From 7772bcff26108437c0fcac6894490655ef718c40 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Thu, 20 Aug 2026 22:37:26 +0200 Subject: [PATCH] nixos/music-assistant: allow binding for AirPlay2 see https://beta.music-assistant.io/player-support/airplay/#airplay-2-group-synchronization --- nixos/modules/services/audio/music-assistant.nix | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/audio/music-assistant.nix b/nixos/modules/services/audio/music-assistant.nix index f3e8c97a7955..947e19c302b8 100644 --- a/nixos/modules/services/audio/music-assistant.nix +++ b/nixos/modules/services/audio/music-assistant.nix @@ -166,8 +166,18 @@ in ); DynamicUser = true; StateDirectory = "music-assistant"; - AmbientCapabilities = ""; - CapabilityBoundingSet = [ "" ]; + # AirPlay 2 requires CAP_NET_BIND_SERVICE to bind to UDP ports 319 and 320 for synchronized group playback. + # Opening the ports in the firewall is not necessary. + # See this older version of the docs: + # https://github.com/music-assistant/music-assistant.io/blob/33175c11961beac4c6a27beff6d4cce269f29efe/src/content/docs/player-support/airplay.md#airplay-2-group-synchronization + AmbientCapabilities = [ + "" + ] + ++ lib.optionals (lib.elem "airplay" cfg.providers) [ "CAP_NET_BIND_SERVICE" ]; + CapabilityBoundingSet = [ + "" + ] + ++ lib.optionals (lib.elem "airplay" cfg.providers) [ "CAP_NET_BIND_SERVICE" ]; DevicePolicy = "closed"; LockPersonality = true; # breaks pyopenssl's cffi calls, used in remote access feature