{ config, lib, pkgs, ... }: let cfg = config.security.pam.mount; oflRequired = cfg.logoutHup || cfg.logoutTerm || cfg.logoutKill; fake_ofl = pkgs.writeShellScriptBin "fake_ofl" '' SIGNAL=$1 MNTPT=$2 ${pkgs.lsof}/bin/lsof | ${pkgs.gnugrep}/bin/grep $MNTPT | ${pkgs.gawk}/bin/awk '{print $2}' | ${pkgs.findutils}/bin/xargs ${pkgs.util-linux}/bin/kill -$SIGNAL ''; anyPamMount = lib.any (lib.attrByPath [ "pamMount" ] false) ( lib.attrValues config.security.pam.services ); in { options = { security.pam.mount = { enable = lib.mkOption { type = lib.types.bool; default = false; description = '' Enable PAM mount system to mount filesystems on user login. ''; }; extraVolumes = lib.mkOption { type = lib.types.listOf lib.types.str; default = [ ]; description = '' List of volume definitions for pam_mount. For more information, visit . ''; }; additionalSearchPaths = lib.mkOption { type = lib.types.listOf lib.types.package; default = [ ]; example = lib.literalExpression "[ pkgs.bindfs ]"; description = '' Additional programs to include in the search path of pam_mount. Useful for example if you want to use some FUSE filesystems like bindfs. ''; }; cryptMountOptions = lib.mkOption { type = lib.types.listOf lib.types.str; default = [ ]; example = lib.literalExpression '' [ "allow_discard" ] ''; description = '' Global mount options that apply to every crypt volume. You can define volume-specific options in the volume definitions. ''; }; fuseMountOptions = lib.mkOption { type = lib.types.listOf lib.types.str; default = [ ]; example = lib.literalExpression '' [ "nodev" "nosuid" "force-user=%(USER)" "gid=%(USERGID)" "perms=0700" "chmod-deny" "chown-deny" "chgrp-deny" ] ''; description = '' Global mount options that apply to every FUSE volume. You can define volume-specific options in the volume definitions. ''; }; debugLevel = lib.mkOption { type = lib.types.int; default = 0; example = 1; description = '' Sets the Debug-Level. 0 disables debugging, 1 enables pam_mount tracing, and 2 additionally enables tracing in mount.crypt. The default is 0. For more information, visit . ''; }; logoutWait = lib.mkOption { type = lib.types.int; default = 0; description = '' Amount of microseconds to wait until killing remaining processes after final logout. For more information, visit . ''; }; logoutHup = lib.mkOption { type = lib.types.bool; default = false; description = '' Kill remaining processes after logout by sending a SIGHUP. ''; }; logoutTerm = lib.mkOption { type = lib.types.bool; default = false; description = '' Kill remaining processes after logout by sending a SIGTERM. ''; }; logoutKill = lib.mkOption { type = lib.types.bool; default = false; description = '' Kill remaining processes after logout by sending a SIGKILL. ''; }; createMountPoints = lib.mkOption { type = lib.types.bool; default = true; description = '' Create mountpoints for volumes if they do not exist. ''; }; removeCreatedMountPoints = lib.mkOption { type = lib.types.bool; default = true; description = '' Remove mountpoints created by pam_mount after logout. This only affects mountpoints that have been created by pam_mount in the same session. ''; }; }; }; config = lib.mkIf (cfg.enable || anyPamMount) { environment.systemPackages = [ pkgs.pam_mount ]; environment.etc."security/pam_mount.conf.xml" = { source = let extraUserVolumes = lib.filterAttrs ( n: u: u.cryptHomeLuks != null || u.pamMount != { } ) config.users.users; mkAttr = k: v: ''${k}="${v}"''; userVolumeEntry = user: let attrs = { user = user.name; path = user.cryptHomeLuks; mountpoint = user.home; } // user.pamMount; in "\n"; in pkgs.writeText "pam_mount.conf.xml" '' ${lib.makeBinPath ([ pkgs.util-linux ] ++ cfg.additionalSearchPaths)} ${pkgs.fuse}/bin/mount.fuse %(VOLUME) %(MNTPT) -o ,${ lib.concatStringsSep "," (cfg.fuseMountOptions ++ [ "%(OPTIONS)" ]) }' ${pkgs.fuse}/bin/fusermount -u %(MNTPT) ${pkgs.pam_mount}/bin/mount.crypt -o ,${ lib.concatStringsSep "," (cfg.cryptMountOptions ++ [ "%(OPTIONS)" ]) } %(VOLUME) %(MNTPT) ${pkgs.pam_mount}/bin/umount.crypt %(MNTPT) ${pkgs.pam_mount}/bin/pmvarrun -u %(USER) -o %(OPERATION) ${lib.optionalString oflRequired "${fake_ofl}/bin/fake_ofl %(SIGNAL) %(MNTPT)"} ${lib.concatStrings (map userVolumeEntry (lib.attrValues extraUserVolumes))} ${lib.concatStringsSep "\n" cfg.extraVolumes} ''; }; }; }