From f9be47e08cd957bfddb93fa080810798057be047 Mon Sep 17 00:00:00 2001 From: Michael Hoang Date: Sat, 16 Dec 2023 12:53:30 +1100 Subject: [PATCH 1/2] nixos/mosh: use `mkEnableOption` --- nixos/modules/programs/mosh.nix | 20 ++++++-------------- 1 file changed, 6 insertions(+), 14 deletions(-) diff --git a/nixos/modules/programs/mosh.nix b/nixos/modules/programs/mosh.nix index 9e56e1731d7c..012cd2c895d9 100644 --- a/nixos/modules/programs/mosh.nix +++ b/nixos/modules/programs/mosh.nix @@ -1,7 +1,5 @@ { config, lib, pkgs, ... }: -with lib; - let cfg = config.programs.mosh; @@ -9,28 +7,22 @@ let in { options.programs.mosh = { - enable = mkOption { - description = lib.mdDoc '' - Whether to enable mosh. Note, this will open ports in your firewall! - ''; - default = false; - type = lib.types.bool; - }; - withUtempter = mkOption { + enable = lib.mkEnableOption "mosh"; + withUtempter = lib.mkEnableOption "" // { description = lib.mdDoc '' Whether to enable libutempter for mosh. + This is required so that mosh can write to /var/run/utmp (which can be queried with `who` to display currently connected user sessions). Note, this will add a guid wrapper for the group utmp! ''; default = true; - type = lib.types.bool; }; }; - config = mkIf cfg.enable { - environment.systemPackages = with pkgs; [ mosh ]; + config = lib.mkIf cfg.enable { + environment.systemPackages = [ pkgs.mosh ]; networking.firewall.allowedUDPPortRanges = [ { from = 60000; to = 61000; } ]; - security.wrappers = mkIf cfg.withUtempter { + security.wrappers = lib.mkIf cfg.withUtempter { utempter = { source = "${pkgs.libutempter}/lib/utempter/utempter"; owner = "root"; From 5a211498edf9d124a5bcb647ca78a20d73c61cbe Mon Sep 17 00:00:00 2001 From: Michael Hoang Date: Sun, 10 Dec 2023 21:16:09 +1100 Subject: [PATCH 2/2] nixos/mosh: add `programs.mosh.openFirewall` --- nixos/modules/programs/mosh.nix | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/nixos/modules/programs/mosh.nix b/nixos/modules/programs/mosh.nix index 012cd2c895d9..593246ab6dcd 100644 --- a/nixos/modules/programs/mosh.nix +++ b/nixos/modules/programs/mosh.nix @@ -8,6 +8,10 @@ in { options.programs.mosh = { enable = lib.mkEnableOption "mosh"; + openFirewall = lib.mkEnableOption "" // { + description = "Whether to automatically open the necessary ports in the firewall."; + default = true; + }; withUtempter = lib.mkEnableOption "" // { description = lib.mdDoc '' Whether to enable libutempter for mosh. @@ -21,7 +25,7 @@ in config = lib.mkIf cfg.enable { environment.systemPackages = [ pkgs.mosh ]; - networking.firewall.allowedUDPPortRanges = [ { from = 60000; to = 61000; } ]; + networking.firewall.allowedUDPPortRanges = lib.optional cfg.openFirewall { from = 60000; to = 61000; }; security.wrappers = lib.mkIf cfg.withUtempter { utempter = { source = "${pkgs.libutempter}/lib/utempter/utempter";