sync with labv2.nix + standalone flake with toDisk app
Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
dd1fb16e1b
commit
94f299bb81
77 changed files with 2785 additions and 796 deletions
BIN
lib/images/windows/templates/apps/7zip-file-associations.reg
Normal file
BIN
lib/images/windows/templates/apps/7zip-file-associations.reg
Normal file
Binary file not shown.
20
lib/images/windows/templates/apps/7zip.nix
Normal file
20
lib/images/windows/templates/apps/7zip.nix
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
# Install 7-Zip and set file associations
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://github.com/ip7z/7zip/releases/download/26.00/7z2600-x64.msi";
|
||||
hash = "sha256-w4jQREhxyhGyEjcAGvFYz92tfhN4UXleW2XO5ptRhJU=";
|
||||
};
|
||||
assocReg = ./7zip-file-associations.reg;
|
||||
in {
|
||||
name = "7zip";
|
||||
cdroms = [ (makeFilesISO { name = "7zip"; files = [ installer assocReg ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing 7-Zip...
|
||||
msiexec /i "D:\7z2600-x64.msi" /qn /norestart
|
||||
|
||||
echo Importing 7-Zip file associations...
|
||||
regedit /s "D:\7zip-file-associations.reg"
|
||||
'';
|
||||
}
|
||||
18
lib/images/windows/templates/apps/edge-webview.nix
Normal file
18
lib/images/windows/templates/apps/edge-webview.nix
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
# Install Microsoft Edge WebView2 Runtime
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/7ff41be4-dbce-4efe-823f-c7d33a4e3c5e/MicrosoftEdgeWebview2Setup.exe";
|
||||
hash = "sha256-Asl+XjKpfYlhY+xoo+o6sDOeV/J0NIuGiTmWOLZJsrk=";
|
||||
};
|
||||
in {
|
||||
name = "edge-webview";
|
||||
cdroms = [ (makeFilesISO { name = "edge-webview"; files = [ installer ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing Edge WebView2 Runtime...
|
||||
copy D:\MicrosoftEdgeWebview2Setup.exe C:\webview-setup.exe
|
||||
start /wait C:\webview-setup.exe /silent /install
|
||||
del /q C:\webview-setup.exe
|
||||
'';
|
||||
}
|
||||
Binary file not shown.
26
lib/images/windows/templates/apps/imageglass.nix
Normal file
26
lib/images/windows/templates/apps/imageglass.nix
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
# Install ImageGlass and set file associations
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://github.com/d2phap/ImageGlass/releases/download/9.4.1.15/ImageGlass_9.4.1.15_x64.msi";
|
||||
hash = "sha256-o7q+5XpGLK+P/GQxvN/Ud5w1NxPpJ24AL54HNwda32Q=";
|
||||
};
|
||||
assocReg = ./imageglass-file-associations.reg;
|
||||
in {
|
||||
name = "imageglass";
|
||||
cdroms = [ (makeFilesISO { name = "imageglass"; files = [ installer assocReg ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing ImageGlass...
|
||||
msiexec /i "D:\ImageGlass_9.4.1.15_x64.msi" /qn /norestart ALLUSERS=1
|
||||
|
||||
echo Importing ImageGlass file associations...
|
||||
regedit /s "D:\imageglass-file-associations.reg"
|
||||
|
||||
:: delete shortcut on desktop
|
||||
del /q "C:\Users\Public\Desktop\ImageGlass.lnk"
|
||||
|
||||
:: Remove Paint Brush class registration
|
||||
reg delete "HKLM\SOFTWARE\Classes\PBrush" /f 2>nul
|
||||
'';
|
||||
}
|
||||
29
lib/images/windows/templates/apps/office.nix
Normal file
29
lib/images/windows/templates/apps/office.nix
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
# Install Microsoft Office 2024 (Word, Excel, PowerPoint) via offline deployment
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
officeSrc = pkgs.fetchurl {
|
||||
url = "https://git.sagar.ch/dotfiles/office-2024-word-excel-powerpoint/archive/4351e8d93ceb28f65de9ec4dc9c27dccbe91ff34.zip";
|
||||
hash = "sha256-ulNecpkUH6O9cqYhgtmG++a1gi+c4HIR1Vvo22VygJs=";
|
||||
};
|
||||
in {
|
||||
name = "office";
|
||||
cdroms = [ (makeFilesISO { name = "office"; files = [ officeSrc ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing Microsoft Office 2024...
|
||||
call D:\office-2024-word-excel-powerpoint\install.bat
|
||||
|
||||
:: Office privacy policies (HKCU, preserved to new users via CopyProfile)
|
||||
reg add "HKCU\Software\Policies\Microsoft\office\16.0\common\privacy" /v "disconnectedstate" /t REG_DWORD /d 2 /f >nul
|
||||
reg add "HKCU\Software\Policies\Microsoft\office\16.0\common\privacy" /v "usercontentdisabled" /t REG_DWORD /d 2 /f >nul
|
||||
reg add "HKCU\Software\Policies\Microsoft\office\16.0\common\privacy" /v "downloadcontentdisabled" /t REG_DWORD /d 2 /f >nul
|
||||
reg add "HKCU\Software\Policies\Microsoft\office\16.0\common\privacy" /v "controllerconnectedservicesenabled" /t REG_DWORD /d 2 /f >nul
|
||||
reg add "HKCU\Software\Policies\Microsoft\office\common\clienttelemetry" /v "sendtelemetry" /t REG_DWORD /d 3 /f >nul
|
||||
|
||||
:: incase of enabling connected experiences, this disables the dialog box that shows at first run
|
||||
:: reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\Privacy\SettingsStore\Anonymous" /v "OptionalConnectedExperiencesNoticeVersion" /t REG_DWORD /d 2 /f >nul
|
||||
|
||||
:: supress dialogbox - Choose your theme for 365 Apps
|
||||
reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\PromoDialog" /v "FluentWelcomeDialogShown" /t REG_DWORD /d 1 /f >nul
|
||||
'';
|
||||
}
|
||||
16
lib/images/windows/templates/apps/sandboxie.nix
Normal file
16
lib/images/windows/templates/apps/sandboxie.nix
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
# Install Sandboxie-Plus
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://github.com/sandboxie-plus/Sandboxie/releases/download/v1.15.6/Sandboxie-Plus-x64-v1.15.6.exe";
|
||||
hash = "sha256-0VQXy9rFCJCfVyHLJYXe/s6imcwEZugsNOKMhUoLUVM=";
|
||||
};
|
||||
in {
|
||||
name = "sandboxie";
|
||||
cdroms = [ (makeFilesISO { name = "sandboxie"; files = [ installer ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing Sandboxie-Plus...
|
||||
start /wait D:\Sandboxie-Plus-x64-v1.15.6.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /MERGETASKS="!desktopicon"
|
||||
'';
|
||||
}
|
||||
40
lib/images/windows/templates/apps/thorium.nix
Normal file
40
lib/images/windows/templates/apps/thorium.nix
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
# Install Thorium browser and set as default via Active Setup (all users)
|
||||
# PS-SFTA is stored in Program Files and runs at each user's first logon.
|
||||
# post-oobe.cmd also runs SFTA for the initial user.
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://github.com/Alex313031/Thorium-Win/releases/download/M138.0.7204.303/thorium_AVX2_mini_installer.exe";
|
||||
hash = "sha256-43daDPX4N7NbVx1UfmO6KDMKKufhmpeQMO7qTeRggqo=";
|
||||
};
|
||||
sfta = pkgs.fetchurl {
|
||||
url = "https://raw.githubusercontent.com/DanysysTeam/PS-SFTA/master/SFTA.ps1";
|
||||
hash = "sha256-Prb23uP9jJFgQEIGC51ljwjshdP9ChR2kRnf14vDCFE=";
|
||||
};
|
||||
in {
|
||||
name = "thorium";
|
||||
cdroms = [ (makeFilesISO { name = "thorium"; files = [ installer sfta ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing Thorium browser...
|
||||
copy D:\thorium_AVX2_mini_installer.exe C:\thorium_installer.exe
|
||||
start /wait C:\thorium_installer.exe --silent --system-level --do-not-launch-chrome
|
||||
del /q C:\thorium_installer.exe
|
||||
echo Waiting for setup.exe to finish...
|
||||
:wait_loop
|
||||
tasklist /fi "imagename eq setup.exe" 2>nul | find /i "setup.exe" >nul
|
||||
if not errorlevel 1 (
|
||||
timeout /t 5 /nobreak >nul
|
||||
goto wait_loop
|
||||
)
|
||||
|
||||
echo Setting up Thorium as default browser for all users...
|
||||
:: Store SFTA in Program Files (survives sysprep as installed program)
|
||||
mkdir "C:\Program Files\vmix" 2>nul
|
||||
copy D:\SFTA.ps1 "C:\Program Files\vmix\SFTA.ps1" >nul
|
||||
:: Register Active Setup: runs at first logon for every new user
|
||||
reg add "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\vmix-default-browser" /v "(Default)" /t REG_SZ /d "Set default browser" /f >nul
|
||||
reg add "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\vmix-default-browser" /v "StubPath" /t REG_SZ /d "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command \". 'C:\\Program Files\\vmix\\SFTA.ps1'; Set-FTA 'ThoriumHTM' '.htm'; Set-FTA 'ThoriumHTM' '.html'; Set-PTA 'ThoriumHTM' 'http'; Set-PTA 'ThoriumHTM' 'https'\"" /f >nul
|
||||
reg add "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\vmix-default-browser" /v "Version" /t REG_SZ /d "1,0,0,0" /f >nul
|
||||
'';
|
||||
}
|
||||
19
lib/images/windows/templates/apps/vlc.nix
Normal file
19
lib/images/windows/templates/apps/vlc.nix
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
# Install VLC and register shell handlers for video/audio formats
|
||||
{ pkgs, makeFilesISO, ... }:
|
||||
let
|
||||
installer = pkgs.fetchurl {
|
||||
url = "https://get.videolan.org/vlc/3.0.21/win64/vlc-3.0.21-win64.exe";
|
||||
hash = "sha256-l0JomlDpbdwE2Azv8EayjaK+79YXvhgWb4xecV7GDFk=";
|
||||
};
|
||||
in {
|
||||
name = "vlc";
|
||||
cdroms = [ (makeFilesISO { name = "vlc"; files = [ installer ]; }) ];
|
||||
auditScript = ''
|
||||
@echo off
|
||||
echo Installing VLC...
|
||||
start /wait D:\vlc-3.0.21-win64.exe /S /L=1033
|
||||
|
||||
:: delete shortcut on desktop
|
||||
del /q "C:\Users\Public\Desktop\VLC media player.lnk"
|
||||
'';
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue