New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sed-opal-unlocker: init at 1.0.0 #89518
Conversation
This pull request has been mentioned on NixOS Discourse. There might be relevant details there: |
# in case someone wants to embed this in an initramfs or PBA image. | ||
sedutil-passhasher = stdenv.mkDerivation { | ||
inherit version src; | ||
name = "sedutil-passhasher"; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
name = "sedutil-passhasher"; | |
pname = "sedutil-passhasher"; |
|
||
sed-opal-unlocker = stdenv.mkDerivation { | ||
inherit version src; | ||
name = "sed-opal-unlocker"; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
name = "sed-opal-unlocker"; | |
pname = "sed-opal-unlocker"; |
sedutil-passhasher = stdenv.mkDerivation { | ||
inherit version src; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if someone is expected to use this separately, you could make a separate file and just do:
{ ... , sed-opal-unlocker }:
stdenv.mkDerivation {
inherit (sed-opal-unlocker) version src;
pname = ...;
...
}; | ||
|
||
sed-opal-unlocker = stdenv.mkDerivation { | ||
inherit version src; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
inherit version src; | |
inherit version src meta; |
# generate a password hash. This keeps python3 out of the main closure, | ||
# in case someone wants to embed this in an initramfs or PBA image. | ||
sedutil-passhasher = stdenv.mkDerivation { | ||
inherit version src; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
inherit version src; | |
inherit version src meta; |
I marked this as stale due to inactivity. → More info |
Closing because author did not respond in the last months. Feel free to reopen the discussion. |
Motivation for this change
Add sed-opal-unlocker, a tiny utility program to unlock self-encrypting drives using the TGC OPAL standard.
I have been using this for around a year now to unlock my laptop drive when resuming from hibernation, using
powerManagement.powerUpCommands
, and it's solid.I split out the
sedutil-passhasher
script to a passthru derivation as it's only needed once to generate the password hash, and python doesn't need to be in the closure just to unlock a drive.Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)