Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
69 lines
2.4 KiB
Nix
69 lines
2.4 KiB
Nix
# Build a pre-installed Windows qcow2 image using QEMU unattended install.
|
|
# Boots into Audit Mode after install and shuts down.
|
|
# Apply templates via customizeImageFold to install software (auditScript)
|
|
# and customize registry (windowsRegistry), then generalize when done.
|
|
{ pkgs, lib, drivers, makeWinISO, makeAuditModeAutounattend, ... }:
|
|
{
|
|
name ? "windows",
|
|
upstreamISO,
|
|
productKey ? "",
|
|
imageIndex ? 1,
|
|
diskSize ? "64G",
|
|
bypassRequirements ? false,
|
|
locale ? "en-US",
|
|
efi ? true,
|
|
smp ? 4,
|
|
memSize ? 4096,
|
|
vncDisplay ? null, # e.g. ":10" to enable VNC on port 5910 for monitoring
|
|
windowsVersionForVirtioDrivers ? "w10", # "w10", "w11", "2k22", "2k19", etc.
|
|
}:
|
|
let
|
|
AutounattendedXml = makeAuditModeAutounattend {
|
|
inherit locale productKey imageIndex
|
|
efi bypassRequirements windowsVersionForVirtioDrivers;
|
|
diskIndex = 0;
|
|
virtioDriverLetter = "E";
|
|
};
|
|
|
|
iso = makeWinISO {
|
|
iso = upstreamISO;
|
|
inherit AutounattendedXml;
|
|
};
|
|
|
|
drv = pkgs.runCommand "${name}-vmix.qcow2" {
|
|
__noChroot = true;
|
|
requiredSystemFeatures = [ "kvm" ];
|
|
nativeBuildInputs = with pkgs; [ qemu ];
|
|
} ''
|
|
# create empty disk
|
|
qemu-img create -f qcow2 disk.qcow2 ${diskSize}
|
|
|
|
# writable UEFI NVRAM so boot order persists across reboots
|
|
cp ${pkgs.OVMF.fd}/FV/OVMF_VARS.fd vars.fd
|
|
chmod +w vars.fd
|
|
|
|
echo "=== Starting Windows unattended install (this takes 15-30 minutes) ==="
|
|
|
|
# Windows installs unattended, reboots into Audit Mode,
|
|
# deletes cached Autounattend, shuts down → QEMU exits.
|
|
timeout 3600 qemu-system-x86_64 \
|
|
${if vncDisplay != null then "-vnc ${vncDisplay}" else "-nographic"} \
|
|
-accel kvm \
|
|
-m ${toString memSize} \
|
|
-smp ${toString smp} \
|
|
-cpu host \
|
|
-machine type=q35 \
|
|
-drive if=pflash,format=raw,readonly=on,file=${pkgs.OVMF.fd}/FV/OVMF_CODE.fd \
|
|
-drive if=pflash,format=raw,file=vars.fd \
|
|
-rtc base=localtime,clock=host \
|
|
-device qemu-xhci -device usb-tablet \
|
|
-global ICH9-LMB.disable_s3=1 -global ICH9-LMB.disable_s4=1 \
|
|
-drive file=disk.qcow2,format=qcow2,if=virtio \
|
|
-drive file=${iso},media=cdrom,readonly=on \
|
|
-drive file=${drivers.virtio-iso},media=cdrom,readonly=on \
|
|
-nic user,model=virtio-net-pci
|
|
|
|
echo "=== Windows install complete (Audit Mode image) ==="
|
|
mv disk.qcow2 $out
|
|
'';
|
|
in drv // { _vmixOsType = "windows"; }
|