nixos/nebula: fix inverted tun.device length assertion

Resolves #565467.

Assisted-by: OpenCode (kimi-k3)
This commit is contained in:
Amadeus Mader
2026-09-21 12:54:00 +02:00
parent 110e5a0f98
commit a2fbe4fa45
4 changed files with 46 additions and 1 deletions

View File

@@ -292,7 +292,7 @@ in
assertions = lib.mapAttrsToList (netName: netCfg: {
# IFNAMSIZ caps network device names to 16 chars (including NULL terminator).
# Without this check, users might end up with a truncated interface name.
assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15;
assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15;
message = ''
Network device names can't be longer than 15 chars.
`config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit.

View File

@@ -1241,6 +1241,7 @@ in
nebula-lighthouse-service = runTest ./nebula-lighthouse-service.nix;
nebula.connectivity = runTest ./nebula/connectivity.nix;
nebula.reload = runTest ./nebula/reload.nix;
nebula.tunless = runTest ./nebula/tunless.nix;
neo4j = runTest ./neo4j.nix;
netbird = runTest ./netbird.nix;
netbird-relay = runTest ./netbird-relay.nix;

View File

@@ -0,0 +1,43 @@
{ ... }:
{
name = "nebula";
nodes = {
lighthouse =
{ pkgs, ... }:
{
environment.systemPackages = [ pkgs.nebula ];
services.nebula.networks.smoke = {
# Note that these paths won't exist when the machine is first booted.
ca = "/etc/nebula/ca.crt";
cert = "/etc/nebula/lighthouse.crt";
key = "/etc/nebula/lighthouse.key";
isLighthouse = true;
listen = {
host = "0.0.0.0";
port = 4242;
};
# A lighthouse can run without a tun interface. The device name is
# unused then, so the length assertion must not apply to it.
tun.disable = true;
};
};
};
testScript = ''
# Create the certificate and sign the lighthouse's keys.
lighthouse.succeed(
"mkdir -p /etc/nebula",
'nebula-cert ca -duration $((10*365*24*60))m -name "Smoke Test" -out-crt /etc/nebula/ca.crt -out-key /etc/nebula/ca.key',
'nebula-cert sign -duration $((365*24*60))m -ca-crt /etc/nebula/ca.crt -ca-key /etc/nebula/ca.key -name "lighthouse" -groups "lighthouse" -networks "10.0.100.1/24" -out-crt /etc/nebula/lighthouse.crt -out-key /etc/nebula/lighthouse.key',
'chown -R nebula-smoke:nebula-smoke /etc/nebula'
)
# Restart nebula to pick up the keys and verify it listens without creating a tun device.
lighthouse.systemctl("restart nebula@smoke.service")
lighthouse.wait_for_unit("nebula@smoke.service")
lighthouse.wait_until_succeeds("ss -lun | grep -q ':4242'", timeout=10)
lighthouse.fail("ip link show nebula.smoke")
'';
}

View File

@@ -54,6 +54,7 @@ buildGoModule (finalAttrs: {
inherit (nixosTests.nebula)
connectivity
reload
tunless
;
};