commit fb87d3c1aa3ed23158a3842443bdd594b71bff4c from: Alejandro Bernal Estrada date: Thu May 21 20:25:11 2026 UTC add: configuración del sistema Nitro 5 commit - 9e74f4c6b993fae893b2a32e1f21efa363e99828 commit + fb87d3c1aa3ed23158a3842443bdd594b71bff4c blob - /dev/null blob + 4ba4b2e0f87e19942ddfd11137c8880e24853d71 (mode 644) --- /dev/null +++ system/channels.scm @@ -0,0 +1,28 @@ +;; ~/.config/guix/channels.scm +;; +;; Canales de Guix para el Nitro 5 +;; Incluye el canal oficial + nonguix para kernel no-libre y NVIDIA +;; + canal personal con paquetes propios (Mullvad VPN, Zen Browser, etc.) + +(list + ;; Canal oficial de GNU Guix + (channel + (name 'guix) + (url "https://git.savannah.gnu.org/git/guix.git")) + + ;; nonguix: kernel Linux no-libre, firmware, NVIDIA drivers + ;; NO menciones este canal en canales oficiales de Guix (es su política) + (channel + (name 'nonguix) + (url "https://gitlab.com/nonguix/nonguix") + (introduction + (make-channel-introduction + "897c1a470da759236cc11798f4e0a5f7d4d59fbc" + (openpgp-fingerprint + "2A39 3FFF 68F4 EF7A 3D29 12AF 6F51 20A0 22FB B2D5")))) + + ;; Canal personal: paquetes binarios (Mullvad VPN, Zen Browser, etc.) + (channel + (name 'richard) + (url "https://codeberg.org/Richard7987/guix-channel") + (branch "main"))) blob - /dev/null blob + 910721b1cee6bdb5547794a993832141c966a782 (mode 644) --- /dev/null +++ system/config.scm @@ -0,0 +1,346 @@ +;; /etc/config.scm +;; +;; Configuración GNU Guix — Acer Nitro 5 +;; Intel UHD 630 (PCI:0:2:0) + GTX 1050 3GB Max-Q (PCI:1:0:0) +;; PRIME Render Offload | KDE Plasma | nonguix + +(use-modules + ;; Base + (gnu) + (gnu system) + (gnu system nss) + ;; Servicios + (gnu services) + (gnu services base) + (gnu services desktop) + (gnu services xorg) + (gnu services networking) + (gnu services security-token) ; pcscd para YubiKey + (gnu services nftables) ; firewall + ;; Paquetes auxiliares para xorg + (gnu packages xorg) + ;; nonguix — kernel no-libre + NVIDIA + (nongnu packages linux) + (nongnu packages nvidia) + (nongnu system linux-initrd) + ;; Canal personal — Mullvad VPN + (richard services mullvad)) + +;; ══════════════════════════════════════════════════════════════════ +;; NVIDIA — graft y configuración PRIME +;; ══════════════════════════════════════════════════════════════════ + +;; Reemplaza mesa con nvidia para que libglx funcione correctamente +(define transform + (options->transformation + '((with-graft . "mesa=nvda")))) + +;; Xorg: Intel/modesetting como primario, NVIDIA crea GPU screen +;; automáticamente para PRIME render offload +(define %prime-xorg-config + "Section \"ServerLayout\" + Identifier \"layout\" + Screen 0 \"intel\" + Option \"AllowNVIDIAGPUScreens\" + EndSection + + Section \"Device\" + Identifier \"intel\" + Driver \"modesetting\" + BusID \"PCI:0:2:0\" + EndSection + + Section \"Screen\" + Identifier \"intel\" + Device \"intel\" + EndSection + + Section \"Device\" + Identifier \"nvidia\" + Driver \"nvidia\" + BusID \"PCI:1:0:0\" + EndSection") + +;; ══════════════════════════════════════════════════════════════════ +;; Firewall — nftables (stateful, política drop en input) +;; ══════════════════════════════════════════════════════════════════ + +(define %nftables-ruleset + (plain-file "nftables.conf" + "#!/usr/sbin/nft -f + + table inet filter { + + chain input { + type filter hook input priority 0; policy drop; + + # Conexiones establecidas y relacionadas + ct state established,related accept + + # Loopback — siempre permitir + iif \"lo\" accept + + # Descartar paquetes inválidos + ct state invalid drop + + # ICMP (ping) — IPv4 e IPv6 + ip protocol icmp accept + ip6 nexthdr icmpv6 accept + + # Descarta todo lo demás (política drop del chain) + } + + chain forward { + type filter hook forward priority 0; policy drop; + } + + chain output { + type filter hook output priority 0; policy accept; + } + }")) + +;; ══════════════════════════════════════════════════════════════════ +;; Sistema operativo +;; ══════════════════════════════════════════════════════════════════ + +(operating-system + (host-name "nitro") + (timezone "America/Mexico_City") + (locale "es_MX.utf8") + + ;; ── Kernel no-libre ───────────────────────────────────────────── + ;; Necesario para: drivers NVIDIA, WiFi Intel Killer/AX, microcódigo + (kernel linux) + (initrd microcode-initrd) + (firmware (list linux-firmware)) + + (kernel-arguments + (append + '("modprobe.blacklist=nouveau" ; evitar conflicto nouveau/nvidia + "nvidia-drm.modeset=1" ; requerido para Wayland (futuro) + "quiet") ; boot silencioso + %default-kernel-arguments)) + + ;; Cargar módulos NVIDIA al arranque + (kernel-loadable-modules (list nvidia-driver)) + + ;; ── Bootloader ────────────────────────────────────────────────── + (bootloader + (bootloader-configuration + (bootloader grub-efi-bootloader) + (targets '("/boot/efi")))) + + ;; ── Particiones ───────────────────────────────────────────────── + ;; Ajusta las etiquetas según las particiones que crees en la instalación. + ;; Recomendado: durante el installer usa "guix-root" y "EFI" como labels. + ;; Verifica con: lsblk -f + (file-systems + (append + (list + (file-system + (mount-point "/") + (device (file-system-label "guix-root")) + (type "ext4")) + (file-system + (mount-point "/boot/efi") + (device (file-system-label "EFI")) + (type "vfat"))) + %base-file-systems)) + + ;; ── Usuario ───────────────────────────────────────────────────── + (users + (cons + (user-account + (name "richard") + (comment "Richard") + (group "users") + (home-directory "/home/richard") + (supplementary-groups + '("wheel" ; privilegios sudo + "netdev" ; gestión de red + "audio" + "video" + "input" ; teclado/ratón (importante para Wayland futuro) + "lp" ; impresoras + "plugdev"))) ; dispositivos USB — YubiKey + %base-user-accounts)) + + ;; ── Paquetes del sistema ───────────────────────────────────────── + (packages + (append + (list + ;; ── Sistema base ────────────────────────────────────────── + (specification->package "nss-certs") ; certificados HTTPS + (specification->package "git") + (specification->package "neovim") + (specification->package "curl") + (specification->package "wget") + (specification->package "htop") + + ;; ── Diagnóstico GPU ─────────────────────────────────────── + ;; Útiles para verificar que PRIME funciona correctamente + (specification->package "mesa-utils") ; glxinfo, glxgears + (specification->package "vulkan-tools") ; vulkaninfo + + ;; ── Ofimática y escritura ───────────────────────────────── + (specification->package "libreoffice") + (specification->package "texstudio") + ;; Distribución LaTeX completa (pesada ~2GB, ajusta si prefieres + ;; texlive-base + paquetes específicos) + (specification->package "texlive") + ;; Diccionarios para corrector ortográfico (LibreOffice, TeXstudio) + (specification->package "hunspell-dict-es") ; español + (specification->package "aspell-dict-es") + + ;; ── Python científico ───────────────────────────────────── + (specification->package "python") + (specification->package "python-numpy") + (specification->package "python-scipy") + (specification->package "python-matplotlib") + (specification->package "python-sympy") + (specification->package "python-jupyterlab") + (specification->package "python-plotly") + ;; VTK: base para mayavi y pyvista + (specification->package "vtk") + (specification->package "python-vtk") + ;; NOTA: mayavi y pyvista no están empaquetados en Guix oficial. + ;; Instálalos en un entorno aislado después de la instalación: + ;; guix shell python python-vtk python-numpy -- pip install mayavi pyvista + ;; Ver sección "Post-instalación" al final de este archivo. + + ;; ── SageMath ────────────────────────────────────────────── + (specification->package "sagemath") + + ;; ── Blender (se lanzará con PRIME via wrapper) ──────────── + (specification->package "blender") + + ;; ── VPN — wireguard-tools (diagnóstico manual de túneles) ──── + ;; mullvad-vpn se instala automáticamente vía mullvad-service + (specification->package "wireguard-tools") + + ;; ── YubiKey ─────────────────────────────────────────────── + (specification->package "yubikey-personalization") + (specification->package "yubikey-personalization-gui") + (specification->package "yubico-piv-tool") + (specification->package "libfido2") + (specification->package "ccid") ; lector de smartcard + + ;; ── Kleopatra (gestión GPG) ─────────────────────────────── + (specification->package "kleopatra") + + ;; ── Flatpak — para Zen Browser ──────────────────────────── + ;; Zen Browser no está en los canales de Guix todavía. + ;; Después de instalar el sistema: + ;; flatpak remote-add --if-not-exists flathub \ + ;; https://dl.flathub.org/repo/flathub.flatpakrepo + ;; flatpak install flathub app.zen_browser.zen + (specification->package "flatpak")) + + %base-packages)) + + ;; ── Servicios ─────────────────────────────────────────────────── + (services + (cons* + ;; ── NVIDIA ────────────────────────────────────────────────── + ;; udev rules para que /dev/nvidia* tenga permisos correctos + (simple-service 'nvidia-udev udev-service-type + (list nvidia-driver)) + ;; Cargar módulos NVIDIA en el orden correcto + (service kernel-module-loader-service-type + '("nvidia" + "nvidia_modeset" + "nvidia_uvm" + "nvidia_drm")) + + ;; ── KDE Plasma ────────────────────────────────────────────── + (service plasma-desktop-service-type) + + ;; SDDM con Xorg configurado para PRIME render offload + (service sddm-service-type + (sddm-configuration + (xorg-configuration + (xorg-configuration + ;; Módulos: incluir nvidia + módulos default + (modules (cons* nvidia-driver %default-xorg-modules)) + ;; Aplicar el graft mesa→nvidia al servidor Xorg + (server (transform xorg-server)) + ;; NO se pone drivers '("nvidia") aquí — + ;; modesetting maneja la pantalla interna (iGPU) + ;; NVIDIA crea automáticamente un GPU screen secundario + (extra-config (list %prime-xorg-config)))))) + + ;; ── Mullvad VPN — daemon ──────────────────────────────────── + ;; Instala mullvad-vpn y arranca mullvad-daemon al boot. + ;; Nota: mullvad-daemon modifica nftables para su killswitch; + ;; el ruleset de abajo aplica primero y el daemon añade sus reglas + ;; encima. Si el killswitch bloquea tráfico inesperado, revisa: + ;; herd status mullvad + ;; mullvad status + (mullvad-service) + + ;; ── YubiKey — pcscd (daemon de smartcard) ─────────────────── + (service pcscd-service-type) + + ;; ── Firewall — nftables ────────────────────────────────────── + (service nftables-service-type + (nftables-configuration + (ruleset %nftables-ruleset))) + + ;; ── %desktop-services base ─────────────────────────────────── + ;; Incluye: NetworkManager, wpa-supplicant, udisks2, + ;; polkit, dbus, colord, avahi, etc. + ;; Se elimina GDM porque usamos SDDM + (modify-services %desktop-services + (delete gdm-service-type))))) + +;; ══════════════════════════════════════════════════════════════════ +;; POST-INSTALACIÓN (comandos a correr después de instalar) +;; ══════════════════════════════════════════════════════════════════ +;; +;; 1. VERIFICAR PRIME: +;; glxinfo | grep "OpenGL renderer" +;; → debe mostrar Intel / Mesa +;; +;; __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia \ +;; glxinfo | grep "OpenGL renderer" +;; → debe mostrar NVIDIA GTX 1050 +;; +;; 2. BLENDER CON NVIDIA (crear wrapper): +;; Crea ~/.local/share/applications/blender-nvidia.desktop: +;; +;; [Desktop Entry] +;; Name=Blender (NVIDIA) +;; Exec=env __NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender +;; Icon=blender +;; Type=Application +;; Categories=Graphics;3DGraphics; +;; +;; O agrega a tu .bashrc / .zshrc: +;; alias blender-nvidia='__NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender' +;; +;; 3. ZEN BROWSER vía canal personal (richard): +;; Después de actualizar canales con guix pull, instalar: +;; guix install zen-browser +;; O añadir zen-browser a la lista de paquetes del sistema. +;; +;; 4. MULLVAD VPN (el daemon arranca automáticamente vía Shepherd): +;; a) Inicia sesión con tu número de cuenta: +;; mullvad account login XXXXXXXXXX +;; b) Selecciona servidor (opcional — auto conecta si no): +;; mullvad relay set location mx # México +;; c) Conecta: +;; mullvad connect +;; d) Verifica estado: +;; mullvad status +;; herd status mullvad +;; e) Reiniciar daemon si es necesario: +;; herd restart mullvad +;; +;; 5. MAYAVI + PYVISTA (entorno aislado, no contaminan el sistema): +;; guix shell python python-vtk python-numpy python-scipy \ +;; --pure -- pip install mayavi pyvista +;; Para uso frecuente, crea un manifest.scm dedicado. +;; +;; 6. YUBKEY — GPG/SSH (tu config ya existe): +;; gpg --card-status → verifica que pcscd ve la llave +;; ssh-add -L → verifica el agente SSH via YubiKey