parent
61525137fd
commit
e2fd022d63
@ -1026,6 +1026,7 @@
|
||||
./virtualisation/podman.nix
|
||||
./virtualisation/qemu-guest-agent.nix
|
||||
./virtualisation/railcar.nix
|
||||
./virtualisation/spice-usb-redirection.nix
|
||||
./virtualisation/virtualbox-guest.nix
|
||||
./virtualisation/virtualbox-host.nix
|
||||
./virtualisation/vmware-guest.nix
|
||||
|
21
nixos/modules/virtualisation/spice-usb-redirection.nix
Normal file
21
nixos/modules/virtualisation/spice-usb-redirection.nix
Normal file
@ -0,0 +1,21 @@
|
||||
{ config, pkgs, lib, ... }:
|
||||
{
|
||||
options.virtualisation.spiceUSBRedirection.enable = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Install the SPICE USB redirection helper with setuid
|
||||
privileges. This allows unprivileged users to pass USB devices
|
||||
connected to this machine to libvirt VMs, both local and
|
||||
remote. Note that this allows users arbitrary access to USB
|
||||
devices.
|
||||
'';
|
||||
};
|
||||
|
||||
config = lib.mkIf config.virtualisation.spiceUSBRedirection.enable {
|
||||
environment.systemPackages = [ pkgs.spice_gtk ];
|
||||
security.wrappers.spice-client-glib-usb-acl-helper.source = "${pkgs.spice_gtk}/bin/spice-client-glib-usb-acl-helper";
|
||||
};
|
||||
|
||||
meta.maintainers = [ lib.maintainers.lheckemann ];
|
||||
}
|
Loading…
Reference in New Issue
Block a user