Files
nix-config/hosts/idols-ai/default.nix
T
Ryan Yin 77e31bd4cb fix(idols-ai): keep network config across S3 resume
The r8169 NIC drops carrier on S3 resume, and systemd-networkd reacts by reconfiguring enp130s0: it dropped the static address/default route and deleted foreign routing policy rules (mihomo's 9000-9010 and Tailscale's 5210-5270). clash's TUN then lost its outbound interface and networking stayed broken until clash was restarted.

- IgnoreCarrierLoss=10s keeps the static address/route across the short carrier loss.
- ManageForeignRoutingPolicyRules=false stops networkd from deleting the TUN/VPN ip rules during the reconfiguration.
2026-09-14 10:54:33 +08:00

124 lines
4.2 KiB
Nix
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
disko,
myvars,
lib,
pkgs,
...
}:
#############################################################
#
# Ai - my main computer, with NixOS + I5-13600KF + RTX 4090 GPU, for gaming & daily use.
#
#############################################################
let
hostName = "ai"; # Define your hostname.
inherit (myvars.networking) mainGateway mainGateway6 nameservers;
inherit (myvars.networking.hostsAddr.${hostName}) iface ipv4 ipv6;
ipv4WithMask = "${ipv4}/24";
ipv6WithMask = "${ipv6}/64";
in
{
imports = [
disko.nixosModules.default
# disks
./disko-fs.nix
./disko-fs-data.nix
./netdev-mount.nix
# Include the results of the hardware scan.
./hardware-configuration.nix
./hardware-intel.nix
./hardware-nvidia.nix
./preservation.nix
./secureboot.nix
# others
./ai
];
# Zram consumes physical memory for compression, which can cause a deadlock and system hang if the model size approaches the physical memory limit.
# Disable the whole module (zram device + its swappiness=180 sysctl tunings); this host uses a disk swapfile instead.
modules.zram.enable = false;
# zswap: compressed writeback cache in front of the disk swapfile.
# Keeps swapped cold anon pages compressed in RAM instead of the SSD, which frees more
# page cache for the ~78GB mmap'd LLM weights (mmap file pages never go through zswap).
# Safe here: disk swapfile remains the real backing store, no zram deadlock structure.
# - zstd: CPU is not the bottleneck here (llama.cpp peaks ~30% util); its ~2.5x ratio
# keeps ~5G more anon bytes in the capped pool than lz4, and ~5us decompress is noise
# vs the ~100us SSD fault it avoids.
# - 10% pool (~9G): the module default 25% (~23G) would compete with the weight cache.
boot.zswap = {
enable = true;
compressor = "zstd";
maxPoolPercent = 10;
};
services.sunshine.enable = true;
services.tuned.ppdSettings.main.default = lib.mkForce "performance";
powerManagement.resumeCommands = ''
# Insta360 Link may stay enumerated with a stalled UVC endpoint after S3 resume.
${pkgs.coreutils}/bin/sleep 1
${pkgs.usbutils}/bin/usbreset 2e1a:4c01 || true
'';
networking = {
inherit hostName;
# we use networkd instead
networkmanager.enable = false; # provides nmcli/nmtui for wifi adjustment
useDHCP = false;
};
networking.useNetworkd = true;
systemd.network.enable = true;
# networkd removes routing policy rules not defined in .network files
# (ManageForeignRoutingPolicyRules defaults to yes) each time it reconfigures
# a link. On S3 resume it reconfigures enp130s0, which wiped mihomo's
# (9000-9010) and Tailscale's rules and briefly broke routing. Keep foreign
# rules so the VPN/TUN rules survive.
systemd.network.config.networkConfig.ManageForeignRoutingPolicyRules = false;
systemd.network.networks."10-${iface}" = {
matchConfig.Name = [ iface ];
networkConfig = {
Address = [
ipv4WithMask
ipv6WithMask
];
DNS = nameservers;
DHCP = "ipv6"; # enable DHCPv6 only, so we can get a GUA.
IPv6AcceptRA = true; # for Stateless IPv6 Autoconfiguraton (SLAAC)
LinkLocalAddressing = "ipv6";
# r8169 drops carrier on S3 resume; without this, networkd tears down the
# static address/route and clash's TUN auto-detect briefly loses its
# outbound interface, leaving routing broken until clash is restarted.
IgnoreCarrierLoss = "10s";
};
routes = [
{
Destination = "0.0.0.0/0";
Gateway = mainGateway;
}
{
Destination = "::/0";
Gateway = mainGateway6;
GatewayOnLink = true; # it's a gateway on local link.
}
];
linkConfig.RequiredForOnline = "routable";
};
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. Its perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "25.11"; # Did you read the comment?
}