sync with labv2.nix + standalone flake with toDisk app
Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
dd1fb16e1b
commit
94f299bb81
77 changed files with 2785 additions and 796 deletions
10
lib/images/windows/templates/registry/ai.nix
Normal file
10
lib/images/windows/templates/registry/ai.nix
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# Disable Copilot, Recall, and AI data analysis
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsCopilot]
|
||||
"TurnOffWindowsCopilot"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsAI]
|
||||
"AllowRecallEnablement"=dword:00000000
|
||||
"DisableAIDataAnalysis"=dword:00000001
|
||||
''
|
||||
50
lib/images/windows/templates/registry/consumer.nix
Normal file
50
lib/images/windows/templates/registry/consumer.nix
Normal file
|
|
@ -0,0 +1,50 @@
|
|||
# Disable consumer features, suggested apps, push-to-install, widgets, Cortana
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CloudContent]
|
||||
"DisableWindowsConsumerFeatures"=dword:00000001
|
||||
"DisableTailoredExperiencesWithDiagnosticData"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PushToInstall]
|
||||
"DisablePushToInstall"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds]
|
||||
"EnableFeeds"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Dsh]
|
||||
"AllowNewsAndInterests"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search]
|
||||
"AllowCortana"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Explorer]
|
||||
"DisableSearchBoxSuggestions"=dword:00000001
|
||||
"HideSCAMeetNow"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GameDVR]
|
||||
"AllowGameDVR"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\System\GameConfigStore]
|
||||
"GameDVR_Enabled"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Maps]
|
||||
"AutoDownloadAndUpdateMapData"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MapsBroker]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XblAuthManager]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XblGameSave]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\XboxNetApiSvc]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WMPNetworkSvc]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RetailDemo]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
63
lib/images/windows/templates/registry/default.nix
Normal file
63
lib/images/windows/templates/registry/default.nix
Normal file
|
|
@ -0,0 +1,63 @@
|
|||
# Offline registry customization templates.
|
||||
# Each file returns raw registry entries (no header).
|
||||
# Templates are composed into bundles via mkReg which adds the .reg header.
|
||||
{ ... }:
|
||||
let
|
||||
regHeader = "Windows Registry Editor Version 5.00";
|
||||
mkReg = entries: ''
|
||||
${regHeader}
|
||||
${entries}
|
||||
'';
|
||||
|
||||
rdpEntries = import ./rdp.nix;
|
||||
telemetryEntries = import ./telemetry.nix;
|
||||
errorReportingEntries = import ./error-reporting.nix;
|
||||
defenderEntries = import ./defender.nix;
|
||||
updatesEntries = import ./updates.nix;
|
||||
smartScreenEntries = import ./smart-screen.nix;
|
||||
hibernationEntries = import ./hibernation.nix;
|
||||
systemRestoreEntries = import ./system-restore.nix;
|
||||
networkEntries = import ./insecure-samba.nix;
|
||||
privacyEntries = import ./privacy.nix;
|
||||
aiEntries = import ./ai.nix;
|
||||
consumerEntries = import ./consumer.nix;
|
||||
performanceEntries = import ./performance.nix;
|
||||
disableUcpdEntries = import ./disable-ucpd.nix;
|
||||
|
||||
in rec {
|
||||
# === Individual templates ===
|
||||
disableTelemetry = { name = "no-telemetry"; windowsRegistry = mkReg telemetryEntries; };
|
||||
disableErrorReporting = { name = "no-wer"; windowsRegistry = mkReg errorReportingEntries; };
|
||||
disableDefender = { name = "no-defender"; windowsRegistry = mkReg defenderEntries; };
|
||||
disableUpdates = { name = "no-updates"; windowsRegistry = mkReg updatesEntries; };
|
||||
disableSmartScreen = { name = "no-smartscreen"; windowsRegistry = mkReg smartScreenEntries; };
|
||||
disableHibernation = { name = "no-hibernate"; windowsRegistry = mkReg hibernationEntries; };
|
||||
disableSystemRestore = { name = "no-restore"; windowsRegistry = mkReg systemRestoreEntries; };
|
||||
networkTweaks = { name = "network"; windowsRegistry = mkReg networkEntries; };
|
||||
disablePrivacyTracking = { name = "no-tracking"; windowsRegistry = mkReg privacyEntries; };
|
||||
disableAI = { name = "no-ai"; windowsRegistry = mkReg aiEntries; };
|
||||
disableConsumerFeatures = { name = "no-consumer"; windowsRegistry = mkReg consumerEntries; };
|
||||
performanceTweaks = { name = "performance"; windowsRegistry = mkReg performanceEntries; };
|
||||
disableUCPD = { name = "no-ucpd"; windowsRegistry = mkReg disableUcpdEntries; };
|
||||
|
||||
# === Convenience bundles ==
|
||||
|
||||
# Hardened: comprehensive debloat for lab VMs
|
||||
hardened = {
|
||||
name = "hardened";
|
||||
windowsRegistry = mkReg (
|
||||
telemetryEntries
|
||||
+ errorReportingEntries
|
||||
+ defenderEntries
|
||||
+ updatesEntries
|
||||
+ smartScreenEntries
|
||||
+ hibernationEntries
|
||||
+ systemRestoreEntries
|
||||
+ networkEntries
|
||||
+ privacyEntries
|
||||
+ aiEntries
|
||||
+ consumerEntries
|
||||
+ performanceEntries
|
||||
);
|
||||
};
|
||||
}
|
||||
11
lib/images/windows/templates/registry/defender.nix
Normal file
11
lib/images/windows/templates/registry/defender.nix
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
# Disable Windows Defender
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
|
||||
"DisableAntiSpyware"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
|
||||
"DisableRealtimeMonitoring"=dword:00000001
|
||||
''
|
||||
10
lib/images/windows/templates/registry/disable-ucpd.nix
Normal file
10
lib/images/windows/templates/registry/disable-ucpd.nix
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# Disable User Choice Protection Driver (UCPD) on Win11
|
||||
# This allows programmatic changes to file/URL associations via UserChoice
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
|
||||
"EnableUCPD"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UCPD]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
# Disable Windows Error Reporting
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting]
|
||||
"Disabled"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WerSvc]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
9
lib/images/windows/templates/registry/hibernation.nix
Normal file
9
lib/images/windows/templates/registry/hibernation.nix
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
# Disable hibernation and fast startup (avoids disk corruption with snapshots)
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Power]
|
||||
"HiberbootEnabled"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power]
|
||||
"HibernateEnabled"=dword:00000000
|
||||
''
|
||||
12
lib/images/windows/templates/registry/insecure-samba.nix
Normal file
12
lib/images/windows/templates/registry/insecure-samba.nix
Normal file
|
|
@ -0,0 +1,12 @@
|
|||
# Suppress network discovery popup and allow insecure guest logons for SMB
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\NewNetworkWindowOff]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation]
|
||||
"AllowInsecureGuestAuth"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation\Parameters]
|
||||
"AllowInsecureGuestAuth"=dword:00000001
|
||||
"RequireSecuritySignature"=dword:00000000
|
||||
''
|
||||
34
lib/images/windows/templates/registry/performance.nix
Normal file
34
lib/images/windows/templates/registry/performance.nix
Normal file
|
|
@ -0,0 +1,34 @@
|
|||
# VM performance optimizations: disable power throttling, SysMain, lock screen, autorun
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerThrottling]
|
||||
"PowerThrottlingOff"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control]
|
||||
"SvcHostSplitThresholdInKB"=dword:00400000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem]
|
||||
"LongPathsEnabled"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Remote Assistance]
|
||||
"fAllowToGetHelp"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Personalization]
|
||||
"NoLockScreen"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer]
|
||||
"NoDriveTypeAutoRun"=dword:000000ff
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\FileHistory]
|
||||
"Disabled"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysMain]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
44
lib/images/windows/templates/registry/privacy.nix
Normal file
44
lib/images/windows/templates/registry/privacy.nix
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
# Disable activity tracking, advertising ID, location, and input data collection
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
|
||||
"EnableActivityFeed"=dword:00000000
|
||||
"PublishUserActivities"=dword:00000000
|
||||
"UploadUserActivities"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo]
|
||||
"DisabledByGroupPolicy"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Privacy]
|
||||
"TailoredExperiencesWithDiagnosticDataEnabled"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors]
|
||||
"DisableLocation"=dword:00000001
|
||||
"DisableLocationScripting"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lfsvc]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports]
|
||||
"PreventHandwritingErrorReports"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TabletPC]
|
||||
"PreventHandwritingDataSharing"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InputPersonalization]
|
||||
"RestrictImplicitTextCollection"=dword:00000001
|
||||
"RestrictImplicitInkCollection"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace]
|
||||
"AllowWindowsInkWorkspace"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore\Settings]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy]
|
||||
"HasAccepted"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppPrivacy]
|
||||
"LetAppsRunInBackground"=dword:00000002
|
||||
''
|
||||
6
lib/images/windows/templates/registry/smart-screen.nix
Normal file
6
lib/images/windows/templates/registry/smart-screen.nix
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# Disable SmartScreen
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
|
||||
"EnableSmartScreen"=dword:00000000
|
||||
''
|
||||
8
lib/images/windows/templates/registry/system-restore.nix
Normal file
8
lib/images/windows/templates/registry/system-restore.nix
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
# Disable system restore
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
|
||||
"DisableSR"=dword:00000001
|
||||
''
|
||||
15
lib/images/windows/templates/registry/telemetry.nix
Normal file
15
lib/images/windows/templates/registry/telemetry.nix
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
# Disable telemetry, diagnostics tracking, and feedback
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection]
|
||||
"AllowTelemetry"=dword:00000000
|
||||
"DoNotShowFeedbackNotifications"=dword:00000001
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DiagTrack]
|
||||
"Start"=dword:00000004
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dmwappushservice]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
21
lib/images/windows/templates/registry/updates.nix
Normal file
21
lib/images/windows/templates/registry/updates.nix
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
# Disable automatic Windows updates, driver searching, and update-related annoyances
|
||||
''
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
|
||||
"NoAutoUpdate"=dword:00000001
|
||||
"NoAutoRebootWithLoggedOnUsers"=dword:00000001
|
||||
"AUPowerManagement"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization]
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config]
|
||||
"DODownloadMode"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching]
|
||||
"SearchOrderConfig"=dword:00000000
|
||||
|
||||
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DoSvc]
|
||||
"Start"=dword:00000004
|
||||
''
|
||||
Loading…
Add table
Add a link
Reference in a new issue