refactor: reorganize Arch system backup and restore

Separate system configuration from Dotfiles_ArchAP.

Add package manifests, system inventories, reusable templates,
safer backup/deployment scripts, on-demand service management,
TLP and zram configuration, and updated maintenance documentation.
This commit is contained in:
grayTerminal-sh 2026-07-26 23:14:42 +02:00
parent 747f21fc29
commit 14e547ce56
63 changed files with 1594 additions and 997 deletions

16
.gitignore vendored
View file

@ -1,3 +1,4 @@
# Secrets and private material
*.key *.key
*.pem *.pem
*.p12 *.p12
@ -5,10 +6,25 @@
*secret* *secret*
*password* *password*
*token* *token*
*.db
*.sqlite*
.netrc
# Machine identity / credentials
rootfs/etc/ssh/ssh_host_* rootfs/etc/ssh/ssh_host_*
rootfs/etc/sbctl/ rootfs/etc/sbctl/
rootfs/etc/ssl/private/ rootfs/etc/ssl/private/
rootfs/etc/NetworkManager/system-connections/ rootfs/etc/NetworkManager/system-connections/
rootfs/etc/wireguard/ rootfs/etc/wireguard/
rootfs/root/ rootfs/root/
# Temporary files
*.bak
*.tmp
*.swp
*.log
.cache/
build/
# Menu Limine généré avec les snapshots
inventory/boot/limine.conf.current

14
CHANGELOG.md Normal file
View file

@ -0,0 +1,14 @@
# Changelog
## 2026-07-26
- refonte complète de larborescence ;
- séparation correcte des paquets officiels et AUR explicitement installés ;
- sauvegarde des inventaires systemd et stockage ;
- restauration sécurisée par étapes ;
- ajout des outils `batlimit`, Nextcloud ponctuel, Thunderbird/Proton Bridge et VMware/Samba à la demande ;
- ajout des helpers root et règles sudoers minimales ;
- documentation de la migration SSD avec Clonezilla et Btrfs ;
- remplacement de la configuration TLP monolithique par un drop-in minimal ;
- retrait du swapfile de 16 Gio, maintien de zram 6 Gio ;
- suppression des références obsolètes à MangoWM et au service de batterie à 80 %.

142
README.md
View file

@ -1,126 +1,70 @@
# Arch System # Arch System
Sauvegarde de la configuration système de mon poste Arch Linux. Configuration et outillage de reconstruction de mon poste **ArchASP**.
Ce dépôt contient uniquement la partie système. Les dotfiles utilisateur sont stockés dans un dépôt séparé. Ce dépôt couvre la partie système : paquets, services, stockage, énergie, démarrage, outils root et automatisations locales. Les dotfiles complets restent dans un dépôt séparé.
## Contenu ## Objectifs
### Paquets - documenter létat réel du poste ;
- reconstruire une installation Arch sans recopier aveuglément des UUID ou des secrets ;
- conserver les outils personnalisés nécessaires au quotidien ;
- distinguer les services permanents des services lancés à la demande ;
- préparer les migrations de disque Btrfs/Limine/Snapper/Secure Boot.
* `pkglist/pacman.txt` ## Organisation
* `pkglist/aur.txt`
Liste des paquets officiels et AUR installés. - `scripts/backup.sh` : actualise les inventaires et les configurations suivies ;
- `scripts/audit.sh` : contrôle rapide de létat du système ;
- `scripts/deploy.sh` : restauration par étapes, sans écraser automatiquement `fstab` ni le boot ;
- `scripts/prepare-disk.sh` : préparation destructive dun disque pour une nouvelle installation ;
- `inventory/` : informations générées sur le poste ;
- `manifests/` : services intentionnellement activés ;
- `rootfs/` : configurations et helpers installables en root ;
- `Dotfiles_ArchAP` : dépôt séparé pour les configurations, scripts et unités utilisateur ;
- `templates/` : fichiers nécessitant une adaptation à la machine ;
- `docs/` : procédures dentretien, de restauration et de migration SSD.
### Services systemd ## Mise à jour du dépôt
* `systemd/enabled-system.txt`
* `systemd/enabled-user.txt`
Inventaire des services activés.
### Configuration système
* `rootfs/etc/pacman.conf`
* `rootfs/etc/makepkg.conf`
* `rootfs/etc/mkinitcpio.conf`
* `rootfs/etc/fstab`
* `rootfs/etc/nftables.conf`
* `rootfs/etc/tlp.conf`
### Snapper
* `rootfs/etc/snapper/configs/root`
Configuration des snapshots Btrfs.
### Limine
* `rootfs/boot/limine.conf`
* `rootfs/etc/limine-snapper-sync.conf`
Configuration du chargeur de démarrage (+ entrée des snapshots dans le bootloader).
### Systemd
* `rootfs/etc/systemd/system/battery-threshold.service`
Service personnalisé limitant la charge de la batterie à 80 %.
### Documentation
* `docs/lsblk.txt`
* `docs/findmnt.txt`
* `docs/btrfs-subvolumes.txt`
### TLP
* `rootfs/etc/tlp.conf`
Gestion de lénergie :
- profil batterie ASUS : `quiet`
- seuil de charge par défaut : 60 %
- réglages CPU via `amd-pstate-epp`
Documentation de la structure des disques, montages et sous-volumes Btrfs.
## Sauvegarde
Mettre à jour le dépôt :
```bash ```bash
./scripts/check-repo.sh
./scripts/backup.sh ./scripts/backup.sh
git diff --check
git status --short
``` ```
## Réinstallation Toujours relire le diff avant de commit : un inventaire généré peut révéler un paquet ajouté par erreur ou un service réactivé automatiquement.
### 1. Installation de base ## Restauration
Installer Arch Linux. Le déploiement est volontairement découpé :
### 2. Restaurer le dépôt
```bash ```bash
git clone <repo> ./scripts/deploy.sh --packages
cd arch-system ./scripts/deploy.sh --configs
./scripts/deploy.sh --tools
./scripts/deploy.sh --services
``` ```
### 3. Restaurer les fichiers système Pour tout appliquer :
Copie manuelle ou via un futur script de déploiement.
### 4. Réinstaller les paquets
```bash ```bash
sudo pacman -S --needed - < pkglist/pacman.txt ./scripts/deploy.sh --all
``` ```
Puis les paquets AUR. `/etc/fstab`, `limine.conf`, les clés Secure Boot et les connexions réseau ne sont jamais restaurés automatiquement.
### 5. Réactiver les services ## État fonctionnel visé
Utiliser : - Arch Linux, Sway/SwayFX et Wayland ;
- Btrfs avec `@`, `@home`, `@log`, `@pkg` et `@/.snapshots` ;
- Limine + limine-snapper-sync ;
- Secure Boot géré par `sbctl` ;
- zram 6 Gio, sans swapfile permanent ;
- TLP avec seuil de charge ASUS à 60 % ;
- Nextcloud, Proton Mail Bridge, VMware et Samba lancés uniquement à la demande.
```bash ## Sécurité
systemd/enabled-system.txt
```
comme référence.
## Notes
### Secure Boot
Le système utilise sbctl.
Les clés Secure Boot ne sont pas stockées dans ce dépôt.
### Btrfs
Le système utilise Btrfs avec Snapper pour la gestion des snapshots.
### Boot
Le système utilise Limine comme chargeur de démarrage.
Le dépôt est public. Aucun mot de passe, token, clé privée, fichier `.netrc`, base SQLite, connexion NetworkManager ou configuration WireGuard ne doit y être ajouté.

48
docs/architecture.md Normal file
View file

@ -0,0 +1,48 @@
# Architecture du poste
## Stockage
- table de partitions GPT ;
- partition EFI montée sur `/boot` ;
- partition racine Btrfs ;
- sous-volumes :
- `@``/`
- `@home``/home`
- `@log``/var/log`
- `@pkg``/var/cache/pacman/pkg`
- `@/.snapshots``/.snapshots`
Les UUID réels sont enregistrés dans `inventory/storage/` uniquement à titre documentaire. Les modèles de réinstallation utilisent des placeholders.
## Démarrage
- Limine ;
- noyaux LTS et/ou Zen selon les paquets présents ;
- Snapper et limine-snapper-sync pour les entrées de snapshots ;
- Secure Boot avec clés personnelles gérées par `sbctl`.
Les clés Secure Boot ne sont jamais versionnées.
## Mémoire
- 16 Gio de RAM physique environ ;
- zram de 6 Gio, priorité 100 ;
- aucun swapfile permanent.
## Énergie
TLP applique au démarrage :
- profil batterie ASUS `quiet` ;
- politique CPU économe sur batterie ;
- boost CPU désactivé sur batterie ;
- seuil maximal de charge `BAT1` à 60 %.
`batlimit` permet un changement temporaire ; TLP remet 60 % au prochain démarrage.
## Services à la demande
- Nextcloud : une synchronisation avec `nextcloudcmd`, puis sortie ;
- Proton Mail Bridge : démarré avec Thunderbird, arrêté à sa fermeture ;
- VMware : réseau, USB Arbitrator et Samba démarrés avec VMware puis arrêtés ;
- Proton Pass : lancé manuellement.

33
docs/backup.md Normal file
View file

@ -0,0 +1,33 @@
# Sauvegarde du dépôt
## Actualisation
```bash
./scripts/backup.sh
```
Le script exporte :
- paquets officiels explicites avec `pacman -Qqen` ;
- paquets étrangers/AUR explicites avec `pacman -Qqem` ;
- paquets orphelins ;
- unités systemd actives, activées et en échec ;
- timers système et utilisateur ;
- état Btrfs, zram, mémoire et SSD NVMe ;
- configurations système explicitement autorisées ;
- scripts utilisateur suivis par le dépôt.
## Contrôle avant commit
```bash
git diff --check
git diff --stat
git status --short
```
Inspecter particulièrement :
- `pkglist/orphans.txt` ;
- les services qui apparaissent nouvellement activés ;
- les modifications de `nftables.conf`, `mkinitcpio.conf` et `pacman.conf` ;
- labsence de secrets.

View file

@ -0,0 +1,12 @@
# Réinstallation
1. Installer Arch
2. Installer git
3. Cloner arch-system
4. Restaurer les fichiers rootfs
5. Installer les paquets
6. Installer les dotfiles
7. Vérifier Limine
8. Vérifier Snapper
9. Vérifier Secure Boot
10. Vérifier nftables

47
docs/maintenance.md Normal file
View file

@ -0,0 +1,47 @@
# Entretien du dimanche
## État général
```bash
./scripts/audit.sh
```
## Paquets
```bash
sudo pacman -Syu
pacman -Qdt
sudo paccache -rk2
sudo paccache -ruk0
```
Ne jamais supprimer automatiquement les orphelins sans lire la liste : des outils de développement explicitement utilisés peuvent y apparaître.
## Journaux
```bash
journalctl --disk-usage
sudo journalctl --vacuum-size=500M
```
## Btrfs
```bash
sudo btrfs filesystem usage /
sudo btrfs scrub status /
systemctl status fstrim.timer snapper-cleanup.timer snapper-timeline.timer
```
Un `balance` Btrfs nest pas un nettoyage périodique. Ne le lancer quaprès diagnostic.
## Mémoire et pression
```bash
free -h
swapon --show
cat /proc/pressure/cpu
cat /proc/pressure/memory
cat /proc/pressure/io
```
Le chiffre utile est `MemAvailable`, pas seulement `MemFree`.

View file

@ -0,0 +1,48 @@
# Services à la demande
## Nextcloud
`nextcloud-sync` utilise `nextcloudcmd`, affiche une notification et quitte à la fin.
Authentification A2F : créer un mot de passe dapplication et le placer dans `~/.netrc` :
```text
machine cloud.labfytools.com
login florian
password MOT_DE_PASSE_APPLICATION
```
Puis :
```bash
chmod 600 ~/.netrc
```
Le client graphique est bloqué dans lautostart et dans lactivation D-Bus utilisateur.
## Thunderbird et Proton Mail Bridge
Lancer Thunderbird avec :
```bash
thunderbird-proton
```
Le script démarre GNOME Keyring et le service Bridge, attend Thunderbird, puis arrête Bridge.
## VMware et Samba
Lancer VMware avec :
```bash
vmware-on-demand
```
Le helper root démarre uniquement :
- `vmware-networks.service` ;
- `vmware-usbarbitrator.service` ;
- `smb.service` ;
- `nmb.service`.
Ces services restent désactivés au démarrage.

34
docs/refonte-v2.md Normal file
View file

@ -0,0 +1,34 @@
# Refonte v2
## Problèmes corrigés
- `pacman -Qqe` mélangeait paquets officiels et AUR ;
- les inventaires systemd étaient écrits dans un dossier absent ;
- le déploiement recopiait tout `rootfs/`, y compris un `fstab` lié à lancien SSD ;
- `deploy.sh` utilisait `paru` alors que le poste utilise `yay` ;
- la configuration documentait encore MangoWM, zram 4 Gio et un ancien service de batterie ;
- `limine.conf` versionnait des centaines de lignes générées par les snapshots ;
- Samba, VMware, Nextcloud et Proton Mail Bridge étaient décrits comme permanents ;
- aucun garde-fou ne séparait inventaire observé et services réellement voulus.
## Nouvelle règle
- `inventory/` = état observé, généré par `backup.sh` ;
- `manifests/` = intention de configuration ;
- `rootfs/` = configurations et outils système gérés par ce dépôt ;
- les fichiers utilisateur sont gérés séparément dans `Dotfiles_ArchAP` ;
- `templates/` = fichiers à adapter à la machine ;
- aucune restauration aveugle de `/boot` ou `/etc/fstab`.
## Première utilisation
Après avoir remplacé lancienne arborescence par la v2 :
```bash
./scripts/check-repo.sh
./scripts/backup.sh
git diff --check
git status --short
```
Le premier `backup.sh` remplit les inventaires vides avec létat actuel dArchASP.

View file

@ -1,12 +1,67 @@
# Réinstallation # Réinstallation complète
1. Installer Arch ## 1. Préparer le disque
2. Installer git
3. Cloner arch-system Depuis lISO Arch :
4. Restaurer les fichiers rootfs
5. Installer les paquets ```bash
6. Installer les dotfiles sudo ./scripts/prepare-disk.sh /dev/nvme0n1
7. Vérifier Limine ```
8. Vérifier Snapper
9. Vérifier Secure Boot La commande est destructive et exige une confirmation explicite.
10. Vérifier nftables
## 2. Installer la base
Exemple :
```bash
pacstrap -K /mnt base linux-lts linux-firmware amd-ucode btrfs-progs networkmanager git sudo neovim
```
Générer ensuite le `fstab` depuis les montages réels :
```bash
genfstab -U /mnt >> /mnt/etc/fstab
```
Ne jamais recopier directement lancien `fstab`.
## 3. Configuration de base
Après `arch-chroot /mnt` :
- fuseau horaire, locale et hostname ;
- utilisateur et sudo ;
- réseau ;
- Limine ;
- initramfs ;
- Secure Boot ;
- Snapper.
## 4. Cloner le dépôt
```bash
git clone https://git.labfytools.com/fy59/arch-system
cd arch-system
```
## 5. Restaurer par étapes
```bash
./scripts/deploy.sh --packages
./scripts/deploy.sh --configs
./scripts/deploy.sh --tools
./scripts/deploy.sh --services
```
## 6. Finaliser manuellement
- adapter `templates/fstab.btrfs` aux nouveaux UUID ;
- adapter `templates/limine.conf` à lUUID Btrfs ;
- lancer `mkinitcpio -P` ;
- installer et configurer Limine ;
- créer la configuration Snapper ;
- lancer limine-snapper-sync ;
- enrôler puis signer avec `sbctl` ;
- restaurer les dotfiles séparément ;
- tester `nftables`, SSH, audio, veille et seuil de batterie avant le premier usage normal.

15
docs/security.md Normal file
View file

@ -0,0 +1,15 @@
# Sécurité du dépôt
Le dépôt est public. Ne jamais y stocker :
- clés Secure Boot ;
- clés SSH privées ou clés hôte ;
- mots de passe dapplication ;
- `.netrc` ;
- tokens Forgejo ;
- configurations WireGuard ;
- connexions NetworkManager ;
- bases SQLite ou données denquête ;
- sauvegardes brutes de `/root`.
Les règles sudoers fournies sont limitées à des helpers root contrôlés. Ne jamais autoriser sans mot de passe `/usr/bin/systemctl`, `/usr/bin/tee`, un shell ou un éditeur généraliste.

59
docs/ssd-migration.md Normal file
View file

@ -0,0 +1,59 @@
# Migration du SSD 512 Go vers 1 To
## Support de secours
Carte SD Ventoy contenant :
- Arch Linux ;
- Clonezilla Live ;
- GParted Live.
Avec des clés Secure Boot personnelles, désactiver temporairement Secure Boot pour démarrer Ventoy sans supprimer les clés du firmware.
## Avant le clonage
1. placer le SSD neuf dans le boîtier NVMe USB ;
2. vérifier modèle, taille et santé ;
3. identifier la source et la cible par modèle et capacité ;
4. sauvegarder les données irremplaçables ;
5. arrêter les VM et applications écrivant massivement.
Commandes de contrôle :
```bash
lsblk -p -o NAME,MODEL,SIZE,TRAN,FSTYPE,MOUNTPOINTS
sudo smartctl -a /dev/nvme0n1
```
## Clonezilla
Choisir :
```text
device-device
Beginner
disk_to_local_disk
```
Source : Samsung 512 Go. Cible : Fanxiang 1 To.
La cible est entièrement effacée.
## Premier démarrage
- éteindre complètement ;
- monter le Fanxiang dans le portable ;
- ne pas brancher simultanément lancien clone en USB ;
- démarrer et vérifier Btrfs, Limine, Snapper et Secure Boot.
## Utiliser lespace supplémentaire
Agrandir dabord la partition Btrfs avec GParted ou `parted`, puis :
```bash
sudo btrfs filesystem resize max /
df -h /
sudo btrfs filesystem usage /
```
Garder le Samsung intact plusieurs jours avant de le reformater comme SSD externe.

5
inventory/README.md Normal file
View file

@ -0,0 +1,5 @@
# Inventaires générés
Ces fichiers sont régénérés par `scripts/backup.sh` depuis ArchASP.
Ils documentent le système mais ne constituent pas tous une configuration à restaurer automatiquement. Les fichiers de `manifests/` représentent lintention ; les fichiers de `inventory/systemd/` représentent létat observé.

View file

@ -0,0 +1,5 @@
UUID: fd788a35-b3ee-48a4-9d7c-4f9bcdc46614
no stats available
Total to scrub: 322.71GiB
Rate: 0.00B/s
Error summary: no errors found

View file

@ -0,0 +1,30 @@
ID 256 gen 76268 top level 5 path @
ID 257 gen 76268 top level 5 path @home
ID 258 gen 76268 top level 5 path @log
ID 259 gen 75805 top level 5 path @pkg
ID 260 gen 16 top level 256 path var/lib/portables
ID 261 gen 16 top level 256 path var/lib/machines
ID 1517 gen 76268 top level 256 path .snapshots
ID 1756 gen 73850 top level 1517 path .snapshots/239/snapshot
ID 1757 gen 73851 top level 1517 path .snapshots/240/snapshot
ID 1758 gen 73879 top level 1517 path .snapshots/241/snapshot
ID 1759 gen 73880 top level 1517 path .snapshots/242/snapshot
ID 1760 gen 75528 top level 256 path swap
ID 1761 gen 74485 top level 1517 path .snapshots/243/snapshot
ID 1762 gen 74486 top level 1517 path .snapshots/244/snapshot
ID 1763 gen 74492 top level 1517 path .snapshots/245/snapshot
ID 1764 gen 74493 top level 1517 path .snapshots/246/snapshot
ID 1765 gen 74818 top level 1517 path .snapshots/247/snapshot
ID 1766 gen 74821 top level 1517 path .snapshots/248/snapshot
ID 1767 gen 74823 top level 1517 path .snapshots/249/snapshot
ID 1768 gen 74824 top level 1517 path .snapshots/250/snapshot
ID 1769 gen 75514 top level 1517 path .snapshots/251/snapshot
ID 1770 gen 75517 top level 1517 path .snapshots/252/snapshot
ID 1771 gen 75565 top level 1517 path .snapshots/253/snapshot
ID 1772 gen 75566 top level 1517 path .snapshots/254/snapshot
ID 1773 gen 75568 top level 1517 path .snapshots/255/snapshot
ID 1774 gen 75569 top level 1517 path .snapshots/256/snapshot
ID 1775 gen 75802 top level 1517 path .snapshots/257/snapshot
ID 1776 gen 75804 top level 1517 path .snapshots/258/snapshot
ID 1777 gen 76265 top level 1517 path .snapshots/259/snapshot
ID 1778 gen 76267 top level 1517 path .snapshots/260/snapshot

View file

@ -0,0 +1,25 @@
Overall:
Device size: 475.94GiB
Device allocated: 454.94GiB
Device unallocated: 21.00GiB
Device missing: 0.00B
Device slack: 0.00B
Used: 322.71GiB
Free (estimated): 132.19GiB (min: 121.69GiB)
Free (statfs, df): 132.19GiB
Data ratio: 1.00
Metadata ratio: 2.00
Global reserve: 512.00MiB (used: 0.00B)
Multiple profiles: no
Data,single: Size:428.92GiB, Used:317.73GiB (74.08%)
/dev/nvme0n1p2 428.92GiB
Metadata,DUP: Size:13.00GiB, Used:2.49GiB (19.17%)
/dev/nvme0n1p2 26.00GiB
System,DUP: Size:8.00MiB, Used:80.00KiB (0.98%)
/dev/nvme0n1p2 16.00MiB
Unallocated:
/dev/nvme0n1p2 21.00GiB

View file

@ -0,0 +1,31 @@
TARGET SOURCE FSTYPE OPTIONS
/ /dev/nvme0n1p2[/@] btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=256,subvol=/@
├─/proc proc proc rw,nosuid,nodev,noexec,relatime
│ └─/proc/sys/fs/binfmt_misc systemd-1 autofs rw,relatime,fd=44,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=9380
│ └─/proc/sys/fs/binfmt_misc binfmt_misc binfmt_misc rw,nosuid,nodev,noexec,relatime
├─/sys sys sysfs rw,nosuid,nodev,noexec,relatime
│ ├─/sys/firmware/efi/efivars efivarfs efivarfs rw,nosuid,nodev,noexec,relatime
│ ├─/sys/kernel/security securityfs securityfs rw,nosuid,nodev,noexec,relatime
│ ├─/sys/fs/cgroup cgroup2 cgroup2 rw,nosuid,nodev,noexec,relatime,nsdelegate,memory_recursiveprot,memory_hugetlb_accounting
│ ├─/sys/fs/pstore none pstore rw,nosuid,nodev,noexec,relatime
│ ├─/sys/fs/bpf bpf bpf rw,nosuid,nodev,noexec,relatime,mode=700
│ ├─/sys/kernel/debug debugfs debugfs rw,nosuid,nodev,noexec,relatime
│ ├─/sys/kernel/config configfs configfs rw,nosuid,nodev,noexec,relatime
│ ├─/sys/kernel/tracing tracefs tracefs rw,nosuid,nodev,noexec,relatime
│ └─/sys/fs/fuse/connections fusectl fusectl rw,nosuid,nodev,noexec,relatime
├─/dev dev devtmpfs rw,nosuid,relatime,size=7741852k,nr_inodes=1935463,mode=755,inode64,huge=advise
│ ├─/dev/shm tmpfs tmpfs rw,nosuid,nodev,inode64,huge=advise,usrquota
│ ├─/dev/pts devpts devpts rw,nosuid,noexec,relatime,gid=5,mode=600,ptmxmode=000
│ ├─/dev/mqueue mqueue mqueue rw,nosuid,nodev,noexec,relatime
│ └─/dev/hugepages hugetlbfs hugetlbfs rw,nosuid,nodev,relatime,pagesize=2M
├─/run run tmpfs rw,nosuid,nodev,relatime,mode=755,inode64,huge=advise
│ ├─/run/credentials/systemd-journald.service none tmpfs ro,nosuid,nodev,noexec,relatime,nosymfollow,size=1024k,nr_inodes=1024,mode=700,inode64,huge=advise,noswap
│ └─/run/user/1000 tmpfs tmpfs rw,nosuid,nodev,relatime,size=1559772k,nr_inodes=389943,mode=700,uid=1000,gid=1000,inode64,huge=advise
│ ├─/run/user/1000/gvfs gvfsd-fuse fuse.gvfsd-fuse rw,nosuid,nodev,relatime,user_id=1000,group_id=1000
│ └─/run/user/1000/doc portal fuse.portal rw,nosuid,nodev,relatime,user_id=1000,group_id=1000
├─/home /dev/nvme0n1p2[/@home] btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=257,subvol=/@home
├─/.snapshots /dev/nvme0n1p2[/@/.snapshots] btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=1517,subvol=/@/.snapshots
├─/tmp tmpfs tmpfs rw,nosuid,nodev,nr_inodes=1048576,inode64,huge=advise,usrquota
├─/var/cache/pacman/pkg /dev/nvme0n1p2[/@pkg] btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=259,subvol=/@pkg
├─/var/log /dev/nvme0n1p2[/@log] btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvolid=258,subvol=/@log
└─/boot /dev/nvme0n1p1 vfat rw,relatime,fmask=0022,dmask=0022,codepage=437,iocharset=ascii,shortname=mixed,utf8,errors=remount-ro

View file

@ -0,0 +1,12 @@
NAME MODEL SIZE ROTA TRAN FSTYPE FSVER LABEL UUID PARTUUID MOUNTPOINTS
sda Card Reader 14,9G 1 usb
├─sda1 14,9G 1 exfat 1.0 Ventoy B6FD-1B0E 8d4448e5-01
└─sda2 32M 1 vfat FAT16 VTOYEFI 1998-3510 8d4448e5-02
zram0 6G 0 swap 1 zram0 2bb7ba7b-bdf6-46a3-9dcf-39d11b345a6c [SWAP]
nvme0n1 SAMSUNG MZVL8512HELU-00BTW 476,9G 0 nvme
├─nvme0n1p1 1G 0 nvme vfat FAT32 74CA-B4A5 6a729979-0103-4dbd-a639-bb64b6185580 /boot
└─nvme0n1p2 475,9G 0 nvme btrfs fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 85b1221d-8402-4e4a-a8f3-94377eded84a /var/log
/home
/var/cache/pacman/pkg
/.snapshots
/

View file

@ -0,0 +1,3 @@
total utilisé libre partagé tamp/cache disponible
Mem: 14Gi 5,3Gi 2,8Gi 187Mi 6,6Gi 9,6Gi
Échange: 6,0Gi 0B 6,0Gi

View file

@ -0,0 +1,25 @@
Smart Log for NVME device:nvme0 namespace-id:ffffffff
critical_warning : 0
temperature : 41 °C (314 K, 105 °F)
available_spare : 100%
available_spare_threshold : 5%
percentage_used : 1%
endurance group critical warning summary: 0
Data Units Read : 34970959 (17.91 TB)
Data Units Written : 14523079 (7.44 TB)
host_read_commands : 268237215
host_write_commands : 173265514
controller_busy_time : 894
power_cycles : 1848
power_on_hours : 461
unsafe_shutdowns : 61
media_errors : 0
num_err_log_entries : 0
Warning Temperature Time : 0
Critical Composite Temperature Time : 0
Temperature Sensor 1 : 43 °C (316 K, 109 °F)
Temperature Sensor 2 : 41 °C (314 K, 105 °F)
Thermal Management T1 Trans Count : 0
Thermal Management T2 Trans Count : 0
Thermal Management T1 Total Time : 0
Thermal Management T2 Total Time : 0

View file

@ -0,0 +1,2 @@
NAME TYPE SIZE USED PRIO
/dev/zram0 partition 6G 0B 100

View file

@ -0,0 +1,13 @@
NetworkManager-dispatcher.service enabled disabled
NetworkManager-wait-online.service enabled disabled
NetworkManager.service enabled disabled
blueman-mechanism.service enabled disabled
bluetooth.service enabled disabled
cups.service enabled disabled
getty@.service enabled enabled
greetd.service enabled disabled
nftables.service enabled disabled
sshd.service enabled disabled
systemd-timesyncd.service enabled enabled
tlp-pd.service enabled disabled
tlp.service enabled disabled

View file

View file

@ -0,0 +1,19 @@
NetworkManager.service loaded active running Network Manager
bluetooth.service loaded active running Bluetooth service
cups.service loaded active running CUPS Scheduler
dbus-broker.service loaded active running D-Bus System Message Bus
greetd.service loaded active running Greeter daemon
polkit.service loaded active running Authorization Manager
rtkit-daemon.service loaded active running RealtimeKit Scheduling Policy Service
snapperd.service loaded active running DBus interface for snapper
sshd.service loaded active running OpenSSH Daemon
systemd-journald.service loaded active running Journal Service
systemd-logind.service loaded active running User Login Management
systemd-timesyncd.service loaded active running Network Time Synchronization
systemd-udevd.service loaded active running Rule-based Manager for Device Events and Files
systemd-userdbd.service loaded active running User Database Manager
tlp-pd.service loaded active running TLP profiles daemon API service
udisks2.service loaded active running Disk Manager
upower.service loaded active running Daemon for power management
user@1000.service loaded active running User Manager for UID 1000
wpa_supplicant.service loaded active running WPA supplicant

View file

@ -0,0 +1,7 @@
Mon 2026-07-27 00:00:00 CEST 47min Sun 2026-07-26 00:00:04 CEST - shadow.timer shadow.service
Mon 2026-07-27 00:00:00 CEST 47min Sun 2026-07-26 23:00:02 CEST 12min ago snapper-timeline.timer snapper-timeline.service
Mon 2026-07-27 01:06:16 CEST 1h 53min Mon 2026-07-20 07:01:26 CEST - fstrim.timer fstrim.service
Mon 2026-07-27 11:52:03 CEST 12h Sun 2026-07-26 00:29:03 CEST - man-db.timer man-db.service
Mon 2026-07-27 20:39:32 CEST 21h Sun 2026-07-26 20:39:32 CEST 2h 33min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Sat 2026-08-01 22:14:27 CEST 5 days Mon 2026-07-20 14:58:08 CEST - archlinux-keyring-wkd-sync.timer archlinux-keyring-wkd-sync.service
Sun 2026-07-26 23:34:32 CEST 21min Sun 2026-07-26 22:34:32 CEST 38min ago snapper-cleanup.timer snapper-cleanup.service

View file

@ -0,0 +1,10 @@
clean-makepkg.service enabled enabled
cliphist-image.service enabled enabled
cliphist-text.service enabled enabled
gnome-keyring-daemon.service enabled enabled
keyring.service enabled enabled
ssh-agent.service enabled enabled
swayidle.service enabled enabled
wireplumber.service enabled enabled
wlsunset.service enabled enabled
ydotool.service enabled enabled

View file

View file

@ -0,0 +1,30 @@
app-blueman@autostart.service loaded active running Blueman Applet
app-limine\x2dsnapper\x2dnotify@autostart.service loaded active running Limine-snapper-notify
app-print\x2dapplet@autostart.service loaded active running Print Queue Applet
at-spi-dbus-bus.service loaded active running Accessibility services bus
cliphist-image.service loaded active running Cliphist image watcher
cliphist-text.service loaded active running Cliphist text watcher
dbus-:1.2-org.mpris.MediaPlayer2.playerctld@0.service loaded active running dbus-:1.2-org.mpris.MediaPlayer2.playerctld@0.service
dbus-:1.27-org.a11y.atspi.Registry@0.service loaded active running dbus-:1.27-org.a11y.atspi.Registry@0.service
dbus-broker.service loaded active running D-Bus User Message Bus
dconf.service loaded active running User preferences database
gnome-keyring-daemon.service loaded active running GNOME Keyring
gvfs-daemon.service loaded active running Virtual filesystem service
gvfs-metadata.service loaded active running Virtual filesystem metadata service
gvfs-udisks2-volume-monitor.service loaded active running Virtual filesystem service - disk device monitor
mako.service loaded active running Lightweight Wayland notification daemon
pipewire-pulse.service loaded active running PipeWire PulseAudio
pipewire.service loaded active running PipeWire Multimedia Service
protonmail-bridge.service loaded active running Proton Mail Bridge
ssh-agent.service loaded active running SSH agent
swayidle.service loaded active running Wayland swayidle
wayland-session-bindpid@2112.service loaded active running Bind graphical session to PID 2112
wayland-wm@sway.desktop.service loaded active running Main service for Sway, An i3-compatible Wayland compositor
wireplumber.service loaded active running Multimedia Service Session Manager
wlsunset.service loaded active running Wayland color temperature (wlsunset)
xdg-desktop-portal-gtk.service loaded active running Portal service (GTK/GNOME implementation)
xdg-desktop-portal-wlr.service loaded active running Portal service (wlroots implementation)
xdg-desktop-portal.service loaded active running Portal service
xdg-document-portal.service loaded active running flatpak document portal service
xdg-permission-store.service loaded active running sandboxed app permission store
ydotool.service loaded active running Starts ydotoold service

View file

@ -0,0 +1 @@
Sun 2026-07-26 23:13:02 CEST 14s Sun 2026-07-26 23:12:02 CEST 45s ago battery-low-notify.timer battery-low-notify.service

View file

@ -0,0 +1,4 @@
nmb.service
smb.service
vmware-networks.service
vmware-usbarbitrator.service

View file

@ -0,0 +1,13 @@
NetworkManager-dispatcher.service
NetworkManager-wait-online.service
NetworkManager.service
blueman-mechanism.service
bluetooth.service
cups.service
getty@.service
greetd.service
nftables.service
sshd.service
systemd-timesyncd.service
tlp-pd.service
tlp.service

View file

@ -0,0 +1,3 @@
fstrim.timer
snapper-cleanup.timer
snapper-timeline.timer

View file

@ -1,45 +1,12 @@
a2ln
appflowy-bin appflowy-bin
appflowy-bin-debug bibata-cursor-theme
bridge-utils bridge-utils
bridge-utils-debug
calcure
catppuccin-cursors-mocha
catppuccin-gtk-theme-mocha
clang-format-all-git
go-mtpfs-git go-mtpfs-git
hyprwhspr hyprwhspr
jmtpfs jmtpfs
limine-snapper-sync limine-snapper-sync
mangowm-git openai-codex-desktop
mkinitcpio-numlock
openssl-1.1
openssl-1.1-debug
perplexity
proton-authenticator-bin-debug
proton-pass-bin proton-pass-bin
proton-pass-bin-debug
python-convertdate
python-hijridate
python-holidays
python-jalali-core
python-jdatetime
python-korean_lunar_calendar
python-nspektr
python-pulsectl
python-sounddevice
scenefx0.4
simple-mtpfs
spicetify-cli
spicetify-cli-debug
spicetify-marketplace-bin spicetify-marketplace-bin
swayfx vmware-workstation
swaylock-effects
swaylock-effects-debug
ungoogled-chromium-widevine-bin
waybar-module-pacman-updates-git
wlogout-git
xdg-desktop-portal-termfilechooser-hunkyburrito-git
xdg-desktop-portal-termfilechooser-hunkyburrito-git-debug
yay yay
yay-debug

0
pkglist/orphans.txt Normal file
View file

View file

@ -1,12 +1,12 @@
7zip 7zip
a2ln
alsa-utils alsa-utils
amd-ucode amd-ucode
amdgpu_top
android-file-transfer android-file-transfer
android-tools android-tools
ansible ansible
appflowy-bin
atuin atuin
autotiling
axel axel
base base
base-devel base-devel
@ -17,27 +17,26 @@ bind
blueman blueman
bluez bluez
bluez-utils bluez-utils
bridge-utils
bridge-utils-debug
brightnessctl brightnessctl
btop btop
btrfs-progs btrfs-progs
calcure
catppuccin-cursors-mocha
catppuccin-gtk-theme-mocha
ccache ccache
clang clang
clang-format-all-git
cliphist cliphist
cloc
composer composer
cowsay cowsay
cppcheck
cpupower cpupower
cups cups
cups-pk-helper cups-pk-helper
dmidecode
dnsmasq dnsmasq
docker docker
dosfstools dosfstools
efibootmgr efibootmgr
evince
evtest
exfatprogs exfatprogs
eza eza
fastfetch fastfetch
@ -46,17 +45,20 @@ ffmpegthumbnailer
figlet figlet
firefox firefox
firefox-i18n-fr firefox-i18n-fr
freecad
fzf fzf
gimp gimp
gimp-help-fr gimp-help-fr
git git
gnome-keyring gnome-keyring
gnu-free-fonts gnu-free-fonts
go-mtpfs-git
greetd-tuigreet greetd-tuigreet
grim grim
grub grub
gst-libav
gst-plugin-gtk4
gst-plugin-pipewire gst-plugin-pipewire
gst-plugins-good
gtk4 gtk4
gtklock gtklock
gtklock-playerctl-module gtklock-playerctl-module
@ -64,13 +66,12 @@ gtklock-powerbar-module
gtklock-userinfo-module gtklock-userinfo-module
gvfs gvfs
heimdall heimdall
hyprwhspr
i3status-rust i3status-rust
ifuse ifuse
imagemagick imagemagick
inotify-tools inotify-tools
jdk-openjdk jdk-openjdk
jmtpfs john
julia julia
kitty kitty
less less
@ -80,9 +81,7 @@ libimobiledevice
libmtp libmtp
libplist libplist
libpulse libpulse
libvirt
limine limine
limine-snapper-sync
linux-firmware linux-firmware
linux-lts linux-lts
linux-lts-headers linux-lts-headers
@ -92,10 +91,9 @@ luarocks
mako mako
man-pages man-pages
man-pages-fr man-pages-fr
mangowm-git
memtest86+ memtest86+
memtest86+-efi memtest86+-efi
mkinitcpio-numlock meson
mold mold
mpv mpv
mtpfs mtpfs
@ -107,54 +105,61 @@ noto-fonts-emoji
npm npm
ntfs-3g ntfs-3g
ntp ntp
nvme-cli
opencode
openresolv openresolv
openssh openssh
pacman-contrib
pavucontrol pavucontrol
perplexity perl-image-exiftool
php php
pipewire pipewire
pipewire-alsa pipewire-alsa
pipewire-jack pipewire-jack
pipewire-libcamera pipewire-libcamera
pipewire-pulse pipewire-pulse
proton-pass-bin powertop
protonmail-bridge protonmail-bridge
pyenv pyenv
pyright pyright
python-i3ipc python-i3ipc
python-pipenv python-pipenv
python-pynvim python-pynvim
qemu-desktop
qt5-wayland qt5-wayland
qt5ct qt5ct
qt6-wayland qt6-wayland
qt6ct qt6ct
reflector reflector
ripgrep ripgrep
rocm-smi-lib
rofi rofi
rsync rsync
ruby ruby
rustup rustup
samba samba
sbctl sbctl
simple-mtpfs
slurp slurp
snap-pac snap-pac
snapper snapper
sof-firmware sof-firmware
spicetify-marketplace-bin spirv-headers
spotify-launcher spotify-launcher
sqlitebrowser
starship starship
stow stow
sudo sudo
sway
swaybg swaybg
swayfx
swayidle swayidle
swaylock-effects swaylock
swaync swaync
system-config-printer system-config-printer
tcpdump
tela-circle-icon-theme-all tela-circle-icon-theme-all
terminus-font terminus-font
tesseract
tesseract-data-eng
tesseract-data-fra
thunar thunar
thunar-archive-plugin thunar-archive-plugin
thunar-volman thunar-volman
@ -164,43 +169,46 @@ tlp
tlp-pd tlp-pd
tlp-rdw tlp-rdw
tmux tmux
traceroute
transmission-cli
transmission-gtk
tree tree
tree-sitter-cli tree-sitter-cli
ttf-dejavu ttf-dejavu
ttf-fira-code
ttf-jetbrains-mono
ttf-jetbrains-mono-nerd ttf-jetbrains-mono-nerd
tumbler tumbler
ungoogled-chromium-widevine-bin typst
unrar
unzip unzip
usbmuxd usbmuxd
usbutils usbutils
uwsm uwsm
valgrind valgrind
virt-manager
vlc vlc
vulkan-headers vulkan-headers
vulkan-radeon vulkan-radeon
vulkan-tools vulkan-tools
waybar waybar
waybar-module-pacman-updates-git
wayland-utils wayland-utils
webp-pixbuf-loader webp-pixbuf-loader
wev wev
wget wget
whois
wireguard-tools wireguard-tools
wireplumber wireplumber
wl-clipboard wl-clipboard
wlogout-git
wlopm wlopm
wlr-randr wlr-randr
wlsunset wlsunset
wofi wofi
wpa_supplicant wpa_supplicant
xdg-desktop-portal xdg-desktop-portal
xdg-desktop-portal-termfilechooser-hunkyburrito-git
xdg-desktop-portal-wlr xdg-desktop-portal-wlr
xf86-video-amdgpu xf86-video-amdgpu
yay xorg-xrdb
yay-debug xorg-xwayland
yazi yazi
zoxide zoxide
zram-generator zram-generator

View file

@ -1,102 +0,0 @@
term_palette: 1e1e2e;f3ba8;a6e3a1;f9e2af;89b4fa;f5c2e7;94e2d5;cdd6f4
term_palette_bright: 58b70;f38ba8;f9e2af;89b4fa;f5c2e7;94e2d5;cdd6f4
term_background: 1e1e2e
term_foreground: cdd6f4
term_background_bright: 585b70
term_foreground_bright: cdd6f4
timeout: 5
default_entry: 1
interface_resolution: 1920x1080
/Arch Linux Zen
//Kernel Zen
protocol: linux
kernel_path: boot():/vmlinuz-linux-zen
module_path: boot():/amd-ucode.img
module_path: boot():/initramfs-linux-zen.img
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=@ quiet loglevel=3
//Snapshots
### Auto-generated by limine-snapper-sync
comment: 8 / 8 snapshots
///14 │ 2026-05-30 22:04:29
comment: grub-btrfs
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/14/snapshot quiet loglevel=3
///13 │ 2026-05-30 22:04:18
comment: pacman -Rns grub-btrfs
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/13/snapshot quiet loglevel=3
///12 │ 2026-05-29 16:04:32
comment: gimp
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/12/snapshot quiet loglevel=3
///11 │ 2026-05-29 16:04:30
comment: pacman -S --config /etc/pacman.conf -- extra/gimp
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/11/snapshot quiet loglevel=3
///10 │ 2026-05-29 14:10:04
comment: qemu-audio-alsa qemu-audio-dbus qemu-audio-jack qemu-audio-oss qemu-audi
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/10/snapshot quiet loglevel=3
///9 │ 2026-05-29 14:10:03
comment: pacman -S -y -y -u --config /etc/pacman.conf --
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/9/snapshot quiet loglevel=3
///8 │ 2026-05-29 14:08:49
comment: test hook limine
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/8/snapshot quiet loglevel=3
///7 │ 2026-05-29 14:07:32
comment: test limine snapper
////Kernel Zen
protocol: linux
kernel_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/vmlinuz-linux-zen_sha256_059e7313d7686fcd48c40db539b466a5af40c44397216924f6f5ddcf89ffeef1
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/amd-ucode.img_sha256_752576f7cc851091c59ccd8d4a0dd6afd1bb4a0cf48bcbfc2952c011fb25bece
module_path: boot():/04421f06d97d4b9aa9892f30e3a29d35/limine_history/initramfs-linux-zen.img_sha256_4b2fab220fda339eac5a008a6af55064c80626e2e642a9281291f6b336d4ceb3
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=/@/.snapshots/7/snapshot quiet loglevel=3
/Arch Linux LTS
//Kernel LTS
protocol: linux
kernel_path: boot():/vmlinuz-linux-lts
module_path: boot():/amd-ucode.img
module_path: boot():/initramfs-linux-lts.img
kernel_cmdline: root=UUID=fd788a35-b3ee-48a4-9d7c-4f9bcdc46614 rw rootflags=subvol=@ quiet loglevel=3
/Memtest86+
protocol: efi
path: boot():/Memtest86+/memtest.efi

View file

@ -36,6 +36,11 @@ table inet filter {
iifname "virbr0" ct state established,related accept iifname "virbr0" ct state established,related accept
iifname "virbr0" ip daddr 192.168.122.1 accept iifname "virbr0" ip daddr 192.168.122.1 accept
iifname "vmnet8" tcp dport {139,445} accept
iifname "vmnet8" udp dport {137,138} accept
iifname "vmnet1" tcp dport {139,445} accept
iifname "vmnet1" udp dport {137,138} accept
meta nfproto ipv6 drop meta nfproto ipv6 drop
} }
@ -76,6 +81,8 @@ table inet filter {
oifname "wg0" tcp dport 2223 accept oifname "wg0" tcp dport 2223 accept
oifname "wg0" tcp dport { 993, 587 } accept oifname "wg0" tcp dport { 993, 587 } accept
oifname "wg0" udp dport 123 accept
# Handshakes WG via wlan0 # Handshakes WG via wlan0
oifname "wlp1s0" udp dport 51820 accept oifname "wlp1s0" udp dport 51820 accept
oifname "wlp1s0" udp dport 51821 accept oifname "wlp1s0" udp dport 51821 accept
@ -91,6 +98,9 @@ table inet filter {
oifname "wlp1s0" ip daddr 192.168.1.1 icmp type echo-request accept oifname "wlp1s0" ip daddr 192.168.1.1 icmp type echo-request accept
oifname "wlp1s0" ip daddr 192.168.1.0/24 accept oifname "wlp1s0" ip daddr 192.168.1.0/24 accept
oifname "vmnet8" accept
oifname "vmnet1" accept
# Handshakes WG qui passeraient DANS le tunnel Proton (si c'est voulu) # Handshakes WG qui passeraient DANS le tunnel Proton (si c'est voulu)
oifname "wg0" udp dport 51820 accept oifname "wg0" udp dport 51820 accept
oifname "wg0" udp dport 51821 accept oifname "wg0" udp dport 51821 accept
@ -103,9 +113,7 @@ table inet filter {
table ip nat { table ip nat {
chain postrouting { chain postrouting {
type nat hook postrouting priority srcnat; type nat hook postrouting priority srcnat; policy accept;
policy accept;
ip saddr 192.168.122.0/24 oifname "wg0" masquerade ip saddr 192.168.122.0/24 oifname "wg0" masquerade
} }
} }

View file

@ -1,10 +0,0 @@
[Unit]
Description=Set ASUS BAT1 charge threshold to 80%%
After=multi-user.target
[Service]
Type=oneshot
ExecStart=/usr/bin/sh -c 'echo 80 > /sys/class/power_supply/BAT1/charge_control_end_threshold'
[Install]
WantedBy=multi-user.target

View file

@ -0,0 +1,2 @@
[zram0]
compression-algorithm = zstd

View file

@ -1,640 +0,0 @@
# ----------------------------------------------------------------------------
# /etc/tlp.conf - TLP user configuration (version 1.10.0)
# See full explanation: https://linrunner.de/tlp/settings
#
# Copyright (c) 2026 Thomas Koch <linrunner at gmx.net> and others.
# SPDX-License-Identifier: GPL-2.0-or-later
#
# Settings are read in the following order:
#
# 1. Intrinsic defaults
# 2. /etc/tlp.d/*.conf - Drop-in customization snippets
# 3. /etc/tlp.conf - User configuration (this file)
#
# TLP profiles: a part of TLP's parameters is divided into two or three
# groups:
# - performance: parameters ending in _AC are used when AC power is
# connected or when the command 'tlp performance' is run.
# - balanced: parameters ending in _BAT are used when operating
# on battery power or when the command 'tlp balanced' is run.
# - power-saver: parameters ending in _SAV are used when the command
# 'tlp power-saver' is run. If there is no _SAV parameter available
# for a feature, the _BAT parameter will be used instead.
# - Any remaining parameters not divided apply to all TLP profiles.
#
# Please note:
# - If parameters are specified more than once, the last occurrence takes
# precedence. This also means that any parameters defined here will take
# precedence over any drop-ins.
# - You can however, append values to a parameter already defined as default
# or in a previously read file: use PARAMETER+="add values".
# - Important: in its native state, all of the parameters in this file are
# commented out with a leading '#', so the defaults (if any) apply.
# Remove the leading '#' if you want to enable a feature without a default
# or if you want to set a value other than the default.
# - Parameters must always be specified for all TLP profiles, i.e. in the
# AC, BAT and SAV category (where applicable). If you omit one of them,
# the missing profile will receive its value from another profile, since
# a change will only occur if different values are defined.
# - To completely disable a feature, use PARAMETER="".
# Legend for defaults:
# - Default *: effective value when the parameter is missing or the line has
# a leading '#'.
# - Default <none>: feature disabled, use kernel or hardware defaults.
#
# ----------------------------------------------------------------------------
# tlp - Parameters for power saving
# Set to 0 to disable, 1 to enable TLP.
# Default: 1
# TLP_ENABLE=1
# Set to 1 to disable (almost) all defaults of TLP.
# This means that TLP only applies settings that have been explicitly activated
# i.e. parameters without leading '#'.
# Notes:
# - Helpful if one wants to use only selected features of TLP
# - After activation, use tlp-stat -c to display your effective configuration
# - TLP's operation relies on the defaults of TLP_ENABLE, TLP_WARN_LEVEL,
# TLP_AUTO_SWITCH, and TLP_PROFILE_AC/BAT, which are *not* disabled
#
#TLP_DISABLE_DEFAULTS=1
# Control how warnings about invalid settings are issued:
# 0=disabled
# 1=background tasks (boot, resume, change of power source) report to syslog
# 2=shell commands report to the terminal (stderr)
# 3=combination of 1 and 2
# Default: 3
#TLP_WARN_LEVEL=3
# Colorize error, warning, notice and success messages. Colors are specified
# with ANSI codes:
# 1=bold black, 90=grey, 91=red, 92=green, 93=yellow, 94=blue, 95=magenta,
# 96=cyan, 97=white.
# Other colors are possible, refer to:
# https://en.wikipedia.org/wiki/ANSI_escape_code#3-bit_and_4-bit
# Colors must be specified in the order
# "<error> <warning> <notice> <success>".
# By default, errors are shown in red, warnings in yellow, notices in bold
# and success in green.
# Default: "91 93 1 92"
#TLP_MSG_COLORS="91 93 1 92"
# Control automatic switching of the TLP profile when connecting or removing
# the charger, when booting the system or when executing 'tlp start':
# 0=disabled - never switch, use TLP_PROFILE_DEFAULT if configured
# 1=auto - always switch, select TLP_PROFILE_AC on AC and TLP_PROFILE_BAT
# on battery power.
# 2=smart - like auto, but skips the switch if you have manually changed the
# profile away from the previous power source's default profile
# (as defined by TLP_PROFILE_AC/BAT).
# Note: the same applies if the charger was connected/removed during suspend.
# Default: 2
#TLP_AUTO_SWITCH=2
# TLP profiles to use when automatic switching is enabled
# (TLP_AUTO_SWITCH=1 or 2):
# PRF=performance, BAL=balanced, SAV=power-saver.
# Default: PRF (AC power), BAL (battery power)
TLP_PROFILE_AC=PRF
TLP_PROFILE_BAT=BAL
# TLP profile to use when automatic switching is disabled
# (TLP_AUTO_SWITCH=0) or no power supply is detected:
# PRF=performance, BAL=balanced, SAV=power-saver.
# Note: legacy values AC and BAT continue to work. They are mapped to
# PRF and BAL, respectively.
# Default: <none>
#TLP_PROFILE_DEFAULT=BAL
# Power supply classes to ignore when determining TLP profile:
# AC, USB, BAT.
# Separate multiple classes with spaces.
# Note: try on laptops where operation mode AC/BAT is incorrectly detected.
# Default: <none>
#TLP_PS_IGNORE="BAT"
# Seconds laptop mode has to wait after the disk goes idle before doing a
# sync. Non-zero value enables, zero disables laptop mode.
# Default: 0 (AC), 2 (BAT)
#DISK_IDLE_SECS_ON_AC=0
#DISK_IDLE_SECS_ON_BAT=2
# Dirty page values (timeouts in secs).
# Default: 15 (AC), 60 (BAT)
#MAX_LOST_WORK_SECS_ON_AC=15
#MAX_LOST_WORK_SECS_ON_BAT=60
# Select a CPU scaling driver operation mode.
# Intel CPU with intel_pstate driver:
# active, passive.
# AMD Zen 2 or newer CPU with amd-pstate driver as of kernel 6.3/6.4(*):
# active, passive, guided(*).
# Default: <none>
#CPU_DRIVER_OPMODE_ON_AC=active
#CPU_DRIVER_OPMODE_ON_BAT=active
#CPU_DRIVER_OPMODE_ON_SAV=active
# Select a CPU frequency scaling governor.
# Intel CPU with intel_pstate driver or
# AMD CPU with amd-pstate driver in active mode ('amd-pstate-epp'):
# performance, powersave(*).
# Intel CPU with intel_pstate driver in passive mode ('intel_cpufreq') or
# AMD CPU with amd-pstate driver in passive or guided mode ('amd-pstate') or
# Intel, AMD and other CPU brands with acpi-cpufreq driver:
# conservative, ondemand(*), userspace, powersave, performance, schedutil(*)
# Use tlp-stat -p to show the active driver and available governors.
# Important:
# Governors marked (*) above are power efficient for *almost all* workloads
# and therefore kernel and most distributions have chosen them as defaults.
# You should have done your research about advantages/disadvantages *before*
# changing the governor.
# Default: <none>
#CPU_SCALING_GOVERNOR_ON_AC=performance
#CPU_SCALING_GOVERNOR_ON_BAT=powersave
#CPU_SCALING_GOVERNOR_ON_SAV=powersave
# Set the min/max frequency available for the scaling governor.
# Possible values depend on your CPU. For available frequencies see
# the output of tlp-stat -p.
# Notes:
# - Min/max frequencies must always be specified for both AC *and* BAT
# - Not recommended for use with the intel_pstate driver, use
# CPU_MIN/MAX_PERF_ON_AC/BAT below instead
# Default: <none>
#CPU_SCALING_MIN_FREQ_ON_AC=0
#CPU_SCALING_MAX_FREQ_ON_AC=0
#CPU_SCALING_MIN_FREQ_ON_BAT=0
#CPU_SCALING_MAX_FREQ_ON_BAT=0
#CPU_SCALING_MIN_FREQ_ON_SAV=0
#CPU_SCALING_MAX_FREQ_ON_SAV=0
# Set CPU energy/performance policies EPP and EPB:
# performance, balance_performance, default, balance_power, power.
# Values are given in order of increasing power saving.
# Requires:
# * Intel CPU
# EPP: Intel Core i 6th gen. or newer CPU with intel_pstate driver
# EPB: Intel Core i 2nd gen. or newer CPU with intel_pstate driver
# EPP and EPB are mutually exclusive: when EPP is available, Intel CPUs
# will not honor EPB. Only the matching feature will be applied by TLP.
# * AMD Zen 2 or newer CPU
# EPP: amd-pstate driver in active mode ('amd-pstate-epp') as of kernel 6.3
# Default: balance_performance (AC), balance_power (BAT), power (SAV)
CPU_ENERGY_PERF_POLICY_ON_AC=balance_performance
CPU_ENERGY_PERF_POLICY_ON_BAT=balance_power
CPU_ENERGY_PERF_POLICY_ON_SAV=power
# Set Intel CPU P-state performance: 0..100 (%).
# Limit the max/min P-state to control the power dissipation of the CPU.
# Values are stated as a percentage of the available performance.
# Requires Intel Core i 2nd gen. or newer CPU with intel_pstate driver.
# Default: <none>
#CPU_MIN_PERF_ON_AC=0
#CPU_MAX_PERF_ON_AC=100
#CPU_MIN_PERF_ON_BAT=0
#CPU_MAX_PERF_ON_BAT=80
#CPU_MIN_PERF_ON_SAV=0
#CPU_MAX_PERF_ON_SAV=60
# Set the CPU "turbo boost" (Intel) or "core performance boost" (AMD) feature:
# 0=disable, 1=allow.
# Allows to raise the maximum frequency/P-state of some cores if the
# CPU chip is not fully utilized and below it's intended thermal budget.
# Note: a value of 1 does *not* activate boosting, it just allows it.
# Default: <none>
CPU_BOOST_ON_AC=1
CPU_BOOST_ON_BAT=0
CPU_BOOST_ON_SAV=0
# Set CPU dynamic boost feature:
# 0=disable, 1=enable.
# Improve performance by increasing minimum P-state limit dynamically
# whenever a task previously waiting on I/O is selected to run.
# Requires Intel Core i 6th gen. or newer CPU with intel_pstate driver
# in active mode.
# Note: AMD CPUs currently have no tunable for this.
# Default: <none>
#CPU_HWP_DYN_BOOST_ON_AC=1
#CPU_HWP_DYN_BOOST_ON_BAT=1
#CPU_HWP_DYN_BOOST_ON_SAV=0
# Kernel NMI Watchdog:
# 0=disable (default, saves power), 1=enable (for kernel debugging only).
# Default: 0
#NMI_WATCHDOG=0
# Select platform profile:
# performance, balanced, low-power.
# Controls system operating characteristics around power/performance levels,
# thermal and fan speed. Values are given in order of increasing power saving.
# Note: check the output of tlp-stat -p to determine availability on your
# hardware and additional profiles such as: balanced-performance, quiet, cool.
# Default: performance (AC), balanced (BAT), low-power (SAV)
#PLATFORM_PROFILE_ON_AC=performance
PLATFORM_PROFILE_ON_BAT=quiet
#PLATFORM_PROFILE_ON_SAV=low-power
# System suspend mode:
# s2idle: Idle standby - a pure software, light-weight, system sleep state,
# deep: Suspend to RAM - the whole system is put into a low-power state,
# except for memory, usually resulting in higher savings than s2idle.
# CAUTION: changing suspend mode may lead to system instability and even
# data loss. As for the availability of different modes on your system,
# check the output of tlp-stat -s. If unsure, stick with the system default
# by not enabling this.
# Default: <none>
#MEM_SLEEP_ON_AC=s2idle
#MEM_SLEEP_ON_BAT=deep
# Define disk devices on which the following DISK/AHCI_RUNTIME parameters act.
# Separate multiple devices with spaces.
# Devices can be specified by disk ID also (lookup with: tlp diskid).
# Default: "nvme0n1 sda"
#DISK_DEVICES="nvme0n1 sda"
# Disk advanced power management level: 1..254, 255 (max saving, min, off).
# Levels 1..127 may spin down the disk; 255 allowable on most drives.
# Separate values for multiple disks with spaces. Use the special value 'keep'
# to keep the hardware default for the particular disk.
# Default: 254 (AC), 128 (BAT)
#DISK_APM_LEVEL_ON_AC="254 254"
#DISK_APM_LEVEL_ON_BAT="128 128"
# Exclude disk classes from advanced power management (APM):
# sata, ata, usb, ieee1394.
# Separate multiple classes with spaces.
# CAUTION: USB and IEEE1394 disks may fail to mount or data may get corrupted
# with APM enabled. Be careful and make sure you have backups of all affected
# media before removing 'usb' or 'ieee1394' from the denylist!
# Default: "usb ieee1394"
#DISK_APM_CLASS_DENYLIST="usb ieee1394"
# Hard disk spin down timeout:
# 0: spin down disabled
# 1..240: timeouts from 5s to 20min (in units of 5s)
# 241..251: timeouts from 30min to 5.5 hours (in units of 30min)
# See 'man hdparm' for details.
# Separate values for multiple disks with spaces. Use the special value 'keep'
# to keep the hardware default for the particular disk.
# Default: <none>
#DISK_SPINDOWN_TIMEOUT_ON_AC="0 0"
#DISK_SPINDOWN_TIMEOUT_ON_BAT="0 0"
# Select I/O scheduler for the disk devices.
# Multi queue (blk-mq) schedulers:
# mq-deadline(*), none, kyber, bfq
# Single queue schedulers:
# deadline(*), cfq, bfq, noop
# (*) recommended.
# Separate values for multiple disks with spaces. Use the special value 'keep'
# to keep the kernel default scheduler for the particular disk.
# Notes:
# - Multi queue (blk-mq) may need kernel boot option 'scsi_mod.use_blk_mq=1'
# and 'modprobe mq-deadline-iosched|kyber|bfq' on kernels < 5.0
# - Single queue schedulers are legacy now and were removed together with
# the old block layer in kernel 5.0
# Default: keep
#DISK_IOSCHED="mq-deadline mq-deadline"
# AHCI link power management (ALPM) for SATA disks:
# min_power, med_power_with_dipm(*), medium_power, max_performance.
# (*) recommended.
# Multiple values separated with spaces are tried sequentially until success.
# Default: med_power_with_dipm (AC & BAT)
#SATA_LINKPWR_ON_AC="med_power_with_dipm"
#SATA_LINKPWR_ON_BAT="med_power_with_dipm"
# Exclude SATA links from AHCI link power management (ALPM).
# SATA links are specified by their host. Refer to the output of
# tlp-stat -d to determine the host; the format is "hostX".
# Separate multiple hosts with spaces.
# Default: <none>
#SATA_LINKPWR_DENYLIST="host1"
# Runtime Power Management for NVMe, SATA, ATA and USB disks
# as well as SATA ports:
# on=disable, auto=enable.
# Note: SATA controllers are PCIe bus devices and handled by RUNTIME_PM
# further down.
# Default: on (AC), auto (BAT)
#AHCI_RUNTIME_PM_ON_AC=on
#AHCI_RUNTIME_PM_ON_BAT=auto
# Seconds of inactivity before disk is suspended.
# Note: effective only when AHCI_RUNTIME_PM_ON_AC/BAT is activated.
# Default: 15
#AHCI_RUNTIME_PM_TIMEOUT=15
# Power off optical drive in UltraBay/MediaBay: 0=disable, 1=enable.
# Drive can be powered on again by releasing (and reinserting) the eject lever
# or by pressing the disc eject button on newer models.
# Note: an UltraBay/MediaBay hard disk is never powered off.
# Default: 0
#BAY_POWEROFF_ON_AC=0
#BAY_POWEROFF_ON_BAT=0
# Optical drive device to power off
# Default: sr0
#BAY_DEVICE="sr0"
# Intel GPU power management.
# Select power profile for the Intel Xe GPU: base, power_saving.
# Note: requires xe driver.
# Default: base (AC), power_saving (BAT), power_saving (SAV)
# INTEL_GPU_POWER_PROFILE_ON_AC=base
# INTEL_GPU_POWER_PROFILE_ON_BAT=base
# INTEL_GPU_POWER_PROFILE_ON_SAV=power_saving
# Set the min/max/turbo frequency for the Intel GPU.
# Parameters actually used depend on the driver:
# - i915 driver supports min, max and turbo(boost) frequency.
# - xe driver supports min and max frequency only.
# Default: <none>
#INTEL_GPU_MIN_FREQ_ON_AC=0
#INTEL_GPU_MIN_FREQ_ON_BAT=0
#INTEL_GPU_MIN_FREQ_ON_SAV=0
#INTEL_GPU_MAX_FREQ_ON_AC=0
#INTEL_GPU_MAX_FREQ_ON_BAT=0
#INTEL_GPU_MAX_FREQ_ON_SAV=0
#INTEL_GPU_BOOST_FREQ_ON_AC=0
#INTEL_GPU_BOOST_FREQ_ON_BAT=0
#INTEL_GPU_BOOST_FREQ_ON_SAV=0
# AMD GPU power management.
# Performance level (DPM): high, auto, low; auto is recommended.
# Note: requires amdgpu or radeon driver.
# Default: auto (AC), auto (BAT), low (SAV)
#RADEON_DPM_PERF_LEVEL_ON_AC=auto
#RADEON_DPM_PERF_LEVEL_ON_BAT=auto
#RADEON_DPM_PERF_LEVEL_ON_SAV=low
# Display panel adaptive backlight modulation (ABM) level: 0(off), 1..4.
# Values 1..4 control the maximum brightness reduction allowed by the ABM
# algorithm, where 1 represents the least and 4 the most power saving.
# Notes:
# - Requires AMD Vega or newer GPU with amdgpu driver as of kernel 6.9
# - Savings are made at the expense of color balance
# Default: 0 (AC), 1 (BAT), 3 (SAV)
#AMDGPU_ABM_LEVEL_ON_AC=0
#AMDGPU_ABM_LEVEL_ON_BAT=1
#AMDGPU_ABM_LEVEL_ON_SAV=3
# Wi-Fi power saving mode: on=enable, off=disable.
# Default: off (AC), on (BAT)
WIFI_PWR_ON_AC=off
WIFI_PWR_ON_BAT=on
# Disable Wake-on-LAN: Y/N.
# Default: Y
#WOL_DISABLE=Y
# Enable audio power saving for Intel HDA, AC97 devices (timeout in secs).
# A value of 0 disables, >= 1 enables power saving.
# Note: 1 is recommended for Linux desktop environments with PulseAudio,
# systems without PulseAudio may require 10.
# Default: 1
#SOUND_POWER_SAVE_ON_AC=1
#SOUND_POWER_SAVE_ON_BAT=1
# Disable controller too (HDA only): Y/N.
# Note: effective only when SOUND_POWER_SAVE_ON_AC/BAT is activated.
# Default: Y
#SOUND_POWER_SAVE_CONTROLLER=Y
# PCIe Active State Power Management (ASPM):
# default(*), performance, powersave, powersupersave.
# (*) keeps BIOS ASPM defaults (recommended)
# Default: default
#PCIE_ASPM_ON_AC=default
#PCIE_ASPM_ON_BAT=default
#PCIE_ASPM_ON_SAV=default
# Autosuspend PCIe devices (Runtime Power Management):
# on=disable, auto=enable.
# Default: on (AC), auto (BAT)
#RUNTIME_PM_ON_AC=on
#RUNTIME_PM_ON_BAT=auto
# Exclude listed PCIe device adresses from autosuspend.
# Note: this preserves the kernel driver default, to force a certain state
# use RUNTIME_PM_ENABLE/DISABLE instead.
# Separate multiple addresses with spaces.
# Use lspci to get the adresses (1st column).
# Default: <none>
#RUNTIME_PM_DENYLIST="11:22.3 44:55.6"
# Exclude PCIe devices assigned to the listed drivers from autosuspend.
# Note: this preserves the kernel driver default, to force a certain state
# use RUNTIME_PM_ENABLE/DISABLE instead.
# Separate multiple drivers with spaces, use "" to disable completely.
# Default: "amdgpu mei_me nouveau nvidia xhci_hcd"
#RUNTIME_PM_DRIVER_DENYLIST="amdgpu mei_me nouveau nvidia xhci_hcd"
# Permanently enable/disable autosuspend for listed PCIe device addresses
# (independent of the power source). This has priority over all preceding
# autosuspend settings. Separate multiple addresses with spaces.
# Use lspci to get the adresses (1st column).
# Default: <none>
#RUNTIME_PM_ENABLE="11:22.3"
#RUNTIME_PM_DISABLE="44:55.6"
# Autosuspend USB devices:
# 0=disable, 1=enable.
# Default: 1
#USB_AUTOSUSPEND=1
# Exclude listed devices from USB autosuspend (separate with spaces).
# Use lsusb to get the ids.
# Note: input devices (usbhid) and libsane-supported scanners are excluded
# automatically.
# Default: <none>
#USB_DENYLIST="1111:2222 3333:4444"
# Exclude audio devices from USB autosuspend:
# 0=do not exclude, 1=exclude.
# Default: 1
#USB_EXCLUDE_AUDIO=1
# Exclude bluetooth devices from USB autosuspend:
# 0=do not exclude, 1=exclude.
# Default: 0
#USB_EXCLUDE_BTUSB=0
# Exclude phone devices from USB autosuspend:
# 0=do not exclude, 1=exclude (enable charging).
# Default: 0
#USB_EXCLUDE_PHONE=0
# Exclude printers from USB autosuspend:
# 0=do not exclude, 1=exclude.
# Default: 1
#USB_EXCLUDE_PRINTER=1
# Exclude WWAN devices from USB autosuspend:
# 0=do not exclude, 1=exclude.
# Default: 0
#USB_EXCLUDE_WWAN=0
# Allow USB autosuspend for listed devices even if already denylisted or
# excluded above (separate with spaces). Use lsusb to get the ids.
# Default: 0
#USB_ALLOWLIST="1111:2222 3333:4444"
# Radio devices to disable on startup: bluetooth, nfc, wifi, wwan.
# Separate multiple devices with spaces.
# Default: <none>
#DEVICES_TO_DISABLE_ON_STARTUP="bluetooth nfc wifi wwan"
# Radio devices to enable on startup: bluetooth, nfc, wifi, wwan.
# Separate multiple devices with spaces.
# Default: <none>
#DEVICES_TO_ENABLE_ON_STARTUP="wifi"
# Radio devices to enable when switching to the performance profile:
# bluetooth, nfc, wifi, wwan.
# Default: <none>
#DEVICES_TO_ENABLE_ON_AC="bluetooth nfc wifi wwan"
# Radio devices to disable when switching to the balanced or power-saver
# profile:
# bluetooth, nfc, wifi, wwan.
# Default: <none>
#DEVICES_TO_DISABLE_ON_BAT="bluetooth nfc wifi wwan"
# Radio devices to disable when not in use (not connected) and switching
# to the balanced or power-saver profile:
# bluetooth, nfc, wifi, wwan.
# Default: <none>
#DEVICES_TO_DISABLE_ON_BAT_NOT_IN_USE="bluetooth nfc wifi wwan"
# Battery Care -- Charge thresholds
# Charging will start once the charger is connected and the battery level
# is below the start threshold. Charging stops when the battery level
# reaches or exceeds the stop threshold.
# Required hardware: Lenovo ThinkPads and other laptop brands are driven
# via specific plugins:
# - Use the tlp-stat -b command to see if a plugin for your hardware is
# active and to look up vendor-specific threshold values. Some
# laptops support only 1 (on)/0 (off) instead of a percentage level.
# - If your hardware supports a start *and* a stop threshold, you must
# specify both, otherwise TLP will refuse to apply the single threshold.
# - If your hardware supports only a stop threshold, set the start
# value to 0.
# - The names of the batteries shown by tlp-stat -b don't have to match
# the _BAT0 or _BAT1 parameter qualifiers. Please refer to [2]
# to see which qualifier applies to which battery.
# For further explanation and all vendor specific details refer to
# [1] https://linrunner.de/tlp/settings/battery.html
# [2] https://linrunner.de/tlp/settings/bc-vendors.html
# BAT0: Main battery
# Default: <none>
# Charging starts once the battery level is below this threshold.
#START_CHARGE_THRESH_BAT0=75
# Charging stops when the battery level reaches or exceeds this threshold.
#STOP_CHARGE_THRESH_BAT0=80
# BAT1: Secondary battery (primary on some laptops)
# Default: <none>
# Charging starts once the battery level is below this threshold.
START_CHARGE_THRESH_BAT1=0
# Charging stops when the battery level reaches or exceeds this threshold.
STOP_CHARGE_THRESH_BAT1=60
# Restore charge thresholds when AC is unplugged: 0=disable, 1=enable.
# Default: 1
#RESTORE_THRESHOLDS_ON_BAT=0
# ----------------------------------------------------------------------------
# tlp-rdw - Radio Device Wizard
# Note: requires installation of the optional package tlp-rdw.
# Possible devices: bluetooth, wifi, wwan.
# Separate multiple radio devices with spaces.
# Default: <none> (for all parameters below)
# Radio devices to disable on connect.
#DEVICES_TO_DISABLE_ON_LAN_CONNECT="wifi wwan"
#DEVICES_TO_DISABLE_ON_WIFI_CONNECT="wwan"
#DEVICES_TO_DISABLE_ON_WWAN_CONNECT="wifi"
# Radio devices to enable on disconnect.
#DEVICES_TO_ENABLE_ON_LAN_DISCONNECT="wifi wwan"
#DEVICES_TO_ENABLE_ON_WIFI_DISCONNECT=""
#DEVICES_TO_ENABLE_ON_WWAN_DISCONNECT=""
# Radio devices to enable/disable when docked.
# Note: not all docks can be recognized, especially USB-C docks. If a LAN
# cable is connected to the dock, use DEVICES_TO_DISABLE_ON_LAN_CONNECT
# and DEVICES_TO_ENABLE_ON_LAN_DISCONNECT instead.
#DEVICES_TO_ENABLE_ON_DOCK=""
#DEVICES_TO_DISABLE_ON_DOCK=""
# Radio devices to enable/disable when undocked.
#DEVICES_TO_ENABLE_ON_UNDOCK="wifi"
#DEVICES_TO_DISABLE_ON_UNDOCK=""

View file

@ -0,0 +1,22 @@
# Configuration TLP spécifique à ArchASP.
# Le seuil temporaire peut être modifié avec ~/.local/bin/batlimit.
# Ce fichier remet la limite permanente à 60 % au démarrage.
TLP_PROFILE_AC=PRF
TLP_PROFILE_BAT=BAL
CPU_ENERGY_PERF_POLICY_ON_AC=balance_performance
CPU_ENERGY_PERF_POLICY_ON_BAT=balance_power
CPU_ENERGY_PERF_POLICY_ON_SAV=power
CPU_BOOST_ON_AC=1
CPU_BOOST_ON_BAT=0
CPU_BOOST_ON_SAV=0
PLATFORM_PROFILE_ON_BAT=quiet
WIFI_PWR_ON_AC=off
WIFI_PWR_ON_BAT=on
START_CHARGE_THRESH_BAT1=0
STOP_CHARGE_THRESH_BAT1=60

View file

@ -0,0 +1,37 @@
#!/usr/bin/env bash
set -euo pipefail
readonly BATTERY="BAT1"
readonly THRESHOLD_FILE="/sys/class/power_supply/${BATTERY}/charge_control_end_threshold"
if (( $# != 1 )); then
echo "Usage : batlimit-set SEUIL" >&2
exit 2
fi
readonly THRESHOLD="$1"
if [[ ! "$THRESHOLD" =~ ^[0-9]+$ ]]; then
echo "Erreur : le seuil doit être un entier." >&2
exit 2
fi
if (( THRESHOLD < 40 || THRESHOLD > 100 )); then
echo "Erreur : le seuil doit être compris entre 40 et 100." >&2
exit 2
fi
if [[ ! -e "$THRESHOLD_FILE" ]]; then
echo "Erreur : seuil de charge introuvable pour ${BATTERY}." >&2
exit 1
fi
printf '%s\n' "$THRESHOLD" > "$THRESHOLD_FILE"
read -r CURRENT_THRESHOLD < "$THRESHOLD_FILE"
if [[ "$CURRENT_THRESHOLD" != "$THRESHOLD" ]]; then
echo "Erreur : seuil demandé ${THRESHOLD} %, valeur appliquée ${CURRENT_THRESHOLD} %." >&2
exit 1
fi

View file

@ -0,0 +1,32 @@
#!/usr/bin/env bash
set -euo pipefail
readonly START_SERVICES=(
vmware-networks.service
vmware-usbarbitrator.service
smb.service
nmb.service
)
readonly STOP_SERVICES=(
nmb.service
smb.service
vmware-usbarbitrator.service
vmware-networks.service
)
case "${1:-}" in
start)
systemctl start "${START_SERVICES[@]}"
;;
stop)
systemctl stop "${STOP_SERVICES[@]}"
;;
*)
printf 'Usage : %s {start|stop}\n' "$0" >&2
exit 2
;;
esac

55
scripts/audit.sh Executable file
View file

@ -0,0 +1,55 @@
#!/usr/bin/env bash
set -u
section() { printf '\n=== %s ===\n' "$1"; }
section "CHARGE"
uptime
section "MÉMOIRE"
free -h
swapon --show
section "PRESSION"
for file in /proc/pressure/{cpu,memory,io}; do
printf '%s\n' "--- $file"
cat "$file"
done
section "DISQUE"
df -h /
sudo btrfs filesystem usage /
section "TOP CPU"
ps -eo pid,comm,%cpu,%mem,rss --sort=-%cpu | head -n 20
section "TOP RAM"
ps -eo pid,comm,%cpu,%mem,rss --sort=-rss | head -n 20
section "SERVICES EN ÉCHEC"
systemctl --failed
systemctl --user --failed
section "SERVICES À LA DEMANDE"
for unit in vmware-networks.service vmware-usbarbitrator.service smb.service nmb.service; do
printf '%-36s enabled=%-10s active=%s\n' \
"$unit" \
"$(systemctl is-enabled "$unit" 2>/dev/null || true)" \
"$(systemctl is-active "$unit" 2>/dev/null || true)"
done
printf '%-36s enabled=%-10s active=%s\n' \
protonmail-bridge.service \
"$(systemctl --user is-enabled protonmail-bridge.service 2>/dev/null || true)" \
"$(systemctl --user is-active protonmail-bridge.service 2>/dev/null || true)"
section "PROCESSUS INDÉSIRABLES AU REPOS"
pgrep -a -f 'nextcloud|thunderbird|protonmail-bridge|/protonmail/bridge|proton-pass|ollama|llama-server' \
|| echo "Aucun"
section "BATTERIE"
cat /sys/class/power_supply/BAT1/charge_control_end_threshold 2>/dev/null || true
section "DÉMARRAGE"
systemd-analyze
systemd-analyze blame | head -n 15

View file

@ -1,50 +1,234 @@
#!/usr/bin/env bash #!/usr/bin/env bash
set -euo pipefail set -Eeuo pipefail
IFS=$'\n\t'
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)" readonly REPO_DIR="$(
cd "$(dirname "${BASH_SOURCE[0]}")/.."
pwd
)"
echo "[*] Export des paquets" log() {
pacman -Qqe > "$REPO_DIR/pkglist/pacman.txt" printf '[*] %s\n' "$*"
pacman -Qqm > "$REPO_DIR/pkglist/aur.txt" }
echo "[*] Export des services systemd" warn() {
systemctl list-unit-files --state=enabled \ printf '[!] %s\n' "$*" >&2
> "$REPO_DIR/systemd/enabled-system.txt" }
systemctl --user list-unit-files --state=enabled \ copy_root_file() {
> "$REPO_DIR/systemd/enabled-user.txt" local source="$1"
local destination="$2"
local mode="${3:-0644}"
echo "[*] Sauvegarde des fichiers système" if sudo test -f "$source"; then
sudo install \
-D \
-o "$(id -u)" \
-g "$(id -g)" \
-m "$mode" \
"$source" \
"$destination"
else
warn "Fichier absent, ignoré : $source"
fi
}
echo "[*] Documentation stockage" mkdir -p \
"$REPO_DIR/pkglist" \
"$REPO_DIR/inventory/systemd" \
"$REPO_DIR/inventory/storage" \
"$REPO_DIR/inventory/boot" \
"$REPO_DIR/rootfs/etc/snapper/configs" \
"$REPO_DIR/rootfs/etc/systemd" \
"$REPO_DIR/rootfs/usr/local/sbin"
lsblk -f > "$REPO_DIR/docs/lsblk.txt" log "Listes des paquets explicitement installés"
findmnt > "$REPO_DIR/docs/findmnt.txt"
sudo btrfs subvolume list / > "$REPO_DIR/docs/btrfs-subvolumes.txt"
sudo chown -R "$USER:$USER" "$REPO_DIR/docs" pacman -Qqen |
LC_ALL=C sort -u \
> "$REPO_DIR/pkglist/pacman.txt"
sudo rsync -a \ pacman -Qqem |
/etc/pacman.conf \ LC_ALL=C sort -u \
/etc/makepkg.conf \ > "$REPO_DIR/pkglist/aur.txt"
/etc/mkinitcpio.conf \
/etc/fstab \
/etc/nftables.conf \
"$REPO_DIR/rootfs/etc/"
sudo rsync -a \ pacman -Qdtq 2>/dev/null |
/etc/snapper/configs/root \ LC_ALL=C sort -u \
"$REPO_DIR/rootfs/etc/snapper/configs/" > "$REPO_DIR/pkglist/orphans.txt" ||
true
sudo rsync -a \ log "Inventaire systemd système"
/etc/systemd/system/battery-threshold.service \
"$REPO_DIR/rootfs/etc/systemd/system/"
sudo rsync -a \ systemctl list-unit-files \
/boot/limine.conf \ --type=service \
"$REPO_DIR/rootfs/boot/" --state=enabled \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/system-enabled.txt"
sudo chown -R "$USER:$USER" "$REPO_DIR" systemctl --type=service \
--state=running \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/system-running.txt"
echo "[+] Sauvegarde terminée" systemctl list-timers \
--all \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/system-timers.txt"
systemctl --failed \
--no-legend \
--no-pager \
> "$REPO_DIR/inventory/systemd/system-failed.txt" ||
true
log "Inventaire systemd utilisateur"
systemctl --user list-unit-files \
--type=service \
--state=enabled \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/user-enabled.txt"
systemctl --user --type=service \
--state=running \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/user-running.txt"
systemctl --user list-timers \
--all \
--no-legend \
--no-pager |
LC_ALL=C sort \
> "$REPO_DIR/inventory/systemd/user-timers.txt"
systemctl --user --failed \
--no-legend \
--no-pager \
> "$REPO_DIR/inventory/systemd/user-failed.txt" ||
true
log "Inventaire du stockage"
lsblk -e7 \
-o NAME,MODEL,SIZE,ROTA,TRAN,FSTYPE,FSVER,LABEL,UUID,PARTUUID,MOUNTPOINTS \
> "$REPO_DIR/inventory/storage/lsblk.txt"
findmnt \
> "$REPO_DIR/inventory/storage/findmnt.txt"
cp /etc/fstab \
"$REPO_DIR/inventory/storage/fstab.current"
sudo btrfs subvolume list / \
> "$REPO_DIR/inventory/storage/btrfs-subvolumes.txt"
sudo btrfs filesystem usage / \
> "$REPO_DIR/inventory/storage/btrfs-usage.txt"
sudo btrfs scrub status / \
> "$REPO_DIR/inventory/storage/btrfs-scrub.txt" ||
true
free -h \
> "$REPO_DIR/inventory/storage/memory.txt"
swapon --show \
> "$REPO_DIR/inventory/storage/swap.txt"
if command -v nvme >/dev/null 2>&1 && [[ -e /dev/nvme0 ]]; then
sudo nvme smart-log /dev/nvme0 \
> "$REPO_DIR/inventory/storage/nvme-health.txt"
else
: > "$REPO_DIR/inventory/storage/nvme-health.txt"
fi
log "Sauvegarde des configurations système"
copy_root_file \
/etc/pacman.conf \
"$REPO_DIR/rootfs/etc/pacman.conf"
copy_root_file \
/etc/makepkg.conf \
"$REPO_DIR/rootfs/etc/makepkg.conf"
copy_root_file \
/etc/mkinitcpio.conf \
"$REPO_DIR/rootfs/etc/mkinitcpio.conf"
copy_root_file \
/etc/nftables.conf \
"$REPO_DIR/rootfs/etc/nftables.conf"
copy_root_file \
/etc/limine-snapper-sync.conf \
"$REPO_DIR/rootfs/etc/limine-snapper-sync.conf"
copy_root_file \
/etc/tlp.d/10-archasp.conf \
"$REPO_DIR/rootfs/etc/tlp.d/10-archasp.conf"
copy_root_file \
/etc/systemd/zram-generator.conf \
"$REPO_DIR/rootfs/etc/systemd/zram-generator.conf"
copy_root_file \
/etc/snapper/configs/root \
"$REPO_DIR/rootfs/etc/snapper/configs/root"
copy_root_file \
/usr/local/sbin/batlimit-set \
"$REPO_DIR/rootfs/usr/local/sbin/batlimit-set" \
0755
copy_root_file \
/usr/local/sbin/vmware-stack \
"$REPO_DIR/rootfs/usr/local/sbin/vmware-stack" \
0755
log "Génération du template Limine"
if sudo test -f /boot/limine.conf; then
mkdir -p "$REPO_DIR/templates"
sudo awk '
/^[[:space:]]*### Auto-generated by limine-snapper-sync/ {
exit
}
{
print
}
' /boot/limine.conf |
sed -E \
's/root=UUID=[[:xdigit:]-]+/root=UUID=@ROOT_UUID@/g' \
> "$REPO_DIR/templates/limine.conf"
else
warn "Fichier absent : /boot/limine.conf"
fi
log "Sauvegarde terminée"
printf '\n'
printf 'Pacman : %s\n' \
"$(wc -l < "$REPO_DIR/pkglist/pacman.txt")"
printf 'AUR : %s\n' \
"$(wc -l < "$REPO_DIR/pkglist/aur.txt")"
printf 'Orphelins : %s\n' \
"$(wc -l < "$REPO_DIR/pkglist/orphans.txt")"
printf '\n'
git -C "$REPO_DIR" status --short || true

121
scripts/check-repo.sh Executable file
View file

@ -0,0 +1,121 @@
#!/usr/bin/env bash
set -Eeuo pipefail
readonly REPO_DIR="$(
cd "$(dirname "${BASH_SOURCE[0]}")/.."
pwd
)"
status=0
fail() {
printf '[!] %s\n' "$*" >&2
status=1
}
echo '[*] Validation syntaxique Bash'
while IFS= read -r -d '' file; do
bash -n "$file" || status=1
done < <(
find \
"$REPO_DIR/scripts" \
"$REPO_DIR/rootfs/usr/local/sbin" \
-type f \
-print0 2>/dev/null
)
echo '[*] Validation des listes de paquets'
for file in \
"$REPO_DIR/pkglist/pacman.txt" \
"$REPO_DIR/pkglist/aur.txt" \
"$REPO_DIR/pkglist/orphans.txt"
do
[[ -f "$file" ]] || {
fail "Liste absente : $file"
continue
}
LC_ALL=C sort -cu "$file" ||
fail "Liste non triée ou contenant des doublons : $file"
done
if [[ -f "$REPO_DIR/pkglist/pacman.txt" &&
-f "$REPO_DIR/pkglist/aur.txt" ]]; then
if LC_ALL=C comm -12 \
"$REPO_DIR/pkglist/pacman.txt" \
"$REPO_DIR/pkglist/aur.txt" |
grep -q .
then
fail 'Des paquets apparaissent dans les listes Pacman et AUR.'
fi
fi
echo '[*] Recherche de fichiers sensibles'
while IFS= read -r file; do
fail "Fichier potentiellement sensible : $file"
done < <(
find "$REPO_DIR" \
-type f \
\( \
-name '*.key' \
-o -name '*.pem' \
-o -name '*.p12' \
-o -name '.netrc' \
-o -name '*.sqlite' \
-o -name '*.sqlite3' \
-o -name '*.db' \
\) \
-not -path "$REPO_DIR/.git/*"
)
echo '[*] Vérification de la séparation des dépôts'
for forbidden in \
"$REPO_DIR/userfs" \
"$REPO_DIR/inventory/packages" \
"$REPO_DIR/rootfs/etc/sudoers.d"
do
[[ ! -e "$forbidden" ]] ||
fail "Répertoire interdit dans arch-system : $forbidden"
done
echo '[*] Vérification des templates'
grep -q '@ROOT_UUID@' \
"$REPO_DIR/templates/fstab.btrfs" ||
fail 'Placeholder @ROOT_UUID@ absent de fstab.btrfs.'
grep -q '@EFI_UUID@' \
"$REPO_DIR/templates/fstab.btrfs" ||
fail 'Placeholder @EFI_UUID@ absent de fstab.btrfs.'
grep -q '@ROOT_UUID@' \
"$REPO_DIR/templates/limine.conf" ||
fail 'Placeholder @ROOT_UUID@ absent de limine.conf.'
grep -q '@USER@' \
"$REPO_DIR/templates/sudoers.d/batlimit" ||
fail 'Placeholder @USER@ absent du sudoers batlimit.'
grep -q '@USER@' \
"$REPO_DIR/templates/sudoers.d/vmware-stack" ||
fail 'Placeholder @USER@ absent du sudoers VMware.'
if git -C "$REPO_DIR" \
rev-parse --is-inside-work-tree >/dev/null 2>&1
then
echo '[*] Contrôle du diff Git'
git -C "$REPO_DIR" diff --check || status=1
fi
if (( status == 0 )); then
echo '[+] Dépôt valide.'
else
echo '[!] Le dépôt contient encore des erreurs.' >&2
fi
exit "$status"

View file

@ -1,46 +1,289 @@
#!/usr/bin/env bash #!/usr/bin/env bash
set -euo pipefail set -Eeuo pipefail
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)" readonly REPO_DIR="$(
cd "$(dirname "${BASH_SOURCE[0]}")/.."
pwd
)"
echo "[!] Script de restauration Arch" readonly BACKUP_DIR="/root/arch-system-restore-$(date +%F-%H%M%S)"
echo "[!] À lancer uniquement sur une installation fraîche ou volontairement préparée."
echo
read -rp "Continuer ? [y/N] " confirm DO_PACKAGES=0
if [[ "$confirm" != "y" && "$confirm" != "Y" ]]; then DO_CONFIGS=0
echo "Annulé." DO_TOOLS=0
exit 0 DO_SERVICES=0
usage() {
cat <<'EOF'
Usage : deploy.sh [options]
--packages Installe les paquets officiels et AUR
--configs Restaure les configurations système suivies
--tools Installe les helpers root et les règles sudoers
--services Active les services et timers système voulus
--all Exécute toutes les étapes
EOF
}
while (( $# > 0 )); do
case "$1" in
--packages)
DO_PACKAGES=1
;;
--configs)
DO_CONFIGS=1
;;
--tools)
DO_TOOLS=1
;;
--services)
DO_SERVICES=1
;;
--all)
DO_PACKAGES=1
DO_CONFIGS=1
DO_TOOLS=1
DO_SERVICES=1
;;
-h|--help)
usage
exit 0
;;
*)
printf 'Option inconnue : %s\n' "$1" >&2
usage
exit 2
;;
esac
shift
done
if (( DO_PACKAGES + DO_CONFIGS + DO_TOOLS + DO_SERVICES == 0 )); then
usage
exit 2
fi fi
echo "[*] Restauration des fichiers système" read -rp \
sudo rsync -aAXH \ "Déployer arch-system sur $(hostname) pour ${USER} ? [y/N] " \
"$REPO_DIR/rootfs/" / confirm
echo "[*] Installation des paquets officiels" [[ "$confirm" =~ ^[yY]$ ]] || exit 0
sudo pacman -Syu --needed - < "$REPO_DIR/pkglist/pacman.txt"
echo "[*] Paquets AUR" backup_target() {
if command -v paru >/dev/null 2>&1; then local target="$1"
paru -S --needed - < "$REPO_DIR/pkglist/aur.txt"
else if sudo test -e "$target"; then
echo "[!] paru absent, paquets AUR non installés." sudo mkdir -p "$BACKUP_DIR$(dirname "$target")"
echo "[!] Installe paru puis lance :" sudo cp -a "$target" "$BACKUP_DIR$target"
echo " paru -S --needed - < pkglist/aur.txt" fi
}
install_config() {
local source="$1"
local target="$2"
local mode="${3:-0644}"
if [[ ! -f "$source" ]]; then
printf '[!] Source absente : %s\n' "$source" >&2
return 0
fi
backup_target "$target"
sudo install \
-D \
-m "$mode" \
"$source" \
"$target"
}
install_package_list() {
local manager="$1"
local file="$2"
local -a packages=()
if [[ ! -s "$file" ]]; then
printf '[!] Liste vide : %s\n' "$file"
return 0
fi
mapfile -t packages < <(
grep -Ev '^[[:space:]]*(#|$)' "$file"
)
(( ${#packages[@]} > 0 )) || return 0
case "$manager" in
pacman)
sudo pacman -Syu --needed "${packages[@]}"
;;
yay)
yay -S --needed "${packages[@]}"
;;
*)
printf 'Gestionnaire inconnu : %s\n' "$manager" >&2
return 2
;;
esac
}
enable_manifest() {
local file="$1"
local unit
[[ -f "$file" ]] || return 0
while IFS= read -r unit; do
[[ -z "$unit" || "$unit" == \#* ]] && continue
if systemctl cat "$unit" >/dev/null 2>&1; then
sudo systemctl enable "$unit"
else
printf '[!] Unité absente : %s\n' "$unit"
fi
done < "$file"
}
disable_manifest() {
local file="$1"
local unit
[[ -f "$file" ]] || return 0
while IFS= read -r unit; do
[[ -z "$unit" || "$unit" == \#* ]] && continue
sudo systemctl disable --now "$unit" 2>/dev/null || true
done < "$file"
}
if (( DO_PACKAGES )); then
echo '[*] Installation des paquets officiels'
install_package_list \
pacman \
"$REPO_DIR/pkglist/pacman.txt"
if [[ -s "$REPO_DIR/pkglist/aur.txt" ]]; then
if command -v yay >/dev/null 2>&1; then
echo '[*] Installation des paquets AUR'
install_package_list \
yay \
"$REPO_DIR/pkglist/aur.txt"
else
echo '[!] Yay est absent : installation AUR reportée.'
fi
fi
fi fi
echo "[*] Rechargement systemd" if (( DO_CONFIGS )); then
sudo systemctl daemon-reload echo "[*] Sauvegardes dans ${BACKUP_DIR}"
echo "[*] Services à réactiver manuellement selon systemd/enabled-system.txt" # Valider le pare-feu avant de remplacer le fichier actif.
echo "[*] Exemple :" if [[ -f "$REPO_DIR/rootfs/etc/nftables.conf" ]]; then
echo " sudo systemctl enable --now NetworkManager.service" sudo nft -c -f "$REPO_DIR/rootfs/etc/nftables.conf"
echo " sudo systemctl enable --now nftables.service" fi
echo " sudo systemctl enable --now sshd.service"
echo " sudo systemctl enable --now snapper-timeline.timer"
echo " sudo systemctl enable --now snapper-cleanup.timer"
echo install_config \
echo "[+] Restauration terminée." "$REPO_DIR/rootfs/etc/pacman.conf" \
echo "[!] Vérifie /etc/fstab, Limine, Snapper et Secure Boot avant reboot." /etc/pacman.conf
install_config \
"$REPO_DIR/rootfs/etc/makepkg.conf" \
/etc/makepkg.conf
install_config \
"$REPO_DIR/rootfs/etc/mkinitcpio.conf" \
/etc/mkinitcpio.conf
install_config \
"$REPO_DIR/rootfs/etc/nftables.conf" \
/etc/nftables.conf
install_config \
"$REPO_DIR/rootfs/etc/limine-snapper-sync.conf" \
/etc/limine-snapper-sync.conf
install_config \
"$REPO_DIR/rootfs/etc/tlp.d/10-archasp.conf" \
/etc/tlp.d/10-archasp.conf
install_config \
"$REPO_DIR/rootfs/etc/systemd/zram-generator.conf" \
/etc/systemd/zram-generator.conf
install_config \
"$REPO_DIR/rootfs/etc/snapper/configs/root" \
/etc/snapper/configs/root
sudo systemctl daemon-reload
if command -v tlp >/dev/null 2>&1; then
sudo tlp start
fi
echo '[!] fstab, Limine et Secure Boot restent à finaliser manuellement.'
fi
if (( DO_TOOLS )); then
echo '[*] Installation des helpers root'
sudo install \
-D \
-m 0755 \
"$REPO_DIR/rootfs/usr/local/sbin/batlimit-set" \
/usr/local/sbin/batlimit-set
sudo install \
-D \
-m 0755 \
"$REPO_DIR/rootfs/usr/local/sbin/vmware-stack" \
/usr/local/sbin/vmware-stack
echo '[*] Installation des sudoers minimaux'
for name in batlimit vmware-stack; do
template="$REPO_DIR/templates/sudoers.d/$name"
temporary="$(mktemp)"
sed "s/@USER@/${USER}/g" \
"$template" \
> "$temporary"
sudo visudo -cf "$temporary"
sudo install \
-o root \
-g root \
-m 0440 \
"$temporary" \
"/etc/sudoers.d/$name"
rm -f "$temporary"
done
disable_manifest \
"$REPO_DIR/manifests/on-demand-system-services.txt"
fi
if (( DO_SERVICES )); then
echo '[*] Activation des services système'
enable_manifest \
"$REPO_DIR/manifests/system-services.txt"
enable_manifest \
"$REPO_DIR/manifests/system-timers.txt"
disable_manifest \
"$REPO_DIR/manifests/on-demand-system-services.txt"
fi
echo '[+] Déploiement système terminé.'
echo '[*] Les configurations utilisateur restent dans Dotfiles_ArchAP.'
echo '[!] Vérifier fstab, Limine, mkinitcpio, Snapper, nftables et sbctl avant reboot.'

70
scripts/prepare-disk.sh Executable file
View file

@ -0,0 +1,70 @@
#!/usr/bin/env bash
set -Eeuo pipefail
if (( EUID != 0 )); then
echo "Lance ce script avec sudo." >&2
exit 1
fi
if (( $# != 1 )); then
printf 'Usage : %s /dev/nvmeXnY\n' "$0" >&2
exit 2
fi
readonly DISK="$(readlink -f "$1")"
readonly MOUNT_ROOT="/mnt"
[[ -b "$DISK" ]] || { echo "Périphérique invalide : $DISK" >&2; exit 1; }
if findmnt -rn "$MOUNT_ROOT" >/dev/null 2>&1; then
echo "$MOUNT_ROOT est déjà monté. Démonte-le avant de continuer." >&2
exit 1
fi
if lsblk -nr -o MOUNTPOINTS "$DISK" | grep -q '/'; then
echo "Le disque ou une de ses partitions est monté. Abandon." >&2
lsblk -o NAME,MODEL,SIZE,FSTYPE,MOUNTPOINTS "$DISK"
exit 1
fi
lsblk -o NAME,MODEL,SIZE,TRAN,FSTYPE,MOUNTPOINTS "$DISK"
printf '\nCette opération efface entièrement %s.\n' "$DISK"
read -rp "Tape exactement ERASE $DISK : " confirmation
[[ "$confirmation" == "ERASE $DISK" ]] || { echo "Annulé."; exit 0; }
part_suffix=""
[[ "$DISK" =~ [0-9]$ ]] && part_suffix="p"
readonly EFI_PART="${DISK}${part_suffix}1"
readonly ROOT_PART="${DISK}${part_suffix}2"
wipefs -af "$DISK"
parted -s "$DISK" mklabel gpt
parted -s "$DISK" mkpart ESP fat32 1MiB 1025MiB
parted -s "$DISK" set 1 esp on
parted -s "$DISK" mkpart ARCH btrfs 1025MiB 100%
partprobe "$DISK"
udevadm settle
mkfs.fat -F 32 -n EFI "$EFI_PART"
mkfs.btrfs -f -L ARCH "$ROOT_PART"
mount "$ROOT_PART" "$MOUNT_ROOT"
btrfs subvolume create "$MOUNT_ROOT/@"
btrfs subvolume create "$MOUNT_ROOT/@home"
btrfs subvolume create "$MOUNT_ROOT/@log"
btrfs subvolume create "$MOUNT_ROOT/@pkg"
umount "$MOUNT_ROOT"
readonly OPTS="rw,relatime,ssd,discard=async,space_cache=v2"
mount -o "$OPTS,subvol=@" "$ROOT_PART" "$MOUNT_ROOT"
mkdir -p "$MOUNT_ROOT"/{boot,home,var/log,var/cache/pacman/pkg,.snapshots}
btrfs subvolume create "$MOUNT_ROOT/.snapshots"
mount -o "$OPTS,subvol=@home" "$ROOT_PART" "$MOUNT_ROOT/home"
mount -o "$OPTS,subvol=@log" "$ROOT_PART" "$MOUNT_ROOT/var/log"
mount -o "$OPTS,subvol=@pkg" "$ROOT_PART" "$MOUNT_ROOT/var/cache/pacman/pkg"
mount -o "$OPTS,subvol=@/.snapshots" "$ROOT_PART" "$MOUNT_ROOT/.snapshots"
mount "$EFI_PART" "$MOUNT_ROOT/boot"
printf '\n[+] Disque préparé et monté sous %s\n' "$MOUNT_ROOT"
lsblk -o NAME,SIZE,FSTYPE,LABEL,MOUNTPOINTS "$DISK"

6
templates/fstab.btrfs Normal file
View file

@ -0,0 +1,6 @@
UUID=@ROOT_UUID@ / btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@ 0 0
UUID=@ROOT_UUID@ /home btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@home 0 0
UUID=@ROOT_UUID@ /var/log btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@log 0 0
UUID=@ROOT_UUID@ /var/cache/pacman/pkg btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@pkg 0 0
UUID=@ROOT_UUID@ /.snapshots btrfs rw,relatime,ssd,discard=async,space_cache=v2,subvol=/@/.snapshots 0 0
UUID=@EFI_UUID@ /boot vfat rw,relatime,fmask=0022,dmask=0022,utf8,errors=remount-ro 0 2

29
templates/limine.conf Normal file
View file

@ -0,0 +1,29 @@
term_palette: 1e1e2e;f3ba8;a6e3a1;f9e2af;89b4fa;f5c2e7;94e2d5;cdd6f4
term_palette_bright: 58b70;f38ba8;f9e2af;89b4fa;f5c2e7;94e2d5;cdd6f4
term_background: 1e1e2e
term_foreground: cdd6f4
term_background_bright: 585b70
term_foreground_bright: cdd6f4
interface_resolution: 1920x1080
timeout: 5
default_entry: 2
/+Arch Linux
//Kernel Zen
protocol: linux
kernel_path: boot():/vmlinuz-linux-zen
module_path: boot():/amd-ucode.img
module_path: boot():/initramfs-linux-zen.img
kernel_cmdline: root=UUID=@ROOT_UUID@ rw rootflags=subvol=@ quiet loglevel=3
//Kernel LTS
protocol: linux
kernel_path: boot():/vmlinuz-linux-lts
module_path: boot():/amd-ucode.img
module_path: boot():/initramfs-linux-lts.img
kernel_cmdline: root=UUID=@ROOT_UUID@ rw rootflags=subvol=@ quiet loglevel=3
//Snapshots

View file

@ -0,0 +1 @@
@USER@ ALL=(root) NOPASSWD: /usr/local/sbin/batlimit-set

View file

@ -0,0 +1 @@
@USER@ ALL=(root) NOPASSWD: /usr/local/sbin/vmware-stack start, /usr/local/sbin/vmware-stack stop, /usr/local/sbin/vmware-stack status