diff --git a/nixos/modules/services/networking/adguardhome.nix b/nixos/modules/services/networking/adguardhome.nix index 941d668397d9..902a4f735b70 100644 --- a/nixos/modules/services/networking/adguardhome.nix +++ b/nixos/modules/services/networking/adguardhome.nix @@ -240,6 +240,8 @@ in "AF_INET" "AF_INET6" ] + # AF_UNIX to be able to connect to e.g. /dev/log + ++ lib.optionals (cfg.settings.log.file or "" == "syslog") [ "AF_UNIX" ] ++ lib.optionals cfg.allowDHCP [ "AF_PACKET" ]; RestrictNamespaces = true; RestrictRealtime = true; diff --git a/nixos/tests/adguardhome.nix b/nixos/tests/adguardhome.nix index 89048fd987a3..ab115e5db564 100644 --- a/nixos/tests/adguardhome.nix +++ b/nixos/tests/adguardhome.nix @@ -22,6 +22,14 @@ }; }; + syslogConf = { + services.adguardhome = { + enable = true; + + settings.log.file = "syslog"; + }; + }; + declarativeConf = { services.adguardhome = { enable = true; @@ -127,6 +135,12 @@ schemaVersionBefore23.wait_for_unit("adguardhome.service") schemaVersionBefore23.wait_for_open_port(3000) + with subtest("Logging to syslog test"): + # AdGuard is expected to fail when it cannot connect to syslog + # hence its sufficient to look whether the service starts at all + syslogConf.wait_for_unit("adguardhome.service") + syslogConf.wait_for_open_port(3000) + with subtest("Declarative config test, DNS will be reachable"): declarativeConf.wait_for_unit("adguardhome.service") declarativeConf.wait_for_open_port(53)