Commit Diff


commit - 9e74f4c6b993fae893b2a32e1f21efa363e99828
commit + fb87d3c1aa3ed23158a3842443bdd594b71bff4c
blob - /dev/null
blob + 4ba4b2e0f87e19942ddfd11137c8880e24853d71 (mode 644)
--- /dev/null
+++ system/channels.scm
@@ -0,0 +1,28 @@
+;; ~/.config/guix/channels.scm
+;;
+;; Canales de Guix para el Nitro 5
+;; Incluye el canal oficial + nonguix para kernel no-libre y NVIDIA
+;; + canal personal con paquetes propios (Mullvad VPN, Zen Browser, etc.)
+
+(list
+  ;; Canal oficial de GNU Guix
+  (channel
+    (name 'guix)
+    (url "https://git.savannah.gnu.org/git/guix.git"))
+
+  ;; nonguix: kernel Linux no-libre, firmware, NVIDIA drivers
+  ;; NO menciones este canal en canales oficiales de Guix (es su política)
+  (channel
+    (name 'nonguix)
+    (url "https://gitlab.com/nonguix/nonguix")
+    (introduction
+      (make-channel-introduction
+        "897c1a470da759236cc11798f4e0a5f7d4d59fbc"
+        (openpgp-fingerprint
+          "2A39 3FFF 68F4 EF7A 3D29  12AF 6F51 20A0 22FB B2D5"))))
+
+  ;; Canal personal: paquetes binarios (Mullvad VPN, Zen Browser, etc.)
+  (channel
+    (name 'richard)
+    (url "https://codeberg.org/Richard7987/guix-channel")
+    (branch "main")))
blob - /dev/null
blob + 910721b1cee6bdb5547794a993832141c966a782 (mode 644)
--- /dev/null
+++ system/config.scm
@@ -0,0 +1,346 @@
+;; /etc/config.scm
+;;
+;; Configuración GNU Guix — Acer Nitro 5
+;; Intel UHD 630 (PCI:0:2:0) + GTX 1050 3GB Max-Q (PCI:1:0:0)
+;; PRIME Render Offload | KDE Plasma | nonguix
+
+(use-modules
+  ;; Base
+  (gnu)
+  (gnu system)
+  (gnu system nss)
+  ;; Servicios
+  (gnu services)
+  (gnu services base)
+  (gnu services desktop)
+  (gnu services xorg)
+  (gnu services networking)
+  (gnu services security-token)   ; pcscd para YubiKey
+  (gnu services nftables)         ; firewall
+  ;; Paquetes auxiliares para xorg
+  (gnu packages xorg)
+  ;; nonguix — kernel no-libre + NVIDIA
+  (nongnu packages linux)
+  (nongnu packages nvidia)
+  (nongnu system linux-initrd)
+  ;; Canal personal — Mullvad VPN
+  (richard services mullvad))
+
+;; ══════════════════════════════════════════════════════════════════
+;; NVIDIA — graft y configuración PRIME
+;; ══════════════════════════════════════════════════════════════════
+
+;; Reemplaza mesa con nvidia para que libglx funcione correctamente
+(define transform
+  (options->transformation
+   '((with-graft . "mesa=nvda"))))
+
+;; Xorg: Intel/modesetting como primario, NVIDIA crea GPU screen
+;; automáticamente para PRIME render offload
+(define %prime-xorg-config
+  "Section \"ServerLayout\"
+    Identifier     \"layout\"
+    Screen      0  \"intel\"
+    Option         \"AllowNVIDIAGPUScreens\"
+  EndSection
+
+  Section \"Device\"
+    Identifier  \"intel\"
+    Driver      \"modesetting\"
+    BusID       \"PCI:0:2:0\"
+  EndSection
+
+  Section \"Screen\"
+    Identifier  \"intel\"
+    Device      \"intel\"
+  EndSection
+
+  Section \"Device\"
+    Identifier  \"nvidia\"
+    Driver      \"nvidia\"
+    BusID       \"PCI:1:0:0\"
+  EndSection")
+
+;; ══════════════════════════════════════════════════════════════════
+;; Firewall — nftables (stateful, política drop en input)
+;; ══════════════════════════════════════════════════════════════════
+
+(define %nftables-ruleset
+  (plain-file "nftables.conf"
+    "#!/usr/sbin/nft -f
+
+    table inet filter {
+
+      chain input {
+        type filter hook input priority 0; policy drop;
+
+        # Conexiones establecidas y relacionadas
+        ct state established,related accept
+
+        # Loopback — siempre permitir
+        iif \"lo\" accept
+
+        # Descartar paquetes inválidos
+        ct state invalid drop
+
+        # ICMP (ping) — IPv4 e IPv6
+        ip  protocol icmp     accept
+        ip6 nexthdr  icmpv6   accept
+
+        # Descarta todo lo demás (política drop del chain)
+      }
+
+      chain forward {
+        type filter hook forward priority 0; policy drop;
+      }
+
+      chain output {
+        type filter hook output priority 0; policy accept;
+      }
+    }"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Sistema operativo
+;; ══════════════════════════════════════════════════════════════════
+
+(operating-system
+  (host-name "nitro")
+  (timezone  "America/Mexico_City")
+  (locale    "es_MX.utf8")
+
+  ;; ── Kernel no-libre ─────────────────────────────────────────────
+  ;; Necesario para: drivers NVIDIA, WiFi Intel Killer/AX, microcódigo
+  (kernel         linux)
+  (initrd         microcode-initrd)
+  (firmware       (list linux-firmware))
+
+  (kernel-arguments
+    (append
+      '("modprobe.blacklist=nouveau"  ; evitar conflicto nouveau/nvidia
+        "nvidia-drm.modeset=1"        ; requerido para Wayland (futuro)
+        "quiet")                      ; boot silencioso
+      %default-kernel-arguments))
+
+  ;; Cargar módulos NVIDIA al arranque
+  (kernel-loadable-modules (list nvidia-driver))
+
+  ;; ── Bootloader ──────────────────────────────────────────────────
+  (bootloader
+    (bootloader-configuration
+      (bootloader grub-efi-bootloader)
+      (targets    '("/boot/efi"))))
+
+  ;; ── Particiones ─────────────────────────────────────────────────
+  ;; Ajusta las etiquetas según las particiones que crees en la instalación.
+  ;; Recomendado: durante el installer usa "guix-root" y "EFI" como labels.
+  ;; Verifica con: lsblk -f
+  (file-systems
+    (append
+      (list
+        (file-system
+          (mount-point "/")
+          (device      (file-system-label "guix-root"))
+          (type        "ext4"))
+        (file-system
+          (mount-point "/boot/efi")
+          (device      (file-system-label "EFI"))
+          (type        "vfat")))
+      %base-file-systems))
+
+  ;; ── Usuario ─────────────────────────────────────────────────────
+  (users
+    (cons
+      (user-account
+        (name                "richard")
+        (comment             "Richard")
+        (group               "users")
+        (home-directory      "/home/richard")
+        (supplementary-groups
+          '("wheel"      ; privilegios sudo
+            "netdev"     ; gestión de red
+            "audio"
+            "video"
+            "input"      ; teclado/ratón (importante para Wayland futuro)
+            "lp"         ; impresoras
+            "plugdev"))) ; dispositivos USB — YubiKey
+      %base-user-accounts))
+
+  ;; ── Paquetes del sistema ─────────────────────────────────────────
+  (packages
+    (append
+      (list
+        ;; ── Sistema base ──────────────────────────────────────────
+        (specification->package "nss-certs")        ; certificados HTTPS
+        (specification->package "git")
+        (specification->package "neovim")
+        (specification->package "curl")
+        (specification->package "wget")
+        (specification->package "htop")
+
+        ;; ── Diagnóstico GPU ───────────────────────────────────────
+        ;; Útiles para verificar que PRIME funciona correctamente
+        (specification->package "mesa-utils")       ; glxinfo, glxgears
+        (specification->package "vulkan-tools")     ; vulkaninfo
+
+        ;; ── Ofimática y escritura ─────────────────────────────────
+        (specification->package "libreoffice")
+        (specification->package "texstudio")
+        ;; Distribución LaTeX completa (pesada ~2GB, ajusta si prefieres
+        ;; texlive-base + paquetes específicos)
+        (specification->package "texlive")
+        ;; Diccionarios para corrector ortográfico (LibreOffice, TeXstudio)
+        (specification->package "hunspell-dict-es") ; español
+        (specification->package "aspell-dict-es")
+
+        ;; ── Python científico ─────────────────────────────────────
+        (specification->package "python")
+        (specification->package "python-numpy")
+        (specification->package "python-scipy")
+        (specification->package "python-matplotlib")
+        (specification->package "python-sympy")
+        (specification->package "python-jupyterlab")
+        (specification->package "python-plotly")
+        ;; VTK: base para mayavi y pyvista
+        (specification->package "vtk")
+        (specification->package "python-vtk")
+        ;; NOTA: mayavi y pyvista no están empaquetados en Guix oficial.
+        ;; Instálalos en un entorno aislado después de la instalación:
+        ;;   guix shell python python-vtk python-numpy -- pip install mayavi pyvista
+        ;; Ver sección "Post-instalación" al final de este archivo.
+
+        ;; ── SageMath ──────────────────────────────────────────────
+        (specification->package "sagemath")
+
+        ;; ── Blender (se lanzará con PRIME via wrapper) ────────────
+        (specification->package "blender")
+
+        ;; ── VPN — wireguard-tools (diagnóstico manual de túneles) ────
+        ;; mullvad-vpn se instala automáticamente vía mullvad-service
+        (specification->package "wireguard-tools")
+
+        ;; ── YubiKey ───────────────────────────────────────────────
+        (specification->package "yubikey-personalization")
+        (specification->package "yubikey-personalization-gui")
+        (specification->package "yubico-piv-tool")
+        (specification->package "libfido2")
+        (specification->package "ccid")             ; lector de smartcard
+
+        ;; ── Kleopatra (gestión GPG) ───────────────────────────────
+        (specification->package "kleopatra")
+
+        ;; ── Flatpak — para Zen Browser ────────────────────────────
+        ;; Zen Browser no está en los canales de Guix todavía.
+        ;; Después de instalar el sistema:
+        ;;   flatpak remote-add --if-not-exists flathub \
+        ;;     https://dl.flathub.org/repo/flathub.flatpakrepo
+        ;;   flatpak install flathub app.zen_browser.zen
+        (specification->package "flatpak"))
+
+      %base-packages))
+
+  ;; ── Servicios ───────────────────────────────────────────────────
+  (services
+    (cons*
+      ;; ── NVIDIA ──────────────────────────────────────────────────
+      ;; udev rules para que /dev/nvidia* tenga permisos correctos
+      (simple-service 'nvidia-udev udev-service-type
+                      (list nvidia-driver))
+      ;; Cargar módulos NVIDIA en el orden correcto
+      (service kernel-module-loader-service-type
+               '("nvidia"
+                 "nvidia_modeset"
+                 "nvidia_uvm"
+                 "nvidia_drm"))
+
+      ;; ── KDE Plasma ──────────────────────────────────────────────
+      (service plasma-desktop-service-type)
+
+      ;; SDDM con Xorg configurado para PRIME render offload
+      (service sddm-service-type
+               (sddm-configuration
+                 (xorg-configuration
+                   (xorg-configuration
+                     ;; Módulos: incluir nvidia + módulos default
+                     (modules (cons* nvidia-driver %default-xorg-modules))
+                     ;; Aplicar el graft mesa→nvidia al servidor Xorg
+                     (server  (transform xorg-server))
+                     ;; NO se pone drivers '("nvidia") aquí —
+                     ;; modesetting maneja la pantalla interna (iGPU)
+                     ;; NVIDIA crea automáticamente un GPU screen secundario
+                     (extra-config (list %prime-xorg-config))))))
+
+      ;; ── Mullvad VPN — daemon ────────────────────────────────────
+      ;; Instala mullvad-vpn y arranca mullvad-daemon al boot.
+      ;; Nota: mullvad-daemon modifica nftables para su killswitch;
+      ;; el ruleset de abajo aplica primero y el daemon añade sus reglas
+      ;; encima. Si el killswitch bloquea tráfico inesperado, revisa:
+      ;;   herd status mullvad
+      ;;   mullvad status
+      (mullvad-service)
+
+      ;; ── YubiKey — pcscd (daemon de smartcard) ───────────────────
+      (service pcscd-service-type)
+
+      ;; ── Firewall — nftables ──────────────────────────────────────
+      (service nftables-service-type
+               (nftables-configuration
+                 (ruleset %nftables-ruleset)))
+
+      ;; ── %desktop-services base ───────────────────────────────────
+      ;; Incluye: NetworkManager, wpa-supplicant, udisks2,
+      ;;          polkit, dbus, colord, avahi, etc.
+      ;; Se elimina GDM porque usamos SDDM
+      (modify-services %desktop-services
+        (delete gdm-service-type)))))
+
+;; ══════════════════════════════════════════════════════════════════
+;; POST-INSTALACIÓN (comandos a correr después de instalar)
+;; ══════════════════════════════════════════════════════════════════
+;;
+;; 1. VERIFICAR PRIME:
+;;    glxinfo | grep "OpenGL renderer"
+;;    → debe mostrar Intel / Mesa
+;;
+;;    __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia \
+;;    glxinfo | grep "OpenGL renderer"
+;;    → debe mostrar NVIDIA GTX 1050
+;;
+;; 2. BLENDER CON NVIDIA (crear wrapper):
+;;    Crea ~/.local/share/applications/blender-nvidia.desktop:
+;;
+;;    [Desktop Entry]
+;;    Name=Blender (NVIDIA)
+;;    Exec=env __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender
+;;    Icon=blender
+;;    Type=Application
+;;    Categories=Graphics;3DGraphics;
+;;
+;;    O agrega a tu .bashrc / .zshrc:
+;;    alias blender-nvidia='__NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender'
+;;
+;; 3. ZEN BROWSER vía canal personal (richard):
+;;    Después de actualizar canales con guix pull, instalar:
+;;      guix install zen-browser
+;;    O añadir zen-browser a la lista de paquetes del sistema.
+;;
+;; 4. MULLVAD VPN (el daemon arranca automáticamente vía Shepherd):
+;;    a) Inicia sesión con tu número de cuenta:
+;;         mullvad account login XXXXXXXXXX
+;;    b) Selecciona servidor (opcional — auto conecta si no):
+;;         mullvad relay set location mx   # México
+;;    c) Conecta:
+;;         mullvad connect
+;;    d) Verifica estado:
+;;         mullvad status
+;;         herd status mullvad
+;;    e) Reiniciar daemon si es necesario:
+;;         herd restart mullvad
+;;
+;; 5. MAYAVI + PYVISTA (entorno aislado, no contaminan el sistema):
+;;    guix shell python python-vtk python-numpy python-scipy \
+;;      --pure -- pip install mayavi pyvista
+;;    Para uso frecuente, crea un manifest.scm dedicado.
+;;
+;; 6. YUBKEY — GPG/SSH (tu config ya existe):
+;;    gpg --card-status   → verifica que pcscd ve la llave
+;;    ssh-add -L          → verifica el agente SSH via YubiKey