2014-04-14 16:26:48 +02:00
|
|
|
|
{ config, lib, pkgs, utils, ... }:
|
2009-10-12 19:27:57 +02:00
|
|
|
|
|
2012-10-12 23:01:49 +02:00
|
|
|
|
with utils;
|
2014-05-05 20:58:51 +02:00
|
|
|
|
with lib;
|
2009-03-06 13:27:35 +01:00
|
|
|
|
|
2015-10-18 20:20:46 +02:00
|
|
|
|
let
|
|
|
|
|
|
|
|
|
|
swapCfg = {config, options, ...}: {
|
|
|
|
|
|
|
|
|
|
options = {
|
|
|
|
|
|
|
|
|
|
device = mkOption {
|
|
|
|
|
example = "/dev/sda3";
|
|
|
|
|
type = types.str;
|
|
|
|
|
description = "Path of the device.";
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
label = mkOption {
|
|
|
|
|
example = "swap";
|
|
|
|
|
type = types.str;
|
|
|
|
|
description = ''
|
|
|
|
|
Label of the device. Can be used instead of <varname>device</varname>.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
size = mkOption {
|
|
|
|
|
default = null;
|
|
|
|
|
example = 2048;
|
|
|
|
|
type = types.nullOr types.int;
|
|
|
|
|
description = ''
|
|
|
|
|
If this option is set, ‘device’ is interpreted as the
|
|
|
|
|
path of a swapfile that will be created automatically
|
|
|
|
|
with the indicated size (in megabytes) if it doesn't
|
|
|
|
|
exist.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
priority = mkOption {
|
|
|
|
|
default = null;
|
|
|
|
|
example = 2048;
|
|
|
|
|
type = types.nullOr types.int;
|
|
|
|
|
description = ''
|
|
|
|
|
Specify the priority of the swap device. Priority is a value between 0 and 32767.
|
|
|
|
|
Higher numbers indicate higher priority.
|
|
|
|
|
null lets the kernel choose a priority, which will show up as a negative value.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
randomEncryption = mkOption {
|
|
|
|
|
default = false;
|
|
|
|
|
type = types.bool;
|
|
|
|
|
description = ''
|
|
|
|
|
Encrypt swap device with a random key. This way you won't have a persistent swap device.
|
|
|
|
|
|
|
|
|
|
WARNING: Don't try to hibernate when you have at least one swap partition with
|
|
|
|
|
this option enabled! We have no way to set the partition into which hibernation image
|
|
|
|
|
is saved, so if your image ends up on an encrypted one you would lose it!
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
deviceName = mkOption {
|
|
|
|
|
type = types.str;
|
|
|
|
|
internal = true;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
realDevice = mkOption {
|
|
|
|
|
type = types.path;
|
|
|
|
|
internal = true;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
config = rec {
|
|
|
|
|
device = mkIf options.label.isDefined
|
|
|
|
|
"/dev/disk/by-label/${config.label}";
|
|
|
|
|
deviceName = escapeSystemdPath config.device;
|
|
|
|
|
realDevice = if config.randomEncryption then "/dev/mapper/${deviceName}" else config.device;
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
in
|
|
|
|
|
|
2009-07-16 16:51:49 +02:00
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
###### interface
|
2011-09-14 20:20:50 +02:00
|
|
|
|
|
2009-05-28 01:14:38 +02:00
|
|
|
|
options = {
|
|
|
|
|
|
2009-07-16 16:51:49 +02:00
|
|
|
|
swapDevices = mkOption {
|
2009-05-28 01:14:38 +02:00
|
|
|
|
default = [];
|
|
|
|
|
example = [
|
|
|
|
|
{ device = "/dev/hda7"; }
|
|
|
|
|
{ device = "/var/swapfile"; }
|
|
|
|
|
{ label = "bigswap"; }
|
|
|
|
|
];
|
2009-07-16 16:51:49 +02:00
|
|
|
|
description = ''
|
2009-05-28 01:14:38 +02:00
|
|
|
|
The swap devices and swap files. These must have been
|
|
|
|
|
initialised using <command>mkswap</command>. Each element
|
|
|
|
|
should be an attribute set specifying either the path of the
|
|
|
|
|
swap device or file (<literal>device</literal>) or the label
|
|
|
|
|
of the swap device (<literal>label</literal>, see
|
|
|
|
|
<command>mkswap -L</command>). Using a label is
|
|
|
|
|
recommended.
|
2009-07-16 16:51:49 +02:00
|
|
|
|
'';
|
|
|
|
|
|
2015-10-18 20:20:46 +02:00
|
|
|
|
type = types.listOf (types.submodule swapCfg);
|
2009-05-28 01:14:38 +02:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
};
|
2009-07-16 16:51:49 +02:00
|
|
|
|
|
2012-08-07 23:34:10 +02:00
|
|
|
|
config = mkIf ((length config.swapDevices) != 0) {
|
2012-10-12 22:47:11 +02:00
|
|
|
|
|
2012-08-07 23:34:10 +02:00
|
|
|
|
system.requiredKernelConfig = with config.lib.kernelConfig; [
|
|
|
|
|
(isYes "SWAP")
|
|
|
|
|
];
|
2012-10-12 22:47:11 +02:00
|
|
|
|
|
|
|
|
|
# Create missing swapfiles.
|
|
|
|
|
# FIXME: support changing the size of existing swapfiles.
|
2013-01-16 12:33:18 +01:00
|
|
|
|
systemd.services =
|
2012-10-12 22:47:11 +02:00
|
|
|
|
let
|
|
|
|
|
|
2012-10-12 23:01:49 +02:00
|
|
|
|
createSwapDevice = sw:
|
|
|
|
|
assert sw.device != "";
|
2015-10-18 20:20:46 +02:00
|
|
|
|
let realDevice' = escapeSystemdPath sw.realDevice;
|
|
|
|
|
in nameValuePair "mkswap-${sw.deviceName}"
|
|
|
|
|
{ description = "Initialisation of swap device ${sw.device}";
|
|
|
|
|
wantedBy = [ "${realDevice'}.swap" ];
|
|
|
|
|
before = [ "${realDevice'}.swap" ];
|
|
|
|
|
path = [ pkgs.utillinux ] ++ optional sw.randomEncryption pkgs.cryptsetup;
|
2016-01-12 15:27:21 +01:00
|
|
|
|
|
2012-10-12 22:47:11 +02:00
|
|
|
|
script =
|
|
|
|
|
''
|
2015-10-18 20:20:46 +02:00
|
|
|
|
${optionalString (sw.size != null) ''
|
|
|
|
|
if [ ! -e "${sw.device}" ]; then
|
|
|
|
|
fallocate -l ${toString sw.size}M "${sw.device}" ||
|
|
|
|
|
dd if=/dev/zero of="${sw.device}" bs=1M count=${toString sw.size}
|
|
|
|
|
chmod 0600 ${sw.device}
|
|
|
|
|
${optionalString (!sw.randomEncryption) "mkswap ${sw.realDevice}"}
|
|
|
|
|
fi
|
|
|
|
|
''}
|
|
|
|
|
${optionalString sw.randomEncryption ''
|
|
|
|
|
echo "secretkey" | cryptsetup luksFormat --batch-mode ${sw.device}
|
|
|
|
|
echo "secretkey" | cryptsetup luksOpen ${sw.device} ${sw.deviceName}
|
|
|
|
|
cryptsetup luksErase --batch-mode ${sw.device}
|
|
|
|
|
mkswap ${sw.realDevice}
|
|
|
|
|
''}
|
2012-10-12 22:47:11 +02:00
|
|
|
|
'';
|
2016-01-12 15:27:21 +01:00
|
|
|
|
|
2012-10-12 23:32:36 +02:00
|
|
|
|
unitConfig.RequiresMountsFor = [ "${dirOf sw.device}" ];
|
2012-10-12 22:47:11 +02:00
|
|
|
|
unitConfig.DefaultDependencies = false; # needed to prevent a cycle
|
|
|
|
|
serviceConfig.Type = "oneshot";
|
2015-10-18 20:20:46 +02:00
|
|
|
|
serviceConfig.RemainAfterExit = sw.randomEncryption;
|
2016-01-05 19:23:04 +01:00
|
|
|
|
serviceConfig.ExecStop = optionalString sw.randomEncryption "${pkgs.cryptsetup}/bin/cryptsetup luksClose ${sw.deviceName}";
|
2016-01-12 15:27:21 +01:00
|
|
|
|
restartIfChanged = false;
|
2012-10-12 22:47:11 +02:00
|
|
|
|
};
|
|
|
|
|
|
2015-10-18 20:20:46 +02:00
|
|
|
|
in listToAttrs (map createSwapDevice (filter (sw: sw.size != null || sw.randomEncryption) config.swapDevices));
|
2012-10-12 22:47:11 +02:00
|
|
|
|
|
2012-08-07 23:34:10 +02:00
|
|
|
|
};
|
|
|
|
|
|
2006-12-21 02:07:23 +01:00
|
|
|
|
}
|