SKILL.md (4506B)
1 --- 2 name: nixdaemon 3 description: Use when the user is on a NixDaemon machine (NixOS pentest flake, usually at ~/NixDaemon) and asks to fix, change, configure, update or troubleshoot it — desktop black screen, rebuild errors, adding tools or categories, VM guest tools, shared folders, HTB VPN, htbbox/htbtarget/htbtime, Kerberos clock skew, rollback. 4 --- 5 6 # NixDaemon 7 8 ## Overview 9 10 NixDaemon is a NixOS flake: the whole machine is `~/NixDaemon`. Nothing is 11 installed by hand — change a file, rebuild, done; a bad rebuild is undone by 12 booting the previous generation. Answer from this map first, read code second. 13 14 ## Which machine is this? 15 16 ```sh 17 hostname; readlink /run/current-system # nixos-system-<hostname>-… 18 ``` 19 20 | Config | Who | Edit | 21 |---|---|---| 22 | `nixdaemon` (`modules/hosts/generic/`) | **every user** | `_settings.nix`, `_hardware-configuration.nix` | 23 | `nixos` (`modules/hosts/laptop/`) | the author's own laptop only | never on a user's machine — it needs his secrets | 24 25 If `hostname` is not `nixdaemon`, the user renamed it in `_settings.nix`; 26 the flake output is still `#nixdaemon`. 27 28 ## Quick reference 29 30 | Want | Do | 31 |---|---| 32 | Rebuild | `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon` (or `nh os switch -H nixdaemon`) | 33 | Update everything | `cd ~/NixDaemon && nix flake update`, then rebuild | 34 | Undo last rebuild | `sudo nixos-rebuild switch --rollback`, or pick an older generation at boot | 35 | Toolkit category on/off | `pentest = { reversing = true; … }` in `_settings.nix` | 36 | Desktop | `desktop = "niri" \| "xfce" \| "i3" \| "none"` in `_settings.nix` | 37 | VM guest tools | `vm = "vmware" \| "virtualbox" \| "qemu" \| "hyperv"` | 38 | VM shared folders | `sharedFolders = true;` → VMware `/mnt/hgfs/<name>`, VirtualBox `/media/sf_<name>` (also enable sharing in the hypervisor) | 39 | One extra package | `environment.systemPackages` in `modules/hosts/generic/default.nix` | 40 | A tool in a category | its `modules/features/pentest/<cat>.nix`: `packages` + `expectedBins` | 41 | Check before rebuilding | `nix flake check` (smoke-tests every category) | 42 | Cheat cards | `pentest-cheat [section]`, `niri-cheat`, `nix-cheat` | 43 44 ## Traps (each one has bitten someone) 45 46 - **New file → `git add` it.** Flakes only see tracked files. Symptom: "path … does not exist" / missing attribute. Editing existing files needs no add. 47 - **New `.nix` under `modules/` is a flake-parts module**, not a NixOS module (import-tree loads every `*.nix` whose path has no `/_`). Wrap NixOS settings as `{ flake.nixosModules.generic = { pkgs, ... }: { … }; }`, or name it `_x.nix` and import it explicitly. 48 - **Niri needs 3D.** Black screen / thrown back to the greeter in a VM = no OpenGL → `desktop = "xfce"` or `"i3"`. Fix from a text console: Ctrl+Alt+F2 (VirtualBox: Right Ctrl+F2). 49 - **`htbtime` skews the clock → TLS fails.** `htbtime status`; run `htbtime off` before any rebuild, update or `git pull`. 50 - **A rebuild rewrites `/etc/hosts`** → run `htbtarget <ip> <names…>` (or `htbbox use <box>`) again after it. 51 - **aarch64**: BloodHound is off automatically; `pentest.mobile` cannot be enabled. 52 - **`hash mismatch` on a payload download** → upstream replaced a file: `pentest-update`, or switch that category off. 53 - **xfce and i3 are newer** than the niri desktop: theming and resize can be rough in some hypervisors. Say so rather than promising. 54 55 ## Diagnose 56 57 | Symptom | Look at | 58 |---|---| 59 | Rebuild fails | the first `error:` line; `nix flake check` names the broken category | 60 | `Failed assertions: _settings.nix: …` | the message names the misspelled value | 61 | Desktop won't start | `journalctl -b -u display-manager -e` (xfce/i3) or `-u greetd` (niri) | 62 | Home config missing (prompt, kitty, i3 config) | `journalctl -b -u home-manager-$USER -e` | 63 | VPN | `htbvpn status`, `journalctl -u htbvpn@<profile> -e`; profiles live in `~/.config/htb/vpn/*.ovpn`, names `A-Za-z0-9_.-` only | 64 | Kerberos `KRB_AP_ERR_SKEW` | `htbtarget <dc-ip> dc01.<domain>`, then `htbtime`; `htbtime off` when done | 65 | Shared folder empty | hypervisor sharing enabled? `ls /mnt/hgfs` (automounts on access) | 66 67 ## Working rules 68 69 - Show the change (diff) before editing `_settings.nix`; let the user run `sudo` 70 commands unless they ask you to. 71 - Prefer `nixos-rebuild boot` + reboot for kernel, boot-loader or desktop changes. 72 - Never "fix" by editing `/etc/nixos` or installing with `nix-env`/`nix profile`: 73 it is overwritten or drifts. The flake is the only source of truth.