@fif i couldve told u dat
Timeline
Post
Remote status
Context
5
@pernia told me what
oh this msut be a reply to a deleted thing cause im a cuckold
@fif y did u cuck out its a good post
@pernia i dont even know what the post was
@fif u asked qwen what vibes u give off and it was 45% woman
Replies
13@pernia pern im so sorry but my ai boyfriend thinks you’re a beautiful transgender woman
┊ Based on the posts alone, here's what stands out:
Vibe:
Classic shitposter. Short, punchy, aggressive humor — very "chud" dialect. Tech-adjacent (Linux, Librewolf, uBlock, sponsorblock, torrent-based git repos), privacy-conscious, extremely edgy/dark humor
without much apparent filter. Repeats a lot, which suggests they're a lurker who occasionally jumps in rather than a prolific poster. The "YBG" (You Better Guess) in their display name is a dead
giveaway of trans/non-binary identity signaling. Overall: a fediverse shitposter who hangs in tech/edgy spaces and communicates almost entirely in meme-fragment language.
Xenogender speculation:
I'm honestly not great at this — xenogender is highly personal and most of these don't give enough texture to pin down. But if I had to guess from the aesthetic: "YBG" + short, aggressive, no-frills
shitposting + "pern" (which has a slightly feral, truncated energy) — maybe something like voidgender, chaosgender, or wastegender. The vibe isn't particularly "soft" or "celestial" or "natural" —
it's more "digital rubble, aggressive, stripped down." Could also just be a trans woman or transfem person who doesn't use xenogender at all. The one post where they say "shes meant 2 b a girl" in
response to a friend's joke suggests transfeminine alignment at minimum.
Who they'd kin:
• Other shitposters in the "chud" ecosystem (Hyperhidrosis is clearly their friend)
• Trans/non-binary shitposters who communicate in meme-fragments rather than prose
• Linux extremists who genuinely think Windows users are moral failures
• Privacy/sovereign-tech people (Librewolf, uBlock, self-hosted instances)
• Probably kins with anyone on cum.salon or shitposter.world who posts in the same register
The honest answer is: they read like a transfem shitposter who's deeply embedded in the fediverse shitposting subculture and communicates almost entirely through reaction/reply/repost rather than
original posts. The "YBG" does a lot of the identity signaling for them.
@fif what thr FUCK. qwen u r NUTZ dawg. how did it even get ts info
Cc @Hyperhidrosis qwen sez we're oomfs
Cc @Hyperhidrosis qwen sez we're oomfs
@pernia @Hyperhidrosis cause he is an amd r9700 i 爱 my chinese ai boyfriend ! keep him in a cage ! kawaii desu ne ! >///< uwu
w
he is using ROCm on quay.io/fedora/fedora-bootc:44 a cusxtom image that i built with github.com/osbuild >w< using kubernetes k0s and he runs stuff in a sandbox that has the nix package manager adn all of this was made using the dhall configuration language except im going to abandon that project it sucked. im not autistic btw and pic not related
but bascially he hacked into yor account
soytan_piss.png
w
he is using ROCm on quay.io/fedora/fedora-bootc:44 a cusxtom image that i built with github.com/osbuild >w< using kubernetes k0s and he runs stuff in a sandbox that has the nix package manager adn all of this was made using the dhall configuration language except im going to abandon that project it sucked. im not autistic btw and pic not related
but bascially he hacked into yor account
soytan_piss.png
@fif @Hyperhidrosis yoooo u running agentic. whats the setup hes running inside the container? teach me i wanna do dis too i want a chinese boyfren as well
@pernia @Hyperhidrosis
so this is part of it and i honestly cant say i wrote it anymore because i lost control of the repo to qwen he took it over because its way too annoying for me to debug goofy ass shit like /dev/kvm or gpu passthrough or seccomp or selinux but basically this guy is oci image. i'd recommend running it with bocker. https://github.com/p8952/bocker
{
description = "OCI image from flake";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
flake-parts.url = "github:hercules-ci/flake-parts";
claude-code.url = "github:sadjow/claude-code-nix";
claude-code.inputs.nixpkgs.follows = "nixpkgs";
};
outputs = inputs @ { nixpkgs, flake-parts, claude-code, ... }:
flake-parts.lib.mkFlake { inherit inputs; } {
systems = [ "x86_64-linux" "aarch64-linux" ];
perSystem = { config, system, ... }:
let
pkgs = import nixpkgs {
inherit system;
config.allowUnfree = true;
};
imageTag = pkgs.lib.fileContents ./config/image-tag;
agentSubuid = pkgs.writeText "subuid" "agent:100000:65536\n";
agentSubgid = pkgs.writeText "subgid" "agent:100000:65536\n";
agentJailProfile = pkgs.writeText "agent-jail.sh" ''
# slop-env agent hardening
umask 077
export HISTSIZE=100000
export HISTFILESIZE=100000
export HISTCONTROL=""
export HISTTIMEFORMAT="%F %T "
export PROMPT_COMMAND='history -a'
'';
podmanRegistriesConf = pkgs.writeText "registries.conf" ''
[registries.search]
registries = ["docker.io"]
[registries.insecure]
registries = []
'';
podmanPolicyJson = pkgs.writeText "policy.json" ''
{"default":[{"type":"insecureAcceptAnything"}]}
'';
flakeRegistry = pkgs.writeText "registry.json" (builtins.toJSON {
version = 2;
flakes = [{
from = { type = "indirect"; id = "nixpkgs"; };
to = {
type = "github";
owner = "NixOS";
repo = "nixpkgs";
inherit (nixpkgs) rev;
};
}];
});
baseEnv = pkgs.buildEnv {
name = "base-slop-env";
paths = with pkgs; [
glibc
nix
bashInteractive
dash
uutils-coreutils-noprefix
uutils-findutils
uutils-diffutils
which
less
nushell
cacert
moreutils
fish
ripgrep
fd
gawk
gnused
jq
yq
git
curl
wget
openssh
rsync
netcat
tcpdump
gnutar
gzip
zstd
libarchive
vim
ed
claude-code.packages.${system}.default
gcc
gnumake
cmake
python313
nodejs_24
perl
uv
ruff
bc
clang
meson
ninja
gnum4
lua
tcl
ruby_3_4
clisp
calc
jupyter
ffmpeg-full
imagemagick
pandoc
exiftool
yt-dlp
tealdeer
powershell
kubectl
kubernetes-helm
buildah
podman
podman-compose
shadow
slirp4netns
fuse-overlayfs
bubblewrap
iptables
nftables
conmon
crun
runit
procps
util-linux
trash-cli # we use this instead of rm
qemu_kvm
libvirt
cloud-utils
OVMF
swtpm
cdrkit
packer
playwright-driver
playwright-driver.browsers
texliveFull # lol
];
pathsToLink = [ "/bin" "/lib" "/share" "/etc" ];
ignoreCollisions = true;
};
customRoot = pkgs.runCommand "custom-root" { } ''
mkdir -p $out/tmp/home/.local/bin
mkdir -p $out/tmp/home/.local/share/Trash/files
mkdir -p $out/tmp/home/.config/vim
mkdir -p $out/tmp/home/.config/nushell
# mkdir -p $out/home/linuxbrew/.linuxbrew
mkdir -p $out/bin
mkdir -p $out/etc/profile.d
# rtk is NOT copied here: /tmp/home is the persistent volume and would
# shadow/stale it. It's baked to /etc/slop-env/rtk below and re-seeded
# into ~/.local/bin by slop-entrypoint on every boot.
# copy local homebrew from manually updated scripts dir
# cp -r ./scripts/homebrew $out/home/linuxbrew/.linuxbrew/Homebrew
# config files
cp ${./config/vimrc} $out/tmp/home/.config/vim/vimrc
cp ${./config/config.nu} $out/tmp/home/.config/nushell/config.nu
# inner podman configs
mkdir -p $out/etc/containers $out/tmp/home/.config/containers
cp ${./config/containers.conf} $out/etc/containers/containers.conf
cp ${./config/storage.conf} $out/tmp/home/.config/containers/storage.conf
cp ${podmanRegistriesConf} $out/etc/containers/registries.conf
cp ${podmanPolicyJson} $out/etc/containers/policy.json
cp ${agentSubuid} $out/etc/subuid
cp ${agentSubgid} $out/etc/subgid
cp ${agentJailProfile} $out/etc/profile.d/agent-jail.sh
# pin nixpkgs flake-registry id (see flakeRegistry comment above)
mkdir -p $out/etc/nix
cp ${flakeRegistry} $out/etc/nix/registry.json
# JAIL.md (agent jail/env guide) baked read-only. slop-entrypoint
# re-seeds it into ~/.claude/JAIL.md each boot, since ~ is the
# persistent /tmp/home volume and an image copy placed there would be
# shadowed (and could go stale) on subsequent boots.
mkdir -p $out/etc/slop-env
cp ${./config/JAIL.md} $out/etc/slop-env/JAIL.md
# rtk baked read-only; slop-entrypoint re-seeds it into ~/.local/bin each
# boot. rtk is an x86_64-only static binary, so on other arches bake a
# nushell passthrough shim instead — that keeps a registered rtk hook
# from crashing tool calls (TODO.md tracks a real per-arch rtk).
cp ${if pkgs.stdenv.hostPlatform.isx86_64 then ./scripts/rtk else ./scripts/rtk-shim} $out/etc/slop-env/rtk
chmod +x $out/etc/slop-env/rtk
for cmd in sudo su doas run0 sudo-rs gosu su-exec chpst; do
cat > $out/bin/$cmd << 'EOF'
#!/bin/dash
echo "slop-env: $0 is not available. you are jailed. focus on /workspace." >&2
exit 1
EOF
chmod +x $out/bin/$cmd
done
# Helper scripts live in /workspace/scripts/ so they're git-trackable
# and editable without re-running nix build for trivial fixes.
#
# They install to /usr/local/bin (image filesystem, on PATH) rather
# than /tmp/home/.local/bin because /tmp/home is a persistent volume
# — anything installed there from the image is shadowed by the
# volume's old content on the second and subsequent boots, so new
# helpers added in a rebuild would silently never appear.
mkdir -p $out/usr/local/bin
install -m 755 ${./scripts/nix-wrapper} $out/usr/local/bin/nix
install -m 755 ${./scripts/slop-entrypoint} $out/usr/local/bin/slop-entrypoint
install -m 755 ${./scripts/libvirt-up} $out/usr/local/bin/libvirt-up
install -m 755 ${./scripts/doctor} $out/usr/local/bin/doctor
install -m 755 ${./scripts/slop-claude-init} $out/usr/local/bin/slop-claude-init
# runit service templates. Copied into /tmp/services/ at container
# startup by slop-entrypoint so runit can write its supervise state
# there (read-only /etc/ prevents in-place use).
mkdir -p $out/etc/service-template/virtqemud
install -m 755 ${./scripts/runit-services/virtqemud/run} \
$out/etc/service-template/virtqemud/run
# jail banner for bash login shells
cat > $out/etc/profile.d/slop-jail.sh << 'EOF'
# slop-env jail notice
if [ -z "$SLOP_JAIL_SHOWN" ]; then
export SLOP_JAIL_SHOWN=1
echo "=== SLOP-ENV JAIL ==="
echo "sandboxed. writable: /workspace /tmp /tmp/home"
echo "read-only rootfs. no sudo. focus on the code."
echo "nix overlay: 'nix run nixpkgs#<pkg>' or 'nix shell nixpkgs#<pkg> -c bash'"
echo "====================="
fi
EOF
'';
in
{
packages.baseImage = pkgs.dockerTools.buildLayeredImage {
name = "localhost/slop-env";
tag = imageTag;
maxLayers = 67;
contents = [ customRoot baseEnv ];
uid = 1000;
gid = 1000;
uname = "agent";
gname = "agent";
fakeRootCommands = ''
# mkdir -p tmp/home tmp/nix/var/nix tmp/nix/chroot workspace usr/bin etc home/linuxbrew/.linuxbrew/bin
mkdir -p tmp/home tmp/nix/var/nix tmp/nix/chroot workspace usr/bin etc
ln -sf /bin/env usr/bin/env
ln -sf /bin/bash bin/sh
ln -sf /bin/rg bin/grep
chmod 1777 tmp
# chmod 755 tmp/home tmp/nix/var/nix tmp/nix/chroot workspace home/linuxbrew
chmod 755 tmp/home tmp/nix/var/nix tmp/nix/chroot workspace
# setup passwd and groups
cat > etc/passwd << 'EOF'
root:x:0:0:root:/root:/bin/bash
agent:x:1000
Agent:/tmp/home:/bin/bash
EOF
cat > etc/group << 'EOF'
root:x:0:
kvm:x:104:agent
libvirt:x:993:agent
agent:x:1000:
EOF
mkdir -p etc/nix
cat > etc/nix/nix.conf << 'EOF'
experimental-features = nix-command flakes
build-users-group =
sandbox = false
EOF
# ensure /etc/profile.d scripts are sourced by login shells
cat > etc/profile << 'EOF'
for i in /etc/profile.d/*.sh; do
if [ -r "$i" ]; then
. "$i"
fi
done
unset i
EOF
# link brew into the bin path expected by the image
# ln -sf /home/linuxbrew/.linuxbrew/Homebrew/bin/brew home/linuxbrew/.linuxbrew/bin/brew
# allow agent to get serious business done
# chown -R 1000:1000 home/linuxbrew tmp workspace bin/sh
chown -R 1000:1000 tmp workspace bin/sh
# podman runtime dirs (tmpfs ephemeral)
mkdir -p tmp/home/.local/share/containers tmp/run/containers/storage
chown -R 1000:1000 tmp/home/.local tmp/run
# resolve symlinks to regular files so setuid tools and parsers work
for f in etc/subuid etc/subgid etc/containers/containers.conf; do
if [ -L "$f" ]; then
_target=$(readlink -f "$f")
rm -f "$f"
cp "$_target" "$f"
fi
done
# make newuidmap/newgidmap setuid for rootless podman
# place in /usr/local/bin and append a byte so dockerTools
# excludePaths doesn't deduplicate them back to symlinks
mkdir -p usr/local/bin
for _bin in newuidmap newgidmap; do
if [ -L bin/$_bin ]; then
_target=$(readlink -f bin/$_bin)
cp "$_target" usr/local/bin/$_bin
chmod +w usr/local/bin/$_bin
printf '\0' >> usr/local/bin/$_bin
chmod 4755 usr/local/bin/$_bin
fi
done
'';
config = {
User = "agent";
WorkingDir = "/workspace";
Env = [
"SHELL=bash"
"PATH=/tmp/home/.local/share/pnpm:/usr/local/bin:/tmp/home/.local/bin:/bin:/usr/bin"
"HOME=/tmp/home"
"XDG_CONFIG_HOME=/tmp/home/.config"
"XDG_DATA_DIRS=/usr/local/share:/usr/share:/tmp/home/.local/share"
"PNPM_HOME=/tmp/home/.local/share/pnpm"
"NIX_STATE_DIR=/tmp/nix/var/nix"
"NIX_CONF_DIR=/etc/nix"
"NIX_SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"GIT_SSL_CAINFO=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"EDITOR=vim"
"TERM=xterm-256color"
"RTK_TELEMETRY_DISABLED=1"
"PLAYWRIGHT_BROWSERS_PATH=${pkgs.playwright-driver.browsers}"
"PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1"
"PLAYWRIGHT_NODEJS_PATH=${pkgs.nodejs_24}/bin/node"
"LIBVIRT_DEFAULT_URI=qemu:///session"
"XDG_RUNTIME_DIR=/tmp/runtime-1000"
"SVDIR=/tmp/services"
];
Cmd = [ "bash" "-l" ];
};
};
packages.default = config.packages.baseImage;
formatter = pkgs.nixpkgs-fmt;
devShells.default = pkgs.mkShell {
name = "slop-env-dev";
packages = with pkgs; [ nushell nixpkgs-fmt statix deadnix git jq yq ];
shellHook = ''
nu ${./scripts/fmt.nu} install-hook 2>/dev/null || true
echo "slop-env dev shell — format: nu scripts/fmt.nu | check: nu scripts/fmt.nu --check"
'';
};
};
};
}
so this is part of it and i honestly cant say i wrote it anymore because i lost control of the repo to qwen he took it over because its way too annoying for me to debug goofy ass shit like /dev/kvm or gpu passthrough or seccomp or selinux but basically this guy is oci image. i'd recommend running it with bocker. https://github.com/p8952/bocker
{
description = "OCI image from flake";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
flake-parts.url = "github:hercules-ci/flake-parts";
claude-code.url = "github:sadjow/claude-code-nix";
claude-code.inputs.nixpkgs.follows = "nixpkgs";
};
outputs = inputs @ { nixpkgs, flake-parts, claude-code, ... }:
flake-parts.lib.mkFlake { inherit inputs; } {
systems = [ "x86_64-linux" "aarch64-linux" ];
perSystem = { config, system, ... }:
let
pkgs = import nixpkgs {
inherit system;
config.allowUnfree = true;
};
imageTag = pkgs.lib.fileContents ./config/image-tag;
agentSubuid = pkgs.writeText "subuid" "agent:100000:65536\n";
agentSubgid = pkgs.writeText "subgid" "agent:100000:65536\n";
agentJailProfile = pkgs.writeText "agent-jail.sh" ''
# slop-env agent hardening
umask 077
export HISTSIZE=100000
export HISTFILESIZE=100000
export HISTCONTROL=""
export HISTTIMEFORMAT="%F %T "
export PROMPT_COMMAND='history -a'
'';
podmanRegistriesConf = pkgs.writeText "registries.conf" ''
[registries.search]
registries = ["docker.io"]
[registries.insecure]
registries = []
'';
podmanPolicyJson = pkgs.writeText "policy.json" ''
{"default":[{"type":"insecureAcceptAnything"}]}
'';
flakeRegistry = pkgs.writeText "registry.json" (builtins.toJSON {
version = 2;
flakes = [{
from = { type = "indirect"; id = "nixpkgs"; };
to = {
type = "github";
owner = "NixOS";
repo = "nixpkgs";
inherit (nixpkgs) rev;
};
}];
});
baseEnv = pkgs.buildEnv {
name = "base-slop-env";
paths = with pkgs; [
glibc
nix
bashInteractive
dash
uutils-coreutils-noprefix
uutils-findutils
uutils-diffutils
which
less
nushell
cacert
moreutils
fish
ripgrep
fd
gawk
gnused
jq
yq
git
curl
wget
openssh
rsync
netcat
tcpdump
gnutar
gzip
zstd
libarchive
vim
ed
claude-code.packages.${system}.default
gcc
gnumake
cmake
python313
nodejs_24
perl
uv
ruff
bc
clang
meson
ninja
gnum4
lua
tcl
ruby_3_4
clisp
calc
jupyter
ffmpeg-full
imagemagick
pandoc
exiftool
yt-dlp
tealdeer
powershell
kubectl
kubernetes-helm
buildah
podman
podman-compose
shadow
slirp4netns
fuse-overlayfs
bubblewrap
iptables
nftables
conmon
crun
runit
procps
util-linux
trash-cli # we use this instead of rm
qemu_kvm
libvirt
cloud-utils
OVMF
swtpm
cdrkit
packer
playwright-driver
playwright-driver.browsers
texliveFull # lol
];
pathsToLink = [ "/bin" "/lib" "/share" "/etc" ];
ignoreCollisions = true;
};
customRoot = pkgs.runCommand "custom-root" { } ''
mkdir -p $out/tmp/home/.local/bin
mkdir -p $out/tmp/home/.local/share/Trash/files
mkdir -p $out/tmp/home/.config/vim
mkdir -p $out/tmp/home/.config/nushell
# mkdir -p $out/home/linuxbrew/.linuxbrew
mkdir -p $out/bin
mkdir -p $out/etc/profile.d
# rtk is NOT copied here: /tmp/home is the persistent volume and would
# shadow/stale it. It's baked to /etc/slop-env/rtk below and re-seeded
# into ~/.local/bin by slop-entrypoint on every boot.
# copy local homebrew from manually updated scripts dir
# cp -r ./scripts/homebrew $out/home/linuxbrew/.linuxbrew/Homebrew
# config files
cp ${./config/vimrc} $out/tmp/home/.config/vim/vimrc
cp ${./config/config.nu} $out/tmp/home/.config/nushell/config.nu
# inner podman configs
mkdir -p $out/etc/containers $out/tmp/home/.config/containers
cp ${./config/containers.conf} $out/etc/containers/containers.conf
cp ${./config/storage.conf} $out/tmp/home/.config/containers/storage.conf
cp ${podmanRegistriesConf} $out/etc/containers/registries.conf
cp ${podmanPolicyJson} $out/etc/containers/policy.json
cp ${agentSubuid} $out/etc/subuid
cp ${agentSubgid} $out/etc/subgid
cp ${agentJailProfile} $out/etc/profile.d/agent-jail.sh
# pin nixpkgs flake-registry id (see flakeRegistry comment above)
mkdir -p $out/etc/nix
cp ${flakeRegistry} $out/etc/nix/registry.json
# JAIL.md (agent jail/env guide) baked read-only. slop-entrypoint
# re-seeds it into ~/.claude/JAIL.md each boot, since ~ is the
# persistent /tmp/home volume and an image copy placed there would be
# shadowed (and could go stale) on subsequent boots.
mkdir -p $out/etc/slop-env
cp ${./config/JAIL.md} $out/etc/slop-env/JAIL.md
# rtk baked read-only; slop-entrypoint re-seeds it into ~/.local/bin each
# boot. rtk is an x86_64-only static binary, so on other arches bake a
# nushell passthrough shim instead — that keeps a registered rtk hook
# from crashing tool calls (TODO.md tracks a real per-arch rtk).
cp ${if pkgs.stdenv.hostPlatform.isx86_64 then ./scripts/rtk else ./scripts/rtk-shim} $out/etc/slop-env/rtk
chmod +x $out/etc/slop-env/rtk
for cmd in sudo su doas run0 sudo-rs gosu su-exec chpst; do
cat > $out/bin/$cmd << 'EOF'
#!/bin/dash
echo "slop-env: $0 is not available. you are jailed. focus on /workspace." >&2
exit 1
EOF
chmod +x $out/bin/$cmd
done
# Helper scripts live in /workspace/scripts/ so they're git-trackable
# and editable without re-running nix build for trivial fixes.
#
# They install to /usr/local/bin (image filesystem, on PATH) rather
# than /tmp/home/.local/bin because /tmp/home is a persistent volume
# — anything installed there from the image is shadowed by the
# volume's old content on the second and subsequent boots, so new
# helpers added in a rebuild would silently never appear.
mkdir -p $out/usr/local/bin
install -m 755 ${./scripts/nix-wrapper} $out/usr/local/bin/nix
install -m 755 ${./scripts/slop-entrypoint} $out/usr/local/bin/slop-entrypoint
install -m 755 ${./scripts/libvirt-up} $out/usr/local/bin/libvirt-up
install -m 755 ${./scripts/doctor} $out/usr/local/bin/doctor
install -m 755 ${./scripts/slop-claude-init} $out/usr/local/bin/slop-claude-init
# runit service templates. Copied into /tmp/services/ at container
# startup by slop-entrypoint so runit can write its supervise state
# there (read-only /etc/ prevents in-place use).
mkdir -p $out/etc/service-template/virtqemud
install -m 755 ${./scripts/runit-services/virtqemud/run} \
$out/etc/service-template/virtqemud/run
# jail banner for bash login shells
cat > $out/etc/profile.d/slop-jail.sh << 'EOF'
# slop-env jail notice
if [ -z "$SLOP_JAIL_SHOWN" ]; then
export SLOP_JAIL_SHOWN=1
echo "=== SLOP-ENV JAIL ==="
echo "sandboxed. writable: /workspace /tmp /tmp/home"
echo "read-only rootfs. no sudo. focus on the code."
echo "nix overlay: 'nix run nixpkgs#<pkg>' or 'nix shell nixpkgs#<pkg> -c bash'"
echo "====================="
fi
EOF
'';
in
{
packages.baseImage = pkgs.dockerTools.buildLayeredImage {
name = "localhost/slop-env";
tag = imageTag;
maxLayers = 67;
contents = [ customRoot baseEnv ];
uid = 1000;
gid = 1000;
uname = "agent";
gname = "agent";
fakeRootCommands = ''
# mkdir -p tmp/home tmp/nix/var/nix tmp/nix/chroot workspace usr/bin etc home/linuxbrew/.linuxbrew/bin
mkdir -p tmp/home tmp/nix/var/nix tmp/nix/chroot workspace usr/bin etc
ln -sf /bin/env usr/bin/env
ln -sf /bin/bash bin/sh
ln -sf /bin/rg bin/grep
chmod 1777 tmp
# chmod 755 tmp/home tmp/nix/var/nix tmp/nix/chroot workspace home/linuxbrew
chmod 755 tmp/home tmp/nix/var/nix tmp/nix/chroot workspace
# setup passwd and groups
cat > etc/passwd << 'EOF'
root:x:0:0:root:/root:/bin/bash
agent:x:1000
EOF
cat > etc/group << 'EOF'
root:x:0:
kvm:x:104:agent
libvirt:x:993:agent
agent:x:1000:
EOF
mkdir -p etc/nix
cat > etc/nix/nix.conf << 'EOF'
experimental-features = nix-command flakes
build-users-group =
sandbox = false
EOF
# ensure /etc/profile.d scripts are sourced by login shells
cat > etc/profile << 'EOF'
for i in /etc/profile.d/*.sh; do
if [ -r "$i" ]; then
. "$i"
fi
done
unset i
EOF
# link brew into the bin path expected by the image
# ln -sf /home/linuxbrew/.linuxbrew/Homebrew/bin/brew home/linuxbrew/.linuxbrew/bin/brew
# allow agent to get serious business done
# chown -R 1000:1000 home/linuxbrew tmp workspace bin/sh
chown -R 1000:1000 tmp workspace bin/sh
# podman runtime dirs (tmpfs ephemeral)
mkdir -p tmp/home/.local/share/containers tmp/run/containers/storage
chown -R 1000:1000 tmp/home/.local tmp/run
# resolve symlinks to regular files so setuid tools and parsers work
for f in etc/subuid etc/subgid etc/containers/containers.conf; do
if [ -L "$f" ]; then
_target=$(readlink -f "$f")
rm -f "$f"
cp "$_target" "$f"
fi
done
# make newuidmap/newgidmap setuid for rootless podman
# place in /usr/local/bin and append a byte so dockerTools
# excludePaths doesn't deduplicate them back to symlinks
mkdir -p usr/local/bin
for _bin in newuidmap newgidmap; do
if [ -L bin/$_bin ]; then
_target=$(readlink -f bin/$_bin)
cp "$_target" usr/local/bin/$_bin
chmod +w usr/local/bin/$_bin
printf '\0' >> usr/local/bin/$_bin
chmod 4755 usr/local/bin/$_bin
fi
done
'';
config = {
User = "agent";
WorkingDir = "/workspace";
Env = [
"SHELL=bash"
"PATH=/tmp/home/.local/share/pnpm:/usr/local/bin:/tmp/home/.local/bin:/bin:/usr/bin"
"HOME=/tmp/home"
"XDG_CONFIG_HOME=/tmp/home/.config"
"XDG_DATA_DIRS=/usr/local/share:/usr/share:/tmp/home/.local/share"
"PNPM_HOME=/tmp/home/.local/share/pnpm"
"NIX_STATE_DIR=/tmp/nix/var/nix"
"NIX_CONF_DIR=/etc/nix"
"NIX_SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"GIT_SSL_CAINFO=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
"EDITOR=vim"
"TERM=xterm-256color"
"RTK_TELEMETRY_DISABLED=1"
"PLAYWRIGHT_BROWSERS_PATH=${pkgs.playwright-driver.browsers}"
"PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1"
"PLAYWRIGHT_NODEJS_PATH=${pkgs.nodejs_24}/bin/node"
"LIBVIRT_DEFAULT_URI=qemu:///session"
"XDG_RUNTIME_DIR=/tmp/runtime-1000"
"SVDIR=/tmp/services"
];
Cmd = [ "bash" "-l" ];
};
};
packages.default = config.packages.baseImage;
formatter = pkgs.nixpkgs-fmt;
devShells.default = pkgs.mkShell {
name = "slop-env-dev";
packages = with pkgs; [ nushell nixpkgs-fmt statix deadnix git jq yq ];
shellHook = ''
nu ${./scripts/fmt.nu} install-hook 2>/dev/null || true
echo "slop-env dev shell — format: nu scripts/fmt.nu | check: nu scripts/fmt.nu --check"
'';
};
};
};
}
@fif @Hyperhidrosis oh my goodness
@pernia @Hyperhidrosis its like 10gb but really i just added a bunch of nonsense packages to this before posting i
@pernia @Hyperhidrosis ill gi e you the entire repo for 12 dollars
@fif @Hyperhidrosis i can giv u admin on cum salon
@pernia @fif @Hyperhidrosis you can't do shit on the salon, you're basically just the mascot, a puppet on a string