diff --git a/configuration/rescue-cd.nix b/configuration/rescue-cd.nix index 819eb6785db..5aa860ef9fb 100644 --- a/configuration/rescue-cd.nix +++ b/configuration/rescue-cd.nix @@ -76,6 +76,11 @@ rec { nixpkgsURL = http://nix.cs.uu.nl/dist/nix/ + nixpkgsRel; }; + security = { + sudo = { + enable = false; + }; + }; }; diff --git a/etc/default.nix b/etc/default.nix index c61e87c4c7e..33f85cb67a0 100644 --- a/etc/default.nix +++ b/etc/default.nix @@ -140,6 +140,17 @@ import ../helpers/make-etc.nix { target = "ldap.conf"; }) + # "sudo" configuration. + ++ (optional ["security" "sudo" "enable"] { + source = pkgs.runCommand "sudoers" + { src = pkgs.writeText "sudoers-in" (config.get ["security" "sudo" "configFile"]); + } + # Make sure that the sudoers file is syntactically valid. + "${pkgs.sudo}/sbin/visudo -f $src -c && cp $src $out"; + target = "sudoers"; + mode = "0440"; + }) + # A bunch of PAM configuration files for various programs. ++ (map (program: diff --git a/helpers/make-etc.nix b/helpers/make-etc.nix index 9785823248a..94ea248f669 100644 --- a/helpers/make-etc.nix +++ b/helpers/make-etc.nix @@ -8,4 +8,5 @@ stdenv.mkDerivation { /* !!! Use toXML. */ sources = map (x: x.source) configFiles; targets = map (x: x.target) configFiles; + modes = map (x: if x ? mode then x.mode else "symlink") configFiles; } diff --git a/helpers/make-etc.sh b/helpers/make-etc.sh index 7834d553fdc..a7643b63c5b 100644 --- a/helpers/make-etc.sh +++ b/helpers/make-etc.sh @@ -4,7 +4,11 @@ ensureDir $out/etc sources_=($sources) targets_=($targets) +modes_=($modes) for ((i = 0; i < ${#targets_[@]}; i++)); do ensureDir $out/etc/$(dirname ${targets_[$i]}) ln -s ${sources_[$i]} $out/etc/${targets_[$i]} + if test "${modes_[$i]}" != symlink; then + echo "${modes_[$i]}" > $out/etc/${targets_[$i]}.mode + fi done diff --git a/installer/nixos-rebuild.sh b/installer/nixos-rebuild.sh index 33639daa568..190e21d371c 100644 --- a/installer/nixos-rebuild.sh +++ b/installer/nixos-rebuild.sh @@ -30,15 +30,17 @@ if test -z "$NIXOS_CONFIG"; then NIXOS_CONFIG=/etc/nixos/configuration.nix; fi # Pull the manifests defined in the configuration (the "manifests" # attribute). Wonderfully hacky. -manifests=$(nix-instantiate --eval-only --xml --strict \ - $NIXOS/system/system.nix \ - --arg configuration "import $NIXOS_CONFIG" \ - -A manifests \ - | grep '