From 0deadd5baf64cf4dce993a3ab248a2c714a7b4af Mon Sep 17 00:00:00 2001 From: Colin Date: Sun, 2 Jun 2024 05:45:37 +0000 Subject: [PATCH 1/4] nixos/networkmanager: split ModemManager bits into own module this should not result in any observable change by default, the motivation is to make working on either one of these components in isolation of the other a bit easier. --- .../manual/release-notes/rl-2505.section.md | 2 + nixos/modules/module-list.nix | 1 + .../services/networking/modemmanager.nix | 90 +++++++++++++++++++ .../services/networking/networkmanager.nix | 51 ++--------- 4 files changed, 102 insertions(+), 42 deletions(-) create mode 100644 nixos/modules/services/networking/modemmanager.nix diff --git a/nixos/doc/manual/release-notes/rl-2505.section.md b/nixos/doc/manual/release-notes/rl-2505.section.md index 948f097395fe..8c3bf253c6ce 100644 --- a/nixos/doc/manual/release-notes/rl-2505.section.md +++ b/nixos/doc/manual/release-notes/rl-2505.section.md @@ -28,6 +28,8 @@ - [MaryTTS](https://github.com/marytts/marytts), an open-source, multilingual text-to-speech synthesis system written in pure Java. Available as [services.marytts](options.html#opt-services.marytts). +- [networking.modemmanager](options.html#opt-networking.modemmanager) has been split out of [networking.networkmanager](options.html#opt-networking.networkmanager). NetworkManager still enables ModemManager by default, but options exist now to run NetworkManager without ModemManager. + - [Conduwuit](https://conduwuit.puppyirl.gay/), a federated chat server implementing the Matrix protocol, forked from Conduit. Available as [services.conduwuit](#opt-services.conduwuit.enable). - [Traccar](https://www.traccar.org/), a modern GPS Tracking Platform. Available as [services.traccar](#opt-services.traccar.enable). diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 783f20546af4..e014a97fb1a2 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -1135,6 +1135,7 @@ ./services/networking/miredo.nix ./services/networking/mjpg-streamer.nix ./services/networking/mmsd.nix + ./services/networking/modemmanager.nix ./services/networking/monero.nix ./services/networking/morty.nix ./services/networking/mosquitto.nix diff --git a/nixos/modules/services/networking/modemmanager.nix b/nixos/modules/services/networking/modemmanager.nix new file mode 100644 index 000000000000..7cb399bf76a8 --- /dev/null +++ b/nixos/modules/services/networking/modemmanager.nix @@ -0,0 +1,90 @@ +{ config, lib, ... }: +let + cfg = config.networking.modemmanager; +in +{ + meta = { + maintainers = lib.teams.freedesktop.members; + }; + + options = with lib; { + networking.modemmanager = { + enable = mkOption { + type = types.bool; + default = false; + description = '' + Whether to use ModemManager to manage modem devices. + This is usually used by some higher layer manager such as NetworkManager + but can be used standalone especially if using a modem for non-IP + connectivity (e.g. GPS). + ''; + }; + + fccUnlockScripts = mkOption { + type = types.listOf ( + types.submodule { + options = { + id = mkOption { + type = types.str; + description = "vid:pid of either the PCI or USB vendor and product ID"; + }; + path = mkOption { + type = types.path; + description = "Path to the unlock script"; + }; + }; + } + ); + default = [ ]; + example = literalExpression ''[{ id = "03f0:4e1d"; path = "''${pkgs.modemmanager}/share/ModemManager/fcc-unlock.available.d/03f0:4e1d"; }]''; + description = '' + List of FCC unlock scripts to enable on the system, behaving as described in + https://modemmanager.org/docs/modemmanager/fcc-unlock/#integration-with-third-party-fcc-unlock-tools. + ''; + }; + }; + }; + + config = lib.mkIf cfg.enable { + environment.etc = builtins.listToAttrs ( + map ( + e: + lib.nameValuePair "ModemManager/fcc-unlock.d/${e.id}" { + source = e.path; + } + ) cfg.fccUnlockScripts + ); + + systemd.services.ModemManager = { + aliases = [ "dbus-org.freedesktop.ModemManager1.service" ]; + path = lib.optionals (cfg.fccUnlockScripts != [ ]) [ + pkgs.libqmi + pkgs.libmbim + ]; + }; + + /* + [modem-manager] + Identity=unix-group:networkmanager + Action=org.freedesktop.ModemManager* + ResultAny=yes + ResultInactive=no + ResultActive=yes + */ + security.polkit.enable = true; + security.polkit.extraConfig = '' + polkit.addRule(function(action, subject) { + if ( + subject.isInGroup("networkmanager") + && action.id.indexOf("org.freedesktop.ModemManager") == 0 + ) + { return polkit.Result.YES; } + }); + ''; + + environment.systemPackages = [ pkgs.modemmanager ]; + systemd.packages = [ pkgs.modemmanager ]; + services.dbus.packages = [ pkgs.modemmanager ]; + services.udev.packages = [ pkgs.modemmanager ]; + }; +} diff --git a/nixos/modules/services/networking/networkmanager.nix b/nixos/modules/services/networking/networkmanager.nix index dedd53e345fe..deeab7e72efd 100644 --- a/nixos/modules/services/networking/networkmanager.nix +++ b/nixos/modules/services/networking/networkmanager.nix @@ -43,21 +43,13 @@ let ResultAny=yes ResultInactive=no ResultActive=yes - - [modem-manager] - Identity=unix-group:networkmanager - Action=org.freedesktop.ModemManager* - ResultAny=yes - ResultInactive=no - ResultActive=yes */ polkitConf = '' polkit.addRule(function(action, subject) { if ( subject.isInGroup("networkmanager") - && (action.id.indexOf("org.freedesktop.NetworkManager.") == 0 - || action.id.indexOf("org.freedesktop.ModemManager") == 0 - )) + && action.id.indexOf("org.freedesktop.NetworkManager.") == 0 + ) { return polkit.Result.YES; } }); ''; @@ -115,7 +107,6 @@ let }; packages = [ - pkgs.modemmanager pkgs.networkmanager ] ++ cfg.plugins @@ -358,26 +349,6 @@ in ''; }; - fccUnlockScripts = mkOption { - type = types.listOf (types.submodule { - options = { - id = mkOption { - type = types.str; - description = "vid:pid of either the PCI or USB vendor and product ID"; - }; - path = mkOption { - type = types.path; - description = "Path to the unlock script"; - }; - }; - }); - default = [ ]; - example = literalExpression ''[{ id = "03f0:4e1d"; path = "''${pkgs.modemmanager}/share/ModemManager/fcc-unlock.available.d/03f0:4e1d"; }]''; - description = '' - List of FCC unlock scripts to enable on the system, behaving as described in - https://modemmanager.org/docs/modemmanager/fcc-unlock/#integration-with-third-party-fcc-unlock-tools. - ''; - }; ensureProfiles = { profiles = with lib.types; mkOption { type = attrsOf (submodule { @@ -480,7 +451,7 @@ in might conflict with vendor-provided unlock scripts, and should be a conscious decision on a per-device basis. Instead it's recommended to use the - `networking.networkmanager.fccUnlockScripts` option. + `networking.modemmanager.fccUnlockScripts` option. '') (mkRemovedOptionModule [ "networking" "networkmanager" "dynamicHosts" ] '' This option was removed because allowing (multiple) regular users to @@ -493,6 +464,10 @@ in (mkRemovedOptionModule [ "networking" "networkmanager" "firewallBackend" ] '' This option was removed as NixOS is now using iptables-nftables-compat even when using iptables, therefore Networkmanager now uses the nftables backend unconditionally. '') + (mkRenamedOptionModule + [ "networking" "networkmanager" "fccUnlockScripts" ] + [ "networking" "modemmanager" "fccUnlockScripts" ] + ) ]; @@ -526,11 +501,6 @@ in source = "${pkg}/lib/NetworkManager/${pkg.networkManagerPlugin}"; }) cfg.plugins) - // builtins.listToAttrs (map - (e: nameValuePair "ModemManager/fcc-unlock.d/${e.id}" { - source = e.path; - }) - cfg.fccUnlockScripts) // optionalAttrs (cfg.appendNameservers != [ ] || cfg.insertNameservers != [ ]) { "NetworkManager/dispatcher.d/02overridedns".source = overrideNameserversScript; @@ -590,11 +560,6 @@ in wantedBy = [ "network-online.target" ]; }; - systemd.services.ModemManager = { - aliases = [ "dbus-org.freedesktop.ModemManager1.service" ]; - path = lib.optionals (cfg.fccUnlockScripts != []) [ pkgs.libqmi pkgs.libmbim ]; - }; - systemd.services.NetworkManager-dispatcher = { wantedBy = [ "network.target" ]; restartTriggers = [ configFile overrideNameserversScript ]; @@ -654,6 +619,8 @@ in }) { + modemmanager.enable = lib.mkDefault true; + networkmanager.connectionConfig = { "ethernet.cloned-mac-address" = cfg.ethernet.macAddress; "wifi.cloned-mac-address" = cfg.wifi.macAddress; From 5a04fc7e7d9f8d22f9f3b4a3cb16cf836454468a Mon Sep 17 00:00:00 2001 From: Colin Date: Thu, 19 Dec 2024 22:37:13 +0000 Subject: [PATCH 2/4] nixos/networkmanager: format with nixfmt --- .../services/networking/networkmanager.nix | 358 +++++++++++------- 1 file changed, 211 insertions(+), 147 deletions(-) diff --git a/nixos/modules/services/networking/networkmanager.nix b/nixos/modules/services/networking/networkmanager.nix index deeab7e72efd..c46ba8fce7b1 100644 --- a/nixos/modules/services/networking/networkmanager.nix +++ b/nixos/modules/services/networking/networkmanager.nix @@ -1,4 +1,9 @@ -{ config, lib, pkgs, ... }: +{ + config, + lib, + pkgs, + ... +}: with lib; @@ -15,14 +20,10 @@ let plugins = "keyfile"; inherit (cfg) dhcp dns; # If resolvconf is disabled that means that resolv.conf is managed by some other module. - rc-manager = - if config.networking.resolvconf.enable then "resolvconf" - else "unmanaged"; + rc-manager = if config.networking.resolvconf.enable then "resolvconf" else "unmanaged"; }; keyfile = { - unmanaged-devices = - if cfg.unmanaged == [ ] then null - else lib.concatStringsSep ";" cfg.unmanaged; + unmanaged-devices = if cfg.unmanaged == [ ] then null else lib.concatStringsSep ";" cfg.unmanaged; }; logging = { audit = config.security.audit.enable; @@ -30,8 +31,8 @@ let }; connection = cfg.connectionConfig; device = { - "wifi.scan-rand-mac-address" = cfg.wifi.scanRandMacAddress; - "wifi.backend" = cfg.wifi.backend; + "wifi.scan-rand-mac-address" = cfg.wifi.scanRandMacAddress; + "wifi.backend" = cfg.wifi.backend; }; } cfg.settings; configFile = ini.generate "NetworkManager.conf" configAttrs; @@ -54,13 +55,18 @@ let }); ''; - ns = xs: pkgs.writeText "nameservers" ( - concatStrings (map (s: "nameserver ${s}\n") xs) - ); + ns = xs: pkgs.writeText "nameservers" (concatStrings (map (s: "nameserver ${s}\n") xs)); overrideNameserversScript = pkgs.writeScript "02overridedns" '' #!/bin/sh - PATH=${with pkgs; makeBinPath [ gnused gnugrep coreutils ]} + PATH=${ + with pkgs; + makeBinPath [ + gnused + gnugrep + coreutils + ] + } tmp=$(mktemp) sed '/nameserver /d' /etc/resolv.conf > $tmp grep 'nameserver ' /etc/resolv.conf | \ @@ -76,7 +82,15 @@ let }; macAddressOptWifi = mkOption { - type = types.either types.str (types.enum [ "permanent" "preserve" "random" "stable" "stable-ssid" ]); + type = types.either types.str ( + types.enum [ + "permanent" + "preserve" + "random" + "stable" + "stable-ssid" + ] + ); default = "preserve"; example = "00:11:22:33:44:55"; description = '' @@ -92,7 +106,14 @@ let }; macAddressOptEth = mkOption { - type = types.either types.str (types.enum [ "permanent" "preserve" "random" "stable" ]); + type = types.either types.str ( + types.enum [ + "permanent" + "preserve" + "random" + "stable" + ] + ); default = "preserve"; example = "00:11:22:33:44:55"; description = '' @@ -106,13 +127,14 @@ let ''; }; - packages = [ - pkgs.networkmanager - ] - ++ cfg.plugins - ++ lib.optionals (!delegateWireless && !enableIwd) [ - pkgs.wpa_supplicant - ]; + packages = + [ + pkgs.networkmanager + ] + ++ cfg.plugins + ++ lib.optionals (!delegateWireless && !enableIwd) [ + pkgs.wpa_supplicant + ]; in { @@ -140,11 +162,15 @@ in }; connectionConfig = mkOption { - type = with types; attrsOf (nullOr (oneOf [ - bool - int - str - ])); + type = + with types; + attrsOf ( + nullOr (oneOf [ + bool + int + str + ]) + ); default = { }; description = '' Configuration for the [connection] section of NetworkManager.conf. @@ -160,7 +186,7 @@ in settings = mkOption { type = ini.type; - default = {}; + default = { }; description = '' Configuration added to the generated NetworkManager.conf, note that you can overwrite settings with this. Refer to @@ -196,9 +222,7 @@ in check = p: lib.assertMsg - (types.package.check p - && p ? networkManagerPlugin - && lib.isString p.networkManagerPlugin) + (types.package.check p && p ? networkManagerPlugin && lib.isString p.networkManagerPlugin) '' Package ‘${p.name}’, is not a NetworkManager plug-in. Those need to have a ‘networkManagerPlugin’ attribute. @@ -214,7 +238,10 @@ in }; dhcp = mkOption { - type = types.enum [ "dhcpcd" "internal" ]; + type = types.enum [ + "dhcpcd" + "internal" + ]; default = "internal"; description = '' Which program (or internal library) should be used for DHCP. @@ -222,7 +249,14 @@ in }; logLevel = mkOption { - type = types.enum [ "OFF" "ERR" "WARN" "INFO" "DEBUG" "TRACE" ]; + type = types.enum [ + "OFF" + "ERR" + "WARN" + "INFO" + "DEBUG" + "TRACE" + ]; default = "WARN"; description = '' Set the default logging verbosity level. @@ -253,7 +287,10 @@ in macAddress = macAddressOptWifi; backend = mkOption { - type = types.enum [ "wpa_supplicant" "iwd" ]; + type = types.enum [ + "wpa_supplicant" + "iwd" + ]; default = "wpa_supplicant"; description = '' Specify the Wi-Fi backend used for the device. @@ -280,7 +317,12 @@ in }; dns = mkOption { - type = types.enum [ "default" "dnsmasq" "systemd-resolved" "none" ]; + type = types.enum [ + "default" + "dnsmasq" + "systemd-resolved" + "none" + ]; default = "default"; description = '' Set the DNS (`resolv.conf`) processing mode. @@ -295,27 +337,29 @@ in }; dispatcherScripts = mkOption { - type = types.listOf (types.submodule { - options = { - source = mkOption { - type = types.path; - description = '' - Path to the hook script. - ''; - }; + type = types.listOf ( + types.submodule { + options = { + source = mkOption { + type = types.path; + description = '' + Path to the hook script. + ''; + }; - type = mkOption { - type = types.enum (attrNames dispatcherTypesSubdirMap); - default = "basic"; - description = '' - Dispatcher hook type. Look up the hooks described at - [https://developer.gnome.org/NetworkManager/stable/NetworkManager.html](https://developer.gnome.org/NetworkManager/stable/NetworkManager.html) - and choose the type depending on the output folder. - You should then filter the event type (e.g., "up"/"down") from within your script. - ''; + type = mkOption { + type = types.enum (attrNames dispatcherTypesSubdirMap); + default = "basic"; + description = '' + Dispatcher hook type. Look up the hooks described at + [https://developer.gnome.org/NetworkManager/stable/NetworkManager.html](https://developer.gnome.org/NetworkManager/stable/NetworkManager.html) + and choose the type depending on the output folder. + You should then filter the event type (e.g., "up"/"down") from within your script. + ''; + }; }; - }; - }); + } + ); default = [ ]; example = literalExpression '' [ { @@ -350,66 +394,68 @@ in }; ensureProfiles = { - profiles = with lib.types; mkOption { - type = attrsOf (submodule { - freeformType = ini.type; + profiles = + with lib.types; + mkOption { + type = attrsOf (submodule { + freeformType = ini.type; - options = { - connection = { - id = lib.mkOption { - type = str; - description = "This is the name that will be displayed by NetworkManager and GUIs."; + options = { + connection = { + id = lib.mkOption { + type = str; + description = "This is the name that will be displayed by NetworkManager and GUIs."; + }; + type = lib.mkOption { + type = str; + description = "The connection type defines the connection kind, like vpn, wireguard, gsm, wifi and more."; + example = "vpn"; + }; }; - type = lib.mkOption { - type = str; - description = "The connection type defines the connection kind, like vpn, wireguard, gsm, wifi and more."; - example = "vpn"; + }; + }); + apply = (lib.filterAttrsRecursive (n: v: v != { })); + default = { }; + example = { + home-wifi = { + connection = { + id = "home-wifi"; + type = "wifi"; + permissions = ""; + }; + wifi = { + mac-address-blacklist = ""; + mode = "infrastructure"; + ssid = "Home Wi-Fi"; + }; + wifi-security = { + auth-alg = "open"; + key-mgmt = "wpa-psk"; + psk = "$HOME_WIFI_PASSWORD"; + }; + ipv4 = { + dns-search = ""; + method = "auto"; + }; + ipv6 = { + addr-gen-mode = "stable-privacy"; + dns-search = ""; + method = "auto"; }; }; }; - }); - apply = (lib.filterAttrsRecursive (n: v: v != { })); - default = { }; - example = { - home-wifi = { - connection = { - id = "home-wifi"; - type = "wifi"; - permissions = ""; - }; - wifi = { - mac-address-blacklist = ""; - mode = "infrastructure"; - ssid = "Home Wi-Fi"; - }; - wifi-security = { - auth-alg = "open"; - key-mgmt = "wpa-psk"; - psk = "$HOME_WIFI_PASSWORD"; - }; - ipv4 = { - dns-search = ""; - method = "auto"; - }; - ipv6 = { - addr-gen-mode = "stable-privacy"; - dns-search = ""; - method = "auto"; - }; - }; + description = '' + Declaratively define NetworkManager profiles. You can find information about the generated file format [here](https://networkmanager.dev/docs/api/latest/nm-settings-keyfile.html) and [here](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/assembly_networkmanager-connection-profiles-in-keyfile-format_configuring-and-managing-networking). + You current profiles which are most likely stored in `/etc/NetworkManager/system-connections` and there is [a tool](https://github.com/janik-haag/nm2nix) to convert them to the needed nix code. + If you add a new ad-hoc connection via a GUI or nmtui or anything similar it should just work together with the declarative ones. + And if you edit a declarative profile NetworkManager will move it to the persistent storage and treat it like a ad-hoc one, + but there will be two profiles as soon as the systemd unit from this option runs again which can be confusing since NetworkManager tools will start displaying two profiles with the same name and probably a bit different settings depending on what you edited. + A profile won't be deleted even if it's removed from the config until the system reboots because that's when NetworkManager clears it's temp directory. + If `networking.resolvconf.enable` is true, attributes affecting the name resolution (such as `ignore-auto-dns`) may not end up changing `/etc/resolv.conf` as expected when other name services (for example `networking.dhcpcd`) are enabled. Run `resolvconf -l` in the terminal to see what each service produces. + ''; }; - description = '' - Declaratively define NetworkManager profiles. You can find information about the generated file format [here](https://networkmanager.dev/docs/api/latest/nm-settings-keyfile.html) and [here](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/assembly_networkmanager-connection-profiles-in-keyfile-format_configuring-and-managing-networking). - You current profiles which are most likely stored in `/etc/NetworkManager/system-connections` and there is [a tool](https://github.com/janik-haag/nm2nix) to convert them to the needed nix code. - If you add a new ad-hoc connection via a GUI or nmtui or anything similar it should just work together with the declarative ones. - And if you edit a declarative profile NetworkManager will move it to the persistent storage and treat it like a ad-hoc one, - but there will be two profiles as soon as the systemd unit from this option runs again which can be confusing since NetworkManager tools will start displaying two profiles with the same name and probably a bit different settings depending on what you edited. - A profile won't be deleted even if it's removed from the config until the system reboots because that's when NetworkManager clears it's temp directory. - If `networking.resolvconf.enable` is true, attributes affecting the name resolution (such as `ignore-auto-dns`) may not end up changing `/etc/resolv.conf` as expected when other name services (for example `networking.dhcpcd`) are enabled. Run `resolvconf -l` in the terminal to see what each service produces. - ''; - }; environmentFiles = mkOption { - default = []; + default = [ ]; type = types.listOf types.path; example = [ "/run/secrets/network-manager.env" ]; description = '' @@ -444,8 +490,7 @@ in + settings.main.no-auto-default = "*"; }; ``` - '' - ) + '') (mkRemovedOptionModule [ "networking" "networkmanager" "enableFccUnlock" ] '' This option was removed, because using bundled FCC unlock scripts is risky, might conflict with vendor-provided unlock scripts, and should @@ -470,7 +515,6 @@ in ) ]; - ###### implementation config = mkIf cfg.enable { @@ -487,31 +531,38 @@ in hardware.wirelessRegulatoryDatabase = true; - environment.etc = { - "NetworkManager/NetworkManager.conf".source = configFile; - - # The networkmanager-l2tp plugin expects /etc/ipsec.secrets to include /etc/ipsec.d/ipsec.nm-l2tp.secrets; - # see https://github.com/NixOS/nixpkgs/issues/64965 - "ipsec.secrets".text = '' - include ipsec.d/ipsec.nm-l2tp.secrets - ''; - } - // builtins.listToAttrs (map - (pkg: nameValuePair "NetworkManager/${pkg.networkManagerPlugin}" { - source = "${pkg}/lib/NetworkManager/${pkg.networkManagerPlugin}"; - }) - cfg.plugins) - // optionalAttrs (cfg.appendNameservers != [ ] || cfg.insertNameservers != [ ]) + environment.etc = { + "NetworkManager/NetworkManager.conf".source = configFile; + + # The networkmanager-l2tp plugin expects /etc/ipsec.secrets to include /etc/ipsec.d/ipsec.nm-l2tp.secrets; + # see https://github.com/NixOS/nixpkgs/issues/64965 + "ipsec.secrets".text = '' + include ipsec.d/ipsec.nm-l2tp.secrets + ''; + } + // builtins.listToAttrs ( + map ( + pkg: + nameValuePair "NetworkManager/${pkg.networkManagerPlugin}" { + source = "${pkg}/lib/NetworkManager/${pkg.networkManagerPlugin}"; + } + ) cfg.plugins + ) + // optionalAttrs (cfg.appendNameservers != [ ] || cfg.insertNameservers != [ ]) { "NetworkManager/dispatcher.d/02overridedns".source = overrideNameserversScript; } - // listToAttrs (lib.imap1 - (i: s: - { - name = "NetworkManager/dispatcher.d/${dispatcherTypesSubdirMap.${s.type}}03userscript${lib.fixedWidthNumber 4 i}"; - value = { mode = "0544"; inherit (s) source; }; - }) - cfg.dispatcherScripts); + // listToAttrs ( + lib.imap1 (i: s: { + name = "NetworkManager/dispatcher.d/${ + dispatcherTypesSubdirMap.${s.type} + }03userscript${lib.fixedWidthNumber 4 i}"; + value = { + mode = "0544"; + inherit (s) source; + }; + }) cfg.dispatcherScripts + ); environment.systemPackages = packages; @@ -562,10 +613,17 @@ in systemd.services.NetworkManager-dispatcher = { wantedBy = [ "network.target" ]; - restartTriggers = [ configFile overrideNameserversScript ]; + restartTriggers = [ + configFile + overrideNameserversScript + ]; # useful binaries for user-specified hooks - path = [ pkgs.iproute2 pkgs.util-linux pkgs.coreutils ]; + path = [ + pkgs.iproute2 + pkgs.util-linux + pkgs.coreutils + ]; aliases = [ "dbus-org.freedesktop.nm-dispatcher.service" ]; }; @@ -574,17 +632,19 @@ in wantedBy = [ "multi-user.target" ]; before = [ "network-online.target" ]; after = [ "NetworkManager.service" ]; - script = let - path = id: "/run/NetworkManager/system-connections/${id}.nmconnection"; - in '' - mkdir -p /run/NetworkManager/system-connections - '' + lib.concatMapStringsSep "\n" - (profile: '' + script = + let + path = id: "/run/NetworkManager/system-connections/${id}.nmconnection"; + in + '' + mkdir -p /run/NetworkManager/system-connections + '' + + lib.concatMapStringsSep "\n" (profile: '' ${pkgs.envsubst}/bin/envsubst -i ${ini.generate (lib.escapeShellArg profile.n) profile.v} > ${path (lib.escapeShellArg profile.n)} '') (lib.mapAttrsToList (n: v: { inherit n v; }) cfg.ensureProfiles.profiles) - + '' - ${pkgs.networkmanager}/bin/nmcli connection reload - ''; + + '' + ${pkgs.networkmanager}/bin/nmcli connection reload + ''; serviceConfig = { EnvironmentFile = cfg.ensureProfiles.environmentFiles; UMask = "0177"; @@ -625,9 +685,12 @@ in "ethernet.cloned-mac-address" = cfg.ethernet.macAddress; "wifi.cloned-mac-address" = cfg.wifi.macAddress; "wifi.powersave" = - if cfg.wifi.powersave == null then null - else if cfg.wifi.powersave then 3 - else 2; + if cfg.wifi.powersave == null then + null + else if cfg.wifi.powersave then + 3 + else + 2; }; } ]; @@ -637,7 +700,8 @@ in security.polkit.enable = true; security.polkit.extraConfig = polkitConf; - services.dbus.packages = packages + services.dbus.packages = + packages ++ optional cfg.enableStrongSwan pkgs.strongswanNM ++ optional (cfg.dns == "dnsmasq") pkgs.dnsmasq; From 9d4d21b587dd283344fd225a90bd00314ae39659 Mon Sep 17 00:00:00 2001 From: Colin Date: Sun, 2 Jun 2024 05:54:25 +0000 Subject: [PATCH 3/4] nixos/modemmanager: add a `package` option this is helpful for testing module changes or making downstream patches in a way which doesn't force large rebuilds as an overlay would. --- .../services/networking/modemmanager.nix | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/networking/modemmanager.nix b/nixos/modules/services/networking/modemmanager.nix index 7cb399bf76a8..fefee7a448eb 100644 --- a/nixos/modules/services/networking/modemmanager.nix +++ b/nixos/modules/services/networking/modemmanager.nix @@ -1,4 +1,9 @@ -{ config, lib, ... }: +{ + config, + lib, + pkgs, + ... +}: let cfg = config.networking.modemmanager; in @@ -20,6 +25,8 @@ in ''; }; + package = mkPackageOption pkgs "modemmanager" { }; + fccUnlockScripts = mkOption { type = types.listOf ( types.submodule { @@ -82,9 +89,9 @@ in }); ''; - environment.systemPackages = [ pkgs.modemmanager ]; - systemd.packages = [ pkgs.modemmanager ]; - services.dbus.packages = [ pkgs.modemmanager ]; - services.udev.packages = [ pkgs.modemmanager ]; + environment.systemPackages = [ cfg.package ]; + systemd.packages = [ cfg.package ]; + services.dbus.packages = [ cfg.package ]; + services.udev.packages = [ cfg.package ]; }; } From efc3208be2c7ebaf28aae15fa60f3f447f5d2c13 Mon Sep 17 00:00:00 2001 From: Colin Date: Sun, 2 Jun 2024 05:57:51 +0000 Subject: [PATCH 4/4] nixos/networkmanager: add a `package` option this is helpful for testing module changes or making downstream patches in a way which doesn't force large rebuilds as an overlay would. --- nixos/modules/services/networking/networkmanager.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/nixos/modules/services/networking/networkmanager.nix b/nixos/modules/services/networking/networkmanager.nix index c46ba8fce7b1..caa7b0fffffd 100644 --- a/nixos/modules/services/networking/networkmanager.nix +++ b/nixos/modules/services/networking/networkmanager.nix @@ -129,7 +129,7 @@ let packages = [ - pkgs.networkmanager + cfg.package ] ++ cfg.plugins ++ lib.optionals (!delegateWireless && !enableIwd) [ @@ -161,6 +161,8 @@ in ''; }; + package = mkPackageOption pkgs "networkmanager" { }; + connectionConfig = mkOption { type = with types; @@ -643,7 +645,7 @@ in ${pkgs.envsubst}/bin/envsubst -i ${ini.generate (lib.escapeShellArg profile.n) profile.v} > ${path (lib.escapeShellArg profile.n)} '') (lib.mapAttrsToList (n: v: { inherit n v; }) cfg.ensureProfiles.profiles) + '' - ${pkgs.networkmanager}/bin/nmcli connection reload + ${cfg.package}/bin/nmcli connection reload ''; serviceConfig = { EnvironmentFile = cfg.ensureProfiles.environmentFiles;