2008-11-18 10:00:09 -08:00
|
|
|
|
{ config, pkgs, systemPath, wrapperDir
|
2008-11-22 17:29:20 -08:00
|
|
|
|
, defaultShell
|
2007-11-15 09:16:16 -08:00
|
|
|
|
}:
|
2006-12-11 07:32:10 -08:00
|
|
|
|
|
2007-01-16 08:09:43 -08:00
|
|
|
|
let
|
2008-11-22 17:29:20 -08:00
|
|
|
|
extraEtc = config.environment.etc;
|
|
|
|
|
nixEnvVars = config.nix.envVars;
|
|
|
|
|
modulesTree = config.system.modulesTree;
|
|
|
|
|
nssModulesPath = config.system.nssModules.path;
|
2007-01-16 08:09:43 -08:00
|
|
|
|
|
2007-06-10 13:02:07 -07:00
|
|
|
|
|
2007-11-09 10:49:45 -08:00
|
|
|
|
optional = pkgs.lib.optional;
|
2007-01-16 08:09:43 -08:00
|
|
|
|
|
2007-06-10 13:02:07 -07:00
|
|
|
|
|
|
|
|
|
# !!! ugh, these files shouldn't be created here.
|
|
|
|
|
|
|
|
|
|
|
2008-01-04 09:05:48 -08:00
|
|
|
|
pamConsoleHandlers = pkgs.writeText "console.handlers" ''
|
|
|
|
|
console consoledevs /dev/tty[0-9][0-9]* :[0-9]\.[0-9] :[0-9]
|
|
|
|
|
${pkgs.pam_console}/sbin/pam_console_apply lock logfail wait -t tty -s -c ${pamConsolePerms}
|
|
|
|
|
${pkgs.pam_console}/sbin/pam_console_apply unlock logfail wait -r -t tty -s -c ${pamConsolePerms}
|
|
|
|
|
'';
|
2007-06-10 13:02:07 -07:00
|
|
|
|
|
|
|
|
|
pamConsolePerms = ./security/console.perms;
|
|
|
|
|
|
2008-07-16 09:01:09 -07:00
|
|
|
|
|
2007-01-16 08:09:43 -08:00
|
|
|
|
in
|
2007-06-10 13:02:07 -07:00
|
|
|
|
|
2007-01-16 08:09:43 -08:00
|
|
|
|
|
2006-12-11 07:32:10 -08:00
|
|
|
|
import ../helpers/make-etc.nix {
|
|
|
|
|
inherit (pkgs) stdenv;
|
|
|
|
|
|
|
|
|
|
configFiles = [
|
|
|
|
|
{ # TCP/UDP port assignments.
|
|
|
|
|
source = pkgs.iana_etc + "/etc/services";
|
|
|
|
|
target = "services";
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
{ # IP protocol numbers.
|
|
|
|
|
source = pkgs.iana_etc + "/etc/protocols";
|
|
|
|
|
target = "protocols";
|
|
|
|
|
}
|
|
|
|
|
|
2008-03-17 05:33:21 -07:00
|
|
|
|
{ # RPC program numbers.
|
|
|
|
|
source = pkgs.glibc + "/etc/rpc";
|
|
|
|
|
target = "rpc";
|
|
|
|
|
}
|
|
|
|
|
|
2006-12-11 07:32:10 -08:00
|
|
|
|
{ # Hostname-to-IP mappings.
|
2008-01-04 09:05:48 -08:00
|
|
|
|
source = pkgs.substituteAll {
|
|
|
|
|
src = ./hosts;
|
|
|
|
|
extraHosts = config.networking.extraHosts;
|
|
|
|
|
};
|
2006-12-11 07:32:10 -08:00
|
|
|
|
target = "hosts";
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
{ # Friendly greeting on the virtual consoles.
|
2008-01-04 09:05:48 -08:00
|
|
|
|
source = pkgs.writeText "issue" ''
|
|
|
|
|
|
|
|
|
|
[1;32m${config.services.mingetty.greetingLine}[0m
|
|
|
|
|
${config.services.mingetty.helpLine}
|
|
|
|
|
|
|
|
|
|
'';
|
2006-12-11 07:32:10 -08:00
|
|
|
|
target = "issue";
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
{ # Configuration for pwdutils (login, passwd, useradd, etc.).
|
|
|
|
|
# You cannot login without it!
|
2007-03-30 05:59:43 -07:00
|
|
|
|
source = ./login.defs;
|
2006-12-11 07:32:10 -08:00
|
|
|
|
target = "login.defs";
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
{ # Configuration for passwd and friends (e.g., hash algorithm
|
|
|
|
|
# for /etc/passwd).
|
2007-03-30 05:59:43 -07:00
|
|
|
|
source = ./default/passwd;
|
2006-12-11 07:32:10 -08:00
|
|
|
|
target = "default/passwd";
|
|
|
|
|
}
|
|
|
|
|
|
2007-03-20 06:30:14 -07:00
|
|
|
|
{ # Configuration for useradd.
|
|
|
|
|
source = pkgs.substituteAll {
|
2007-03-30 05:59:43 -07:00
|
|
|
|
src = ./default/useradd;
|
2007-03-20 06:30:14 -07:00
|
|
|
|
inherit defaultShell;
|
|
|
|
|
};
|
|
|
|
|
target = "default/useradd";
|
|
|
|
|
}
|
|
|
|
|
|
2006-12-22 09:28:25 -08:00
|
|
|
|
{ # Dhclient hooks for emitting ip-up/ip-down events.
|
|
|
|
|
source = pkgs.substituteAll {
|
2007-03-30 05:59:43 -07:00
|
|
|
|
src = ./dhclient-exit-hooks;
|
2007-01-23 02:22:00 -08:00
|
|
|
|
inherit (pkgs) upstart glibc;
|
2006-12-22 09:28:25 -08:00
|
|
|
|
};
|
|
|
|
|
target = "dhclient-exit-hooks";
|
|
|
|
|
}
|
2007-01-15 06:43:56 -08:00
|
|
|
|
|
2008-03-12 03:18:11 -07:00
|
|
|
|
{ # Script executed when the shell starts as a non-login shell (system-wide version).
|
2007-01-15 06:43:56 -08:00
|
|
|
|
source = pkgs.substituteAll {
|
2008-07-16 09:01:09 -07:00
|
|
|
|
src = ./bashrc.sh;
|
2008-03-17 06:58:57 -07:00
|
|
|
|
inherit systemPath wrapperDir modulesTree nssModulesPath;
|
2008-01-06 10:45:13 -08:00
|
|
|
|
inherit (pkgs) glibc;
|
2007-11-09 10:49:45 -08:00
|
|
|
|
timeZone = config.time.timeZone;
|
|
|
|
|
defaultLocale = config.i18n.defaultLocale;
|
2007-11-15 09:16:16 -08:00
|
|
|
|
inherit nixEnvVars;
|
2007-01-15 06:43:56 -08:00
|
|
|
|
};
|
2008-07-16 09:01:09 -07:00
|
|
|
|
target = "bashrc";
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
{ # Script executed when the shell starts as a login shell.
|
|
|
|
|
source = ./profile.sh;
|
2007-01-15 06:43:56 -08:00
|
|
|
|
target = "profile";
|
|
|
|
|
}
|
2007-01-16 08:09:43 -08:00
|
|
|
|
|
2007-05-02 02:55:35 -07:00
|
|
|
|
{ # Configuration for readline in bash.
|
|
|
|
|
source = ./inputrc;
|
|
|
|
|
target = "inputrc";
|
|
|
|
|
}
|
|
|
|
|
|
2007-11-05 03:19:51 -08:00
|
|
|
|
{ # Nix configuration.
|
2008-01-04 09:05:48 -08:00
|
|
|
|
source = pkgs.writeText "nix.conf" ''
|
2007-11-05 03:19:51 -08:00
|
|
|
|
# WARNING: this file is generated.
|
|
|
|
|
build-users-group = nixbld
|
2007-11-09 10:49:45 -08:00
|
|
|
|
build-max-jobs = ${toString (config.nix.maxJobs)}
|
|
|
|
|
build-use-chroot = ${if config.nix.useChroot then "true" else "false"}
|
2008-10-29 08:42:44 -07:00
|
|
|
|
build-chroot-dirs = /dev /dev/pts /proc /bin
|
2007-11-09 10:49:45 -08:00
|
|
|
|
${config.nix.extraOptions}
|
2008-01-04 09:05:48 -08:00
|
|
|
|
'';
|
2007-11-05 03:19:51 -08:00
|
|
|
|
target = "nix.conf"; # will be symlinked from /nix/etc/nix/nix.conf in activate-configuration.sh.
|
|
|
|
|
}
|
2007-11-08 10:15:12 -08:00
|
|
|
|
|
2008-03-12 03:18:11 -07:00
|
|
|
|
{ # Script executed when the shell starts as a non-login shell (user version).
|
|
|
|
|
source = ./skel/bashrc;
|
|
|
|
|
target = "skel/.bashrc";
|
|
|
|
|
}
|
|
|
|
|
|
2008-01-16 05:59:03 -08:00
|
|
|
|
{ # SSH configuration. Slight duplication of the sshd_config
|
|
|
|
|
# generation in the sshd service.
|
|
|
|
|
source = pkgs.writeText "ssh_config" ''
|
|
|
|
|
${if config.services.sshd.forwardX11 then ''
|
|
|
|
|
ForwardX11 yes
|
|
|
|
|
XAuthLocation ${pkgs.xorg.xauth}/bin/xauth
|
|
|
|
|
'' else ''
|
|
|
|
|
ForwardX11 no
|
|
|
|
|
''}
|
|
|
|
|
'';
|
|
|
|
|
target = "ssh/ssh_config";
|
|
|
|
|
}
|
2006-12-11 07:32:10 -08:00
|
|
|
|
]
|
|
|
|
|
|
2007-11-08 10:15:12 -08:00
|
|
|
|
# Configuration for ssmtp.
|
2007-11-09 10:49:45 -08:00
|
|
|
|
++ optional config.networking.defaultMailServer.directDelivery {
|
2008-01-04 09:05:48 -08:00
|
|
|
|
source = let cfg = config.networking.defaultMailServer; in pkgs.writeText "ssmtp.conf" ''
|
2008-04-24 05:36:50 -07:00
|
|
|
|
MailHub=${cfg.hostName}
|
|
|
|
|
FromLineOverride=YES
|
2008-01-04 09:05:48 -08:00
|
|
|
|
${if cfg.domain != "" then "rewriteDomain=${cfg.domain}" else ""}
|
|
|
|
|
UseTLS=${if cfg.useTLS then "YES" else "NO"}
|
|
|
|
|
UseSTARTTLS=${if cfg.useSTARTTLS then "YES" else "NO"}
|
|
|
|
|
#Debug=YES
|
|
|
|
|
'';
|
2007-11-08 10:15:12 -08:00
|
|
|
|
target = "ssmtp/ssmtp.conf";
|
2007-11-09 10:49:45 -08:00
|
|
|
|
}
|
2007-11-08 10:15:12 -08:00
|
|
|
|
|
2007-01-22 08:42:29 -08:00
|
|
|
|
# Configuration file for fontconfig used to locate
|
|
|
|
|
# (X11) client-rendered fonts.
|
2008-02-13 23:42:52 -08:00
|
|
|
|
++ optional config.fonts.enableFontConfig {
|
2008-07-03 07:35:02 -07:00
|
|
|
|
source = pkgs.makeFontsConf {
|
|
|
|
|
fontDirectories = import ../system/fonts.nix {inherit pkgs config;};
|
|
|
|
|
};
|
2007-01-22 08:42:29 -08:00
|
|
|
|
target = "fonts/fonts.conf";
|
2007-11-09 10:49:45 -08:00
|
|
|
|
}
|
2007-01-22 08:42:29 -08:00
|
|
|
|
|
2007-01-16 08:09:43 -08:00
|
|
|
|
# LDAP configuration.
|
2007-11-09 10:49:45 -08:00
|
|
|
|
++ optional config.users.ldap.enable {
|
2007-04-10 07:10:45 -07:00
|
|
|
|
source = import ./ldap.conf.nix {
|
2007-01-16 08:09:43 -08:00
|
|
|
|
inherit (pkgs) writeText;
|
|
|
|
|
inherit config;
|
|
|
|
|
};
|
|
|
|
|
target = "ldap.conf";
|
2007-11-09 10:49:45 -08:00
|
|
|
|
}
|
2007-01-16 08:09:43 -08:00
|
|
|
|
|
2007-08-16 08:09:06 -07:00
|
|
|
|
# "sudo" configuration.
|
2007-11-09 10:49:45 -08:00
|
|
|
|
++ optional config.security.sudo.enable {
|
2007-08-16 08:09:06 -07:00
|
|
|
|
source = pkgs.runCommand "sudoers"
|
2007-11-09 10:49:45 -08:00
|
|
|
|
{ src = pkgs.writeText "sudoers-in" (config.security.sudo.configFile);
|
2007-08-16 08:09:06 -07:00
|
|
|
|
}
|
|
|
|
|
# Make sure that the sudoers file is syntactically valid.
|
2007-10-10 07:28:40 -07:00
|
|
|
|
# (currently disabled - NIXOS-66)
|
|
|
|
|
#"${pkgs.sudo}/sbin/visudo -f $src -c && cp $src $out";
|
|
|
|
|
"cp $src $out";
|
2007-08-16 08:09:06 -07:00
|
|
|
|
target = "sudoers";
|
|
|
|
|
mode = "0440";
|
2007-11-09 10:49:45 -08:00
|
|
|
|
}
|
2007-08-16 08:09:06 -07:00
|
|
|
|
|
2006-12-11 07:32:10 -08:00
|
|
|
|
# A bunch of PAM configuration files for various programs.
|
|
|
|
|
++ (map
|
|
|
|
|
(program:
|
2007-11-09 10:49:45 -08:00
|
|
|
|
let isLDAPEnabled = config.users.ldap.enable; in
|
2006-12-11 07:32:10 -08:00
|
|
|
|
{ source = pkgs.substituteAll {
|
2007-03-30 05:59:43 -07:00
|
|
|
|
src = ./pam.d + ("/" + program);
|
2007-06-10 13:02:07 -07:00
|
|
|
|
inherit (pkgs) pam_unix2 pam_console;
|
2007-01-16 08:09:43 -08:00
|
|
|
|
pam_ldap =
|
2007-06-10 13:02:07 -07:00
|
|
|
|
if isLDAPEnabled
|
2007-01-16 08:09:43 -08:00
|
|
|
|
then pkgs.pam_ldap
|
|
|
|
|
else "/no-such-path";
|
2007-01-16 14:25:28 -08:00
|
|
|
|
inherit (pkgs.xorg) xauth;
|
2008-07-16 09:01:09 -07:00
|
|
|
|
inherit pamConsoleHandlers;
|
2007-06-10 13:02:07 -07:00
|
|
|
|
isLDAPEnabled = if isLDAPEnabled then "" else "#";
|
2006-12-11 07:32:10 -08:00
|
|
|
|
};
|
|
|
|
|
target = "pam.d/" + program;
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
[
|
2008-04-01 03:16:35 -07:00
|
|
|
|
"atd"
|
2006-12-11 07:32:10 -08:00
|
|
|
|
"login"
|
2007-06-05 04:28:18 -07:00
|
|
|
|
"slim"
|
2007-01-11 07:32:48 -08:00
|
|
|
|
"su"
|
2007-07-09 04:21:04 -07:00
|
|
|
|
"sudo"
|
2006-12-16 13:48:12 -08:00
|
|
|
|
"other"
|
2006-12-11 07:32:10 -08:00
|
|
|
|
"passwd"
|
2006-12-16 13:48:12 -08:00
|
|
|
|
"shadow"
|
|
|
|
|
"sshd"
|
2008-03-06 06:38:17 -08:00
|
|
|
|
"lshd"
|
2008-03-06 06:49:06 -08:00
|
|
|
|
"lsh-pam-checkpw"
|
2006-12-11 07:32:10 -08:00
|
|
|
|
"useradd"
|
2007-02-26 13:18:13 -08:00
|
|
|
|
"chsh"
|
2008-03-06 05:52:10 -08:00
|
|
|
|
"xlock"
|
2008-06-20 06:32:39 -07:00
|
|
|
|
"kde"
|
2008-11-07 03:51:17 -08:00
|
|
|
|
"cups"
|
2007-01-30 07:03:43 -08:00
|
|
|
|
"common"
|
2007-06-10 13:02:07 -07:00
|
|
|
|
"common-console" # shared stuff for interactive local sessions
|
2006-12-11 07:32:10 -08:00
|
|
|
|
]
|
2007-03-30 05:55:09 -07:00
|
|
|
|
)
|
|
|
|
|
|
2007-11-15 09:16:16 -08:00
|
|
|
|
# List of machines for distributed Nix builds in the format expected
|
|
|
|
|
# by build-remote.pl.
|
|
|
|
|
++ optional config.nix.distributedBuilds {
|
|
|
|
|
source = pkgs.writeText "nix.machines"
|
|
|
|
|
(pkgs.lib.concatStrings (map (machine:
|
|
|
|
|
"${machine.sshUser}@${machine.hostName} ${machine.system} ${machine.sshKey} ${toString machine.maxJobs}\n"
|
|
|
|
|
) config.nix.buildMachines));
|
|
|
|
|
target = "nix.machines";
|
|
|
|
|
}
|
|
|
|
|
|
2008-06-11 16:06:53 -07:00
|
|
|
|
# unixODBC drivers (this solution is not perfect.. Because the user has to
|
|
|
|
|
# ask the admin to add a driver.. but it's an easy solution which works)
|
|
|
|
|
++ (let inis = config.environment.unixODBCDrivers pkgs;
|
2008-06-12 05:19:47 -07:00
|
|
|
|
in optional (inis != [] ) {
|
2008-06-11 16:06:53 -07:00
|
|
|
|
source = pkgs.writeText "odbcinst.ini" (pkgs.lib.concatStringsSep "\n" inis);
|
|
|
|
|
target = "odbcinst.ini";
|
|
|
|
|
})
|
|
|
|
|
|
2007-03-30 05:55:09 -07:00
|
|
|
|
# Additional /etc files declared by Upstart jobs.
|
|
|
|
|
++ extraEtc;
|
2007-02-26 13:18:13 -08:00
|
|
|
|
}
|