingdoms-shoukei (laptop): 3 / 6 / 20 min (previous values).
The options have no defaults because the right values depend on the machine. Update the home-manager eval test to inspect the settings option instead of the old config file text.
Desktop speakers on idols-ai use the EBU R128 broadcast standard (-23 dB), while the quiet built-in laptop speakers on 12kingdoms-shoukei keep -12 dB. Move the target out of the shared preset so each host sets its own value.
Declare the output chain via services.easyeffects.extraPresets and load it with preset.output, replacing the GUI-only configuration that did not survive the tmpfs root.
autogain target is set to -12 dB (EasyEffects defaults to -23, which is too quiet for playback); the limiter acts as a transparent -1 dB safety net via threshold=-1 and gain-boost=false.
Emphasize safety precedence in the intro, and replace the narrow Bash pipeline ban with a trigger-based rule: keep POSIX shell as glue and move to Nushell or Python once quoting, error handling, parsing, types, retries, or portability are involved.
- read Asahi aop-sensors ALS via iio and drive eDP-1 backlight
- drop PrivateUsers for wluma so it can reach the real user D-Bus session
- remove hypridle 10min screen-dim listener: its brightnessctl writes fight
wluma and get learned as manual adjustments
Enable gnomeKeyring for the passwd PAM service so pam_gnome_keyring
updates the login keyring password when the login password changes.
Fixes 'Unlock Login Keyring' prompt desync after changing the password
via passwd (greetd session unlock alone does not update the keyring).
The running clash-verge-rev reports app_id "clash-verge" (lowercase), so the
anchored ^Clash-verge$ pattern never matched and the window opened on whatever
workspace was focused (1terminal). Match case-insensitively.
Change-Id: Iddabdbd66597a7325bdb08cb31434c1ee710dc3e
greetd ran the niri session directly, so exiting the session (e.g.
logout from the lock screen) made greetd immediately restart the
desktop with no authentication.
The broad 'file /** rwlkUx' rule conflicts with rix exec rules pulled in
via nested abstractions (xdg-open): AppArmor 5.0 rejects merged rules
with differing exec modifiers, failing apparmor.service on first load.
Compressed writeback cache in front of the disk swapfile keeps cold anon
pages in RAM instead of the SSD, freeing page cache for the ~78GB mmap'd
LLM weights. zstd's ratio keeps ~5G more anon bytes in the capped pool
than lz4 at negligible cost (CPU peaks ~30% on this host); pool capped at
10% so it never competes with the weight cache.
The zram module was auto-imported on all hosts via base scanPaths, and its
swappiness=180/page-cluster=0 tunings leaked onto hosts that disabled zram
(e.g. idols-ai with a disk swapfile, pushing cold anon pages to disk swap).
Wrap the whole module in modules.zram.enable (default true); idols-ai now
turns off zram and its tunings with a single switch.
xwayland-satellite has no compositor-level clipboard bridging, so X11
clients (WeChat/QQ) and Wayland clients cannot see each other's clipboard.
Add the pyclipsync flake input and enable its home-manager module, which
installs the daemon as a systemd user service bound to the graphical session.
Lanzaboote's nested rust-overlay input (2026-06-21) used the now-deprecated
stdenv.isLinux/stdenv.isDarwin aliases in mk-aggregated.nix, triggering two
evaluation warnings on nixpkgs 26.11 (where these aliases gained lib.warn).
rust-overlay fixed this treewide in 892c035d (2026-08-13); update the nested
input to master (f60c1b57, 2026-08-23).
`use modules/argx *` glob-imports argx's `parse` command into the global
scope, shadowing nushell's builtin `parse`. Any script sourced afterwards
that relies on the builtin (e.g. fzf's nushell integration, which uses
`parse --regex`) then fails to parse with `unknown flag`.
Use prefixed imports for `argx` and `lg` instead of `*`: both modules are
still registered for the kubernetes module's submodules (which call
`argx parse` / `lg level`), there are no bare `parse`/`main`/`level` call
sites, and the builtin `parse` stays available.
`lsa` (ls -al) and `dus` (du) render the table at a fixed width of 350 so
columns like size/apparent/physical are never dropped to "..." when the
natural table is wider than the terminal.
At login the xdg-autostart-generator starts apps at
graphical-session.target, racing the portal user services. Sandboxed
apps (nixpak firefox/telegram) end up with broken FileChooser/OpenURI
until manually restarted.
Add a template drop-in on app-@autostart.service that makes every
autostart app wait for the portal stack.
- Add an offlineHosts list to VictoriaMetrics scrape generation: SBCs
and the whole k3s-prod-1 cluster are powered off, shoukei's exporter
is disabled on the machine; also comment out the dnsmasq-exporter
job (runs on suzi).
- Disable node-exporter on shoukei: a laptop on untrusted networks
should not expose :9100 (the firewall is off repo-wide).
- Route severity none|info alerts to the null receiver; meta alerts
and info noise should never page.
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
node-exporter always reports device_error=1 for containerd sandbox shm
bind mounts (tmpfs), producing ~50 bogus critical alerts on the
kubevirt hosts. Verified against live metrics that no non-shm device
errors exist, so nothing real is filtered out.
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
The NixOS alertmanager module pipes the generated config through
envsubst to inject secrets, which silently replaced the template's
$i/$a variables with empty strings, so every telegram notification
failed with a template parse error since Friday's deploy.
Rewrite the template without variables: range + dot, define/template
for the per-alert block, and an if/else split to cap a group at 5
alerts (slice errors when fewer than 5). Verified with amtool template
render against post-envsubst content for both branches.
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
Fix inconsistent volume across bilibili videos at the PipeWire level:
the easyeffects daemon auto-starts at login; an autogain + limiter
chain can be applied per-app (e.g. only to the browser).
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
- Show group-level labels (alertgroup/cluster/env/namespace) once in
the header instead of repeating them per alert.
- Use each rule's summary annotation as the per-alert headline (it
already carries the distinguishing resource name), falling back to
the instance label; show nodename on its own line when present.
- Drop the noisy per-alert label dump and the always-N/A value line.
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
- Trim the telegram template: drop the full label dump, render at
most 5 alerts per group, and note how many were omitted, so
messages stay within Telegram's 4096-char limit.
- Route severity=none meta alerts (Watchdog, InfoInhibitor) to a new
null receiver so they no longer notify.
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>