sync with labv2.nix + standalone flake with toDisk app
Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
dd1fb16e1b
commit
94f299bb81
77 changed files with 2785 additions and 796 deletions
59
lib/images/linux/customizeImage.nix
Normal file
59
lib/images/linux/customizeImage.nix
Normal file
|
|
@ -0,0 +1,59 @@
|
|||
# wrapper function around virt-customize to create custom Linux image from an original OS image
|
||||
{ pkgs, lib, ... }:
|
||||
originalImage: {
|
||||
name ? "",
|
||||
hostname ? "",
|
||||
nameToHostname ? true,
|
||||
diskSize ? "",
|
||||
smp ? 2,
|
||||
memSize ? 1024,
|
||||
install ? [],
|
||||
run ? "",
|
||||
commands ? "",
|
||||
debug ? false,
|
||||
impure ? true,
|
||||
# Linux-only: script to run on first boot (via systemd --firstboot)
|
||||
firstboot ? ""
|
||||
}:
|
||||
let
|
||||
originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name);
|
||||
customImageName = (if name != "" then name else "custom") + "-${originalImageName}-vmix.qcow2";
|
||||
resultImg = "./disk.qcow2";
|
||||
|
||||
setHostname = if hostname != "" then hostname else if nameToHostname then name else "";
|
||||
virtCustomizeArgsHostname = if setHostname != "" then "--hostname '${setHostname}'" else "";
|
||||
|
||||
virtCustomizeArgsInstall = if install != [] then "--install '${lib.strings.concatStringsSep "," install }'" else "";
|
||||
virtCustomizeArgsCommandsFile = if commands != "" then ("--commands-from-file " + pkgs.writeText "${name}-virt-customize-commands-file" commands) else "";
|
||||
virtCustomizeArgsRun = if run != "" then ("--run " + pkgs.writeScript "${name}-virt-customize-run-script" "${run}") else "";
|
||||
|
||||
virtCustomizeArgsFirstboot = lib.optionalString (firstboot != "")
|
||||
("--firstboot " + pkgs.writeScript "${name}-firstboot" firstboot);
|
||||
|
||||
builderCommand = ''
|
||||
export PATH="${pkgs.qemu}/bin:${pkgs.curl}/bin:$PATH"
|
||||
|
||||
# create resulting image backed by original image
|
||||
qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg}
|
||||
[ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize}
|
||||
|
||||
# run script inside image using virt-customize
|
||||
export LIBGUESTFS_APPEND="ipv6.disable=1"
|
||||
|
||||
${pkgs.guestfs-tools}/bin/virt-customize \
|
||||
${lib.optionalString debug "-v"} \
|
||||
-a ${resultImg} \
|
||||
--smp ${builtins.toString smp} \
|
||||
--memsize ${builtins.toString memSize} \
|
||||
${virtCustomizeArgsHostname} \
|
||||
${virtCustomizeArgsInstall} \
|
||||
${virtCustomizeArgsFirstboot} \
|
||||
${virtCustomizeArgsCommandsFile} \
|
||||
${virtCustomizeArgsRun}
|
||||
|
||||
mv ${resultImg} $out
|
||||
'';
|
||||
|
||||
builtImage = pkgs.runCommand customImageName (lib.optionalAttrs impure { __noChroot = true; }) builderCommand;
|
||||
in
|
||||
builtImage // { _vmixOsType = "linux"; }
|
||||
16
lib/images/linux/debian/default.nix
Normal file
16
lib/images/linux/debian/default.nix
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
{ pkgs, lib, system, linux, ... }:
|
||||
let
|
||||
# upstream distro images
|
||||
upstreamImagesJSON = lib.importJSON ./upstream.json;
|
||||
upstreamImages = lib.mapAttrs (name: src: (pkgs.fetchurl src) // { _vmixOsType = "linux"; }) upstreamImagesJSON.${system};
|
||||
templates = (import ./templates.nix) { inherit pkgs lib system linux; };
|
||||
customs = (import ./images.nix) { inherit pkgs lib system linux upstreamImages templates; };
|
||||
mergeUpstreamAndCustomImages =
|
||||
name: upstreamImage:
|
||||
let
|
||||
customImages = lib.optionalAttrs (lib.hasAttr "${name}" customs) customs.${name};
|
||||
in
|
||||
customImages // { upstream = upstreamImage; };
|
||||
|
||||
images = lib.mapAttrs mergeUpstreamAndCustomImages upstreamImages;
|
||||
in images // { inherit templates; }
|
||||
27
lib/images/linux/debian/images.nix
Normal file
27
lib/images/linux/debian/images.nix
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
# create additional useful customized images from templates and upstream images
|
||||
{ pkgs, lib, system, linux, upstreamImages, templates, ... }:
|
||||
with linux;
|
||||
with scriptsNFiles;
|
||||
let
|
||||
upstreamImageName = "v12";
|
||||
in
|
||||
{
|
||||
${upstreamImageName} = rec {
|
||||
# default image with essential functionalities like ssh, networking etc
|
||||
default = customizeImage upstreamImages.${upstreamImageName} (templates.essentials // {
|
||||
name = "default";
|
||||
hostname = "debian";
|
||||
});
|
||||
|
||||
# playground with easy root access
|
||||
play = customizeImage default (templates.rooted // {
|
||||
name = "play";
|
||||
nameToHostname = false;
|
||||
});
|
||||
|
||||
# proxmox
|
||||
proxmox = customizeImage upstreamImages.${upstreamImageName} (templates.proxmoxOnDebian12 // {
|
||||
name = "proxmox";
|
||||
});
|
||||
};
|
||||
}
|
||||
127
lib/images/linux/debian/templates.nix
Normal file
127
lib/images/linux/debian/templates.nix
Normal file
|
|
@ -0,0 +1,127 @@
|
|||
# ready to use customization templates to apply on images
|
||||
{ pkgs, lib, system, linux, ... }:
|
||||
with linux;
|
||||
with scriptsNFiles;
|
||||
{
|
||||
# essential functionalities like ssh, networking etc
|
||||
essentials = {
|
||||
impure = true;
|
||||
install = [ "htop" "openssh-server" "inetutils-ping" "dnsutils" "cloud-guest-utils" "qemu-guest-agent" ];
|
||||
commands = ''
|
||||
upload ${grub-ifnames-0}:/etc/default/grub.d/90-ifnames-0.cfg
|
||||
upload ${grub-disable-microcode}:/etc/default/grub.d/00-disable-microcode.cfg
|
||||
run-command mountpoint -q /boot/efi || mount /boot/efi
|
||||
run-command update-grub
|
||||
upload ${dhcp-network-for-iface { iface = "eth0"; }}:/etc/systemd/network/00-eth0-dhcp.network
|
||||
run ${ssh-service-override-conf-create}
|
||||
upload ${grow-root-sh}:/usr/local/sbin/grow-root.sh
|
||||
upload ${grow-root-service}:/etc/systemd/system/grow-root.service
|
||||
run-command systemctl enable grow-root.service
|
||||
truncate /etc/machine-id
|
||||
delete /var/lib/dbus/machine-id
|
||||
'';
|
||||
};
|
||||
|
||||
# set easy root access
|
||||
rooted = {
|
||||
impure = true;
|
||||
install = [ "openssh-server" ];
|
||||
commands = ''
|
||||
run ${ssh-service-override-conf-create}
|
||||
'';
|
||||
run = ''
|
||||
# set root password and ssh access
|
||||
echo "root:root" | chpasswd
|
||||
sed -i '/PasswordAuthentication no/d' "/etc/ssh/sshd_config"
|
||||
echo "PasswordAuthentication yes\nPermitRootLogin yes" >> "/etc/ssh/sshd_config"
|
||||
'';
|
||||
};
|
||||
|
||||
# install proxmox
|
||||
proxmoxOnDebian12 = {
|
||||
impure = true;
|
||||
diskSize = "+3G";
|
||||
smp = 4;
|
||||
memSize = 4096;
|
||||
install = [ "cloud-guest-utils" ];
|
||||
debug = true;
|
||||
commands =
|
||||
let
|
||||
# proxmox makes it very hard to manually add interfaces directly on /etc/network/interfaces while the pve services are not running
|
||||
# it also doesn't pick up files in interfaces.d
|
||||
# so manually do that via service after boot
|
||||
mergeNetIfacesDService = pkgs.writeText "manual-net-ifaces.d.service" ''
|
||||
[Service]
|
||||
Type = oneshot
|
||||
ExecStart = /bin/bash -c "cat /etc/network/interfaces.d/* >> /etc/network/interfaces; rm /etc/network/interfaces.d/*; ifreload -a;"
|
||||
After = network.target
|
||||
|
||||
[Install]
|
||||
WantedBy = multi-user.target
|
||||
'';
|
||||
in
|
||||
''
|
||||
upload ${grub-ifnames-0}:/etc/default/grub.d/90-ifnames-0.cfg
|
||||
upload ${grub-disable-microcode}:/etc/default/grub.d/00-disable-microcode.cfg
|
||||
|
||||
truncate /etc/machine-id
|
||||
delete /var/lib/dbus/machine-id
|
||||
|
||||
upload ${grow-root-sh}:/usr/local/sbin/grow-root.sh
|
||||
upload ${grow-root-service}:/etc/systemd/system/grow-root.service
|
||||
run-command systemctl enable grow-root.service
|
||||
|
||||
upload ${mergeNetIfacesDService}:/etc/systemd/system/manual-net-ifaces.d.service
|
||||
run-command systemctl enable manual-net-ifaces.d.service
|
||||
'';
|
||||
run = ''
|
||||
# script originally taken and modified from https://pve.proxmox.com/wiki/Install_Proxmox_VE_on_Debian_12_Bookworm
|
||||
# exit if error
|
||||
set -e
|
||||
|
||||
# grow root partition
|
||||
/usr/local/sbin/grow-root.sh
|
||||
|
||||
# mount efi for grub changes
|
||||
mount /boot/efi || true
|
||||
|
||||
# add proxmox repo
|
||||
echo "deb [arch=amd64] http://download.proxmox.com/debian/pve bookworm pve-no-subscription" > /etc/apt/sources.list.d/pve-install-repo.list
|
||||
wget https://enterprise.proxmox.com/debian/proxmox-release-bookworm.gpg -O /etc/apt/trusted.gpg.d/proxmox-release-bookworm.gpg
|
||||
apt-get update && apt full-upgrade -y --no-install-recommends;
|
||||
|
||||
# necessary precursors
|
||||
echo "0.0.0.0\t\t`cat /etc/hostname`" >> /etc/hosts; # necessary for SSL certificate creation
|
||||
mkdir -p /run/network; # bug https://github.com/CumulusNetworks/ifupdown2/issues/276
|
||||
|
||||
# install
|
||||
apt install -y proxmox-default-kernel proxmox-ve postfix open-iscsi chrony --no-install-recommends;
|
||||
|
||||
# remove previous kernels
|
||||
apt remove -y os-prober linux-image-amd64 'linux-image-6.*';
|
||||
|
||||
# otherwise grub upgrades make the device unbootable
|
||||
echo 'grub-efi-amd64 grub2/force_efi_extra_removable boolean true' | debconf-set-selections -v -u
|
||||
rm -rf /boot/efi/*
|
||||
grub-install /dev/sda
|
||||
grub-install --target=x86_64-efi --removable
|
||||
|
||||
# disable subscription warning
|
||||
# https://dannyda.com/2020/05/17/how-to-remove-you-do-not-have-a-valid-subscription-for-this-server-from-proxmox-virtual-environment-6-1-2-proxmox-ve-6-1-2-pve-6-1-2/
|
||||
sed -i -z "s/res === null ||\n\s* res === undefined ||\n\s* \!res ||\n\s* res.data.status.toLowerCase() \!== 'active'/false/g" /usr/share/javascript/proxmox-widget-toolkit/proxmoxlib.js
|
||||
|
||||
# stop hangs due to network
|
||||
systemctl disable systemd-networkd-wait-online.service
|
||||
|
||||
# create vmbr0 conf, enable dhcp. this conf will be picked by manual-net-ifaces.d.service
|
||||
cat >> /etc/network/interfaces.d/vmbr0.conf << EOF
|
||||
auto vmbr0
|
||||
iface vmbr0 inet dhcp
|
||||
bridge-ports eth0
|
||||
bridge-stp off
|
||||
bridge-fd 0
|
||||
|
||||
EOF
|
||||
'';
|
||||
};
|
||||
}
|
||||
22
lib/images/linux/debian/upstream.json
Normal file
22
lib/images/linux/debian/upstream.json
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
{
|
||||
"aarch64-linux": {
|
||||
"v12": {
|
||||
"sha256": "00gzq6pvpw2idvb4nl4chw6x7j9qjqj7d1j4hsngm241bks6b8h1",
|
||||
"url": "https://cloud.debian.org/images/cloud/bookworm/20240507-1740/debian-12-generic-arm64-20240507-1740.qcow2"
|
||||
},
|
||||
"v13": {
|
||||
"sha256": "01liz34ikbqp7ij9ajginizxcrk1fiw3flqchq01knl8mar3givk",
|
||||
"url": "https://cloud.debian.org/images/cloud/trixie/daily/20240512-1745/debian-13-generic-arm64-daily-20240512-1745.qcow2"
|
||||
}
|
||||
},
|
||||
"x86_64-linux": {
|
||||
"v12": {
|
||||
"sha256": "5fvoe45ooVSPwQ3FRn8+ge18sAvSVk+m3iUO71WTM1A=",
|
||||
"url": "https://cloud.debian.org/images/cloud/bookworm/20250530-2128/debian-12-generic-amd64-20250530-2128.qcow2"
|
||||
},
|
||||
"v13": {
|
||||
"sha256": "1bixl6gnzigwryac1arc3n81nv4hwdi6wxpwmvrgigzni64b3x6w",
|
||||
"url": "https://cloud.debian.org/images/cloud/trixie/daily/20250605-2134/debian-13-generic-amd64-daily-20250605-2134.raw"
|
||||
}
|
||||
}
|
||||
}
|
||||
14
lib/images/linux/default.nix
Normal file
14
lib/images/linux/default.nix
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
{ pkgs, lib, system, ... }:
|
||||
let
|
||||
linux = rec {
|
||||
# basic scripts and files used across various Linux images
|
||||
scriptsNFiles = (import ./scripts-n-files.nix) { inherit pkgs lib; };
|
||||
customizeImage = (import ./customizeImage.nix) { inherit pkgs lib; };
|
||||
customizeImageFold = builtins.foldl' customizeImage;
|
||||
};
|
||||
debian = (import ./debian) { inherit pkgs lib system linux; };
|
||||
in linux // {
|
||||
images = {
|
||||
debian = debian;
|
||||
};
|
||||
}
|
||||
82
lib/images/linux/scripts-n-files.nix
Normal file
82
lib/images/linux/scripts-n-files.nix
Normal file
|
|
@ -0,0 +1,82 @@
|
|||
# minimal set of scripts and services by various images
|
||||
{ pkgs, lib, ... }: {
|
||||
# bring back simple interface names like eth0 eth1 etc
|
||||
grub-ifnames-0 = pkgs.writeText "grub-ifnames-0" ''
|
||||
GRUB_CMDLINE_LINUX="net.ifnames=0 biosdevname=0 $GRUB_CMDLINE_LINUX"
|
||||
'';
|
||||
|
||||
# no need for CPU microcode updating in VMs
|
||||
grub-disable-microcode = pkgs.writeText "grub-disable-microcode" ''
|
||||
GRUB_CMDLINE_LINUX="dis_ucode_ldr $GRUB_CMDLINE_LINUX"
|
||||
'';
|
||||
|
||||
# dhcp for eth0
|
||||
dhcp-network-for-iface = { iface, routeMetric ? 1024, useDNS ? true }: pkgs.writeText "${iface}-network" ''
|
||||
[Match]
|
||||
Name=${iface}
|
||||
|
||||
[Network]
|
||||
DHCP=yes
|
||||
|
||||
[DHCP]
|
||||
ClientIdentifier=mac
|
||||
RouteMetric=${toString routeMetric}
|
||||
|
||||
${if useDNS then ''
|
||||
[DHCPv4]
|
||||
UseDNS=True
|
||||
UseDomains=True
|
||||
'' else ''
|
||||
[DHCPv4]
|
||||
UseDNS=false
|
||||
''}
|
||||
'';
|
||||
|
||||
# generate ssh host keys before starting sshd
|
||||
ssh-service-override-conf-create = pkgs.writeScript "ssh-override-conf-create.sh" ''
|
||||
mkdir -p /etc/systemd/system/ssh.service.d
|
||||
|
||||
cat > /etc/systemd/system/ssh.service.d/override.conf << EOF
|
||||
[Service]
|
||||
ExecStartPre=
|
||||
ExecStartPre=`which ssh-keygen` -A
|
||||
ExecStartPre=`which sshd` -t
|
||||
|
||||
EOF
|
||||
'';
|
||||
|
||||
# script to grow root partition
|
||||
grow-root-sh = pkgs.writeScript "grow-root-sh" ''
|
||||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
command -v growpart >/dev/null || { >&2 echo "growpart not found. Install package cloud-guest-utils or cloud-utils."; exit 1; }
|
||||
|
||||
ROOTPART=$(findmnt / -o source -n)
|
||||
DISK=''${ROOTPART%[0-9]*}
|
||||
PARTNUM=''${ROOTPART##*[!0-9]}
|
||||
|
||||
# resize and grow if possible
|
||||
growpart "$DISK" "$PARTNUM" && resize2fs "$ROOTPART" || true
|
||||
'';
|
||||
|
||||
# service to grow root partition on boot
|
||||
grow-root-service = pkgs.writeText "grow-root-service" ''
|
||||
[Service]
|
||||
Type = oneshot
|
||||
ExecStart = /usr/local/sbin/grow-root.sh
|
||||
|
||||
[Install]
|
||||
WantedBy = multi-user.target
|
||||
'';
|
||||
|
||||
add-9p-mounts-to-fstab = shares:
|
||||
let
|
||||
shareToFstabEntry = name: share: "${name} ${share.target} 9p trans=virtio,version=9p2000.L,rw,posixacl,msize=104857600,cache=loose 0 0";
|
||||
in
|
||||
pkgs.writeText "9p-to-fstab-sh" ''
|
||||
cat >> /etc/fstab << EOF
|
||||
${lib.concatStringsSep "\n" (lib.mapAttrsToList shareToFstabEntry shares)}
|
||||
EOF
|
||||
'';
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue