aboutsummaryrefslogtreecommitdiffhomepage
path: root/nixos.nix
diff options
context:
space:
mode:
Diffstat (limited to 'nixos.nix')
-rw-r--r--nixos.nix62
1 files changed, 30 insertions, 32 deletions
diff --git a/nixos.nix b/nixos.nix
index 35486679..800c81e3 100644
--- a/nixos.nix
+++ b/nixos.nix
@@ -24,11 +24,38 @@ let
getsubuid = userid: appid: userid * 100000 + 10000 + appid;
getsubname = userid: appid: "u${toString userid}_a${toString appid}";
getsubhome = userid: appid: "${cfg.stateDir}/u${toString userid}/a${toString appid}";
+
+ mountpoints = {
+ ${cfg.sharefs.name} = mkIf (cfg.sharefs.source != null) {
+ depends = [ cfg.sharefs.source ];
+ device = "sharefs";
+ fsType = "fuse.sharefs";
+ noCheck = true;
+ options = [
+ "rw"
+ "noexec"
+ "nosuid"
+ "nodev"
+ "noatime"
+ "allow_other"
+ "mkdir"
+ "source=${cfg.sharefs.source}"
+ "setuid=${toString config.users.users.${cfg.sharefs.user}.uid}"
+ "setgid=${toString config.users.groups.${cfg.sharefs.group}.gid}"
+ ];
+ };
+ };
in
{
imports = [ (import ./options.nix packages) ];
+ options = {
+ # Forward declare a dummy option for VM filesystems since the real one won't exist
+ # unless the VM module is actually imported.
+ virtualisation.fileSystems = lib.mkOption { };
+ };
+
config = mkIf cfg.enable {
assertions = [
(
@@ -66,38 +93,9 @@ in
) "" cfg.users;
};
- systemd.services = {
- sharefs = mkIf (cfg.sharefs.source != null) {
- unitConfig.RequiresMountsFor = cfg.sharefs.source;
- serviceConfig = {
- NoNewPrivileges = true;
- };
- script = ''
- ${pkgs.coreutils}/bin/install -dm0 ${cfg.sharefs.name}
-
- exec ${cfg.package}/libexec/sharefs -f \
- -o ${
- lib.join "," [
- "noexec"
- "nosuid"
- "nodev"
- "noatime"
- "auto_unmount"
- "allow_other"
- "setuid=$(id -u ${cfg.sharefs.user})"
- "setgid=$(id -g ${cfg.sharefs.group})"
- "source=${cfg.sharefs.source}"
- "mkdir"
- ]
- } ${cfg.sharefs.name}
- '';
-
- # do not unmount on configuration changes
- restartIfChanged = false;
-
- wantedBy = [ "multi-user.target" ];
- };
- };
+ environment.systemPackages = optional (cfg.sharefs.source != null) cfg.sharefs.package;
+ fileSystems = mountpoints;
+ virtualisation.fileSystems = mountpoints;
home-manager =
let