Compare commits

..

3 commits

Author SHA1 Message Date
b6a080af4b WIP: add Windows Update template with online COM API updates
Add essentials.windowsUpdate template that boots Audit Mode, uses the
Windows Update COM API to search/download/install all available updates
(cumulative, .NET, Defender), handles multi-round reboots with Audit
Mode preservation, and compacts the image afterward.

Known issues being worked:
- Audit Mode preservation after update reboot needs verification
- Install takes ~60-90 min with 4GB RAM on slow machines

Includes full session notes in wip/ with detailed test log, build
commands, issue analysis, timing data, and Claude memory files.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-06-09 13:17:27 +05:30
f33b8e7ce3 WIP: add Windows Update template with online COM API updates
Add essentials.windowsUpdate template that boots Audit Mode, uses the
Windows Update COM API to search/download/install all available updates
(cumulative, .NET, Defender), handles multi-round reboots with Audit
Mode preservation, and compacts the image afterward.

Known issues being worked:
- Audit Mode preservation after update reboot needs verification
- Install takes ~60-90 min with 4GB RAM on slow machines

See wip/win10-update.session.md for full context and TODOs.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-06-09 10:31:08 +05:30
3b454b749a switch from HWID to TSforge activation
- Switch MAS from /HWID to /Z-Windows (TSforge ZeroCID) which is
  hardware-independent and survives VM migration
- Re-install product key and restart SPP service before TSforge
  to restore licensing state after sysprep
- Add nicModel option to customizeImage and generalize for images
  without VirtIO drivers
- Update MAS activation script to latest version

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-06-09 10:06:41 +05:30
19 changed files with 744 additions and 860 deletions

View file

@ -15,12 +15,9 @@
lib = pkgs.lib; lib = pkgs.lib;
vmixLib = import ./lib { inherit pkgs lib system; }; vmixLib = import ./lib { inherit pkgs lib system; };
in { in {
overlays.default = final: prev: { inherit vmixLib; }; overlays.default = import ./overlay.nix;
nixosModules.default = { config, pkgs, lib, ... }: { nixosModules.default = import ./module.nix;
imports = [ ./nixos/default.nix ];
config.nixpkgs.overlays = [ self.overlays.default ];
};
lib.${system} = vmixLib; lib.${system} = vmixLib;

View file

@ -50,18 +50,11 @@ with scriptsNFiles;
# proxmox makes it very hard to manually add interfaces directly on /etc/network/interfaces while the pve services are not running # proxmox makes it very hard to manually add interfaces directly on /etc/network/interfaces while the pve services are not running
# it also doesn't pick up files in interfaces.d # it also doesn't pick up files in interfaces.d
# so manually do that via service after boot # so manually do that via service after boot
# After= must live in [Unit] — in [Service] systemd ignores it, leaving the
# merge/ifreload racing networking.service (and ifreload fails outright if it
# runs before /run/network exists, see ifupdown2#276).
mergeNetIfacesDService = pkgs.writeText "manual-net-ifaces.d.service" '' mergeNetIfacesDService = pkgs.writeText "manual-net-ifaces.d.service" ''
[Unit]
After = networking.service
Wants = networking.service
[Service] [Service]
Type = oneshot Type = oneshot
ExecStartPre = /bin/mkdir -p /run/network
ExecStart = /bin/bash -c "cat /etc/network/interfaces.d/* >> /etc/network/interfaces; rm /etc/network/interfaces.d/*; ifreload -a;" ExecStart = /bin/bash -c "cat /etc/network/interfaces.d/* >> /etc/network/interfaces; rm /etc/network/interfaces.d/*; ifreload -a;"
After = network.target
[Install] [Install]
WantedBy = multi-user.target WantedBy = multi-user.target

View file

@ -3,7 +3,6 @@ let
windows = rec { windows = rec {
drivers = import ./drivers { inherit pkgs system; }; drivers = import ./drivers { inherit pkgs system; };
makeFilesISO = (import ./helpers/makeFilesISO.nix) { inherit pkgs; }; makeFilesISO = (import ./helpers/makeFilesISO.nix) { inherit pkgs; };
makeConfigMedium = (import ./helpers/makeConfigMedium.nix) { inherit pkgs lib makeFilesISO; };
customizeImage = (import ./helpers/customizeImage.nix) { inherit pkgs lib; }; customizeImage = (import ./helpers/customizeImage.nix) { inherit pkgs lib; };
customizeImageFold = builtins.foldl' customizeImage; customizeImageFold = builtins.foldl' customizeImage;
templates = (import ./templates) { inherit pkgs lib system drivers makeFilesISO; }; templates = (import ./templates) { inherit pkgs lib system drivers makeFilesISO; };
@ -15,20 +14,14 @@ let
win10 = (import ./win10) { inherit pkgs lib system windows; }; win10 = (import ./win10) { inherit pkgs lib system windows; };
win11 = (import ./win11) { inherit pkgs lib system windows; }; win11 = (import ./win11) { inherit pkgs lib system windows; };
# Recursively add .generalize and .seal to every derivation leaf in the tree # Recursively add .generalize to every derivation leaf in the image tree
addGeneralize = val: addGeneralize = val:
if val ? _vmixOsType then if val ? _vmixOsType then
val // { val // { generalize = args:
generalize = args: let
let templateArgs = builtins.removeAttrs args [ "vncDisplay" ];
templateArgs = builtins.removeAttrs args [ "vncDisplay" ]; displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; };
displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; }; in windows.customizeImage val (windows.templates.generalize templateArgs // displayArgs);
in windows.customizeImage val (windows.templates.generalize templateArgs // displayArgs);
seal = args:
let
templateArgs = builtins.removeAttrs args [ "vncDisplay" ];
displayArgs = lib.optionalAttrs (args ? vncDisplay) { inherit (args) vncDisplay; };
in windows.customizeImage val (windows.templates.seal templateArgs // displayArgs);
} }
else if builtins.isAttrs val then else if builtins.isAttrs val then
lib.mapAttrs (_: addGeneralize) val lib.mapAttrs (_: addGeneralize) val

View file

@ -29,12 +29,6 @@
compact ? false, compact ? false,
# QEMU timeout in seconds (default 30 min, increase for Windows Update) # QEMU timeout in seconds (default 30 min, increase for Windows Update)
qemuTimeout ? 1800, qemuTimeout ? 1800,
# Blank disk attached for the Audit Mode boot, e.g. { size = "100G"; }.
# Windows sees it as disk 1, which is what lets a template partition it and
# relocate profiles onto it in that same boot instead of deferring OOBE to
# real hardware. Emitted as the derivation's `data` output, so whatever the
# template writes to it survives the build.
extraDisk ? null,
}: }:
let let
originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name); originalImageName = lib.strings.removeSuffix "-vmix" (lib.strings.removeSuffix ".qcow2" originalImage.name);
@ -73,11 +67,6 @@
]); ]);
cdromArgs = lib.concatMapStringsSep " \\\n " (cd: "-drive file=${cd},media=cdrom,readonly=on") cdroms; cdromArgs = lib.concatMapStringsSep " \\\n " (cd: "-drive file=${cd},media=cdrom,readonly=on") cdroms;
extraDiskImg = "./extra.qcow2";
extraDiskArgs = lib.optionalString (extraDisk != null)
(if isAHCI
then "-drive file=${extraDiskImg},format=qcow2,if=none,id=disk1 -device ide-hd,drive=disk1"
else "-drive file=${extraDiskImg},format=qcow2,if=virtio");
displayArg = if vncDisplay != null then "-vnc ${vncDisplay}" else null; displayArg = if vncDisplay != null then "-vnc ${vncDisplay}" else null;
@ -99,11 +88,7 @@
VMIX_DISPLAY="-nographic" VMIX_DISPLAY="-nographic"
${lib.optionalString (vncDisplay != null) ''VMIX_DISPLAY="-vnc ${vncDisplay}"''} ${lib.optionalString (vncDisplay != null) ''VMIX_DISPLAY="-vnc ${vncDisplay}"''}
${lib.optionalString (vncDisplay == null) '' ${lib.optionalString (vncDisplay == null) ''
# find, not a glob: under nullglob a non-matching /tmp/.vmix-display-* VMIX_DF=$(ls -t /tmp/.vmix-display-* 2>/dev/null | head -1)
# disappears entirely, leaving `ls -t` to list the build directory and
# hand back nix's own env-vars dump. Exporting that as DISPLAY bloats
# the environment until every exec dies with E2BIG.
VMIX_DF=$(find /tmp -maxdepth 1 -type f -name '.vmix-display-*' -printf '%T@ %p\n' 2>/dev/null | sort -rn | head -1 | cut -d' ' -f2-)
if [ -n "$VMIX_DF" ]; then if [ -n "$VMIX_DF" ]; then
export DISPLAY=$(sed -n '1p' "$VMIX_DF") export DISPLAY=$(sed -n '1p' "$VMIX_DF")
export XAUTHORITY=$(sed -n '2p' "$VMIX_DF") export XAUTHORITY=$(sed -n '2p' "$VMIX_DF")
@ -124,7 +109,6 @@
then "-drive file=${resultImg},format=qcow2,if=none,id=disk0 -device ide-hd,drive=disk0" then "-drive file=${resultImg},format=qcow2,if=none,id=disk0 -device ide-hd,drive=disk0"
else "-drive file=${resultImg},format=qcow2,if=virtio"} \ else "-drive file=${resultImg},format=qcow2,if=virtio"} \
${cdromArgs} \ ${cdromArgs} \
${extraDiskArgs} \
-nic user,model=${if nicModel != null then nicModel else if isAHCI then "e1000" else "virtio-net-pci"}" -nic user,model=${if nicModel != null then nicModel else if isAHCI then "e1000" else "virtio-net-pci"}"
timeout ${toString qemuTimeout} qemu-system-x86_64 $VMIX_DISPLAY $QEMU_ARGS || \ timeout ${toString qemuTimeout} qemu-system-x86_64 $VMIX_DISPLAY $QEMU_ARGS || \
@ -143,10 +127,6 @@
# create resulting image backed by original image # create resulting image backed by original image
qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg} qemu-img create -f qcow2 -b ${originalImage} -F qcow2 ${resultImg}
[ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize} [ -n "${diskSize}" ] && qemu-img resize ${resultImg} ${diskSize}
${lib.optionalString (extraDisk != null) ''
echo "=== vmix: creating extra disk (${extraDisk.size}) ==="
qemu-img create -f qcow2 ${extraDiskImg} ${extraDisk.size}
''}
${virtWinRegMerge} ${virtWinRegMerge}
${auditBootCommands} ${auditBootCommands}
${lib.optionalString compact '' ${lib.optionalString compact ''
@ -155,14 +135,10 @@
mv compact.qcow2 ${resultImg} mv compact.qcow2 ${resultImg}
''} ''}
mv ${resultImg} $out mv ${resultImg} $out
${lib.optionalString (extraDisk != null) "mv ${extraDiskImg} $data"}
''; '';
builtImage = pkgs.runCommand customImageName ({ builtImage = pkgs.runCommand customImageName ({
nativeBuildInputs = with pkgs; [ qemu perl guestfs-tools ]; nativeBuildInputs = with pkgs; [ qemu perl guestfs-tools ];
requiredSystemFeatures = [ "kvm" ]; requiredSystemFeatures = [ "kvm" ];
} // lib.optionalAttrs impure { __noChroot = true; } } // lib.optionalAttrs impure { __noChroot = true; }) builderCommand;
# A second output rather than a directory, so ${image} keeps meaning the OS
# qcow2 for every existing consumer and the fold can still back onto it.
// lib.optionalAttrs (extraDisk != null) { outputs = [ "out" "data" ]; }) builderCommand;
in in
builtImage // { _vmixOsType = "windows"; useAHCI = isAHCI; } builtImage // { _vmixOsType = "windows"; useAHCI = isAHCI; }

View file

@ -1,59 +0,0 @@
# Per-VM config medium for a sealed Windows image (see templates.seal).
#
# A sealed image carries no per-VM data. The values that differ between VMs --
# hostname, the static address the guest asserts, timezone, desktop tint -- are
# written here as a PowerShell data file and packed into a tiny ISO. config.nix
# attaches it as a read-only CD-ROM; the image's baked first-boot scripts
# (vmix-load-config.cmd finds it, then dot-source it) apply the values. So one
# sealed store path is shared by every VM, and only this cheap ISO is per-VM.
#
# Usage:
# makeConfigMedium {
# name = "win-config";
# hostname = "panda-win";
# staticIP = { address = "10.10.10.26"; prefixLength = 24;
# gateway = "10.10.10.1"; dns = [ "10.10.10.1" ]; };
# timezone = "E. South America Standard Time";
# bgColor = "#856558";
# }
{ pkgs, lib, makeFilesISO, ... }:
{
name ? "vmix-config",
hostname ? "",
# The per-VM account. The sealed image carries a generic bootstrap account
# (only there to carry OOBE); on first boot this real account is created from
# here, gets the SID-bound profile on D:\Users\<username>, and the bootstrap
# is retired. Distinct per VM -- nothing about the account is shared/baked.
username ? "",
password ? "",
# { address; prefixLength; gateway; dns = [ ... ]; }
staticIP ? null,
timezone ? null,
# Solid desktop background as a hex string, e.g. "#856558". Converted to the
# registry's decimal "R G B" on the target, in vmix-apply-config.ps1.
bgColor ? null,
}:
let
dnsList = lib.optionalString (staticIP != null)
(lib.concatMapStringsSep "," (s: "'${s}'") staticIP.dns);
# Consumed by dot-sourcing (. C:\vmix-config.ps1), so it only assigns
# variables. Anything not set here is simply absent, and the baked scripts
# guard on that ($VmixIpAddress being null skips the static-IP assignment).
configPs1 = pkgs.writeText "vmix-config.ps1" ''
# vmix per-VM config -- generated, read by the sealed image's baked scripts.
$VmixHostname = '${hostname}'
${lib.optionalString (username != "") "$VmixUsername = '${username}'"}
${lib.optionalString (username != "") "$VmixPassword = '${password}'"}
${lib.optionalString (staticIP != null) ''
$VmixIpAddress = '${staticIP.address}'
$VmixPrefixLength = ${toString staticIP.prefixLength}
$VmixGateway = '${staticIP.gateway}'
$VmixDns = @(${dnsList})''}
${lib.optionalString (timezone != null) "$VmixTimeZone = '${timezone}'"}
${lib.optionalString (bgColor != null) "$VmixBgColor = '${bgColor}'"}
'';
in
# makeFilesISO strips the store-hash prefix, so this lands at the ISO root as
# exactly vmix-config.ps1 -- which is what vmix-load-config.cmd scans for.
makeFilesISO { inherit name; files = [ configPs1 ]; }

View file

@ -49,11 +49,7 @@ let
VMIX_DISPLAY="-nographic" VMIX_DISPLAY="-nographic"
${lib.optionalString (displayArg != null) ''VMIX_DISPLAY="${displayArg}"''} ${lib.optionalString (displayArg != null) ''VMIX_DISPLAY="${displayArg}"''}
${lib.optionalString (displayArg == null) '' ${lib.optionalString (displayArg == null) ''
# find, not a glob: under nullglob a non-matching /tmp/.vmix-display-* VMIX_DF=$(ls -t /tmp/.vmix-display-* 2>/dev/null | head -1)
# disappears entirely, leaving `ls -t` to list the build directory and
# hand back nix's own env-vars dump. Exporting that as DISPLAY bloats the
# environment until every exec dies with E2BIG.
VMIX_DF=$(find /tmp -maxdepth 1 -type f -name '.vmix-display-*' -printf '%T@ %p\n' 2>/dev/null | sort -rn | head -1 | cut -d' ' -f2-)
if [ -n "$VMIX_DF" ]; then if [ -n "$VMIX_DF" ]; then
export DISPLAY=$(sed -n '1p' "$VMIX_DF") export DISPLAY=$(sed -n '1p' "$VMIX_DF")
export XAUTHORITY=$(sed -n '2p' "$VMIX_DF") export XAUTHORITY=$(sed -n '2p' "$VMIX_DF")

View file

@ -20,6 +20,7 @@ in rec {
bestPerformance = import ./essentials/best-performance.nix args; bestPerformance = import ./essentials/best-performance.nix args;
clearFileAssociations = import ./essentials/clear-file-associations.nix args; clearFileAssociations = import ./essentials/clear-file-associations.nix args;
virtioDrivers = import ./essentials/virtio-drivers.nix args; virtioDrivers = import ./essentials/virtio-drivers.nix args;
windowsUpdate = import ./essentials/windows-update.nix args;
}; };
# Applications # Applications
@ -39,24 +40,6 @@ in rec {
# Generalize (sysprep + OOBE). Pass seal=true for hardware deployment. # Generalize (sysprep + OOBE). Pass seal=true for hardware deployment.
generalize = import ./generalize.nix args; generalize = import ./generalize.nix args;
# Seal: a generic OOBE-deferred base whose per-VM data is not baked but
# delivered at deploy time on a config medium (helpers/makeConfigMedium.nix).
# One sealed store path is shared by every VM; each VM's first boot mints its
# own SID and builds the whole profile on the relocated data volume (D:).
#
# The baked account is a generic bootstrap that only exists to carry OOBE to a
# logon -- the real, per-VM account (username/password) comes from the config
# medium, and the bootstrap is retired on the target. So nothing per-VM is
# baked. RDP and locale stay caller args.
seal = templateArgs: generalize ({
delayOobeRun = true;
configMedium = true;
username = "vmixsetup";
password = "vmixsetup";
profilesDirectory = "D:\\Users";
dataDisk = { driveLetter = "D"; label = "data"; };
} // templateArgs);
# Offline registry templates # Offline registry templates
reg = import ./registry args; reg = import ./registry args;

View file

@ -0,0 +1,114 @@
# Apply all available Windows Updates via the Windows Update COM API in Audit Mode.
# Handles reboots automatically — re-registers via RunOnce and continues updating.
# Compacts the image afterward to flatten the COW chain.
#
# Usage:
# essentials.windowsUpdate {}
# essentials.windowsUpdate { maxRounds = 5; }
{ pkgs, lib, ... }:
{ maxRounds ? 3 }:
{
name = "windows-update";
compact = true;
memSize = 4096;
qemuTimeout = 7200;
auditScript = ''
@echo off
setlocal
:: Track update round via a counter file
set "ROUND_FILE=C:\vmix-update-round.txt"
set "MAX_ROUNDS=${toString maxRounds}"
if exist "%ROUND_FILE%" (
set /p ROUND=<"%ROUND_FILE%"
) else (
set "ROUND=1"
)
echo === vmix: Windows Update round %ROUND% of %MAX_ROUNDS% ===
:: Ensure Windows Update service is running
net start wuauserv 2>nul
sc config wuauserv start= auto
:: Remove any update-blocking policies (LTSC may have these)
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul
:: Give the service time to initialize on first round
if "%ROUND%"=="1" (
echo Waiting for Windows Update service to initialize...
timeout /t 30 /nobreak >nul
)
:: Run Windows Update via PowerShell COM API
powershell -ExecutionPolicy Bypass -Command ^
"try {" ^
" $session = New-Object -ComObject Microsoft.Update.Session;" ^
" $searcher = $session.CreateUpdateSearcher();" ^
" Write-Host 'Searching for updates...';" ^
" $result = $searcher.Search('IsInstalled=0');" ^
" $count = $result.Updates.Count;" ^
" Write-Host \"Found $count updates\";" ^
" if ($count -eq 0) { exit 0 };" ^
" foreach ($u in $result.Updates) { Write-Host \" - $($u.Title)\" };" ^
" $updatesToInstall = New-Object -ComObject Microsoft.Update.UpdateColl;" ^
" foreach ($u in $result.Updates) {" ^
" if ($u.EulaAccepted -eq $false) { $u.AcceptEula() };" ^
" $updatesToInstall.Add($u) | Out-Null" ^
" };" ^
" $downloader = $session.CreateUpdateDownloader();" ^
" $downloader.Updates = $updatesToInstall;" ^
" Write-Host 'Downloading...';" ^
" $downloader.Download() | Out-Null;" ^
" $installer = $session.CreateUpdateInstaller();" ^
" $installer.Updates = $updatesToInstall;" ^
" Write-Host 'Installing...';" ^
" $installResult = $installer.Install();" ^
" Write-Host \"Result: $($installResult.ResultCode)\";" ^
" for ($i = 0; $i -lt $updatesToInstall.Count; $i++) {" ^
" $hr = $installResult.GetUpdateResult($i).HResult;" ^
" Write-Host \" $($updatesToInstall.Item($i).Title): code=$hr\"" ^
" };" ^
" if ($installResult.RebootRequired) { exit 3010 } else { exit 0 }" ^
"} catch {" ^
" Write-Host \"ERROR: $_\";" ^
" exit 1" ^
"}"
set "WU_EXIT=%ERRORLEVEL%"
echo Windows Update exit code: %WU_EXIT%
:: Cleanup component store
echo Cleaning up component store...
dism /Online /Cleanup-Image /StartComponentCleanup /ResetBase /Quiet 2>nul
:: Check if we need to reboot and continue
set /a "NEXT_ROUND=%ROUND%+1"
if "%WU_EXIT%"=="3010" (
if %ROUND% LSS %MAX_ROUNDS% (
echo Reboot required, scheduling round %NEXT_ROUND%...
echo %NEXT_ROUND% > "%ROUND_FILE%"
:: Copy script to a path the wrapper won't delete
copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v vmixUpdate /t REG_SZ /d "cmd /c C:\vmix-update-continue.cmd" /f
:: Preserve Audit Mode across reboot (updates can reset it)
reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f
:: Immediate reboot (preempts wrapper shutdown)
shutdown /r /f /t 0
exit /b
) else (
echo Max update rounds reached.
)
)
:: Done clean up and shutdown
del /q "%ROUND_FILE%" 2>nul
del /q "C:\vmix-update-continue.cmd" 2>nul
echo === vmix: Windows Update complete ===
shutdown /s /f /t 10 /c "vmix: windows-update complete"
'';
}

View file

@ -23,49 +23,9 @@ in
enableRDP ? false, enableRDP ? false,
# NIC model for the build VM (e.g. "e1000" for images without VirtIO drivers) # NIC model for the build VM (e.g. "e1000" for images without VirtIO drivers)
nicModel ? null, nicModel ? null,
# Static IPv4 for the guest's single NIC, applied from inside Windows:
# { address = "10.10.10.26"; prefixLength = 24; gateway = "10.10.10.1";
# dns = [ "10.10.10.1" ]; }
staticIP ? null,
# Relocate user profiles, e.g. "D:\\Users". Needs the volume to exist by the
# time specialize runs, which is what dataDisk arranges.
profilesDirectory ? null,
# Partition the non-OS disk and relocate user profiles onto it, e.g.
# { driveLetter = "D"; label = "data"; size = "100G"; }. The disk is attached
# during the build (see extraDisk in the returned set), so this is done and
# verified before the image ever reaches a host.
dataDisk ? null,
# Unified Write Filter: protect a volume by redirecting its writes to a
# disk-backed overlay held on another one, e.g.
# { protectedVolume = "C:"; swapfileVolume = "D:"; overlaySizeMB = 8192; }
writeFilter ? null,
# delayOobeRun = true: sysprep only, OOBE + activation on real hardware # delayOobeRun = true: sysprep only, OOBE + activation on real hardware
# delayOobeRun = false: sysprep + OOBE + activation in build VM # delayOobeRun = false: sysprep + OOBE + activation in build VM
delayOobeRun ? false, delayOobeRun ? false,
# configMedium = true: this is a generic sealed base whose per-VM data
# (hostname, static IP, timezone, desktop tint) is NOT baked. The target's
# first boot reads it off a small removable config CD (see makeConfigMedium)
# via baked finder/apply scripts. Implies the OOBE is deferred to the target,
# so it is only meaningful together with delayOobeRun = true. Lets one sealed
# store path be shared by every VM built from it.
configMedium ? false,
# Skip sysprep's SID reset (use /oobe without /generalize), so every rebuild
# of the layers above the cached base install carries the same machine SID --
# and therefore the same account SID. A profile kept on a persistent disk then
# matches on file ACLs, its NTUSER.DAT hive, and ProfileList across rebuilds,
# with no ownership fixups. As a side effect MountedDevices survives too, so
# the data disk keeps its drive letter without a boot-time reassign.
#
# Correct only for an image that is always this one machine; a fleet that
# deploys the same image to many hosts wants the default generalization.
keepMachineSid ? false,
# Known-Folder redirection: keep the SID-bound profile on C: (so /generalize
# can still randomize the SID per machine) but point the user's data folders
# at the persistent data disk, so files -- not per-user registry settings --
# survive an OS rebuild. e.g. { base = "D:\\UserData"; folders = [ "Desktop"
# "Documents" "Downloads" ]; }. Needs dataDisk to provide the volume, and is
# mutually exclusive with profilesDirectory.
folderRedirect ? null,
}: let }: let
# Convert "8e8cd8" hex to "142 140 216" decimal RGB for Windows registry # Convert "8e8cd8" hex to "142 140 216" decimal RGB for Windows registry
hexToRgbStr = hex: let hexToRgbStr = hex: let
@ -82,429 +42,9 @@ in
stripHash = s: lib.removePrefix "#" s; stripHash = s: lib.removePrefix "#" s;
bgRgb = if bgColor != null then hexToRgbStr (stripHash bgColor) else null; bgRgb = if bgColor != null then hexToRgbStr (stripHash bgColor) else null;
uwfProtected = if writeFilter != null then (writeFilter.protectedVolume or "C:") else "C:";
uwfSwapVolume = if writeFilter != null then (writeFilter.swapfileVolume or "D:") else "D:";
uwfOverlaySizeMB = if writeFilter != null then (writeFilter.overlaySizeMB or 8192) else 8192;
# Runs from RunOnce on the target's first boot rather than during the build,
# for two reasons: enabling the DISM feature needs a reboot before uwfmgr
# exists at all, and the overlay swapfile has to be created on the real data
# volume rather than on the build's throwaway copy of it.
#
# Order is forced by uwfmgr: create-swapfile is only accepted while the
# filter is off and the overlay is already in disk mode. The default disk
# overlay would otherwise sit at C:\uwfswap.sys, on the volume being
# protected. Enabling the filter itself only takes effect after a restart.
uwfConfigScript = pkgs.writeText "vmix-uwf-config.cmd" ''
@echo off
uwfmgr.exe overlay set-type disk
uwfmgr.exe overlay set-size ${toString uwfOverlaySizeMB}
uwfmgr.exe volume create-swapfile ${uwfSwapVolume}
uwfmgr.exe volume protect ${uwfProtected}
uwfmgr.exe filter enable
del /q C:\vmix-uwf-config.cmd 2>nul
shutdown /r /t 10 /c "vmix: activating the write filter"
'';
staticDnsList = lib.optionalString (staticIP != null)
(lib.concatMapStringsSep "," (s: "'${s}'") staticIP.dns);
# Its own file rather than inline in post-oobe.cmd: the command is long, and
# cmd's handling of quotes and pipes inside it is a needless hazard.
#
# Two things this has to get right. The adapter may not be up yet when
# FirstLogonCommands runs, so it is waited for rather than assumed. And the
# interface arrives DHCP-managed -- assigning an address without turning DHCP
# off first does not stick, which is how a VM meant to be at a fixed address
# ended up holding a lease instead.
# PowerShell in its own file: it grew a wait loop and a retry, which are no
# fun to keep correct inside a cmd one-liner.
#
# Two things it must survive. DHCP is turned off before the address is set,
# so any failure to set it strands the box with no address at all -- which is
# exactly what happened after an internal reboot, where a stale ARP entry for
# the address from the previous instance tripped duplicate-address detection
# and New-NetIPAddress threw. DadTransmits 0 turns that detection off so the
# static always binds, and the assignment is retried rather than fatal.
# Two shapes. Baked: the address is a build-time literal. configMedium: the
# address is read from C:\vmix-config.ps1 (dot-sourced), which the finder
# dropped there off the config CD -- so the same sealed script serves every
# VM. The wait/retry logic is identical either way.
staticIPAssign = if configMedium
then { addr = "$VmixIpAddress"; prefix = "$VmixPrefixLength"; gw = "$VmixGateway"; dns = "$VmixDns"; }
else { addr = "'${staticIP.address}'"; prefix = toString staticIP.prefixLength; gw = "'${staticIP.gateway}'"; dns = staticDnsList; };
staticIPScriptPs1 = pkgs.writeText "vmix-static-ip.ps1" ''
${lib.optionalString configMedium ''
if (-not (Test-Path C:\vmix-config.ps1)) { Write-Output 'vmix: no config yet'; exit 0 }
. C:\vmix-config.ps1
if (-not $VmixIpAddress) { Write-Output 'vmix: no static address in config'; exit 0 }
''}
$a = $null
for ($n = 0; $n -lt 30; $n++) {
$a = Get-NetAdapter -Physical | Where-Object Status -eq 'Up' | Sort-Object ifIndex | Select-Object -First 1
if ($a) { break }
Start-Sleep -Seconds 2
}
if (-not $a) { Write-Output 'vmix: no adapter came up'; exit 1 }
$i = $a.ifIndex
Set-NetIPInterface -InterfaceIndex $i -Dhcp Disabled -DadTransmits 0 -ErrorAction SilentlyContinue
Remove-NetIPAddress -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue
Remove-NetRoute -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue
$ok = $false
for ($k = 0; $k -lt 5 -and -not $ok; $k++) {
try {
New-NetIPAddress -InterfaceIndex $i -IPAddress ${staticIPAssign.addr} -PrefixLength ${staticIPAssign.prefix} -DefaultGateway ${staticIPAssign.gw} -ErrorAction Stop | Out-Null
$ok = $true
} catch {
Write-Output ('vmix: assign attempt ' + $k + ' failed: ' + $_.Exception.Message)
Start-Sleep -Seconds 2
Remove-NetIPAddress -InterfaceIndex $i -AddressFamily IPv4 -Confirm:$false -ErrorAction SilentlyContinue
}
}
if (-not $ok) { Write-Output 'vmix: could not set static address'; exit 1 }
Set-DnsClientServerAddress -InterfaceIndex $i -ServerAddresses ${staticIPAssign.dns}
New-NetFirewallRule -DisplayName 'ICMPv4 Echo' -Protocol ICMPv4 -IcmpType 8 -Direction Inbound -Action Allow -Profile Any -Enabled True -ErrorAction SilentlyContinue | Out-Null
Write-Output ('vmix: set ' + ${staticIPAssign.addr} + ' on ifIndex ' + $i)
'';
# Finder: the config CD's drive letter is unknown, so scan for the marker file
# and stage it on C: where the baked scripts expect it. Runs on the target's
# first boot (post-oobe), before the per-boot static-IP task needs it.
loadConfigScript = pkgs.writeText "vmix-load-config.cmd" ''
@echo off
for %%D in (E F G H I J K L M N O P Q R S T U V W X Y Z D) do (
if exist %%D:\vmix-config.ps1 (
copy /y %%D:\vmix-config.ps1 C:\vmix-config.ps1 >nul
goto :done
)
)
:done
'';
# Applies the per-VM config that is not an answer-file field: timezone, the
# desktop tint (per user, so run under the created account in post-oobe), and
# the machine rename. Rename is pending until the post-oobe reboot.
applyConfigScript = pkgs.writeText "vmix-apply-config.ps1" ''
if (-not (Test-Path C:\vmix-config.ps1)) { exit 0 }
. C:\vmix-config.ps1
if ($VmixTimeZone) { & tzutil /s "$VmixTimeZone" }
if ($VmixBgColor) {
$hex = ([string]$VmixBgColor).TrimStart('#')
$r = [Convert]::ToInt32($hex.Substring(0,2),16)
$g = [Convert]::ToInt32($hex.Substring(2,2),16)
$b = [Convert]::ToInt32($hex.Substring(4,2),16)
Set-ItemProperty 'HKCU:\Control Panel\Colors' -Name Background -Value "$r $g $b"
Set-ItemProperty 'HKCU:\Control Panel\Desktop' -Name WallPaper -Value ""
Set-ItemProperty 'HKCU:\Control Panel\Desktop' -Name WallpaperStyle -Value '0'
}
if ($VmixHostname -and $env:COMPUTERNAME -ne $VmixHostname) {
Rename-Computer -NewName $VmixHostname -Force -ErrorAction SilentlyContinue
}
'';
# Creates the real per-VM account from the config and hands the machine over
# to it. The sealed image bakes only a generic bootstrap account (${username})
# -- enough to carry OOBE to a logon so this can run -- and the real account
# is made here, on the target, from the CD. Autologon is switched to it and a
# one-shot cleanup is armed; the post-oobe reboot then lets the real account
# log in and build its own SID-bound profile on D:\Users\<username>, after
# which the bootstrap is retired. So the account, like the SID, is per-VM and
# nothing about it is shared or baked. Runs as the bootstrap user in post-oobe.
createUserScript = pkgs.writeText "vmix-create-user.ps1" ''
if (-not (Test-Path C:\vmix-config.ps1)) { exit 0 }
. C:\vmix-config.ps1
if (-not $VmixUsername) { exit 0 }
if ($VmixUsername -ieq '${username}') { exit 0 }
& net user $VmixUsername $VmixPassword /add
& net localgroup Administrators $VmixUsername /add
$w = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon'
Set-ItemProperty $w -Name AutoAdminLogon -Value '1'
Set-ItemProperty $w -Name DefaultUserName -Value $VmixUsername
Set-ItemProperty $w -Name DefaultPassword -Value $VmixPassword
Remove-ItemProperty $w -Name DefaultDomainName -ErrorAction SilentlyContinue
# Fires at the real account's first logon (HKLM RunOnce = next user to log
# on), i.e. after the reboot below, once the bootstrap is no longer in use.
Set-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce' `
-Name vmixFinalize -Value 'cmd /c C:\vmix-finalize.cmd' -Type String
'';
# Runs once as the real account (RunOnce, after the hand-over reboot), so the
# fresh machine SID and the real profile already exist. This is where activation
# belongs -- on that fresh SID, not the throwaway bootstrap's. It then finishes
# per-user setup, retires the bootstrap, unmounts the config CD for good, and
# wipes every vmix artifact off C:\ so the running machine carries no leftover
# setup files. Self-deletes last.
finalizeScript = pkgs.writeText "vmix-finalize.cmd" ''
@echo off
:: 1) Activate Windows on the real account's fresh SID (TSforge, offline).
cscript //nologo C:\Windows\System32\slmgr.vbs /ipk M7XTQ-FN8P6-TTKYV-9D4CC-J462D
cscript //nologo C:\Windows\System32\slmgr.vbs /rilc
net stop sppsvc /y 2>nul
net start sppsvc
ping -n 8 127.0.0.1 >nul
if exist C:\MAS_AIO.cmd ( echo. | call C:\MAS_AIO.cmd /Z-Windows )
if exist "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" (
if exist C:\MAS_AIO.cmd ( echo. | call C:\MAS_AIO.cmd /Ohook )
)
:: 2) Per-user desktop tint, now that the real account is logged in.
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-apply-config.ps1 >nul 2>&1
:: 3) Retire the bootstrap account and its profile (idle now).
powershell -NoProfile -ExecutionPolicy Bypass -Command "Get-CimInstance Win32_UserProfile | Where-Object { $_.LocalPath -like '*\${username}' } | Remove-CimInstance -ErrorAction SilentlyContinue"
net user ${username} /delete >nul 2>&1
:: 4) Unmount the config CD and keep it unmounted -- drop its letter and stop
:: the mount manager auto-lettering it (D: keeps its explicit assignment).
powershell -NoProfile -ExecutionPolicy Bypass -Command "Get-CimInstance Win32_Volume -Filter 'DriveType=5 AND DriveLetter IS NOT NULL' | ForEach-Object { $_.DriveLetter=$null; [void]($_ | Set-CimInstance) }"
> C:\Windows\Temp\vmix-am.txt echo automount disable
>> C:\Windows\Temp\vmix-am.txt echo automount scrub
diskpart /s C:\Windows\Temp\vmix-am.txt >nul 2>&1
del /q C:\Windows\Temp\vmix-am.txt 2>nul
:: 5) Wipe every vmix setup artifact from C:\.
del /q C:\MAS_AIO.cmd C:\vmix-config.ps1 C:\vmix-data-initialized 2>nul
del /q C:\vmix-load-config.cmd C:\vmix-apply-config.ps1 C:\vmix-create-user.ps1 2>nul
del /q C:\vmix-init-data-disk.cmd C:\vmix-data-profile.cmd C:\vmix-heal-profile.ps1 2>nul
del /q C:\vmix-static-ip.cmd C:\vmix-static-ip.ps1 2>nul
del /q C:\oobe-unattend.xml C:\post-oobe.cmd 2>nul
:: 6) Self-delete.
(goto) 2>nul & del "%~f0"
'';
# Thin launcher, so the scheduled task has a cmd to point at.
staticIPScript = pkgs.writeText "vmix-static-ip.cmd" ''
@echo off
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-static-ip.ps1 > C:\Windows\Temp\vmix-static-ip.log 2>&1
'';
dataDriveLetter = if dataDisk != null then (dataDisk.driveLetter or "D") else "D";
dataLabel = if dataDisk != null then (dataDisk.label or "data") else "data";
# ProfilesDirectory is only honoured when the volume it names already exists,
# and a freshly created zvol arrives RAW. Initializing the disk here, in the
# same specialize pass, brings it up before oobeSystem creates any profile.
#
# Idempotent, because specialize runs again on every sysprep: a RAW disk gets
# a GPT label, one full-size NTFS partition and the drive letter, while a disk
# that already holds data keeps it and only has its letter re-asserted. The
# OS disk is added to QEMU first and so is always disk 0.
initDataDiskScript = pkgs.writeText "vmix-init-data-disk.cmd" (if configMedium then ''
@echo off
:: Sealed-image variant. Two extra hazards over the baked path:
::
:: 1. The per-VM config rides an optical drive, and on the target's first
:: boot the raw data disk has no volume yet -- so Windows letters the CD
:: as ${dataDriveLetter}:, exactly where the profile volume must go. The
:: plain `if exist ${dataDriveLetter}:\` guard would then see the CD and
:: skip, leaving ProfilesDirectory pointed at read-only media. So a first
:: boot is tracked by a marker, not by the letter, and any occupant of
:: ${dataDriveLetter}: is moved aside before the data disk claims it.
:: 2. Left to Shell-Setup's FolderLocations, ProfilesDirectory can be
:: evaluated before this disk exists (unordered within specialize) and
:: silently fall back to C:. Setting it here, in the same step that just
:: created the volume, removes that race.
if exist C:\vmix-data-initialized goto :ensure
:: First boot: park whatever holds ${dataDriveLetter}: (the config CD) on Y:
:: so the data disk can take the letter. Harmless if the letter is free.
> C:\Windows\Temp\vmix-cd.txt echo select volume ${dataDriveLetter}
>> C:\Windows\Temp\vmix-cd.txt echo assign letter=Y noerr
diskpart /s C:\Windows\Temp\vmix-cd.txt > nul 2>&1
:: Lay disk 1 (the host zvol) out from scratch and give it the letter.
> C:\Windows\Temp\vmix-dd-init.txt echo select disk 1
>> C:\Windows\Temp\vmix-dd-init.txt echo clean
>> C:\Windows\Temp\vmix-dd-init.txt echo convert gpt
>> C:\Windows\Temp\vmix-dd-init.txt echo create partition primary
>> C:\Windows\Temp\vmix-dd-init.txt echo format fs=ntfs quick label="${dataLabel}"
>> C:\Windows\Temp\vmix-dd-init.txt echo assign letter=${dataDriveLetter}
diskpart /s C:\Windows\Temp\vmix-dd-init.txt
echo initialized > C:\vmix-data-initialized
goto :ensure
:ensure
:: The letter normally persists via MountedDevices; re-assert if it is gone.
if exist ${dataDriveLetter}:\ goto :profiledir
> C:\Windows\Temp\vmix-dd-assign.txt echo select disk 1
>> C:\Windows\Temp\vmix-dd-assign.txt echo select partition 1
>> C:\Windows\Temp\vmix-dd-assign.txt echo assign letter=${dataDriveLetter}
diskpart /s C:\Windows\Temp\vmix-dd-assign.txt > nul 2>&1
:profiledir
${lib.optionalString (profilesDirectory != null) ''
:: Point new profiles at the data volume, now that it exists. REG_EXPAND_SZ
:: to match Windows' own ProfilesDirectory type.
if exist ${dataDriveLetter}:\ (
if not exist "${profilesDirectory}" mkdir "${profilesDirectory}"
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList" /v ProfilesDirectory /t REG_EXPAND_SZ /d "${profilesDirectory}" /f > nul 2>&1
)''}
del /q C:\Windows\Temp\vmix-cd.txt C:\Windows\Temp\vmix-dd-init.txt C:\Windows\Temp\vmix-dd-assign.txt 2>nul
:done
'' else ''
@echo off
:: diskpart rather than the Storage cmdlets. New-Partition and
:: Format-Volume need services that are not up yet this early in
:: specialize, so they fail where Initialize-Disk succeeds -- which left
:: the disk carrying a GPT header and nothing else, and ProfilesDirectory
:: pointing at a volume that never existed.
if exist ${dataDriveLetter}:\ goto :done
:: The volume may already be laid out and merely unlettered, in which case
:: assigning is enough and cleaning would destroy the profile.
> C:\Windows\Temp\vmix-dd-assign.txt echo select disk 1
>> C:\Windows\Temp\vmix-dd-assign.txt echo select partition 1
>> C:\Windows\Temp\vmix-dd-assign.txt echo assign letter=${dataDriveLetter}
diskpart /s C:\Windows\Temp\vmix-dd-assign.txt > nul 2>&1
if exist ${dataDriveLetter}:\ goto :cleanup
:: Nothing there to keep, so lay the disk out from scratch.
> C:\Windows\Temp\vmix-dd-init.txt echo select disk 1
>> C:\Windows\Temp\vmix-dd-init.txt echo clean
>> C:\Windows\Temp\vmix-dd-init.txt echo convert gpt
>> C:\Windows\Temp\vmix-dd-init.txt echo create partition primary
>> C:\Windows\Temp\vmix-dd-init.txt echo format fs=ntfs quick label="${dataLabel}"
>> C:\Windows\Temp\vmix-dd-init.txt echo assign letter=${dataDriveLetter}
diskpart /s C:\Windows\Temp\vmix-dd-init.txt
:cleanup
del /q C:\Windows\Temp\vmix-dd-assign.txt C:\Windows\Temp\vmix-dd-init.txt 2>nul
:done
'');
# PowerShell in its own file, so neither cmd quoting nor Nix's '' need to be
# fought. If the account's real profile got backed up to a .bak key (the
# temporary-profile fallback), put it back: drop the temp key, rename .bak to
# the live SID, remove the temp directory, and drop a flag so the caller
# knows to reboot.
# Known-Folder GUIDs for the redirectable user folders.
knownFolderGuids = {
Desktop = "{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}";
Documents = "{FDD39AD0-238F-46AF-ADB4-6C85480369C7}";
Downloads = "{374DE290-123F-4565-9164-39C4925E467B}";
Pictures = "{33E28130-4E1E-4676-835A-98395C3BC476}";
Music = "{4BD8D571-6D19-48D3-BE97-422220080E43}";
Videos = "{18989B1D-99B5-455B-841C-AB7C74E4DDFC}";
Favorites = "{1777F761-68AD-4D8A-87BD-30B759FA33DD}";
};
redirectFolders = if folderRedirect != null
then (folderRedirect.folders or [ "Desktop" "Documents" "Downloads" "Pictures" "Music" "Videos" ])
else [ ];
redirectBase = if folderRedirect != null then (folderRedirect.base or "D:\\UserData") else "D:\\UserData";
# Per-user, run once per profile via Active Setup: point each known folder at
# its directory under the data volume. SHSetKnownFolderPath updates both the
# registration and the shell-folder registry; it does not move files, so a
# freshly created profile's empty C: folder is simply repointed at the D: one,
# which already holds this user's accumulated files after a rebuild.
folderRedirectPs1 = pkgs.writeText "vmix-redirect-folders.ps1" (lib.optionalString (folderRedirect != null) ''
$sig = @'
[DllImport("shell32.dll", CharSet=CharSet.Unicode)]
public static extern int SHSetKnownFolderPath(ref System.Guid rfid, uint dwFlags, System.IntPtr hToken, string pszPath);
'@
$kf = Add-Type -MemberDefinition $sig -Name KFP -Namespace Vmix -PassThru
$map = @{
${lib.concatMapStringsSep "\n " (f: "'${f}' = '${knownFolderGuids.${f}}'") redirectFolders}
}
foreach ($name in $map.Keys) {
$target = Join-Path '${redirectBase}' $name
New-Item -ItemType Directory -Force -Path $target -ErrorAction SilentlyContinue | Out-Null
$guid = [System.Guid]$map[$name]
[void]$kf::SHSetKnownFolderPath([ref]$guid, 0, [System.IntPtr]::Zero, $target)
}
'');
# Active Setup fires StubPath once per user at first logon -- including the
# fresh profile each generalized rebuild creates -- which is exactly when the
# redirection needs re-applying. Backslashes doubled for .reg.
activeSetupRegistry = lib.optionalString (folderRedirect != null) ''
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6f3b8c2a-1d4e-4f9a-b8c1-0a1b2c3d4e5f}]
@="vmix folder redirection"
"StubPath"="powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File C:\\vmix-redirect-folders.ps1"
"Version"="1"
'';
healProfileScript = pkgs.writeText "vmix-heal-profile.ps1" (lib.optionalString (profilesDirectory != null) ''
$pl = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList'
$bak = Get-ChildItem $pl -ErrorAction SilentlyContinue | Where-Object {
$_.PSChildName -like '*.bak' -and
(Get-ItemProperty $_.PSPath -ErrorAction SilentlyContinue).ProfileImagePath -eq '${profilesDirectory}\${username}'
} | Select-Object -First 1
if ($bak) {
$sid = $bak.PSChildName -replace '\.bak$'
Remove-Item (Join-Path $pl $sid) -Recurse -Force -ErrorAction SilentlyContinue
Rename-Item $bak.PSPath $sid -ErrorAction SilentlyContinue
Remove-Item '${profilesDirectory}\TEMP' -Recurse -Force -ErrorAction SilentlyContinue
New-Item -Path C:\Windows\Temp\vmix-profile-healed -ItemType File -Force | Out-Null
}
'');
# One onstart / SYSTEM script for whatever the data disk needs before logon:
# assign its letter, and then either heal a relocated profile that went
# temporary (profilesDirectory) or make the redirected data folders reachable
# by whatever account this rebuild created (folderRedirect). Both cannot apply
# at once -- a profile is either wholly on D: or only its data folders are.
bootDataProfileScript = pkgs.writeText "vmix-data-profile.cmd" ''
@echo off
${lib.optionalString (dataDisk != null) "call C:\\vmix-init-data-disk.cmd"}
${lib.optionalString (profilesDirectory != null) ''
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-heal-profile.ps1 > C:\Windows\Temp\vmix-data-profile.log 2>&1
if exist C:\Windows\Temp\vmix-profile-healed (
del /q C:\Windows\Temp\vmix-profile-healed
shutdown /r /t 5 /c "vmix: repaired relocated profile, restarting"
)
''}
${lib.optionalString (folderRedirect != null) ''
:: The redirected folders live under a per-user account whose SID changes on
:: every generalized rebuild, so grant the well-known Users group -- which
:: any account joins and which is SID-stable across machines -- inheritable
:: full control, and let the per-user redirect (Active Setup) point the known
:: folders here. Runs as SYSTEM, before any logon.
if not exist "${redirectBase}" mkdir "${redirectBase}"
${lib.concatMapStringsSep "\n " (f: ''if not exist "${redirectBase}\${f}" mkdir "${redirectBase}\${f}"'') redirectFolders}
icacls "${redirectBase}" /grant *S-1-5-32-545:(OI)(CI)F /t > C:\Windows\Temp\vmix-redirect-prep.log 2>&1
''}
'';
folderLocationsXml = lib.optionalString (profilesDirectory != null) ''
<!-- Profiles live on the data disk, so the OS disk stays disposable
and rebuilding it does not take the profile along -->
<FolderLocations>
<ProfilesDirectory>${profilesDirectory}</ProfilesDirectory>
</FolderLocations>'';
# ProfilesDirectory as an offline .reg merge, for the keepMachineSid path
# where the specialize pass (and its FolderLocations) does not run. virt-win-reg
# applies this before the Audit Mode boot, so it is in place when OOBE creates
# the account. Backslashes are doubled for .reg syntax.
profileListRegistry = lib.optionalString (keepMachineSid && profilesDirectory != null) ''
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList]
"ProfilesDirectory"="${builtins.replaceStrings [''\''] [''\\''] profilesDirectory}"
'';
dataDiskXml = lib.optionalString (dataDisk != null) ''
<!-- Runs during specialize, before the first profile is created -->
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64"
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
<RunSynchronous>
<RunSynchronousCommand wcm:action="add">
<Order>1</Order>
<Path>cmd /c C:\vmix-init-data-disk.cmd</Path>
<Description>vmix: initialize the data disk</Description>
</RunSynchronousCommand>
</RunSynchronous>
</component>'';
# Post-OOBE script: runs as the created user via FirstLogonCommands. # Post-OOBE script: runs as the created user via FirstLogonCommands.
postOobeScript = pkgs.writeText "post-oobe.cmd" '' postOobeScript = pkgs.writeText "post-oobe.cmd" ''
@echo off @echo off
${lib.optionalString configMedium ''
:: Stage the per-VM config off the removable CD, then apply the parts that
:: are not answer-file fields (timezone, desktop tint, machine rename). The
:: static address is left to the per-boot task registered below.
call C:\vmix-load-config.cmd
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-apply-config.ps1 > C:\Windows\Temp\vmix-apply-config.log 2>&1
''}
${lib.optionalString (!autoLogon) '' ${lib.optionalString (!autoLogon) ''
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon /f 2>nul reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v AutoAdminLogon /f 2>nul
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName /f 2>nul reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultUserName /f 2>nul
@ -541,7 +81,6 @@ in
powershell -Command "Get-AppxPackage *MicrosoftEdgeDevToolsClient* | Remove-AppxPackage -ErrorAction SilentlyContinue" powershell -Command "Get-AppxPackage *MicrosoftEdgeDevToolsClient* | Remove-AppxPackage -ErrorAction SilentlyContinue"
${lib.optionalString (!configMedium) ''
:: Re-install product key and licenses to restore activation IDs after sysprep :: Re-install product key and licenses to restore activation IDs after sysprep
cscript //nologo C:\Windows\System32\slmgr.vbs /ipk M7XTQ-FN8P6-TTKYV-9D4CC-J462D cscript //nologo C:\Windows\System32\slmgr.vbs /ipk M7XTQ-FN8P6-TTKYV-9D4CC-J462D
cscript //nologo C:\Windows\System32\slmgr.vbs /rilc cscript //nologo C:\Windows\System32\slmgr.vbs /rilc
@ -560,9 +99,6 @@ in
) )
) )
del /q C:\MAS_AIO.cmd 2>nul del /q C:\MAS_AIO.cmd 2>nul
''}
:: configMedium: activation is deferred to the boot-2 finalize, so it runs
:: on the real account's fresh SID. MAS_AIO.cmd is kept for it until then.
${lib.optionalString enableRDP '' ${lib.optionalString enableRDP ''
:: Enable RDP :: Enable RDP
@ -576,80 +112,14 @@ in
reg add "HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv" /v Start /t REG_DWORD /d 2 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv" /v Start /t REG_DWORD /d 2 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService" /v Start /t REG_DWORD /d 2 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService" /v Start /t REG_DWORD /d 2 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\TermService" /v Start /t REG_DWORD /d 2 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\TermService" /v Start /t REG_DWORD /d 2 /f
:: A VM reached over RDP must never suspend itself off the network. The
:: default Balanced plan sleeps after 15 min idle; switch to High
:: Performance and zero every idle timeout, and turn hibernate off.
powercfg /setactive SCHEME_MIN
powercfg /change standby-timeout-ac 0
powercfg /change standby-timeout-dc 0
powercfg /change hibernate-timeout-ac 0
powercfg /change hibernate-timeout-dc 0
powercfg /change monitor-timeout-ac 0
powercfg /hibernate off
''} ''}
${lib.optionalString (staticIP != null && !configMedium) ''
:: This VM's only NIC sits on a macvtap bridged to the host's LAN, so its
:: address is a LAN address that nothing hands out -- the guest asserts it.
:: Registered to run at every boot rather than applied here. OOBE runs in
:: the build VM, whose NIC is qemu user networking on another subnet with
:: another MAC -- so an address set now lands on an adapter that does not
:: exist on the real host. Windows sees the target's NIC as new hardware
:: and falls back to DHCP, which is exactly what happened. Per-boot also
:: survives the adapter being replaced again later.
schtasks /create /tn "vmix-static-ip" /tr "C:\vmix-static-ip.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f > nul 2>&1
''}
${lib.optionalString configMedium ''
:: configMedium (sealed images) run OOBE on the real target NIC, so the
:: address is set here once and left in the persistent store -- it survives
:: reboots on its own, no per-boot task and no script left on disk. Runs on
:: this bootstrap boot so the real account is already reachable on boot 2.
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-static-ip.ps1 > C:\Windows\Temp\vmix-static-ip.log 2>&1
''}
${lib.optionalString (dataDisk != null && !configMedium) ''
:: Ensures D: is assigned on every boot -- the image ships without a
:: persisted letter for the data disk -- and heals a profile that went
:: temporary before D: was ready. Onstart / SYSTEM, like the address task.
:: configMedium does not need this: the letter persists via MountedDevices
:: in the overlay after the first boot, so there is nothing to re-assert.
schtasks /create /tn "vmix-data-profile" /tr "C:\vmix-data-profile.cmd" /sc onstart /ru SYSTEM /rl HIGHEST /f > nul 2>&1
''}
${lib.optionalString (writeFilter != null) ''
:: Install the feature now, but defer configuring it: uwfmgr does not exist
:: until this has been through a reboot, and the swapfile belongs on the
:: real data volume, so RunOnce picks it up on the target's first boot.
dism /online /enable-feature /featurename:Client-UnifiedWriteFilter /all /norestart
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v "vmixUwf" /t REG_SZ /d "C:\vmix-uwf-config.cmd" /f
''}
${lib.optionalString keepMachineSid ''
:: /oobe without /generalize leaves the system set to re-run windeploy (OOBE)
:: on every boot -- shutting down here in a FirstLogonCommand cuts OOBE off
:: before it resets that state itself. Clear it, or the target boots into a
:: Setup with no unattend left to consume and hangs on a black screen.
reg add "HKLM\SYSTEM\Setup" /v SetupType /t REG_DWORD /d 0 /f
reg delete "HKLM\SYSTEM\Setup" /v OOBEInProgress /f 2>nul
reg delete "HKLM\SYSTEM\Setup" /v CmdLine /f 2>nul
''}
${lib.optionalString configMedium ''
:: Runs last, as the generic bootstrap account: create the real per-VM
:: account from the config, switch autologon to it and arm the cleanup. The
:: reboot below then logs the real account in for the first time, building
:: its SID-bound profile on D:\Users\<username>.
powershell -NoProfile -ExecutionPolicy Bypass -File C:\vmix-create-user.ps1 > C:\Windows\Temp\vmix-create-user.log 2>&1
''}
:: Clean up :: Clean up
del /q C:\oobe-unattend.xml 2>nul del /q C:\oobe-unattend.xml 2>nul
del /q C:\vmix-audit-script.cmd 2>nul del /q C:\vmix-audit-script.cmd 2>nul
del /q C:\vmix-audit-wrapper.cmd 2>nul del /q C:\vmix-audit-wrapper.cmd 2>nul
${if configMedium then "shutdown /r /t 5 /c \"vmix: applying per-VM config\"" ${if delayOobeRun then "" else "shutdown /s /t 5 /c \"vmix generalize complete\""}
else if delayOobeRun then ""
else "shutdown /s /t 5 /c \"vmix generalize complete\""}
del /q C:\post-oobe.cmd 2>nul del /q C:\post-oobe.cmd 2>nul
''; '';
@ -657,26 +127,15 @@ in
<?xml version="1.0" encoding="utf-8"?> <?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend" <unattend xmlns="urn:schemas-microsoft-com:unattend"
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"> xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
<!-- CopyProfile bakes the Audit Mode customizations into the Default <!-- Copy Administrator profile to default (preserves Audit Mode customizations) -->
profile, but it is dropped when profiles are being relocated: the
two interfere, and sysprep picking a profile to copy while the
profile root is moving underneath it is the likelier reason a
correctly formatted data volume came back holding nothing. Having a
profile that persists matters more than the customizations do.
FolderLocations appears in both passes on purpose. Which one
actually honours it is not something the documentation is crisp
about, and naming it twice costs nothing. -->
<settings pass="specialize"> <settings pass="specialize">
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" <component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64"
publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS"> publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
${lib.optionalString (profilesDirectory == null) " <CopyProfile>true</CopyProfile>"} <CopyProfile>true</CopyProfile>
<Themes> <Themes>
<WindowColor>Automatic</WindowColor> <WindowColor>Automatic</WindowColor>
</Themes> </Themes>
${folderLocationsXml}
</component> </component>
${dataDiskXml}
</settings> </settings>
<settings pass="oobeSystem"> <settings pass="oobeSystem">
@ -721,7 +180,6 @@ ${dataDiskXml}
<Username>${username}</Username> <Username>${username}</Username>
</AutoLogon> </AutoLogon>
<ComputerName>${hostname}</ComputerName> <ComputerName>${hostname}</ComputerName>
${folderLocationsXml}
<TimeZone>${timezone}</TimeZone> <TimeZone>${timezone}</TimeZone>
<FirstLogonCommands> <FirstLogonCommands>
<SynchronousCommand wcm:action="add"> <SynchronousCommand wcm:action="add">
@ -735,46 +193,13 @@ ${folderLocationsXml}
</unattend> </unattend>
''; '';
in { in {
name = if configMedium then "seal" else if delayOobeRun then "generalize-delay-oobe" else "generalize"; name = if delayOobeRun then "generalize-delay-oobe" else "generalize";
inherit nicModel; inherit nicModel;
# With keepMachineSid the specialize pass never runs (see the sysprep line),
# so the profile relocation cannot ride the unattend there. It is written to
# the registry offline instead, before the build's OOBE creates the profile,
# so the account still lands on the data volume. Empty otherwise.
windowsRegistry = profileListRegistry + activeSetupRegistry;
# The blank disk is attached for the Audit Mode boot itself, so the disk-init
# command and the profile relocation both happen under OOBE in the build VM.
# That is what makes delayOobeRun unnecessary: nothing is left to do on real
# hardware. The written disk comes back as this derivation's `data` output.
#
# Under delayOobeRun there is no build-VM OOBE to relocate into, and the real
# data volume is the host's zvol attached at deploy time -- so building an
# empty throwaway disk here would be pure waste. Gated off: the target's
# specialize formats the real disk (dataDiskXml) and OOBE creates the profile
# on it. This is what lets a sealed image ship without a `data` output.
extraDisk = if (dataDisk != null && !delayOobeRun) then { size = dataDisk.size or "100G"; } else null;
uploads = [ uploads = [
{ source = oobeXml; dest = "/oobe-unattend.xml"; } { source = oobeXml; dest = "/oobe-unattend.xml"; }
{ source = postOobeScript; dest = "/post-oobe.cmd"; } { source = postOobeScript; dest = "/post-oobe.cmd"; }
{ source = masScript; dest = "/MAS_AIO.cmd"; } { source = masScript; dest = "/MAS_AIO.cmd"; }
] ++ lib.optionals (dataDisk != null) ( ];
[ { source = initDataDiskScript; dest = "/vmix-init-data-disk.cmd"; }
{ source = bootDataProfileScript; dest = "/vmix-data-profile.cmd"; }
]
++ lib.optional (profilesDirectory != null) { source = healProfileScript; dest = "/vmix-heal-profile.ps1"; }
++ lib.optional (folderRedirect != null) { source = folderRedirectPs1; dest = "/vmix-redirect-folders.ps1"; }
)
++ lib.optional (writeFilter != null) { source = uwfConfigScript; dest = "/vmix-uwf-config.cmd"; }
++ lib.optionals configMedium [
{ source = loadConfigScript; dest = "/vmix-load-config.cmd"; }
{ source = applyConfigScript; dest = "/vmix-apply-config.ps1"; }
{ source = createUserScript; dest = "/vmix-create-user.ps1"; }
{ source = finalizeScript; dest = "/vmix-finalize.cmd"; }
]
++ lib.optionals (staticIP != null || configMedium) [
{ source = staticIPScript; dest = "/vmix-static-ip.cmd"; }
{ source = staticIPScriptPs1; dest = "/vmix-static-ip.ps1"; }
];
# delayOobeRun: sysprep + shutdown — OOBE runs on real hardware # delayOobeRun: sysprep + shutdown — OOBE runs on real hardware
# generalize: sysprep + reboot into OOBE in the same QEMU session # generalize: sysprep + reboot into OOBE in the same QEMU session
auditScript = '' auditScript = ''
@ -783,22 +208,7 @@ in {
del /q C:\Windows\Panther\unattend.xml 2>nul del /q C:\Windows\Panther\unattend.xml 2>nul
del /q C:\Windows\Panther\Unattend\unattend.xml 2>nul del /q C:\Windows\Panther\Unattend\unattend.xml 2>nul
del /q C:\Windows\System32\Sysprep\Panther\unattend.xml 2>nul del /q C:\Windows\System32\Sysprep\Panther\unattend.xml 2>nul
${lib.optionalString (dataDisk != null && !delayOobeRun) '' C:\Windows\System32\Sysprep\sysprep.exe /generalize /oobe ${if delayOobeRun then "/shutdown" else "/reboot"} /quiet /unattend:C:\oobe-unattend.xml
:: Lay the data disk out here, in Audit Mode, rather than leaving it to the
:: specialize pass alone. Component order within a pass is not guaranteed,
:: and FolderLocations is applied by Shell-Setup while the disk is prepared
:: by Deployment -- so relocation can be evaluated before the volume it
:: names exists, which silently leaves profiles on C:. Audit Mode is a
:: fully booted OS with the disk already attached, so this always works.
:: The specialize copy stays as a letter re-assertion after generalize
:: clears MountedDevices.
::
:: Only when there is a build disk to lay out. Under delayOobeRun (sealed
:: images) the disk is the host's zvol, present only on the target, so this
:: is left to the target's specialize pass alone.
call C:\vmix-init-data-disk.cmd
''}
C:\Windows\System32\Sysprep\sysprep.exe ${lib.optionalString (!keepMachineSid) "/generalize "}/oobe ${if delayOobeRun then "/shutdown" else "/reboot"} /quiet /unattend:C:\oobe-unattend.xml
''; '';
} }

View file

@ -9,7 +9,9 @@ rec {
upstreamISO = upstreamISOs.win10-ltsc-2021; upstreamISO = upstreamISOs.win10-ltsc-2021;
productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D"; productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D";
}; };
basic = customizeImageFold upstream (with templates; [ # Apply all available Windows Updates (cumulative, .NET, Defender)
updated = customizeImage upstream (templates.essentials.windowsUpdate {});
basic = customizeImageFold updated (with templates; [
essentials.virtioTools essentials.virtioTools
essentials.removeIE essentials.removeIE
essentials.removeWMP essentials.removeWMP
@ -38,8 +40,9 @@ rec {
productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D"; productKey = "M7XTQ-FN8P6-TTKYV-9D4CC-J462D";
useAHCI = true; useAHCI = true;
}; };
laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {});
laptopSlim = customizeImageFold laptopUpstream templates.bundles.laptopSlim; laptopSlim = customizeImageFold laptopUpdated templates.bundles.laptopSlim;
laptop = customizeImageFold laptopUpstream templates.bundles.laptop; laptop = customizeImageFold laptopUpdated templates.bundles.laptop;
} }

View file

@ -12,7 +12,8 @@ rec {
windowsVersionForVirtioDrivers = "w11"; windowsVersionForVirtioDrivers = "w11";
}; };
basic = customizeImageFold upstream (with templates; [ updated = customizeImage upstream (templates.essentials.windowsUpdate {});
basic = customizeImageFold updated (with templates; [
essentials.virtioTools essentials.virtioTools
essentials.removeIE essentials.removeIE
essentials.removeWMP essentials.removeWMP
@ -45,9 +46,11 @@ rec {
windowsVersionForVirtioDrivers = "w11"; windowsVersionForVirtioDrivers = "w11";
}; };
laptopSlim = customizeImageFold laptopUpstream laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {});
laptopSlim = customizeImageFold laptopUpdated
(templates.bundles.laptopSlim ++ [ templates.reg.disableUCPD ]); (templates.bundles.laptopSlim ++ [ templates.reg.disableUCPD ]);
laptop = customizeImageFold laptopUpstream laptop = customizeImageFold laptopUpdated
(templates.bundles.laptop ++ [ templates.reg.disableUCPD ]); (templates.bundles.laptop ++ [ templates.reg.disableUCPD ]);
} }

6
module.nix Normal file
View file

@ -0,0 +1,6 @@
{ ... }:
{
imports = [
./nixos/default.nix
];
}

View file

@ -1,7 +1,7 @@
{ config, pkgs, lib, ... }: { config, pkgs, lib, ... }:
with lib; with lib;
let let
vmixLib = pkgs.vmixLib; vmixLib = import ./../lib {inherit pkgs lib; };
args = { inherit config pkgs lib vmixLib; }; args = { inherit config pkgs lib vmixLib; };
in in
{ {
@ -15,4 +15,6 @@ in
(types.submodule (import ./namespaceSubmoduleOptions.nix args)); (types.submodule (import ./namespaceSubmoduleOptions.nix args));
default = {}; default = {};
}; };
config.nixpkgs.overlays = [ (import ../overlay.nix) ];
} }

View file

@ -172,10 +172,6 @@ let
let let
wanCfg = cfg // { spaceName = spaceName; }; wanCfg = cfg // { spaceName = spaceName; };
vethInNSToHost.iface = "vhost"; vethInNSToHost.iface = "vhost";
# Temporary peer name, unique per namespace. The peer briefly exists in the
# host namespace before being moved; a shared name ("vhost") lets parallel
# wan.net.vmix@* starts steal each other's peer ends, cross-wiring namespaces.
vethInNSToHost.tempIface = "vh-${wanCfg.spaceName}";
vethOnHostToNS.iface = "vn-${wanCfg.spaceName}"; vethOnHostToNS.iface = "vn-${wanCfg.spaceName}";
vethOnHostToNS.ipv4.address = calc.cidr.host 1 wanCfg.ipv4.range; vethOnHostToNS.ipv4.address = calc.cidr.host 1 wanCfg.ipv4.range;
vethInNSToHost.ipv4.address = calc.cidr.host 2 wanCfg.ipv4.range; vethInNSToHost.ipv4.address = calc.cidr.host 2 wanCfg.ipv4.range;
@ -184,9 +180,8 @@ let
portForwardRules = lib.concatStringsSep "\n" (lib.mapAttrsToList (hostIPnPort: nsPort: "iptables -t nat -A PREROUTING -p tcp --dport ${hostIPnPort} -j DNAT --to-destination ${vethInNSToHost.ipv4.address}:${toString nsPort}") wanCfg.forwardPorts); portForwardRules = lib.concatStringsSep "\n" (lib.mapAttrsToList (hostIPnPort: nsPort: "iptables -t nat -A PREROUTING -p tcp --dport ${hostIPnPort} -j DNAT --to-destination ${vethInNSToHost.ipv4.address}:${toString nsPort}") wanCfg.forwardPorts);
createWanCommands = '' createWanCommands = ''
ip link add ${vethOnHostToNS.iface} type veth peer name ${vethInNSToHost.tempIface} ip link add ${vethOnHostToNS.iface} type veth peer name ${vethInNSToHost.iface}
ip link set ${vethInNSToHost.tempIface} netns ${wanCfg.spaceName}.vmix ip link set ${vethInNSToHost.iface} netns ${wanCfg.spaceName}.vmix
ip netns exec ${wanCfg.spaceName}.vmix ip link set ${vethInNSToHost.tempIface} name ${vethInNSToHost.iface}
ip address add ${vethOnHostToNS.ipv4.address}/${networkPrefix} dev ${vethOnHostToNS.iface} ip address add ${vethOnHostToNS.ipv4.address}/${networkPrefix} dev ${vethOnHostToNS.iface}
ip netns exec ${wanCfg.spaceName}.vmix ip address add ${vethInNSToHost.ipv4.address}/${networkPrefix} dev ${vethInNSToHost.iface} ip netns exec ${wanCfg.spaceName}.vmix ip address add ${vethInNSToHost.ipv4.address}/${networkPrefix} dev ${vethInNSToHost.iface}
@ -291,6 +286,5 @@ in
{ {
config.systemd.services = namespaceGlobalService // networkServices; config.systemd.services = namespaceGlobalService // networkServices;
config.systemd.targets = networkTargets; config.systemd.targets = networkTargets;
config.boot.kernel.sysctl."net.ipv4.ip_forward" = lib.mkForce 1; config.boot.kernel.sysctl."net.ipv4.ip_forward" = lib.mkDefault 1;
config.boot.kernel.sysctl."net.ipv4.conf.all.forwarding" = lib.mkForce true;
} }

View file

@ -79,23 +79,6 @@ let
# Auto-detect Windows from _vmixOsType marker on the disk image # Auto-detect Windows from _vmixOsType marker on the disk image
isWindows = vmCfg.windows.enable || (hasOsDisk && (vmCfg.disks.os.file._vmixOsType or "linux") == "windows"); isWindows = vmCfg.windows.enable || (hasOsDisk && (vmCfg.disks.os.file._vmixOsType or "linux") == "windows");
# Interrupt remapping in the virtual IOMMU only works on a split irqchip,
# so viommu wins over the full in-kernel irqchip hideVirtualized asks for.
machineIrqchipArg =
if vmCfg.pci.viommu.enable then ",kernel-irqchip=split"
else optionalString vmCfg.cpu.hideVirtualized ",kernel_irqchip=on";
# Functions of one physical device have to reach the guest as functions
# of one device too. Giving each address its own root port splits a GPU
# from its own HDMI audio, and Navi cannot then reset or power-manage
# either half -- the guest ends up with a card stuck in D3. So group by
# everything left of the function digit and place each group behind a
# single root port, multifunction, at the same slot.
pciDeviceOf = addr: head (splitString "." addr);
pciFunctionOf = addr: last (splitString "." addr);
pciGroups = map
(dev: filter (a: pciDeviceOf a == dev) vmCfg.pci.passthrough)
(unique (map pciDeviceOf vmCfg.pci.passthrough));
# Linux VMs: apply customizeImage with 9p fstab and machine-id setup # Linux VMs: apply customizeImage with 9p fstab and machine-id setup
linuxOsImage = vmixLib.linux.customizeImage vmCfg.disks.os.file { linuxOsImage = vmixLib.linux.customizeImage vmCfg.disks.os.file {
@ -125,34 +108,13 @@ let
if [ ! -f "$PERSIST_PATH" ]; then if [ ! -f "$PERSIST_PATH" ]; then
echo "Seeding persistent disk from store image..." echo "Seeding persistent disk from store image..."
mkdir -p "$(dirname "$PERSIST_PATH")" mkdir -p "$(dirname "$PERSIST_PATH")"
${if vmCfg.disks.os.persistMode == "backing" cp --no-preserve=mode "${toString storeImage}" "$PERSIST_PATH"
then ''qemu-img create -f qcow2 -F qcow2 -b "${toString storeImage}" "$PERSIST_PATH"''
else ''cp --no-preserve=mode "${toString storeImage}" "$PERSIST_PATH"''}
chmod 600 "$PERSIST_PATH" chmod 600 "$PERSIST_PATH"
fi fi
''; '';
persistExecStartPre = lib.optional (hasOsDisk && vmCfg.disks.os.persist) seedPersistentDiskScript; persistExecStartPre = lib.optional (hasOsDisk && vmCfg.disks.os.persist) seedPersistentDiskScript;
# A GC root pinning the OS overlay's ACTUAL backing store path, so
# nix-collect-garbage cannot delete the store image the disk reads through.
gcrootLink = "/nix/var/nix/gcroots/vmix-${vmCfg.name}-osbacking";
gcrootScript = pkgs.writeShellScript "${vmCfg.name}-gcroot-vmix" ''
# Read the live overlay's backing (not the config's current image, which
# drifts to a new store path after a rebuild while the overlay keeps
# backing the old one). Pinning the top of the chain transitively keeps
# the whole chain -- qcow2 backing_file paths are registered nix refs.
BACK=""
if [ -f "${vmCfg.disks.os.persistPath}" ]; then
BACK=$(qemu-img info "${vmCfg.disks.os.persistPath}" 2>/dev/null | awk '/^backing file:/ {print $3; exit}')
fi
[ -z "$BACK" ] && BACK="${toString storeImage}"
if [ -n "$BACK" ]; then
mkdir -p /nix/var/nix/gcroots
ln -sfn "$BACK" "${gcrootLink}"
fi
'';
# QEMU expects single-letter boot codes (e.g. c,d,n), while vmix uses readable names. # QEMU expects single-letter boot codes (e.g. c,d,n), while vmix uses readable names.
bootOrderQemu = bootOrderQemu =
let let
@ -212,9 +174,6 @@ let
''} ''}
exec qemu-system-${vmCfg.arch} \ exec qemu-system-${vmCfg.arch} \
${if vmCfg.nographic && vmCfg.pci.passthrough != [] then "-display none -vga none" else optionalString vmCfg.nographic "-nographic"} \ ${if vmCfg.nographic && vmCfg.pci.passthrough != [] then "-display none -vga none" else optionalString vmCfg.nographic "-nographic"} \
${# QEMU realizes devices in command-line order and intel-iommu must
# exist before anything it translates, so it leads the device list.
optionalString vmCfg.pci.viommu.enable "-device intel-iommu,intremap=on,caching-mode=on"} \
${optionalString (vmCfg.vnc.enable && vmCfg.vnc.passwordFile != null) "-object secret,id=vnc-pass-${vmCfg.name},file=${escapeShellArg vmCfg.vnc.passwordFile}"} \ ${optionalString (vmCfg.vnc.enable && vmCfg.vnc.passwordFile != null) "-object secret,id=vnc-pass-${vmCfg.name},file=${escapeShellArg vmCfg.vnc.passwordFile}"} \
${optionalString vmCfg.vnc.enable "-vnc ${vncArgs}"} \ ${optionalString vmCfg.vnc.enable "-vnc ${vncArgs}"} \
${optionalString (vmCfg.spice.enable && vmCfg.spice.passwordFile != null) "-object secret,id=spice-pass-${vmCfg.name},file=${escapeShellArg vmCfg.spice.passwordFile}"} \ ${optionalString (vmCfg.spice.enable && vmCfg.spice.passwordFile != null) "-object secret,id=spice-pass-${vmCfg.name},file=${escapeShellArg vmCfg.spice.passwordFile}"} \
@ -230,21 +189,17 @@ let
${optionalString vmCfg.mem.balloon "-device virtio-balloon-pci"} \ ${optionalString vmCfg.mem.balloon "-device virtio-balloon-pci"} \
-smp cores=${toString vmCfg.cpu.cores} \ -smp cores=${toString vmCfg.cpu.cores} \
-cpu ${vmCfg.cpu.model}${optionalString vmCfg.cpu.hideVirtualized ",kvm=off,hv_vendor_id=1234567890ab,-hypervisor"} \ -cpu ${vmCfg.cpu.model}${optionalString vmCfg.cpu.hideVirtualized ",kvm=off,hv_vendor_id=1234567890ab,-hypervisor"} \
-machine type=${vmCfg.pc.type}${machineIrqchipArg} \ -machine type=${vmCfg.pc.type}${optionalString vmCfg.cpu.hideVirtualized ",kernel_irqchip=on"} \
${optionalString vmCfg.bios.efi "-bios ${pkgs.OVMF.fd}/FV/OVMF.fd"} \ ${optionalString vmCfg.bios.efi "-bios ${pkgs.OVMF.fd}/FV/OVMF.fd"} \
${optionalString vmCfg.bios.tpm "-chardev socket,id=chrtpm,path=/tmp/mytpm-sock -tpmdev emulator,id=tpm0,chardev=chrtpm -device tpm-tis,tpmdev=tpm0"} \ ${optionalString vmCfg.bios.tpm "-chardev socket,id=chrtpm,path=/tmp/mytpm-sock -tpmdev emulator,id=tpm0,chardev=chrtpm -device tpm-tis,tpmdev=tpm0"} \
${# Windows: localtime RTC, USB tablet for mouse, disable S3/S4 sleep. ${# Windows: localtime RTC, USB tablet for mouse, disable S3/S4 sleep
# The q35 power/LPC bridge is ICH9-LPC -- ICH9-LMB was a typo qemu
# rejects ("invalid class name"), so the sleep states stayed offered
# and an idle guest could suspend itself right off the network.
optionalString isWindows '' optionalString isWindows ''
-rtc base=localtime,clock=host \ -rtc base=localtime,clock=host \
-device qemu-xhci -device usb-tablet \ -device qemu-xhci -device usb-tablet \
-global ICH9-LPC.disable_s3=1 -global ICH9-LPC.disable_s4=1 \ -global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \
''} \ ''} \
${optionalString hasOsDisk "-drive file=${osDiskPath},format=qcow2,if=virtio${optionalString (vmCfg.disks.os.persist == false) ",snapshot=on"}"} \ ${optionalString hasOsDisk "-drive file=${osDiskPath},format=qcow2,if=virtio${optionalString (vmCfg.disks.os.persist == false) ",snapshot=on"}"} \
${optionalString (vmCfg.disks.iso.file != null) "-drive file=${toString vmCfg.disks.iso.file},media=cdrom,readonly=on"} \ ${optionalString (vmCfg.disks.iso.file != null) "-drive file=${toString vmCfg.disks.iso.file},media=cdrom,readonly=on"} \
${optionalString (vmCfg.disks.config.file != null) "-drive file=${toString vmCfg.disks.config.file},media=cdrom,readonly=on"} \
${concatMapStrings (diskCfg: '' ${concatMapStrings (diskCfg: ''
-drive file=${toString diskCfg.file},format=${diskCfg.format},if=${vmCfg.disks.bus} \ -drive file=${toString diskCfg.file},format=${diskCfg.format},if=${vmCfg.disks.bus} \
'') (attrValues vmCfg.disks.add)} \ '') (attrValues vmCfg.disks.add)} \
@ -263,11 +218,10 @@ let
-device ${vmCfg.nicModel},netdev=macvtap-${macvtap.name},mac=$(ip l show ${macvtap.iface} | awk '/link\/ether/{print $2}') \ -device ${vmCfg.nicModel},netdev=macvtap-${macvtap.name},mac=$(ip l show ${macvtap.iface} | awk '/link\/ether/{print $2}') \
-netdev tap,id=macvtap-${macvtap.name},fd=${toString (i+2)} ${toString (i+2)}<>/dev/tap$(ip l show ${macvtap.iface} | awk -F':' '/${macvtap.iface}/{print $1}') \ -netdev tap,id=macvtap-${macvtap.name},fd=${toString (i+2)} ${toString (i+2)}<>/dev/tap$(ip l show ${macvtap.iface} | awk -F':' '/${macvtap.iface}/{print $1}') \
'') allMacvtaps)} \ '') allMacvtaps)} \
${concatStrings (imap1 (i: group: '' ${concatStrings (imap1 (i: pciAddr: ''
-device pcie-root-port,id=pci-passthrough${toString i},chassis=${toString i},slot=${toString i} \ -device pcie-root-port,id=pci-passthrough${toString i},chassis=${toString i},slot=${toString i} \
'' + concatStrings (imap0 (j: pciAddr: '' -device vfio-pci,host=${pciAddr},bus=pci-passthrough${toString i}${optionalString (i == 1) ",x-vga=on${optionalString (vmCfg.pci.romFile != null) ",romfile=${vmCfg.pci.romFile}"}"} \
-device vfio-pci,host=${pciAddr},bus=pci-passthrough${toString i},addr=0x0.${pciFunctionOf pciAddr}${optionalString (length group > 1 && j == 0) ",multifunction=on"}${optionalString (i == 1 && j == 0) "${optionalString vmCfg.pci.vgaPassthrough ",x-vga=on"}${optionalString (vmCfg.pci.romFile != null) ",romfile=${vmCfg.pci.romFile}"}"} \ '') vmCfg.pci.passthrough)} \
'') group)) pciGroups)} \
${concatMapStrings (usbDev: '' ${concatMapStrings (usbDev: ''
-device usb-host,vendorid=0x${usbDev.vendorId},productid=0x${usbDev.productId} \ -device usb-host,vendorid=0x${usbDev.vendorId},productid=0x${usbDev.productId} \
'') vmCfg.usb.hostDevices} \ '') vmCfg.usb.hostDevices} \
@ -279,8 +233,7 @@ let
"vm.vmix@${vmCfg.name}" = rec { "vm.vmix@${vmCfg.name}" = rec {
bindsTo = [ "net.vmix@${spaceName}.target" ] ++ lib.optional (allMacvtaps != []) "macvtaps.vm.vmix@${vmCfg.name}.service"; bindsTo = [ "net.vmix@${spaceName}.target" ] ++ lib.optional (allMacvtaps != []) "macvtaps.vm.vmix@${vmCfg.name}.service";
unitConfig.JoinsNamespaceOf = "ns.net.vmix@${spaceName}.service"; unitConfig.JoinsNamespaceOf = "ns.net.vmix@${spaceName}.service";
after = bindsTo ++ lib.optional (hasOsDisk && vmCfg.disks.os.persist) "vm.vmix-gcroot@${vmCfg.name}.service"; after = bindsTo;
wants = lib.optional (hasOsDisk && vmCfg.disks.os.persist) "vm.vmix-gcroot@${vmCfg.name}.service";
path = with pkgs; [ iproute2 qemu gawk coreutils ]; path = with pkgs; [ iproute2 qemu gawk coreutils ];
serviceConfig = { serviceConfig = {
ExecStartPre = persistExecStartPre ++ [ createTapsforLansScript ]; ExecStartPre = persistExecStartPre ++ [ createTapsforLansScript ];
@ -310,18 +263,6 @@ let
ExecStop = deleteMacvTapsScript; ExecStop = deleteMacvTapsScript;
}; };
}; };
}
// lib.optionalAttrs (cfg.enable && hasOsDisk && vmCfg.disks.os.persist) {
"vm.vmix-gcroot@${vmCfg.name}" = {
before = [ "vm.vmix@${vmCfg.name}.service" ];
wantedBy = [ "multi-user.target" ];
path = with pkgs; [ qemu coreutils ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
ExecStart = gcrootScript;
};
};
}; };
vmServices = concatMapAttrs (spaceName: namespaceCfg: (concatMapAttrs (mkServices4aVMInNamespace spaceName) namespaceCfg.vms)) vmixCfg.namespaces; vmServices = concatMapAttrs (spaceName: namespaceCfg: (concatMapAttrs (mkServices4aVMInNamespace spaceName) namespaceCfg.vms)) vmixCfg.namespaces;

View file

@ -173,32 +173,11 @@ with lib;
default = ""; default = "";
description = "Mutable path for the persistent OS disk (e.g. /storage/vms/myvm/os.qcow2). Required when persist = true."; description = "Mutable path for the persistent OS disk (e.g. /storage/vms/myvm/os.qcow2). Required when persist = true.";
}; };
disks.os.persistMode = mkOption {
type = types.enum [ "copy" "backing" ];
default = "copy";
description = ''
How the persistent OS disk is seeded from the store image (persist = true).
copy: a full cp of the store image; the mutable disk holds everything.
backing: a thin qcow2 overlay backing onto the shared store image, so many
VMs share one base and each holds only its own deltas. The store image (and
its backing chain) must then survive GC -- vmix pins it via a per-VM gcroot.
'';
};
disks.iso.file = mkOption { disks.iso.file = mkOption {
type = types.nullOr (types.either types.path types.str); type = types.nullOr (types.either types.path types.str);
description = "Path to the ISO file. Can be a Nix store path or a string path to a local file."; description = "Path to the ISO file. Can be a Nix store path or a string path to a local file.";
default = null; default = null;
}; };
disks.config.file = mkOption {
type = types.nullOr (types.either types.path types.str);
default = null;
description = ''
A small read-only config medium attached as a second CD-ROM. For Windows
sealed images (templates.seal) this is the per-VM ISO from
vmixLib.windows.makeConfigMedium, carrying hostname/static-IP/etc. that
the image's baked first-boot scripts consume. Null to attach nothing.
'';
};
disks.add = mkOption { disks.add = mkOption {
default = {}; default = {};
type = types.attrsOf (types.submodule { type = types.attrsOf (types.submodule {
@ -283,36 +262,11 @@ with lib;
default = []; default = [];
description = "PCI device addresses to passthrough via VFIO (e.g. [\"0000:03:00.0\" \"0000:03:00.1\"])."; description = "PCI device addresses to passthrough via VFIO (e.g. [\"0000:03:00.0\" \"0000:03:00.1\"]).";
}; };
pci.vgaPassthrough = mkOption {
type = types.bool;
default = true;
description = ''
Route legacy VGA to the first passthrough device (x-vga=on), which a
guest needs in order to drive that card as its own display.
Turn it off when the guest only forwards the device onward to a nested
guest: x-vga=on claims the VGA path the emulated adapter wants, and the
nested guest does its own routing anyway.
'';
};
pci.romFile = mkOption { pci.romFile = mkOption {
type = types.nullOr types.path; type = types.nullOr types.path;
default = null; default = null;
description = "GPU VBIOS ROM file for the first passthrough device. Required when GPU PCI ROM BAR doesn't expose the full VBIOS (common with AMD Navi+)."; description = "GPU VBIOS ROM file for the first passthrough device. Required when GPU PCI ROM BAR doesn't expose the full VBIOS (common with AMD Navi+).";
}; };
pci.viommu.enable = mkOption {
type = types.bool;
default = false;
description = ''
Give the guest a virtual Intel IOMMU, so a guest that is itself a
hypervisor can bind a passed-through device to vfio-pci and hand it on
to a nested guest. Without one the guest sees no IOMMU and cannot
re-assign anything it was given.
Implies kernel-irqchip=split, which interrupt remapping requires and
which replaces the full in-kernel irqchip cpu.hideVirtualized asks for.
'';
};
usb.hostDevices = mkOption { usb.hostDevices = mkOption {
default = []; default = [];

7
overlay.nix Normal file
View file

@ -0,0 +1,7 @@
final: prev:
let
# Pin vmixLib to nixpkgs 25-11 so all VM images are built with a consistent toolchain
vmixPkgs = prev.v25-11 or prev;
in {
vmixLib = vmixPkgs.callPackage ./lib {};
}

View file

@ -0,0 +1,41 @@
# vmix.nix Project Memory
## Build Preferences
- Always use VNC display (`:1` / port 5901) when building Windows images so progress can be monitored
- Pass `vncDisplay = ":1"` to customizeImage templates for build monitoring
- Use `gvnccapture localhost:1 /tmp/screenshot.png` to take VNC screenshots (package: gtk-vnc)
- For VNC inside vmix namespace: `ip netns exec windows.vmix nix-shell -p gtk-vnc --run 'gvnccapture 127.0.0.1:1 /tmp/screenshot.png'`
## Key Architecture
- Offline registry uses `ControlSet001` (not `CurrentControlSet`) for virt-win-reg merges
- Sysprep resets offline registry changes — RDP must be re-enabled in post-OOBE script
- TermService won't listen on port 3389 in Audit Mode without a password on Administrator
- `LimitBlankPasswordUse=0` alone is NOT sufficient for RDP in Audit Mode — password required
- OOBE AutoLogon `<Password>` in unattend XML is unreliable — set via `reg add` in post-oobe.cmd instead
- OOBE creates user with blank password regardless of unattend — set real password via `net user` in post-oobe.cmd
- `sc config` can fail silently for some services — use `reg add` to set `Start` value directly
## RDP on Win10 IoT Enterprise LTSC 2021
- **CRITICAL**: `rdpwd.sys` and `tdtcp.sys` don't exist in this Windows build (removed in 19041+)
- `termsrv.dll` version is `10.0.19041.1202` — not supported by RDPWrap v1.6.2 or community INI files
- TermService runs but never creates the `rdp-tcp` WinStation listener — no port 3389
- The ISO (`en-us_windows_10_iot_enterprise_ltsc_2021_x64_dvd_257ad90f.iso`) has 2 indexes:
- Index 1: Windows 10 Enterprise LTSC 2021
- Index 2: Windows 10 IoT Enterprise LTSC 2021
- Product key `M7XTQ-FN8P6-TTKYV-9D4CC-J462D` = Enterprise LTSC (not IoT)
- MAS HWID activation switches edition to IoT Enterprise S (partial key YY74H)
- **TODO**: Either generate custom RDPWrap config for termsrv 10.0.19041.1202, use a different ISO, or use third-party RDP server
## generalize.nix Changes
- `enableRDP` flag added — applies RDP settings in post-oobe.cmd (survives sysprep)
- AutoLogon fix: blank password in unattend, real password + AutoAdminLogon registry in post-oobe.cmd
- `LogonCount=999` for persistent AutoLogon
- SessionEnv + UmRdpService set to auto-start via `reg add` (Start=2)
- Firewall: `Enable-NetFirewallRule -DisplayGroup 'Remote Desktop'` + `Set-NetFirewallRule -Profile Any`
## labv2.nix junto Deployment
- vmix flake input rev is pinned in `flake.nix` — must update the URL to change versions
- Use `path:/storage/gitrepos/vmix.nix` for local dev, `git+https://...?rev=<hash>` for production
- `colmena apply-local` doesn't support `--override-input`
- DNS: `dns.resolver.useHostResolvConf = true` breaks when host uses systemd-resolved (127.0.0.53) — use explicit upstream like `1.1.1.1`
- QEMU Guest Agent socket at `/tmp/qga-win10.sock` — use from inside namespace

530
wip/win10-update.session.md Normal file
View file

@ -0,0 +1,530 @@
# Windows Update Template - Full Development Session Log
## Original Request
User wanted a reproducible way to update Windows images, inspired by https://massgrave.dev/update-windows-iso. The upstream Win10 LTSC 2021 ISO is stored in a git-lfs repo at `git.sagar.ch`.
## Approach Evolution
### Phase 1: ISO Update Approach (abandoned)
Initially explored creating an updated ISO by integrating cumulative updates. Considered:
1. **UUP Dump approach**: The massgrave page links to uupdump.net which provides download scripts for building fresh ISOs from Microsoft's UUP (Unified Update Platform) files. The user received a bash script from UUP dump that:
- Uses `aria2c` to download UUP .cab files from Microsoft CDN
- Uses `cabextract`, `wimlib-imagex`, `chntpw` to build an ISO
- Uses `genisoimage`/`mkisofs` to create the final ISO
- Problem: downloads `core;professional` (Home/Pro), NOT LTSC
- Problem: download URLs contain auth tokens that expire — not reproducible
2. **Offline DISM approach**: Considered creating a Nix derivation that:
- Boots a Windows worker VM from the existing upstream image
- Mounts the original ISO inside the VM
- Uses `DISM /Image` to service install.wim offline (mount WIM, apply .cab updates, unmount)
- Extracts the updated install.wim via guestfs
- Rebuilds the ISO with genisoimage on the Linux host
- Problem: very complex, requires managing WIM indexes, boot.wim, etc.
- Problem: needs a "worker" Windows VM just to run DISM
3. **Offline .msu approach**: Considered downloading specific .msu files from Microsoft Update Catalog:
- Search catalog.update.microsoft.com for `cumulative update for windows 10 version 21H2 x64`
- Found latest: KB5087544 (May 2026), KB5088859 (.NET), KB2267602 (Defender)
- Problem: catalog uses JavaScript popups for downloads — can't scrape URLs
- Could use `curl` POST to `DownloadDialog.aspx` with update GUIDs, but GUIDs are hard to extract
- The download URLs from `catalog.s.download.windowsupdate.com` are stable (don't expire) but finding them requires browser interaction
### Phase 2: customizeImage Template (adopted)
User said: "instead of iso, let's create a customizeImage template that basically updates the existing image and runs qcow2 compact on it"
This is much simpler — apply updates to the running Windows image during Audit Mode, not to the ISO.
### Phase 3: Online vs Offline Updates
Initially built the template with two modes:
- **Offline mode**: user provides `.msu`/`.cab` files as `fetchurl` derivations, applied via `DISM /Online /Add-Package`
- **Online mode**: triggers Windows Update service directly via COM API
User said "just do online updates" — removed offline mode entirely.
## What was built
### New files
- `lib/images/windows/templates/essentials/windows-update.nix` — template that boots into Audit Mode, runs Windows Update via COM API, handles reboots automatically, compacts image
### Modified files
- `lib/images/windows/helpers/customizeImage.nix` — added `compact`, `qemuTimeout` parameters (committed in `3b454b7` on master alongside other changes)
- `lib/images/windows/templates/default.nix` — wired `windowsUpdate` into `essentials`
- `lib/images/windows/win10/images.nix` — added `updated` step between `upstream` and `basic`
- `lib/images/windows/win11/images.nix` — same
### New customizeImage parameters
#### `compact ? false`
Added to `customizeImage.nix`. When true, runs `qemu-img convert -O qcow2` after the audit boot to flatten the COW chain into a standalone qcow2 with no backing file dependency. This is important for the update template because the updates add several GB of data to the COW overlay.
Implementation in `builderCommand`:
```bash
${lib.optionalString compact ''
echo "=== vmix: compacting image ==="
qemu-img convert -O qcow2 ${resultImg} compact.qcow2
mv compact.qcow2 ${resultImg}
''}
mv ${resultImg} $out
```
#### `qemuTimeout ? 1800`
Added to `customizeImage.nix`. Replaces the hardcoded `timeout 1800` in the QEMU boot command. The Windows Update template sets this to `7200` (2 hours) because update installation with reboots can take a long time.
Both `timeout` invocations in the builder (primary and SDL-fallback) now use `${toString qemuTimeout}`.
### How the template works
The template is a function that takes `{ maxRounds ? 3 }` and returns a customizeImage-compatible attrset:
```nix
{
name = "windows-update";
compact = true;
memSize = 4096;
qemuTimeout = 7200;
auditScript = "...";
}
```
#### Audit script flow
1. **Round tracking**: Uses `C:\vmix-update-round.txt` to track which round we're on across reboots. First run creates the file with "1", subsequent runs read and increment.
2. **Service initialization**:
```batch
net start wuauserv 2>nul
sc config wuauserv start= auto
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul
```
The LTSC image may have update-blocking group policies. We delete them. We also wait 30 seconds on first round for the service to initialize and sync with Microsoft.
3. **PowerShell COM API**: The core update logic uses `Microsoft.Update.Session`:
```powershell
$session = New-Object -ComObject Microsoft.Update.Session
$searcher = $session.CreateUpdateSearcher()
$result = $searcher.Search('IsInstalled=0')
# ... accept EULAs, download, install ...
if ($installResult.RebootRequired) { exit 3010 } else { exit 0 }
```
- Exit code `3010` = reboot required
- Exit code `0` = no reboot needed (or no updates found)
- Exit code `1` = error (caught by try/catch)
- Per-update results are logged with HResult codes
4. **Component cleanup**: After updates, runs `dism /Online /Cleanup-Image /StartComponentCleanup /ResetBase /Quiet` to reclaim space from superseded update components.
5. **Reboot handling** (if exit code 3010 and round < maxRounds):
```batch
:: Copy script to survive wrapper deletion
copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul
:: Register for next boot
reg add "HKLM\...\RunOnce" /v vmixUpdate /d "cmd /c C:\vmix-update-continue.cmd" /f
:: Preserve Audit Mode
reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f
:: Reboot
shutdown /r /f /t 0
exit /b
```
6. **Final shutdown**: When all rounds complete (or no more updates), the script shuts down:
```batch
del /q "%ROUND_FILE%" 2>nul
del /q "C:\vmix-update-continue.cmd" 2>nul
echo === vmix: Windows Update complete ===
shutdown /s /f /t 10 /c "vmix: windows-update complete"
```
### Pipeline integration
#### win10/images.nix
```nix
ltsc = rec {
upstream = makeImage { ... };
updated = customizeImage upstream (templates.essentials.windowsUpdate {});
basic = customizeImageFold updated (with templates; [ ... ]);
# ... withApps, withAMDGPU ...
};
laptopUpstream = makeImage { ... useAHCI = true; };
laptopUpdated = customizeImage laptopUpstream (templates.essentials.windowsUpdate {});
laptopSlim = customizeImageFold laptopUpdated templates.bundles.laptopSlim;
laptop = customizeImageFold laptopUpdated templates.bundles.laptop;
```
#### win11/images.nix
Same pattern — `updated` step inserted between `upstream` and `basic`, `laptopUpdated` between `laptopUpstream` and `laptopSlim`/`laptop`.
### Usage examples
```nix
# Online mode (default) - triggers Windows Update service
essentials.windowsUpdate {}
essentials.windowsUpdate { maxRounds = 5; }
# In image pipeline
updated = customizeImage upstream (templates.essentials.windowsUpdate {});
basic = customizeImageFold updated [ ... ];
# Override VNC display and disable compact for debugging
vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; compact = false; })
```
## Detailed Test Log
### Build 1: First attempt (no VNC, wrong attr path)
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
in vmixLib.images.win10.ltsc.updated
'
```
**Result**: Error — `attribute 'images' missing`. The correct path is `vmixLib.windows.images.win10.ltsc.updated`, not `vmixLib.images.win10.ltsc.updated`.
### Build 2: Correct path, VNC :1, original script (no wuauserv start)
```bash
nix build ... --expr '
let vmixLib = ...;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {};
in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":1"; })
'
```
**Result**: Build "succeeded" but image size identical to upstream (5.03 GB vs 5.02 GB). The COM API found 0 updates because:
- Windows Update service (`wuauserv`) wasn't running in Audit Mode
- No time given for service to initialize
- Possible update-blocking policies active
**Build log showed**: QEMU booted, script ran, shut down — no errors visible in nix log (VNC output isn't captured).
### Build 3: Added wuauserv start, policy removal, 30s wait
Updated `windows-update.nix` to add:
```batch
net start wuauserv 2>nul
sc config wuauserv start= auto
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul
timeout /t 30 /nobreak >nul
```
Also added EULA acceptance and try/catch error handling to the PowerShell block.
**Build with VNC :55, chained virtio tools first**:
```bash
nix build ... --expr '
let vmixLib = ...;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
withVirtio = vmixLib.windows.customizeImage upstream vmixLib.windows.templates.essentials.virtioTools;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {};
in vmixLib.windows.customizeImage withVirtio (windowsUpdate // { vncDisplay = ":55"; compact = false; })
'
```
**VNC observations** (screenshots taken with `gvnccapture localhost:55 /tmp/screenshot.png`):
- **T+2min**: Boot screen "Please wait"
- **T+3min**: CMD window showing:
```
=== vmix audit: windows-update ===
=== vmix: Windows Update round 1 of 3 ===
The Windows Update service is starting.
The Windows Update service was started successfully.
[SC] ChangeServiceConfig SUCCESS
Waiting for Windows Update service to initialize...
Searching for updates...
```
- **T+7min**: Found 6 updates:
```
Found 6 updates
- 2022-02 Cumulative Update Preview for .NET Framework 3.5 and 4.8 for Windows 10 Version 21H2 for x64 (KB5010472)
- Microsoft .NET Framework 4.8.1 for Windows 10 Version 21H2 for x64 (KB5011048)
- Windows Malicious Software Removal Tool x64 - v5.141 (KB890830)
- 2026-05 Cumulative Update for .NET Framework 3.5, 4.8 and 4.8.1 for Windows 10 Version 21H2 for x64 (KB5088859)
- Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.451.326.0) - Current Channel (Broad)
- 2026-05 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5087544)
Downloading...
```
- **T+12min**: "Installing..."
- **T+20min through T+55min**: Still "Installing..." — KB5087544 is a massive cumulative update spanning Oct 2021 → May 2026
- **T+58min**: Sysprep dialog showing on desktop — the machine rebooted after update install and landed in Audit Mode desktop, but the round 2 script didn't run
**Issue discovered**: The wrapper script (`vmix-audit-wrapper.cmd`) deletes `C:\vmix-audit-script.cmd` after the audit script returns but before the reboot completes. The RunOnce entry points to the deleted file.
### Build 4: Added script copy fix + shutdown fix
Updated script to:
1. Copy itself to `C:\vmix-update-continue.cmd` before rebooting
2. Register `cmd /c C:\vmix-update-continue.cmd` in RunOnce (not the original path)
3. Always call `shutdown /s /f /t 10` when done (handles both wrapper and RunOnce invocation)
**Same build command as Build 3.**
**VNC observations**:
- **T+3min**: Round 1 started, same 6 updates found
- **T+7min**: Downloading...
- **T+12min**: Installing...
- **T+55min**: TianoCore UEFI boot screen — machine rebooted!
- **T+57min**: "Working on updates — 90% complete" — Windows finalizing update installation after reboot
- **T+62min**: "Working on updates — 19% complete" (different counter — this is the post-reboot finalization)
- **T+70min**: Sysprep dialog... but NO round 2 script running
**Issue discovered**: After reboot, Windows exited Audit Mode and entered OOBE ("Choose your keyboard layout" screen) instead of staying in Audit Mode. The cumulative update reset the Audit Mode flags during its finalization pass.
Wait — actually on this build we saw the Sysprep dialog (which IS Audit Mode). The issue was the RunOnce not firing. On a subsequent build, we saw the keyboard layout screen (OOBE). The behavior is inconsistent.
### Build 5: Added Audit Mode preservation
Added registry keys before reboot to preserve Audit Mode:
```batch
reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f
```
**Same build command. VNC observations**:
- **T+3min**: Round 1 started, same 6 updates found
- **T+70min**: Still on "Installing..." — round 1 didn't finish in 70 min on this machine
- **T+100min**: "Working on updates — 19% complete" — rebooted, finalizing
- **T+110min**: "Choose your keyboard layout" — OOBE screen again!
**Session ended here** — the Audit Mode preservation fix hasn't been verified as working yet. The machine was moved to a faster machine for continued testing.
## Detailed Issue Analysis
### Issue 1: Windows Update service not running
**Root cause**: In Audit Mode, the Windows Update service (`wuauserv`) has `Start=3` (manual) and isn't auto-started. The COM API requires the service to be running to search for updates.
**Fix**: Explicitly start the service and set it to auto-start:
```batch
net start wuauserv 2>nul
sc config wuauserv start= auto
```
Also remove any group policies that block updates (LTSC may have these pre-configured):
```batch
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /f 2>nul
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f 2>nul
```
And wait 30 seconds for the service to initialize and sync with Microsoft servers on first round.
### Issue 2: Wrapper deletes script before reboot completes
**Root cause**: The `customizeImage.nix` wrapper script flow:
```
call C:\vmix-audit-script.cmd ← our update script
del /q C:\vmix-audit-script.cmd ← DELETE happens here
shutdown /s /t 5 ← may override our shutdown /r
del /q C:\vmix-audit-wrapper.cmd
```
When our script calls `shutdown /r /f /t 0` and then `exit /b`, control returns to the wrapper. The wrapper deletes the script file. Even though `shutdown /r /t 0` was called, the batch file continues executing and the delete happens before the system actually reboots.
The RunOnce entry points to `C:\vmix-audit-script.cmd` which no longer exists after reboot.
Additionally, the wrapper's `shutdown /s /t 5` may override our `shutdown /r /t 0` (though in practice the `/t 0` reboot usually wins).
**Fix**: Copy the script to a separate path before rebooting:
```batch
copy /y "%~f0" "C:\vmix-update-continue.cmd" >nul
reg add "HKLM\...\RunOnce" /v vmixUpdate /d "cmd /c C:\vmix-update-continue.cmd" /f
```
The wrapper only knows about `C:\vmix-audit-script.cmd` and `C:\vmix-audit-wrapper.cmd`. It doesn't know about `C:\vmix-update-continue.cmd`, so that file survives.
### Issue 3: Audit Mode lost after update reboot
**Root cause**: Windows Audit Mode is maintained by registry keys:
- `HKLM\SYSTEM\Setup\Status\AuditBoot` (AuditBoot = 1)
- `HKLM\SYSTEM\Setup` (AuditInProgress = 1)
Some cumulative updates include "specialize" or "generalize" passes during their finalization that can clear these keys, causing Windows to transition from Audit Mode to OOBE on the next boot.
**Fix**: Explicitly set the Audit Mode registry keys right before rebooting:
```batch
reg add "HKLM\SYSTEM\Setup\Status\AuditBoot" /v AuditBoot /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\Setup" /v AuditInProgress /t REG_DWORD /d 1 /f
```
**Status**: NOT YET VERIFIED. The last build with this fix was still in the install phase when the session ended. The fix may or may not be sufficient — some updates may clear these keys AFTER the reboot during the "Working on updates X% complete" phase, which would happen after our registry writes.
**Alternative approaches if the fix doesn't work**:
1. Use `C:\Windows\System32\Sysprep\sysprep.exe /audit /reboot /quiet` instead of `shutdown /r` — this explicitly tells Windows to re-enter Audit Mode
2. Set up a `SetupComplete.cmd` or `Specialize` unattend pass that forces Audit Mode
3. Use a scheduled task instead of RunOnce (scheduled tasks persist across mode transitions)
4. Accept single-round updates only (`maxRounds = 1`) — no reboot needed if updates don't require it
### Issue 4: No shutdown after round 2
**Root cause**: When the script is invoked via RunOnce (round 2+), it runs directly — not through the wrapper. The wrapper is what normally calls `shutdown /s /t 5` after the script completes. Without the wrapper, the script finishes and the machine just sits at the Audit Mode desktop indefinitely (until the 2-hour QEMU timeout).
**Fix**: The script itself calls `shutdown /s /f /t 10` when all rounds are complete. This is harmless when called from the wrapper (two shutdown commands — the second one either fails silently or is a no-op since shutdown is already pending).
## All Build Commands Used
### Quick evaluation (check attribute paths)
```bash
nix eval --impure --expr '
let vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
in builtins.attrNames vmixLib.windows.images.win10.ltsc
'
```
### Build updated image directly (no VNC, with compact)
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
in vmixLib.windows.images.win10.ltsc.updated
'
```
### Build with VNC monitoring on port 5901 (display :1)
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {};
in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":1"; })
'
```
### Build with virtio tools + VNC :55 + no compact (debugging)
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
withVirtio = vmixLib.windows.customizeImage upstream vmixLib.windows.templates.essentials.virtioTools;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {};
in vmixLib.windows.customizeImage withVirtio (windowsUpdate // { vncDisplay = ":55"; compact = false; })
'
```
### Build with more RAM (8GB) for faster installs
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate {};
in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; memSize = 8192; })
'
```
### Build with more rounds
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
upstream = vmixLib.windows.images.win10.ltsc.upstream;
windowsUpdate = vmixLib.windows.templates.essentials.windowsUpdate { maxRounds = 5; };
in vmixLib.windows.customizeImage upstream (windowsUpdate // { vncDisplay = ":55"; })
'
```
### Full pipeline test (upstream → updated → basic → generalize)
```bash
nix build --print-build-logs --impure --option sandbox relaxed --expr '
let
vmixLib = (builtins.getFlake "path:/storage/gitrepos/vmix.nix").lib.x86_64-linux;
in vmixLib.windows.images.win10.ltsc.basic.generalize {
username = "User"; password = ""; hostname = "WIN-VM";
vncDisplay = ":55";
}
'
```
### VNC monitoring commands
```bash
# Take a screenshot
nix-shell -p gtk-vnc --run 'gvnccapture localhost:55 /tmp/screenshot.png'
# Connect with a VNC viewer
vncviewer localhost:5955
# Check if QEMU is running
ps aux | grep 'qemu-system' | grep -v grep
# Check nix build log for a store path
nix log /nix/store/HASH-windows-update-....qcow2
# Check image info
nix-shell -p qemu --run 'qemu-img info /nix/store/HASH-....qcow2'
```
## Image sizes observed
| Image | disk size | virtual size |
|-------|-----------|-------------|
| upstream (win10-ltsc-2021) | 5.02 GB | 64 GB |
| updated (killed build, round 1 only) | 8.33 GB | 64 GB |
| upstream (compacted, no updates) | 5.03 GB | 64 GB |
## Updates found by Windows Update (Win10 LTSC 2021 → May 2026)
1. **2022-02 Cumulative Update Preview for .NET Framework 3.5 and 4.8** (KB5010472)
2. **Microsoft .NET Framework 4.8.1** for Windows 10 21H2 x64 (KB5011048)
3. **Windows Malicious Software Removal Tool x64 v5.141** (KB890830)
4. **2026-05 Cumulative Update for .NET Framework 3.5, 4.8 and 4.8.1** (KB5088859)
5. **Security Intelligence Update for Microsoft Defender Antivirus** (KB2267602, Version 1.451.326.0+)
6. **2026-05 Cumulative Update for Windows 10 Version 21H2** (KB5087544) — the big one, ~870 MB
## Timing observations (4 vCPU, 4GB RAM machine)
- Nix evaluation: ~30 seconds
- VirtIO tools step (cached): instant
- Windows boot to Audit Mode desktop: ~60 seconds
- Windows Update search: ~2-3 minutes
- Download all 6 updates: ~3-5 minutes
- Install all updates (especially KB5087544): **50-70 minutes**
- Reboot + "Working on updates" finalization: ~10-15 minutes
- Total for round 1: ~70-90 minutes
- DISM cleanup: ~2-5 minutes
- qemu-img convert (compact): ~2-3 minutes
## Remaining TODO (for next session on faster machine)
- [ ] **CRITICAL**: Verify the Audit Mode preservation fix works (AuditBoot + AuditInProgress registry keys)
- [ ] If Audit Mode fix doesn't work, try `sysprep /audit /reboot /quiet` instead of `shutdown /r`
- [ ] Test round 2 → round 3 flow (find additional updates after cumulative? likely Defender definition updates)
- [ ] Test with `compact = true` to verify final standalone image
- [ ] Test full pipeline: `upstream → updated → basic → generalize`
- [ ] Test win11 images
- [ ] Consider using 8GB RAM (`memSize = 8192`) for faster update installs
- [ ] Consider: should `windowsUpdate` go before or after `virtioTools`? Currently before in the pipeline, but the explicit build command chains virtio first for better I/O
- [ ] The template is impure (downloads from Microsoft during build) — this is intentional but should be documented
- [ ] Consider `maxRounds = 1` mode for builds where you only want non-reboot updates
- [ ] The `compact` step doesn't compress — consider adding `-c` flag to `qemu-img convert` for compressed qcow2
- [ ] The wrapper's `shutdown /s /t 5` may still race with the script's `shutdown /r /t 0` — consider using `shutdown /a` (abort) before `shutdown /r` to cancel any pending shutdown
## Architecture notes
### How customizeImage works (for context)
1. Creates a COW overlay on the original image: `qemu-img create -f qcow2 -b ${originalImage} -F qcow2 disk.qcow2`
2. Optionally resizes: `qemu-img resize disk.qcow2 ${diskSize}`
3. Merges offline registry entries via `virt-win-reg --merge`
4. Injects audit script + wrapper via `virt-customize --upload`
5. Adds RunOnce registry entry for the wrapper
6. Boots QEMU with the image (user networking, UEFI, VirtIO or AHCI)
7. The wrapper runs the audit script, then shuts down
8. Optionally compacts: `qemu-img convert -O qcow2`
9. Moves result to `$out`
### The wrapper problem
The wrapper (`vmix-audit-wrapper.cmd`) is designed for simple, single-boot templates:
```batch
call C:\vmix-audit-script.cmd
del /q C:\vmix-audit-script.cmd
shutdown /s /t 5
del /q C:\vmix-audit-wrapper.cmd
```
This is fine for templates that don't reboot. But the Windows Update template needs multiple reboots, which conflicts with the wrapper's assumptions. The workarounds (copy script, self-shutdown) are necessary because modifying the wrapper would affect all templates.
A future improvement might be to add a `multiboot` flag to customizeImage that changes the wrapper behavior for templates that need reboots.
### Why QEMU user networking works for Windows Update
QEMU's `-nic user` (SLIRP) provides NAT networking. The guest gets DHCP and can reach the internet via the host. Windows Update uses HTTPS to Microsoft's servers, which works through NAT. No special firewall rules or port forwarding needed.
### Why VirtIO tools are chained before updates (in test builds)
The upstream image uses VirtIO storage (`if=virtio`) but doesn't have VirtIO guest tools installed. The update template doesn't need guest tools to work, but having them improves:
- Disk I/O performance (VirtIO balloon, better driver)
- Memory management
- Guest agent for monitoring
In the pipeline (`win10/images.nix`), updates are applied directly to `upstream` without virtio tools, because virtio tools installation is part of the `basic` step. For testing, we chain them explicitly.