nixos/adguardhome: allow AF_UNIX when log.file=="syslog" (#532141)

This commit is contained in:
Gergő Gutyina
2026-09-28 09:30:08 +00:00
committed by GitHub
2 changed files with 16 additions and 0 deletions

View File

@@ -240,6 +240,8 @@ in
"AF_INET"
"AF_INET6"
]
# AF_UNIX to be able to connect to e.g. /dev/log
++ lib.optionals (cfg.settings.log.file or "" == "syslog") [ "AF_UNIX" ]
++ lib.optionals cfg.allowDHCP [ "AF_PACKET" ];
RestrictNamespaces = true;
RestrictRealtime = true;

View File

@@ -22,6 +22,14 @@
};
};
syslogConf = {
services.adguardhome = {
enable = true;
settings.log.file = "syslog";
};
};
declarativeConf = {
services.adguardhome = {
enable = true;
@@ -127,6 +135,12 @@
schemaVersionBefore23.wait_for_unit("adguardhome.service")
schemaVersionBefore23.wait_for_open_port(3000)
with subtest("Logging to syslog test"):
# AdGuard is expected to fail when it cannot connect to syslog
# hence its sufficient to look whether the service starts at all
syslogConf.wait_for_unit("adguardhome.service")
syslogConf.wait_for_open_port(3000)
with subtest("Declarative config test, DNS will be reachable"):
declarativeConf.wait_for_unit("adguardhome.service")
declarativeConf.wait_for_open_port(53)