From c9a1d2da80bca0a85e8c18f6d2db71c4d1127eda Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Thu, 29 Jan 2026 20:15:19 -0600 Subject: Spring Cleaning - create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs --- modules/system/nixos/bluetooth.nix | 40 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 modules/system/nixos/bluetooth.nix (limited to 'modules/system/nixos/bluetooth.nix') diff --git a/modules/system/nixos/bluetooth.nix b/modules/system/nixos/bluetooth.nix new file mode 100644 index 0000000..1795547 --- /dev/null +++ b/modules/system/nixos/bluetooth.nix @@ -0,0 +1,40 @@ +{ + lib, + config, + ... +}: let + cfg = config.collinux.system.bluetooth; +in + lib.mkIf cfg.enable { + hardware.bluetooth = { + enable = true; + powerOnBoot = true; + + settings.General = { + ControllerMode = "bredr"; + FastConnectable = true; + JustWorksRepairing = "always"; + }; + }; + + systemd.user.services."mpris-proxy" = { + unitConfig = { + BindsTo = ["bluetooth.target"]; + After = ["bluetooth.target"]; + }; + + wantedBy = ["bluetooth.target"]; + + # serviceConfig already exists (?) + }; + + # hardening (down to 2.1 OK) + systemd.services."bluetooth".serviceConfig = { + IPAddressDeny = "any"; + ProtectKernelLogs = true; + ProtectKernelModules = lib.mkForce true; + RestrictAddressFamilies = ["AF_UNIX" "AF_BLUETOOTH"]; + ProtectClock = true; + ProcSubset = "pid"; + }; + } -- cgit v1.3.1