From fdde154c63eeb8e6aac5129f9226f38c4b0b8bf0 Mon Sep 17 00:00:00 2001 From: Grace Yoder Date: Sat, 3 Oct 2026 14:54:12 -0400 Subject: hamano again --- .gitignore | 1 - configuration.nix | 21 ++++- darwin.nix | 6 +- home.nix | 38 ++++++++- home/helix.nix | 11 ++- home/linux.nix | 6 ++ home/shell.nix | 22 +++--- home/ssh.nix | 20 ++++- hosts.nix | 47 +++++++++++ hosts/hamano.nix | 36 --------- hosts/hardware-configurations/knuth.nix | 47 +++++++++++ hosts/knuth.nix | 43 +++++++++++ hosts/turing.nix | 9 ++- modules/caddy.nix | 55 ++++++------- modules/dns.nix | 16 ++-- modules/gitsrv.nix | 133 ++++++++++++++++++++++++++++++++ modules/users.nix | 16 ++-- system.nix | 22 ++++++ tailnet.nix | 3 +- 19 files changed, 442 insertions(+), 110 deletions(-) create mode 100644 home/linux.nix create mode 100644 hosts.nix delete mode 100644 hosts/hamano.nix create mode 100644 hosts/hardware-configurations/knuth.nix create mode 100644 hosts/knuth.nix create mode 100644 modules/gitsrv.nix create mode 100644 system.nix diff --git a/.gitignore b/.gitignore index 6fc4cbe..8ed425a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1 @@ -/host.nix /hardware-configuration.nix diff --git a/configuration.nix b/configuration.nix index 2b48913..4382d53 100644 --- a/configuration.nix +++ b/configuration.nix @@ -1,7 +1,22 @@ -{ ... }: +{ lib, ... }: let - host = import ./host.nix; + host = import ./hosts.nix; + # system = import ./system.nix; in +assert lib.assertMsg ( + host.type != "home" +) "${host.name} is a Home Manager host; use home-manager instead."; { - imports = [ (./hosts + "/${host.name}.nix") ]; + imports = [ + # system.module + (./hosts + "/${host.name}.nix") + ] + ++ lib.optional (host.type == "nixos") (./hosts/hardware-configurations + "/${host.name}.nix"); + + nixpkgs.hostPlatform = host.system; + # nix.settings.nix-path = lib.mkDefault system.module.nix.nixPath; + + security.sudo.extraConfig = '' + Defaults env_keep += "NIX_HOST" + ''; } diff --git a/darwin.nix b/darwin.nix index 6e339c3..fe1cc70 100755 --- a/darwin.nix +++ b/darwin.nix @@ -7,13 +7,11 @@ let paneru = builtins.getFlake "github:karinushka/paneru/5a033bc3a59f752ae72944f06945ab13cc570e04"; - host = import ./host.nix; + host = import ./hosts.nix; in { imports = [ paneru.darwinModules.paneru ]; - nixpkgs.config.allowUnfree = true; - nixpkgs.hostPlatform = "aarch64-darwin"; networking.hostName = host.name; environment.systemPackages = [ @@ -28,7 +26,7 @@ in users.users.${config.system.primaryUser} = { name = config.system.primaryUser; - home = "/Users/${config.system.primaryUser}"; + home = host.home; shell = pkgs.fish; }; diff --git a/home.nix b/home.nix index 26a425c..85ad395 100755 --- a/home.nix +++ b/home.nix @@ -1,24 +1,31 @@ { lib, + config, ... }: let - host = import ./host.nix; + host = import ./hosts.nix; in { home = { username = host.user; homeDirectory = host.home; + sessionVariables = { + NIX_HOST = "\${NIX_HOST:-$(hostname -f 2>/dev/null || hostname)}"; + XDG_CONFIG_HOME = "${host.home}/.config"; + }; }; + nixpkgs.config.allowUnfree = true; + imports = [ + # (import ./system.nix).module ./home/base.nix ./home/shell.nix ./home/helix.nix ./home/tmux.nix ./home/vim.nix - ./home/langs.nix ./home/vcs.nix ] ++ lib.optionals (host.name == "turing") [ @@ -28,15 +35,38 @@ in "h:turing" ]; }) + ./home/langs.nix ./home/packages.nix ./home/typst.nix ./home/pkgs_mac.nix ./home/ghostty.nix - ] - ++ lib.optionals (lib.hasSuffix "cs.purdue.edu" host.name) [ + ++ lib.optionals (host.name == "cs.purdue.edu") [ # Symlinked items from nix store are bad and do not work for ssh + ./home/langs.nix ./home/cs_purdue.nix ./home/typst.nix + ./home/linux.nix + ] + ++ lib.optionals (host.name == "vulcan") [ + ./home/langs.nix + (import ./home/ssh.nix { + principals = [ + "t:human" + "t:dev" + "h:vulcan" + ]; + }) + ./home/linux.nix + ] + ++ lib.optionals (host.name == "knuth") [ + (import ./home/ssh.nix { + principals = [ + "t:human" + "t:dev" + "h:knuth" + ]; + }) + ./home/linux.nix ]; } diff --git a/home/helix.nix b/home/helix.nix index fca1c32..9ba92c3 100755 --- a/home/helix.nix +++ b/home/helix.nix @@ -31,8 +31,8 @@ in programs.helix = { enable = true; - package = pkgs.steelix; - extraPackages = [ pkgs.steel ]; + package = pkgs.helix; + # extraPackages = [ pkgs.steel ]; defaultEditor = false; settings = { theme = "grace_rose_pine"; @@ -45,7 +45,7 @@ in select = "underline"; }; default-yank-register = "+"; - clipboard-provider = if (import ../host.nix).name == "turing" then "pasteboard" else "termcode"; + clipboard-provider = if (import ../hosts.nix).name == "turing" then "pasteboard" else "termcode"; cursorline = true; cursorcolumn = true; continue-comments = false; @@ -171,6 +171,11 @@ in tinymist = { command = "${pkgs.tinymist}/bin/tinymist"; config.tinymist.formatterMode = "typstyle"; + typstExtraArgs = [ + "--features" + "bundle,html" + "site.typ" + ]; }; rust-analyzer = { diff --git a/home/linux.nix b/home/linux.nix new file mode 100644 index 0000000..7cd14a0 --- /dev/null +++ b/home/linux.nix @@ -0,0 +1,6 @@ +{ pkgs, home, ... }: +{ + home.packages = with pkgs; [ + ghostty + ]; +} diff --git a/home/shell.nix b/home/shell.nix index d3f9ccd..d374157 100755 --- a/home/shell.nix +++ b/home/shell.nix @@ -37,17 +37,17 @@ in (import "${tpbSrc}/default.nix" { inherit pkgs; }).overrideAttrs - (_: { - unpackPhase = '' - mkdir source - tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ - -C "$src" -cf - . \ - | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ - -C source -xf - - chmod -R u+w source - sourceRoot=source - ''; - }) + (_: { + unpackPhase = '' + mkdir source + tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ + -C "$src" -cf - . \ + | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ + -C source -xf - + chmod -R u+w source + sourceRoot=source + ''; + }) ) ]; diff --git a/home/ssh.nix b/home/ssh.nix index f0e75c7..ddcce96 100644 --- a/home/ssh.nix +++ b/home/ssh.nix @@ -8,10 +8,24 @@ ... }: -{ - home.file.".ssh/authorized_keys".text = '' - cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink +let + authorizedKeys = '' + cert-authority,principals="t:rebuild,${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink ${lib.concatStringsSep "\n" extraKeys} ''; +in +{ + home.activation.authorizedKeys = lib.hm.dag.entryAfter [ "writeBoundary" ] '' + run mkdir -p "$HOME/.ssh" + run chmod 700 "$HOME/.ssh" + + if [[ -z "''${DRY_RUN:-}" ]]; then + cat > "$HOME/.ssh/authorized_keys" <<'EOF' + ${authorizedKeys} + EOF + + chmod 600 "$HOME/.ssh/authorized_keys" + fi + ''; } diff --git a/hosts.nix b/hosts.nix new file mode 100644 index 0000000..e7bf6b1 --- /dev/null +++ b/hosts.nix @@ -0,0 +1,47 @@ +let + hosts = { + turing = { + user = "grace"; + home = "/Users/grace"; + system = "aarch64-darwin"; + type = "darwin"; + }; + + "cs.purdue.edu" = { + user = "yoder177"; + home = "/homes/yoder177"; + system = "x86_64-linux"; + type = "home"; + }; + + vulcan = { + user = "scie"; + home = "/home/scie"; + system = "x86_64-linux"; + type = "home"; + }; + + dijkstra = { + user = "scie"; + home = "/home/scie"; + system = "x86_64-linux"; + type = "home"; + }; + + knuth = { + user = "grace"; + home = "/home/scie"; + system = "x86_64-linux"; + type = "nixos"; + }; + }; + + hostname = builtins.getEnv "NIX_HOST"; + name = + if builtins.match "(.+\\.)?cs\\.purdue\\.edu" hostname != null then + "cs.purdue.edu" + else + builtins.head (builtins.split "\\." hostname); +in +(hosts.${name} or (throw "Set NIX_HOST to a host in hosts.nix (got '${hostname}').")) +// { inherit name; } diff --git a/hosts/hamano.nix b/hosts/hamano.nix deleted file mode 100644 index 2056d70..0000000 --- a/hosts/hamano.nix +++ /dev/null @@ -1,36 +0,0 @@ -{ ... }: - -let - host = import ../host.nix; -in -{ - imports = [ - ../hardware-configuration.nix - ../modules/dns.nix - ../modules/caddy.nix - ../modules/tailscale.nix - ../modules/users.nix - ]; - - nix.settings.experimental-features = [ - "nix-command" - "flakes" - ]; - - boot.loader.systemd-boot.enable = true; - networking.hostName = host.name; - - services.openssh = { - enable = true; - openFirewall = true; - - ports = [ 2222 ]; - - settings = { - PermitRootLogin = "no"; - PasswordAuthentication = false; - KbdInteractiveAuthentication = false; - }; - }; - -} diff --git a/hosts/hardware-configurations/knuth.nix b/hosts/hardware-configurations/knuth.nix new file mode 100644 index 0000000..918ed86 --- /dev/null +++ b/hosts/hardware-configurations/knuth.nix @@ -0,0 +1,47 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "sr_mod" + "virtio_blk" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/09759176-834c-4c87-ada7-7092adcb1320"; + fsType = "ext4"; + }; + + swapDevices = [ + { device = "/dev/disk/by-uuid/7c0dd096-b1dd-4a12-bdd0-cc212ac541e6"; } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.ens3.useDHCP = lib.mkDefault true; + # networking.interfaces.ens4.useDHCP = lib.mkDefault true; + # networking.interfaces.ens5.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/knuth.nix b/hosts/knuth.nix new file mode 100644 index 0000000..9685d51 --- /dev/null +++ b/hosts/knuth.nix @@ -0,0 +1,43 @@ +{ ... }: + +let + host = import ../hosts.nix; +in +{ + imports = [ + ../modules/dns.nix + ../modules/caddy.nix + ../modules/gitsrv.nix + ../modules/tailscale.nix + ../modules/users.nix + ]; + nix.settings.trusted-users = [ + "root" + "grace" +]; + + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + boot.loader.grub = { + enable = true; + device = "/dev/vda"; + }; + networking.hostName = host.name; + + services.openssh = { + enable = true; + openFirewall = true; + + ports = [ 2222 ]; + + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + }; + +} diff --git a/hosts/turing.nix b/hosts/turing.nix index c54c9ac..436b105 100755 --- a/hosts/turing.nix +++ b/hosts/turing.nix @@ -1,10 +1,11 @@ { config, ... }: let - home-manager = builtins.fetchTarball - "https://github.com/nix-community/home-manager/archive/master.tar.gz"; + + home-manager = builtins.fetchTarball "https://github.com/nix-community/home-manager/archive/master.tar.gz"; in { + nixpkgs.config.allowUnfree = true; nix.settings.experimental-features = [ "nix-command" "flakes" @@ -16,13 +17,13 @@ in ]; home-manager = { - useGlobalPkgs = true; + useGlobalPkgs = false; useUserPackages = true; backupFileExtension = "backup"; users.${config.system.primaryUser} = { imports = [ ../home.nix ]; home.username = config.system.primaryUser; - home.homeDirectory = "/Users/${config.system.primaryUser}"; + home.homeDirectory = config.users.users.${config.system.primaryUser}.home; }; }; } diff --git a/modules/caddy.nix b/modules/caddy.nix index 9c8e70d..d9023f5 100644 --- a/modules/caddy.nix +++ b/modules/caddy.nix @@ -1,8 +1,4 @@ -{ - pkgs, - lib, - ... -}: +{ config, ... }: let tailnet = import ../tailnet.nix; @@ -15,32 +11,37 @@ in 443 ]; - services.caddy = { - enable = true; - - package = pkgs.caddy.withPlugins { - plugins = [ - "github.com/mholt/caddy-l4@v0.1.2" - ]; + # TCP forwarding lives here alongside Caddy's HTTP/HTTPS reverse proxies. + systemd.sockets.git-ssh-proxy = { + wantedBy = [ "sockets.target" ]; + listenStreams = [ "0.0.0.0:22" ]; + }; - hash = lib.fakeHash; + systemd.services.git-ssh-proxy = { + description = "TCP proxy for Git SSH"; + requires = [ "git-ssh-proxy.socket" ]; + serviceConfig = { + ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra-git}:22"; + DynamicUser = true; }; + }; - globalConfig = '' - layer4 { - 0.0.0.0:22 { - route { - proxy ${tailnet.dijkstra-git}:22 - } - } + systemd.sockets.minecraft-proxy = { + wantedBy = [ "sockets.target" ]; + listenStreams = [ "0.0.0.0:25565" ]; + }; - 0.0.0.0:25565 { - route { - proxy ${tailnet.dijkstra}:25565 - } - } - } - ''; + systemd.services.minecraft-proxy = { + description = "TCP proxy for Minecraft"; + requires = [ "minecraft-proxy.socket" ]; + serviceConfig = { + ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra}:25565"; + DynamicUser = true; + }; + }; + + services.caddy = { + enable = true; extraConfig = '' # TODO: make it nice diff --git a/modules/dns.nix b/modules/dns.nix index 5454cc5..26c42f0 100644 --- a/modules/dns.nix +++ b/modules/dns.nix @@ -1,13 +1,11 @@ { pkgs, ... }: let - serial = "2026100201"; + serial = "2026100401"; public = { - hamano = "152.44.39.247"; lee = "152.44.40.91"; - knuth = "x.x.x.x"; - unused = "x.x.x.x"; + knuth = "209.50.50.6"; }; tailnet = import ../tailnet.nix; @@ -110,9 +108,10 @@ in # https://github.com/tailscale/tailscale/issues/1543#issuecomment-4703759447 file = mkPrimaryZone { domain = "gae.moe"; - address = public.hamano; + address = public.knuth; extraRecords = '' - ns1 IN A ${public.hamano} + ns1 IN A ${public.knuth} + _hi 3600 IN TXT "hi :3" ${tailnetRecords} ''; @@ -126,6 +125,9 @@ in file = mkPrimaryZone { domain = "grace.pink"; address = public.lee; + extraRecords = '' + _atproto 3600 IN TXT "did=did:plc:rtokeh2dsmapicefqxkefbfn" + ''; }; }; @@ -135,7 +137,7 @@ in file = mkPrimaryZone { domain = "words.gay"; - address = public.unused; + address = public.lee; }; }; } diff --git a/modules/gitsrv.nix b/modules/gitsrv.nix new file mode 100644 index 0000000..e4098e7 --- /dev/null +++ b/modules/gitsrv.nix @@ -0,0 +1,133 @@ +{ + config, + pkgs, + lib, + ... +}: + +let + gitoliteKeys = { + gitolite-admin = [ + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace_yoder@outlook.com" + # "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINySDE+jaYpuAWUdPQf/JcAWETeHgmh+T5Y4GUa7MfeM grace@turing" + ]; + + grace = [ ]; + grace-read = [ ]; + }; + + mkGitoliteKey = + user: key: + ''command="${pkgs.gitolite}/bin/gitolite-shell ${user}",restrict ${key}''; + + gitoliteAuthorizedKeys = + lib.concatStringsSep "\n" ( + lib.flatten ( + lib.mapAttrsToList ( + user: keys: + map (mkGitoliteKey user) keys + ) gitoliteKeys + ) + ); + + fixGitolitePermissions = pkgs.writeShellScript "fix-gitolite-permissions" '' + set -eu + + ${pkgs.coreutils}/bin/mkdir -p /var/lib/git-server/.ssh + + ${pkgs.coreutils}/bin/chown git:git /var/lib/git-server + ${pkgs.coreutils}/bin/chmod 0750 /var/lib/git-server + + ${pkgs.coreutils}/bin/chown git:git /var/lib/git-server/.ssh + ${pkgs.coreutils}/bin/chmod 0700 /var/lib/git-server/.ssh + + if [ -e /var/lib/git-server/.ssh/authorized_keys ]; then + ${pkgs.coreutils}/bin/chown git:git \ + /var/lib/git-server/.ssh/authorized_keys + + ${pkgs.coreutils}/bin/chmod 0600 \ + /var/lib/git-server/.ssh/authorized_keys + fi + ''; +in +{ + services.gitolite = { + enable = true; + + user = "git"; + group = "git"; + + dataDir = "/var/lib/git-server"; + + adminPubkey = + "sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace_yoder@outlook.com"; + }; + + # IMPORTANT: + # mode != "symlink" makes these REAL /etc files instead of + # symlinks through /nix/store, which sshd StrictModes rejects. + + environment.etc."ssh/git-user-ca.pub" = { + mode = "0644"; + user = "root"; + group = "root"; + + text = '' + ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink + ''; + }; + + environment.etc."ssh/git-principals" = { + mode = "0644"; + user = "root"; + group = "root"; + + text = '' + command="${pkgs.gitolite}/bin/gitolite-shell grace",restrict t:dev + command="${pkgs.gitolite}/bin/gitolite-shell grace-read",restrict u:grace + ''; + }; + + environment.etc."ssh/git-authorized-keys" = { + mode = "0644"; + user = "root"; + group = "root"; + + text = gitoliteAuthorizedKeys + "\n"; + }; + + services.openssh = { + enable = true; + + ports = [ + 22 + 2222 + ]; + + extraConfig = '' + Match User git + TrustedUserCAKeys /etc/ssh/git-user-ca.pub + AuthorizedPrincipalsFile /etc/ssh/git-principals + AuthorizedKeysFile /etc/ssh/git-authorized-keys + + PubkeyAuthentication yes + PasswordAuthentication no + KbdInteractiveAuthentication no + + DisableForwarding yes + PermitTTY no + PermitUserRC no + X11Forwarding no + ''; + }; + + systemd.services.gitolite-init.serviceConfig.ExecStartPre = + lib.mkBefore [ + "+${fixGitolitePermissions}" + ]; + + systemd.tmpfiles.rules = [ + "d /var/lib/git-server 0750 git git -" + "d /var/lib/git-server/.ssh 0700 git git -" + ]; +} diff --git a/modules/users.nix b/modules/users.nix index 53fce69..d18e366 100644 --- a/modules/users.nix +++ b/modules/users.nix @@ -1,15 +1,21 @@ { pkgs, ... }: let + host = import ../hosts.nix; home-manager = builtins.fetchTarball "https://github.com/nix-community/home-manager/archive/master.tar.gz"; - host = import ../host.nix; in { imports = [ "${home-manager}/nixos" ]; - users.users.grace = { + nix.settings.trusted-users = [ + "root" + "grace" + ]; + + users.users.${host.user} = { isNormalUser = true; - description = "grace"; + description = host.user; + home = host.home; extraGroups = [ "wheel" "networkmanager" @@ -23,11 +29,11 @@ in security.sudo.wheelNeedsPassword = false; home-manager = { - useGlobalPkgs = true; + useGlobalPkgs = false; useUserPackages = true; backupFileExtension = "backup"; - users.grace = { + users.${host.user} = { imports = [ ../home.nix ]; home.username = host.user; diff --git a/system.nix b/system.nix new file mode 100644 index 0000000..56a65c3 --- /dev/null +++ b/system.nix @@ -0,0 +1,22 @@ +let + nixpkgs = builtins.fetchTarball "https://github.com/NixOS/nixpkgs/archive/master.tar.gz"; + home-manager = builtins.fetchTarball "https://github.com/nix-community/home-manager/archive/master.tar.gz"; +in + import "${nixpkgs}/nixos" { + # home-manager = home-manager; + + configuration = { + + imports = [ ./configuration.nix ]; + + nix.nixPath = [ + "nixpkgs=${nixpkgs}" + "home-manager=${home-manager}" + "nixos-config=${toString ./configuration.nix}" + "darwin-config=${toString ./configuration.nix}" + "/nix/var/nix/profiles/per-user/root/channels" + ]; + + nixpkgs.config.allowUnfree = true; + }; + } diff --git a/tailnet.nix b/tailnet.nix index ec5095b..5161387 100644 --- a/tailnet.nix +++ b/tailnet.nix @@ -6,9 +6,8 @@ dijkstra-minecraft = "100.71.208.59"; gen-pad = "100.107.122.73"; gen-phone = "100.94.78.68"; - hamano = "100.103.143.121"; iphone182 = "100.67.207.48"; - knuth = "100.123.43.44"; + knuth = "100.94.152.41"; lee = "100.73.228.2"; steamdeck = "100.77.30.106"; thomson = "100.111.206.21"; -- cgit v1.3.1