diff --git a/nixos/modules/services/home-automation/openthread-border-router.nix b/nixos/modules/services/home-automation/openthread-border-router.nix index 5be4facce644..4d0c84e5b204 100644 --- a/nixos/modules/services/home-automation/openthread-border-router.nix +++ b/nixos/modules/services/home-automation/openthread-border-router.nix @@ -19,12 +19,6 @@ let "debug" = 7; }; logLevel = lib.getAttr cfg.logLevel logLevelMappings; - # Use correct iptables for otbr-firewall (legacy vs nf-compat) - iptables = - let - inherit (config.networking) firewall; - in - if firewall.backend == "iptables" then firewall.package else pkgs.iptables; in { meta.maintainers = with lib.maintainers; [ @@ -221,7 +215,6 @@ in }; serviceConfig = { Group = "otbr"; - ExecStartPre = "${utils.escapeSystemdExecArg (lib.getExe' cfg.package "otbr-firewall")} start"; ExecStart = lib.concatStringsSep " " ( lib.concatLists [ [ @@ -242,7 +235,6 @@ in (map utils.escapeSystemdExecArg cfg.extraArgs) ] ); - ExecStopPost = "${utils.escapeSystemdExecArg (lib.getExe' cfg.package "otbr-firewall")} stop"; KillMode = "mixed"; Restart = "on-failure"; RestartSec = 5; @@ -280,10 +272,6 @@ in "CAP_NET_RAW" ]; }; - path = [ - pkgs.ipset - iptables - ]; }; # Sync with: src/web/otbr-web.service.in diff --git a/pkgs/by-name/op/openthread-border-router/firewall-script.patch b/pkgs/by-name/op/openthread-border-router/firewall-script.patch deleted file mode 100644 index 013e5b18748b..000000000000 --- a/pkgs/by-name/op/openthread-border-router/firewall-script.patch +++ /dev/null @@ -1,16 +0,0 @@ -diff --git a/script/otbr-firewall b/script/otbr-firewall ---- a/script/otbr-firewall -+++ b/script/otbr-firewall -@@ -38,12 +38,8 @@ - # Description: This service sets up firewall for OTBR. - ### END INIT INFO - --THREAD_IF="wpan0" - OTBR_FORWARD_INGRESS_CHAIN="OTBR_FORWARD_INGRESS" - --. /lib/lsb/init-functions --. /lib/init/vars.sh -- - set -euxo pipefail - - ipset_destroy_if_exist() diff --git a/pkgs/by-name/op/openthread-border-router/package.nix b/pkgs/by-name/op/openthread-border-router/package.nix index 5f968dc5d0c8..e417729167bd 100644 --- a/pkgs/by-name/op/openthread-border-router/package.nix +++ b/pkgs/by-name/op/openthread-border-router/package.nix @@ -12,16 +12,18 @@ cjson, bashNonInteractive, buildNpmPackage, + libnftnl, + libmnl, }: let pname = "openthread-border-router"; - version = "2026.06.0"; + version = "2026.09.0"; src = fetchFromGitHub { owner = "openthread"; repo = "ot-br-posix"; tag = "v${version}"; - hash = "sha256-7si62h1nXnAzEmloThCcOeY3VhfSIFV+7kWKgJywcvk="; + hash = "sha256-b/RuAy/A1e5kWJ2x4+/sZ7VDGW1StiXMF/g6kXHSoWQ="; fetchSubmodules = true; }; @@ -29,7 +31,7 @@ let pname = "${pname}-frontend"; inherit version; src = "${src}/src/web/web-service/frontend"; - npmDepsHash = "sha256-7UVfPICyIbHEClpr3p7eDR46OUzS8mVf6P7phnDpVLk="; + npmDepsHash = "sha256-8KenFVtfxC0jkfZHHuYeV2Dj2kmzHUQTeACvRtOyZLA="; dontNpmBuild = true; }; in @@ -39,11 +41,6 @@ stdenv.mkDerivation { strictDeps = true; __structuredAttrs = true; - patches = [ - # Patch the firewall script so we can run it within the systemd start script - ./firewall-script.patch - ]; - nativeBuildInputs = [ pkg-config cmake @@ -62,6 +59,8 @@ stdenv.mkDerivation { dbus cjson (lib.getBin bashNonInteractive) + libnftnl + libmnl ]; postInstall = '' @@ -69,11 +68,8 @@ stdenv.mkDerivation { ''; cmakeFlags = [ - (lib.cmakeFeature "CMAKE_POLICY_VERSION_MINIMUM" "3.5") - (lib.cmakeBool "BUILD_TESTING" false) (lib.cmakeBool "INSTALL_SYSTEMD_UNIT" false) - (lib.cmakeBool "Boost_USE_STATIC_LIBS" false) (lib.cmakeBool "OTBR_REST" true) # OpenThread's built-in mDNS publisher (upstream default). No Avahi daemon needed. @@ -85,6 +81,7 @@ stdenv.mkDerivation { (lib.cmakeBool "OTBR_BORDER_ROUTING" true) (lib.cmakeBool "OTBR_DBUS" true) (lib.cmakeBool "OTBR_TREL" true) + (lib.cmakeBool "OTBR_NFTABLES" true) (lib.cmakeFeature "OTBR_VERSION" version) # otbr-agent aborts on startup with "Vendor name must be set." unless a vendor