{
config,
lib,
pkgs,
...
}:
let
cfg = config.security.pam.mount;
oflRequired = cfg.logoutHup || cfg.logoutTerm || cfg.logoutKill;
fake_ofl = pkgs.writeShellScriptBin "fake_ofl" ''
SIGNAL=$1
MNTPT=$2
${pkgs.lsof}/bin/lsof | ${pkgs.gnugrep}/bin/grep $MNTPT | ${pkgs.gawk}/bin/awk '{print $2}' | ${pkgs.findutils}/bin/xargs ${pkgs.util-linux}/bin/kill -$SIGNAL
'';
anyPamMount = lib.any (lib.attrByPath [ "pamMount" ] false) (
lib.attrValues config.security.pam.services
);
in
options = {
security.pam.mount = {
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Enable PAM mount system to mount filesystems on user login.
};
extraVolumes = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
List of volume definitions for pam_mount.
For more information, visit <https://pam-mount.sourceforge.net/pam_mount.conf.5.html>.
additionalSearchPaths = lib.mkOption {
type = lib.types.listOf lib.types.package;
example = lib.literalExpression "[ pkgs.bindfs ]";
Additional programs to include in the search path of pam_mount.
Useful for example if you want to use some FUSE filesystems like bindfs.
cryptMountOptions = lib.mkOption {
example = lib.literalExpression ''
[ "allow_discard" ]
Global mount options that apply to every crypt volume.
You can define volume-specific options in the volume definitions.
fuseMountOptions = lib.mkOption {
[ "nodev" "nosuid" "force-user=%(USER)" "gid=%(USERGID)" "perms=0700" "chmod-deny" "chown-deny" "chgrp-deny" ]
Global mount options that apply to every FUSE volume.
debugLevel = lib.mkOption {
type = lib.types.int;
default = 0;
example = 1;
Sets the Debug-Level. 0 disables debugging, 1 enables pam_mount tracing,
and 2 additionally enables tracing in mount.crypt. The default is 0.
logoutWait = lib.mkOption {
Amount of microseconds to wait until killing remaining processes after
final logout.
logoutHup = lib.mkOption {
Kill remaining processes after logout by sending a SIGHUP.
logoutTerm = lib.mkOption {
Kill remaining processes after logout by sending a SIGTERM.
logoutKill = lib.mkOption {
Kill remaining processes after logout by sending a SIGKILL.
createMountPoints = lib.mkOption {
default = true;
Create mountpoints for volumes if they do not exist.
removeCreatedMountPoints = lib.mkOption {
Remove mountpoints created by pam_mount after logout. This
only affects mountpoints that have been created by pam_mount
in the same session.
config = lib.mkIf (cfg.enable || anyPamMount) {
environment.systemPackages = [ pkgs.pam_mount ];
environment.etc."security/pam_mount.conf.xml" = {
source =
extraUserVolumes = lib.filterAttrs (
n: u: u.cryptHomeLuks != null || u.pamMount != { }
) config.users.users;
mkAttr = k: v: ''${k}="${v}"'';
userVolumeEntry =
user:
attrs = {
user = user.name;
path = user.cryptHomeLuks;
mountpoint = user.home;
} // user.pamMount;
"<volume ${lib.concatStringsSep " " (lib.mapAttrsToList mkAttr attrs)} />\n";
pkgs.writeText "pam_mount.conf.xml" ''
<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE pam_mount SYSTEM "pam_mount.conf.xml.dtd">
<!-- auto generated from Nixos: modules/config/users-groups.nix -->
<pam_mount>
<debug enable="${toString cfg.debugLevel}" />
<!-- if activated, requires ofl from hxtools to be present -->
<logout wait="${toString cfg.logoutWait}" hup="${if cfg.logoutHup then "yes" else "no"}" term="${
if cfg.logoutTerm then "yes" else "no"
}" kill="${if cfg.logoutKill then "yes" else "no"}" />
<!-- set PATH variable for pam_mount module -->
<path>${lib.makeBinPath ([ pkgs.util-linux ] ++ cfg.additionalSearchPaths)}</path>
<!-- create mount point if not present -->
<mkmountpoint enable="${if cfg.createMountPoints then "1" else "0"}" remove="${
if cfg.removeCreatedMountPoints then "true" else "false"
}" />
<!-- specify the binaries to be called -->
<!-- the comma in front of the options is necessary for empty options -->
<fusemount>${pkgs.fuse}/bin/mount.fuse %(VOLUME) %(MNTPT) -o ,${
lib.concatStringsSep "," (cfg.fuseMountOptions ++ [ "%(OPTIONS)" ])
}'</fusemount>
<fuseumount>${pkgs.fuse}/bin/fusermount -u %(MNTPT)</fuseumount>
<cryptmount>${pkgs.pam_mount}/bin/mount.crypt -o ,${
lib.concatStringsSep "," (cfg.cryptMountOptions ++ [ "%(OPTIONS)" ])
} %(VOLUME) %(MNTPT)</cryptmount>
<cryptumount>${pkgs.pam_mount}/bin/umount.crypt %(MNTPT)</cryptumount>
<pmvarrun>${pkgs.pam_mount}/bin/pmvarrun -u %(USER) -o %(OPERATION)</pmvarrun>
${lib.optionalString oflRequired "<ofl>${fake_ofl}/bin/fake_ofl %(SIGNAL) %(MNTPT)</ofl>"}
${lib.concatStrings (map userVolumeEntry (lib.attrValues extraUserVolumes))}
${lib.concatStringsSep "\n" cfg.extraVolumes}
</pam_mount>
}