commit - 9e74f4c6b993fae893b2a32e1f21efa363e99828
commit + fb87d3c1aa3ed23158a3842443bdd594b71bff4c
blob - /dev/null
blob + 4ba4b2e0f87e19942ddfd11137c8880e24853d71 (mode 644)
--- /dev/null
+++ system/channels.scm
+;; ~/.config/guix/channels.scm
+;;
+;; Canales de Guix para el Nitro 5
+;; Incluye el canal oficial + nonguix para kernel no-libre y NVIDIA
+;; + canal personal con paquetes propios (Mullvad VPN, Zen Browser, etc.)
+
+(list
+ ;; Canal oficial de GNU Guix
+ (channel
+ (name 'guix)
+ (url "https://git.savannah.gnu.org/git/guix.git"))
+
+ ;; nonguix: kernel Linux no-libre, firmware, NVIDIA drivers
+ ;; NO menciones este canal en canales oficiales de Guix (es su política)
+ (channel
+ (name 'nonguix)
+ (url "https://gitlab.com/nonguix/nonguix")
+ (introduction
+ (make-channel-introduction
+ "897c1a470da759236cc11798f4e0a5f7d4d59fbc"
+ (openpgp-fingerprint
+ "2A39 3FFF 68F4 EF7A 3D29 12AF 6F51 20A0 22FB B2D5"))))
+
+ ;; Canal personal: paquetes binarios (Mullvad VPN, Zen Browser, etc.)
+ (channel
+ (name 'richard)
+ (url "https://codeberg.org/Richard7987/guix-channel")
+ (branch "main")))
blob - /dev/null
blob + 910721b1cee6bdb5547794a993832141c966a782 (mode 644)
--- /dev/null
+++ system/config.scm
+;; /etc/config.scm
+;;
+;; Configuración GNU Guix — Acer Nitro 5
+;; Intel UHD 630 (PCI:0:2:0) + GTX 1050 3GB Max-Q (PCI:1:0:0)
+;; PRIME Render Offload | KDE Plasma | nonguix
+
+(use-modules
+ ;; Base
+ (gnu)
+ (gnu system)
+ (gnu system nss)
+ ;; Servicios
+ (gnu services)
+ (gnu services base)
+ (gnu services desktop)
+ (gnu services xorg)
+ (gnu services networking)
+ (gnu services security-token) ; pcscd para YubiKey
+ (gnu services nftables) ; firewall
+ ;; Paquetes auxiliares para xorg
+ (gnu packages xorg)
+ ;; nonguix — kernel no-libre + NVIDIA
+ (nongnu packages linux)
+ (nongnu packages nvidia)
+ (nongnu system linux-initrd)
+ ;; Canal personal — Mullvad VPN
+ (richard services mullvad))
+
+;; ══════════════════════════════════════════════════════════════════
+;; NVIDIA — graft y configuración PRIME
+;; ══════════════════════════════════════════════════════════════════
+
+;; Reemplaza mesa con nvidia para que libglx funcione correctamente
+(define transform
+ (options->transformation
+ '((with-graft . "mesa=nvda"))))
+
+;; Xorg: Intel/modesetting como primario, NVIDIA crea GPU screen
+;; automáticamente para PRIME render offload
+(define %prime-xorg-config
+ "Section \"ServerLayout\"
+ Identifier \"layout\"
+ Screen 0 \"intel\"
+ Option \"AllowNVIDIAGPUScreens\"
+ EndSection
+
+ Section \"Device\"
+ Identifier \"intel\"
+ Driver \"modesetting\"
+ BusID \"PCI:0:2:0\"
+ EndSection
+
+ Section \"Screen\"
+ Identifier \"intel\"
+ Device \"intel\"
+ EndSection
+
+ Section \"Device\"
+ Identifier \"nvidia\"
+ Driver \"nvidia\"
+ BusID \"PCI:1:0:0\"
+ EndSection")
+
+;; ══════════════════════════════════════════════════════════════════
+;; Firewall — nftables (stateful, política drop en input)
+;; ══════════════════════════════════════════════════════════════════
+
+(define %nftables-ruleset
+ (plain-file "nftables.conf"
+ "#!/usr/sbin/nft -f
+
+ table inet filter {
+
+ chain input {
+ type filter hook input priority 0; policy drop;
+
+ # Conexiones establecidas y relacionadas
+ ct state established,related accept
+
+ # Loopback — siempre permitir
+ iif \"lo\" accept
+
+ # Descartar paquetes inválidos
+ ct state invalid drop
+
+ # ICMP (ping) — IPv4 e IPv6
+ ip protocol icmp accept
+ ip6 nexthdr icmpv6 accept
+
+ # Descarta todo lo demás (política drop del chain)
+ }
+
+ chain forward {
+ type filter hook forward priority 0; policy drop;
+ }
+
+ chain output {
+ type filter hook output priority 0; policy accept;
+ }
+ }"))
+
+;; ══════════════════════════════════════════════════════════════════
+;; Sistema operativo
+;; ══════════════════════════════════════════════════════════════════
+
+(operating-system
+ (host-name "nitro")
+ (timezone "America/Mexico_City")
+ (locale "es_MX.utf8")
+
+ ;; ── Kernel no-libre ─────────────────────────────────────────────
+ ;; Necesario para: drivers NVIDIA, WiFi Intel Killer/AX, microcódigo
+ (kernel linux)
+ (initrd microcode-initrd)
+ (firmware (list linux-firmware))
+
+ (kernel-arguments
+ (append
+ '("modprobe.blacklist=nouveau" ; evitar conflicto nouveau/nvidia
+ "nvidia-drm.modeset=1" ; requerido para Wayland (futuro)
+ "quiet") ; boot silencioso
+ %default-kernel-arguments))
+
+ ;; Cargar módulos NVIDIA al arranque
+ (kernel-loadable-modules (list nvidia-driver))
+
+ ;; ── Bootloader ──────────────────────────────────────────────────
+ (bootloader
+ (bootloader-configuration
+ (bootloader grub-efi-bootloader)
+ (targets '("/boot/efi"))))
+
+ ;; ── Particiones ─────────────────────────────────────────────────
+ ;; Ajusta las etiquetas según las particiones que crees en la instalación.
+ ;; Recomendado: durante el installer usa "guix-root" y "EFI" como labels.
+ ;; Verifica con: lsblk -f
+ (file-systems
+ (append
+ (list
+ (file-system
+ (mount-point "/")
+ (device (file-system-label "guix-root"))
+ (type "ext4"))
+ (file-system
+ (mount-point "/boot/efi")
+ (device (file-system-label "EFI"))
+ (type "vfat")))
+ %base-file-systems))
+
+ ;; ── Usuario ─────────────────────────────────────────────────────
+ (users
+ (cons
+ (user-account
+ (name "richard")
+ (comment "Richard")
+ (group "users")
+ (home-directory "/home/richard")
+ (supplementary-groups
+ '("wheel" ; privilegios sudo
+ "netdev" ; gestión de red
+ "audio"
+ "video"
+ "input" ; teclado/ratón (importante para Wayland futuro)
+ "lp" ; impresoras
+ "plugdev"))) ; dispositivos USB — YubiKey
+ %base-user-accounts))
+
+ ;; ── Paquetes del sistema ─────────────────────────────────────────
+ (packages
+ (append
+ (list
+ ;; ── Sistema base ──────────────────────────────────────────
+ (specification->package "nss-certs") ; certificados HTTPS
+ (specification->package "git")
+ (specification->package "neovim")
+ (specification->package "curl")
+ (specification->package "wget")
+ (specification->package "htop")
+
+ ;; ── Diagnóstico GPU ───────────────────────────────────────
+ ;; Útiles para verificar que PRIME funciona correctamente
+ (specification->package "mesa-utils") ; glxinfo, glxgears
+ (specification->package "vulkan-tools") ; vulkaninfo
+
+ ;; ── Ofimática y escritura ─────────────────────────────────
+ (specification->package "libreoffice")
+ (specification->package "texstudio")
+ ;; Distribución LaTeX completa (pesada ~2GB, ajusta si prefieres
+ ;; texlive-base + paquetes específicos)
+ (specification->package "texlive")
+ ;; Diccionarios para corrector ortográfico (LibreOffice, TeXstudio)
+ (specification->package "hunspell-dict-es") ; español
+ (specification->package "aspell-dict-es")
+
+ ;; ── Python científico ─────────────────────────────────────
+ (specification->package "python")
+ (specification->package "python-numpy")
+ (specification->package "python-scipy")
+ (specification->package "python-matplotlib")
+ (specification->package "python-sympy")
+ (specification->package "python-jupyterlab")
+ (specification->package "python-plotly")
+ ;; VTK: base para mayavi y pyvista
+ (specification->package "vtk")
+ (specification->package "python-vtk")
+ ;; NOTA: mayavi y pyvista no están empaquetados en Guix oficial.
+ ;; Instálalos en un entorno aislado después de la instalación:
+ ;; guix shell python python-vtk python-numpy -- pip install mayavi pyvista
+ ;; Ver sección "Post-instalación" al final de este archivo.
+
+ ;; ── SageMath ──────────────────────────────────────────────
+ (specification->package "sagemath")
+
+ ;; ── Blender (se lanzará con PRIME via wrapper) ────────────
+ (specification->package "blender")
+
+ ;; ── VPN — wireguard-tools (diagnóstico manual de túneles) ────
+ ;; mullvad-vpn se instala automáticamente vía mullvad-service
+ (specification->package "wireguard-tools")
+
+ ;; ── YubiKey ───────────────────────────────────────────────
+ (specification->package "yubikey-personalization")
+ (specification->package "yubikey-personalization-gui")
+ (specification->package "yubico-piv-tool")
+ (specification->package "libfido2")
+ (specification->package "ccid") ; lector de smartcard
+
+ ;; ── Kleopatra (gestión GPG) ───────────────────────────────
+ (specification->package "kleopatra")
+
+ ;; ── Flatpak — para Zen Browser ────────────────────────────
+ ;; Zen Browser no está en los canales de Guix todavía.
+ ;; Después de instalar el sistema:
+ ;; flatpak remote-add --if-not-exists flathub \
+ ;; https://dl.flathub.org/repo/flathub.flatpakrepo
+ ;; flatpak install flathub app.zen_browser.zen
+ (specification->package "flatpak"))
+
+ %base-packages))
+
+ ;; ── Servicios ───────────────────────────────────────────────────
+ (services
+ (cons*
+ ;; ── NVIDIA ──────────────────────────────────────────────────
+ ;; udev rules para que /dev/nvidia* tenga permisos correctos
+ (simple-service 'nvidia-udev udev-service-type
+ (list nvidia-driver))
+ ;; Cargar módulos NVIDIA en el orden correcto
+ (service kernel-module-loader-service-type
+ '("nvidia"
+ "nvidia_modeset"
+ "nvidia_uvm"
+ "nvidia_drm"))
+
+ ;; ── KDE Plasma ──────────────────────────────────────────────
+ (service plasma-desktop-service-type)
+
+ ;; SDDM con Xorg configurado para PRIME render offload
+ (service sddm-service-type
+ (sddm-configuration
+ (xorg-configuration
+ (xorg-configuration
+ ;; Módulos: incluir nvidia + módulos default
+ (modules (cons* nvidia-driver %default-xorg-modules))
+ ;; Aplicar el graft mesa→nvidia al servidor Xorg
+ (server (transform xorg-server))
+ ;; NO se pone drivers '("nvidia") aquí —
+ ;; modesetting maneja la pantalla interna (iGPU)
+ ;; NVIDIA crea automáticamente un GPU screen secundario
+ (extra-config (list %prime-xorg-config))))))
+
+ ;; ── Mullvad VPN — daemon ────────────────────────────────────
+ ;; Instala mullvad-vpn y arranca mullvad-daemon al boot.
+ ;; Nota: mullvad-daemon modifica nftables para su killswitch;
+ ;; el ruleset de abajo aplica primero y el daemon añade sus reglas
+ ;; encima. Si el killswitch bloquea tráfico inesperado, revisa:
+ ;; herd status mullvad
+ ;; mullvad status
+ (mullvad-service)
+
+ ;; ── YubiKey — pcscd (daemon de smartcard) ───────────────────
+ (service pcscd-service-type)
+
+ ;; ── Firewall — nftables ──────────────────────────────────────
+ (service nftables-service-type
+ (nftables-configuration
+ (ruleset %nftables-ruleset)))
+
+ ;; ── %desktop-services base ───────────────────────────────────
+ ;; Incluye: NetworkManager, wpa-supplicant, udisks2,
+ ;; polkit, dbus, colord, avahi, etc.
+ ;; Se elimina GDM porque usamos SDDM
+ (modify-services %desktop-services
+ (delete gdm-service-type)))))
+
+;; ══════════════════════════════════════════════════════════════════
+;; POST-INSTALACIÓN (comandos a correr después de instalar)
+;; ══════════════════════════════════════════════════════════════════
+;;
+;; 1. VERIFICAR PRIME:
+;; glxinfo | grep "OpenGL renderer"
+;; → debe mostrar Intel / Mesa
+;;
+;; __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia \
+;; glxinfo | grep "OpenGL renderer"
+;; → debe mostrar NVIDIA GTX 1050
+;;
+;; 2. BLENDER CON NVIDIA (crear wrapper):
+;; Crea ~/.local/share/applications/blender-nvidia.desktop:
+;;
+;; [Desktop Entry]
+;; Name=Blender (NVIDIA)
+;; Exec=env __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender
+;; Icon=blender
+;; Type=Application
+;; Categories=Graphics;3DGraphics;
+;;
+;; O agrega a tu .bashrc / .zshrc:
+;; alias blender-nvidia='__NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender'
+;;
+;; 3. ZEN BROWSER vía canal personal (richard):
+;; Después de actualizar canales con guix pull, instalar:
+;; guix install zen-browser
+;; O añadir zen-browser a la lista de paquetes del sistema.
+;;
+;; 4. MULLVAD VPN (el daemon arranca automáticamente vía Shepherd):
+;; a) Inicia sesión con tu número de cuenta:
+;; mullvad account login XXXXXXXXXX
+;; b) Selecciona servidor (opcional — auto conecta si no):
+;; mullvad relay set location mx # México
+;; c) Conecta:
+;; mullvad connect
+;; d) Verifica estado:
+;; mullvad status
+;; herd status mullvad
+;; e) Reiniciar daemon si es necesario:
+;; herd restart mullvad
+;;
+;; 5. MAYAVI + PYVISTA (entorno aislado, no contaminan el sistema):
+;; guix shell python python-vtk python-numpy python-scipy \
+;; --pure -- pip install mayavi pyvista
+;; Para uso frecuente, crea un manifest.scm dedicado.
+;;
+;; 6. YUBKEY — GPG/SSH (tu config ya existe):
+;; gpg --card-status → verifica que pcscd ve la llave
+;; ssh-add -L → verifica el agente SSH via YubiKey