Compare commits

..

2 Commits

Author SHA1 Message Date
f94aaba6c1 docs: correct the gotcha claiming the Gitea CLI is installed
No gitea-axi, tea or gh exists on the NixOS build, and there is no tea
login or GITEA_* environment to authenticate with. The flake names
gitea-axi only in the claude-code module's permissions and never packages
it, so pull requests cannot be opened from this machine.

The previous wording described the laptop while it still ran CachyOS with
these tools installed by hand.
2026-07-19 16:41:39 -04:00
25049c8aef feat(neogaia): adopt the upstream hardware profile (task 0013)
The laptop's hardware facts were guessed before it ran NixOS. Hand them to
the upstream nixos-hardware profile for this exact model, which fixes four
things that are wrong on the running machine: the laptop suspends into
s2idle rather than deep S3, the PS/2 mouse driver loads over an i2c
touchpad, no thermal management runs, and firmware updates are impossible.

The profile is taken wholesale, including the Intel graphics support it
carries. Those packages are inert without a display server, and trimming
them would mean diverging from upstream for no present benefit.

Drop the host's own Intel microcode setting, which the profile now defaults
from the redistributable firmware already enabled here.

The input follows the base nixpkgs: only its NixOS modules are consumed, so
its own pin would be evaluated by nothing while drifting silently.

The two acceptance criteria needing a reboot are left open; the sleep mode
and module blacklist only take effect on a fresh boot.
2026-07-19 16:41:34 -04:00
5 changed files with 65 additions and 9 deletions

View File

@@ -10,9 +10,36 @@ The microcode setting the `Host` currently declares is dropped, because the prof
## Acceptance criteria
- [ ] `nixos-hardware` is a flake input
- [ ] The Dell XPS 13 9380 profile is imported by the `neogaia` `Host`
- [ ] The `Host`'s own Intel microcode setting is removed, now that the profile supplies it
- [ ] `nix flake check` builds the `neogaia` toplevel
- [x] `nixos-hardware` is a flake input
- [x] The Dell XPS 13 9380 profile is imported by the `neogaia` `Host`
- [x] The `Host`'s own Intel microcode setting is removed, now that the profile supplies it
- [x] `nix flake check` builds the `neogaia` toplevel
- [ ] Manual confirmation after a rebuild: the default sleep mode is deep rather than s2idle
- [ ] Manual confirmation after a rebuild: the thermal and power management services are active, and the PS/2 mouse driver is no longer loaded
## Implementation Notes
The two manual criteria are left unresolved deliberately, and this task is not
finished until the operator resolves them. Both require a `nixos-rebuild switch`
followed by a **reboot**, neither of which can be performed here: the rebuild
needs root, and the sleep-mode and module-blacklist changes only take effect on a
fresh boot rather than on activation, since the modules in question are already
loaded.
The strongest evidence obtainable short of that reboot was gathered from the
evaluated configuration, and all of it agrees with the intent: the deep-sleep
kernel parameter is present, the PS/2 mouse module is blacklisted, the thermal,
power and firmware services are enabled, and Intel microcode updates remain on
through the profile's default now that the `Host` no longer sets them. That
confirms what was built, not what the machine does.
The input follows the base nixpkgs. Locking it without that pulled a second
nixpkgs into the lock file, which nothing evaluates — only the NixOS modules are
consumed — and which would drift silently. Following matches every other input
here except chaotic, whose separate pin is deliberate.
Verify after rebooting:
cat /sys/power/mem_sleep # expect [deep], currently [s2idle] deep
systemctl is-active thermald tlp # expect active, currently inactive
lsmod | grep psmouse # expect no output, currently loaded

View File

@@ -34,9 +34,11 @@ The domain model (Host, Module, Skeleton, Auto-loader, Enable convention, overla
- The primary build/verify seam for any Host is `nix flake check`, which builds `checks.x86_64-linux.<host>` (the system toplevel); cheap targeted checks use `nix eval .#nixosConfigurations.<host>.config...`.
- chaotic-nyx must **not** follow our `nixpkgs`, and its packages are built against chaotic's own pinned nixpkgs (its overlay defaults to `onTopOf = "flake-nixpkgs"`, the cache-friendly path).
That is what lets the `nyx-cache.chaotic.cx` binary cache hit instead of compiling the CachyOS kernel from source; the tradeoff is that chaotic packages do not see our `unstable`/`stable` overlays.
- The remote is self-hosted Gitea (`git.alexion.dev`), driven with `gitea-axi` rather than `tea`; `gh` is not installed.
- The remote is self-hosted Gitea (`git.alexion.dev`), and the intended CLI is `gitea-axi` rather than `tea`.
`gitea-axi` resolves the repository from the `origin` remote and takes credentials from the `axi` tea login, so both are implicit inside a checkout.
`tea` remains installed only as that credential source.
**None of it is installed on the NixOS build.** No `gitea-axi`, no `tea`, no `gh`, no tea login under `~/.config/tea`, and no `GITEA_*` environment — the flake names `gitea-axi` only in the claude-code module's permissions and never packages it.
Pull requests therefore cannot be opened from this machine until a module provides the tool and its credentials; branches can only be pushed.
The earlier claim that `tea` remains installed described the machine while it still ran CachyOS with these tools installed by hand.
- `~/.claude/skills` is generated by home-manager with `recursive = true`, so the directories are real and writable but every leaf file is a read-only symlink into the store.
Editing a skill in place fails; its source is `modules/claude-code/skills/<name>/` here, applied by a rebuild.
Creating a new file under `~/.claude/skills/` succeeds silently and is the trap — it stays outside the repo and reaches no other machine.

21
flake.lock generated
View File

@@ -117,6 +117,26 @@
"type": "github"
}
},
"nixos-hardware": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1784310968,
"narHash": "sha256-rkSPTePrKqs4dg+i7ZFCq93+HrClac6oSwXX927SVjA=",
"owner": "NixOS",
"repo": "nixos-hardware",
"rev": "779c32a00155994c86cde8213a8dd4df139d4355",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixos-hardware",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1784120854,
@@ -208,6 +228,7 @@
"chaotic": "chaotic",
"disko": "disko",
"home-manager": "home-manager_2",
"nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs_2",
"nixpkgs-stable": "nixpkgs-stable",
"nixpkgs-unstable": "nixpkgs-unstable",

View File

@@ -28,6 +28,12 @@
inputs.nixpkgs.follows = "nixpkgs";
};
# Upstream per-machine hardware profiles; each host imports its own.
nixos-hardware = {
url = "github:NixOS/nixos-hardware";
inputs.nixpkgs.follows = "nixpkgs";
};
# CachyOS kernel and binary cache. Pins its own nixpkgs so its cache stays
# usable and the kernel is fetched from it.
chaotic.url = "github:chaotic-cx/nyx/nyxpkgs-unstable";

View File

@@ -1,8 +1,9 @@
{ pkgs, ... }:
{ inputs, pkgs, ... }:
# neogaia — Dell XPS 13 9380 laptop.
# Disk layout is in ./disk.nix; `fileSystems` are derived from it, none declared here.
{
imports = [
inputs.nixos-hardware.nixosModules.dell-xps-13-9380
./hardware-configuration.nix
./disk.nix
];
@@ -15,9 +16,8 @@
boot.kernelPackages = pkgs.linuxPackages_cachyos;
hardware.cpu.intel.updateMicrocode = true;
# Redistributable firmware for the QCA6174 wifi (ath10k blobs).
# Intel microcode updates follow from this; none declared here.
hardware.enableRedistributableFirmware = true;
# RAM-backed swap; no on-disk swap partition.