diff options
| author | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-04 20:01:06 +0530 |
|---|---|---|
| committer | Arpit Chakladar <arpitchakladar+git@gmail.com> | 2026-08-04 20:01:06 +0530 |
| commit | 0a7afa2d1e576f05253b62c6b17e5e4873fbdebc (patch) | |
| tree | 4aec8cee7c4db281510bc42ff4e214252428afa4 | |
| parent | 2e0f6163f61cb1e4195f1a08ad1148e57a4f5843 (diff) | |
| download | home-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.tar.gz home-manager-config-0a7afa2d1e576f05253b62c6b17e5e4873fbdebc.zip | |
feat: moved gpg data directory, other gopass ssh keys, script builder
- Using ~/.local/share/gnupg/ for storing the data for gnupg, and made
the necessary changes in all places to that effect
- Additional ssh keys can be added to gopass under ssh/, which is on top
of the git servers that already existed
- Using pkgs.writeShellApplication for creating the scripts, stopped
setting path for each dependency (creating a long PATH variable and
thus finding binaries may take longer), instead using the inbuild dependency (runtimeInputs) for the scripts
| -rw-r--r-- | modules/communication/neomutt/keybindings.nix | 357 | ||||
| -rw-r--r-- | modules/communication/neomutt/macros.nix | 34 | ||||
| -rw-r--r-- | modules/desktop/waybar/lib.nix | 1 | ||||
| -rw-r--r-- | modules/desktop/waybar/module/window.nix | 1 | ||||
| -rw-r--r-- | modules/desktop/waybar/module/workspaces.nix | 1 | ||||
| -rw-r--r-- | modules/scripts/gopass-ssh-load/default.nix | 16 | ||||
| -rw-r--r-- | modules/scripts/gopass-ssh-load/script.sh | 39 | ||||
| -rw-r--r-- | modules/scripts/lib.nix | 34 | ||||
| -rw-r--r-- | modules/scripts/neomutt-sync/script.sh | 4 | ||||
| -rw-r--r-- | modules/scripts/usque-warp/script.sh | 25 | ||||
| -rw-r--r-- | modules/scripts/yazi-file-chooser/script.sh | 4 | ||||
| -rw-r--r-- | modules/security/gpg/default.nix | 5 | ||||
| -rw-r--r-- | modules/security/ssh/default.nix | 6 |
13 files changed, 306 insertions, 221 deletions
diff --git a/modules/communication/neomutt/keybindings.nix b/modules/communication/neomutt/keybindings.nix index 929d3e2..59712fa 100644 --- a/modules/communication/neomutt/keybindings.nix +++ b/modules/communication/neomutt/keybindings.nix @@ -1,14 +1,20 @@ # Keybindings - Vim-style keyboard shortcuts for neomutt +# +# Covers the core menus: generic (fallback), index, pager, sidebar, +# attach, browser, compose. Menus like pgp/smime/mix/postpone/alias/query +# are intentionally left mostly on defaults - they're rarely touched and +# not worth risking an incorrect binding for. Press `?` inside neomutt +# in any menu to see the live, authoritative list of bound functions. { config, lib, ... }: { config.programs.neomutt.binds = lib.mkIf config.communication.neomutt.enable [ - # --- sidebar navigation (vim: k=up, j=down) --- + # --- sidebar navigation (vim: Ctrl-k=up, Ctrl-j=down) --- { map = [ "index" "pager" ]; - key = "\\CK"; + key = "\\Ck"; action = "sidebar-prev"; } { @@ -16,86 +22,87 @@ "index" "pager" ]; - key = "\\CJ"; + key = "\\Cj"; action = "sidebar-next"; } { - # select the highlighted mailbox directly, no Ctrl+O needed + # jump into the highlighted mailbox map = [ "index" "pager" ]; - key = "o"; + key = "\\Co"; action = "sidebar-open"; } - - # --- open / go deeper (vim: l = right/forward) --- { - map = [ "index" ]; - key = "<Return>"; - action = "display-message"; + map = [ + "index" + "pager" + ]; + key = "\\Cp"; + action = "sidebar-prev-new"; } { - map = [ "index" ]; - key = "l"; - action = "display-message"; + map = [ + "index" + "pager" + ]; + key = "\\Cn"; + action = "sidebar-next-new"; } { - map = [ "browser" ]; - key = "<Return>"; - action = "select-entry"; + # show/hide the sidebar column entirely + map = [ + "index" + "pager" + ]; + key = "B"; + action = "sidebar-toggle-visible"; } + + # --- basic entry navigation (generic = fallback for every list-style menu) --- { - map = [ "browser" ]; - key = "l"; - action = "select-entry"; + map = [ "generic" ]; + key = "j"; + action = "next-entry"; } { - map = [ "attach" ]; - key = "<Return>"; - action = "view-attach"; + map = [ "generic" ]; + key = "k"; + action = "previous-entry"; } { - map = [ "attach" ]; - key = "l"; - action = "view-attach"; + map = [ "generic" ]; + key = "gg"; + action = "first-entry"; } { map = [ - "alias" - "query" + "index" + "generic" ]; - key = "<Return>"; - action = "select-entry"; + key = "G"; + action = "last-entry"; } - # --- back / exit / fold-close (vim: h = left/back) --- - { - map = [ "pager" ]; - key = "h"; - action = "exit"; - } + # --- scroll-to-position, straight from vim (zt/zz/zb) --- { - map = [ "browser" ]; - key = "h"; - action = "exit"; + map = [ "generic" ]; + key = "zt"; + action = "current-top"; } { - map = [ "attach" ]; - key = "h"; - action = "exit"; + map = [ "generic" ]; + key = "zz"; + action = "current-middle"; } { - # in the index, h/l act as fold-close/fold-open on a thread - # rather than "back" (there's nowhere to go "back" to from the - # top-level index) -- same convention as fold/tree keybindings - # in tools like NERDTree or fugitive. - map = [ "index" ]; - key = "h"; - action = "collapse-thread"; + map = [ "generic" ]; + key = "zb"; + action = "current-bottom"; } - # --- pager line scrolling (vim: j/k move by line) --- + # --- pager scrolling --- { map = [ "pager" ]; key = "j"; @@ -107,26 +114,6 @@ action = "previous-line"; } { - # kept from before: jump straight to the next unread message, - # extends the h/l "back/forward" metaphor already in use - map = [ "pager" ]; - key = "l"; - action = "next-unread"; - } - - # --- top/bottom of buffer (vim: gg/G -- NOT 0/$, which mean - # start/end of *line* in vim and would be a false friend here) --- - { - map = [ "index" ]; - key = "gg"; - action = "first-entry"; - } - { - map = [ "index" ]; - key = "G"; - action = "last-entry"; - } - { map = [ "pager" ]; key = "gg"; action = "top"; @@ -137,63 +124,61 @@ action = "bottom"; } { - map = [ "browser" ]; - key = "gg"; - action = "first-entry"; - } - { - map = [ "browser" ]; - key = "G"; - action = "last-entry"; - } - - # --- page scrolling (vim: Ctrl-f/b full page, Ctrl-d/u half page) --- - { - map = [ "pager" ]; - key = "\\Cf"; - action = "next-page"; - } - { - map = [ "pager" ]; - key = "\\Cb"; - action = "previous-page"; - } - { - map = [ "pager" ]; + map = [ + "generic" + "index" + "pager" + ]; key = "\\Cd"; action = "half-down"; } { - map = [ "pager" ]; + map = [ + "generic" + "index" + "pager" + ]; key = "\\Cu"; action = "half-up"; } { - # index has no half-page concept, so Ctrl-d/u fall back to - # the same full-page scroll as Ctrl-f/b - map = [ "index" ]; + map = [ + "generic" + "index" + "pager" + ]; key = "\\Cf"; action = "next-page"; } { + # NOTE: Ctrl-B is deliberately left unbound in the pager map here - + # macros.nix claims it there for the chawan browser-view macro. map = [ "index" ]; key = "\\Cb"; action = "previous-page"; } + + # --- h/l as "back / go into", vim left/right --- { - map = [ "index" ]; - key = "\\Cd"; - action = "half-down"; + map = [ "pager" ]; + key = "h"; + action = "exit"; + } + { + map = [ "pager" ]; + key = "l"; + action = "view-attachments"; } { map = [ "index" ]; - key = "\\Cu"; - action = "half-up"; + key = "l"; + action = "display-message"; } - # --- search (vim: / forward, ? backward, n/N repeat) --- + # --- search (mostly default already, restated for a complete reference) --- { map = [ + "generic" "index" "pager" ]; @@ -202,6 +187,7 @@ } { map = [ + "generic" "index" "pager" ]; @@ -210,6 +196,7 @@ } { map = [ + "generic" "index" "pager" ]; @@ -218,6 +205,7 @@ } { map = [ + "generic" "index" "pager" ]; @@ -225,90 +213,147 @@ action = "search-opposite"; } - # --- undelete --- - { - # capital D deletes the whole thread, mirroring the v/V - # (single vs. whole-thread) convention used below for tagging - map = [ "index" ]; - key = "D"; - action = "delete-thread"; - } + # --- delete / undelete, vim dd --- { map = [ "index" "pager" ]; + key = "dd"; + action = "delete-message"; + } + { + map = [ "index" ]; + key = "dT"; + action = "delete-thread"; + } + { + map = [ "index" ]; key = "u"; action = "undelete-message"; } - - # --- copy (vim: yy yank -- non-destructive, unlike save-message - # which moves/deletes the original) --- { - map = [ - "index" - "pager" - ]; - key = "y"; - action = "noop"; + map = [ "index" ]; + key = "U"; + action = "undelete-thread"; } { - map = [ - "index" - "pager" - ]; - key = "yy"; - action = "copy-message"; + map = [ "attach" ]; + key = "dd"; + action = "delete-entry"; + } + { + map = [ "attach" ]; + key = "u"; + action = "undelete-entry"; + } + + # --- limit / filter the index, gf = filter, gF = clear filter --- + { + # prompts for a limit pattern; macros.nix binds gF to clear it + map = [ "index" ]; + key = "gf"; + action = "limit"; } - # --- tagging (vim: v/V visual select single/whole block) --- - # NOTE: this overrides neomutt's default "v" (view-attachments). - # Attachments are still reachable from the pager/index via the - # mailcap auto-view or the attach menu, but if you want plain - # "v" back for view-attachments, just delete these two binds. + # --- unread / new / flagged navigation --- { map = [ "index" ]; - key = "v"; - action = "tag-entry"; + key = "]"; + action = "next-unread"; } { map = [ "index" ]; - key = "V"; - action = "tag-thread"; + key = "["; + action = "previous-unread"; } - - # --- mailbox switching --- { map = [ "index" ]; - key = "gt"; - action = "next-unread-mailbox"; + key = "}"; + action = "next-new"; } - # --- filter/limit (vim: gf to 'find'/'filter') --- - # gF is the "clear filter" counterpart, defined as a macro - # (see macros.nix) since resetting the limit needs a fixed - # pattern rather than an interactive prompt. { map = [ "index" ]; - key = "gf"; - action = "limit"; + key = "{"; + action = "previous-new"; + } + { + map = [ "index" ]; + key = "gn"; + action = "next-flagged"; + } + { + map = [ "index" ]; + key = "gp"; + action = "previous-flagged"; } - # --- help message to show functions and keybindings --- + # --- attach menu --- { - map = [ - "index" - "pager" - "browser" - "attach" - ]; - key = "g?"; - action = "help"; + map = [ "attach" ]; + key = "l"; + action = "view-attach"; + } + { + map = [ "attach" ]; + key = "s"; + action = "save-entry"; + } + { + map = [ "attach" ]; + key = "p"; + action = "print-entry"; } + # --- browser (folder / file picker) --- { - map = [ "pager" ]; - key = "H"; - action = "display-toggle-weed"; + map = [ "browser" ]; + key = "j"; + action = "next-entry"; + } + { + map = [ "browser" ]; + key = "k"; + action = "previous-entry"; + } + { + map = [ "browser" ]; + key = "gg"; + action = "first-entry"; + } + { + map = [ "browser" ]; + key = "G"; + action = "last-entry"; + } + { + # neomutt has no dedicated "go up a directory" function - the ".." + # row is a normal entry, so l/Enter on it goes up just fine + map = [ "browser" ]; + key = "l"; + action = "select-entry"; + } + { + map = [ "browser" ]; + key = "\\Cd"; + action = "half-down"; + } + { + map = [ "browser" ]; + key = "\\Cu"; + action = "half-up"; + } + + # --- compose menu --- + { + map = [ "compose" ]; + key = "j"; + action = "next-entry"; + } + { + map = [ "compose" ]; + key = "k"; + action = "previous-entry"; } ]; } diff --git a/modules/communication/neomutt/macros.nix b/modules/communication/neomutt/macros.nix index 3fdc769..4a1fd5d 100644 --- a/modules/communication/neomutt/macros.nix +++ b/modules/communication/neomutt/macros.nix @@ -3,18 +3,19 @@ { config.programs.neomutt.macros = lib.mkIf config.communication.neomutt.enable [ { + # sync the mailbox and run the external sync script, silencing the + # "press any key" prompt around it. Vim mnemonic: g-prefixed, "go sync". map = [ "index" "pager" ]; - key = "O"; + key = "gs"; action = "<enter-command>set my_wait_key=$wait_key wait_key=no<enter><sync-mailbox><shell-escape>${lib.getExe config.scripts.neomutt-sync.package}<enter><sync-mailbox><enter-command>set wait_key=$my_wait_key<enter>"; } { - # gx: open the message body in interactive chawan -- real vim-style - # cursor navigation (hjkl, Tab/Shift-Tab between links, Enter to - # follow, B back, q to return to neomutt). Replaces the old - # urlscan-based link picker. + # extract every URL from the message via urlscan into a picker menu, + # then follow the selected one. Vim mnemonic: gx, same as vim-plugins + # that open the link/file under the cursor. map = [ "index" "pager" @@ -23,35 +24,42 @@ action = "<pipe-message>urlscan<enter>"; } { - # Ctrl-B in the pager: same interactive chawan view as gx, kept as - # a second binding since Ctrl-B is a common muscle-memory key - # for "open this in a browser-like view". + # open the message body in interactive chawan -- real vim-style + # cursor navigation (hjkl, Tab/Shift-Tab between links, Enter to + # follow, B back, q to return to neomutt). Replaces the old + # urlscan-based link picker. + # Kept on Ctrl-B since that's common muscle-memory for "open this in + # a browser-like view" - previous-page is intentionally NOT bound to + # Ctrl-B in the pager (see binds.nix) so this doesn't get shadowed. map = [ "pager" ]; key = "\\Cb"; action = "<enter-command>set my_pipe_decode=$pipe_decode pipe_decode=yes<enter><pipe-message>${lib.getExe config.web.chawan.package} -o \"title='neomutt'\"<enter><enter-command>set pipe_decode=$my_pipe_decode<enter>"; } { - # Ctrl-B on a specific attachment (not just the top-level + # on a specific attachment (not just the top-level # message): pipe-entry sends the selected attachment instead. + # Same gx mnemonic as the index/pager macro above. map = [ "attach" ]; - key = "\\Cb"; + key = "gx"; action = "<pipe-entry>${lib.getExe config.web.chawan.package} -o \"title='neomutt'\" <enter>"; } { - # gF: clear the current limit/filter and show every message again, + # clear the current limit/filter and show every message again, # the counterpart to gf (interactive limit prompt) in binds.nix map = [ "index" ]; key = "gF"; action = "<limit>all<enter>"; } { - # ZZ: save and quit, vim-style (sync mailbox, then quit) + # save and quit, vim-style (sync mailbox, then quit) - same ZZ + # you'd type in vim to write and exit map = [ "index" ]; key = "ZZ"; action = "<sync-mailbox><quit>"; } { - # ZQ: quit without saving, vim-style counterpart to ZZ + # quit without saving, vim-style counterpart to ZZ - same ZQ + # you'd type in vim to discard and exit map = [ "index" ]; key = "ZQ"; action = "<exit>"; diff --git a/modules/desktop/waybar/lib.nix b/modules/desktop/waybar/lib.nix index b9e5a98..ca7a5a8 100644 --- a/modules/desktop/waybar/lib.nix +++ b/modules/desktop/waybar/lib.nix @@ -25,6 +25,7 @@ let "screen-recording" = mkIcon "#FF5555" ""; "system-monitor" = mkIcon "#50FA7B" ""; "neovim" = mkIcon "#005900" ""; + "gopass" = mkIcon "#FFD700" ""; }; in { diff --git a/modules/desktop/waybar/module/window.nix b/modules/desktop/waybar/module/window.nix index 04c39cf..0727662 100644 --- a/modules/desktop/waybar/module/window.nix +++ b/modules/desktop/waybar/module/window.nix @@ -20,5 +20,6 @@ "screen-recording" = "${icons."screen-recording"} Screen Recording"; "system-monitor" = "${icons."system-monitor"} System Monitor"; "nvim(.*)" = "${icons."neovim"} $1"; + "gopass" = "${icons."gopass"} gopass"; }; } diff --git a/modules/desktop/waybar/module/workspaces.nix b/modules/desktop/waybar/module/workspaces.nix index 7b4f21a..e8a12fa 100644 --- a/modules/desktop/waybar/module/workspaces.nix +++ b/modules/desktop/waybar/module/workspaces.nix @@ -44,5 +44,6 @@ icons."screen-recording"; "title<system-monitor>" = lib.mkIf config.scripts.system-monitor.enable icons."system-monitor"; "title<nvim(.*)>" = lib.mkIf config.development.nixvim.enable icons."neovim"; + "title<gopass>" = lib.mkIf config.development.nixvim.enable icons."gopass"; }; } diff --git a/modules/scripts/gopass-ssh-load/default.nix b/modules/scripts/gopass-ssh-load/default.nix index 002a4ac..e0a4615 100644 --- a/modules/scripts/gopass-ssh-load/default.nix +++ b/modules/scripts/gopass-ssh-load/default.nix @@ -6,10 +6,26 @@ }: let inherit ((import ../lib.nix { inherit lib pkgs; })) mkScriptModule; + + gitPlatformKeys = [ + "github" + "gitlab" + "bitbucket" + "codeberg" + "srht" + ]; + + gopassKeys = + lib.optionals config.development.git.useSSH gitPlatformKeys ++ config.security.ssh.extraGopassKeys; + base = mkScriptModule { name = "gopass-ssh-load"; path = ./script.sh; description = "Load SSH keys from gopass password store"; + env = { + GNUPGHOME = config.home.sessionVariables.GNUPGHOME; + GOPASS_SSH_KEYS = lib.concatStringsSep " " gopassKeys; + }; deps = with pkgs; [ config.security.gopass.package gnupg diff --git a/modules/scripts/gopass-ssh-load/script.sh b/modules/scripts/gopass-ssh-load/script.sh index e8bc0ee..43c83b0 100644 --- a/modules/scripts/gopass-ssh-load/script.sh +++ b/modules/scripts/gopass-ssh-load/script.sh @@ -1,5 +1,12 @@ -export SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +set -o errexit +set -o nounset +set -o pipefail +# Load SSH keys from gopass password store +export GNUPGHOME="${GNUPGHOME:-$HOME/.local/share/gnupg}" + +SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" +export SSH_AUTH_SOCK if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then echo "Error: SSH_AUTH_SOCK is not set or valid." >&2 exit 1 @@ -9,25 +16,31 @@ if ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then exit 0 fi -for key in github gitlab bitbucket codeberg sourcehut; do +# GOPASS_SSH_KEYS: space-separated list of gopass entry names under ssh/ +# e.g. GOPASS_SSH_KEYS="github gitlab work-server" +if [ -z "${GOPASS_SSH_KEYS:-}" ]; then + echo "Error: GOPASS_SSH_KEYS is not set. Example: GOPASS_SSH_KEYS=\"github gitlab\"" >&2 + exit 1 +fi + +# shellcheck disable=SC2086 +read -r -a keys <<< "$GOPASS_SSH_KEYS" + +for key in "${keys[@]}"; do if gopass cat "ssh/$key" > /dev/null 2>&1; then tmpdir=$(mktemp -d) keyfile="$tmpdir/key" gopass cat "ssh/$key" > "$keyfile" 2>/dev/null chmod 600 "$keyfile" - if ! ssh-add "$keyfile" 2>/dev/null; then - passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null) - if [ -n "$passphrase" ]; then - tmpcopy=$(mktemp) - cp "$keyfile" "$tmpcopy" - chmod 600 "$tmpcopy" - if ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then - ssh-add "$tmpcopy" 2>/dev/null - fi - rm -f "$tmpcopy" - fi + passphrase=$(gopass cat "ssh/$key/passphrase" 2>/dev/null || true) + if [ -n "$passphrase" ]; then + ssh-keygen -p -P "$passphrase" -N "" -f "$keyfile" 2>/dev/null fi + + ssh-add "$keyfile" 2>/dev/null rm -rf "$tmpdir" + else + echo "Warning: no gopass entry ssh/$key" >&2 fi done diff --git a/modules/scripts/lib.nix b/modules/scripts/lib.nix index 2d2aed3..70affba 100644 --- a/modules/scripts/lib.nix +++ b/modules/scripts/lib.nix @@ -8,31 +8,19 @@ let descLines = lib.filter (s: s != "") (lib.splitString "\n" description); descComment = if descLines == [ ] then "" else lib.concatMapStringsSep "\n" (line: "# ${line}") descLines + "\n"; - envVars = lib.concatStringsSep "\n" (lib.mapAttrsToList (n: v: "${n}=\"${toString v}\"") env); - wrappedScript = pkgs.writeTextFile { - name = name; - executable = true; - destination = "/bin/${name}"; - text = '' - #!${shell} - ${descComment}${envVars} - ${builtins.readFile path} - ''; - }; + envVars = lib.concatStringsSep "\n" ( + lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg (toString v)}") env + ); in - pkgs.runCommand name - { - nativeBuildInputs = [ pkgs.makeWrapper ]; - meta.mainProgram = name; - } - '' - mkdir -p $out/bin - cp ${wrappedScript}/bin/${name} $out/bin/${name} - chmod +x $out/bin/${name} - - wrapProgram $out/bin/${name} \ - --prefix PATH : ${lib.makeBinPath deps} + pkgs.writeShellApplication { + inherit name; + runtimeInputs = deps; + text = '' + #!${shell} + ${descComment}${envVars} + ${builtins.readFile path} ''; + }; mkScriptModule = { diff --git a/modules/scripts/neomutt-sync/script.sh b/modules/scripts/neomutt-sync/script.sh index 96d866d..b2db42a 100644 --- a/modules/scripts/neomutt-sync/script.sh +++ b/modules/scripts/neomutt-sync/script.sh @@ -1,7 +1,7 @@ -export DIALOGRC=$(mktemp) +DIALOGRC=$(mktemp) NOTMUCH_LOG=$(mktemp) TITLE="[SYNCING MAIL]" -BACK_TITLE= +export DIALOGRC trap 'rm -f "$DIALOGRC" "$NOTMUCH_LOG"' EXIT # Clean up everything on exit cat << 'EOF' > "$DIALOGRC" diff --git a/modules/scripts/usque-warp/script.sh b/modules/scripts/usque-warp/script.sh index 5736018..01b298e 100644 --- a/modules/scripts/usque-warp/script.sh +++ b/modules/scripts/usque-warp/script.sh @@ -1,3 +1,4 @@ +#!/usr/bin/env bash set -euo pipefail CONFIG_DIR="$HOME/.cache/usque" CONFIG="$CONFIG_DIR/config.json" @@ -23,13 +24,13 @@ is_running() { [[ -f "$PID_FILE" ]] || return 1 local pid pid=$(cat "$PID_FILE" 2>/dev/null || true) - [[ -n "$pid" ]] && kill -0 "$pid" 2>/dev/null + [[ -n "$pid" ]] || return 1 + sudo kill -0 "$pid" 2>/dev/null } ensure_config() { echo "Creating $CONFIG_DIR..." mkdir -p "$CONFIG_DIR" - rm -f "$CONFIG" echo "Registering Cloudflare WARP account..." usque -c "$CONFIG" register < <(yes) if [[ ! -f "$CONFIG" ]]; then @@ -44,7 +45,7 @@ remove_tun_default_routes() { while ip route show | grep -qE "^default .*dev $dev"; do ROUTE=$(ip route show | grep -E "^default .*dev $dev" | head -n1) echo "Removing route: $ROUTE" - sudo ip route del $ROUTE || true + sudo ip route del "$ROUTE" || break done } @@ -52,7 +53,7 @@ connect() { ensure_config if [[ -f "$PID_FILE" ]]; then OLD_PID=$(cat "$PID_FILE") - if kill -0 "$OLD_PID" 2>/dev/null; then + if sudo kill -0 "$OLD_PID" 2>/dev/null; then echo "usque-warp is already running (PID $OLD_PID)" exit 1 else @@ -73,12 +74,12 @@ connect() { BEFORE_IFACES=$(list_tun_ifaces) echo "Starting usque..." - sudo usque nativetun -c "$CONFIG" >"$LOG_FILE" 2>&1 & + sudo usque nativetun -c "$CONFIG" 2>&1 | sudo tee "$LOG_FILE" >/dev/null & echo $! > "$PID_FILE" echo "Waiting for MASQUE connection..." MASQUE_IP="" - for i in {1..30}; do + for _ in {1..30}; do MASQUE_IP=$(grep -oP 'MASQUE connection to \K[0-9.]+(?=:443)' "$LOG_FILE" 2>/dev/null || true) if [[ -n "$MASQUE_IP" ]]; then break @@ -87,14 +88,14 @@ connect() { done if [[ -z "$MASQUE_IP" ]]; then echo "Failed to detect MASQUE endpoint" - kill "$(cat "$PID_FILE")" 2>/dev/null || true + sudo kill "$(cat "$PID_FILE")" 2>/dev/null || true rm -f "$PID_FILE" exit 1 fi echo "Waiting for usque interface..." TUN_DEV="" - for i in {1..30}; do + for _ in {1..30}; do AFTER_IFACES=$(list_tun_ifaces) TUN_DEV=$(comm -13 <(echo "$BEFORE_IFACES" | sort) <(echo "$AFTER_IFACES" | sort) | head -n1) [[ -n "$TUN_DEV" ]] && break @@ -102,7 +103,7 @@ connect() { done if [[ -z "$TUN_DEV" ]]; then echo "Failed to detect usque interface" - kill "$(cat "$PID_FILE")" 2>/dev/null || true + sudo kill "$(cat "$PID_FILE")" 2>/dev/null || true rm -f "$PID_FILE" exit 1 fi @@ -115,7 +116,7 @@ connect() { echo "Cannot determine gateway/interface" exit 1 fi - echo "$MASQUE_IP $GATEWAY $INTERFACE" >> "$STATE_FILE" + echo "MASQUE_IP=$MASQUE_IP GATEWAY=$GATEWAY INTERFACE=$INTERFACE" >> "$STATE_FILE" echo "Allowing MASQUE endpoint outside tunnel..." sudo ip route replace \ @@ -146,7 +147,7 @@ disconnect() { fi if [[ -f "$STATE_FILE" ]]; then - MASQUE_IP=$(grep -oP '[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+' "$STATE_FILE" | head -n1 || true) + MASQUE_IP=$(grep -oP 'MASQUE_IP=\K[0-9.]+' "$STATE_FILE" || true) if [[ -n "$MASQUE_IP" ]]; then echo "Removing MASQUE route: $MASQUE_IP" sudo ip route del "$MASQUE_IP" 2>/dev/null || true @@ -156,7 +157,7 @@ disconnect() { if [[ -f "$PID_FILE" ]]; then PID=$(cat "$PID_FILE") - if kill -0 "$PID" 2>/dev/null; then + if sudo kill -0 "$PID" 2>/dev/null; then echo "Stopping usque..." sudo kill "$PID" 2>/dev/null || true fi diff --git a/modules/scripts/yazi-file-chooser/script.sh b/modules/scripts/yazi-file-chooser/script.sh index a2f9166..e02c742 100644 --- a/modules/scripts/yazi-file-chooser/script.sh +++ b/modules/scripts/yazi-file-chooser/script.sh @@ -4,9 +4,9 @@ # $4 = initial directory path # $5 = output path file (where portal expects selected paths) -multiple="$1" +# multiple="$1" directory="$2" -save="$3" +# save="$3" path="$4" out="$5" diff --git a/modules/security/gpg/default.nix b/modules/security/gpg/default.nix index cd77549..88c57d1 100644 --- a/modules/security/gpg/default.nix +++ b/modules/security/gpg/default.nix @@ -21,6 +21,11 @@ config = lib.mkIf config.security.gpg.enable { programs.gpg = { enable = true; + homedir = "${config.xdg.dataHome}/gnupg"; + }; + + home.sessionVariables = { + GNUPGHOME = config.programs.gpg.homedir; }; services.gpg-agent = { diff --git a/modules/security/ssh/default.nix b/modules/security/ssh/default.nix index c616677..9b89deb 100644 --- a/modules/security/ssh/default.nix +++ b/modules/security/ssh/default.nix @@ -16,6 +16,12 @@ default = config.programs.ssh.package; description = "The ssh package to use."; }; + + extraGopassKeys = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + description = "Additional SSH keys to load from the gopass store (entries under ssh/), in addition to the git platform keys."; + }; }; config = lib.mkIf config.security.ssh.enable { |
