NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

SKILL.md (4506B)


      1 ---
      2 name: nixdaemon
      3 description: Use when the user is on a NixDaemon machine (NixOS pentest flake, usually at ~/NixDaemon) and asks to fix, change, configure, update or troubleshoot it — desktop black screen, rebuild errors, adding tools or categories, VM guest tools, shared folders, HTB VPN, htbbox/htbtarget/htbtime, Kerberos clock skew, rollback.
      4 ---
      5 
      6 # NixDaemon
      7 
      8 ## Overview
      9 
     10 NixDaemon is a NixOS flake: the whole machine is `~/NixDaemon`. Nothing is
     11 installed by hand — change a file, rebuild, done; a bad rebuild is undone by
     12 booting the previous generation. Answer from this map first, read code second.
     13 
     14 ## Which machine is this?
     15 
     16 ```sh
     17 hostname; readlink /run/current-system      # nixos-system-<hostname>-…
     18 ```
     19 
     20 | Config | Who | Edit |
     21 |---|---|---|
     22 | `nixdaemon` (`modules/hosts/generic/`) | **every user** | `_settings.nix`, `_hardware-configuration.nix` |
     23 | `nixos` (`modules/hosts/laptop/`) | the author's own laptop only | never on a user's machine — it needs his secrets |
     24 
     25 If `hostname` is not `nixdaemon`, the user renamed it in `_settings.nix`;
     26 the flake output is still `#nixdaemon`.
     27 
     28 ## Quick reference
     29 
     30 | Want | Do |
     31 |---|---|
     32 | Rebuild | `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon` (or `nh os switch -H nixdaemon`) |
     33 | Update everything | `cd ~/NixDaemon && nix flake update`, then rebuild |
     34 | Undo last rebuild | `sudo nixos-rebuild switch --rollback`, or pick an older generation at boot |
     35 | Toolkit category on/off | `pentest = { reversing = true; … }` in `_settings.nix` |
     36 | Desktop | `desktop = "niri" \| "xfce" \| "i3" \| "none"` in `_settings.nix` |
     37 | VM guest tools | `vm = "vmware" \| "virtualbox" \| "qemu" \| "hyperv"` |
     38 | VM shared folders | `sharedFolders = true;` → VMware `/mnt/hgfs/<name>`, VirtualBox `/media/sf_<name>` (also enable sharing in the hypervisor) |
     39 | One extra package | `environment.systemPackages` in `modules/hosts/generic/default.nix` |
     40 | A tool in a category | its `modules/features/pentest/<cat>.nix`: `packages` + `expectedBins` |
     41 | Check before rebuilding | `nix flake check` (smoke-tests every category) |
     42 | Cheat cards | `pentest-cheat [section]`, `niri-cheat`, `nix-cheat` |
     43 
     44 ## Traps (each one has bitten someone)
     45 
     46 - **New file → `git add` it.** Flakes only see tracked files. Symptom: "path … does not exist" / missing attribute. Editing existing files needs no add.
     47 - **New `.nix` under `modules/` is a flake-parts module**, not a NixOS module (import-tree loads every `*.nix` whose path has no `/_`). Wrap NixOS settings as `{ flake.nixosModules.generic = { pkgs, ... }: { … }; }`, or name it `_x.nix` and import it explicitly.
     48 - **Niri needs 3D.** Black screen / thrown back to the greeter in a VM = no OpenGL → `desktop = "xfce"` or `"i3"`. Fix from a text console: Ctrl+Alt+F2 (VirtualBox: Right Ctrl+F2).
     49 - **`htbtime` skews the clock → TLS fails.** `htbtime status`; run `htbtime off` before any rebuild, update or `git pull`.
     50 - **A rebuild rewrites `/etc/hosts`** → run `htbtarget <ip> <names…>` (or `htbbox use <box>`) again after it.
     51 - **aarch64**: BloodHound is off automatically; `pentest.mobile` cannot be enabled.
     52 - **`hash mismatch` on a payload download** → upstream replaced a file: `pentest-update`, or switch that category off.
     53 - **xfce and i3 are newer** than the niri desktop: theming and resize can be rough in some hypervisors. Say so rather than promising.
     54 
     55 ## Diagnose
     56 
     57 | Symptom | Look at |
     58 |---|---|
     59 | Rebuild fails | the first `error:` line; `nix flake check` names the broken category |
     60 | `Failed assertions: _settings.nix: …` | the message names the misspelled value |
     61 | Desktop won't start | `journalctl -b -u display-manager -e` (xfce/i3) or `-u greetd` (niri) |
     62 | Home config missing (prompt, kitty, i3 config) | `journalctl -b -u home-manager-$USER -e` |
     63 | VPN | `htbvpn status`, `journalctl -u htbvpn@<profile> -e`; profiles live in `~/.config/htb/vpn/*.ovpn`, names `A-Za-z0-9_.-` only |
     64 | Kerberos `KRB_AP_ERR_SKEW` | `htbtarget <dc-ip> dc01.<domain>`, then `htbtime`; `htbtime off` when done |
     65 | Shared folder empty | hypervisor sharing enabled? `ls /mnt/hgfs` (automounts on access) |
     66 
     67 ## Working rules
     68 
     69 - Show the change (diff) before editing `_settings.nix`; let the user run `sudo`
     70   commands unless they ask you to.
     71 - Prefer `nixos-rebuild boot` + reboot for kernel, boot-loader or desktop changes.
     72 - Never "fix" by editing `/etc/nixos` or installing with `nix-env`/`nix profile`:
     73   it is overwritten or drifts. The flake is the only source of truth.