commit - b614376fa8156d2ebee9daeda7069ace5c890043
commit + 4af61d4412a45612c07e0915bcae9f78a32e9c65
blob - /dev/null
blob + 295ce4da959fdad1d56c9f880bee60a753ca3688 (mode 644)
--- /dev/null
+++ system/home.scm
+;; system/home.scm
+;;
+;; Guix Home — usuario richard (Nitro 5)
+;; Gestiona .bashrc, gpg-agent.conf y paquetes de usuario.
+;;
+;; Aplicar después de instalar el sistema:
+;; guix home reconfigure system/home.scm
+;;
+;; Primera vez (en la instalación):
+;; guix home init system/home.scm
+
+(use-modules
+ (gnu home)
+ (gnu home services)
+ (gnu home services shells)
+ (gnu packages)
+ (guix gexp))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Contenido de ~/.bashrc — bloque YubiKey / gpg-agent
+;; ══════════════════════════════════════════════════════════════════
+
+(define %yubikey-bashrc
+ (plain-file "yubikey-gpg-agent"
+ "\
+# ── YubiKey: gpg-agent como agente SSH ──────────────────────────────
+# Necesario para firmar commits y autenticar SSH con la llave del YubiKey.
+export GPG_TTY=$(tty)
+export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
+export DISPLAY=${DISPLAY:-:0}
+export WAYLAND_DISPLAY=${WAYLAND_DISPLAY:-wayland-0}
+gpgconf --launch gpg-agent
+
+# Resetea gpg-agent y refresca el contexto de pinentry.
+# Correr si GPG o SSH falla tras desconectar/reconectar el YubiKey.
+yubico() {
+ echo \"Reiniciando gpg-agent...\"
+ gpgconf --kill gpg-agent
+ export GPG_TTY=$(tty)
+ export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
+ export DISPLAY=${DISPLAY:-:0}
+ export WAYLAND_DISPLAY=${WAYLAND_DISPLAY:-wayland-0}
+ gpgconf --launch gpg-agent
+ # Notifica al nuevo agente el TTY/display para que pinentry funcione en SSH
+ gpg-connect-agent updatestartuptty /bye &>/dev/null
+ if ssh-add -L &>/dev/null; then
+ echo \"OK — YubiKey lista\"
+ else
+ echo \"Error: no se detecta la clave. ¿Está conectada la YubiKey?\"
+ fi
+}
+"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; ~/.gnupg/gpg-agent.conf
+;; ══════════════════════════════════════════════════════════════════
+
+(define %gpg-agent-conf
+ (plain-file "gpg-agent.conf"
+ "\
+# Habilita soporte SSH — SSH_AUTH_SOCK apunta al socket de gpg-agent
+enable-ssh-support
+
+# Tiempo de caché del PIN en segundos (10 min / 2 h máximo)
+default-cache-ttl 600
+max-cache-ttl 7200
+
+# pinentry-qt: diálogo gráfico para KDE Plasma
+# gpg-agent lo localiza via PATH del perfil de usuario
+pinentry-program pinentry-qt
+"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Home environment
+;; ══════════════════════════════════════════════════════════════════
+
+(home-environment
+
+ ;; ── Paquetes de usuario ────────────────────────────────────────
+ (packages
+ (map specification->package
+ '(;; GPG / YubiKey
+ "gnupg"
+ "pinentry-qt" ; diálogo PIN para KDE Plasma
+ "openssh" ; ssh, ssh-add, ssh-keygen
+
+ ;; Herramientas de desarrollo
+ "git"
+ "neovim"
+ "python"
+
+ ;; Diagnóstico GPU
+ "mesa-utils" ; glxinfo, glxgears
+ "vulkan-tools"))) ; vulkaninfo
+
+ ;; ── Servicios ─────────────────────────────────────────────────
+ (services
+ (list
+
+ ;; ── bash: YubiKey/gpg-agent ─────────────────────────────
+ (service home-bash-service-type
+ (home-bash-configuration
+ (bashrc (list %yubikey-bashrc))))
+
+ ;; ── gpg-agent.conf ──────────────────────────────────────
+ (service home-files-service-type
+ `((".gnupg/gpg-agent.conf" ,%gpg-agent-conf))))))