diff --git a/flake.nix b/flake.nix index 4ec2e5a..9cbbbde 100644 --- a/flake.nix +++ b/flake.nix @@ -15,12 +15,9 @@ lib = pkgs.lib; vmixLib = import ./lib { inherit pkgs lib system; }; in { - overlays.default = final: prev: { inherit vmixLib; }; + overlays.default = import ./overlay.nix; - nixosModules.default = { config, pkgs, lib, ... }: { - imports = [ ./nixos/default.nix ]; - config.nixpkgs.overlays = [ self.overlays.default ]; - }; + nixosModules.default = import ./module.nix; lib.${system} = vmixLib; diff --git a/lib/images/linux/debian/templates.nix b/lib/images/linux/debian/templates.nix index af90a77..1fffeb3 100644 --- a/lib/images/linux/debian/templates.nix +++ b/lib/images/linux/debian/templates.nix @@ -50,18 +50,11 @@ with scriptsNFiles; # proxmox makes it very hard to manually add interfaces directly on /etc/network/interfaces while the pve services are not running # it also doesn't pick up files in interfaces.d # so manually do that via service after boot - # After= must live in [Unit] — in [Service] systemd ignores it, leaving the - # merge/ifreload racing networking.service (and ifreload fails outright if it - # runs before /run/network exists, see ifupdown2#276). mergeNetIfacesDService = pkgs.writeText "manual-net-ifaces.d.service" '' - [Unit] - After = networking.service - Wants = networking.service - [Service] Type = oneshot - ExecStartPre = /bin/mkdir -p /run/network ExecStart = /bin/bash -c "cat /etc/network/interfaces.d/* >> /etc/network/interfaces; rm /etc/network/interfaces.d/*; ifreload -a;" + After = network.target [Install] WantedBy = multi-user.target diff --git a/lib/images/windows/default.nix b/lib/images/windows/default.nix index d66c043..b01dcdd 100644 --- a/lib/images/windows/default.nix +++ b/lib/images/windows/default.nix @@ -3,7 +3,6 @@ let windows = rec { drivers = import ./drivers { inherit pkgs system; }; makeFilesISO = (import ./helpers/makeFilesISO.nix) { inherit pkgs; }; - makeConfigMedium = (import ./helpers/makeConfigMedium.nix) { inherit pkgs lib makeFilesISO; }; customizeImage = (import ./helpers/customizeImage.nix) { inherit pkgs lib; }; customizeImageFold = builtins.foldl' customizeImage; templates = (import ./templates) { inherit pkgs lib system drivers makeFilesISO; }; @@ -15,20 +14,14 @@ let win10 = (import ./win10) { inherit pkgs lib system windows; }; win11 = (import ./win11) { inherit pkgs lib system windows; }; - # Recursively add .generalize and .seal to every derivation leaf in the tree + # Recursively add .generalize to every derivation leaf in the image tree addGeneralize = val: if val ? _vmixOsType then - val // { - generalize = args: - let - templateArgs = builtins.removeAttrs args [ "vncDisplay" ]; - displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; }; - in windows.customizeImage val (windows.templates.generalize templateArgs // displayArgs); - seal = args: - let - templateArgs = builtins.removeAttrs args [ "vncDisplay" ]; - displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; }; - in windows.customizeImage val (windows.templates.seal templateArgs // displayArgs); + val // { generalize = args: + let + templateArgs = builtins.removeAttrs args [ "vncDisplay" ]; + displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; }; + in windows.customizeImage val (windows.templates.generalize templateArgs // displayArgs); } else if builtins.isAttrs val then lib.mapAttrs (_: addGeneralize) val diff --git a/lib/images/windows/helpers/customizeImage.nix b/lib/images/windows/helpers/customizeImage.nix index 51b4d30..19758b9 100644 --- a/lib/images/windows/helpers/customizeImage.nix +++ b/lib/images/windows/helpers/customizeImage.nix @@ -29,12 +29,6 @@ compact ? false, # QEMU timeout in seconds (default 30 min, increase for Windows Update) qemuTimeout ? 1800, - # Blank disk attached for the Audit Mode boot, e.g. { size = "100G"; }. - # Windows sees it as disk 1, which is what lets a template partition it and - # relocate profiles onto it in that same boot instead of deferring OOBE to - # real hardware. Emitted as the derivation's `data` output, so whatever the - # template writes to it survives the build. - extraDisk ? null, }: let originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name); @@ -73,11 +67,6 @@ ]); cdromArgs = lib.concatMapStringsSep " \\\n " (cd: "-drive file=${cd},media=cdrom,readonly=on") cdroms; - extraDiskImg = "./extra.qcow2"; - extraDiskArgs = lib.optionalString (extraDisk != null) - (if isAHCI - then "-drive file=${extraDiskImg},format=qcow2,if=none,id=disk1 -device ide-hd,drive=disk1" - else "-drive file=${extraDiskImg},format=qcow2,if=virtio"); displayArg = if vncDisplay != null then "-vnc ${vncDisplay}" else null; @@ -99,11 +88,7 @@ VMIX_DISPLAY="-nographic" ${lib.optionalString (vncDisplay != null) ''VMIX_DISPLAY="-vnc ${vncDisplay}"''} ${lib.optionalString (vncDisplay == null) '' - # find, not a glob: under nullglob a non-matching /tmp/.vmix-display-* - # disappears entirely, leaving `ls -t` to list the build directory and - # hand back nix's own env-vars dump. Exporting that as DISPLAY bloats - # the environment until every exec dies with E2BIG. - VMIX_DF=$(find /tmp -maxdepth 1 -type f -name '.vmix-display-*' -printf '%T@ %p\n' 2>/dev/null | sort -rn | head -1 | cut -d' ' -f2-) + VMIX_DF=$(ls -t /tmp/.vmix-display-* 2>/dev/null | head -1) if [ -n "$VMIX_DF" ]; then export DISPLAY=$(sed -n '1p' "$VMIX_DF") export XAUTHORITY=$(sed -n '2p' "$VMIX_DF") @@ -124,7 +109,6 @@ then "-drive file=${resultImg},format=qcow2,if=none,id=disk0 -device ide-hd,drive=disk0" else "-drive file=${resultImg},format=qcow2,if=virtio"} \ ${cdromArgs} \ - ${extraDiskArgs} \ -nic user,model=${if nicModel != null then nicModel else if isAHCI then "e1000" else "virtio-net-pci"}" timeout ${toString qemuTimeout} qemu-system-x86_64 $VMIX_DISPLAY $QEMU_ARGS || \ @@ -143,10 +127,6 @@ # create resulting image backed by original image qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg} [ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize} - ${lib.optionalString (extraDisk != null) '' - echo "=== vmix: creating extra disk (${extraDisk.size}) ===" - qemu-img create -f qcow2 ${extraDiskImg} ${extraDisk.size} - ''} ${virtWinRegMerge} ${auditBootCommands} ${lib.optionalString compact '' @@ -155,14 +135,10 @@ mv compact.qcow2 ${resultImg} ''} mv ${resultImg} $out - ${lib.optionalString (extraDisk != null) "mv ${extraDiskImg} $data"} ''; builtImage = pkgs.runCommand customImageName ({ nativeBuildInputs = with pkgs; [ qemu perl guestfs-tools ]; requiredSystemFeatures = [ "kvm" ]; - } // lib.optionalAttrs impure { __noChroot = true; } - # A second output rather than a directory, so ${image} keeps meaning the OS - # qcow2 for every existing consumer and the fold can still back onto it. - // lib.optionalAttrs (extraDisk != null) { outputs = [ "out" "data" ]; }) builderCommand; + } // lib.optionalAttrs impure { __noChroot = true; }) builderCommand; in builtImage // { _vmixOsType = "windows"; useAHCI = isAHCI; } diff --git a/lib/images/windows/helpers/makeConfigMedium.nix b/lib/images/windows/helpers/makeConfigMedium.nix deleted file mode 100644 index 8a90be1..0000000 --- a/lib/images/windows/helpers/makeConfigMedium.nix +++ /dev/null @@ -1,59 +0,0 @@ -# Per-VM config medium for a sealed Windows image (see templates.seal). -# -# A sealed image carries no per-VM data. The values that differ between VMs -- -# hostname, the static address the guest asserts, timezone, desktop tint -- are -# written here as a PowerShell data file and packed into a tiny ISO. config.nix -# attaches it as a read-only CD-ROM; the image's baked first-boot scripts -# (vmix-load-config.cmd finds it, then dot-source it) apply the values. So one -# sealed store path is shared by every VM, and only this cheap ISO is per-VM. -# -# Usage: -# makeConfigMedium { -# name = "win-config"; -# hostname = "panda-win"; -# staticIP = { address = "10.10.10.26"; prefixLength = 24; -# gateway = "10.10.10.1"; dns = [ "10.10.10.1" ]; }; -# timezone = "E. South America Standard Time"; -# bgColor = "#856558"; -# } -{ pkgs, lib, makeFilesISO, ... }: -{ - name ? "vmix-config", - hostname ? "", - # The per-VM account. The sealed image carries a generic bootstrap account - # (only there to carry OOBE); on first boot this real account is created from - # here, gets the SID-bound profile on D:\Users\, and the bootstrap - # is retired. Distinct per VM -- nothing about the account is shared/baked. - username ? "", - password ? "", - # { address; prefixLength; gateway; dns = [ ... ]; } - staticIP ? null, - timezone ? null, - # Solid desktop background as a hex string, e.g. "#856558". Converted to the - # registry's decimal "R G B" on the target, in vmix-apply-config.ps1. - bgColor ? null, -}: -let - dnsList = lib.optionalString (staticIP != null) - (lib.concatMapStringsSep "," (s: "'${s}'") staticIP.dns); - - # Consumed by dot-sourcing (. C:\vmix-config.ps1), so it only assigns - # variables. Anything not set here is simply absent, and the baked scripts - # guard on that ($VmixIpAddress being null skips the static-IP assignment). - configPs1 = pkgs.writeText "vmix-config.ps1" '' - # vmix per-VM config -- generated, read by the sealed image's baked scripts. - $VmixHostname = '${hostname}' - ${lib.optionalString (username != "") "$VmixUsername = '${username}'"} - ${lib.optionalString (username != "") "$VmixPassword = '${password}'"} - ${lib.optionalString (staticIP != null) '' - $VmixIpAddress = '${staticIP.address}' - $VmixPrefixLength = ${toString staticIP.prefixLength} - $VmixGateway = '${staticIP.gateway}' - $VmixDns = @(${dnsList})''} - ${lib.optionalString (timezone != null) "$VmixTimeZone = '${timezone}'"} - ${lib.optionalString (bgColor != null) "$VmixBgColor = '${bgColor}'"} - ''; -in -# makeFilesISO strips the store-hash prefix, so this lands at the ISO root as -# exactly vmix-config.ps1 -- which is what vmix-load-config.cmd scans for. -makeFilesISO { inherit name; files = [ configPs1 ]; } diff --git a/lib/images/windows/helpers/makeImage.nix b/lib/images/windows/helpers/makeImage.nix index 0f16750..983c6fb 100644 --- a/lib/images/windows/helpers/makeImage.nix +++ b/lib/images/windows/helpers/makeImage.nix @@ -49,11 +49,7 @@ let VMIX_DISPLAY="-nographic" ${lib.optionalString (displayArg != null) ''VMIX_DISPLAY="${displayArg}"''} ${lib.optionalString (displayArg == null) '' - # find, not a glob: under nullglob a non-matching /tmp/.vmix-display-* - # disappears entirely, leaving `ls -t` to list the build directory and - # hand back nix's own env-vars dump. Exporting that as DISPLAY bloats the - # environment until every exec dies with E2BIG. - VMIX_DF=$(find /tmp -maxdepth 1 -type f -name '.vmix-display-*' -printf '%T@ %p\n' 2>/dev/null | sort -rn | head -1 | cut -d' ' -f2-) + VMIX_DF=$(ls -t /tmp/.vmix-display-* 2>/dev/null | head -1) if [ -n "$VMIX_DF" ]; then export DISPLAY=$(sed -n '1p' "$VMIX_DF") export XAUTHORITY=$(sed -n '2p' "$VMIX_DF") diff --git a/lib/images/windows/templates/default.nix b/lib/images/windows/templates/default.nix index 8bf1a10..78a282e 100644 --- a/lib/images/windows/templates/default.nix +++ b/lib/images/windows/templates/default.nix @@ -20,6 +20,7 @@ in rec { bestPerformance = import ./essentials/best-performance.nix args; clearFileAssociations = import ./essentials/clear-file-associations.nix args; virtioDrivers = import ./essentials/virtio-drivers.nix args; + windowsUpdate = import ./essentials/windows-update.nix args; }; # Applications @@ -39,24 +40,6 @@ in rec { # Generalize (sysprep + OOBE). Pass seal=true for hardware deployment. generalize = import ./generalize.nix args; - # Seal: a generic OOBE-deferred base whose per-VM data is not baked but - # delivered at deploy time on a config medium (helpers/makeConfigMedium.nix). - # One sealed store path is shared by every VM; each VM's first boot mints its - # own SID and builds the whole profile on the relocated data volume (D:). - # - # The baked account is a generic bootstrap that only exists to carry OOBE to a - # logon -- the real, per-VM account (username/password) comes from the config - # medium, and the bootstrap is retired on the target. So nothing per-VM is - # baked. RDP and locale stay caller args. - seal = templateArgs: generalize ({ - delayOobeRun = true; - configMedium = true; - username = "vmixsetup"; - password = "vmixsetup"; - profilesDirectory = "D:\\Users"; - dataDisk = { driveLetter = "D"; label = "data"; }; - } // templateArgs); - # Offline registry templates reg = import ./registry args; diff --git a/lib/images/windows/templates/essentials/windows-update.nix b/lib/images/windows/templates/essentials/windows-update.nix new file mode 100644 index 0000000..5b3e188 --- /dev/null +++ b/lib/images/windows/templates/essentials/windows-update.nix @@ -0,0 +1,114 @@ +# Apply all available Windows Updates via the Windows Update COM API in Audit Mode. +# Handles reboots automatically — re-registers via RunOnce and continues updating. +# Compacts the image afterward to flatten the COW chain. +# +# Usage: +# essentials.windowsUpdate {} +# essentials.windowsUpdate { maxRounds = 5; } +{ pkgs, lib, ... }: +{ maxRounds ? 3 }: +{ + name = "windows-update"; + compact = true; + memSize = 4096; + qemuTimeout = 7200; + auditScript = '' + @echo off + setlocal + + :: Track update round via a counter file + set "ROUND_FILE=C:\vmix-update-round.txt" + set "MAX_ROUNDS=${toString maxRounds}" + + if exist "%ROUND_FILE%" ( + set /p ROUND=<"%ROUND_FILE%" + ) else ( + set "ROUND=1" + ) + + echo === vmix: Windows Update round %ROUND% of %MAX_ROUNDS% === + + :: Ensure Windows Update service is running + net start wuauserv 2>nul + sc config wuauserv start= auto + + :: Remove any update-blocking policies (LTSC may have these) + reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul + reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul + + :: Give the service time to initialize on first round + if "%ROUND%"=="1" ( + echo Waiting for Windows Update service to initialize... + timeout /t 30 /nobreak >nul + ) + + :: Run Windows Update via PowerShell COM API + powershell -ExecutionPolicy Bypass -Command ^ + "try {" ^ + " $session = New-Object -ComObject Microsoft.Update.Session;" ^ + " $searcher = $session.CreateUpdateSearcher();" ^ + " Write-Host 'Searching for updates...';" ^ + " $result = $searcher.Search('IsInstalled=0');" ^ + " $count = $result.Updates.Count;" ^ + " Write-Host \"Found $count updates\";" ^ + " if ($count -eq 0) { exit 0 };" ^ + " foreach ($u in $result.Updates) { Write-Host \" - $($u.Title)\" };" ^ + " $updatesToInstall = New-Object -ComObject Microsoft.Update.UpdateColl;" ^ + " foreach ($u in $result.Updates) {" ^ + " if ($u.EulaAccepted -eq $false) { $u.AcceptEula() };" ^ + " $updatesToInstall.Add($u) | Out-Null" ^ + " };" ^ + " $downloader = $session.CreateUpdateDownloader();" ^ + " $downloader.Updates = $updatesToInstall;" ^ + " Write-Host 'Downloading...';" ^ + " $downloader.Download() | Out-Null;" ^ + " $installer = $session.CreateUpdateInstaller();" ^ + " $installer.Updates = $updatesToInstall;" ^ + " Write-Host 'Installing...';" ^ + " $installResult = $installer.Install();" ^ + " Write-Host \"Result: $($installResult.ResultCode)\";" ^ + " for ($i = 0; $i -lt $updatesToInstall.Count; $i++) {" ^ + " $hr = $installResult.GetUpdateResult($i).HResult;" ^ + " Write-Host \" $($updatesToInstall.Item($i).Title): code=$hr\"" ^ + " };" ^ + " if ($installResult.RebootRequired) { exit 3010 } else { exit 0 }" ^ + "} catch {" ^ + " Write-Host \"ERROR: $_\";" ^ + " exit 1" ^ + "}" + + set "WU_EXIT=%ERRORLEVEL%" + echo Windows Update exit code: %WU_EXIT% + + :: Cleanup component store + echo Cleaning up component store... + dism /Online /Cleanup-Image /StartComponentCleanup /ResetBase /Quiet 2>nul + + :: Check if we need to reboot and continue + set /a "NEXT_ROUND=%ROUND%+1" + + if "%WU_EXIT%"=="3010" ( + if %ROUND% LSS %MAX_ROUNDS% ( + echo Reboot required, scheduling round %NEXT_ROUND%... + echo %NEXT_ROUND% > "%ROUND_FILE%" + :: Copy script to a path the wrapper won't delete + copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul + reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v vmixUpdate /t REG_SZ /d "cmd /c C:\vmix-update-continue.cmd" /f + :: Preserve Audit Mode across reboot (updates can reset it) + reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f + reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f + :: Immediate reboot (preempts wrapper shutdown) + shutdown /r /f /t 0 + exit /b + ) else ( + echo Max update rounds reached. + ) + ) + + :: Done — clean up and shutdown + del /q "%ROUND_FILE%" 2>nul + del /q "C:\vmix-update-continue.cmd" 2>nul + echo === vmix: Windows Update complete === + shutdown /s /f /t 10 /c "vmix: windows-update complete" + ''; +} diff --git a/lib/images/windows/templates/generalize.nix b/lib/images/windows/templates/generalize.nix index b883d89..cf1f2e2 100644 --- a/lib/images/windows/templates/generalize.nix +++ b/lib/images/windows/templates/generalize.nix @@ -23,49 +23,9 @@ in enableRDP ? false, # NIC model for the build VM (e.g. "e1000" for images without VirtIO drivers) nicModel ? null, - # Static IPv4 for the guest's single NIC, applied from inside Windows: - # { address = "10.10.10.26"; prefixLength = 24; gateway = "10.10.10.1"; - # dns = [ "10.10.10.1" ]; } - staticIP ? null, - # Relocate user profiles, e.g. "D:\\Users". Needs the volume to exist by the - # time specialize runs, which is what dataDisk arranges. - profilesDirectory ? null, - # Partition the non-OS disk and relocate user profiles onto it, e.g. - # { driveLetter = "D"; label = "data"; size = "100G"; }. The disk is attached - # during the build (see extraDisk in the returned set), so this is done and - # verified before the image ever reaches a host. - dataDisk ? null, - # Unified Write Filter: protect a volume by redirecting its writes to a - # disk-backed overlay held on another one, e.g. - # { protectedVolume = "C:"; swapfileVolume = "D:"; overlaySizeMB = 8192; } - writeFilter ? null, # delayOobeRun = true: sysprep only, OOBE + activation on real hardware # delayOobeRun = false: sysprep + OOBE + activation in build VM delayOobeRun ? false, - # configMedium = true: this is a generic sealed base whose per-VM data - # (hostname, static IP, timezone, desktop tint) is NOT baked. The target's - # first boot reads it off a small removable config CD (see makeConfigMedium) - # via baked finder/apply scripts. Implies the OOBE is deferred to the target, - # so it is only meaningful together with delayOobeRun = true. Lets one sealed - # store path be shared by every VM built from it. - configMedium ? false, - # Skip sysprep's SID reset (use /oobe without /generalize), so every rebuild - # of the layers above the cached base install carries the same machine SID -- - # and therefore the same account SID. A profile kept on a persistent disk then - # matches on file ACLs, its NTUSER.DAT hive, and ProfileList across rebuilds, - # with no ownership fixups. As a side effect MountedDevices survives too, so - # the data disk keeps its drive letter without a boot-time reassign. - # - # Correct only for an image that is always this one machine; a fleet that - # deploys the same image to many hosts wants the default generalization. - keepMachineSid ? false, - # Known-Folder redirection: keep the SID-bound profile on C: (so /generalize - # can still randomize the SID per machine) but point the user's data folders - # at the persistent data disk, so files -- not per-user registry settings -- - # survive an OS rebuild. e.g. { base = "D:\\UserData"; folders = [ "Desktop" - # "Documents" "Downloads" ]; }. Needs dataDisk to provide the volume, and is - # mutually exclusive with profilesDirectory. - folderRedirect ? null, }: let # Convert "8e8cd8" hex to "142 140 216" decimal RGB for Windows registry hexToRgbStr = hex: let @@ -82,429 +42,9 @@ in stripHash = s: lib.removePrefix "#" s; bgRgb = if bgColor != null then hexToRgbStr (stripHash bgColor) else null; - uwfProtected = if writeFilter != null then (writeFilter.protectedVolume or "C:") else "C:"; - uwfSwapVolume = if writeFilter != null then (writeFilter.swapfileVolume or "D:") else "D:"; - uwfOverlaySizeMB = if writeFilter != null then (writeFilter.overlaySizeMB or 8192) else 8192; - - # Runs from RunOnce on the target's first boot rather than during the build, - # for two reasons: enabling the DISM feature needs a reboot before uwfmgr - # exists at all, and the overlay swapfile has to be created on the real data - # volume rather than on the build's throwaway copy of it. - # - # Order is forced by uwfmgr: create-swapfile is only accepted while the - # filter is off and the overlay is already in disk mode. The default disk - # overlay would otherwise sit at C:\uwfswap.sys, on the volume being - # protected. Enabling the filter itself only takes effect after a restart. - uwfConfigScript = pkgs.writeText "vmix-uwf-config.cmd" '' - @echo off - uwfmgr.exe overlay set-type disk - uwfmgr.exe overlay set-size ${toString uwfOverlaySizeMB} - uwfmgr.exe volume create-swapfile ${uwfSwapVolume} - uwfmgr.exe volume protect ${uwfProtected} - uwfmgr.exe filter enable - del /q C:\vmix-uwf-config.cmd 2>nul - shutdown /r /t 10 /c "vmix: activating the write filter" - ''; - - staticDnsList = lib.optionalString (staticIP != null) - (lib.concatMapStringsSep "," (s: "'${s}'") staticIP.dns); - - # Its own file rather than inline in post-oobe.cmd: the command is long, and - # cmd's handling of quotes and pipes inside it is a needless hazard. - # - # Two things this has to get right. The adapter may not be up yet when - # FirstLogonCommands runs, so it is waited for rather than assumed. And the - # interface arrives DHCP-managed -- assigning an address without turning DHCP - # off first does not stick, which is how a VM meant to be at a fixed address - # ended up holding a lease instead. - # PowerShell in its own file: it grew a wait loop and a retry, which are no - # fun to keep correct inside a cmd one-liner. - # - # Two things it must survive. DHCP is turned off before the address is set, - # so any failure to set it strands the box with no address at all -- which is - # exactly what happened after an internal reboot, where a stale ARP entry for - # the address from the previous instance tripped duplicate-address detection - # and New-NetIPAddress threw. DadTransmits 0 turns that detection off so the - # static always binds, and the assignment is retried rather than fatal. - # Two shapes. Baked: the address is a build-time literal. configMedium: the - # address is read from C:\vmix-config.ps1 (dot-sourced), which the finder - # dropped there off the config CD -- so the same sealed script serves every - # VM. The wait/retry logic is identical either way. - staticIPAssign = if configMedium - then { addr = "$VmixIpAddress"; prefix = "$VmixPrefixLength"; gw = "$VmixGateway"; dns = "$VmixDns"; } - else { addr = "'${staticIP.address}'"; prefix = toString staticIP.prefixLength; gw = "'${staticIP.gateway}'"; dns = staticDnsList; }; - staticIPScriptPs1 = pkgs.writeText "vmix-static-ip.ps1" '' - ${lib.optionalString configMedium '' - if (-not (Test-Path C:\vmix-config.ps1)) { Write-Output 'vmix: no config yet'; exit 0 } - . C:\vmix-config.ps1 - if (-not $VmixIpAddress) { Write-Output 'vmix: no static address in config'; exit 0 } - ''} - $a = $null - for ($n = 0; $n -lt 30; $n++) { - $a = Get-NetAdapter -Physical | Where-Object Status -eq 'Up' | Sort-Object ifIndex | Select-Object -First 1 - if ($a) { break } - Start-Sleep -Seconds 2 - } - if (-not $a) { Write-Output 'vmix: no adapter came up'; exit 1 } - $i = $a.ifIndex - Set-NetIPInterface -InterfaceIndex $i -Dhcp Disabled -DadTransmits 0 -ErrorAction SilentlyContinue - Remove-NetIPAddress -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue - Remove-NetRoute -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue - $ok = $false - for ($k = 0; $k -lt 5 -and -not $ok; $k++) { - try { - New-NetIPAddress -InterfaceIndex $i -IPAddress ${staticIPAssign.addr} -PrefixLength ${staticIPAssign.prefix} -DefaultGateway ${staticIPAssign.gw} -ErrorAction Stop | Out-Null - $ok = $true - } catch { - Write-Output ('vmix: assign attempt ' + $k + ' failed: ' + $_.Exception.Message) - Start-Sleep -Seconds 2 - Remove-NetIPAddress -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue - } - } - if (-not $ok) { Write-Output 'vmix: could not set static address'; exit 1 } - Set-DnsClientServerAddress -InterfaceIndex $i -ServerAddresses ${staticIPAssign.dns} - New-NetFirewallRule -DisplayName 'ICMPv4 Echo' -Protocol ICMPv4 -IcmpType 8 -Direction Inbound -Action Allow -Profile Any -Enabled True -ErrorAction SilentlyContinue | Out-Null - Write-Output ('vmix: set ' + ${staticIPAssign.addr} + ' on ifIndex ' + $i) - ''; - - # Finder: the config CD's drive letter is unknown, so scan for the marker file - # and stage it on C: where the baked scripts expect it. Runs on the target's - # first boot (post-oobe), before the per-boot static-IP task needs it. - loadConfigScript = pkgs.writeText "vmix-load-config.cmd" '' - @echo off - for %%D in (E F G H I J K L M N O P Q R S T U V W X Y Z D) do ( - if exist %%D:\vmix-config.ps1 ( - copy /y %%D:\vmix-config.ps1 C:\vmix-config.ps1 >nul - goto :done - ) - ) - :done - ''; - - # Applies the per-VM config that is not an answer-file field: timezone, the - # desktop tint (per user, so run under the created account in post-oobe), and - # the machine rename. Rename is pending until the post-oobe reboot. - applyConfigScript = pkgs.writeText "vmix-apply-config.ps1" '' - if (-not (Test-Path C:\vmix-config.ps1)) { exit 0 } - . C:\vmix-config.ps1 - if ($VmixTimeZone) { & tzutil /s "$VmixTimeZone" } - if ($VmixBgColor) { - $hex = ([string]$VmixBgColor).TrimStart('#') - $r = [Convert]::ToInt32($hex.Substring(0,2),16) - $g = [Convert]::ToInt32($hex.Substring(2,2),16) - $b = [Convert]::ToInt32($hex.Substring(4,2),16) - Set-ItemProperty 'HKCU:\Control Panel\Colors' -Name Background -Value "$r $g $b" - Set-ItemProperty 'HKCU:\Control Panel\Desktop' -Name WallPaper -Value "" - Set-ItemProperty 'HKCU:\Control Panel\Desktop' -Name WallpaperStyle -Value '0' - } - if ($VmixHostname -and $env:COMPUTERNAME -ne $VmixHostname) { - Rename-Computer -NewName $VmixHostname -Force -ErrorAction SilentlyContinue - } - ''; - - # Creates the real per-VM account from the config and hands the machine over - # to it. The sealed image bakes only a generic bootstrap account (${username}) - # -- enough to carry OOBE to a logon so this can run -- and the real account - # is made here, on the target, from the CD. Autologon is switched to it and a - # one-shot cleanup is armed; the post-oobe reboot then lets the real account - # log in and build its own SID-bound profile on D:\Users\, after - # which the bootstrap is retired. So the account, like the SID, is per-VM and - # nothing about it is shared or baked. Runs as the bootstrap user in post-oobe. - createUserScript = pkgs.writeText "vmix-create-user.ps1" '' - if (-not (Test-Path C:\vmix-config.ps1)) { exit 0 } - . C:\vmix-config.ps1 - if (-not $VmixUsername) { exit 0 } - if ($VmixUsername -ieq '${username}') { exit 0 } - & net user $VmixUsername $VmixPassword /add - & net localgroup Administrators $VmixUsername /add - $w = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' - Set-ItemProperty $w -Name AutoAdminLogon -Value '1' - Set-ItemProperty $w -Name DefaultUserName -Value $VmixUsername - Set-ItemProperty $w -Name DefaultPassword -Value $VmixPassword - Remove-ItemProperty $w -Name DefaultDomainName -ErrorAction SilentlyContinue - # Fires at the real account's first logon (HKLM RunOnce = next user to log - # on), i.e. after the reboot below, once the bootstrap is no longer in use. - Set-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce' ` - -Name vmixFinalize -Value 'cmd /c C:\vmix-finalize.cmd' -Type String - ''; - - # Runs once as the real account (RunOnce, after the hand-over reboot), so the - # fresh machine SID and the real profile already exist. This is where activation - # belongs -- on that fresh SID, not the throwaway bootstrap's. It then finishes - # per-user setup, retires the bootstrap, unmounts the config CD for good, and - # wipes every vmix artifact off C:\ so the running machine carries no leftover - # setup files. Self-deletes last. - finalizeScript = pkgs.writeText "vmix-finalize.cmd" '' - @echo off - :: 1) Activate Windows on the real account's fresh SID (TSforge, offline). - cscript //nologo C:\Windows\System32\slmgr.vbs /ipk M7XTQ-FN8P6-TTKYV-9D4CC-J462D - cscript //nologo C:\Windows\System32\slmgr.vbs /rilc - net stop sppsvc /y 2>nul - net start sppsvc - ping -n 8 127.0.0.1 >nul - if exist C:\MAS_AIO.cmd ( echo. | call C:\MAS_AIO.cmd /Z-Windows ) - if exist "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" ( - if exist C:\MAS_AIO.cmd ( echo. | call C:\MAS_AIO.cmd /Ohook ) - ) - :: 2) Per-user desktop tint, now that the real account is logged in. - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-apply-config.ps1 >nul 2>&1 - :: 3) Retire the bootstrap account and its profile (idle now). - powershell -NoProfile -ExecutionPolicy Bypass -Command "Get-CimInstance Win32_UserProfile | Where-Object { $_.LocalPath -like '*\${username}' } | Remove-CimInstance -ErrorAction SilentlyContinue" - net user ${username} /delete >nul 2>&1 - :: 4) Unmount the config CD and keep it unmounted -- drop its letter and stop - :: the mount manager auto-lettering it (D: keeps its explicit assignment). - powershell -NoProfile -ExecutionPolicy Bypass -Command "Get-CimInstance Win32_Volume -Filter 'DriveType=5 AND DriveLetter IS NOT NULL' | ForEach-Object { $_.DriveLetter=$null; [void]($_ | Set-CimInstance) }" - > C:\Windows\Temp\vmix-am.txt echo automount disable - >> C:\Windows\Temp\vmix-am.txt echo automount scrub - diskpart /s C:\Windows\Temp\vmix-am.txt >nul 2>&1 - del /q C:\Windows\Temp\vmix-am.txt 2>nul - :: 5) Wipe every vmix setup artifact from C:\. - del /q C:\MAS_AIO.cmd C:\vmix-config.ps1 C:\vmix-data-initialized 2>nul - del /q C:\vmix-load-config.cmd C:\vmix-apply-config.ps1 C:\vmix-create-user.ps1 2>nul - del /q C:\vmix-init-data-disk.cmd C:\vmix-data-profile.cmd C:\vmix-heal-profile.ps1 2>nul - del /q C:\vmix-static-ip.cmd C:\vmix-static-ip.ps1 2>nul - del /q C:\oobe-unattend.xml C:\post-oobe.cmd 2>nul - :: 6) Self-delete. - (goto) 2>nul & del "%~f0" - ''; - - # Thin launcher, so the scheduled task has a cmd to point at. - staticIPScript = pkgs.writeText "vmix-static-ip.cmd" '' - @echo off - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-static-ip.ps1 > C:\Windows\Temp\vmix-static-ip.log 2>&1 - ''; - - dataDriveLetter = if dataDisk != null then (dataDisk.driveLetter or "D") else "D"; - dataLabel = if dataDisk != null then (dataDisk.label or "data") else "data"; - - # ProfilesDirectory is only honoured when the volume it names already exists, - # and a freshly created zvol arrives RAW. Initializing the disk here, in the - # same specialize pass, brings it up before oobeSystem creates any profile. - # - # Idempotent, because specialize runs again on every sysprep: a RAW disk gets - # a GPT label, one full-size NTFS partition and the drive letter, while a disk - # that already holds data keeps it and only has its letter re-asserted. The - # OS disk is added to QEMU first and so is always disk 0. - initDataDiskScript = pkgs.writeText "vmix-init-data-disk.cmd" (if configMedium then '' - @echo off - :: Sealed-image variant. Two extra hazards over the baked path: - :: - :: 1. The per-VM config rides an optical drive, and on the target's first - :: boot the raw data disk has no volume yet -- so Windows letters the CD - :: as ${dataDriveLetter}:, exactly where the profile volume must go. The - :: plain `if exist ${dataDriveLetter}:\` guard would then see the CD and - :: skip, leaving ProfilesDirectory pointed at read-only media. So a first - :: boot is tracked by a marker, not by the letter, and any occupant of - :: ${dataDriveLetter}: is moved aside before the data disk claims it. - :: 2. Left to Shell-Setup's FolderLocations, ProfilesDirectory can be - :: evaluated before this disk exists (unordered within specialize) and - :: silently fall back to C:. Setting it here, in the same step that just - :: created the volume, removes that race. - if exist C:\vmix-data-initialized goto :ensure - - :: First boot: park whatever holds ${dataDriveLetter}: (the config CD) on Y: - :: so the data disk can take the letter. Harmless if the letter is free. - > C:\Windows\Temp\vmix-cd.txt echo select volume ${dataDriveLetter} - >> C:\Windows\Temp\vmix-cd.txt echo assign letter=Y noerr - diskpart /s C:\Windows\Temp\vmix-cd.txt > nul 2>&1 - - :: Lay disk 1 (the host zvol) out from scratch and give it the letter. - > C:\Windows\Temp\vmix-dd-init.txt echo select disk 1 - >> C:\Windows\Temp\vmix-dd-init.txt echo clean - >> C:\Windows\Temp\vmix-dd-init.txt echo convert gpt - >> C:\Windows\Temp\vmix-dd-init.txt echo create partition primary - >> C:\Windows\Temp\vmix-dd-init.txt echo format fs=ntfs quick label="${dataLabel}" - >> C:\Windows\Temp\vmix-dd-init.txt echo assign letter=${dataDriveLetter} - diskpart /s C:\Windows\Temp\vmix-dd-init.txt - echo initialized > C:\vmix-data-initialized - goto :ensure - - :ensure - :: The letter normally persists via MountedDevices; re-assert if it is gone. - if exist ${dataDriveLetter}:\ goto :profiledir - > C:\Windows\Temp\vmix-dd-assign.txt echo select disk 1 - >> C:\Windows\Temp\vmix-dd-assign.txt echo select partition 1 - >> C:\Windows\Temp\vmix-dd-assign.txt echo assign letter=${dataDriveLetter} - diskpart /s C:\Windows\Temp\vmix-dd-assign.txt > nul 2>&1 - - :profiledir - ${lib.optionalString (profilesDirectory != null) '' - :: Point new profiles at the data volume, now that it exists. REG_EXPAND_SZ - :: to match Windows' own ProfilesDirectory type. - if exist ${dataDriveLetter}:\ ( - if not exist "${profilesDirectory}" mkdir "${profilesDirectory}" - reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" /v ProfilesDirectory /t REG_EXPAND_SZ /d "${profilesDirectory}" /f > nul 2>&1 - )''} - del /q C:\Windows\Temp\vmix-cd.txt C:\Windows\Temp\vmix-dd-init.txt C:\Windows\Temp\vmix-dd-assign.txt 2>nul - :done - '' else '' - @echo off - :: diskpart rather than the Storage cmdlets. New-Partition and - :: Format-Volume need services that are not up yet this early in - :: specialize, so they fail where Initialize-Disk succeeds -- which left - :: the disk carrying a GPT header and nothing else, and ProfilesDirectory - :: pointing at a volume that never existed. - if exist ${dataDriveLetter}:\ goto :done - - :: The volume may already be laid out and merely unlettered, in which case - :: assigning is enough and cleaning would destroy the profile. - > C:\Windows\Temp\vmix-dd-assign.txt echo select disk 1 - >> C:\Windows\Temp\vmix-dd-assign.txt echo select partition 1 - >> C:\Windows\Temp\vmix-dd-assign.txt echo assign letter=${dataDriveLetter} - diskpart /s C:\Windows\Temp\vmix-dd-assign.txt > nul 2>&1 - if exist ${dataDriveLetter}:\ goto :cleanup - - :: Nothing there to keep, so lay the disk out from scratch. - > C:\Windows\Temp\vmix-dd-init.txt echo select disk 1 - >> C:\Windows\Temp\vmix-dd-init.txt echo clean - >> C:\Windows\Temp\vmix-dd-init.txt echo convert gpt - >> C:\Windows\Temp\vmix-dd-init.txt echo create partition primary - >> C:\Windows\Temp\vmix-dd-init.txt echo format fs=ntfs quick label="${dataLabel}" - >> C:\Windows\Temp\vmix-dd-init.txt echo assign letter=${dataDriveLetter} - diskpart /s C:\Windows\Temp\vmix-dd-init.txt - - :cleanup - del /q C:\Windows\Temp\vmix-dd-assign.txt C:\Windows\Temp\vmix-dd-init.txt 2>nul - :done - ''); - - # PowerShell in its own file, so neither cmd quoting nor Nix's '' need to be - # fought. If the account's real profile got backed up to a .bak key (the - # temporary-profile fallback), put it back: drop the temp key, rename .bak to - # the live SID, remove the temp directory, and drop a flag so the caller - # knows to reboot. - # Known-Folder GUIDs for the redirectable user folders. - knownFolderGuids = { - Desktop = "{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}"; - Documents = "{FDD39AD0-238F-46AF-ADB4-6C85480369C7}"; - Downloads = "{374DE290-123F-4565-9164-39C4925E467B}"; - Pictures = "{33E28130-4E1E-4676-835A-98395C3BC476}"; - Music = "{4BD8D571-6D19-48D3-BE97-422220080E43}"; - Videos = "{18989B1D-99B5-455B-841C-AB7C74E4DDFC}"; - Favorites = "{1777F761-68AD-4D8A-87BD-30B759FA33DD}"; - }; - redirectFolders = if folderRedirect != null - then (folderRedirect.folders or [ "Desktop" "Documents" "Downloads" "Pictures" "Music" "Videos" ]) - else [ ]; - redirectBase = if folderRedirect != null then (folderRedirect.base or "D:\\UserData") else "D:\\UserData"; - - # Per-user, run once per profile via Active Setup: point each known folder at - # its directory under the data volume. SHSetKnownFolderPath updates both the - # registration and the shell-folder registry; it does not move files, so a - # freshly created profile's empty C: folder is simply repointed at the D: one, - # which already holds this user's accumulated files after a rebuild. - folderRedirectPs1 = pkgs.writeText "vmix-redirect-folders.ps1" (lib.optionalString (folderRedirect != null) '' - $sig = @' - [DllImport("shell32.dll", CharSet=CharSet.Unicode)] - public static extern int SHSetKnownFolderPath(ref System.Guid rfid, uint dwFlags, System.IntPtr hToken, string pszPath); - '@ - $kf = Add-Type -MemberDefinition $sig -Name KFP -Namespace Vmix -PassThru - $map = @{ - ${lib.concatMapStringsSep "\n " (f: "'${f}' = '${knownFolderGuids.${f}}'") redirectFolders} - } - foreach ($name in $map.Keys) { - $target = Join-Path '${redirectBase}' $name - New-Item -ItemType Directory -Force -Path $target -ErrorAction SilentlyContinue | Out-Null - $guid = [System.Guid]$map[$name] - [void]$kf::SHSetKnownFolderPath([ref]$guid, 0, [System.IntPtr]::Zero, $target) - } - ''); - - # Active Setup fires StubPath once per user at first logon -- including the - # fresh profile each generalized rebuild creates -- which is exactly when the - # redirection needs re-applying. Backslashes doubled for .reg. - activeSetupRegistry = lib.optionalString (folderRedirect != null) '' - Windows Registry Editor Version 5.00 - - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6f3b8c2a-1d4e-4f9a-b8c1-0a1b2c3d4e5f}] - @="vmix folder redirection" - "StubPath"="powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File C:\\vmix-redirect-folders.ps1" - "Version"="1" - ''; - - healProfileScript = pkgs.writeText "vmix-heal-profile.ps1" (lib.optionalString (profilesDirectory != null) '' - $pl = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList' - $bak = Get-ChildItem $pl -ErrorAction SilentlyContinue | Where-Object { - $_.PSChildName -like '*.bak' -and - (Get-ItemProperty $_.PSPath -ErrorAction SilentlyContinue).ProfileImagePath -eq '${profilesDirectory}\${username}' - } | Select-Object -First 1 - if ($bak) { - $sid = $bak.PSChildName -replace '\.bak$' - Remove-Item (Join-Path $pl $sid) -Recurse -Force -ErrorAction SilentlyContinue - Rename-Item $bak.PSPath $sid -ErrorAction SilentlyContinue - Remove-Item '${profilesDirectory}\TEMP' -Recurse -Force -ErrorAction SilentlyContinue - New-Item -Path C:\Windows\Temp\vmix-profile-healed -ItemType File -Force | Out-Null - } - ''); - - # One onstart / SYSTEM script for whatever the data disk needs before logon: - # assign its letter, and then either heal a relocated profile that went - # temporary (profilesDirectory) or make the redirected data folders reachable - # by whatever account this rebuild created (folderRedirect). Both cannot apply - # at once -- a profile is either wholly on D: or only its data folders are. - bootDataProfileScript = pkgs.writeText "vmix-data-profile.cmd" '' - @echo off - ${lib.optionalString (dataDisk != null) "call C:\\vmix-init-data-disk.cmd"} - ${lib.optionalString (profilesDirectory != null) '' - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-heal-profile.ps1 > C:\Windows\Temp\vmix-data-profile.log 2>&1 - if exist C:\Windows\Temp\vmix-profile-healed ( - del /q C:\Windows\Temp\vmix-profile-healed - shutdown /r /t 5 /c "vmix: repaired relocated profile, restarting" - ) - ''} - ${lib.optionalString (folderRedirect != null) '' - :: The redirected folders live under a per-user account whose SID changes on - :: every generalized rebuild, so grant the well-known Users group -- which - :: any account joins and which is SID-stable across machines -- inheritable - :: full control, and let the per-user redirect (Active Setup) point the known - :: folders here. Runs as SYSTEM, before any logon. - if not exist "${redirectBase}" mkdir "${redirectBase}" - ${lib.concatMapStringsSep "\n " (f: ''if not exist "${redirectBase}\${f}" mkdir "${redirectBase}\${f}"'') redirectFolders} - icacls "${redirectBase}" /grant *S-1-5-32-545:(OI)(CI)F /t > C:\Windows\Temp\vmix-redirect-prep.log 2>&1 - ''} - ''; - - folderLocationsXml = lib.optionalString (profilesDirectory != null) '' - - - ${profilesDirectory} - ''; - - # ProfilesDirectory as an offline .reg merge, for the keepMachineSid path - # where the specialize pass (and its FolderLocations) does not run. virt-win-reg - # applies this before the Audit Mode boot, so it is in place when OOBE creates - # the account. Backslashes are doubled for .reg syntax. - profileListRegistry = lib.optionalString (keepMachineSid && profilesDirectory != null) '' - Windows Registry Editor Version 5.00 - - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList] - "ProfilesDirectory"="${builtins.replaceStrings [''\''] [''\\''] profilesDirectory}" - ''; - - dataDiskXml = lib.optionalString (dataDisk != null) '' - - - - - 1 - cmd /c C:\vmix-init-data-disk.cmd - vmix: initialize the data disk - - - ''; - # Post-OOBE script: runs as the created user via FirstLogonCommands. postOobeScript = pkgs.writeText "post-oobe.cmd" '' @echo off - ${lib.optionalString configMedium '' - :: Stage the per-VM config off the removable CD, then apply the parts that - :: are not answer-file fields (timezone, desktop tint, machine rename). The - :: static address is left to the per-boot task registered below. - call C:\vmix-load-config.cmd - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-apply-config.ps1 > C:\Windows\Temp\vmix-apply-config.log 2>&1 - ''} ${lib.optionalString (!autoLogon) '' reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon /f 2>nul reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName /f 2>nul @@ -541,7 +81,6 @@ in powershell -Command "Get-AppxPackage *MicrosoftEdgeDevToolsClient* | Remove-AppxPackage -ErrorAction SilentlyContinue" - ${lib.optionalString (!configMedium) '' :: Re-install product key and licenses to restore activation IDs after sysprep cscript //nologo C:\Windows\System32\slmgr.vbs /ipk M7XTQ-FN8P6-TTKYV-9D4CC-J462D cscript //nologo C:\Windows\System32\slmgr.vbs /rilc @@ -560,9 +99,6 @@ in ) ) del /q C:\MAS_AIO.cmd 2>nul - ''} - :: configMedium: activation is deferred to the boot-2 finalize, so it runs - :: on the real account's fresh SID. MAS_AIO.cmd is kept for it until then. ${lib.optionalString enableRDP '' :: Enable RDP @@ -576,80 +112,14 @@ in reg add "HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv" /v Start /t REG_DWORD /d 2 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService" /v Start /t REG_DWORD /d 2 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\TermService" /v Start /t REG_DWORD /d 2 /f - :: A VM reached over RDP must never suspend itself off the network. The - :: default Balanced plan sleeps after 15 min idle; switch to High - :: Performance and zero every idle timeout, and turn hibernate off. - powercfg /setactive SCHEME_MIN - powercfg /change standby-timeout-ac 0 - powercfg /change standby-timeout-dc 0 - powercfg /change hibernate-timeout-ac 0 - powercfg /change hibernate-timeout-dc 0 - powercfg /change monitor-timeout-ac 0 - powercfg /hibernate off ''} - ${lib.optionalString (staticIP != null && !configMedium) '' - :: This VM's only NIC sits on a macvtap bridged to the host's LAN, so its - :: address is a LAN address that nothing hands out -- the guest asserts it. - :: Registered to run at every boot rather than applied here. OOBE runs in - :: the build VM, whose NIC is qemu user networking on another subnet with - :: another MAC -- so an address set now lands on an adapter that does not - :: exist on the real host. Windows sees the target's NIC as new hardware - :: and falls back to DHCP, which is exactly what happened. Per-boot also - :: survives the adapter being replaced again later. - schtasks /create /tn "vmix-static-ip" /tr "C:\vmix-static-ip.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f > nul 2>&1 - ''} - - ${lib.optionalString configMedium '' - :: configMedium (sealed images) run OOBE on the real target NIC, so the - :: address is set here once and left in the persistent store -- it survives - :: reboots on its own, no per-boot task and no script left on disk. Runs on - :: this bootstrap boot so the real account is already reachable on boot 2. - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-static-ip.ps1 > C:\Windows\Temp\vmix-static-ip.log 2>&1 - ''} - - ${lib.optionalString (dataDisk != null && !configMedium) '' - :: Ensures D: is assigned on every boot -- the image ships without a - :: persisted letter for the data disk -- and heals a profile that went - :: temporary before D: was ready. Onstart / SYSTEM, like the address task. - :: configMedium does not need this: the letter persists via MountedDevices - :: in the overlay after the first boot, so there is nothing to re-assert. - schtasks /create /tn "vmix-data-profile" /tr "C:\vmix-data-profile.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f > nul 2>&1 - ''} - - ${lib.optionalString (writeFilter != null) '' - :: Install the feature now, but defer configuring it: uwfmgr does not exist - :: until this has been through a reboot, and the swapfile belongs on the - :: real data volume, so RunOnce picks it up on the target's first boot. - dism /online /enable-feature /featurename:Client-UnifiedWriteFilter /all /norestart - reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v "vmixUwf" /t REG_SZ /d "C:\vmix-uwf-config.cmd" /f - ''} - - - ${lib.optionalString keepMachineSid '' - :: /oobe without /generalize leaves the system set to re-run windeploy (OOBE) - :: on every boot -- shutting down here in a FirstLogonCommand cuts OOBE off - :: before it resets that state itself. Clear it, or the target boots into a - :: Setup with no unattend left to consume and hangs on a black screen. - reg add "HKLM\SYSTEM\Setup" /v SetupType /t REG_DWORD /d 0 /f - reg delete "HKLM\SYSTEM\Setup" /v OOBEInProgress /f 2>nul - reg delete "HKLM\SYSTEM\Setup" /v CmdLine /f 2>nul - ''} - ${lib.optionalString configMedium '' - :: Runs last, as the generic bootstrap account: create the real per-VM - :: account from the config, switch autologon to it and arm the cleanup. The - :: reboot below then logs the real account in for the first time, building - :: its SID-bound profile on D:\Users\. - powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-create-user.ps1 > C:\Windows\Temp\vmix-create-user.log 2>&1 - ''} :: Clean up del /q C:\oobe-unattend.xml 2>nul del /q C:\vmix-audit-script.cmd 2>nul del /q C:\vmix-audit-wrapper.cmd 2>nul - ${if configMedium then "shutdown /r /t 5 /c \"vmix: applying per-VM config\"" - else if delayOobeRun then "" - else "shutdown /s /t 5 /c \"vmix generalize complete\""} + ${if delayOobeRun then "" else "shutdown /s /t 5 /c \"vmix generalize complete\""} del /q C:\post-oobe.cmd 2>nul ''; @@ -657,26 +127,15 @@ in - + -${lib.optionalString (profilesDirectory == null) " true"} + true Automatic -${folderLocationsXml} -${dataDiskXml} @@ -721,7 +180,6 @@ ${dataDiskXml} ${username} ${hostname} -${folderLocationsXml} ${timezone} @@ -735,46 +193,13 @@ ${folderLocationsXml} ''; in { - name = if configMedium then "seal" else if delayOobeRun then "generalize-delay-oobe" else "generalize"; + name = if delayOobeRun then "generalize-delay-oobe" else "generalize"; inherit nicModel; - # With keepMachineSid the specialize pass never runs (see the sysprep line), - # so the profile relocation cannot ride the unattend there. It is written to - # the registry offline instead, before the build's OOBE creates the profile, - # so the account still lands on the data volume. Empty otherwise. - windowsRegistry = profileListRegistry + activeSetupRegistry; - # The blank disk is attached for the Audit Mode boot itself, so the disk-init - # command and the profile relocation both happen under OOBE in the build VM. - # That is what makes delayOobeRun unnecessary: nothing is left to do on real - # hardware. The written disk comes back as this derivation's `data` output. - # - # Under delayOobeRun there is no build-VM OOBE to relocate into, and the real - # data volume is the host's zvol attached at deploy time -- so building an - # empty throwaway disk here would be pure waste. Gated off: the target's - # specialize formats the real disk (dataDiskXml) and OOBE creates the profile - # on it. This is what lets a sealed image ship without a `data` output. - extraDisk = if (dataDisk != null && !delayOobeRun) then { size = dataDisk.size or "100G"; } else null; uploads = [ { source = oobeXml; dest = "/oobe-unattend.xml"; } { source = postOobeScript; dest = "/post-oobe.cmd"; } { source = masScript; dest = "/MAS_AIO.cmd"; } - ] ++ lib.optionals (dataDisk != null) ( - [ { source = initDataDiskScript; dest = "/vmix-init-data-disk.cmd"; } - { source = bootDataProfileScript; dest = "/vmix-data-profile.cmd"; } - ] - ++ lib.optional (profilesDirectory != null) { source = healProfileScript; dest = "/vmix-heal-profile.ps1"; } - ++ lib.optional (folderRedirect != null) { source = folderRedirectPs1; dest = "/vmix-redirect-folders.ps1"; } - ) - ++ lib.optional (writeFilter != null) { source = uwfConfigScript; dest = "/vmix-uwf-config.cmd"; } - ++ lib.optionals configMedium [ - { source = loadConfigScript; dest = "/vmix-load-config.cmd"; } - { source = applyConfigScript; dest = "/vmix-apply-config.ps1"; } - { source = createUserScript; dest = "/vmix-create-user.ps1"; } - { source = finalizeScript; dest = "/vmix-finalize.cmd"; } - ] - ++ lib.optionals (staticIP != null || configMedium) [ - { source = staticIPScript; dest = "/vmix-static-ip.cmd"; } - { source = staticIPScriptPs1; dest = "/vmix-static-ip.ps1"; } - ]; + ]; # delayOobeRun: sysprep + shutdown — OOBE runs on real hardware # generalize: sysprep + reboot into OOBE in the same QEMU session auditScript = '' @@ -783,22 +208,7 @@ in { del /q C:\Windows\Panther\unattend.xml 2>nul del /q C:\Windows\Panther\Unattend\unattend.xml 2>nul del /q C:\Windows\System32\Sysprep\Panther\unattend.xml 2>nul - ${lib.optionalString (dataDisk != null && !delayOobeRun) '' - :: Lay the data disk out here, in Audit Mode, rather than leaving it to the - :: specialize pass alone. Component order within a pass is not guaranteed, - :: and FolderLocations is applied by Shell-Setup while the disk is prepared - :: by Deployment -- so relocation can be evaluated before the volume it - :: names exists, which silently leaves profiles on C:. Audit Mode is a - :: fully booted OS with the disk already attached, so this always works. - :: The specialize copy stays as a letter re-assertion after generalize - :: clears MountedDevices. - :: - :: Only when there is a build disk to lay out. Under delayOobeRun (sealed - :: images) the disk is the host's zvol, present only on the target, so this - :: is left to the target's specialize pass alone. - call C:\vmix-init-data-disk.cmd - ''} - C:\Windows\System32\Sysprep\sysprep.exe ${lib.optionalString (!keepMachineSid) "/generalize "}/oobe ${if delayOobeRun then "/shutdown" else "/reboot"} /quiet /unattend:C:\oobe-unattend.xml + C:\Windows\System32\Sysprep\sysprep.exe /generalize /oobe ${if delayOobeRun then "/shutdown" else "/reboot"} /quiet /unattend:C:\oobe-unattend.xml ''; } diff --git a/lib/images/windows/win10/images.nix b/lib/images/windows/win10/images.nix index 67ec23d..1aabf77 100644 --- a/lib/images/windows/win10/images.nix +++ b/lib/images/windows/win10/images.nix @@ -9,7 +9,9 @@ rec { upstreamISO = upstreamISOs.win10-ltsc-2021; productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D"; }; - basic = customizeImageFold upstream (with templates; [ + # Apply all available Windows Updates (cumulative, .NET, Defender) + updated = customizeImage upstream (templates.essentials.windowsUpdate {}); + basic = customizeImageFold updated (with templates; [ essentials.virtioTools essentials.removeIE essentials.removeWMP @@ -38,8 +40,9 @@ rec { productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D"; useAHCI = true; }; + laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {}); - laptopSlim = customizeImageFold laptopUpstream templates.bundles.laptopSlim; + laptopSlim = customizeImageFold laptopUpdated templates.bundles.laptopSlim; - laptop = customizeImageFold laptopUpstream templates.bundles.laptop; + laptop = customizeImageFold laptopUpdated templates.bundles.laptop; } diff --git a/lib/images/windows/win11/images.nix b/lib/images/windows/win11/images.nix index 54eb076..730638e 100644 --- a/lib/images/windows/win11/images.nix +++ b/lib/images/windows/win11/images.nix @@ -12,7 +12,8 @@ rec { windowsVersionForVirtioDrivers = "w11"; }; - basic = customizeImageFold upstream (with templates; [ + updated = customizeImage upstream (templates.essentials.windowsUpdate {}); + basic = customizeImageFold updated (with templates; [ essentials.virtioTools essentials.removeIE essentials.removeWMP @@ -45,9 +46,11 @@ rec { windowsVersionForVirtioDrivers = "w11"; }; - laptopSlim = customizeImageFold laptopUpstream + laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {}); + + laptopSlim = customizeImageFold laptopUpdated (templates.bundles.laptopSlim ++ [ templates.reg.disableUCPD ]); - laptop = customizeImageFold laptopUpstream + laptop = customizeImageFold laptopUpdated (templates.bundles.laptop ++ [ templates.reg.disableUCPD ]); } diff --git a/module.nix b/module.nix new file mode 100644 index 0000000..1f26736 --- /dev/null +++ b/module.nix @@ -0,0 +1,6 @@ +{ ... }: +{ + imports = [ + ./nixos/default.nix + ]; +} \ No newline at end of file diff --git a/nixos/default.nix b/nixos/default.nix index 75dce49..2944e04 100644 --- a/nixos/default.nix +++ b/nixos/default.nix @@ -1,7 +1,7 @@ { config, pkgs, lib, ... }: with lib; let - vmixLib = pkgs.vmixLib; + vmixLib = import ./../lib {inherit pkgs lib; }; args = { inherit config pkgs lib vmixLib; }; in { @@ -15,4 +15,6 @@ in (types.submodule (import ./namespaceSubmoduleOptions.nix args)); default = {}; }; -} + + config.nixpkgs.overlays = [ (import ../overlay.nix) ]; +} \ No newline at end of file diff --git a/nixos/networks/config.nix b/nixos/networks/config.nix index 658b6ac..faaafba 100644 --- a/nixos/networks/config.nix +++ b/nixos/networks/config.nix @@ -172,10 +172,6 @@ let let wanCfg = cfg // { spaceName = spaceName; }; vethInNSToHost.iface = "vhost"; - # Temporary peer name, unique per namespace. The peer briefly exists in the - # host namespace before being moved; a shared name ("vhost") lets parallel - # wan.net.vmix@* starts steal each other's peer ends, cross-wiring namespaces. - vethInNSToHost.tempIface = "vh-${wanCfg.spaceName}"; vethOnHostToNS.iface = "vn-${wanCfg.spaceName}"; vethOnHostToNS.ipv4.address = calc.cidr.host 1 wanCfg.ipv4.range; vethInNSToHost.ipv4.address = calc.cidr.host 2 wanCfg.ipv4.range; @@ -184,9 +180,8 @@ let portForwardRules = lib.concatStringsSep "\n" (lib.mapAttrsToList (hostIPnPort: nsPort: "iptables -t nat -A PREROUTING -p tcp --dport ${hostIPnPort} -j DNAT --to-destination ${vethInNSToHost.ipv4.address}:${toString nsPort}") wanCfg.forwardPorts); createWanCommands = '' - ip link add ${vethOnHostToNS.iface} type veth peer name ${vethInNSToHost.tempIface} - ip link set ${vethInNSToHost.tempIface} netns ${wanCfg.spaceName}.vmix - ip netns exec ${wanCfg.spaceName}.vmix ip link set ${vethInNSToHost.tempIface} name ${vethInNSToHost.iface} + ip link add ${vethOnHostToNS.iface} type veth peer name ${vethInNSToHost.iface} + ip link set ${vethInNSToHost.iface} netns ${wanCfg.spaceName}.vmix ip address add ${vethOnHostToNS.ipv4.address}/${networkPrefix} dev ${vethOnHostToNS.iface} ip netns exec ${wanCfg.spaceName}.vmix ip address add ${vethInNSToHost.ipv4.address}/${networkPrefix} dev ${vethInNSToHost.iface} @@ -291,6 +286,5 @@ in { config.systemd.services = namespaceGlobalService // networkServices; config.systemd.targets = networkTargets; - config.boot.kernel.sysctl."net.ipv4.ip_forward" = lib.mkForce 1; - config.boot.kernel.sysctl."net.ipv4.conf.all.forwarding" = lib.mkForce true; + config.boot.kernel.sysctl."net.ipv4.ip_forward" = lib.mkDefault 1; } diff --git a/nixos/vms/config.nix b/nixos/vms/config.nix index fa5c4cd..42b0868 100644 --- a/nixos/vms/config.nix +++ b/nixos/vms/config.nix @@ -79,23 +79,6 @@ let # Auto-detect Windows from _vmixOsType marker on the disk image isWindows = vmCfg.windows.enable || (hasOsDisk && (vmCfg.disks.os.file._vmixOsType or "linux") == "windows"); - # Interrupt remapping in the virtual IOMMU only works on a split irqchip, - # so viommu wins over the full in-kernel irqchip hideVirtualized asks for. - machineIrqchipArg = - if vmCfg.pci.viommu.enable then ",kernel-irqchip=split" - else optionalString vmCfg.cpu.hideVirtualized ",kernel_irqchip=on"; - # Functions of one physical device have to reach the guest as functions - # of one device too. Giving each address its own root port splits a GPU - # from its own HDMI audio, and Navi cannot then reset or power-manage - # either half -- the guest ends up with a card stuck in D3. So group by - # everything left of the function digit and place each group behind a - # single root port, multifunction, at the same slot. - pciDeviceOf = addr: head (splitString "." addr); - pciFunctionOf = addr: last (splitString "." addr); - pciGroups = map - (dev: filter (a: pciDeviceOf a == dev) vmCfg.pci.passthrough) - (unique (map pciDeviceOf vmCfg.pci.passthrough)); - # Linux VMs: apply customizeImage with 9p fstab and machine-id setup linuxOsImage = vmixLib.linux.customizeImage vmCfg.disks.os.file { @@ -125,34 +108,13 @@ let if [ ! -f "$PERSIST_PATH" ]; then echo "Seeding persistent disk from store image..." mkdir -p "$(dirname "$PERSIST_PATH")" - ${if vmCfg.disks.os.persistMode == "backing" - then ''qemu-img create -f qcow2 -F qcow2 -b "${toString storeImage}" "$PERSIST_PATH"'' - else ''cp --no-preserve=mode "${toString storeImage}" "$PERSIST_PATH"''} + cp --no-preserve=mode "${toString storeImage}" "$PERSIST_PATH" chmod 600 "$PERSIST_PATH" fi ''; persistExecStartPre = lib.optional (hasOsDisk && vmCfg.disks.os.persist) seedPersistentDiskScript; - # A GC root pinning the OS overlay's ACTUAL backing store path, so - # nix-collect-garbage cannot delete the store image the disk reads through. - gcrootLink = "/nix/var/nix/gcroots/vmix-${vmCfg.name}-osbacking"; - gcrootScript = pkgs.writeShellScript "${vmCfg.name}-gcroot-vmix" '' - # Read the live overlay's backing (not the config's current image, which - # drifts to a new store path after a rebuild while the overlay keeps - # backing the old one). Pinning the top of the chain transitively keeps - # the whole chain -- qcow2 backing_file paths are registered nix refs. - BACK="" - if [ -f "${vmCfg.disks.os.persistPath}" ]; then - BACK=$(qemu-img info "${vmCfg.disks.os.persistPath}" 2>/dev/null | awk '/^backing file:/ {print $3; exit}') - fi - [ -z "$BACK" ] && BACK="${toString storeImage}" - if [ -n "$BACK" ]; then - mkdir -p /nix/var/nix/gcroots - ln -sfn "$BACK" "${gcrootLink}" - fi - ''; - # QEMU expects single-letter boot codes (e.g. c,d,n), while vmix uses readable names. bootOrderQemu = let @@ -212,9 +174,6 @@ let ''} exec qemu-system-${vmCfg.arch} \ ${if vmCfg.nographic && vmCfg.pci.passthrough != [] then "-display none -vga none" else optionalString vmCfg.nographic "-nographic"} \ - ${# QEMU realizes devices in command-line order and intel-iommu must - # exist before anything it translates, so it leads the device list. - optionalString vmCfg.pci.viommu.enable "-device intel-iommu,intremap=on,caching-mode=on"} \ ${optionalString (vmCfg.vnc.enable && vmCfg.vnc.passwordFile != null) "-object secret,id=vnc-pass-${vmCfg.name},file=${escapeShellArg vmCfg.vnc.passwordFile}"} \ ${optionalString vmCfg.vnc.enable "-vnc ${vncArgs}"} \ ${optionalString (vmCfg.spice.enable && vmCfg.spice.passwordFile != null) "-object secret,id=spice-pass-${vmCfg.name},file=${escapeShellArg vmCfg.spice.passwordFile}"} \ @@ -230,21 +189,17 @@ let ${optionalString vmCfg.mem.balloon "-device virtio-balloon-pci"} \ -smp cores=${toString vmCfg.cpu.cores} \ -cpu ${vmCfg.cpu.model}${optionalString vmCfg.cpu.hideVirtualized ",kvm=off,hv_vendor_id=1234567890ab,-hypervisor"} \ - -machine type=${vmCfg.pc.type}${machineIrqchipArg} \ + -machine type=${vmCfg.pc.type}${optionalString vmCfg.cpu.hideVirtualized ",kernel_irqchip=on"} \ ${optionalString vmCfg.bios.efi "-bios ${pkgs.OVMF.fd}/FV/OVMF.fd"} \ ${optionalString vmCfg.bios.tpm "-chardev socket,id=chrtpm,path=/tmp/mytpm-sock -tpmdev emulator,id=tpm0,chardev=chrtpm -device tpm-tis,tpmdev=tpm0"} \ - ${# Windows: localtime RTC, USB tablet for mouse, disable S3/S4 sleep. - # The q35 power/LPC bridge is ICH9-LPC -- ICH9-LMB was a typo qemu - # rejects ("invalid class name"), so the sleep states stayed offered - # and an idle guest could suspend itself right off the network. + ${# Windows: localtime RTC, USB tablet for mouse, disable S3/S4 sleep optionalString isWindows '' -rtc base=localtime,clock=host \ -device qemu-xhci -device usb-tablet \ - -global ICH9-LPC.disable_s3=1 -global ICH9-LPC.disable_s4=1 \ + -global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \ ''} \ ${optionalString hasOsDisk "-drive file=${osDiskPath},format=qcow2,if=virtio${optionalString (vmCfg.disks.os.persist == false) ",snapshot=on"}"} \ ${optionalString (vmCfg.disks.iso.file != null) "-drive file=${toString vmCfg.disks.iso.file},media=cdrom,readonly=on"} \ - ${optionalString (vmCfg.disks.config.file != null) "-drive file=${toString vmCfg.disks.config.file},media=cdrom,readonly=on"} \ ${concatMapStrings (diskCfg: '' -drive file=${toString diskCfg.file},format=${diskCfg.format},if=${vmCfg.disks.bus} \ '') (attrValues vmCfg.disks.add)} \ @@ -263,11 +218,10 @@ let -device ${vmCfg.nicModel},netdev=macvtap-${macvtap.name},mac=$(ip l show ${macvtap.iface} | awk '/link\/ether/{print $2}') \ -netdev tap,id=macvtap-${macvtap.name},fd=${toString (i+2)} ${toString (i+2)}<>/dev/tap$(ip l show ${macvtap.iface} | awk -F':' '/${macvtap.iface}/{print $1}') \ '') allMacvtaps)} \ - ${concatStrings (imap1 (i: group: '' + ${concatStrings (imap1 (i: pciAddr: '' -device pcie-root-port,id=pci-passthrough${toString i},chassis=${toString i},slot=${toString i} \ - '' + concatStrings (imap0 (j: pciAddr: '' - -device vfio-pci,host=${pciAddr},bus=pci-passthrough${toString i},addr=0x0.${pciFunctionOf pciAddr}${optionalString (length group > 1 && j == 0) ",multifunction=on"}${optionalString (i == 1 && j == 0) "${optionalString vmCfg.pci.vgaPassthrough ",x-vga=on"}${optionalString (vmCfg.pci.romFile != null) ",romfile=${vmCfg.pci.romFile}"}"} \ - '') group)) pciGroups)} \ + -device vfio-pci,host=${pciAddr},bus=pci-passthrough${toString i}${optionalString (i == 1) ",x-vga=on${optionalString (vmCfg.pci.romFile != null) ",romfile=${vmCfg.pci.romFile}"}"} \ + '') vmCfg.pci.passthrough)} \ ${concatMapStrings (usbDev: '' -device usb-host,vendorid=0x${usbDev.vendorId},productid=0x${usbDev.productId} \ '') vmCfg.usb.hostDevices} \ @@ -279,8 +233,7 @@ let "vm.vmix@${vmCfg.name}" = rec { bindsTo = [ "net.vmix@${spaceName}.target" ] ++ lib.optional (allMacvtaps != []) "macvtaps.vm.vmix@${vmCfg.name}.service"; unitConfig.JoinsNamespaceOf = "ns.net.vmix@${spaceName}.service"; - after = bindsTo ++ lib.optional (hasOsDisk && vmCfg.disks.os.persist) "vm.vmix-gcroot@${vmCfg.name}.service"; - wants = lib.optional (hasOsDisk && vmCfg.disks.os.persist) "vm.vmix-gcroot@${vmCfg.name}.service"; + after = bindsTo; path = with pkgs; [ iproute2 qemu gawk coreutils ]; serviceConfig = { ExecStartPre = persistExecStartPre ++ [ createTapsforLansScript ]; @@ -310,18 +263,6 @@ let ExecStop = deleteMacvTapsScript; }; }; - } - // lib.optionalAttrs (cfg.enable && hasOsDisk && vmCfg.disks.os.persist) { - "vm.vmix-gcroot@${vmCfg.name}" = { - before = [ "vm.vmix@${vmCfg.name}.service" ]; - wantedBy = [ "multi-user.target" ]; - path = with pkgs; [ qemu coreutils ]; - serviceConfig = { - Type = "oneshot"; - RemainAfterExit = true; - ExecStart = gcrootScript; - }; - }; }; vmServices = concatMapAttrs (spaceName: namespaceCfg: (concatMapAttrs (mkServices4aVMInNamespace spaceName) namespaceCfg.vms)) vmixCfg.namespaces; diff --git a/nixos/vms/submoduleOptions.nix b/nixos/vms/submoduleOptions.nix index 24e9f8f..0158c2b 100644 --- a/nixos/vms/submoduleOptions.nix +++ b/nixos/vms/submoduleOptions.nix @@ -173,32 +173,11 @@ with lib; default = ""; description = "Mutable path for the persistent OS disk (e.g. /storage/vms/myvm/os.qcow2). Required when persist = true."; }; - disks.os.persistMode = mkOption { - type = types.enum [ "copy" "backing" ]; - default = "copy"; - description = '' - How the persistent OS disk is seeded from the store image (persist = true). - copy: a full cp of the store image; the mutable disk holds everything. - backing: a thin qcow2 overlay backing onto the shared store image, so many - VMs share one base and each holds only its own deltas. The store image (and - its backing chain) must then survive GC -- vmix pins it via a per-VM gcroot. - ''; - }; disks.iso.file = mkOption { type = types.nullOr (types.either types.path types.str); description = "Path to the ISO file. Can be a Nix store path or a string path to a local file."; default = null; }; - disks.config.file = mkOption { - type = types.nullOr (types.either types.path types.str); - default = null; - description = '' - A small read-only config medium attached as a second CD-ROM. For Windows - sealed images (templates.seal) this is the per-VM ISO from - vmixLib.windows.makeConfigMedium, carrying hostname/static-IP/etc. that - the image's baked first-boot scripts consume. Null to attach nothing. - ''; - }; disks.add = mkOption { default = {}; type = types.attrsOf (types.submodule { @@ -283,36 +262,11 @@ with lib; default = []; description = "PCI device addresses to passthrough via VFIO (e.g. [\"0000:03:00.0\" \"0000:03:00.1\"])."; }; - pci.vgaPassthrough = mkOption { - type = types.bool; - default = true; - description = '' - Route legacy VGA to the first passthrough device (x-vga=on), which a - guest needs in order to drive that card as its own display. - - Turn it off when the guest only forwards the device onward to a nested - guest: x-vga=on claims the VGA path the emulated adapter wants, and the - nested guest does its own routing anyway. - ''; - }; pci.romFile = mkOption { type = types.nullOr types.path; default = null; description = "GPU VBIOS ROM file for the first passthrough device. Required when GPU PCI ROM BAR doesn't expose the full VBIOS (common with AMD Navi+)."; }; - pci.viommu.enable = mkOption { - type = types.bool; - default = false; - description = '' - Give the guest a virtual Intel IOMMU, so a guest that is itself a - hypervisor can bind a passed-through device to vfio-pci and hand it on - to a nested guest. Without one the guest sees no IOMMU and cannot - re-assign anything it was given. - - Implies kernel-irqchip=split, which interrupt remapping requires and - which replaces the full in-kernel irqchip cpu.hideVirtualized asks for. - ''; - }; usb.hostDevices = mkOption { default = []; diff --git a/overlay.nix b/overlay.nix new file mode 100644 index 0000000..0f26929 --- /dev/null +++ b/overlay.nix @@ -0,0 +1,7 @@ +final: prev: +let + # Pin vmixLib to nixpkgs 25-11 so all VM images are built with a consistent toolchain + vmixPkgs = prev.v25-11 or prev; +in { + vmixLib = vmixPkgs.callPackage ./lib {}; +} \ No newline at end of file diff --git a/wip/claude-memory/MEMORY.md b/wip/claude-memory/MEMORY.md new file mode 100644 index 0000000..fd5116d --- /dev/null +++ b/wip/claude-memory/MEMORY.md @@ -0,0 +1,41 @@ +# vmix.nix Project Memory + +## Build Preferences +- Always use VNC display (`:1` / port 5901) when building Windows images so progress can be monitored +- Pass `vncDisplay = ":1"` to customizeImage templates for build monitoring +- Use `gvnccapture localhost:1 /tmp/screenshot.png` to take VNC screenshots (package: gtk-vnc) +- For VNC inside vmix namespace: `ip netns exec windows.vmix nix-shell -p gtk-vnc --run 'gvnccapture 127.0.0.1:1 /tmp/screenshot.png'` + +## Key Architecture +- Offline registry uses `ControlSet001` (not `CurrentControlSet`) for virt-win-reg merges +- Sysprep resets offline registry changes — RDP must be re-enabled in post-OOBE script +- TermService won't listen on port 3389 in Audit Mode without a password on Administrator +- `LimitBlankPasswordUse=0` alone is NOT sufficient for RDP in Audit Mode — password required +- OOBE AutoLogon `` in unattend XML is unreliable — set via `reg add` in post-oobe.cmd instead +- OOBE creates user with blank password regardless of unattend — set real password via `net user` in post-oobe.cmd +- `sc config` can fail silently for some services — use `reg add` to set `Start` value directly + +## RDP on Win10 IoT Enterprise LTSC 2021 +- **CRITICAL**: `rdpwd.sys` and `tdtcp.sys` don't exist in this Windows build (removed in 19041+) +- `termsrv.dll` version is `10.0.19041.1202` — not supported by RDPWrap v1.6.2 or community INI files +- TermService runs but never creates the `rdp-tcp` WinStation listener — no port 3389 +- The ISO (`en-us_windows_10_iot_enterprise_ltsc_2021_x64_dvd_257ad90f.iso`) has 2 indexes: + - Index 1: Windows 10 Enterprise LTSC 2021 + - Index 2: Windows 10 IoT Enterprise LTSC 2021 +- Product key `M7XTQ-FN8P6-TTKYV-9D4CC-J462D` = Enterprise LTSC (not IoT) +- MAS HWID activation switches edition to IoT Enterprise S (partial key YY74H) +- **TODO**: Either generate custom RDPWrap config for termsrv 10.0.19041.1202, use a different ISO, or use third-party RDP server + +## generalize.nix Changes +- `enableRDP` flag added — applies RDP settings in post-oobe.cmd (survives sysprep) +- AutoLogon fix: blank password in unattend, real password + AutoAdminLogon registry in post-oobe.cmd +- `LogonCount=999` for persistent AutoLogon +- SessionEnv + UmRdpService set to auto-start via `reg add` (Start=2) +- Firewall: `Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'` + `Set-NetFirewallRule -Profile Any` + +## labv2.nix junto Deployment +- vmix flake input rev is pinned in `flake.nix` — must update the URL to change versions +- Use `path:/storage/gitrepos/vmix.nix` for local dev, `git+https://...?rev=` for production +- `colmena apply-local` doesn't support `--override-input` +- DNS: `dns.resolver.useHostResolvConf = true` breaks when host uses systemd-resolved (127.0.0.53) — use explicit upstream like `1.1.1.1` +- QEMU Guest Agent socket at `/tmp/qga-win10.sock` — use from inside namespace diff --git a/wip/win10-update.session.md b/wip/win10-update.session.md new file mode 100644 index 0000000..60018ab --- /dev/null +++ b/wip/win10-update.session.md @@ -0,0 +1,530 @@ +# Windows Update Template - Full Development Session Log + +## Original Request +User wanted a reproducible way to update Windows images, inspired by https://massgrave.dev/update-windows-iso. The upstream Win10 LTSC 2021 ISO is stored in a git-lfs repo at `git.sagar.ch`. + +## Approach Evolution + +### Phase 1: ISO Update Approach (abandoned) +Initially explored creating an updated ISO by integrating cumulative updates. Considered: + +1. **UUP Dump approach**: The massgrave page links to uupdump.net which provides download scripts for building fresh ISOs from Microsoft's UUP (Unified Update Platform) files. The user received a bash script from UUP dump that: + - Uses `aria2c` to download UUP .cab files from Microsoft CDN + - Uses `cabextract`, `wimlib-imagex`, `chntpw` to build an ISO + - Uses `genisoimage`/`mkisofs` to create the final ISO + - Problem: downloads `core;professional` (Home/Pro), NOT LTSC + - Problem: download URLs contain auth tokens that expire — not reproducible + +2. **Offline DISM approach**: Considered creating a Nix derivation that: + - Boots a Windows worker VM from the existing upstream image + - Mounts the original ISO inside the VM + - Uses `DISM /Image` to service install.wim offline (mount WIM, apply .cab updates, unmount) + - Extracts the updated install.wim via guestfs + - Rebuilds the ISO with genisoimage on the Linux host + - Problem: very complex, requires managing WIM indexes, boot.wim, etc. + - Problem: needs a "worker" Windows VM just to run DISM + +3. **Offline .msu approach**: Considered downloading specific .msu files from Microsoft Update Catalog: + - Search catalog.update.microsoft.com for `cumulative update for windows 10 version 21H2 x64` + - Found latest: KB5087544 (May 2026), KB5088859 (.NET), KB2267602 (Defender) + - Problem: catalog uses JavaScript popups for downloads — can't scrape URLs + - Could use `curl` POST to `DownloadDialog.aspx` with update GUIDs, but GUIDs are hard to extract + - The download URLs from `catalog.s.download.windowsupdate.com` are stable (don't expire) but finding them requires browser interaction + +### Phase 2: customizeImage Template (adopted) +User said: "instead of iso, let's create a customizeImage template that basically updates the existing image and runs qcow2 compact on it" + +This is much simpler — apply updates to the running Windows image during Audit Mode, not to the ISO. + +### Phase 3: Online vs Offline Updates +Initially built the template with two modes: +- **Offline mode**: user provides `.msu`/`.cab` files as `fetchurl` derivations, applied via `DISM /Online /Add-Package` +- **Online mode**: triggers Windows Update service directly via COM API + +User said "just do online updates" — removed offline mode entirely. + +## What was built + +### New files +- `lib/images/windows/templates/essentials/windows-update.nix` — template that boots into Audit Mode, runs Windows Update via COM API, handles reboots automatically, compacts image + +### Modified files +- `lib/images/windows/helpers/customizeImage.nix` — added `compact`, `qemuTimeout` parameters (committed in `3b454b7` on master alongside other changes) +- `lib/images/windows/templates/default.nix` — wired `windowsUpdate` into `essentials` +- `lib/images/windows/win10/images.nix` — added `updated` step between `upstream` and `basic` +- `lib/images/windows/win11/images.nix` — same + +### New customizeImage parameters + +#### `compact ? false` +Added to `customizeImage.nix`. When true, runs `qemu-img convert -O qcow2` after the audit boot to flatten the COW chain into a standalone qcow2 with no backing file dependency. This is important for the update template because the updates add several GB of data to the COW overlay. + +Implementation in `builderCommand`: +```bash +${lib.optionalString compact '' +echo "=== vmix: compacting image ===" +qemu-img convert -O qcow2 ${resultImg} compact.qcow2 +mv compact.qcow2 ${resultImg} +''} +mv ${resultImg} $out +``` + +#### `qemuTimeout ? 1800` +Added to `customizeImage.nix`. Replaces the hardcoded `timeout 1800` in the QEMU boot command. The Windows Update template sets this to `7200` (2 hours) because update installation with reboots can take a long time. + +Both `timeout` invocations in the builder (primary and SDL-fallback) now use `${toString qemuTimeout}`. + +### How the template works + +The template is a function that takes `{ maxRounds ? 3 }` and returns a customizeImage-compatible attrset: + +```nix +{ + name = "windows-update"; + compact = true; + memSize = 4096; + qemuTimeout = 7200; + auditScript = "..."; +} +``` + +#### Audit script flow + +1. **Round tracking**: Uses `C:\vmix-update-round.txt` to track which round we're on across reboots. First run creates the file with "1", subsequent runs read and increment. + +2. **Service initialization**: + ```batch + net start wuauserv 2>nul + sc config wuauserv start= auto + reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul + reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul + ``` + The LTSC image may have update-blocking group policies. We delete them. We also wait 30 seconds on first round for the service to initialize and sync with Microsoft. + +3. **PowerShell COM API**: The core update logic uses `Microsoft.Update.Session`: + ```powershell + $session = New-Object -ComObject Microsoft.Update.Session + $searcher = $session.CreateUpdateSearcher() + $result = $searcher.Search('IsInstalled=0') + # ... accept EULAs, download, install ... + if ($installResult.RebootRequired) { exit 3010 } else { exit 0 } + ``` + - Exit code `3010` = reboot required + - Exit code `0` = no reboot needed (or no updates found) + - Exit code `1` = error (caught by try/catch) + - Per-update results are logged with HResult codes + +4. **Component cleanup**: After updates, runs `dism /Online /Cleanup-Image /StartComponentCleanup /ResetBase /Quiet` to reclaim space from superseded update components. + +5. **Reboot handling** (if exit code 3010 and round < maxRounds): + ```batch + :: Copy script to survive wrapper deletion + copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul + :: Register for next boot + reg add "HKLM\...\RunOnce" /v vmixUpdate /d "cmd /c C:\vmix-update-continue.cmd" /f + :: Preserve Audit Mode + reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f + reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f + :: Reboot + shutdown /r /f /t 0 + exit /b + ``` + +6. **Final shutdown**: When all rounds complete (or no more updates), the script shuts down: + ```batch + del /q "%ROUND_FILE%" 2>nul + del /q "C:\vmix-update-continue.cmd" 2>nul + echo === vmix: Windows Update complete === + shutdown /s /f /t 10 /c "vmix: windows-update complete" + ``` + +### Pipeline integration + +#### win10/images.nix +```nix +ltsc = rec { + upstream = makeImage { ... }; + updated = customizeImage upstream (templates.essentials.windowsUpdate {}); + basic = customizeImageFold updated (with templates; [ ... ]); + # ... withApps, withAMDGPU ... +}; +laptopUpstream = makeImage { ... useAHCI = true; }; +laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {}); +laptopSlim = customizeImageFold laptopUpdated templates.bundles.laptopSlim; +laptop = customizeImageFold laptopUpdated templates.bundles.laptop; +``` + +#### win11/images.nix +Same pattern — `updated` step inserted between `upstream` and `basic`, `laptopUpdated` between `laptopUpstream` and `laptopSlim`/`laptop`. + +### Usage examples +```nix +# Online mode (default) - triggers Windows Update service +essentials.windowsUpdate {} +essentials.windowsUpdate { maxRounds = 5; } + +# In image pipeline +updated = customizeImage upstream (templates.essentials.windowsUpdate {}); +basic = customizeImageFold updated [ ... ]; + +# Override VNC display and disable compact for debugging +vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; compact = false; }) +``` + +## Detailed Test Log + +### Build 1: First attempt (no VNC, wrong attr path) +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + in vmixLib.images.win10.ltsc.updated +' +``` +**Result**: Error — `attribute 'images' missing`. The correct path is `vmixLib.windows.images.win10.ltsc.updated`, not `vmixLib.images.win10.ltsc.updated`. + +### Build 2: Correct path, VNC :1, original script (no wuauserv start) +```bash +nix build ... --expr ' + let vmixLib = ...; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {}; + in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":1"; }) +' +``` +**Result**: Build "succeeded" but image size identical to upstream (5.03 GB vs 5.02 GB). The COM API found 0 updates because: +- Windows Update service (`wuauserv`) wasn't running in Audit Mode +- No time given for service to initialize +- Possible update-blocking policies active + +**Build log showed**: QEMU booted, script ran, shut down — no errors visible in nix log (VNC output isn't captured). + +### Build 3: Added wuauserv start, policy removal, 30s wait +Updated `windows-update.nix` to add: +```batch +net start wuauserv 2>nul +sc config wuauserv start= auto +reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul +reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul +timeout /t 30 /nobreak >nul +``` + +Also added EULA acceptance and try/catch error handling to the PowerShell block. + +**Build with VNC :55, chained virtio tools first**: +```bash +nix build ... --expr ' + let vmixLib = ...; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + withVirtio = vmixLib.windows.customizeImage upstream vmixLib.windows.templates.essentials.virtioTools; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {}; + in vmixLib.windows.customizeImage withVirtio (windowsUpdate // { vncDisplay = ":55"; compact = false; }) +' +``` + +**VNC observations** (screenshots taken with `gvnccapture localhost:55 /tmp/screenshot.png`): + +- **T+2min**: Boot screen "Please wait" +- **T+3min**: CMD window showing: + ``` + === vmix audit: windows-update === + === vmix: Windows Update round 1 of 3 === + The Windows Update service is starting. + The Windows Update service was started successfully. + [SC] ChangeServiceConfig SUCCESS + Waiting for Windows Update service to initialize... + Searching for updates... + ``` +- **T+7min**: Found 6 updates: + ``` + Found 6 updates + - 2022-02 Cumulative Update Preview for .NET Framework 3.5 and 4.8 for Windows 10 Version 21H2 for x64 (KB5010472) + - Microsoft .NET Framework 4.8.1 for Windows 10 Version 21H2 for x64 (KB5011048) + - Windows Malicious Software Removal Tool x64 - v5.141 (KB890830) + - 2026-05 Cumulative Update for .NET Framework 3.5, 4.8 and 4.8.1 for Windows 10 Version 21H2 for x64 (KB5088859) + - Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.451.326.0) - Current Channel (Broad) + - 2026-05 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5087544) + Downloading... + ``` +- **T+12min**: "Installing..." +- **T+20min through T+55min**: Still "Installing..." — KB5087544 is a massive cumulative update spanning Oct 2021 → May 2026 +- **T+58min**: Sysprep dialog showing on desktop — the machine rebooted after update install and landed in Audit Mode desktop, but the round 2 script didn't run + +**Issue discovered**: The wrapper script (`vmix-audit-wrapper.cmd`) deletes `C:\vmix-audit-script.cmd` after the audit script returns but before the reboot completes. The RunOnce entry points to the deleted file. + +### Build 4: Added script copy fix + shutdown fix + +Updated script to: +1. Copy itself to `C:\vmix-update-continue.cmd` before rebooting +2. Register `cmd /c C:\vmix-update-continue.cmd` in RunOnce (not the original path) +3. Always call `shutdown /s /f /t 10` when done (handles both wrapper and RunOnce invocation) + +**Same build command as Build 3.** + +**VNC observations**: +- **T+3min**: Round 1 started, same 6 updates found +- **T+7min**: Downloading... +- **T+12min**: Installing... +- **T+55min**: TianoCore UEFI boot screen — machine rebooted! +- **T+57min**: "Working on updates — 90% complete" — Windows finalizing update installation after reboot +- **T+62min**: "Working on updates — 19% complete" (different counter — this is the post-reboot finalization) +- **T+70min**: Sysprep dialog... but NO round 2 script running + +**Issue discovered**: After reboot, Windows exited Audit Mode and entered OOBE ("Choose your keyboard layout" screen) instead of staying in Audit Mode. The cumulative update reset the Audit Mode flags during its finalization pass. + +Wait — actually on this build we saw the Sysprep dialog (which IS Audit Mode). The issue was the RunOnce not firing. On a subsequent build, we saw the keyboard layout screen (OOBE). The behavior is inconsistent. + +### Build 5: Added Audit Mode preservation + +Added registry keys before reboot to preserve Audit Mode: +```batch +reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f +reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f +``` + +**Same build command. VNC observations**: +- **T+3min**: Round 1 started, same 6 updates found +- **T+70min**: Still on "Installing..." — round 1 didn't finish in 70 min on this machine +- **T+100min**: "Working on updates — 19% complete" — rebooted, finalizing +- **T+110min**: "Choose your keyboard layout" — OOBE screen again! + +**Session ended here** — the Audit Mode preservation fix hasn't been verified as working yet. The machine was moved to a faster machine for continued testing. + +## Detailed Issue Analysis + +### Issue 1: Windows Update service not running +**Root cause**: In Audit Mode, the Windows Update service (`wuauserv`) has `Start=3` (manual) and isn't auto-started. The COM API requires the service to be running to search for updates. + +**Fix**: Explicitly start the service and set it to auto-start: +```batch +net start wuauserv 2>nul +sc config wuauserv start= auto +``` + +Also remove any group policies that block updates (LTSC may have these pre-configured): +```batch +reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul +reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul +``` + +And wait 30 seconds for the service to initialize and sync with Microsoft servers on first round. + +### Issue 2: Wrapper deletes script before reboot completes +**Root cause**: The `customizeImage.nix` wrapper script flow: +``` +call C:\vmix-audit-script.cmd ← our update script +del /q C:\vmix-audit-script.cmd ← DELETE happens here +shutdown /s /t 5 ← may override our shutdown /r +del /q C:\vmix-audit-wrapper.cmd +``` + +When our script calls `shutdown /r /f /t 0` and then `exit /b`, control returns to the wrapper. The wrapper deletes the script file. Even though `shutdown /r /t 0` was called, the batch file continues executing and the delete happens before the system actually reboots. + +The RunOnce entry points to `C:\vmix-audit-script.cmd` which no longer exists after reboot. + +Additionally, the wrapper's `shutdown /s /t 5` may override our `shutdown /r /t 0` (though in practice the `/t 0` reboot usually wins). + +**Fix**: Copy the script to a separate path before rebooting: +```batch +copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul +reg add "HKLM\...\RunOnce" /v vmixUpdate /d "cmd /c C:\vmix-update-continue.cmd" /f +``` + +The wrapper only knows about `C:\vmix-audit-script.cmd` and `C:\vmix-audit-wrapper.cmd`. It doesn't know about `C:\vmix-update-continue.cmd`, so that file survives. + +### Issue 3: Audit Mode lost after update reboot +**Root cause**: Windows Audit Mode is maintained by registry keys: +- `HKLM\SYSTEM\Setup\Status\AuditBoot` (AuditBoot = 1) +- `HKLM\SYSTEM\Setup` (AuditInProgress = 1) + +Some cumulative updates include "specialize" or "generalize" passes during their finalization that can clear these keys, causing Windows to transition from Audit Mode to OOBE on the next boot. + +**Fix**: Explicitly set the Audit Mode registry keys right before rebooting: +```batch +reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f +reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f +``` + +**Status**: NOT YET VERIFIED. The last build with this fix was still in the install phase when the session ended. The fix may or may not be sufficient — some updates may clear these keys AFTER the reboot during the "Working on updates X% complete" phase, which would happen after our registry writes. + +**Alternative approaches if the fix doesn't work**: +1. Use `C:\Windows\System32\Sysprep\sysprep.exe /audit /reboot /quiet` instead of `shutdown /r` — this explicitly tells Windows to re-enter Audit Mode +2. Set up a `SetupComplete.cmd` or `Specialize` unattend pass that forces Audit Mode +3. Use a scheduled task instead of RunOnce (scheduled tasks persist across mode transitions) +4. Accept single-round updates only (`maxRounds = 1`) — no reboot needed if updates don't require it + +### Issue 4: No shutdown after round 2 +**Root cause**: When the script is invoked via RunOnce (round 2+), it runs directly — not through the wrapper. The wrapper is what normally calls `shutdown /s /t 5` after the script completes. Without the wrapper, the script finishes and the machine just sits at the Audit Mode desktop indefinitely (until the 2-hour QEMU timeout). + +**Fix**: The script itself calls `shutdown /s /f /t 10` when all rounds are complete. This is harmless when called from the wrapper (two shutdown commands — the second one either fails silently or is a no-op since shutdown is already pending). + +## All Build Commands Used + +### Quick evaluation (check attribute paths) +```bash +nix eval --impure --expr ' + let vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + in builtins.attrNames vmixLib.windows.images.win10.ltsc +' +``` + +### Build updated image directly (no VNC, with compact) +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + in vmixLib.windows.images.win10.ltsc.updated +' +``` + +### Build with VNC monitoring on port 5901 (display :1) +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {}; + in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":1"; }) +' +``` + +### Build with virtio tools + VNC :55 + no compact (debugging) +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + withVirtio = vmixLib.windows.customizeImage upstream vmixLib.windows.templates.essentials.virtioTools; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {}; + in vmixLib.windows.customizeImage withVirtio (windowsUpdate // { vncDisplay = ":55"; compact = false; }) +' +``` + +### Build with more RAM (8GB) for faster installs +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {}; + in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; memSize = 8192; }) +' +``` + +### Build with more rounds +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + upstream = vmixLib.windows.images.win10.ltsc.upstream; + windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate { maxRounds = 5; }; + in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; }) +' +``` + +### Full pipeline test (upstream → updated → basic → generalize) +```bash +nix build --print-build-logs --impure --option sandbox relaxed --expr ' + let + vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux; + in vmixLib.windows.images.win10.ltsc.basic.generalize { + username = "User"; password = ""; hostname = "WIN-VM"; + vncDisplay = ":55"; + } +' +``` + +### VNC monitoring commands +```bash +# Take a screenshot +nix-shell -p gtk-vnc --run 'gvnccapture localhost:55 /tmp/screenshot.png' + +# Connect with a VNC viewer +vncviewer localhost:5955 + +# Check if QEMU is running +ps aux | grep 'qemu-system' | grep -v grep + +# Check nix build log for a store path +nix log /nix/store/HASH-windows-update-....qcow2 + +# Check image info +nix-shell -p qemu --run 'qemu-img info /nix/store/HASH-....qcow2' +``` + +## Image sizes observed +| Image | disk size | virtual size | +|-------|-----------|-------------| +| upstream (win10-ltsc-2021) | 5.02 GB | 64 GB | +| updated (killed build, round 1 only) | 8.33 GB | 64 GB | +| upstream (compacted, no updates) | 5.03 GB | 64 GB | + +## Updates found by Windows Update (Win10 LTSC 2021 → May 2026) +1. **2022-02 Cumulative Update Preview for .NET Framework 3.5 and 4.8** (KB5010472) +2. **Microsoft .NET Framework 4.8.1** for Windows 10 21H2 x64 (KB5011048) +3. **Windows Malicious Software Removal Tool x64 v5.141** (KB890830) +4. **2026-05 Cumulative Update for .NET Framework 3.5, 4.8 and 4.8.1** (KB5088859) +5. **Security Intelligence Update for Microsoft Defender Antivirus** (KB2267602, Version 1.451.326.0+) +6. **2026-05 Cumulative Update for Windows 10 Version 21H2** (KB5087544) — the big one, ~870 MB + +## Timing observations (4 vCPU, 4GB RAM machine) +- Nix evaluation: ~30 seconds +- VirtIO tools step (cached): instant +- Windows boot to Audit Mode desktop: ~60 seconds +- Windows Update search: ~2-3 minutes +- Download all 6 updates: ~3-5 minutes +- Install all updates (especially KB5087544): **50-70 minutes** +- Reboot + "Working on updates" finalization: ~10-15 minutes +- Total for round 1: ~70-90 minutes +- DISM cleanup: ~2-5 minutes +- qemu-img convert (compact): ~2-3 minutes + +## Remaining TODO (for next session on faster machine) +- [ ] **CRITICAL**: Verify the Audit Mode preservation fix works (AuditBoot + AuditInProgress registry keys) +- [ ] If Audit Mode fix doesn't work, try `sysprep /audit /reboot /quiet` instead of `shutdown /r` +- [ ] Test round 2 → round 3 flow (find additional updates after cumulative? likely Defender definition updates) +- [ ] Test with `compact = true` to verify final standalone image +- [ ] Test full pipeline: `upstream → updated → basic → generalize` +- [ ] Test win11 images +- [ ] Consider using 8GB RAM (`memSize = 8192`) for faster update installs +- [ ] Consider: should `windowsUpdate` go before or after `virtioTools`? Currently before in the pipeline, but the explicit build command chains virtio first for better I/O +- [ ] The template is impure (downloads from Microsoft during build) — this is intentional but should be documented +- [ ] Consider `maxRounds = 1` mode for builds where you only want non-reboot updates +- [ ] The `compact` step doesn't compress — consider adding `-c` flag to `qemu-img convert` for compressed qcow2 +- [ ] The wrapper's `shutdown /s /t 5` may still race with the script's `shutdown /r /t 0` — consider using `shutdown /a` (abort) before `shutdown /r` to cancel any pending shutdown + +## Architecture notes + +### How customizeImage works (for context) +1. Creates a COW overlay on the original image: `qemu-img create -f qcow2 -b ${originalImage} -F qcow2 disk.qcow2` +2. Optionally resizes: `qemu-img resize disk.qcow2 ${diskSize}` +3. Merges offline registry entries via `virt-win-reg --merge` +4. Injects audit script + wrapper via `virt-customize --upload` +5. Adds RunOnce registry entry for the wrapper +6. Boots QEMU with the image (user networking, UEFI, VirtIO or AHCI) +7. The wrapper runs the audit script, then shuts down +8. Optionally compacts: `qemu-img convert -O qcow2` +9. Moves result to `$out` + +### The wrapper problem +The wrapper (`vmix-audit-wrapper.cmd`) is designed for simple, single-boot templates: +```batch +call C:\vmix-audit-script.cmd +del /q C:\vmix-audit-script.cmd +shutdown /s /t 5 +del /q C:\vmix-audit-wrapper.cmd +``` + +This is fine for templates that don't reboot. But the Windows Update template needs multiple reboots, which conflicts with the wrapper's assumptions. The workarounds (copy script, self-shutdown) are necessary because modifying the wrapper would affect all templates. + +A future improvement might be to add a `multiboot` flag to customizeImage that changes the wrapper behavior for templates that need reboots. + +### Why QEMU user networking works for Windows Update +QEMU's `-nic user` (SLIRP) provides NAT networking. The guest gets DHCP and can reach the internet via the host. Windows Update uses HTTPS to Microsoft's servers, which works through NAT. No special firewall rules or port forwarding needed. + +### Why VirtIO tools are chained before updates (in test builds) +The upstream image uses VirtIO storage (`if=virtio`) but doesn't have VirtIO guest tools installed. The update template doesn't need guest tools to work, but having them improves: +- Disk I/O performance (VirtIO balloon, better driver) +- Memory management +- Guest agent for monitoring + +In the pipeline (`win10/images.nix`), updates are applied directly to `upstream` without virtio tools, because virtio tools installation is part of the `basic` step. For testing, we chain them explicitly.