diff options
| author | Ryan Lahfa <masterancpp@gmail.com> | 2023-03-22 20:27:18 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2023-03-22 20:27:18 +0100 |
| commit | b712670a1fa2be70d23ce65d83b1ccbbdabe5ad2 (patch) | |
| tree | ab146d86cc41961e0ffa1ceae6f2597c8b14949e | |
| parent | Merge pull request #217366 from puppe/fix-yggdrasil (diff) | |
| download | nixpkgs-origin/revert-217366-fix-yggdrasil.tar.gz | |
Revert "nixos/yggdrasil: fix configFile option"origin/revert-217366-fix-yggdrasil
| -rw-r--r-- | nixos/modules/services/networking/yggdrasil.nix | 186 |
1 files changed, 79 insertions, 107 deletions
diff --git a/nixos/modules/services/networking/yggdrasil.nix b/nixos/modules/services/networking/yggdrasil.nix index 55a6002d61af..fd7193154c6c 100644 --- a/nixos/modules/services/networking/yggdrasil.nix +++ b/nixos/modules/services/networking/yggdrasil.nix @@ -8,8 +8,7 @@ let configFileProvided = cfg.configFile != null; format = pkgs.formats.json { }; -in -{ +in { imports = [ (mkRenamedOptionModule [ "services" "yggdrasil" "config" ] @@ -22,7 +21,7 @@ in settings = mkOption { type = format.type; - default = { }; + default = {}; example = { Peers = [ "tcp://aa.bb.cc.dd:eeeee" @@ -46,7 +45,7 @@ in If no keys are specified then ephemeral keys are generated and the Yggdrasil interface will have a random IPv6 address - each time the service is started. This is the default. + each time the service is started, this is the default. If both {option}`configFile` and {option}`settings` are supplied, they will be combined, with values from @@ -62,13 +61,8 @@ in default = null; example = "/run/keys/yggdrasil.conf"; description = lib.mdDoc '' - A file which contains JSON or HJSON configuration for yggdrasil. See - the {option}`settings` option for more information. - - Note: This file must not be larger than 1 MB because it is passed to - the yggdrasil process via systemd‘s LoadCredential mechanism. For - details, see <https://systemd.io/CREDENTIALS/> and `man 5 - systemd.exec`. + A file which contains JSON configuration for yggdrasil. + See the {option}`settings` option for more information. ''; }; @@ -83,20 +77,20 @@ in type = bool; default = false; description = lib.mdDoc '' - Whether to open the UDP port used for multicast peer discovery. The - NixOS firewall blocks link-local communication, so in order to make - incoming local peering work you will also need to configure - `MulticastInterfaces` in your Yggdrasil configuration - ({option}`settings` or {option}`configFile`). You will then have to - add the ports that you configure there to your firewall configuration - ({option}`networking.firewall.allowedTCPPorts` or - {option}`networking.firewall.interfaces.<name>.allowedTCPPorts`). + Whether to open the UDP port used for multicast peer + discovery. The NixOS firewall blocks link-local + communication, so in order to make local peering work you + will also need to set `LinkLocalTCPPort` in your + yggdrasil configuration ({option}`settings` or + {option}`configFile`) to a port number other than 0, + and then add that port to + {option}`networking.firewall.allowedTCPPorts`. ''; }; denyDhcpcdInterfaces = mkOption { type = listOf str; - default = [ ]; + default = []; example = [ "tap*" ]; description = lib.mdDoc '' Disable the DHCP client for any interface whose name matches @@ -124,102 +118,80 @@ in }; }; - config = mkIf cfg.enable ( - let - binYggdrasil = "${cfg.package}/bin/yggdrasil"; - binHjson = "${pkgs.hjson-go}/bin/hjson-cli"; - in - { - assertions = [{ - assertion = config.networking.enableIPv6; - message = "networking.enableIPv6 must be true for yggdrasil to work"; - }]; - - system.activationScripts.yggdrasil = mkIf cfg.persistentKeys '' - if [ ! -e ${keysPath} ] - then - mkdir --mode=700 -p ${builtins.dirOf keysPath} - ${binYggdrasil} -genconf -json \ - | ${pkgs.jq}/bin/jq \ - 'to_entries|map(select(.key|endswith("Key")))|from_entries' \ - > ${keysPath} - fi - ''; - - systemd.services.yggdrasil = { - description = "Yggdrasil Network Service"; - after = [ "network-pre.target" ]; - wants = [ "network.target" ]; - before = [ "network.target" ]; - wantedBy = [ "multi-user.target" ]; + config = mkIf cfg.enable (let binYggdrasil = cfg.package + "/bin/yggdrasil"; + in { + assertions = [{ + assertion = config.networking.enableIPv6; + message = "networking.enableIPv6 must be true for yggdrasil to work"; + }]; - # This script first prepares the config file, then it starts Yggdrasil. - # The preparation could also be done in ExecStartPre/preStart but only - # systemd versions >= v252 support reading credentials in ExecStartPre. As - # of February 2023, systemd v252 is not yet in the stable branch of NixOS. - # - # This could be changed in the future once systemd version v252 has - # reached NixOS but it does not have to be. Config file preparation is - # fast enough, it does not need elevated privileges, and `set -euo - # pipefail` should make sure that the service is not started if the - # preparation fails. Therefore, it is not necessary to move the - # preparation to ExecStartPre. - script = '' - set -euo pipefail + system.activationScripts.yggdrasil = mkIf cfg.persistentKeys '' + if [ ! -e ${keysPath} ] + then + mkdir --mode=700 -p ${builtins.dirOf keysPath} + ${binYggdrasil} -genconf -json \ + | ${pkgs.jq}/bin/jq \ + 'to_entries|map(select(.key|endswith("Key")))|from_entries' \ + > ${keysPath} + fi + ''; - # prepare config file - ${(if settingsProvided || configFileProvided || cfg.persistentKeys then - "echo " + systemd.services.yggdrasil = { + description = "Yggdrasil Network Service"; + after = [ "network-pre.target" ]; + wants = [ "network.target" ]; + before = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; - + (lib.optionalString settingsProvided - "'${builtins.toJSON cfg.settings}'") - + (lib.optionalString configFileProvided - "$(${binHjson} -c \"$CREDENTIALS_DIRECTORY/yggdrasil.conf\")") - + (lib.optionalString cfg.persistentKeys "$(cat ${keysPath})") - + " | ${pkgs.jq}/bin/jq -s add | ${binYggdrasil} -normaliseconf -useconf" - else - "${binYggdrasil} -genconf") + " > /run/yggdrasil/yggdrasil.conf"} + preStart = + (if settingsProvided || configFileProvided || cfg.persistentKeys then + "echo " - # start yggdrasil - ${binYggdrasil} -useconffile /run/yggdrasil/yggdrasil.conf - ''; + + (lib.optionalString settingsProvided + "'${builtins.toJSON cfg.settings}'") + + (lib.optionalString configFileProvided "$(cat ${cfg.configFile})") + + (lib.optionalString cfg.persistentKeys "$(cat ${keysPath})") + + " | ${pkgs.jq}/bin/jq -s add | ${binYggdrasil} -normaliseconf -useconf" + else + "${binYggdrasil} -genconf") + " > /run/yggdrasil/yggdrasil.conf"; - serviceConfig = { - ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; - Restart = "always"; + serviceConfig = { + ExecStart = + "${binYggdrasil} -useconffile /run/yggdrasil/yggdrasil.conf"; + ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; + Restart = "always"; - DynamicUser = true; - StateDirectory = "yggdrasil"; - RuntimeDirectory = "yggdrasil"; - RuntimeDirectoryMode = "0750"; - BindReadOnlyPaths = lib.optional cfg.persistentKeys keysPath; - LoadCredential = - mkIf configFileProvided "yggdrasil.conf:${cfg.configFile}"; + DynamicUser = true; + StateDirectory = "yggdrasil"; + RuntimeDirectory = "yggdrasil"; + RuntimeDirectoryMode = "0750"; + BindReadOnlyPaths = lib.optional configFileProvided cfg.configFile + ++ lib.optional cfg.persistentKeys keysPath; + ReadWritePaths = "/run/yggdrasil"; - AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE"; - CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE"; - MemoryDenyWriteExecute = true; - ProtectControlGroups = true; - ProtectHome = "tmpfs"; - ProtectKernelModules = true; - ProtectKernelTunables = true; - RestrictAddressFamilies = "AF_UNIX AF_INET AF_INET6 AF_NETLINK"; - RestrictNamespaces = true; - RestrictRealtime = true; - SystemCallArchitectures = "native"; - SystemCallFilter = [ "@system-service" "~@privileged @keyring" ]; - } // (if (cfg.group != null) then { - Group = cfg.group; - } else { }); - }; + AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE"; + CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE"; + MemoryDenyWriteExecute = true; + ProtectControlGroups = true; + ProtectHome = "tmpfs"; + ProtectKernelModules = true; + ProtectKernelTunables = true; + RestrictAddressFamilies = "AF_UNIX AF_INET AF_INET6 AF_NETLINK"; + RestrictNamespaces = true; + RestrictRealtime = true; + SystemCallArchitectures = "native"; + SystemCallFilter = [ "@system-service" "~@privileged @keyring" ]; + } // (if (cfg.group != null) then { + Group = cfg.group; + } else {}); + }; - networking.dhcpcd.denyInterfaces = cfg.denyDhcpcdInterfaces; - networking.firewall.allowedUDPPorts = mkIf cfg.openMulticastPort [ 9001 ]; + networking.dhcpcd.denyInterfaces = cfg.denyDhcpcdInterfaces; + networking.firewall.allowedUDPPorts = mkIf cfg.openMulticastPort [ 9001 ]; - # Make yggdrasilctl available on the command line. - environment.systemPackages = [ cfg.package ]; - } - ); + # Make yggdrasilctl available on the command line. + environment.systemPackages = [ cfg.package ]; + }); meta = { doc = ./yggdrasil.md; maintainers = with lib.maintainers; [ gazally ehmry ]; |
