nixos/nebula: fix inverted tun.device length assertion (#565501)

This commit is contained in:
@mjones
2026-09-27 22:28:12 +00:00
committed by GitHub
2 changed files with 29 additions and 7 deletions

View File

@@ -292,7 +292,7 @@ in
assertions = lib.mapAttrsToList (netName: netCfg: {
# IFNAMSIZ caps network device names to 16 chars (including NULL terminator).
# Without this check, users might end up with a truncated interface name.
assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15;
assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15;
message = ''
Network device names can't be longer than 15 chars.
`config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit.

View File

@@ -1,6 +1,9 @@
{ pkgs, lib, ... }:
{
pkgs,
lib,
...
}:
let
# We'll need to be able to trade cert files between nodes via scp.
inherit (import ../ssh-keys.nix pkgs)
snakeOilPrivateKey
@@ -44,13 +47,11 @@ let
}
extraConfig
];
in
{
name = "nebula";
nodes = {
lighthouse =
{ ... }@args:
makeNebulaNode args "lighthouse" {
@@ -97,6 +98,24 @@ in
};
};
};
# A lighthouse can run without a tun interface, no device name = skip length check pr 565501
services.nebula.networks.tunless = {
ca = "/etc/nebula/ca.crt";
cert = "/etc/nebula/lighthouse.crt";
key = "/etc/nebula/lighthouse.key";
isLighthouse = true;
listen = {
host = "0.0.0.0";
port = 4243;
};
tun = {
disable = true;
device = "nebula.tunless-too-long";
};
user = "nebula-smoke";
group = "nebula-smoke";
};
};
allowAny =
@@ -265,12 +284,10 @@ in
};
};
};
};
testScript =
let
setUpPrivateKey = name: ''
${name}.start()
${name}.succeed(
@@ -379,6 +396,11 @@ in
lighthouse.wait_until_succeeds("ping -c1 -W1 10.0.100.1", timeout=10)
lighthouse.wait_until_succeeds("ping -c1 -W1 2001:db8::1", timeout=10)
# The tunless network starts without a tun device despite its (deliberately over-long) configured device name. pr 565501
lighthouse.wait_for_unit("nebula@tunless.service")
lighthouse.wait_until_succeeds("ss -lun | grep -q ':4243'", timeout=10)
lighthouse.fail("ip link show nebula.tunless-too-long")
# Start all the machines to be set up
allowAny.start()
allowFromLighthouse.start()