Key sudo's credential cache per user rather than per terminal, holding it for 60 minutes. An authentication made in the operator's own terminal then covers commands issued by processes holding no terminal of their own, which previously failed with a bare non-zero exit and no output. No command is made passwordless. The password remains required; only the cache holding it is shared, and any process running as the primary user can spend that credential until it lapses. A PreToolUse hook refuses a privileged command while the cache is cold, naming the command that warms it, so the condition announces itself rather than presenting as a stall. Both states were exercised against the running system.
10 KiB
10 KiB
dotfiles-nixos
One flake that builds every machine the user owns.
The domain model (Host, Module, Skeleton, Auto-loader, Enable convention, overlays) lives in .claude/CONTEXT.md; the current deliverable's spec is .claude/spec/laptop-mvi.md.
Conventions
- Write comments only where they earn their place, and keep them concise.
Assume the reader can read code: comment the "why", not the "what", and explain "what" only when it is genuinely non-obvious.
A comment must be self-contained to its file — accurate to a reader looking at that file alone.
Do not write about history ("used to be X", "now moved here") or future state, about how a value is consumed elsewhere, or to justify the choice against alternatives; state the positive reason a thing exists, keeping any real stakes as a present-tense consequence.
The only permitted cross-file mention is a bare pointer explaining why something is absent here (e.g. "disko derives
fileSystems; none declared here"), never narrating what the other file or tool does. Do not use the domain model's capitalized terms (Host, Module, Skeleton, Auto-loader, Enable convention) as glossary references; describe things in plain language, using "host"/"module" only as ordinary lowercase nouns. Never reference agent-facing state (anything under.claude/orCLAUDE.md). A file-top header is one concise purpose line, added only where the filename or path does not already say it — never a feature inventory of the code below. For a placeholder, say so plainly plus any actionable present-tense directive ("Placeholder: regenerate with nixos-generate-config on the target machine"), never "placeholder for ". Optiondescription/mkEnableOptionstrings are user-facing documentation rather than comments, so they may describe behaviour more fully — but the self-contained rule and the bans on glossary terms and agent-state references still apply. - Comments posted to Gitea (pull requests, issues, reviews) go out under the operator's account, so sign every one to make clear the author is the agent, not the operator.
End the comment with a
— Claudesign-off. (A dedicated bot account may replace this later; until then, the sign-off is the only marker.) - Commit messages follow Conventional Commits, specified in
docs/conventional-commits.md. Scope is the module or host the change belongs to (fish,nvim,neogaia), omitted for repo-wide changes. Keep messages free of Gitea-specific references: this repository is mirrored to GitHub, where issue and pull-request numbers resolve to unrelated things.
Gotchas
- This repo is developed on
neogaia, which now runs the NixOS it builds. Flakes and the chaotic substituter come from this flake's ownnix.settings, so noNIX_CONFIGexport or per-command--extra-experimental-featuresis needed, and building a toplevel withboot.kernelPackages = linuxPackages_cachyosfetches the kernel fromnyx-cacherather than compiling it. Both were true only while the machine still ran CachyOS against a distro Nix daemon. - The substituters a
nix buildfetches from are the daemon's (/etc/nix/nix.conf), not thenix.settingsof the config being built — those only govern the built system. The two coincide here because the dev host runs this flake; they diverge on any machine that does not. - Git identity is not declared in the flake — there is no
programs.git— so it must be set by hand before the first commit on a fresh machine. The July 2026 reimage confirmed this: it wiped the hand-written~/.gitconfig, and the next commit failed withAuthor identity unknown, auto-detectingalexion@neogaia.(none). It now lives in this checkout's.git/config, which reaches no other machine and does not survive the next reimage either; history usesalexion <contact@alexion.dev>. - The primary build/verify seam for any Host is
nix flake check, which buildschecks.x86_64-linux.<host>(the system toplevel); cheap targeted checks usenix eval .#nixosConfigurations.<host>.config.... - A flake only sees git-tracked files, so a new file that has not been
git added is invisible to evaluation even though it exists on disk. The failure names the path and reads as if the file were missing:error: Path 'secrets/shared.yaml' does not exist in Git repository. Staging is enough; the file need not be committed. - chaotic-nyx must not follow our
nixpkgs, and its packages are built against chaotic's own pinned nixpkgs (its overlay defaults toonTopOf = "flake-nixpkgs", the cache-friendly path). That is what lets thenyx-cache.chaotic.cxbinary cache hit instead of compiling the CachyOS kernel from source; the tradeoff is that chaotic packages do not see ourunstable/stableoverlays. - The remote is self-hosted Gitea (
git.alexion.dev), and the intended CLI isgitea-axirather thantea.gitea-axiresolves the repository from theoriginremote and takes credentials from theaxitea login, so both are implicit inside a checkout. None of it is installed on the NixOS build. Nogitea-axi, notea, nogh, no tea login under~/.config/tea, and noGITEA_*environment — the flake namesgitea-axionly as the claude-code module'sSessionStarthook command and never packages it, so that hook invokes a binary that is not onPATH. Pull requests therefore cannot be opened from this machine until a module provides the tool and its credentials; branches can only be pushed. The earlier claim thattearemains installed described the machine while it still ran CachyOS with these tools installed by hand. ~/.claude/skillsis generated by home-manager withrecursive = true, so the directories are real and writable but every leaf file is a read-only symlink into the store. Editing a skill in place fails; its source ismodules/claude-code/skills/<name>/here, applied by a rebuild. Creating a new file under~/.claude/skills/succeeds silently and is the trap — it stays outside the repo and reaches no other machine. Copying out of that tree needscp -rLpluschmod -R u+w: a plaincp -rcopies the symlinks, putting store paths into the destination, and dereferenced files keep the store's read-only mode.home-manager.users.<user>.home.fileis keyed by absolute path, not by a path relative to the home directory. Evaluatinghome.file.".claude/CLAUDE.md"fails with "does not provide attribute"; the working key ishome.file."/home/alexion/.claude/CLAUDE.md". List the real keys withnix eval --json .#nixosConfigurations.<host>.config.home-manager.users.<user>.home.file --apply builtins.attrNamesrather than guessing one. A key's.sourceis the input file, whose store path differs from the deployed symlink's target (home-manager copies it to ahm_-prefixed path) even though the contents match.- nixpkgs
vimPlugins.nord-nvimisshaunsingh/nord.nvim(norequire("nord").setup()); the config wantsgbprod/nord.nvim, which is packaged asvimPlugins.gbprod-nord. - nixpkgs
vimPlugins.nvim-treesittertracks the rewrittenmainbranch: there is norequire("nvim-treesitter.configs").setup{ensure_installed,highlight,indent}. Under nixvim, useplugins.treesitterwithhighlight.enable/indent.enableandgrammarPackages = with config.programs.nixvim.plugins.treesitter.package.builtGrammars; [ ... ]— the module's ownpackage.builtGrammars, notpkgs.vimPlugins.nvim-treesitter.*(whose query files can mismatch). The module targets the main branch and enables features via neovim-native APIs (vim.treesitter.start(),require'nvim-treesitter'.indentexpr()). - Neovim is configured via nixvim (flake input
nixvim, consumed asinputs.nixvim.homeModules.nixvimadded tohome-manager.sharedModules, config underhome-manager.users.<user>.programs.nixvim).nixvim.inputs.nixpkgs.follows = "nixpkgs"is set; nixvim then emits a benign eval warning that its pinned nixpkgs differs from the followed one — builds and runs fine, do not "fix" it by dropping the follows. - To reference the nixvim-built package's own attrs (e.g. treesitter
builtGrammars) inside our NixOS module, givehome-manager.users.<user>the module-function form (hm: { programs.nixvim = { ... hm.config.programs.nixvim... }; }), since the outerconfigis the NixOS config, not the home-manager one. - The agent's Bash sandbox blocks
sudoand swallows it into a bare exit 1 with no stderr, which looks identical to the command itself failing. Re-run with the sandbox disabled to see the real error (sudo: a password is required) before diagnosing anything else. Separately,nixos-generate-config --show-hardware-configneeds root on this machine even just to print: unprivileged it dies atFailed to retrieve subvolume info for /, because the root filesystem is btrfs. - Sudo's credential cache is keyed per user rather than per terminal (
timestamp_type=global, 60-minute window, declared by the claude-code module), so an authentication made in one terminal counts for commands the agent runs. Warming it withsudo -vthrough the agent's own shell — including the!prefix — never works: that shell has no controlling terminal, and sudo reportsa terminal is required to read the password. It has to be a separate terminal. APreToolUsehook refuses privileged commands while the cache is cold, so a cold cache announces itself instead of stalling; a failure without that message is the sandbox, not the cache. home-manager.users.<user>cannot be assigned twice at the same level in one module:home-manager.users.${user}.home.packagesalongsidehome-manager.users.${user}.programs.xfails witherror: dynamic attribute 'alexion' already defined. The interpolated key makes it a dynamic attribute, which nix will not merge the way it merges static paths. Nest both under a singlehome-manager.users.${user} = { ... }.- Verifying a nixvim change headless:
programs.nixvim.build.package's wrapper has no-u, so running$OUT/bin/nvimloads the caller's~/.config/nvim(the dev host's real config), not the built config — silently. To exercise the built config, launch with-u "$(nix build --no-link --print-out-paths .#…programs.nixvim.build.initFile)"and a scratchHOME/XDG_CONFIG_HOME.conceallevelis window-local: set it withopt_local/vim.wo, nevervim.bo[buf](which errors).