nix-files/TODO.md

136 lines
7.5 KiB
Markdown
Raw Normal View History

2023-05-26 05:58:08 +00:00
## BUGS
2023-12-13 17:41:31 +00:00
- nixpkgs date is incorrect (1970.01.01...)
- ringer (i.e. dino incoming call) doesn't prevent moby from sleeping
- `nix` operations from lappy hang when `desko` is unreachable
- could at least direct the cache to `http://desko-hn:5001`
2024-01-31 16:28:56 +00:00
- entering the wrong password in unl0kr hangs the TTY
2023-05-26 05:58:08 +00:00
2023-05-16 11:24:34 +00:00
## REFACTORING:
2023-06-27 21:45:30 +00:00
2023-11-23 03:56:00 +00:00
- fold hosts/common/home/ssh.nix -> hosts/common/users/colin.nix
2023-05-13 10:04:46 +00:00
### sops/secrets
- rework secrets to leverage `sane.fs`
- remove sops activation script as it's covered by my systemd sane.fs impl
2023-05-13 10:04:46 +00:00
### roles
- allow any host to take the role of `uninsane.org`
- will make it easier to test new services?
2023-05-13 10:04:46 +00:00
2023-05-15 00:42:39 +00:00
### upstreaming
- split out a sxmo module usable by NUR consumers
2023-05-26 21:04:12 +00:00
- bump nodejs version in lemmy-ui
2023-05-15 00:42:39 +00:00
- add updateScripts to all my packages in nixpkgs
- fix lightdm-mobile-greeter for newer libhandy
- REVIEW/integrate jellyfin dataDir config: <https://github.com/NixOS/nixpkgs/pull/233617>
2023-05-15 00:42:39 +00:00
2023-08-28 09:36:11 +00:00
#### upstreaming to non-nixpkgs repos
- gtk: build schemas even on cross compilation: <https://github.com/NixOS/nixpkgs/pull/247844>
2023-05-15 00:36:25 +00:00
2023-05-16 11:24:34 +00:00
## IMPROVEMENTS:
2023-05-14 02:08:09 +00:00
### security/resilience
- validate duplicity backups!
- encrypt more ~ dirs (~/archives, ~/records, ..?)
- best to do this after i know for sure i have good backups
- port all sane.programs to be sandboxed
2024-01-31 16:28:56 +00:00
- enforce that all `environment.packages` has a sandbox profile (or explicitly opts out)
- integrate `xdg-open` with the sandbox profiles
2024-01-23 16:41:06 +00:00
- xdg-open can run as a highly-permissioned service, fielding requests.
2024-01-31 16:28:56 +00:00
- when it determines the handler, it can enforce the sandbox profile on that handler's behalf,
2024-01-23 16:41:06 +00:00
ensuring that anything launched with xdg-open is lowly-permissioned.
- then, the actual desktop can be permissioned *lower*. e.g. no access to ~/.ssh, even in nautilus.
`xdg-open terminal` would grant a high-permission interactive terminal, for doing high-permissioned things.
- i think there's already a xdg-open dbus equivalent in gnome. search "firejail URL issue"
2024-01-31 16:28:56 +00:00
- ALTERNATIVELY:
1. compute the closure of each program and its `suggestedPrograms`
2. jump into a sandbox for the above
3. launch some program which fields requests and passes them to xdg-open
4. launch the original program we seek to sandbox in a _nested_ sandbox, of just its own files, but with xdg-open aliased to forward requests to the proxy.
- i don't know how exactly the proxy works: `mkfifo`? a TCP socket that traverses a network namespace? there's some complexity here.
- this is sort of just a more sophisticated version of the above.
- computing sandbox unions is probably far more difficult than it appears. e.g. what to do when a `bwrap` program wishes to call a `landlock` program? how is that outer scope to be sandboxed? my sandboxes are already frail enough that making them dynamic like this will surely cause unpredictable breakages.
- lock down dbus calls within the sandbox
- otherwise anyone can `systemd-run --user ...` to potentially escape a sandbox
- <https://github.com/flatpak/xdg-dbus-proxy>
2024-01-22 02:04:32 +00:00
- remove `.ssh` access from Firefox!
- limit access to `~/private/knowledge/secrets` through an agent that requires GUI approval, so a firefox exploit can't steal all my logins
- make dconf stuff less monolithic
- i.e. per-app dconf profiles for those which need it. possible static config.
2023-05-14 02:08:09 +00:00
- canaries for important services
- e.g. daily email checks; daily backup checks
- integrate `nix check` into Gitea actions?
2023-05-13 10:04:46 +00:00
2023-05-15 00:36:25 +00:00
### user experience
- install apps:
- display QR codes for WiFi endpoints: <https://linuxphoneapps.org/apps/noappid.wisperwind.wifi2qr/>
2023-11-13 23:53:15 +00:00
- shopping list (not in nixpkgs): <https://linuxphoneapps.org/apps/ro.hume.cosmin.shoppinglist/>
2023-11-13 00:14:21 +00:00
- offline Wikipedia (or, add to `wike`)
- offline docs viewer (gtk): <https://github.com/workbenchdev/Biblioteca>
2023-11-13 23:53:15 +00:00
- some type of games manager/launcher
- Gnome Highscore (retro games)?: <https://gitlab.gnome.org/World/highscore>
- better maps for mobile (Osmin (QtQuick)? Pure Maps (Qt/Kirigami)? Gnome Maps is improved in 45)
- note-taking app: <https://linuxphoneapps.org/categories/note-taking/>
- OSK overlay specifically for mobile gaming
- i.e. mock joysticks, for use with SuperTux and SuperTuxKart
- install mobile-friendly games:
2023-11-14 03:36:15 +00:00
- Shattered Pixel Dungeon (nixpkgs `shattered-pixel-dungeon`; doesn't cross-compile b/c openjdk/libIDL) <https://github.com/ebolalex/shattered-pixel-dungeon>
2023-11-13 23:53:15 +00:00
- UnCiv (Civ V clone; nixpkgs `unciv`; doesn't cross-compile): <https://github.com/yairm210/UnCiv>
- Simon Tatham's Puzzle Collection (not in nixpkgs) <https://git.tartarus.org/?p=simon/puzzles.git>
- Shootin Stars (Godot; not in nixpkgs) <https://gitlab.com/greenbeast/shootin-stars>
2023-12-07 10:38:44 +00:00
- numberlink (generic name for Flow Free). not packaged in Nix
- Neverball (https://neverball.org/screenshots.php). nix: as `neverball`
2024-02-05 21:46:09 +00:00
- blurble (https://linuxphoneapps.org/games/app.drey.blurble/). nix: not as of 2024-02-05
2023-11-13 00:14:21 +00:00
#### moby
- fix cpuidle (gets better power consumption): <https://xnux.eu/log/077.html>
2023-09-11 01:30:29 +00:00
- SwayNC:
- don't show MPRIS if no players detected
- this is a problem of playerctld, i guess
- add option to change audio output
2023-09-13 10:14:07 +00:00
- fix colors (red alert) to match overall theme
2023-08-22 08:53:55 +00:00
- moby: tune GPS
- run only geoclue, and not gpsd, to save power?
- tune QGPS setting in eg25-control, for less jitter?
- direct mepo to prefer gpsd, with fallback to geoclue, for better accuracy?
- configure geoclue to do some smoothing?
- manually do smoothing, as some layer between mepo and geoclue/gpsd?
- moby: show battery state on ssh login
2023-05-15 00:36:25 +00:00
- moby: improve gPodder launch time
2023-07-02 03:00:46 +00:00
- moby: theme GTK apps (i.e. non-adwaita styles)
- especially, make the menubar collapsible
2023-07-03 05:08:26 +00:00
- try Gradience tool specifically for theming adwaita? <https://linuxphoneapps.org/apps/com.github.gradienceteam.gradience/>
- phog: remove the gnome-shell runtime dependency to save hella closure size
2023-09-11 01:30:29 +00:00
#### non-moby
2023-11-10 17:34:15 +00:00
- RSS: integrate a paywall bypass
- e.g. self-hosted [ladder](https://github.com/everywall/ladder) (like 12ft.io)
2023-09-11 01:30:29 +00:00
- neovim: set up language server (lsp; rnix-lsp; nvim-lspconfig)
- Helix: make copy-to-system clipboard be the default
- firefox/librewolf: persist history
- just not cookies or tabs
2023-05-15 00:38:32 +00:00
- package Nix/NixOS docs for Zeal
- install [doc-browser](https://github.com/qwfy/doc-browser)
- this supports both dash (zeal) *and* the datasets from <https://devdocs.io> (which includes nix!)
- install [devhelp](https://wiki.gnome.org/Apps/Devhelp) (gnome)
2023-05-17 00:26:18 +00:00
- have xdg-open parse `<repo:...> URIs (or adjust them so that it _can_ parse)
- sane-bt-search: show details like 5.1 vs stereo, h264 vs h265
- maybe just color these "keywords" in all search results?
2023-07-02 02:54:07 +00:00
- uninsane.org: make URLs relative to allow local use (and as offline homepage)
2023-07-01 00:57:36 +00:00
- email: fix so that local mail doesn't go to junk
- git sendmail flow adds the DKIM signatures, but gets delivered locally w/o having the sig checked, so goes into Junk
- could change junk filter from "no DKIM success" to explicit "DKIM failed"
2023-05-15 00:36:25 +00:00
2023-05-13 12:52:45 +00:00
### perf
- debug nixos-rebuild times
- i bet sane.programs adds a LOT of time, with how it automatically creates an attrs for EVERY package in nixpkgs.
2023-07-21 09:13:15 +00:00
- add `pkgs.impure-cached.<foo>` package set to build things with ccache enabled
- every package here can be auto-generated, and marked with some env var so that it doesn't pollute the pure package set
- would be super handy for package prototyping!
2023-12-13 17:41:31 +00:00
- fix desko so it doesn't dispatch so many build jobs to servo by default
2023-05-13 10:04:46 +00:00
2023-05-16 11:24:34 +00:00
## NEW FEATURES:
2023-05-13 10:04:46 +00:00
- migrate MAME cabinet to nix
- boot it from PXE from servo?
2023-05-17 08:49:06 +00:00
- enable IPv6