Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
82 lines
No EOL
2.2 KiB
Nix
82 lines
No EOL
2.2 KiB
Nix
# minimal set of scripts and services by various images
|
|
{ pkgs, lib, ... }: {
|
|
# bring back simple interface names like eth0 eth1 etc
|
|
grub-ifnames-0 = pkgs.writeText "grub-ifnames-0" ''
|
|
GRUB_CMDLINE_LINUX="net.ifnames=0 biosdevname=0 $GRUB_CMDLINE_LINUX"
|
|
'';
|
|
|
|
# no need for CPU microcode updating in VMs
|
|
grub-disable-microcode = pkgs.writeText "grub-disable-microcode" ''
|
|
GRUB_CMDLINE_LINUX="dis_ucode_ldr $GRUB_CMDLINE_LINUX"
|
|
'';
|
|
|
|
# dhcp for eth0
|
|
dhcp-network-for-iface = { iface, routeMetric ? 1024, useDNS ? true }: pkgs.writeText "${iface}-network" ''
|
|
[Match]
|
|
Name=${iface}
|
|
|
|
[Network]
|
|
DHCP=yes
|
|
|
|
[DHCP]
|
|
ClientIdentifier=mac
|
|
RouteMetric=${toString routeMetric}
|
|
|
|
${if useDNS then ''
|
|
[DHCPv4]
|
|
UseDNS=True
|
|
UseDomains=True
|
|
'' else ''
|
|
[DHCPv4]
|
|
UseDNS=false
|
|
''}
|
|
'';
|
|
|
|
# generate ssh host keys before starting sshd
|
|
ssh-service-override-conf-create = pkgs.writeScript "ssh-override-conf-create.sh" ''
|
|
mkdir -p /etc/systemd/system/ssh.service.d
|
|
|
|
cat > /etc/systemd/system/ssh.service.d/override.conf << EOF
|
|
[Service]
|
|
ExecStartPre=
|
|
ExecStartPre=`which ssh-keygen` -A
|
|
ExecStartPre=`which sshd` -t
|
|
|
|
EOF
|
|
'';
|
|
|
|
# script to grow root partition
|
|
grow-root-sh = pkgs.writeScript "grow-root-sh" ''
|
|
#!/bin/bash
|
|
set -e
|
|
|
|
command -v growpart >/dev/null || { >&2 echo "growpart not found. Install package cloud-guest-utils or cloud-utils."; exit 1; }
|
|
|
|
ROOTPART=$(findmnt / -o source -n)
|
|
DISK=''${ROOTPART%[0-9]*}
|
|
PARTNUM=''${ROOTPART##*[!0-9]}
|
|
|
|
# resize and grow if possible
|
|
growpart "$DISK" "$PARTNUM" && resize2fs "$ROOTPART" || true
|
|
'';
|
|
|
|
# service to grow root partition on boot
|
|
grow-root-service = pkgs.writeText "grow-root-service" ''
|
|
[Service]
|
|
Type = oneshot
|
|
ExecStart = /usr/local/sbin/grow-root.sh
|
|
|
|
[Install]
|
|
WantedBy = multi-user.target
|
|
'';
|
|
|
|
add-9p-mounts-to-fstab = shares:
|
|
let
|
|
shareToFstabEntry = name: share: "${name} ${share.target} 9p trans=virtio,version=9p2000.L,rw,posixacl,msize=104857600,cache=loose 0 0";
|
|
in
|
|
pkgs.writeText "9p-to-fstab-sh" ''
|
|
cat >> /etc/fstab << EOF
|
|
${lib.concatStringsSep "\n" (lib.mapAttrsToList shareToFstabEntry shares)}
|
|
EOF
|
|
'';
|
|
} |