Compare commits
15
Commits
360e30fee5
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
da27f27026 | ||
|
|
4e418e56be | ||
|
|
c4f172441d | ||
|
|
37931e5288 | ||
|
|
0d86dcd7da | ||
|
|
b579fcc371 | ||
|
|
f51460749a | ||
|
|
3b798f5ebf | ||
|
|
df184b6e06 | ||
|
|
138af7f592 | ||
|
|
17f0d98c22 | ||
|
|
34a18f92ee | ||
|
|
2feb7934ac | ||
|
|
8f7dcb6e2a | ||
|
|
e8328251af |
@@ -49,5 +49,7 @@ jobs:
|
|||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
- uses: cachix/install-nix-action@v31
|
- uses: cachix/install-nix-action@v31
|
||||||
- run: nix flake check --all-systems
|
- run: nix flake check --all-systems
|
||||||
- run: ./test/nixos-search/ci-test.sh
|
# FIXME: Re-enable when the nixos-search input is usable again.
|
||||||
|
# This is also disabled in ./test/run-tests.sh.
|
||||||
|
# - run: ./test/nixos-search/ci-test.sh
|
||||||
- run: ./test/shellcheck.sh
|
- run: ./test/shellcheck.sh
|
||||||
|
|||||||
@@ -1,3 +1,7 @@
|
|||||||
|
> [!WARNING]
|
||||||
|
> **Archived and unmaintained as of August 13, 2026.**
|
||||||
|
> v0.0.139 is the final release; there will be no further updates or security fixes.
|
||||||
|
|
||||||
<p align="center">
|
<p align="center">
|
||||||
<img
|
<img
|
||||||
width="320"
|
width="320"
|
||||||
|
|||||||
+6
-1
@@ -16,7 +16,12 @@ You can import a GPG key by running the following command with that individual
|
|||||||
|
|
||||||
## Wall of Fame
|
## Wall of Fame
|
||||||
|
|
||||||
*empty*
|
### [haoxucu](https://github.com/haoxucu)
|
||||||
|
|
||||||
|
* Reported that `netns-exec` was executable by all normal users ([fixed in `34a18f92`](https://github.com/fort-nix/nix-bitcoin/commit/34a18f92eeacc754e5857249aaf8decf24e98cde)); received 5% of the fund.
|
||||||
|
* Reported that `lnd-create-macaroons` exposed the LND admin macaroon in `curl`'s process arguments ([fixed in `df184b6e`](https://github.com/fort-nix/nix-bitcoin/commit/df184b6e06cc3404add42ccf5ae68306395e8d6c)); received 10% of the fund.
|
||||||
|
|
||||||
|
Both rewards were paid in transaction [`5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888`](https://mempool.nixbitcoin.org/tx/5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888).
|
||||||
|
|
||||||
|
|
||||||
## nix-bitcoin security fund
|
## nix-bitcoin security fund
|
||||||
|
|||||||
+1
-1
@@ -97,5 +97,5 @@ It's easiest to use an existing service as a template:
|
|||||||
Most other services use packages that are already included in nixpkgs.
|
Most other services use packages that are already included in nixpkgs.
|
||||||
|
|
||||||
## Switching to a new NixOS release
|
## Switching to a new NixOS release
|
||||||
- Run command `update-flake.sh 25.11`
|
- Run command `update-flake.sh 26.05`
|
||||||
- Treewide: check if any `TODO-EXTERNAL` comments can be resolved
|
- Treewide: check if any `TODO-EXTERNAL` comments can be resolved
|
||||||
|
|||||||
@@ -82,6 +82,7 @@ read -rd '' src <<'EOF' || :
|
|||||||
inherit (nix-bitcoin.inputs) nixpkgs;
|
inherit (nix-bitcoin.inputs) nixpkgs;
|
||||||
# legacyInstallDirs = true;
|
# legacyInstallDirs = true;
|
||||||
config = {
|
config = {
|
||||||
|
imports = [ ../test/lib/extra-container-workaround.nix ];
|
||||||
containers.nb-adhoc = {
|
containers.nb-adhoc = {
|
||||||
# bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; };
|
# bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; };
|
||||||
extra.addressPrefix = "10.200.255";
|
extra.addressPrefix = "10.200.255";
|
||||||
|
|||||||
@@ -324,7 +324,7 @@
|
|||||||
# this value at the release version of the first install of this system.
|
# this value at the release version of the first install of this system.
|
||||||
# Before changing this value read the documentation for this option
|
# Before changing this value read the documentation for this option
|
||||||
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
||||||
system.stateVersion = "25.11"; # Did you read the comment?
|
system.stateVersion = "26.05"; # Did you read the comment?
|
||||||
|
|
||||||
# The nix-bitcoin release version that your config is compatible with.
|
# The nix-bitcoin release version that your config is compatible with.
|
||||||
# When upgrading to a backwards-incompatible release, nix-bitcoin will display an
|
# When upgrading to a backwards-incompatible release, nix-bitcoin will display an
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
inputs = {
|
inputs = {
|
||||||
nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
||||||
# You can also use a version branch to track a specific NixOS release
|
# You can also use a version branch to track a specific NixOS release
|
||||||
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
|
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
|
||||||
|
|
||||||
nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
||||||
nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
||||||
@@ -31,6 +31,9 @@
|
|||||||
# legacyInstallDirs = true;
|
# legacyInstallDirs = true;
|
||||||
|
|
||||||
config = {
|
config = {
|
||||||
|
# See the file for why this is needed and when it can be removed
|
||||||
|
imports = [ (nix-bitcoin.outPath + "/test/lib/extra-container-workaround.nix") ];
|
||||||
|
|
||||||
containers.mynode = {
|
containers.mynode = {
|
||||||
# Always start container along with the container host
|
# Always start container along with the container host
|
||||||
autoStart = true;
|
autoStart = true;
|
||||||
|
|||||||
@@ -75,6 +75,8 @@ fi
|
|||||||
#
|
#
|
||||||
read -rd '' src <<EOF || true
|
read -rd '' src <<EOF || true
|
||||||
{ pkgs, lib, ... }: {
|
{ pkgs, lib, ... }: {
|
||||||
|
imports = [ $(realpath "${BASH_SOURCE[0]%/*}"/../test/lib/extra-container-workaround.nix) ];
|
||||||
|
|
||||||
containers.demo-node = {
|
containers.demo-node = {
|
||||||
extra.addressPrefix = "10.250.0";
|
extra.addressPrefix = "10.250.0";
|
||||||
extra.enableWAN = true;
|
extra.enableWAN = true;
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
|
|
||||||
inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
||||||
# You can also use a version branch to track a specific NixOS release
|
# You can also use a version branch to track a specific NixOS release
|
||||||
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
|
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
|
||||||
|
|
||||||
inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
||||||
inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
||||||
|
|||||||
Generated
+7
-7
@@ -44,16 +44,16 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1782847189,
|
"lastModified": 1786313170,
|
||||||
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
|
"narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
|
"rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"ref": "nixos-25.11",
|
"ref": "nixos-26.05",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -76,11 +76,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs-unstable": {
|
"nixpkgs-unstable": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1784453100,
|
"lastModified": 1786348146,
|
||||||
"narHash": "sha256-zpGZb8FYui+i8KLtC0nlcmb0voR2zB80Qn8pe7lzIbk=",
|
"narHash": "sha256-we5zDEFfn8TgzeWKjKDMIjeQZ59omEPl23NIF+13/ys=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "b471514bed69eff5255c8e63c1f80e5fe56c616f",
|
"rev": "d482ef84049d9b7276b83a06e4e4d76983830097",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
'';
|
'';
|
||||||
|
|
||||||
inputs = {
|
inputs = {
|
||||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
||||||
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||||
nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05";
|
nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05";
|
||||||
flake-utils.url = "github:numtide/flake-utils";
|
flake-utils.url = "github:numtide/flake-utils";
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ curl -fsS -L -O "$baseUrl/nar-hash.txt"
|
|||||||
curl -fsS -L -O "$baseUrl/nar-hash.txt.asc"
|
curl -fsS -L -O "$baseUrl/nar-hash.txt.asc"
|
||||||
|
|
||||||
# Verify signature for nar-hash
|
# Verify signature for nar-hash
|
||||||
gpg --verify nar-hash.txt.asc &> /dev/null || {
|
gpg --verify nar-hash.txt.asc nar-hash.txt &> /dev/null || {
|
||||||
>&2 echo "Error: Signature verification failed. Please open an issue in the project repository."
|
>&2 echo "Error: Signature verification failed. Please open an issue in the project repository."
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -239,6 +239,11 @@ in {
|
|||||||
--datadir='${cfg.btcpayserver.dataDir}'
|
--datadir='${cfg.btcpayserver.dataDir}'
|
||||||
'';
|
'';
|
||||||
User = cfg.btcpayserver.user;
|
User = cfg.btcpayserver.user;
|
||||||
|
# Since 2.4.0, btcpayserver uses `Host.CreateDefaultBuilder`, which sets the
|
||||||
|
# ASP.NET content root to the working directory instead of the app directory.
|
||||||
|
# The web root (`wwwroot`) is resolved relative to the content root, so
|
||||||
|
# btcpayserver must be started from its app directory.
|
||||||
|
WorkingDirectory = "${cfg.btcpayserver.package}/lib/btcpayserver";
|
||||||
# Also restart after the program has exited successfully.
|
# Also restart after the program has exited successfully.
|
||||||
# This is required to support restarting from the web interface after
|
# This is required to support restarting from the web interface after
|
||||||
# interactive plugin installation.
|
# interactive plugin installation.
|
||||||
|
|||||||
+4
-1
@@ -265,13 +265,16 @@ in {
|
|||||||
curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}";
|
curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}";
|
||||||
restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1";
|
restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1";
|
||||||
# Setting macaroon permissions for other users needs root permissions
|
# Setting macaroon permissions for other users needs root permissions
|
||||||
|
# The admin macaroon is passed to curl via a fd because argv is
|
||||||
|
# world-readable through /proc/<pid>/cmdline
|
||||||
script = nbLib.rootScript "lnd-create-macaroons" ''
|
script = nbLib.rootScript "lnd-create-macaroons" ''
|
||||||
umask ug=r,o=
|
umask ug=r,o=
|
||||||
${lib.concatMapStrings (macaroon: ''
|
${lib.concatMapStrings (macaroon: ''
|
||||||
echo "Create custom macaroon ${macaroon}"
|
echo "Create custom macaroon ${macaroon}"
|
||||||
macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon"
|
macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon"
|
||||||
|
adminMacaroonHex=$(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')
|
||||||
${curl} \
|
${curl} \
|
||||||
-H "Grpc-Metadata-macaroon: $(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')" \
|
-H @<(printf 'Grpc-Metadata-macaroon: %s\n' "$adminMacaroonHex") \
|
||||||
-X POST \
|
-X POST \
|
||||||
-d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \
|
-d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \
|
||||||
${restUrl}/macaroon |\
|
${restUrl}/macaroon |\
|
||||||
|
|||||||
@@ -37,7 +37,6 @@ let
|
|||||||
type = types.str;
|
type = types.str;
|
||||||
description = ''
|
description = ''
|
||||||
User that is allowed to execute commands in the service network namespaces.
|
User that is allowed to execute commands in the service network namespaces.
|
||||||
The user's group is also authorized.
|
|
||||||
'';
|
'';
|
||||||
default = config.nix-bitcoin.operator.name;
|
default = config.nix-bitcoin.operator.name;
|
||||||
};
|
};
|
||||||
@@ -122,8 +121,10 @@ in {
|
|||||||
source = config.nix-bitcoin.pkgs.netns-exec;
|
source = config.nix-bitcoin.pkgs.netns-exec;
|
||||||
capabilities = "cap_sys_admin=ep";
|
capabilities = "cap_sys_admin=ep";
|
||||||
owner = cfg.allowedUser;
|
owner = cfg.allowedUser;
|
||||||
group = ""; # Set to the group of `owner`
|
# Don't authorize the group of `owner`. For normal users, this group is
|
||||||
permissions = "550";
|
# `users`, which is shared by all normal users.
|
||||||
|
group = "root";
|
||||||
|
permissions = "500";
|
||||||
};
|
};
|
||||||
|
|
||||||
systemd.services = {
|
systemd.services = {
|
||||||
|
|||||||
+3
-3
@@ -4,18 +4,18 @@ pkgs: pkgsUnstable: pkgs-25_05:
|
|||||||
inherit (pkgs)
|
inherit (pkgs)
|
||||||
bitcoin
|
bitcoin
|
||||||
bitcoind
|
bitcoind
|
||||||
|
btcpayserver
|
||||||
charge-lnd
|
charge-lnd
|
||||||
|
clightning
|
||||||
electrs
|
electrs
|
||||||
|
elementsd
|
||||||
extra-container
|
extra-container
|
||||||
lightning-pool
|
lightning-pool
|
||||||
lndconnect;
|
lndconnect;
|
||||||
|
|
||||||
inherit (pkgsUnstable)
|
inherit (pkgsUnstable)
|
||||||
bitcoind-knots
|
bitcoind-knots
|
||||||
btcpayserver
|
|
||||||
clboss
|
clboss
|
||||||
clightning
|
|
||||||
elementsd
|
|
||||||
fulcrum
|
fulcrum
|
||||||
lightning-loop
|
lightning-loop
|
||||||
lnd;
|
lnd;
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
# FIXME:
|
||||||
|
# Remove this file, along with the imports in ../../dev/dev.sh,
|
||||||
|
# ../../examples/container/flake.nix, ../../examples/deploy-container.sh and
|
||||||
|
# ./make-test.nix, as soon as extra-container declares these options itself
|
||||||
|
# (https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix).
|
||||||
|
#
|
||||||
|
# extra-container evaluates the container host with a minimal module set to keep
|
||||||
|
# eval times low. NixOS 26.05 added references to the following options to
|
||||||
|
# `system/boot/systemd.nix`, which is part of that module set, while their
|
||||||
|
# declaring modules are not.
|
||||||
|
#
|
||||||
|
# The defaults match the ones from the declaring modules. Like extra-container's
|
||||||
|
# own dummy options, these declarations have no type because they only exist to
|
||||||
|
# make host eval succeed. They don't affect the resulting container units.
|
||||||
|
|
||||||
|
{ lib, pkgs, ... }: {
|
||||||
|
options = {
|
||||||
|
environment.variables = lib.mkOption { default = {}; };
|
||||||
|
i18n.imperativeLocale = lib.mkOption { default = false; };
|
||||||
|
services.openssh.enable = lib.mkOption { default = false; };
|
||||||
|
system.nixos-init.package = lib.mkOption { default = pkgs.nixos-init; };
|
||||||
|
time.timeZone = lib.mkOption { default = null; };
|
||||||
|
};
|
||||||
|
}
|
||||||
+17
-5
@@ -22,8 +22,8 @@ let
|
|||||||
test.shellcheckServices.enable = true;
|
test.shellcheckServices.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
testScript = nodes: let
|
testScript = { nodes, ... }: let
|
||||||
cfg = nodes.nodes.machine;
|
cfg = nodes.machine;
|
||||||
data = {
|
data = {
|
||||||
data = cfg.test.data;
|
data = cfg.test.data;
|
||||||
tests = cfg.tests;
|
tests = cfg.tests;
|
||||||
@@ -56,12 +56,23 @@ let
|
|||||||
extra-container.lib.buildContainers {
|
extra-container.lib.buildContainers {
|
||||||
inherit system legacyInstallDirs;
|
inherit system legacyInstallDirs;
|
||||||
config = {
|
config = {
|
||||||
|
imports = [ ./extra-container-workaround.nix ];
|
||||||
|
|
||||||
# The container name has a 11 char length limit
|
# The container name has a 11 char length limit
|
||||||
containers.nb-test = { config, ... }: {
|
containers.nb-test = { config, ... }: {
|
||||||
imports = [
|
imports = [
|
||||||
{
|
{
|
||||||
config = {
|
config = {
|
||||||
extra = config.config.test.container;
|
extra = {
|
||||||
|
# Defined here instead of in the container config because NixOS
|
||||||
|
# 26.05 derives the container's `networking.interfaces` from
|
||||||
|
# `localAddress`, which extra-container derives from
|
||||||
|
# `addressPrefix`. Reading it from the container config would
|
||||||
|
# thus be circular.
|
||||||
|
addressPrefix = "10.225.255";
|
||||||
|
inherit (config.config.test.container)
|
||||||
|
enableWAN firewallAllowHost exposeLocalhost;
|
||||||
|
};
|
||||||
config = testConfig;
|
config = testConfig;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -117,8 +128,9 @@ let
|
|||||||
# Needed because duplicity requires 270 MB of free temp space, regardless of backup size
|
# Needed because duplicity requires 270 MB of free temp space, regardless of backup size
|
||||||
diskSize = 1024;
|
diskSize = 1024;
|
||||||
|
|
||||||
# Min. 800 MiB needed to avoid 'out of memory' errors
|
# The `netns` scenarios need more than 2 GiB: netns-isolation adds a
|
||||||
memorySize = lib.mkDefault 2048;
|
# network namespace per service, which costs a few hundred MiB of slab.
|
||||||
|
memorySize = lib.mkDefault 4096;
|
||||||
|
|
||||||
# There are no perf gains beyond 3 cores.
|
# There are no perf gains beyond 3 cores.
|
||||||
# Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90.
|
# Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90.
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ with lib;
|
|||||||
container = {
|
container = {
|
||||||
# Forwarded to extra-container. For descriptions, see
|
# Forwarded to extra-container. For descriptions, see
|
||||||
# https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix
|
# https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix
|
||||||
addressPrefix = mkOption { default = "10.225.255"; };
|
# `addressPrefix` is not settable here, see ./make-test.nix.
|
||||||
enableWAN = mkOption { default = false; };
|
enableWAN = mkOption { default = false; };
|
||||||
firewallAllowHost = mkOption { default = true; };
|
firewallAllowHost = mkOption { default = true; };
|
||||||
exposeLocalhost = mkOption { default = false; };
|
exposeLocalhost = mkOption { default = false; };
|
||||||
|
|||||||
Generated
+47
-63
@@ -1,31 +1,49 @@
|
|||||||
{
|
{
|
||||||
"nodes": {
|
"nodes": {
|
||||||
"flake-utils": {
|
"flake-parts": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"systems": "systems"
|
"nixpkgs-lib": [
|
||||||
|
"nixos-search",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1731533236,
|
"lastModified": 1785627969,
|
||||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
|
||||||
"owner": "numtide",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-utils",
|
"repo": "flake-parts",
|
||||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "numtide",
|
"owner": "hercules-ci",
|
||||||
"repo": "flake-utils",
|
"repo": "flake-parts",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"flake-schemas": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1780327564,
|
||||||
|
"narHash": "sha256-HiRPtA0spK+Dkgbhz/1zW9glXxNVB+L4Rj2VYmdawb8=",
|
||||||
|
"owner": "DeterminateSystems",
|
||||||
|
"repo": "flake-schemas",
|
||||||
|
"rev": "6cc9bd98891b1fc6bb2b8cb3277df8bc72799ca6",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "DeterminateSystems",
|
||||||
|
"repo": "flake-schemas",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nixos-infra": {
|
"nixos-infra": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1778186763,
|
"lastModified": 1785876137,
|
||||||
"narHash": "sha256-WYpwAXUSbAvyygzaPJ5A0MpBgCRDfOn/JlA6bhAExOM=",
|
"narHash": "sha256-maIa1tcvLYFyedzvWApdpaMLzDyTWktCXeugLOEZzDs=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "infra",
|
"repo": "infra",
|
||||||
"rev": "f7fcb33b303e1026a99206c8a9a4f4d93907d5d1",
|
"rev": "952d0cfaf5d2ae350f9a2746c61e03d53a15b8db",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -36,19 +54,19 @@
|
|||||||
},
|
},
|
||||||
"nixos-search": {
|
"nixos-search": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-utils": "flake-utils",
|
"flake-parts": "flake-parts",
|
||||||
|
"flake-schemas": "flake-schemas",
|
||||||
"nixos-infra": "nixos-infra",
|
"nixos-infra": "nixos-infra",
|
||||||
"nixpkgs": "nixpkgs",
|
"nixpkgs": "nixpkgs",
|
||||||
"nixpkgs-npmlock2nix": "nixpkgs-npmlock2nix",
|
"systems": "systems",
|
||||||
"npmlock2nix": "npmlock2nix",
|
|
||||||
"treefmt-nix": "treefmt-nix"
|
"treefmt-nix": "treefmt-nix"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1778708793,
|
"lastModified": 1786265380,
|
||||||
"narHash": "sha256-LXzXKjaxm23vLEOVefy9HNfedZvdI/FvoJlFd/jjNc0=",
|
"narHash": "sha256-JX5Q9o03xYMUpAoHB4nz/0Pf3SeL7GrXoKKJhkUMNps=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixos-search",
|
"repo": "nixos-search",
|
||||||
"rev": "4a3cb26d1ccaa9c62f29071c228dff07c3686e38",
|
"rev": "7507fd6accc65981f02f66f5c6c328e09efc1221",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -59,50 +77,15 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1777954456,
|
"lastModified": 1785967620,
|
||||||
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
|
"narHash": "sha256-929m7iW8q2uv3mZHNwY8Um6XKj99rbIcZsWS9cT1vaI=",
|
||||||
"owner": "NixOS",
|
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
|
||||||
"repo": "nixpkgs",
|
"type": "tarball",
|
||||||
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
|
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1048607.b7c2ada94fe9/nixexprs.tar.xz"
|
||||||
"type": "github"
|
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "NixOS",
|
"type": "tarball",
|
||||||
"ref": "nixos-unstable",
|
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||||
"repo": "nixpkgs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs-npmlock2nix": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1636623366,
|
|
||||||
"narHash": "sha256-jOQMlv9qFSj0U66HB+ujZoapty0UbewmSNbX8+3ujUQ=",
|
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"npmlock2nix": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1758100811,
|
|
||||||
"narHash": "sha256-qJc3ffjHVXUdZqytKcDK9XZ2b3BQ1RdYfZFuYgxbrn4=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "npmlock2nix",
|
|
||||||
"rev": "4d9060afbaa5f57ee0b8ef11c7044ed287a7d302",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "npmlock2nix",
|
|
||||||
"type": "github"
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": {
|
"root": {
|
||||||
@@ -111,6 +94,7 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems": {
|
"systems": {
|
||||||
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
@@ -133,11 +117,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1775636079,
|
"lastModified": 1785945821,
|
||||||
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
|
"narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
|
||||||
"owner": "numtide",
|
"owner": "numtide",
|
||||||
"repo": "treefmt-nix",
|
"repo": "treefmt-nix",
|
||||||
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
|
"rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|||||||
+7
-1
@@ -332,7 +332,13 @@ all() {
|
|||||||
shellcheck
|
shellcheck
|
||||||
examples
|
examples
|
||||||
flake
|
flake
|
||||||
nixosSearch
|
# FIXME: Re-enable when the nixos-search input is usable again.
|
||||||
|
# flake-info at the currently locked rev supplies nixpkgs to its inner eval
|
||||||
|
# via `builtins.getFlake` instead of NIX_PATH. This breaks the postPatch in
|
||||||
|
# ./nixos-search/flake.nix and both runners in ./nixos-search, which pass
|
||||||
|
# nix-bitcoin's pinned nixpkgs through NIX_PATH.
|
||||||
|
# Run explicitly with `./run-tests.sh nixosSearch`.
|
||||||
|
# nixosSearch
|
||||||
}
|
}
|
||||||
|
|
||||||
# An alias for buildTest
|
# An alias for buildTest
|
||||||
|
|||||||
@@ -279,6 +279,10 @@ let
|
|||||||
test.data.netns = config.nix-bitcoin.netns-isolation.netns;
|
test.data.netns = config.nix-bitcoin.netns-isolation.netns;
|
||||||
tests.netns-isolation = true;
|
tests.netns-isolation = true;
|
||||||
environment.systemPackages = [ pkgs.fping ];
|
environment.systemPackages = [ pkgs.fping ];
|
||||||
|
|
||||||
|
# Used for testing that `netns-exec` is not executable by users other than
|
||||||
|
# the operator. Like all normal users, this user is a member of group `users`.
|
||||||
|
users.users.unauthorized.isNormalUser = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
regtestBase = { config, pkgs, ... }: {
|
regtestBase = { config, pkgs, ... }: {
|
||||||
|
|||||||
+16
-7
@@ -1,5 +1,6 @@
|
|||||||
from collections import OrderedDict
|
from collections import OrderedDict
|
||||||
import json
|
import json
|
||||||
|
import os
|
||||||
import re
|
import re
|
||||||
|
|
||||||
def succeed(*cmds):
|
def succeed(*cmds):
|
||||||
@@ -331,6 +332,21 @@ def _():
|
|||||||
f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address"
|
f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# netns-exec should fail for unauthorized namespaces
|
||||||
|
assert_matches(
|
||||||
|
"runuser -u operator -- netns-exec nb-clightning ip a 2>&1 || true",
|
||||||
|
"nb-clightning is not an allowed netns",
|
||||||
|
)
|
||||||
|
|
||||||
|
# netns-exec should only be executable by the operator user.
|
||||||
|
# User `unauthorized` is a member of group `users`, like all normal users.
|
||||||
|
# Netns `nb-clightning` is rejected by netns-exec before it accesses the
|
||||||
|
# netns, so the error below can only originate from the exec permissions.
|
||||||
|
assert_matches(
|
||||||
|
"runuser -u unauthorized -- netns-exec nb-clightning ip a 2>&1 || true",
|
||||||
|
"Permission denied",
|
||||||
|
)
|
||||||
|
|
||||||
if "joinmarket" in enabled_tests:
|
if "joinmarket" in enabled_tests:
|
||||||
# netns-exec should drop capabilities
|
# netns-exec should drop capabilities
|
||||||
assert_matches(
|
assert_matches(
|
||||||
@@ -338,13 +354,6 @@ def _():
|
|||||||
re.compile("^Current: =$", re.MULTILINE),
|
re.compile("^Current: =$", re.MULTILINE),
|
||||||
)
|
)
|
||||||
|
|
||||||
if "clightning" in enabled_tests:
|
|
||||||
# netns-exec should fail for unauthorized namespaces
|
|
||||||
machine.fail("netns-exec nb-clightning ip a")
|
|
||||||
|
|
||||||
# netns-exec should only be executable by the operator user
|
|
||||||
machine.fail("runuser -u clightning -- netns-exec nb-bitcoind ip a")
|
|
||||||
|
|
||||||
|
|
||||||
# Impure: stops bitcoind (and dependent services)
|
# Impure: stops bitcoind (and dependent services)
|
||||||
@test("backups")
|
@test("backups")
|
||||||
|
|||||||
Reference in New Issue
Block a user