Commit Graph

203 Commits

Author SHA1 Message Date
Fernando Rodrigues
70d349bd21 nixos/users-groups: set default user description definitions with mkDefault
The GECOS fields we set as the default for `nobody` and `root` are quite arbitrary, and it stands to reason that users may wish to alter them without resorting to `mkForce`.

Signed-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>
2026-08-18 17:41:57 +10:00
r-vdp
5692c926f2 nixos/users-groups: drop the weak-hash activation warning
The libxcrypt transition was in 23.05, so I think we've given
people sufficient time to fix hashes of mutable users.

Part of #475305.
2026-06-07 18:10:38 +03:00
Michael Daniels
2e87c2f8f4 nixos/*: remove unused let bindings
Generated using deadnix (with some manual work); split from #514611.
2026-05-01 20:39:14 -04:00
Will Fancher
5312ce1bae nixos/systemd-stage-1/users-groups: Assert against cryptsetup-askpass 2026-04-07 21:53:09 -04:00
Sandro
d9db9fe986 nixos/config: correct hashedPasswordFile doc (#403825) 2026-03-04 01:07:51 +00:00
isabel
80091ae929 nixos/users-groups: fix assertion (#399546) 2026-03-03 17:55:08 +00:00
Wolfgang Walther
fea5e1f7c1 various: add {file} tags for nixos option descriptions (#455811) 2026-02-10 10:01:28 +00:00
Dyego Aurélio
28096cc5e3 treewide: apply nixfmt 1.2.0 2026-01-22 18:37:56 -03:00
h7x4
b36f8e0b79 various: add {file} tags for nixos option descriptions 2026-01-18 21:49:31 +09:00
Grimmauld
1d19809402 linger-users: default to null, be explicit about null = imperative 2025-11-10 23:06:36 +01:00
Adam Dinwoodie
531d3a9a45 linger-users: allow disabling for bashless profile
The linger-users systemd unit runs a Bash script.  To allow this to be
avoided for the bashless profile, provide an option to have NixOS not
manage lingering for any users.

To make this feasible, add the possibility for each individual user
account to not have its lingering configuration managed by NixOS at all,
and make this the default from 26.05.  In practice, this won't result in
a change of behaviour except for people who manually use `loginctl
enable-linger` commands to add lingering for some user accounts, then
rely on NixOS to disable lingering the next time the systemd units are
restarted.
2025-11-09 19:54:39 +00:00
Adam Dinwoodie
2130c0a63e linger-users: log when deconfiguring linger
If systemd has recorded that a user should be lingering despite them not
having an account on the system, that record is removed.  When that
happens, log for the sake of future debugging and investigations.

Suggested-By: Grimmauld <grimmauld@grimmauld.de>
2025-11-08 18:20:30 +00:00
Adam Dinwoodie
e3cb0fe2ca linger-users: use systemd directory options
Using systemd properties avoids the need for manually running mkdir and
cd commands, and helps systemd clean up properly when appropriate.

Suggested-By: Grimmauld <grimmauld@grimmauld.de>
2025-11-08 18:20:30 +00:00
Adam Dinwoodie
ac476b9cbc users-groups: use loginctl from configured systemctl
If a user has configured a different systemd package,
linger-users.service should respect that and use the provided loginctl
executable rather than the one from the default nixpkgs package.
2025-11-08 18:16:04 +00:00
Adam Dinwoodie
3734842aa1 linger-users: fix shellcheck warnings
Running with systemd.enableStrictShellChecks with lingering users causes
failures due to parsing the output from `ls`.  Rewrite the script to
avoid parsing ls, and instead rely on loginctl enable-linger and
disable-linger commands being idempotent and run them unconditionally.

This also fixes a bug where the systemd unit for adding and removing
lingering user configuration is only enabled if there are users
configured with lingering in the NixOS configuration.  This means that
if a NixOS system is built with some lingering users, then the linger
configuration is removed from all those users, the script to disable
lingering won't be run, and those users will incorrectly continue to
have lingering enabled.

Fixes #418101.
2025-11-08 18:16:04 +00:00
Lukas Wurzinger
0a3b3a9dee nixos/users-groups: fix assertion 2025-10-23 04:05:01 +02:00
Aliaksandr
f28be96fda treewide: mkAliasOptionModuleMD -> mkAliasOptionModule 2025-10-21 15:42:47 +03:00
nixpkgs-ci[bot]
98a73a9815 Merge master into staging-next 2025-10-20 06:06:41 +00:00
h7x4
8414b2a6e0 nixos/users-groups: use submodule config in hashedPasswordFile.default (#432944) 2025-10-20 04:53:13 +00:00
nixpkgs-ci[bot]
94e79f47bf Merge master into staging-next 2025-10-18 00:15:17 +00:00
Sandro Jäckel
1f60b27cd1 userborn: do not use mkForce to disable activationScripts 2025-10-16 23:24:26 +02:00
Will Fancher
f75a8b7e9a nixos/users-groups: New clock system group 2025-10-03 01:35:22 -04:00
Rasheeq Azad
939fa2ab2b nixos/users-groups: use submodule config in hashedPasswordFile.default
This fixes nixos-option of hashedPasswordFile.
2025-08-11 17:34:53 -04:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
isabel
6cdee65115 nixos/users-groups: group members filter by enabled 2025-07-18 22:19:11 +01:00
Katalin Rebhan
6f7d7cf76f nixos/users-groups: allow changing default home directory 2025-05-25 19:25:06 +02:00
Christian Demsar
b8089bd262 nixos/config: correct hashedPasswordFile doc
`chpasswd -e` accepts entries in the form of:

    <user>:<hashed-password-etc>

However, using a value in the above format fails to set the password
hash. Using ONLY the <hashed-password> generated by `mkpasswd` works as
expected.
2025-05-03 01:42:49 -04:00
Silvan Mosberger
374e6bcc40 treewide: Format all Nix files
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:

  nix-build ci -A fmt.check

This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).

This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).

Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).

If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.
2025-04-01 20:10:43 +02:00
Silvan Mosberger
4f6e508a09 nixos/users-groups: Enforce ASCII usernames and fix repeated doubling of activation script runtime (#385904) 2025-03-19 17:33:49 +01:00
Philip Taron
f041d52e7b nixos/users-groups: Add assert on null shells (#279431) 2025-03-07 12:54:52 -08:00
Silvan Mosberger
b602f86829 nixos/users-groups: Catch invalid usernames early
Prevents running into the problem from the parent commit in the first
place.
2025-02-28 22:33:55 +01:00
Sandro
d1c535f62a nixos/user-groups: add a toggle for user account creation (#358646) 2025-02-27 23:47:20 +01:00
Sandro
03b6a553eb nixos/users-groups: split isSystemUser/isNormalUser and uid check into two (#357944) 2025-02-16 20:35:45 +01:00
NotAShelf
1dd23b5d74 nixos/user-groups: add a toggle for user account creation
Microscopic change that allows users to toggle user accounts, per user, conditionally.
2025-02-02 02:07:03 +03:00
Peder Bergebakken Sundt
953f72e76e nixos/*: tag manpage references 2025-01-27 02:47:01 +01:00
Maximilian Bosch
cb9b3fd788 nixos/modules: remove a few whitespaces from the pw override parts
Otherwise the evaluation warnings have a two or even three lines of
whitespace between paragraphs.
2024-12-22 15:32:56 +01:00
fidgetingbits
52ce5caf36 nixos/users-groups: Correct and refactor password override documentation
Testing showed that the existing documentation regarding password override
ordering was incorrect. This commit corrects the errors and refactors
the way the text is constructed to make updating future ordering
changes significantly easier.
2024-12-15 12:21:32 +08:00
Sandro Jäckel
db0a0b1173 nixos/users-groups: split isSystemUser/isNormalUser and uid check into two
Before the error message only mentioned isSystemUser/isNormalUser which
lead to a confusing situation when setting isNormalUser and an uid like
500 which would generate an error like:

error:
Failed assertions:
- Exactly one of users.users.other.isSystemUser and users.users.other.isNormalUser must be set.

from which you cannot know that setting the uid to 500 *and* setting
isNormalUser is the actual problem.

With this patch the error looks like:

error:
Failed assertions:
- A user cannot have a users.users.fixme.uid set below 1000 and set users.users.fixme.isNormalUser.
Either users.users.fixme.isSystemUser must be set to true instead of users.users.fixme.isNormalUser
or users.users.fixme.uid must be changed to 1000 or above.
2024-11-22 15:46:00 +01:00
Maximilian Bosch
7cb22a0acb nixos/users-groups: dump values of password options if multiple options have definitions
This was suggested since it might make it a little easier to identify
the places where the definitions come from.

Retrieving the effective definitions from the module-system seems
non-trivial, especially for submodules though, hence only the values are
shown for now.

I'd argue that especially the `password` option are mostly a convenience
thing for test setups. If the password is an actual secret, it should be
treated as such, i.e. `hashedPasswordFile` should be used.

For the `shadow` VM test, the new section of the warning looks like
this:

    The values of these options are:
    * users.users."leo".hashedPassword: "$6$ymzs8WINZ5wGwQcV$VC2S0cQiX8NVukOLymysTPn4v1zJoJp3NGyhnqyv/dAf4NWZsBWYveQcj6gEJr4ZUjRBRjM0Pj1L8TCQ8hUUp0"
    * users.users."leo".hashedPasswordFile: null
    * users.users."leo".password: null
    * users.users."leo".initialHashedPassword: "!"
    * users.users."leo".initialPassword: null
2024-10-17 17:41:34 +02:00
Philip Taron
1438803fb5 nixos/users-groups: avoid top level with lib; use lib before builtins (#327757) 2024-07-17 20:00:54 +02:00
stuebinm
6afb255d97 nixos: remove all uses of lib.mdDoc
these changes were generated with nixq 0.0.2, by running

  nixq ">> lib.mdDoc[remove] Argument[keep]" --batchmode nixos/**.nix
  nixq ">> mdDoc[remove] Argument[keep]" --batchmode nixos/**.nix
  nixq ">> Inherit >> mdDoc[remove]" --batchmode nixos/**.nix

two mentions of the mdDoc function remain in nixos/, both of which
are inside of comments.

Since lib.mdDoc is already defined as just id, this commit is a no-op as
far as Nix (and the built manual) is concerned.
2024-04-13 10:07:35 -07:00
edef
725bb4e48c lib: add xor
This gets clumsily reimplemented in various places, to no useful end.
2024-04-04 19:46:58 +00:00
Adam Stephens
790fb86a7f nixos/users-groups: move linger to oneshot and add nixos test 2024-03-21 19:51:05 -04:00
Adam Stephens
564c3749d9 nixos/users-groups: fix broken linger 2024-03-21 13:47:15 -04:00
Jordan Williams
8558d7b1ce nixos/users-groups: Fix the update-lingering activation script failing
The update-lingering activation script currently fails during rebuilds.
This happens when removing a user with linger enabled.
The call to loginctl disable-linger runs for the non-existent user.
This returns an error code which causes the failure.

To mitigate this, this PR removes any residual linger files.
These are files named for the user in /var/lib/systemd/linger.
A simple check for user existence determines whether to delete the file.
This happens before the call to disable-linger to avoid any errors.

Fixes #283769.
2024-03-03 12:00:25 -06:00
Maximilian Bosch
f6954309e8 nixos/users-groups: warn on ambiguous password settings
After 4b128008c5 it took me a while in a
test setup to find out why `root` didn't have the password anymore I
declared in my config.

Because of that I got reminded how the order of preference works for the
password options:

    hashedPassword > password > hashedPasswordFile

If the user is new, initialPassword & initialHashedPassword are also
relevant. Also, the override is silent in contrast to any other
conflicting definition in NixOS.

To make this less surprising I decided to warn in such a case -
assertions would probably break too much that technically works as
intended.

Also removed the `initialHashedPassword` for `root`. This would cause a
warning whenever you set something in your own config and a `!` is added
automatically by `users-groups.pl`.

`systemd-sysusers` also seems to implement these precedence rules, so
having the warning for that case also seems useful.
2024-02-09 16:44:35 +01:00
nikstur
eec1845744 nixos/systemd-sysusers: init 2024-01-18 23:08:14 +01:00
Aneesh Agrawal
f4bd2c83e9 nixos/users-groups: Add assert on null shells
I recently set up a new machine with tmpfs-on-root
and switched to mutableUsers = false as part of that.
I missed that an existing user with `shell = null`
was no longer valid as part of this change.
(`shell = null` is still useful for `mutableUsers = true`.)

Add an assertion to prevent future issues.

Also fix a typo in an option name in a comment,
this confused me slightly
(I originally planned to extend that existing assertion.)
2024-01-07 13:32:24 -05:00
Alyssa Ross
59dc10b5a6 nixos/users-groups: fix confusing error message
If we include users with unset groups, we get this very confusing
message, with invalid Nix code:

       - The following users have a primary group that is undefined: qyliss
       Hint: Add this to your NixOS configuration:
         users.groups. = {};

We don't need to include such users in this check, since they'll be
caught anyway by this one:

       - users.users.qyliss.group is unset. This used to default to
       nogroup, but this is unsafe. For example you can create a group
       for this user with:
       users.users.qyliss.group = "qyliss";
       users.groups.qyliss = {};
2023-12-14 02:08:16 +01:00
Anthony Roussel
e30f48be94 treewide: fix redirected and broken URLs
Using the script in maintainers/scripts/update-redirected-urls.sh
2023-11-11 10:49:01 +01:00