Compare commits
15
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
da27f27026 | ||
|
|
4e418e56be | ||
|
|
c4f172441d | ||
|
|
37931e5288 | ||
|
|
0d86dcd7da | ||
|
|
b579fcc371 | ||
|
|
f51460749a | ||
|
|
3b798f5ebf | ||
|
|
df184b6e06 | ||
|
|
138af7f592 | ||
|
|
17f0d98c22 | ||
|
|
34a18f92ee | ||
|
|
2feb7934ac | ||
|
|
8f7dcb6e2a | ||
|
|
e8328251af |
@@ -49,5 +49,7 @@ jobs:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: cachix/install-nix-action@v31
|
||||
- run: nix flake check --all-systems
|
||||
- run: ./test/nixos-search/ci-test.sh
|
||||
# FIXME: Re-enable when the nixos-search input is usable again.
|
||||
# This is also disabled in ./test/run-tests.sh.
|
||||
# - run: ./test/nixos-search/ci-test.sh
|
||||
- run: ./test/shellcheck.sh
|
||||
|
||||
@@ -1,3 +1,7 @@
|
||||
> [!WARNING]
|
||||
> **Archived and unmaintained as of August 13, 2026.**
|
||||
> v0.0.139 is the final release; there will be no further updates or security fixes.
|
||||
|
||||
<p align="center">
|
||||
<img
|
||||
width="320"
|
||||
|
||||
+6
-1
@@ -16,7 +16,12 @@ You can import a GPG key by running the following command with that individual
|
||||
|
||||
## Wall of Fame
|
||||
|
||||
*empty*
|
||||
### [haoxucu](https://github.com/haoxucu)
|
||||
|
||||
* Reported that `netns-exec` was executable by all normal users ([fixed in `34a18f92`](https://github.com/fort-nix/nix-bitcoin/commit/34a18f92eeacc754e5857249aaf8decf24e98cde)); received 5% of the fund.
|
||||
* Reported that `lnd-create-macaroons` exposed the LND admin macaroon in `curl`'s process arguments ([fixed in `df184b6e`](https://github.com/fort-nix/nix-bitcoin/commit/df184b6e06cc3404add42ccf5ae68306395e8d6c)); received 10% of the fund.
|
||||
|
||||
Both rewards were paid in transaction [`5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888`](https://mempool.nixbitcoin.org/tx/5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888).
|
||||
|
||||
|
||||
## nix-bitcoin security fund
|
||||
|
||||
+1
-1
@@ -97,5 +97,5 @@ It's easiest to use an existing service as a template:
|
||||
Most other services use packages that are already included in nixpkgs.
|
||||
|
||||
## Switching to a new NixOS release
|
||||
- Run command `update-flake.sh 25.11`
|
||||
- Run command `update-flake.sh 26.05`
|
||||
- Treewide: check if any `TODO-EXTERNAL` comments can be resolved
|
||||
|
||||
@@ -82,6 +82,7 @@ read -rd '' src <<'EOF' || :
|
||||
inherit (nix-bitcoin.inputs) nixpkgs;
|
||||
# legacyInstallDirs = true;
|
||||
config = {
|
||||
imports = [ ../test/lib/extra-container-workaround.nix ];
|
||||
containers.nb-adhoc = {
|
||||
# bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; };
|
||||
extra.addressPrefix = "10.200.255";
|
||||
|
||||
@@ -324,7 +324,7 @@
|
||||
# this value at the release version of the first install of this system.
|
||||
# Before changing this value read the documentation for this option
|
||||
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
||||
system.stateVersion = "25.11"; # Did you read the comment?
|
||||
system.stateVersion = "26.05"; # Did you read the comment?
|
||||
|
||||
# The nix-bitcoin release version that your config is compatible with.
|
||||
# When upgrading to a backwards-incompatible release, nix-bitcoin will display an
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
inputs = {
|
||||
nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
||||
# You can also use a version branch to track a specific NixOS release
|
||||
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
|
||||
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
|
||||
|
||||
nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
||||
nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
||||
@@ -31,6 +31,9 @@
|
||||
# legacyInstallDirs = true;
|
||||
|
||||
config = {
|
||||
# See the file for why this is needed and when it can be removed
|
||||
imports = [ (nix-bitcoin.outPath + "/test/lib/extra-container-workaround.nix") ];
|
||||
|
||||
containers.mynode = {
|
||||
# Always start container along with the container host
|
||||
autoStart = true;
|
||||
|
||||
@@ -75,6 +75,8 @@ fi
|
||||
#
|
||||
read -rd '' src <<EOF || true
|
||||
{ pkgs, lib, ... }: {
|
||||
imports = [ $(realpath "${BASH_SOURCE[0]%/*}"/../test/lib/extra-container-workaround.nix) ];
|
||||
|
||||
containers.demo-node = {
|
||||
extra.addressPrefix = "10.250.0";
|
||||
extra.enableWAN = true;
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
|
||||
inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
|
||||
# You can also use a version branch to track a specific NixOS release
|
||||
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
|
||||
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
|
||||
|
||||
inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs";
|
||||
inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
|
||||
|
||||
Generated
+7
-7
@@ -44,16 +44,16 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1782847189,
|
||||
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
|
||||
"lastModified": 1786313170,
|
||||
"narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
|
||||
"rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-25.11",
|
||||
"ref": "nixos-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
@@ -76,11 +76,11 @@
|
||||
},
|
||||
"nixpkgs-unstable": {
|
||||
"locked": {
|
||||
"lastModified": 1784453100,
|
||||
"narHash": "sha256-zpGZb8FYui+i8KLtC0nlcmb0voR2zB80Qn8pe7lzIbk=",
|
||||
"lastModified": 1786348146,
|
||||
"narHash": "sha256-we5zDEFfn8TgzeWKjKDMIjeQZ59omEPl23NIF+13/ys=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b471514bed69eff5255c8e63c1f80e5fe56c616f",
|
||||
"rev": "d482ef84049d9b7276b83a06e4e4d76983830097",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
'';
|
||||
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
|
||||
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
||||
nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05";
|
||||
flake-utils.url = "github:numtide/flake-utils";
|
||||
|
||||
@@ -31,7 +31,7 @@ curl -fsS -L -O "$baseUrl/nar-hash.txt"
|
||||
curl -fsS -L -O "$baseUrl/nar-hash.txt.asc"
|
||||
|
||||
# Verify signature for nar-hash
|
||||
gpg --verify nar-hash.txt.asc &> /dev/null || {
|
||||
gpg --verify nar-hash.txt.asc nar-hash.txt &> /dev/null || {
|
||||
>&2 echo "Error: Signature verification failed. Please open an issue in the project repository."
|
||||
exit 1
|
||||
}
|
||||
|
||||
@@ -239,6 +239,11 @@ in {
|
||||
--datadir='${cfg.btcpayserver.dataDir}'
|
||||
'';
|
||||
User = cfg.btcpayserver.user;
|
||||
# Since 2.4.0, btcpayserver uses `Host.CreateDefaultBuilder`, which sets the
|
||||
# ASP.NET content root to the working directory instead of the app directory.
|
||||
# The web root (`wwwroot`) is resolved relative to the content root, so
|
||||
# btcpayserver must be started from its app directory.
|
||||
WorkingDirectory = "${cfg.btcpayserver.package}/lib/btcpayserver";
|
||||
# Also restart after the program has exited successfully.
|
||||
# This is required to support restarting from the web interface after
|
||||
# interactive plugin installation.
|
||||
|
||||
+4
-1
@@ -265,13 +265,16 @@ in {
|
||||
curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}";
|
||||
restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1";
|
||||
# Setting macaroon permissions for other users needs root permissions
|
||||
# The admin macaroon is passed to curl via a fd because argv is
|
||||
# world-readable through /proc/<pid>/cmdline
|
||||
script = nbLib.rootScript "lnd-create-macaroons" ''
|
||||
umask ug=r,o=
|
||||
${lib.concatMapStrings (macaroon: ''
|
||||
echo "Create custom macaroon ${macaroon}"
|
||||
macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon"
|
||||
adminMacaroonHex=$(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')
|
||||
${curl} \
|
||||
-H "Grpc-Metadata-macaroon: $(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')" \
|
||||
-H @<(printf 'Grpc-Metadata-macaroon: %s\n' "$adminMacaroonHex") \
|
||||
-X POST \
|
||||
-d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \
|
||||
${restUrl}/macaroon |\
|
||||
|
||||
@@ -37,7 +37,6 @@ let
|
||||
type = types.str;
|
||||
description = ''
|
||||
User that is allowed to execute commands in the service network namespaces.
|
||||
The user's group is also authorized.
|
||||
'';
|
||||
default = config.nix-bitcoin.operator.name;
|
||||
};
|
||||
@@ -122,8 +121,10 @@ in {
|
||||
source = config.nix-bitcoin.pkgs.netns-exec;
|
||||
capabilities = "cap_sys_admin=ep";
|
||||
owner = cfg.allowedUser;
|
||||
group = ""; # Set to the group of `owner`
|
||||
permissions = "550";
|
||||
# Don't authorize the group of `owner`. For normal users, this group is
|
||||
# `users`, which is shared by all normal users.
|
||||
group = "root";
|
||||
permissions = "500";
|
||||
};
|
||||
|
||||
systemd.services = {
|
||||
|
||||
+3
-3
@@ -4,18 +4,18 @@ pkgs: pkgsUnstable: pkgs-25_05:
|
||||
inherit (pkgs)
|
||||
bitcoin
|
||||
bitcoind
|
||||
btcpayserver
|
||||
charge-lnd
|
||||
clightning
|
||||
electrs
|
||||
elementsd
|
||||
extra-container
|
||||
lightning-pool
|
||||
lndconnect;
|
||||
|
||||
inherit (pkgsUnstable)
|
||||
bitcoind-knots
|
||||
btcpayserver
|
||||
clboss
|
||||
clightning
|
||||
elementsd
|
||||
fulcrum
|
||||
lightning-loop
|
||||
lnd;
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
# FIXME:
|
||||
# Remove this file, along with the imports in ../../dev/dev.sh,
|
||||
# ../../examples/container/flake.nix, ../../examples/deploy-container.sh and
|
||||
# ./make-test.nix, as soon as extra-container declares these options itself
|
||||
# (https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix).
|
||||
#
|
||||
# extra-container evaluates the container host with a minimal module set to keep
|
||||
# eval times low. NixOS 26.05 added references to the following options to
|
||||
# `system/boot/systemd.nix`, which is part of that module set, while their
|
||||
# declaring modules are not.
|
||||
#
|
||||
# The defaults match the ones from the declaring modules. Like extra-container's
|
||||
# own dummy options, these declarations have no type because they only exist to
|
||||
# make host eval succeed. They don't affect the resulting container units.
|
||||
|
||||
{ lib, pkgs, ... }: {
|
||||
options = {
|
||||
environment.variables = lib.mkOption { default = {}; };
|
||||
i18n.imperativeLocale = lib.mkOption { default = false; };
|
||||
services.openssh.enable = lib.mkOption { default = false; };
|
||||
system.nixos-init.package = lib.mkOption { default = pkgs.nixos-init; };
|
||||
time.timeZone = lib.mkOption { default = null; };
|
||||
};
|
||||
}
|
||||
+17
-5
@@ -22,8 +22,8 @@ let
|
||||
test.shellcheckServices.enable = true;
|
||||
};
|
||||
|
||||
testScript = nodes: let
|
||||
cfg = nodes.nodes.machine;
|
||||
testScript = { nodes, ... }: let
|
||||
cfg = nodes.machine;
|
||||
data = {
|
||||
data = cfg.test.data;
|
||||
tests = cfg.tests;
|
||||
@@ -56,12 +56,23 @@ let
|
||||
extra-container.lib.buildContainers {
|
||||
inherit system legacyInstallDirs;
|
||||
config = {
|
||||
imports = [ ./extra-container-workaround.nix ];
|
||||
|
||||
# The container name has a 11 char length limit
|
||||
containers.nb-test = { config, ... }: {
|
||||
imports = [
|
||||
{
|
||||
config = {
|
||||
extra = config.config.test.container;
|
||||
extra = {
|
||||
# Defined here instead of in the container config because NixOS
|
||||
# 26.05 derives the container's `networking.interfaces` from
|
||||
# `localAddress`, which extra-container derives from
|
||||
# `addressPrefix`. Reading it from the container config would
|
||||
# thus be circular.
|
||||
addressPrefix = "10.225.255";
|
||||
inherit (config.config.test.container)
|
||||
enableWAN firewallAllowHost exposeLocalhost;
|
||||
};
|
||||
config = testConfig;
|
||||
};
|
||||
}
|
||||
@@ -117,8 +128,9 @@ let
|
||||
# Needed because duplicity requires 270 MB of free temp space, regardless of backup size
|
||||
diskSize = 1024;
|
||||
|
||||
# Min. 800 MiB needed to avoid 'out of memory' errors
|
||||
memorySize = lib.mkDefault 2048;
|
||||
# The `netns` scenarios need more than 2 GiB: netns-isolation adds a
|
||||
# network namespace per service, which costs a few hundred MiB of slab.
|
||||
memorySize = lib.mkDefault 4096;
|
||||
|
||||
# There are no perf gains beyond 3 cores.
|
||||
# Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90.
|
||||
|
||||
@@ -31,7 +31,7 @@ with lib;
|
||||
container = {
|
||||
# Forwarded to extra-container. For descriptions, see
|
||||
# https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix
|
||||
addressPrefix = mkOption { default = "10.225.255"; };
|
||||
# `addressPrefix` is not settable here, see ./make-test.nix.
|
||||
enableWAN = mkOption { default = false; };
|
||||
firewallAllowHost = mkOption { default = true; };
|
||||
exposeLocalhost = mkOption { default = false; };
|
||||
|
||||
Generated
+47
-63
@@ -1,31 +1,49 @@
|
||||
{
|
||||
"nodes": {
|
||||
"flake-utils": {
|
||||
"flake-parts": {
|
||||
"inputs": {
|
||||
"systems": "systems"
|
||||
"nixpkgs-lib": [
|
||||
"nixos-search",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1731533236,
|
||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
||||
"lastModified": 1785627969,
|
||||
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-schemas": {
|
||||
"locked": {
|
||||
"lastModified": 1780327564,
|
||||
"narHash": "sha256-HiRPtA0spK+Dkgbhz/1zW9glXxNVB+L4Rj2VYmdawb8=",
|
||||
"owner": "DeterminateSystems",
|
||||
"repo": "flake-schemas",
|
||||
"rev": "6cc9bd98891b1fc6bb2b8cb3277df8bc72799ca6",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "DeterminateSystems",
|
||||
"repo": "flake-schemas",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixos-infra": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1778186763,
|
||||
"narHash": "sha256-WYpwAXUSbAvyygzaPJ5A0MpBgCRDfOn/JlA6bhAExOM=",
|
||||
"lastModified": 1785876137,
|
||||
"narHash": "sha256-maIa1tcvLYFyedzvWApdpaMLzDyTWktCXeugLOEZzDs=",
|
||||
"owner": "NixOS",
|
||||
"repo": "infra",
|
||||
"rev": "f7fcb33b303e1026a99206c8a9a4f4d93907d5d1",
|
||||
"rev": "952d0cfaf5d2ae350f9a2746c61e03d53a15b8db",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -36,19 +54,19 @@
|
||||
},
|
||||
"nixos-search": {
|
||||
"inputs": {
|
||||
"flake-utils": "flake-utils",
|
||||
"flake-parts": "flake-parts",
|
||||
"flake-schemas": "flake-schemas",
|
||||
"nixos-infra": "nixos-infra",
|
||||
"nixpkgs": "nixpkgs",
|
||||
"nixpkgs-npmlock2nix": "nixpkgs-npmlock2nix",
|
||||
"npmlock2nix": "npmlock2nix",
|
||||
"systems": "systems",
|
||||
"treefmt-nix": "treefmt-nix"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1778708793,
|
||||
"narHash": "sha256-LXzXKjaxm23vLEOVefy9HNfedZvdI/FvoJlFd/jjNc0=",
|
||||
"lastModified": 1786265380,
|
||||
"narHash": "sha256-JX5Q9o03xYMUpAoHB4nz/0Pf3SeL7GrXoKKJhkUMNps=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixos-search",
|
||||
"rev": "4a3cb26d1ccaa9c62f29071c228dff07c3686e38",
|
||||
"rev": "7507fd6accc65981f02f66f5c6c328e09efc1221",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -59,50 +77,15 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1777954456,
|
||||
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
|
||||
"type": "github"
|
||||
"lastModified": 1785967620,
|
||||
"narHash": "sha256-929m7iW8q2uv3mZHNwY8Um6XKj99rbIcZsWS9cT1vaI=",
|
||||
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1048607.b7c2ada94fe9/nixexprs.tar.xz"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs-npmlock2nix": {
|
||||
"locked": {
|
||||
"lastModified": 1636623366,
|
||||
"narHash": "sha256-jOQMlv9qFSj0U66HB+ujZoapty0UbewmSNbX8+3ujUQ=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"npmlock2nix": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1758100811,
|
||||
"narHash": "sha256-qJc3ffjHVXUdZqytKcDK9XZ2b3BQ1RdYfZFuYgxbrn4=",
|
||||
"owner": "nix-community",
|
||||
"repo": "npmlock2nix",
|
||||
"rev": "4d9060afbaa5f57ee0b8ef11c7044ed287a7d302",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"repo": "npmlock2nix",
|
||||
"type": "github"
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
@@ -111,6 +94,7 @@
|
||||
}
|
||||
},
|
||||
"systems": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1681028828,
|
||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||
@@ -133,11 +117,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775636079,
|
||||
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
|
||||
"lastModified": 1785945821,
|
||||
"narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
|
||||
"rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
+7
-1
@@ -332,7 +332,13 @@ all() {
|
||||
shellcheck
|
||||
examples
|
||||
flake
|
||||
nixosSearch
|
||||
# FIXME: Re-enable when the nixos-search input is usable again.
|
||||
# flake-info at the currently locked rev supplies nixpkgs to its inner eval
|
||||
# via `builtins.getFlake` instead of NIX_PATH. This breaks the postPatch in
|
||||
# ./nixos-search/flake.nix and both runners in ./nixos-search, which pass
|
||||
# nix-bitcoin's pinned nixpkgs through NIX_PATH.
|
||||
# Run explicitly with `./run-tests.sh nixosSearch`.
|
||||
# nixosSearch
|
||||
}
|
||||
|
||||
# An alias for buildTest
|
||||
|
||||
@@ -279,6 +279,10 @@ let
|
||||
test.data.netns = config.nix-bitcoin.netns-isolation.netns;
|
||||
tests.netns-isolation = true;
|
||||
environment.systemPackages = [ pkgs.fping ];
|
||||
|
||||
# Used for testing that `netns-exec` is not executable by users other than
|
||||
# the operator. Like all normal users, this user is a member of group `users`.
|
||||
users.users.unauthorized.isNormalUser = true;
|
||||
};
|
||||
|
||||
regtestBase = { config, pkgs, ... }: {
|
||||
|
||||
+16
-7
@@ -1,5 +1,6 @@
|
||||
from collections import OrderedDict
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
|
||||
def succeed(*cmds):
|
||||
@@ -331,6 +332,21 @@ def _():
|
||||
f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address"
|
||||
)
|
||||
|
||||
# netns-exec should fail for unauthorized namespaces
|
||||
assert_matches(
|
||||
"runuser -u operator -- netns-exec nb-clightning ip a 2>&1 || true",
|
||||
"nb-clightning is not an allowed netns",
|
||||
)
|
||||
|
||||
# netns-exec should only be executable by the operator user.
|
||||
# User `unauthorized` is a member of group `users`, like all normal users.
|
||||
# Netns `nb-clightning` is rejected by netns-exec before it accesses the
|
||||
# netns, so the error below can only originate from the exec permissions.
|
||||
assert_matches(
|
||||
"runuser -u unauthorized -- netns-exec nb-clightning ip a 2>&1 || true",
|
||||
"Permission denied",
|
||||
)
|
||||
|
||||
if "joinmarket" in enabled_tests:
|
||||
# netns-exec should drop capabilities
|
||||
assert_matches(
|
||||
@@ -338,13 +354,6 @@ def _():
|
||||
re.compile("^Current: =$", re.MULTILINE),
|
||||
)
|
||||
|
||||
if "clightning" in enabled_tests:
|
||||
# netns-exec should fail for unauthorized namespaces
|
||||
machine.fail("netns-exec nb-clightning ip a")
|
||||
|
||||
# netns-exec should only be executable by the operator user
|
||||
machine.fail("runuser -u clightning -- netns-exec nb-bitcoind ip a")
|
||||
|
||||
|
||||
# Impure: stops bitcoind (and dependent services)
|
||||
@test("backups")
|
||||
|
||||
Reference in New Issue
Block a user