Commit Briefs

d8f81a9588 Alejandro Bernal Estrada

fix: licencia MIT, disparar CI (main)





b1bc859966 Alejandro Bernal Estrada

fix: módulos faltantes (transformations, services/linux), binutils y ruta absoluta

pinentry


b67fc13f02 Alejandro Bernal Estrada

add: .guix-authorizations para autenticación del canal


b49e3f9fc9 Alejandro Bernal Estrada

fix: pre-cachear PIN en yubico y usar pinentry-curses


4af61d4412 Alejandro Bernal Estrada

add: configuración Guix Home con YubiKey/gpg-agent y paquetes de usuario


b614376fa8 Alejandro Bernal Estrada

feat: añadir introduction OpenPGP al canal richard


17ca291dac Alejandro Bernal Estrada

fix: corregir binutils, detección .deb y orden nftables


Branches

Tags

Tree

.forgejo/
.guix-authorizationscommits | blame
.guix-channelcommits | blame
LICENSEcommits | blame
README.mdcommits | blame
richard/
scripts/
system/

README.md

# guix-channel

Canal personal de GNU Guix para el Nitro 5 — Richard Bernal Estrada.

[![Audit](https://codeberg.org/Richard7987/guix-channel/actions/workflows/audit.yml/badge.svg)](https://codeberg.org/Richard7987/guix-channel/actions)
[![Version](https://img.shields.io/badge/sistema-v2026.1-blue?style=flat)](https://codeberg.org/Richard7987/guix-channel/releases)
[![Guix](https://img.shields.io/badge/GNU_Guix-1.5-orange?style=flat)](https://guix.gnu.org)
[![Licencia](https://img.shields.io/badge/licencia-MIT-green?style=flat)](LICENSE)

Canal con paquetes binarios y configuración de sistema para el Acer Nitro 5
(Intel UHD 630 + GTX 1050 Max-Q, PRIME Render Offload, KDE Plasma).

---

## Estructura

```
guix-channel/
├── .forgejo/workflows/
│   └── audit.yml           ← CI: verificación estática automática
├── richard/
│   ├── packages/
│   │   ├── zen-browser.scm ← Zen Browser 1.12.9b (binary wrap)
│   │   └── mullvad.scm     ← Mullvad VPN 2026.1 (binary wrap desde .deb)
│   └── services/
│       └── mullvad.scm     ← Servicio Shepherd para mullvad-daemon
├── scripts/
│   └── audit.py            ← Script de verificación estática (58 checks)
└── system/
    ├── channels.scm        ← Canales: guix + nonguix + este canal
    ├── config.scm          ← Configuración del sistema (/etc/config.scm)
    └── home.scm            ← Guix Home: GPG, YubiKey, bash
```

---

## Agregar el canal

Añade esto a `~/.config/guix/channels.scm`:

```scheme
(channel
  (name 'richard)
  (url "https://codeberg.org/Richard7987/guix-channel")
  (branch "main")
  (introduction
    (make-channel-introduction
      "17ca291dac7ec48ce8266b3726d1fdcc513e99f7"
      (openpgp-fingerprint
        "91CA 581F 7B78 01E8 8673  D228 DBD5 F61D 8A0A 14D7"))))
```

Luego:

```bash
guix pull
guix install zen-browser  # o mullvad-vpn
```

---

## Instalar el sistema completo (Nitro 5)

```bash
# 1. Clonar el repo
git clone git@codeberg.org:Richard7987/guix-channel.git ~/guix-channel

# 2. Copiar configuraciones
sudo cp ~/guix-channel/system/config.scm /etc/config.scm
mkdir -p ~/.config/guix
cp ~/guix-channel/system/channels.scm ~/.config/guix/channels.scm

# 3. Actualizar canales y reconfigurar
guix pull
sudo guix system reconfigure /etc/config.scm

# 4. Aplicar configuración de usuario (Guix Home)
guix home reconfigure ~/guix-channel/system/home.scm
```

---

## Paquetes incluidos

### Zen Browser (`zen-browser`)

Fork de Firefox enfocado en privacidad con barra lateral y espacios de trabajo.
Empaquetado como binary wrap desde el tarball oficial de GitHub.

```bash
guix install zen-browser
```

Para actualizar a una versión nueva:

```bash
# 1. Editar richard/packages/zen-browser.scm — cambiar 'version'
# 2. Obtener el hash nuevo:
guix download https://github.com/zen-browser/desktop/releases/download/VERSION/zen.linux-x86_64.tar.xz
# 3. Reemplazar el (base32 "...") con el hash obtenido
git commit -am "zen-browser: actualizar a VERSION"
git push
```

### Mullvad VPN (`mullvad-vpn` + servicio Shepherd)

Cliente VPN centrado en privacidad. Incluye daemon (`mullvad-daemon`)
y CLI (`mullvad`). El daemon arranca automáticamente con el sistema.

```bash
# Tras instalar el sistema, activar la cuenta:
mullvad account login TU_NUMERO_DE_CUENTA

# Conectar
mullvad relay set location mx   # servidores en México
mullvad connect

# Estado
mullvad status
herd status mullvad
```

Para actualizar:

```bash
# 1. Editar richard/packages/mullvad.scm — cambiar 'version'
# 2. Obtener el hash:
wget https://github.com/mullvad/mullvadvpn-app/releases/download/VERSION/MullvadVPN-VERSION_amd64.deb
sha256sum MullvadVPN-VERSION_amd64.deb | python3 scripts/nix32.py
# 3. Reemplazar el (base32 "...") con el resultado
```

---

## Hardware objetivo

| Componente | Detalle |
|---|---|
| Laptop | Acer Nitro 5 |
| CPU | Intel Coffee Lake-H |
| iGPU | Intel UHD 630 (`PCI:0:2:0`) |
| dGPU | NVIDIA GTX 1050 3 GB Max-Q (`PCI:1:0:0`) |
| GPU Mode | PRIME Render Offload (sin MUX switch) |
| DE | KDE Plasma 6 + SDDM |
| Kernel | Linux no-libre (nonguix) |

### Verificar PRIME tras instalar

```bash
# Debe mostrar Intel/Mesa
glxinfo | grep "OpenGL renderer"

# Debe mostrar NVIDIA GTX 1050
__NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia \
  glxinfo | grep "OpenGL renderer"

# Lanzar Blender con NVIDIA
__NV_PRIME_RENDER_OFFLOAD=1 __GLX_VENDOR_LIBRARY_NAME=nvidia blender
```

---

## Versionado

Este proyecto usa **CalVer** (`YYYY.N`):

| Versión | Fecha | Cambios |
|---|---|---|
| v2026.1 | Mayo 2026 | Versión inicial: KDE Plasma, PRIME Offload, Mullvad, Zen Browser, YubiKey |

Para crear un nuevo release en Codeberg:

```bash
git tag v2026.2
git push origin v2026.2
```

---

## CI — Verificación estática

El script `scripts/audit.py` corre 58 checks automáticos en cada push:

- Validez de hashes nix32 (formato y longitud)
- Imports de módulos requeridos en todos los archivos `.scm`
- Presencia de servicios críticos (`nvidia-service-type`, `sddm-service-type`, etc.)
- Configuración PRIME (`BusID`, `AllowNVIDIAGPUScreens`, `nvda`)
- Paquetes requeridos en el sistema
- Configuración de Guix Home (GPG, YubiKey, pinentry)

```bash
# Correr localmente
python3 scripts/audit.py
```

---

## Licencia

GPL-3.0 — ver [LICENSE](LICENSE)