Compare commits

..
15 Commits
Author SHA1 Message Date
Jonas Nick da27f27026 fetch-release: fix signature verification!
nix-bitcoin tests / build_test_drivers (push) Canceled after 0s
nix-bitcoin tests / check_flake (push) Canceled after 0s
nix-bitcoin tests / test_scenario (default) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (joinmarket-bitcoind-29) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (netns) (push) Canceled after 0s
nix-bitcoin tests / test_scenario (netnsRegtest) (push) Canceled after 0s
`gpg --verify nar-hash.txt.asc` with a single argument lets gpg pick the
verification mode from the file's packet structure. For a real detached
signature it hashes the sibling nar-hash.txt, but for an inline signed
message it verifies the payload embedded in the .asc itself, never reads
nar-hash.txt, prints "not a detached signature; file was NOT verified!"
and still exits 0. The `&> /dev/null` hid that warning.
2026-08-31 08:12:01 +00:00
Jonas Nick 4e418e56be SECURITY: add haoxucu to wall of fame 2026-08-31 07:07:23 +00:00
Jonas Nick c4f172441d README: add archival notice 2026-08-15 16:09:51 +00:00
Jonas Nick 37931e5288 Merge fort-nix/nix-bitcoin#848: lnd: don't pass the admin macaroon in curl argv
df184b6e06 lnd: don't pass the admin macaroon in `curl` argv (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: d18fa7176c59f33a38222a2d3d44320769ac83e091104594a9572e44ce38205d341767ea598da1b5500208c1e9f6645ed5c3b9390438d95912e44d1c5f3a4752
2026-08-13 10:44:26 +00:00
Jonas Nick 0d86dcd7da Merge fort-nix/nix-bitcoin#847: update nixpkgs
f51460749a ci: disable the nixos-search test (Jonas Nick)
3b798f5ebf test: increase VM memory to 4 GiB (Jonas Nick)
17f0d98c22 update nixpkgs (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 0e40353d9d7937dd7a80c05416360c30ada7ee231d6263883072d60a707443e765d35f6a393e718ed1ef66f2e2cdbd1deadd6cd720dccb5c5e18711159cda38a
2026-08-13 10:43:37 +00:00
Jonas Nick b579fcc371 Merge fort-nix/nix-bitcoin#846: netns-isolation: fix netns-exec being executable by all normal users
34a18f92ee netns-isolation: fix netns-exec being executable by all normal users (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 3aa359bb61967b76299918b893b85f5d92909029237cba892b367f94c82643268dceaf2928157b47d4973a8af81e5e9ef29651bc45db0e3b149966b16c41bc8b
2026-08-12 18:26:21 +00:00
Jonas Nick f51460749a ci: disable the nixos-search test 2026-08-12 18:23:10 +00:00
Jonas Nick 3b798f5ebf test: increase VM memory to 4 GiB 2026-08-12 18:22:32 +00:00
Jonas Nick df184b6e06 lnd: don't pass the admin macaroon in curl argv
`lnd-create-macaroons` interpolated the hex-encoded admin macaroon into
`curl`'s argv, where any local user could read it from world-readable
`/proc/<pid>/cmdline`. The unit's `ProtectProc=invisible` doesn't apply,
because `nbLib.rootScript`'s `+` prefix disables sandboxing for the
process. Pass the header on a file descriptor instead, so the credential
never enters any argv (`printf` is a bash builtin); the request sent to
lnd is unchanged. Only configurations with a non-empty
`services.lnd.macaroons` were affected, which `services.charge-lnd` and
`services.btcpayserver` with `lightningBackend = "lnd"` set automatically.
2026-08-12 18:02:07 +00:00
Jonas Nick 138af7f592 Merge fort-nix/nix-bitcoin#844: NixOS 25.11 -> 26.05
2feb7934ac run-tests: disable the nixos-search test (Jonas Nick)
8f7dcb6e2a containers: fix for NixOS 26.05 (Jonas Nick)
e8328251af udpate nixos 25.11 -> 26.05 (Jonas Nick)

Pull request description:

Top commit has no ACKs.

Tree-SHA512: 78d3f3ba4dc43a71c5e30b9b663a51ba7ba11c880bf9113a6cb20d22b1df5a8227c8a29a6be23f7bbee2be801c5b81432bc80cd957b4758196e01c3b68ed6707
2026-08-11 09:42:34 +00:00
Jonas Nick 17f0d98c22 update nixpkgs
bitcoin: 31.0 -> 31.1
bitcoind: 31.0 -> 31.1
btcpayserver: 2.3.4 -> 2.4.2
clboss: 0.16.0 -> 0.16.1
2026-08-11 09:41:31 +00:00
Jonas Nick 34a18f92ee netns-isolation: fix netns-exec being executable by all normal users
The `netns-exec` wrapper was created with `group = ""`, which makes the
`security.wrappers` activation run `chown ${allowedUser}:`. GNU chown
resolves the trailing colon to the owner's login group, and because the
operator is defined with `isNormalUser = true`, that group is the shared
group `users`. Together with mode 550, this made the wrapper executable
by every normal user on the host instead of only by `allowedUser`.

The wrapper carries `cap_sys_admin=ep` and the NixOS security wrapper
performs no owner check, so any normal user could enter `nb-joinmarket`,
the only netns that `netns-exec` permits. This exposes joinmarketd's
unauthenticated control port on 127.0.0.1 inside that netns and allows
sending packets from the joinmarket netns address. This can only ever become a
problem if there's a second, normal user on the host.

Use mode 500 so that only `allowedUser` can execute the wrapper. Also
set the group to `root`, so that `users` doesn't silently become an
authorized group again if the mode is ever loosened.

The netns-isolation test asserted this property with
`runuser -u clightning -- netns-exec nb-bitcoind ip a`, which fails
regardless of the file mode, because `clightning` is a system user with
its own group and `nb-bitcoind` is not in netns-exec's allowlist.
Replace it with a check that a normal user is denied by the exec
permissions, and assert the reason for each failure instead of only the
exit status.
2026-08-09 19:40:39 +00:00
Jonas Nick 2feb7934ac run-tests: disable the nixos-search test 2026-08-08 06:54:06 +00:00
Jonas Nick 8f7dcb6e2a containers: fix for NixOS 26.05 2026-08-08 06:54:06 +00:00
Jonas Nick e8328251af udpate nixos 25.11 -> 26.05 2026-08-08 06:54:06 +00:00
23 changed files with 164 additions and 99 deletions
+3 -1
View File
@@ -49,5 +49,7 @@ jobs:
- uses: actions/checkout@v4
- uses: cachix/install-nix-action@v31
- run: nix flake check --all-systems
- run: ./test/nixos-search/ci-test.sh
# FIXME: Re-enable when the nixos-search input is usable again.
# This is also disabled in ./test/run-tests.sh.
# - run: ./test/nixos-search/ci-test.sh
- run: ./test/shellcheck.sh
+4
View File
@@ -1,3 +1,7 @@
> [!WARNING]
> **Archived and unmaintained as of August 13, 2026.**
> v0.0.139 is the final release; there will be no further updates or security fixes.
<p align="center">
<img
width="320"
+6 -1
View File
@@ -16,7 +16,12 @@ You can import a GPG key by running the following command with that individual
## Wall of Fame
*empty*
### [haoxucu](https://github.com/haoxucu)
* Reported that `netns-exec` was executable by all normal users ([fixed in `34a18f92`](https://github.com/fort-nix/nix-bitcoin/commit/34a18f92eeacc754e5857249aaf8decf24e98cde)); received 5% of the fund.
* Reported that `lnd-create-macaroons` exposed the LND admin macaroon in `curl`'s process arguments ([fixed in `df184b6e`](https://github.com/fort-nix/nix-bitcoin/commit/df184b6e06cc3404add42ccf5ae68306395e8d6c)); received 10% of the fund.
Both rewards were paid in transaction [`5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888`](https://mempool.nixbitcoin.org/tx/5b93fbad4b9a2c35daaf40b74fc76f0b69d2b75bc4da927cd3398dbc432eb888).
## nix-bitcoin security fund
+1 -1
View File
@@ -97,5 +97,5 @@ It's easiest to use an existing service as a template:
Most other services use packages that are already included in nixpkgs.
## Switching to a new NixOS release
- Run command `update-flake.sh 25.11`
- Run command `update-flake.sh 26.05`
- Treewide: check if any `TODO-EXTERNAL` comments can be resolved
+1
View File
@@ -82,6 +82,7 @@ read -rd '' src <<'EOF' || :
inherit (nix-bitcoin.inputs) nixpkgs;
# legacyInstallDirs = true;
config = {
imports = [ ../test/lib/extra-container-workaround.nix ];
containers.nb-adhoc = {
# bindMounts."/shared" = { hostPath = "/my/hostpath"; isReadOnly = false; };
extra.addressPrefix = "10.200.255";
+1 -1
View File
@@ -324,7 +324,7 @@
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "25.11"; # Did you read the comment?
system.stateVersion = "26.05"; # Did you read the comment?
# The nix-bitcoin release version that your config is compatible with.
# When upgrading to a backwards-incompatible release, nix-bitcoin will display an
+4 -1
View File
@@ -12,7 +12,7 @@
inputs = {
nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
# You can also use a version branch to track a specific NixOS release
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
# nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
nixpkgs.follows = "nix-bitcoin/nixpkgs";
nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
@@ -31,6 +31,9 @@
# legacyInstallDirs = true;
config = {
# See the file for why this is needed and when it can be removed
imports = [ (nix-bitcoin.outPath + "/test/lib/extra-container-workaround.nix") ];
containers.mynode = {
# Always start container along with the container host
autoStart = true;
+2
View File
@@ -75,6 +75,8 @@ fi
#
read -rd '' src <<EOF || true
{ pkgs, lib, ... }: {
imports = [ $(realpath "${BASH_SOURCE[0]%/*}"/../test/lib/extra-container-workaround.nix) ];
containers.demo-node = {
extra.addressPrefix = "10.250.0";
extra.enableWAN = true;
+1 -1
View File
@@ -10,7 +10,7 @@
inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/release";
# You can also use a version branch to track a specific NixOS release
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-25.11";
# inputs.nix-bitcoin.url = "github:fort-nix/nix-bitcoin/nixos-26.05";
inputs.nixpkgs.follows = "nix-bitcoin/nixpkgs";
inputs.nixpkgs-unstable.follows = "nix-bitcoin/nixpkgs-unstable";
Generated
+7 -7
View File
@@ -44,16 +44,16 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1782847189,
"narHash": "sha256-twXPFqFsrrY5r28Zh7Homgcp2gUMBgQ6WDS98Q/3xFI=",
"lastModified": 1786313170,
"narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b6018f87da91d19d0ab4cf979885689b469cdd41",
"rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-25.11",
"ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
@@ -76,11 +76,11 @@
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1784453100,
"narHash": "sha256-zpGZb8FYui+i8KLtC0nlcmb0voR2zB80Qn8pe7lzIbk=",
"lastModified": 1786348146,
"narHash": "sha256-we5zDEFfn8TgzeWKjKDMIjeQZ59omEPl23NIF+13/ys=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b471514bed69eff5255c8e63c1f80e5fe56c616f",
"rev": "d482ef84049d9b7276b83a06e4e4d76983830097",
"type": "github"
},
"original": {
+1 -1
View File
@@ -5,7 +5,7 @@
'';
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
nixpkgs-25_05.url = "github:NixOS/nixpkgs/nixos-25.05";
flake-utils.url = "github:numtide/flake-utils";
+1 -1
View File
@@ -31,7 +31,7 @@ curl -fsS -L -O "$baseUrl/nar-hash.txt"
curl -fsS -L -O "$baseUrl/nar-hash.txt.asc"
# Verify signature for nar-hash
gpg --verify nar-hash.txt.asc &> /dev/null || {
gpg --verify nar-hash.txt.asc nar-hash.txt &> /dev/null || {
>&2 echo "Error: Signature verification failed. Please open an issue in the project repository."
exit 1
}
+5
View File
@@ -239,6 +239,11 @@ in {
--datadir='${cfg.btcpayserver.dataDir}'
'';
User = cfg.btcpayserver.user;
# Since 2.4.0, btcpayserver uses `Host.CreateDefaultBuilder`, which sets the
# ASP.NET content root to the working directory instead of the app directory.
# The web root (`wwwroot`) is resolved relative to the content root, so
# btcpayserver must be started from its app directory.
WorkingDirectory = "${cfg.btcpayserver.package}/lib/btcpayserver";
# Also restart after the program has exited successfully.
# This is required to support restarting from the web interface after
# interactive plugin installation.
+4 -1
View File
@@ -265,13 +265,16 @@ in {
curl = "${pkgs.curl}/bin/curl -fsS --cacert ${cfg.certPath}";
restUrl = "https://${nbLib.addressWithPort cfg.restAddress cfg.restPort}/v1";
# Setting macaroon permissions for other users needs root permissions
# The admin macaroon is passed to curl via a fd because argv is
# world-readable through /proc/<pid>/cmdline
script = nbLib.rootScript "lnd-create-macaroons" ''
umask ug=r,o=
${lib.concatMapStrings (macaroon: ''
echo "Create custom macaroon ${macaroon}"
macaroonPath="$RUNTIME_DIRECTORY/${macaroon}.macaroon"
adminMacaroonHex=$(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')
${curl} \
-H "Grpc-Metadata-macaroon: $(${pkgs.xxd}/bin/xxd -ps -u -c 99999 '${networkDir}/admin.macaroon')" \
-H @<(printf 'Grpc-Metadata-macaroon: %s\n' "$adminMacaroonHex") \
-X POST \
-d '{"permissions":[${cfg.macaroons.${macaroon}.permissions}]}' \
${restUrl}/macaroon |\
+4 -3
View File
@@ -37,7 +37,6 @@ let
type = types.str;
description = ''
User that is allowed to execute commands in the service network namespaces.
The user's group is also authorized.
'';
default = config.nix-bitcoin.operator.name;
};
@@ -122,8 +121,10 @@ in {
source = config.nix-bitcoin.pkgs.netns-exec;
capabilities = "cap_sys_admin=ep";
owner = cfg.allowedUser;
group = ""; # Set to the group of `owner`
permissions = "550";
# Don't authorize the group of `owner`. For normal users, this group is
# `users`, which is shared by all normal users.
group = "root";
permissions = "500";
};
systemd.services = {
+3 -3
View File
@@ -4,18 +4,18 @@ pkgs: pkgsUnstable: pkgs-25_05:
inherit (pkgs)
bitcoin
bitcoind
btcpayserver
charge-lnd
clightning
electrs
elementsd
extra-container
lightning-pool
lndconnect;
inherit (pkgsUnstable)
bitcoind-knots
btcpayserver
clboss
clightning
elementsd
fulcrum
lightning-loop
lnd;
+24
View File
@@ -0,0 +1,24 @@
# FIXME:
# Remove this file, along with the imports in ../../dev/dev.sh,
# ../../examples/container/flake.nix, ../../examples/deploy-container.sh and
# ./make-test.nix, as soon as extra-container declares these options itself
# (https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix).
#
# extra-container evaluates the container host with a minimal module set to keep
# eval times low. NixOS 26.05 added references to the following options to
# `system/boot/systemd.nix`, which is part of that module set, while their
# declaring modules are not.
#
# The defaults match the ones from the declaring modules. Like extra-container's
# own dummy options, these declarations have no type because they only exist to
# make host eval succeed. They don't affect the resulting container units.
{ lib, pkgs, ... }: {
options = {
environment.variables = lib.mkOption { default = {}; };
i18n.imperativeLocale = lib.mkOption { default = false; };
services.openssh.enable = lib.mkOption { default = false; };
system.nixos-init.package = lib.mkOption { default = pkgs.nixos-init; };
time.timeZone = lib.mkOption { default = null; };
};
}
+17 -5
View File
@@ -22,8 +22,8 @@ let
test.shellcheckServices.enable = true;
};
testScript = nodes: let
cfg = nodes.nodes.machine;
testScript = { nodes, ... }: let
cfg = nodes.machine;
data = {
data = cfg.test.data;
tests = cfg.tests;
@@ -56,12 +56,23 @@ let
extra-container.lib.buildContainers {
inherit system legacyInstallDirs;
config = {
imports = [ ./extra-container-workaround.nix ];
# The container name has a 11 char length limit
containers.nb-test = { config, ... }: {
imports = [
{
config = {
extra = config.config.test.container;
extra = {
# Defined here instead of in the container config because NixOS
# 26.05 derives the container's `networking.interfaces` from
# `localAddress`, which extra-container derives from
# `addressPrefix`. Reading it from the container config would
# thus be circular.
addressPrefix = "10.225.255";
inherit (config.config.test.container)
enableWAN firewallAllowHost exposeLocalhost;
};
config = testConfig;
};
}
@@ -117,8 +128,9 @@ let
# Needed because duplicity requires 270 MB of free temp space, regardless of backup size
diskSize = 1024;
# Min. 800 MiB needed to avoid 'out of memory' errors
memorySize = lib.mkDefault 2048;
# The `netns` scenarios need more than 2 GiB: netns-isolation adds a
# network namespace per service, which costs a few hundred MiB of slab.
memorySize = lib.mkDefault 4096;
# There are no perf gains beyond 3 cores.
# Benchmark: Ryzen 7 2700 (8 cores), VM test `default` as of 34f6eb90.
+1 -1
View File
@@ -31,7 +31,7 @@ with lib;
container = {
# Forwarded to extra-container. For descriptions, see
# https://github.com/erikarvstedt/extra-container/blob/master/eval-config.nix
addressPrefix = mkOption { default = "10.225.255"; };
# `addressPrefix` is not settable here, see ./make-test.nix.
enableWAN = mkOption { default = false; };
firewallAllowHost = mkOption { default = true; };
exposeLocalhost = mkOption { default = false; };
+47 -63
View File
@@ -1,31 +1,49 @@
{
"nodes": {
"flake-utils": {
"flake-parts": {
"inputs": {
"systems": "systems"
"nixpkgs-lib": [
"nixos-search",
"nixpkgs"
]
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"lastModified": 1785627969,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-schemas": {
"locked": {
"lastModified": 1780327564,
"narHash": "sha256-HiRPtA0spK+Dkgbhz/1zW9glXxNVB+L4Rj2VYmdawb8=",
"owner": "DeterminateSystems",
"repo": "flake-schemas",
"rev": "6cc9bd98891b1fc6bb2b8cb3277df8bc72799ca6",
"type": "github"
},
"original": {
"owner": "DeterminateSystems",
"repo": "flake-schemas",
"type": "github"
}
},
"nixos-infra": {
"flake": false,
"locked": {
"lastModified": 1778186763,
"narHash": "sha256-WYpwAXUSbAvyygzaPJ5A0MpBgCRDfOn/JlA6bhAExOM=",
"lastModified": 1785876137,
"narHash": "sha256-maIa1tcvLYFyedzvWApdpaMLzDyTWktCXeugLOEZzDs=",
"owner": "NixOS",
"repo": "infra",
"rev": "f7fcb33b303e1026a99206c8a9a4f4d93907d5d1",
"rev": "952d0cfaf5d2ae350f9a2746c61e03d53a15b8db",
"type": "github"
},
"original": {
@@ -36,19 +54,19 @@
},
"nixos-search": {
"inputs": {
"flake-utils": "flake-utils",
"flake-parts": "flake-parts",
"flake-schemas": "flake-schemas",
"nixos-infra": "nixos-infra",
"nixpkgs": "nixpkgs",
"nixpkgs-npmlock2nix": "nixpkgs-npmlock2nix",
"npmlock2nix": "npmlock2nix",
"systems": "systems",
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1778708793,
"narHash": "sha256-LXzXKjaxm23vLEOVefy9HNfedZvdI/FvoJlFd/jjNc0=",
"lastModified": 1786265380,
"narHash": "sha256-JX5Q9o03xYMUpAoHB4nz/0Pf3SeL7GrXoKKJhkUMNps=",
"owner": "nixos",
"repo": "nixos-search",
"rev": "4a3cb26d1ccaa9c62f29071c228dff07c3686e38",
"rev": "7507fd6accc65981f02f66f5c6c328e09efc1221",
"type": "github"
},
"original": {
@@ -59,50 +77,15 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1777954456,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
"lastModified": 1785967620,
"narHash": "sha256-929m7iW8q2uv3mZHNwY8Um6XKj99rbIcZsWS9cT1vaI=",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.11pre1048607.b7c2ada94fe9/nixexprs.tar.xz"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs-npmlock2nix": {
"locked": {
"lastModified": 1636623366,
"narHash": "sha256-jOQMlv9qFSj0U66HB+ujZoapty0UbewmSNbX8+3ujUQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "c5ed8beb478a8ca035f033f659b60c89500a3034",
"type": "github"
}
},
"npmlock2nix": {
"flake": false,
"locked": {
"lastModified": 1758100811,
"narHash": "sha256-qJc3ffjHVXUdZqytKcDK9XZ2b3BQ1RdYfZFuYgxbrn4=",
"owner": "nix-community",
"repo": "npmlock2nix",
"rev": "4d9060afbaa5f57ee0b8ef11c7044ed287a7d302",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "npmlock2nix",
"type": "github"
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"root": {
@@ -111,6 +94,7 @@
}
},
"systems": {
"flake": false,
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
@@ -133,11 +117,11 @@
]
},
"locked": {
"lastModified": 1775636079,
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
"lastModified": 1785945821,
"narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
"rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
"type": "github"
},
"original": {
+7 -1
View File
@@ -332,7 +332,13 @@ all() {
shellcheck
examples
flake
nixosSearch
# FIXME: Re-enable when the nixos-search input is usable again.
# flake-info at the currently locked rev supplies nixpkgs to its inner eval
# via `builtins.getFlake` instead of NIX_PATH. This breaks the postPatch in
# ./nixos-search/flake.nix and both runners in ./nixos-search, which pass
# nix-bitcoin's pinned nixpkgs through NIX_PATH.
# Run explicitly with `./run-tests.sh nixosSearch`.
# nixosSearch
}
# An alias for buildTest
+4
View File
@@ -279,6 +279,10 @@ let
test.data.netns = config.nix-bitcoin.netns-isolation.netns;
tests.netns-isolation = true;
environment.systemPackages = [ pkgs.fping ];
# Used for testing that `netns-exec` is not executable by users other than
# the operator. Like all normal users, this user is a member of group `users`.
users.users.unauthorized.isNormalUser = true;
};
regtestBase = { config, pkgs, ... }: {
+16 -7
View File
@@ -1,5 +1,6 @@
from collections import OrderedDict
import json
import os
import re
def succeed(*cmds):
@@ -331,6 +332,21 @@ def _():
f"nc -l {ip('bitcoind')} 1080 2>&1 || true", "nc: Cannot assign requested address"
)
# netns-exec should fail for unauthorized namespaces
assert_matches(
"runuser -u operator -- netns-exec nb-clightning ip a 2>&1 || true",
"nb-clightning is not an allowed netns",
)
# netns-exec should only be executable by the operator user.
# User `unauthorized` is a member of group `users`, like all normal users.
# Netns `nb-clightning` is rejected by netns-exec before it accesses the
# netns, so the error below can only originate from the exec permissions.
assert_matches(
"runuser -u unauthorized -- netns-exec nb-clightning ip a 2>&1 || true",
"Permission denied",
)
if "joinmarket" in enabled_tests:
# netns-exec should drop capabilities
assert_matches(
@@ -338,13 +354,6 @@ def _():
re.compile("^Current: =$", re.MULTILINE),
)
if "clightning" in enabled_tests:
# netns-exec should fail for unauthorized namespaces
machine.fail("netns-exec nb-clightning ip a")
# netns-exec should only be executable by the operator user
machine.fail("runuser -u clightning -- netns-exec nb-bitcoind ip a")
# Impure: stops bitcoind (and dependent services)
@test("backups")