diff --git a/nixos/modules/services/networking/nebula.nix b/nixos/modules/services/networking/nebula.nix index 7ef930fff68f..6f7d69cb6f99 100644 --- a/nixos/modules/services/networking/nebula.nix +++ b/nixos/modules/services/networking/nebula.nix @@ -292,7 +292,7 @@ in assertions = lib.mapAttrsToList (netName: netCfg: { # IFNAMSIZ caps network device names to 16 chars (including NULL terminator). # Without this check, users might end up with a truncated interface name. - assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15; + assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15; message = '' Network device names can't be longer than 15 chars. `config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit. diff --git a/nixos/tests/nebula/connectivity.nix b/nixos/tests/nebula/connectivity.nix index 3e96f613b11f..b7782815dc1c 100644 --- a/nixos/tests/nebula/connectivity.nix +++ b/nixos/tests/nebula/connectivity.nix @@ -1,6 +1,9 @@ -{ pkgs, lib, ... }: +{ + pkgs, + lib, + ... +}: let - # We'll need to be able to trade cert files between nodes via scp. inherit (import ../ssh-keys.nix pkgs) snakeOilPrivateKey @@ -44,13 +47,11 @@ let } extraConfig ]; - in { name = "nebula"; nodes = { - lighthouse = { ... }@args: makeNebulaNode args "lighthouse" { @@ -97,6 +98,24 @@ in }; }; }; + + # A lighthouse can run without a tun interface, no device name = skip length check pr 565501 + services.nebula.networks.tunless = { + ca = "/etc/nebula/ca.crt"; + cert = "/etc/nebula/lighthouse.crt"; + key = "/etc/nebula/lighthouse.key"; + isLighthouse = true; + listen = { + host = "0.0.0.0"; + port = 4243; + }; + tun = { + disable = true; + device = "nebula.tunless-too-long"; + }; + user = "nebula-smoke"; + group = "nebula-smoke"; + }; }; allowAny = @@ -265,12 +284,10 @@ in }; }; }; - }; testScript = let - setUpPrivateKey = name: '' ${name}.start() ${name}.succeed( @@ -379,6 +396,11 @@ in lighthouse.wait_until_succeeds("ping -c1 -W1 10.0.100.1", timeout=10) lighthouse.wait_until_succeeds("ping -c1 -W1 2001:db8::1", timeout=10) + # The tunless network starts without a tun device despite its (deliberately over-long) configured device name. pr 565501 + lighthouse.wait_for_unit("nebula@tunless.service") + lighthouse.wait_until_succeeds("ss -lun | grep -q ':4243'", timeout=10) + lighthouse.fail("ip link show nebula.tunless-too-long") + # Start all the machines to be set up allowAny.start() allowFromLighthouse.start()