sync with labv2.nix + standalone flake with toDisk app
Previous history (https://git.sagar.ch/dotfiles/labv2.nix/commits/branch/master/modules/apps/vmix): - c359054 daku working! - 8de5cff fix integer overflow in vmix network lib - 9c25a66 daku on 25.05. with ollama - 385a3bf vmix enables relaxed sandbox - c363da1 restructure vmixLib into linux/windows subattrs with OS-specific customizeImage - edd4dc2 vmix: port namespace model and module improvements from conf.nix - 6666ecf vmix: add SPICE support, install virtio guest tools with SPICE agent - 46f5671 vmix: add QEMU guest agent channel for Windows VMs - e1fea34 vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection - c27ae68 vmix: make customizeImage chroot-sandboxed by default, opt-in impure - 305fbac virt customize needs chroot for now due to usr bin env things. could be fixed later - 264d30f vmix: add win10 VM on desk, disable SMB signing for guest Samba access - 9b64f51 vmix: split Windows templates into per-category files, add comprehensive debloat - ef91bf8 vmix: fix missing parent registry keys in Windows templates - f87f340 win10 VM on panda with AMD GPU + USB passthrough - 38e474f vmix: split Windows build into Audit Mode install + composable templates - a6a8db3 vmix: win11 support, remove build VNC, switch VMs to SPICE - 6cf5a21 generalize stage sets bg color, accent color and sets visual effects to performance - a84849f remove rdp template since it doesn't even work - 5245263 vmix: best performance template + generalize cleanup - ab12dd3 vmix: use CopyProfile for best performance visual effects - bce3326 vmix: CopyProfile for best performance visual effects - 2496107 vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) - 29a6123 wip: debug default associations xml - 2a2e5f5 vmix: fix DefaultAssociations.xml cmd.exe escaping - cc6ff9d vmix: move DefaultAssociations.xml to template only - a4a78ec vmix: add removeWMP template to remove Windows Media Player - 3fe56de vmix: improved Edge removal (files, shortcuts, scheduled tasks) - a491767 vmix: fully remove Edge via post-oobe AppxPackage removal - 6ca1619 vmix: remove Edge DevToolsClient SystemApps + AppxPackage - 0c1ec35 vmix: sandboxie windows app template - 628bbd2 vmix: add Sandboxie-Plus template - f055a41 vmix: reorganize templates, add file associations, remove Paint - 34326f4 vmix: set Thorium as default browser via PS-SFTA in post-oobe - 86af258 vmix: Active Setup for default browser (all users, no post-oobe needed) - 35b8cb0 remove vnc display from thorium template - c7e0af6 vmix: fix Win11 generalize timeout + UCPD disable for URL associations - 43a1345 vmix: add Office 2024 template + Ohook activation in generalize - 03bbce0 vmix: updated office installation xml. more privacy options enabled - 790a0ee vmix: thorium installation - hide SFTA window - a0e5c18 vmix: fix office install.bat call + add privacy registry policies - 3df38ca vmix: fix Ohook activation + suppress Office theme dialog - df39ba3 vmix: remove sandboxie shortcut from desktop - 50d5972 vmix: skip Sandboxie desktop shortcut via installer flag - ee2fa0f vmix: fix win10 default browser - 938315b vmix: windows: set accent color to automatic. remove accent color from unnecessary elements - beceda8 vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
dd1fb16e1b
commit
736503d730
77 changed files with 2785 additions and 796 deletions
113
lib/images/windows/helpers/customizeImage.nix
Normal file
113
lib/images/windows/helpers/customizeImage.nix
Normal file
|
|
@ -0,0 +1,113 @@
|
|||
# Customize Windows images via offline registry merge and/or Audit Mode script execution.
|
||||
#
|
||||
# Templates can provide:
|
||||
# windowsRegistry — merged offline via virt-win-reg (fast, no boot needed)
|
||||
# auditScript — injected into image and run in Audit Mode via QEMU boot
|
||||
# cdroms — ISO files to attach as CDs when booting for auditScript
|
||||
#
|
||||
# Both can be combined: registry is applied first (offline), then the script runs (online).
|
||||
{ pkgs, lib, ... }:
|
||||
originalImage: {
|
||||
name ? "",
|
||||
diskSize ? "",
|
||||
impure ? true,
|
||||
# Offline: merge .reg file into registry via virt-win-reg
|
||||
windowsRegistry ? "",
|
||||
# Online: boot into Audit Mode and run this script
|
||||
auditScript ? "",
|
||||
# CD-ROMs to attach when booting for auditScript (e.g. VirtIO ISO)
|
||||
cdroms ? [],
|
||||
# Files to upload into the image before running auditScript
|
||||
# List of { source = <drv or path>; dest = "/Windows/path"; }
|
||||
uploads ? [],
|
||||
# QEMU settings for auditScript boot
|
||||
vncDisplay ? null,
|
||||
smp ? 4,
|
||||
memSize ? 4096,
|
||||
}:
|
||||
let
|
||||
originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name);
|
||||
customImageName = (if name != "" then name else "custom") + "-${originalImageName}-vmix.qcow2";
|
||||
resultImg = "./disk.qcow2";
|
||||
|
||||
hasRegistry = windowsRegistry != "";
|
||||
hasAuditScript = auditScript != "";
|
||||
|
||||
# Offline registry merge
|
||||
windowsRegFile = pkgs.writeText "${name}-registry.reg" windowsRegistry;
|
||||
virtWinRegMerge = lib.optionalString hasRegistry ''
|
||||
|
||||
echo "=== vmix: merging registry entries (${name}) ==="
|
||||
virt-win-reg --merge ${resultImg} ${windowsRegFile}
|
||||
'';
|
||||
|
||||
# Audit Mode script injection + QEMU boot
|
||||
auditScriptFile = pkgs.writeText "${name}-audit.cmd" auditScript;
|
||||
wrapperScript = pkgs.writeText "${name}-audit-wrapper.cmd" ''
|
||||
@echo off
|
||||
echo === vmix audit: ${name} ===
|
||||
call C:\vmix-audit-script.cmd
|
||||
echo === vmix audit: ${name} complete ===
|
||||
del /q C:\vmix-audit-script.cmd 2>nul
|
||||
shutdown /s /t 5 /c "vmix: ${name} complete" 2>nul
|
||||
del /q C:\vmix-audit-wrapper.cmd 2>nul
|
||||
'';
|
||||
runOnceReg = pkgs.writeText "${name}-runonce.reg" (lib.concatStringsSep "\n" [
|
||||
"Windows Registry Editor Version 5.00"
|
||||
""
|
||||
''[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]''
|
||||
''"vmixAudit"="C:\\vmix-audit-wrapper.cmd"''
|
||||
""
|
||||
]);
|
||||
|
||||
cdromArgs = lib.concatMapStringsSep " \\\n " (cd: "-drive file=${cd},media=cdrom,readonly=on") cdroms;
|
||||
|
||||
auditBootCommands = lib.optionalString hasAuditScript ''
|
||||
|
||||
echo "=== vmix: injecting audit script (${name}) ==="
|
||||
virt-customize -a ${resultImg} \
|
||||
--upload ${auditScriptFile}:/vmix-audit-script.cmd \
|
||||
--upload ${wrapperScript}:/vmix-audit-wrapper.cmd \
|
||||
${lib.concatMapStringsSep " \\\n " (u: let dir = builtins.dirOf u.dest; in "${lib.optionalString (dir != "/") "--mkdir ${dir}"} --upload ${u.source}:${u.dest}") uploads}
|
||||
|
||||
echo "=== vmix: adding RunOnce entry ==="
|
||||
virt-win-reg --merge ${resultImg} ${runOnceReg}
|
||||
|
||||
# Boot into Audit Mode to run the script
|
||||
cp ${pkgs.OVMF.fd}/FV/OVMF_VARS.fd vars.fd
|
||||
chmod +w vars.fd
|
||||
|
||||
echo "=== vmix: booting Audit Mode for ${name} (VNC: ${if vncDisplay != null then vncDisplay else "disabled"}) ==="
|
||||
timeout 1800 qemu-system-x86_64 \
|
||||
${if vncDisplay != null then "-vnc ${vncDisplay}" else "-nographic"} \
|
||||
-accel kvm \
|
||||
-m ${toString memSize} \
|
||||
-smp ${toString smp} \
|
||||
-cpu host \
|
||||
-machine type=q35 \
|
||||
-drive if=pflash,format=raw,readonly=on,file=${pkgs.OVMF.fd}/FV/OVMF_CODE.fd \
|
||||
-drive if=pflash,format=raw,file=vars.fd \
|
||||
-rtc base=localtime,clock=host \
|
||||
-device qemu-xhci -device usb-tablet \
|
||||
-global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \
|
||||
-drive file=${resultImg},format=qcow2,if=virtio \
|
||||
${cdromArgs} \
|
||||
-nic user,model=virtio-net-pci
|
||||
|
||||
echo "=== vmix: audit script ${name} complete ==="
|
||||
'';
|
||||
|
||||
builderCommand = ''
|
||||
# create resulting image backed by original image
|
||||
qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg}
|
||||
[ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize}
|
||||
${virtWinRegMerge}
|
||||
${auditBootCommands}
|
||||
mv ${resultImg} $out
|
||||
'';
|
||||
builtImage = pkgs.runCommand customImageName ({
|
||||
nativeBuildInputs = with pkgs; [ qemu perl guestfs-tools ];
|
||||
requiredSystemFeatures = [ "kvm" ];
|
||||
} // lib.optionalAttrs impure { __noChroot = true; }) builderCommand;
|
||||
in
|
||||
builtImage // { _vmixOsType = "windows"; }
|
||||
Loading…
Add table
Add a link
Reference in a new issue