Compare commits

...
15 Commits
Author SHA1 Message Date
Jonas Nick da27f27026 fetch-release: fix signature verification!
nix-bitcoin tests / build_test_drivers (push) Canceled after 0s
nix-bitcoin tests / check_flake (push) Canceled after 0s
nix-bitcoin tests / test_scenario (default) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (joinmarket-bitcoind-29) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (netns) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (netnsRegtest) (push) Canceled after 0s
`gpg --verify nar-hash.txt.asc` with a single argument lets gpg pick the
verification mode from the file's packet structure. For a real detached
signature it hashes the sibling nar-hash.txt, but for an inline signed
message it verifies the payload embedded in the .asc itself, never reads
nar-hash.txt, prints "not a detached signature; file was NOT verified!"
and still exits 0. The `&> /dev/null` hid that warning.
2026-08-31 08:12:01 +00:00
Jonas Nick 4e418e56be SECURITY: add haoxucu to wall of fame 2026-08-31 07:07:23 +00:00
Jonas Nick c4f172441d README: add archival notice 2026-08-15 16:09:51 +00:00
Jonas Nick 37931e5288 Merge fort-nix/nix-bitcoin#848: lnd: don't pass the admin macaroon in curl argv
df184b6e06 lnd: don't pass the admin macaroon in `curl` argv (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: d18fa7176c59f33a38222a2d3d44320769ac83e091104594a9572e44ce38205d341767ea598da1b5500208c1e9f6645ed5c3b9390438d95912e44d1c5f3a4752
2026-08-13 10:44:26 +00:00
Jonas Nick 0d86dcd7da Merge fort-nix/nix-bitcoin#847: update nixpkgs
f51460749a ci: disable the nixos-search test (Jonas Nick)
3b798f5ebf test: increase VM memory to 4 GiB (Jonas Nick)
17f0d98c22 update nixpkgs (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 0e40353d9d7937dd7a80c05416360c30ada7ee231d6263883072d60a707443e765d35f6a393e718ed1ef66f2e2cdbd1deadd6cd720dccb5c5e18711159cda38a
2026-08-13 10:43:37 +00:00
Jonas Nick b579fcc371 Merge fort-nix/nix-bitcoin#846: netns-isolation: fix netns-exec being executable by all normal users
34a18f92ee netns-isolation: fix netns-exec being executable by all normal users (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 3aa359bb61967b76299918b893b85f5d92909029237cba892b367f94c82643268dceaf2928157b47d4973a8af81e5e9ef29651bc45db0e3b149966b16c41bc8b
2026-08-12 18:26:21 +00:00
Jonas Nick f51460749a ci: disable the nixos-search test 2026-08-12 18:23:10 +00:00
Jonas Nick 3b798f5ebf test: increase VM memory to 4 GiB 2026-08-12 18:22:32 +00:00
Jonas Nick df184b6e06 lnd: don't pass the admin macaroon in curl argv
`lnd-create-macaroons` interpolated the hex-encoded admin macaroon into
`curl`'s argv, where any local user could read it from world-readable
`/proc/<pid>/cmdline`. The unit's `ProtectProc=invisible` doesn't apply,
because `nbLib.rootScript`'s `+` prefix disables sandboxing for the
process. Pass the header on a file descriptor instead, so the credential
never enters any argv (`printf` is a bash builtin); the request sent to
lnd is unchanged. Only configurations with a non-empty
`services.lnd.macaroons` were affected, which `services.charge-lnd` and
`services.btcpayserver` with `lightningBackend = "lnd"` set automatically.
2026-08-12 18:02:07 +00:00
Jonas Nick 138af7f592 Merge fort-nix/nix-bitcoin#844: NixOS 25.11 -> 26.05
2feb7934ac run-tests: disable the nixos-search test (Jonas Nick)
8f7dcb6e2a containers: fix for NixOS 26.05 (Jonas Nick)
e8328251af udpate nixos 25.11 -> 26.05 (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 78d3f3ba4dc43a71c5e30b9b663a51ba7ba11c880bf9113a6cb20d22b1df5a8227c8a29a6be23f7bbee2be801c5b81432bc80cd957b4758196e01c3b68ed6707
2026-08-11 09:42:34 +00:00
Jonas Nick 17f0d98c22 update nixpkgs
bitcoin: 31.0 -> 31.1
bitcoind: 31.0 -> 31.1
btcpayserver: 2.3.4 -> 2.4.2
clboss: 0.16.0 -> 0.16.1
2026-08-11 09:41:31 +00:00
Jonas Nick 34a18f92ee netns-isolation: fix netns-exec being executable by all normal users
The `netns-exec` wrapper was created with `group = ""`, which makes the
`security.wrappers` activation run `chown ${allowedUser}:`. GNU chown
resolves the trailing colon to the owner's login group, and because the
operator is defined with `isNormalUser = true`, that group is the shared
group `users`. Together with mode 550, this made the wrapper executable
by every normal user on the host instead of only by `allowedUser`.

The wrapper carries `cap_sys_admin=ep` and the NixOS security wrapper
performs no owner check, so any normal user could enter `nb-joinmarket`,
the only netns that `netns-exec` permits. This exposes joinmarketd's
unauthenticated control port on 127.0.0.1 inside that netns and allows
sending packets from the joinmarket netns address. This can only ever become a
problem if there's a second, normal user on the host.

Use mode 500 so that only `allowedUser` can execute the wrapper. Also
set the group to `root`, so that `users` doesn't silently become an
authorized group again if the mode is ever loosened.

The netns-isolation test asserted this property with
`runuser -u clightning -- netns-exec nb-bitcoind ip a`, which fails
regardless of the file mode, because `clightning` is a system user with
its own group and `nb-bitcoind` is not in netns-exec's allowlist.
Replace it with a check that a normal user is denied by the exec
permissions, and assert the reason for each failure instead of only the
exit status.
2026-08-09 19:40:39 +00:00
Jonas Nick 2feb7934ac run-tests: disable the nixos-search test 2026-08-08 06:54:06 +00:00
Jonas Nick 8f7dcb6e2a containers: fix for NixOS 26.05 2026-08-08 06:54:06 +00:00
Jonas Nick e8328251af udpate nixos 25.11 -> 26.05 2026-08-08 06:54:06 +00:00
23 changed files with 164 additions and 99 deletions
+3 -1
View File
@@ -49,5 +49,7 @@ jobs:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- uses: cachix/install-nix-action@v31 - uses: cachix/install-nix-action@v31
- run: nix flake check --all-systems - run: nix flake check --all-systems
- run: ./test/nixos-search/ci-test.sh # FIXME: Re-enable when the nixos-search input is usable again.
# This is also disabled in ./test/run-tests.sh.
# - run: ./test/nixos-search/ci-test.sh
- run: ./test/shellcheck.sh - run: ./test/shellcheck.sh
+4
View File
@@ -1,3 +1,7 @@
> [!WARNING]
> **Archived and unmaintained as of August 13, 2026.**
> v0.0.139 is the final release; there will be no further updates or security fixes.
<p align="center"> <p align="center">
<img <img
width="320" width="320"
+6 -1
View File
@@ -16,7 +16,12 @@ You can import a GPG key by running the following command with that individual
## Wall of Fame ## Wall of Fame
*empty* ### [haoxucu](https://github.com/haoxucu)
* Reported that `netns-exec` was executable by all normal users ([fixed in `34a18f92`](https://github.com/fort-nix/nix-bitcoin/commit/34a18f92eeacc754e5857249aaf8decf24e98cde)); received 5% of the fund.
* Reported that `lnd-create-macaroons` exposed the LND admin macaroon in `curl`'s process arguments ([fixed in `df184b6e`](https://github.com/fort-nix/nix-bitcoin/commit/df184b6e06cc3404add42ccf5ae68306395e8d6c)); received 10% of the fund.
Both rewards were paid in transaction [`5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888`](https://mempool.nixbitcoin.org/tx/5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888).
## nix-bitcoin security fund ## nix-bitcoin security fund
+1 -1
View File
@@ -97,5 +97,5 @@ It's easiest to use an existing service as a template:
Most other services use packages that are already included in nixpkgs. Most other services use packages that are already included in nixpkgs.
## Switching to a new NixOS release ## Switching to a new NixOS release
- Run command `update-flake.sh 25.11` - Run command `update-flake.sh 26.05`
- Treewide: check if any `TODO-EXTERNAL` comments can be resolved - Treewide: check if any `TODO-EXTERNAL` comments can be resolved
+1
View File
@@ -82,6 +82,7 @@ read -rd '' src <<'EOF' || :
inherit (nix-bitcoin.inputs) nixpkgs; inherit (nix-bitcoin.inputs) nixpkgs;
# legacyInstallDirs = true; # legacyInstallDirs = true;
config = { config = {
imports = [ ../test/lib/extra-container-workaround.nix ];
containers.nb-adhoc = { containers.nb-adhoc = {
# bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; }; # bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; };
extra.addressPrefix = "10.200.255"; extra.addressPrefix = "10.200.255";
+1 -1
View File
@@ -324,7 +324,7 @@
# this value at the release version of the first install of this system. # this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option # Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "25.11"; # Did you read the comment? system.stateVersion = "26.05"; # Did you read the comment?
# The nix-bitcoin release version that your config is compatible with. # The nix-bitcoin release version that your config is compatible with.
# When upgrading to a backwards-incompatible release, nix-bitcoin will display an # When upgrading to a backwards-incompatible release, nix-bitcoin will display an
+4 -1
View File
@@ -12,7 +12,7 @@
inputs = { inputs = {
nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release"; nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
# You can also use a version branch to track a specific NixOS release # You can also use a version branch to track a specific NixOS release
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11"; # nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
nixpkgs.follows = "nix-bitcoin/nixpkgs"; nixpkgs.follows = "nix-bitcoin/nixpkgs";
nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable"; nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
@@ -31,6 +31,9 @@
# legacyInstallDirs = true; # legacyInstallDirs = true;
config = { config = {
# See the file for why this is needed and when it can be removed
imports = [ (nix-bitcoin.outPath + "/test/lib/extra-container-workaround.nix") ];
containers.mynode = { containers.mynode = {
# Always start container along with the container host # Always start container along with the container host
autoStart = true; autoStart = true;
+2
View File
@@ -75,6 +75,8 @@ fi
# #
read -rd '' src <<EOF || true read -rd '' src <<EOF || true
{ pkgs, lib, ... }: { { pkgs, lib, ... }: {
imports = [ $(realpath "${BASH_SOURCE[0]%/*}"/../test/lib/extra-container-workaround.nix) ];
containers.demo-node = { containers.demo-node = {
extra.addressPrefix = "10.250.0"; extra.addressPrefix = "10.250.0";
extra.enableWAN = true; extra.enableWAN = true;
+1 -1
View File
@@ -10,7 +10,7 @@
inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release"; inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
# You can also use a version branch to track a specific NixOS release # You can also use a version branch to track a specific NixOS release
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11"; # inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs"; inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs";
inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable"; inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
Generated
+7 -7
View File
@@ -44,16 +44,16 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1782847189, "lastModified": 1786313170,
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=", "narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41", "rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "NixOS",
"ref": "nixos-25.11", "ref": "nixos-26.05",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }
@@ -76,11 +76,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1784453100, "lastModified": 1786348146,
"narHash": "sha256-zpGZb8FYui+i8KLtC0nlcmb0voR2zB80Qn8pe7lzIbk=", "narHash": "sha256-we5zDEFfn8TgzeWKjKDMIjeQZ59omEPl23NIF+13/ys=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b471514bed69eff5255c8e63c1f80e5fe56c616f", "rev": "d482ef84049d9b7276b83a06e4e4d76983830097",
"type": "github" "type": "github"
}, },
"original": { "original": {
+1 -1
View File
@@ -5,7 +5,7 @@
''; '';
inputs = { inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05"; nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05";
flake-utils.url = "github:numtide/flake-utils"; flake-utils.url = "github:numtide/flake-utils";
+1 -1
View File
@@ -31,7 +31,7 @@ curl -fsS -L -O "$baseUrl/nar-hash.txt"
curl -fsS -L -O "$baseUrl/nar-hash.txt.asc" curl -fsS -L -O "$baseUrl/nar-hash.txt.asc"
# Verify signature for nar-hash # Verify signature for nar-hash
gpg --verify nar-hash.txt.asc &> /dev/null || { gpg --verify nar-hash.txt.asc nar-hash.txt &> /dev/null || {
>&2 echo "Error: Signature verification failed. Please open an issue in the project repository." >&2 echo "Error: Signature verification failed. Please open an issue in the project repository."
exit 1 exit 1
} }
+5
View File
@@ -239,6 +239,11 @@ in {
--datadir='${cfg.btcpayserver.dataDir}' --datadir='${cfg.btcpayserver.dataDir}'
''; '';
User = cfg.btcpayserver.user; User = cfg.btcpayserver.user;
# Since 2.4.0, btcpayserver uses `Host.CreateDefaultBuilder`, which sets the
# ASP.NET content root to the working directory instead of the app directory.
# The web root (`wwwroot`) is resolved relative to the content root, so
# btcpayserver must be started from its app directory.
WorkingDirectory = "${cfg.btcpayserver.package}/lib/btcpayserver";
# Also restart after the program has exited successfully. # Also restart after the program has exited successfully.
# This is required to support restarting from the web interface after # This is required to support restarting from the web interface after
# interactive plugin installation. # interactive plugin installation.
+4 -1
View File
@@ -265,13 +265,16 @@ in {
curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}"; curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}";
restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1"; restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1";
# Setting macaroon permissions for other users needs root permissions # Setting macaroon permissions for other users needs root permissions
# The admin macaroon is passed to curl via a fd because argv is
# world-readable through /proc/<pid>/cmdline
script = nbLib.rootScript "lnd-create-macaroons" '' script = nbLib.rootScript "lnd-create-macaroons" ''
umask ug=r,o= umask ug=r,o=
${lib.concatMapStrings (macaroon: '' ${lib.concatMapStrings (macaroon: ''
echo "Create custom macaroon ${macaroon}" echo "Create custom macaroon ${macaroon}"
macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon" macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon"
adminMacaroonHex=$(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')
${curl} \ ${curl} \
-H "Grpc-Metadata-macaroon: $(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')" \ -H @<(printf 'Grpc-Metadata-macaroon: %s\n' "$adminMacaroonHex") \
-X POST \ -X POST \
-d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \ -d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \
${restUrl}/macaroon |\ ${restUrl}/macaroon |\
+4 -3
View File
@@ -37,7 +37,6 @@ let
type = types.str; type = types.str;
description = '' description = ''
User that is allowed to execute commands in the service network namespaces. User that is allowed to execute commands in the service network namespaces.
The user's group is also authorized.
''; '';
default = config.nix-bitcoin.operator.name; default = config.nix-bitcoin.operator.name;
}; };
@@ -122,8 +121,10 @@ in {
source = config.nix-bitcoin.pkgs.netns-exec; source = config.nix-bitcoin.pkgs.netns-exec;
capabilities = "cap_sys_admin=ep"; capabilities = "cap_sys_admin=ep";
owner = cfg.allowedUser; owner = cfg.allowedUser;
group = ""; # Set to the group of `owner` # Don't authorize the group of `owner`. For normal users, this group is
permissions = "550"; # `users`, which is shared by all normal users.
group = "root";
permissions = "500";
}; };
systemd.services = { systemd.services = {
+3 -3
View File
@@ -4,18 +4,18 @@ pkgs: pkgsUnstable: pkgs-25_05:
inherit (pkgs) inherit (pkgs)
bitcoin bitcoin
bitcoind bitcoind
btcpayserver
charge-lnd charge-lnd
clightning
electrs electrs
elementsd
extra-container extra-container
lightning-pool lightning-pool
lndconnect; lndconnect;
inherit (pkgsUnstable) inherit (pkgsUnstable)
bitcoind-knots bitcoind-knots
btcpayserver
clboss clboss
clightning
elementsd
fulcrum fulcrum
lightning-loop lightning-loop
lnd; lnd;
+24
View File
@@ -0,0 +1,24 @@
# FIXME:
# Remove this file, along with the imports in ../../dev/dev.sh,
# ../../examples/container/flake.nix, ../../examples/deploy-container.sh and
# ./make-test.nix, as soon as extra-container declares these options itself
# (https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix).
#
# extra-container evaluates the container host with a minimal module set to keep
# eval times low. NixOS 26.05 added references to the following options to
# `system/boot/systemd.nix`, which is part of that module set, while their
# declaring modules are not.
#
# The defaults match the ones from the declaring modules. Like extra-container's
# own dummy options, these declarations have no type because they only exist to
# make host eval succeed. They don't affect the resulting container units.
{ lib, pkgs, ... }: {
options = {
environment.variables = lib.mkOption { default = {}; };
i18n.imperativeLocale = lib.mkOption { default = false; };
services.openssh.enable = lib.mkOption { default = false; };
system.nixos-init.package = lib.mkOption { default = pkgs.nixos-init; };
time.timeZone = lib.mkOption { default = null; };
};
}
+17 -5
View File
@@ -22,8 +22,8 @@ let
test.shellcheckServices.enable = true; test.shellcheckServices.enable = true;
}; };
testScript = nodes: let testScript = { nodes, ... }: let
cfg = nodes.nodes.machine; cfg = nodes.machine;
data = { data = {
data = cfg.test.data; data = cfg.test.data;
tests = cfg.tests; tests = cfg.tests;
@@ -56,12 +56,23 @@ let
extra-container.lib.buildContainers { extra-container.lib.buildContainers {
inherit system legacyInstallDirs; inherit system legacyInstallDirs;
config = { config = {
imports = [ ./extra-container-workaround.nix ];
# The container name has a 11 char length limit # The container name has a 11 char length limit
containers.nb-test = { config, ... }: { containers.nb-test = { config, ... }: {
imports = [ imports = [
{ {
config = { config = {
extra = config.config.test.container; extra = {
# Defined here instead of in the container config because NixOS
# 26.05 derives the container's `networking.interfaces` from
# `localAddress`, which extra-container derives from
# `addressPrefix`. Reading it from the container config would
# thus be circular.
addressPrefix = "10.225.255";
inherit (config.config.test.container)
enableWAN firewallAllowHost exposeLocalhost;
};
config = testConfig; config = testConfig;
}; };
} }
@@ -117,8 +128,9 @@ let
# Needed because duplicity requires 270 MB of free temp space, regardless of backup size # Needed because duplicity requires 270 MB of free temp space, regardless of backup size
diskSize = 1024; diskSize = 1024;
# Min. 800 MiB needed to avoid 'out of memory' errors # The `netns` scenarios need more than 2 GiB: netns-isolation adds a
memorySize = lib.mkDefault 2048; # network namespace per service, which costs a few hundred MiB of slab.
memorySize = lib.mkDefault 4096;
# There are no perf gains beyond 3 cores. # There are no perf gains beyond 3 cores.
# Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90. # Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90.
+1 -1
View File
@@ -31,7 +31,7 @@ with lib;
container = { container = {
# Forwarded to extra-container. For descriptions, see # Forwarded to extra-container. For descriptions, see
# https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix # https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix
addressPrefix = mkOption { default = "10.225.255"; }; # `addressPrefix` is not settable here, see ./make-test.nix.
enableWAN = mkOption { default = false; }; enableWAN = mkOption { default = false; };
firewallAllowHost = mkOption { default = true; }; firewallAllowHost = mkOption { default = true; };
exposeLocalhost = mkOption { default = false; }; exposeLocalhost = mkOption { default = false; };
+47 -63
View File
@@ -1,31 +1,49 @@
{ {
"nodes": { "nodes": {
"flake-utils": { "flake-parts": {
"inputs": { "inputs": {
"systems": "systems" "nixpkgs-lib": [
"nixos-search",
"nixpkgs"
]
}, },
"locked": { "locked": {
"lastModified": 1731533236, "lastModified": 1785627969,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", "narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "flake-parts",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", "rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "numtide", "owner": "hercules-ci",
"repo": "flake-utils", "repo": "flake-parts",
"type": "github"
}
},
"flake-schemas": {
"locked": {
"lastModified": 1780327564,
"narHash": "sha256-HiRPtA0spK+Dkgbhz/1zW9glXxNVB+L4Rj2VYmdawb8=",
"owner": "DeterminateSystems",
"repo": "flake-schemas",
"rev": "6cc9bd98891b1fc6bb2b8cb3277df8bc72799ca6",
"type": "github"
},
"original": {
"owner": "DeterminateSystems",
"repo": "flake-schemas",
"type": "github" "type": "github"
} }
}, },
"nixos-infra": { "nixos-infra": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1778186763, "lastModified": 1785876137,
"narHash": "sha256-WYpwAXUSbAvyygzaPJ5A0MpBgCRDfOn/JlA6bhAExOM=", "narHash": "sha256-maIa1tcvLYFyedzvWApdpaMLzDyTWktCXeugLOEZzDs=",
"owner": "NixOS", "owner": "NixOS",
"repo": "infra", "repo": "infra",
"rev": "f7fcb33b303e1026a99206c8a9a4f4d93907d5d1", "rev": "952d0cfaf5d2ae350f9a2746c61e03d53a15b8db",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -36,19 +54,19 @@
}, },
"nixos-search": { "nixos-search": {
"inputs": { "inputs": {
"flake-utils": "flake-utils", "flake-parts": "flake-parts",
"flake-schemas": "flake-schemas",
"nixos-infra": "nixos-infra", "nixos-infra": "nixos-infra",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"nixpkgs-npmlock2nix": "nixpkgs-npmlock2nix", "systems": "systems",
"npmlock2nix": "npmlock2nix",
"treefmt-nix": "treefmt-nix" "treefmt-nix": "treefmt-nix"
}, },
"locked": { "locked": {
"lastModified": 1778708793, "lastModified": 1786265380,
"narHash": "sha256-LXzXKjaxm23vLEOVefy9HNfedZvdI/FvoJlFd/jjNc0=", "narHash": "sha256-JX5Q9o03xYMUpAoHB4nz/0Pf3SeL7GrXoKKJhkUMNps=",
"owner": "nixos", "owner": "nixos",
"repo": "nixos-search", "repo": "nixos-search",
"rev": "4a3cb26d1ccaa9c62f29071c228dff07c3686e38", "rev": "7507fd6accc65981f02f66f5c6c328e09efc1221",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -59,50 +77,15 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1777954456, "lastModified": 1785967620,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=", "narHash": "sha256-929m7iW8q2uv3mZHNwY8Um6XKj99rbIcZsWS9cT1vaI=",
"owner": "NixOS", "rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
"repo": "nixpkgs", "type": "tarball",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1", "url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1048607.b7c2ada94fe9/nixexprs.tar.xz"
"type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "type": "tarball",
"ref": "nixos-unstable", "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-npmlock2nix": {
"locked": {
"lastModified": 1636623366,
"narHash": "sha256-jOQMlv9qFSj0U66HB+ujZoapty0UbewmSNbX8+3ujUQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
"type": "github"
}
},
"npmlock2nix": {
"flake": false,
"locked": {
"lastModified": 1758100811,
"narHash": "sha256-qJc3ffjHVXUdZqytKcDK9XZ2b3BQ1RdYfZFuYgxbrn4=",
"owner": "nix-community",
"repo": "npmlock2nix",
"rev": "4d9060afbaa5f57ee0b8ef11c7044ed287a7d302",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "npmlock2nix",
"type": "github"
} }
}, },
"root": { "root": {
@@ -111,6 +94,7 @@
} }
}, },
"systems": { "systems": {
"flake": false,
"locked": { "locked": {
"lastModified": 1681028828, "lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
@@ -133,11 +117,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1775636079, "lastModified": 1785945821,
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", "narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
"owner": "numtide", "owner": "numtide",
"repo": "treefmt-nix", "repo": "treefmt-nix",
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", "rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
"type": "github" "type": "github"
}, },
"original": { "original": {
+7 -1
View File
@@ -332,7 +332,13 @@ all() {
shellcheck shellcheck
examples examples
flake flake
nixosSearch # FIXME: Re-enable when the nixos-search input is usable again.
# flake-info at the currently locked rev supplies nixpkgs to its inner eval
# via `builtins.getFlake` instead of NIX_PATH. This breaks the postPatch in
# ./nixos-search/flake.nix and both runners in ./nixos-search, which pass
# nix-bitcoin's pinned nixpkgs through NIX_PATH.
# Run explicitly with `./run-tests.sh nixosSearch`.
# nixosSearch
} }
# An alias for buildTest # An alias for buildTest
+4
View File
@@ -279,6 +279,10 @@ let
test.data.netns = config.nix-bitcoin.netns-isolation.netns; test.data.netns = config.nix-bitcoin.netns-isolation.netns;
tests.netns-isolation = true; tests.netns-isolation = true;
environment.systemPackages = [ pkgs.fping ]; environment.systemPackages = [ pkgs.fping ];
# Used for testing that `netns-exec` is not executable by users other than
# the operator. Like all normal users, this user is a member of group `users`.
users.users.unauthorized.isNormalUser = true;
}; };
regtestBase = { config, pkgs, ... }: { regtestBase = { config, pkgs, ... }: {
+16 -7
View File
@@ -1,5 +1,6 @@
from collections import OrderedDict from collections import OrderedDict
import json import json
import os
import re import re
def succeed(*cmds): def succeed(*cmds):
@@ -331,6 +332,21 @@ def _():
f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address" f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address"
) )
# netns-exec should fail for unauthorized namespaces
assert_matches(
"runuser -u operator -- netns-exec nb-clightning ip a 2>&1 || true",
"nb-clightning is not an allowed netns",
)
# netns-exec should only be executable by the operator user.
# User `unauthorized` is a member of group `users`, like all normal users.
# Netns `nb-clightning` is rejected by netns-exec before it accesses the
# netns, so the error below can only originate from the exec permissions.
assert_matches(
"runuser -u unauthorized -- netns-exec nb-clightning ip a 2>&1 || true",
"Permission denied",
)
if "joinmarket" in enabled_tests: if "joinmarket" in enabled_tests:
# netns-exec should drop capabilities # netns-exec should drop capabilities
assert_matches( assert_matches(
@@ -338,13 +354,6 @@ def _():
re.compile("^Current: =$", re.MULTILINE), re.compile("^Current: =$", re.MULTILINE),
) )
if "clightning" in enabled_tests:
# netns-exec should fail for unauthorized namespaces
machine.fail("netns-exec nb-clightning ip a")
# netns-exec should only be executable by the operator user
machine.fail("runuser -u clightning -- netns-exec nb-bitcoind ip a")
# Impure: stops bitcoind (and dependent services) # Impure: stops bitcoind (and dependent services)
@test("backups") @test("backups")