From a2fbe4fa45b0049cd475d4918c9fcf29ca8b1371 Mon Sep 17 00:00:00 2001 From: Amadeus Mader Date: Mon, 21 Sep 2026 12:54:00 +0200 Subject: [PATCH 1/2] nixos/nebula: fix inverted tun.device length assertion Resolves #565467. Assisted-by: OpenCode (kimi-k3) --- nixos/modules/services/networking/nebula.nix | 2 +- nixos/tests/all-tests.nix | 1 + nixos/tests/nebula/tunless.nix | 43 ++++++++++++++++++++ pkgs/by-name/ne/nebula/package.nix | 1 + 4 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 nixos/tests/nebula/tunless.nix diff --git a/nixos/modules/services/networking/nebula.nix b/nixos/modules/services/networking/nebula.nix index 7ef930fff68f..6f7d69cb6f99 100644 --- a/nixos/modules/services/networking/nebula.nix +++ b/nixos/modules/services/networking/nebula.nix @@ -292,7 +292,7 @@ in assertions = lib.mapAttrsToList (netName: netCfg: { # IFNAMSIZ caps network device names to 16 chars (including NULL terminator). # Without this check, users might end up with a truncated interface name. - assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15; + assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15; message = '' Network device names can't be longer than 15 chars. `config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit. diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 58950fafd903..8109ee869fa8 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -1241,6 +1241,7 @@ in nebula-lighthouse-service = runTest ./nebula-lighthouse-service.nix; nebula.connectivity = runTest ./nebula/connectivity.nix; nebula.reload = runTest ./nebula/reload.nix; + nebula.tunless = runTest ./nebula/tunless.nix; neo4j = runTest ./neo4j.nix; netbird = runTest ./netbird.nix; netbird-relay = runTest ./netbird-relay.nix; diff --git a/nixos/tests/nebula/tunless.nix b/nixos/tests/nebula/tunless.nix new file mode 100644 index 000000000000..dac1607e27e8 --- /dev/null +++ b/nixos/tests/nebula/tunless.nix @@ -0,0 +1,43 @@ +{ ... }: +{ + name = "nebula"; + + nodes = { + lighthouse = + { pkgs, ... }: + { + environment.systemPackages = [ pkgs.nebula ]; + + services.nebula.networks.smoke = { + # Note that these paths won't exist when the machine is first booted. + ca = "/etc/nebula/ca.crt"; + cert = "/etc/nebula/lighthouse.crt"; + key = "/etc/nebula/lighthouse.key"; + isLighthouse = true; + listen = { + host = "0.0.0.0"; + port = 4242; + }; + # A lighthouse can run without a tun interface. The device name is + # unused then, so the length assertion must not apply to it. + tun.disable = true; + }; + }; + }; + + testScript = '' + # Create the certificate and sign the lighthouse's keys. + lighthouse.succeed( + "mkdir -p /etc/nebula", + 'nebula-cert ca -duration $((10*365*24*60))m -name "Smoke Test" -out-crt /etc/nebula/ca.crt -out-key /etc/nebula/ca.key', + 'nebula-cert sign -duration $((365*24*60))m -ca-crt /etc/nebula/ca.crt -ca-key /etc/nebula/ca.key -name "lighthouse" -groups "lighthouse" -networks "10.0.100.1/24" -out-crt /etc/nebula/lighthouse.crt -out-key /etc/nebula/lighthouse.key', + 'chown -R nebula-smoke:nebula-smoke /etc/nebula' + ) + + # Restart nebula to pick up the keys and verify it listens without creating a tun device. + lighthouse.systemctl("restart nebula@smoke.service") + lighthouse.wait_for_unit("nebula@smoke.service") + lighthouse.wait_until_succeeds("ss -lun | grep -q ':4242'", timeout=10) + lighthouse.fail("ip link show nebula.smoke") + ''; +} diff --git a/pkgs/by-name/ne/nebula/package.nix b/pkgs/by-name/ne/nebula/package.nix index 024c280c7a72..1da168e521e4 100644 --- a/pkgs/by-name/ne/nebula/package.nix +++ b/pkgs/by-name/ne/nebula/package.nix @@ -54,6 +54,7 @@ buildGoModule (finalAttrs: { inherit (nixosTests.nebula) connectivity reload + tunless ; }; From e7cbd8815e15c626d808f8e224ef840f75bf64f2 Mon Sep 17 00:00:00 2001 From: Amadeus Mader Date: Tue, 22 Sep 2026 15:41:19 +0200 Subject: [PATCH 2/2] nixos/nebula: move tunless test to existing test --- nixos/tests/all-tests.nix | 1 - nixos/tests/nebula/connectivity.nix | 34 +++++++++++++++++++---- nixos/tests/nebula/tunless.nix | 43 ----------------------------- pkgs/by-name/ne/nebula/package.nix | 1 - 4 files changed, 28 insertions(+), 51 deletions(-) delete mode 100644 nixos/tests/nebula/tunless.nix diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 8109ee869fa8..58950fafd903 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -1241,7 +1241,6 @@ in nebula-lighthouse-service = runTest ./nebula-lighthouse-service.nix; nebula.connectivity = runTest ./nebula/connectivity.nix; nebula.reload = runTest ./nebula/reload.nix; - nebula.tunless = runTest ./nebula/tunless.nix; neo4j = runTest ./neo4j.nix; netbird = runTest ./netbird.nix; netbird-relay = runTest ./netbird-relay.nix; diff --git a/nixos/tests/nebula/connectivity.nix b/nixos/tests/nebula/connectivity.nix index 3e96f613b11f..b7782815dc1c 100644 --- a/nixos/tests/nebula/connectivity.nix +++ b/nixos/tests/nebula/connectivity.nix @@ -1,6 +1,9 @@ -{ pkgs, lib, ... }: +{ + pkgs, + lib, + ... +}: let - # We'll need to be able to trade cert files between nodes via scp. inherit (import ../ssh-keys.nix pkgs) snakeOilPrivateKey @@ -44,13 +47,11 @@ let } extraConfig ]; - in { name = "nebula"; nodes = { - lighthouse = { ... }@args: makeNebulaNode args "lighthouse" { @@ -97,6 +98,24 @@ in }; }; }; + + # A lighthouse can run without a tun interface, no device name = skip length check pr 565501 + services.nebula.networks.tunless = { + ca = "/etc/nebula/ca.crt"; + cert = "/etc/nebula/lighthouse.crt"; + key = "/etc/nebula/lighthouse.key"; + isLighthouse = true; + listen = { + host = "0.0.0.0"; + port = 4243; + }; + tun = { + disable = true; + device = "nebula.tunless-too-long"; + }; + user = "nebula-smoke"; + group = "nebula-smoke"; + }; }; allowAny = @@ -265,12 +284,10 @@ in }; }; }; - }; testScript = let - setUpPrivateKey = name: '' ${name}.start() ${name}.succeed( @@ -379,6 +396,11 @@ in lighthouse.wait_until_succeeds("ping -c1 -W1 10.0.100.1", timeout=10) lighthouse.wait_until_succeeds("ping -c1 -W1 2001:db8::1", timeout=10) + # The tunless network starts without a tun device despite its (deliberately over-long) configured device name. pr 565501 + lighthouse.wait_for_unit("nebula@tunless.service") + lighthouse.wait_until_succeeds("ss -lun | grep -q ':4243'", timeout=10) + lighthouse.fail("ip link show nebula.tunless-too-long") + # Start all the machines to be set up allowAny.start() allowFromLighthouse.start() diff --git a/nixos/tests/nebula/tunless.nix b/nixos/tests/nebula/tunless.nix deleted file mode 100644 index dac1607e27e8..000000000000 --- a/nixos/tests/nebula/tunless.nix +++ /dev/null @@ -1,43 +0,0 @@ -{ ... }: -{ - name = "nebula"; - - nodes = { - lighthouse = - { pkgs, ... }: - { - environment.systemPackages = [ pkgs.nebula ]; - - services.nebula.networks.smoke = { - # Note that these paths won't exist when the machine is first booted. - ca = "/etc/nebula/ca.crt"; - cert = "/etc/nebula/lighthouse.crt"; - key = "/etc/nebula/lighthouse.key"; - isLighthouse = true; - listen = { - host = "0.0.0.0"; - port = 4242; - }; - # A lighthouse can run without a tun interface. The device name is - # unused then, so the length assertion must not apply to it. - tun.disable = true; - }; - }; - }; - - testScript = '' - # Create the certificate and sign the lighthouse's keys. - lighthouse.succeed( - "mkdir -p /etc/nebula", - 'nebula-cert ca -duration $((10*365*24*60))m -name "Smoke Test" -out-crt /etc/nebula/ca.crt -out-key /etc/nebula/ca.key', - 'nebula-cert sign -duration $((365*24*60))m -ca-crt /etc/nebula/ca.crt -ca-key /etc/nebula/ca.key -name "lighthouse" -groups "lighthouse" -networks "10.0.100.1/24" -out-crt /etc/nebula/lighthouse.crt -out-key /etc/nebula/lighthouse.key', - 'chown -R nebula-smoke:nebula-smoke /etc/nebula' - ) - - # Restart nebula to pick up the keys and verify it listens without creating a tun device. - lighthouse.systemctl("restart nebula@smoke.service") - lighthouse.wait_for_unit("nebula@smoke.service") - lighthouse.wait_until_succeeds("ss -lun | grep -q ':4242'", timeout=10) - lighthouse.fail("ip link show nebula.smoke") - ''; -} diff --git a/pkgs/by-name/ne/nebula/package.nix b/pkgs/by-name/ne/nebula/package.nix index 1da168e521e4..024c280c7a72 100644 --- a/pkgs/by-name/ne/nebula/package.nix +++ b/pkgs/by-name/ne/nebula/package.nix @@ -54,7 +54,6 @@ buildGoModule (finalAttrs: { inherit (nixosTests.nebula) connectivity reload - tunless ; };