sync with labv2.nix + standalone flake with toDisk app
Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
dd1fb16e1b
commit
94f299bb81
77 changed files with 2785 additions and 796 deletions
113
lib/images/windows/helpers/customizeImage.nix
Normal file
113
lib/images/windows/helpers/customizeImage.nix
Normal file
|
|
@ -0,0 +1,113 @@
|
|||
# Customize Windows images via offline registry merge and/or Audit Mode script execution.
|
||||
#
|
||||
# Templates can provide:
|
||||
# windowsRegistry — merged offline via virt-win-reg (fast, no boot needed)
|
||||
# auditScript — injected into image and run in Audit Mode via QEMU boot
|
||||
# cdroms — ISO files to attach as CDs when booting for auditScript
|
||||
#
|
||||
# Both can be combined: registry is applied first (offline), then the script runs (online).
|
||||
{ pkgs, lib, ... }:
|
||||
originalImage: {
|
||||
name ? "",
|
||||
diskSize ? "",
|
||||
impure ? true,
|
||||
# Offline: merge .reg file into registry via virt-win-reg
|
||||
windowsRegistry ? "",
|
||||
# Online: boot into Audit Mode and run this script
|
||||
auditScript ? "",
|
||||
# CD-ROMs to attach when booting for auditScript (e.g. VirtIO ISO)
|
||||
cdroms ? [],
|
||||
# Files to upload into the image before running auditScript
|
||||
# List of { source = <drv or path>; dest = "/Windows/path"; }
|
||||
uploads ? [],
|
||||
# QEMU settings for auditScript boot
|
||||
vncDisplay ? null,
|
||||
smp ? 4,
|
||||
memSize ? 4096,
|
||||
}:
|
||||
let
|
||||
originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name);
|
||||
customImageName = (if name != "" then name else "custom") + "-${originalImageName}-vmix.qcow2";
|
||||
resultImg = "./disk.qcow2";
|
||||
|
||||
hasRegistry = windowsRegistry != "";
|
||||
hasAuditScript = auditScript != "";
|
||||
|
||||
# Offline registry merge
|
||||
windowsRegFile = pkgs.writeText "${name}-registry.reg" windowsRegistry;
|
||||
virtWinRegMerge = lib.optionalString hasRegistry ''
|
||||
|
||||
echo "=== vmix: merging registry entries (${name}) ==="
|
||||
virt-win-reg --merge ${resultImg} ${windowsRegFile}
|
||||
'';
|
||||
|
||||
# Audit Mode script injection + QEMU boot
|
||||
auditScriptFile = pkgs.writeText "${name}-audit.cmd" auditScript;
|
||||
wrapperScript = pkgs.writeText "${name}-audit-wrapper.cmd" ''
|
||||
@echo off
|
||||
echo === vmix audit: ${name} ===
|
||||
call C:\vmix-audit-script.cmd
|
||||
echo === vmix audit: ${name} complete ===
|
||||
del /q C:\vmix-audit-script.cmd 2>nul
|
||||
shutdown /s /t 5 /c "vmix: ${name} complete" 2>nul
|
||||
del /q C:\vmix-audit-wrapper.cmd 2>nul
|
||||
'';
|
||||
runOnceReg = pkgs.writeText "${name}-runonce.reg" (lib.concatStringsSep "\n" [
|
||||
"Windows Registry Editor Version 5.00"
|
||||
""
|
||||
''[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]''
|
||||
''"vmixAudit"="C:\\vmix-audit-wrapper.cmd"''
|
||||
""
|
||||
]);
|
||||
|
||||
cdromArgs = lib.concatMapStringsSep " \\\n " (cd: "-drive file=${cd},media=cdrom,readonly=on") cdroms;
|
||||
|
||||
auditBootCommands = lib.optionalString hasAuditScript ''
|
||||
|
||||
echo "=== vmix: injecting audit script (${name}) ==="
|
||||
virt-customize -a ${resultImg} \
|
||||
--upload ${auditScriptFile}:/vmix-audit-script.cmd \
|
||||
--upload ${wrapperScript}:/vmix-audit-wrapper.cmd \
|
||||
${lib.concatMapStringsSep " \\\n " (u: let dir = builtins.dirOf u.dest; in "${lib.optionalString (dir != "/") "--mkdir ${dir}"} --upload ${u.source}:${u.dest}") uploads}
|
||||
|
||||
echo "=== vmix: adding RunOnce entry ==="
|
||||
virt-win-reg --merge ${resultImg} ${runOnceReg}
|
||||
|
||||
# Boot into Audit Mode to run the script
|
||||
cp ${pkgs.OVMF.fd}/FV/OVMF_VARS.fd vars.fd
|
||||
chmod +w vars.fd
|
||||
|
||||
echo "=== vmix: booting Audit Mode for ${name} (VNC: ${if vncDisplay != null then vncDisplay else "disabled"}) ==="
|
||||
timeout 1800 qemu-system-x86_64 \
|
||||
${if vncDisplay != null then "-vnc ${vncDisplay}" else "-nographic"} \
|
||||
-accel kvm \
|
||||
-m ${toString memSize} \
|
||||
-smp ${toString smp} \
|
||||
-cpu host \
|
||||
-machine type=q35 \
|
||||
-drive if=pflash,format=raw,readonly=on,file=${pkgs.OVMF.fd}/FV/OVMF_CODE.fd \
|
||||
-drive if=pflash,format=raw,file=vars.fd \
|
||||
-rtc base=localtime,clock=host \
|
||||
-device qemu-xhci -device usb-tablet \
|
||||
-global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \
|
||||
-drive file=${resultImg},format=qcow2,if=virtio \
|
||||
${cdromArgs} \
|
||||
-nic user,model=virtio-net-pci
|
||||
|
||||
echo "=== vmix: audit script ${name} complete ==="
|
||||
'';
|
||||
|
||||
builderCommand = ''
|
||||
# create resulting image backed by original image
|
||||
qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg}
|
||||
[ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize}
|
||||
${virtWinRegMerge}
|
||||
${auditBootCommands}
|
||||
mv ${resultImg} $out
|
||||
'';
|
||||
builtImage = pkgs.runCommand customImageName ({
|
||||
nativeBuildInputs = with pkgs; [ qemu perl guestfs-tools ];
|
||||
requiredSystemFeatures = [ "kvm" ];
|
||||
} // lib.optionalAttrs impure { __noChroot = true; }) builderCommand;
|
||||
in
|
||||
builtImage // { _vmixOsType = "windows"; }
|
||||
174
lib/images/windows/helpers/makeAuditModeAutounattend.nix
Normal file
174
lib/images/windows/helpers/makeAuditModeAutounattend.nix
Normal file
|
|
@ -0,0 +1,174 @@
|
|||
# Autounattend.xml for unattended Windows installation into Audit Mode.
|
||||
# Minimal — only what's needed to install Windows and enter Audit Mode.
|
||||
# All customization (hostname, timezone, telemetry, UAC, etc.) is done via templates.
|
||||
{ pkgs, lib, ... }:
|
||||
{
|
||||
locale ? "en-US",
|
||||
productKey ? "",
|
||||
diskIndex ? 0,
|
||||
imageIndex ? 1,
|
||||
efi ? true,
|
||||
virtioDriverLetter ? "E",
|
||||
bypassRequirements ? false,
|
||||
windowsVersionForVirtioDrivers
|
||||
}: pkgs.writeText "Autounattend.xml" ''
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<unattend xmlns="urn:schemas-microsoft-com:unattend"
|
||||
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
|
||||
|
||||
<!-- windowsPE — locale, product key, VirtIO drivers, disk partitioning -->
|
||||
<settings pass="windowsPE">
|
||||
<component name="Microsoft-Windows-International-Core-WinPE" processorArchitecture="amd64"
|
||||
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||
<SetupUILanguage>
|
||||
<UILanguage>${locale}</UILanguage>
|
||||
</SetupUILanguage>
|
||||
<InputLocale>${locale}</InputLocale>
|
||||
<SystemLocale>${locale}</SystemLocale>
|
||||
<UILanguage>${locale}</UILanguage>
|
||||
<UserLocale>${locale}</UserLocale>
|
||||
</component>
|
||||
|
||||
<component name="Microsoft-Windows-PnpCustomizationsWinPE" processorArchitecture="amd64"
|
||||
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||
<DriverPaths>
|
||||
<PathAndCredentials wcm:action="add" wcm:keyValue="1">
|
||||
<Path>${virtioDriverLetter}:\amd64\${windowsVersionForVirtioDrivers}</Path>
|
||||
</PathAndCredentials>
|
||||
</DriverPaths>
|
||||
</component>
|
||||
|
||||
<component name="Microsoft-Windows-Setup" processorArchitecture="amd64"
|
||||
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||
<UserData>
|
||||
${lib.optionalString (productKey != "") ''
|
||||
<ProductKey>
|
||||
<Key>${productKey}</Key>
|
||||
</ProductKey>
|
||||
''}
|
||||
<AcceptEula>true</AcceptEula>
|
||||
</UserData>
|
||||
|
||||
<ImageInstall>
|
||||
<OSImage>
|
||||
<InstallFrom>
|
||||
<MetaData wcm:action="add">
|
||||
<Key>/IMAGE/INDEX</Key>
|
||||
<Value>${toString imageIndex}</Value>
|
||||
</MetaData>
|
||||
</InstallFrom>
|
||||
<InstallTo>
|
||||
<DiskID>${toString diskIndex}</DiskID>
|
||||
<PartitionID>${if efi then "3" else "1"}</PartitionID>
|
||||
</InstallTo>
|
||||
</OSImage>
|
||||
</ImageInstall>
|
||||
|
||||
<DiskConfiguration>
|
||||
<Disk wcm:action="add">
|
||||
<DiskID>${toString diskIndex}</DiskID>
|
||||
<WillWipeDisk>true</WillWipeDisk>
|
||||
${if efi then ''
|
||||
<CreatePartitions>
|
||||
<CreatePartition wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<Size>100</Size>
|
||||
<Type>EFI</Type>
|
||||
</CreatePartition>
|
||||
<CreatePartition wcm:action="add">
|
||||
<Order>2</Order>
|
||||
<Size>16</Size>
|
||||
<Type>MSR</Type>
|
||||
</CreatePartition>
|
||||
<CreatePartition wcm:action="add">
|
||||
<Order>3</Order>
|
||||
<Extend>true</Extend>
|
||||
<Type>Primary</Type>
|
||||
</CreatePartition>
|
||||
</CreatePartitions>
|
||||
<ModifyPartitions>
|
||||
<ModifyPartition wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<PartitionID>1</PartitionID>
|
||||
<Format>FAT32</Format>
|
||||
<Label>EFI</Label>
|
||||
</ModifyPartition>
|
||||
<ModifyPartition wcm:action="add">
|
||||
<Order>2</Order>
|
||||
<PartitionID>2</PartitionID>
|
||||
</ModifyPartition>
|
||||
<ModifyPartition wcm:action="add">
|
||||
<Order>3</Order>
|
||||
<PartitionID>3</PartitionID>
|
||||
<Format>NTFS</Format>
|
||||
<Label>Windows</Label>
|
||||
</ModifyPartition>
|
||||
</ModifyPartitions>
|
||||
'' else ''
|
||||
<CreatePartitions>
|
||||
<CreatePartition wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<Extend>true</Extend>
|
||||
<Type>Primary</Type>
|
||||
</CreatePartition>
|
||||
</CreatePartitions>
|
||||
<ModifyPartitions>
|
||||
<ModifyPartition wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<PartitionID>1</PartitionID>
|
||||
<Format>NTFS</Format>
|
||||
<Label>Windows</Label>
|
||||
<Active>true</Active>
|
||||
</ModifyPartition>
|
||||
</ModifyPartitions>
|
||||
''}
|
||||
</Disk>
|
||||
</DiskConfiguration>
|
||||
|
||||
${lib.optionalString bypassRequirements ''
|
||||
<RunSynchronous>
|
||||
<RunSynchronousCommand wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<Path>reg add HKLM\SYSTEM\Setup\LabConfig /v BypassTPMCheck /t REG_DWORD /d 1 /f</Path>
|
||||
</RunSynchronousCommand>
|
||||
<RunSynchronousCommand wcm:action="add">
|
||||
<Order>2</Order>
|
||||
<Path>reg add HKLM\SYSTEM\Setup\LabConfig /v BypassSecureBootCheck /t REG_DWORD /d 1 /f</Path>
|
||||
</RunSynchronousCommand>
|
||||
<RunSynchronousCommand wcm:action="add">
|
||||
<Order>3</Order>
|
||||
<Path>reg add HKLM\SYSTEM\Setup\LabConfig /v BypassRAMCheck /t REG_DWORD /d 1 /f</Path>
|
||||
</RunSynchronousCommand>
|
||||
</RunSynchronous>
|
||||
''}
|
||||
</component>
|
||||
</settings>
|
||||
|
||||
<!-- specialize — inject RunOnce to clean up cached Autounattend and shutdown -->
|
||||
<settings pass="specialize">
|
||||
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64"
|
||||
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||
<RunSynchronous>
|
||||
<RunSynchronousCommand wcm:action="add">
|
||||
<Order>1</Order>
|
||||
<Path>reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v vmixCleanup /t REG_SZ /d "cmd /c del /q C:\Windows\Panther\unattend.xml" /f</Path>
|
||||
</RunSynchronousCommand>
|
||||
<RunSynchronousCommand wcm:action="add">
|
||||
<Order>2</Order>
|
||||
<Path>reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v vmixShutdown /t REG_SZ /d "shutdown /s /t 10 /c vmix-audit-ready" /f</Path>
|
||||
</RunSynchronousCommand>
|
||||
</RunSynchronous>
|
||||
</component>
|
||||
</settings>
|
||||
|
||||
<!-- oobeSystem — enter Audit Mode -->
|
||||
<settings pass="oobeSystem">
|
||||
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64"
|
||||
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||
<Reseal>
|
||||
<Mode>Audit</Mode>
|
||||
</Reseal>
|
||||
</component>
|
||||
</settings>
|
||||
</unattend>
|
||||
''
|
||||
23
lib/images/windows/helpers/makeFilesISO.nix
Normal file
23
lib/images/windows/helpers/makeFilesISO.nix
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
# Create an ISO from a list of files. Zips are automatically extracted.
|
||||
# Nix store hash prefixes are stripped from filenames.
|
||||
# Usage:
|
||||
# makeFilesISO { name = "my-stuff"; files = [ ./foo.exe someZip anotherFile ]; }
|
||||
# makeFilesISO { name = "my-stuff"; files = [ (pkgs.fetchurl { ... }) ]; }
|
||||
{ pkgs, ... }:
|
||||
{ name ? "files", files }:
|
||||
pkgs.runCommand "${name}.iso" {
|
||||
nativeBuildInputs = with pkgs; [ unzip cdrkit file ];
|
||||
} ''
|
||||
mkdir -p content
|
||||
${builtins.concatStringsSep "\n" (map (f: ''
|
||||
if file --mime-type -b "${f}" | grep -q "application/zip"; then
|
||||
unzip -q -o "${f}" -d content
|
||||
else
|
||||
# Strip nix store hash prefix (e.g. "abc123-foo.exe" -> "foo.exe")
|
||||
fname=$(basename "${f}")
|
||||
stripped="''${fname#*-}"
|
||||
cp "${f}" "content/$stripped"
|
||||
fi
|
||||
'') files)}
|
||||
genisoimage -o $out -joliet -joliet-long -rational-rock content
|
||||
''
|
||||
69
lib/images/windows/helpers/makeImage.nix
Normal file
69
lib/images/windows/helpers/makeImage.nix
Normal file
|
|
@ -0,0 +1,69 @@
|
|||
# Build a pre-installed Windows qcow2 image using QEMU unattended install.
|
||||
# Boots into Audit Mode after install and shuts down.
|
||||
# Apply templates via customizeImageFold to install software (auditScript)
|
||||
# and customize registry (windowsRegistry), then generalize when done.
|
||||
{ pkgs, lib, drivers, makeWinISO, makeAuditModeAutounattend, ... }:
|
||||
{
|
||||
name ? "windows",
|
||||
upstreamISO,
|
||||
productKey ? "",
|
||||
imageIndex ? 1,
|
||||
diskSize ? "64G",
|
||||
bypassRequirements ? false,
|
||||
locale ? "en-US",
|
||||
efi ? true,
|
||||
smp ? 4,
|
||||
memSize ? 4096,
|
||||
vncDisplay ? null, # e.g. ":10" to enable VNC on port 5910 for monitoring
|
||||
windowsVersionForVirtioDrivers ? "w10", # "w10", "w11", "2k22", "2k19", etc.
|
||||
}:
|
||||
let
|
||||
AutounattendedXml = makeAuditModeAutounattend {
|
||||
inherit locale productKey imageIndex
|
||||
efi bypassRequirements windowsVersionForVirtioDrivers;
|
||||
diskIndex = 0;
|
||||
virtioDriverLetter = "E";
|
||||
};
|
||||
|
||||
iso = makeWinISO {
|
||||
iso = upstreamISO;
|
||||
inherit AutounattendedXml;
|
||||
};
|
||||
|
||||
drv = pkgs.runCommand "${name}-vmix.qcow2" {
|
||||
__noChroot = true;
|
||||
requiredSystemFeatures = [ "kvm" ];
|
||||
nativeBuildInputs = with pkgs; [ qemu ];
|
||||
} ''
|
||||
# create empty disk
|
||||
qemu-img create -f qcow2 disk.qcow2 ${diskSize}
|
||||
|
||||
# writable UEFI NVRAM so boot order persists across reboots
|
||||
cp ${pkgs.OVMF.fd}/FV/OVMF_VARS.fd vars.fd
|
||||
chmod +w vars.fd
|
||||
|
||||
echo "=== Starting Windows unattended install (this takes 15-30 minutes) ==="
|
||||
|
||||
# Windows installs unattended, reboots into Audit Mode,
|
||||
# deletes cached Autounattend, shuts down → QEMU exits.
|
||||
timeout 3600 qemu-system-x86_64 \
|
||||
${if vncDisplay != null then "-vnc ${vncDisplay}" else "-nographic"} \
|
||||
-accel kvm \
|
||||
-m ${toString memSize} \
|
||||
-smp ${toString smp} \
|
||||
-cpu host \
|
||||
-machine type=q35 \
|
||||
-drive if=pflash,format=raw,readonly=on,file=${pkgs.OVMF.fd}/FV/OVMF_CODE.fd \
|
||||
-drive if=pflash,format=raw,file=vars.fd \
|
||||
-rtc base=localtime,clock=host \
|
||||
-device qemu-xhci -device usb-tablet \
|
||||
-global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \
|
||||
-drive file=disk.qcow2,format=qcow2,if=virtio \
|
||||
-drive file=${iso},media=cdrom,readonly=on \
|
||||
-drive file=${drivers.virtio-iso},media=cdrom,readonly=on \
|
||||
-nic user,model=virtio-net-pci
|
||||
|
||||
echo "=== Windows install complete (Audit Mode image) ==="
|
||||
mv disk.qcow2 $out
|
||||
'';
|
||||
in drv // { _vmixOsType = "windows"; }
|
||||
40
lib/images/windows/helpers/makeWinISO.nix
Normal file
40
lib/images/windows/helpers/makeWinISO.nix
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
# Remaster a Windows ISO: remove boot prompt, optionally inject Autounattend.xml and scripts
|
||||
{ pkgs, ... }:
|
||||
{ iso, AutounattendedXml ? null, postInstallScript ? null }:
|
||||
pkgs.runCommand "windows-remastered.iso" {
|
||||
nativeBuildInputs = with pkgs; [ p7zip cdrkit ];
|
||||
} ''
|
||||
workdir=$(mktemp -d)
|
||||
isopath="${iso}"
|
||||
if [ -d "$isopath" ]; then
|
||||
isopath="$(find "$isopath" -maxdepth 1 -name '*.iso' -type f | head -n1)"
|
||||
if [ -z "$isopath" ]; then
|
||||
echo "ERROR: no .iso file found in $isopath"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
7z x -o"$workdir" "$isopath" > /dev/null
|
||||
|
||||
# remove "Press any key to boot from CD/DVD" prompt
|
||||
if [ -f "$workdir/efi/microsoft/boot/efisys_noprompt.bin" ]; then
|
||||
cp "$workdir/efi/microsoft/boot/efisys_noprompt.bin" \
|
||||
"$workdir/efi/microsoft/boot/efisys.bin"
|
||||
fi
|
||||
if [ -f "$workdir/efi/microsoft/boot/cdboot_noprompt.efi" ]; then
|
||||
cp "$workdir/efi/microsoft/boot/cdboot_noprompt.efi" \
|
||||
"$workdir/efi/microsoft/boot/cdboot.efi"
|
||||
fi
|
||||
rm -f "$workdir/boot/bootfix.bin"
|
||||
|
||||
# inject unattend and post-install script into ISO root
|
||||
${if AutounattendedXml != null then ''cp ${AutounattendedXml} "$workdir/Autounattend.xml"'' else ""}
|
||||
${if postInstallScript != null then ''cp ${postInstallScript} "$workdir/post-install.cmd"'' else ""}
|
||||
|
||||
genisoimage \
|
||||
-allow-limited-size -iso-level 3 -o "$out" \
|
||||
-joliet -joliet-long -rational-rock -udf \
|
||||
-b boot/etfsboot.com -no-emul-boot -boot-load-size 8 -boot-info-table \
|
||||
-eltorito-alt-boot -e efi/microsoft/boot/efisys.bin -no-emul-boot \
|
||||
"$workdir"
|
||||
rm -rf "$workdir"
|
||||
''
|
||||
Loading…
Add table
Add a link
Reference in a new issue